HEUR:Trojan.Win32.Generic (Kaspersky), BankerGeneric.YR, Bancos.YR, ZeroAccess.YR, TrojanDropperVtimrun.YR (Lavasoft MAS)Behaviour: Trojan-Dropper, Banker, Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: fbefc3451c37847af3efc0e1d7828a54
SHA1: 81ca9ae6af856f10ee76e0fba132f1148a93c1df
SHA256: f8c30a3b4f22926075465bc175627dacd891d2de8692aff347a590e75de640f5
SSDeep: 49152:2ahQOhJ5RO3fFKukkCO6a1EVPvFU0xt3mtS 72cfGumtlZ0pc 2gFie:vxh7wvnCra1EVrDOS 7l8tlZ0 2wh
Size: 3741184 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2015-02-07 11:53:36
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan-Dropper. Trojan program, intended for stealth installation of other malware into user's system.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
vcredist_x86.exe:1332
%original file name%.exe:1260
The Trojan injects its code into the following process(es):
rSwooYMM.exe:1036
jWcYYUcg.exe:580
FeEQMIQs.exe:2016
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process rSwooYMM.exe:1036 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\totalcmd\TOTALCMD.EXE.exe (35505 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe (11518 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe (7385 bytes)
C:\totalcmd\TCMADMIN.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe (7385 bytes)
C:\totalcmd\TCUNINST.EXE.exe (7385 bytes)
C:\totalcmd\TcUsbRun.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\MAAo.txt (55978 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe (7433 bytes)
C:\totalcmd\TCMDX32.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe (7385 bytes)
\\STORAGE2\PIPE\srvsvc (72 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe (7971 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe (10177 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe (7385 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp (0 bytes)
C:\totalcmd\TCUNINST.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp (0 bytes)
C:\totalcmd\TCMADMIN.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg (0 bytes)
C:\totalcmd\TCMDX32.EXE (0 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg (0 bytes)
C:\totalcmd\TOTALCMD.EXE (0 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp (0 bytes)
The process %original file name%.exe:1260 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exe (7881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vcredist_x86.exe (17629 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\eGwUgscE.bat (4 bytes)
%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe (7857 bytes)
%Documents and Settings%\All Users\BOAMIgUE\jWcYYUcg.exe (7857 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\eGwUgscE.bat (0 bytes)
Registry activity
The process rSwooYMM.exe:1036 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "83 D0 4E CE 6C B6 62 02 D5 80 11 2A 69 D9 0D E8"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rSwooYMM.exe" = "%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exe"
The process vcredist_x86.exe:1332 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "27 C1 5E 85 C2 49 23 B1 1C 54 B5 C2 DB D3 5B BB"
The process jWcYYUcg.exe:580 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D3 91 B5 A0 FC 90 80 82 70 01 0B 0F 8C 31 78 17"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FeEQMIQs.exe" = "%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe"
The process %original file name%.exe:1260 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "12 86 E4 25 07 55 C7 D2 C2 16 E7 19 59 FC 50 AD"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FeEQMIQs.exe" = "%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "%System%\userinit.exe,%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe,"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rSwooYMM.exe" = "%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exe"
The process FeEQMIQs.exe:2016 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4C 4B 71 B3 08 C4 74 64 CD E7 DA 7E 52 2E 14 27"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FeEQMIQs.exe" = "%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe"
Dropped PE files
MD5 | File path |
---|---|
adb01e6cb54908ddb4cd964f58f91a70 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe |
a718552c32247a0847156b4cb7cd42cf | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe |
2943318ea3eb331283c6898deebabfea | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe |
866eecd827042fe6d2f8302f5bac9ac1 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe |
a4c5708248171b42703287a798b3a6d2 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe |
6d495d6a67ac0327881b8f290e346fc5 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe |
dcec31285210560bea5498527e722106 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe |
a34796afd84b987f1e8415b79ebde062 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe |
41967989536003c144627d814bc8444f | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe |
a177d7e090e72140d9ed69dbc586c101 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe |
a26fc4d8e8630b250499ed70b8c3df61 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe |
1566cc316921e8f0c278581bdab8273d | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe |
7d5e08695a3c016e135006ed760be343 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe |
19fa3b49137ea3e98ac49e05818779b5 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe |
d12b944e569452439a3d6fbde5c651d1 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe |
b76229b82f08e44aa9085597ab84cb63 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe |
491b3ace6fd09ce0603655c5bc0bf30a | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe |
b8eb0e2509189da9a665a925a96f11b5 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe |
e3de18377f8d1e9003432397eb619860 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe |
8772475f03eda2450e0f9313a073fd6b | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe |
dcdb05b3724c364add67087d49d5ad2a | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe |
60f2786d0b3e2c064f4f517a0eda11f0 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe |
53d4cce065bdc8236ceb7ddb32645926 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe |
9f356cdadf3053667ad3b4bbf3775a51 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe |
a40710e952309a5696350ba096fc6118 | c:\Documents and Settings\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe |
c4745e4fe5cc9a8015197954dd6012cf | c:\Documents and Settings\All Users\BOAMIgUE\jWcYYUcg.exe |
562a7974ee349553d6ec0cf7460a6af5 | c:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe |
b6d694ed810b813ba9782dd61dffaa24 | c:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe |
b47ce90789d3789e5f5e197a74f2a809 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe |
2d964097b353fb01982d0db04a1485a6 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe |
11b77caddff8838b51985589b3411d26 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe |
455eca8381e50ad83f0123e16ba95da3 | c:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe |
9c1cae9b635f72deac90ff64ad1459a6 | c:\Documents and Settings\All Users\hUEQccwo\FeEQMIQs.exe |
6402438591b548121f54b0706a2c6423 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\vcredist_x86.exe |
157a646e16378e82b3209bc256428699 | c:\Documents and Settings\"%CurrentUserName%"\NwIscAww\rSwooYMM.exe |
36ae2cf8e743c65988646f6bdedd2ce4 | c:\Perl\eg\IEExamples\ie_animated.gif.exe |
af27f4d4caa102bd95856f7dca0b5041 | c:\Perl\eg\IEExamples\psbwlogo.gif.exe |
13aba291b9f0efafe53e2b29b1af63db | c:\Perl\eg\aspSamples\ASbanner.gif.exe |
31cc9f2873ef654e6e340b11d2f9958b | c:\Perl\eg\aspSamples\Main_Banner.gif.exe |
c32cb9b2ca69dec02cff5892fd14502b | c:\Perl\eg\aspSamples\psbwlogo.gif.exe |
1d5de47cb3578be846cf55fde23965c7 | c:\Perl\html\images\AS_logo.gif.exe |
436a8e0673960522068227e33ac5786e | c:\Perl\html\images\PerlCritic_run.png.exe |
83fe8a50d77acabcc955c8095faed5cf | c:\Perl\html\images\aslogo.gif.exe |
d1a07052db4240c3e2049a8fceacfba8 | c:\Perl\html\images\ppm_gui.png.exe |
93e0828f9f46b8d0a6c9ba33199d5886 | c:\Perl\lib\ActivePerl\PPM\images\gecko.png.exe |
735d34bc4f824e4e60d4baa2ec0d856a | c:\Perl\lib\ActivePerl\PPM\images\perl_48x48.png.exe |
b19dc65235162149fc6c7b58340f5b3d | c:\Perl\lib\Devel\NYTProf\js\asc.png.exe |
29e30f97cb88ff3f6905d33adbe75e1e | c:\Perl\lib\Devel\NYTProf\js\bg.png.exe |
78b51877035ea45234d90318b62137a4 | c:\Perl\lib\Devel\NYTProf\js\desc.png.exe |
9e585951eebd2a88cea4ca765f94fc26 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient.png.exe |
1c0f6da12993f0f6c021224f7a75ab27 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient20.png.exe |
3166b942f903a4b2b000147341304b49 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient30.png.exe |
c5f3949854fe701b89f259545278736e | c:\Perl\lib\Devel\NYTProf\js\jit\gradient40.png.exe |
291586302b7ce89dc28b93b5b578d0a9 | c:\Perl\lib\Devel\NYTProf\js\jit\gradient50.png.exe |
609850d61804aafd9f2d7249c2b21003 | c:\Perl\lib\Mozilla\CA\cacert.pem.exe |
7c5e9a29a620e68a9d739b20ed224326 | c:\totalcmd\TCMADMIN.EXE.exe |
cbff68cdae95d69e6fe345371bda498f | c:\totalcmd\TCMDX32.EXE.exe |
aa9d199fba87a4fd42c9079eaf190fa7 | c:\totalcmd\TCUNINST.EXE.exe |
7d34f65de84cd7da9c0c1df1b3780d59 | c:\totalcmd\TOTALCMD.EXE.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
vcredist_x86.exe:1332
%original file name%.exe:1260 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\totalcmd\TOTALCMD.EXE.exe (35505 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma.exe (11518 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\adm.bmp.exe (7385 bytes)
C:\totalcmd\TCMADMIN.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\snowflake.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\guitar.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\lift-off.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\kick.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\butterfly.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\palm tree.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\guest.bmp.exe (7385 bytes)
C:\totalcmd\TCUNINST.EXE.exe (7385 bytes)
C:\totalcmd\TcUsbRun.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\duck.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\red flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\dirt bike.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\MAAo.txt (55978 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\horses.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\pink flower.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\astronaut.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\cat.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\chess.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\ball.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\skater.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\beach.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg.exe (7433 bytes)
C:\totalcmd\TCMDX32.EXE.exe (7433 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg.exe (7433 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\frog.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\fish.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\airplane.bmp.exe (7385 bytes)
\\STORAGE2\PIPE\srvsvc (72 bytes)
%Documents and Settings%\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg.exe (7433 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Adobe\Reader 9.3\Setup Files\Setup.exe (7971 bytes)
%Documents and Settings%\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma.exe (10177 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\drip.bmp.exe (7385 bytes)
%Documents and Settings%\All Users\Application Data\Microsoft\User Account Pictures\Default Pictures\car.bmp.exe (7385 bytes)
%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exe (7881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vcredist_x86.exe (17629 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\eGwUgscE.bat (4 bytes)
%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe (7857 bytes)
%Documents and Settings%\All Users\BOAMIgUE\jWcYYUcg.exe (7857 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"rSwooYMM.exe" = "%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FeEQMIQs.exe" = "%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "%System%\userinit.exe,%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exe," - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 3739648 | 3737088 | 5.53548 | c933938c97759abdf276472b9fb7ed35 |
.rdata | 3743744 | 4096 | 512 | 1.69938 | b98b6e69be186bae66452caedfd4ec30 |
.data | 3747840 | 5 | 512 | 0.070639 | 86be069652e225becfca32bd5c9d4197 |
.rsrc | 3751936 | 1372 | 1536 | 2.37023 | 829f2bf92f204e09ba987b48414d8352 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://google.com/ | 173.194.112.73 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET / HTTP/1.1
Host: google.com
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=B3AYVdq2LeaG8Qe0woGwAw
Content-Length: 262
Date: Sun, 29 Mar 2015 21:35:03 GMT
Server: GFE/2.0
Alternate-Protocol: 80:quic,p=0.5
<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=B3AYVdq2LeaG8Qe0woGwAw">here</A>...</BODY></HTML>....
GET / HTTP/1.1
Host: google.com
HTTP/1.1 302 Found
Cache-Control: private
Content-Type: text/html; charset=UTF-8
Location: hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=B3AYVe3sLeaG8Qe0woGwAw
Content-Length: 262
Date: Sun, 29 Mar 2015 21:35:03 GMT
Server: GFE/2.0
Alternate-Protocol: 80:quic,p=0.5
<HTML><HEAD><meta http-equiv="content-type" content="text/html;charset=utf-8">.<TITLE>302 Moved</TITLE></HEAD><BODY>.<H1>302 Moved</H1>.The document has moved.<A HREF="hXXp://VVV.google.com.ua/?gfe_rd=cr&ei=B3AYVe3sLeaG8Qe0woGwAw">here</A>...</BODY></HTML>....
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
rSwooYMM.exe_1036:
.text
.text
.rdata
.rdata
@.data
@.data
b5.ug
b5.ug
%X5D1
%X5D1
%u>CM
%u>CM
25.Yo
25.Yo
%S2
%S2
h1.Vb})_>
h1.Vb})_>
'.dT4h
'.dT4h
aq;R%u)_4'k~
aq;R%u)_4'k~
Z.WhOR
Z.WhOR
.Kc.b&
.Kc.b&
; .cb
; .cb
z.QWG
z.QWG
z.Aq>?IX
z.Aq>?IX
.Rm-?G
.Rm-?G
%fm[
%fm[
.Zq[cA
.Zq[cA
s$K.lB
s$K.lB
.YO=Z
.YO=Z
J%F,p#t
J%F,p#t
dkLwl.pmk
dkLwl.pmk
.kbd/
.kbd/
R.egn`I
R.egn`I
mwEB
mwEB
'4U%X
'4U%X
%skpH
%skpH
.Jgt>
.Jgt>
V.pn3
V.pn3
$g,.qP
$g,.qP
XP.BF
XP.BF
Fk7
L"8*.tDsD5
c.nIk
GXD%f
q%DLMrlR
x.TI4
S@.aYU
%s]|q
jX-%D
].tq5
y`z5.Oe!4
DG%drs
.SLIM}R1
CB.kE
.DD~.
%<.dj>)"G.pdl$.ty}$.xp>9.5:5_tR.%c-r}!L}ox.Yw;|Zw$.LN:q%F|%U=un]Xm%s9q%S6dTWindows Internet ExplorerWindows Task Managertaskmgr.execmd.exetaskkill /F /IM taskmgr.exe /Tvcredist_x86.exec.exe•S^.kYd!Microsoft Windows%6s6j 6_-%u.qt90.IrF3'K%s)cntdll.dlluser32.dllkernel32.dllMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mrSwooYMM.exe_1036_rwx_009A0000_00001000:C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\TempFeEQMIQs.exe_2016:.text.rdata@.datab5.ug.hFgU.oe`"t!.lN-=t&t%xGTcPoopUk') 2ß.xXlT 'A%fSx01/-.xOf(.Gr6nGTny/T%x8f3x\-ÕO3C]i5.lUnldxGjY4%x(mNUk.xG.Gm@ttdFX.xGC%uYlI&%6XG.Vk\.k.qNk%XmTgX> %XUPC,i'.Tf-%X]Q|.TV]SrP[.wOh`2%f%fR[.wO.FtjhYS[.wg.am$%fR[.wNv[[.wI,[.wGUk!F%SEQF4[.ww.Al|3x.pzNbRfR[.wIu[[.wIE8[.wc]%Cs,fR[.wHS[.wlS[.wuS[.wxr/%u.vQ[.wOL.WZyuL[.wlp[.wub.Gr,.L[.wzS[.wzf.KpVD[.wuw\[.wL,[.wsg%fxM1,[.wtfR[.wDwS[.wJZbXBSsh|[.wvP[.wHU[.wIwR[.wqvQ[.wJfR[.wLvV[.wI-3%x(l[.wc|[.wqcX.SA*`.VRS[.wv,[.wvR[.wOL[.wNe#.TP,[.wzAf%dQ[.wHwP[.wwZ[.wyL[.wvS[.wpuY[.wO5"%xdFw\[.wynP.BE%co ,2#CiTCpbl[.wv.cqdT4[.wcH'%Uzo}m&T.cpb{y.xGyv[[.wH.Nfe`wP[.wzht%F:jTn\[.wytQ[.wH,[.wb{.lngw\[.ww6[.wt,[.wl3]9%UA{,[.wup[[.wFv4[.wGpKt[.wKp[.wp5.fz%V[.wHl[.wqsQ[.wHw\[.wzP[.wv~j-2}|T=.je2;bG.YY|fR[.wErU[.wG/O[.wKvL[.wGe\[.wG\[.wGWwP[.wpv".bBalMicrosoft Windows1t%UFoleaut32.dllkernel32.dllntdll.dlluser32.dllMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mrSwooYMM.exe_1036_rwx_00A00000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMMrSwooYMM.exe_1036_rwx_00A10000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQsrSwooYMM.exe_1036_rwx_00A30000_000EA000:b5.ug.hFgU.oe`"t!.lN-=t&t%xGTcPoopUk') 2ß.xXlT 'A%fSx01/-.xOf(.Gr6nGTny/T%x8f3x\-ÕO3C]i5.lUnldxGjY4%x(mNUk.xG.Gm@ttdFX.xGC%uYlI&%6XG.Vk\.k.qNk%XmTgX> %XUPC,i'.Tf-%X]Q|.TV]SrP[.wOh`2%f%fR[.wO.FtjhYS[.wg.am$%fR[.wNv[[.wI,[.wGUk!F%SEQF4[.ww.Al|3x.pzNbRfR[.wIu[[.wIE8[.wc]%Cs,fR[.wHS[.wlS[.wuS[.wxr/%u.vQ[.wOL.WZyuL[.wlp[.wub.Gr,.L[.wzS[.wzf.KpVD[.wuw\[.wL,[.wsg%fxM1,[.wtfR[.wDwS[.wJZbXBSsh|[.wvP[.wHU[.wIwR[.wqvQ[.wJfR[.wLvV[.wI-3%x(l[.wc|[.wqcX.SA*`.VRS[.wv,[.wvR[.wOL[.wNe#.TP,[.wzAf%dQ[.wHwP[.wwZ[.wyL[.wvS[.wpuY[.wO5"%xdFw\[.wynP.BE%co ,2#CiTCpbl[.wv.cqdT4[.wcH'%Uzo}m&T.cpb{y.xGyv[[.wH.Nfe`wP[.wzht%F:jTn\[.wytQ[.wH,[.wb{.lngw\[.ww6[.wt,[.wl3]9%UA{,[.wup[[.wFv4[.wGpKt[.wKp[.wp5.fz%V[.wHl[.wqsQ[.wHw\[.wzP[.wv~j-2}|T=.je2;bG.YY|fR[.wErU[.wG/O[.wKvL[.wGe\[.wG\[.wGWwP[.wpv".bBal6j 6_-%u1t%UFMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mrSwooYMM.exe_1036_rwx_00E20000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.infrSwooYMM.exe_1036_rwx_00E30000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.infrSwooYMM.exe_1036_rwx_00E40000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exejWcYYUcg.exe_580:.text.rdata@.datab5.ug.hFgU.oe`"t!.lN-=t&t%xGTcPoopUk') 2ß.xXlT 'A%fSx01/-.xOf(.Gr6nGTny/T%x8f3x\-ÕO3C]i5.lUnldxGjY4%x(mNUk.xG.Gm@ttdFX.xGC%uYlI&%6XG.Vk\.k.qNk%XmTgX> %XUPC,i'.Tf-%X]Q|.TV]SrP[.wOh`2%f%fR[.wO.FtjhYS[.wg.am$%fR[.wNv[[.wI,[.wGUk!F%SEQF4[.ww.Al|3x.pzNbRfR[.wIu[[.wIE8[.wc]%Cs,fR[.wHS[.wlS[.wuS[.wxr/%u.vQ[.wOL.WZyuL[.wlp[.wub.Gr,.L[.wzS[.wzf.KpVD[.wuw\[.wL,[.wsg%fxM1,[.wtfR[.wDwS[.wJZbXBSsh|[.wvP[.wHU[.wIwR[.wqvQ[.wJfR[.wLvV[.wI-3%x(l[.wc|[.wqcX.SA*`.VRS[.wv,[.wvR[.wOL[.wNe#.TP,[.wzAf%dQ[.wHwP[.wwZ[.wyL[.wvS[.wpuY[.wO5"%xdFw\[.wynP.BE%co ,2#CiTCpbl[.wv.cqdT4[.wcH'%Uzo}m&T.cpb{y.xGyv[[.wH.Nfe`wP[.wzht%F:jTn\[.wytQ[.wH,[.wb{.lngw\[.ww6[.wt,[.wl3]9%UA{,[.wup[[.wFv4[.wGpKt[.wKp[.wp5.fz%V[.wHl[.wqsQ[.wHw\[.wzP[.wv~j-2}|T=.je2;bG.YY|fR[.wErU[.wG/O[.wKvL[.wGe\[.wG\[.wGWwP[.wpv".bBal2software\microsoft\windows\currentversion\run1t%UFntdll.dlluser32.dllFreeEncryptedFileKeyInfoadvapi32.dllGetProcessHeapkernel32.dllMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mrSwooYMM.exe_1036_rwx_00E50000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exerSwooYMM.exe_1036_rwx_00E80000_00001000:rSwooYMM.exerSwooYMM.exe_1036_rwx_00E90000_00001000:FeEQMIQs.exerSwooYMM.exe_1036_rwx_00EA0000_00001000:taskkill /FI "USERNAME eq adm" /F /IM rSwooYMM.exerSwooYMM.exe_1036_rwx_00EB0000_00001000:taskkill /FI "USERNAME eq adm" /F /IM FeEQMIQs.exerSwooYMM.exe_1036_rwx_00EC0000_00001000:%Documents and Settings%\All Users\BOAMIgUE\jWcYYUcg.exerSwooYMM.exe_1036_rwx_00ED0000_00001000:%Documents and Settings%\All Users\MAAo.txtrSwooYMM.exe_1036_rwx_00EE0000_00001000:notepad.exe "%Documents and Settings%\All Users\MAAo.txt"rSwooYMM.exe_1036_rwx_00EF0000_00001000:%Documents and Settings%\All Users\BOAMIgUEvcredist_x86.exe_1332:.text`.data.rsrcADVAPI32.dllKERNEL32.dllNTDLL.DLLGDI32.dllUSER32.dllCOMCTL32.dllVERSION.dlladvapi32.dlladvpack.dllwininit.iniSoftware\Microsoft\Windows\CurrentVersion\App Pathssetupapi.dllsetupx.dllIXPd.TMPTMP4351$.TMPFINISHMSGUSRQCMDADMQCMDmsdownld.tmpwextract.pdbPSSSSSShRegCloseKeyRegOpenKeyExARegCreateKeyExARegQueryInfoKeyAGetWindowsDirectoryAExitWindowsExMsgWaitForMultipleObjectsrundll32.exe %s,InstallHinfSection %s 128 %sSHELL32.DLLSoftware\Microsoft\Windows\CurrentVersion\RunOncePendingFileRenameOperationsSystem\CurrentControlSet\Control\Session Manager\FileRenameOperationswextract_cleanup%d%s /D:%srundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"Command.com /c %s33333330333333333333333VCREDI~3.EXEvcredist.msivcredis1.cabV-[C.Yx%u/8f63738393:3/Vx.bVYudP "#v~O.WG#(I?%uIH(>.oK.TZ]V/tfL2|).bp%s@0z.UPjk^".Gef.Oek$,*%D^-Y}\T.QM%#*.Ffs.dI>!O~|%uTo.Ja#Lkx].nip,}_EF%fq1kq.LhH@.rN_6]Q.xO.vE"G..Ts2b.XQ>Pv}%dIr.Jq2y?.Uz2IC~H%d2X.zSJtCP!oPS.MVBp%dM.JB:Y.ZdTnoGJ%d.Qzg_un[.AGm9M.Pl_F,rF.ljxF.oG~VQEI%x**k%sS%uziu//.Byv.nd1O4%x6FF[.lv ?%SNmLG%s?*x4N.bxdxV%UM.xjtK1%C0F%c;vd.Chj.SA.Q&s1v%D.drO.NYQo3-.uP8.ct%mØ!*]$5N.Mki%fh)'%d^ ,w%s\$kxZ.BIkm.bzgF/F%Xd;.Iq7Phh.gv7l.nRa.qaPl3.wBGij.WF.kQ6rm.Ew\[.EanqR[.yv8.pbg'#m.Buiw.on}.jDgSUp=.dw#Q^.sEwR %x_YjGYQ.cg.BIB}#]%7st]%uEA%.tlre8;.jzkX.drc#z%U{x-o!.lq{=lQQ%F5}{.LB.lCA!.xS)@.WmSO.IJ:1NuZvfAPT%Fb%Xt[is9%dEBl%CjExExP.JR>^\R'ÌX-.zHY|h.lt@%s3ius-.Lcm#.Nn.Iinxz*h%fgE.jE?cMDV%$.MZEF.kJhk¬mD.SohRPH%XJxB&%U:cXP%d.eQyGi..Di/N#z.Mi5W -H}.La(KZ66n%X%D=>pI.ByeK&x.yQ,7.wCN,.gla'.AjXHmsgN"[i%clu9.rj*DH3.ma3.Dbwe/p2%c-py7C}4b\j.Amjz.wiu6.TIQ%Ef%Csn.Bf092.US\.taT*mt%xs*r.mKx:.oWF=@(.OpF.gdJdB%cIO^.FGZ/5.HD%x sO.jZwnXM%sN,c3.eP.kC=5D.AT_@5.tz5>.vE]JeQssh|.%s].FlI(S~[%u/W.gb.MB,:H.mx^$o,.iI1.cA^?52a%XuAx%fZf!Oc.va=(=.=7f:$h}%Cj*Ub.aFeTCP65%UZx.EDi.LD []%a%e%i%m%q%u%*#.!.%.).-.1/5sEn%D.hL*ds{%UW.IpztlUd%uPz.AeO8WB%uKgF.lC(BH|%F>/.UI1M.MOtz.DP:=1V_ÿ&x.fJ&&.rr#].tpev.my~V:.ZTvm.vpR,H.XBR~C~{Ih#.zK_eXÎ7?\S%CkG` %C.bTu5{=.VI6m.PwV.RmENg:b%Cl.MDQ%.nt822a%cPAs7\4j%sr:
U3
* support services
2. SCOPE OF LICENSE. The software is licensed, not sold. This agreement only gives you some rights to use the software. Microsoft reserves all other rights. Unless applicable law gives you more rights despite this limitation, you may use the software only as expressly permitted in this agreement. In doing so, you must comply with any technical limitations in the software that only allow you to use it in certain ways. You may not
5. EXPORT RESTRICTIONS. The software is subject to United States export laws and regulations. You must comply with all domestic and international export laws and regulations that apply to the software. These laws include restrictions on destinations, end users and end use. For additional information, see VVV.microsoft.com/exporting.
6. SUPPORT SERVICES. Because this software is
we may not provide support services for it.
7. ENTIRE AGREEMENT. This agreement, and the terms for supplements, updates, Internet-based services and support services that you use, are the entire agreement for the software and support services.
9. LEGAL EFFECT. This agreement describes certain legal rights. You may have other rights under the laws of your country. You may also have rights with respect to the party from whom you acquired the software. This agreement does not change your rights under the laws of your country if the laws of your country do not permit it to do so.
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
/C: -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
WEXTRACT.EXE
Windows
Operating System
6.00.2900.2180rSwooYMM.exe_1036_rwx_01170000_00001000:
.text
`.rdata
@.datarSwooYMM.exe_1036_rwx_01190000_02300000:
:za.Sj
ntdll.dll
kernel32.dll
user32.dll
:]).ZR
8MsGt
6L
.ZotA
#I.%x
V.sAbb
zXz%F
.Mt>\
ReE.Kcm
gB!.NG
>%0U`u?T
ch4l
%st&0
=HW\%u
~n.jM
3Dl6%X,
#T#[.vca.d#q
#E.Yc
W.AcPnNcZ
nG.jcx.
&Tcf.vcd.pcb.
|.By1
}i|%d
.fEg(
S.gw )
k@.ejB
.sd'?
bDxU%F
Z"%Dx
1cEyq%Si
}.vU.h
4|.ia]
T.enk|&
m.SPmh
%fYn!
7|%5'- 4
C.Ttk:
.PSWz
V=C%U
:0.qS1
]%dYg|
".nW9w
|@.jYa
j5_%s
.XW}>S
u.mwY
S%Xo7
.yY?.
7A4c7H-x.Mt
)>.Mt
Ftp7A
1S.ij
sT%fk
.JBwu.$9l
hC;q%sw@>
e/>%D
=.YI-
PaU%C
ay.In
~o8.wj
.AbZhC
|%x&
A'%sF9MC
T.nZ7|
@.FMR
%d/R.KeB .YO.BI_2]>x(..MC%F}{-y.VH%^]lM.tRP.hg}vtBx%c#ys?xm].vmp{.OU){.sw%FO);F_@g(.PS%uN=U$ym^R^.TC^%Fs^Rw.JEz.nC7Bz1.hRt1.hVfsqlhuK.xsqlrJ"sqlx6Jh~sqltl\^.ppp\^.ppqv.ERsqlt6Cvsqlt6Cxi.llo.vmJ`~sqlv6Jh{.Pb~5.hztN\^.tvK.sqhb|sqld6Cb|~sql36Jq.mJ`W~sql-6JL(M%X(ML.M%X.ML,M%X,Mr%X"ML M%X ML&M%X&ML$M%X$MKeyQ*cwQ*huQ*bsQM.WbN()^.MiJ.Wf0.GgU>sqlosql~6hoDv^.dpw^.BwDp^.DwJ%U>Mw^.AvXDv^.Evw^.DvXDP^.GvJDh^.FvJDv^.FvJDv^.IvJDv^.HvJDv^.KvJDv^.JvXDv^.Mvw^.Lvw^.Ovw^.NvJDv^.QvJDv^.Pvw^.cvJDv^.cvw^.bvJDv^.bvDw^.fvXDy^.hvXDv^.rvDw^.rvDv^.tvw^.tvXDv^.wvw^.wvLDv^.vv/5%U:MU.TD.mDv^.ovhoDv^.nvUK%U./5%U>MJDv^.MuJDv^.UuJDv^.auXDv^.auq^.xuX1I.YthoDv^.CuhmDv^.Fun~N%fy{XDv^.AtXDv^.Btw^.HtJDv^.Htw^.LtJDv^.LtJDv^.OtXDv^.btXDr^.ftJDv^.wt/5%U6MDv^%xtXX2h.Ztw.HmTN~.NM~*lpM~.pN~b.sO.bi6RfQ2l.Wzn=UrSwooYMM.exe_1036_rwx_03B90000_01E00000:.text`.rdata@.data.rsrc@.relocu%Uh`QSSShQVSSht.PShT$lRSSh| "UDPQRhL$ QSShL$,QSShQSSShlVURVSShlVUt.Ph\tGHt.Ht&operand of unlimited repeat could match the empty stringPOSIX named classes are supported only within a classerroffset passed as NULLPOSIX collating elements are not supportedthis version of PCRE is not compiled with PCRE_UTF8 supportPCRE does not support \L, \l, \N{name}, \U, or \usupport for \P, \p, and \X has not been compiledthis version of PCRE is not compiled with PCRE_UCP support\N is not supported in a classinflate 1.2.5 Copyright 1995-2010 Mark AdlerPlease contact the application's support team for more information.- Attempt to initialize the CRT more than once.- CRT not initialized- floating point support not loadedoperatorGetProcessWindowStationUSER32.DLLRtlRunOnceExecuteOnceadvapi32_hack::try_hack: bad PE passedadvapi32_hack::try_hack: cannot read import tableadvapi32_hack::try_hack: cannot find section .text.dataadvapi32_hack::try_hack: cannot find section .dataadvapi32_hack::try_hack: cannot read section .textCannot read module %s, error %dCannot read exports of %s, error %dadvapi32_hack::try_hack: cannot read exports, error %d.apisetBad .apiset catalog - don`t fit in sectionString in cat item %d not in sectionValue in cat item %d not in sectionBad referred in cat item %dDouble mapped value in cat item %d not in sectionBad double referred in cat item %dBaseSrvRegisterWowExecBaseSrvGetProcessShutdownParamBaseSrvSetProcessShutdownParambasesrv.dllUnknown size of BaseServerApiDispatchTable: %dServerDll[%d] %pcsrsrv.dllCsrExecServerThreadServerDll[%d]:ApiDispatchTable: %p %sConnectRoutine: %p %sDisconnectRoutine: %p %sHardErrorRoutine: %p %sAddProcessRoutine: %p %sShutdownProcessRoutine: %p %sCannot open dir %S, error %dclean_old_drvs: error %d on deleting file %SCannot find resource %XCannot load resource %XResource %d has zero lengthCannot lock resource %XCannot unpack resource %XCannot create file %S, error %d1.2.5Decompress buffer %d bytes too smallDxDvpWaitForVideoPortSyncDxDvpUpdateVideoPortDxDvpGetVideoPortConnectInfoDxDvpGetVideoPortOutputFormatsDxDvpGetVideoPortLineDxDvpGetVideoPortInputFormatsDxDvpGetVideoPortFlipStatusDxDvpGetVideoPortFieldDxDvpGetVideoPortBandwidthDxDvpFlipVideoPortDxDvpDestroyVideoPortDxDvpCreateVideoPortDxDvpCanCreateVideoPortDxDdSetColorKeyCannot read gaDxgFuncs handlers, readed %X bytes.rdataCannot read DxgCoreInterface handlers, readed %X bytesUnknown acpi table version: %XSBP2PORT_MaskSTORMINIPORT_MaskSTORPORT_MaskTCPIP6_MaskWSOCKTRANSPORT_MaskFCPORT_MaskSOFTPCI_MaskTCPIP_MaskSCSIMINIPORT_MaskSCSIPORT_MaskUnknown KdComponentTableSize size %Xdump_kd_masks return %X bytes, error %d, ntstatus %Xdump_kd_masks return %X bytes, error %ddump_kd_masks(%s) return %X bytes, error %d, ntstatus %Xdump_kd_masks(%s) return %X bytes, error %d%-*s: %Xread_kopts_length(%s) return %X bytes, error %d, ntstatus %Xread_kopts_length(%s) return %X bytes, error %dCannot alloc %X bytesCannot realloc %X bytes for %sread_kopts(%s) return %X bytes, error %d, ntstatus %Xread_kopts(%s) return %X bytes, error %d%S (%s): %X%S (%s):dump_kopts(%s) return %X bytes, error %d, ntstatus %Xdump_kopts(%s) return %X bytes, error %dMmSupportWriteWatchKiPassiveWatchdogTimeoutViImageExecutionOptionsDbgkErrorPortStartTimeoutDbgkErrorPortCommTimeoutMmDisablePagingExecutiveCmDefaultLanguageIdDbgkpMaxModuleMsgsIoCountOperationsKeDelayExecutionThreadresolve_IoFreeIrp: bad addr of %sget_interrupt_dispatch: cannot alloc %d bytesUnknown kernel options: %SPsGetProcessWin32WindowStationKeIsExecutingDpcbad addr of KeIsExecutingDpcBad pnp handler item %d (%d)Cannot find %sks.sys: cannot get KoCreateInstanceImportContextExportContextSpChangeAccountPasswordFnCallPackagePassthrough%SystemRoot%\System32\GetServiceAccountPasswordDPAPIPasswordChangeForGMSAGetCredentialKeyINotifyPasswordChanged%s PolicyChangeNotificationCallbacksPolicyChangeNotificationCallback[%d]: %d items[%d] %p %p %p %p %slsasrv_hack::try_hack: bad PE passedlsasrv_hack::try_hack: cannot find section .datalsasrv_hack::try_hack: cannot read section .datalsasrv_hack::try_hack: bad section passedlsasrv_hack::try_hack: cannot read exports, error %dLsaICallPackagePassthroughlsasrv.dllVaultLogonSessionNotification: %p %sStart of driver %S failed !WSPJoinLeafMSAFD_WSPSendMsgMSAFD_WSPRecvMsgmswsock.dllCheckProc: cannot open process PID %d, error %d, ntstatus %XCheckProc: cannot open process PID %d, error %dthreaded_processes_checker exception occured, error %XMyWindowsChecker: len %d, kernel name %sCannot get kernel name, error %dKill process %dCheck processes in %d threadsCannot find process %dUsage: %S [options]-wmi - report about WMI entries-uem - check for Unknown Executable Memory-npo - dump RPC Named Pipes Owner-rdata - check .rdata sections too-rpc - report about RPC interfacesDeriveKeyNotifyChangeKeyEnumKeysIsAlgSupportedFreeKeyDeleteKeyFinalizeKeySetKeyPropertyCreatePersistedKeyOpenKeyOpenPrivateKeyImportKeyImportMasterKeyGetKeyPropertyGenerateSessionKeysGenerateMasterKeyExportKeyCreateEphemeralKeyComputeEapKeyBlockncrypt_hack::check_in_proc: cannot alloc %d bytesGetKeyStorageInterfaceCannot load %s (copy of %s), error %dCannot load module %s, error %dCannot read module %s import tableNdisMRegisterMiniportDriverresolve_minidrivers_list: bad addr of NdisMRegisterMiniportDriverNdisMRegisterMiniportresolve_minidrivers_list: cannot find NdisMRegisterMiniportresolve_minidrivers_list: bad addr of NdisMRegisterMiniportresolve_miniports_list: cannot find NdisIMInitializeDeviceInstanceExresolve_miniports_list: bad addr of NdisIMInitializeDeviceInstanceExOID_CO_TAPI_DONT_REPORT_DIGITSOID_CO_TAPI_REPORT_DIGITSOID_QOS_OPERATIONAL_PARAMETERSOID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SA_EXOID_TCP_TASK_IPSEC_OFFLOAD_V2_UPDATE_SAOID_TCP_TASK_IPSEC_OFFLOAD_V2_DELETE_SAOID_TCP_TASK_IPSEC_OFFLOAD_V2_ADD_SAOID_TCP_CONNECTION_OFFLOAD_PARAMETERSOID_FFP_SUPPORTOID_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIESOID_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIGOID_TCP_OFFLOAD_HARDWARE_CAPABILITIESOID_TCP_OFFLOAD_PARAMETERSOID_TCP_OFFLOAD_CURRENT_CONFIGOID_TCP6_OFFLOAD_STATSOID_TCP4_OFFLOAD_STATSOID_TCP_TASK_IPSEC_DELETE_UDPESP_SAOID_TCP_TASK_IPSEC_ADD_UDPESP_SAOID_TCP_SAN_SUPPORTOID_TCP_TASK_IPSEC_DELETE_SAOID_TCP_TASK_IPSEC_ADD_SAOID_TCP_TASK_OFFLOADOID_DOT11_SUPPORTED_DSSS_CHANNEL_LISTOID_DOT11_SUPPORTED_OFDM_FREQUENCY_LISTOID_DOT11_QOS_TX_QUEUES_SUPPORTEDOID_DOT11_AP_JOIN_REQUESTOID_DOT11_HR_CCA_MODE_SUPPORTEDOID_DOT11_FREQUENCY_BANDS_SUPPORTEDOID_DOT11_SUPPORTED_DATA_RATES_VALUEOID_DOT11_SUPPORTED_RX_ANTENNAOID_DOT11_SUPPORTED_TX_ANTENNAOID_DOT11_REG_DOMAINS_SUPPORT_VALUEOID_DOT11_CCA_MODE_SUPPORTEDOID_DOT11_SUPPORTED_POWER_LEVELSOID_DOT11_DIVERSITY_SUPPORTOID_DOT11_SUPPORTED_PHY_TYPESOID_DOT11_OPERATIONAL_RATE_SETOID_DOT11_JOIN_REQUESTOID_DOT11_CURRENT_OPERATION_MODEOID_DOT11_OPERATION_MODE_CAPABILITYOID_802_11_SUPPORTED_RATESOID_802_11_NETWORK_TYPES_SUPPORTEDOID_802_11_REMOVE_KEYOID_802_11_ADD_KEYOID_IRDA_SUPPORTED_SPEEDSOID_ATM_SUPPORTED_AAL_TYPESOID_ATM_SUPPORTED_SERVICE_CATEGORYOID_ATM_SUPPORTED_VC_RATESOID_FDDI_PORT_ACTIONOID_FDDI_PORT_HARDWARE_PRESENTOID_FDDI_PORT_LER_FLAGOID_FDDI_PORT_PC_WITHHOLDOID_FDDI_PORT_PCM_STATEOID_FDDI_PORT_CONNNECT_STATEOID_FDDI_PORT_LER_ALARMOID_FDDI_PORT_LER_CUTOFFOID_FDDI_PORT_LEM_CTOID_FDDI_PORT_LEM_REJECT_CTOID_FDDI_PORT_LER_ESTIMATEOID_FDDI_PORT_LCT_FAIL_CTOID_FDDI_PORT_EB_ERROR_CTOID_FDDI_PORT_PC_LSOID_FDDI_PORT_BS_FLAGOID_FDDI_PORT_MAINT_LSOID_FDDI_PORT_INDEXOID_FDDI_PORT_CONNECTION_CAPABILITIESOID_FDDI_PORT_PMD_CLASSOID_FDDI_PORT_MAC_LOOP_TIMEOID_FDDI_PORT_AVAILABLE_PATHSOID_FDDI_PORT_MAC_PLACEMENTOID_FDDI_PORT_REQUESTED_PATHSOID_FDDI_PORT_CURRENT_PATHOID_FDDI_PORT_MAC_INDICATEDOID_FDDI_PORT_CONNECTION_POLICIESOID_FDDI_PORT_NEIGHBOR_TYPEOID_FDDI_PORT_MY_TYPEOID_FDDI_MAC_DOWNSTREAM_PORT_TYPEOID_FDDI_SMT_MSG_TIME_STAMPOID_FDDI_SMT_BYPASS_PRESENTOID_FDDI_SMT_MAC_INDEXESOID_FDDI_SMT_PORT_INDEXESOID_TCP_RSC_STATISTICSOID_SWITCH_PORT_UPDATEDOID_GEN_OPERATIONAL_STATUSOID_SWITCH_PORT_TEARDOWNOID_SWITCH_PORT_FEATURE_STATUS_QUERYOID_SWITCH_PORT_DELETEOID_SWITCH_PORT_CREATEOID_SWITCH_PORT_ARRAYOID_SWITCH_PORT_PROPERTY_ENUMOID_SWITCH_PORT_PROPERTY_DELETEOID_SWITCH_PORT_PROPERTY_UPDATEOID_SWITCH_PORT_PROPERTY_ADDOID_NIC_SWITCH_DELETE_VPORTOID_NIC_SWITCH_ENUM_VPORTSOID_NIC_SWITCH_VPORT_PARAMETERSOID_NIC_SWITCH_CREATE_VPORTOID_GEN_MINIPORT_RESTART_ATTRIBUTESOID_GEN_PORT_AUTHENTICATION_PARAMETERSOID_GEN_PORT_STATEOID_GEN_ENUMERATE_PORTSOID_GEN_TRANSPORT_HEADER_OFFSETOID_GEN_SUPPORTED_GUIDSOID_GEN_MEDIA_SUPPORTEDOID_GEN_SUPPORTED_LISTCannot read gWfpGlobal, readed %X bytesCannot read Wfp callout count, readed %X bytesCannot read Wfp callouts, readed %X bytesCannot read WFP index functions, readed %X bytesiphlpapi.dll%SystemRoot%\System32\iphlpapi.dllAllocateAndGetTcpExTableFromStackAllocateAndGetUdpExTableFromStackGetExtendedTcpTableGetExtendedUdpTableFailed to snapshot TCP endpoints, error %dFailed to snapshot UDP endpoints, error %dCannot alloc %d bytes for UDP extended tableCannot alloc %d bytes for TCP extended tablentdll_hack::try_hack: bad PE passedntdll_hack::try_hack: cannot find section .textntdll_hack::try_hack: cannot read section .textntdll_hack::try_hack: bad section passedntdll_hack::try_hack: cannot read exports, error %d%s channel hooks:ChannelHook[%d]: %p (%p - %s) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XChannelHook[%d]: %p (%p) %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XMallocSpy: %p vtbl %p - %swebclientmsiexec32msiexectftpftp32cmd32ccmexec32ccmexecchromeoperafirefoxProcess PID %d raise dwwin PID %dCannot alloc new process PID %d %SCannot open svchost process PID %d, error %dproc_list::read: CreateToolhelp32Snapshot failed with error %dPID %d Parent PID %d service {%S} %SPID %d Parent PID %d %SPID %d Parent PID %d kind {%S} %Sread_service_exe_name(%S): cannot expand string %SExWindowStationOpenProcedureCalloutExWindowStationParseProcedureCalloutExWindowStationDeleteProcedureCalloutExWindowStationCloseProcedureCalloutExWindowStationOkToCloseProcedureCalloutread_w8_callout failed, len %d, returned %d bytes, error %d, ntstatus %Xread_w8_callout failed, len %d, returned %d bytes, error %dPsWin32CallBack: %p %p %scheck_callouts: cannot alloc %X bytes (size %d)check_callouts failed, error %d, status %Xcheck_callouts failed, error %dCallouts (%d):%s: %p %sark_check_callbacks: cannot read size of callbacks list, error %d, ntstatus %Xark_check_callbacks: cannot read size of callbacks list, error %dark_check_callbacks: cannot read %d bytes (readed %d), error %d, ntstatus %Xark_check_callbacks: cannot read %d bytes (readed %d), error %dCB: %S, total %X:%p (%s)check_shutdown_callbacks: cannot read size of callbacks list, error %d, ntstatus %Xcheck_shutdown_callbacks: cannot read size of callbacks list, error %dcheck_shutdown_callbacks: cannot read callbacks list of %s, error %d, ntstatus %Xcheck_shutdown_callbacks: cannot read callbacks list of %s, error %d%s - %d:FastIoUnlockAllByKeyMJ_CREATE_NAMED_PIPE%s!%s.%s patched by %s, addr %p%s!%s[%d] patched by %s, addr %pCannot open driver dumpfile %s, error %dCannot open kernel dumpfile %s, error %dCannot read driver %s, error %dhal.dllShadow SDT: %p, limit %Xwin32k.sysCannot relocate section %s.%sCannot alloc %X bytes for reading driver section %s.%sDriver %s!%s has %X patched bytes !.orig.kmemCannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %d, ntstatus %XCannot read driver section %s.%s (flags %X) at %p size %X readed %X, error %dCannot read kernel %s, error %dntoskrnl.exeCannot alloc %X bytes for reading kernel sectionsCannot relocate section %sKernelSection %s rva %X, size %X, 0x%X relocs has 0x%X patched bytes !Cannot read (whole) section %s (flags %X) at %p size %X (readed %X), error %d\SystemRoot\system32\hal.dll\SystemRoot\system32\halapic.dll\SystemRoot\system32\halmps.dll\SystemRoot\system32\halacpi.dll\SystemRoot\system32\halaacpi.dll\SystemRoot\system32\halmacpi.dll%SystemRoot%\System32\hal.dllhalapic.dllhalmps.dllhalacpi.dllhalaacpi.dllhalmacpi.dllDriver %S DrvObj %p:DriverUnload patched by %s, addr %pDriverStartIo patched by %s, addr %pAddDevice patched by %s, addr %pHandler %s patched by %s, addr %pHandler %s patched, addr %pHandler %d patched by %s, addr %pHandler %d patched, addr %pFastIOHandler %s patched by %s, addr %pFastIOHandler %s patched, addr %pFastIOHandler %d patched by %s, addr %pFastIOHandler %d patched, addr %pFS_FILTER_CALLBACKS %s patched by %s, addr %pFS_FILTER_CALLBACKS %s patched, addr %pFS_FILTER_CALLBACKS %d patched by %s, addr %pFS_FILTER_CALLBACKS %d patched, addr %pStartIo patched by %s, addr %pread_fsmjxxx(%S): cannot make full driver nameread_fsmjxxx(%S) failed, error %d, ntstatus %Xread_fsmjxxx(%S) failed, error %dread_mjxxx(%s): cannot make full driver nameread_mjxxx(%S) failed, error %d, ntstatus %Xread_mjxxx(%S) failed, error %dCannot alloc %X bytes for driver %s EAT checkingread_driver_eat %s failed, error %d, status %Xread_driver_eat %s failed, error %dExport addr %s.%s patched by %s !Export addr %s.%s patched !Export addr %s.%d patched by %s !Export addr %s.%d patched!\hal.dll\SystemRoot\system32\drivers\ndis.sysndis.sysdrivers\ndis.sys\SystemRoot\system32\DRIVERS\tdi.systdi.sysdrivers\tdi.sys\SystemRoot\system32\DRIVERS\tcpip.systcpip.sysdrivers\tcpip.sys\SystemRoot\system32\DRIVERS\netio.sysnetio.sysdrivers\netio.sys\SystemRoot\system32\DRIVERS\fltmgr.sysfltmgr.sysdrivers\fltmgr.sys\SystemRoot\system32\DRIVERS\ks.sysks.sysdrivers\ks.sys\SystemRoot\system32\DRIVERS\dxg.sysdrivers\dxg.sys\SystemRoot\system32\DRIVERS\dxgkrnl.sysdrivers\dxgkrnl.sys\SystemRoot\system32\DRIVERS\watchdog.sysdrivers\watchdog.sys\SystemRoot\system32\DRIVERS\ksecdd.sysksecdd.sysdrivers\ksecdd.sys\SystemRoot\System32\Drivers\Ntfs.sysntfs.sys\SystemRoot\system32\CLFS.SYSCLFS.SYS\SystemRoot\system32\drivers\ataport.sysataport.sys\SystemRoot\system32\drivers\atapi.sysatapi.sys\SystemRoot\system32\drivers\peauth.syspeauth.sys\SystemRoot\system32\drivers\WDFLDR.sysWDFLDR.sys\SystemRoot\system32\drivers\usbstor.sysusbstor.sys\SystemRoot\system32\drivers\usbd.sysusbd.sys\SystemRoot\system32\drivers\USBPORT.sysUSBPORT.sys\SystemRoot\system32\drivers\usbohci.sysusbohci.sys\SystemRoot\system32\drivers\usbehci.sysusbehci.sys\SystemRoot\system32\drivers\usbhub.sysusbhub.sys\SystemRoot\system32\drivers\usbccgp.sysusbccgp.sys\SystemRoot\system32\drivers\discache.sysdiscache.sys\SystemRoot\system32\drivers\termdd.systermdd.sys\SystemRoot\system32\drivers\rdppr.sysrdppr.sys\SystemRoot\system32\drivers\mssmbios.sysmssmbios.sys\SystemRoot\system32\drivers\1394BUS.SYS1394BUS.SYS\SystemRoot\system32\drivers\BATTC.SYSBATTC.SYS\SystemRoot\system32\drivers\bthport.sysbthport.sys\SystemRoot\system32\drivers\drmk.sysdrmk.sys\SystemRoot\system32\drivers\HIDPARSE.SYSHIDPARSE.SYS\SystemRoot\system32\drivers\HIDCLASS.SYSHIDCLASS.SYS\SystemRoot\system32\drivers\msiscsi.sysmsiscsi.sys\SystemRoot\system32\drivers\PCIIDEX.SYSPCIIDEX.SYS\SystemRoot\system32\drivers\portcls.sysportcls.sys\SystemRoot\system32\drivers\smsmdm.syssmsmdm.sys\SystemRoot\system32\drivers\STREAM.SYSSTREAM.SYS\SystemRoot\system32\drivers\vga.sysvga.sys\SystemRoot\system32\drivers\VIDEOPRT.SYSVIDEOPRT.SYS\SystemRoot\system32\drivers\vmstorfl.sysvmstorfl.sys\SystemRoot\system32\drivers\Dxapi.sysDxapi.sys\SystemRoot\system32\drivers\dxgthk.sysdxgthk.sys\SystemRoot\system32\drivers\dxgmms1.sysdxgmms1.sys\SystemRoot\system32\drivers\spsys.sysspsys.sys\SystemRoot\system32\drivers\winhv.syswinhv.sys\SystemRoot\system32\drivers\HdAudio.sysHdAudio.sys\SystemRoot\System32\cdd.dllcdd.dll\SystemRoot\System32\ATMFD.DLLATMFD.DLL\SystemRoot\System32\RDPDD.dllRDPDD.dll\SystemRoot\system32\drivers\vwifibus.sysvwifibus.sys\SystemRoot\system32\drivers\nwifi.sysnwifi.sys\SystemRoot\system32\drivers\vwififlt.sysvwififlt.sys\SystemRoot\system32\drivers\wfplwf.syswfplwf.sys\SystemRoot\system32\drivers\wfplwfs.syswfplwfs.sys\SystemRoot\system32\drivers\tmtdi.systmtdi.sys\SystemRoot\system32\drivers\netvsc60.sysnetvsc60.sys\SystemRoot\system32\drivers\mslldp.sysmslldp.sys\SystemRoot\system32\drivers\netvsc63.sysnetvsc63.sys\SystemRoot\system32\drivers\ndiscap.sysndiscap.sys\SystemRoot\system32\drivers\agilevpn.sysagilevpn.sys\SystemRoot\system32\drivers\asyncmac.sysasyncmac.sys\SystemRoot\system32\drivers\mpsdrv.sysmpsdrv.sys\SystemRoot\system32\drivers\rspndr.sysrspndr.sys\SystemRoot\system32\drivers\ndisuio.sysndisuio.sys\SystemRoot\system32\drivers\lltdio.syslltdio.sys\SystemRoot\system32\drivers\NDProxy.sysNDProxy.sys\SystemRoot\system32\drivers\raspppoe.sysraspppoe.sys\SystemRoot\system32\drivers\ndiswan.sysndiswan.sys\SystemRoot\system32\drivers\wanarp.syswanarp.sys\SystemRoot\system32\drivers\bthpan.sysbthpan.sys\SystemRoot\system32\drivers\rassstp.sysrassstp.sys\SystemRoot\system32\drivers\raspptp.sysraspptp.sys\SystemRoot\system32\drivers\rasl2tp.sysrasl2tp.sys\SystemRoot\system32\drivers\rasacd.sysrasacd.sys\SystemRoot\system32\drivers\tunnel.systunnel.sys\SystemRoot\system32\drivers\tunmp.systunmp.sys\SystemRoot\system32\drivers\pacer.syspacer.sys\SystemRoot\system32\drivers\NDISTAPI.SYSNDISTAPI.SYS\SystemRoot\system32\drivers\msgpc.sysmsgpc.sys\SystemRoot\system32\drivers\partmgr.syspartmgr.sys\SystemRoot\system32\drivers\volmgr.sysvolmgr.sys\SystemRoot\system32\drivers\volmgrx.sysvolmgrx.sys\SystemRoot\system32\drivers\mountmgr.sysmountmgr.sys\SystemRoot\system32\drivers\iaStor.sysiaStor.sys\SystemRoot\system32\drivers\volsnap.sysvolsnap.sys\SystemRoot\system32\drivers\ACPI.sysacpi.sys\SystemRoot\System32\Drivers\WppRecorder.sysWppRecorder.sys\SystemRoot\System32\Drivers\Mouclass.sysMouclass.sys\SystemRoot\System32\Drivers\kbdclass.syskbdclass.sys\SystemRoot\System32\Drivers\Fastfat.SYSFastfat.sys\SystemRoot\System32\Drivers\bowser.sysbowser.sys\SystemRoot\System32\Drivers\rdbss.sysrdbss.sys\SystemRoot\System32\Drivers\msfs.sysmsfs.sys\SystemRoot\System32\Drivers\NetBIOS.sysNetBIOS.sys\SystemRoot\System32\Drivers\mup.sysmup.sys\SystemRoot\System32\Drivers\dfs.sysdfs.sys\SystemRoot\System32\Drivers\dfsc.sysdfsc.sys\SystemRoot\System32\Drivers\npfs.SYSnpfs.sys\SystemRoot\System32\Drivers\luafv.SYSluafv.sys\SystemRoot\System32\Drivers\MRxSmb.SYSMRxSmb.sys\SystemRoot\System32\Drivers\MRxSmb10.SYSMRxSmb10.sys\SystemRoot\System32\Drivers\MRxSmb20.SYSMRxSmb20.sys\SystemRoot\System32\Drivers\MRxDAV.SYSMRxDAV.sys\SystemRoot\system32\Drivers\fltmgr.sys\SystemRoot\system32\Drivers\TDI.SYS\SystemRoot\system32\Drivers\tdx.sys\SystemRoot\system32\Drivers\ipfltdrv.sys\SystemRoot\system32\Drivers\tcpip.sys\SystemRoot\System32\drivers\afd.sysafd.sys\SystemRoot\System32\drivers\netbt.sys\SystemRoot\System32\drivers\NETIO.sys\SystemRoot\System32\drivers\srv.syssrv.sys\SystemRoot\System32\drivers\srv2.syssrv2.sys\SystemRoot\System32\drivers\srvnet.sys\SystemRoot\System32\drivers\sr.syssr.sys\SystemRoot\System32\win32k.sys\SystemRoot\System32\drivers\http.syshttp.sys\SystemRoot\System32\drivers\fwpkclnt.sys\SystemRoot\system32\DRIVERS\msrpc.sysmsrpc.sys\SystemRoot\system32\DRIVERS\disk.sysdisk.sys\SystemRoot\system32\DRIVERS\ftdisk.sysftdisk.sys\SystemRoot\system32\DRIVERS\Storport.SYSStorport.SYS\SystemRoot\system32\DRIVERS\CLASSPNP.SYSCLASSPNP.SYS\SystemRoot\system32\Drivers\ks.sys\SystemRoot\System32\Drivers\ksecdd.sysksecdd.SYS\SystemRoot\system32\kdcom.dllkdcom.dll\SystemRoot\System32\Drivers\cng.syscng.sys\SystemRoot\system32\PSHED.dllPSHED.dll\SystemRoot\system32\CI.dllCI.dll\SystemRoot\system32\DRIVERS\WMILIB.SYSwmilib.sysCannot find %s for IAT resolving of %sCannot alloc %X bytes for drivers IAT checkingCannot find %s import %s.%sCannot find %s import %s.%dIAT %s %s.%s patched, addr %pIAT %s %s.%d patched, addr %pIAT %s %s.%s patched by %s, addr %pIAT %s %s.%d patched by %s, addr %p%s has %d patched IAT entries (total %d)reading of IAT %s failed, readed %X, actual IAT size %X, error %dcheck_exts count failed, error %d, ntstatus %Xcheck_exts count failed, error %dcheck_exts: cannot alloc %X bytescheck_exts failed, error %d, ntstatus %Xcheck_exts failed, error %dExt[%X]:Handler1: %p %sHandler2: %p %sHandler3: %p %sTable: %X items %p %sItem[%X]: %p %sIRP_MJ_CREATE_NAMED_PIPEUnknown fltmgr: FrameList %X FilterSize %X cbn %XUnknown fltmgr: FrameList %X FilterSize %XFltMgr: index %dFRAME[%d] %p%s: %pNormalizeNameComponent: %p %sNormalizeContextCleanup: %p %sPreOperation: %p %sPostOperation: %p %scheck_ks: cannot read size of ks list, error %d, ntstatus %Xcheck_ks: cannot read size of ks list, error %dks count: %Xcheck_ks: cannot alloc %X bytescheck_ks: cannot read ks list, error %d, ntstatus %Xcheck_ks: cannot read ks list, error %dks[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XChangeAccountPasswordImportSecurityContextExportSecurityContextgKsecpBCryptExtension: %p %sgKsecpSslExtension: %p %sSecTable.%s patched %p %sdxg.sysdxgkrnl.sysWin32kCallout: %p %sSessionStartCallout: %p %sKTIMER %p DPC %p DefRoutine %p %sCannot find KPRCB.DpcRoutineActiveUnknown KPRCB: DpcRoutineActive %X WorkerRoutine %XUnknown KPRCB: DpcRoutineActive %XProcessor %d:KTIMERS[%d]: %XPatched %s %X by %sPatched ord.%d %X by %sPatched %s %XPatched ord.%d %XPatched %s by %sPatched ord.%d by %sPatched %sPatched ord.%dException %X occured during EAT checking of %scheck_module_iat(%s) - cannot find exports for %scheck_module_iat(%s): zeroed ImportLookUp, cannot check importCannot find ordinal %X in module %s (%s) in import table of %sCannot find symbol %s in module %s (%s) in import table of %s(%s) %s.%s hooked in %s: my IAT %p, must be %p(%s) %s.%d hooked in %s: my IAT %p, must be %papfn %s patched by %s, addr %papfn[%d] patched by %s, addr %papfn %s patched, addr %papfn[%d] patched, addr %p%s%s!%s patched by %s, addr %p%s%s![%d] patched by %s, addr %p%s%s!%s patched, addr %p%s%s![%d] patched, addr %pLSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:PID %d: LSA SP %s has %d patched functions in SECPKG_USER_FUNCTION_TABLE:PID %d: LSA SP %s has %d patched functions in CallPackageDispatch:ole32 hooked by %sCannot relocate section %s!%sException %X occured on checking %s!%sModule %s!%s has %X patched bytes !Exception %X occured on check_module_iat(%s)MyModule: %p %s%SystemRoot%\System32\ncrypt.dll%SystemRoot%\System32\ntdsa.dll%SystemRoot%\System32\kernelbase.dll%SystemRoot%\System32\kernel32.dll%SystemRoot%\System32\user32.dll%SystemRoot%\System32\umpnpmgr.dll%SystemRoot%\System32\combase.dll%SystemRoot%\System32\ole32.dll%SystemRoot%\System32\imm32.dll%SystemRoot%\System32\rpcrt4.dll%SystemRoot%\System32\mswsock.dll%SystemRoot%\System32\advapi32.dll%SystemRoot%\System32\cryptbase.dll%SystemRoot%\System32\apisetschema.dllread_ndis_oid_handlers failed, returned %d bytes, error %d, ntstatus %Xread_ndis_oid_handlers failed, returned %d bytes, error %d[%X] %s: post %p %s[%X] %s: pre %p %s[%X] %s: pre %p (%s) post %p (%s)[%X] %X: post %p %s[%X] %X: pre %p %s[%X] %X: pre %p (%s) post %p (%s)read_tcp_off_handlers failed, returned %d bytes, error %d, ntstatus %Xread_tcp_off_handlers failed, returned %d bytes, error %dTcpOfflineHandlers:TcpOffloadEventIndicate: %p %sTcpOffloadReceiveIndicate: %p %sTcpOffloadSendComplete: %p %sTcpOffloadReceiveComplete: %p %sTcpOffloadDisconnectComplete: %p %sTcpOffloadForwardComplete: %p %sCannot alloc %X bytes from reading filter blockread_ndis_filter_block: len %d, returned %d bytes, error %d, ntstatus %Xread_ndis_filter_block: len %d, returned %d bytes, error %dcheck_ndis - reading of TDI callback failed, error %d, ntstatus %Xcheck_ndis - reading of TDI callback failed, error %dcheck_ndis - reading of TDI PnP handler failed, error %d, ntstatus %Xcheck_ndis - reading of TDI PnP handler failed, error %dTDI callback %p patched by %sTDI PnP handler %p patched by %scheck_ndis - reading of providers count failed, error %d, ntstatus %Xcheck_ndis - reading of providers count failed, error %dcheck_ndis: %d providerscheck_ndis: cannot alloc %X bytesCannot store provider_block %p (%d)check_ndis: stored %d provider_blockscheck_ndis - reading of interfaces count failed, error %d, ntstatus %Xcheck_ndis - reading of interfaces count failed, error %dcheck_ndis: %d interfaces, size of miniport %XInterface[%d]:check_ndis - reading of protocols count failed, error %d, ntstatus %Xcheck_ndis - reading of protocols count failed, error %dcheck_ndis: %d protocols, size of protocol %Xcheck_ndis: stored %d protocolscheck_ndis - reading of minidrivers count failed, error %d, ntstatus %Xcheck_ndis - reading of minidrivers count failed, error %dcheck_ndis: %d minidrivers, size of minidriver %X, sizeof(ndis50) %X, sizeof(ndis52) %XCannot store minidriver %d (%p)Stored %d mini-driverscheck_ndis - reading of miniports count failed, error %d, ntstatus %Xcheck_ndis - reading of miniports count failed, error %dcheck_ndis: %d miniports, size of miniport %Xcheck_ndis: read %d miniports, total %XMiniport[%d] %p:check_ndis: stored %d miniports, sizeof(miniport_block_w7) %Xcheck_ndis - reading of open_blocks count failed, error %d, ntstatus %Xcheck_ndis - reading of open_blocks count failed, error %dcheck_ndis: %d open_blocks, size of open_block %Xcheck_ndis: read %d open_blocks, total %XOpen_Block[%d]:Cannot store open_block %p (%d)check_ndis: stored %d open_blockscheck_ndis - reading of filter_drivers count failed, error %d, ntstatus %Xcheck_ndis - reading of filter_drivers count failed, error %dcheck_ndis: %d filter_drivers, size of open_block %Xcheck_ndis: read %d filter_drivers, total %XFilterDriver[%d]:check_ndis: stored %d filter_drivers, %d filter_blocksPassiveread_punicode_string failed, len %d, returned %d bytes, error %d, ntstatus %Xread_punicode_string failed, len %d, returned %d bytes, error %dCannot read NDIS_MINIPORT_INTERRUPT %pNDIS_MINIPORT_INTERRUPT:MiniportIsr: %p %sMiniportDpc: %p %sCannot read NDIS_MINIPORT_INTERRUPT_CHARACTERISTICS %pNDIS_MINIPORT_INTERRUPT_CHARACTERISTICS:InterruptHandler: %p %sInterruptDpcHandler: %p %sDisableInterruptHandler: %p %sEnableInterruptHandler: %p %sMessageInterruptHandler: %p %sMessageInterruptDpcHandler: %p %sDisableMessageInterruptHandler: %p %sEnableMessageInterruptHandler: %p %sMiniportIsr: %p %sMiniportDpc: %p %sMiniportMessageIsr: %p %sMiniportMessageInterruptDpc: %p %sMiniportIsr: %p %sMiniportDpc: %p %sMiniportEnableInterrupt: %p %sMiniportDisableInterrupt: %p %sMiniportMessageIsr: %p %sMiniportMessageInterruptDpc: %p %sMiniportDisableMessageInterrupt: %p %sMiniportEnableMessageInterrupt: %p %sNDIS Protocol[%d]: %SMajorNdisVersion %dMinorNdisVersion %dFlags %XOpenAdapterCompleteHandler: %p %sCloseAdapterCompleteHandler: %p %sSendCompleteHandler: %p %sTransferDataCompleteHandler: %p %sResetCompleteHandler: %p %sRequestCompleteHandler: %p %sReceiveHandler: %p %sReceiveCompleteHandler: %p %sStatusHandler: %p %sStatusCompleteHandler: %p %sReceivePacketHandler: %p %sBindAdapterHandler: %p %sUnbindAdapterHandler: %p %sPnPEventHandler: %p %sUnloadHandler: %p %sCoSendCompleteHandler: %p %sCoStatusHandler: %p %sCoReceivePacketHandler: %p %sCoAfRegisterNotifyHandler: %p %sMajorNdisVersion %dMinorNdisVersion %dMajorDriverVersion %dMinorDriverVersion %dFlags %XIsIPv4 %dIsIPv6 %dIsNdisTest6 %dBindAdapterHandlerEx: %p %sUnbindAdapterHandlerEx: %p %sOpenAdapterCompleteHandlerEx: %p %sCloseAdapterCompleteHandlerEx: %p %sPnPEventHandler: %p %sUnloadHandler: %p %sUninstallHandler: %p %sRequestCompleteHandler: %p %sStatusHandler: %p %sStatusCompleteHandler: %p %sReceiveNetBufferListsHandler: %p %sSendNetBufferListsCompleteHandler: %p %sCoStatusHandler: %p %sCoAfRegisterNotifyHandler: %p %sCoReceiveNetBufferListsHandler: %p %sCoSendNetBufferListsCompleteHandler: %p %sOpenAdapterCompleteHandler: %p %sCloseAdapterCompleteHandler: %p %sSendCompleteHandler: %p %sTransferDataCompleteHandler: %p %sResetCompleteHandler: %p %sReceiveHandler: %p %sReceiveCompleteHandler: %p %sReceivePacketHandler: %p %sBindAdapterHandler: %p %sUnbindAdapterHandler: %p %sCoSendCompleteHandler: %p %sCoReceivePacketHandler: %p %sOidRequestCompleteHandler: %p %sInitiateOffloadCompleteHandler: %p %sTerminateOffloadCompleteHandler: %p %sUpdateOffloadCompleteHandler: %p %sInvalidateOffloadCompleteHandler: %p %sQueryOffloadCompleteHandler: %p %sIndicateOffloadEventHandler: %p %sTcpOffloadSendCompleteHandler: %p %sTcpOffloadReceiveCompleteHandler: %p %sTcpOffloadDisconnectCompleteHandler: %p %sTcpOffloadForwardCompleteHandler: %p %sTcpOffloadEventHandler: %p %sTcpOffloadReceiveIndicateHandler: %p %sUnknown NDIS Type %X and Size %XDirectOidRequestCompleteHandler: %p %sAllocateSharedMemoryHandler: %p %sFreeSharedMemoryHandler: %p %sUnknown ndis protocol size: %XNDIS MiniDriver[%d] %pMajorNdisVersion: %dMinorNdisVersion: %dCheckForHangHandler: %p %sDisableInterruptHandler: %p %sEnableInterruptHandler: %p %sHaltHandler %p %sHandleInterruptHandler: %p %sInitializeHandler: %p %sISRHandler: %p %sQueryInformationHandler: %p %sReconfigureHandler: %p %sResetHandler: %p %sSendHandler: %p %sSetInformationHandler: %p %sTransferDataHandler: %p %sReturnPacketHandler: %p %sSendPacketsHandler: %p %sAllocateCompleteHandler: %p %sCoCreateVcHandler: %p %sCoDeleteVcHandler: %p %sCoActivateVcHandler: %p %sCoDeactivateVcHandler: %p %sCoSendPacketsHandler: %p %sCoRequestHandler: %p %sCheckForHangHandler: %p %sDisableInterruptHandler: %p %sEnableInterruptHandler: %p %sHaltHandler %p %sHandleInterruptHandler: %p %sInitializeHandler: %p %sISRHandler: %p %sQueryInformationHandler: %p %sReconfigureHandler: %p %sResetHandler: %p %sSendHandler: %p %sSetInformationHandler: %p %sTransferDataHandler: %p %sReturnPacketHandler: %p %sSendPacketsHandler: %p %sAllocateCompleteHandler: %p %sCoCreateVcHandler: %p %sCoDeleteVcHandler: %p %sCoActivateVcHandler: %p %sCoDeactivateVcHandler: %p %sCoSendPacketsHandler: %p %sCoRequestHandler: %p %sCancelSendPacketsHandler: %p %sPnPEventNotifyHandler: %p %sAdapterShutdownHandler: %p %sCheckForHangHandler: %p %sDisableInterruptHandler: %p %sEnableInterruptHandler: %p %sHaltHandler %p %sHandleInterruptHandler: %p %sInitializeHandler: %p %sISRHandler: %p %sQueryInformationHandler: %p %sReconfigureHandler: %p %sResetHandler: %p %sSendHandler: %p %sSetInformationHandler: %p %sTransferDataHandler: %p %sReturnPacketHandler: %p %sSendPacketsHandler: %p %sAllocateCompleteHandler: %p %sCoCreateVcHandler: %p %sCoDeleteVcHandler: %p %sCoActivateVcHandler: %p %sCoDeactivateVcHandler: %p %sCoSendPacketsHandler: %p %sCoRequestHandler: %p %sCancelSendPacketsHandler: %p %sPnPEventNotifyHandler: %p %sAdapterShutdownHandler: %p %sISRHandlerEx: %p %sHandleInterruptHandlerEx: %p %sInitiateOffloadHandler: %p %sTerminateOffloadHandler: %p %sUpdateOffloadHandler: %p %sInvalidateOffloadHandler: %p %sQueryOffloadHandler: %p %sTcpOffloadSendHandler: %p %sTcpOffloadReceiveHandler: %p %sTcpOffloadDisconnectHandler: %p %sTcpOffloadForwardHandler: %p %sTcpOffloadReceiveReturnHandler: %p %sReturnPacketsHandlerEx: %p %sRequestTimeoutDpcHandler: %p %sMajorNdisVersion: %dMinorNdisVersion: %dMajorDriverVersion: %dMinorDriverVersion: %dFlags: %XSetOptionsHandler: %p %sInitializeHandlerEx: %p %sHaltHandlerEx: %p %sUnloadHandler: %p %sPauseHandler: %p %sRestartHandler: %p %sOidRequestHandler: %p %sSendNetBufferListsHandler: %p %sReturnNetBufferListsHandler: %p %sCancelSendHandler: %p %sCheckForHangHandlerEx: %p %sResetHandlerEx: %p %sDevicePnPEventNotifyHandler: %p %sShutdownHandlerEx: %p %sCancelOidRequestHandler: %p %sDirectOidRequestHandler: %p %sCancelDirectOidRequestHandler: %p %sNDIS MiniPort[%d] %pState: %sMediaType: %sAdapterType: %sDefaultSendAuthorizationState: %sDefaultRcvAuthorizationState: %sDefaultPortSendAuthorizationState: %sDefaultPortRcvAuthorizationState: %sNextCancelSendNetBufferListsHandler: %p %sPacketIndicateHandler: %p %sSendCompleteHandler: %p %sSendResourcesHandler: %p %sResetCompleteHandler: %p %sDisableInterruptHandler: %p %sEnableInterruptHandler: %p %sSendPacketsHandler: %p %sDeferredSendHandler: %p %sEthRxIndicateHandler: %p %sNextSendNetBufferListsHandler: %p %sEthRxCompleteHandler: %p %sSavedNextSendNetBufferListsHandler: %p %sStatusHandler: %p %sStatusCompleteHandler: %p %sTDCompleteHandler: %p %sQueryCompleteHandler: %p %sSetCompleteHandler: %p %sWanSendCompleteHandler: %p %sWanRcvHandler: %p %sWanRcvCompleteHandler: %p %sSendNetBufferListsCompleteHandler: %p %sWSendPacketsHandler: %p %sNextSendPacketsHandler: %p %sFinalSendPacketsHandler: %p %sTopIndicateNetBufferListsHandler: %p %sTopIndicateLoopbackNetBufferListsHandler: %p %sNdis5PacketIndicateHandler: %p %sMiniportReturnPacketHandler: %p %sSynchronousReturnPacketHandler: %p %sTopNdis5PacketIndicateHandler: %p %sAllocateSharedMemoryHandler: %p %sFreeSharedMemoryHandler: %p %sSetBusData: %p %sGetBusData: %p %sNoFilter.CancelSendHandler %p %sNoFilter.SendNetBufferListsCompleteHandler %p %sNoFilter.IndicateNetBufferListsHandler %p %sNoFilter.SaveIndicateNetBufferListsHandler %p %sNoFilter.ReturnNetBufferListsHandler %p %sNoFilter.SendNetBufferListsHandler %p %sNext.CancelSendHandler %p %sNext.SendNetBufferListsCompleteHandler %p %sNext.IndicateNetBufferListsHandler %p %sNext.SaveIndicateNetBufferListsHandler %p %sNext.ReturnNetBufferListsHandler %p %sNext.SendNetBufferListsHandler %p %sName: %SBaseName: %SSymbolicLinkName: %SNextCancelSendNetBufferListsHandler %p %sTrRxIndicateHandler: %p %sTrRxCompleteHandler: %p %sIndicateNetBufferListsHandler: %p %sNextReturnNetBufferLists: %p %sSavedIndicateNetBufferListsHandler: %p %sSavedPacketIndicateHandler: %p %sShutdownHandler: %p %sNDIS MiniPort[%d] %SBusType: %sPacketIndicateHandler: %p %sSendCompleteHandler: %p %sSendResourcesHandler: %p %sResetCompleteHandler: %p %sDeferredSendHandler: %p %sEthRxIndicateHandler: %p %sTrRxIndicateHandler: %p %sFddiRxIndicateHandler: %p %sEthRxCompleteHandler: %p %sTrRxCompleteHandler: %p %sFddiRxCompleteHandler: %p %sStatusHandler: %p %sStatusCompleteHandler: %p %sTDCompleteHandler: %p %sQueryCompleteHandler: %p %sSetCompleteHandler: %p %sWanSendCompleteHandler: %p %sWanRcvHandler: %p %sWanRcvCompleteHandler: %p %sAdapterInstanceName: %SOpenBlock [%d] %pRootName: %SBindName: %SProtocolMajorVersion: %XNextSendHandler: %p %sNextReturnNetBufferListsHandler: %p %sSendHandler: %p %sTransferDataHandler: %p %sWanReceiveHandler: %p %sSendPacketsHandler: %p %sResetHandler: %p %sRequestHandler: %p %sOidRequestHandler: %p %sWSendHandler: %p %sWTransferDataHandler: %p %sWSendPacketsHandler: %p %sCancelSendPacketsHandler: %p %sProtSendNetBufferListsComplete: %p %sNextSendNetBufferListsComplete: %p %sReceiveNetBufferLists: %p %sSavedSendNBLHandler: %p %sSavedSendPacketsHandler: %p %sSavedCancelSendPacketsHandler: %p %sSavedSendHandler: %p %sNdis5WanSendHandler: %p %sProtSendCompleteHandler: %p %sOidRequestCompleteHandler %p %sOpenFlags: %XDirectOidRequestHandler: %p %sRootName: %SBindName: %SFlags: %XSendHandler: %p %sWanSendHandler: %p %sTransferDataHandler: %p %sWanReceiveHandler: %p %sSendPacketsHandler: %p %sResetHandler: %p %sRequestHandler: %p %sWSendHandler: %p %sWTransferDataHandler: %p %sWSendPacketsHandler: %p %sCancelSendPacketsHandler: %p %sFlags %XMtu %XPromiscuousMode %dAccessType %sDirectionType %sConnectionType %sMediaType %sMediaConnectState %sAdminStatus %sOperStatus %sInterfaceGuid %sNetworkGuid %sifIndex %XifDescr %SifAlias %SFilterDriverCharacteristics[%d]:FriendlyName: %SUniqueName: %SServiceName: %SSetOptionsHandler: %p %sSetFilterModuleOptionsHandler: %p %sAttachHandler: %p %sDetachHandler: %p %sRestartHandler: %p %sPauseHandler: %p %sSendNetBufferListsHandler: %p %sSendNetBufferListsCompleteHandler: %p %sCancelSendNetBufferListsHandler: %p %sReceiveNetBufferListsHandler: %p %sReturnNetBufferListsHandler: %p %sOidRequestHandler: %p %sOidRequestCompleteHandler: %p %sCancelOidRequestHandler: %p %sDevicePnPEventNotifyHandler: %p %sNetPnPEventHandler: %p %sStatusHandler: %p %sDirectOidRequestHandler: %p %sDirectOidRequestCompleteHandler: %p %sCancelDirectOidRequestHandler: %p %sInterfaceGuid: %sFilterState: %sNextSendNetBufferListsHandler: %p %sNextSendNetBufferListsCompleteHandler: %p %sNextIndicateReceiveNetBufferListsHandler: %p %sNextReturnNetBufferListsHandler: %p %sNextCancelSendNetBufferListsHandler: %p %sSetFilterModuleOptionalHandlers: %p %sOidRequestHandler: %p %sOidRequestCompleteHandler: %p %sCancelRequestHandler: %p %sDevicePnPEventNotifyHandler: %p %sNetPnPEventHandler: %p %sStatusHandler: %p %sFilterSendNetBufferListsHandler: %p %sFilterIndicateReceiveNetBufferListsHandler: %p %sFilterCancelSendNetBufferListsHandler: %p %sInitiateOffloadCompleteHandler: %p %sTerminateOffloadCompleteHandler: %p %sUpdateOffloadCompleteHandler: %p %sInvalidateOffloadCompleteHandler: %p %sQueryOffloadCompleteHandler: %p %sIndicateOffloadEventHandler: %p %sTcpOffloadSendCompleteHandler: %p %sTcpOffloadReceiveCompleteHandler: %p %sTcpOffloadDisconnectCompleteHandler: %p %sTcpOffloadForwardCompleteHandler: %p %sTcpOffloadEventHandler: %p %sTcpOffloadReceiveIndicateHandler: %p %sInitiateOffloadHandler: %p %sTerminateOffloadHandler: %p %sUpdateOffloadHandler: %p %sInvalidateOffloadHandler: %p %sQueryOffloadHandler: %p %sTcpOffloadReceiveReturnHandler: %p %sDirectOidRequestHandler: %p %sDirectOidRequestCompleteHandler: %p %sCancelDirectOidRequestHandler: %p %sTcpOffloadSendHandler: %p %sTcpOffloadReceiveHandler: %p %sTcpOffloadDisconnectHandler: %p %sTcpOffloadForwardHandler: %p %sProvider[%d]: %pQueryObjectHandler: %p %sSetObjectHandler: %p %sFilterDriverBlock[%d]InitiateOffloadHandler: %p %sTerminateOffloadHandler: %p %sUpdateOffloadHandler: %p %sInvalidateOffloadHandler: %p %sQueryOffloadHandler: %p %sTcpOffloadReceiveReturnHandler: %p %sTcpOffloadSendHandler: %p %sTcpOffloadReceiveHandler: %p %sTcpOffloadDisconnectHandler: %p %sTcpOffloadForwardHandler: %p %sClCreateVcHandler: %p %sClDeleteVcHandler: %p %sClOidRequestHandler: %p %sClOidRequestCompleteHandler: %p %sClOpenAfCompleteHandlerEx: %p %sClCloseAfCompleteHandler: %p %sClRegisterSapCompleteHandler: %p %sClDeregisterSapCompleteHandler: %p %sClMakeCallCompleteHandler: %p %sClModifyCallQoSCompleteHandler: %p %sClCloseCallCompleteHandler: %p %sClAddPartyCompleteHandler: %p %sClDropPartyCompleteHandler: %p %sClIncomingCallHandler: %p %sClIncomingCallQoSChangeHandler: %p %sClIncomingCloseCallHandler: %p %sClIncomingDropPartyHandler: %p %sClCallConnectedHandler: %p %sClNotifyCloseAfHandler: %p %sCmCreateVcHandler: %p %sCmDeleteVcHandler: %p %sCmOpenAfHandler: %p %sCmCloseAfHandler: %p %sCmRegisterSapHandler: %p %sCmDeregisterSapHandler: %p %sCmMakeCallHandler: %p %sCmCloseCallHandler: %p %sCmIncomingCallCompleteHandler: %p %sCmAddPartyHandler: %p %sCmDropPartyHandler: %p %sCmActivateVcCompleteHandler: %p %sCmDeactivateVcCompleteHandler: %p %sCmModifyCallQoSHandler: %p %sCmOidRequestHandler: %p %sCmOidRequestCompleteHandler: %p %sCmNotifyCloseAfCompleteHandler: %p %sDriverVersion: %XCoCreateVcHandler: %p %sCoDeleteVcHandler: %p %sCoActivateVcHandler: %p %sCoDeactivateVcHandler: %p %sCoSendNetBufferListsHandler: %p %sCoRequestHandler: %p %sCoOidRequestHandler: %p %sInitiateOffloadHandler: %p %sTerminateOffloadHandler: %p %sUpdateOffloadHandler: %p %sInvalidateOffloadHandler: %p %sQueryOffloadHandler: %p %sTcpOffloadSendHandler: %p %sTcpOffloadReceiveHandler: %p %sTcpOffloadDisconnectHandler: %p %sTcpOffloadForwardHandler: %p %sTcpOffloadReceiveReturnHandler: %p %sAddDeviceHandler: %p %sRemoveDeviceHandler: %p %sFilterResourceRequirementsHandler: %p %sStartDeviceHandler: %p %sServiceName: %SCoCreateVcHandler: %p %sCoDeleteVcHandler: %p %sCoActivateVcHandler: %p %sCoDeactivateVcHandler: %p %sCoSendNetBufferListsHandler: %p %sCoRequestHandler: %p %sCoOidRequestHandler: %p %sInitiateOffloadHandler: %p %sTerminateOffloadHandler: %p %sUpdateOffloadHandler: %p %sInvalidateOffloadHandler: %p %sQueryOffloadHandler: %p %sTcpOffloadSendHandler: %p %sTcpOffloadReceiveHandler: %p %sTcpOffloadDisconnectHandler: %p %sTcpOffloadForwardHandler: %p %sTcpOffloadReceiveReturnHandler: %p %sAddDeviceHandler: %p %sRemoveDeviceHandler: %p %sFilterResourceRequirementsHandler: %p %sStartDeviceHandler: %p %sOpenNDKAdapterHandler: %p %sCloseNDKAdapterHandler: %p %sIdleNotificationHandler: %p %sCancelIdleNotificationHandler: %p %sAllocateNetBufferListForwardingContextHandler: %p %sFreeNetBufferListForwardingContextHandler: %p %sAddNetBufferListDestinationHandler: %p %sSetNetBufferListSourceHandler: %p %sGrowNetBufferListDestinationsHandler: %p %sGetNetBufferListDestinationsHandler: %p %sUpdateNetBufferListDestinationsHandler: %p %sCopyNetBufferListInfoHandler: %p %sReferenceSwitchNicHandler: %p %sDereferenceSwitchNicHandler: %p %sReferenceSwitchPortHandler: %p %sDereferenceSwitchPortHandler: %p %sReportFilteredNetBufferListsHandler: %p %sImageName: %SSetNetBufferListSwitchContextHandler: %p %sGetNetBufferListSwitchContextHandler: %p %snetio legacy handler %p %sread netio legacy handler failed, error %d, status %Xread netio legacy handler failed, error %d%p %sread netio WfpNblInfoDispTable failed, error %d, status %Xread netio WfpNblInfoDispTable failed, error %dnetio MacShim %p %sWfpShim[%d] %p %sUnknown WFP callout size %dWFP callout[%d]:ClassifyCallback: %p %sNotifyCallback: %p %suFlowDeleteFunction: %p %sException %X on sysptr seed reading at %pDecode system scheme - %sDecode scheme - %sCannot read my process cookie, error %XTrace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X (%p) %sTrace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %pSystemFunction%3.3d (%p) %sPFNCLIENT.%s patched by %s (%p)PFNCLIENT.%s patched %pcheck_user32_pfnclient: exception %X occuredPFNCLIENTWORKER.%s patched by %s (%p)PFNCLIENTWORKER.%s patched %pConsoleCtrlHandler[%d]: %s (%p)ConsoleCtrlHandler[%d]: %p UNKNOWNConsoleCtrlHandler: %s (%p)UnhandledExceptionFilter: %s (%p)ShimModule: %s (%p)RtlpStartThreadFunc: %s (%p)RtlpExitThreadFunc: %s (%p)RtlpUnhandledExceptionFilter: %s (%p)RtlSecureMemoryCacheCallback: %s (%p)TppLogpRoutine: %s (%p)CsrServerApiRoutine: %s (%p)LdrpManifestProberRoutine: %s (%p)LdrpCreateActCtxLanguage: %s (%p)LdrpReleaseActCtx: %s (%p)LdrpAppCompatDllRedirectionCallbackFunction: %s (%p)%s%s!%s patched by %s (addr %p)%s%s.%d patched by %s (addr %p)%s%s.%d patched, addr %pPID %d trace callbacks: %dTrace[%d] %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X %p %sProcess PID %d has the same token as system process: %p !!!Process PID %d token: %p%p %s %8X%p %s %8XCheckProc: cannot get modules list for PID %d (%S), error %d, ntstatus %XCheckProc: cannot get modules list for PID %d (%S), error %dCheckProcess PID %d (%S):PEB.PostProcessInitRoutine: %p %sPEB.PostProcessInitRoutine: %p UNKNOWNPEB.pShimData: %pPEB.AppCompat: %pPEB.FastPebLockRoutine: %p %sPEB.FastPebLockRoutine: %p UNKNOWNPEB.FastPebUnlockRoutine: %p %sPEB.FastPebUnlockRoutine: %p UNKNOWNModule: %s at %pCannot read %s, PID %d, error %dPID %d: LSA SP %s has %d patched functions in SECPKG_FUNCTION_TABLE:PID %d: ncrypt has %d patched functionsPID %d: mswsock has %d patched functions in SockProcTablePID %d: mswsock has %d patched functions in NspVectorPID %d: mswsock has %d patched MSAFD functionsSHAREDINFO.aheList: %pPID %d: ntdsa has %d patched functionsPID %d - ole32 hooked by %sPID %d - ole32 hooked by unknown module, addr %pPID %d: rpcrt4 has %d patched functionsPID %d: basesrv has %d patched user functionsPID %d: winsrv has %d patched user functionsPID %d: winsrv has %d patched cons functionsPID %d: lsasrv has %d patched functionsPID %d: lsasrv has %d patched functions in LsapSspiExtensionPID %d: lsasrv has %d patched functions in LsapLookupExtensionPID %d: lsasrv has %d patched functions in LsapLsasrvIfTableCannot alloc %X bytes for EAT checking of %s, PID %dCannot read EAT of %s, PID %dCannot alloc %X bytes for checking section %s of %s, PID %dCannot read section %s content %X bytes of %s, PID %dCannot make section %s of %s, PID %dModule %s section %s has %X patched bytes, PID %dPID %d: user32 has %d patched imm32 functionsPID %d: advapi32 has %d patched functionsPID %d: kernel32 has %d patched functionsShimHandler[%d]: %p %sShimHandler[%d]: %p UNKNOWN, located at %pApplicationRecoveryCallback: %s (%p)%s, PID %d:Cannot alloc %X bytes for IAT checking of %s, PID %dCannot read IAT (size %X at %p) of %s, PID %dCannot find function %s.%s for module %s process %dCannot find function %s.%d for module %s process %dIAT Patched %s.%s in module %s process %d by %sIAT Patched %s.%s in module %s process %d, addr %pIAT Patched %s.%d in module %s process %d by %sIAT Patched %s.%d in module %s process %dCannot alloc %X bytes for delayed IAT checking of %s, PID %dCannot read delayed IAT (size %X at %p) of %s, PID %dCannot find delayed function %s.%s for module %s process %dCannot find delayed function %s.%d for module %s process %dLdrpDllNotificationList: %d%p %sRead %d QueuedWorkerItems:[%d] %p %scheck_drivers_reinit: cannot read size of list, error %d, status %Xcheck_drivers_reinit: cannot read size of list, error %dcheck_drivers_reinit: cannot alloc %X bytescheck_drivers_reinit: cannot read list, error %d, ntstatus %Xcheck_drivers_reinit: cannot read list, error %d[%d] Drv %p %s routine %p %sread_shutdown_notificators: cannot read size of %s, error %d, status %Xread_shutdown_notificators: cannot read size of %s, error %dread_shutdown_notificators: cannot alloc %X bytesread_shutdown_notificators: cannot read %s, error %d, ntstatus %Xread_shutdown_notificators: cannot read %s, error %d[%d] DevObj %p Drv %p (addr %p) %s[%d] DevObj %p Drv %p %sMailSlot: %S, server %d (%S)MailSlot: %S, server %dNamedPipe: %S, server %d (%S)NamedPipe: %S, server %dFlags: %X, server %d (%S)Flags: %X, creator %d, server %dFlags: %X, server %dEndpoints: %dEndpoint %S PID %d (%S):Endpoint %S:RPC controls: %d%S: %S%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%dCannot load kernel %sUnknown scheduler: ReadySummary %X DispatcherReadyListHead %XUnknown scheduler: ReadySummary %X DeferredReadyListHead %XUnknown scheduler: ReadySummary %XReaded %d threads, total %dThread %p ProcID %X ThreadID %X Win32Thread %p %sThread %p ProcID %X ThreadID %X Priority %d Win32Thread %pThread %p ProcID %X ThreadID %X %sThread %p ProcID %X ThreadID %X Priority %dreading count of threads on processor %d failed, error %X%d threadsreading of threads on processor %d failed, error %XScheduler index %dreading count of threads failed, error %Xreading of threads failed, error %XCannot find ETHREAD.ServiceTableUnknown version of ETHREAD, offset %XCannot alloc %X bytes for ProcessesAndThreadsInformationCannot realloc %X bytes for ProcessesAndThreadsInformationProcessesAndThreadsInformation failed, error %Xread_sdt for threadID %X failed, error %d, status %Xread_sdt for threadID %X failed, error %dProcessID %X (%S) ThreadID %X SDT %p %sProcessID %X ThreadID %X SDT %p %sread_thread_token for threadID %X failed, error %d, status %Xread_thread_token for threadID %X failed, error %dProcessID %X (%S) ThreadID %X token %p ImpersonationLevel %dProcessID %X ThreadID %X token %p ImpersonationLevel %dCannot detect ETHREAD.StartAddressUnknown kernel %s, StartAddress %X, IrpList %X, StackLimit %X, StackBase %XUnknown kernel %s, StartAddress %X, StackLimit %X, StackBase %XUnknown kernel %s, StartAddress %X, IrpList %XUnknown kernel %s, StartAddress %XCannot read count of system threads, ntstatus %XCannot alloc %d bytesCannot read system threads, ntstatus %X%d System ThreadsThread %p Start %p %c stack %p limit %p %sread IPSec status failed, error %d, status %Xread IPSec status failed, error %dIPSec status %XIPSecHandler: %p %sIPSecQueryStatus: %p %sIPSecSendCmplt: %p %sIPSecNdisStatus: %p %sIPSecRcvFWPacket: %p %scheck_tdi_pnp_clnts: cannot read size of clnts list, error %d, ntstatus %Xcheck_tdi_pnp_clnts: cannot read size of clnts list, error %dcheck_tdi_pnp_clnts: cannot alloc %X bytescheck_tdi_pnp_clnts: cannot read clnts list, error %d, ntstatus %Xcheck_tdi_pnp_clnts: cannot read clnts list, error %dTDI PnP clients: %d (readed %d)[%d]: version %X %SPnPPowerHandler: %p %sBindHandler: %p %sUnBindHandler: %p %sAddAddressHandler: %p %sDelAddressHandler: %p %sMicrosoft-Windows-Windows Firewall With Advanced SecurityMicrosoft-Windows-Kernel-BootMicrosoft-Windows-EQoSMicrosoft-Windows-XWizardsASP.NET EventsMicrosoft-Windows-UIRibbonMicrosoft-Windows-WPD-CompositeClassDriverMicrosoft-Windows-Wired-AutoConfigMicrosoft-Windows-PrintServiceMicrosoft-Windows-ApplicationExperience-LookupServiceTriggerMicrosoft-Windows-IDCRLMicrosoft-Windows-MPS-DRVMicrosoft-Windows-P2P-MeshMicrosoft-Windows-TabletPC-MathRecognizerMicrosoft-Windows-Spell-CheckingMicrosoft-Windows-FaxMicrosoft-Windows-GroupPolicyMicrosoft-Windows-CrashdumpMicrosoft-Windows-PrintSpoolerMicrosoft-Windows-LanguagePackSetupMicrosoft-Windows-OneXMicrosoft-Windows-OfflineFiles-CscApiMicrosoft-Windows-ADSIMicrosoft-Windows-Dhcp-ClientMicrosoft-Windows-CertificateServicesClient-AutoEnrollmentMicrosoft-Windows-NlaSvcMicrosoft-Windows-Diagnosis-MSDEMicrosoft-Windows-SpoolerWin32SPLMicrosoft-Windows-SPB-ClassExtensionMicrosoft-Windows-Kernel-MemoryMicrosoft-Windows-Application Server-ApplicationsMicrosoft-Windows-MUIMicrosoft-Windows-P2P-CollabMicrosoft-Windows-Security-NetlogonMicrosoft-Windows-SQM-EventsMicrosoft-Windows-USB-USBPORTMicrosoft-Windows-SendToMicrosoft-Windows-AITMicrosoft-Windows-P2P-CRPPrintFilterPipelineSvc_ObjectsGuidMicrosoft-Windows-IME-JPPREDMicrosoft-Windows-WMPMicrosoft-Windows-Eqos-SQM-ProviderMSDADIAG.ETWMicrosoft-Windows-Processor-AggregatorMicrosoft-Windows-ErrorReportingConsoleMicrosoft-Windows-SmartCard-TPM-VCard-ModuleMicrosoft-Windows-User Profiles ServiceMicrosoft-Windows-Crypto-CNGMicrosoft-Windows-LinkLayerDiscoveryProtocolMicrosoft-Windows-TaskbarCPLMicrosoft-Windows-Networking-CorrelationMicrosoft-Windows-RestartManagerMicrosoft-Windows-WMPDMCCoreMicrosoft-Windows-TCPIPMicrosoft-Windows-MSDTCMicrosoft-Windows-Resources-MrmBcMicrosoft-Windows-Time-ServiceMicrosoft-Windows-HomeGroup-ProviderServiceMicrosoft-Windows-DriverFrameworks-UserModeMicrosoft-Windows-Runtime-NetworkingMicrosoft-Windows-Network-Connection-BrokerMicrosoft-Windows-Shell-AppWizCplMicrosoft-Windows-PDCMicrosoft-Windows-BiometricsMicrosoft-Windows-IME-SCDICCOMPILERMicrosoft-Windows-WininitMicrosoft-Windows-Dwm-DwmMicrosoft-Windows-Photo-Image-CodecMicrosoft-Windows-TaskSchedulerMicrosoft-Windows-oskMicrosoft-Windows-Kernel-PowerTriggerMicrosoft-Windows-EventLog-WMIProviderMicrosoft-Windows-IME-OEDCompilerMicrosoft-Windows-WER-SystemErrorReportingMicrosoft-Windows-DeplorchMicrosoft-Windows-SPB-HIDI2CMicrosoft-Windows-UxThemeMicrosoft-Windows-BfeTriggerProviderMicrosoft-Windows-Media-StreamingMicrosoft-Windows-Remotefs-UTProviderMicrosoft-Windows-Ntfs-SQMMicrosoft-Windows-User-PnPMicrosoft-Windows-AltTabMicrosoft-Windows-Kernel-StoreMgrMicrosoft-Windows-WindowsColorSystemMicrosoft-Windows-RemoteDesktopServices-RemoteFX-VM-User-Mode-TransportMicrosoft-Windows-MSMPEG2ADECMicrosoft-Windows-TerminalServices-PnPDevicesMicrosoft-Windows-GettingStartedMicrosoft-Windows-NarratorWindows Wininit TraceMicrosoft-Windows-FileHistory-UIMicrosoft-Windows-MediaFoundation-PlayAPIMicrosoft-Windows-CertificateServicesClient-Lifecycle-SystemMicrosoft-Windows-BitLocker-Driver-PerformanceMicrosoft-Windows-PerfProcMicrosoft-Windows-Resource-Leak-DiagnosticMicrosoft-Windows-WebServicesMicrosoft-Windows-FileHistory-ServiceMicrosoft-Windows-MediaEngineMicrosoft-Windows-StartupRepairMicrosoft-Windows-Security-IdentityStoreMicrosoft-Windows-IME-SCSettingMicrosoft-Windows-FileHistory-EventListenerMicrosoft-Windows-Program-Compatibility-AssistantMicrosoft-Windows-DesktopActivityModeratorMicrosoft-Windows-MemoryDiagnostics-ScheduleMicrosoft-Windows-FileHistory-EngineMicrosoft-Windows-PerfDiskMicrosoft-Windows-OOBE-Machine-CoreMicrosoft-Windows-WLAN-AutoConfigMicrosoft-Windows-FileHistory-ConfigManagerMicrosoft-Windows-Search-ProfileNotifyMicrosoft-Windows-PerfCtrsUMPass Driver TraceMicrosoft-Windows-FileHistory-CatalogMicrosoft-Windows-WlanDlgMicrosoft-Windows-CDROMMicrosoft-Windows-Crypto-NCryptCertificate Services Client CredentialRoaming TraceMicrosoft-Windows-CredUIWindows Firewall ServiceMicrosoft-Windows-FileHistory-CoreMicrosoft-Windows-Direct3D11Microsoft-Windows-DirectoryServices-DeploymentMicrosoft-Windows-All-User-Install-AgentMicrosoft-Windows-Kernel-Licensing-StartServiceTriggerMicrosoft-Windows-ServerManager-ManagementProviderMicrosoft-Windows-Diagnosis-ScriptedDiagnosticsProviderMicrosoft-Windows-IIS-W3SVC-WPMicrosoft-Windows-TerminalServices-MediaRedirection-DShowMicrosoft-Windows-Rdms-UIMicrosoft-Windows-Feedback-Service-TriggerProviderMicrosoft-Windows-EventlogMicrosoft-Windows-CodeIntegrityMicrosoft-Windows-WPDClassInstallerMicrosoft-Windows-NetworkAccessProtectionMicrosoft-Windows-UIAutomationCoreMicrosoft-Windows-StartLmhostsMicrosoft-Windows-IME-BrokerMicrosoft-Windows-Kernel-ProcessMicrosoft-Windows-CertificateServicesClientMicrosoft-Windows-AppXDeploymentMicrosoft-Windows-Shell-CoreMicrosoft-Windows-Anytime-UpgradeMicrosoft-Windows-PCIMicrosoft-Windows-WPD-MTPBTMicrosoft-Windows-CertificationAuthorityClient-CertCliMicrosoft-Windows-Srv2Microsoft-Windows-TunnelDriver-SQM-ProviderMicrosoft-Windows-Security-Licensing-SLCMicrosoft-Windows-ATAPortMicrosoft-Windows-RecoveryMicrosoft-Windows-GenericRoamingMicrosoft-Windows-Sdbus-SQMMicrosoft-Windows-DirectCompositionMicrosoft-Windows-P2PIMSvcMicrosoft-Windows-WCN-Config-RegistrarMicrosoft-Windows-WPD-APIMicrosoft-Windows-P2P-PNRPMicrosoft-Windows-DeviceUxWindows Mobile Performance HooksMicrosoft-Windows-ProcessStateManagerWindows Connect NowMicrosoft-Windows-Networking-RealTimeCommunicationMicrosoft-Windows-EventSystemMicrosoft-Windows-SpaceportWindows Mobile Remote APIMicrosoft-Windows-Dhcp-Nap-Enforcement-ClientMicrosoft-Windows-WinNatWindows Mobile AirSync Engine 2Microsoft-Windows-WCN-Config-Registrar-SecureWindows Mobile AirSync Engine 1Microsoft-Windows-Security-KerberosWindows Mobile ActiveSync EngineMicrosoft-Windows-WSC-SRVMicrosoft-Windows-Eventlog-ForwardPluginWindows Mobile Serial ConnectivityMicrosoft-Windows-TerminalServices-SessionBroker-ClientMicrosoft-Windows-WMPNSS-PublicAPIWindows Mobile Desktop PassthroughMicrosoft-Windows-RPC-EventsMicrosoft-Windows-LanguageProfileMicrosoft-Windows-Anytime-Upgrade-EventsMicrosoft-Windows-Management-UIMicrosoft-Windows-SMBClientMicrosoft-Windows-TerminalServices-RdpSoundDriverMicrosoft-Windows-Dwm-ApiMicrosoft-Windows-QoS-qWAVEMicrosoft-Windows-Kernel-Tm-TriggerMicrosoft-Windows-IPNATMicrosoft-Windows-NetworkBridgeMicrosoft-Windows-MPS-CLNTMicrosoft-Windows-Diagnosis-ScheduledMicrosoft-Windows-WMPNSS-ServiceMicrosoft-Windows-DxpTaskRingtoneMicrosoft-Windows-Kernel-AppCompatMicrosoft-Windows-TimeBrokerMicrosoft-Windows-DeviceConfidenceMicrosoft-Windows-Shell-ShwebsvcMicrosoft-Windows-Diagnostics-PerformanceWindows NetworkMap TraceMicrosoft-Windows-TerminalServices-PrintersMicrosoft-Windows-AppLockerMicrosoft-Windows-AudioMicrosoft-Windows-LLTD-MapperIOMicrosoft-Windows-HotspotAuthMicrosoft-Windows-Firewall-CPLMicrosoft-Windows-Kernel-IoTraceMicrosoft-Windows-PerflibMicrosoft-Windows-BootUXMicrosoft-Windows-WMPDMCUIMicrosoft-Windows-DiskMicrosoft-Windows-IME-JPLMPMicrosoft-Windows-Security-SPP-UX-NotificationsMicrosoft-Windows-TerminalServices-ClientActiveXCoreMicrosoft-Windows-IIS-IISResetMicrosoft-Windows-WindowsUIImmersiveWindows Firewall Control PanelMicrosoft-Windows-DeviceSetupManagerMicrosoft-Windows-EnrollmentPolicyWebServiceMicrosoft-Windows-IME-RoamingMicrosoft-Windows-SetupQueueMicrosoft-Windows-SmartCard-AuditMicrosoft-Windows-ServicingMicrosoft-Windows-ACL-UIMicrosoft-Windows-WWAN-CFEMicrosoft-Windows-FCRegSvcMicrosoft-Windows-IIS-IisMetabaseAuditMicrosoft-Windows-Kernel-WDIMicrosoft-Windows-TabletPC-MathInputMicrosoft-Windows-Kernel-GeneralWindows Media Player TraceMicrosoft-Windows-DxpTaskDLNAMicrosoft-Windows-User Profiles GeneralMicrosoft-Windows-Kernel-WSService-StartServiceTriggerMicrosoft-Windows-WebAuthMicrosoft-Windows-API-TracingMicrosoft-Windows-FunctionDiscoveryMicrosoft-Windows-StickyNotesMicrosoft-Windows-WCN-WscEapPeer-TraceMicrosoft-Windows-QoS-WMI-DiagMicrosoft-Windows-NetworkProvisioningMicrosoft-Windows-Network-DataUsageMicrosoft-Windows-AppSruProvMicrosoft-Windows-WebcamExperienceMicrosoft-Windows-EaseOfAccessMicrosoft-Windows-Spellchecking-HostMicrosoft-Windows-IME-CandidateUIMicrosoft-Windows-TPM-WMIMicrosoft-Windows-Security-SPPMicrosoft-Windows-DirectShow-KernelSupportMicrosoft-Windows-Diagnosis-AdvancedTaskManagerMicrosoft-Windows-ThemeCPLWindows Mobile Co-installerMicrosoft-Windows-MPRMSGMicrosoft-Windows-EnhancedStorage-EhStorCertDrvMicrosoft-Windows-NdisImPlatformEventProviderMicrosoft-Windows-FunctionDiscoveryHostMicrosoft-Windows-MediaFoundation-MSVideoDSPMicrosoft-Windows-IME-JPTIPWindows Kernel TraceMicrosoft-SQLServerDataToolsMicrosoft-Windows-ASN1Microsoft-Windows-Crypto-BCryptMicrosoft-Windows-HealthCenterCPLMicrosoft-Windows-XAMLMicrosoft-Windows-PDFReaderMicrosoft-Windows-TerminalServices-ServerUSBDevicesMicrosoft-Windows-WWAN-SVC-EVENTSMicrosoft-Windows-Search-ProtocolHandlersMicrosoft-Windows-IdCtrlsMicrosoft-Windows-User-ControlPanelMicrosoft-Windows-Runtime-MediaMicrosoft-Windows-CAPI2Windows Mobile Sync HandlersMicrosoft-Windows-PowerCfgMicrosoft-Windows-SrumTelemetryMicrosoft-Windows-Base-Filtering-Engine-ConnectionsMicrosoft-Windows-SidebarMicrosoft-Windows-NDF-HelperClassDiscoveryMicrosoft-Windows-PerfNetMicrosoft-Windows-PortableDeviceStatusProviderMicrosoft-Windows-TabletPC-Platform-ManipulationsMicrosoft-Windows-Subsys-SMSSMicrosoft-Windows-LDAP-ClientMicrosoft-Windows-Security-SPP-UX-GCMicrosoft-Windows-Media Center ExtenderMicrosoft-Windows-DiskDiagnosticMicrosoft-Windows-TSF-msutbMicrosoft-Windows-Reliability-Analysis-Agent{B6501BA0-C61A-C4E6-6FA2-A4E7F8C8E7A0}Microsoft-Windows-Kernel-Processor-PowerMicrosoft-Windows-NCSIMicrosoft-Windows-NetworkConnectivityStatusMicrosoft-Windows-wmvdecodMicrosoft-Windows-ServiceTriggerPerfEventProviderMicrosoft-Windows-Service Pack InstallerMicrosoft-Windows-Bluetooth-HidGattMicrosoft-Windows-TabletPC-Platform-Input-NinputMicrosoft-Windows-Tcpip-SQM-ProviderMicrosoft-Windows-MPS-SRVMicrosoft-Windows-KnownFoldersMicrosoft-Windows-NAPIPSecEnfMicrosoft-Windows-EnrollmentWebServiceMicrosoft-Windows-Deduplication-ChangeMicrosoft-Windows-OfflineFiles-CscFastSyncMicrosoft-Windows-UxInitMicrosoft-Windows-BranchCacheClientEventProviderMicrosoft-Windows-ForwardingMicrosoft-Windows-RPC-Proxy-LBSMicrosoft-Windows-Kernel-DiskMicrosoft-Windows-TriggerEmulatorProviderMicrosoft-Windows-SystemHealthAgentMicrosoft-Windows-Memory-Diagnostic-Task-HandlerMicrosoft-Windows-Winsock-WS2HELPMicrosoft-Windows-ThemeUIMicrosoft-Windows-TerminalServices-MediaRedirectionMicrosoft-Windows-TerminalServices-ClientUSBDevicesMicrosoft-Windows-TabletPC-CoreInkRecognitionMicrosoft-Windows-COMMicrosoft-Windows-PnPMgrTriggerProviderMicrosoft-Windows-LoadPerfMicrosoft-Windows-System-RestoreMicrosoft-Windows-UserAccountControlMicrosoft-Windows-Services-SvchostMicrosoft-Windows-PushNotifications-DeveloperMicrosoft-Windows-LiveIdMicrosoft-Windows-Security-SPP-UXMicrosoft-Windows-VANMicrosoft-Windows-FirstUX-PerfInstrumentationMicrosoft-Windows-Kernel-TmMicrosoft-Windows-Kernel-ShimEngineMicrosoft-Windows-EapHostMicrosoft-Windows-CertPolEngMicrosoft-Windows-MsLbfoEventProviderMicrosoft-Windows-ComplusMicrosoft-Windows-EFSMicrosoft-Windows-WwaHostMicrosoft-Windows-ServerManagerMicrosoft-Windows-ComDlg32Microsoft-Windows-MP4SDECDMicrosoft-Windows-PeopleNearMeMicrosoft-Windows-SmartCard-Bluetooth-ProfileMicrosoft-Windows-TZUtilMicrosoft-Windows-ApplicationExperience-SwitchBackMicrosoft-Windows-UI-Input-InkingMicrosoft-Windows-VDRVROOTWindows Firewall NetShell PluginWindows Firewall APIMicrosoft-Windows-Kernel-AcpiMicrosoft-Windows-WinRMMicrosoft-Windows-Direct3D10_1Microsoft-Windows-Kernel-LicensingSqmMicrosoft-Windows-SpoolerSpoolssMicrosoft-Windows-FilterManagerMicrosoft-Windows-ActionQueueMicrosoft-Windows-IME-KRAPIMicrosoft-Windows-Resource-Exhaustion-DetectorMicrosoft-Windows-ApplicationExperienceInfrastructureMicrosoft-Windows-StorSqmMicrosoft-Windows-SearchMicrosoft-Windows-HttpEventMicrosoft-Windows-AxInstallServiceMicrosoft-Windows-Diagnosis-PerfHostMicrosoft-Windows-InternationalMicrosoft-Windows-CertificateServicesClient-CredentialRoamingMicrosoft-Windows-SoftwareRestrictionPoliciesMicrosoft-Windows-Windows DefenderMicrosoft-Windows-ShareMedia-ControlPanelMicrosoft-Windows-CertificateServicesClient-Lifecycle-UserMicrosoft-Windows-WPD-MTPUSMicrosoft-Windows-DirectWriteMicrosoft-Windows-RPCSSMicrosoft-Windows-DeviceSyncMicrosoft-Windows-NcdAutoSetupMicrosoft-Windows-Diagnosis-PCWMicrosoft-Windows-DistributedCOMATA Port Driver Tracing ProviderMicrosoft-Windows-WebdavClient-LookupServiceTriggerMicrosoft-Windows-USB-USBXHCIMicrosoft-Windows-Diagnosis-PLAMicrosoft-Windows-WlanConnMicrosoft-Windows-WinlogonMicrosoft-Windows-stobjectMicrosoft-Windows-Mobile-Broadband-Experience-SmsRouterMicrosoft-Windows-D3D10Level9Microsoft-Windows-WAS-ListenerAdapterMicrosoft-Windows-ServerManager-MultiMachineMicrosoft-Windows-AppxPackagingOMMicrosoft-Windows-PushNotifications-PlatformMicrosoft-Windows-OOBE-Machine-Plugins-WirelessMicrosoft-Windows-IME-JPAPISBP2 Port Driver Tracing ProviderMicrosoft-Windows-BranchCacheEventProviderMicrosoft-Windows-Immersive-Shell-APIMicrosoft-Windows-ntshruiMicrosoft-Windows-KPSSVCMicrosoft-Windows-BitLocker-DrivePreparationToolMicrosoft-Windows-EapMethods-SimMicrosoft-Windows-Shell-ZipFolderMicrosoft-Windows-Search-CoreMicrosoft-Windows-OfflineFiles-CscNetApiMicrosoft-Windows-Diagnosis-WDIMicrosoft-Windows-PortableDeviceSyncProviderMicrosoft-Windows-Diagnostics-PerfTrack-CountersMicrosoft-Windows-Speech-TTSMicrosoft-Windows-Component-Resources-MrmCore-EventsMicrosoft-Windows-BranchCacheMicrosoft-Windows-SystemEventsBrokerMicrosoft-Windows-VolumeControlMicrosoft-Windows-Win32kMicrosoft-Windows-Kernel-WHEAMicrosoft-Windows-P2P-MeetingsMicrosoft-Windows-Diagnosis-WDCMicrosoft-Windows-Serial-ClassExtensionMicrosoft-Windows-KPSSVC-WPPMicrosoft-Windows-CertificateServices-DeploymentMicrosoft-Windows-PerfOSMicrosoft-Windows-ResetEngMicrosoft-Windows-Runtime-GraphicsMicrosoft-Windows-IPSEC-SRVMicrosoft-Windows-CorruptedFileRecovery-ServerWindows Mobile Bluetooth ConnectivityMicrosoft-Windows-DLNA-NamespaceMicrosoft-Windows-WLAN-MediaManagerCertificate Services Client TraceMicrosoft-Windows-BranchCacheSMBMicrosoft-Windows-PrintService-USBMonMicrosoft-Windows-OOBE-MachineMicrosoft-Windows-DXPMicrosoft-Windows-Immersive-ShellMicrosoft-Windows-OOBE-Machine-PluginsMicrosoft-Windows-Reliability-Analysis-EngineMicrosoft-Windows-Application-ExperienceMicrosoft-Windows-KdsSvcMicrosoft-Windows-MediaFoundation-PlatformMicrosoft-Windows-Security-Configuration-WizardMicrosoft-Windows-DisplayColorCalibrationWindows Mobile Device Center BaseMicrosoft-Windows-WPD-MTPClassDriverMicrosoft-Windows-DNS-ClientMicrosoft-Windows-MSDTC ClientMicrosoft-Windows-NDIS-PacketCaptureWindows Remote Management TraceMicrosoft-Windows-MSPaintMicrosoft-Windows-HomeGroup-ListenerServiceMicrosoft-Windows-Sensor-Service-TriggerMicrosoft-Windows-EapMethods-TtlsMicrosoft-Windows-Remotefs-SmbMicrosoft-Windows-SMBWitnessClientMicrosoft-Windows-USB-USBHUBMicrosoft-Windows-DirectWrite-FontCacheMicrosoft-Windows-WindowsBackupMicrosoft-Windows-NWiFiMicrosoft-Windows-WER-DiagMicrosoft-Windows-UACMicrosoft-Windows-LUAMicrosoft-Windows-AppIDMicrosoft-Windows-IIS-WMSVCMicrosoft-Windows-Shell-OpenWithMicrosoft-Windows-MediaFoundation-MFReadWriteMicrosoft-Windows-BrokerInfrastructureMicrosoft-Windows-Fault-Tolerant-HeapMicrosoft-Windows-Shell-DefaultProgramsMicrosoft-Windows-Dism-CliMicrosoft-Windows-SMBDirectMicrosoft-Windows-IME-SCTIPMicrosoft-Windows-EnergyEfficiencyWizardMicrosoft-Windows-ParentalControlsMicrosoft-Windows-Smartcard-ServerMicrosoft-Windows-FMSMicrosoft-Windows-Devices-LocationMicrosoft-Windows-LLTD-ResponderMicrosoft-Windows-MsLbfoSysEvtProvidersqlosMicrosoft-Windows-TerminalServices-RemoteConnectionManagerMicrosoft-Windows-SCPNPMicrosoft-Windows-WordpadWMI_Tracing_Client_OperationsMicrosoft-Windows-Security-Audit-Configuration-ClientMicrosoft-Windows-EFSADUWindows Notification Facility ProviderMicrosoft-Windows-DiagCplWindows NetworkItemFactory TraceMicrosoft-Windows-ApplicationExperience-CacheMicrosoft-Windows-ResourcePublicationMicrosoft-Windows-FailoverClustering-ClientMicrosoft-Windows-Runtime-Networking-BackgroundTransferMicrosoft-Windows-AppHostMicrosoft-Windows-NetAdapterCim-DiagMicrosoft-Windows-IIS-FTPMicrosoft-Windows-IphlpsvcMicrosoft-Windows-WinINetMicrosoft-Windows-TabletPC-InputPersonalizationMicrosoft-Windows-SpoolerFilterPipelineSVCMicrosoft-Windows-GlobalizationMicrosoft-Windows-Bits-ClientMicrosoft-Windows-WFPMicrosoft-Windows-ServicesMicrosoft-Windows-IdleTriggerProviderMicrosoft-Windows-DxgKrnlMicrosoft-Windows-HealthCenterMicrosoft-Windows-OtpCredentialProviderEvtMicrosoft-Windows-MemoryDiagnostics-ResultsMicrosoft-Windows-NcasvcMicrosoft-Windows-SystemSettingsMicrosoft-Windows-PDHMicrosoft-Windows-WMPNSSUIMicrosoft-Windows-BdeTriggerProviderMicrosoft-Windows-Diagnostics-PerfTrackMicrosoft-Windows-IIS-APPHOSTSVCMicrosoft-Windows-CoreWindowMicrosoft-Windows-HelpMicrosoft-Windows-WindowsUpdateClientMicrosoft-Windows-IIS-W3SVC-PerfCountersMicrosoft-Windows-WMIMicrosoft-Windows-TabletPC-Platform-Input-WispMicrosoft-Windows-ProcessExitMonitorMicrosoft-Windows-IME-JPSettingMicrosoft-Windows-Diagnosis-ScriptedMicrosoft-Windows-GroupPolicyTriggerProviderFile Kernel Trace; Operation Set 2Microsoft-Windows-IIS-ConfigurationMicrosoft-Windows-Diagnosis-TaskManagerMicrosoft-Windows-Diagnosis-DPSMicrosoft-Windows-UserPnpMicrosoft-Windows-Security-SPP-UX-GenuineCenter-LoggingMicrosoft-Windows-Schannel-EventsNetJoinMicrosoft-Windows-TabletPC-InputPanelMicrosoft-Windows-FileServices-ServerManager-EventProviderMicrosoft-Windows-MediaFoundation-PerformanceMicrosoft-Windows-EndpointTriggerProviderMicrosoft-Windows-IME-KRTIPMicrosoft-Windows-Mobile-Broadband-Experience-SmsApiMicrosoft-Windows-Hyper-V-NetvscMicrosoft-Windows-DirectSoundMicrosoft-Windows-TabletPC-Platform-Input-CoreMicrosoft-Windows-PushNotifications-InProcMicrosoft-Windows-Kernel-NetworkMicrosoft-Windows-DiskDiagnosticResolverMicrosoft-Windows-NdisImPlatformSysEvtProviderMicrosoft-Windows-MeetingSpaceMicrosoft-Windows-Base-Filtering-Engine-Resource-FlowsMicrosoft-Windows-RasServerMicrosoft-Windows-VHDMPMicrosoft-Windows-WindowsSystemAssessmentToolMicrosoft-Windows-DCLocatorMicrosoft-Windows-Diagnosis-MSDTMicrosoft-Windows-WLGPASQLSRV32.1Microsoft-Windows-CertificateServicesClient-CertEnrollMicrosoft-Windows-IME-TCCOREMicrosoft-Windows-SmartCard-Bluetooth-TransportMicrosoft-Windows-WMVENCODMicrosoft-Windows-mobsyncMicrosoft-Windows-EFSTriggerProviderMicrosoft-Windows-DUSERMicrosoft-Windows-DiskDiagnosticDataCollectorMicrosoft-Windows-DirectAccess-MediaManagerMicrosoft-Windows-DisplaySwitchMicrosoft-Windows-PackageStateRoamingMicrosoft-Windows-Crypto-DPAPIMicrosoft-Windows-IME-CustomerFeedbackManagerUIsqlserverMicrosoft-Windows-User-LoaderMicrosoft-Windows-NetworkProfileTriggerProviderMicrosoft-Windows-NetworkProfileWindows Firewall API - GPMicrosoft-Windows-CmiSetupMicrosoft-Windows-SysprepMicrosoft-Windows-WindeployMicrosoft-Windows-SetupMicrosoft-Windows-OobeLdrMicrosoft-Windows-SetupUGCMicrosoft-Windows-AuditMicrosoft-Windows-SetupClMicrosoft-Windows-WinsrvMicrosoft-Windows-WinHttpMicrosoft-Windows-RadioManagerMicrosoft-Windows-Websocket-Protocol-ComponentMicrosoft-Windows-WebIOMicrosoft-Windows-Dwm-CoreMicrosoft-Windows-Registry-SQM-ProviderMicrosoft-Windows-WHEA-LoggerMicrosoft-Windows-PeerToPeerDrtEventProviderMicrosoft-Windows-BitLocker-DriverMicrosoft-Windows-SettingSyncMicrosoft-Windows-Mobile-Broadband-Experience-Api-InternalMicrosoft-Windows-EnhancedStorage-EhStorTcgDrvMicrosoft-Windows-PowerShellMicrosoft-Windows-DirectShow-CoreMicrosoft-Windows-Kernel-PowerMicrosoft-Windows-msmpeg2vencMicrosoft-Windows-MPEG2_DLNA-EncoderMicrosoft-Windows-Remote-FileSystem-LogMicrosoft-Windows-Kernel-PnPMicrosoft-Windows-AppXDeployment-ServerMicrosoft-Windows-Folder RedirectionMicrosoft-Windows-OfflineFiles-CscUMMicrosoft-Windows-ServerManager-DeploymentProviderMicrosoft-Windows-ServiceReportingApiMicrosoft-Windows-StorDiagMicrosoft-Windows-IME-CustomerFeedbackManagerMicrosoft-Windows-Kernel-EventTracingMicrosoft-Windows-Kernel-BootDiagnosticsMicrosoft-Windows-DXGIMicrosoft-Windows-Build-RegDllMicrosoft-Windows-PNRPSvcMicrosoft-Windows-NduMicrosoft-Windows-FirewallMicrosoft-Windows-WcmsvcMicrosoft-Windows-OLEACCMicrosoft-Windows-MSDTC Client 2Microsoft-Windows-InputSwitchMicrosoft-Windows-Runtime-WebAPIMicrosoft-Windows-HALMicrosoft-Windows-International-RegionalOptionsControlPanelMicrosoft-Windows-RPCMicrosoft-Windows-MFH264EncMicrosoft-Windows-SharedAccess_NATMicrosoft-Windows-DeviceAssociationServiceMicrosoft-Windows-Bluetooth-MTPEnumMicrosoft-Windows-BitLocker-API{C5BFFE2E-9D87-D568-A09E-08FC83D0C7C2}Microsoft-Windows-IPMIProviderMicrosoft-Windows-IME-TIPMicrosoft-Windows-WindowsToGo-StartupOptionsMicrosoft-Windows-BackupMicrosoft-Windows-WMP-MediaDeliveryEngineMicrosoft-Windows-PrintBRMMicrosoft-Windows-ServerManager-ConfigureSMRemotingMicrosoft-Windows-Video-For-WindowsMicrosoft-Windows-ClearTypeTextTunerMicrosoft-Windows-Subsys-CsrMicrosoft-Windows-USB-UCXMicrosoft-Windows-RemoteApp and Desktop ConnectionsWindows Winlogon TraceMicrosoft-Windows-RasSstpMicrosoft-Windows-UAC-FileVirtualizationMicrosoft-Windows-ClassicSruMonMicrosoft-Windows-Security-IdentityListenerMicrosoft-Windows-WWAN-MM-EVENTSMicrosoft-Windows-MsiServerMicrosoft-Windows-PhotoAcqMicrosoft-Windows-Power-TroubleshooterMicrosoft-Windows-DxpTaskSyncProviderMicrosoft-Windows-Remotefs-RdbssMicrosoft-Windows-AppIDServiceTriggerMicrosoft-Windows-Kernel-FileMicrosoft-Windows-TSF-msctfMicrosoft-Windows-PowerCplMicrosoft-Windows-LanGPAMicrosoft-Windows-WWAN-MediaManagerMicrosoft-Windows-PrimaryNetworkIconMicrosoft-Windows-OfflineFilesMicrosoft-Windows-UIAnimationMicrosoft-Windows-Security-AuditingMicrosoft-Windows-WCN-Config-Registrar-Wizard-TraceMicrosoft-Windows-WWAN-NDISUIO-EVENTSMicrosoft-Windows-NetworkManagerTriggerProviderMicrosoft-Windows-Winsock-AFDMicrosoft-Windows-Remote-FileSystem-MonitorMicrosoft-Windows-WABSyncProvider.NET Common Language RuntimeMicrosoft-Windows-MSMPEG2VDECMicrosoft-Windows-DateTimeControlPanelWindows Firewall DriverMicrosoft-Windows-IIS-W3SVCMicrosoft-Windows-WWAN-UI-EVENTSMicrosoft-Windows-Speech-UserExperienceMicrosoft-Windows-Dism-ApiMicrosoft-Windows-Store-Client-UIMicrosoft-Windows-CalculatorMicrosoft-Windows-Shell-ConnectedAccountStateMicrosoft-Windows-PrintDialogsMicrosoft-Windows-Network-and-Sharing-CenterMicrosoft-Windows-Crypto-RNGMicrosoft-Windows-MSDTC 2Microsoft-Windows-SpellCheckerMicrosoft-Windows-propsysMicrosoft-Windows-WPD-MTPIPMicrosoft-Windows-DocumentsMicrosoft-Windows-StorPortMicrosoft-Windows-MagnificationMicrosoft-Windows-Shell-AuthUIMicrosoft-Windows-Dwm-RedirMicrosoft-Windows-BTH-BTHUSBMicrosoft-Windows-NtfsMicrosoft-Windows-SensMicrosoft-Windows-UserAccessLoggingMicrosoft-Windows-RemoteDesktopServices-RdpCoreTSMicrosoft-Windows-COM-PerfMicrosoft-Windows-StorageSpaces-BackgroundAgentMicrosoft-Windows-Kernel-PrefetchPortable Device Connectivity API TraceMicrosoft-Windows-RemoteAssistanceMicrosoft-Windows-MFMicrosoft-Windows-MediaFoundation-MSVProcMicrosoft-Windows-TBSMicrosoft-Windows-FeedbackToolMicrosoft-Windows-WlanPrefMicrosoft-Windows-OfflineFiles-CscDclUserMicrosoft-Windows-Http-SQM-ProviderMicrosoft-Windows-Wireless-Network-Setup-Wizard-TraceMicrosoft-Windows-MCTMicrosoft-Windows-HotStartMicrosoft-Windows-Diagnostics-NetworkingMicrosoft-Windows-SensorsMicrosoft-Windows-SmbServerMicrosoft-Windows-USB-USBHUB3Microsoft-Windows-Dot3MMMicrosoft-Windows-KernelStreamingMicrosoft-Windows-Mobile-Broadband-Experience-ApiMicrosoft-Windows-VolumeSnapshot-DriverMicrosoft-Windows-MobilityCenterMicrosoft-Windows-OfflineFiles-CscServiceMicrosoft-Windows-SuperfetchMicrosoft-Windows-IPBusEnumMicrosoft-Windows-MprddmMicrosoft-Windows-Dwm-UdwmMicrosoft-Windows-AppModel-StateMicrosoft-Windows-WCN-FD-Provider-TraceMicrosoft-Windows-Resource-Exhaustion-ResolverMicrosoft-Windows-Iphlpsvc-TraceMicrosoft-Windows-WUSAMicrosoft-Windows-TerminalServices-LocalSessionManagerMicrosoft-Windows-RPC-FirewallManagerMicrosoft-Windows-WCN-Common-TraceMicrosoft-Windows-MediaFoundation-MFCaptureEngineMicrosoft-Windows-ReadyBoostDriverMicrosoft-Windows-DUIMicrosoft-Windows-WMP-Setup_WMMicrosoft-Windows-Direct3D10Microsoft-Windows-DfsSvcMicrosoft-Windows-IME-SCCOREMicrosoft-Windows-NTLMMicrosoft-Windows-VWiFiMicrosoft-Windows-Kernel-PnPConfigMicrosoft-Windows-Winsock-SQMMicrosoft-Windows-SpoolerSpoolSVMicrosoft-Windows-NetshellMicrosoft-Windows-UserModePowerServiceMicrosoft-Windows-HttpServiceHTTP Service TraceMicrosoft-Windows-D3D9Microsoft-Windows-AppModel-RuntimeMicrosoft-Windows-CEIPMicrosoft-Windows-Directory-Services-SAMMicrosoft-Windows-SpoolerTCPMonMicrosoft-Windows-ReadyBoostMicrosoft-Windows-L2NACPMicrosoft-Windows-LLTD-MapperMicrosoft-Windows-DeduplicationMicrosoft-Windows-HomeGroup-ControlPanelMicrosoft-Windows-Mobile-Broadband-Experience-Parser-TaskMicrosoft-Windows-DomainJoinManagerTriggerProviderMicrosoft-Windows-SruMonMicrosoft-Windows-ELS-HyphenationTCPIP Service TraceMicrosoft-Windows-DriverFrameworks-KernelModeMicrosoft-Windows-CorruptedFileRecovery-ClientMicrosoft-Windows-WMI-ActivityMicrosoft-Windows-COMRuntimeMicrosoft-Windows-WASMicrosoft-Windows-WnvMicrosoft-Windows-ShsvcsMicrosoft-Windows-NDISMicrosoft-Windows-WinMDEFile Kernel Trace; Operation Set 1Microsoft-Windows-Proximity-CommonMicrosoft-Windows-Ntfs-UBPMMicrosoft-Windows-Kernel-RegistryMicrosoft-Windows-RemoteDesktopServices-RemoteDesktopSessionManagerMicrosoft-Windows-TunnelDriverMicrosoft-Windows-QoS-PacerMicrosoft-Windows-EventCollectorMicrosoft-Windows-OOBE-Machine-DUIMicrosoft-Windows-IME-TCTIPMicrosoft-Windows-WCNWizMicrosoft-Windows-DisplayMicrosoft-Windows-OcSetupMicrosoft-Windows-DesktopWindowManager-DiagMicrosoft-Windows-FileInfoMinifilterMicrosoft-Windows-TextPredictionEngineMicrosoft-Windows-NetworkGCWMicrosoft-Windows-DHCPv6-ClientMicrosoft-Windows-PlayToManagerNDIS_STATUS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIGNDIS_STATUS_PORT_STATEMS_Windows_AeLookupServiceTrigger_ProviderMicrosoft_Windows_SQM_ProviderMS_Windows_AIT_ProviderNDIS_TCP_CONNECTION_OFFLOAD_CURRENT_CONFIGNDIS_TCP_OFFLOAD_CURRENT_CONFIGPARPORT_WMI_ALLOCATE_FREE_COUNTS_GUIDNDIS_GEN_ENUMERATE_PORTSGUID_QOS_TC_SUPPORTEDMS1394_PortVendorRegisterAccessGuidiSCSI_PersistentLoginsGuidiSCSI_PortalInfoClassGuidSerailPortPerfGuidPortClsEventUdpIpGuidTcpIpGuidiSCSI_OperationsGuidCTLGUID_usbportNDIS_STATUS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIESiSCSI_DiscoveryOperationsGuidSerialPortNameGuidCTLGUID_WebClntTracePOINTER_PORT_WMI_STD_DATA_GUIDKEYBOARD_PORT_WMI_STD_DATA_GUIDMSKeyboard_ClassInformationGuidNDIS_GEN_CO_MEDIA_SUPPORTEDMS_Windows_AeSwitchBack_ProviderSerialPortHWGuidMS_SM_PortInformationMethodsataport_CtlGuidstorport_CtlGuidMS1394_PortDriverInformationGuidBTHPORT_WMI_HCI_PACKET_INFOSerialPortCommGuidiScsiLBOperationsGuidMS_Windows_AeCache_ProviderNDIS_GEN_PORT_STATEWindowsBackup TracingControlGuidWmiMonitorListedSupportedSourceModes_GUIDNDIS_GEN_MEDIA_SUPPORTEDCTLGUID_certpropBTHPORT_WMI_SDP_SERVER_LOG_INFOKEYBOARD_PORT_WMI_EXTENDED_IDiSCSIRedirectPortalGuidNDIS_GEN_PORT_AUTHENTICATION_PARAMETERSBTHPORT_WMI_SDP_DATABASE_EVENTNDIS_TCP_CONNECTION_OFFLOAD_HARDWARE_CAPABILITIESiSCSI_TCPIPConfigGuidSerialPortPropertiesGuidPortCls_IrpProcessingiSCSI_SecurityConfigOperationsGuidNDIS_TCP_OFFLOAD_PARAMETERSPortCls_PowerStateMicrosoft_Windows_GameUxiSCSI_InitiatorLoginStatisticsGuidMS1394_PortErrorInformationGuidPortCls_PinStateCTLGUID_PortClsNDIS_TCP_OFFLOAD_HARDWARE_CAPABILITIESCTRLGUID_MF_PIPELINE.PX`i``.HBS&{%UD(_dump_wmi_guidentries failed, error %d, status %Xdump_wmi_guidentries failed, error %ddump_wmi_guidentries: cannot alloc %X bytes (total %d)dump_wmi_guidentries: read failed, error %d, status %Xdump_wmi_guidentries: read failed, error %dWMI guidentries: total %X readed %X:[%X] %X flag %X refcnt %X - %s[%X] %X flag %X refcnt %X %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2Xdump_wmi_regentries failed, error %d, status %Xdump_wmi_regentries failed, error %ddump_wmi_regentries: cannot alloc %X bytes (total %d)dump_wmi_regentries: read failed, error %d, status %Xdump_wmi_regentries: read failed, error %dWMI regentries: total %X readed %X:[%X] flags %X refcnt %X dev %p prov %X DS %p %s[%X] flags %X refcnt %X cb %p prov %X DS %p %sEtw[%d]:Type %X Index %X InternalCB %p (%s) %sType %X Index %X InternalCB %p %sType %X Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XType %X Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2Xdump_Etw: exception occured, code %Xdump_Etws: exception occured, code %XKPRCB.EtwSupport %p:KPRCB[%d].EtwSupport %p:read_kernel_etws count failed, error %d, ntstatus %Xread_kernel_etws count failed, error %dread_kernel_etws: cannot alloc %X bytesread_kernel_etws failed, error %d, ntstatus %Xread_kernel_etws failed, error %dKEtw[%X]:KEtw[%X]: RefCount %d, KProvider - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XKEtw[%X]: RefCount %d %s[%X] %p %sType %X InUse %d Index %X InternalCB %p (%s) %sType %X InUse %d Index %X InternalCB %p %sType %X InUse %d Index %X InternalCB %p (%s) ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XType %X InUse %d Index %X InternalCB %p ProviderId: %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XEtwCallback[%d] %p %s:EtwCallback[%d]:EtwTrace[%d] %p Ctx %p %s:EtwTrace[%d] %p Ctx %p %s - %8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2XUnknown type %d for Etw[%d]DEVINTERFACE_MT_TRANSPORTDEVINTERFACE_KEYBOARDDEVINTERFACE_COMPORTDEVINTERFACE_VIAMINIPORTDEVINTERFACE_STORAGEPORTDEVINTERFACE_IRPORTcheck_pnp_notifiers failed, error %d, status %Xcheck_pnp_notifiers failed, error %dcheck_pnp_notifiers: cannot alloc %X bytes (total %d)check_pnp_notifiers: read failed, error %d, status %Xcheck_pnp_notifiers: read failed, error %dPnp Notifiers: total %d, readed %dPnp[%d] %p %s %s addr %pPnp[%d] %s %s addr %p %scheck_pnp_handlers failed, error %d, status %Xcheck_pnp_handlers failed, error %dPlugPlayHandlerTable: %d itemsPlugPlayHandlerTable[%d] %p %sPlugPlayHandlerTable[%d] %pcheck_sess_notify, error %d, status %Xcheck_sess_notify, error %dcheck_sess_notify: cannot alloc %X bytes (total %d)check_sess_notify: read failed, error %d, status %Xcheck_sess_notify: read failed, error %dIopSessionNotifications: %dSessionNotifier[%d]: class %d len %X session %p cb %p %scheck_sess_term_ntfs failed, error %d, status %Xcheck_sess_term_ntfs failed, error %dcheck_sess_term_ntfs: cannot alloc %X bytes (total %d)check_sess_term_ntfs: read failed, error %d, status %Xcheck_sess_term_ntfs: read failed, error %dLogonSessionTerminatedRoutines: %d[%d] %p %scheck_fs_changes failed, error %d, status %Xcheck_fs_changes failed, error %dcheck_fs_changes: cannot alloc %X bytes (total %d)check_fs_changes: read failed, error %d, status %Xcheck_fs_changes: read failed, error %dFS Change notifiers: %d (actual %d)DriverObj %p addr %p %sCannot read count for %s, error %dCount of %s is too big - %XCannot read %s table, error %dCannot read entry %d from table of %s, error %dcheck_vista_cmp_list get count failed, error %d, status %Xcheck_vista_cmp_list get count failed, error %dcheck_vista_cmp_list failed, error %d, status %Xcheck_vista_cmp_list failed, error %dcheck_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %d, ntstatus %Xcheck_ai_cbs: cannot read ExpDisQueryAttributeInformation, error %dExpDisQueryAttributeInformation %p %scheck_ai_cbs: cannot read ExpDisSetAttributeInformation, error %d, ntstatus %Xcheck_ai_cbs: cannot read ExpDisSetAttributeInformation, error %dExpDisSetAttributeInformation %p %scheck_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %d, ntstatus %Xcheck_dbgk_lkmd: cannot read DbgkLkmd_cblist, error %dDbgkLkmd[%d] callback %p %scheck_fsrtl: cannot read FltMgrCallbacks, error %d, ntstatus %Xcheck_fsrtl: cannot read FltMgrCallbacks, error %dFltMgrCallbacks: %p %scheck_fsrtl: cannot read FsRtlpMupCalls, error %d, ntstatus %Xcheck_fsrtl: cannot read FsRtlpMupCalls, error %dFsRtlpMupCalls: %p %scheck_Iof: cannot read pIofCallDriver, error %d, ntstatus %Xcheck_Iof: cannot read pIofCallDriver, error %dpIofCallDriver %p patched by %scheck_Iof: cannot read pIofCompleteRequest, error %d, ntstatus %Xcheck_Iof: cannot read pIofCompleteRequest, error %dpIofCompleteRequest %p patched by %scheck_Iof: cannot read pIoAllocateIrp, error %d, ntstatus %Xcheck_Iof: cannot read pIoAllocateIrp, error %dpIoAllocateIrp %p patched by %scheck_Iof: cannot read pIoFreeIrp, error %d, ntstatus %Xcheck_Iof: cannot read pIoFreeIrp, error %dpIoFreeIrp %p patched by %scheck_Iof: cannot read HvlpHypercallCodeVa, error %d, ntstatus %Xcheck_Iof: cannot read HvlpHypercallCodeVa, error %dHvlpHypercallCodeVa %p patched by %s%SystemRoot%\System32\sxssrv.dll%SystemRoot%\System32\csrsrv.dll%SystemRoot%\System32\basesrv.dll%SystemRoot%\System32\winsrv.dll%SystemRoot%\System32\lsasrv.dll%SystemRoot%\System32\ntdll.dllKiDebugRoutine %p hooked by %sPspLegoNotifyRoutine %p hooked by %sKiTimeUpdateNotifyRoutine %p hooked by %sKiSwapContextNotifyRoutine %p hooked by %sKiThreadSelectNotifyRoutine %p hooked by %sSysenter patched, addr %p not in %s !!!Mailslot: %SNamedPipe: %SDEVCLASS_MULTIPORTSERIALDEVCLASS_PORTSDEVCLASS_KEYBOARDDEVCLASS_APMSUPPORTread_dev_chrs(%S) failed, ntstatus %XDrvObj %p name %S %sDrvObj %p nameLen %X %sdev_props failed, status %XClassGUID: %SClassGUID: %S - %sCannot open directory %S, error %XCannot realloc %d bytesCannot open device directory, error %XCannot open driver directory, error %XCannot open FileSystem directory, error %XUnknown HAL private dispatch table version %XHalAcpiTimerInit: %p %sHalAcpiTimerCarry: %p %sHalAcpiMachineStateInit: %p %sHalAcpiQueryFlags: %p %sHalAcpiPicStateIntact: %p %sHalRestoreInterruptControllerState: %p %sHalPciInterfaceReadConfig: %p %sHalPciInterfaceWriteConfig: %p %sHalSetVectorState: %p %sHalGetApicVersion: %p %sHalSetMaxLegacyPciBusNumber: %p %sHalIsVectorValid: %p %sHalAcpiGetTableDispatch: %p %sHalAcpiGetRsdpDispatch: %p %sHalAcpiGetFacsMappingDispatch: %p %sHalAcpiGetAllTablesDispatch: %p %sHalAcpiPmRegisterAvailable: %p %sHalAcpiPmRegisterRead: %p %sHalAcpiPmRegisterWrite: %p %sHalHandlerForBus: %p %sHalHandlerForConfigSpace: %p %sHalLocateHiberRanges: %p %sHalRegisterBusHandler: %p %sHalSetWakeEnable: %p %sHalSetWakeAlarm: %p %sHalPciTranslateBusAddress: %p %sHalPciAssignSlotResources: %p %sHalHaltSystem: %p %sHalFindBusAddressTranslation: %p %sHalResetDisplay: %p %sHalHandlerForBus: %p %sHalHandlerForConfigSpace: %p %sHalLocateHiberRanges: %p %sHalRegisterBusHandler: %p %sHalSetWakeEnable: %p %sHalSetWakeAlarm: %p %sHalPciTranslateBusAddress: %p %sHalPciAssignSlotResources: %p %sHalHaltSystem: %p %sHalFindBusAddressTranslation: %p %sHalResetDisplay: %p %sKdSetupPciDeviceForDebugging: %p %sKdReleasePciDeviceforDebugging: %p %sKdGetAcpiTablePhase0: %p %sKdCheckPowerButton: %p %sHalVectorToIDTEntry: %p %sKdMapPhysicalMemory64: %p %sKdUnmapVirtualAddress: %p %sHalMmMemoryUsage: %p %sHalAllocateMapRegisters: %p %sKdGetPciDataByOffset: %p %sKdSetPciDataByOffset: %p %sHalGetInterruptVector: %p %sHalGetVectorInput: %p %sHalLoadMicrocode: %p %sHalUnloadMicrocode: %p %sHalMcUpdatePostUpdate: %p %sHalAllocateMessageTarget: %p %sHalFreeMessageTarget: %p %sHalDpReplaceBegin: %p %sHalDpReplaceTarget: %p %sHalDpReplaceControl: %p %sHalDpReplaceEnd: %p %sHalPrepareForBugcheck: %p %sHalQueryWakeTime: %p %sHalReportIdleStateUsage: %p %sHalHandlerForBus: %p %sHalHandlerForConfigSpace: %p %sHalLocateHiberRanges: %p %sHalRegisterBusHandler: %p %sHalSetWakeEnable: %p %sHalSetWakeAlarm: %p %sHalPciTranslateBusAddress: %p %sHalPciAssignSlotResources: %p %sHalHaltSystem: %p %sHalFindBusAddressTranslation: %p %sHalResetDisplay: %p %sHalAllocateMapRegisters: %p %sKdSetupPciDeviceForDebugging: %p %sKdReleasePciDeviceforDebugging: %p %sKdGetAcpiTablePhase0: %p %sKdCheckPowerButton: %p %sHalVectorToIDTEntry: %p %sKdMapPhysicalMemory64: %p %sKdUnmapVirtualAddress: %p %sKdGetPciDataByOffset: %p %sKdSetPciDataByOffset: %p %sHalGetInterruptVector: %p %sHalGetVectorInput: %p %sHalLoadMicrocode: %p %sHalUnloadMicrocode: %p %sHalMcUpdatePostUpdate: %p %sHalAllocateMessageTarget: %p %sHalFreeMessageTarget: %p %sHalDpReplaceBegin: %p %sHalDpReplaceTarget: %p %sHalDpReplaceControl: %p %sHalDpReplaceEnd: %p %sHalPrepareForBugcheck: %p %sHalQueryWakeTime: %p %sHalReportIdleStateUsage: %p %sHalTscSynchronization: %p %sHalWheaInitProcessorGenericSection: %p %sHalStopLegacyUsbInterrupts: %p %sHalReadWheaPhysicalMemory: %p %sHalWriteWheaPhysicalMemory: %p %sHalDpMaskLevelTriggeredInterrupts: %p %sHalDpUnmaskLevelTriggeredInterrupts: %p %sHalDpGetInterruptReplayState: %p %sHalDpReplayInterrupts: %p %sHalQueryIoPortAccessSupported: %p %sHalHandlerForBus: %p %sHalHandlerForConfigSpace: %p %sHalLocateHiberRanges: %p %sHalRegisterBusHandler: %p %sHalSetWakeEnable: %p %sHalSetWakeAlarm: %p %sHalPciTranslateBusAddress: %p %sHalPciAssignSlotResources: %p %sHalHaltSystem: %p %sHalFindBusAddressTranslation: %p %sHalResetDisplay: %p %sHalAllocateMapRegisters: %p %sKdSetupPciDeviceForDebugging: %p %sKdReleasePciDeviceforDebugging: %p %sKdGetAcpiTablePhase0: %p %sKdCheckPowerButton: %p %sHalVectorToIDTEntry: %p %sKdMapPhysicalMemory64: %p %sKdUnmapVirtualAddress: %p %sKdGetPciDataByOffset: %p %sKdSetPciDataByOffset: %p %sHalGetInterruptVector: %p %sHalGetVectorInput: %p %sHalLoadMicrocode: %p %sHalUnloadMicrocode: %p %sHalMcUpdatePostUpdate: %p %sHalAllocateMessageTarget: %p %sHalFreeMessageTarget: %p %sHalDpReplaceBegin: %p %sHalDpReplaceTarget: %p %sHalDpReplaceControl: %p %sHalDpReplaceEnd: %p %sHalPrepareForBugcheck: %p %sHalQueryWakeTime: %p %sHalReportIdleStateUsage: %p %sHalTscSynchronization: %p %sHalWheaInitProcessorGenericSection: %p %sHalStopLegacyUsbInterrupts: %p %sHalReadWheaPhysicalMemory: %p %sHalWriteWheaPhysicalMemory: %p %sHalInterruptMaskLevelTriggeredLines: %p %sHalInterruptUnmaskLevelTriggeredLines: %p %sHalDpGetInterruptReplayState: %p %sHalDpReplayInterrupts: %p %sHalQueryIoPortAccessSupported: %p %sKdSetupIntegratedDeviceForDebugging: %p %sKdReleaseIntegratedDeviceForDebugging: %p %sHalEnlightenmentInitialize: %p %sHalAllocateEarlyPages: %p %sHalMapEarlyPages: %p %sHalTimerGetClockOwner: %p %sHalTimerGetClockConfiguration: %p %sHalTimerNotifyProcessorFreeze: %p %sHalTimerPrepareProcessorForIdle: %p %sHalDiagRegisterLogRoutine: %p %sHalTimerResumeProcessorFromIdle: %p %sHalTimerResetLastClockTick: %p %sHalVectorToIDTEntryEx: %p %sHalSecondaryInterruptQueryPrimaryInformation: %p %sHalMaskInterrupt: %p %sHalUnmaskInterrupt: %p %sHalIsInterruptTypeSecondary: %p %sHalAllocateGsivForSecondaryInterrupt: %p %sHalAddInterruptRemapping: %p %sHalRemoveInterruptRemapping: %p %sHalSaveAndDisableEnlightenment: %p %sHalRestoreHvEnlightenment: %p %sHalPciEarlyRestore: %p %sHalInterruptGetLocalIdentifier: %p %sHalAllocatePmcCounterSet: %p %sHalCollectPmcCounters: %p %sHalFreePmcCounterSet: %p %sHalTimerQueryCycleCounter: %p %sHalTimerGetNextTickDuration: %p %sHalPciMarkHiberPhase: %p %sHalInterruptQueryProcessorRestartEntryPoint: %p %sHalInterruptRequestSecondaryInterrupt: %p %sHalInterruptEnumerateUnmaskedInterrupts: %p %sHalBiosDisplayReset: %p %sHalGetDmaAdapter: %p %sHalCheckPowerButton: %p %sHalMapPhysicalMemoryWriteThrough64: %p %sHalUnmapVirtualAddress: %p %sHalKdReadPCIConfig: %p %sHalKdWritePCIConfig: %p %sHalTimerQueryWakeTime: %p %sHalTimerReportIdleStateUsage: %p %sHalKdEnumerateDebuggingDevices: %p %sHalFlushIoRectangleExternalCache: %p %sHalPowerEarlyRestore: %p %sHalQueryCapsuleCapabilities: %p %sHalUpdateCapsule: %p %sHalPciMultiStageResumeCapable: %p %scheck_hal_private_disp_table: cannot read table, error %d, ntstatus %Xcheck_hal_private_disp_table: cannot read table, error %dcheck_hal_disp_table: cannot read table, error %d, ntstatus %Xcheck_hal_disp_table: cannot read table, error %dHalQuerySystemInformation: %p %sHalSetSystemInformation: %p %sHalQueryBusSlots: %p %sHalExamineMBR: %p %sHalIoReadPartitionTable: %p %sHalIoSetPartitionInformation: %p %sHalIoWritePartitionTable: %p %sHalReferenceHandlerForBus %p %sHalReferenceBusHandler %p %sHalDereferenceBusHandler %p %sHalInitPnpDriver %p %sHalInitPowerManagement %p %sHalGetDmaAdapter %p %sHalGetInterruptTranslator %p %sHalStartMirroring %p %sHalEndMirroring %p %sHalMirrorPhysicalMemory %p %sHalEndOfBoot %p %sHalMirrorVerify %p %sHalGetCachedAcpiTable %p %sHalSetPciErrorHandlerCallback %p %sread_hal_apci_disp_table return %X bytes, error %d, ntstatus %Xread_hal_apci_disp_table return %X bytes, error %dBad HalAcpiDispatchTable version: %Xread_gdt_size failed, error %d, ntstatus %Xread_gdt_size failed, error %dCannot alloc %d bytes for GDT entriesread_gdt failed, error %d, ntstatus %Xread_gdt failed, error %dDescriptor[%d] %s S %d DPL %d type %X base %X limit %XWinChecker::dump_ldt failed, error %X, ntstatus %XWinChecker::dump_ldt failed, error %XWinChecker::dump_ldt: cannot alloc ldt array, size %XLdt[%d]:Base: XLimit: XAVL: %dD/B: %dDPL: %dG: %dP: %dS: %dType: %dCannot read code for kinterrupt(%X) thunk, error %dIDT patched: unknown type %X selector %X addr %p for int%XIDT patched: unknown selector %X for int%XIDT patched: int%X has unknown selector %X base %X limit %X addr %pIDT patched: int%X addr %p by module %sIDT int%X addr %p KINTERRUPT %pIDT patched: int%X addr %pInt%X: selector %X type TASK DPL %X base %X limit %XInt%X: selector %X type %X DPL %X addr %p base %X limit %XInt%X: selector %X type %X DPL %X addr %pread_idt_size failed, error %d, ntstatus %Xread_idt_size failed, error %dread_idt: cannot alloc %d bytes for IDT storageread_idt failed, error %d, ntstatus %Xread_idt failed, error %dCannot read kinterrupt (%X), error %dKInterrupt %X (%p):Size %X type %XServiceRoutine %p %sDispatchAddress %p %scheck_ob_types: cannot read size of ObTypes list, error %d, ntstatus %Xcheck_ob_types: cannot read size of ObTypes list, error %dcheck_ob_types: cannot read %d bytes (readed %d), error %d, ntstatus %Xcheck_ob_types: cannot read %d bytes (readed %d), error %dfill_ob_type: cannot read ObType %S (%X), error %dCannot read ObType %S (%X), error %dObType %S:DumpProcedure: %p %sOpenProcedure: %p %sCloseProcedure: %p %sDeleteProcedure: %p %sParseProcedure: %p %sSecurityProcedure: %p %sQueryNameProcedure: %p %sOkayToCloseProcedure: %p %sZwAlpcConnectPortExZwOpenKeyTransactedExZwOpenKeyExZwOpenKeyTransactedZwCreateKeyTransactedZwAlpcSendWaitReceivePortZwAlpcImpersonateClientOfPortZwAlpcDisconnectPortZwAlpcDeletePortSectionZwAlpcCreatePortSectionZwAlpcCreatePortZwAlpcConnectPortZwAlpcAcceptConnectPortZwUnloadKey2ZwQueryOpenSubKeysExZwLoadKeyExZwQueryPortInformationProcessZwWaitForKeyedEventZwReleaseKeyedEventZwOpenKeyedEventZwCreateKeyedEventZwUnloadKeyExZwSaveKeyExZwRenameKeyZwLockRegistryKeyZwLockProductActivationKeysZwCompressKeyZwCompactKeysZwYieldExecutionZwUnloadKeyZwSetValueKeyZwSetThreadExecutionStateZwSetInformationKeyZwSetDefaultHardErrorPortZwSecureConnectPortZwSaveMergedKeysZwSaveKeyZwRestoreKeyZwRequestWaitReplyPortZwRequestPortZwReplyWaitReplyPortZwReplyWaitReceivePortExZwReplyWaitReceivePortZwReplyPortZwReplaceKeyZwRegisterThreadTerminatePortZwQueryValueKeyZwQueryOpenSubKeysZwQueryMultipleValueKeyZwQueryKeyZwQueryInformationPortZwOpenKeyZwNotifyChangeMultipleKeysZwNotifyChangeKeyZwLoadKey2ZwLoadKeyZwListenPortZwImpersonateClientOfPortZwFlushKeyZwEnumerateValueKeyZwEnumerateKeyZwDeleteValueKeyZwDeleteKeyZwDelayExecutionZwCreateWaitablePortZwCreatePortZwCreateNamedPipeFileZwCreateKeyZwConnectPortZwCompleteConnectPortZwAcceptConnectPortFindKiServiceTable: relocation type %d found at XCannot read body of %s !Cannot extract index of %s, error %dkernel %s don`t contains KeServiceDescriptorTable function !Cannot find SDT in %sCannot read ntdll.dllCannot read body of %s!Cannot read body of ZwYieldExecution!Cannot extract index of ZwYieldExecution, error %dCannot extract index of ZwPlugPlayControl , error %d%s: %pSDT entry %X (%s) hooked %p %s!SDT entry %X hooked %p %s!Need unhook %d items in SSDTUNHOOK_ITEM: Index %X Offset %XUnhook SSDT failed, lasterror %dUnhooked %d SSDT itemsNtUserSetProcessRestrictionExemptionNtUserAcquireIAMKeyNtGdiDdDDICreateKeyedMutex2NtGdiDdDDIOpenKeyedMutex2NtGdiDdDDIAcquireKeyedMutex2NtGdiDdDDIReleaseKeyedMutex2NtUserSetTHQAPublicKeyNtGdiDdDDIReleaseKeyedMutexNtGdiDdDDIAcquireKeyedMutexNtGdiDdDDIDestroyKeyedMutexNtGdiDdDDIOpenKeyedMutexNtGdiDdDDICreateKeyedMutexNtUserEndTouchOperationNtUserSfmDxReportPendingBindingsToDwmNtGdiDDCCIGetTimingReportNtUserUnregisterSessionPortNtUserRegisterSessionPortNtUserRegisterErrorReportingDialogNtGdiSetOPMSigningKeyAndSequenceNumbersNtGdiGetCertificateSizeNtGdiGetCertificateNtUserWaitForMsgAndEventNtUserVkKeyScanExNtUserUnregisterHotKeyNtUserUnlockWindowStationNtUserUnloadKeyboardLayoutNtUserUnhookWindowsHookExNtUserSetWindowStationUserNtUserSetWindowsHookExNtUserSetWindowsHookAWNtUserSetProcessWindowStationNtUserSetKeyboardStateNtUserSetImeHotKeyNtUserSetConsoleReserveKeysNtUserRegisterHotKeyNtUserOpenWindowStationNtUserMapVirtualKeyExNtUserLockWindowStationNtUserLoadKeyboardLayoutExNtUserGetProcessWindowStationNtUserGetKeyStateNtUserGetKeyNameTextNtUserGetKeyboardStateNtUserGetKeyboardLayoutNameNtUserGetKeyboardLayoutListNtUserGetImeHotKeyNtUserGetCPDNtUserGetAsyncKeyStateNtUserCreateWindowStationNtUserCloseWindowStationNtUserCheckImeHotKeyNtUserCallMsgFilterNtUserAlterWindowStyleNtUserActivateKeyboardLayoutNtGdiScaleViewportExtExNtGdiDvpWaitForVideoPortSyncNtGdiDvpUpdateVideoPortNtGdiDvpGetVideoPortConnectInfoNtGdiDvpGetVideoPortOutputFormatsNtGdiDvpGetVideoPortLineNtGdiDvpGetVideoPortInputFormatsNtGdiDvpGetVideoPortFlipStatusNtGdiDvpGetVideoPortFieldNtGdiDvpGetVideoPortBandwidthNtGdiDvpFlipVideoPortNtGdiDvpDestroyVideoPortNtGdiDvpCreateVideoPortNtGdiDvpCanCreateVideoPortNtGdiDdSetColorKeyread_shadow_sdt failed, error %dcheck_win32k_sdt: cannot alloc %d bytesCannot read win32k_sdt at %p size %X, error %dwin32k_sdt[%d] (%s) hooked, addr %p %swin32k_sdt[%d] hooked, addr %p %sGetNamedPipeServerProcessIdread_kddb read %X bytes, error %dcannot read MmNonPagedPoolStart (%p), error %dcannot read MmNonPagedPoolEnd (%p), error %dcannot read MmPagedPoolStart (%p), error %dcannot read MmPagedPoolEnd (%p), error %dcannot read KernelVerifier (%p), error %dWindowsType: %SETHREAD.StartAddress %XKiProcessorBlock: %p (%X)KernelVerifier: %XKeBugCheckCallbackList: %p (%X)WorkerRoutine: %p %sIdleFunction: %p %sIdleFunction: %p %sKPRCB[%d].WorkerRoutine: %p %sKPRCB[%d].IdleFunction: %p %sKPRCB[%d].IdleFunction: %p %sread_kpcr return %X bytes, error %d, ntstatus %Xread_kpcr return %X bytes, error %dKPCR[%d] %p major %X minor %XKPCR[%d] %pget_os_info return %X bytes, error %d, ntstatus %Xget_os_info return %X bytes, error %dNtMajorVersion: %dNtMinorVersion: %dBuildNumber: %dGlobalFlag: %XProcessors: %dMmVerifierFlags %dMmSystemSize %d %sDebuggerEnabled %dDebuggerNotPresent %dSafeBootMode %dNXSupportPolicy %XCR0 %8.8X %sCR4 %8.8X %sCannot open mailslot %S, error %dget_mail_slot_owner(%S): returned %d bytes, error %d, ntstatus %Xget_mail_slot_owner(%S): returned %d bytes, error %dCannot open named pipe %S, error %dGetNamedPipeServerProcessId(%S) failed, error %dget_named_pipe_owner(%S): returned %d bytes, error %d, ntstatus %Xget_named_pipe_owner(%S): returned %d bytes, error %dread_lpc_port_chars: len %d, returned %d bytes, error %d, ntstatus %Xread_lpc_port_chars: len %d, returned %d bytes, error %dread_unicode_string: len %d, returned %d bytes, error %d, ntstatus %Xread_unicode_string: len %d, returned %d bytes, error %dread_drivers_list: cannot get size of drivers list, returned %d bytes, error %d, ntstatus %Xread_drivers_list: cannot get size of drivers list, returned %d bytes, error %dread_drivers_list: cannot alloc %X bytes for driver listread_drivers_list: cannot read drivers list, error %d, ntstatus %Xread_drivers_list: cannot read drivers list, error %d%p:%X flags %X LoadCount %d %sread_KiThreadSelectNotifyRoutine failed, error %dread_KiSwapContextNotifyRoutine failed, error %dread_KiTimeUpdateNotifyRoutine failed, error %dread_PspLegoNotifyRoutine failed, error %dread_KiDebugRoutine failed, error %dread_msrs failed, error %d, ntstatus %Xread_msrs failed, error %dIManageProcess: Cannot OpenProcess %dIManageProcess: Cannot open process %dread_win32_process for PID %X failed, error %d, status %Xread_win32_process for PID %X failed, error %dread_dword(%p, PID %d) failed, error %d, ntstatus %Xread_dword(%p, PID %d) failed, error %dread_ptr(%p, PID %d) failed, error %d, ntstatus %Xread_ptr(%p, PID %d) failed, error %drp_ReadProcessMemory(%p size %X) from %p error %dread_token for PID %X failed, error %d, status %Xread_token for PID %X failed, error %dopen_proc(%d, access %X) failed, error %d, ntstatus %Xopen_proc(%d, access %X) failed, error %drp_OpenProcess(%d, access %X) dwRet %d, error %drp_TerminateProcess(%p, %X) dwRet %d, error %dMajor %d Minor %d BuildNumber %d PlatformId %d ServicePackMajor %d ServicePackMinor %d SuiteMask %d ProductType %d CSDVersion %SProductType: %XCannot open RPC control, error %Xmsgsvcsend_ILocalObjectExporterIVsShellIWbemLoginClientIDICertProtect_IBTFTPApiEvents_s_PasswordRecoverywininet_UrlCache_IObjectExporterWMsgAPIsWMsgKAPIsINCryptKeyIsoHttpProxyMgrProviderIKeySvcRWcnTransportRpcIPortResolveIWbemLoginHelperLRpcSIDKeyISmartCardRootCertsIDebugPortSupplier2IAsyncOperationIPipelineElementOnlineProviderCertInterfaceIBackgroundCopyJobHttpOptionsHttpProxyMgrClientIStaticPortMappingCollectionIKeySvcs_WindowsShutdownIWebBrowser2IDebugPortSupplierLocale2IUPnPHttpHeaderControlWINHTTP_AUTOPROXY_SERVICEIErcLuaSupportIDebugPortSupplier3IKeySvc2BackupKeyIWerReportICertPassageIStaticPortMappingIDebugPortSupplierEx2IWbemLevel1LoginIWebBrowserAppmsgsvcIShellWindowsRpcBindingFromStringBinding(%S) failed: %dRpcMgmtInqIfIds(%S) failed: %dRpcStringBindingCompose failed: %dRpcBindingFromStringBinding failed: %dRpcMgmtInqIfIds failed: %d%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : %s%8.8X-%4.4X-%4.4X-%2.2X%2.2X-%2.2X%2.2X%2.2X%2.2X%2.2X%2.2X version %d.%d : (%s)RpcMgmtEpEltInqBegin failed: %dCannot read npc table, readed %X bytesrpcrt4%s.AddressChangeFn: %p %srpcrt4_hack::check_myself: exception %d occuredrpcrt4_hack::try_hack: cannot find RpcServerRegisterIfExI_RpcInitNdrImportsload_driver(%S) returned %XLoaded kernel driver: %SError loading kernel driver: %ls - 0xxError loading kernel driver: %S - 0xxError loading kernel driver: %S - OpenSCManager 0xxtcpipClientImmProcessKeyfnHkOPTINLPEVENTMSGfnHkINLPMSGfnSENTDDEMSGfnDWORDOPTINLPMSGRealMsgWaitForMultipleObjectsExPEB.KernelCallbackTable patched, %puser32_hack::try_hack: bad PE passeduser32_hack::try_hack: cannot read import tablepfnWowMsgBoxIndirectCallbackUnknown apfnDispatch size: %d%s_hack::try_hack: bad PE passed%s_hack::try_hack: cannot read exports, error %d%s_hack::try_hack: cannot find section .data%s_hack::try_hack: cannot read section .data%s_hack::try_hack: cannot read section .rdata%s_hack::try_hack: cannot find section .text%s_hack::try_hack: cannot read section .textDxgkReleaseKeyedMutex2DxgkAcquireKeyedMutex2DxgkOpenKeyedMutex2DxgkCreateKeyedMutex2DxgkReleaseKeyedMutexDxgkAcquireKeyedMutexDxgkDestroyKeyedMutexDxgkOpenKeyedMutexDxgkCreateKeyedMutexCannot read gDxgkInterface, readed %X bytesWindowHasShadowDisableProcessWindowsGhostingzzzUnhookWindowsHookxxxUpdateWindowsxxxArrangeIconicWindowsSetWindowStateClearWindowStateSetMsgBoxGetKeyboardTypeGetKeyboardLayoutRemotePassthruDisablexxxRemotePassthruEnableCannot read gpsi, readed %X bytesCannot read gpsi handlers, readed %X bytesCannot read apfnSimpleCall, readed %X bytesCannot read gapfnMessageCall, readed %X bytesCannot read gapfnScSendMessage, readed %X bytesCannot read gaNewProcAddresses, readed %X bytesCannot open logfile %SCannot create stop event, error %dDriver %S loaded from %SSrvGetConsoleKeyboardLayoutNameSrvSetConsoleKeyShortcutsSrvGetConsoleAliasExesSrvGetConsoleAliasExesLengthSrvVDMConsoleOperationSrvGetLargestConsoleWindowSizeSrvExitWindowsExwinsrv.dllUnknown size of ConsoleServerApiDispatchTable: %dUnknown size of UserServerApiDispatchTable: %dCallUserpExitWindowsExGetConsoleAliasExesInternalGetConsoleAliasExesLengthInternalSetConsoleKeyShortcutsGetConsoleKeyboardLayoutNameWorkerSetConsoleOutputCPInternalGetConsoleOutputCPGetLargestConsoleWindowSizereg_ccs_services::read failed - error %dCannot open key %S, error %dSafeSecondaryLog(%d) failed, error %dSafeSecondaryLog failed, error %dSafeSendLog(%d) failed, error %dSafeSendLog failed, error %dBad memory %p len %X in dump_hex_bufferCannot alloc %d bytes for delayed importsCannot alloc %d bytes for importsread_import_safe(%s) failed %XCannot realloc %d bytes for iatread_delayed_safe(%s) failed %Xstore2md_cache: cannot alloc %d bytesstore2md_cache: cannot realloc, alloced %d byteswdigest.dlltspkg.dllschannel.dllpku2u.dllnegoexts.dllmsv1_0.dlllivessp.dllkerberos.dllumpnpmgr.dllcombase.dllntdsa.dllntdll.dllcryptbase.dllncrypt.dllrpcrt4.dllimm32.dlluser32.dllkernelbase.dllkernel32.dlladvapi32.dllole32.dllCannot alloc %X bytes for relocsSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequiredWS2_32.dllRPCRT4.dllGetProcessHeapGetWindowsDirectoryAKERNEL32.dllRegCloseKeyRegOpenKeyExWRegOpenKeyExARegCreateKeyExWADVAPI32.dllGetWindowsDirectoryWGetCPInfoRegQueryInfoKeyWRegEnumKeyWzcÃ.?AVMyWindowsChecker@@.?AV?$rpcrt4_hack@U_IMAGE_NT_HEADERS@@@@.?AVtcpip_hack@@.?AV?$import_holder@U_IMAGE_NT_HEADERS@@@CMN@@.?AVinmem_import_holder@CMN@@.?AVimport_holder_intf@CMN@@.?AVmodule_import@CMN@@aR.RnX.UJ^Aw%xyWf.Gkf%0X0m0>$?(?,?0?3&4;456?90:77g77>7[7`7|76#8*878^8~811_10#101#2020 11h1J36%7S77*717>7[8=!>&>9>>>7&7@7l7Â8N8V8z8:);4;>;\;0%0X0= >$>(>,>0>?,?4?\?|?.----/01/01/01KERNEL32.DLLmscoree.dllU%SystemRoot%\system32\svchost.exe%SystemRoot%\system32\svchostWSOCKTRANSPORTTCPIP6TCPIPSTORPORTSTORMINIPORTSOFTPCISCSIPORTSCSIMINIPORTSBP2PORTFCPORTPassiveWatchdogTimeoutsImageExecutionOptionsErrorPortStartTimeoutErrorPortCommTimeoutDisablePagingExecutiveDebuggerMaxModuleMsgsCountOperationsB\\.\Psapi.dllsWindows PowerShelltHost Process for Windows TasksWindows Problem Reporting 32 bitWindows Problem ReportingWindows Modules InstallermWindows Start-Up ApplicationtWindows Search IndexersWindows Server Initial Configuration TasksWindows Media PlayerDump Reporting ToolError ReporterrWindows Control Panel 32 bitWindows Control PanelWindows Connect Now - Config Registrar ServiceWindows Media Player Network Sharing ServiceWindows firewallWindows Error Reporting ServicetWindows DefendervError reporting serviceeWindows update serviceWindows Image AcquisitionWebClienttWindows Security Center Notification AppyWindows Based Script HostWindows installer 32 bitWindows installerWindows 16-bit Virtual MachineWindows Management InstrumentationWindows User Mode Driver ManagerMS tftpMS ftp 32 bitMS ftpMicrosoft Help and Support CenterCmd.exe 32 bitCmd.exeWindows Logon User Interface HostWindows updatetGoogle ChromerOpera Internet BrowserMozilla Thunderbird Mail and News ClientdFirefox browserServices.exe%SystemRoot%\msagent\agentsvr.exe%SystemRoot%\System32\dfrgfat.exe%SystemRoot%\System32\dfrgntfs.exe%SystemRoot%\System32\services.exe%SystemRoot%\System32\svchost.exe%SystemRoot%\System32\alg.exe%SystemRoot%\System32\spoolsv.exe%SystemRoot%\System32\net.exe%SystemRoot%\System32\net1.exe%SystemRoot%\System32\cmd.exe%SystemRoot%\System32\notepad.exe%SystemRoot%\System32\calc.exe%SystemRoot%\System32\PTF.exe%SystemRoot%\System32\tPTF.exe%SystemRoot%\System32\telnet.exe%SystemRoot%\System32\taskkill.exe%SystemRoot%\System32\ctfmon.exe%SystemRoot%\System32\wdfmgr.exe%SystemRoot%\System32\mmc.exe%SystemRoot%\System32\userinit.exe%SystemRoot%\System32\wbem\wmiprvse.exe%SystemRoot%\System32\wbem\wmiadap.exe%SystemRoot%\explorer.exe%SystemRoot%\System32\lsass.exe%SystemRoot%\System32\winlogon.exe%SystemRoot%\System32\LogonUI.exe%SystemRoot%\System32\wuauclt.exe%SystemRoot%\System32\wuauclt1.exe%SystemRoot%\System32\CCM\CcmExec.exe%SystemRoot%\System32\csrss.exe%SystemRoot%\System32\smss.exe\SystemRoot\System32\smss.exe%SystemRoot%\System32\inetsrv\w3wp.exe%SystemRoot%\System32\schtasks.exe%SystemRoot%\System32\tstheme.exe%SystemRoot%\System32\control.exe%SystemRoot%\System32\taskmgr.exe%SystemRoot%\System32\dwwin.exe%SystemRoot%\System32\drwtsn32.exe%SystemRoot%\System32\dumprep.exe%SystemRoot%\System32\dfssvc.exe%SystemRoot%\System32\dllhost.exe%SystemRoot%\System32\ntvdm.exe%SystemRoot%\System32\rundll32.exe%SystemRoot%\System32\msiexec.exe%SystemRoot%\System32\mshta.exe%SystemRoot%\System32\regsvr32.exe%SystemRoot%\System32\cscript.exe%SystemRoot%\System32\wscript.exe%SystemRoot%\System32\wscntfy.exe%SystemRoot%\System32\mstsc.exe%SystemRoot%\System32\dashost.exefar.exeFar.exeCLSID\{FC7D9E02-3F9E-11d3-93C0-00C04F72DAF7}\InprocServer32CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}\LocalServer32CLSID\{0002DF01-0000-0000-C000-000000000046}\LocalServer32iedw.exe%SystemRoot%\System32\oobechk.exe%SystemRoot%\System32\oobe.exe%SystemRoot%\System32\psxss.exe%SystemRoot%\System32\internat.exeAcroRd32.exeexcel.exeoutlook.exewinword.exepowerpnt.exewmplayer.exefirefox.exethunderbird.exeOpera.exeWinRAR.exe%SystemRoot%\System32\wininit.exe%SystemRoot%\System32\lsm.exe%SystemRoot%\System32\dwm.exe%SystemRoot%\System32\werfault.exe%SystemRoot%\System32\taskeng.exe%SystemRoot%\System32\conime.exe%SystemRoot%\System32\wudfhost.exe%SystemRoot%\System32\taskhost.exe%SystemRoot%\System32\conhost.exe%SystemRoot%\System32\rdpclip.exe%SystemRoot%\System32\SearchFilterHost.exe%SystemRoot%\System32\SearchProtocolHost.execsrss.exesvchost.exealg.exesPptpMiniportTcpippsapi.dll127.0.0.1\\.\pipe\\\.\mailslot\SOFTWARE\Microsoft\Windows NT\CurrentVersion\\.\Pipe\\\.\Mailslot\ncacn_ip_tcp:ncadg_ip_udp:\\pipe\\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SOFTWARE\Microsoft\PowerShell\1\ShellIds\Microsoft.PowerShellRemediationExeSOFTWARE\Classes\SCCM.VAppLauncher\shell\Open\commandSOFTWARE\Classes\CLSID\{00AAB372-0D6D-4976-B5F5-9BC7605E30BB}\LocalServer32SOFTWARE\Classes\CLSID\{3C296D07-90AE-4FAC-86F9-65EAA8B82D22}\LocalServer32SOFTWARE\Classes\CLSID\{D63B10C5-BB46-4990-A94F-E40B9D520160}\LocalServer32SOFTWARE\Classes\CLSID\{03e64e17-b220-4052-9b9b-155f9cb8e016}\LocalServer32SOFTWARE\Classes\CLSID\{1F69F884-285E-418E-9715-B9EEE402DD5F}\LocalServer32Software\Microsoft\Windows\CurrentVersion\WINEVT\publishersWindows checker1.0.0.3432wincheck.exe0, 0, 8, 16rSwooYMM.exe_1036_rwx_05990000_00001000:.text.rdata@.datarSwooYMM.exe_1036_rwx_06260000_00005000:.text`.rdata@.data.relocbrieflz.dllrSwooYMM.exe_1036_rwx_06270000_00020000:33.52878980,-86.74808730hXXps://twitter.com/dedricyoung/status/540256799258333184hXXp://VVV.fortressbtcaz.com/atm-locations/hXXps://twitter.com/ZenBox_Kiosk/status/544511003741134848hXXps://twitter.com/holdn2aces/status/539192798285955072hXXp://bitcoinmerchant.com/atm/hXXp://newsbtc.com/2014/06/14/los-angeles-slated-get-two-bitcoin-atms-next-week/hXXp://coinagellc.com/hXXp://coinucopia.io/hXXp://coinpath.us/hXXp://bitcoinmerchant.com/?gd_place=downtown-johnny-brownsVVV.coinspeaker.com/2014/09/10/exclusive-bitaccess-btm-launch-in-san-francisco/Skyhook Bitcoin ATM machine in San Marcos at Rossi's Pizza & Sports BarRossi's Pizza & Sports BarhXXp://bitcoinmerchant.com/places/rossis-pizza/hXXp://VVV.eventbrite.com/e/the-state-of-crypto-at-hero-city-at-draper-university-tickets-11764007463hXXp://VVV.publicwire.com/coin-citadel-announces-official-launch-with-installation-of-its-first-bitcoin-atm/hXXps://xbteller.com/locations/hXXps://VVV.xbteller.com/amagi-metals-home-second-denver-bitcoin-atm/hXXps://denverbitcoincenter.com/?page_id=139hXXp://VVV.reddit.com/r/Bitcoin/comments/28m7bg/photo_of_the_diy_bitcoin_atm_in_fort_collins/38.92182910,-77.04205270hXXp://VVV.washingtoncitypaper.com/blogs/citydesk/2014/12/02/the-diner-gets-d-c-s-first-bitcoin-atm/33.95813880,-83.37524090hXXp://VVV.reddit.com/r/Bitcoin/comments/2qheol/new_bitcoin_atm_in_downtown_athens_ga/33.77307770,-84.40334350hXXp://VVV.coinfucius.io/33.78539490,-84.41705430hXXp://VVV.reddit.com/r/Bitcoin/comments/2ddn9w/first_public_bitcoin_atm_vending_machine_in/33.77444410,-84.3712304033.94159090,-84.52270910hXXp://VVV.reddit.com/r/SPSU/comments/2hgykc/bitcoin_atm/hXXp://VVV.yelp.com/biz_photos/boise-techmall-boise-2?pt=biz_photo&ref=twitter&select=aoi04bUd6dtDxq_Bi5Us7w#aoi04bUd6dtDxq_Bi5Us7w41.94273670,-87.65328300hXXp://VVV.chicagotribune.com/news/local/breaking/chi-bitcoin-theres-an-atm-for-that-20140728,0,6190181.story41.85836980,-87.66027450hXXp://VVV.redleafchicago.com/2014/11/24/hello-world/41.91028290,-87.67650120hXXps://twitter.com/redleafatm/status/55011380609838694441.88849150,-87.63553370hXXp://VVV.reddit.com/r/Bitcoin/comments/2gsozf/review_of_robocoin_atm_at_the_merchandise_mart_in/Skyhook Bitcoin ATM machine in Edwardsville at Unkle Munkeys Coin ClubUnkle Munkeys Coin Club38.78777230,-89.98093500hXXps://twitter.com/UnkleMunkeyBrnd/status/523589044459286529/photo/141.88127910,-87.8388883039.77035910,-86.07256720101 S.Broadway , Leavenworth, KS 66048, United States39.31801960,-94.92100830hXXp://VVV.coinsignal.info/content/atm-locations-2/tom-anns-haircolorists-location/Skyhook Bitcoin ATM machine in Overland Park at New Century Imports LLCNew Century Imports LLC38.97129120,-94.7020330038.85501440,-94.67620420hXXps://twitter.com/bitcoinbeamer/status/53801449711851520042.35179480,-71.05668790hXXp://libertyteller.com/42.37269250,-71.1197847042.36267440,-71.0867047042.36345490,-71.10122130hXXp://VVV.ihavebitcoins.com/featured/restaurant-moksa-near-mit-gets-new-bitcoin-atm/42.36355600,-71.10113130hXXps://twitter.com/VeggieGalaxy/status/51676150765770752042.37258260,-71.11988000hXXp://zenbox.us/locations/39.28489060,-76.58884800hXXp://VVV.baltimoresun.com/business/bs-bz-bitcoin-atm-20141020-story.html42.49912210,-83.41944430hXXp://VVV.reddit.com/r/Bitcoin/comments/26v5wi/bitcoin_atm_now_at_the_bronx_deli_of_farmington/42.97936190,-85.67162640hXXp://VVV.reddit.com/r/Bitcoin/comments/2emxaa/grand_rapids_bitcoin_atm/39.10784540,-94.5843520038.80531710,-94.45661780hXXp://pressreleases.kcstar.com/release/messages/67131/38.81283130,-94.47858170hXXp://VVV.coinsignal.info/content/atm-locations-2/old-gold-guys-raymore-mo-location/38.58176160,-90.24435210hXXps://twitter.com/KryptozCom/status/502222720499589120/photo/135.91338200,-79.05472740hXXp://VVV.reddit.com/r/Bitcoin/comments/2jnd7d/north_carolinas_1st_btm/47.92078110,-97.09040020hXXp://coinoutletatm.com/university-of-north-dakotas-center-for-innovation-offers-new-feature-for-spring-semester-a-coinoutlet-bitcoin-atm/Skyhook Bitcoin ATM machine in Grand Forks at DOSHOST.netDOSHOST.net47.92156240,-97.09073040hXXp://VVV.doshost.net/archives/17641.23908300,-96.01426430hXXps://VVV.facebook.com/jonasthebtm42.91533290,-72.24737760hXXps://VVV.facebook.com/101Deals42.98514670,-71.46335890hXXp://VVV.reddit.com/r/Bitcoin/comments/2kw1u1/what_happens_when_you_buy_bitcoin_and_beer_in/hXXp://VVV.reddit.com/r/Bitcoin/comments/2eeg7q/albuquerque_nm_gets_two_bitcoin_vending_machines/hXXp://VVV.prweb.com/releases/2014/12/prweb12401593.htmhXXp://VVV.coinsetter.com/bitcoin-news/2014/05/22/d-becomes-first-casino-offer-robocoin-bitcoin-atm/hXXp://techcrunch.com/2014/07/30/robocoin-opens-the-first-bitcoin-atm-in-vegas-baby/hXXp://VVV.reddit.com/r/Bitcoin/comments/2igl72/nu_yalk_pizza_in_reno_nv_is_the_first_place_ive/42.65414720,-73.75056760hXXp://VVV.meetup.com/Capital-Region-Bitcoin-Meetup/events/188256382/40.72318430,-73.95300660hXXps://twitter.com/GetCoinCafe/status/499756817065730050/photo/142.92440570,-78.87723450hXXp://VVV.reddit.com/r/Bitcoinbuffalo/comments/2lzb29/first_bitcoin_atm_available_on_elmwood_and_bidwell/40.76572000,-73.99072000hXXps://VVV.facebook.com/photo.php?fbid=1010545369297244040.73407350,-74.00059840hXXp://VVV.reddit.com/r/Bitcoin/comments/2e0s3w/nyc_finally_getting_a_bitcoin_atm_this_thursday/40.76571540,-73.99068730hXXp://press.pycbitcoin.com/2014/10/bitcoin-atm-launches-following.html39.98534430,-83.00557680hXXps://twitter.com/champbronc2/status/52346928567998054441.66751060,-81.3718400036.18479680,-95.99309440hXXp://VVV.kjrh.com/news/local-news/internet-cafe-opens-in-north-tulsa-offers-bitcoin-machineGenesis Coin Bitcoin ATM machine in Portland at Float OnPortland4530 SE Hawthorne Blvd, Portland, OR 97215, United StateshXXp://VVV.reddit.com/r/Bitcoin/comments/2da9o4/so_found_this_today_first_bitcoin_atm_in_oregon/Robocoin Kiosk Bitcoin ATM machine in Portland at Pioneer Place Mall700 SW 5th Ave, Portland, OR 97204, United StateshXXp://VVV.bitcoinnw.com/bitcoin-kiosk.htmlSkyhook Bitcoin ATM machine in Portland at BrainSilo - PDX Hackerspace2119 N Kerby Ave #2, Portland, OR 97227, United States40.04612850,-76.29624260hXXp://fox43.com/2014/11/14/pas-first-bitcoin-atm-comes-to-lancaster/32.78545680,-79.93438070hXXp://newsbtc.com/2014/04/10/south-carolina-gets-first-robocoin-bitcoin-atm/30.22374910,-97.76737460hXXp://VVV.youtube.com/watch?v=9Ar8c9XxK4c30.27983720,-97.71969370hXXps://twitter.com/coinadvocate/status/50806057766803046430.26679860,-97.74201950hXXp://VVV.vcpost.com/articles/21752/20140219/robocoin-to-open-first-bitcoin-atm-in-the-us-on-february-20-2014.htm30.28229400,-97.74244140hXXps://twitter.com/TheBitMom/status/49392403371749785632.81172470,-96.81330560hXXp://VVV.meetup.com/Dallas-Bitcoin-User-Meetup/events/206533132/32.78350520,-96.78315360hXXp://VVV.reddit.com/r/Bitcoin/comments/2e6k65/dallas_welcomes_its_first_bitcoin_atm/32.80706400,-96.7973207033.20260650,-97.12707060hXXp://VVV.reddit.com/r/Bitcoin/comments/2cwqrr/first_bitcoin_atm_near_university_of_north_texas/29.75210320,-95.35772430hXXp://VVV.houstonchronicle.com/business/article/Bitcoin-ATM-gives-Houstonians-access-to-digital-5948585.phpCoinOutlet Bitcoin ATM machine in Salt Lake City at Overstock.com HeadquartersOverstock.com HeadquartershXXp://VVV.nasdaq.com/press-release/overstockcom-installs-bitcoin-atm-at-corporate-hq-20150109-0030039.00418990,-77.43031500hXXp://VVV.blockbox.io/bitcoin-machine/Skyhook Bitcoin ATM machine in Burlington at Blu-BinBurlington49 Church St, Burlington Town Center, Burlington, VT 05401, USA44.47881370,-73.21287710hXXps://VVV.cryptocoinsnews.com/first-bitcoin-atm-vermont/Robocoin Kiosk Bitcoin ATM machine in Seattle at Spitfire Sports BarSpitfire Sports BarhXXp://newsbtc.com/2014/05/01/two-way-bitcoin-atm-hits-seattle-washington/hXXp://dailyuw.com/archive/2014/10/01/news/bitcoin-atm-unveiled-condon-hallhXXp://pointofcoin.com/2015/01/09/bitcoin-atm-now-open-in-vancouver-westfield/43.04024220,-87.91463640hXXps://VVV.facebook.com/firstbtmofmkehXXp://bitcoinagile.com/48B7F/calgary-gets-first-ever-bitcoin-atm-courtesy-of-business-duo_streamhXXp://btcsolutions.ca/atm/hXXp://newsbtc.com/2014/02/26/robocoin-bitcoin-atm-debut-north-americas-largest-shopping-mall-thursday/hXXp://VVV.reddit.com/r/Bitcoin/comments/285ja2/247_bitcoin_atm_available_for_edmonton_and_area/hXXp://coinrangers.com/coin/hXXp://VVV.straight.com/blogra/663831/bitcoin-atm-coming-bcit-campus-burnabyhXXp://VVV.reddit.com/r/BitcoinCA/comments/2qok16/press_release_new_bitcoin_atms_hit_the_tricities/hXXps://twitter.com/ThirstyCamelCaf/status/518255929633304576Genesis Coin Bitcoin ATM machine in Port Moody at IBAY ComputersPort Moody2929 Saint Johns Street, Port Moody, BC V3H 2C2, CanadahXXp://VVV.bitsent.ca/maphXXp://VVV.bitnational.com/hXXps://twitter.com/Cdn_Crypto/status/543480858343403521Lamassu Bitcoin ATM machine in Vancouver at Decentral.bangtownDecentral.bangtownhXXp://VVV.reddit.com/r/Bitcoin/comments/28dfca/quadriga_cx_plans_to_install_30_bitcoin_atms_in/ci9zg3chXXp://VVV.straight.com/blogra/669211/more-bitcoin-atms-vancouverhXXp://VVV.straight.com/blogra/587466/vancouver-now-home-two-bitcoin-atmshXXp://VVV.coindesk.com/money-spinners-london-break-bitcoin-atm-record/hXXp://newsbtc.com/2014/06/05/vancouver-second-robocoin-bitcoin-atm/hXXp://VVV.vancitybuzz.com/2013/10/first-in-line-at-the-worlds-first-bitcoin-atm/hXXps://twitter.com/btcsolutionsca/status/559194591966949376hXXp://VVV.bitbrokersinc.com/#atmhXXp://newsbtc.com/2014/04/21/genesis1-bitcoin-atm-enters-service-whistler-british-columbia/49.88150330,-97.12862610hXXp://winnipeg.ctvnews.ca/winnipeg-s-first-bitcoin-atm-now-accepting-cash-1.168852949.89338320,-97.11771920hXXps://VVV.facebook.com/evolutionbitcoin/photos/a.1488240341457496.1073741829.1476806912600839/1493331734281690/44.63694800,-63.58923930hXXp://unews.ca/dal-gets-its-own-bitcoin-atm/44.64621300,-63.57422600hXXp://VVV.cbc.ca/news/canada/nova-scotia/bitcoin-atm-in-halifax-a-first-in-atlantic-canada-1.260913143.52108390,-80.21082490hXXp://VVV.guelphmercury.com/news-story/4584672-bitcoin-atms-open-door-for-digital-currency-in-guelph/45.29577870,-75.89239140hXXp://VVV.reddit.com/r/BitcoinCA/comments/2bk7mc/bitcoin_in_the_burbs729_kanata/43.57768340,-79.61418730hXXp://VVV.coindesk.com/money-spinners-canada-grow-already-prominent-atm-presence/46.33128330,-79.46549620hXXp://crypto-kiosk.ca/45.42919230,-75.69278320hXXp://VVV.resilient21.com/atm/45.42371560,-75.68125520hXXp://VVV.reddit.com/r/Bitcoin/comments/25viks/lamassu_atm_now_live_in_father_and_sons_in_ottawa/43.64514770,-79.39501910hXXp://VVV.reddit.com/r/Bitcoin/comments/2djjfm/fleet_of_six_new_bitcoin_atms_arrive_in_shopping/43.64094260,-79.3938500043.66240410,-79.42280600hXXp://torontogold.com/buy-bitcoin/43.66622250,-79.3849191043.65874250,-79.43919770hXXps://twitter.com/QuadrigaCoinEx/status/52548849360332800045.45554590,-73.46503580hXXp://instacoinatm.com/locations.html45.43482740,-73.67417530hXXp://instacoinatm.com/bitcoin-lachine-en.html45.56092640,-73.741387303485 Boulevard, St.Laurent, Montreal Quebec, Canada45.51312360,-73.5707337045.53580200,-73.57175980hXXp://VVV.reddit.com/r/Bitcoin/comments/25df3t/first_2way_bitcoin_atm_in_montreal/45.49817570,-73.65729260hXXps://twitter.com/BitcoinBrands/status/51997457456667443545.51396230,-73.5728598045.51059480,-73.6891456045.50008080,-73.5758708045.52475440,-73.5846393045.49819020,-73.62641400hXXp://VVV.autocoinage.com/45.54618810,-73.5760680046.83774910,-71.22319340hXXp://newsbtc.com/2014/04/05/genesis1-bitcoin-atm-goes-active-duty-quebec-city/45.59196170,-73.5814444045.89097500,-74.1617332045.71786010,-73.51134730hXXp://VVV.fox5vegas.com/story/25851972/first-lamassu-bitcoin-atm-to-open-in-quebec45.48777730,-73.58653400hXXp://VVV.reginabitcoin.ca/hXXps://localbitcoins.com/ad/109315/bitcoin-atm-3-morgan-terrace-bardon-qld-4065-australiahXXp://ezibit.com.au/atmDiamond Circle Bitcoin ATM machine in Burleigh Heads at Burleigh Bluff CafeBurleigh HeadsBurleigh Bluff CafeOld Burleigh Theatre Arcade, Shop 1 / 66 Goodwin Terrace, Burleigh Heads 4220, Australiadiamondcircle.net/blogs/news/15483573-diamond-circle-lauches-bitcoin-atmhXXp://VVV.canberratimes.com.au/act-news/canberra-latest-addition-to-bitcoin-boom-with-hightech-atm-20140719-zuri2.htmlhXXps://twitter.com/genesiscoin/status/502357087439962113hXXps://twitter.com/MutantB/status/548663007492857856hXXp://VVV.bitrocket.co/#locationshXXps://twitter.com/PolyEsterBooks/status/477610976041119744hXXp://VVV.themercury.com.au/news/tasmania/tasmanias-first-bitcoin-atm-opens-in-launceston/story-fnj4f7k1-1227183495527hXXp://VVV.reddit.com/r/Bitcoin/comments/2ac2a9/my_first_bitcoin_atm_experience/ciui3j6hXXps://localbitcoins.com/ad/85099/bitcoin-atm-673-bourke-st-melbourne-vic-3000-australiahXXp://newsbtc.com/2014/05/29/third-bitcoin-atm-australia-launches-melbourne/hXXp://VVV.reddit.com/r/Bitcoin/comments/1u09q9/bitcoin_atms_for_australia_the_first_in_melbourne/hXXps://VVV.getbitcoin.com.au/bitcoin-news/melbournes-chapel-st-gets-new-bitcoin-atmhXXp://VVV.coinstation.com.au/hXXp://bitscan.com/articles/sydneys-first-bitcoin-atm-opens-to-the-public/hXXp://VVV.reddit.com/r/Bitcoin/comments/2cr2ga/bitrocket_launches_bitcoin_machine_at_the_hub/hXXp://VVV.smh.com.au/business/banking-and-finance/bitcoin-goes-retail-with-westfield-atm-20140415-36ozb.html50.83102130,-0.13610500hXXps://twitter.com/martindotnet/status/54921348224020480250.82617170,-0.1386061050.82251260,-0.14137330hXXp://VVV.brightonandhovenews.org/2014/08/21/brighton-gets-uks-second-ever-bitcoin-atm/3381251.45369470,-2.59485510hXXp://bitcoinmagazine.com/13315/satoshipoint-bitcoin-atms-uk/52.23544280,0.15405730hXXps://twitter.com/nigelstreet/status/52270479064485888054.14935760,-4.48051590hXXp://VVV.qwikbit.com/#locations11:00 - 17:0055.86577750,-4.26662690hXXp://VVV.digitalspy.co.uk/gaming/news/a570714/cex-store-trials-bitcoin-purchases-in-glasgow.html51.52257850,-0.08575830hXXps://twitter.com/campuslondon/status/52920854214714982451.51706150,-0.08184590hXXp://VVV.vaiex.com/ATM/51.52736830,-0.07827520hXXp://bitcoinexaminer.org/buying-btc-in-london-just-got-easier-new-lamassu-machine-at-the-old-shoreditch-station/51.52090530,-0.12117420hXXp://VVV.coindesk.com/robocoin-machine-heats-competition-londons-bitcoin-atms/51.52561740,-0.0877112051.51662110,-0.1331826051.52229700,-0.07807200hXXps://coinreport.net/vancouver-bitcoiniacs-expands-globally/53.48339390,-2.24177420hXXps://uk.webuy.com/blog/feature.php?article=tag:blogger.com,1999:blog-1918688228918285001.post-154706367739965569253.48075070,-2.23406650hXXp://VVV.bitcoinmanchester.org.uk/meetings/bitcoinmanchester-13/53.37984650,-1.46291610hXXps://twitter.com/SheffieldBTC/status/54086794405898240160.18539810,24.81233980hXXp://bittimaatti.fi/locations60.16914630,24.93319580hXXps://bittiraha.fi/content/kampin-kauppakeskukseen-bitcoin-automaatti60.17183100,24.94120000hXXp://hotbutler.com/online/kiosks.html60.19922800,24.93311400HotButler Bitcoin ATM machine in Helsinki at Port of Helsinki (West terminal)Port of Helsinki (West terminal)60.16112520,24.9578823060.23755910,24.85771360hXXps://bittiraha.fi/content/viikkokatsaus-392014-paypal-bittimaatit-simpsonit-greenpeace-ja-bitcoin-kansanedustaja60.17332440,24.9410248060.16410100,24.94411100hXXp://VVV.coindesk.com/localbitcoins-manufacturing-low-cost-bitcoin-atm/60.16328730,24.9384361062.24431450,25.74849330hXXps://bittiraha.fi/bittimaatti#english61.49911990,23.75485490hXXp://yle.fi/uutiset/eurot_vaihtuvat_virtuaalirahaksi_uusissa_automaateissa/750342262.98835870,27.7272963060.45023300,22.2608092052.37217120,4.8765958052.37953760,4.89438530hXXp://VVV.reddit.com/r/Bitcoin/comments/2on8l2/amsterdam_new_twoway_mr_bitcoin_atm_café_kobalt/52.37531800,4.90124400hXXp://bitcoinexaminer.org/new-btcomatic-vending-machine-arrives-amsterdam/52.36559890,4.88973580hXXps://twitter.com/JacobInnopay/status/52822640321364787451.97791810,5.90557970hXXps://twitter.com/coindesk/status/49705081503168512051.98387540,5.91079310hXXps://twitter.com/fourdigits/status/54595781022872371252.01123600,4.35799600hXXp://VVV.reddit.com/r/Bitcoin/comments/28ejm9/cool_news_we_reached_100_bitcoin_atms_worldwide/cia8w3o52.54163170,5.71310940hXXps://twitter.com/bitsendnl/status/501368865897869312/photo/152.07493490,4.31865720hXXp://VVV.cryptocoinsnews.com/2014/03/20/bitcoin-community-helps-boulevard-get-btc-atm/52.07816510,4.30528030hXXp://coincourant.nl/nieuwe-btm-in-haagse-barbershop-co/52.21412790,5.1472718051.58866400,4.52880010hXXp://VVV.byelex.nl/en/about-byelex/news/byecoin-launches-first-bitcoin-atm-historical-location-brabanthXXps://VVV.facebook.com/572672896184976/photos/pb.572672896184976.-2207520000.1417980856./679464232172508/hXXp://VVV.chinadailyasia.com/hknews/2014-11/26/content_15195342.htmlhXXps://twitter.com/genesiscoin/status/52645835430287360224/7/365hXXp://VVV.cryptocoinsnews.com/news/hk-bitcoin-atm-store-hong-kong-now-open-247365/2014/05/19hXXp://VVV.reddit.com/r/Bitcoin/comments/27mm2c/bitculus_robocoin_atm_set_up_in_hong_kongs/hXXp://hongkong.coconuts.co/2014/07/24/spotted-bitcoin-atm-being-set-bonham-road-near-hkus-east-gatehXXp://VVV.reddit.com/r/Bitcoin/comments/20ai4d/hong_kongs_first_atm_goes_live_at_anx_buy_bitcoin/1.29210310,103.85555850hXXp://VVV.straitstimes.com/breaking-news/money/story/bitcoin-atms-open-singapore-201402281.31042690,103.86239990hXXps://twitter.com/villeohman/status/5381991948012748811.29681800,103.78699000hXXps://twitter.com/wizgotD/status/5153814103081738241.29670890,103.85009400hXXp://coinrepublic.com/4-bitcoin-atms-now-active-in-singapore/1.29491650,103.841232701.30336180,103.853188001.29133350,103.850128001.28118890,103.84866090hXXp://imaginarymarkets.com/singapores-robocoin-bitcoin-atm-to-be-deployed-17-march-launch/1.29179200,103.83982300hXXp://imaginarymarkets.com/asias-first-bitcoin-atm-tembusu-terminals-pte-ltd-launches-2nd-machine-brings-singapore-count-to-8-eclat-office-club/1.28755410,103.84928990hXXp://VVV.bloomberg.com/news/2014-02-27/bitcoin-machine-allowing-cash-exchange-installed-in-singapore.html1.29680660,103.78694290hXXps://VVV.facebook.com/tembusu.sg/photos/a.712722372127818.1073741827.644000805666642/712721692127886/?type=1hXXp://newsbtc.com/2014/05/25/two-way-bitcoin-atm-hits-beijings-art-district/G/F, no Pelota Basca Avenida , do Dr.Rodrigo Rodrigues no. 1470-1526, Macau, ChinahXXps://VVV.facebook.com/572672896184976/photos/a.578346215617644.1073741827.572672896184976/620802604705338/hXXp://VVV.bitcoinatm.com.hk/#!3-More-Bitcoinnect-in-Macau/c1aes/CBA9F3AD-BFCF-4AD6-9989-1F9ADCBDA51ChXXp://VVV.coindesk.com/btc-china-launches-first-soft-bitcoin-atm-interface-international-markets/hXXps://twitter.com/genesiscoin/status/535492734304268288hXXps://VVV.facebook.com/permalink.php?story_fbid=652703991515199&id=57267289618497644.31587800,9.32790540hXXp://VVV.rischiocalcolato.it/2014/12/moneta-digitale-ed-ecco-il-secondo-bitcoin-atm-liguria-chiavari.html44.42836190,8.8931741045.47289160,9.21127100hXXp://VVV.newmoney.it/robocoin-bitcoin-milano/43.72724720,10.42213790hXXps://bitcointalk.org/index.php?topic=662410.044.69620460,10.62998500hXXps://bitcointalk.org/index.php?topic=769333.041.88223890,12.46731540hXXp://VVV.coindesk.com/bit-wallet-launches-italys-first-home-grown-bitcoin-atm/41.90530590,12.51846790hXXps://twitter.com/RobocoinItalia/status/53356057462256844846.04025430,13.25319300hXXps://bitcointalk.org/index.php?topic=626650.049.18890020,16.61428180hXXp://VVV.fxstreet.cz/zpravodajstvi-67660.html49.83692970,18.28209750hXXp://VVV.bitcomat.cz/cz/49.72380190,13.3362084050.10003050,14.43006950hXXp://VVV.coindesk.com/czech-bitcoin-atm-maker-general-bytes-ready-ship-worldwide/50.07688430,14.40529680hXXp://praguepost.com/finance/39299-bitcoin-center-opens-in-prague50.09851280,14.43659560hXXp://praguepost.com/finance/37311-hn-prague-gets-its-first-bitcoin-atmDelnicka 43, 170 00 Praha 7, Czech Republic50.10335540,14.45046580hXXps://twitter.com/generalbytes/status/52156255524935270450.08632880,14.42709620hXXps://VVV.facebook.com/wBTCb/posts/151357315221327946.21130500,6.14854240hXXp://VVV.tdg.ch/high-tech/bitcoin-gagne-economie-reelle-geneve/story/2740603646.20792190,6.14383140hXXps://VVV.facebook.com/BitcoinSuisse/photos/pb.479796742127588.-2207520000.1420747054./760056330768293/46.51851660,6.63404870hXXps://twitter.com/SbexCh/status/53847730399583846546.00875640,8.95707690BitXatm Bitcoin ATM machine in St.Gallen at Restaurant HornliSt.Gallen47.42566170,9.3753714047.38483210,8.52094220hXXps://VVV.facebook.com/media/set/?set=a.612661035507824.1073741833.479796742127588&type=147.37103970,8.54350740hXXp://VVV.bitcoinnews.ch/bitcoin-bankomat-in-zuerich-kafi-schoffel/BTCPoint Bitcoin ATM machine in Barcelona at MOB (Makers of Barcelona)41.39185090,2.17717930hXXps://twitter.com/steffenhiller/status/51905519581766041638.90942170,1.43016140hXXp://VVV.noudiari.es/2014/12/abre-en-ibiza-el-primer-cajero-de-bitcoins/BTCPoint Bitcoin ATM machine in Madrid at Bar-Restaurante La Complutense40.48560210,-3.36047320hXXp://VVV.cryptocoinsnews.com/es/noticias-sobre-bitcoin/nuevo-cajero-de-bitcoin-en-madrid/2014/05/2840.43236760,-3.68716140hXXps://bitcointalk.org/index.php?topic=655437.msg7750907#msg775090740.42088450,-3.69134470hXXp://VVV.oroyfinanzas.com/2014/10/primer-cajero-bitcoin-mundo-madrid-robocoin/10.00 - 21.0050.27049910,19.00498190hXXp://bitcoinist.net/the-first-robocoin-in-poland/52.23028580,21.01690850hXXp://VVV.coindesk.com/poland-gets-first-bitcoin-atm-30-planned/52.23193530,21.00287500hXXp://bitcoinomat.pl/bankomat-bitcoin-bobby-burger/51.09974330,17.02875400hXXp://VVV.bitello.pl/19.37081980,-99.16651330hXXps://twitter.com/BlueDavid/status/48227273514224025819.05419170,-98.22964580hXXp://bitsoex.tumblr.com/post/87584183654/bitsos-bitcoin-atm-in-mexico-mexican-bitcoinhXXp://VVV.coindesk.com/mexicos-first-bitcoin-atms-will-also-deal-altcoins/46.07609200,14.51149800hXXp://VVV.reddit.com/r/Bitcoin/comments/22olp3/first_bitcoin_atm_in_slovenia/46.05259240,14.50379240hXXps://twitter.com/GoCommunicate/status/50758612030602854546.05212800,14.50428600hXXp://VVV.sloveniatimes.com/slovenia-gets-first-bitcoin-atm45.97346920,14.30303300hXXps://twitter.com/CoinmachineSi/status/468824419671232514hXXp://japancryptocoin.org/coinblog/bitcoin-buy-atm-skyhook/hXXps://twitter.com/wiz/status/555700667155628032hXXp://VVV.live5news.com/story/25642271/first-bitcoin-atm-launched-in-japanhXXp://internetcom.jp/busnews/20140618/6.htmlhXXp://VVV.coindesk.com/south-korea-launches-first-bitcoin-atm/hXXps://localbitcoins.com/ad/89406/bitcoin-atm-39-5-jongno-2i-ga-jongno-gu-seoul-south-koreaTuesdays 5pm-10pm, For opening hours on other days, check on hXXps://hackerspace-bamberg.de49.90196940,10.89286830hXXp://log.hackerspace-bamberg.de/post/90992433175/first-open-source-bitcoin-atm-projectskyhook-and51.47997470,7.21683130hXXps://VVV.facebook.com/events/1508009722777902/48.78895690,9.15275710hXXp://VVV.reddit.com/r/Bitcoin/comments/2k3wuz/the_bitcoin_accepting_bar_of_the_community/32.06467770,34.77047510hXXps://coinreport.net/first-israeli-bitcoin-atm-debut/32.06462000,34.77047970hXXp://VVV.i24news.tv/en/tv/replay/economy/385220961200132.07526250,34.77496880hXXp://VVV.bitcoinatm.co.il/#!home/mainPage55.68903600,12.57368900hXXp://VVV.reddit.com/r/Bitcoin/comments/2m3tvv/denmarks_copencoincom_btcatm_hattrick_3rd_danish/55.68138990,12.58274530hXXp://copencoin.com/bitcoin-atms-in-copenhagen55.67872750,12.5788788044.42960520,26.10457800hXXp://bitcoinromania.ro/bancomat/primul-robocoin-bitcoin-atm-in-romania/44.45234900,26.07710830hXXp://bitcoinromania.ro/bancomat/sambata-22-noiembrie-1400-bitcoin-atm-2-soft-opening/3.14320200,101.66743500hXXp://VVV.coindesk.com/money-spinners-weeks-bitcoin-atm-news-2/5.43826630,100.3100268053.34114180,-6.26323250hXXp://VVV.meetup.com/Bitcoin-Dublin/events/219500057/?eventId=219500057&action=detail53.34741170,-6.26741900hXXp://bitcoin-atm.ie/#contact51.21898230,4.4082943051.04981530,3.72129120hXXp://VVV.reddit.com/r/Bitcoin/comments/2hi8x9/first_bitcoin_atm_in_belgium_ghent_just_heard_it/Skyhook Bitcoin ATM machine in Bois-Colombes at Computer Store PcDuo.frComputer Store PcDuo.fr48.91338820,2.27223980hXXp://cointelegraph.com/news/112466/french-startup-mineoncloud-announces-third-bitcoin-atm-in-france48.86772080,2.34985410hXXp://VVV.coindesk.com/europes-first-bitcoin-centre-open-france/-23.55371800,-46.68803970-23.58742430,-46.67904680hXXp://exame.abril.com.br/seu-dinheiro/noticias/sao-paulo-recebe-1o-caixa-eletronico-de-bitcoins-do-paisLamassu Bitcoin ATM machine in Kuta, Bali at Bitcoin.co.id Information CenterBitcoin.co.id Information Center-8.70138280,115.16982840Jalan Monkey Forest 88X, Ubud, Gianyar, Bali 80571, Indonesia-8.51802720,115.26141470hXXps://twitter.com/SUWBali/status/53397513265862246547.07358420,15.43280210hXXp://VVV.reddit.com/r/Bitcoin/comments/28qqeb/first_austrian_bitcoin_atm_available_on_june_23rd/48.18629550,16.35486310hXXps://twitter.com/TeamTimelack/status/49745612482913075248.14279151,17.10948980hXXp://VVV.mojbitcoin.sk/48.71785700,21.26344080hXXp://VVV.decentralplan.com/-26.00267480,28.07638430hXXp://VVV.coindesk.com/africas-first-bitcoin-atm-ready-may-launch/50.45442590,30.50613500hXXp://VVV.coinside.ru/2014/09/09/pervoe-posolstvo-bitcoin-v-ukraine/hXXps://localbitcoins.com/ad/89661/bitcoin-atm-no-151-section-1-dunhua-south-rd-daan-district-taipei-city-taiwan-10659.33199500,18.06796440hXXps://VVV.facebook.com/Safello/photos/pb.162293217287730.-2207520000.1414696123./272863666230684/?type=1&theaterhXXps://twitter.com/genesiscoin/status/50124252592801382542.84321230,74.59018650hXXp://eurasianet.org/node/68876-34.54299940,-58.48266100hXXp://panampost.com/belen-marty/2014/09/09/argentinas-first-bitcoin-atm-open-for-business/47.49811810,19.05542890hXXp://bitcoinist.net/first-hungarian-bitcoin-atm-debuts-in-downtown-budapest/45.81736090,15.97632740hXXp://crobitcoin.com/prvi-batm-u-hrvatskoj/42.67065800,23.35110050hXXp://VVV.bitcoin.bg/bitomat.htmlhXXp://VVV.nzherald.co.nz/business/news/article.cfm?c_id=3&objectid=11230162-25.29692970,-57.58048030hXXps://VVV.facebook.com/BeOkayParaguay/photos/pb.209762075870385.-2207520000.1415391354./326046260908632/$500-$60027.00712470,49.66037450hXXp://VVV.openstreetmap.org/node/2574072438PortugalAvenida Fontes Pereira de Melo 42E, 1050-094 Lisboa, Portugal38.73223780,-9.14558710hXXp://bitcoinist.net/portuguese-entrepreneur-launches-first-100-portuguese-made-bitcoin-atm/Skyhook Bitcoin ATM machine in Makati at Bitmarket.ph OfficesBitmarket.ph OfficeshXXp://VVV.bitmarket.ph/atm44.81206010,20.45877970hXXp://VVV.netokracija.com/bitcoin-atm-beograd-86437Burlington, VT (1)Portland, OR (3)Port Moody, BC (1)Burleigh Heads (1)St.Gallen (1)rSwooYMM.exe_1036_rwx_06290000_00079000:33.52878980,-86.74808730hXXps://twitter.com/dedricyoung/status/540256799258333184hXXp://VVV.fortressbtcaz.com/atm-locations/hXXps://twitter.com/ZenBox_Kiosk/status/544511003741134848hXXps://twitter.com/holdn2aces/status/539192798285955072hXXp://bitcoinmerchant.com/atm/hXXp://newsbtc.com/2014/06/14/los-angeles-slated-get-two-bitcoin-atms-next-week/hXXp://coinagellc.com/hXXp://coinucopia.io/hXXp://coinpath.us/hXXp://bitcoinmerchant.com/?gd_place=downtown-johnny-brownsVVV.coinspeaker.com/2014/09/10/exclusive-bitaccess-btm-launch-in-san-francisco/Skyhook Bitcoin ATM machine in San Marcos at Rossi's Pizza & Sports BarRossi's Pizza & Sports BarhXXp://bitcoinmerchant.com/places/rossis-pizza/hXXp://VVV.eventbrite.com/e/the-state-of-crypto-at-hero-city-at-draper-university-tickets-11764007463hXXp://VVV.publicwire.com/coin-citadel-announces-official-launch-with-installation-of-its-first-bitcoin-atm/hXXps://xbteller.com/locations/hXXps://VVV.xbteller.com/amagi-metals-home-second-denver-bitcoin-atm/hXXps://denverbitcoincenter.com/?page_id=139hXXp://VVV.reddit.com/r/Bitcoin/comments/28m7bg/photo_of_the_diy_bitcoin_atm_in_fort_collins/38.92182910,-77.04205270hXXp://VVV.washingtoncitypaper.com/blogs/citydesk/2014/12/02/the-diner-gets-d-c-s-first-bitcoin-atm/33.95813880,-83.37524090hXXp://VVV.reddit.com/r/Bitcoin/comments/2qheol/new_bitcoin_atm_in_downtown_athens_ga/33.77307770,-84.40334350hXXp://VVV.coinfucius.io/33.78539490,-84.41705430hXXp://VVV.reddit.com/r/Bitcoin/comments/2ddn9w/first_public_bitcoin_atm_vending_machine_in/33.77444410,-84.3712304033.94159090,-84.52270910hXXp://VVV.reddit.com/r/SPSU/comments/2hgykc/bitcoin_atm/hXXp://VVV.yelp.com/biz_photos/boise-techmall-boise-2?pt=biz_photo&ref=twitter&select=aoi04bUd6dtDxq_Bi5Us7w#aoi04bUd6dtDxq_Bi5Us7w41.94273670,-87.65328300hXXp://VVV.chicagotribune.com/news/local/breaking/chi-bitcoin-theres-an-atm-for-that-20140728,0,6190181.story41.85836980,-87.66027450hXXp://VVV.redleafchicago.com/2014/11/24/hello-world/41.91028290,-87.67650120hXXps://twitter.com/redleafatm/status/55011380609838694441.88849150,-87.63553370hXXp://VVV.reddit.com/r/Bitcoin/comments/2gsozf/review_of_robocoin_atm_at_the_merchandise_mart_in/Skyhook Bitcoin ATM machine in Edwardsville at Unkle Munkeys Coin ClubUnkle Munkeys Coin Club38.78777230,-89.98093500hXXps://twitter.com/UnkleMunkeyBrnd/status/523589044459286529/photo/141.88127910,-87.8388883039.77035910,-86.07256720101 S.Broadway , Leavenworth, KS 66048, United States39.31801960,-94.92100830hXXp://VVV.coinsignal.info/content/atm-locations-2/tom-anns-haircolorists-location/Skyhook Bitcoin ATM machine in Overland Park at New Century Imports LLCNew Century Imports LLC38.97129120,-94.7020330038.85501440,-94.67620420hXXps://twitter.com/bitcoinbeamer/status/53801449711851520042.35179480,-71.05668790hXXp://libertyteller.com/42.37269250,-71.1197847042.36267440,-71.0867047042.36345490,-71.10122130hXXp://VVV.ihavebitcoins.com/featured/restaurant-moksa-near-mit-gets-new-bitcoin-atm/42.36355600,-71.10113130hXXps://twitter.com/VeggieGalaxy/status/51676150765770752042.37258260,-71.11988000hXXp://zenbox.us/locations/39.28489060,-76.58884800hXXp://VVV.baltimoresun.com/business/bs-bz-bitcoin-atm-20141020-story.html42.49912210,-83.41944430hXXp://VVV.reddit.com/r/Bitcoin/comments/26v5wi/bitcoin_atm_now_at_the_bronx_deli_of_farmington/42.97936190,-85.67162640hXXp://VVV.reddit.com/r/Bitcoin/comments/2emxaa/grand_rapids_bitcoin_atm/39.10784540,-94.5843520038.80531710,-94.45661780hXXp://pressreleases.kcstar.com/release/messages/67131/38.81283130,-94.47858170hXXp://VVV.coinsignal.info/content/atm-locations-2/old-gold-guys-raymore-mo-location/38.58176160,-90.24435210hXXps://twitter.com/KryptozCom/status/502222720499589120/photo/135.91338200,-79.05472740hXXp://VVV.reddit.com/r/Bitcoin/comments/2jnd7d/north_carolinas_1st_btm/47.92078110,-97.09040020hXXp://coinoutletatm.com/university-of-north-dakotas-center-for-innovation-offers-new-feature-for-spring-semester-a-coinoutlet-bitcoin-atm/Skyhook Bitcoin ATM machine in Grand Forks at DOSHOST.netDOSHOST.net47.92156240,-97.09073040hXXp://VVV.doshost.net/archives/17641.23908300,-96.01426430hXXps://VVV.facebook.com/jonasthebtm42.91533290,-72.24737760hXXps://VVV.facebook.com/101Deals42.98514670,-71.46335890hXXp://VVV.reddit.com/r/Bitcoin/comments/2kw1u1/what_happens_when_you_buy_bitcoin_and_beer_in/hXXp://VVV.reddit.com/r/Bitcoin/comments/2eeg7q/albuquerque_nm_gets_two_bitcoin_vending_machines/hXXp://VVV.prweb.com/releases/2014/12/prweb12401593.htmhXXp://VVV.coinsetter.com/bitcoin-news/2014/05/22/d-becomes-first-casino-offer-robocoin-bitcoin-atm/hXXp://techcrunch.com/2014/07/30/robocoin-opens-the-first-bitcoin-atm-in-vegas-baby/hXXp://VVV.reddit.com/r/Bitcoin/comments/2igl72/nu_yalk_pizza_in_reno_nv_is_the_first_place_ive/42.65414720,-73.75056760hXXp://VVV.meetup.com/Capital-Region-Bitcoin-Meetup/events/188256382/40.72318430,-73.95300660hXXps://twitter.com/GetCoinCafe/status/499756817065730050/photo/142.92440570,-78.87723450hXXp://VVV.reddit.com/r/Bitcoinbuffalo/comments/2lzb29/first_bitcoin_atm_available_on_elmwood_and_bidwell/40.76572000,-73.99072000hXXps://VVV.facebook.com/photo.php?fbid=1010545369297244040.73407350,-74.00059840hXXp://VVV.reddit.com/r/Bitcoin/comments/2e0s3w/nyc_finally_getting_a_bitcoin_atm_this_thursday/40.76571540,-73.99068730hXXp://press.pycbitcoin.com/2014/10/bitcoin-atm-launches-following.html39.98534430,-83.00557680hXXps://twitter.com/champbronc2/status/52346928567998054441.66751060,-81.3718400036.18479680,-95.99309440hXXp://VVV.kjrh.com/news/local-news/internet-cafe-opens-in-north-tulsa-offers-bitcoin-machineGenesis Coin Bitcoin ATM machine in Portland at Float OnPortland4530 SE Hawthorne Blvd, Portland, OR 97215, United StateshXXp://VVV.reddit.com/r/Bitcoin/comments/2da9o4/so_found_this_today_first_bitcoin_atm_in_oregon/Robocoin Kiosk Bitcoin ATM machine in Portland at Pioneer Place Mall700 SW 5th Ave, Portland, OR 97204, United StateshXXp://VVV.bitcoinnw.com/bitcoin-kiosk.htmlSkyhook Bitcoin ATM machine in Portland at BrainSilo - PDX Hackerspace2119 N Kerby Ave #2, Portland, OR 97227, United States40.04612850,-76.29624260hXXp://fox43.com/2014/11/14/pas-first-bitcoin-atm-comes-to-lancaster/32.78545680,-79.93438070hXXp://newsbtc.com/2014/04/10/south-carolina-gets-first-robocoin-bitcoin-atm/30.22374910,-97.76737460hXXp://VVV.youtube.com/watch?v=9Ar8c9XxK4c30.27983720,-97.71969370hXXps://twitter.com/coinadvocate/status/50806057766803046430.26679860,-97.74201950hXXp://VVV.vcpost.com/articles/21752/20140219/robocoin-to-open-first-bitcoin-atm-in-the-us-on-february-20-2014.htm30.28229400,-97.74244140hXXps://twitter.com/TheBitMom/status/49392403371749785632.81172470,-96.81330560hXXp://VVV.meetup.com/Dallas-Bitcoin-User-Meetup/events/206533132/32.78350520,-96.78315360hXXp://VVV.reddit.com/r/Bitcoin/comments/2e6k65/dallas_welcomes_its_first_bitcoin_atm/32.80706400,-96.7973207033.20260650,-97.12707060hXXp://VVV.reddit.com/r/Bitcoin/comments/2cwqrr/first_bitcoin_atm_near_university_of_north_texas/29.75210320,-95.35772430hXXp://VVV.houstonchronicle.com/business/article/Bitcoin-ATM-gives-Houstonians-access-to-digital-5948585.phpCoinOutlet Bitcoin ATM machine in Salt Lake City at Overstock.com HeadquartersOverstock.com HeadquartershXXp://VVV.nasdaq.com/press-release/overstockcom-installs-bitcoin-atm-at-corporate-hq-20150109-0030039.00418990,-77.43031500hXXp://VVV.blockbox.io/bitcoin-machine/Skyhook Bitcoin ATM machine in Burlington at Blu-BinBurlington49 Church St, Burlington Town Center, Burlington, VT 05401, USA44.47881370,-73.21287710hXXps://VVV.cryptocoinsnews.com/first-bitcoin-atm-vermont/Robocoin Kiosk Bitcoin ATM machine in Seattle at Spitfire Sports BarSpitfire Sports BarhXXp://newsbtc.com/2014/05/01/two-way-bitcoin-atm-hits-seattle-washington/hXXp://dailyuw.com/archive/2014/10/01/news/bitcoin-atm-unveiled-condon-hallhXXp://pointofcoin.com/2015/01/09/bitcoin-atm-now-open-in-vancouver-westfield/43.04024220,-87.91463640hXXps://VVV.facebook.com/firstbtmofmkerSwooYMM.exe_1036_rwx_06320000_00004000:Burlington, VT (1)Portland, OR (3)rSwooYMM.exe_1036_rwx_06430000_00001000:notepad.exe "%Documents and Settings%\%current user%\myfile"rSwooYMM.exe_1036_rwx_06440000_00001000:%Documents and Settings%\%current user%\myfilerSwooYMM.exe_1036_rwx_06450000_00060000:.text`.rdata@.data.reloct#<.th>?.tS;?.tT;?.tV;\$83\$4#3\$(#\$$3&&&&6666????""""****2222::::$$$$\\\\00006666####====?456789:;(3-!0,1'8"5.*2$key expansionmsvcrt.dllKERNEL32.dllWS2_32.dllADVAPI32.dllclient.dllzcÃrSwooYMM.exe_1036_rwx_064B0000_00026000:.text`.rdata@.data.reloct#<.th>?.tS;?.tT;?.tV;\$83\$4#3\$(#\$$3&&&&6666????""""****2222::::$$$$\\\\00006666####====?456789:;(3-!0,1'8"5.*2$key expansionmsvcrt.dllKERNEL32.dllWS2_32.dllADVAPI32.dllclient.dllzcÃrSwooYMM.exe_1036_rwx_064F0000_00071000:HTTP/1.1 200 OK(7),01444'9=82<.342>rSwooYMM.exe_1036_rwx_069F0000_00001000:GET /maps/api/staticmap?center=32.33597550,-111.04410110&zoom=14&size=150x150&maptype=roadmap&markers=color:red|label:s|32.33597550,-111.04410110&sensor=false&format=jpg HTTP/1.1Host:maps.google.comUser Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)rSwooYMM.exe_1036_rwx_06E30000_00020000:smss.execsrss.exewinlogon.exeservices.exelsass.exevmacthlp.exesvchost.exespoolsv.exejqs.exevmtoolsd.exeVMUpgradeHelper.exealg.exeexplorer.exeVMwareTray.exeVMwareUser.exedisablejavawarnsec.exesandbox_svc.exeProcmon.exewmiprvse.exerSwooYMM.exeFeEQMIQs.exejWcYYUcg.exevcredist_x86.execmd.exeperl.exetshark.exeFeEQMIQs.exe_2016_rwx_009A0000_00001000:C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\TempFeEQMIQs.exe_2016_rwx_00A00000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMMFeEQMIQs.exe_2016_rwx_00A10000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQsFeEQMIQs.exe_2016_rwx_00A30000_000EA000:b5.ug.hFgU.oe`"t!.lN-=t&t%xGTcPoopUk') 2ß.xXlT 'A%fSx01/-.xOf(.Gr6nGTny/T%x8f3x\-ÕO3C]i5.lUnldxGjY4%x(mNUk.xG.Gm@ttdFX.xGC%uYlI&%6XG.Vk\.k.qNk%XmTgX> %XUPC,i'.Tf-%X]Q|.TV]SrP[.wOh`2%f%fR[.wO.FtjhYS[.wg.am$%fR[.wNv[[.wI,[.wGUk!F%SEQF4[.ww.Al|3x.pzNbRfR[.wIu[[.wIE8[.wc]%Cs,fR[.wHS[.wlS[.wuS[.wxr/%u.vQ[.wOL.WZyuL[.wlp[.wub.Gr,.L[.wzS[.wzf.KpVD[.wuw\[.wL,[.wsg%fxM1,[.wtfR[.wDwS[.wJZbXBSsh|[.wvP[.wHU[.wIwR[.wqvQ[.wJfR[.wLvV[.wI-3%x(l[.wc|[.wqcX.SA*`.VRS[.wv,[.wvR[.wOL[.wNe#.TP,[.wzAf%dQ[.wHwP[.wwZ[.wyL[.wvS[.wpuY[.wO5"%xdFw\[.wynP.BE%co ,2#CiTCpbl[.wv.cqdT4[.wcH'%Uzo}m&T.cpb{y.xGyv[[.wH.Nfe`wP[.wzht%F:jTn\[.wytQ[.wH,[.wb{.lngw\[.ww6[.wt,[.wl3]9%UA{,[.wup[[.wFv4[.wGpKt[.wKp[.wp5.fz%V[.wHl[.wqsQ[.wHw\[.wzP[.wv~j-2}|T=.je2;bG.YY|fR[.wErU[.wG/O[.wKvL[.wGe\[.wG\[.wGWwP[.wpv".bBal1t%UFMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mFeEQMIQs.exe_2016_rwx_00E20000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.infFeEQMIQs.exe_2016_rwx_00E30000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.infFeEQMIQs.exe_2016_rwx_00E40000_00001000:%Documents and Settings%\%current user%\NwIscAww\rSwooYMM.exeFeEQMIQs.exe_2016_rwx_00E50000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exeFeEQMIQs.exe_2016_rwx_00E80000_00001000:rSwooYMM.exeFeEQMIQs.exe_2016_rwx_00E90000_00001000:FeEQMIQs.exeFeEQMIQs.exe_2016_rwx_00EA0000_00001000:taskkill /FI "USERNAME eq adm" /F /IM rSwooYMM.exeFeEQMIQs.exe_2016_rwx_00EB0000_00001000:taskkill /FI "USERNAME eq adm" /F /IM FeEQMIQs.exeFeEQMIQs.exe_2016_rwx_00EC0000_00001000:%Documents and Settings%\All Users\BOAMIgUE\jWcYYUcg.exeFeEQMIQs.exe_2016_rwx_00ED0000_00001000:%Documents and Settings%\All Users\MAAo.txtFeEQMIQs.exe_2016_rwx_00EE0000_00001000:notepad.exe "%Documents and Settings%\All Users\MAAo.txt"FeEQMIQs.exe_2016_rwx_00EF0000_00001000:%Documents and Settings%\All Users\BOAMIgUEjWcYYUcg.exe_580_rwx_00720000_00001000:%WinDir%\TEMPjWcYYUcg.exe_580_rwx_00780000_00001000:%Documents and Settings%\LocalService\NwIscAww\rSwooYMMjWcYYUcg.exe_580_rwx_00790000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQsjWcYYUcg.exe_580_rwx_007B0000_000EA000:b5.ug.hFgU.oe`"t!.lN-=t&t%xGTcPoopUk') 2ß.xXlT 'A%fSx01/-.xOf(.Gr6nGTny/T%x8f3x\-ÕO3C]i5.lUnldxGjY4%x(mNUk.xG.Gm@ttdFX.xGC%uYlI&%6XG.Vk\.k.qNk%XmTgX> %XUPC,i'.Tf-%X]Q|.TV]SrP[.wOh`2%f%fR[.wO.FtjhYS[.wg.am$%fR[.wNv[[.wI,[.wGUk!F%SEQF4[.ww.Al|3x.pzNbRfR[.wIu[[.wIE8[.wc]%Cs,fR[.wHS[.wlS[.wuS[.wxr/%u.vQ[.wOL.WZyuL[.wlp[.wub.Gr,.L[.wzS[.wzf.KpVD[.wuw\[.wL,[.wsg%fxM1,[.wtfR[.wDwS[.wJZbXBSsh|[.wvP[.wHU[.wIwR[.wqvQ[.wJfR[.wLvV[.wI-3%x(l[.wc|[.wqcX.SA*`.VRS[.wv,[.wvR[.wOL[.wNe#.TP,[.wzAf%dQ[.wHwP[.wwZ[.wyL[.wvS[.wpuY[.wO5"%xdFw\[.wynP.BE%co ,2#CiTCpbl[.wv.cqdT4[.wcH'%Uzo}m&T.cpb{y.xGyv[[.wH.Nfe`wP[.wzht%F:jTn\[.wytQ[.wH,[.wb{.lngw\[.ww6[.wt,[.wl3]9%UA{,[.wup[[.wFv4[.wGpKt[.wKp[.wp5.fz%V[.wHl[.wqsQ[.wHw\[.wzP[.wv~j-2}|T=.je2;bG.YY|fR[.wErU[.wG/O[.wKvL[.wGe\[.wG\[.wGWwP[.wpv".bBal1t%UFMicrosoft Windows eine Wiederherstellung in einem Moment beginnen..klicken, um zu kopierenStrafe zahlen. Jeder Versuch, diese Nachricht zu entfernen werden die Dateien, Hardware und Windows-Installation unwiederbringlich beschffnen Sie den Internet-Browser. An die Adresse gehen: blockchain.info/wallet und klicken Sie auf 'Erstellen Sie ein neues Wallet'.,Geben Sie Ihre E-Mail-Adresse (optional) und Ihr Passwort ein. Achten Sie darauf, Ihr Passwort sicher ist.-Sparen Sie Ihr Passwort sicher, vorzugsweise offline (klicken Notepad)..Folgen Sie den Anweisungen auf der Website aufgefordert werden, und achten Sie genau auf die Sicherheitsempfehlungen.1.Machen BitCoin Zahlung:2|Anmeldung zu Ihrem Bitcoin Wallet blockchain.info/wallet/login5DKlicken Sie auf "Import / Export".6- und Kleinschreibung) indem Sie es und klicken Sie auf 'Add Private Key'.78Klicken Sie auf "Sweep Key".9.Internationale Anbieter=WebbrowserD&de.bitcoin.it/wiki/GKennen Sie die Gefahren der Verletzung des Urheberrechts. Besuchen copyright.gov/help/faq/faq-infringement.html f~Microsoft Windows will begin a restoration process in a moment.Operation Global III is a coordinated effort by U.S., Canadian and European law enforcement agencies targeting computers with pirated content.$Open Internet Browser. Go to the address: blockchain.info/wallet and click 'Start A New Wallet'.,Enter your e-mail address(optional) and password. Make sure your password is secure.-zSave your password safely, preferably offline(click Notepad)..Follow the steps prompted on the website and pay close attention to the security recommendations.1tLogin to your Bitcoin wallet blockchain.info/wallet/login 54Click on Import / Export. 6Enter the paper wallet's private key by typing it manually (case sensitive) and click on 'Add Private Key'.7$Click 'Sweep Key'.9.International Exchanges=&en.bitcoin.it/wiki/GKnow the dangers of copyright infringement. Visit copyright.gov/help/faq/faq-infringement.html for more information.Jun reato federale che porta pene fino a cinque anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (17 USC s.506, 18 USC s.2319)un crimine federale che comporta pene fino a quindici anni di prigione federale, 250.000 dollari di multa, confisca e la restituzione (18 USC s.2339A)Microsoft Windows inizierImporto:Qualsiasi tentativo di rimuovere questo messaggio potrebbe danneggiare il vostro file, hardware e di installazione di Windows oltre il recupero."Operazione globale III dagli Stati Uniti, Canada, Europa, Australia, Nuova Zelanda e altre forze dell'ordine di tutto il mondo\Registrazione di un nuovo portafoglio BitCoin:Aprire Internet Browser. Vai all'indirizzo: blockchain.info/wallet e cliccare su 'Crea un nuovo Portafoglio'.,Inserisci il tuo indirizzo e-mail (opzionale) e la password. Assicurati che il tuo passwordSalvare la password in modo sicuro, preferibilmente non in linea (fare clic su Notepad)..Seguire i passaggi spinto sul sito e prestare la massima attenzione alle raccomandazioni di sicurezza.1|Accedi al tuo portafoglio Bitcoin blockchain.info/wallet/login5Inserire la chiave privata 'Paper Wallet' digitando manualmente (maiuscole e minuscole) e fare clic su 'Add Private Key'.72Fare clic su 'Sweep Key'.9&it.bitcoin.it/wiki/GConoscere i pericoli di violazione del copyright. Visita copyright.gov/help/faq/faq-infringement.html per maggiori informazioni.JMicrosoft Windows se iniciarFine Importe:n de Windows sin posibilidad de recuperaciOperacin: blockchain.info/wallet y haga clic en 'Crear un nuevo monedero'.,gina web y prestar mucha atencipAcceda a su cartera blockchain.info/wallet/login Bitcoin5FHaga clic en "Importar / Exportar".6sculas) y haga clic en" Add Private Key ".72Haga clic en 'Sweep Key'.9Navegador WebD&es.bitcoin.it/wiki/Gn de copyright. Visita copyright.gov/help/faq/faq-infringement.html para mjWcYYUcg.exe_580_rwx_00BA0000_00001000:%Documents and Settings%\LocalService\NwIscAww\rSwooYMM.infjWcYYUcg.exe_580_rwx_00BB0000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.infjWcYYUcg.exe_580_rwx_00BC0000_00001000:%Documents and Settings%\LocalService\NwIscAww\rSwooYMM.exejWcYYUcg.exe_580_rwx_00BD0000_00001000:%Documents and Settings%\All Users\hUEQccwo\FeEQMIQs.exejWcYYUcg.exe_580_rwx_00C00000_00001000:rSwooYMM.exejWcYYUcg.exe_580_rwx_00C10000_00001000:FeEQMIQs.exejWcYYUcg.exe_580_rwx_00C20000_00001000:taskkill /FI "USERNAME eq SYSTEM" /F /IM rSwooYMM.exejWcYYUcg.exe_580_rwx_00C30000_00001000:taskkill /FI "USERNAME eq SYSTEM" /F /IM FeEQMIQs.exe8>