HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.MulDrop6.37406 (DrWeb), Artemis!D3956BF8E2B8 (McAfee), Trojan.Agent (Ikarus), Gen:Variant.Symmi.59849 (FSecure), Atros3.AECM.dropper (AVG), Win32:BackDoor-ACX [Trj] (Avast), Gen:Variant.Symmi.59849 (AdAware), Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericInjector.YR (Lavasoft MAS)Behaviour: Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: d3956bf8e2b8c3c5f444988fdf1a4ba9
SHA1: 0363b512f7c225fb67cf1aad6ac86ce50a66e7d3
SHA256: 27f255199df7308f3b9a65c2dc96b7dfd7eba34e15f09064ca0b237458470729
SSDeep: 196608:6IJZr93L3aTz5znkqPU3oaTwwTLGtMAcQSJ:TJZx3mTz qPUYhKLsMn
Size: 6419968 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-10-14 08:50:27
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1144
server.exe:868
The Trojan injects its code into the following process(es):
delet.exe:1088
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1144 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\server.exe (12280 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\MINECR~1.EXE (103687 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\server.exe (0 bytes)
The process server.exe:868 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\delet.exe (3742 bytes)
Registry activity
The process %original file name%.exe:1144 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AF A2 DE D2 3B 6B 3B C6 D5 F3 35 F1 49 58 D7 AF"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0"
The process server.exe:868 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C0 F9 6C 88 05 77 5D 1E 12 1C A8 7C FE 95 D0 C2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Application Data]
"delet.exe" = "delet"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process delet.exe:1088 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "41 BB 00 3A 30 22 AC 33 78 AA 4E 57 F1 C8 68 77"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DtServ32sm.exe" = "%Documents and Settings%\%current user%\Application Data\delet.exe"
Dropped PE files
MD5 | File path |
---|---|
24bf5f1bd4fa93eacdb198629a063fe6 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\.minecraft\Minecraft_Launcher.exe |
56179e0c5f021e4907cf01873ff5baeb | c:\Documents and Settings\"%CurrentUserName%"\Application Data\delet.exe |
0f61afdd36c1f3502302cc9d8053fee6 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\MINECR~1.EXE |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1144
server.exe:868 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\server.exe (12280 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\MINECR~1.EXE (103687 bytes)
%Documents and Settings%\%current user%\Application Data\delet.exe (3742 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DtServ32sm.exe" = "%Documents and Settings%\%current user%\Application Data\delet.exe" - Reboot the computer.
Static Analysis
VersionInfo
Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16428
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: Language Neutral
Company Name: Microsoft CorporationProduct Name: Internet ExplorerProduct Version: 11.00.9600.16428Legal Copyright: (c) Microsoft Corporation. All rights reserved.Legal Trademarks: Original Filename: WEXTRACT.EXE .MUIInternal Name: Wextract File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)File Description: Win32 Cabinet Self-Extractor Comments: Language: Language Neutral
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 26060 | 26112 | 4.42567 | e9bf1a1e456a9a811b1b86e6602e3636 |
.data | 32768 | 6796 | 1024 | 2.20139 | 317f8a934ee443eee01c2a315bde9ca1 |
.idata | 40960 | 4216 | 4608 | 3.49941 | d8675ba112ef922c6057a02546757a1a |
.rsrc | 49152 | 6385664 | 6382080 | 5.54291 | bb97440fe02eb11a41aba48a706229cf |
.reloc | 6434816 | 5038 | 5120 | 2.58043 | 83de2f9b2c95be6fea06bced7e8a058e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
javaw.exe_484:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
/Xusage.txt
/Xusage.txt
-Djava.class.path=%s
-Djava.class.path=%s
Unable to locate JRE meeting specification "%s"
Unable to locate JRE meeting specification "%s"
1.6.0_18-b07
1.6.0_18-b07
JRE-Version = %s, JRE-Restrict-Search = %s Selected = %s
JRE-Version = %s, JRE-Restrict-Search = %s Selected = %s
Syntax error in version specification "%s"
Syntax error in version specification "%s"
Invalid or corrupt jarfile %s
Invalid or corrupt jarfile %s
Unable to access jarfile %s
Unable to access jarfile %s
-Djava.awt.headless=
-Djava.awt.headless=
-Djava.awt.headless=true
-Djava.awt.headless=true
option[-] = '%s'
option[-] = '%s'
ignoreUnrecognized is %s,
ignoreUnrecognized is %s,
sun.jnu.encoding
sun.jnu.encoding
isSupported
isSupported
-Dsun.java.command=
-Dsun.java.command=
-Dsun.java.launcher=SUN_STANDARD
-Dsun.java.launcher=SUN_STANDARD
A %c separated list of directories, JAR archives,
A %c separated list of directories, JAR archives,
load Java programming language agent, see java.lang.instrument
load Java programming language agent, see java.lang.instrument
The default VM is %s%s
The default VM is %s%s
is a synonym for the "%s" VM [deprecated]
is a synonym for the "%s" VM [deprecated]
to select the "%s" VM
to select the "%s" VM
Usage: %s [-options] class [args...]
Usage: %s [-options] class [args...]
(to execute a class)
(to execute a class)
or %s [-options] -jar jarfile [args...]
or %s [-options] -jar jarfile [args...]
(to execute a jar file)
(to execute a jar file)
Can't open %s
Can't open %s
Could not find the main class: %s. Program will exit.
Could not find the main class: %s. Program will exit.
Failed to load Main Class: %s
Failed to load Main Class: %s
Could not find the main class: %s. Program will exit.
Could not find the main class: %s. Program will exit.
argv[-] = '%s'
argv[-] = '%s'
Apps' argc is %d
Apps' argc is %d
Main-Class is '%s'
Main-Class is '%s'
Warning: %s VM not supported; %s VM will be used
Warning: %s VM not supported; %s VM will be used
Error: %s VM not supported
Error: %s VM not supported
Error: Unable to resolve VM alias %s
Error: Unable to resolve VM alias %s
Error: Corrupt jvm.cfg file; cycle in alias list.
Error: Corrupt jvm.cfg file; cycle in alias list.
Default VM: %s
Default VM: %s
%s requires class path specification
%s requires class path specification
%s full version "%s"
%s full version "%s"
Warning: %s option is no longer supported.
Warning: %s option is no longer supported.
-Xrunhprof:cpu=old,file=java.prof
-Xrunhprof:cpu=old,file=java.prof
-Xrunhprof:cpu=old,file=%s
-Xrunhprof:cpu=old,file=%s
%ld micro seconds to parse jvm.cfg
%ld micro seconds to parse jvm.cfg
name: %s vmType: %s alias: %s
name: %s vmType: %s alias: %s
name: %s vmType: %s server_class: %s
name: %s vmType: %s server_class: %s
jvm.cfg[%d] = ->%s
jvm.cfg[%d] = ->%s
Warning: unknown VM type on line %d of `%s'
Warning: unknown VM type on line %d of `%s'
Warning: missing server class VM on line %d of `%s'
Warning: missing server class VM on line %d of `%s'
Warning: missing VM alias on line %d of `%s'
Warning: missing VM alias on line %d of `%s'
Warning: missing VM type on line %d of `%s'
Warning: missing VM type on line %d of `%s'
Warning: no leading - on line %d of `%s'
Warning: no leading - on line %d of `%s'
Error: could not open `%s'
Error: could not open `%s'
\jvm.cfg
\jvm.cfg
\bin\splashscreen.dll
\bin\splashscreen.dll
%s\jvm.dll
%s\jvm.dll
%s\bin\%s\jvm.dll
%s\bin\%s\jvm.dll
Version major.minor.micro = %s.%s
Version major.minor.micro = %s.%s
Failed reading value of registry key:
Failed reading value of registry key:
Software\JavaSoft\Java Runtime Environment\%s\JavaHome
Software\JavaSoft\Java Runtime Environment\%s\JavaHome
Error opening registry key 'Software\JavaSoft\Java Runtime Environment\%s'
Error opening registry key 'Software\JavaSoft\Java Runtime Environment\%s'
Registry key 'Software\JavaSoft\Java Runtime Environment\CurrentVersion'
Registry key 'Software\JavaSoft\Java Runtime Environment\CurrentVersion'
has value '%s', but '1.6' is required.
has value '%s', but '1.6' is required.
Error opening registry key 'Software\JavaSoft\Java Runtime Environment'
Error opening registry key 'Software\JavaSoft\Java Runtime Environment'
-Dsun.java2d.opengl
-Dsun.java2d.opengl
-Dsun.java2d.d3d
-Dsun.java2d.d3d
-Dsun.java2d.noddraw
-Dsun.java2d.noddraw
-Dsun.awt.warmup
-Dsun.awt.warmup
Unable to resolve path to current %s executable: %s
Unable to resolve path to current %s executable: %s
CreateProcess(%s, ...) failed: %s
CreateProcess(%s, ...) failed: %s
ReExec Args: %s
ReExec Args: %s
ReExec Command: %s (%s)
ReExec Command: %s (%s)
ExecJRE: new: %s
ExecJRE: new: %s
ExecJRE: old: %s
ExecJRE: old: %s
Error: could not find java.dll
Error: could not find java.dll
JRE path is %s
JRE path is %s
%s\jre\bin\java.dll
%s\jre\bin\java.dll
%s\bin\java.dll
%s\bin\java.dll
Error loading: %s
Error loading: %s
CRT path is %s
CRT path is %s
\bin\msvcr71.dll
\bin\msvcr71.dll
EnsureJreInstallation:%s:load failed
EnsureJreInstallation:%s:load failed
\bin\jkernel.dll
\bin\jkernel.dll
EnsureJreInstallation::not found
EnsureJreInstallation::not found
EnsureJreInstallation:unsupported platform
EnsureJreInstallation:unsupported platform
Error: can't find JNI interfaces in: %s
Error: can't find JNI interfaces in: %s
JVM path is %s
JVM path is %s
\bin\awt.dll
\bin\awt.dll
\bin\java.dll
\bin\java.dll
\bin\verify.dll
\bin\verify.dll
Error: no `%s' JVM at `%s'.
Error: no `%s' JVM at `%s'.
Error: no known VMs. (check for corrupt jvm.cfg file)
Error: no known VMs. (check for corrupt jvm.cfg file)
before: "%s"
before: "%s"
after : "%s"
after : "%s"
META-INF/MANIFEST.MF
META-INF/MANIFEST.MF
1.1.3
1.1.3
inflate 1.1.3 Copyright 1995-1998 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
mscoree.dll
mscoree.dll
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
kernel32.dll
kernel32.dll
- This application cannot run using the active version of the Microsoft .NET Runtime
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
Please contact the application's support team for more information.
GetProcessWindowStation
GetProcessWindowStation
user32.dll
user32.dll
internal state. The program cannot safely continue execution and must
internal state. The program cannot safely continue execution and must
continue execution and must now be terminated.
continue execution and must now be terminated.
C:\BUILD_~1\jdk6_18\control\build\WINDOW~1\tmp\java\javaw\obj\javaw.pdb
C:\BUILD_~1\jdk6_18\control\build\WINDOW~1\tmp\java\javaw\obj\javaw.pdb
RegCloseKey
RegCloseKey
RegOpenKeyExA
RegOpenKeyExA
RegEnumKeyA
RegEnumKeyA
ADVAPI32.dll
ADVAPI32.dll
USER32.dll
USER32.dll
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
%Program Files%\Java\jre6\bin\javaw.exe
%Program Files%\Java\jre6\bin\javaw.exe
name="javaw.exe"
name="javaw.exe"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
3333333333330
3333333333330
333333333307
333333333307
PP%d(jjjjj
PP%d(jjjjj
6.0.180.7
6.0.180.7
javaw.exe
javaw.exe
javaw.exe_1880:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
/Xusage.txt
/Xusage.txt
-Djava.class.path=%s
-Djava.class.path=%s
Unable to locate JRE meeting specification "%s"
Unable to locate JRE meeting specification "%s"
1.6.0_18-b07
1.6.0_18-b07
JRE-Version = %s, JRE-Restrict-Search = %s Selected = %s
JRE-Version = %s, JRE-Restrict-Search = %s Selected = %s
Syntax error in version specification "%s"
Syntax error in version specification "%s"
Invalid or corrupt jarfile %s
Invalid or corrupt jarfile %s
Unable to access jarfile %s
Unable to access jarfile %s
-Djava.awt.headless=
-Djava.awt.headless=
-Djava.awt.headless=true
-Djava.awt.headless=true
option[-] = '%s'
option[-] = '%s'
ignoreUnrecognized is %s,
ignoreUnrecognized is %s,
sun.jnu.encoding
sun.jnu.encoding
isSupported
isSupported
-Dsun.java.command=
-Dsun.java.command=
-Dsun.java.launcher=SUN_STANDARD
-Dsun.java.launcher=SUN_STANDARD
A %c separated list of directories, JAR archives,
A %c separated list of directories, JAR archives,
load Java programming language agent, see java.lang.instrument
load Java programming language agent, see java.lang.instrument
The default VM is %s%s
The default VM is %s%s
is a synonym for the "%s" VM [deprecated]
is a synonym for the "%s" VM [deprecated]
to select the "%s" VM
to select the "%s" VM
Usage: %s [-options] class [args...]
Usage: %s [-options] class [args...]
(to execute a class)
(to execute a class)
or %s [-options] -jar jarfile [args...]
or %s [-options] -jar jarfile [args...]
(to execute a jar file)
(to execute a jar file)
Can't open %s
Can't open %s
Could not find the main class: %s. Program will exit.
Could not find the main class: %s. Program will exit.
Failed to load Main Class: %s
Failed to load Main Class: %s
Could not find the main class: %s. Program will exit.
Could not find the main class: %s. Program will exit.
argv[-] = '%s'
argv[-] = '%s'
Apps' argc is %d
Apps' argc is %d
Main-Class is '%s'
Main-Class is '%s'
Warning: %s VM not supported; %s VM will be used
Warning: %s VM not supported; %s VM will be used
Error: %s VM not supported
Error: %s VM not supported
Error: Unable to resolve VM alias %s
Error: Unable to resolve VM alias %s
Error: Corrupt jvm.cfg file; cycle in alias list.
Error: Corrupt jvm.cfg file; cycle in alias list.
Default VM: %s
Default VM: %s
%s requires class path specification
%s requires class path specification
%s full version "%s"
%s full version "%s"
Warning: %s option is no longer supported.
Warning: %s option is no longer supported.
-Xrunhprof:cpu=old,file=java.prof
-Xrunhprof:cpu=old,file=java.prof
-Xrunhprof:cpu=old,file=%s
-Xrunhprof:cpu=old,file=%s
%ld micro seconds to parse jvm.cfg
%ld micro seconds to parse jvm.cfg
name: %s vmType: %s alias: %s
name: %s vmType: %s alias: %s
name: %s vmType: %s server_class: %s
name: %s vmType: %s server_class: %s
jvm.cfg[%d] = ->%s
jvm.cfg[%d] = ->%s
Warning: unknown VM type on line %d of `%s'
Warning: unknown VM type on line %d of `%s'
Warning: missing server class VM on line %d of `%s'
Warning: missing server class VM on line %d of `%s'
Warning: missing VM alias on line %d of `%s'
Warning: missing VM alias on line %d of `%s'
Warning: missing VM type on line %d of `%s'
Warning: missing VM type on line %d of `%s'
Warning: no leading - on line %d of `%s'
Warning: no leading - on line %d of `%s'
Error: could not open `%s'
Error: could not open `%s'
\jvm.cfg
\jvm.cfg
\bin\splashscreen.dll
\bin\splashscreen.dll
%s\jvm.dll
%s\jvm.dll
%s\bin\%s\jvm.dll
%s\bin\%s\jvm.dll
Version major.minor.micro = %s.%s
Version major.minor.micro = %s.%s
Failed reading value of registry key:
Failed reading value of registry key:
Software\JavaSoft\Java Runtime Environment\%s\JavaHome
Software\JavaSoft\Java Runtime Environment\%s\JavaHome
Error opening registry key 'Software\JavaSoft\Java Runtime Environment\%s'
Error opening registry key 'Software\JavaSoft\Java Runtime Environment\%s'
Registry key 'Software\JavaSoft\Java Runtime Environment\CurrentVersion'
Registry key 'Software\JavaSoft\Java Runtime Environment\CurrentVersion'
has value '%s', but '1.6' is required.
has value '%s', but '1.6' is required.
Error opening registry key 'Software\JavaSoft\Java Runtime Environment'
Error opening registry key 'Software\JavaSoft\Java Runtime Environment'
-Dsun.java2d.opengl
-Dsun.java2d.opengl
-Dsun.java2d.d3d
-Dsun.java2d.d3d
-Dsun.java2d.noddraw
-Dsun.java2d.noddraw
-Dsun.awt.warmup
-Dsun.awt.warmup
Unable to resolve path to current %s executable: %s
Unable to resolve path to current %s executable: %s
CreateProcess(%s, ...) failed: %s
CreateProcess(%s, ...) failed: %s
ReExec Args: %s
ReExec Args: %s
ReExec Command: %s (%s)
ReExec Command: %s (%s)
ExecJRE: new: %s
ExecJRE: new: %s
ExecJRE: old: %s
ExecJRE: old: %s
Error: could not find java.dll
Error: could not find java.dll
JRE path is %s
JRE path is %s
%s\jre\bin\java.dll
%s\jre\bin\java.dll
%s\bin\java.dll
%s\bin\java.dll
Error loading: %s
Error loading: %s
CRT path is %s
CRT path is %s
\bin\msvcr71.dll
\bin\msvcr71.dll
EnsureJreInstallation:%s:load failed
EnsureJreInstallation:%s:load failed
\bin\jkernel.dll
\bin\jkernel.dll
EnsureJreInstallation::not found
EnsureJreInstallation::not found
EnsureJreInstallation:unsupported platform
EnsureJreInstallation:unsupported platform
Error: can't find JNI interfaces in: %s
Error: can't find JNI interfaces in: %s
JVM path is %s
JVM path is %s
\bin\awt.dll
\bin\awt.dll
\bin\java.dll
\bin\java.dll
\bin\verify.dll
\bin\verify.dll
Error: no `%s' JVM at `%s'.
Error: no `%s' JVM at `%s'.
Error: no known VMs. (check for corrupt jvm.cfg file)
Error: no known VMs. (check for corrupt jvm.cfg file)
before: "%s"
before: "%s"
after : "%s"
after : "%s"
META-INF/MANIFEST.MF
META-INF/MANIFEST.MF
1.1.3
1.1.3
inflate 1.1.3 Copyright 1995-1998 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
mscoree.dll
mscoree.dll
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
kernel32.dll
kernel32.dll
- This application cannot run using the active version of the Microsoft .NET Runtime
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
Please contact the application's support team for more information.
GetProcessWindowStation
GetProcessWindowStation
user32.dll
user32.dll
internal state. The program cannot safely continue execution and must
internal state. The program cannot safely continue execution and must
continue execution and must now be terminated.
continue execution and must now be terminated.
C:\BUILD_~1\jdk6_18\control\build\WINDOW~1\tmp\java\javaw\obj\javaw.pdb
C:\BUILD_~1\jdk6_18\control\build\WINDOW~1\tmp\java\javaw\obj\javaw.pdb
RegCloseKey
RegCloseKey
RegOpenKeyExA
RegOpenKeyExA
RegEnumKeyA
RegEnumKeyA
ADVAPI32.dll
ADVAPI32.dll
USER32.dll
USER32.dll
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
%Program Files%\Java\jre6\bin\javaw.exe
%Program Files%\Java\jre6\bin\javaw.exe
name="javaw.exe"
name="javaw.exe"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
3333333333330
3333333333330
333333333307
333333333307
PP%d(jjjjj
PP%d(jjjjj
6.0.180.7
6.0.180.7
javaw.exe
javaw.exe
delet.exe_1088:
.text
.text
`.itext
`.itext
`.data
`.data
.idata
.idata
.rdata
.rdata
@.reloc
@.reloc
B.rsrc
B.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
%s_%d
%s_%d
USER32.DLL
USER32.DLL
EInvalidGraphicOperation
EInvalidGraphicOperation
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
ole32.dll
ole32.dll
uxtheme.dll
uxtheme.dll
DWMAPI.DLL
DWMAPI.DLL
clWebSnow
clWebSnow
clWebFloralWhite
clWebFloralWhite
clWebLavenderBlush
clWebLavenderBlush
clWebOldLace
clWebOldLace
clWebIvory
clWebIvory
clWebCornSilk
clWebCornSilk
clWebBeige
clWebBeige
clWebAntiqueWhite
clWebAntiqueWhite
clWebWheat
clWebWheat
clWebAliceBlue
clWebAliceBlue
clWebGhostWhite
clWebGhostWhite
clWebLavender
clWebLavender
clWebSeashell
clWebSeashell
clWebLightYellow
clWebLightYellow
clWebPapayaWhip
clWebPapayaWhip
clWebNavajoWhite
clWebNavajoWhite
clWebMoccasin
clWebMoccasin
clWebBurlywood
clWebBurlywood
clWebAzure
clWebAzure
clWebMintcream
clWebMintcream
clWebHoneydew
clWebHoneydew
clWebLinen
clWebLinen
clWebLemonChiffon
clWebLemonChiffon
clWebBlanchedAlmond
clWebBlanchedAlmond
clWebBisque
clWebBisque
clWebPeachPuff
clWebPeachPuff
clWebTan
clWebTan
clWebYellow
clWebYellow
clWebDarkOrange
clWebDarkOrange
clWebRed
clWebRed
clWebDarkRed
clWebDarkRed
clWebMaroon
clWebMaroon
clWebIndianRed
clWebIndianRed
clWebSalmon
clWebSalmon
clWebCoral
clWebCoral
clWebGold
clWebGold
clWebTomato
clWebTomato
clWebCrimson
clWebCrimson
clWebBrown
clWebBrown
clWebChocolate
clWebChocolate
clWebSandyBrown
clWebSandyBrown
clWebLightSalmon
clWebLightSalmon
clWebLightCoral
clWebLightCoral
clWebOrange
clWebOrange
clWebOrangeRed
clWebOrangeRed
clWebFirebrick
clWebFirebrick
clWebSaddleBrown
clWebSaddleBrown
clWebSienna
clWebSienna
clWebPeru
clWebPeru
clWebDarkSalmon
clWebDarkSalmon
clWebRosyBrown
clWebRosyBrown
clWebPaleGoldenrod
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebLightGoldenrodYellow
clWebOlive
clWebOlive
clWebForestGreen
clWebForestGreen
clWebGreenYellow
clWebGreenYellow
clWebChartreuse
clWebChartreuse
clWebLightGreen
clWebLightGreen
clWebAquamarine
clWebAquamarine
clWebSeaGreen
clWebSeaGreen
clWebGoldenRod
clWebGoldenRod
clWebKhaki
clWebKhaki
clWebOliveDrab
clWebOliveDrab
clWebGreen
clWebGreen
clWebYellowGreen
clWebYellowGreen
clWebLawnGreen
clWebLawnGreen
clWebPaleGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumAquamarine
clWebMediumSeaGreen
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkOliveGreen
clWebDarkgreen
clWebDarkgreen
clWebLimeGreen
clWebLimeGreen
clWebLime
clWebLime
clWebSpringGreen
clWebSpringGreen
clWebMediumSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebPaleTurquoise
clWebLightCyan
clWebLightCyan
clWebLightBlue
clWebLightBlue
clWebLightSkyBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebDarkBlue
clWebIndigo
clWebIndigo
clWebMediumTurquoise
clWebMediumTurquoise
clWebTurquoise
clWebTurquoise
clWebCyan
clWebCyan
clWebPowderBlue
clWebPowderBlue
clWebSkyBlue
clWebSkyBlue
clWebRoyalBlue
clWebRoyalBlue
clWebMediumBlue
clWebMediumBlue
clWebMidnightBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebDarkTurquoise
clWebCadetBlue
clWebCadetBlue
clWebDarkCyan
clWebDarkCyan
clWebTeal
clWebTeal
clWebDeepskyBlue
clWebDeepskyBlue
clWebDodgerBlue
clWebDodgerBlue
clWebBlue
clWebBlue
clWebNavy
clWebNavy
clWebDarkViolet
clWebDarkViolet
clWebDarkOrchid
clWebDarkOrchid
clWebMagenta
clWebMagenta
clWebDarkMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebMediumVioletRed
clWebPaleVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebBlueViolet
clWebMediumOrchid
clWebMediumOrchid
clWebMediumPurple
clWebMediumPurple
clWebPurple
clWebPurple
clWebDeepPink
clWebDeepPink
clWebLightPink
clWebLightPink
clWebViolet
clWebViolet
clWebOrchid
clWebOrchid
clWebPlum
clWebPlum
clWebThistle
clWebThistle
clWebHotPink
clWebHotPink
clWebPink
clWebPink
clWebLightSteelBlue
clWebLightSteelBlue
clWebMediumSlateBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebLightSlateGray
clWebWhite
clWebWhite
clWebLightgrey
clWebLightgrey
clWebGray
clWebGray
clWebSteelBlue
clWebSteelBlue
clWebSlateBlue
clWebSlateBlue
clWebSlateGray
clWebSlateGray
clWebWhiteSmoke
clWebWhiteSmoke
clWebSilver
clWebSilver
clWebDimGray
clWebDimGray
clWebMistyRose
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlateBlue
clWebDarkSlategray
clWebDarkSlategray
clWebGainsboro
clWebGainsboro
clWebDarkGray
clWebDarkGray
clWebBlack
clWebBlack
comctl32.dll
comctl32.dll
AutoHotkeysH
AutoHotkeysH
AutoHotkeys
AutoHotkeys
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview8fC
KeyPreview8fC
WindowStatet
WindowStatet
OnKeyDown
OnKeyDown
OnKeyPressphC
OnKeyPressphC
OnKeyUp
OnKeyUp
GlassFrame.Bottom
GlassFrame.Bottom
GlassFrame.Enabled
GlassFrame.Enabled
GlassFrame.Left
GlassFrame.Left
GlassFrame.Right
GlassFrame.Right
GlassFrame.SheetOfGlass
GlassFrame.SheetOfGlass
GlassFrame.Top
GlassFrame.Top
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
User32.dll
User32.dll
VBoxService.exe
VBoxService.exe
SbieDll.dll
SbieDll.dll
dbghelp.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
55274-640-2673064-23950
76487-644-3177037-23510
76487-644-3177037-23510
76487-337-8429955-22614
76487-337-8429955-22614
\\.\Syser
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SyserBoot
\\.\SICE
\\.\SICE
\\.\NTICE
\\.\NTICE
user32.dll
user32.dll
Software\Microsoft\Windows\CurrentVersion\Run\
Software\Microsoft\Windows\CurrentVersion\Run\
127.0.0.1
127.0.0.1
notepad.exe
notepad.exe
1.0.4
1.0.4
PSAPI.dll
PSAPI.dll
C:\Users\gurkan.arkas\Desktop\Server\SuperObject.pas
C:\Users\gurkan.arkas\Desktop\Server\SuperObject.pas
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
SOFTWARE\Mozilla\Mozilla Firefox\
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
SOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\
nss3.dll
nss3.dll
PK11_GetInternalKeySlot
PK11_GetInternalKeySlot
mozglue.dll
mozglue.dll
msvcr120.dll
msvcr120.dll
msvcp120.dll
msvcp120.dll
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\profiles.ini
\Mozilla\Firefox\
\Mozilla\Firefox\
logins.json
logins.json
Mozilla Firefox
Mozilla Firefox
logins[
logins[
].hostname
].hostname
].encryptedUsername
].encryptedUsername
].encryptedPassword
].encryptedPassword
sqlite3_bind_blob
sqlite3_bind_blob
sqlite3_bind_text
sqlite3_bind_text
sqlite3_bind_double
sqlite3_bind_double
sqlite3_bind_int
sqlite3_bind_int
sqlite3_bind_int64
sqlite3_bind_int64
sqlite3_bind_null
sqlite3_bind_null
sqlite3_bind_parameter_index
sqlite3_bind_parameter_index
sqlite3_open
sqlite3_open
sqlite3_close
sqlite3_close
sqlite3_errmsg
sqlite3_errmsg
sqlite3_errcode
sqlite3_errcode
sqlite3_free
sqlite3_free
sqlite3_prepare_v2
sqlite3_prepare_v2
sqlite3_column_count
sqlite3_column_count
sqlite3_column_name
sqlite3_column_name
sqlite3_column_decltype
sqlite3_column_decltype
sqlite3_step
sqlite3_step
sqlite3_column_blob
sqlite3_column_blob
sqlite3_column_bytes
sqlite3_column_bytes
sqlite3_column_double
sqlite3_column_double
sqlite3_column_text
sqlite3_column_text
sqlite3_column_type
sqlite3_column_type
sqlite3_column_int64
sqlite3_column_int64
sqlite3_finalize
sqlite3_finalize
sqlite3_reset
sqlite3_reset
SQL error or missing database
SQL error or missing database
An internal logic error in SQLite
An internal logic error in SQLite
Operation terminated by sqlite3_interrupt()
Operation terminated by sqlite3_interrupt()
Uses OS features not supported on host
Uses OS features not supported on host
2nd parameter to sqlite3_bind out of range
2nd parameter to sqlite3_bind out of range
sqlite3_step() has another row ready
sqlite3_step() has another row ready
sqlite3_step() has finished executing
sqlite3_step() has finished executing
Unknown SQLite Error Code "
Unknown SQLite Error Code "
ESQLiteException
ESQLiteException
TSQLiteDatabase
TSQLiteDatabase
TSQLiteTable
TSQLiteTable
Failed to open database "%s" : %s
Failed to open database "%s" : %s
Failed to open database "%s" : unknown error
Failed to open database "%s" : unknown error
Error [%d]: %s.
Error [%d]: %s.
"%s": %s
"%s": %s
Error executing SQL
Error executing SQL
Could not prepare SQL statement
Could not prepare SQL statement
Error executing SQL statement
Error executing SQL statement
SQLite is Busy
SQLite is Busy
\Google\Chrome\User Data\Default\Login Data
\Google\Chrome\User Data\Default\Login Data
SELECT * FROM logins
SELECT * FROM logins
password_value
password_value
Google Chrome
Google Chrome
origin_url
origin_url
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
sqlite3.dll
sqlite3.dll
TUnicodeKeyboard
TUnicodeKeyboard
Klog.dat
Klog.dat
\Klog.dat
\Klog.dat
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows Server 2003
Windows Server 2003
Windows Server 2003 R2
Windows Server 2003 R2
Windows Vista
Windows Vista
Windows Server 2008
Windows Server 2008
Windows Server 2008 R2
Windows Server 2008 R2
Windows 7
Windows 7
Windows 8
Windows 8
Windows Server 2012
Windows Server 2012
Windows 8.1
Windows 8.1
Windows Server 2012 R2
Windows Server 2012 R2
Windows 10
Windows 10
Windows Server 2016 Technical Preview
Windows Server 2016 Technical Preview
%s|%s@%s|%s|%s|%s|%s|%s|%s|%s|%s|%s|
%s|%s@%s|%s|%s|%s|%s|%s|%s|%s|%s|%s|
deflate 1.0.4 Copyright 1995-1996 Jean-loup Gailly
deflate 1.0.4 Copyright 1995-1996 Jean-loup Gailly
%Documents and Settings%\%current user%\Application Data\delet.exe
%Documents and Settings%\%current user%\Application Data\delet.exe
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
GetKeyboardType
GetKeyboardType
keybd_event
keybd_event
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyExA
MapVirtualKeyExA
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
GetAsyncKeyState
GetAsyncKeyState
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
EnumChildWindows
EnumChildWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
version.dll
version.dll
SetNamedPipeHandleState
SetNamedPipeHandleState
GetCPInfo
GetCPInfo
CreatePipe
CreatePipe
RegOpenKeyA
RegOpenKeyA
RegFlushKey
RegFlushKey
RegEnumKeyExA
RegEnumKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyA
RegCreateKeyA
wininet.dll
wininet.dll
InternetOpenUrlA
InternetOpenUrlA
shell32.dll
shell32.dll
ShellExecuteA
ShellExecuteA
SHFileOperationA
SHFileOperationA
wsock32.dll
wsock32.dll
winmm.dll
winmm.dll
msacm32.dll
msacm32.dll
msvcrt.dll
msvcrt.dll
crypt32.dll
crypt32.dll
shfolder.dll
shfolder.dll
6 6$6(6,6064686
6 6$6(6,6064686
77C8U8r8
77C8U8r8
9,:0:4:8:<:>
9,:0:4:8:<:>
;#;'; ;/;4;
;#;'; ;/;4;
=#='= =/=3=7=
=#='= =/=3=7=
&0/050:3
&0/050:3
0$0 02090
0$0 02090
;!;%;);-;1;5;
;!;%;);-;1;5;
1 1$1(1,1014181
1 1$1(1,1014181
22272
22272
4&4.464>4
4&4.464>4
7$7(7,70747
7$7(7,70747
SQLite3
SQLite3
KWindows
KWindows
FF_Passwords
FF_Passwords
UrlMon
UrlMon
UnitKeyboardStarter
UnitKeyboardStarter
GOutlookPasswords
GOutlookPasswords
UnitDownloadExec
UnitDownloadExec
UnitChrome
UnitChrome
SQLiteTable3
SQLiteTable3
delet.exe
delet.exe
DtServ32sm.exe
DtServ32sm.exe
njton.noip.me#PTPF0
njton.noip.me#PTPF0
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
logins
logins
66006666
66006666
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Invalid stream operation
Invalid stream operation
Alt Clipboard does not support Icons/Menu '%s' is already being used by another form
Alt Clipboard does not support Icons/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.&Cannot change the size of a JPEG image
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.&Cannot change the size of a JPEG image
JPEG error #%d
JPEG error #%d
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
No help found for %s#No context-sensitive help installed
No help found for %s#No context-sensitive help installed
Unsupported clipboard format
Unsupported clipboard format
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)"Unable to find a Table of Contents
Thread Error: %s (%d)"Unable to find a Table of Contents
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Interface not supported
Interface not supported
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x Invalid floating point operation
External exception %x Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
!'%s' is not a valid integer value('%s' is not a valid floating point value
!'%s' is not a valid integer value('%s' is not a valid floating point value
I/O error %d
I/O error %d