Trojan.Generic.14770424 (B) (Emsisoft), Trojan.Generic.14770424 (AdAware), GenericEmailWorm.YR (Lavasoft MAS)Behaviour: Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 0e1c4dccff99c005b907daa5631c0c5b
SHA1: d35b7640f4d22c0b6daca1b6dbd540f45826a6db
SHA256: 0896a84562af1fe96ea2cef6e062b35a542c301a457298da0373c860507f9dfd
SSDeep: 393216:7HumT1dPqqcfZlk7xMCGHG7rbYI09mEQxU:7HumTrPqqcTk9MCMSEI09mr
Size: 12897792 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: ASPackv212, UPolyXv05_v6
Company:
Created at: 2011-12-22 15:26:30
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
AntiMalware.exe:900
AntiMalware.exe:668
hosts.exe:1148
UpdateAAM.Exe:1276
UpdateAAMF.exe:1792
UpdateAAMF.exe:1388
xsfxdel~.exe:1508
xsfxdel~.exe:1244
xsfxdel~.exe:264
%original file name%.exe:432
AAnti-Malware.tmp:896
avupdate.exe:344
DefaultBrowserFinder.exe:1704
ipconfig.exe:1756
ipconfig.exe:2044
ipconfig.exe:512
GASender.exe:376
taskkill.exe:476
taskkill.exe:412
taskkill.exe:1108
taskkill.exe:1012
reader.exe:1500
AuslogicsAM.Exe:744
hostYS.exe:452
hostYS.exe:468
hostYS.exe:1276
AntiMalware32.exe:1520
AAnti-Malware.exe:1824
AuslogicsAM.exe:208
AsAnti-Malware.exe:1416
host.exe:1532
The Trojan injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process AntiMalware.exe:900 makes changes in the file system.
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\AntiMalware.madExcept (0 bytes)
The process AntiMalware.exe:668 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\1F356F4D07FE8C483E769E4586569404 (85 bytes)
%WinDir%\Tasks\Auslogics Anti-Malware Start Anti-Malware þn adm logon.job (394 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70 (75 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70 (232 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\1F356F4D07FE8C483E769E4586569404 (228 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\AntiMalware.madExcept (0 bytes)
The process hosts.exe:1148 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\host.exe (84 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\hostYS.exe (6310 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xsfxdel~.exe (41 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\host.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C (0 bytes)
The process UpdateAAMF.exe:1792 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1792KUP9.bat (476 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1792KUP9.bat (0 bytes)
The process UpdateAAMF.exe:1388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAMF.exe (1624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAM.Exe (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xsfxdel~.exe (41 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAMF.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAM.Exe (0 bytes)
The process xsfxdel~.exe:1508 makes changes in the file system.
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\AuslogicsAM.exe (0 bytes)
The process xsfxdel~.exe:1244 makes changes in the file system.
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\hosts.exe (0 bytes)
The process %original file name%.exe:432 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\AsAnti-Malware.exe (55603 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AuslogicsAM.exe (30622 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UpdateAAMF.exe (6435 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Auslogics Anti-Malware v1.5.0.0.bat (1 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\UpdateAAMF.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AsAnti-Malware.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Auslogics Anti-Malware v1.5.0.0.bat (0 bytes)
The process AAnti-Malware.tmp:896 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\SetupCustom.dll (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\is-DROGR.tmp (32429 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-9UOJV.tmp (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\is-H1HO9.tmp (23811 bytes)
%Program Files%\Auslogics\Anti-Malware\unins000.dat (18953 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-73S7H.tmp (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vcl160.bpl (23811 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-0PEOI.tmp (512 bytes)
%Program Files%\Auslogics\Anti-Malware\Setup\is-IP4VF.tmp (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-3GQT8.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-4JR8D.tmp (673 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-MBQEI.tmp (11518 bytes)
%Program Files%\Auslogics\Anti-Malware\is-5SHR6.tmp (7433 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-IHAP4.tmp (440 bytes)
%Program Files%\Auslogics\Anti-Malware\is-RREEI.tmp (7726 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-SGPPU.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-SU9CD.tmp (22 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-VF5DI.tmp (2105 bytes)
%Program Files%\Auslogics\Anti-Malware\is-PL9Q2.tmp (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\AxComponentsRTL.bpl (7726 bytes)
%Program Files%\Auslogics\Anti-Malware\Data\is-6PDB3.tmp (52 bytes)
%Program Files%\Auslogics\Anti-Malware\is-9A6GM.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-I3BSA.tmp (7971 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-MLV61.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\sqlite3.dll (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\DefaultBrowserFinder.exe (2105 bytes)
%Program Files%\Auslogics\Anti-Malware\is-RJ6NG.tmp (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsVCL.bpl (30490 bytes)
%Program Files%\Auslogics\Anti-Malware\is-N6L6C.tmp (3073 bytes)
%Program Files%\Auslogics\Anti-Malware\is-EGKI6.tmp (4545 bytes)
%Program Files%\Auslogics\Anti-Malware\is-O7A0H.tmp (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GASender.exe (2321 bytes)
%Documents and Settings%\%current user%\Desktop\Auslogics Anti-Malware.lnk (841 bytes)
%Program Files%\Auslogics\Anti-Malware\Lang\is-DGBMT.tmp (57 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GA.xml (915 bytes)
%Program Files%\Auslogics\Anti-Malware\Data\is-TEDCN.tmp (1 bytes)
%Program Files%\Auslogics\Anti-Malware\is-PCAUO.tmp (1281 bytes)
%Program Files%\Auslogics\Anti-Malware\is-VTD90.tmp (7726 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Auslogics\Anti-Malware\Auslogics Anti-Malware.lnk (859 bytes)
%Program Files%\Auslogics\Anti-Malware\is-27QD2.tmp (3361 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Auslogics\Anti-Malware\Auslogics Anti-Malware on the Web.url (127 bytes)
%Program Files%\Auslogics\Anti-Malware\is-GI8KK.tmp (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\rtl160.bpl (21387 bytes)
%Program Files%\Auslogics\Anti-Malware\is-ANVG4.tmp (30490 bytes)
%Program Files%\Auslogics\Anti-Malware\is-AF66U.tmp (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\reader.exe (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\_isetup\_shfoldr.dll (23 bytes)
%Program Files%\Auslogics\Anti-Malware\is-KLITQ.tmp (1281 bytes)
%Program Files%\Auslogics\Anti-Malware\unins000.msg (646 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GASender.exe (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GA.xml (919 bytes)
%Program Files%\Auslogics\Anti-Malware\is-ONRD2.tmp (21387 bytes)
%Program Files%\Auslogics\Anti-Malware\is-V2EUI.tmp (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GoogleAnalyticsHelper.dll (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp (4 bytes)
%Program Files%\Auslogics\Anti-Malware\is-35DLC.tmp (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GoogleAnalyticsHelper.dll (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\EULA.rtf (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsRTL.bpl (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vclimg160.bpl (2105 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\SetupCustom.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\reader.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\_isetup\_shfoldr.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\_isetup (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GASender.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GA.xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vclimg160.bpl (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vcl160.bpl (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\sqlite3.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GoogleAnalyticsHelper.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\EULA.rtf (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\DefaultBrowserFinder.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsRTL.bpl (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\rtl160.bpl (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsVCL.bpl (0 bytes)
The process avupdate.exe:344 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\savapilib_xvdf-win32-en.info (2 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\avupdate.log (6840 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\idx\master.idx (56 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\ave2-win32-int.info.gz (2 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\savapilib_xvdf-win32-en.info.gz (776 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\ave2-win32-int.info (8 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\xbv00000.vdf.gz (1461144 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\xvdf.info (5064 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\xvdf.info.gz (784 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\aevdf.dat (5 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\aevdf.dat.gz (1 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\master.idx (56 bytes)
The process GASender.exe:376 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
The process hostYS.exe:452 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%System%\drivers\etc\hosts (819 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ozmdosf (1345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (588 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\ozmdosf (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (0 bytes)
The process hostYS.exe:468 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\hostYS.ini (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (588 bytes)
%System%\drivers\etc\hosts (760 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ryruxgc (1345 bytes)
%System%\drivers\etc\BACKUP\hosts_2015-10-24_09-33-13.txt (734 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ryruxgc (0 bytes)
The process hostYS.exe:1276 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\akazbet (1345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (588 bytes)
%System%\drivers\etc\hosts (790 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\akazbet (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (0 bytes)
The process AntiMalware32.exe:1520 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Auslogics\Anti-Malware\AntiMalware.exe (14928 bytes)
%Program Files%\Auslogics\Anti-Malware\Yaron'S Team.ico (1425 bytes)
%Program Files%\Auslogics\Anti-Malware\CommonForms.Routine.dll (4501 bytes)
%Program Files%\Auslogics\Anti-Malware\CommonForms.Site.dll (14461 bytes)
%Program Files%\Auslogics\Anti-Malware\AntiMalwareHelper.dll (10521 bytes)
%Documents and Settings%\%current user%\Desktop\Auslogics Anti-Malware.lnk (1 bytes)
The Trojan deletes the following file(s):
%Program Files%\Auslogics\Anti-Malware\__tmp_rar_sfx_access_check_2519875 (0 bytes)
The process AAnti-Malware.exe:1824 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-81GHI.tmp\AAnti-Malware.tmp (7386 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-81GHI.tmp\AAnti-Malware.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-81GHI.tmp (0 bytes)
The process AuslogicsAM.exe:208 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09 (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware64.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AuslogicsAM.Exe (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xsfxdel~.exe (41 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware32.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\hosts.exe (3820 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AuslogicsAM.Exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware64.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware32.exe (0 bytes)
The process AsAnti-Malware.exe:1416 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\7ZipSfx.000\AAnti-Malware.exe (59049 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\7ZipSfx.000 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7ZipSfx.000\AAnti-Malware.exe (0 bytes)
The process host.exe:1532 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1532M414.BAT (228 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1532M414.BAT (0 bytes)
Registry activity
The process AntiMalware.exe:900 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "14 39 B8 73 20 6F EE C3 78 D9 18 E8 E9 36 7C 34"
The process AntiMalware.exe:668 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F7 40 12 61 E3 C4 86 3F 3F A4 D1 ED 51 2B 01 C1"
[HKLM\SOFTWARE\Auslogics\Anti-Malware\1.x\Settings]
"General.Language" = "enu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Auslogics\Anti-Malware\1.x\Settings]
"General.InstallDateTime" = "7C 82 4E BC AC A7 E4 40"
The process hosts.exe:1148 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "14 E6 23 15 F0 A9 57 EE A6 D0 E2 A4 F9 37 65 DC"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp]
"xsfxdel~.exe" = "xsfxdel~"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\~sfx0027F7EB5C]
"host.exe" = "host"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process UpdateAAM.Exe:1276 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C0 2D BD C0 78 9F 41 1F 24 5A 33 4C F4 E0 B7 2E"
The process UpdateAAMF.exe:1792 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "66 65 4D 88 56 71 21 50 D4 80 C7 36 46 BD 37 C9"
The process UpdateAAMF.exe:1388 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "29 97 7B 72 13 AA 2B 73 B8 AA 72 AC 4F 7B 79 0A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\~sfx006C96E0CE]
"UpdateAAMF.exe" = "Updating Auslogics Anti-Malware"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process xsfxdel~.exe:1508 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C4 C3 42 F4 BA 8D 1B D0 7C B5 8E 65 FD 62 BC 8D"
The process xsfxdel~.exe:1244 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4B B2 B3 EF 52 95 61 6C 5D 9E 2B CF 8A B8 C4 30"
The process xsfxdel~.exe:264 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CA AD 49 3C 8F 92 2B C1 D4 40 82 06 69 EC FC 1E"
The process %original file name%.exe:432 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "08 7F 46 72 E4 3A A8 BC 5E AA 07 EF F7 0F 5C A2"
The process AAnti-Malware.tmp:896 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\is-BPSPP.tmp]
"DefaultBrowserFinder.exe" = "DefaultBrowserFinder"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"Inno Setup: Setup Version" = "5.5.4 (u)"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\_Del_AAnti-Malware]
"GASender.exe" = "GoogleAnalyticsSender"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"DisplayVersion" = "1.5.0.0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"Inno Setup: Language" = "enu"
"DisplayName" = "Auslogics Anti-Malware"
"HelpLink" = "http://www.auslogics.com/en/support/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Auslogics\Anti-Malware]
"antimalware.exe" = "Anti-Malware"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"UninstallString" = "%Program Files%\Auslogics\Anti-Malware\unins000.exe"
"Contact" = "info@auslogics.com"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"Inno Setup: Icon Group" = "Auslogics\Anti-Malware"
"InstallDate" = "20151024"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Auslogics\Google Analytics Package\1.x\Settings]
"ClientID" = "{4B53BE45-D88A-40EF-BA87-A411B28557B9}"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"MinorVersion" = "5"
[HKLM\SOFTWARE\Auslogics\Anti-Malware\1.x\Settings]
"GoogleAnalytics.InstallDate" = "81 E8 BF BB AC A7 E4 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"NoModify" = "1"
"Readme" = "http://www.auslogics.com/en/software/anti-malware/"
"Inno Setup: User" = "%CurrentUserName%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\is-BPSPP.tmp]
"Reader.exe" = "reader"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"Publisher" = "Auslogics Labs Pty Ltd"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"DisplayIcon" = "%Program Files%\Auslogics\Anti-Malware\AntiMalware.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"InstallLocation" = "%Program Files%\Auslogics\Anti-Malware\"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8C 57 69 55 61 64 48 2F 1C C7 01 61 18 E0 75 07"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"URLUpdateInfo" = "http://www.auslogics.com/en/checkforupdate/?product=anti-malware&version=1.5.0.0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"QuietUninstallString" = "%Program Files%\Auslogics\Anti-Malware\unins000.exe /SILENT"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"NoRepair" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5A6F7C9-F91E-45C7-8DAA-289CBB0C817D}_is1]
"Inno Setup: App Path" = "%Program Files%\Auslogics\Anti-Malware"
"URLInfoAbout" = "http://www.auslogics.com/en/software/anti-malware/"
"MajorVersion" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process avupdate.exe:344 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E5 08 CD B6 37 5E 37 24 B4 90 23 E9 0A 15 48 D3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process DefaultBrowserFinder.exe:1704 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F1 39 9E 77 B4 0E E0 E9 36 AE 9D 8D C3 C5 7B A6"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Auslogics\Anti-Malware\1.x\Settings]
"General.DefWebBrowser"
The process ipconfig.exe:1756 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7C 53 9E 1E 8B 20 E6 DF BA D9 70 85 8D 0C 46 AB"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"
The process ipconfig.exe:2044 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "94 BC 69 47 A3 87 44 E5 AC 10 10 0C 7B A6 26 67"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"
The process ipconfig.exe:512 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3C ED 56 50 CE 5C 66 D5 F7 88 30 0B F1 D0 B6 9E"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
"EventMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"ControlFlags" = "1"
The process GASender.exe:376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DF E3 A4 52 D5 5D 74 02 7D 59 43 5F 78 53 A1 56"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process taskkill.exe:476 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "92 D6 D6 A6 49 DC 1B B6 C3 64 68 45 C3 5B 08 94"
The process taskkill.exe:412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "00 A5 F9 26 DC A7 8D 9E 5C D7 E6 75 C7 6D B4 9D"
The process taskkill.exe:1108 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CD F3 3A 5C 45 C6 F1 3A 4F EF 6E 98 63 2C 17 44"
The process taskkill.exe:1012 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9B FD 25 CA 84 26 40 25 8E D5 41 8D 4A 95 15 2D"
The process reader.exe:1500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8A 2E B0 4E 5F F9 91 EF FF E2 49 CC CA 9A 31 13"
[HKLM\SOFTWARE\Auslogics\Anti-Malware\1.x\Settings]
"General.PartnerId" = "auslogics"
The process AuslogicsAM.Exe:744 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C1 D6 BB 26 53 63 02 BB 6B EA 74 C6 65 03 A3 0C"
The process hostYS.exe:452 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "90 90 94 B5 03 E9 EE A7 BB 83 AD A6 75 BC 4E 09"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process hostYS.exe:468 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "59 11 E0 B9 51 1D C3 67 C7 60 90 89 07 9A 15 FE"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process hostYS.exe:1276 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "26 67 8D D9 8C 61 A9 AC 15 5D 80 02 A0 45 DD B2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process AntiMalware32.exe:1520 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EA 26 BA 25 13 DE 9C 3F 4B CB 0E 3F 7D D2 5A 67"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\WinRAR SFX]
"C%%Program Files%Auslogics%Anti-Malware" = "%Program Files%\Auslogics\Anti-Malware"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
The process AAnti-Malware.exe:1824 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3A A5 80 B8 82 87 18 52 BC DA A8 F9 08 25 2E A7"
The process AuslogicsAM.exe:208 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "23 0E 60 9B 8F 83 1A EA 31 E9 99 F3 74 06 42 FF"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\xsfxdel~.exe,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\~sfx00561FAE09]
"AuslogicsAM.Exe" = "AuslogicsAM - Yaron'S Team"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process AsAnti-Malware.exe:1416 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Favorites" = "%Documents and Settings%\All Users\Favorites"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Video" = ""
"NetHood" = "%Documents and Settings%\%current user%\NetHood"
"Fonts" = "%WinDir%\Fonts"
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"PrintHood" = "%Documents and Settings%\%current user%\PrintHood"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7ZipSfx.000]
"AAnti-Malware.exe" = "Auslogics Anti-Malware Installation File"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Templates" = "%Documents and Settings%\%current user%\Templates"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Administrative Tools" = "%Documents and Settings%\All Users\Start Menu\Programs\Administrative Tools"
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Templates" = "%Documents and Settings%\All Users\Templates"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Administrative Tools" = ""
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
"SendTo" = "%Documents and Settings%\%current user%\SendTo"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2E 65 CB 9F 69 F0 2E B6 F5 9C CF 06 55 AB 02 FA"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Music" = "%Documents and Settings%\%current user%\My Documents\My Music"
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CD Burning" = "%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\CD Burning"
"Recent" = "%Documents and Settings%\%current user%\Recent"
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process host.exe:1532 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AC 73 96 E3 06 BD 55 F6 53 6F A1 EE B0 36 7B A5"
Dropped PE files
MD5 | File path |
---|---|
faf8c32dc57273a5d8f6cdbb92f06b31 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\_Del_AAnti-Malware\AxComponentsRTL.bpl |
642f22baf8b13d9dbe0d087edb864acb | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\_Del_AAnti-Malware\GASender.exe |
ca6374c51e3e0d5a1621ced59887c726 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\_Del_AAnti-Malware\GoogleAnalyticsHelper.dll |
4a9a0f661cf3386fa6f8f16c99f9b137 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\xsfxdel~.exe |
f579ccd8e68a75f0f4cc6b45bec3932b | c:\Program Files\Auslogics\Anti-Malware\ActionCenterForms.dll |
06de8be4bbadbd7b01973d293fa47816 | c:\Program Files\Auslogics\Anti-Malware\ActionCenterHelper.dll |
13ea3f9fcf45328a682f6c8983c22343 | c:\Program Files\Auslogics\Anti-Malware\AntiMalware.exe |
83fd812c09c37a95857605ca338b3a67 | c:\Program Files\Auslogics\Anti-Malware\AntiMalwareHelper.dll |
384a1b82c987de35596e393fe81cc22c | c:\Program Files\Auslogics\Anti-Malware\AxBrowsers.dll |
faf8c32dc57273a5d8f6cdbb92f06b31 | c:\Program Files\Auslogics\Anti-Malware\AxComponentsRTL.bpl |
8eab8b7ed4dbf47074203667236ec7e9 | c:\Program Files\Auslogics\Anti-Malware\AxComponentsVCL.bpl |
beb5851257425a10dad97e6cb079345b | c:\Program Files\Auslogics\Anti-Malware\CommonForms.Routine.dll |
1c0f78b7deda23e5fae06a439a9689d5 | c:\Program Files\Auslogics\Anti-Malware\CommonForms.Site.dll |
86faeb3a041a31fdae168faca5cd5310 | c:\Program Files\Auslogics\Anti-Malware\DebugHelper.dll |
a103c9f89c5f9e3b313ea1b364484e75 | c:\Program Files\Auslogics\Anti-Malware\Engine\avupdate.exe |
1196302ef9190c26fbc1e106032ed85f | c:\Program Files\Auslogics\Anti-Malware\Engine\savapi.exe |
96a13be2cebba9383973f7b44f7e21d8 | c:\Program Files\Auslogics\Anti-Malware\Engine\savapi3.dll |
82c8d52e9933c5e5b49f4052894b3c0a | c:\Program Files\Auslogics\Anti-Malware\Engine\savapi_stub.exe |
f35c6f578d1cb2c4796aa7282c5ae47e | c:\Program Files\Auslogics\Anti-Malware\Engine\vdfupd.dll |
642f22baf8b13d9dbe0d087edb864acb | c:\Program Files\Auslogics\Anti-Malware\GASender.exe |
ca6374c51e3e0d5a1621ced59887c726 | c:\Program Files\Auslogics\Anti-Malware\GoogleAnalyticsHelper.dll |
847d9d4048083e4dbf9d7af8210b26ad | c:\Program Files\Auslogics\Anti-Malware\Localizer.dll |
23e6c8b688e5fc6678643e04ab7fcb2e | c:\Program Files\Auslogics\Anti-Malware\ProductHelper.dll |
702a4dcb816f9324b37c144c41c7e814 | c:\Program Files\Auslogics\Anti-Malware\SendDebugLog.exe |
a30f1ab942327c0ff2d6f0aa4df3b112 | c:\Program Files\Auslogics\Anti-Malware\SettingsHelper.dll |
c9665e8e10ef26fbd016ac46b259652e | c:\Program Files\Auslogics\Anti-Malware\Setup\SetupCustom.dll |
b0994b460c87b82397cdcf1cd540b292 | c:\Program Files\Auslogics\Anti-Malware\TaskSchedulerHelper.dll |
8f8c5bfd8df9e8a0790b8fea573c8e09 | c:\Program Files\Auslogics\Anti-Malware\rtl160.bpl |
3bc21e1edc7476bac8ebfec6db0c5754 | c:\Program Files\Auslogics\Anti-Malware\sqlite3.dll |
a07799cf34d46376f36b0b3bc7efed12 | c:\Program Files\Auslogics\Anti-Malware\unins000.exe |
4fcd7ac6b6c6bffe8e439a9d9c32a6ed | c:\Program Files\Auslogics\Anti-Malware\vcl160.bpl |
d0021f782e0db51a712e96b5ad32348e | c:\Program Files\Auslogics\Anti-Malware\vclimg160.bpl |
HOSTS file anomalies
The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses. The modified file is 819 bytes in size. The following strings are added to the hosts file listed below:
127.0.0.1 | lm.auslogics.com |
127.0.0.1 | ocsp.usertrust.com |
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
AntiMalware.exe:900
AntiMalware.exe:668
hosts.exe:1148
UpdateAAM.Exe:1276
UpdateAAMF.exe:1792
UpdateAAMF.exe:1388
xsfxdel~.exe:1508
xsfxdel~.exe:1244
xsfxdel~.exe:264
%original file name%.exe:432
AAnti-Malware.tmp:896
avupdate.exe:344
DefaultBrowserFinder.exe:1704
ipconfig.exe:1756
ipconfig.exe:2044
ipconfig.exe:512
GASender.exe:376
taskkill.exe:476
taskkill.exe:412
taskkill.exe:1108
taskkill.exe:1012
reader.exe:1500
AuslogicsAM.Exe:744
hostYS.exe:452
hostYS.exe:468
hostYS.exe:1276
AntiMalware32.exe:1520
AAnti-Malware.exe:1824
AuslogicsAM.exe:208
AsAnti-Malware.exe:1416
host.exe:1532 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\1F356F4D07FE8C483E769E4586569404 (85 bytes)
%WinDir%\Tasks\Auslogics Anti-Malware Start Anti-Malware þn adm logon.job (394 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\B69D763EB21649DA26F20618312DEE70 (75 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\B69D763EB21649DA26F20618312DEE70 (232 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\1F356F4D07FE8C483E769E4586569404 (228 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\host.exe (84 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\hostYS.exe (6310 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\xsfxdel~.exe (41 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1792KUP9.bat (476 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAMF.exe (1624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx006C96E0CE\UpdateAAM.Exe (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AsAnti-Malware.exe (55603 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\AuslogicsAM.exe (30622 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\UpdateAAMF.exe (6435 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Auslogics Anti-Malware v1.5.0.0.bat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\SetupCustom.dll (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\is-DROGR.tmp (32429 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-9UOJV.tmp (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\is-H1HO9.tmp (23811 bytes)
%Program Files%\Auslogics\Anti-Malware\unins000.dat (18953 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-73S7H.tmp (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vcl160.bpl (23811 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-0PEOI.tmp (512 bytes)
%Program Files%\Auslogics\Anti-Malware\Setup\is-IP4VF.tmp (2321 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-3GQT8.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-4JR8D.tmp (673 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-MBQEI.tmp (11518 bytes)
%Program Files%\Auslogics\Anti-Malware\is-5SHR6.tmp (7433 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-IHAP4.tmp (440 bytes)
%Program Files%\Auslogics\Anti-Malware\is-RREEI.tmp (7726 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-SGPPU.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-SU9CD.tmp (22 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-VF5DI.tmp (2105 bytes)
%Program Files%\Auslogics\Anti-Malware\is-PL9Q2.tmp (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\AxComponentsRTL.bpl (7726 bytes)
%Program Files%\Auslogics\Anti-Malware\Data\is-6PDB3.tmp (52 bytes)
%Program Files%\Auslogics\Anti-Malware\is-9A6GM.tmp (601 bytes)
%Program Files%\Auslogics\Anti-Malware\is-I3BSA.tmp (7971 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\is-MLV61.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\sqlite3.dll (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\DefaultBrowserFinder.exe (2105 bytes)
%Program Files%\Auslogics\Anti-Malware\is-RJ6NG.tmp (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsVCL.bpl (30490 bytes)
%Program Files%\Auslogics\Anti-Malware\is-N6L6C.tmp (3073 bytes)
%Program Files%\Auslogics\Anti-Malware\is-EGKI6.tmp (4545 bytes)
%Program Files%\Auslogics\Anti-Malware\is-O7A0H.tmp (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GASender.exe (2321 bytes)
%Documents and Settings%\%current user%\Desktop\Auslogics Anti-Malware.lnk (841 bytes)
%Program Files%\Auslogics\Anti-Malware\Lang\is-DGBMT.tmp (57 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GA.xml (915 bytes)
%Program Files%\Auslogics\Anti-Malware\Data\is-TEDCN.tmp (1 bytes)
%Program Files%\Auslogics\Anti-Malware\is-PCAUO.tmp (1281 bytes)
%Program Files%\Auslogics\Anti-Malware\is-VTD90.tmp (7726 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Auslogics\Anti-Malware\Auslogics Anti-Malware.lnk (859 bytes)
%Program Files%\Auslogics\Anti-Malware\is-27QD2.tmp (3361 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Auslogics\Anti-Malware\Auslogics Anti-Malware on the Web.url (127 bytes)
%Program Files%\Auslogics\Anti-Malware\is-GI8KK.tmp (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\rtl160.bpl (21387 bytes)
%Program Files%\Auslogics\Anti-Malware\is-ANVG4.tmp (30490 bytes)
%Program Files%\Auslogics\Anti-Malware\is-AF66U.tmp (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\reader.exe (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\_isetup\_shfoldr.dll (23 bytes)
%Program Files%\Auslogics\Anti-Malware\is-KLITQ.tmp (1281 bytes)
%Program Files%\Auslogics\Anti-Malware\unins000.msg (646 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GASender.exe (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GA.xml (919 bytes)
%Program Files%\Auslogics\Anti-Malware\is-ONRD2.tmp (21387 bytes)
%Program Files%\Auslogics\Anti-Malware\is-V2EUI.tmp (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_Del_AAnti-Malware\GoogleAnalyticsHelper.dll (4545 bytes)
%Program Files%\Auslogics\Anti-Malware\is-35DLC.tmp (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\GoogleAnalyticsHelper.dll (4545 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\EULA.rtf (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\AxComponentsRTL.bpl (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-BPSPP.tmp\vclimg160.bpl (2105 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\savapilib_xvdf-win32-en.info (2 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\avupdate.log (6840 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\idx\master.idx (56 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\ave2-win32-int.info.gz (2 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\savapilib_xvdf-win32-en.info.gz (776 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\xbv00000.vdf.gz (1461144 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\xvdf.info (5064 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\xvdf.info.gz (784 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\aevdf.dat (5 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\x_vdf\aevdf.dat.gz (1 bytes)
%Program Files%\Auslogics\Anti-Malware\Engine\tmp\avupdate_tmp_yDs7J8\idx\master.idx (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%System%\drivers\etc\hosts (819 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ozmdosf (1345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut3.tmp (588 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx0027F7EB5C\hostYS.ini (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut1.tmp (588 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\ryruxgc (1345 bytes)
%System%\drivers\etc\BACKUP\hosts_2015-10-24_09-33-13.txt (734 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\akazbet (1345 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\aut2.tmp (588 bytes)
%Program Files%\Auslogics\Anti-Malware\AntiMalware.exe (14928 bytes)
%Program Files%\Auslogics\Anti-Malware\Yaron'S Team.ico (1425 bytes)
%Program Files%\Auslogics\Anti-Malware\CommonForms.Routine.dll (4501 bytes)
%Program Files%\Auslogics\Anti-Malware\CommonForms.Site.dll (14461 bytes)
%Program Files%\Auslogics\Anti-Malware\AntiMalwareHelper.dll (10521 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-81GHI.tmp\AAnti-Malware.tmp (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09 (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware64.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AuslogicsAM.Exe (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\AntiMalware32.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sfx00561FAE09\hosts.exe (3820 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7ZipSfx.000\AAnti-Malware.exe (59049 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1532M414.BAT (228 bytes) - Restore the original content of the HOSTS file (%System%\drivers\etc\hosts): 127.0.0.1 localhost
Static Analysis
VersionInfo
Company Name: NVIDIA Corporation
Product Name: Auslogics Anti-Malware v1.5.0.0
Product Version: 1. 5. 0. 0
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1. 5. 0. 0
File Description: Auslogics Anti-Malware v1.5.0.0
Comments:
Language: English
Company Name: NVIDIA CorporationProduct Name: Auslogics Anti-Malware v1.5.0.0Product Version: 1. 5. 0. 0Legal Copyright: Legal Trademarks: Original Filename: Internal Name: File Version: 1. 5. 0. 0File Description: Auslogics Anti-Malware v1.5.0.0Comments: Language: English
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 65536 | 19968 | 5.53198 | 719b39935f308676231d201439a3c9fe |
.rdata | 69632 | 8192 | 2560 | 5.36832 | fa2ba291eb1b4bb1b02584c5831f0677 |
.data | 77824 | 20480 | 512 | 0.294503 | 133ebd28cbca80219108c7efad8713c0 |
.rsrc | 98304 | 13099008 | 12830208 | 5.54509 | 2132ecd01d3d49fd4091328d012d6d4b |
Yaron.S | 13197312 | 45056 | 43520 | 3.84471 | 3f56e3a647f2e828b399e62e97b74df3 |
.adata | 13242368 | 4096 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
avupdate.exe_344:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
L$%SQ
L$%SQ
!"MMM#M$M%MM&M'()MMMM*MMMMMMMM MMMMMMMMMMMM,MM-.MMMMMMMMMMM/M0MMMMMMMMMMMMMM12MM345MM6789:MMMMMMMM;?MM@MMMMMABCMMMMMDMEMMMMMFMMGHIJKMMML
!"MMM#M$M%MM&M'()MMMM*MMMMMMMM MMMMMMMMMMMM,MM-.MMMMMMMMMMM/M0MMMMMMMMMMMMMM12MM345MM6789:MMMMMMMM;?MM@MMMMMABCMMMMMDMEMMMMMFMMGHIJKMMML
>%uij
>%uij
FL9D$(uÂ$
FL9D$(uÂ$
uÂ$ u
uÂ$ u
RWj%Sj
RWj%Sj
FTPG
FTPG
FTPj
FTPj
|$@3|$
|$@3|$
FtPS
FtPS
SHA256 block transform for x86, CRYPTOGAMS by
SHA256 block transform for x86, CRYPTOGAMS by
Camellia for x86 by
Camellia for x86 by
AES for Intel AES-NI, CRYPTOGAMS by
AES for Intel AES-NI, CRYPTOGAMS by
6-9'6-9'
6-9'6-9'
$6.:$6.:
$6.:$6.:
*?#1*?#1
*?#1*?#1
>8$4,8$4,
>8$4,8$4,
AES for x86, CRYPTOGAMS by
AES for x86, CRYPTOGAMS by
RC4 for x86, CRYPTOGAMS by
RC4 for x86, CRYPTOGAMS by
DlSHA512 block transform for x86, CRYPTOGAMS by
DlSHA512 block transform for x86, CRYPTOGAMS by
SHA1 block transform for x86, CRYPTOGAMS by
SHA1 block transform for x86, CRYPTOGAMS by
GHASH for x86, CRYPTOGAMS by
GHASH for x86, CRYPTOGAMS by
Montgomery Multiplication for x86, CRYPTOGAMS by
Montgomery Multiplication for x86, CRYPTOGAMS by
GF(2^m) Multiplication for x86, CRYPTOGAMS by
GF(2^m) Multiplication for x86, CRYPTOGAMS by
Uxs.Ux
Uxs.Ux
Wx.oUx
Wx.oUx
Error: %s
Error: %s
avupdate_startup.log
avupdate_startup.log
avupdate.log
avupdate.log
avupdate_msg.avr
avupdate_msg.avr
Command Line: %s%s
Command Line: %s%s
2.1.2.27
2.1.2.27
%.0f kB/s %s
%.0f kB/s %s
[%d/%d %s %d (%d%%)]
[%d/%d %s %d (%d%%)]
Smtp timeout
Smtp timeout
smtp-timeout
smtp-timeout
Mailer: smtp, sendmail
Mailer: smtp, sendmail
Smtp password
Smtp password
smtp-password
smtp-password
Smtp user
Smtp user
smtp-user
smtp-user
Smtp port
Smtp port
smtp-port
smtp-port
Smtp server
Smtp server
smtp-server
smtp-server
Smtp :
Smtp :
Password (compat)
Password (compat)
share-userpass
share-userpass
Password
Password
password
password
Proxy password (compat)
Proxy password (compat)
proxy-userpass
proxy-userpass
Proxy password
Proxy password
proxy-password
proxy-password
Proxy port
Proxy port
proxy-port
proxy-port
Key directory (compat)
Key directory (compat)
keydir
keydir
Key directory
Key directory
key-dir
key-dir
Product-name file. Contains the product name that will be present in the user-agent string. Default value: productname.dat
Product-name file. Contains the product name that will be present in the user-agent string. Default value: productname.dat
vdfupd library version : not available (error code %d)
vdfupd library version : not available (error code %d)
avupdate version : %s
avupdate version : %s
%s-%s-%s
%s-%s-%s
antivir%d.vdf
antivir%d.vdf
aevdf.dat
aevdf.dat
aeset.dat
aeset.dat
Failed to read the product-name file '%s'. Reason: %s
Failed to read the product-name file '%s'. Reason: %s
productname.dat
productname.dat
XXXXXX
XXXXXX
%s -> %s
%s -> %s
.info.lz
.info.lz
.info.gz
.info.gz
PTF://
PTF://
hXXp://
hXXp://
hXXps://
hXXps://
%DRIVERSDIR%
%DRIVERSDIR%
%COMMONAPPDATADIR%
%COMMONAPPDATADIR%
%SYSTEM32DIR%
%SYSTEM32DIR%
UPDATED_FILE=%s
UPDATED_FILE=%s
FILE_TO_REMOVE=%s
FILE_TO_REMOVE=%s
selfUpdateSettings.txt
selfUpdateSettings.txt
CURLOPT_PROXY
CURLOPT_PROXY
CURLOPT_PROXYAUTH
CURLOPT_PROXYAUTH
CURLOPT_HTTPHEADER
CURLOPT_HTTPHEADER
CURLOPT_PASSWORD
CURLOPT_PASSWORD
CURLOPT_USERNAME
CURLOPT_USERNAME
CURLOPT_HTTPAUTH
CURLOPT_HTTPAUTH
CURLOPT_DNS_CACHE_TIMEOUT
CURLOPT_DNS_CACHE_TIMEOUT
CURLOPT_IPRESOLVE
CURLOPT_IPRESOLVE
CURLOPT_SSL_VERIFYHOST
CURLOPT_SSL_VERIFYHOST
CURLOPT_SSL_VERIFYPEER
CURLOPT_SSL_VERIFYPEER
CURLOPT_FOLLOWLOCATION
CURLOPT_FOLLOWLOCATION
CURLOPT_BUFFERSIZE
CURLOPT_BUFFERSIZE
CURLOPT_FTP_RESPONSE_TIMEOUT
CURLOPT_FTP_RESPONSE_TIMEOUT
CURLOPT_LOW_SPEED_TIME
CURLOPT_LOW_SPEED_TIME
CURLOPT_LOW_SPEED_LIMIT
CURLOPT_LOW_SPEED_LIMIT
CURLOPT_CONNECTTIMEOUT
CURLOPT_CONNECTTIMEOUT
CURLOPT_FAILONERROR
CURLOPT_FAILONERROR
CURLOPT_NOPROGRESS
CURLOPT_NOPROGRESS
CURLOPT_NOSIGNAL
CURLOPT_NOSIGNAL
CURLOPT_WRITEDATA
CURLOPT_WRITEDATA
CURLOPT_WRITEFUNCTION
CURLOPT_WRITEFUNCTION
%%x
%%x
CURLOPT_HEADERDATA
CURLOPT_HEADERDATA
CURLOPT_HEADERFUNCTION
CURLOPT_HEADERFUNCTION
CURLOPT_URL
CURLOPT_URL
WinHttpDetectAutoProxyConfigUrl
WinHttpDetectAutoProxyConfigUrl
WinHttpSetTimeouts
WinHttpSetTimeouts
WinHttpCloseHandle
WinHttpCloseHandle
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WinHttpOpen
WinHttpOpen
.info
.info
${DAY}/${MONTH}/${YEAR} ${HOUR}:${MINUTE}:${SECOND} ${FULLHOST} ${PROGRAM}[${PID}]: ${SOURCE}: ${LEVEL}: ${MSG}
${DAY}/${MONTH}/${YEAR} ${HOUR}:${MINUTE}:${SECOND} ${FULLHOST} ${PROGRAM}[${PID}]: ${SOURCE}: ${LEVEL}: ${MSG}
${MSG}
${MSG}
smtp
smtp
--%s--
--%s--
avsmtptmp.$$$
avsmtptmp.$$$
From: %s
From: %s
To: %s
To: %s
Subject: %s
Subject: %s
Unrecognized Win32 error code %d
Unrecognized Win32 error code %d
Cannot open file %s. Reason: Error at reading the file header
Cannot open file %s. Reason: Error at reading the file header
Cannot open file %s. Reason: %s
Cannot open file %s. Reason: %s
.dylib
.dylib
%d.%d.%d.%d
%d.%d.%d.%d
aecore.dll
aecore.dll
vdfupd.dll
vdfupd.dll
Iphlpapi.dll
Iphlpapi.dll
%s error: %d
%s error: %d
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
deflate 1.1.3 Copyright 1995-1998 Jean-loup Gailly
inflate 1.1.3 Copyright 1995-1998 Mark Adler
inflate 1.1.3 Copyright 1995-1998 Mark Adler
Unable to parse FTP file list
Unable to parse FTP file list
Error in the SSH layer
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Illegal operation
TFTP: Access Violation
TFTP: Access Violation
TFTP: File Not Found
TFTP: File Not Found
Login denied
Login denied
Issuer check against peer certificate failed
Issuer check against peer certificate failed
Invalid LDAP URL
Invalid LDAP URL
Unrecognized or bad HTTP Content or Transfer-Encoding
Unrecognized or bad HTTP Content or Transfer-Encoding
Problem with the SSL CA cert (path? access rights?)
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with given CA certificates
Peer certificate cannot be authenticated with given CA certificates
Problem with the local SSL certificate
Problem with the local SSL certificate
SSL peer certificate or SSH remote key was not OK
SSL peer certificate or SSH remote key was not OK
An unknown option was passed in to libcurl
An unknown option was passed in to libcurl
A libcurl function was given a bad argument
A libcurl function was given a bad argument
Operation was aborted by an application callback
Operation was aborted by an application callback
FTP: command REST failed
FTP: command REST failed
FTP: command PORT failed
FTP: command PORT failed
HTTP response code said error
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: couldn't set file type
Error in the HTTP2 framing layer
Error in the HTTP2 framing layer
FTP: can't figure out the host in the PASV response
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: unknown PASS reply
FTP: The server did not accept the PRET command.
FTP: The server did not accept the PRET command.
FTP: Accepting server connect has timed out
FTP: Accepting server connect has timed out
FTP: The server failed to connect to data port
FTP: The server failed to connect to data port
FTP: weird server reply
FTP: weird server reply
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
URL using bad/illegal format or missing URL
URL using bad/illegal format or missing URL
Unsupported protocol
Unsupported protocol
Winsock version not supported
Winsock version not supported
Protocol family not supported
Protocol family not supported
Address family not supported
Address family not supported
Operation not supported
Operation not supported
Socket is unsupported
Socket is unsupported
Protocol is unsupported
Protocol is unsupported
Protocol option is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
Unknown error %d (%#x)
Could not resolve %s: %s
Could not resolve %s: %s
getaddrinfo() failed for %s:%d; %s
getaddrinfo() failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
init_resolve_thread() failed for %s; %s
%s:%d
%s:%d
Hostname was %sfound in DNS cache
Hostname was %sfound in DNS cache
Added %s:%d:%s to DNS cache
Added %s:%d:%s to DNS cache
Resolve %s found illegal!
Resolve %s found illegal!
%5[^:]:%d:%5s
%5[^:]:%d:%5s
Connected to %s (%s) port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
IDN support not present, can't parse Unicode domains
Protocol "%s" not supported or disabled in libcurl
Protocol "%s" not supported or disabled in libcurl
http_proxy
http_proxy
Port number out of range
Port number out of range
%s://%s%s%s:%hu%s%s%s
%s://%s%s%s:%hu%s%s%s
;type=%c
;type=%c
[%*45[0123456789abcdefABCDEF:.]%c
[%*45[0123456789abcdefABCDEF:.]%c
Couldn't find host %s in the _netrc file; using defaults
Couldn't find host %s in the _netrc file; using defaults
PTF@example.com
PTF@example.com
Couldn't resolve host '%s'
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
Couldn't resolve proxy '%s'
User-Agent: %s
User-Agent: %s
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Server doesn't support pipelining
Server doesn't support pipelining
Found bundle for host %s: %p
Found bundle for host %s: %p
Please URL encode %% as %%, see RFC 6874.
Please URL encode %% as %%, see RFC 6874.
Connection #%ld to host %s left intact
Connection #%ld to host %s left intact
Rebuilt URL to: %s
Rebuilt URL to: %s
SMTP.
SMTP.
malformed
malformed
:]://%[^
:]://%[^
[^:]:%[^
[^:]:%[^
Re-using existing connection! (#%ld) with host %s
Re-using existing connection! (#%ld) with host %s
Found connection %ld, with requests in the pipe (%zu)
Found connection %ld, with requests in the pipe (%zu)
%s://%s
%s://%s
Internal error removing splay node = %d
Internal error removing splay node = %d
Internal error clearing splay node = %d
Internal error clearing splay node = %d
Curl_poll(%d ds, %d ms)
Curl_poll(%d ds, %d ms)
Operation timed out after %ld milliseconds with %I64d bytes received
Operation timed out after %ld milliseconds with %I64d bytes received
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
Operation timed out after %ld milliseconds with %I64d out of %I64d bytes received
In state %d with no easy_conn, bail out!
In state %d with no easy_conn, bail out!
Pipe broke: handle 0x%p, url = %s
Pipe broke: handle 0x%p, url = %s
[%s %s %s]
[%s %s %s]
Send failure: %s
Send failure: %s
Recv failure: %s
Recv failure: %s
Write callback asked for PAUSE when not supported!
Write callback asked for PAUSE when not supported!
%s cookie %s="%s" for domain %s, path %s, expire %I64d
%s cookie %s="%s" for domain %s, path %s, expire %I64d
#HttpOnly_
#HttpOnly_
skipped cookie with bad tailmatch domain: %s
skipped cookie with bad tailmatch domain: %s
httponly
httponly
23[^;
23[^;
=]=I99[^;
=]=I99[^;
%s%s%s
%s%s%s
# Fatal libcurl error
# Fatal libcurl error
# Netscape HTTP Cookie File
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# This file was generated by libcurl! Edit at your own risk.
WARNING: failed to save cookies in %s
WARNING: failed to save cookies in %s
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Failed to set SO_KEEPALIVE on fd %d
Failed to set SO_KEEPALIVE on fd %d
bind failed with errno %d: %s
bind failed with errno %d: %s
Local port: %hu
Local port: %hu
Couldn't bind to '%s'
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
getsockname() failed with errno %d: %s
Bind to local port %hu failed, trying next
Bind to local port %hu failed, trying next
Name '%s' family %i resolved to '%s' family %i
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to interface '%s'
Couldn't bind to interface '%s'
Local Interface %s is ip %s using address family %i
Local Interface %s is ip %s using address family %i
ssloc inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
getpeername() failed with errno %d: %s
getpeername() failed with errno %d: %s
TCP_NODELAY set
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Could not set TCP_NODELAY: %s
Immediate connect fail for %s: %s
Immediate connect fail for %s: %s
sa_addr inet_ntop() failed with errno %d: %s
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
Trying %s...
Failed to connect to %s port %ld: %s
Failed to connect to %s port %ld: %s
connect to %s port %ld failed: %s
connect to %s port %ld failed: %s
0123456789
0123456789
libcurl is now using a weak random seed!
libcurl is now using a weak random seed!
not supported file type '%s' for certificate
not supported file type '%s' for certificate
file type P12 for certificate not supported
file type P12 for certificate not supported
file type ENG for certificate not implemented
file type ENG for certificate not implemented
not supported file type for private key
not supported file type for private key
Private key does not match the certificate public key
Private key does not match the certificate public key
file type P12 for private key not supported
file type P12 for private key not supported
file type ENG for private key not supported
file type ENG for private key not supported
unable to set private key file: '%s' type %s
unable to set private key file: '%s' type %s
unable to use client certificate (no key found or wrong pass phrase?)
unable to use client certificate (no key found or wrong pass phrase?)
SSL Engine not supported
SSL Engine not supported
select/poll on SSL socket, errno: %d
select/poll on SSL socket, errno: %d
SSL read: %s, errno %d
SSL read: %s, errno %d
d-d-d d:d:d %s
d-d-d d:d:d %s
common name: %s (matched)
common name: %s (matched)
SSL: certificate subject name '%s' does not match target host name '%s'
SSL: certificate subject name '%s' does not match target host name '%s'
SSL: unable to obtain common name from peer certificate
SSL: unable to obtain common name from peer certificate
SSL: illegal cert name field
SSL: illegal cert name field
SSL: no alternative certificate subject name matches target host name '%s'
SSL: no alternative certificate subject name matches target host name '%s'
subjectAltName does not match %s
subjectAltName does not match %s
subjectAltName: %s matched
subjectAltName: %s matched
CERT verify
CERT verify
Client key exchange
Client key exchange
Server key exchange
Server key exchange
CERT
CERT
Client CERT
Client CERT
Request CERT
Request CERT
Client key
Client key
SSLv%c, %s%s (%d):
SSLv%c, %s%s (%d):
OpenSSL was built without SSLv2 support
OpenSSL was built without SSLv2 support
Unsupported SSL protocol version
Unsupported SSL protocol version
SSL: SSL_set_fd failed: %s
SSL: SSL_set_fd failed: %s
SSL: SSL_set_session failed: %s
SSL: SSL_set_session failed: %s
error loading CRL file: %s
error loading CRL file: %s
CRLfile: %s
CRLfile: %s
CAfile: %s
CAfile: %s
CApath: %s
CApath: %s
successfully set certificate verify locations:
successfully set certificate verify locations:
error setting certificate verify locations, continuing anyway:
error setting certificate verify locations, continuing anyway:
error setting certificate verify locations:
error setting certificate verify locations:
failed setting cipher list: %s
failed setting cipher list: %s
ALL!EXPORT!EXPORT40!EXPORT56!aNULL!LOW!RC4
ALL!EXPORT!EXPORT40!EXPORT56!aNULL!LOW!RC4
SSL: couldn't create a context: %s
SSL: couldn't create a context: %s
SSL connection using %s / %s
SSL connection using %s / %s
SSL certificate problem, verify that the CA cert is OK.
SSL certificate problem, verify that the CA cert is OK.
SSL certificate problem: %s
SSL certificate problem: %s
Unknown SSL protocol error in connection to %s:%ld
Unknown SSL protocol error in connection to %s:%ld
%s: %s
%s: %s
x:
x:
%s(%s)
%s(%s)
%s: %s
%s: %s
Signature: %s
Signature: %s
Cert
Cert
RSA Public Key
RSA Public Key
RSA Public Key (%d bits)
RSA Public Key (%d bits)
pub_key
pub_key
priv_key
priv_key
Serial Number: %s
Serial Number: %s
x%c
x%c
Unable to load public key
Unable to load public key
Public Key Algorithm
Public Key Algorithm
Public Key Algorithm: %s
Public Key Algorithm: %s
Expire date: %s
Expire date: %s
Start date: %s
Start date: %s
Signature Algorithm: %s
Signature Algorithm: %s
Issuer: %s
Issuer: %s
- Subject: %s
- Subject: %s
--- Certificate chain
--- Certificate chain
SSL certificate verify ok.
SSL certificate verify ok.
SSL certificate verify result: %s (%ld), continuing anyway.
SSL certificate verify result: %s (%ld), continuing anyway.
SSL certificate verify result: %s (%ld)
SSL certificate verify result: %s (%ld)
SSL certificate issuer check ok (%s)
SSL certificate issuer check ok (%s)
SSL: Certificate issuer check failed (%s)
SSL: Certificate issuer check failed (%s)
SSL: Unable to read issuer cert (%s)
SSL: Unable to read issuer cert (%s)
SSL: Unable to open issuer cert (%s)
SSL: Unable to open issuer cert (%s)
issuer: %s
issuer: %s
expire date: %s
expire date: %s
start date: %s
start date: %s
subject: %s
subject: %s
Server certificate:
Server certificate:
SSL: couldn't get peer certificate!
SSL: couldn't get peer certificate!
SSL_write() return error %d
SSL_write() return error %d
SSL_write() error: %s
SSL_write() error: %s
SSL_write() returned SYSCALL, errno = %d
SSL_write() returned SYSCALL, errno = %d
--:--:--
--:--:--
%3I64d %s %3I64d %s %3I64d %s %s %s %s %s %s %s
%3I64d %s %3I64d %s %3I64d %s %s %s %s %s %s %s
%s%s%s%s%s%s
%s%s%s%s%s%s
Session: %s
Session: %s
%s %s RTSP/1.0
%s %s RTSP/1.0
Range: %s
Range: %s
Referer: %s
Referer: %s
Accept-Encoding: %s
Accept-Encoding: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Refusing to issue an RTSP SETUP without a Transport: header.
Transport: %s
Transport: %s
Transport:
Transport:
Refusing to issue an RTSP request [%s] without a session ID.
Refusing to issue an RTSP request [%s] without a session ID.
Got RTSP Session ID Line [%s], but wanted ID [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
Unable to read the CSeq header: [%s]
Unable to read the CSeq header: [%s]
SMTPS
SMTPS
SMTP
SMTP
EHLO %s
EHLO %s
HELO %s
HELO %s
AUTH %s
AUTH %s
AUTH %s %s
AUTH %s %s
%s %s
%s %s
MAIL FROM:%s SIZE=%s
MAIL FROM:%s SIZE=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s
MAIL FROM:%s
RCPT TO:
RCPT TO:
RCPT TO:%s
RCPT TO:%s
Got unexpected smtp-server response: %d
Got unexpected smtp-server response: %d
Remote access denied: %d
Remote access denied: %d
Access denied: %d
Access denied: %d
Authentication failed: %d
Authentication failed: %d
Command failed: %d
Command failed: %d
MAIL failed: %d
MAIL failed: %d
RCPT failed: %d
RCPT failed: %d
DATA failed: %d
DATA failed: %d
LOGIN
LOGIN
No known authentication mechanisms supported!
No known authentication mechanisms supported!
STARTTLS denied. %c
STARTTLS denied. %c
STARTTLS not supported.
STARTTLS not supported.
USER %s
USER %s
APOP %s %s
APOP %s %s
Access denied. %c
Access denied. %c
PASS %s
PASS %s
STLS not supported.
STLS not supported.
%cd
%cd
LOGIN %s %s
LOGIN %s %s
AUTHENTICATE %s
AUTHENTICATE %s
AUTHENTICATE %s %s
AUTHENTICATE %s %s
LIST "%s" *
LIST "%s" *
SELECT %s
SELECT %s
FETCH %s BODY[%s]
FETCH %s BODY[%s]
FETCH %s BODY[%s]
FETCH %s BODY[%s]
APPEND %s (\Seen) {%I64d}
APPEND %s (\Seen) {%I64d}
SEARCH %s
SEARCH %s
LOGINDISABLED
LOGINDISABLED
TFTP
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
set timeouts for state %d; Total %ld, retry %d maxtry %d
invalid tsize -:%s:- value in OACK packet
invalid tsize -:%s:- value in OACK packet
%s (%ld)
%s (%ld)
blksize is smaller than min supported
blksize is smaller than min supported
%s (%d)
%s (%d)
blksize is larger than max supported
blksize is larger than max supported
%s (%d) %s (%d)
%s (%d) %s (%d)
got option=(%s) value=(%s)
got option=(%s) value=(%s)
tftp_rx: internal error
tftp_rx: internal error
Timeout waiting for block %d ACK. Retries = %d
Timeout waiting for block %d ACK. Retries = %d
Received unexpected DATA packet block %d, expecting block %d
Received unexpected DATA packet block %d, expecting block %d
Received last DATA packet block %d again.
Received last DATA packet block %d again.
tftp_tx: internal error, event: %i
tftp_tx: internal error, event: %i
tftp_tx: giving up waiting for block %d ack
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
Received ACK for block %d, expecting %d
bind() failed; %s
bind() failed; %s
tftp_send_first: internal error
tftp_send_first: internal error
%s%c%s%c
%s%c%s%c
TFTP finished
TFTP finished
TFTP response timeout
TFTP response timeout
Can't get the size of %s
Can't get the size of %s
Can't open %s for writing
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
Couldn't open file %s
CLIENT libcurl 7.38.0
CLIENT libcurl 7.38.0
MATCH %s %s %s
MATCH %s %s %s
DEFINE %s %s
DEFINE %s %s
insufficient winsock version to support telnet
insufficient winsock version to support telnet
WSAStartup failed (%d)
WSAStartup failed (%d)
%s %d %d
%s %d %d
%s %s %d
%s %s %d
%s %s %s
%s %s %s
%s IAC %d
%s IAC %d
%s IAC %s
%s IAC %s
Sending data failed (%d)
Sending data failed (%d)
%d (unknown)
%d (unknown)
%s (unsupported)
%s (unsupported)
%s IAC SB
%s IAC SB
Unknown telnet option %s
Unknown telnet option %s
Syntax error in telnet option: %s
Syntax error in telnet option: %s
7[^= ]%*[ =]%5s
7[^= ]%*[ =]%5s
USER,%s
USER,%s
%c%c%c%c%s%c%c
%c%c%c%c%s%c%c
%c%s%c%s
%c%s%c%s
7[^,],7s
7[^,],7s
%c%c%c%c
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSACloseEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACreateEvent failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
WS2_32.DLL
FTPS
FTPS
PORT
PORT
Failure sending PORT command: %s
Failure sending PORT command: %s
,%d,%d
,%d,%d
Failure sending EPRT command: %s
Failure sending EPRT command: %s
%s |%d|%s|%hu|
%s |%d|%s|%hu|
bind() failed, we ran out of ports!
bind() failed, we ran out of ports!
bind(port=%hu) failed: %s
bind(port=%hu) failed: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) on non-local address failed: %s
socket failure: %s
socket failure: %s
failed to resolve the address provided to PORT: %s
failed to resolve the address provided to PORT: %s
getsockname() failed: %s
getsockname() failed: %s
Connect data stream passively
Connect data stream passively
STOR %s
STOR %s
APPE %s
APPE %s
SIZE %s
SIZE %s
RETR %s
RETR %s
ftp server doesn't support SIZE
ftp server doesn't support SIZE
PBSZ %d
PBSZ %d
Access denied: d
Access denied: d
ACCT %s
ACCT %s
ACCT rejected by server: d
ACCT rejected by server: d
Connecting to %s (%s) port %d
Connecting to %s (%s) port %d
Failure sending QUIT command: %s
Failure sending QUIT command: %s
Uploading to a URL without a file name!
Uploading to a URL without a file name!
FTP response aborted due to select/poll error: %d
FTP response aborted due to select/poll error: %d
FTP response timeout
FTP response timeout
MDTM %s
MDTM %s
Bad PASV/EPSV response: d
Bad PASV/EPSV response: d
Can't resolve new host %s:%hu
Can't resolve new host %s:%hu
Can't resolve proxy host %s:%hu
Can't resolve proxy host %s:%hu
Skips %d.%d.%d.%d for data connection, uses %s instead
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
%d,%d,%d,%d,%d,%d
Illegal port number in EPSV reply
Illegal port number in EPSV reply
%c%c%c%u%c
%c%c%c%u%c
ddd d:d:d GMT
ddd d:d:d GMT
dddddd
dddddd
unsupported MDTM reply format
unsupported MDTM reply format
QUOT string not accepted: %s
QUOT string not accepted: %s
Wildcard - "%s" skipped by user
Wildcard - "%s" skipped by user
Wildcard - START of "%s"
Wildcard - START of "%s"
Preparing for accepting server on data port
Preparing for accepting server on data port
CWD %s
CWD %s
Failed FTP upload:
Failed FTP upload:
RETR response: d
RETR response: d
server did not report OK, got %d
server did not report OK, got %d
Failure sending ABOR command: %s
Failure sending ABOR command: %s
Remembering we are in dir "%s"
Remembering we are in dir "%s"
ftp_perform ends with SECONDARY: %d
ftp_perform ends with SECONDARY: %d
PRET RETR %s
PRET RETR %s
PRET STOR %s
PRET STOR %s
PRET %s
PRET %s
REST %d
REST %d
Got a d response code instead of the assumed 200
Got a d response code instead of the assumed 200
TYPE %c
TYPE %c
Failed to do PORT
Failed to do PORT
PRET command not accepted: d
PRET command not accepted: d
Failed to MKD dir: d
Failed to MKD dir: d
MKD %s
MKD %s
QUOT command failed with d
QUOT command failed with d
Entry path is '%s'
Entry path is '%s'
PROT %c
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
Got a d ftp-server response when 220 was expected
Got a d ftp-server response when 220 was expected
HTTPS
HTTPS
%sAuthorization: Basic %s
%sAuthorization: Basic %s
%s:%s
%s:%s
%s auth using %s with user '%s'
%s auth using %s with user '%s'
HTTP/
HTTP/
Avoided giant realloc for header (max is %d)!
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %d
The requested URL returned error: %d
The requested URL returned error: %s
The requested URL returned error: %s
If-Unmodified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Last-Modified: %s
If-Modified-Since: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
%s, d %s M d:d:d GMT
Failed sending HTTP POST request
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Internal HTTP POST error!
Failed sending HTTP request
Failed sending HTTP request
%s%s=%s
%s%s=%s
%s HTTP/%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s
PTF://%s:%s@%s
PTF://%s:%s@%s
Content-Range: bytes %s/%I64d
Content-Range: bytes %s/%I64d
Content-Range: bytes %s%I64d/%I64d
Content-Range: bytes %s%I64d/%I64d
Range: bytes=%s
Range: bytes=%s
Host: %s%s%s:%hu
Host: %s%s%s:%hu
Host: %s%s%s
Host: %s%s%s
Chunky upload is not supported by HTTP 1.0
Chunky upload is not supported by HTTP 1.0
HTTP error before end of send, stop sending
HTTP error before end of send, stop sending
HTTP/1.0 connection set to keep alive!
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
HTTP 1.0, assume close after body
RTSP/%d.%d =
RTSP/%d.%d =
HTTP =
HTTP =
HTTP/%d.%d =
HTTP/%d.%d =
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
SOCKS4%s request granted.
SOCKS4%s request granted.
Failed to resolve "%s" for SOCKS4 connect.
Failed to resolve "%s" for SOCKS4 connect.
SOCKS4 connect to %s (locally resolved)
SOCKS4 connect to %s (locally resolved)
SOCKS4 communication to %s:%d
SOCKS4 communication to %s:%d
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
User was rejected by the SOCKS5 server (%d %d).
Received HTTP code %d from proxy after CONNECT
Received HTTP code %d from proxy after CONNECT
TUNNEL_STATE switched to: %d
TUNNEL_STATE switched to: %d
HTTP/1.%d %d
HTTP/1.%d %d
CONNECT %s HTTP/%s
CONNECT %s HTTP/%s
%s%s%s%s
%s%s%s%s
Host: %s
Host: %s
%s%s%s:%hu
%s%s%s:%hu
%s:%hu
%s:%hu
Establish HTTP proxy tunnel to %s:%hu
Establish HTTP proxy tunnel to %s:%hu
login
login
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Read callback asked for PAUSE when not supported!
Read callback asked for PAUSE when not supported!
operation aborted by callback
operation aborted by callback
ioctl callback returned error %d
ioctl callback returned error %d
the ioctl callback returned %d
the ioctl callback returned %d
seek callback returned error %d
seek callback returned error %d
%s in chunked-encoding
%s in chunked-encoding
Simulate a HTTP 304 response!
Simulate a HTTP 304 response!
HTTP server doesn't seem to support byte ranges. Cannot resume.
HTTP server doesn't seem to support byte ranges. Cannot resume.
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Excess found in a non pipelined read: excess = %zu, size = %I64d, maxdownload = %I64d, bytecount = %I64d
Excess found in a non pipelined read: excess = %zu, size = %I64d, maxdownload = %I64d, bytecount = %I64d
Rewinding stream by : %zu bytes on url %s (size = %I64d, maxdownload = %I64d, bytecount = %I64d, nread = %zd)
Rewinding stream by : %zu bytes on url %s (size = %I64d, maxdownload = %I64d, bytecount = %I64d, nread = %zd)
Rewinding stream by : %zd bytes on url %s (zero-length body)
Rewinding stream by : %zd bytes on url %s (zero-length body)
No URL set!
No URL set!
[^?&/:]://%c
[^?&/:]://%c
Disables POST, goes with %s
Disables POST, goes with %s
Issue another request to this URL: '%s'
Issue another request to this URL: '%s'
%s, algorithm="%s"
%s, algorithm="%s"
%s, opaque="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", cnonce="%s", nc=x, qop=%s, response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%.*s", cnonce="%s", nc=x, qop=%s, response="%s"
%s:%s:x:%s:%s:%s
%s:%s:x:%s:%s:%s
%s:%.*s
%s:%.*s
%s:%s:%s
%s:%s:%s
xxxx
xxxx
%sAuthorization: NTLM %s
%sAuthorization: NTLM %s
Conn: %ld (%p) Receive pipe weight: (%I64d/%zu), penalized: %s
Conn: %ld (%p) Receive pipe weight: (%I64d/%zu), penalized: %s
Site %s:%d is pipeline blacklisted
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
Server %s is blacklisted
Server %s is not blacklisted
Server %s is not blacklisted
d:d
d:d
d:d:d
d:d:d
%s/%s
%s/%s
%s xxxxxxxxxxxxxxxx
%s xxxxxxxxxxxxxxxx
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s,qop=%s
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s,qop=%s
00000001
00000001
user=%s
user=%s
auth=Bearer %s
auth=Bearer %s
0123456789-
0123456789-
%c%c==
%c%c==
%c%c%c=
%c%c%c=
.html
.html
.jpeg
.jpeg
; filename="%s"
; filename="%s"
------------------------xx
------------------------xx
couldn't open file "%s"
couldn't open file "%s"
Content-Type: %s
Content-Type: %s
Content-Type: multipart/mixed; boundary=%s
Content-Type: multipart/mixed; boundary=%s
%s; boundary=%s
%s; boundary=%s
NTLMSSP%c
NTLMSSP%c
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%s%s
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%s%s
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c
%c%c%c%c%c%c%c%c%c%c
%c%c%c%c%c%c%c%c%c%c
1.2.3
1.2.3
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
Unexpected end of file encountered in %s
Unexpected end of file encountered in %s
No MIME base64 lines found in %s
No MIME base64 lines found in %s
Content-Type: %s; charset=US-ASCII; name="%s"
Content-Type: %s; charset=US-ASCII; name="%s"
Content-Disposition: attachment; filename="%s"
Content-Disposition: attachment; filename="%s"
Creating %s
Creating %s
Section %s not MIME base64
Section %s not MIME base64
Couldn't open %s for output
Couldn't open %s for output
%s file not found
%s file not found
%s % .2d%.2d
%s % .2d%.2d
%a, %d %b %Y %H:%M:%S
%a, %d %b %Y %H:%M:%S
Date: %s
Date: %s
Machine: %s
Machine: %s
AUTH LOGIN
AUTH LOGIN
The required parameter '%s' was not specified.
The required parameter '%s' was not specified.
The value for the option '%s' must be specified.
The value for the option '%s' must be specified.
Unexpected parameter '%s'.
Unexpected parameter '%s'.
'%s' is not a correct numeric value for option '%s'.
'%s' is not a correct numeric value for option '%s'.
Separator expected after the option '%s'.
Separator expected after the option '%s'.
Option '%s' does not require a value.
Option '%s' does not require a value.
Option '%s' requires a value.
Option '%s' requires a value.
Invalid option '-%s'.
Invalid option '-%s'.
Unknown option '%s'.
Unknown option '%s'.
Unknown long option '%s'.
Unknown long option '%s'.
Usage: %s
Usage: %s
Encoding for configuration file '%s' is not supported
Encoding for configuration file '%s' is not supported
Can't open configuration file %s
Can't open configuration file %s
No more options can be saved from the configuration file '%s' (line '%d')
No more options can be saved from the configuration file '%s' (line '%d')
Error parsing the configuration file '%s'. Line '%d' too long.
Error parsing the configuration file '%s'. Line '%d' too long.
Error parsing the configuration file '%s' at line '%i'.
Error parsing the configuration file '%s' at line '%i'.
Error parsing the configuration file '%s'.
Error parsing the configuration file '%s'.
%s%d %d
%s%d %d
Register FAILED ! source=[%s] h=%p lasterror=%d
Register FAILED ! source=[%s] h=%p lasterror=%d
Expected tcp address format is '[host:]port'.
Expected tcp address format is '[host:]port'.
Expected listen address format is 'inet:port[@host]' or 'unix:socket_path'.
Expected listen address format is 'inet:port[@host]' or 'unix:socket_path'.
No execute permission.
No execute permission.
Path cannot be accessed (no execute permission).
Path cannot be accessed (no execute permission).
Port value is not a number in accepted range.
Port value is not a number in accepted range.
Path '%s' is not a unix socket file.
Path '%s' is not a unix socket file.
Path '%s' is not a file.
Path '%s' is not a file.
Path '%s' cannot be accessed (no execute permission).
Path '%s' cannot be accessed (no execute permission).
Path '%s' cannot be accessed (no write permission).
Path '%s' cannot be accessed (no write permission).
Path '%s' cannot be accessed (no read permission).
Path '%s' cannot be accessed (no read permission).
Path '%s' is not a directory.
Path '%s' is not a directory.
Path '%s' does not exist.
Path '%s' does not exist.
Path '%s' is not absolute.
Path '%s' is not absolute.
Accepted port values are numbers between '%I64d' and '%I64d'.
Accepted port values are numbers between '%I64d' and '%I64d'.
Contains multiple-precision arithmetic code originally written by David Ireland, copyright (c) 2001-6 by D.I. Management Services Pty Limited , and is used with permission.
Contains multiple-precision arithmetic code originally written by David Ireland, copyright (c) 2001-6 by D.I. Management Services Pty Limited , and is used with permission.
?OpenSSL 1.0.1j 15 Oct 2014
?OpenSSL 1.0.1j 15 Oct 2014
%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%s
%-23s %s Kx=%-8s Au=%-4s Enc=%-9s Mac=%-4s%s
EXPORT56
EXPORT56
EXPORT40
EXPORT40
EXPORT
EXPORT
.\ssl\ssl_cert.c
.\ssl\ssl_cert.c
wrong number of key bits
wrong number of key bits
unsupported status type
unsupported status type
unsupported ssl version
unsupported ssl version
unsupported protocol
unsupported protocol
unsupported elliptic curve
unsupported elliptic curve
unsupported digest type
unsupported digest type
unsupported compression algorithm
unsupported compression algorithm
unsupported cipher
unsupported cipher
unknown pkey type
unknown pkey type
unknown key exchange type
unknown key exchange type
unknown certificate type
unknown certificate type
unable to find public key parameters
unable to find public key parameters
unable to extract public key
unable to extract public key
unable to decode ecdh certs
unable to decode ecdh certs
unable to decode dh certs
unable to decode dh certs
tried to use unsupported cipher
tried to use unsupported cipher
tls peer did not respond with certificate list
tls peer did not respond with certificate list
tls illegal exporter label
tls illegal exporter label
tls client cert req with anon cipher
tls client cert req with anon cipher
tlsv1 unsupported extension
tlsv1 unsupported extension
tlsv1 certificate unobtainable
tlsv1 certificate unobtainable
tlsv1 bad certificate status response
tlsv1 bad certificate status response
tlsv1 bad certificate hash value
tlsv1 bad certificate hash value
tlsv1 alert export restriction
tlsv1 alert export restriction
sslv3 alert unsupported certificate
sslv3 alert unsupported certificate
sslv3 alert no certificate
sslv3 alert no certificate
sslv3 alert certificate unknown
sslv3 alert certificate unknown
sslv3 alert certificate revoked
sslv3 alert certificate revoked
sslv3 alert certificate expired
sslv3 alert certificate expired
sslv3 alert bad certificate
sslv3 alert bad certificate
signature for non signing certificate
signature for non signing certificate
reuse cert type not zero
reuse cert type not zero
reuse cert length not zero
reuse cert length not zero
public key not rsa
public key not rsa
public key is not rsa
public key is not rsa
public key encrypt error
public key encrypt error
peer error unsupported certificate type
peer error unsupported certificate type
peer error no certificate
peer error no certificate
peer error certificate
peer error certificate
peer did not return a certificate
peer did not return a certificate
null ssl method passed
null ssl method passed
no publickey
no publickey
no private key assigned
no private key assigned
no privatekey
no privatekey
Peer haven't sent GOST certificate, required for selected ciphersuite
Peer haven't sent GOST certificate, required for selected ciphersuite
no client cert received
no client cert received
no client cert method
no client cert method
no ciphers passed
no ciphers passed
no certificate specified
no certificate specified
no certificate set
no certificate set
no certificate returned
no certificate returned
no certificate assigned
no certificate assigned
no certificates returned
no certificates returned
missing tmp rsa pkey
missing tmp rsa pkey
missing tmp rsa key
missing tmp rsa key
missing tmp ecdh key
missing tmp ecdh key
missing tmp dh key
missing tmp dh key
missing rsa signing cert
missing rsa signing cert
missing rsa encrypting cert
missing rsa encrypting cert
missing rsa certificate
missing rsa certificate
missing export tmp rsa key
missing export tmp rsa key
missing export tmp dh key
missing export tmp dh key
missing dsa signing cert
missing dsa signing cert
missing dh rsa cert
missing dh rsa cert
missing dh key
missing dh key
missing dh dsa cert
missing dh dsa cert
krb5 server rd_req (keytab perms?)
krb5 server rd_req (keytab perms?)
key arg too long
key arg too long
invalid ticket keys length
invalid ticket keys length
http request
http request
https proxy request
https proxy request
error generating tmp rsa key
error generating tmp rsa key
ecc cert should have sha1 signature
ecc cert should have sha1 signature
ecc cert should have rsa signature
ecc cert should have rsa signature
ecc cert not for signing
ecc cert not for signing
ecc cert not for key agreement
ecc cert not for key agreement
cert length mismatch
cert length mismatch
certificate verify failed
certificate verify failed
bad ecc cert
bad ecc cert
bad dh pub key length
bad dh pub key length
TLS1_SETUP_KEY_BLOCK
TLS1_SETUP_KEY_BLOCK
TLS1_EXPORT_KEYING_MATERIAL
TLS1_EXPORT_KEYING_MATERIAL
tls1_cert_verify_mac
tls1_cert_verify_mac
SSL_VERIFY_CERT_CHAIN
SSL_VERIFY_CERT_CHAIN
SSL_use_RSAPrivateKey_file
SSL_use_RSAPrivateKey_file
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey_ASN1
SSL_use_RSAPrivateKey
SSL_use_RSAPrivateKey
SSL_use_PrivateKey_file
SSL_use_PrivateKey_file
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey_ASN1
SSL_use_PrivateKey
SSL_use_PrivateKey
SSL_use_certificate_file
SSL_use_certificate_file
SSL_use_certificate_ASN1
SSL_use_certificate_ASN1
SSL_use_certificate
SSL_use_certificate
SSL_SET_PKEY
SSL_SET_PKEY
SSL_SET_CERT
SSL_SET_CERT
SSL_SESS_CERT_NEW
SSL_SESS_CERT_NEW
SSL_GET_SIGN_PKEY
SSL_GET_SIGN_PKEY
SSL_GET_SERVER_SEND_PKEY
SSL_GET_SERVER_SEND_PKEY
SSL_GET_SERVER_SEND_CERT
SSL_GET_SERVER_SEND_CERT
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_RSAPrivateKey_file
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey_ASN1
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_RSAPrivateKey
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_PrivateKey_ASN1
SSL_CTX_use_PrivateKey
SSL_CTX_use_PrivateKey
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_chain_file
SSL_CTX_use_certificate_chain_file
SSL_CTX_use_certificate_ASN1
SSL_CTX_use_certificate_ASN1
SSL_CTX_use_certificate
SSL_CTX_use_certificate
SSL_CTX_set_client_cert_engine
SSL_CTX_set_client_cert_engine
SSL_CTX_check_private_key
SSL_CTX_check_private_key
SSL_CHECK_SRVR_ECC_CERT_AND_ALG
SSL_CHECK_SRVR_ECC_CERT_AND_ALG
SSL_check_private_key
SSL_check_private_key
SSL_CERT_NEW
SSL_CERT_NEW
SSL_CERT_INSTANTIATE
SSL_CERT_INSTANTIATE
SSL_CERT_INST
SSL_CERT_INST
SSL_CERT_DUP
SSL_CERT_DUP
SSL_add_file_cert_subjects_to_stack
SSL_add_file_cert_subjects_to_stack
SSL_add_dir_cert_subjects_to_stack
SSL_add_dir_cert_subjects_to_stack
SSL3_SETUP_KEY_BLOCK
SSL3_SETUP_KEY_BLOCK
SSL3_SEND_SERVER_KEY_EXCHANGE
SSL3_SEND_SERVER_KEY_EXCHANGE
SSL3_SEND_SERVER_CERTIFICATE
SSL3_SEND_SERVER_CERTIFICATE
SSL3_SEND_CLIENT_KEY_EXCHANGE
SSL3_SEND_CLIENT_KEY_EXCHANGE
SSL3_SEND_CLIENT_CERTIFICATE
SSL3_SEND_CLIENT_CERTIFICATE
SSL3_SEND_CERTIFICATE_REQUEST
SSL3_SEND_CERTIFICATE_REQUEST
SSL3_OUTPUT_CERT_CHAIN
SSL3_OUTPUT_CERT_CHAIN
SSL3_GET_SERVER_CERTIFICATE
SSL3_GET_SERVER_CERTIFICATE
SSL3_GET_KEY_EXCHANGE
SSL3_GET_KEY_EXCHANGE
SSL3_GET_CLIENT_KEY_EXCHANGE
SSL3_GET_CLIENT_KEY_EXCHANGE
SSL3_GET_CLIENT_CERTIFICATE
SSL3_GET_CLIENT_CERTIFICATE
SSL3_GET_CERT_VERIFY
SSL3_GET_CERT_VERIFY
SSL3_GET_CERT_STATUS
SSL3_GET_CERT_STATUS
SSL3_GET_CERTIFICATE_REQUEST
SSL3_GET_CERTIFICATE_REQUEST
SSL3_GENERATE_KEY_BLOCK
SSL3_GENERATE_KEY_BLOCK
SSL3_CHECK_CERT_AND_ALGORITHM
SSL3_CHECK_CERT_AND_ALGORITHM
SSL3_ADD_CERT_TO_BUF
SSL3_ADD_CERT_TO_BUF
SSL2_SET_CERTIFICATE
SSL2_SET_CERTIFICATE
SSL2_GENERATE_KEY_MATERIAL
SSL2_GENERATE_KEY_MATERIAL
REQUEST_CERTIFICATE
REQUEST_CERTIFICATE
GET_CLIENT_MASTER_KEY
GET_CLIENT_MASTER_KEY
DTLS1_SEND_SERVER_KEY_EXCHANGE
DTLS1_SEND_SERVER_KEY_EXCHANGE
DTLS1_SEND_SERVER_CERTIFICATE
DTLS1_SEND_SERVER_CERTIFICATE
DTLS1_SEND_CLIENT_KEY_EXCHANGE
DTLS1_SEND_CLIENT_KEY_EXCHANGE
DTLS1_SEND_CLIENT_CERTIFICATE
DTLS1_SEND_CLIENT_CERTIFICATE
DTLS1_SEND_CERTIFICATE_REQUEST
DTLS1_SEND_CERTIFICATE_REQUEST
DTLS1_OUTPUT_CERT_CHAIN
DTLS1_OUTPUT_CERT_CHAIN
DTLS1_ADD_CERT_TO_BUF
DTLS1_ADD_CERT_TO_BUF
CLIENT_MASTER_KEY
CLIENT_MASTER_KEY
CLIENT_CERTIFICATE
CLIENT_CERTIFICATE
os.length session_id)
os.length session_id)
TLSv1 part of OpenSSL 1.0.1j 15 Oct 2014
TLSv1 part of OpenSSL 1.0.1j 15 Oct 2014
SSLv3 part of OpenSSL 1.0.1j 15 Oct 2014
SSLv3 part of OpenSSL 1.0.1j 15 Oct 2014
SSLv2 part of OpenSSL 1.0.1j 15 Oct 2014
SSLv2 part of OpenSSL 1.0.1j 15 Oct 2014
s->session->master_key_length >= 0 && s->session->master_key_length session->master_key)
s->session->master_key_length >= 0 && s->session->master_key_length session->master_key)
DTLSv1 part of OpenSSL 1.0.1j 15 Oct 2014
DTLSv1 part of OpenSSL 1.0.1j 15 Oct 2014
key expansion
key expansion
client write key
client write key
server write key
server write key
%s:%d: rec->data != rec->input
%s:%d: rec->data != rec->input
c->iv_len session->key_arg)
c->iv_len session->key_arg)
s->s2->key_material_length s2->key_material
s->s2->key_material_length s2->key_material
GOST signature length is %d
GOST signature length is %d
ssl_sess_cert
ssl_sess_cert
ssl_cert
ssl_cert
evp_pkey
evp_pkey
x509_pkey
x509_pkey
%s(%d): OpenSSL internal error, assertion failed: %s
%s(%d): OpenSSL internal error, assertion failed: %s
SHA-256 part of OpenSSL 1.0.1j 15 Oct 2014
SHA-256 part of OpenSSL 1.0.1j 15 Oct 2014
\X
\X
X.509 part of OpenSSL 1.0.1j 15 Oct 2014
X.509 part of OpenSSL 1.0.1j 15 Oct 2014
OPENSSL_ALLOW_PROXY_CERTS
OPENSSL_ALLOW_PROXY_CERTS
passed a null parameter
passed a null parameter
DSO support routines
DSO support routines
x509 certificate routines
x509 certificate routines
error:lX:%s:%s:%s
error:lX:%s:%s:%s
openssl.cnf
openssl.cnf
ASN.1 part of OpenSSL 1.0.1j 15 Oct 2014
ASN.1 part of OpenSSL 1.0.1j 15 Oct 2014
d.registeredID
d.registeredID
d.iPAddress
d.iPAddress
d.uniformResourceIdentifier
d.uniformResourceIdentifier
d.ediPartyName
d.ediPartyName
d.directoryName
d.directoryName
d.dNSName
d.dNSName
d.rfc822Name
d.rfc822Name
d.otherName
d.otherName
Stack part of OpenSSL 1.0.1j 15 Oct 2014
Stack part of OpenSSL 1.0.1j 15 Oct 2014
unsupported or invalid name syntax
unsupported or invalid name syntax
unsupported or invalid name constraint syntax
unsupported or invalid name constraint syntax
unsupported name constraint type
unsupported name constraint type
name constraints minimum and maximum not supported
name constraints minimum and maximum not supported
Unsupported extension feature
Unsupported extension feature
invalid or inconsistent certificate policy extension
invalid or inconsistent certificate policy extension
invalid or inconsistent certificate extension
invalid or inconsistent certificate extension
key usage does not include digital signature
key usage does not include digital signature
key usage does not include CRL signing
key usage does not include CRL signing
unable to get CRL issuer certificate
unable to get CRL issuer certificate
key usage does not include certificate signing
key usage does not include certificate signing
authority and subject key identifier mismatch
authority and subject key identifier mismatch
certificate rejected
certificate rejected
certificate not trusted
certificate not trusted
unsupported certificate purpose
unsupported certificate purpose
proxy certificates not allowed, please set the appropriate flag
proxy certificates not allowed, please set the appropriate flag
invalid non-CA certificate (has CA markings)
invalid non-CA certificate (has CA markings)
invalid CA certificate
invalid CA certificate
certificate revoked
certificate revoked
certificate chain too long
certificate chain too long
unable to verify the first certificate
unable to verify the first certificate
unable to get local issuer certificate
unable to get local issuer certificate
self signed certificate in certificate chain
self signed certificate in certificate chain
self signed certificate
self signed certificate
format error in certificate's notAfter field
format error in certificate's notAfter field
format error in certificate's notBefore field
format error in certificate's notBefore field
certificate has expired
certificate has expired
certificate is not yet valid
certificate is not yet valid
certificate signature failure
certificate signature failure
unable to decode issuer public key
unable to decode issuer public key
unable to decrypt certificate's signature
unable to decrypt certificate's signature
unable to get certificate CRL
unable to get certificate CRL
unable to get issuer certificate
unable to get issuer certificate
x%s
x%s
%s - d:d:d%.*s %d%s
%s - d:d:d%.*s %d%s
%*s
%*s
%*s%s
%*s%s
%*s%s:
%*s%s:
CERTIFICATE
CERTIFICATE
Big Number part of OpenSSL 1.0.1j 15 Oct 2014
Big Number part of OpenSSL 1.0.1j 15 Oct 2014
cert_info
cert_info
MD5 part of OpenSSL 1.0.1j 15 Oct 2014
MD5 part of OpenSSL 1.0.1j 15 Oct 2014
libdes part of OpenSSL 1.0.1j 15 Oct 2014
libdes part of OpenSSL 1.0.1j 15 Oct 2014
DES part of OpenSSL 1.0.1j 15 Oct 2014
DES part of OpenSSL 1.0.1j 15 Oct 2014
MD4 part of OpenSSL 1.0.1j 15 Oct 2014
MD4 part of OpenSSL 1.0.1j 15 Oct 2014
lhash part of OpenSSL 1.0.1j 15 Oct 2014
lhash part of OpenSSL 1.0.1j 15 Oct 2014
Any Extended Key Usage
Any Extended Key Usage
anyExtendedKeyUsage
anyExtendedKeyUsage
supportedAlgorithms
supportedAlgorithms
crossCertificatePair
crossCertificatePair
certificateRevocationList
certificateRevocationList
cACertificate
cACertificate
userCertificate
userCertificate
userPassword
userPassword
supportedApplicationContext
supportedApplicationContext
Microsoft Local Key set
Microsoft Local Key set
LocalKeySet
LocalKeySet
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-None-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
id-Gost28147-89-CryptoPro-KeyMeshing
password based MAC
password based MAC
id-PasswordBasedMAC
id-PasswordBasedMAC
X509v3 Certificate Issuer
X509v3 Certificate Issuer
certificateIssuer
certificateIssuer
certicom-arc
certicom-arc
Proxy Certificate Information
Proxy Certificate Information
proxyCertInfo
proxyCertInfo
Microsoft Smartcardlogin
Microsoft Smartcardlogin
msSmartcardLogin
msSmartcardLogin
joint-iso-itu-t
joint-iso-itu-t
JOINT-ISO-ITU-T
JOINT-ISO-ITU-T
set-rootKeyThumb
set-rootKeyThumb
setAttr-Cert
setAttr-Cert
setCext-cCertRequired
setCext-cCertRequired
setCext-certType
setCext-certType
setct-CertResTBE
setct-CertResTBE
setct-CertReqTBEX
setct-CertReqTBEX
setct-CertReqTBE
setct-CertReqTBE
setct-AcqCardCodeMsgTBE
setct-AcqCardCodeMsgTBE
setct-CertInqReqTBS
setct-CertInqReqTBS
setct-CertResData
setct-CertResData
setct-CertReqTBS
setct-CertReqTBS
setct-CertReqData
setct-CertReqData
setct-PCertResTBS
setct-PCertResTBS
setct-PCertReqData
setct-PCertReqData
setct-AcqCardCodeMsg
setct-AcqCardCodeMsg
certificate extensions
certificate extensions
set-certExt
set-certExt
set-msgExt
set-msgExt
id-ecPublicKey
id-ecPublicKey
id-cmc-confirmCertAcceptance
id-cmc-confirmCertAcceptance
id-cmc-getCert
id-cmc-getCert
id-regInfo-certReq
id-regInfo-certReq
id-regCtrl-protocolEncrKey
id-regCtrl-protocolEncrKey
id-regCtrl-oldCertID
id-regCtrl-oldCertID
id-it-revPassphrase
id-it-revPassphrase
id-it-keyPairParamRep
id-it-keyPairParamRep
id-it-keyPairParamReq
id-it-keyPairParamReq
id-it-unsupportedOIDs
id-it-unsupportedOIDs
id-it-caKeyUpdateInfo
id-it-caKeyUpdateInfo
id-it-encKeyPairTypes
id-it-encKeyPairTypes
id-it-signKeyPairTypes
id-it-signKeyPairTypes
id-it-caProtEncCert
id-it-caProtEncCert
id-mod-attribute-cert
id-mod-attribute-cert
id-mod-qualified-cert-93
id-mod-qualified-cert-93
id-mod-qualified-cert-88
id-mod-qualified-cert-88
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certCRLTimestamp
id-smime-aa-ets-certValues
id-smime-aa-ets-certValues
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-CertificateRefs
id-smime-aa-ets-otherSigCert
id-smime-aa-ets-otherSigCert
id-smime-aa-smimeEncryptCerts
id-smime-aa-smimeEncryptCerts
id-smime-aa-signingCertificate
id-smime-aa-signingCertificate
id-smime-aa-encrypKeyPref
id-smime-aa-encrypKeyPref
id-smime-aa-msgSigDigest
id-smime-aa-msgSigDigest
id-smime-ct-publishCert
id-smime-ct-publishCert
id-smime-mod-msg-v3
id-smime-mod-msg-v3
sdsiCertificate
sdsiCertificate
x509Certificate
x509Certificate
localKeyID
localKeyID
certBag
certBag
pkcs8ShroudedKeyBag
pkcs8ShroudedKeyBag
keyBag
keyBag
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And2-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
pbeWithSHA1And3-KeyTripleDES-CBC
TLS Web Client Authentication
TLS Web Client Authentication
TLS Web Server Authentication
TLS Web Server Authentication
X509v3 Extended Key Usage
X509v3 Extended Key Usage
extendedKeyUsage
extendedKeyUsage
X509v3 Authority Key Identifier
X509v3 Authority Key Identifier
authorityKeyIdentifier
authorityKeyIdentifier
X509v3 Certificate Policies
X509v3 Certificate Policies
certificatePolicies
certificatePolicies
X509v3 Private Key Usage Period
X509v3 Private Key Usage Period
privateKeyUsagePeriod
privateKeyUsagePeriod
X509v3 Key Usage
X509v3 Key Usage
keyUsage
keyUsage
X509v3 Subject Key Identifier
X509v3 Subject Key Identifier
subjectKeyIdentifier
subjectKeyIdentifier
Netscape Certificate Sequence
Netscape Certificate Sequence
nsCertSequence
nsCertSequence
Netscape CA Policy Url
Netscape CA Policy Url
nsCaPolicyUrl
nsCaPolicyUrl
Netscape Renewal Url
Netscape Renewal Url
nsRenewalUrl
nsRenewalUrl
Netscape CA Revocation Url
Netscape CA Revocation Url
nsCaRevocationUrl
nsCaRevocationUrl
Netscape Revocation Url
Netscape Revocation Url
nsRevocationUrl
nsRevocationUrl
Netscape Base Url
Netscape Base Url
nsBaseUrl
nsBaseUrl
Netscape Cert Type
Netscape Cert Type
nsCertType
nsCertType
Netscape Certificate Extension
Netscape Certificate Extension
nsCertExt
nsCertExt
extendedCertificateAttributes
extendedCertificateAttributes
challengePassword
challengePassword
dhKeyAgreement
dhKeyAgreement
Diffie-Hellman part of OpenSSL 1.0.1j 15 Oct 2014
Diffie-Hellman part of OpenSSL 1.0.1j 15 Oct 2014
EVP part of OpenSSL 1.0.1j 15 Oct 2014
EVP part of OpenSSL 1.0.1j 15 Oct 2014
crlUrl
crlUrl
certStatus
certStatus
certId
certId
OCSP_CERTSTATUS
OCSP_CERTSTATUS
value.unknown
value.unknown
value.revoked
value.revoked
value.good
value.good
value.byKey
value.byKey
value.byName
value.byName
reqCert
reqCert
OCSP_CERTID
OCSP_CERTID
issuerKeyHash
issuerKeyHash
certs
certs
.\crypto\pem\pem_pkey.c
.\crypto\pem\pem_pkey.c
ENCRYPTED PRIVATE KEY
ENCRYPTED PRIVATE KEY
PRIVATE KEY
PRIVATE KEY
ANY PRIVATE KEY
ANY PRIVATE KEY
RSA part of OpenSSL 1.0.1j 15 Oct 2014
RSA part of OpenSSL 1.0.1j 15 Oct 2014
CERTIFICATE REQUEST
CERTIFICATE REQUEST
NEW CERTIFICATE REQUEST
NEW CERTIFICATE REQUEST
RSA PRIVATE KEY
RSA PRIVATE KEY
DSA PRIVATE KEY
DSA PRIVATE KEY
EC PRIVATE KEY
EC PRIVATE KEY
TRUSTED CERTIFICATE
TRUSTED CERTIFICATE
.\crypto\engine\eng_pkey.c
.\crypto\engine\eng_pkey.c
PEM part of OpenSSL 1.0.1j 15 Oct 2014
PEM part of OpenSSL 1.0.1j 15 Oct 2014
phrase is too short, needs to be at least %d chars
phrase is too short, needs to be at least %d chars
Enter PEM pass phrase:
Enter PEM pass phrase:
X509 CERTIFICATE
X509 CERTIFICATE
EC part of OpenSSL 1.0.1j 15 Oct 2014
EC part of OpenSSL 1.0.1j 15 Oct 2014
.\crypto\ec\ec_key.c
.\crypto\ec\ec_key.c
.\crypto\dh\dh_key.c
.\crypto\dh\dh_key.c
len>=0 && lenkey)
len>=0 && lenkey)
j key)
j key)
SHA-512 part of OpenSSL 1.0.1j 15 Oct 2014
SHA-512 part of OpenSSL 1.0.1j 15 Oct 2014
SHA1 part of OpenSSL 1.0.1j 15 Oct 2014
SHA1 part of OpenSSL 1.0.1j 15 Oct 2014
RAND part of OpenSSL 1.0.1j 15 Oct 2014
RAND part of OpenSSL 1.0.1j 15 Oct 2014
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
You need to read the OpenSSL FAQ, hXXp://VVV.openssl.org/support/faq.html
DSA part of OpenSSL 1.0.1j 15 Oct 2014
DSA part of OpenSSL 1.0.1j 15 Oct 2014
value.single
value.single
value.set
value.set
X509_PUBKEY
X509_PUBKEY
public_key
public_key
.\crypto\asn1\x_pubkey.c
.\crypto\asn1\x_pubkey.c
appl [ %d ]
appl [ %d ]
cont [ %d ]
cont [ %d ]
priv [ %d ]
priv [ %d ]
'() ,-./:=?
'() ,-./:=?
%d.%d.%d.%d/%d.%d.%d.%d
%d.%d.%d.%d/%d.%d.%d.%d
ddddddZ
ddddddZ
ddddddZ
ddddddZ
C:\home\openssl_x86_static/ssl
C:\home\openssl_x86_static/ssl
C:\home\openssl_x86_static/ssl/certs
C:\home\openssl_x86_static/ssl/certs
C:\home\openssl_x86_static/ssl/cert.pem
C:\home\openssl_x86_static/ssl/cert.pem
SSL_CERT_DIR
SSL_CERT_DIR
SSL_CERT_FILE
SSL_CERT_FILE
CONF part of OpenSSL 1.0.1j 15 Oct 2014
CONF part of OpenSSL 1.0.1j 15 Oct 2014
%lu:%s:%s:%d:%s
%lu:%s:%s:%d:%s
%sx -
%sx -
x -
x -
name.relativename
name.relativename
name.fullname
name.fullname
certificateHold
certificateHold
Certificate Hold
Certificate Hold
cessationOfOperation
cessationOfOperation
Cessation Of Operation
Cessation Of Operation
keyCompromise
keyCompromise
Key Compromise
Key Compromise
%*sOnly Attribute Certificates
%*sOnly Attribute Certificates
%*sOnly CA Certificates
%*sOnly CA Certificates
%*sOnly User Certificates
%*sOnly User Certificates
PROXY_CERT_INFO_EXTENSION
PROXY_CERT_INFO_EXTENSION
AUTHORITY_KEYID
AUTHORITY_KEYID
keyid
keyid
X509_CERT_PAIR
X509_CERT_PAIR
X509_CERT_AUX
X509_CERT_AUX
Load certs from files in a directory
Load certs from files in a directory
%s%clx.%s%d
%s%clx.%s%d
pubkey
pubkey
enc_key
enc_key
key_enc_algor
key_enc_algor
cert
cert
d.encrypted
d.encrypted
d.digest
d.digest
d.signed_and_enveloped
d.signed_and_enveloped
d.enveloped
d.enveloped
d.sign
d.sign
d.data
d.data
d.other
d.other
EC_PRIVATEKEY
EC_PRIVATEKEY
publicKey
publicKey
privateKey
privateKey
value.implicitlyCA
value.implicitlyCA
value.parameters
value.parameters
value.named_curve
value.named_curve
p.char_two
p.char_two
p.prime
p.prime
p.ppBasis
p.ppBasis
p.tpBasis
p.tpBasis
p.onBasis
p.onBasis
p.other
p.other
PKCS8_PRIV_KEY_INFO
PKCS8_PRIV_KEY_INFO
pkey
pkey
pkeyalg
pkeyalg
.\crypto\evp\evp_pkey.c
.\crypto\evp\evp_pkey.c
NETSCAPE_CERT_SEQUENCE
NETSCAPE_CERT_SEQUENCE
.pp@0
.pp@0
aEÃ
aEÃ
(#EÚ
(#EÚ
ÚE
ÚE
AES part of OpenSSL 1.0.1j 15 Oct 2014
AES part of OpenSSL 1.0.1j 15 Oct 2014
RC2 part of OpenSSL 1.0.1j 15 Oct 2014
RC2 part of OpenSSL 1.0.1j 15 Oct 2014
IDEA part of OpenSSL 1.0.1j 15 Oct 2014
IDEA part of OpenSSL 1.0.1j 15 Oct 2014
unsupported type
unsupported type
unsupported recpientinfo type
unsupported recpientinfo type
unsupported recipient type
unsupported recipient type
unsupported key encryption algorithm
unsupported key encryption algorithm
unsupported kek algorithm
unsupported kek algorithm
unsupported content type
unsupported content type
signer certificate not found
signer certificate not found
private key does not match certificate
private key does not match certificate
no public key
no public key
no private key
no private key
no password
no password
no msgsigdigest
no msgsigdigest
no key or cert
no key or cert
no key
no key
not supported for this key type
not supported for this key type
not key transport
not key transport
msgsigdigest wrong length
msgsigdigest wrong length
msgsigdigest verification failure
msgsigdigest verification failure
msgsigdigest error
msgsigdigest error
invalid key length
invalid key length
invalid key encryption parameter
invalid key encryption parameter
invalid encrypted key length
invalid encrypted key length
error setting key
error setting key
error getting public key
error getting public key
certificate verify error
certificate verify error
certificate has no keyid
certificate has no keyid
certificate already present
certificate already present
CMS_SIGNERINFO_VERIFY_CERT
CMS_SIGNERINFO_VERIFY_CERT
CMS_RecipientInfo_set0_pkey
CMS_RecipientInfo_set0_pkey
CMS_RecipientInfo_set0_password
CMS_RecipientInfo_set0_password
CMS_RecipientInfo_set0_key
CMS_RecipientInfo_set0_key
CMS_RecipientInfo_ktri_cert_cmp
CMS_RecipientInfo_ktri_cert_cmp
cms_msgSigDigest_add1
cms_msgSigDigest_add1
CMS_GET0_CERTIFICATE_CHOICES
CMS_GET0_CERTIFICATE_CHOICES
CMS_EncryptedData_set1_key
CMS_EncryptedData_set1_key
CMS_decrypt_set1_pkey
CMS_decrypt_set1_pkey
CMS_decrypt_set1_password
CMS_decrypt_set1_password
CMS_decrypt_set1_key
CMS_decrypt_set1_key
CMS_add1_recipient_cert
CMS_add1_recipient_cert
CMS_add0_recipient_password
CMS_add0_recipient_password
CMS_add0_recipient_key
CMS_add0_recipient_key
CMS_add0_cert
CMS_add0_cert
unsupported requestorname type
unsupported requestorname type
no certificates in chain
no certificates in chain
error parsing url
error parsing url
PARSE_HTTP_LINE1
PARSE_HTTP_LINE1
OCSP_parse_url
OCSP_parse_url
OCSP_cert_id_new
OCSP_cert_id_new
unimplemented public key method
unimplemented public key method
invalid cmd number
invalid cmd number
invalid cmd name
invalid cmd name
failed loading public key
failed loading public key
failed loading private key
failed loading private key
cmd not executable
cmd not executable
ENGINE_UNLOAD_KEY
ENGINE_UNLOAD_KEY
ENGINE_load_ssl_client_cert
ENGINE_load_ssl_client_cert
ENGINE_load_public_key
ENGINE_load_public_key
ENGINE_load_private_key
ENGINE_load_private_key
ENGINE_get_pkey_meth
ENGINE_get_pkey_meth
ENGINE_get_pkey_asn1_meth
ENGINE_get_pkey_asn1_meth
ENGINE_ctrl_cmd_string
ENGINE_ctrl_cmd_string
ENGINE_ctrl_cmd
ENGINE_ctrl_cmd
ENGINE_cmd_is_executable
ENGINE_cmd_is_executable
unsupported version
unsupported version
unsupported md algorithm
unsupported md algorithm
invalid signer certificate purpose
invalid signer certificate purpose
ess signing certificate error
ess signing certificate error
ess add signing cert error
ess add signing cert error
TS_VERIFY_CERT
TS_VERIFY_CERT
TS_TST_INFO_set_msg_imprint
TS_TST_INFO_set_msg_imprint
TS_RESP_CTX_set_signer_cert
TS_RESP_CTX_set_signer_cert
TS_RESP_CTX_set_certs
TS_RESP_CTX_set_certs
TS_REQ_set_msg_imprint
TS_REQ_set_msg_imprint
TS_MSG_IMPRINT_set_algo
TS_MSG_IMPRINT_set_algo
TS_CHECK_SIGNING_CERTS
TS_CHECK_SIGNING_CERTS
ESS_SIGNING_CERT_NEW_INIT
ESS_SIGNING_CERT_NEW_INIT
ESS_CERT_ID_NEW_INIT
ESS_CERT_ID_NEW_INIT
ESS_ADD_SIGNING_CERT
ESS_ADD_SIGNING_CERT
functionality not supported
functionality not supported
WIN32_JOINER
WIN32_JOINER
unsupported pkcs12 mode
unsupported pkcs12 mode
key gen error
key gen error
PKCS8_add_keyusage
PKCS8_add_keyusage
PKCS12_PBE_keyivgen
PKCS12_PBE_keyivgen
PKCS12_newpass
PKCS12_newpass
PKCS12_MAKE_SHKEYBAG
PKCS12_MAKE_SHKEYBAG
PKCS12_MAKE_KEYBAG
PKCS12_MAKE_KEYBAG
PKCS12_key_gen_uni
PKCS12_key_gen_uni
PKCS12_key_gen_asc
PKCS12_key_gen_asc
PKCS12_add_localkeyid
PKCS12_add_localkeyid
unsupported option
unsupported option
unable to get issuer keyid
unable to get issuer keyid
policy syntax not currently supported
policy syntax not currently supported
operation not defined
operation not defined
no proxy cert policy language defined
no proxy cert policy language defined
no issuer certificate
no issuer certificate
extension setting not supported
extension setting not supported
V2I_EXTENDED_KEY_USAGE
V2I_EXTENDED_KEY_USAGE
V2I_AUTHORITY_KEYID
V2I_AUTHORITY_KEYID
S2I_SKEY_ID
S2I_SKEY_ID
S2I_ASN1_SKEY_ID
S2I_ASN1_SKEY_ID
R2I_CERTPOL
R2I_CERTPOL
unsupported cipher type
unsupported cipher type
unknown operation
unknown operation
unable to find certificate
unable to find certificate
signing not supported for this key type
signing not supported for this key type
operation not supported on this type
operation not supported on this type
no recipient matches key
no recipient matches key
no recipient matches certificate
no recipient matches certificate
encryption not supported for this key type
encryption not supported for this key type
decrypted key is wrong length
decrypted key is wrong length
PKCS7_add_certificate
PKCS7_add_certificate
unsupported method
unsupported method
no port specified
no port specified
no port defined
no port defined
no accept port specified
no accept port specified
broken pipe
broken pipe
BIO_get_port
BIO_get_port
ECDH_compute_key
ECDH_compute_key
data too large for key size
data too large for key size
unsupported field
unsupported field
passed null parameter
passed null parameter
not a supported NIST prime
not a supported NIST prime
missing private key
missing private key
keys not set
keys not set
invalid private key
invalid private key
gf2m not supported
gf2m not supported
PKEY_EC_SIGN
PKEY_EC_SIGN
PKEY_EC_PARAMGEN
PKEY_EC_PARAMGEN
PKEY_EC_KEYGEN
PKEY_EC_KEYGEN
PKEY_EC_DERIVE
PKEY_EC_DERIVE
PKEY_EC_CTRL_STR
PKEY_EC_CTRL_STR
PKEY_EC_CTRL
PKEY_EC_CTRL
o2i_ECPublicKey
o2i_ECPublicKey
i2o_ECPublicKey
i2o_ECPublicKey
i2d_ECPrivateKey
i2d_ECPrivateKey
EC_KEY_set_public_key_affine_coordinates
EC_KEY_set_public_key_affine_coordinates
EC_KEY_print_fp
EC_KEY_print_fp
EC_KEY_print
EC_KEY_print
EC_KEY_new
EC_KEY_new
EC_KEY_generate_key
EC_KEY_generate_key
EC_KEY_copy
EC_KEY_copy
EC_KEY_check_key
EC_KEY_check_key
ECKEY_TYPE2PARAM
ECKEY_TYPE2PARAM
ECKEY_PUB_ENCODE
ECKEY_PUB_ENCODE
ECKEY_PUB_DECODE
ECKEY_PUB_DECODE
ECKEY_PRIV_ENCODE
ECKEY_PRIV_ENCODE
ECKEY_PRIV_DECODE
ECKEY_PRIV_DECODE
ECKEY_PARAM_DECODE
ECKEY_PARAM_DECODE
ECKEY_PARAM2TYPE
ECKEY_PARAM2TYPE
DO_EC_KEY_PRINT
DO_EC_KEY_PRINT
d2i_ECPrivateKey
d2i_ECPrivateKey
zlib not supported
zlib not supported
fips mode not supported
fips mode not supported
wrong public key type
wrong public key type
unsupported public key type
unsupported public key type
unsupported encryption algorithm
unsupported encryption algorithm
unsupported any defined by type
unsupported any defined by type
unknown public key type
unknown public key type
unable to decode rsa private key
unable to decode rsa private key
unable to decode rsa key
unable to decode rsa key
streaming not supported
streaming not supported
private key header missing
private key header missing
digest and key type not supported
digest and key type not supported
bad password read
bad password read
X509_PKEY_new
X509_PKEY_new
i2d_RSA_PUBKEY
i2d_RSA_PUBKEY
i2d_PublicKey
i2d_PublicKey
i2d_PrivateKey
i2d_PrivateKey
i2d_EC_PUBKEY
i2d_EC_PUBKEY
i2d_DSA_PUBKEY
i2d_DSA_PUBKEY
d2i_X509_PKEY
d2i_X509_PKEY
d2i_PublicKey
d2i_PublicKey
d2i_PrivateKey
d2i_PrivateKey
d2i_AutoPrivateKey
d2i_AutoPrivateKey
unsupported algorithm
unsupported algorithm
unknown key type
unknown key type
unable to get certs public key
unable to get certs public key
public key encode error
public key encode error
public key decode error
public key decode error
no cert set for us to verify
no cert set for us to verify
method not supported
method not supported
loading cert dir
loading cert dir
key values mismatch
key values mismatch
key type mismatch
key type mismatch
cert already in hash table
cert already in hash table
cant check dh key
cant check dh key
X509_verify_cert
X509_verify_cert
X509_STORE_add_cert
X509_STORE_add_cert
X509_REQ_check_private_key
X509_REQ_check_private_key
X509_PUBKEY_set
X509_PUBKEY_set
X509_PUBKEY_get
X509_PUBKEY_get
X509_load_cert_file
X509_load_cert_file
X509_load_cert_crl_file
X509_load_cert_crl_file
X509_get_pubkey_parameters
X509_get_pubkey_parameters
X509_check_private_key
X509_check_private_key
GET_CERT_BY_SUBJECT
GET_CERT_BY_SUBJECT
ADD_CERT_DIR
ADD_CERT_DIR
PKEY_DSA_KEYGEN
PKEY_DSA_KEYGEN
PKEY_DSA_CTRL
PKEY_DSA_CTRL
DSA_generate_key
DSA_generate_key
unsupported key components
unsupported key components
unsupported encryption
unsupported encryption
read key
read key
public key no rsa
public key no rsa
problems getting password
problems getting password
keyblob too short
keyblob too short
keyblob header parse error
keyblob header parse error
expecting public key blob
expecting public key blob
expecting private key blob
expecting private key blob
error converting private key
error converting private key
PEM_WRITE_PRIVATEKEY
PEM_WRITE_PRIVATEKEY
PEM_READ_PRIVATEKEY
PEM_READ_PRIVATEKEY
PEM_READ_BIO_PRIVATEKEY
PEM_READ_BIO_PRIVATEKEY
PEM_PK8PKEY
PEM_PK8PKEY
PEM_F_PEM_WRITE_PKCS8PRIVATEKEY
PEM_F_PEM_WRITE_PKCS8PRIVATEKEY
DO_PK8PKEY_FP
DO_PK8PKEY_FP
DO_PK8PKEY
DO_PK8PKEY
d2i_PKCS8PrivateKey_fp
d2i_PKCS8PrivateKey_fp
d2i_PKCS8PrivateKey_bio
d2i_PKCS8PrivateKey_bio
unsupported salt type
unsupported salt type
unsupported private key algorithm
unsupported private key algorithm
unsupported prf
unsupported prf
unsupported key size
unsupported key size
unsupported key derivation function
unsupported key derivation function
unsupported keylength
unsupported keylength
unsuported number of rounds
unsuported number of rounds
private key encode error
private key encode error
private key decode error
private key decode error
operaton not initialized
operaton not initialized
operation not supported for this keytype
operation not supported for this keytype
no operation set
no operation set
no key set
no key set
keygen failure
keygen failure
invalid operation
invalid operation
expecting a ec key
expecting a ec key
expecting a ecdsa key
expecting a ecdsa key
expecting a dsa key
expecting a dsa key
expecting a dh key
expecting a dh key
expecting an rsa key
expecting an rsa key
different key types
different key types
ctrl operation not implemented
ctrl operation not implemented
command not supported
command not supported
camellia key setup failed
camellia key setup failed
bn pubkey error
bn pubkey error
bad key length
bad key length
aes key setup failed
aes key setup failed
PKEY_SET_TYPE
PKEY_SET_TYPE
PKCS5_V2_PBKDF2_KEYIVGEN
PKCS5_V2_PBKDF2_KEYIVGEN
PKCS5_v2_PBE_keyivgen
PKCS5_v2_PBE_keyivgen
PKCS5_PBE_keyivgen
PKCS5_PBE_keyivgen
FIPS_CIPHER_CTX_SET_KEY_LENGTH
FIPS_CIPHER_CTX_SET_KEY_LENGTH
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover_init
EVP_PKEY_verify_recover
EVP_PKEY_verify_recover
EVP_PKEY_verify_init
EVP_PKEY_verify_init
EVP_PKEY_verify
EVP_PKEY_verify
EVP_PKEY_sign_init
EVP_PKEY_sign_init
EVP_PKEY_sign
EVP_PKEY_sign
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen_init
EVP_PKEY_paramgen
EVP_PKEY_paramgen
EVP_PKEY_new
EVP_PKEY_new
EVP_PKEY_keygen_init
EVP_PKEY_keygen_init
EVP_PKEY_keygen
EVP_PKEY_keygen
EVP_PKEY_get1_RSA
EVP_PKEY_get1_RSA
EVP_PKEY_get1_EC_KEY
EVP_PKEY_get1_EC_KEY
EVP_PKEY_GET1_ECDSA
EVP_PKEY_GET1_ECDSA
EVP_PKEY_get1_DSA
EVP_PKEY_get1_DSA
EVP_PKEY_get1_DH
EVP_PKEY_get1_DH
EVP_PKEY_encrypt_old
EVP_PKEY_encrypt_old
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt_init
EVP_PKEY_encrypt
EVP_PKEY_encrypt
EVP_PKEY_derive_set_peer
EVP_PKEY_derive_set_peer
EVP_PKEY_derive_init
EVP_PKEY_derive_init
EVP_PKEY_derive
EVP_PKEY_derive
EVP_PKEY_decrypt_old
EVP_PKEY_decrypt_old
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt_init
EVP_PKEY_decrypt
EVP_PKEY_decrypt
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_dup
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_ctrl_str
EVP_PKEY_CTX_ctrl
EVP_PKEY_CTX_ctrl
EVP_PKEY_copy_parameters
EVP_PKEY_copy_parameters
EVP_PKEY2PKCS8_broken
EVP_PKEY2PKCS8_broken
EVP_PKCS82PKEY_BROKEN
EVP_PKCS82PKEY_BROKEN
EVP_PKCS82PKEY
EVP_PKCS82PKEY
EVP_CIPHER_CTX_set_key_length
EVP_CIPHER_CTX_set_key_length
ECKEY_PKEY2PKCS8
ECKEY_PKEY2PKCS8
ECDSA_PKEY2PKCS8
ECDSA_PKEY2PKCS8
DSA_PKEY2PKCS8
DSA_PKEY2PKCS8
DSAPKEY2PKCS8
DSAPKEY2PKCS8
D2I_PKEY
D2I_PKEY
CAMELLIA_INIT_KEY
CAMELLIA_INIT_KEY
AES_INIT_KEY
AES_INIT_KEY
AESNI_INIT_KEY
AESNI_INIT_KEY
key size too small
key size too small
invalid public key
invalid public key
PKEY_DH_KEYGEN
PKEY_DH_KEYGEN
PKEY_DH_DERIVE
PKEY_DH_DERIVE
GENERATE_KEY
GENERATE_KEY
DH_generate_key
DH_generate_key
DH_compute_key
DH_compute_key
COMPUTE_KEY
COMPUTE_KEY
unsupported signature type
unsupported signature type
unsupported mask parameter
unsupported mask parameter
unsupported mask algorithm
unsupported mask algorithm
rsa operations not supported
rsa operations not supported
operation not allowed in fips mode
operation not allowed in fips mode
invalid keybits
invalid keybits
illegal or unsupported padding mode
illegal or unsupported padding mode
digest too big for rsa key
digest too big for rsa key
data too small for key size
data too small for key size
RSA_generate_key_ex
RSA_generate_key_ex
RSA_generate_key
RSA_generate_key
RSA_check_key
RSA_check_key
RSA_BUILTIN_KEYGEN
RSA_BUILTIN_KEYGEN
PKEY_RSA_VERIFYRECOVER
PKEY_RSA_VERIFYRECOVER
PKEY_RSA_VERIFY
PKEY_RSA_VERIFY
PKEY_RSA_SIGN
PKEY_RSA_SIGN
PKEY_RSA_CTRL_STR
PKEY_RSA_CTRL_STR
PKEY_RSA_CTRL
PKEY_RSA_CTRL
.\crypto\evp\evp_key.c
.\crypto\evp\evp_key.c
nkey
nkey
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
hexkey
hexkey
rsa_keygen_pubexp
rsa_keygen_pubexp
rsa_keygen_bits
rsa_keygen_bits
ECDH part of OpenSSL 1.0.1j 15 Oct 2014
ECDH part of OpenSSL 1.0.1j 15 Oct 2014
ECDSA part of OpenSSL 1.0.1j 15 Oct 2014
ECDSA part of OpenSSL 1.0.1j 15 Oct 2014
%s: (%d bit)
%s: (%d bit)
Public-Key
Public-Key
Private-Key
Private-Key
recommended-private-length: %d bits
recommended-private-length: %d bits
public-key:
public-key:
private-key:
private-key:
PKCS#3 DH Public-Key
PKCS#3 DH Public-Key
PKCS#3 DH Private-Key
PKCS#3 DH Private-Key
Public-Key: (%d bit)
Public-Key: (%d bit)
Private-Key: (%d bit)
Private-Key: (%d bit)
TXT_DB part of OpenSSL 1.0.1j 15 Oct 2014
TXT_DB part of OpenSSL 1.0.1j 15 Oct 2014
USER32.DLL
USER32.DLL
NETAPI32.DLL
NETAPI32.DLL
KERNEL32.DLL
KERNEL32.DLL
ADVAPI32.DLL
ADVAPI32.DLL
IP Address:%d.%d.%d.%d
IP Address:%d.%d.%d.%d
URI:%s
URI:%s
DNS:%s
DNS:%s
email:%s
email:%s
EdiPartyName:
EdiPartyName:
X400Name:
X400Name:
othername:
othername:
CONF_def part of OpenSSL 1.0.1j 15 Oct 2014
CONF_def part of OpenSSL 1.0.1j 15 Oct 2014
[[%s]]
[[%s]]
[%s] %s=%s
[%s] %s=%s
keylen
keylen
EVP_CIPHER_key_length(cipher)
EVP_CIPHER_key_length(cipher)
%*sPolicy Text: %s
%*sPolicy Text: %s
%*scrlUrl:
%*scrlUrl:
EXTENDED_KEY_USAGE
EXTENDED_KEY_USAGE
%*sZone: %s, User:
%*sZone: %s, User:
.\crypto\x509v3\v3_akey.c
.\crypto\x509v3\v3_akey.c
d.usernotice
d.usernotice
d.cpsuri
d.cpsuri
CERTIFICATEPOLICIES
CERTIFICATEPOLICIES
%*sExplicit Text: %s
%*sExplicit Text: %s
%*sNumber%s:
%*sNumber%s:
%*sOrganization: %s
%*sOrganization: %s
%*sCPS: %s
%*sCPS: %s
PKEY_USAGE_PERIOD
PKEY_USAGE_PERIOD
keyCertSign
keyCertSign
Certificate Sign
Certificate Sign
keyAgreement
keyAgreement
Key Agreement
Key Agreement
keyEncipherment
keyEncipherment
Key Encipherment
Key Encipherment
.\crypto\x509v3\v3_skey.c
.\crypto\x509v3\v3_skey.c
.\crypto\asn1\x_pkey.c
.\crypto\asn1\x_pkey.c
%'%1$=%C%K%O%s%
%'%1$=%C%K%O%s%
.%.-.3.7.9.?.W.[.o.y.
.%.-.3.7.9.?.W.[.o.y.
C%C'C3C7C9COCWCiC
C%C'C3C7C9COCWCiC
Basis Type: %s
Basis Type: %s
Field Type: %s
Field Type: %s
ASN1 OID: %s
ASN1 OID: %s
%s %s%lu (%s0x%lx)
%s %s%lu (%s0x%lx)
%s.dll
%s.dll
RIPE-MD160 part of OpenSSL 1.0.1j 15 Oct 2014
RIPE-MD160 part of OpenSSL 1.0.1j 15 Oct 2014
SHA part of OpenSSL 1.0.1j 15 Oct 2014
SHA part of OpenSSL 1.0.1j 15 Oct 2014
CAST part of OpenSSL 1.0.1j 15 Oct 2014
CAST part of OpenSSL 1.0.1j 15 Oct 2014
Blowfish part of OpenSSL 1.0.1j 15 Oct 2014
Blowfish part of OpenSSL 1.0.1j 15 Oct 2014
keylength
keylength
keyfunc
keyfunc
.\crypto\pkcs12\p12_key.c
.\crypto\pkcs12\p12_key.c
Verifying - %s
Verifying - %s
d.receiptList
d.receiptList
d.allOrFirstTier
d.allOrFirstTier
d.compressedData
d.compressedData
d.authenticatedData
d.authenticatedData
d.encryptedData
d.encryptedData
d.digestedData
d.digestedData
d.envelopedData
d.envelopedData
d.signedData
d.signedData
d.ori
d.ori
d.pwri
d.pwri
d.kekri
d.kekri
d.kari
d.kari
d.ktri
d.ktri
CMS_PasswordRecipientInfo
CMS_PasswordRecipientInfo
keyDerivationAlgorithm
keyDerivationAlgorithm
keyIdentifier
keyIdentifier
CMS_KeyAgreeRecipientInfo
CMS_KeyAgreeRecipientInfo
recipientEncryptedKeys
recipientEncryptedKeys
CMS_OriginatorIdentifierOrKey
CMS_OriginatorIdentifierOrKey
d.originatorKey
d.originatorKey
CMS_OriginatorPublicKey
CMS_OriginatorPublicKey
CMS_RecipientEncryptedKey
CMS_RecipientEncryptedKey
CMS_KeyAgreeRecipientIdentifier
CMS_KeyAgreeRecipientIdentifier
d.rKeyId
d.rKeyId
CMS_RecipientKeyIdentifier
CMS_RecipientKeyIdentifier
CMS_OtherKeyAttribute
CMS_OtherKeyAttribute
keyAttr
keyAttr
keyAttrId
keyAttrId
CMS_KeyTransRecipientInfo
CMS_KeyTransRecipientInfo
encryptedKey
encryptedKey
keyEncryptionAlgorithm
keyEncryptionAlgorithm
certificates
certificates
d.crl
d.crl
d.subjectKeyIdentifier
d.subjectKeyIdentifier
d.issuerAndSerialNumber
d.issuerAndSerialNumber
CMS_CertificateChoices
CMS_CertificateChoices
d.v2AttrCert
d.v2AttrCert
d.v1AttrCert
d.v1AttrCert
d.extendedCertificate
d.extendedCertificate
d.certificate
d.certificate
CMS_OtherCertificateFormat
CMS_OtherCertificateFormat
otherCert
otherCert
otherCertFormat
otherCertFormat
value.bag
value.bag
value.safes
value.safes
value.shkeybag
value.shkeybag
value.keybag
value.keybag
value.sdsicert
value.sdsicert
value.x509cert
value.x509cert
value.other
value.other
utf8 to ucs2 conversion failed on cmdline:
utf8 to ucs2 conversion failed on cmdline:
command.com
command.com
Operation not supported on socket
Operation not supported on socket
Socket type not supported
Socket type not supported
Protocol not supported
Protocol not supported
Socket operation on non-socket
Socket operation on non-socket
Operation already in progress
Operation already in progress
Operation now in progress
Operation now in progress
Operation would block
Operation would block
passwords do not match
passwords do not match
Shared memory is implemented using a key system
Shared memory is implemented using a key system
The specified child process is not done executing
The specified child process is not done executing
The specified child process is done executing
The specified child process is done executing
Your code just forked, and you are currently executing in the parent process
Your code just forked, and you are currently executing in the parent process
Your code just forked, and you are currently executing in the child process
Your code just forked, and you are currently executing in the child process
No thread key structure was provided and one was required.
No thread key structure was provided and one was required.
%d.%d%c
%d.%d%c
=%c
=%c
ntdll.dll
ntdll.dll
\\.\pipe\apr-pipe-%u.%lu
\\.\pipe\apr-pipe-%u.%lu
127.0.0.1
127.0.0.1
SHELL32.dll
SHELL32.dll
MPR.dll
MPR.dll
GetProcessWindowStation
GetProcessWindowStation
USER32.dll
USER32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyW
RegCreateKeyW
ReportEventW
ReportEventW
ReportEventA
ReportEventA
ADVAPI32.dll
ADVAPI32.dll
VERSION.dll
VERSION.dll
WS2_32.dll
WS2_32.dll
IPHLPAPI.DLL
IPHLPAPI.DLL
CreateNamedPipeW
CreateNamedPipeW
GetWindowsDirectoryW
GetWindowsDirectoryW
PeekNamedPipe
PeekNamedPipe
CreatePipe
CreatePipe
CreateNamedPipeA
CreateNamedPipeA
KERNEL32.dll
KERNEL32.dll
MSVCR90.dll
MSVCR90.dll
_amsg_exit
_amsg_exit
_crt_debugger_hook
_crt_debugger_hook
l}C.we
l}C.we
Operation not permitted
Operation not permitted
Inappropriate I/O control opera
Inappropriate I/O control opera
Broken pipe
Broken pipe
-Q.mC
-Q.mC
.dp'4
.dp'4
%d/%d %s %d (%d%%)
%d/%d %s %d (%d%%)
avupdate.conf
avupdate.conf
update library version : %s
update library version : %s
M--_---
M--_---
\\.\pipe\avupdate-pipe-%u.%lu
\\.\pipe\avupdate-pipe-%u.%lu
WTSAPI32.dll
WTSAPI32.dll
explorer.exe
explorer.exe
nwinhttp.dll
nwinhttp.dll
NTVDM.EXE
NTVDM.EXE
PSAPI.DLL
PSAPI.DLL
VDMDBG.DLL
VDMDBG.DLL
requested feature requires XML_DTD support in Expat
requested feature requires XML_DTD support in Expat
unexpected parser state - please send a bug report
unexpected parser state - please send a bug report
xml=hXXp://VVV.w3.org/XML/1998/namespace
xml=hXXp://VVV.w3.org/XML/1998/namespace
hXXp://VVV.w3.org/XML/1998/namespace
hXXp://VVV.w3.org/XML/1998/namespace
hXXp://VVV.w3.org/2000/xmlns/
hXXp://VVV.w3.org/2000/xmlns/
TypesSupported
TypesSupported
lX.av$
lX.av$
\\?\UNC\
\\?\UNC\
WINDOWS 95 A
WINDOWS 95 A
WINDOWS 95 B
WINDOWS 95 B
WINDOWS 95 C
WINDOWS 95 C
WINDOWS 98 FE
WINDOWS 98 FE
WINDOWS 98 SE
WINDOWS 98 SE
WINDOWS ME
WINDOWS ME
WINDOWS NT 300 W
WINDOWS NT 300 W
WINDOWS NT 300 S
WINDOWS NT 300 S
WINDOWS NT 350 W
WINDOWS NT 350 W
WINDOWS NT 350 S
WINDOWS NT 350 S
WINDOWS 351 W
WINDOWS 351 W
WINDOWS 351 S
WINDOWS 351 S
WINDOWS NT 4 W
WINDOWS NT 4 W
WINDOWS NT 4 S
WINDOWS NT 4 S
WINDOWS 2000 WORKSTATION
WINDOWS 2000 WORKSTATION
WINDOWS 2000 SERVER
WINDOWS 2000 SERVER
WINDOWS XP
WINDOWS XP
WINDOWS 2003
WINDOWS 2003
WINDOWS VISTA
WINDOWS VISTA
WINDOWS 2008
WINDOWS 2008
WINDOWS 2008 R2
WINDOWS 2008 R2
WINDOWS XP 64 BITS
WINDOWS XP 64 BITS
WINDOWS VISTA 64 BITS
WINDOWS VISTA 64 BITS
WINDOWS 2003 64 BITS
WINDOWS 2003 64 BITS
WINDOWS 2008 64 BITS
WINDOWS 2008 64 BITS
WINDOWS 2008 R2 64 BITS
WINDOWS 2008 R2 64 BITS
WINDOWS 7
WINDOWS 7
WINDOWS 7 64 BITS
WINDOWS 7 64 BITS
WINDOWS 8
WINDOWS 8
WINDOWS 8 64 BITS
WINDOWS 8 64 BITS
@WINDOWS 8.1
@WINDOWS 8.1
WINDOWS 8.1 64 BITS
WINDOWS 8.1 64 BITS
WINDOWS SERVER 2012
WINDOWS SERVER 2012
WINDOWS SERVER 2012 64 BITS
WINDOWS SERVER 2012 64 BITS
WINDOWS SERVER 2012 R2
WINDOWS SERVER 2012 R2
WINDOWS SERVER 2012 R2 64 BITS
WINDOWS SERVER 2012 R2 64 BITS
Avira Operations GmbH & Co. KG
Avira Operations GmbH & Co. KG
updater.exe
updater.exe
2000 - 2014 Avira Operations GmbH & Co. KG and its Licensors
2000 - 2014 Avira Operations GmbH & Co. KG and its Licensors