Gen:Variant.Application.Bundler.Graftor.155902 (AdAware), Trojan.Win32.Swrort.3.FD, PUPYahooCompanion.YR, SearchProtectToolbar.YR, PUPAirInstaller.YR, PUPInstallXSearchProtectForYahoo.YR (Lavasoft MAS)Behaviour: Trojan, Installer, PUP
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 98ba02d6d3f380fea52cfa8537577349
SHA1: 538cb396449e87894453c4d8e702d3749f001588
SHA256: c80e911aac8e75033ef3b9581f2264377bcf6a2dd98e195c23733e505de98308
SSDeep: 49152:dBWE6uqIvAyJYb6c061BhNT/wTj1gBLd5aRS :dd6uqIvAwYE6jhNTTLEx
Size: 1984536 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: SafeInstall, LLC
Created at: 2014-09-29 18:55:07
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):No processes have been created.The Trojan injects its code into the following process(es):
%original file name%.exe:1388
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\kaspersky.vi.zip (888 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\financealert.vi.zip (780 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\registryhelper.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\close.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\view.petite_oo_v5.vi.json (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartdriverupdater.vi.zip (928 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\responsemanager.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\clickmanager.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\config.xml (13784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\astroarcade.vi.zip (804 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\json2.js (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\offerbox.vi.zip (793 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\webbar.vi.zip (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\installprogress.png (998 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\offerparser.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortonsecurityscan.vi.zip (834 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenconfig.js (240 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driversupport.vi.zip (882 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\kmsxSuite.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driverfighter.vi.zip (939 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\spyhunter.vi.zip (804 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\minmax.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenmanager.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\testsuitemanager.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\geniusbox.vi.zip (764 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\lodash.custom.min.js (1928 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\blasteroids.vi.zip (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\step-contents-stepped.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\weatherbug.vi.zip (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\bg-installprogress.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenfactory.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driverscanner.vi.zip (811 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\jenkatgamesarcadeplus.vi.zip (856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\chocolatebar.vi.zip (790 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\adobeflashplayer.vi.zip (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\pcoptimizerpro_offer.vi.zip (732 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\product-icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\vebasearch.vi.zip (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\pcspeedup.vi.zip (820 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn-win.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\rockettab.vi.zip (883 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\custom-check.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\fulldiskfighter.vi.zip (968 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\noyahoo.js (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\websearches.vi.zip (731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\petite_oo_v5.vi.zip (9352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoosuite.vi.zip (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymCCIS2.zip (162 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartpccleaner.vi.zip (930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\bg_disc_wrap.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\savepathdeals.vi.zip (870 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\converterfreeonline.vi.zip (690 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\slowpcfighter.vi.zip (926 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\ping.response.json (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn.png (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_startpage.vi.zip (422 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\.DS_Store (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\adobeflashplayer_13778.txt (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\checkbox.png (650 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\container-separator.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartweb.vi.zip (821 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_defaultsearch.vi.zip (434 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\css\style.css (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\gamehug.vi.zip (792 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn-win-cancel.png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\winferno.vi.zip (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\yahoo.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\mypcbackup.vi.zip (904 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\contentexplorer.vi.zip (823 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\98ba02d6d3f380fea52cfa8537577349.log (2905673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\optimizerpro.vi.zip (803 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\common.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\maxthon.vi.zip (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\defaulttab.vi.zip (866 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\utils.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\stormwatch.vi.zip (778 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\genieo.vi.zip (904 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_defaultsearch.test.vi.zip (747 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\desktoptemperaturemonitor.vi.zip (787 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\step-contents.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\adobeflashplayer.vi.json (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_keepmysettingsx.vi.zip (412 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortonantivirus.vi.zip (892 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\jquery.min.js (6984 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\resultsbay.vi.zip (920 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\adobeflashplayer\adobeflash_tn.png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\uninstallhelper.vi.zip (507 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortoninternetsecurity.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screen.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\config.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\petite_oo_v5.vi.html (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\knctr.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymCCIS.dll (11704 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\arcadeparlor.vi.zip (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\filewhiz_tn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_startpage.test.vi.zip (739 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\script.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\title-bar.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\knockout-2.2.1.js (2696 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\petite_oo_v5.vi.json (74 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\MSHist012014041020140411\index.dat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\MSHist012014041020140411 (0 bytes)
Registry activity
The process %original file name%.exe:1388 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014120120141202]
"CacheRepair" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014120120141202]
"CacheLimit" = "8192"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "%original file name%.exe"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\InstallIQ]
"test" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1412006107"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014120120141202]
"CacheOptions" = "11"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "73 3C 49 81 48 E4 B8 A6 A7 6B E6 76 8C 21 FE 29"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014120120141202]
"CachePrefix" = ":2014120120141202:"
"CachePath" = "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012014120120141202\"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following registry key(s):
[HKLM\SOFTWARE\InstallIQ]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014041020140411]
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
[HKLM\SOFTWARE\InstallIQ]
"test"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
6bec059e9f70b59873807c4f2a72a8b5 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SymCCIS.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\kaspersky.vi.zip (888 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\financealert.vi.zip (780 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\registryhelper.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\close.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\view.petite_oo_v5.vi.json (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartdriverupdater.vi.zip (928 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\responsemanager.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\clickmanager.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\config.xml (13784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\astroarcade.vi.zip (804 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\json2.js (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\offerbox.vi.zip (793 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\webbar.vi.zip (801 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\installprogress.png (998 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\offerparser.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortonsecurityscan.vi.zip (834 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenconfig.js (240 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driversupport.vi.zip (882 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\kmsxSuite.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driverfighter.vi.zip (939 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\spyhunter.vi.zip (804 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\minmax.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenmanager.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\testsuitemanager.js (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\geniusbox.vi.zip (764 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\lodash.custom.min.js (1928 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\blasteroids.vi.zip (833 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\step-contents-stepped.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\weatherbug.vi.zip (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\bg-installprogress.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screenfactory.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\driverscanner.vi.zip (811 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\jenkatgamesarcadeplus.vi.zip (856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\chocolatebar.vi.zip (790 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\adobeflashplayer.vi.zip (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\pcoptimizerpro_offer.vi.zip (732 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\product-icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\vebasearch.vi.zip (822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\pcspeedup.vi.zip (820 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn-win.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\rockettab.vi.zip (883 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\custom-check.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\fulldiskfighter.vi.zip (968 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\noyahoo.js (323 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\websearches.vi.zip (731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\petite_oo_v5.vi.zip (9352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoosuite.vi.zip (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymCCIS2.zip (162 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartpccleaner.vi.zip (930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\bg_disc_wrap.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\savepathdeals.vi.zip (870 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\converterfreeonline.vi.zip (690 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\slowpcfighter.vi.zip (926 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\ping.response.json (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn.png (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_startpage.vi.zip (422 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\.DS_Store (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\adobeflashplayer_13778.txt (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\checkbox.png (650 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\container-separator.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\smartweb.vi.zip (821 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_defaultsearch.vi.zip (434 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\css\style.css (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\gamehug.vi.zip (792 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\btn-win-cancel.png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\winferno.vi.zip (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\yahoo.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\mypcbackup.vi.zip (904 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\contentexplorer.vi.zip (823 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\98ba02d6d3f380fea52cfa8537577349.log (2905673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\optimizerpro.vi.zip (803 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\common.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\maxthon.vi.zip (754 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\defaulttab.vi.zip (866 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\utils.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\stormwatch.vi.zip (778 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\genieo.vi.zip (904 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_defaultsearch.test.vi.zip (747 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\desktoptemperaturemonitor.vi.zip (787 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\step-contents.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\adobeflashplayer.vi.json (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_keepmysettingsx.vi.zip (412 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortonantivirus.vi.zip (892 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\jquery.min.js (6984 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\resultsbay.vi.zip (920 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\adobeflashplayer\adobeflash_tn.png (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\uninstallhelper.vi.zip (507 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\nortoninternetsecurity.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\screen.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\config.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\petite_oo_v5.vi.html (776 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\knctr.vi.zip (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymCCIS.dll (11704 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\arcadeparlor.vi.zip (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\filewhiz_tn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\yahoo_hpds_startpage.test.vi.zip (739 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\script.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\images\title-bar.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\library\js\knockout-2.2.1.js (2696 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\qs_33b5f90\dialogs\petite_oo_v5.vi.json (74 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: SafeInstall, LLC
Product Name: SafeInstaller
Product Version: 1.0.62.0
Legal Copyright: Copyright (C) 2014
Legal Trademarks:
Original Filename: safeinstall.exe
Internal Name: SafeInstaller
File Version: 1.0.62.0
File Description: Safe Installer
Comments:
Language: Language Neutral
Company Name: SafeInstall, LLCProduct Name: SafeInstallerProduct Version: 1.0.62.0Legal Copyright: Copyright (C) 2014Legal Trademarks: Original Filename: safeinstall.exeInternal Name: SafeInstallerFile Version: 1.0.62.0File Description: Safe InstallerComments: Language: Language Neutral
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 510521 | 510976 | 4.49605 | acbae90f15e0ab88907cda08422c8728 |
.text-qu | 516096 | 3859 | 4096 | 4.1569 | 8f2cae097474c78be207689a44c79dcd |
.text-co | 520192 | 86200 | 86528 | 4.48692 | 919433c91a5073b4fa81456af419c559 |
.text-co | 610304 | 75703 | 75776 | 4.46795 | d992bcc5832d16cb7ba32efa1aaff89d |
.text-co | 688128 | 48353 | 48640 | 4.47927 | 42586e65ca0d2153c501cc24dca42d8d |
.text-co | 737280 | 14255 | 14336 | 4.47094 | 445d57d50825bb9070a06a4b10b4506b |
.text-co | 753664 | 28663 | 28672 | 4.61464 | b17f17a229e5d367f32bc136acc8885e |
.text-co | 782336 | 10274 | 10752 | 4.36693 | 5b9fcd22150ad80c75238ed267c0c617 |
.text-co | 794624 | 263610 | 263680 | 4.59569 | b6098a9750f8c0c856b9dcd1751afd4d |
.text-ti | 1060864 | 43367 | 43520 | 4.59306 | 368149fa1ad6d87b82b638825cca4fc4 |
.text-co | 1105920 | 16090 | 16384 | 4.37334 | c1d250e53a6dd9ea921b33dcda18d226 |
.text-co | 1122304 | 59 | 512 | 0.606205 | fd1050284a5003ed67440ea315813a66 |
.text-co | 1126400 | 12734 | 12800 | 4.43255 | 05b33d71a48cf76c46efe0f01941db12 |
.rdata | 1142784 | 269166 | 269312 | 3.89814 | 7a35ab145f15a477441bf544488296ac |
.data | 1413120 | 27140 | 17408 | 3.36778 | ee97a78550d085b70fd95952addc1404 |
.data-qu | 1441792 | 41 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1445888 | 188 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1449984 | 56 | 512 | 0.042395 | c740e02ec7aeddf2ce7343b5944cca6c |
.data-co | 1454080 | 40 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1458176 | 44 | 512 | 0.014135 | 2d5fe836dd5a60fa37b7c590cfc70410 |
.data-co | 1462272 | 41 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1466368 | 40 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1470464 | 2932 | 3072 | 1.37225 | 9e0d70ac78ecdb593fd151ae94d6bf07 |
.data-ti | 1474560 | 1176 | 1536 | 1.01082 | 9103168d3d5a7637f77612a86c6a6856 |
.data-co | 1478656 | 40 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.data-co | 1482752 | 4 | 512 | 0.014135 | d340f23a7d18057bb02252a3cb40b877 |
.data-co | 1486848 | 40 | 512 | 0 | bf619eac0cdf3f68d496ea9344137e8b |
.rsrc | 1490944 | 564804 | 565248 | 5.27343 | 0c347aa3b0cc673efe9b71a2ae10fa71 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://66.77.96.160/api/productsession | |
hxxp://1-vinstaller.com/api/productsession |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
POST /api/productsession HTTP/1.1
Content-Type: application/json; charset=utf-8
Accept: application/json
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
Host: 1-vinstaller.com
Content-Length: 266
Cache-Control: no-cache
{"CampaignName":"","ShortName":"adobeflashplayer","ProductSubId":-1,"AccountId":8527,"VersionId":-1,"InstallerVersion":"1.0.62.0","OSId":5,"TemplateId":309,"LangId":1033,"ParentOfferIds":[],"Browsers":[{"Key":"IE","Value":6}],"DefaultBrowser":{"Key":"IE","Value":6}}
HTTP/1.1 200 OK
Cache-Control: no-cache
Pragma: no-cache
Content-Type: application/json; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
P3P: CP="PSA OUR DEM"
X-Robots-Tag: noindex, nofollow
Set-Cookie: dtCookie=2$D9F930590B2E5AF9023B3D45DD15DAA4|1-vinstaller.com|1; Path=/; Domain=.1-vinstaller.com
Date: Mon, 01 Dec 2014 04:02:56 GMT
Content-Length: 5209
{"Response":{"configuration":{"month":11,"week":48,"year":2014,"targetbrowser":{"Key":"IE","Value":"6"},"pingurl":"hXXp://1-vinstaller.com/api/productsession","postbackurl":"hXXp://1-vinstaller.com/api/trackofferinstalldetails","errorurl":"hXXp://1-vinstaller.com/api/installerror","host":"hXXp://dl2.vic9installer.com/lm/","compliant":false,"randomoffersort":false},"productsession":{"productid":3515,"productsubid":-1,"productsessionid":"3790dd53-357f-4fe3-b5e3-32c0fb8ffc47","shortname":"adobeflashplayer","deviceclienttype":7,"guiclienttype":7,"versionid":-1,"session":{"accountid":8527,"vendorid":4752,"campaignid":228330,"campaignname":"Default","countryid":804,"country":"UA"}},"accountconfiguration":{"accountid":8527,"accountverticalid":18,"showwelcomescreen":true,"showdownloadmanager":true,"showfirstofferinwelcomescreen":true,"allowicondrop":true,"active":true},"offers":[],"offermapping":[],"restrictedoffers":[{"offerid":19977,"restrictiontype":"CountryRestriction"},{"offerid":20116,"restrictiontype":"CountryRestriction"},{"offerid":20351,"restrictiontype":"CountryRestriction"},{"offerid":20422,"restrictiontype":"CountryRestriction"},{"offerid":20304,"restrictiontype":"CountryRestriction"},{"offerid":20421,"restrictiontype":"CountryRestriction"},{"offerid":20419,"restrictiontype":"CountryRestriction"},{"offerid":20003,"restrictiontype":"CountryRestriction"},{"offerid":20213,"restrictiontype":"CountryRestriction"},{"offerid":20420,"restrictiontype":"CountryRestriction"},{"offerid":20334,"restrictiontype":"Countr
<<< skipped >>>
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_1388:
.text
.text
`.text-qu
`.text-qu
`.text-co
`.text-co
`.text-co"(
`.text-co"(
`.text-tig
`.text-tig
`.text-co;
`.text-co;
`.rdata
`.rdata
@.data
@.data
.data-qu)
.data-qu)
.data-co
.data-co
.data-co8
.data-co8
.data-co(
.data-co(
.data-co,
.data-co,
.data-co)
.data-co)
.data-cot
.data-cot
.data-ti
.data-ti
.rsrc
.rsrc
CSShZ
CSShZ
CSSh4
CSSh4
CSSh9
CSSh9
CSSh>
CSSh>
CSShl
CSShl
CSSh[
CSSh[
CSSh`
CSSh`
<:>
<:>
t8Ht.HHt#
t8Ht.HHt#
.FGy1
.FGy1
Af;FP}%S3
Af;FP}%S3
|$|.tD
|$|.tD
#t.Ht
#t.Ht
2 34 567
2 34 567
u.SSV
u.SSV
1t.Ht
1t.Ht
9sxv%UW
9sxv%UW
function not supported
function not supported
operation canceled
operation canceled
address_family_not_supported
address_family_not_supported
operation_in_progress
operation_in_progress
operation_not_supported
operation_not_supported
protocol_not_supported
protocol_not_supported
operation_would_block
operation_would_block
address family not supported
address family not supported
broken pipe
broken pipe
inappropriate io control operation
inappropriate io control operation
not supported
not supported
operation in progress
operation in progress
operation not permitted
operation not permitted
operation not supported
operation not supported
operation would block
operation would block
protocol not supported
protocol not supported
operator
operator
GetProcessWindowStation
GetProcessWindowStation
Operation not permitted
Operation not permitted
Inappropriate I/O control operation
Inappropriate I/O control operation
Broken pipe
Broken pipe
0xX
0xX
Invalid CRT parameter
Invalid CRT parameter
QuickStartApp.cpp
QuickStartApp.cpp
vi.engine.xml
vi.engine.xml
chk_firefox
chk_firefox
chk_chrome
chk_chrome
%s[%d]
%s[%d]
position=%d, active=%d
position=%d, active=%d
%d,%d,%d
%d,%d,%d
** Debug mode: simulating stopping Firefox
** Debug mode: simulating stopping Firefox
** Debug mode: simulating stopping Chrome
** Debug mode: simulating stopping Chrome
%s must be closed before continuing. Press OK to close %s now. You may need to close %s manually.
%s must be closed before continuing. Press OK to close %s now. You may need to close %s manually.
Firefox
Firefox
Google Chrome
Google Chrome
%d err: %s
%d err: %s
Chrome
Chrome
firefox
firefox
chrome
chrome
opera
opera
searchprotector.exe
searchprotector.exe
view=%d,sel=%d,inst=%d,conf=%d,can=%d,err=%d,eid=%d,pos=%d,%s
view=%d,sel=%d,inst=%d,conf=%d,can=%d,err=%d,eid=%d,pos=%d,%s
.json
.json
control.txt
control.txt
00000000-0000-0000-0000-000000000000
00000000-0000-0000-0000-000000000000
QuickStartProcess.cpp
QuickStartProcess.cpp
%programfiles%\Free Offers from Freeze.com
%programfiles%\Free Offers from Freeze.com
disabling offer because system doesn't have Firefox
disabling offer because system doesn't have Firefox
disabling offer because system doesn't have Chrome
disabling offer because system doesn't have Chrome
%s[%s]: view=%s accept=%s
%s[%s]: view=%s accept=%s
%s,%s
%s,%s
WindowsErrorCode
WindowsErrorCode
targetbrowser/key
targetbrowser/key
%s:v=%s,id=%s,rc=%d,f=%d,e=%d,i=%s,p=%s,pb=%s,ex=%s,tr=%s,px=%d
%s:v=%s,id=%s,rc=%d,f=%d,e=%d,i=%s,p=%s,pb=%s,ex=%s,tr=%s,px=%d
%s:v=%s,rc=%d,os=%s,%s,%s|ie=%s
%s:v=%s,rc=%d,os=%s,%s,%s|ie=%s
%d,%d,%s,%s,%s,%s
%d,%d,%s,%s,%s,%s
%d,%d,%d,%d,%d
%d,%d,%d,%d,%d
%d,%d,%s,%s,%s,%s,%s
%d,%d,%s,%s,%s,%s,%s
%d,%s,%s,%s,%s,%d,%d,%d,%d,%d,%d,%d,%d,%s,%s,%d,%s
%d,%s,%s,%s,%s,%d,%d,%d,%d,%d,%d,%d,%d,%s,%s,%d,%s
offers
offers
%s,%s,%s,%s,%s,%s,%s,%s
%s,%s,%s,%s,%s,%s,%s,%s
%s,%d,%s,%s
%s,%d,%s,%s
%s,%s,%u,%u,%d,%s
%s,%s,%u,%u,%d,%s
Unable to open thankyou page; url is empty or invalid!
Unable to open thankyou page; url is empty or invalid!
statsd.response.txt
statsd.response.txt
Web.Installer.VDI.CommError
Web.Installer.VDI.CommError
Web.Installer.VDI.InstallError
Web.Installer.VDI.InstallError
Web.Installer.VDI.OfferDownloadError
Web.Installer.VDI.OfferDownloadError
Web.Installer.VDI.OfferInstallError
Web.Installer.VDI.OfferInstallError
Web.Installer.VDI.OfferInstallFailed
Web.Installer.VDI.OfferInstallFailed
hXXp://dl2.v47installer.com/lm/bundles/keepmysettingsx/keepmysettingsx.zip
hXXp://dl2.v47installer.com/lm/bundles/keepmysettingsx/keepmysettingsx.zip
hXXp://sdspapi.com/api/values
hXXp://sdspapi.com/api/values
hXXp://us.yhs4.search.yahoo.com/yhs/search?p={searchTerms}&ei=UTF-8&hspart=w3i&hsimp=yhs-synd1&type=W3i_DS,221,0_0,Search,20140522,19669,0,FF29,7635
hXXp://us.yhs4.search.yahoo.com/yhs/search?p={searchTerms}&ei=UTF-8&hspart=w3i&hsimp=yhs-synd1&type=W3i_DS,221,0_0,Search,20140522,19669,0,FF29,7635
Software\Microsoft\Windows\CurrentVersion\Uninstall\InstallX Search Protect for Yahoo
Software\Microsoft\Windows\CurrentVersion\Uninstall\InstallX Search Protect for Yahoo
hXXp://dl2.v47installer.com/lm/bundles/keepmysettingsx/spv1.zip
hXXp://dl2.v47installer.com/lm/bundles/keepmysettingsx/spv1.zip
spv1.zip
spv1.zip
.html
.html
MainWnd.cpp
MainWnd.cpp
OfferThread.cpp
OfferThread.cpp
Setting offer checkbox value: key=
Setting offer checkbox value: key=
COfferExe::GetXpiFilename
COfferExe::GetXpiFilename
c:\winapps\windows\main\installer.quickstart.application\installer.quickstart.lib\OfferExe.h
c:\winapps\windows\main\installer.quickstart.application\installer.quickstart.lib\OfferExe.h
downloadurl
downloadurl
downloadurl.64bit
downloadurl.64bit
msie.downloadurl
msie.downloadurl
msie.commandline
msie.commandline
firefox.downloadurl
firefox.downloadurl
firefox.commandline
firefox.commandline
chrome.downloadurl
chrome.downloadurl
chrome.commandline
chrome.commandline
allbrowser.downloadurl
allbrowser.downloadurl
allbrowser.commandline
allbrowser.commandline
regkeyadd
regkeyadd
ieregkey
ieregkey
firefox.pref
firefox.pref
firefox.xpimethod
firefox.xpimethod
firefox.xpilocation
firefox.xpilocation
firefox.xpidelete
firefox.xpidelete
LUA account detected, and flag lua_runasdesktopuser detected, forcing executeAsDesktopUser
LUA account detected, and flag lua_runasdesktopuser detected, forcing executeAsDesktopUser
iconurl
iconurl
residenturl
residenturl
configuration/downloadurl
configuration/downloadurl
configuration/downloadurl.64bit
configuration/downloadurl.64bit
configuration/msie.downloadurl
configuration/msie.downloadurl
configuration/msie.commandline
configuration/msie.commandline
configuration/firefox.downloadurl
configuration/firefox.downloadurl
configuration/firefox.commandline
configuration/firefox.commandline
configuration/chrome.downloadurl
configuration/chrome.downloadurl
configuration/chrome.commandline
configuration/chrome.commandline
configuration/allbrowser.downloadurl
configuration/allbrowser.downloadurl
configuration/allbrowser.commandline
configuration/allbrowser.commandline
configuration/regkeyadd
configuration/regkeyadd
configuration/ieregkey
configuration/ieregkey
configuration/firefox.pref
configuration/firefox.pref
configuration/firefox.xpimethod
configuration/firefox.xpimethod
configuration/firefox.xpilocation
configuration/firefox.xpilocation
configuration/firefox.xpidelete
configuration/firefox.xpidelete
configuration/iconurl
configuration/iconurl
configuration/residenturl
configuration/residenturl
adding %s entry, ourVal='%s', theirVal='%s'
adding %s entry, ourVal='%s', theirVal='%s'
COfferExe::Download
COfferExe::Download
Download url is empty!
Download url is empty!
_firefox is NULL!
_firefox is NULL!
COfferExe::OnInstall
COfferExe::OnInstall
Install is a dropfile; no exe to run...
Install is a dropfile; no exe to run...
Icon offer (in exe config) detected, running icon install
Icon offer (in exe config) detected, running icon install
COfferExe::Run
COfferExe::Run
COfferExe::HandleFirefoxOptions
COfferExe::HandleFirefoxOptions
firefoxoffer
firefoxoffer
HandleFirefoxOptions called with incorrect preferences set in config!
HandleFirefoxOptions called with incorrect preferences set in config!
COfferExe::BuildCommandLine
COfferExe::BuildCommandLine
msiexec.exe /i "%s" /qn ALLUSERS=2 REBOOT=ReallySuppress
msiexec.exe /i "%s" /qn ALLUSERS=2 REBOOT=ReallySuppress
msiexec.exe /i "%s" %s
msiexec.exe /i "%s" %s
Could not find firefox exe to install
Could not find firefox exe to install
Offer is installing XPI for Firefox 8 or higher, enabling GUI.
Offer is installing XPI for Firefox 8 or higher, enabling GUI.
"%s" "%s"
"%s" "%s"
"%s" %s
"%s" %s
COfferExe::RunSearchProtectInstall
COfferExe::RunSearchProtectInstall
COfferExe::WaitForInstallProcess
COfferExe::WaitForInstallProcess
OfferExe.cpp
OfferExe.cpp
COfferExe::WaitForProcessStarted
COfferExe::WaitForProcessStarted
waiting for registry key:
waiting for registry key:
COfferExe::WaitForRegistryValue
COfferExe::WaitForRegistryValue
Registry key found.
Registry key found.
Registry key found (64-bit).
Registry key found (64-bit).
COfferExe::WaitForFile
COfferExe::WaitForFile
COfferExe::InstallXpi
COfferExe::InstallXpi
Bad RegKeyAdd config; not correct format: (missing hive \ )
Bad RegKeyAdd config; not correct format: (missing hive \ )
Bad RegKeyAdd config; not correct format: (missing , )
Bad RegKeyAdd config; not correct format: (missing , )
Bad RegKeyAdd config; not correct format: (missing = )
Bad RegKeyAdd config; not correct format: (missing = )
unable to set regkey from following RegKeyAdd:
unable to set regkey from following RegKeyAdd:
RegKeyAdd:
RegKeyAdd:
unrecognized values in RegKeyAdd:
unrecognized values in RegKeyAdd:
unable to set regkey from following IERegKey:
unable to set regkey from following IERegKey:
IERegKeyAdd:
IERegKeyAdd:
unrecognized values in IERegKey:
unrecognized values in IERegKey:
COfferExe::FinishXpiInstall
COfferExe::FinishXpiInstall
COfferExe::CancelXpiInstall
COfferExe::CancelXpiInstall
COfferExe::RunIconInstall
COfferExe::RunIconInstall
%s_%s.url
%s_%s.url
COfferExe::InstallResident
COfferExe::InstallResident
residentUrl is NULL!
residentUrl is NULL!
~.exe
~.exe
installx.dat
installx.dat
installx.cfg
installx.cfg
hXXp://click.freeze.com/?clname=resident
hXXp://click.freeze.com/?clname=resident
sessionurl
sessionurl
configuration/url
configuration/url
configuration/msie.url
configuration/msie.url
configuration/firefox.url
configuration/firefox.url
configuration/firefox.newtaburl
configuration/firefox.newtaburl
configuration/chrome.url
configuration/chrome.url
All urls are empty!
All urls are empty!
COfferStartPage::InstallFirefox
COfferStartPage::InstallFirefox
_firefox is NULL!
_firefox is NULL!
** Debug mode: simulated setting Firefox startpage:
** Debug mode: simulated setting Firefox startpage:
Error writing Firefox pref for startpage!
Error writing Firefox pref for startpage!
Error setting Firefox new tab!
Error setting Firefox new tab!
Set new tab in Firefox.
Set new tab in Firefox.
Firefox startpage set successful.
Firefox startpage set successful.
chromeoffer
chromeoffer
COfferStartPage::InstallChrome
COfferStartPage::InstallChrome
_chrome is NULL!
_chrome is NULL!
** Debug mode: simulated setting Chrome startpage:
** Debug mode: simulated setting Chrome startpage:
Error setting Chrome startpage: browser is still running!
Error setting Chrome startpage: browser is still running!
Error writing Chrome pref for startpage!
Error writing Chrome pref for startpage!
Can't set new tab Chrome, function is implemented with Default Search.
Can't set new tab Chrome, function is implemented with Default Search.
Chrome startpage set successful.
Chrome startpage set successful.
OfferStartPage.cpp
OfferStartPage.cpp
startpageurl
startpageurl
oldstartpageurl
oldstartpageurl
hXXp://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
hXXp://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
hXXp://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=#REVENUE_TAG#
hXXp://search.yahoo.com/search?p={searchTerms}&ei=UTF-8&fr=w3i&type=#REVENUE_TAG#
hXXp://search.yahoo.com/favicon.ico
hXXp://search.yahoo.com/favicon.ico
configuration/msie.searchname
configuration/msie.searchname
configuration/firefox.searchname
configuration/firefox.searchname
configuration/firefox.suggesturl
configuration/firefox.suggesturl
configuration/firefox.selectedengine
configuration/firefox.selectedengine
configuration/firefox.keywordurl
configuration/firefox.keywordurl
configuration/chrome.selectedengine
configuration/chrome.selectedengine
configuration/chrome.keyword
configuration/chrome.keyword
configuration/chrome.faviconurl
configuration/chrome.faviconurl
configuration/chrome.suggesturl
configuration/chrome.suggesturl
configuration/chrome.newtaburl
configuration/chrome.newtaburl
Error setting IE search: url is empty!
Error setting IE search: url is empty!
Internet Explorer version 6 or older does not support default search!
Internet Explorer version 6 or older does not support default search!
COfferDefaultSearch::InstallFirefox
COfferDefaultSearch::InstallFirefox
** Debug mode: simulated setting Firefox default search:
** Debug mode: simulated setting Firefox default search:
Failed to write Yahoo xml for Firefox!
Failed to write Yahoo xml for Firefox!
Firefox default search set successful.
Firefox default search set successful.
COfferDefaultSearch::InstallChrome
COfferDefaultSearch::InstallChrome
** Debug mode: simulated setting Chrome default search:
** Debug mode: simulated setting Chrome default search:
Failed to set search pref for chrome!
Failed to set search pref for chrome!
Chrome default search set successful.
Chrome default search set successful.
OfferDefaultSearch.cpp
OfferDefaultSearch.cpp
searchurl
searchurl
oldsearchurl
oldsearchurl
hXXp://vinstaller.com/api/trackofferinstalldetails
hXXp://vinstaller.com/api/trackofferinstalldetails
hXXp://vinstaller.com/api/installerror
hXXp://vinstaller.com/api/installerror
ping.response.json
ping.response.json
postback.response.json
postback.response.json
vmtest.txt
vmtest.txt
vmtest.txt is present, enbaling offers for vmtest
vmtest.txt is present, enbaling offers for vmtest
config.xml
config.xml
pingurl
pingurl
postbackurl
postbackurl
errorurl
errorurl
statsdurl
statsdurl
uninstalloptionurl
uninstalloptionurl
PingUrl
PingUrl
PostbackUrl
PostbackUrl
Sending session request, url=
Sending session request, url=
Ping url is empty!
Ping url is empty!
Ping url is invalid!
Ping url is invalid!
hXXp://dl5.v1installer.com/
hXXp://dl5.v1installer.com/
PingResponse.cpp
PingResponse.cpp
targetbrowser/Key
targetbrowser/Key
PingThread.cpp
PingThread.cpp
offer %s[%s]: isInstalled=%d canShow=%d
offer %s[%s]: isInstalled=%d canShow=%d
rule %s[%s]: isInstalled=%d
rule %s[%s]: isInstalled=%d
QuickStartDetectThread.cpp
QuickStartDetectThread.cpp
ResourceThread.cpp
ResourceThread.cpp
Sending postback request, url=
Sending postback request, url=
Postback url is empty!
Postback url is empty!
Postback url is invalid!
Postback url is invalid!
Response/url
Response/url
passed
passed
CRequirementManager::RunExecute
CRequirementManager::RunExecute
CRequirementManager::ParseExecuteResult
CRequirementManager::ParseExecuteResult
invalid flag in execute result:
invalid flag in execute result:
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
Running requirement.OnInstall:
Running requirement.OnInstall:
Running requirement.OnCancel:
Running requirement.OnCancel:
requirement.OnCancel is empty, skipping.
requirement.OnCancel is empty, skipping.
Running requirement.OnExit:
Running requirement.OnExit:
requirement.OnExit is empty, skipping.
requirement.OnExit is empty, skipping.
%programdata%\W3i\UninstallHelper\iqu.ini
%programdata%\W3i\UninstallHelper\iqu.ini
2.0.1.0
2.0.1.0
%programdata%\W3i\UninstallHelper\import
%programdata%\W3i\UninstallHelper\import
quickstart.xml
quickstart.xml
quickstart%d.xml
quickstart%d.xml
Failed to save IQU data, too many import files in directory!
Failed to save IQU data, too many import files in directory!
%programfiles%\W3i\UninstallHelper\UninstallHelper.exe
%programfiles%\W3i\UninstallHelper\UninstallHelper.exe
quickstart_si.xml
quickstart_si.xml
quickstart_si%d.xml
quickstart_si%d.xml
Failed to save SoftwareInfo data, too many import files in directory!
Failed to save SoftwareInfo data, too many import files in directory!
hXXp://dl.installiq.com/API/IQU/SoftwareInfo.aspx
hXXp://dl.installiq.com/API/IQU/SoftwareInfo.aspx
UH executable not found!
UH executable not found!
"%s" /silent /noswinfo
"%s" /silent /noswinfo
%s:%d
%s:%d
handling firefox cookies...
handling firefox cookies...
FF.GetCookiesError
FF.GetCookiesError
FF.NoCookies
FF.NoCookies
firefox: no cookies found
firefox: no cookies found
FF.SetCookieError
FF.SetCookieError
FF.SetCookies
FF.SetCookies
firefox: set cookies
firefox: set cookies
getting firefox cookies for
getting firefox cookies for
CCookieManager::GetFirefoxCookies
CCookieManager::GetFirefoxCookies
Error enumerating firefox cookies!
Error enumerating firefox cookies!
firefoxenum
firefoxenum
hXXp://
hXXp://
cookie.dat
cookie.dat
Vista.NoResult
Vista.NoResult
Vista.SavedLow
Vista.SavedLow
Vista.NoCookies
Vista.NoCookies
Vista.CopiedLow
Vista.CopiedLow
%a, %d-%b-%Y %H:%M:%S GMT
%a, %d-%b-%Y %H:%M:%S GMT
cookieman.exe
cookieman.exe
Vista.ExtractError
Vista.ExtractError
Vista.CreateLowError
Vista.CreateLowError
handling chrome cookies
handling chrome cookies
Chrome.GetCookiesError
Chrome.GetCookiesError
Chrome.NoCookies
Chrome.NoCookies
Chrome: no cookies found
Chrome: no cookies found
Chrome.SetCookieError
Chrome.SetCookieError
Chrome.SetCookies
Chrome.SetCookies
Chrome: set cookies succeeded
Chrome: set cookies succeeded
getting Chrome cookies for
getting Chrome cookies for
CCookieManager::GetChromeCookies
CCookieManager::GetChromeCookies
Error enumerating chrome cookies!
Error enumerating chrome cookies!
chromeenum
chromeenum
Safari.GetCookiesError
Safari.GetCookiesError
Safari.NoCookies
Safari.NoCookies
Safari.SetCookieError
Safari.SetCookieError
Safari.SetCookies
Safari.SetCookies
ErrorLogger.cpp
ErrorLogger.cpp
explorer.exe
explorer.exe
CDialogWindowJson::OnBeforeNavigate2, url=
CDialogWindowJson::OnBeforeNavigate2, url=
DialogWindowJson.cpp
DialogWindowJson.cpp
%s: view=%s accept=%s
%s: view=%s accept=%s
chk_%s=
chk_%s=
checkbox found; %s=%s
checkbox found; %s=%s
adding disclosure(%s): %s
adding disclosure(%s): %s
installedbrowsers/firefox
installedbrowsers/firefox
installedbrowsers/chrome
installedbrowsers/chrome
installedbrowsers/opera
installedbrowsers/opera
view.buildconfig.json
view.buildconfig.json
view.productconfig.json
view.productconfig.json
ProgressDialog.cpp
ProgressDialog.cpp
Installing %d of %d
Installing %d of %d
uninstalloption.exe
uninstalloption.exe
InstallIQFirefoxLock
InstallIQFirefoxLock
postinstallexecute
postinstallexecute
postinstallexecuteintegrity
postinstallexecuteintegrity
stopfirefox
stopfirefox
stopchrome
stopchrome
disablechromeextensions
disablechromeextensions
configuration/postinstallexecute
configuration/postinstallexecute
configuration/postinstallexecuteintegrity
configuration/postinstallexecuteintegrity
/msie.autoconfirm
/msie.autoconfirm
/firefox.autoconfirm
/firefox.autoconfirm
/chrome.autoconfirm
/chrome.autoconfirm
msie.autoconfirm
msie.autoconfirm
firefox.autoconfirm
firefox.autoconfirm
chrome.autoconfirm
chrome.autoconfirm
COffer::WaitForFirefoxLock
COffer::WaitForFirefoxLock
Offer.cpp
Offer.cpp
_firefoxLock is already created!
_firefoxLock is already created!
Waiting for Firefox lock...
Waiting for Firefox lock...
Firefox lock status:
Firefox lock status:
Releasing Firefox lock
Releasing Firefox lock
PostInstallExecute:
PostInstallExecute:
iexplore.exe
iexplore.exe
** Debug mode: simulating PostInstallExecute:
** Debug mode: simulating PostInstallExecute:
Cannot run post-install execute, file does not exist:
Cannot run post-install execute, file does not exist:
COffer::PostInstallExecute
COffer::PostInstallExecute
PostInstallExecute command failed!
PostInstallExecute command failed!
http:
http:
Adding UH data: %s|%s,%s
Adding UH data: %s|%s,%s
Failed to extract uninstall option exe!
Failed to extract uninstall option exe!
Error; uninstalloption.exe doesn't exist (after download and extract!)
Error; uninstalloption.exe doesn't exist (after download and extract!)
Error copying uninstalloption.exe to program files!
Error copying uninstalloption.exe to program files!
error downloading uninstall option url!
error downloading uninstall option url!
hXXp://airdownload.adobe.com/air/win/download/latest/AdobeAIRInstaller.exe
hXXp://airdownload.adobe.com/air/win/download/latest/AdobeAIRInstaller.exe
%programfiles%\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
%programfiles%\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe
"%s" %s "%s"
"%s" %s "%s"
AdobeAirInstaller.exe
AdobeAirInstaller.exe
Uninstall keys:
Uninstall keys:
/uninstallkeys/uninstallkey
/uninstallkeys/uninstallkey
%s/uninstallkeys/uninstallkey[%d]/type/text()
%s/uninstallkeys/uninstallkey[%d]/type/text()
%s/uninstallkeys/uninstallkey[%d]/value/text()
%s/uninstallkeys/uninstallkey[%d]/value/text()
%firefoxprofiles%
%firefoxprofiles%
Unknown uninstall key type encountered, skipping lookup
Unknown uninstall key type encountered, skipping lookup
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
HRESULT:0x%X
HRESULT:0x%X
crterr:%d
crterr:%d
Win32Err:%d
Win32Err:%d
@ line %d in function .
@ line %d in function .
wininet.dll
wininet.dll
Unknown error: %d
Unknown error: %d
IDispatch error #%d
IDispatch error #%d
LoadLibrary failed in loading current exe:
LoadLibrary failed in loading current exe:
CoreResource.cpp
CoreResource.cpp
CStringW.GetBuffer failed!
CStringW.GetBuffer failed!
0xx
0xx
%s. {%s} @ line %d in function in module %s.
%s. {%s} @ line %d in function in module %s.
Win32Err:%d
Win32Err:%d
HRESULT:0x%X
HRESULT:0x%X
Error:%d
Error:%d
HttpStatus:%d
HttpStatus:%d
L%d:d.d.d_d:d:d.d
L%d:d.d.d_d:d:d.d
-- %s line %d --
-- %s line %d --
[X]
[X]
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 /%d
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 /%d
%s_%x%x%x%x%x
%s_%x%x%x%x%x
CoreFile.cpp
CoreFile.cpp
Exception %X in module %s at: 0x%p.
Exception %X in module %s at: 0x%p.
dbghelp.dll
dbghelp.dll
0x%p %s
0x%p %s
CoreProcess.cpp
CoreProcess.cpp
ShellExecuteCommand:
ShellExecuteCommand:
Failed to execute command:
Failed to execute command:
CCoreProcess::ShellExecuteCommand
CCoreProcess::ShellExecuteCommand
CCoreProcess::CloseProcessWindowsByModuleName
CCoreProcess::CloseProcessWindowsByModuleName
CCoreProcess::ShellExecuteCommandAndWait
CCoreProcess::ShellExecuteCommandAndWait
CCoreProcess::GetProcessExe32
CCoreProcess::GetProcessExe32
CCoreProcess::GetProcessExe64
CCoreProcess::GetProcessExe64
kernel32.dll
kernel32.dll
CoreXml.cpp
CoreXml.cpp
_ftprintf_s failed writing header to
_ftprintf_s failed writing header to
]/Key/text()
]/Key/text()
CCoreXml::ParseRequiredKeyValue
CCoreXml::ParseRequiredKeyValue
CCoreXml::ParseRequiredKeyInt
CCoreXml::ParseRequiredKeyInt
CoreThread.cpp
CoreThread.cpp
hXXps://
hXXps://
PTF://
PTF://
CCoreSystem::GetWindowsVersionId
CCoreSystem::GetWindowsVersionId
Missing windows version, check the code!!
Missing windows version, check the code!!
CoreSystem.cpp
CoreSystem.cpp
%s (Build %d)
%s (Build %d)
CCoreSystem::CacheWindowsInfo
CCoreSystem::CacheWindowsInfo
Unknown OS! Major: 0xX, Minor: 0xX
Unknown OS! Major: 0xX, Minor: 0xX
%windows%
%windows%
%system%
%system%
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Þsktopdir%
Þsktopdir%
Þsktop%
Þsktop%
%userprofile%
%userprofile%
%s0x%.2x%.2x%.2x%.2x%.2x%.2x-
%s0x%.2x%.2x%.2x%.2x%.2x%.2x-
SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727
SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727
SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322
SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322
SOFTWARE\Microsoft\.NETFramework\policy\v1.0
SOFTWARE\Microsoft\.NETFramework\policy\v1.0
3321-3705
3321-3705
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
Iphlpapi.dll
Iphlpapi.dll
%windows%\Desktop
%windows%\Desktop
VBoxService.exe
VBoxService.exe
vboxtray.exe
vboxtray.exe
proc.vboxsvc
proc.vboxsvc
vmtoolsd.exe
vmtoolsd.exe
proc.vboxtray
proc.vboxtray
vmicsvc.exe
vmicsvc.exe
proc.vmtools
proc.vmtools
proc.hvsvc
proc.hvsvc
reg.vboxguest
reg.vboxguest
reg.vboxmouse
reg.vboxmouse
reg.vboxsvc
reg.vboxsvc
reg.vboxsf
reg.vboxsf
reg.vboxvid
reg.vboxvid
reg.vboxbios
reg.vboxbios
%system%\vboxhook.dll
%system%\vboxhook.dll
reg.vboxsguest
reg.vboxsguest
file.vboxhook
file.vboxhook
reg.vmvid
reg.vmvid
reg.vmpci
reg.vmpci
reg.vmdbg
reg.vmdbg
reg.vmcrd
reg.vmcrd
reg.vmmem
reg.vmmem
reg.vmmouse
reg.vmmouse
reg.vmdsk
reg.vmdsk
reg.vmtools
reg.vmtools
reg.vmsnap
reg.vmsnap
reg.vmnet64
reg.vmnet64
reg.hvgenctr
reg.hvgenctr
reg.hvvmbus
reg.hvvmbus
SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\0000
SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\0000
reg.hvvid
reg.hvvid
SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}\0000
SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}\0000
reg.hvscsi
reg.hvscsi
reg.hvinput
reg.hvinput
reg.vboxdisk
reg.vboxdisk
reg.vmdisk
reg.vmdisk
reg.hvdisk
reg.hvdisk
sng.vmt1
sng.vmt1
sng.vmt3
sng.vmt3
sng.vmt2
sng.vmt2
gen.dbg
gen.dbg
sng.vmt4
sng.vmt4
CCoreRegKey::Create
CCoreRegKey::Create
Warning: HKEY_CLASSES_ROOT opened for writing! This can lead to unpredictable results.
Warning: HKEY_CLASSES_ROOT opened for writing! This can lead to unpredictable results.
RegCreateKeyEx failed on key=
RegCreateKeyEx failed on key=
RegOpenKeyEx failed on key=
RegOpenKeyEx failed on key=
CCoreRegKey::Open
CCoreRegKey::Open
Registry key is not open! (
Registry key is not open! (
CCoreRegKey::GetValueType
CCoreRegKey::GetValueType
CoreRegKey.cpp
CoreRegKey.cpp
CCoreRegKey::GetValueSize
CCoreRegKey::GetValueSize
CCoreRegKey::GetValue
CCoreRegKey::GetValue
CCoreRegKey::GetValueString
CCoreRegKey::GetValueString
CCoreRegKey::SetValue
CCoreRegKey::SetValue
CCoreRegKey::DeleteValue
CCoreRegKey::DeleteValue
CCoreRegKey::DeleteKey
CCoreRegKey::DeleteKey
RegDeleteKeyEx failed on
RegDeleteKeyEx failed on
RegDeleteKeyExA
RegDeleteKeyExA
RegDeleteKey failed on
RegDeleteKey failed on
CCoreRegKey::EnumSubKeys
CCoreRegKey::EnumSubKeys
CCoreRegKey::CopyTree
CCoreRegKey::CopyTree
SHCopyKey failed for
SHCopyKey failed for
CCoreEntryPoint::CCoreEntryPoint
CCoreEntryPoint::CCoreEntryPoint
CCoreEntryPoint::LoadProcAddress
CCoreEntryPoint::LoadProcAddress
Advapi32.dll
Advapi32.dll
UniqueId.cpp
UniqueId.cpp
subKey is NULL!
subKey is NULL!
0.0.0.0
0.0.0.0
%u,%u,%u,%u
%u,%u,%u,%u
\/:*?"|
\/:*?"|
Failed to create URL file!
Failed to create URL file!
createurlfilefail
createurlfilefail
Encryption key not initialized!
Encryption key not initialized!
CoreEvent.cpp
CoreEvent.cpp
shell32.dll
shell32.dll
CoreVista.cpp
CoreVista.cpp
Software\Microsoft\Windows\CurrentVersion\Policies\System
Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_USERS
HKEY_USERS
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
%Y-%m-%dT%H:%M:%S
%Y-%m-%dT%H:%M:%S
CommandLine.cpp
CommandLine.cpp
%s.%s
%s.%s
iexplore,ie.http
iexplore,ie.http
Failed to get IE version key!
Failed to get IE version key!
Loading IE cookies for url:[
Loading IE cookies for url:[
wrote %d cookies
wrote %d cookies
CoreInternetExplorer.cpp
CoreInternetExplorer.cpp
Unable to find iexplore.exe, using shell execute (with possible warnings)
Unable to find iexplore.exe, using shell execute (with possible warnings)
-noframemerging "%s"
-noframemerging "%s"
ie.http\shell\open\command
ie.http\shell\open\command
Default search regkey not found (may be a brand new install)
Default search regkey not found (may be a brand new install)
ieframe.dll
ieframe.dll
EnumSubKeys failed!
EnumSubKeys failed!
hXXp://VVV.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
hXXp://VVV.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
url is empty!
url is empty!
Replacing existing provider url:
Replacing existing provider url:
Error setting provider url!
Error setting provider url!
FindFirstUrlCacheEntry() failed!!
FindFirstUrlCacheEntry() failed!!
CCoreInternetExplorer::FindFirstHistoryUrl
CCoreInternetExplorer::FindFirstHistoryUrl
CCoreInternetExplorer::FindNextHistoryUrl
CCoreInternetExplorer::FindNextHistoryUrl
findfirsturlfailed
findfirsturlfailed
FindNextUrlCacheEntry() failed!!
FindNextUrlCacheEntry() failed!!
FindUrlCache handle is null!! Did you call FindFirstHistoryUrl first??
FindUrlCache handle is null!! Did you call FindFirstHistoryUrl first??
CCoreInternetExplorer::FindCloseHistoryUrl
CCoreInternetExplorer::FindCloseHistoryUrl
findnexturlfailed
findnexturlfailed
findcloseurlfailed
findcloseurlfailed
FindCloseUrlCache() failed!!
FindCloseUrlCache() failed!!
msgText is required!
msgText is required!
msgTitle is required!
msgTitle is required!
browser.search.selectedEngine
browser.search.selectedEngine
browser.search.defaultenginename
browser.search.defaultenginename
browser.startup.homepage
browser.startup.homepage
keyword.URL
keyword.URL
MozillaWindowClass
MozillaWindowClass
MozillaUIWindowClass
MozillaUIWindowClass
firefox.exe,firefox.url,firefoxportableurl,firefoxurl,firefox
firefox.exe,firefox.url,firefoxportableurl,firefoxurl,firefox
Software\Mozilla\Mozilla Firefox
Software\Mozilla\Mozilla Firefox
Failed to get Firefox version key!
Failed to get Firefox version key!
CCoreFirefox::GetVersion
CCoreFirefox::GetVersion
Profile%d
Profile%d
firefoxver
firefoxver
%appdata%\Mozilla\Firefox
%appdata%\Mozilla\Firefox
Firefox versions prior to 3 are not supported by LoadProfileCookies!
Firefox versions prior to 3 are not supported by LoadProfileCookies!
profiles.ini
profiles.ini
Loading Firefox3 cookies for url:[
Loading Firefox3 cookies for url:[
%s=%s
%s=%s
cookies.sqlite
cookies.sqlite
Enumerating Firefox3 cookies for
Enumerating Firefox3 cookies for
cookies.txt
cookies.txt
Enumerating Firefox cookies for
Enumerating Firefox cookies for
Found partial cookie in Firefox profile:
Found partial cookie in Firefox profile:
firefox.exe
firefox.exe
-requestPending -osint -new-window "%s"
-requestPending -osint -new-window "%s"
PathToExe
PathToExe
prefs.js
prefs.js
%programfiles%\Mozilla Firefox
%programfiles%\Mozilla Firefox
CoreFirefox.cpp
CoreFirefox.cpp
CCoreFirefox::GetPrefString
CCoreFirefox::GetPrefString
CCoreFirefox::SetPrefString
CCoreFirefox::SetPrefString
user_pref("%s", %s%s%s);
user_pref("%s", %s%s%s);
CCoreFirefox::SetDefaultSearch
CCoreFirefox::SetDefaultSearch
searchUrl is empty!
searchUrl is empty!
Can't set search engine while Firefox is running!
Can't set search engine while Firefox is running!
suggestionUrl is empty!
suggestionUrl is empty!
Setting Firefox default search engine:
Setting Firefox default search engine:
SuggestionUrl=
SuggestionUrl=
SearchUrl=
SearchUrl=
Failed to write Yahoo search prefs for Firefox!
Failed to write Yahoo search prefs for Firefox!
hXXp://VVV.mozilla.org/2006/browser/search/
hXXp://VVV.mozilla.org/2006/browser/search/
browser.search.order.1
browser.search.order.1
browser.search.order.2
browser.search.order.2
places.sqlite
places.sqlite
downloads.sqlite
downloads.sqlite
select source from moz_downloads where source like '%%%s%%' order by id desc
select source from moz_downloads where source like '%%%s%%' order by id desc
Failed to open downloads.sqlite database!
Failed to open downloads.sqlite database!
select url from moz_places where url like '%%%s%%' order by id desc
select url from moz_places where url like '%%%s%%' order by id desc
Failed to open places.sqlite database!
Failed to open places.sqlite database!
cannot set startpage; firefox is currently running!
cannot set startpage; firefox is currently running!
CCoreFirefox::SetStartpage
CCoreFirefox::SetStartpage
browser.startup.page
browser.startup.page
Cannot set newtab because firefox is running!
Cannot set newtab because firefox is running!
CCoreFirefox::SetNewTab
CCoreFirefox::SetNewTab
browser.newtab.url
browser.newtab.url
firefox pref: keyword.URL=
firefox pref: keyword.URL=
browser.search.param.yahoo-fr
browser.search.param.yahoo-fr
firefox pref: browser.search.param.yahoo-fr=
firefox pref: browser.search.param.yahoo-fr=
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreChrome.h
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreChrome.h
CCoreChrome::SetCookie
CCoreChrome::SetCookie
Chrome_WidgetWin_0
Chrome_WidgetWin_0
Chrome_WindowImpl_0
Chrome_WindowImpl_0
Chrome_WidgetWin_1
Chrome_WidgetWin_1
Chrome_RenderWidgetHostHWND
Chrome_RenderWidgetHostHWND
%local_appdata%\Google\Chrome\User Data\Default\Cookies
%local_appdata%\Google\Chrome\User Data\Default\Cookies
chrome.exe,chrome.hwd,chromehtml,chromiumhtml,chrome,chromium
chrome.exe,chrome.hwd,chromehtml,chromiumhtml,chrome,chromium
Loading Google Chrome cookies for url:[
Loading Google Chrome cookies for url:[
CCoreChrome; Cookie file does not exist
CCoreChrome; Cookie file does not exist
host_key like '%
host_key like '%
select name, value, host_key, path, expires_utc from cookies where
select name, value, host_key, path, expires_utc from cookies where
CCoreChrome::EnumCookiesLegacy
CCoreChrome::EnumCookiesLegacy
Enumerating Google Chrome cookies for
Enumerating Google Chrome cookies for
Chrome cookie file does not exist
Chrome cookie file does not exist
Enumerating Google Chrome cookies (v33) for
Enumerating Google Chrome cookies (v33) for
select host_key, name, value, path, expires_utc from cookies where host_key like '%
select host_key, name, value, path, expires_utc from cookies where host_key like '%
select host_key, name, value, path, expires_utc, encrypted_value from cookies where host_key like '%
select host_key, name, value, path, expires_utc, encrypted_value from cookies where host_key like '%
CCoreChrome::EnumCookiesV33
CCoreChrome::EnumCookiesV33
Chrome cookie:
Chrome cookie:
Failed to decrypt chrome cookie:
Failed to decrypt chrome cookie:
--new-window "%s"
--new-window "%s"
chrome.dll
chrome.dll
chrome.exe
chrome.exe
Unable to find chrome.exe, using shell execute (with possible warnings)
Unable to find chrome.exe, using shell execute (with possible warnings)
%local_appdata%\Google\Chrome\Application
%local_appdata%\Google\Chrome\Application
ChromeHTML\shell\open\command
ChromeHTML\shell\open\command
CCoreChrome::GetStartpage
CCoreChrome::GetStartpage
%programfiles%\Google\Chrome\Application
%programfiles%\Google\Chrome\Application
session/urls_to_restore_on_startup
session/urls_to_restore_on_startup
CCoreChrome::GetStartupPages
CCoreChrome::GetStartupPages
CoreChrome.cpp
CoreChrome.cpp
session/startup_urls
session/startup_urls
CCoreChrome::IsMultiStartPageEnabled
CCoreChrome::IsMultiStartPageEnabled
CCoreChrome::SetStartpage
CCoreChrome::SetStartpage
CCoreChrome::SetStartPageOld
CCoreChrome::SetStartPageOld
CCoreChrome::SetStartPageNew
CCoreChrome::SetStartPageNew
SELECT value FROM meta WHERE key='Default Search Provider ID'
SELECT value FROM meta WHERE key='Default Search Provider ID'
%local_appdata%\Google\Chrome\User Data\Default\Web Data
%local_appdata%\Google\Chrome\User Data\Default\Web Data
SELECT id, short_name, url FROM keywords where id = %s
SELECT id, short_name, url FROM keywords where id = %s
CCoreChrome::GetDSUrlFromPrefTemplate
CCoreChrome::GetDSUrlFromPrefTemplate
default_search_provider_data/template_url_data
default_search_provider_data/template_url_data
default_search_provider_data/template_url_data/url
default_search_provider_data/template_url_data/url
{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
default_search_provider_data/template_url_data/id
default_search_provider_data/template_url_data/id
default_search_provider_data/template_url_data/short_name
default_search_provider_data/template_url_data/short_name
CCoreChrome: Name param cannot be blank
CCoreChrome: Name param cannot be blank
CCoreChrome::SetDefaultSearch
CCoreChrome::SetDefaultSearch
CCoreChrome: url param cannot be blank
CCoreChrome: url param cannot be blank
CCoreChrome: keyword param cannot be blank
CCoreChrome: keyword param cannot be blank
Found existing default search in Chrome: id=
Found existing default search in Chrome: id=
hXXp://VVV.yahoo.com/favicon.ico
hXXp://VVV.yahoo.com/favicon.ico
Successfully set Default Search provider in chrome
Successfully set Default Search provider in chrome
failed to set Database keyword search!!
failed to set Database keyword search!!
CCoreChrome::SetDatabaseKeywordSearch
CCoreChrome::SetDatabaseKeywordSearch
keywords
keywords
UPDATE meta SET value='%s' WHERE key='Default Search Provider ID'
UPDATE meta SET value='%s' WHERE key='Default Search Provider ID'
sql string is empty
sql string is empty
CCoreChrome::SetPrefDefaultSearchTemplate
CCoreChrome::SetPrefDefaultSearchTemplate
Successfully added default search data to keyword and meta tables
Successfully added default search data to keyword and meta tables
chrome preferences failed to load!
chrome preferences failed to load!
keyword
keyword
default_search_provider_data/template_url_data/
default_search_provider_data/template_url_data/
favicon_url
favicon_url
suggestions_url
suggestions_url
new_tab_url
new_tab_url
originating_url
originating_url
instant_url
instant_url
search_terms_replacement_key
search_terms_replacement_key
search_url_post_params
search_url_post_params
image_url
image_url
instant_url_post_params
instant_url_post_params
suggestions_url_post_params
suggestions_url_post_params
image_url_post_params
image_url_post_params
CCoreChrome::FindSearchEntryID
CCoreChrome::FindSearchEntryID
url = '
url = '
keyword like '%
keyword like '%
url like '%
url like '%
SELECT id FROM keywords WHERE
SELECT id FROM keywords WHERE
Setting existing default search in Chrome:
Setting existing default search in Chrome:
CCoreChrome::SetExistingDefaultSearchUrl
CCoreChrome::SetExistingDefaultSearchUrl
Error opening Chrome Web Data!
Error opening Chrome Web Data!
CCoreChrome::LookupExistingDefaultSearchUrl
CCoreChrome::LookupExistingDefaultSearchUrl
Looking up default search url:
Looking up default search url:
SELECT * FROM keywords WHERE url='%s'
SELECT * FROM keywords WHERE url='%s'
Sqlite is not open!
Sqlite is not open!
LookupDefaultSearchUrl: url not found in table
LookupDefaultSearchUrl: url not found in table
SELECT * FROM keywords WHERE short_name='%s'
SELECT * FROM keywords WHERE short_name='%s'
LookupDefaultSearchUrl: id not found in row
LookupDefaultSearchUrl: id not found in row
CCoreChrome::GetPreference
CCoreChrome::GetPreference
CCoreChrome::LoadChromePreferences
CCoreChrome::LoadChromePreferences
%local_appdata%\Google\Chrome\User Data\Default\Preferences
%local_appdata%\Google\Chrome\User Data\Default\Preferences
suggest_url
suggest_url
suggest_url_post_params
suggest_url_post_params
, show_in_default_list=%s, safe_for_autoreplace=%s, input_encodings='%s'
, show_in_default_list=%s, safe_for_autoreplace=%s, input_encodings='%s'
UPDATE %s set short_name='%s', keyword='%s', url='%s', favicon_url='%s'
UPDATE %s set short_name='%s', keyword='%s', url='%s', favicon_url='%s'
, suggest_url='%s'
, suggest_url='%s'
, new_tab_url='%s'
, new_tab_url='%s'
INSERT INTO %s (
INSERT INTO %s (
WHERE id=%s
WHERE id=%s
keywords_backup
keywords_backup
safe_for_autoreplace, originating_url, date_created, usage_count,
safe_for_autoreplace, originating_url, date_created, usage_count,
short_name, keyword, favicon_url, url,
short_name, keyword, favicon_url, url,
created_by_policy, instant_url, last_modified, sync_guid
created_by_policy, instant_url, last_modified, sync_guid
input_encodings, show_in_default_list, suggest_url, prepopulate_id,
input_encodings, show_in_default_list, suggest_url, prepopulate_id,
, new_tab_url
, new_tab_url
'%s', '%s', '%s', '%s',
'%s', '%s', '%s', '%s',
'%s', %s, '%s', %s,
'%s', %s, '%s', %s,
%s, '%s', %s, %s,
%s, '%s', %s, %s,
, '%s'
, '%s'
%s, '%s', %s, '%s'
%s, '%s', %s, '%s'
%local_appdata%\Google\Chrome\User Data\Default\History
%local_appdata%\Google\Chrome\User Data\Default\History
select url from downloads_url_chains where url like '%%%s%%' order by id desc
select url from downloads_url_chains where url like '%%%s%%' order by id desc
Found chrome extension
Found chrome extension
Setting chrome extension [
Setting chrome extension [
CCoreFirefoxXpiInstaller::Install
CCoreFirefoxXpiInstaller::Install
CoreFirefoxXPIInstaller.cpp
CoreFirefoxXPIInstaller.cpp
CCoreFirefoxXpiInstaller::GetXpiInfo
CCoreFirefoxXpiInstaller::GetXpiInfo
install.rdf
install.rdf
xml.LoadBuffer failed on
xml.LoadBuffer failed on
Installing Firefox add-ons via package...
Installing Firefox add-ons via package...
Create install.rdf failed!
Create install.rdf failed!
Firefox.exe not found!
Firefox.exe not found!
CCoreFirefoxXpiInstaller::InstallAsPackage
CCoreFirefoxXpiInstaller::InstallAsPackage
installiq.xpi
installiq.xpi
Running Firefox to install add-ons:
Running Firefox to install add-ons:
Error running Firefox!
Error running Firefox!
CCoreFirefoxXpiInstaller::CreateInstallRDF
CCoreFirefoxXpiInstaller::CreateInstallRDF
xmlns:NC="hXXp://home.netscape.com/NC-rdf#"
xmlns:NC="hXXp://home.netscape.com/NC-rdf#"
xmlns:em="hXXp://VVV.mozilla.org/2004/em-rdf#">
xmlns:em="hXXp://VVV.mozilla.org/2004/em-rdf#">
multi@installiq.com
multi@installiq.com
{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
*.*.*
*.*.*
CCoreFirefoxXpiInstaller::SetResult
CCoreFirefoxXpiInstaller::SetResult
Error creating install.rdf!
Error creating install.rdf!
CCoreFirefoxXpiInstaller::GetExtensionsFolder
CCoreFirefoxXpiInstaller::GetExtensionsFolder
Installed Firefox extension:
Installed Firefox extension:
Can't get Firefox default profiles folder!
Can't get Firefox default profiles folder!
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreSearchProtectorApp.h
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreSearchProtectorApp.h
keepmysettingsx.exe
keepmysettingsx.exe
hXXp://download.installiq.com/lm/bundles/keepmysettingsx/softwareinstallation_13471.exe
hXXp://download.installiq.com/lm/bundles/keepmysettingsx/softwareinstallation_13471.exe
hXXps://installer.freeze.com/LogError.aspx
hXXps://installer.freeze.com/LogError.aspx
Restoring V1 toolbar uninstall key...
Restoring V1 toolbar uninstall key...
Error replacing toolbar uninstall key!
Error replacing toolbar uninstall key!
Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Software\Microsoft\Windows\CurrentVersion\Uninstall\KeepMySettingsX
Software\Microsoft\Windows\CurrentVersion\Uninstall\KeepMySettingsX
Renaming V1 uninstall key...
Renaming V1 uninstall key...
Error opeing uninstall registry key in HKLM\
Error opeing uninstall registry key in HKLM\
Error copying V1 registry key!
Error copying V1 registry key!
CoreSearchProtectorApp.cpp
CoreSearchProtectorApp.cpp
Error removing V1 registry key from HKLM\
Error removing V1 registry key from HKLM\
CCoreSearchProtectorApp.ShutDown: window not found
CCoreSearchProtectorApp.ShutDown: window not found
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
Error removing registry key from HKLM\
Error removing registry key from HKLM\
apiurl
apiurl
offerurl
offerurl
dsotherurl
dsotherurl
spotherurl
spotherurl
searchkeyword
searchkeyword
%s/provider[%d]
%s/provider[%d]
hXXp://google.com
hXXp://google.com
hXXp://bing.com
hXXp://bing.com
hXXps://VVV.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-us:IE-Address&ie=&oe=
hXXps://VVV.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-us:IE-Address&ie=&oe=
firefoxsearch
firefoxsearch
chromesearch
chromesearch
firefoxstartpage
firefoxstartpage
chromestartpage
chromestartpage
config.dat
config.dat
Error replacing Yahoo Toolbar uninstall key!
Error replacing Yahoo Toolbar uninstall key!
Yahoo uninstall key not found
Yahoo uninstall key not found
Software\Microsoft\Windows\CurrentVersion\Uninstall\
Software\Microsoft\Windows\CurrentVersion\Uninstall\
UninstallKey
UninstallKey
ChromePriorSearchUrl
ChromePriorSearchUrl
UninstallKey=
UninstallKey=
ChromePriorStartPage
ChromePriorStartPage
ChromeStartPage
ChromeStartPage
FirefoxPriorStartPage
FirefoxPriorStartPage
FirefoxPriorSearchUrl
FirefoxPriorSearchUrl
CoreBrowserOptionUninstaller.cpp
CoreBrowserOptionUninstaller.cpp
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreSafari.h
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreSafari.h
safari.exe,safariurl,safari
safari.exe,safariurl,safari
%appdata%\Apple Computer\Safari\Cookies\Cookies.binarycookies
%appdata%\Apple Computer\Safari\Cookies\Cookies.binarycookies
Loading Safari cookies for url:[
Loading Safari cookies for url:[
CoreSafari.cpp
CoreSafari.cpp
%appdata%\Apple Computer\Safari\Cookies\Cookies.plist
%appdata%\Apple Computer\Safari\Cookies\Cookies.plist
Failed to get Safari version key!
Failed to get Safari version key!
safari.exe
safari.exe
-url "%s"
-url "%s"
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
http\shell\open\command
http\shell\open\command
Can't find shell associations or shell command reg keys!
Can't find shell associations or shell command reg keys!
CoreBrowser.cpp
CoreBrowser.cpp
Dll %s failed, resultcode = %x
Dll %s failed, resultcode = %x
SymCCIS2.zip
SymCCIS2.zip
SymCCIS.dll
SymCCIS.dll
RunDLL productlist="%s" resultcodes="%s"
RunDLL productlist="%s" resultcodes="%s"
SCCLog.txt
SCCLog.txt
SymCCISDll.txt
SymCCISDll.txt
SymCCIS_CheckCriteria.txt
SymCCIS_CheckCriteria.txt
SymInstallStub.txt
SymInstallStub.txt
Detect.cpp
Detect.cpp
/execute/text()
/execute/text()
Missing ExecuteResult in requirement config!
Missing ExecuteResult in requirement config!
/executeresult/text()
/executeresult/text()
%programfiles%\iTunes\iTunes.exe
%programfiles%\iTunes\iTunes.exe
SOFTWARE\Microsoft\Windows Live\Messenger
SOFTWARE\Microsoft\Windows Live\Messenger
msnmsgr.exe
msnmsgr.exe
ydetect.yas
ydetect.yas
ydetect.ytb
ydetect.ytb
ydetect.yhp
ydetect.yhp
Rules.cpp
Rules.cpp
RegKeyExists
RegKeyExists
regkey
regkey
firefoxprefs
firefoxprefs
chromeprefs
chromeprefs
CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\InprocServer32
CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\InprocServer32
%firefoxprofiles%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\install.rdf
%firefoxprofiles%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}\install.rdf
CDetectionYahooToolbar::IsInstalledFirefox
CDetectionYahooToolbar::IsInstalledFirefox
multireg: unable to parse key:
multireg: unable to parse key:
KeyExists
KeyExists
SourceKey
SourceKey
hkey_local_machine
hkey_local_machine
hkey_current_user
hkey_current_user
hkey_current_config
hkey_current_config
hkey_classes_root
hkey_classes_root
multireg: key found:
multireg: key found:
multireg%d
multireg%d
1.1.0.6
1.1.0.6
//flag[%d]/text()
//flag[%d]/text()
Cannot evaluate .NET Version, .NET may not be installed!
Cannot evaluate .NET Version, .NET may not be installed!
DetectionFile.cpp
DetectionFile.cpp
wajam_validate.zip
wajam_validate.zip
wajamexemissing
wajamexemissing
extracted wajam exe file not found!
extracted wajam exe file not found!
Timed out waiting for wajam_validate.exe!
Timed out waiting for wajam_validate.exe!
Unable to get returncode from wajam_validate.exe!
Unable to get returncode from wajam_validate.exe!
wajam_validate.exe detection process result = %d
wajam_validate.exe detection process result = %d
yahoo.com
yahoo.com
live.com
live.com
google.com
google.com
ask.com
ask.com
msn.com
msn.com
aol.com
aol.com
DetectionFirefoxPrefs.cpp
DetectionFirefoxPrefs.cpp
CDetectionFirefoxPrefs::OnEvaluate
CDetectionFirefoxPrefs::OnEvaluate
CDetectionChromePrefs::OnEvaluate
CDetectionChromePrefs::OnEvaluate
DetectionChromePrefs.cpp
DetectionChromePrefs.cpp
minwindowsversion
minwindowsversion
)] disabled because of minimum windows version.
)] disabled because of minimum windows version.
DetectionRule.cpp
DetectionRule.cpp
Disabled; rule target is not Firefox
Disabled; rule target is not Firefox
Disabled; rule target is not Chrome
Disabled; rule target is not Chrome
Disabled; Firefox is not installed
Disabled; Firefox is not installed
Disabled; Chrome is not installed
Disabled; Chrome is not installed
asktbdet.zip
asktbdet.zip
Ask detection process result = %d
Ask detection process result = %d
CoreWininet.cpp
CoreWininet.cpp
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
wininet: connecting to %s:%d
wininet: connecting to %s:%d
HTTPSendRequest:
HTTPSendRequest:
wininet: HttpOpenRequest failed!
wininet: HttpOpenRequest failed!
CCoreWininet::HTTPSendRequest
CCoreWininet::HTTPSendRequest
wininet: Request handle is NULL after HttpSendRequest!
wininet: Request handle is NULL after HttpSendRequest!
httpopenrequest
httpopenrequest
unable to set wininet http decoding
unable to set wininet http decoding
httpreqerr
httpreqerr
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
httpaddheaders
httpaddheaders
wininet: HttpAddRequestHeaders (post flag) failed!
wininet: HttpAddRequestHeaders (post flag) failed!
Range: bytes=%u-%u
Range: bytes=%u-%u
Range: bytes=%u-
Range: bytes=%u-
httpaddheader
httpaddheader
wininet: HttpAddRequestHeaders (range specification) failed!
wininet: HttpAddRequestHeaders (range specification) failed!
wininet: HttpSendRequest failed! (verb=
wininet: HttpSendRequest failed! (verb=
httpsendreq
httpsendreq
wininet: HttpSendRequest failed!
wininet: HttpSendRequest failed!
httptimeout
httptimeout
httpqueryinfo
httpqueryinfo
wininet: HttpQueryInfo failed!
wininet: HttpQueryInfo failed!
httpproxy
httpproxy
httpstatus
httpstatus
wininet: Server responded with error: %d, %s. %s %s
wininet: Server responded with error: %d, %s. %s %s
wininet: HttpSendRequest: status OK received
wininet: HttpSendRequest: status OK received
wininet: HttpQueryInfo for file size failed!
wininet: HttpQueryInfo for file size failed!
wininet: HttpQueryInfo for content range failed!
wininet: HttpQueryInfo for content range failed!
wininet: Operation cancelled by caller.
wininet: Operation cancelled by caller.
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion\Internet Settings
HTTP Status %d: %s
HTTP Status %d: %s
apiUrl is null!
apiUrl is null!
API url is invalid!
API url is invalid!
%m/%d/%Y
%m/%d/%Y
Url is null!
Url is null!
%s, %s, l=0xx
%s, %s, l=0xx
[0x%X]
[0x%X]
d:%s
d:%s
01234567
01234567
%s(%s);
%s(%s);
CoreJSON2.cpp
CoreJSON2.cpp
Node path not valid; node "%s" in path "%s" is not type Node!
Node path not valid; node "%s" in path "%s" is not type Node!
PackageZlib.cpp
PackageZlib.cpp
Error: %d bytes of %d read from file %s.
Error: %d bytes of %d read from file %s.
unzOpenCurrentFilePassword failed!
unzOpenCurrentFilePassword failed!
Error: %d bytes of %d were written to file %s.
Error: %d bytes of %d were written to file %s.
unzOpenCurrentFilePassword failed! err=
unzOpenCurrentFilePassword failed! err=
Package.cpp
Package.cpp
autorun.txt
autorun.txt
CCoreSqlite::OpenDatabase
CCoreSqlite::OpenDatabase
CCoreSqlite::CloseDatabase
CCoreSqlite::CloseDatabase
sqlite3_exec failed, returned error:
sqlite3_exec failed, returned error:
CCoreSqlite::ExecuteStatement
CCoreSqlite::ExecuteStatement
CCoreSqlite::StandardExecuteCallback
CCoreSqlite::StandardExecuteCallback
dbexecerror
dbexecerror
CoreSqlite.cpp
CoreSqlite.cpp
CCoreSqlite::PrepareCompiledStmt
CCoreSqlite::PrepareCompiledStmt
sqlempty
sqlempty
Cannot prepare statement, sql is empty!
Cannot prepare statement, sql is empty!
sqliteerror
sqliteerror
Failed to prepare compiled statement, sqlite returned error: %d
Failed to prepare compiled statement, sqlite returned error: %d
CCoreSqlite::BindTextToCompiledStmt
CCoreSqlite::BindTextToCompiledStmt
bind text failed, errorcode=%d
bind text failed, errorcode=%d
CCoreSqlite::ExecuteCompiledStmt
CCoreSqlite::ExecuteCompiledStmt
sqlitestepfailed
sqlitestepfailed
sqlite3_step failed, errorcode=%d
sqlite3_step failed, errorcode=%d
CCoreSqlite::CheckStmtRowValid
CCoreSqlite::CheckStmtRowValid
Cannot get row results: statement has not executed!!
Cannot get row results: statement has not executed!!
CCoreSqlite::CloseCompiledStmt
CCoreSqlite::CloseCompiledStmt
sqlite3_finalize failed, errorcode=%d
sqlite3_finalize failed, errorcode=%d
SQLite format 3
SQLite format 3
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
CREATE TABLE sqlite_master(
CREATE TABLE sqlite_master(
sql text
sql text
3.7.5
3.7.5
CREATE TEMP TABLE sqlite_temp_master(
CREATE TEMP TABLE sqlite_temp_master(
zip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
zip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
unzip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
unzip 1.01 Copyright 1998-2004 Gilles Vollant - hXXp://VVV.winimage.com/zLibDll
1.2.7
1.2.7
deflate 1.2.7 Copyright 1995-2012 Jean-loup Gailly and Mark Adler
deflate 1.2.7 Copyright 1995-2012 Jean-loup Gailly and Mark Adler
inflate 1.2.7 Copyright 1995-2012 Mark Adler
inflate 1.2.7 Copyright 1995-2012 Mark Adler
SQLITE_
SQLITE_
d:d:d
d:d:d
d-d-d d:d:d
d-d-d d:d:d
d-d-d
d-d-d
failed to allocate %u bytes of memory
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
failed memory resize %u to %u bytes
922337203685477580
922337203685477580
API call with %s database connection pointer
API call with %s database connection pointer
RowKey
RowKey
%s-shm
%s-shm
%s\etilqs_
%s\etilqs_
OsError 0x%x (%u)
OsError 0x%x (%u)
Recovered %d frames from WAL file %s
Recovered %d frames from WAL file %s
2nd reference to page %d
2nd reference to page %d
invalid page number %d
invalid page number %d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
Failed to read ptrmap key=%d
Failed to read ptrmap key=%d
failed to get page %d
failed to get page %d
%d of %d pages missing from overflow list starting at %d
%d of %d pages missing from overflow list starting at %d
Page %d:
Page %d:
freelist leaf count too big on page %d
freelist leaf count too big on page %d
btreeInitPage() returns error code %d
btreeInitPage() returns error code %d
unable to get the page. error code=%d
unable to get the page. error code=%d
On tree page %d cell %d:
On tree page %d cell %d:
On page %d at right child:
On page %d at right child:
Multiple uses for byte %d of page %d
Multiple uses for byte %d of page %d
Corruption detected in cell %d on page %d
Corruption detected in cell %d on page %d
Fragmentation of %d bytes reported as %d on page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Page %d is never used
Outstanding page count goes from %d to %d during this analysis
Outstanding page count goes from %d to %d during this analysis
Pointer map page %d is referenced
Pointer map page %d is referenced
unknown database %s
unknown database %s
keyinfo(%d
keyinfo(%d
%s(%d)
%s(%d)
foreign key constraint failed
foreign key constraint failed
%s-mjX
%s-mjX
unable to use function %s in the requested context
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
bind on a busy prepared statement: [%s]
zeroblob(%d)
zeroblob(%d)
constraint failed at %d in [%s]
constraint failed at %d in [%s]
abort at %d in [%s]: %s
abort at %d in [%s]: %s
no such savepoint: %s
no such savepoint: %s
cannot open savepoint - SQL statements in progress
cannot open savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot %s savepoint - SQL statements in progress
cannot %s savepoint - SQL statements in progress
cannot commit transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_temp_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
sqlite_master
sqlite_master
cannot change %s wal mode from within a transaction
cannot change %s wal mode from within a transaction
statement aborts at %d: [%s] %s
statement aborts at %d: [%s] %s
database table is locked: %s
database table is locked: %s
cannot open value of type %s
cannot open value of type %s
cannot open view: %s
cannot open view: %s
cannot open virtual table: %s
cannot open virtual table: %s
foreign key
foreign key
no such column: "%s"
no such column: "%s"
cannot open %s column for writing
cannot open %s column for writing
indexed
indexed
misuse of aliased aggregate %s
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s.%s
%s: %s
%s: %s
%s: %s.%s
%s: %s.%s
not authorized to use function: %s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
too many terms in %s BY clause
variable number must be between ?1 and ?%d
variable number must be between ?1 and ?%d
Expression tree is too large (maximum depth %d)
Expression tree is too large (maximum depth %d)
too many columns in %s
too many columns in %s
too many SQL variables
too many SQL variables
misuse of aggregate: %s()
misuse of aggregate: %s()
EXECUTE %s%s SUBQUERY %d
EXECUTE %s%s SUBQUERY %d
%s%.*s"%w"
%s%.*s"%w"
%.*s"%w"%s
%.*s"%w"%s
sqlite_rename_trigger
sqlite_rename_trigger
sqlite_rename_table
sqlite_rename_table
sqlite_rename_parent
sqlite_rename_parent
type='trigger' AND (%s)
type='trigger' AND (%s)
%s OR name=%Q
%s OR name=%Q
there is already another table or index with this name: %s
there is already another table or index with this name: %s
table %s may not be altered
table %s may not be altered
sqlite_
sqlite_
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
view %s may not be altered
view %s may not be altered
sqlite_sequence
sqlite_sequence
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
Cannot add a PRIMARY KEY column
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_stat1
sqlite_stat1
sqlite_altertab_%s
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE tbl=%Q
DELETE FROM %Q.%s WHERE tbl=%Q
invalid name: "%s"
invalid name: "%s"
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
too many attached databases - max %d
too many attached databases - max %d
database %s is already in use
database %s is already in use
unable to open database: %s
unable to open database: %s
cannot detach database %s
cannot detach database %s
no such database: %s
no such database: %s
database %s is locked
database %s is locked
sqlite_attach
sqlite_attach
sqlite_detach
sqlite_detach
%s %T cannot reference objects in database %s
%s %T cannot reference objects in database %s
access to %s.%s is prohibited
access to %s.%s is prohibited
access to %s.%s.%s is prohibited
access to %s.%s.%s is prohibited
object name reserved for internal use: %s
object name reserved for internal use: %s
too many columns on %s
too many columns on %s
there is already an index named %s
there is already an index named %s
default value of column [%s] is not constant
default value of column [%s] is not constant
duplicate column name: %s
duplicate column name: %s
table "%s" has more than one primary key
table "%s" has more than one primary key
no such collation sequence: %s
no such collation sequence: %s
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE %s %.*s
CREATE %s %.*s
CREATE TABLE %Q.sqlite_sequence(name,seq)
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
view %s is circularly defined
table %s may not be dropped
table %s may not be dropped
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
use DROP VIEW to delete view %s
use DROP VIEW to delete view %s
use DROP TABLE to delete table %s
use DROP TABLE to delete table %s
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %s.sqlite_sequence WHERE name=%Q
foreign key on %s should reference only one column of table %T
foreign key on %s should reference only one column of table %T
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
unknown column "%s" in foreign key definition
unknown column "%s" in foreign key definition
number of columns in foreign key does not match the number of columns in the referenced table
number of columns in foreign key does not match the number of columns in the referenced table
indexed columns are not unique
indexed columns are not unique
table %s may not be indexed
table %s may not be indexed
virtual tables may not be indexed
virtual tables may not be indexed
views may not be indexed
views may not be indexed
index %s already exists
index %s already exists
there is already a table named %s
there is already a table named %s
table %s has no column named %s
table %s has no column named %s
sqlite_autoindex_%s_%d
sqlite_autoindex_%s_%d
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
CREATE%s INDEX %.*s
CREATE%s INDEX %.*s
no such index: %S
no such index: %S
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
a JOIN clause is required before %s
a JOIN clause is required before %s
unable to identify the object to be reindexed
unable to identify the object to be reindexed
cannot modify %s because it is a view
cannot modify %s because it is a view
table %s may not be modified
table %s may not be modified
sqlite_source_id
sqlite_source_id
sqlite_version
sqlite_version
sqlite_compileoption_get
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_compileoption_used
foreign key mismatch
foreign key mismatch
table %S has %d columns but %d values were supplied
table %S has %d columns but %d values were supplied
table %S has no column named %s
table %S has no column named %s
%d values for %d columns
%d values for %d columns
%s.%s may not be NULL
%s.%s may not be NULL
PRIMARY KEY must be unique
PRIMARY KEY must be unique
sqlite3_extension_init
sqlite3_extension_init
no entry point [%s] in shared library [%s]
no entry point [%s] in shared library [%s]
unable to open shared library [%s]
unable to open shared library [%s]
automatic extension loading failed: %s
automatic extension loading failed: %s
error during initialization: %s
error during initialization: %s
foreign_keys
foreign_keys
foreign_key_list
foreign_key_list
*** in database %s ***
*** in database %s ***
unsupported encoding: %s
unsupported encoding: %s
malformed database schema (%s)
malformed database schema (%s)
%s - %s
%s - %s
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
unsupported file format
unsupported file format
database schema is locked: %s
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
unknown or unsupported join type: %T %T%s%T
a NATURAL join may not have an ON or USING clause
a NATURAL join may not have an ON or USING clause
RIGHT and FULL OUTER JOINs are not currently supported
RIGHT and FULL OUTER JOINs are not currently supported
cannot join using column %s - column not present in both tables
cannot join using column %s - column not present in both tables
cannot have both ON and USING clauses in the same join
cannot have both ON and USING clauses in the same join
USE TEMP B-TREE FOR %s
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
COMPOUND SUBQUERIES %d AND %d %s(%s)
ORDER BY clause should come after %s not before
ORDER BY clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
SELECTs to the left and right of %s do not have the same number of result columns
LIMIT clause should come after %s not before
LIMIT clause should come after %s not before
sqlite_subquery_%p_
sqlite_subquery_%p_
no such index: %s
no such index: %s
no such table: %s
no such table: %s
sqlite3_get_table() called with two or more incompatible queries
sqlite3_get_table() called with two or more incompatible queries
cannot create INSTEAD OF trigger on table: %S
cannot create INSTEAD OF trigger on table: %S
cannot create %s trigger on view: %S
cannot create %s trigger on view: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
-- TRIGGER %s
-- TRIGGER %s
no such trigger: %S
no such trigger: %S
no such column: %s
no such column: %s
cannot VACUUM - SQL statements in progress
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor failed: %s
vtable constructor did not declare schema: %s
vtable constructor did not declare schema: %s
no such module: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
table %s: xBestIndex returned an invalid plan
%s TABLE %s
%s TABLE %s
%s SUBQUERY %d
%s SUBQUERY %d
%s AS %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING %s%sINDEX%s%s%s
%s (rowid=?)
%s (rowid=?)
%s USING INTEGER PRIMARY KEY
%s USING INTEGER PRIMARY KEY
%s (rowid>?)
%s (rowid>?)
%s (rowid>? AND rowid)
%s (rowid>? AND rowid)
%s VIRTUAL TABLE INDEX %d:%s
%s VIRTUAL TABLE INDEX %d:%s
%s (rowid)
%s (rowid)
at most %d tables in a join
at most %d tables in a join
%s (~%lld rows)
%s (~%lld rows)
cannot use index: %s
cannot use index: %s
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unable to close due to unfinished backup operation
SQL logic error or missing database
SQL logic error or missing database
unknown operation
unknown operation
large file support is disabled
large file support is disabled
unknown database: %s
unknown database: %s
no such vfs: %s
no such vfs: %s
database corruption at line %d of [%.10s]
database corruption at line %d of [%.10s]
cannot open file at line %d of [%.10s]
cannot open file at line %d of [%.10s]
misuse at line %d of [%.10s]
misuse at line %d of [%.10s]
%s>
%s>
X;
X;
%s='%s'
%s='%s'
%s="%s"
%s="%s"
encoding="%s"
encoding="%s"
version="%s"
version="%s"
standalone="%s"
standalone="%s"
CoreDialogCloseProcess.cpp
CoreDialogCloseProcess.cpp
CoreHtmlDialog.cpp
CoreHtmlDialog.cpp
onBeforeNavigate2 called, url=
onBeforeNavigate2 called, url=
CoreIEControl.cpp
CoreIEControl.cpp
uxtheme.dll
uxtheme.dll
CCoreWinTask::AddExecAction
CCoreWinTask::AddExecAction
Error getting IExecAction!
Error getting IExecAction!
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreOpera.h
c:\winapps\windows\main\core.cpplib\core.cpplib.browser\CoreOpera.h
EnumCookies is not implemented for Opera!
EnumCookies is not implemented for Opera!
CCoreOpera::EnumCookies
CCoreOpera::EnumCookies
CCoreOpera::SetCookie
CCoreOpera::SetCookie
SetCookie is not implemented for Opera!
SetCookie is not implemented for Opera!
CCoreOpera::LoadCookies
CCoreOpera::LoadCookies
LoadCookies is not implemented for Opera!
LoadCookies is not implemented for Opera!
opera.exe,opera.protocol,opera.url,opera,operanext,operastable
opera.exe,opera.protocol,opera.url,opera,operanext,operastable
CCoreOpera::OpenUrl
CCoreOpera::OpenUrl
OpenURL is not implemented for Opera!
OpenURL is not implemented for Opera!
Software\Opera Software
Software\Opera Software
opera.exe
opera.exe
%programfiles%\Opera
%programfiles%\Opera
launcher.exe
launcher.exe
%programfiles%\Opera Next
%programfiles%\Opera Next
CoreIEHost.cpp
CoreIEHost.cpp
m_WebBrowserEvents failed
m_WebBrowserEvents failed
IWebBrowser2 failed
IWebBrowser2 failed
_WebBrowserEvents failed
_WebBrowserEvents failed
_webBrowser->Quit failed!
_webBrowser->Quit failed!
Not initialized or _webBrowser is NULL!
Not initialized or _webBrowser is NULL!
Sending Quit to web browser...
Sending Quit to web browser...
IWebBrowser failed!
IWebBrowser failed!
CCoreIEHost::DeleteHistoryUrl
CCoreIEHost::DeleteHistoryUrl
CCoreIEHost.OnDocumentComplete:
CCoreIEHost.OnDocumentComplete:
WebBrowser object is NULL!
WebBrowser object is NULL!
Error: Collection didn't support IHTMLElementCollection!
Error: Collection didn't support IHTMLElementCollection!
*** set key code to 0 ****
*** set key code to 0 ****
C:\winapps\Windows\MAIN\Installer.QuickStart.Application\ReleaseNoMFC\quickstart.pdb
C:\winapps\Windows\MAIN\Installer.QuickStart.Application\ReleaseNoMFC\quickstart.pdb
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
OLEAUT32.dll
OLEAUT32.dll
SHDeleteEmptyKeyA
SHDeleteEmptyKeyA
SHLWAPI.dll
SHLWAPI.dll
COMCTL32.dll
COMCTL32.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
ShellExecuteExA
ShellExecuteExA
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
PSAPI.DLL
PSAPI.DLL
VERSION.dll
VERSION.dll
USERENV.dll
USERENV.dll
InternetCrackUrlA
InternetCrackUrlA
InternetCanonicalizeUrlA
InternetCanonicalizeUrlA
InternetCombineUrlA
InternetCombineUrlA
FindFirstUrlCacheEntryA
FindFirstUrlCacheEntryA
FindNextUrlCacheEntryA
FindNextUrlCacheEntryA
FindCloseUrlCache
FindCloseUrlCache
HttpOpenRequestA
HttpOpenRequestA
HttpAddRequestHeadersA
HttpAddRequestHeadersA
HttpSendRequestA
HttpSendRequestA
HttpQueryInfoA
HttpQueryInfoA
WININET.dll
WININET.dll
UrlEscapeA
UrlEscapeA
SHCopyKeyA
SHCopyKeyA
gdiplus.dll
gdiplus.dll
IsValidURL
IsValidURL
urlmon.dll
urlmon.dll
GetWindowsDirectoryA
GetWindowsDirectoryA
EnumWindows
EnumWindows
EnumChildWindows
EnumChildWindows
GetKeyboardState
GetKeyboardState
GDI32.dll
GDI32.dll
RegCloseKey
RegCloseKey
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
RegDeleteKeyA
RegDeleteKeyA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegEnumKeyExA
RegEnumKeyExA
ADVAPI32.dll
ADVAPI32.dll
CRYPT32.dll
CRYPT32.dll
zcÃ
zcÃ
.?AV?$_Ref_count@VCOfferExe@@@std@@
.?AV?$_Ref_count@VCOfferExe@@@std@@
.?AV?$_Ref_count_obj@VCOfferExe@@@std@@
.?AV?$_Ref_count_obj@VCOfferExe@@@std@@
.?AV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@
.?AV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@
.?AVCOfferExe@@
.?AVCOfferExe@@
.?AVCCoreStringUrl@@
.?AVCCoreStringUrl@@
.?AV?$CFlags@W4WebArgFlag@@@@
.?AV?$CFlags@W4WebArgFlag@@@@
.?AV?$CCoreEntryPoint@P6GJPAUHKEY__@@PBDKK@Z@@
.?AV?$CCoreEntryPoint@P6GJPAUHKEY__@@PBDKK@Z@@
.?AVCCoreRegKey@@
.?AVCCoreRegKey@@
.?AV?$CAtlArray@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@@ATL@@
.?AV?$CAtlArray@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@@ATL@@
.?AVCCoreFirefox@@
.?AVCCoreFirefox@@
.?AV?$CFlags@W4CoreFirefoxCache@@@@
.?AV?$CFlags@W4CoreFirefoxCache@@@@
.?AV?$_Func_impl@U?$_Callable_obj@V?$_Bind@$00XU?$_Pmf_wrap@P8CCoreChrome@@AEXPAVCCoreSqlite@@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@ZXV1@PAV2@PAV34@U_Nil@std@@U56@U56@U56@U56@@std@@QAVCCoreChrome@@AAV?$_Ph@$00@2@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@U_Nil@2@U72@U72@U72@@std@@$0A@@std@@V?$allocator@V?$_Func_class@XPAVCCoreSqlite@@U_Nil@std@@U23@U23@U23@U23@U23@@std@@@2@XPAVCCoreSqlite@@U_Nil@2@U52@U52@U52@U52@U52@@std@@
.?AV?$_Func_impl@U?$_Callable_obj@V?$_Bind@$00XU?$_Pmf_wrap@P8CCoreChrome@@AEXPAVCCoreSqlite@@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@ZXV1@PAV2@PAV34@U_Nil@std@@U56@U56@U56@U56@@std@@QAVCCoreChrome@@AAV?$_Ph@$00@2@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@U_Nil@2@U72@U72@U72@@std@@$0A@@std@@V?$allocator@V?$_Func_class@XPAVCCoreSqlite@@U_Nil@std@@U23@U23@U23@U23@U23@@std@@@2@XPAVCCoreSqlite@@U_Nil@2@U52@U52@U52@U52@U52@@std@@
.?AVCCoreChrome@@
.?AVCCoreChrome@@
.?AV?$CFlags@W4CoreChromeCache@@@@
.?AV?$CFlags@W4CoreChromeCache@@@@
.?AV?$_Func_base@XPAVCCoreSqlite@@U_Nil@std@@U23@U23@U23@U23@U23@@std@@
.?AV?$_Func_base@XPAVCCoreSqlite@@U_Nil@std@@U23@U23@U23@U23@U23@@std@@
.?AV?$_Bind@$00XU?$_Pmf_wrap@P8CCoreChrome@@AEXPAVCCoreSqlite@@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@ZXV1@PAV2@PAV34@U_Nil@std@@U56@U56@U56@U56@@std@@QAVCCoreChrome@@AAV?$_Ph@$00@2@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@U_Nil@2@U72@U72@U72@@std@@
.?AV?$_Bind@$00XU?$_Pmf_wrap@P8CCoreChrome@@AEXPAVCCoreSqlite@@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@ZXV1@PAV2@PAV34@U_Nil@std@@U56@U56@U56@U56@@std@@QAVCCoreChrome@@AAV?$_Ph@$00@2@PAV?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@U_Nil@2@U72@U72@U72@@std@@
.?AVCCoreFirefoxXpiInstaller@@
.?AVCCoreFirefoxXpiInstaller@@
.?AV?$_Ref_count_obj@VCCoreOpera@@@std@@
.?AV?$_Ref_count_obj@VCCoreOpera@@@std@@
.?AV?$_Ref_count_obj@VCCoreChrome@@@std@@
.?AV?$_Ref_count_obj@VCCoreChrome@@@std@@
.?AV?$_Ref_count_obj@VCCoreFirefox@@@std@@
.?AV?$_Ref_count_obj@VCCoreFirefox@@@std@@
.?AV?$_Ref_count_obj@VCDetectionChromePrefs@@@std@@
.?AV?$_Ref_count_obj@VCDetectionChromePrefs@@@std@@
.?AV?$_Ref_count_obj@VCDetectionFirefoxPrefs@@@std@@
.?AV?$_Ref_count_obj@VCDetectionFirefoxPrefs@@@std@@
.?AVCDetectionFirefoxPrefs@@
.?AVCDetectionFirefoxPrefs@@
.?AVCDetectionChromePrefs@@
.?AVCDetectionChromePrefs@@
.?AV?$CAtlArray@UWebArg@@V?$CElementTraits@UWebArg@@@ATL@@@ATL@@
.?AV?$CAtlArray@UWebArg@@V?$CElementTraits@UWebArg@@@ATL@@@ATL@@
.?AVCCoreWebArgs@@
.?AVCCoreWebArgs@@
.?AVCCoreSqlite@@
.?AVCCoreSqlite@@
.?AV?$CAtlArray@PAV?$CAtlMap@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V12@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@V32@@ATL@@V?$CElementTraits@PAV?$CAtlMap@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V12@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@V32@@ATL@@@2@@ATL@@
.?AV?$CAtlArray@PAV?$CAtlMap@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V12@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@V32@@ATL@@V?$CElementTraits@PAV?$CAtlMap@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@V12@V?$CElementTraits@V?$CStringT@DV?$StrTraitATL@DV?$ChTraitsCRT@D@ATL@@@ATL@@@ATL@@@2@V32@@ATL@@@2@@ATL@@
.?AVCCoreSqliteResult@@
.?AVCCoreSqliteResult@@
.?AVexecution_error@TinyXPath@@
.?AVexecution_error@TinyXPath@@
.?AV?$CFlags@W4CoreOperaCache@@@@
.?AV?$CFlags@W4CoreOperaCache@@@@
.?AVCCoreOpera@@
.?AVCCoreOpera@@
.?AUDWebBrowserEvents2@@
.?AUDWebBrowserEvents2@@
.?AVCCoreWebBrowserEvents@@
.?AVCCoreWebBrowserEvents@@
c:\%original file name%.exe
c:\%original file name%.exe
@.reloc
@.reloc
Vista.BadArgs
Vista.BadArgs
\cookie.ini
\cookie.ini
\cookie.dat
\cookie.dat
Vista.BadArgs2
Vista.BadArgs2
Domain%d
Domain%d
Name%d
Name%d
\cookie%d.dat
\cookie%d.dat
\cookie%d.ini
\cookie%d.ini
Vista.NoAppLow
Vista.NoAppLow
Vista.WideFail
Vista.WideFail
Vista.GetCookieFail
Vista.GetCookieFail
Vista.AllocFail
Vista.AllocFail
Vista.CreateFileError
Vista.CreateFileError
Vista.WriteFileError
Vista.WriteFileError
Vista.SetCookie
Vista.SetCookie
SetCookie%d
SetCookie%d
Vista.SetCookieError
Vista.SetCookieError
Error: %d. %s
Error: %d. %s
C:\winapps\Windows\MAIN\Installer.QuickStart.Application\ReleaseNoMFC\Installer.CookieMan.pdb
C:\winapps\Windows\MAIN\Installer.QuickStart.Application\ReleaseNoMFC\Installer.CookieMan.pdb
3 3%3,323
3 3%3,323
.ao &
.ao &
$.OA[W
$.OA[W
C_.jN
C_.jN
fs.MJ
fs.MJ
\%S6j
\%S6j
<.vmx>
<.vmx>
;.Ur?
;.Ur?
7:.Vmeu
7:.Vmeu
-N.sZ
-N.sZ
v.GEJh
v.GEJh
}N5%d
}N5%d
.nX9k
.nX9k
U;9%u
U;9%u
g 8%U
g 8%U
'/O.Axy
'/O.Axy
f7%X[
f7%X[
@: .pI^
@: .pI^
wajam_validate.exe
wajam_validate.exe
R2dmjg
R2dmjg
t..CD
t..CD
.qmZ
.qmZ
petite_oo_v5.vi.zip
petite_oo_v5.vi.zip
54.gP
54.gP
QEXE
QEXE
7.dQ
7.dQ
%x9q3
%x9q3
.VFbd
.VFbd
.Ps.UlJ
.Ps.UlJ
".lii
".lii
-w}]Y
-w}]Y
.iSKD
.iSKD
6.tR&
6.tR&
adobeflashplayer.vi.zip
adobeflashplayer.vi.zip
zýi
zýi
(.lGo
(.lGo
%9UjH
%9UjH
rockettab.vi.zip
rockettab.vi.zip
offerbox.vi.zip
offerbox.vi.zip
pcoptimizerpro_offer.vi.zip
pcoptimizerpro_offer.vi.zip
pcspeedup.vi.zip
pcspeedup.vi.zip
w1.ce
w1.ce
registryhelper.vi.zip
registryhelper.vi.zip
driverscanner.vi.zipFTvv
driverscanner.vi.zipFTvv
fulldiskfighter.vi.zip
fulldiskfighter.vi.zip
smartpccleaner.vi.zip%
smartpccleaner.vi.zip%
financealert.vi.zip
financealert.vi.zip
weatherbug.vi.zip
weatherbug.vi.zip
nortonsecurityscan.vi.zip
nortonsecurityscan.vi.zip
vebasearch.vi.zip
vebasearch.vi.zip
chocolatebar.vi.zip
chocolatebar.vi.zip
maxthon.vi.zip@
maxthon.vi.zip@
winferno.vi.zip
winferno.vi.zip
uninstallhelper.vi.zip
uninstallhelper.vi.zip
driverfighter.vi.zip
driverfighter.vi.zip
kaspersky.vi.zip
kaspersky.vi.zip
slowpcfighter.vi.zip
slowpcfighter.vi.zip
genieo.vi.zip
genieo.vi.zip
%CZiJ7x
%CZiJ7x
astroarcade.vi.zip
astroarcade.vi.zip
nortoninternetsecurity.vi.zipJ
nortoninternetsecurity.vi.zipJ
defaulttab.vi.zip.
defaulttab.vi.zip.
~[1.og
~[1.og
webbar.vi.zip
webbar.vi.zip
yahoosuite.vi.zip
yahoosuite.vi.zip
<.pa>
<.pa>
arcadeparlor.vi.zip
arcadeparlor.vi.zip
blasteroids.vi.zip
blasteroids.vi.zip
stormwatch.vi.zipk=
stormwatch.vi.zipk=
nortonantivirus.vi.zip2
nortonantivirus.vi.zip2
converterfreeonline.vi.zip
converterfreeonline.vi.zip
yahoo_hpds_defaultsearch.test.vi.zip
yahoo_hpds_defaultsearch.test.vi.zip
resultsbay.vi.zip
resultsbay.vi.zip
spyhunter.vi.zip
spyhunter.vi.zip
mypcbackup.vi.zip
mypcbackup.vi.zip
jenkatgamesarcadeplus.vi.zip
jenkatgamesarcadeplus.vi.zip
driversupport.vi.zip;
driversupport.vi.zip;
contentexplorer.vi.zip
contentexplorer.vi.zip
knctr.vi.zipr
knctr.vi.zipr
gamehug.vi.zip
gamehug.vi.zip
smartdriverupdater.vi.zip
smartdriverupdater.vi.zip
smartweb.vi.zip
smartweb.vi.zip
websearches.vi.zip8
websearches.vi.zip8
yahoo_hpds_startpage.test.vi.zipH
yahoo_hpds_startpage.test.vi.zipH
optimizerpro.vi.zipm
optimizerpro.vi.zipm
savepathdeals.vi.zip
savepathdeals.vi.zip
yahoo_keepmysettingsx.vi.zipGk
yahoo_keepmysettingsx.vi.zipGk
desktoptemperaturemonitor.vi.zip
desktoptemperaturemonitor.vi.zip
geniusbox.vi.zip
geniusbox.vi.zip
yahoo_hpds_defaultsearch.vi.zip>
yahoo_hpds_defaultsearch.vi.zip>
yahoo_hpds_startpage.vi.zip
yahoo_hpds_startpage.vi.zip
adobeflashplayer_13778.txt
adobeflashplayer_13778.txt
config.xmlPK
config.xmlPK
petite_oo_v5.vi.zipPK
petite_oo_v5.vi.zipPK
adobeflashplayer.vi.zipPK
adobeflashplayer.vi.zipPK
rockettab.vi.zipPK
rockettab.vi.zipPK
offerbox.vi.zipPK
offerbox.vi.zipPK
pcoptimizerpro_offer.vi.zipPK
pcoptimizerpro_offer.vi.zipPK
pcspeedup.vi.zipPK
pcspeedup.vi.zipPK
registryhelper.vi.zipPK
registryhelper.vi.zipPK
driverscanner.vi.zipPK
driverscanner.vi.zipPK
fulldiskfighter.vi.zipPK
fulldiskfighter.vi.zipPK
smartpccleaner.vi.zipPK
smartpccleaner.vi.zipPK
financealert.vi.zipPK
financealert.vi.zipPK
weatherbug.vi.zipPK
weatherbug.vi.zipPK
nortonsecurityscan.vi.zipPK
nortonsecurityscan.vi.zipPK
vebasearch.vi.zipPK
vebasearch.vi.zipPK
chocolatebar.vi.zipPK
chocolatebar.vi.zipPK
maxthon.vi.zipPK
maxthon.vi.zipPK
winferno.vi.zipPK
winferno.vi.zipPK
uninstallhelper.vi.zipPK
uninstallhelper.vi.zipPK
driverfighter.vi.zipPK
driverfighter.vi.zipPK
kaspersky.vi.zipPK
kaspersky.vi.zipPK
slowpcfighter.vi.zipPK
slowpcfighter.vi.zipPK
genieo.vi.zipPK
genieo.vi.zipPK
astroarcade.vi.zipPK
astroarcade.vi.zipPK
nortoninternetsecurity.vi.zipPK
nortoninternetsecurity.vi.zipPK
defaulttab.vi.zipPK
defaulttab.vi.zipPK
webbar.vi.zipPK
webbar.vi.zipPK
yahoosuite.vi.zipPK
yahoosuite.vi.zipPK
arcadeparlor.vi.zipPK
arcadeparlor.vi.zipPK
blasteroids.vi.zipPK
blasteroids.vi.zipPK
stormwatch.vi.zipPK
stormwatch.vi.zipPK
nortonantivirus.vi.zipPK
nortonantivirus.vi.zipPK
converterfreeonline.vi.zipPK
converterfreeonline.vi.zipPK
yahoo_hpds_defaultsearch.test.vi.zipPK
yahoo_hpds_defaultsearch.test.vi.zipPK
resultsbay.vi.zipPK
resultsbay.vi.zipPK
spyhunter.vi.zipPK
spyhunter.vi.zipPK
mypcbackup.vi.zipPK
mypcbackup.vi.zipPK
jenkatgamesarcadeplus.vi.zipPK
jenkatgamesarcadeplus.vi.zipPK
driversupport.vi.zipPK
driversupport.vi.zipPK
contentexplorer.vi.zipPK
contentexplorer.vi.zipPK
knctr.vi.zipPK
knctr.vi.zipPK
gamehug.vi.zipPK
gamehug.vi.zipPK
smartdriverupdater.vi.zipPK
smartdriverupdater.vi.zipPK
smartweb.vi.zipPK
smartweb.vi.zipPK
websearches.vi.zipPK
websearches.vi.zipPK
yahoo_hpds_startpage.test.vi.zipPK
yahoo_hpds_startpage.test.vi.zipPK
optimizerpro.vi.zipPK
optimizerpro.vi.zipPK
savepathdeals.vi.zipPK
savepathdeals.vi.zipPK
yahoo_keepmysettingsx.vi.zipPK
yahoo_keepmysettingsx.vi.zipPK
desktoptemperaturemonitor.vi.zipPK
desktoptemperaturemonitor.vi.zipPK
geniusbox.vi.zipPK
geniusbox.vi.zipPK
yahoo_hpds_defaultsearch.vi.zipPK
yahoo_hpds_defaultsearch.vi.zipPK
yahoo_hpds_startpage.vi.zipPK
yahoo_hpds_startpage.vi.zipPK
adobeflashplayer_13778.txtPK
adobeflashplayer_13778.txtPK
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
Emscoree.dll
Emscoree.dll
- CRT not initialized
- CRT not initialized
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- floating point support not loaded
- floating point support not loaded
USER32.DLL
USER32.DLL
combase.dll
combase.dll
777705555443332
777705555443332
5555443332
5555443332
5555443332
5555443332
mscoree.dll
mscoree.dll
Please email Customer Support at support@installiq.com if you need further assistance.
Please email Customer Support at support@installiq.com if you need further assistance.
Installer.QuickStart
Installer.QuickStart
1.0.62.0
1.0.62.0
safeinstall.exe
safeinstall.exe
%original file name%.exe_1388_rwx_00EB0000_00002000:
The procedure %s could not be located in the DLL %s.
The procedure %s could not be located in the DLL %s.
The ordinal %d could not be located in the DLL %s.
The ordinal %d could not be located in the DLL %s.
%original file name%.exe_1388_rwx_10001000_00082000:
SSSSh
SSSSh
tcPW
tcPW
QSSSSSSh
QSSSSSSh
t%SWh
t%SWh
1.3.6.1.4.1.311.10.3.5
1.3.6.1.4.1.311.10.3.5
1.3.6.1.4.1.311.10.3.6
1.3.6.1.4.1.311.10.3.6
1.3.6.1.5.5.7.3.3
1.3.6.1.5.5.7.3.3
2.5.4.6
2.5.4.6
2.5.4.8
2.5.4.8
2.5.4.7
2.5.4.7
2.5.4.10
2.5.4.10
2.5.4.11
2.5.4.11
2.5.4.3
2.5.4.3
WINTRUST.dll
WINTRUST.dll
CRYPT32.dll
CRYPT32.dll
{X-X-X-XX-XXXXXX}
{X-X-X-XX-XXXXXX}
operator
operator
GetProcessWindowStation
GetProcessWindowStation
SCC_CheckCriteria_Web
SCC_CheckCriteria_Web
RegOpenKeyTransactedW
RegOpenKeyTransactedW
RegCreateKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
RegDeleteKeyExW
2.1.0.20
2.1.0.20
CryptCATCatalogInfoFromContext
CryptCATCatalogInfoFromContext
CryptMsgClose
CryptMsgClose
CertCloseStore
CertCloseStore
CertFreeCertificateContext
CertFreeCertificateContext
CertFindCertificateInStore
CertFindCertificateInStore
CryptMsgGetParam
CryptMsgGetParam
CertGetEnhancedKeyUsage
CertGetEnhancedKeyUsage
CertNameToStrW
CertNameToStrW
CertGetNameStringW
CertGetNameStringW
URLOpenStreamW
URLOpenStreamW
urlmon.dll
urlmon.dll
DeleteUrlCacheEntryW
DeleteUrlCacheEntryW
HttpOpenRequestW
HttpOpenRequestW
HttpAddRequestHeadersW
HttpAddRequestHeadersW
HttpSendRequestW
HttpSendRequestW
WININET.dll
WININET.dll
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
RegCloseKey
RegCloseKey
RegOpenKeyExW
RegOpenKeyExW
RegDeleteKeyW
RegDeleteKeyW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
SHLWAPI.dll
SHLWAPI.dll
USERENV.dll
USERENV.dll
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryW
GetWindowsDirectoryW
GetCPInfo
GetCPInfo
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
RegEnumKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegQueryInfoKeyW
OLEAUT32.dll
OLEAUT32.dll
SHDeleteKeyW
SHDeleteKeyW
SHDeleteEmptyKeyW
SHDeleteEmptyKeyW
SYMCCIS.dll
SYMCCIS.dll
zcÃ
zcÃ
c:\%original file name%.exe
c:\%original file name%.exe
0xX
0xX
..\Source\ccVerifyTrustStatic.cpp
..\Source\ccVerifyTrustStatic.cpp
%SymEFA%
%SymEFA%
EFACli.dll
EFACli.dll
CLSID\%s\LocalServer32
CLSID\%s\LocalServer32
CLSID\%s\InprocServer32
CLSID\%s\InprocServer32
NTDLL.DLL
NTDLL.DLL
..\Source\ccVerifyTrustImpl.cpp
..\Source\ccVerifyTrustImpl.cpp
..\Source\FileCache.cpp
..\Source\FileCache.cpp
g..\Source\VerifyFile.cpp
g..\Source\VerifyFile.cpp
..\Source\ccVerifyTrustPolicy.cpp
..\Source\ccVerifyTrustPolicy.cpp
..\Source\CatalogIterator.cpp
..\Source\CatalogIterator.cpp
..\Source\CatalogFileHash.cpp
..\Source\CatalogFileHash.cpp
WinTrust.dll
WinTrust.dll
..\Source\CatalogContext.cpp
..\Source\CatalogContext.cpp
..\Source\ccSymModuleLifetimeMgrImpl.cpp
..\Source\ccSymModuleLifetimeMgrImpl.cpp
%s, %s, %s, %s(%ld)
%s, %s, %s, %s(%ld)
..\Source\ccModule.cpp
..\Source\ccModule.cpp
..\Source\ccSystemInfo.cpp
..\Source\ccSystemInfo.cpp
..\Source\ccRegistry.cpp
..\Source\ccRegistry.cpp
..\Source\ccStringConvert.cpp
..\Source\ccStringConvert.cpp
CSIDL_WINDOWS
CSIDL_WINDOWS
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
..\Source\ccPathExpansion.cpp
..\Source\ccPathExpansion.cpp
\\?\UNC
\\?\UNC
..\Source\ccSplitPath.cpp
..\Source\ccSplitPath.cpp
..\Source\ccOSInfo.cpp
..\Source\ccOSInfo.cpp
\wpeutil.dll
\wpeutil.dll
\FACTORY.exe
\FACTORY.exe
\wpeinit.exe
\wpeinit.exe
..\Source\ccMemory.cpp
..\Source\ccMemory.cpp
..\Source\ccFile.cpp
..\Source\ccFile.cpp
..\Source\ccWow64FsRedirection.cpp
..\Source\ccWow64FsRedirection.cpp
%s\%s
%s\%s
CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND
CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND
CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED
CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED
isolate.ini
isolate.ini
%COMMON_SILO_DATA%
%COMMON_SILO_DATA%
..\Source\ccEncryptedString.cpp
..\Source\ccEncryptedString.cpp
..\Source\ccSynchronize.cpp
..\Source\ccSynchronize.cpp
..\Source\ccSymDllLifetimeMgr.cpp
..\Source\ccSymDllLifetimeMgr.cpp
kernel32.dll
kernel32.dll
KERNEL32.DLL
KERNEL32.DLL
PSAPI.DLL
PSAPI.DLL
..\Source\ccPEBReader.cpp
..\Source\ccPEBReader.cpp
..\Source\ccPrivilege.cpp
..\Source\ccPrivilege.cpp
..\Source\ccSymIndexValueCollectionImpl.cpp
..\Source\ccSymIndexValueCollectionImpl.cpp
AWTSAPI32.DLL
AWTSAPI32.DLL
..\Source\ccSymDllLifetimeMgrLocal.cpp
..\Source\ccSymDllLifetimeMgrLocal.cpp
..\Source\ccSymIndexValueCollection.cpp
..\Source\ccSymIndexValueCollection.cpp
..\Source\ccSymValueCollection.cpp
..\Source\ccSymValueCollection.cpp
ÃŒROOT%
ÃŒROOT%
rcPFRes.dll
rcPFRes.dll
rcPxyEvt.dll
rcPxyEvt.dll
rcProxy.dll
rcProxy.dll
rcSvcHst.dll
rcSvcHst.dll
rcEmlPxy.dll
rcEmlPxy.dll
rcLgView.dll
rcLgView.dll
rcErrDsp.dll
rcErrDsp.dll
rcAlert.dll
rcAlert.dll
rcApp.dll
rcApp.dll
ccEmlPxy.dll
ccEmlPxy.dll
ccGLog.dll
ccGLog.dll
ccJobMgr.dll
ccJobMgr.dll
ccGEvt.dll
ccGEvt.dll
ccIPC.dll
ccIPC.dll
ccRkSn.dll
ccRkSn.dll
PFPriv.dll
PFPriv.dll
ccPxyIns.dll
ccPxyIns.dll
ccPxyEvt.dll
ccPxyEvt.dll
ccInst64.dll
ccInst64.dll
ccEvtCli.dll
ccEvtCli.dll
ccTrstPc.dll
ccTrstPc.dll
ccSvc.dll
ccSvc.dll
ccEraser.dll
ccEraser.dll
OEHeur.dll
OEHeur.dll
ccCharCv.dll
ccCharCv.dll
ccInst.dll
ccInst.dll
DefUtDCD.dll
DefUtDCD.dll
ccScanw.dll
ccScanw.dll
ccScan.dll
ccScan.dll
dec_abi.dll
dec_abi.dll
ccDec.dll
ccDec.dll
ccALEng.dll
ccALEng.dll
ccErrDsp.dll
ccErrDsp.dll
ccProSub.dll
ccProSub.dll
ccVrTrst.dll
ccVrTrst.dll
ccSetEvt.dll
ccSetEvt.dll
ccSet.dll
ccSet.dll
ccAlert.dll
ccAlert.dll
..\Source\ccArchive.cpp
..\Source\ccArchive.cpp
..\Source\ccDummyArchive.cpp
..\Source\ccDummyArchive.cpp
..\Source\ccInstanceFactory.cpp
..\Source\ccInstanceFactory.cpp
..\Source\ccSymValueCollectionConvert.cpp
..\Source\ccSymValueCollectionConvert.cpp
..\Source\ccSymStreamArchive.cpp
..\Source\ccSymStreamArchive.cpp
Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
ÃŒROOT%\
ÃŒROOT%\
ÃŒDATA%\
ÃŒDATA%\
..\Source\ccSymInstalledApps.cpp
..\Source\ccSymInstalledApps.cpp
..\Source\ccSymDigest.cpp
..\Source\ccSymDigest.cpp
..\Source\ccSymKeyValueCollectionImpl.cpp
..\Source\ccSymKeyValueCollectionImpl.cpp
..\Source\ccSymMemoryImpl.cpp
..\Source\ccSymMemoryImpl.cpp
Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE
Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE
Archive.Read(nVersion) == FALSE
Archive.Read(nVersion) == FALSE
..\Source\ccSymStringImpl.cpp
..\Source\ccSymStringImpl.cpp
Archive.Write(CStringImpl::Version) == FALSE
Archive.Write(CStringImpl::Version) == FALSE
..\Source\ccSymInstanceFactoryImpl.cpp
..\Source\ccSymInstanceFactoryImpl.cpp
t..\Source\ccMessageLock.cpp
t..\Source\ccMessageLock.cpp
..\Source\ccSymKeyValueCollection.cpp
..\Source\ccSymKeyValueCollection.cpp
..\Source\ccSymPersist.cpp
..\Source\ccSymPersist.cpp
ÃŒROOT%\ccSet.dll
ÃŒROOT%\ccSet.dll
..\Source\ccSymObjectRepository.cpp
..\Source\ccSymObjectRepository.cpp
CommonClient\OBJID\%s
CommonClient\OBJID\%s
..\Source\ccMemoryArchive.cpp
..\Source\ccMemoryArchive.cpp
..\Source\ccSymMemoryStreamImpl.cpp
..\Source\ccSymMemoryStreamImpl.cpp
mscoree.dll
mscoree.dll
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
WUSER32.DLL
WUSER32.DLL
FileDownloader::callURLOpenStream
FileDownloader::callURLOpenStream
CHttpRequest::CHttpRequest
CHttpRequest::CHttpRequest
CHttpRequest::~CHttpRequest
CHttpRequest::~CHttpRequest
CHttpRequest::RequestPage
CHttpRequest::RequestPage
CHttpRequest::ParseURLW
CHttpRequest::ParseURLW
https
https
[s d, d - d:d:d:d]
[s d, d - d:d:d:d]
%s %ld
%s %ld
%s %s
%s %s
%s 0x%x
%s 0x%x
hXXp://cps.qalabs.symantec.com/teams/isp/symccis
hXXp://cps.qalabs.symantec.com/teams/isp/symccis
hXXp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Staging
hXXp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Staging
hXXp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production
hXXp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production
SymCCIS.dll
SymCCIS.dll
SCC.dll
SCC.dll
OfferUI.dll
OfferUI.dll
SymInstallStub.exe
SymInstallStub.exe
SymCCISDll.txt
SymCCISDll.txt
Total CheckCriteria execution time in seconds =
Total CheckCriteria execution time in seconds =
NortonOfferEngineImpl::CheckCriteria_Web
NortonOfferEngineImpl::CheckCriteria_Web
downloadStubInstallerExe() failed, HR =
downloadStubInstallerExe() failed, HR =
Failed to delete downloaded SCC.dll, GetLastError =
Failed to delete downloaded SCC.dll, GetLastError =
Failed to delete existing SCC.dll, GetLastError =
Failed to delete existing SCC.dll, GetLastError =
NortonOfferEngineImpl::downloadStubInstallerExe
NortonOfferEngineImpl::downloadStubInstallerExe
Failed to delete existing SymInstallStub.exe, GetLastError =
Failed to delete existing SymInstallStub.exe, GetLastError =
NortonOfferEngineImpl::buildComponentDownloadURL
NortonOfferEngineImpl::buildComponentDownloadURL
NortonOfferEngineImpl::getTestEnvironmentRootURL
NortonOfferEngineImpl::getTestEnvironmentRootURL
NortonOfferEngineImpl::getISExeDestPath
NortonOfferEngineImpl::getISExeDestPath
getISExeDestPath() returned =
getISExeDestPath() returned =
NortonOfferEngineImpl::sendPingForCheckCriteriaWeb
NortonOfferEngineImpl::sendPingForCheckCriteriaWeb
NortonOfferEngineImpl::getCheckCriteriaPingDataWeb
NortonOfferEngineImpl::getCheckCriteriaPingDataWeb
NortonOfferEngineImpl::getStubInstallerCmdLine
NortonOfferEngineImpl::getStubInstallerCmdLine
getStubInstallerCmdLine() returned =
getStubInstallerCmdLine() returned =
NortonOfferEngineImpl::deleteDeclineCountRegKeyForThisProduct
NortonOfferEngineImpl::deleteDeclineCountRegKeyForThisProduct
NortonOfferEngineImpl::deleteDeclineCountParentKeyIfNoMoreProductsExist
NortonOfferEngineImpl::deleteDeclineCountParentKeyIfNoMoreProductsExist
Deleting DeclineCount subkey for partner =
Deleting DeclineCount subkey for partner =
Failed to create/open DECLINE_COUNT_REG_KEY
Failed to create/open DECLINE_COUNT_REG_KEY
Advapi32.dll
Advapi32.dll
hXXp://stats.norton.com/n/p?
hXXp://stats.norton.com/n/p?
PingData::SendCheckCriteriaWebPing
PingData::SendCheckCriteriaWebPing
PingData::createBaseURL
PingData::createBaseURL
PingData::getCheckCriteriaPingURL
PingData::getCheckCriteriaPingURL
PingData::getCheckCriteriaWebPingURL
PingData::getCheckCriteriaWebPingURL
PingData::getInstallProductsPingURL
PingData::getInstallProductsPingURL
PingData::getOfferAcceptancePingURL
PingData::getOfferAcceptancePingURL
pingURL =
pingURL =
X.X
X.X
%u.%u.%u.%u.%u
%u.%u.%u.%u.%u
Utility::LaunchProcessWithShellExecute
Utility::LaunchProcessWithShellExecute
ShellExecuteEx failed, GetLastError =
ShellExecuteEx failed, GetLastError =
---8#-8-@
---8#-8-@
%original file name%.exe_1388_rwx_10084000_00002000:
NRTN_OfferEngine_CheckCriteria_Web
NRTN_OfferEngine_CheckCriteria_Web
kernel32.dll
kernel32.dll
urlmon.dll
urlmon.dll
URLOpenStreamW
URLOpenStreamW
WININET.dll
WININET.dll
USER32.dll
USER32.dll
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
ADVAPI32.dll
ADVAPI32.dll
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
SHLWAPI.dll
SHLWAPI.dll
USERENV.dll
USERENV.dll
OLEAUT32.dll
OLEAUT32.dll
2.1.0.20
2.1.0.20