Trojan.Win32.Patched.oy (Kaspersky), Trojan.Generic.8884557 (B) (Emsisoft), Trojan.Generic.8884557 (AdAware), Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericInjector.YR, GenericDownloader.YR (Lavasoft MAS)Behaviour: Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 026387233b94b92200dc63fd4f7ceb1f
SHA1: 4c41516046b67e5be5ff469d806e4bf8ce4a1b87
SHA256: fc17a1455facfafa55fbc81a88c0b2c14ed4390fbfa3f15175ffc9c60bed6758
SSDeep: 49152:Dr6ASzxURFp2YZiYaTNhYikKJqdhcFSgWRdMHe6vsTT0lRTFf/3:JSzmOYaTNhYikKJqduF1WRu3RTN
Size: 3379712 bytes
File type: EXE
Platform: WIN32
Entropy: Not Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2007-11-21 02:59:32
Analyzed on: WindowsXPESX SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:680
server.exe:1472
The Trojan injects its code into the following process(es):
%original file name%.exe:2772
server.exe:3420
explorer.exe:3164
Explorer.EXE:1948
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:680 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%System%\install\server.exe (23404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\adm2.txt (1675 bytes)
The Trojan deletes the following file(s):
C:\default.html (0 bytes)
Registry activity
The process %original file name%.exe:2772 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A1 9C F8 96 9C 25 64 6B 99 CD 53 A4 AB B3 1A EC"
The process %original file name%.exe:680 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F8 93 93 43 78 D7 BD B9 11 8E 4E C8 FB BC D9 13"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f3-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{773a730e-74fb-11e2-b597-000c293bdf2f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f2-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"Policies" = "%System%\install\server.exe"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%\install]
"server.exe" = "Adobe Flash Player 9.0 r115"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f5-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1A677I5M-2OSX-5880-GG7I-2B6BT6KNOX30}]
"StubPath" = "%System%\install\server.exe Restart"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
"Policies" = "%System%\install\server.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "%System%\install\server.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "%System%\install\server.exe"
The process server.exe:1472 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0E 4F 01 07 8D 25 99 9F 9F BC AF 8C DB F0 E9 4D"
The process server.exe:3420 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "53 18 86 7E 70 DC 39 30 E2 92 72 D2 F4 10 D0 DC"
Dropped PE files
There are no dropped PE files.
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:680
server.exe:1472 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%System%\install\server.exe (23404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\adm2.txt (1675 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"HKCU" = "%System%\install\server.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HKLM" = "%System%\install\server.exe" - Reboot the computer.
Static Analysis
VersionInfo
Company Name: Adobe Systems, Inc.
Product Name: Shockwave Flash
Product Version: 9,0,115,0
Legal Copyright:
Legal Trademarks: Adobe Flash Player
Original Filename: SAFlashPlayer.exe
Internal Name: Adobe Flash Player 9.0
File Version: 9,0,115,0
File Description: Adobe Flash Player 9.0 r115
Comments:
Language: French (France)
Company Name: Adobe Systems, Inc.Product Name: Shockwave FlashProduct Version: 9,0,115,0Legal Copyright: Legal Trademarks: Adobe Flash PlayerOriginal Filename: SAFlashPlayer.exeInternal Name: Adobe Flash Player 9.0File Version: 9,0,115,0File Description: Adobe Flash Player 9.0 r115Comments: Language: French (France)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 2592768 | 2590208 | 4.83412 | 0b7803c9a16451f226d8444c16bfe1fd |
.rdata | 2596864 | 266240 | 265216 | 4.14288 | 5d55278c4f59c68dc7964796f42c847c |
.data | 2863104 | 1073152 | 200704 | 4.55053 | 9ec3438de6890fbb599edc00f44d5549 |
.rodata | 3936256 | 4096 | 512 | 1.05455 | 9fb5b9a0ad543e27640acd389e508b3e |
.rsrc | 3940352 | 322112 | 322560 | 4.54951 | 8916a8c0eb86fc9885ba6e49784a7ed7 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_2772:
.text
.text
.rdata
.rdata
@.data
@.data
.rodata
.rodata
.rsrc
.rsrc
JWx%f
JWx%f
uâ„¢u!
uâ„¢u!
9H%u$
9H%u$
9y%u/
9y%u/
D$4PSSh
D$4PSSh
L$4QSSh
L$4QSSh
>%u
>%u
~%UVW
~%UVW
D$Dt%SR
D$Dt%SR
SSSht
SSSht
SSSSht
SSSSht
t5SSSh
t5SSSh
tASSSh
tASSSh
SSShS
SSShS
SSSSShd
SSSSShd
SSSSSh
SSSSSh
SSSh&
SSSh&
SSShO
SSShO
SSSh'
SSSh'
SSSh1
SSSh1
SSShn
SSShn
SSShT
SSShT
!!!!!!""#$%&'(((((())* ,-.DDDDDDDD//01234555676789:;<:>?@ABC
!!!!!!""#$%&'(((((())* ,-.DDDDDDDD//01234555676789:;<:>?@ABC
88888888
88888888
8888888888
8888888888
88888888888888
88888888888888
8888888888888
8888888888888
UDPQ
UDPQ
!"#$%&'()* ,
!"#$%&'()* ,
-./01234456
-./01234456
.idata
.idata
P.reloc
P.reloc
P.rsrc
P.rsrc
####@####
####@####
kernel32.dll
kernel32.dll
ShellExecuteA
ShellExecuteA
shell32.dll
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
C:\default.html
C:\default.html
PSAPI.dll
PSAPI.dll
VBoxService.exe
VBoxService.exe
SbieDll.dll
SbieDll.dll
dbghelp.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
55274-640-2673064-23950
76487-644-3177037-23510
76487-644-3177037-23510
76487-337-8429955-22614
76487-337-8429955-22614
\\.\Syser
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SyserBoot
\\.\SICE
\\.\SICE
\\.\NTICE
\\.\NTICE
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
explorer.exe
explorer.exe
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
oleaut32.dll
oleaut32.dll
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCreateKeyA
RegCreateKeyA
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
FindExecutableA
FindExecutableA
?*?/?]?}?
?*?/?]?}?
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@####
####@#### ####@####
####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
y.YZJO
y.YZJO
nr.AQ
nr.AQ
E.naM
E.naM
$T.GN
$T.GN
R:\JD
R:\JD
R%fLJg
R%fLJg
>.RW$
>.RW$
Az.Sc
Az.Sc
Qw>%UPRi
Qw>%UPRi
z<.mj>
z<.mj>
2X.jtL
2X.jtL
\X%X,``
\X%X,``
%XXTTD*/
%XXTTD*/
.TdiL
.TdiL
.In:|k
.In:|k
Nd/.zk
Nd/.zk
KWindows
KWindows
flash.filters.DropShadowFilter
flash.filters.DropShadowFilter
@flash.filters.GlowFilter
@flash.filters.GlowFilter
flash.filters.BlurFilter
flash.filters.BlurFilter
flash.filters.BevelFilter
flash.filters.BevelFilter
flash.filters.ConvolutionFilter
flash.filters.ConvolutionFilter
flash.filters.DisplacementMapFilter
flash.filters.DisplacementMapFilter
flash.filters.GradientGlowFilter
flash.filters.GradientGlowFilter
flash.filters.GradientBevelFilter
flash.filters.GradientBevelFilter
flash.filters.ColorMatrixFilter
flash.filters.ColorMatrixFilter
application/x-www-form-urlencoded
application/x-www-form-urlencoded
flash.geom.Rectangle
flash.geom.Rectangle
flash.geom.Point
flash.geom.Point
flash.geom.Transform
flash.geom.Transform
portrait
portrait
flash.display.BitmapData
flash.display.BitmapData
flash.geom.Matrix
flash.geom.Matrix
flash.geom.ColorTransform
flash.geom.ColorTransform
ProductDownloadBaseUrl
ProductDownloadBaseUrl
CodeSignRootCert
CodeSignRootCert
AutoUpdateVersionUrl
AutoUpdateVersionUrl
.macromedia.com
.macromedia.com
hXXp://
hXXp://
.macromedia.com/support/flashplayer/sys/
.macromedia.com/support/flashplayer/sys/
hXXps://
hXXps://
mms.cfg
mms.cfg
hXXp://VVV.macromedia.com
hXXp://VVV.macromedia.com
hXXps://VVV.macromedia.com/support/flashplayer/sys/
hXXps://VVV.macromedia.com/support/flashplayer/sys/
FlashAuthor.cfg
FlashAuthor.cfg
=cacheSize.txt
=cacheSize.txt
%3 %3 %d %2:%2:%2 GMT%c%2%2 %d
%3 %3 %d %2:%2:%2 GMT%c%2%2 %d
0 1 2 3 4 5 6 7
0 1 2 3 4 5 6 7
!%),.?]}
!%),.?]}
for (var i=0; i
for (var i=0; i
for (var i=index; i
for (var i=index; i
return s.replace(/&/g, "&").replace(/, "/g, ">").replace(/"/g, """).replace(/'/g, "'");
return s.replace(/&/g, "&").replace(/, "/g, ">").replace(/"/g, """).replace(/'/g, "'");
return "" value.getTime() "";
return "" value.getTime() "";
Client.Header.MustUnderstand
Client.Header.MustUnderstand
Client.Data.UnderFlow
Client.Data.UnderFlow
NetConnection.Call.BadVersion
NetConnection.Call.BadVersion
_global.System
_global.System
flash.net.FileReference
flash.net.FileReference
PTF://
PTF://
https:
https:
.macromedia.com/
.macromedia.com/
%s%sdescription.xml
%s%sdescription.xml
%s%s.xml
%s%s.xml
%s%s.z
%s%s.z
%s?product=%s&signed=true&%s%s
%s?product=%s&signed=true&%s%s
%s&product=%s&signed=true&%s%s
%s&product=%s&signed=true&%s%s
hXXp://fpdownload2.macromedia.com/get/
hXXp://fpdownload2.macromedia.com/get/
hXXps://fpdownload.macromedia.com/get/
hXXps://fpdownload.macromedia.com/get/
hXXps://VVV.macromedia.com/bin/flashdownload.cgi
hXXps://VVV.macromedia.com/bin/flashdownload.cgi
-https=
-https=
9,0,115,0
9,0,115,0
VVV.macromedia.com
VVV.macromedia.com
Download.Complete
Download.Complete
Download.Cancelled
Download.Cancelled
Download.Failed
Download.Failed
unknown URL
unknown URL
>1.2.3
>1.2.3
Webdings
Webdings
Curlz MT
Curlz MT
http:
http:
[[IMPORT]]/
[[IMPORT]]/
by-ftp-filename
by-ftp-filename
/crossdomain.xml
/crossdomain.xml
to-ports
to-ports
.local
.local
SHA-256 part of OpenSSL 0.9.8d 28 Sep 2006
SHA-256 part of OpenSSL 0.9.8d 28 Sep 2006
A=%b&SA=%b&SV=%b&EV=%b&MP3=%b&AE=%b&VE=%b&ACC=%b&PR=%b&SP=%b&SB=%b&DEB=%b&V=%s%s&PT=%s&AVD=%b&LFD=%b&WD=%b&TLS=%b
A=%b&SA=%b&SV=%b&EV=%b&MP3=%b&AE=%b&VE=%b&ACC=%b&PR=%b&SP=%b&SB=%b&DEB=%b&V=%s%s&PT=%s&AVD=%b&LFD=%b&WD=%b&TLS=%b
hXXp://%s/
hXXp://%s/
.maxscroll
.maxscroll
.scroll
.scroll
NetConnection.Call.Failed
NetConnection.Call.Failed
HTTP:
HTTP:
onKeyUp
onKeyUp
onKeyDown
onKeyDown
url_stream_port
url_stream_port
url_stream_host
url_stream_host
url_stream_path
url_stream_path
NetConnection.Call.Prohibited
NetConnection.Call.Prohibited
url_request_target
url_request_target
url_request
url_request
password
password
vnd.ms.wmhtml:
vnd.ms.wmhtml:
URLNotFound
URLNotFound
hXXp://settingsmanager.adobe.com
hXXp://settingsmanager.adobe.com
hXXp://VVV.adobe.com
hXXp://VVV.adobe.com
hXXp://VVV.macromedia.com/support/flashplayer/sys/
hXXp://VVV.macromedia.com/support/flashplayer/sys/
onHTTPStatus
onHTTPStatus
iso_646.irv:1991
iso_646.irv:1991
windows-936
windows-936
tcp01140
tcp01140
webcdic-fi-278 euro
webcdic-fi-278 euro
webcdic-se-278 euro
webcdic-se-278 euro
%cp037
%cp037
%csibm037
%csibm037
Tcp852
Tcp852
iso_646.irv:1983
iso_646.irv:1983
csshiftjis
csshiftjis
jwindows-874
jwindows-874
windows-1250
windows-1250
windows-1251
windows-1251
windows-1252
windows-1252
windows-1253
windows-1253
windows-1254
windows-1254
windows-1255
windows-1255
windows-1256
windows-1256
windows-1257
windows-1257
windows-1258
windows-1258
windows-31j
windows-31j
cswindows31j
cswindows31j
imm32.dll
imm32.dll
System.IME
System.IME
,,0,0,,,
,,0,0,,,
WWW_OpenURL
WWW_OpenURL
ddeexec
ddeexec
dwmapi.dll
dwmapi.dll
d3d8.dll
d3d8.dll
ddraw.dll
ddraw.dll
RegDeleteKeyW
RegDeleteKeyW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
version.dll
version.dll
ShellExecuteExW
ShellExecuteExW
Windows 95
Windows 95
Windows 98/ME
Windows 98/ME
Windows NT
Windows NT
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows Vista
Windows Vista
Windows
Windows
Adobe Windows
Adobe Windows
Macromedia Windows
Macromedia Windows
&M=%s&R=%dx%d&DP=%d&COL=%s&AR=%s&OS=%s&L=%s&IME=%b
&M=%s&R=%dx%d&DP=%d&COL=%s&AR=%s&OS=%s&L=%s&IME=%b
*.exe
*.exe
*.swf
*.swf
W@\\?\
W@\\?\
).mdmp
).mdmp
SAFlashPlayer.exe
SAFlashPlayer.exe
player_crash_log_(*).mdmp
player_crash_log_(*).mdmp
z>https
z>https
onHTTPError
onHTTPError
&Macromedia Flash Certificate Authority1
&Macromedia Flash Certificate Authority1
secure@macromedia.com1
secure@macromedia.com1
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
update.bat
update.bat
VerifyMessage : Second CertVerifySubjectCertificateContext() failed.
VerifyMessage : Second CertVerifySubjectCertificateContext() failed.
VerifyMessage : CertVerifySubjectCertificateContext() failed.
VerifyMessage : CertVerifySubjectCertificateContext() failed.
VerifyMessage : Certificate chain is too long.
VerifyMessage : Certificate chain is too long.
VerifyMessage : CertCreateCertificateContext() failed.
VerifyMessage : CertCreateCertificateContext() failed.
VerifyMessage : CryptGetMessageCertificates() failed.
VerifyMessage : CryptGetMessageCertificates() failed.
VerifyMessage : Unable to read external root certificate specified in MMS.CFG by CodeSignRootCert.
VerifyMessage : Unable to read external root certificate specified in MMS.CFG by CodeSignRootCert.
\\?\UNC\
\\?\UNC\
HTTP/1.0
HTTP/1.0
%d.%d.%d.%d
%d.%d.%d.%d
trapallkeys
trapallkeys
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpDetectAutoProxyConfigUrl
WinHttpDetectAutoProxyConfigUrl
WinHttpGetDefaultProxyConfiguration
WinHttpGetDefaultProxyConfiguration
WinHttpCloseHandle
WinHttpCloseHandle
WinHttpOpen
WinHttpOpen
winhttp.dll
winhttp.dll
URLDownloadToFileA
URLDownloadToFileA
urlmon.dll
urlmon.dll
jsproxy.dll
jsproxy.dll
DetectAutoProxyUrl
DetectAutoProxyUrl
wininet.dll
wininet.dll
http=
http=
https=
https=
Secur32.dll
Secur32.dll
Security.dll
Security.dll
CertCloseStore
CertCloseStore
CertOpenSystemStoreW
CertOpenSystemStoreW
CertFreeCertificateContext
CertFreeCertificateContext
CertFreeCertificateChain
CertFreeCertificateChain
CertVerifyCertificateChainPolicy
CertVerifyCertificateChainPolicy
CertGetCertificateChain
CertGetCertificateChain
crypt32.dll
crypt32.dll
.jpeg
.jpeg
FtpOpenFileA
FtpOpenFileA
HttpQueryInfoA
HttpQueryInfoA
HttpSendRequestA
HttpSendRequestA
HttpOpenRequestA
HttpOpenRequestA
User32.dll
User32.dll
FlashPlayer.ProtectedMediaForFlashPlayer
FlashPlayer.ProtectedMediaForFlashPlayer
FlashPlayer.ProtectedMediaForFlashPlayer\DefaultIcon
FlashPlayer.ProtectedMediaForFlashPlayer\DefaultIcon
FlashPlayer.ProtectedMediaForFlashPlayer\shell\open\command
FlashPlayer.ProtectedMediaForFlashPlayer\shell\open\command
FlashPlayer.AudioForFlashPlayer
FlashPlayer.AudioForFlashPlayer
FlashPlayer.AudioForFlashPlayer\DefaultIcon
FlashPlayer.AudioForFlashPlayer\DefaultIcon
FlashPlayer.AudioForFlashPlayer\shell\open\command
FlashPlayer.AudioForFlashPlayer\shell\open\command
FlashPlayer.VideoForFlashPlayer
FlashPlayer.VideoForFlashPlayer
FlashPlayer.VideoForFlashPlayer\DefaultIcon
FlashPlayer.VideoForFlashPlayer\DefaultIcon
FlashPlayer.VideoForFlashPlayer\shell\open\command
FlashPlayer.VideoForFlashPlayer\shell\open\command
FlashPlayer.FlashVideo
FlashPlayer.FlashVideo
FlashPlayer.FlashVideo\DefaultIcon
FlashPlayer.FlashVideo\DefaultIcon
FlashPlayer.FlashVideo\shell\open\command
FlashPlayer.FlashVideo\shell\open\command
ShockwaveFlash.ShockwaveFlash
ShockwaveFlash.ShockwaveFlash
ShockwaveFlash.ShockwaveFlash\DefaultIcon
ShockwaveFlash.ShockwaveFlash\DefaultIcon
ShockwaveFlash.ShockwaveFlash\shell\open\command
ShockwaveFlash.ShockwaveFlash\shell\open\command
keyFrameInterval
keyFrameInterval
tag=%s;timestamp=%d;zone=%d;uri=%s
tag=%s;timestamp=%d;zone=%d;uri=%s
NetConnection.Connect.CertificateAPIError
NetConnection.Connect.CertificateAPIError
NetConnection.Connect.CertificateInvalid
NetConnection.Connect.CertificateInvalid
NetConnection.Connect.CertificateRevoked
NetConnection.Connect.CertificateRevoked
NetConnection.Connect.CertificateUntrustedSigner
NetConnection.Connect.CertificateUntrustedSigner
NetConnection.Connect.CertificatePrincipalMismatch
NetConnection.Connect.CertificatePrincipalMismatch
NetConnection.Connect.CertificateExpired
NetConnection.Connect.CertificateExpired
NetConnection.Connect.SSLHandshakeFailed
NetConnection.Connect.SSLHandshakeFailed
NetConnection.Connect.SSLNotAvailable
NetConnection.Connect.SSLNotAvailable
NetConnection.Connect.ProxyAuthFailed
NetConnection.Connect.ProxyAuthFailed
CONNECT %s:%d HTTP/1.1
CONNECT %s:%d HTTP/1.1
127.0.0.1
127.0.0.1
fpadPort
fpadPort
.Unmuted
.Unmuted
.Muted
.Muted
Camera.Unmuted
Camera.Unmuted
Camera.Muted
Camera.Muted
Microphone.Unmuted
Microphone.Unmuted
Microphone.Muted
Microphone.Muted
/bin/flashhelp.cgi
/bin/flashhelp.cgi
~&\;:"',? #
~&\;:"',? #
macromedia.com
macromedia.com
/support/flashplayer/sys/
/support/flashplayer/sys/
SharedObject.Failed
SharedObject.Failed
SharedObject.Flush.Failed
SharedObject.Flush.Failed
SharedObject.Flush.Success
SharedObject.Flush.Success
hXXp://%s
hXXp://%s
hXXp://a.
hXXp://a.
SharedObject.BadPersistence
SharedObject.BadPersistence
SharedObject.UriMismatch
SharedObject.UriMismatch
NetConnection.Connect.Failed
NetConnection.Connect.Failed
NetConnection.Connect.Success
NetConnection.Connect.Success
NetConnection.Connect.Closed
NetConnection.Connect.Closed
port
port
pageUrl
pageUrl
tcUrl
tcUrl
swfUrl
swfUrl
HTTPS
HTTPS
@NetStream.Buffer.Flush
@NetStream.Buffer.Flush
NetStream.Buffer.Full
NetStream.Buffer.Full
NetStream.Buffer.Empty
NetStream.Buffer.Empty
NetStream.Play.Stop
NetStream.Play.Stop
NetStream.Play.Start
NetStream.Play.Start
NetStream.Unpause.Notify
NetStream.Unpause.Notify
NetStream.Pause.Notify
NetStream.Pause.Notify
b?NetStream.Play.NoSupportedTrackFound
b?NetStream.Play.NoSupportedTrackFound
NetStream.Play.FileStructureInvalid
NetStream.Play.FileStructureInvalid
NetStream.Seek.Notify
NetStream.Seek.Notify
NetStream.Seek.InvalidTime
NetStream.Seek.InvalidTime
NetStream.Play.StreamNotFound
NetStream.Play.StreamNotFound
NetStream.Publish.BadName
NetStream.Publish.BadName
NetStream.Play.Failed
NetStream.Play.Failed
HttpEndRequestA
HttpEndRequestA
HttpSendRequestExA
HttpSendRequestExA
HttpAddRequestHeadersA
HttpAddRequestHeadersA
FileReference.upload
FileReference.upload
FileReference.download
FileReference.download
FileReference.browse
FileReference.browse
FileReferenceList.browse
FileReferenceList.browse
trapAllKeys
trapAllKeys
BitmapData.draw
BitmapData.draw
Operation
Operation
operationStr
operationStr
Loader.content
Loader.content
LoaderContext.checkPolicyFile
LoaderContext.checkPolicyFile
LoaderContext.securityDomain
LoaderContext.securityDomain
Loader.load
Loader.load
LoaderInfo.loader
LoaderInfo.loader
LoaderInfo.content
LoaderInfo.content
LocalConnection.send
LocalConnection.send
LocalConnection.connect
LocalConnection.connect
NetConnection.connect
NetConnection.connect
NetStream.play
NetStream.play
keyDown
keyDown
keyFocusChange
keyFocusChange
keyUp
keyUp
httpStatus
httpStatus
navigateToURL
navigateToURL
sendToURL
sendToURL
hXXp://VVV.adobe.com/2006/actionscript/flash/proxy
hXXp://VVV.adobe.com/2006/actionscript/flash/proxy
SharedObject.getLocal
SharedObject.getLocal
SharedObject.getRemote
SharedObject.getRemote
.connect
.connect
Sound.load
Sound.load
Sound.id3
Sound.id3
@SoundMixer.computeSpectrum
@SoundMixer.computeSpectrum
Stage.removeChildAt
Stage.removeChildAt
Stage.swapChildrenAt
Stage.swapChildrenAt
flash.text
flash.text
URLStream.load
URLStream.load
OleAut32.dll
OleAut32.dll
q.CUN3C
q.CUN3C
4294967295
4294967295
@wKA%2:%2:%2 %cM
@wKA%2:%2:%2 %cM
%2:%2:%2 GMT%c%2%2
%2:%2:%2 GMT%c%2%2
%3 %3 %d %d
%3 %3 %d %d
%3 %3 %d %2:%2:%2 %d UTC
%3 %3 %d %2:%2:%2 %d UTC
%3 %3 %d %d %2:%2:%2 %cM
%3 %3 %d %d %2:%2:%2 %cM
-2147483648
-2147483648
hXXp://VVV.w3.org/XML/1998/namespace
hXXp://VVV.w3.org/XML/1998/namespace
builtin.as$0
builtin.as$0
hasOwnProperty!hXXp://adobe.com/AS3/2006/builtin
hasOwnProperty!hXXp://adobe.com/AS3/2006/builtin
Boolean.prototype.toString
Boolean.prototype.toString
Boolean.prototype.valueOf
Boolean.prototype.valueOf
Number.prototype.toString
Number.prototype.toString
Number.prototype.valueOf
Number.prototype.valueOf
int.prototype.toString
int.prototype.toString
int.prototype.valueOf
int.prototype.valueOf
uint.prototype.toString
uint.prototype.toString
uint.prototype.valueOf
uint.prototype.valueOf
String.prototype.toString
String.prototype.toString
String.prototype.valueOf
String.prototype.valueOf
RETURNINDEXEDARRAY
RETURNINDEXEDARRAY
join
join
_join
_join
builtin.as$0:MethodClosure
builtin.as$0:MethodClosure
Math.as$1
Math.as$1
Error.as$2
Error.as$2
RegExp.as$3
RegExp.as$3
Date.as$4
Date.as$4
XML.as$5
XML.as$5
QName.prototype.toString
QName.prototype.toString
((('&%$#"!
((('&%$#"!
*{?.cu
*{?.cu
!,"/%0&3%4&7-8.;-<.>O=P>SATBWAXB[I\J_I`JcMdNgMhNkUlVoUpVsYtZwYxZ{]|^
!,"/%0&3%4&7-8.;-<.>O=P>SATBWAXB[I\J_I`JcMdNgMhNkUlVoUpVsYtZwYxZ{]|^
$ 29:3,%
$ 29:3,%
&-4;7?
&-4;7?
#)0*$%&' 12,-./3894567:;?
#)0*$%&' 12,-./3894567:;?
!""##$$%%%&&&''''
!""##$$%%%&&&''''
#%*,!"$(' -.
#%*,!"$(' -.
mscoree.dll
mscoree.dll
- This application cannot run using the active version of the Microsoft .NET Runtime
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
Please contact the application's support team for more information.
internal state. The program cannot safely continue execution and must
internal state. The program cannot safely continue execution and must
continue execution and must now be terminated.
continue execution and must now be terminated.
GetProcessWindowStation
GetProcessWindowStation
e:\flashfarm\depot\main\player\branches\FlashPlayer\FlashPlayer9_DotReleases\platform\win32\standalone\Release\FlashPlayer.pdb
e:\flashfarm\depot\main\player\branches\FlashPlayer\FlashPlayer9_DotReleases\platform\win32\standalone\Release\FlashPlayer.pdb
WININET.dll
WININET.dll
CertVerifySubjectCertificateContext
CertVerifySubjectCertificateContext
CertFindCertificateInStore
CertFindCertificateInStore
CertCreateCertificateContext
CertCreateCertificateContext
CryptGetMessageCertificates
CryptGetMessageCertificates
CRYPT32.dll
CRYPT32.dll
VERSION.dll
VERSION.dll
WINMM.dll
WINMM.dll
OLEAUT32.dll
OLEAUT32.dll
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
MapVirtualKeyA
MapVirtualKeyA
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
comdlg32.dll
comdlg32.dll
ADVAPI32.dll
ADVAPI32.dll
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
WS2_32.dll
WS2_32.dll
GetProcessHeap
GetProcessHeap
FlashPlayer.exe
FlashPlayer.exe
pcre_exec
pcre_exec
t.ZgN2_:
t.ZgN2_:
~.Oo 0
~.Oo 0
flash.utils
flash.utils
flash.debugger
flash.debugger
adobe.utils
adobe.utils
MMExecute
MMExecute
flash.profiler
flash.profiler
flash.net
flash.net
URLRequest
URLRequest
sendToURL"flash.errors:IllegalOperationError
sendToURL"flash.errors:IllegalOperationError
flash.errors
flash.errors
IllegalOperationError
IllegalOperationError
flash.errors:IOError
flash.errors:IOError
flash.errors:MemoryError
flash.errors:MemoryError
flash.errors:StackOverflowError
flash.errors:StackOverflowError
flash.errors:ScriptTimeoutError
flash.errors:ScriptTimeoutError
flash.errors:InvalidSWFError
flash.errors:InvalidSWFError
flash.errors:EOFError
flash.errors:EOFError
flash_errors.as$1
flash_errors.as$1
flash.text:CSMSettings
flash.text:CSMSettings
CSMSettings.as$3
CSMSettings.as$3
CSMSettings flash.net:IDynamicPropertyOutput
CSMSettings flash.net:IDynamicPropertyOutput
IDynamicPropertyOutput flash.net:IDynamicPropertyWriter
IDynamicPropertyOutput flash.net:IDynamicPropertyWriter
flash.utils:IExternalizable
flash.utils:IExternalizable
flash.display
flash.display
IBitmapDrawable!flash.accessibility:Accessibility
IBitmapDrawable!flash.accessibility:Accessibility
flash.accessibility
flash.accessibility
Accessibility.as$12/flash.accessibility:AccessibilityImplementation
Accessibility.as$12/flash.accessibility:AccessibilityImplementation
stub!AccessibilityImplementation.as$13
stub!AccessibilityImplementation.as$13
flash.geom
flash.geom
ExcludeClass flash.accessibility:AccessibilityProperties
ExcludeClass flash.accessibility:AccessibilityProperties
AccessibilityProperties.as$14
AccessibilityProperties.as$14
flash.system:ApplicationDomain
flash.system:ApplicationDomain
flash.system
flash.system
ApplicationDomain.as$16
ApplicationDomain.as$16
flash.geom:ColorTransform
flash.geom:ColorTransform
ColorTransform.as$23
ColorTransform.as$23
concat flash.ui:ContextMenuBuiltInItems
concat flash.ui:ContextMenuBuiltInItems
flash.ui
flash.ui
ContextMenuBuiltinItems.as$26
ContextMenuBuiltinItems.as$26
adobe.utils:CustomActions
adobe.utils:CustomActions
CustomActions.as$29
CustomActions.as$29
flash.utils:Endian
flash.utils:Endian
Endian.as$32
Endian.as$32
flash.utils:IDataInput
flash.utils:IDataInput
flash.utils:IDataOutput
flash.utils:IDataOutput
writeObject'flash.filters:DisplacementMapFilterMode
writeObject'flash.filters:DisplacementMapFilterMode
flash.filters
flash.filters
DisplacementMapFilterMode.as$37
DisplacementMapFilterMode.as$37
flash.display:BlendMode
flash.display:BlendMode
BlendMode.as$39
BlendMode.as$39
flash.events:Event
flash.events:Event
flash.events
flash.events
Event.as$43
Event.as$43
flash.events:EventPhase
flash.events:EventPhase
EventPhase.as$44 flash.external:ExternalInterface
EventPhase.as$44 flash.external:ExternalInterface
ExternalInterface.as$46
ExternalInterface.as$46
flash.external
flash.external
_evalJS.__flash__addCallback(document.getElementById("
_evalJS.__flash__addCallback(document.getElementById("
document.getElementById("
document.getElementById("
").SetReturnValue(
").SetReturnValue(
; } catch (e) { 6").SetReturnValue("" e "");"").SetReturnValue("");#"" e "";
; } catch (e) { 6").SetReturnValue("" e "");"").SetReturnValue("");#"" e "";
FSCommand.as$47
FSCommand.as$47
flash.system:FSCommand
flash.system:FSCommand
flash.net:FileFilter
flash.net:FileFilter
FileFilter.as$48
FileFilter.as$48
flash.text:Font
flash.text:Font
Font.as$52
Font.as$52
flash.text:FontType
flash.text:FontType
FontType.as$53
FontType.as$53
flash.display:Graphics
flash.display:Graphics
Graphics.as$58
Graphics.as$58
flash.display:GradientType
flash.display:GradientType
GradientType.as$59
GradientType.as$59
flash.display:SpreadMethod
flash.display:SpreadMethod
SpreadMethod.as$60!flash.display:InterpolationMethod
SpreadMethod.as$60!flash.display:InterpolationMethod
InterpolationMethod.as$61
InterpolationMethod.as$61
flash.display:LineScaleMode
flash.display:LineScaleMode
LineScaleMode.as$62
LineScaleMode.as$62
flash.display:CapsStyle
flash.display:CapsStyle
CapsStyle.as$63
CapsStyle.as$63
flash.display:JointStyle
flash.display:JointStyle
JointStyle
JointStyle
JointStyle.as$64
JointStyle.as$64
flash.events:IEventDispatcher
flash.events:IEventDispatcher
flash.display:BitmapDataChannel
flash.display:BitmapDataChannel
BitmapDataChannel.as$69
BitmapDataChannel.as$69
flash.filters:BitmapFilter
flash.filters:BitmapFilter
BitmapFilter.as$70
BitmapFilter.as$70
flash.filters:BitmapFilterType
flash.filters:BitmapFilterType
BitmapFilterType.as$71!flash.filters:BitmapFilterQuality
BitmapFilterType.as$71!flash.filters:BitmapFilterQuality
BitmapFilterQuality.as$72
BitmapFilterQuality.as$72
flash.display:PixelSnapping
flash.display:PixelSnapping
PixelSnapping.as$74
PixelSnapping.as$74
flash.ui:Keyboard
flash.ui:Keyboard
Keyboard
Keyboard
Keyboard.as$77
Keyboard.as$77
flash.ui:KeyLocation
flash.ui:KeyLocation
KeyLocation
KeyLocation
KeyLocation.as$78
KeyLocation.as$78
flash.text:TextLineMetrics
flash.text:TextLineMetrics
TextLineMetrics.as$80
TextLineMetrics.as$80
flash.system:SecurityDomain
flash.system:SecurityDomain
SecurityDomain.as$83
SecurityDomain.as$83
flash.system:LoaderContext
flash.system:LoaderContext
LoaderContext.as$84
LoaderContext.as$84
flash.geom:Matrix
flash.geom:Matrix
Matrix.as$87
Matrix.as$87
flash.ui:Mouse
flash.ui:Mouse
Mouse.as$91
Mouse.as$91
flash.display:Scene
flash.display:Scene
Scene.as$94
Scene.as$94
flash.display:FrameLabel
flash.display:FrameLabel
FrameLabel.as$95
FrameLabel.as$95
flash.net:ObjectEncoding
flash.net:ObjectEncoding
ObjectEncoding.as$101
ObjectEncoding.as$101
flash.geom:Point
flash.geom:Point
Point.as$102
Point.as$102
flash.printing:PrintJobOptions
flash.printing:PrintJobOptions
PrintJobOptions.as$104
PrintJobOptions.as$104
flash.printing
flash.printing
PrintJobOptions"flash.printing:PrintJobOrientation
PrintJobOptions"flash.printing:PrintJobOrientation
PORTRAIT
PORTRAIT
PrintJobOrientation.as$105
PrintJobOrientation.as$105
flash.display:SWFVersion
flash.display:SWFVersion
SWFVersion.as$106!flash.display:ActionScriptVersion
SWFVersion.as$106!flash.display:ActionScriptVersion
ActionScriptVersion.as$107
ActionScriptVersion.as$107
flash.utils:Proxy
flash.utils:Proxy
Proxy.as$1112hXXp://VVV.adobe.com/2006/actionscript/flash/proxy
Proxy.as$1112hXXp://VVV.adobe.com/2006/actionscript/flash/proxy
flash.geom:Rectangle
flash.geom:Rectangle
Rectangle.as$112
Rectangle.as$112
flash.net:Responder
flash.net:Responder
Responder.as$113
Responder.as$113
flash.system:Security
flash.system:Security
Security.as$114
Security.as$114
flash.system:SecurityPanel
flash.system:SecurityPanel
SecurityPanel.as$115
SecurityPanel.as$115
flash.media:ID3Info
flash.media:ID3Info
flash.media
flash.media
ID3Info.as$121
ID3Info.as$121
flash.media:SoundLoaderContext
flash.media:SoundLoaderContext
SoundLoaderContext.as$122
SoundLoaderContext.as$122
flash.media:SoundTransform
flash.media:SoundTransform
SoundTransform.as$124
SoundTransform.as$124
flash.media:SoundMixer
flash.media:SoundMixer
SoundMixer.as$125
SoundMixer.as$125
flash.display:StageAlign
flash.display:StageAlign
StageAlign.as$127
StageAlign.as$127
flash.display:StageDisplayState
flash.display:StageDisplayState
StageDisplayState.as$128
StageDisplayState.as$128
flash.display:StageQuality
flash.display:StageQuality
StageQuality.as$129
StageQuality.as$129
flash.display:StageScaleMode
flash.display:StageScaleMode
StageScaleMode.as$130
StageScaleMode.as$130
flash.system:System
flash.system:System
System.as$135
System.as$135
flash.system:Capabilities
flash.system:Capabilities
Capabilities.as$136
Capabilities.as$136
flash.system:IMEConversionMode
flash.system:IMEConversionMode
IMEConversionMode.as$138
IMEConversionMode.as$138
flash.text:TextExtent
flash.text:TextExtent
TextExtent.as$139
TextExtent.as$139
flash.text:TextFieldAutoSize
flash.text:TextFieldAutoSize
TextFieldAutoSize.as$141
TextFieldAutoSize.as$141
flash.text:TextFieldType
flash.text:TextFieldType
TextFieldType.as$142
TextFieldType.as$142
flash.text:TextFormat
flash.text:TextFormat
TextFormat.as$143
TextFormat.as$143
flash.text:TextFormatDisplay
flash.text:TextFormatDisplay
TextFormatDisplay.as$144
TextFormatDisplay.as$144
flash.text:TextFormatAlign
flash.text:TextFormatAlign
TextFormatAlign.as$145
TextFormatAlign.as$145
flash.text:TextRenderer
flash.text:TextRenderer
TextRenderer.as$146
TextRenderer.as$146
flash.text:AntiAliasType
flash.text:AntiAliasType
AntiAliasType.as$147!flash.net:SharedObjectFlushStatus
AntiAliasType.as$147!flash.net:SharedObjectFlushStatus
SharedObjectFlushStatus.as$148
SharedObjectFlushStatus.as$148
flash.text:GridFitType
flash.text:GridFitType
GridFitType.as$149
GridFitType.as$149
flash.text:TextColorType
flash.text:TextColorType
TextColorType.as$150
TextColorType.as$150
flash.text:TextDisplayMode
flash.text:TextDisplayMode
TextDisplayMode.as$151
TextDisplayMode.as$151
flash.text:FontStyle
flash.text:FontStyle
FontStyle.as$152
FontStyle.as$152
flash.text:TextRun
flash.text:TextRun
TextRun.as$153
TextRun.as$153
flash.text:TextSnapshot
flash.text:TextSnapshot
TextSnapshot.as$154
TextSnapshot.as$154
flash.geom:Transform
flash.geom:Transform
Transform.as$158
Transform.as$158
flash.net:URLLoaderDataFormat
flash.net:URLLoaderDataFormat
URLLoaderDataFormat
URLLoaderDataFormat
URLLoaderDataFormat.as$160
URLLoaderDataFormat.as$160
flash.net:URLRequest
flash.net:URLRequest
URLRequest.as$161
URLRequest.as$161
flash.net:URLRequestHeader
flash.net:URLRequestHeader
URLRequestHeader.as$162
URLRequestHeader.as$162
URLRequestHeader
URLRequestHeader
flash.net:URLRequestMethod
flash.net:URLRequestMethod
URLRequestMethod
URLRequestMethod
URLRequestMethod.as$163
URLRequestMethod.as$163
flash.net:URLVariables
flash.net:URLVariables
URLVariables.as$165
URLVariables.as$165
URLVariables
URLVariables
flash.xml:XMLNode
flash.xml:XMLNode
flash.xml
flash.xml
XMLNode.as$167
XMLNode.as$167
flash.xml:XMLNodeType
flash.xml:XMLNodeType
XMLNodeType.as$168
XMLNodeType.as$168
flash.xml:XMLParser
flash.xml:XMLParser
XMLParser.as$170
XMLParser.as$170
flash.xml:XMLTag
flash.xml:XMLTag
XMLTag.as$172
XMLTag.as$172
Sampler.as$173
Sampler.as$173
flash.sampler
flash.sampler
flash.sampler:StackFrame
flash.sampler:StackFrame
flash.sampler:Sample
flash.sampler:Sample
flash.sampler:NewObjectSample
flash.sampler:NewObjectSample
NewObjectSample flash.sampler:DeleteObjectSample
NewObjectSample flash.sampler:DeleteObjectSample
adobe.utils:XMLUI
adobe.utils:XMLUI
XMLUI.as$174
XMLUI.as$174
flash.trace:Trace
flash.trace:Trace
flash.trace
flash.trace
Trace.as$175
Trace.as$175
flash.utils:Dictionary
flash.utils:Dictionary
Dictionary.as$176
Dictionary.as$176
flash.net:DynamicPropertyOutput
flash.net:DynamicPropertyOutput
DynamicPropertyOutput.as$7
DynamicPropertyOutput.as$7
flash.display:BitmapData
flash.display:BitmapData
BitmapData.as$68
BitmapData.as$68
flash.utils:ObjectInput
flash.utils:ObjectInput
ObjectInput.as$5
ObjectInput.as$5
flash.utils:ObjectOutput
flash.utils:ObjectOutput
ObjectOutput.as$4
ObjectOutput.as$4
flash.utils:ByteArray
flash.utils:ByteArray
ByteArray.as$20
ByteArray.as$20
flash.events:ActivityEvent
flash.events:ActivityEvent
ActivityEvent.as$15
ActivityEvent.as$15
flash.events:TextEvent
flash.events:TextEvent
TextEvent.as$30
TextEvent.as$30
flash.events:FocusEvent
flash.events:FocusEvent
KEY_FOCUS_CHANGE
KEY_FOCUS_CHANGE
FocusEvent.as$51
FocusEvent.as$51
m_shiftKey
m_shiftKey
m_keyCode
m_keyCode
shiftKey
shiftKey
keyCode
keyCode
flash.events:HTTPStatusEvent
flash.events:HTTPStatusEvent
HTTP_STATUS
HTTP_STATUS
HTTPStatusEvent.as$65
HTTPStatusEvent.as$65
HTTPStatusEvent
HTTPStatusEvent
flash.events:KeyboardEvent
flash.events:KeyboardEvent
KEY_DOWN
KEY_DOWN
KEY_UP
KEY_UP
KeyboardEvent.as$79
KeyboardEvent.as$79
m_keyLocation
m_keyLocation
m_ctrlKey
m_ctrlKey
m_altKey
m_altKey
KeyboardEvent
KeyboardEvent
keyLocation
keyLocation
ctrlKey
ctrlKey
altKey
altKey
flash.events:ContextMenuEvent
flash.events:ContextMenuEvent
ContextMenuEvent.as$88
ContextMenuEvent.as$88
flash.events:MouseEvent
flash.events:MouseEvent
MouseEvent.as$92
MouseEvent.as$92
flash.events:NetStatusEvent
flash.events:NetStatusEvent
NetStatusEvent.as$98
NetStatusEvent.as$98
flash.events:NetFilterEvent
flash.events:NetFilterEvent
NetFilterEvent.as$100
NetFilterEvent.as$100
flash.events:ProgressEvent
flash.events:ProgressEvent
ProgressEvent.as$110
ProgressEvent.as$110
flash.events:StatusEvent
flash.events:StatusEvent
StatusEvent.as$132
StatusEvent.as$132
flash.events:SyncEvent
flash.events:SyncEvent
SyncEvent.as$134
SyncEvent.as$134
flash.events:TimerEvent
flash.events:TimerEvent
TimerEvent.as$157
TimerEvent.as$157
flash.events:WeakMethodClosure
flash.events:WeakMethodClosure
WeakMethodClosure flash.events:WeakFunctionClosure
WeakMethodClosure flash.events:WeakFunctionClosure
flash.events:EventDispatcher
flash.events:EventDispatcher
EventDispatcher.as$45
EventDispatcher.as$45
flash.events.Event
flash.events.Event
flash.filters:BevelFilter
flash.filters:BevelFilter
BevelFilter.as$17
BevelFilter.as$17
flash.filters:BlurFilter
flash.filters:BlurFilter
BlurFilter.as$18
BlurFilter.as$18
flash.filters:ColorMatrixFilter
flash.filters:ColorMatrixFilter
ColorMatrixFilter.as$22
ColorMatrixFilter.as$22
flash.filters:ConvolutionFilter
flash.filters:ConvolutionFilter
ConvolutionFilter.as$28
ConvolutionFilter.as$28
ConvolutionFilter#flash.filters:DisplacementMapFilter
ConvolutionFilter#flash.filters:DisplacementMapFilter
DisplacementMapFilter.as$36
DisplacementMapFilter.as$36
flash.filters:DropShadowFilter
flash.filters:DropShadowFilter
DropShadowFilter.as$40
DropShadowFilter.as$40
flash.filters:GlowFilter
flash.filters:GlowFilter
GlowFilter.as$55
GlowFilter.as$55
GlowFilter!flash.filters:GradientBevelFilter
GlowFilter!flash.filters:GradientBevelFilter
GradientBevelFilter.as$56
GradientBevelFilter.as$56
GradientBevelFilter flash.filters:GradientGlowFilter
GradientBevelFilter flash.filters:GradientGlowFilter
GradientGlowFilter.as$57
GradientGlowFilter.as$57
flash.xml:XMLDocument
flash.xml:XMLDocument
XMLDocument.as$169
XMLDocument.as$169
flash.events:FullScreenEvent
flash.events:FullScreenEvent
FullScreenEvent.as$54
FullScreenEvent.as$54
flash.events:DataEvent
flash.events:DataEvent
DataEvent.as$31
DataEvent.as$31
flash.events:ErrorEvent
flash.events:ErrorEvent
ErrorEvent.as$42
ErrorEvent.as$42
flash.events:IMEEvent
flash.events:IMEEvent
ImeEvent.as$75
ImeEvent.as$75
flash.media:Camera
flash.media:Camera
setKeyFrameInterval
setKeyFrameInterval
Camera.as$21
Camera.as$21
flash.events.StatusEvent
flash.events.StatusEvent
flash.events.ActivityEvent
flash.events.ActivityEvent
flash.ui:ContextMenu
flash.ui:ContextMenu
ContextMenu.as$25
ContextMenu.as$25
flash.events.ContextMenuEvent
flash.events.ContextMenuEvent
flash.ui:ContextMenuItem
flash.ui:ContextMenuItem
ContextMenuItem.as$27
ContextMenuItem.as$27
flash.display:DisplayObject
flash.display:DisplayObject
DisplayObject.as$38
DisplayObject.as$38
flash.net:FileReference
flash.net:FileReference
FileReference.as$49
FileReference.as$49
flash.events.DataEvent
flash.events.DataEvent
flash.events.HTTPStatusEvent
flash.events.HTTPStatusEvent
flash.events.SecurityErrorEvent
flash.events.SecurityErrorEvent
flash.events.ProgressEvent
flash.events.ProgressEvent
flash.events.IOErrorEvent
flash.events.IOErrorEvent
flash.net:FileReferenceList
flash.net:FileReferenceList
FileReferenceList.as$50
FileReferenceList.as$50
flash.display:LoaderInfo
flash.display:LoaderInfo
LoaderInfo.as$82
LoaderInfo.as$82
loaderURL
loaderURL
flash.net:LocalConnection
flash.net:LocalConnection
LocalConnection.as$85
LocalConnection.as$85
flash.events.AsyncErrorEvent
flash.events.AsyncErrorEvent
flash.media:Microphone
flash.media:Microphone
Microphone.as$89
Microphone.as$89
flash.net:NetConnection
flash.net:NetConnection
NetConnection.as$97
NetConnection.as$97
flash.events.NetStatusEvent
flash.events.NetStatusEvent
flash.net:NetStream
flash.net:NetStream
NetStream.as$99
NetStream.as$99
flash.printing:PrintJob
flash.printing:PrintJob
PrintJob.as$103
PrintJob.as$103
adobe.utils:ProductManager
adobe.utils:ProductManager
ProductManager.as$108
ProductManager.as$108
flash.events.ErrorEvent
flash.events.ErrorEvent
flash.net:SharedObject
flash.net:SharedObject
SharedObject.as$118
SharedObject.as$118
flash.events.SyncEvent
flash.events.SyncEvent
flash.net:Socket
flash.net:Socket
Socket.as$119
Socket.as$119
flash.media:Sound
flash.media:Sound
Sound.as$120
Sound.as$120
flash.media:SoundChannel
flash.media:SoundChannel
leftPeak
leftPeak
SoundChannel.as$123
SoundChannel.as$123
flash.text:StyleSheet
flash.text:StyleSheet
StyleSheet.as$133
StyleSheet.as$133
flash.system:IME
flash.system:IME
IME.as$137
IME.as$137
flash.events.IMEEvent
flash.events.IMEEvent
flash.utils:Timer
flash.utils:Timer
Timer.as$155
Timer.as$155
flash.events.TimerEvent
flash.events.TimerEvent
flash.net:URLLoader
flash.net:URLLoader
URLLoader.as$159
URLLoader.as$159
URLStream
URLStream
URLLoader
URLLoader
flash.net:URLStream
flash.net:URLStream
URLStream.as$164
URLStream.as$164
flash.net:XMLSocket
flash.net:XMLSocket
XMLSocket.as$171
XMLSocket.as$171
flash.events:AsyncErrorEvent
flash.events:AsyncErrorEvent
AsyncErrorEvent.as$41
AsyncErrorEvent.as$41
flash.events:IOErrorEvent
flash.events:IOErrorEvent
IOErrorEvent.as$67
IOErrorEvent.as$67
flash.events:SecurityErrorEvent
flash.events:SecurityErrorEvent
SecurityErrorEvent.as$116
SecurityErrorEvent.as$116
flash.display:AVM1Movie
flash.display:AVM1Movie
AVM1Movie.as$11
AVM1Movie.as$11
flash.display:IBitmapDrawable
flash.display:IBitmapDrawable
flash.display:Bitmap
flash.display:Bitmap
Bitmap.as$73
Bitmap.as$73
flash.display:InteractiveObject
flash.display:InteractiveObject
InteractiveObject.as$76
InteractiveObject.as$76
flash.events.KeyboardEvent
flash.events.KeyboardEvent
flash.events.MouseEvent
flash.events.MouseEvent
flash.events.FocusEvent
flash.events.FocusEvent
flash.display:MorphShape
flash.display:MorphShape
MorphShape.as$90
MorphShape.as$90
flash.display:Shape
flash.display:Shape
Shape.as$117
Shape.as$117
flash.text:StaticText
flash.text:StaticText
StaticText.as$131
StaticText.as$131
flash.media:Video
flash.media:Video
Video.as$166
Video.as$166
SetIntervalTimer.as$156
SetIntervalTimer.as$156
flash.utils:SetIntervalTimer
flash.utils:SetIntervalTimer
flash.display:SimpleButton
flash.display:SimpleButton
SimpleButton.as$19
SimpleButton.as$19
SimpleButton$flash.display:DisplayObjectContainer
SimpleButton$flash.display:DisplayObjectContainer
DisplayObjectContainer.as$24
DisplayObjectContainer.as$24
flash.text:TextField
flash.text:TextField
TextField.as$140
TextField.as$140
alwaysShowSelection
alwaysShowSelection
displayAsPassword
displayAsPassword
flash.events.TextEvent
flash.events.TextEvent
flash.display:Loader
flash.display:Loader
Loader.as$81
Loader.as$81
flash.display:Sprite
flash.display:Sprite
Sprite.as$93
Sprite.as$93
flash.display:Stage
flash.display:Stage
Stage.as$126
Stage.as$126
flash.events.FullScreenEvent
flash.events.FullScreenEvent
flash.display:MovieClip
flash.display:MovieClip
MovieClip.as$96
MovieClip.as$96
-./0123456789:;?
-./0123456789:;?
f$,&a%dl
f$,&a%dl
f$,)a%dl
f$,)a%dl
f$, a%dl
f$, a%dl
f$,3a%dl
f$,3a%dl
f$,-a%dl
f$,-a%dl
f$,/a%dl
f$,/a%dl
&!&!*! !.!.!
&!&!*! !.!.!
b......AAf999999
b......AAf999999
AA.AAAA
AA.AAAA
......AAAA
......AAAA
....AAA
....AAA
....AA
....AA
...AAA
...AAA
...AA
...AA
%9ss:V=#cEEc#=V
%9ss:V=#cEEc#=V
j.pO5
j.pO5
9999999
9999999
%%%%%%%u%h
%%%%%%%u%h
%uuuu%h
%uuuu%h
HB%%%%%%%u
HB%%%%%%%u
HB%%%%%uuuuJ
HB%%%%%uuuuJ
HB%%uuuuuuu#k
HB%%uuuuuuu#k
H%uuuuuuuuuuuuuuuuuu
H%uuuuuuuuuuuuuuuuuu
H%uuuuuuuuuuuuu
H%uuuuuuuuuuuuu
ÃŒcz___}]]]}___}]]]}]]]}]]]}___z
ÃŒcz___}]]]}___}]]]}]]]}]]]}___z
111111111
111111111
C3@%u)
C3@%u)
33s
33s
:$.EJ
:$.EJ
HR.ma
HR.ma
1333333333
1333333333
..YLc.*
..YLc.*
4:;;100`.
4:;;100`.
.BOOO
.BOOO
!),.:;?]}
!),.:;?]}
\VVV.macromedia.com
\VVV.macromedia.com
r.exe
r.exe
\Logs\codesign.txt
\Logs\codesign.txt
lWinHTTP AutoProxy Test
lWinHTTP AutoProxy Test
control.tlb
control.tlb
Adobe Flash Player has stopped a potentially unsafe operation.
Adobe Flash Player has stopped a potentially unsafe operation.
Adobe Flash Player ha interrotto un'operazione potenzialmente pericolosa.
Adobe Flash Player ha interrotto un'operazione potenzialmente pericolosa.
Adobe Flash Player ha detenido una operaci
Adobe Flash Player ha detenido una operaci
Enter the World Wide Web location (URL) or specify the local file you would like to open.
Enter the World Wide Web location (URL) or specify the local file you would like to open.
Geben Sie die Internetadresse (URL) oder eine lokale Datei an, die Sie
Geben Sie die Internetadresse (URL) oder eine lokale Datei an, die Sie
cifiez l'adresse URL (World Wide Web) ou le fichier local
cifiez l'adresse URL (World Wide Web) ou le fichier local
Passo &avanti
Passo &avanti
Specificare l'indirizzo (URL) dell'elemento da aprire.
Specificare l'indirizzo (URL) dell'elemento da aprire.
n Web (URL) o especifique el archivo local que desee abrir.
n Web (URL) o especifique el archivo local que desee abrir.
World Wide Web
World Wide Web
(URL)
(URL)
Adobe Flash Player 9;Adobe Flash movie (*.swf)|*.swf;*.spl|All Files (*.*)|*.*||
Adobe Flash Player 9;Adobe Flash movie (*.swf)|*.swf;*.spl|All Files (*.*)|*.*||
Projector (*.exe)|*.exe||GCopyright
Projector (*.exe)|*.exe||GCopyright
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Alle Dateien (*.*)|*.*||
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Alle Dateien (*.*)|*.*||
Projektor (*.exe)|*.exe||KCopyright
Projektor (*.exe)|*.exe||KCopyright
ndern schwebend. Adobe und Flash sind Marken oder registrierte Marken in den USA und/oder anderen L
ndern schwebend. Adobe und Flash sind Marken oder registrierte Marken in den USA und/oder anderen L
Adobe Flash Player 9CAdobe Flash movie (*.swf)|*.swf;*.spl|Tous les fichiers (*.*)|*.*||
Adobe Flash Player 9CAdobe Flash movie (*.swf)|*.swf;*.spl|Tous les fichiers (*.*)|*.*||
Projection (*.exe)|*.exe||HCopyright
Projection (*.exe)|*.exe||HCopyright
ricain 6.879.327 ; Brevets en cours aux
ricain 6.879.327 ; Brevets en cours aux
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Tutti i file (*.*)|*.*||
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Tutti i file (*.*)|*.*||
Proiettore (*.exe)|*.exe||LCopyright
Proiettore (*.exe)|*.exe||LCopyright
Adobe Flash Player 9DAdobe Flash movie (*.swf)|*.swf;*.spl|Todos los archivos (*.*)|*.*||
Adobe Flash Player 9DAdobe Flash movie (*.swf)|*.swf;*.spl|Todos los archivos (*.*)|*.*||
Proyector (*.exe)|*.exe||PCopyright
Proyector (*.exe)|*.exe||PCopyright
Adobe Flash Player 9:Adobe Flash movie (*.swf)|*.swf;*.spl|
Adobe Flash Player 9:Adobe Flash movie (*.swf)|*.swf;*.spl|
(*.*)|*.*||
(*.*)|*.*||
(*.exe)|*.exe||4Copyright (C) 1996-2007 Adobe Systems Incorporated. v
(*.exe)|*.exe||4Copyright (C) 1996-2007 Adobe Systems Incorporated. v
6,879,327
6,879,327
Adobe Flash Player 96Adobe Flash movie (*.swf)|*.swf;*.spl|
Adobe Flash Player 96Adobe Flash movie (*.swf)|*.swf;*.spl|
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.K
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.K
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.J
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.J
(*.*)|*.*||
(*.*)|*.*||
(*.exe)|*.exe||ICopyright (C) 1996-2007 Adobe Systems Incorporated. All Rights Reserved.
(*.exe)|*.exe||ICopyright (C) 1996-2007 Adobe Systems Incorporated. All Rights Reserved.
%original file name%.exe_2772_rwx_00608000_0006C000:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
####@####
####@####
kernel32.dll
kernel32.dll
ShellExecuteA
ShellExecuteA
shell32.dll
shell32.dll
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
GetWindowsDirectoryA
GetWindowsDirectoryA
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
C:\default.html
C:\default.html
PSAPI.dll
PSAPI.dll
VBoxService.exe
VBoxService.exe
SbieDll.dll
SbieDll.dll
dbghelp.dll
dbghelp.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
55274-640-2673064-23950
55274-640-2673064-23950
76487-644-3177037-23510
76487-644-3177037-23510
76487-337-8429955-22614
76487-337-8429955-22614
\\.\Syser
\\.\Syser
\\.\SyserDbgMsg
\\.\SyserDbgMsg
\\.\SyserBoot
\\.\SyserBoot
\\.\SICE
\\.\SICE
\\.\NTICE
\\.\NTICE
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
explorer.exe
explorer.exe
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
oleaut32.dll
oleaut32.dll
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCreateKeyA
RegCreateKeyA
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
FindExecutableA
FindExecutableA
?*?/?]?}?
?*?/?]?}?
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@####
####@#### ####@####
####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####
y.YZJO
y.YZJO
nr.AQ
nr.AQ
E.naM
E.naM
$T.GN
$T.GN
R:\JD
R:\JD
R%fLJg
R%fLJg
>.RW$
>.RW$
Az.Sc
Az.Sc
Qw>%UPRi
Qw>%UPRi
z<.mj>
z<.mj>
2X.jtL
2X.jtL
\X%X,``
\X%X,``
%XXTTD*/
%XXTTD*/
.TdiL
.TdiL
.In:|k
.In:|k
Nd/.zk
Nd/.zk
KWindows
KWindows
explorer.exe_3164:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
BROWSEUI.dll
BROWSEUI.dll
GDI32.dll
GDI32.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
msvcrt.dll
msvcrt.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
SHDOCVW.dll
SHDOCVW.dll
SHELL32.dll
SHELL32.dll
SHLWAPI.dll
SHLWAPI.dll
USER32.dll
USER32.dll
UxTheme.dll
UxTheme.dll
FTSSh
FTSSh
t0SSh
t0SSh
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
SShwk
SShwk
98~%SP
98~%SP
ExplorerStartMsgLoop
ExplorerStartMsgLoop
PSSh;
PSSh;
6SSSSh
6SSSSh
SSSSh
SSSSh
SPSSSShL
SPSSSShL
u%SSh
u%SSh
t.WWWW
t.WWWW
xpsp2res.dll
xpsp2res.dll
xpsp3res.dll
xpsp3res.dll
tbSSh
tbSSh
Software\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartMenu
Software\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartMenu
Software\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel
Software\Microsoft\Windows\CurrentVersion\Explorer\StartMenu\StartPanel
kernel32.dll
kernel32.dll
GetSystemWindowsDirectoryW
GetSystemWindowsDirectoryW
NetGetJoinInformation
NetGetJoinInformation
WINMM.dll
WINMM.dll
SETUPAPI.dll
SETUPAPI.dll
WINSTA.dll
WINSTA.dll
OLEACC.dll
OLEACC.dll
USERENV.dll
USERENV.dll
ntdll.dll
ntdll.dll
RegEnumKeyExW
RegEnumKeyExW
RegNotifyChangeKeyValue
RegNotifyChangeKeyValue
RegOpenKeyExA
RegOpenKeyExA
RegEnumKeyW
RegEnumKeyW
RegCloseKey
RegCloseKey
RegCreateKeyW
RegCreateKeyW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
OffsetViewportOrgEx
OffsetViewportOrgEx
GetViewportOrgEx
GetViewportOrgEx
SetViewportOrgEx
SetViewportOrgEx
SetProcessShutdownParameters
SetProcessShutdownParameters
GetProcessHeap
GetProcessHeap
GetWindowsDirectoryW
GetWindowsDirectoryW
CreateIoCompletionPort
CreateIoCompletionPort
ShellExecuteExW
ShellExecuteExW
SHRegCloseUSKey
SHRegCloseUSKey
SHRegCreateUSKeyW
SHRegCreateUSKeyW
AssocQueryKeyW
AssocQueryKeyW
SHRegOpenUSKeyW
SHRegOpenUSKeyW
SHDeleteKeyW
SHDeleteKeyW
TileWindows
TileWindows
ExitWindowsEx
ExitWindowsEx
RegisterHotKey
RegisterHotKey
UnregisterHotKey
UnregisterHotKey
EnumChildWindows
EnumChildWindows
GetKeyState
GetKeyState
GetAsyncKeyState
GetAsyncKeyState
CascadeWindows
CascadeWindows
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
EnumWindows
EnumWindows
explorer.pdb
explorer.pdb
name="Microsoft.Windows.Shell.explorer"
name="Microsoft.Windows.Shell.explorer"
version="5.1.0.0"
version="5.1.0.0"
Windows Shell
Windows Shell
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
]]"```^]]\
]]"```^]]\
3333333330
3333333330
3333330
3333330
333333334
333333334
)@. '5 !*
)@. '5 !*
.DEHHF>?/
.DEHHF>?/
2
2
&$%Uooqkezs
&$%Uooqkezs
['$$#%&(4
['$$#%&(4
3333333333333333333
3333333333333333333
33333333333330
33333333333330
7''''))
7''''))
3'')))33.
3'')))33.
222`444(555
222`444(555
%%%{///-
%%%{///-
000000000
000000000
00000000
00000000
`[66...00
`[66...00
0000000
0000000
`]66./.000
`]66./.000
/./././././././.
/./././././././.
66///0000
66///0000
0000000000000
0000000000000
0000000000
0000000000
6666,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6,0.010.010.010.010.010.010.010.010.010.010.001
6666,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6,0.010.010.010.010.010.010.010.010.010.010.001
4366666666K,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6.010.010.010.010.010.010.010.010.010.010.000
4366666666K,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6,6.010.010.010.010.010.010.010.010.010.010.000
:;
:;
) ) ) ) )
) ) ) ) )
|2222'2'2'2'2'2'2'2'2'2'2'2'2'2'2'2',),),),),),),),),),),),),),),),),),),),),),,
|2222'2'2'2'2'2'2'2'2'2'2'2'2'2'2'2',),),),),),),),),),),),),),),),),),),),),),,
22222222222
22222222222
3333333
3333333
.SB99;;;99twv}ut{oxt~
.SB99;;;99twv}ut{oxt~
.SB;;;:::2:w}{{qddgghg
.SB;;;:::2:w}{{qddgghg
" """ """ """ """ "" #
" """ """ """ """ "" #
""" """ """ "#
""" """ """ "#
.SG>''';;9::p
.SG>''';;9::p
:5:5:5:5:5:5:5:5:5:5#"
:5:5:5:5:5:5:5:5:5:5#"
# # # # # # # # # # # # # # # # # # # # # ##$
# # # # # # # # # # # # # # # # # # # # # ##$
( # # # # # # # # # # # # # # # # # # # # ###
( # # # # # # # # # # # # # # # # # # # # ###
1232123212321232123
1232123212321232123
(&(((&(((&(((&(((&((&&)
(&(((&(((&(((&(((&((&&)
&(((&(((&(((&()
&(((&(((&(((&()
`,''')))
`,''')))
'4,4'4,4'4,4'4,4'4,4)(
'4,4'4,4'4,4'4,4'4,4)(
55///0000
55///0000
5555-5-5-5-5-5-5-5-5-5-5-5-5-5-5-5-0
5555-5-5-5-5-5-5-5-5-5-5-5-5-5-5-5-0
555555555
555555555
55555555
55555555
5555555
5555555
14441444144414441
14441444144414441
4343434343434343
4343434343434343
5555555555555
5555555555555
5555555555
5555555555
-,-,-,-,-,-,-,-,-,-,-*.
-,-,-,-,-,-,-,-,-,-,-*.
..............................JFJFJFJFJFJFJFJFJFJFJ.-
..............................JFJFJFJFJFJFJFJFJFJFJ.-
{22*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-../
{22*2*2*2*2*2*2*2*2*2*2*2*2*2*2*2*.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-../
|ujjjjuhF..BBBBBBBBBBBBT
|ujjjjuhF..BBBBBBBBBBBBT
~j|F.BB*BBB*BBB*Bwop
~j|F.BB*BBB*BBB*Bwop
&!!!&!!!&
&!!!&!!!&
44466666
44466666
44444444416
44444444416
4446666
4446666
66666666
66666666
|= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |=
|= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |=
|= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |=
|= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |= |=
DDDDE%CTDD@
DDDDE%CTDD@
A%US$
A%US$
%UUUU
%UUUU
%%UUU
%%UUU
33U
33U
""2222!!
""2222!!
!"!"%UUR""
!"!"%UUR""
!""!"#2"""
!""!"#2"""
"!!"#3"!"
"!!"#3"!"
dnnnnn:n.nfCnmddddd
dnnnnn:n.nfCnmddddd
////;/;;88
////;/;;88
;888;;!/
;888;;!/
!//!!;;^
!//!!;;^
:;:!::!!!
:;:!::!!!
.88.88.8
.88.88.8
.N.NN.M
.N.NN.M
::8.8...
::8.8...
:::!;;:!
:::!;;:!
//!!;888
//!!;888
.8.8.88...
.8.8.88...
:;!::!!;!//!;
:;!::!!;!//!;
!!;:!!::
!!;:!!::
.88..8..
.88..8..
!!:::/^!
!!:::/^!
!;/;!;;;!!!:
!;/;!;;;!!!:
.8:!!!!^
.8:!!!!^
!!:;:::..
!!:;:::..
/:!^^!;{8{../
/:!^^!;{8{../
...:::.-
...:::.-
**6***66*6**6566*5666 ,
**6***66*6**6566*5666 ,
6*6666*6*6 655*65
6*6666*6*6 655*65
6*65 56*5 55 555 *5 6
6*65 56*5 55 555 *5 6
555( 55 (5 5(
555( 55 (5 5(
76 5 66 555*677
76 5 66 555*677
6*6 5 5(5 (55( '5((5 (556 ('5
6*6 5 5(5 (55( '5((5 (556 ('5
665**6(('S((((((S(((]('((@('SS((S(((((((6C-.NEC66S5sU
665**6(('S((((((S(((]('((@('SS((S(((((((6C-.NEC66S5sU
555(555(5((5(5(5(
555(555(5((5(5(5(
5 5 5 5555 (555(555'(((5(5('55(((
5 5 5 5555 (555(555'(((5(5('55(((
((''('5'5(5('('('('('((''('(((@(((('&(((&
((''('5'5(5('('('('('((''('(((@(((('&(((&
%&&%&&&&3>&3&3&33&3&3333&&3>3333
%&&%&&&&3>&3&3&33&3&3333&&3>3333
'(3&'&3&
'(3&'&3&
3&33&&((
3&33&&((
3323>33>%>3%>3>33>3%3&%
3323>33>%>3%>3>33>3%3&%
*5'(('((&@3(
*5'(('((&@3(
,63%3>323>3%>&>33323>>%>
,63%3>323>3%>&>33323>>%>
3(3'(((@@'5('@(@(&('(
3(3'(((@@'5('@(@(&('(
>2>323%>3
>2>323%>3
75((((@3&333&3&&&%&3&&3&33>33%3>23%>3
75((((@3&333&3&&&%&3&&3&33>33%3>23%>3
>2%$32%>2>%>2$3>
>2%$32%>2>%>2$3>
3&%&&3&33>3>33
3&%&&3&33>3>33
3>%>3%&3$23>23$2>2%$>2>
3>%>3%&3$23>23$2>2%$>2>
)4433((&(&('*
)4433((&(&('*
('((((''(**6(('' *
('((((''(**6(('' *
32323>3>
32323>3>
2$%>22%>%3' (
2$%>22%>%3' (
&(&''((5(5 *
&(&''((5(5 *
'(&(&((&('''
'(&(&((&('''
&&%&3&&%3%
&&%&3&&%3%
2%>22>22
2%>22>22
5''3(((3(('&(&'&
5''3(((3(('&(&'&
3%%3%3%2#$
3%%3%3%2#$
22$22$2%$22$2%2%$2%$2$222%$22
22$22$2%$22$2%2%$2%$2$222%$22
&>2$2$2$222$22$%%
&>2$2$2$222$22$%%
:7'((('(3('(3(&(&
:7'((('(3('(3(&(&
222222222222
222222222222
22222222222222
22222222222222
222222222222222
222222222222222
22$22$22$22$
22$22$22$22$
&(%3%&&&&3&&&3%3
&(%3%&&&&3&&&3%3
222222222222222222
222222222222222222
&&(&3(&(&'('((3'(&&
&&(&3(&(&'('((3'(&&
2222222
2222222
22$
22$
&&(3(3('(&'
&&(3(3('(&'
222"2212
222"2212
22
22
(&(3(3((
(&(3(3((
((565 ((( 6
((565 ((( 6
333&33(&&
333&33(&&
'(('('(('(
'(('('(('(
'&%%"$
'&%%"$
2"2"22"2
2"2"22"2
2222
2222
"2"22
"2"22
2%('(3'32222?&'
2%('(3'32222?&'
2"2"2"121212
2"2"2"121212
2"2"2$"?
2"2"2$"?
%%22%2
%%22%2
&3(3(3((&
&3(3(3((&
"2"
"2"
1"?((&21
1"?((&21
22
22
2%""22&&
2%""22&&
2
2
'&('(3(''
'&('(3(''
((%%%"
((%%%"
5(3%"%
5(3%"%
"2%5*67
"2%5*67
))) ))))
))) ))))
""**
""**
"*
"*
#2#---2222-222442-
#2#---2222-222442-
---(-%
---(-%
$/222(--444222!
$/222(--444222!
#&-221269924999;
#&-221269924999;
&$-22-($2%
&$-22-($2%
#(2---222622212-
#(2---222622212-
#2221299629968
#2221299629968
#&--%#(2##!
#&--%#(2##!
-222422422426662-%
-222422422426662-%
"2-##&
"2-##&
!##-#-&%---#---#&-219662%
!##-#-&%---#---#&-219662%
$&-(151,44.9
$&-(151,44.9
&1242662-
&1242662-
-(..19.19
-(..19.19
,4492.12
,4492.12
12-$-,-,
12-$-,-,
-, $$----
-, $$----
#%#-15/-&
#%#-15/-&
-,(,,(,(,
-,(,,(,(,
$$11651566/,$&&
$$11651566/,$&&
,2592&&&-
,2592&&&-
2466/!$$
2466/!$$
""*
""*
) '????[
) '????[
&&&$-556>>61,,5994511-
&&&$-556>>61,,5994511-
$(//$$$(6>6/,$,-$
$(//$$$(6>6/,$,-$
#$-22692/,,$,-&
#$-22692/,,$,-&
-266661..4514#
-266661..4514#
&,2-&#
&,2-&#
&-222,22--#
&-222,22--#
#&&---2-,-&$&(,,291.566..BNNNTNNNNNAABIAA88
#&&---2-,-&$&(,,291.566..BNNNTNNNNNAABIAA88
&!#&!-##
&!#&!-##
--//11468>885882&
--//11468>885882&
$266961$&--$&%
$266961$&--$&%
,1661,!-((#
,1661,!-((#
&$,4255$,92
&$,4255$,92
&$,44..&
&$,44..&
""**""***""
""**""***""
"****
"****
"**""""*""""
"**""""*""""
&-569./-,16522$
&-569./-,16522$
.BAA=86546888=AAAEAAEMNRMQQSWZZ\]gk__m__\
.BAA=86546888=AAAEAAEMNRMQQSWZZ\]gk__m__\
bTRHHHHHQQHQJQWJSSSSSSSSSSSSSSSSWWSSSS\\V]VZW8,.FW]\\]\]\]\\ZZ\\WFR>38(
bTRHHHHHQQHQJQWJSSSSSSSSSSSSSSSSWWSSSS\\V]VZW8,.FW]\\]\]\]\\ZZ\\WFR>38(
.BTTkgn]ktvgmvvvvvmvvvsvzzzyzyzyzyyyzmkkkkkZSRA816;F87
.BTTkgn]ktvgmvvvvvmvvvsvzzzyzyzyzyyyzmkkkkkZSRA816;F87
yzyzyzym^Z]WN3 $&$.Wt\
yzyzyzym^Z]WN3 $&$.Wt\
""*"""****""""
""*"""****""""
"***"**""**
"***"**""**
$5612,.2,
$5612,.2,
&$$,,,5]
&$$,,,5]
$]t.Ft
$]t.Ft
7%8U8
7%8U8
3 303
3 303
2
8 8$8(8,80848885%5,575{67 7$7(7,70747rundll32.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AdvancedSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartPageSoftware\Microsoft\Windows\CurrentVersion\Explorer\Advanced::{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}::{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}::{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}::{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}::{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}::{D20EA4E1-3957-11d2-A40B-0C5020524153}::{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}{208D2C60-3AEA-1069-A2D7-08002B30309D}{20D04FE0-3AEA-1069-A2D8-08002B30309D}Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites{450D8FBA-AD25-11D0-98A8-0800361B1103}CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}Software\Microsoft\Windows\CurrentVersion\RunOnceSoftware\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoadSoftware\Microsoft\Windows\CurrentVersion\Explorer\DontShowMeThisDialogAgainSoftware\Microsoft\Windows\CurrentVersion\Explorer\Desktop\CleanupWiz\\.\WMIDataDeviceSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunSoftware\Microsoft\Windows NT\CurrentVersion\WindowsExplorerIsShellMutexdesk.cplSoftware\Microsoft\Windows\CurrentVersion\Explorertourstart.exetourstart.exe,0Microsoft.OfferTourWINWORD.EXESoftware\Microsoft\Windows\CurrentVersion\AppletsSoftware\Microsoft\Windows\CurrentVersion\Applets\Tourexplorer.exe,9Microsoft.FixScreenResolutionshell:::{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}Software\Microsoft\Windows\CurrentVersion\Explorer\FileAssociationSoftware\Microsoft\Windows NT\CurrentVersionshell:::{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}Software\Microsoft\Windows\CurrentVersion\Explorer\StartPageSoftware\Microsoft\Windows\CurrentVersion\Policies\ExplorerDDEEXECUTESHORTCIRCUIThttp\shellIEXPLORE.EXESoftware\Microsoft\Windows\CurrentVersion\Explorer\Streams\DesktopSoftware\Microsoft\Windows\CurrentVersion\RunOnceExcomctl32.dllSoftware\Microsoft\Windows\Internet SettingsAutoConfigURLsystem.iniAppEvents\Schemes\Apps\.Default\%s\.currentSoftware\Microsoft\Windows\CurrentVersion\Explorer\TrayNotifyMSShellRunDlgReadyres://mys.dll/mys.hta /explorermshta.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\WelcomeSoftware\Microsoft\Windows\CurrentVersion\Explorer\TipsSOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\MYScys.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\srvWizinstall.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Control PanelOUTLOOK.EXEexplorer.exe,16iernonce.dllWININET.DLLUpdateURLWindowsUpdateHWND%xSoftware\Microsoft\Windows\CurrentVersion\OemStartMenuDatafldrclnr.dll,Wizard_RunDLLiexplore.exewinbrand.dllSoftware\Microsoft\Windows\CurrentVersion\Explorer\Remote\%dshell32.dllnusrmgr.cpl ,initialTask=ChangePictureNewExeNameWindowsediskeer.dlltimedate.cplSoftware\Microsoft\Windows\CurrentVersion\Explorer\Comdlg32\LastVisitedMRUSoftware\Microsoft\Windows\CurrentVersion\Explorer\Comdlg32\OpenSaveMRUSoftware\Microsoft\Windows\CurrentVersion\Explorer\Doc Find Spec MRUSoftware\Microsoft\Windows\CurrentVersion\Explorer\RunMRUSoftware\Microsoft\Internet Explorer\TypedURLs%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Calculator.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Games\Solitaire.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Paint.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\WordPad.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\System Tools\Files and Settings Transfer Wizard.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Windows Movie Maker.lnk%USERPROFILE%\Start Menu\Programs\Accessories\Tour Windows XP.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Windows Messenger.lnk%USERPROFILE%\Start Menu\Programs\Windows Media Player.lnk%ALLUSERSPROFILE%\Start Menu\Programs\MSN.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Get Online with MSN.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Get Going with Tablet PC.lnk%ALLUSERSPROFILE%\Start Menu\Set Program Access and Defaults.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Windows Journal.lnk%ALLUSERSPROFILE%\Start Menu\Programs\Accessories\Media Center\Media Center.lnk%USERPROFILE%\Start Menu\Programs\Internet Explorer.lnkSoftware\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanelTSAppCMP.DLLnetapi32.dll%SystemRoot%\system32\restore\rstrui.exeRunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ?0x%X?%sRunDLL32.EXE%s%d%sSoftware\Microsoft\Windows\CurrentVersion\Policies\Systemsettings.dllexplorer.exe "explorer.exe /e, "WindowsLogonWindowsLogoff%s %sSoftware\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\CountuAppWiz.Cpl\explorer.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu::{20D04FE0-3AEA-1069-A2D8-08002B30309D}taskmgr.exeShellExecuteSoftware\Microsoft\Windows\CurrentVersion\Explorer\AppKey\%d\WindowsShell.ManifestGet Online with MSN.lnkSet Program Access and Defaults.lnkLink%dOEM%dSoftware\Microsoft\Windows\CurrentVersion\SMDEn::{D20EA4E1-3957-11d2-A40B-0C5020524152}There is a file or folder on your computer called "%s" which could cause certain applications to not function correctly. Renaming it to "%s" would solve this problem. Would you like to rename it now?Ca&scade WindowsTile Windows &HorizontallyTile Windows V&ertically&Windows Security...&Help and Support&Log Off %s...Windows Explorer6.00.2900.5512 (xpsp.080413-2105)EXPLORER.EXEWindowsOperating System6.00.2900.5512Keep the &taskbar on top of other windowsTo remove records of recently accessed documents, programs, and Web sites, click Clear.Windows displays icons for active and urgent notifications, and hides inactive ones. You can change this behavior for items in the list below.Select this option to use the menu style from earlier versions of Windows.6There is not enough memory to complete this operation.8Unable to run command.The folder '%1' has been removed.WMy Computer or Windows Explorer has not been properly initialized yet. Try again later.&Undo %sWindows is running in safe mode.This special diagnostic mode of Windows enables you to fix a problem which may be caused by your network or hardware settings. Make sure these settings are correct in Control Panel, and then try starting Windows again. While in safe mode, some of your devices may not be available.startRThere was an internal error and one of the windows you were using has been closed.Restrictions{This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator.&Show Open WindowsWindows was unable to change the display settings for the new configuration. Return the computer to the previous state, shut down Windows, and restart the computer in the desired configuration.There may be a problem with your display settings if you continue. To safely change to a new configuration, you should shut down Windows and restart the computer in the desired configuration. Do you want to continue anyway?This pre-release version of "Internet Explorer 4.0" Desktop/Explorer has expired. Please update to the latest release of "Internet Explorer 4.0" from WWW.MICROSOFT.COMhelpctr.exe>-FromStartHelpTake a tour of Windows XPNOpens a window where you can pick search options and work with search results.aOpens a central location for Help topics, tutorials, troubleshooting, and other support services./Opens a program, folder, document, or Web site.Provides options for closing your programs and logging off, or for leaving your programs running and switching to another user.lProvides options for turning off or restarting your computer, or for activating Stand By or Hibernate modes.RDisconnects your session. You can reconnect to the session when you log on again.&Windows SecurityiOpens the My Documents folder, where you can store letters, reports, notes, and other kinds of documents./Displays recently opened documents and folders.KOpens the My Music folder, where you can store music and other audio files.]Opens the My Pictures folder, where you can store digital photos, images, and graphics files.zGives access to, and information about, the disk drives, cameras, scanners, and other hardware connected to your computer.MGives access to, and information about, folders and files on other computers.8Connects to other computers, networks, and the Internet.explorer.exe_3164_rwx_00090000_00001000:KERNEL32.DLLexplorer.exe_3164_rwx_001D0000_00001000:KERNEL32.DLLexplorer.exe_3164_rwx_00210000_00001000:KERNEL32.DLLexplorer.exe_3164_rwx_00250000_00001000:KERNEL32.DLLserver.exe_3420:.text.rdata@.data.rodata.rsrcJWx%fuâ„¢u!9H%u$9y%u/D$4PSShL$4QSSh>%u~%UVWD$Dt%SRSSShtSSSShtt5SSShtASSShSSShSSSSSShdSSSSShSSSh&SSShOSSSh'SSSh1SSShnSSShT!!!!!!""#$%&'(((((())* ,-.DDDDDDDD//01234555676789:;<:>?@ABC888888888888888888888888888888888888888888888UDPQ!"#$%&'()* ,-./01234456.idataP.relocP.rsrc####@####kernel32.dllShellExecuteAshell32.dllSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersGetWindowsDirectoryASOFTWARE\Microsoft\Windows\CurrentVersionC:\default.htmlPSAPI.dllVBoxService.exeSbieDll.dlldbghelp.dllSoftware\Microsoft\Windows\CurrentVersion55274-640-2673064-2395076487-644-3177037-2351076487-337-8429955-22614\\.\Syser\\.\SyserDbgMsg\\.\SyserBoot\\.\SICE\\.\NTICESoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunSoftware\Microsoft\Windows\CurrentVersion\Runexplorer.exeuser32.dllGetKeyboardTypeadvapi32.dllRegOpenKeyExARegCloseKeyoleaut32.dllRegDeleteKeyARegCreateKeyExARegCreateKeyAMsgWaitForMultipleObjectsFindExecutableA?*?/?]?}?####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@########@#### ####@########@#### ####@#### ####@#### ####@########@#### ####@#### ####@########@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####y.YZJOnr.AQE.naM$T.GNR:\JDR%fLJg>.RW$Az.ScQw>%UPRiz<.mj>2X.jtL\X%X,``%XXTTD*/.TdiL.In:|kNd/.zkKWindowsflash.filters.DropShadowFilter@flash.filters.GlowFilterflash.filters.BlurFilterflash.filters.BevelFilterflash.filters.ConvolutionFilterflash.filters.DisplacementMapFilterflash.filters.GradientGlowFilterflash.filters.GradientBevelFilterflash.filters.ColorMatrixFilterapplication/x-www-form-urlencodedflash.geom.Rectangleflash.geom.Pointflash.geom.Transformportraitflash.display.BitmapDataflash.geom.Matrixflash.geom.ColorTransformProductDownloadBaseUrlCodeSignRootCertAutoUpdateVersionUrl.macromedia.comhXXp://.macromedia.com/support/flashplayer/sys/hXXps://mms.cfghXXp://VVV.macromedia.comhXXps://VVV.macromedia.com/support/flashplayer/sys/FlashAuthor.cfg=cacheSize.txt%3 %3 %d %2:%2:%2 GMT%c%2%2 %d0 1 2 3 4 5 6 7!%),.?]}for (var i=0; ifor (var i=index; ireturn s.replace(/&/g, "&").replace(/, "/g, ">").replace(/"/g, """).replace(/'/g, "'");return "" value.getTime() "";Client.Header.MustUnderstandClient.Data.UnderFlowNetConnection.Call.BadVersion_global.Systemflash.net.FileReferencePTF://https:.macromedia.com/%s%sdescription.xml%s%s.xml%s%s.z%s?product=%s&signed=true&%s%s%s&product=%s&signed=true&%s%shXXp://fpdownload2.macromedia.com/get/hXXps://fpdownload.macromedia.com/get/hXXps://VVV.macromedia.com/bin/flashdownload.cgi-https=9,0,115,0VVV.macromedia.comDownload.CompleteDownload.CancelledDownload.Failedunknown URL>1.2.3WebdingsCurlz MThttp:[[IMPORT]]/by-ftp-filename/crossdomain.xmlto-ports.localSHA-256 part of OpenSSL 0.9.8d 28 Sep 2006A=%b&SA=%b&SV=%b&EV=%b&MP3=%b&AE=%b&VE=%b&ACC=%b&PR=%b&SP=%b&SB=%b&DEB=%b&V=%s%s&PT=%s&AVD=%b&LFD=%b&WD=%b&TLS=%bhXXp://%s/.maxscroll.scrollNetConnection.Call.FailedHTTP:onKeyUponKeyDownurl_stream_porturl_stream_hosturl_stream_pathNetConnection.Call.Prohibitedurl_request_targeturl_requestpasswordvnd.ms.wmhtml:URLNotFoundhXXp://settingsmanager.adobe.comhXXp://VVV.adobe.comhXXp://VVV.macromedia.com/support/flashplayer/sys/onHTTPStatusiso_646.irv:1991windows-936tcp01140webcdic-fi-278 eurowebcdic-se-278 euro%cp037%csibm037Tcp852iso_646.irv:1983csshiftjisjwindows-874windows-1250windows-1251windows-1252windows-1253windows-1254windows-1255windows-1256windows-1257windows-1258windows-31jcswindows31jimm32.dllSystem.IME,,0,0,,,WWW_OpenURLddeexecdwmapi.dlld3d8.dllddraw.dllRegDeleteKeyWRegOpenKeyExWRegCreateKeyExWversion.dllShellExecuteExWWindows 95Windows 98/MEWindows NTWindows 2000Windows XPWindows VistaWindowsAdobe WindowsMacromedia Windows&M=%s&R=%dx%d&DP=%d&COL=%s&AR=%s&OS=%s&L=%s&IME=%b*.exe*.swfW@\\?\).mdmpSAFlashPlayer.exeplayer_crash_log_(*).mdmpz>httpsonHTTPError&Macromedia Flash Certificate Authority1secure@macromedia.com1Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Foldersupdate.batVerifyMessage : Second CertVerifySubjectCertificateContext() failed.VerifyMessage : CertVerifySubjectCertificateContext() failed.VerifyMessage : Certificate chain is too long.VerifyMessage : CertCreateCertificateContext() failed.VerifyMessage : CryptGetMessageCertificates() failed.VerifyMessage : Unable to read external root certificate specified in MMS.CFG by CodeSignRootCert.\\?\UNC\HTTP/1.0%d.%d.%d.%dtrapallkeysWinHttpGetIEProxyConfigForCurrentUserWinHttpGetProxyForUrlWinHttpDetectAutoProxyConfigUrlWinHttpGetDefaultProxyConfigurationWinHttpCloseHandleWinHttpOpenwinhttp.dllURLDownloadToFileAurlmon.dlljsproxy.dllDetectAutoProxyUrlwininet.dllhttp=https=Secur32.dllSecurity.dllCertCloseStoreCertOpenSystemStoreWCertFreeCertificateContextCertFreeCertificateChainCertVerifyCertificateChainPolicyCertGetCertificateChaincrypt32.dll.jpegFtpOpenFileAHttpQueryInfoAHttpSendRequestAHttpOpenRequestAUser32.dllFlashPlayer.ProtectedMediaForFlashPlayerFlashPlayer.ProtectedMediaForFlashPlayer\DefaultIconFlashPlayer.ProtectedMediaForFlashPlayer\shell\open\commandFlashPlayer.AudioForFlashPlayerFlashPlayer.AudioForFlashPlayer\DefaultIconFlashPlayer.AudioForFlashPlayer\shell\open\commandFlashPlayer.VideoForFlashPlayerFlashPlayer.VideoForFlashPlayer\DefaultIconFlashPlayer.VideoForFlashPlayer\shell\open\commandFlashPlayer.FlashVideoFlashPlayer.FlashVideo\DefaultIconFlashPlayer.FlashVideo\shell\open\commandShockwaveFlash.ShockwaveFlashShockwaveFlash.ShockwaveFlash\DefaultIconShockwaveFlash.ShockwaveFlash\shell\open\commandkeyFrameIntervaltag=%s;timestamp=%d;zone=%d;uri=%sNetConnection.Connect.CertificateAPIErrorNetConnection.Connect.CertificateInvalidNetConnection.Connect.CertificateRevokedNetConnection.Connect.CertificateUntrustedSignerNetConnection.Connect.CertificatePrincipalMismatchNetConnection.Connect.CertificateExpiredNetConnection.Connect.SSLHandshakeFailedNetConnection.Connect.SSLNotAvailableNetConnection.Connect.ProxyAuthFailedCONNECT %s:%d HTTP/1.1127.0.0.1fpadPort.Unmuted.MutedCamera.UnmutedCamera.MutedMicrophone.UnmutedMicrophone.Muted/bin/flashhelp.cgi~&\;:"',? #macromedia.com/support/flashplayer/sys/SharedObject.FailedSharedObject.Flush.FailedSharedObject.Flush.SuccesshXXp://%shXXp://a.SharedObject.BadPersistenceSharedObject.UriMismatchNetConnection.Connect.FailedNetConnection.Connect.SuccessNetConnection.Connect.ClosedportpageUrltcUrlswfUrlHTTPS@NetStream.Buffer.FlushNetStream.Buffer.FullNetStream.Buffer.EmptyNetStream.Play.StopNetStream.Play.StartNetStream.Unpause.NotifyNetStream.Pause.Notifyb?NetStream.Play.NoSupportedTrackFoundNetStream.Play.FileStructureInvalidNetStream.Seek.NotifyNetStream.Seek.InvalidTimeNetStream.Play.StreamNotFoundNetStream.Publish.BadNameNetStream.Play.FailedHttpEndRequestAHttpSendRequestExAHttpAddRequestHeadersAFileReference.uploadFileReference.downloadFileReference.browseFileReferenceList.browsetrapAllKeysBitmapData.drawOperationoperationStrLoader.contentLoaderContext.checkPolicyFileLoaderContext.securityDomainLoader.loadLoaderInfo.loaderLoaderInfo.contentLocalConnection.sendLocalConnection.connectNetConnection.connectNetStream.playkeyDownkeyFocusChangekeyUphttpStatusnavigateToURLsendToURLhXXp://VVV.adobe.com/2006/actionscript/flash/proxySharedObject.getLocalSharedObject.getRemote.connectSound.loadSound.id3@SoundMixer.computeSpectrumStage.removeChildAtStage.swapChildrenAtflash.textURLStream.loadOleAut32.dllq.CUN3C4294967295@wKA%2:%2:%2 %cM%2:%2:%2 GMT%c%2%2%3 %3 %d %d%3 %3 %d %2:%2:%2 %d UTC%3 %3 %d %d %2:%2:%2 %cM-2147483648hXXp://VVV.w3.org/XML/1998/namespacebuiltin.as$0hasOwnProperty!hXXp://adobe.com/AS3/2006/builtinBoolean.prototype.toStringBoolean.prototype.valueOfNumber.prototype.toStringNumber.prototype.valueOfint.prototype.toStringint.prototype.valueOfuint.prototype.toStringuint.prototype.valueOfString.prototype.toStringString.prototype.valueOfRETURNINDEXEDARRAYjoin_joinbuiltin.as$0:MethodClosureMath.as$1Error.as$2RegExp.as$3Date.as$4XML.as$5QName.prototype.toString((('&%$#"!*{?.cu!,"/%0&3%4&7-8.;-<.>O=P>SATBWAXB[I\J_I`JcMdNgMhNkUlVoUpVsYtZwYxZ{]|^$ 29:3,%&-4;7?#)0*$%&' 12,-./3894567:;?!""##$$%%%&&&''''#%*,!"$(' -.mscoree.dll- This application cannot run using the active version of the Microsoft .NET RuntimePlease contact the application's support team for more information.internal state. The program cannot safely continue execution and mustcontinue execution and must now be terminated.GetProcessWindowStatione:\flashfarm\depot\main\player\branches\FlashPlayer\FlashPlayer9_DotReleases\platform\win32\standalone\Release\FlashPlayer.pdbWININET.dllCertVerifySubjectCertificateContextCertFindCertificateInStoreCertCreateCertificateContextCryptGetMessageCertificatesCRYPT32.dllVERSION.dllWINMM.dllOLEAUT32.dllGetCPInfoKERNEL32.dllGetKeyboardLayoutGetKeyStateMapVirtualKeyAUSER32.dllGDI32.dllcomdlg32.dllADVAPI32.dllSHELL32.dllole32.dllWS2_32.dllGetProcessHeapFlashPlayer.exepcre_exect.ZgN2_:~.Oo 0flash.utilsflash.debuggeradobe.utilsMMExecuteflash.profilerflash.netURLRequestsendToURL"flash.errors:IllegalOperationErrorflash.errorsIllegalOperationErrorflash.errors:IOErrorflash.errors:MemoryErrorflash.errors:StackOverflowErrorflash.errors:ScriptTimeoutErrorflash.errors:InvalidSWFErrorflash.errors:EOFErrorflash_errors.as$1flash.text:CSMSettingsCSMSettings.as$3CSMSettings flash.net:IDynamicPropertyOutputIDynamicPropertyOutput flash.net:IDynamicPropertyWriterflash.utils:IExternalizableflash.displayIBitmapDrawable!flash.accessibility:Accessibilityflash.accessibilityAccessibility.as$12/flash.accessibility:AccessibilityImplementationstub!AccessibilityImplementation.as$13flash.geomExcludeClass flash.accessibility:AccessibilityPropertiesAccessibilityProperties.as$14flash.system:ApplicationDomainflash.systemApplicationDomain.as$16flash.geom:ColorTransformColorTransform.as$23concat flash.ui:ContextMenuBuiltInItemsflash.uiContextMenuBuiltinItems.as$26adobe.utils:CustomActionsCustomActions.as$29flash.utils:EndianEndian.as$32flash.utils:IDataInputflash.utils:IDataOutputwriteObject'flash.filters:DisplacementMapFilterModeflash.filtersDisplacementMapFilterMode.as$37flash.display:BlendModeBlendMode.as$39flash.events:Eventflash.eventsEvent.as$43flash.events:EventPhaseEventPhase.as$44 flash.external:ExternalInterfaceExternalInterface.as$46flash.external_evalJS.__flash__addCallback(document.getElementById("document.getElementById("").SetReturnValue(; } catch (e) { 6").SetReturnValue("" e "");"").SetReturnValue("");#"" e "";FSCommand.as$47flash.system:FSCommandflash.net:FileFilterFileFilter.as$48flash.text:FontFont.as$52flash.text:FontTypeFontType.as$53flash.display:GraphicsGraphics.as$58flash.display:GradientTypeGradientType.as$59flash.display:SpreadMethodSpreadMethod.as$60!flash.display:InterpolationMethodInterpolationMethod.as$61flash.display:LineScaleModeLineScaleMode.as$62flash.display:CapsStyleCapsStyle.as$63flash.display:JointStyleJointStyleJointStyle.as$64flash.events:IEventDispatcherflash.display:BitmapDataChannelBitmapDataChannel.as$69flash.filters:BitmapFilterBitmapFilter.as$70flash.filters:BitmapFilterTypeBitmapFilterType.as$71!flash.filters:BitmapFilterQualityBitmapFilterQuality.as$72flash.display:PixelSnappingPixelSnapping.as$74flash.ui:KeyboardKeyboardKeyboard.as$77flash.ui:KeyLocationKeyLocationKeyLocation.as$78flash.text:TextLineMetricsTextLineMetrics.as$80flash.system:SecurityDomainSecurityDomain.as$83flash.system:LoaderContextLoaderContext.as$84flash.geom:MatrixMatrix.as$87flash.ui:MouseMouse.as$91flash.display:SceneScene.as$94flash.display:FrameLabelFrameLabel.as$95flash.net:ObjectEncodingObjectEncoding.as$101flash.geom:PointPoint.as$102flash.printing:PrintJobOptionsPrintJobOptions.as$104flash.printingPrintJobOptions"flash.printing:PrintJobOrientationPORTRAITPrintJobOrientation.as$105flash.display:SWFVersionSWFVersion.as$106!flash.display:ActionScriptVersionActionScriptVersion.as$107flash.utils:ProxyProxy.as$1112hXXp://VVV.adobe.com/2006/actionscript/flash/proxyflash.geom:RectangleRectangle.as$112flash.net:ResponderResponder.as$113flash.system:SecuritySecurity.as$114flash.system:SecurityPanelSecurityPanel.as$115flash.media:ID3Infoflash.mediaID3Info.as$121flash.media:SoundLoaderContextSoundLoaderContext.as$122flash.media:SoundTransformSoundTransform.as$124flash.media:SoundMixerSoundMixer.as$125flash.display:StageAlignStageAlign.as$127flash.display:StageDisplayStateStageDisplayState.as$128flash.display:StageQualityStageQuality.as$129flash.display:StageScaleModeStageScaleMode.as$130flash.system:SystemSystem.as$135flash.system:CapabilitiesCapabilities.as$136flash.system:IMEConversionModeIMEConversionMode.as$138flash.text:TextExtentTextExtent.as$139flash.text:TextFieldAutoSizeTextFieldAutoSize.as$141flash.text:TextFieldTypeTextFieldType.as$142flash.text:TextFormatTextFormat.as$143flash.text:TextFormatDisplayTextFormatDisplay.as$144flash.text:TextFormatAlignTextFormatAlign.as$145flash.text:TextRendererTextRenderer.as$146flash.text:AntiAliasTypeAntiAliasType.as$147!flash.net:SharedObjectFlushStatusSharedObjectFlushStatus.as$148flash.text:GridFitTypeGridFitType.as$149flash.text:TextColorTypeTextColorType.as$150flash.text:TextDisplayModeTextDisplayMode.as$151flash.text:FontStyleFontStyle.as$152flash.text:TextRunTextRun.as$153flash.text:TextSnapshotTextSnapshot.as$154flash.geom:TransformTransform.as$158flash.net:URLLoaderDataFormatURLLoaderDataFormatURLLoaderDataFormat.as$160flash.net:URLRequestURLRequest.as$161flash.net:URLRequestHeaderURLRequestHeader.as$162URLRequestHeaderflash.net:URLRequestMethodURLRequestMethodURLRequestMethod.as$163flash.net:URLVariablesURLVariables.as$165URLVariablesflash.xml:XMLNodeflash.xmlXMLNode.as$167flash.xml:XMLNodeTypeXMLNodeType.as$168flash.xml:XMLParserXMLParser.as$170flash.xml:XMLTagXMLTag.as$172Sampler.as$173flash.samplerflash.sampler:StackFrameflash.sampler:Sampleflash.sampler:NewObjectSampleNewObjectSample flash.sampler:DeleteObjectSampleadobe.utils:XMLUIXMLUI.as$174flash.trace:Traceflash.traceTrace.as$175flash.utils:DictionaryDictionary.as$176flash.net:DynamicPropertyOutputDynamicPropertyOutput.as$7flash.display:BitmapDataBitmapData.as$68flash.utils:ObjectInputObjectInput.as$5flash.utils:ObjectOutputObjectOutput.as$4flash.utils:ByteArrayByteArray.as$20flash.events:ActivityEventActivityEvent.as$15flash.events:TextEventTextEvent.as$30flash.events:FocusEventKEY_FOCUS_CHANGEFocusEvent.as$51m_shiftKeym_keyCodeshiftKeykeyCodeflash.events:HTTPStatusEventHTTP_STATUSHTTPStatusEvent.as$65HTTPStatusEventflash.events:KeyboardEventKEY_DOWNKEY_UPKeyboardEvent.as$79m_keyLocationm_ctrlKeym_altKeyKeyboardEventkeyLocationctrlKeyaltKeyflash.events:ContextMenuEventContextMenuEvent.as$88flash.events:MouseEventMouseEvent.as$92flash.events:NetStatusEventNetStatusEvent.as$98flash.events:NetFilterEventNetFilterEvent.as$100flash.events:ProgressEventProgressEvent.as$110flash.events:StatusEventStatusEvent.as$132flash.events:SyncEventSyncEvent.as$134flash.events:TimerEventTimerEvent.as$157flash.events:WeakMethodClosureWeakMethodClosure flash.events:WeakFunctionClosureflash.events:EventDispatcherEventDispatcher.as$45flash.events.Eventflash.filters:BevelFilterBevelFilter.as$17flash.filters:BlurFilterBlurFilter.as$18flash.filters:ColorMatrixFilterColorMatrixFilter.as$22flash.filters:ConvolutionFilterConvolutionFilter.as$28ConvolutionFilter#flash.filters:DisplacementMapFilterDisplacementMapFilter.as$36flash.filters:DropShadowFilterDropShadowFilter.as$40flash.filters:GlowFilterGlowFilter.as$55GlowFilter!flash.filters:GradientBevelFilterGradientBevelFilter.as$56GradientBevelFilter flash.filters:GradientGlowFilterGradientGlowFilter.as$57flash.xml:XMLDocumentXMLDocument.as$169flash.events:FullScreenEventFullScreenEvent.as$54flash.events:DataEventDataEvent.as$31flash.events:ErrorEventErrorEvent.as$42flash.events:IMEEventImeEvent.as$75flash.media:CamerasetKeyFrameIntervalCamera.as$21flash.events.StatusEventflash.events.ActivityEventflash.ui:ContextMenuContextMenu.as$25flash.events.ContextMenuEventflash.ui:ContextMenuItemContextMenuItem.as$27flash.display:DisplayObjectDisplayObject.as$38flash.net:FileReferenceFileReference.as$49flash.events.DataEventflash.events.HTTPStatusEventflash.events.SecurityErrorEventflash.events.ProgressEventflash.events.IOErrorEventflash.net:FileReferenceListFileReferenceList.as$50flash.display:LoaderInfoLoaderInfo.as$82loaderURLflash.net:LocalConnectionLocalConnection.as$85flash.events.AsyncErrorEventflash.media:MicrophoneMicrophone.as$89flash.net:NetConnectionNetConnection.as$97flash.events.NetStatusEventflash.net:NetStreamNetStream.as$99flash.printing:PrintJobPrintJob.as$103adobe.utils:ProductManagerProductManager.as$108flash.events.ErrorEventflash.net:SharedObjectSharedObject.as$118flash.events.SyncEventflash.net:SocketSocket.as$119flash.media:SoundSound.as$120flash.media:SoundChannelleftPeakSoundChannel.as$123flash.text:StyleSheetStyleSheet.as$133flash.system:IMEIME.as$137flash.events.IMEEventflash.utils:TimerTimer.as$155flash.events.TimerEventflash.net:URLLoaderURLLoader.as$159URLStreamURLLoaderflash.net:URLStreamURLStream.as$164flash.net:XMLSocketXMLSocket.as$171flash.events:AsyncErrorEventAsyncErrorEvent.as$41flash.events:IOErrorEventIOErrorEvent.as$67flash.events:SecurityErrorEventSecurityErrorEvent.as$116flash.display:AVM1MovieAVM1Movie.as$11flash.display:IBitmapDrawableflash.display:BitmapBitmap.as$73flash.display:InteractiveObjectInteractiveObject.as$76flash.events.KeyboardEventflash.events.MouseEventflash.events.FocusEventflash.display:MorphShapeMorphShape.as$90flash.display:ShapeShape.as$117flash.text:StaticTextStaticText.as$131flash.media:VideoVideo.as$166SetIntervalTimer.as$156flash.utils:SetIntervalTimerflash.display:SimpleButtonSimpleButton.as$19SimpleButton$flash.display:DisplayObjectContainerDisplayObjectContainer.as$24flash.text:TextFieldTextField.as$140alwaysShowSelectiondisplayAsPasswordflash.events.TextEventflash.display:LoaderLoader.as$81flash.display:SpriteSprite.as$93flash.display:StageStage.as$126flash.events.FullScreenEventflash.display:MovieClipMovieClip.as$96-./0123456789:;?f$,&a%dlf$,)a%dlf$, a%dlf$,3a%dlf$,-a%dlf$,/a%dl&!&!*! !.!.!b......AAf999999AA.AAAA......AAAA....AAA....AA...AAA...AA%9ss:V=#cEEc#=Vj.pO59999999%%%%%%%u%h%uuuu%hHB%%%%%%%uHB%%%%%uuuuJHB%%uuuuuuu#kH%uuuuuuuuuuuuuuuuuuH%uuuuuuuuuuuuuÃŒcz___}]]]}___}]]]}]]]}]]]}___z111111111C3@%u)
33s
:$.EJ
HR.ma
1333333333
..YLc.*
4:;;100`.
.BOOO
!),.:;?]}
\VVV.macromedia.com
r.exe
\Logs\codesign.txt
lWinHTTP AutoProxy Test
control.tlb
Adobe Flash Player has stopped a potentially unsafe operation.
Adobe Flash Player ha interrotto un'operazione potenzialmente pericolosa.
Adobe Flash Player ha detenido una operaci
Enter the World Wide Web location (URL) or specify the local file you would like to open.
Geben Sie die Internetadresse (URL) oder eine lokale Datei an, die Sie
cifiez l'adresse URL (World Wide Web) ou le fichier local
Passo &avanti
Specificare l'indirizzo (URL) dell'elemento da aprire.
n Web (URL) o especifique el archivo local que desee abrir.
World Wide Web
(URL)
Adobe Flash Player 9;Adobe Flash movie (*.swf)|*.swf;*.spl|All Files (*.*)|*.*||
Projector (*.exe)|*.exe||GCopyright
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Alle Dateien (*.*)|*.*||
Projektor (*.exe)|*.exe||KCopyright
ndern schwebend. Adobe und Flash sind Marken oder registrierte Marken in den USA und/oder anderen L
Adobe Flash Player 9CAdobe Flash movie (*.swf)|*.swf;*.spl|Tous les fichiers (*.*)|*.*||
Projection (*.exe)|*.exe||HCopyright
ricain 6.879.327 ; Brevets en cours aux
Adobe Flash Player 9>Adobe Flash movie (*.swf)|*.swf;*.spl|Tutti i file (*.*)|*.*||
Proiettore (*.exe)|*.exe||LCopyright
Adobe Flash Player 9DAdobe Flash movie (*.swf)|*.swf;*.spl|Todos los archivos (*.*)|*.*||
Proyector (*.exe)|*.exe||PCopyright
Adobe Flash Player 9:Adobe Flash movie (*.swf)|*.swf;*.spl|
(*.*)|*.*||
(*.exe)|*.exe||4Copyright (C) 1996-2007 Adobe Systems Incorporated. v
6,879,327
Adobe Flash Player 96Adobe Flash movie (*.swf)|*.swf;*.spl|
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.K
(*.exe)|*.exe||3Copyright (C) 1996-2007 Adobe Systems Incorporated.J
(*.*)|*.*||
(*.exe)|*.exe||ICopyright (C) 1996-2007 Adobe Systems Incorporated. All Rights Reserved.explorer.exe_3164_rwx_00290000_00001000:
KERNEL32.DLLexplorer.exe_3164_rwx_002D0000_00001000:
KERNEL32.DLLexplorer.exe_3164_rwx_00D20000_00001000:
advapi32.dllexplorer.exe_3164_rwx_00D50000_00001000:
RegOpenKeyAexplorer.exe_3164_rwx_00D60000_00001000:
advapi32.dllexplorer.exe_3164_rwx_00D90000_00001000:
gdi32.dllexplorer.exe_3164_rwx_00DE0000_00001000:
gdi32.dllexplorer.exe_3164_rwx_00E10000_00001000:
gdiplus.dllexplorer.exe_3164_rwx_00E50000_00001000:
gdiplus.dllexplorer.exe_3164_rwx_00F90000_00001000:
mpr.dllexplorer.exe_3164_rwx_00FD0000_00001000:
mpr.dllexplorer.exe_3164_rwx_01400000_00001000:
msacm32.dllexplorer.exe_3164_rwx_01540000_00001000:
msacm32.dllexplorer.exe_3164_rwx_01570000_00001000:
ntdll.dllexplorer.exe_3164_rwx_016B0000_00001000:
ntdll.dllexplorer.exe_3164_rwx_016E0000_00001000:
ole32.dllexplorer.exe_3164_rwx_01820000_00001000:
ole32.dllexplorer.exe_3164_rwx_01850000_00001000:
oleaut32.dllexplorer.exe_3164_rwx_01990000_00001000:
oleaut32.dllexplorer.exe_3164_rwx_019C0000_00001000:
powrprof.dllexplorer.exe_3164_rwx_01B00000_00001000:
powrprof.dllexplorer.exe_3164_rwx_01B30000_00001000:
shell32.dllexplorer.exe_3164_rwx_01C70000_00001000:
shell32.dllexplorer.exe_3164_rwx_01CA0000_00001000:
user32.dllexplorer.exe_3164_rwx_01DE0000_00001000:
user32.dllexplorer.exe_3164_rwx_01E10000_00001000:
version.dllexplorer.exe_3164_rwx_01F50000_00001000:
version.dllexplorer.exe_3164_rwx_01F80000_00001000:
wininet.dllexplorer.exe_3164_rwx_020B0000_00001000:
FtpOpenFileAexplorer.exe_3164_rwx_020C0000_00001000:
wininet.dllexplorer.exe_3164_rwx_020F0000_00001000:
winmm.dllexplorer.exe_3164_rwx_02230000_00001000:
winmm.dllexplorer.exe_3164_rwx_02260000_00001000:
wsock32.dllexplorer.exe_3164_rwx_023A0000_00001000:
wsock32.dllexplorer.exe_3164_rwx_02850000_00042000:
`.rsrc
kernel32.dll
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
u%CNu
%s[%d]
getservbyport
WSAAsyncGetServByPort
WSAJoinLeaf
WS2_32.DLL
127.0.0.1
TIdSocketListWindows
TIdStackWindowsU
IdStackWindows
ftpTransfer
ftpReady
ftpAborted
ClientPortMinClientPortMaxhPortEIdCanNotBindPortInRangeEIdInvalidPortRangeSVWsaUsernamePasswordPasswordPorth0.0.0.1TIdTCPConnectionTIdTCPConnection|IdTCPConnectionEIdTCPConnectionErrorEIdObjectTypeNotSupportedZ:\CyberGate\Personal Edition v1.x\Workplace\v1.x\3.4.2.2\Client\Indy\IdStrings.pasTIdTCPServerIdTCPServerCmdDelimiterhTIdTCPServerConnectionDefaultPortOnExecuteXLEIdTCPServerErrorEIdNoExecuteSpecifiedTIdTCPClientTIdTCPClientptIdTCPClientBoundPorthPortUTOnHTTPDocumentTIdHTTPProxyServerIdHTTPProxyServerOnHTTPDocumentHTTP/1.0Windows Firewall Update1.2.3deflate 1.2.3 Copyright 1995-2005 Jean-loup GaillyKWindowsIdTCPStreamIdTCPServerDIdHTTPProxyServerGetCPInfoRegOpenKeyExARegCloseKeyRegFlushKeyRegCreateKeyExAGetKeyboardTypeMsgWaitForMultipleObjects((&)))!&$"#$$&-)01$$'&,--%.&,4\@%c.idata.edataP.relocP.rsrcvKey'P.reKERNEL32.DLLadvapi32.dlluser32.dllwsock32.dllfuncoes.dllStartHttpProxyCommand not supported.Address type not supported.;Cannot call TerminateAndWaitFor on FreeAndTerminate threadsSocket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.Protocol not supported.Socket type not supported."Operation not supported on socket.Protocol family not supported.0Address family not supported by protocol family.%s is not a valid service.Socket Error # %dOperation would block.Operation now in progress.Operation already in progress.Socket operation on non-socket.Object type not supported.No execute handler found.No data to read.$Can not bind in port range (%d - %d)Invalid Port Range (%d - %d)No command handler found.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)Resolving hostname %s.Connecting to %s.%s.Seek not implemented$Operation not allowed on sorted listProperty %s does not existThread creation error: %sThread Error: %s (%d)Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.File "%s" not found1Only one TIdAntiFreeze can exist per application.#A component named %s already exists%String list does not allow duplicatesCannot create file "%s". %sCannot open file "%s". %s$''%s'' is not a valid component nameInvalid property value List capacity out of bounds (%d)List count out of bounds (%d)List index out of bounds (%d) Out of memory while expanding memory streamError reading %s%s%s: %sFailed to set data for '%s'Ancestor for '%s' not foundCannot assign a %s to a %sECheckSynchronize called from thread $%x, which is NOT the main threadClass %s not found%List does not allow duplicates ($0%x)%s (%s, line %d)Abstract Error?Access violation at address %p in module '%s'. %s of address %pSystem Error. Code: %d.Invalid variant operation%Invalid variant operation (%s%.8x)%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)Operation not supportedExternal exception %xInterface not supportedInvalid pointer operationInvalid class typecast0Access violation at address %p. %s of address %pPrivileged instruction(Exception %s in module %s at %p.Application Error1Format '%s' invalid or incompatible with argumentNo argument for format '%s'"Variant method calls not supported!'%s' is not a valid integer valueI/O error %dInteger overflow Invalid floating point operationexplorer.exe_3164_rwx_029A0000_00042000:`.rsrckernel32.dll$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)oleaut32.dllEVariantBadIndexErroru%CNu%s[%d]getservbyportWSAAsyncGetServByPortWSAJoinLeafWS2_32.DLL127.0.0.1TIdSocketListWindowsTIdStackWindowsUIdStackWindowsftpTransferftpReadyftpAbortedClientPortMinClientPortMaxhPortEIdCanNotBindPortInRangeEIdInvalidPortRangeSVWsaUsernamePasswordPasswordPorth0.0.0.1TIdTCPConnectionTIdTCPConnection|IdTCPConnectionEIdTCPConnectionErrorEIdObjectTypeNotSupportedZ:\CyberGate\Personal Edition v1.x\Workplace\v1.x\3.4.2.2\Client\Indy\IdStrings.pasTIdTCPServerIdTCPServerCmdDelimiterhTIdTCPServerConnectionDefaultPortOnExecuteXLEIdTCPServerErrorEIdNoExecuteSpecifiedTIdTCPClientTIdTCPClientptIdTCPClientBoundPorthPortUTOnHTTPDocumentTIdHTTPProxyServerIdHTTPProxyServerOnHTTPDocumentHTTP/1.0Windows Firewall Update1.2.3deflate 1.2.3 Copyright 1995-2005 Jean-loup GaillyKWindowsIdTCPStreamIdTCPServerDIdHTTPProxyServerGetCPInfoRegOpenKeyExARegCloseKeyRegFlushKeyRegCreateKeyExAGetKeyboardTypeMsgWaitForMultipleObjects((&)))!&$"#$$&-)01$$'&,--%.&,4\@%c.idata.edataP.relocP.rsrcvKey'P.reKERNEL32.DLLadvapi32.dlluser32.dllwsock32.dllfuncoes.dllStartHttpProxyCommand not supported.Address type not supported.;Cannot call TerminateAndWaitFor on FreeAndTerminate threadsSocket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.Protocol not supported.Socket type not supported."Operation not supported on socket.Protocol family not supported.0Address family not supported by protocol family.%s is not a valid service.Socket Error # %dOperation would block.Operation now in progress.Operation already in progress.Socket operation on non-socket.Object type not supported.No execute handler found.No data to read.$Can not bind in port range (%d - %d)Invalid Port Range (%d - %d)No command handler found.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)Resolving hostname %s.Connecting to %s.%s.Seek not implemented$Operation not allowed on sorted listProperty %s does not existThread creation error: %sThread Error: %s (%d)Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.File "%s" not found1Only one TIdAntiFreeze can exist per application.#A component named %s already exists%String list does not allow duplicatesCannot create file "%s". %sCannot open file "%s". %s$''%s'' is not a valid component nameInvalid property value List capacity out of bounds (%d)List count out of bounds (%d)List index out of bounds (%d) Out of memory while expanding memory streamError reading %s%s%s: %sFailed to set data for '%s'Ancestor for '%s' not foundCannot assign a %s to a %sECheckSynchronize called from thread $%x, which is NOT the main threadClass %s not found%List does not allow duplicates ($0%x)%s (%s, line %d)Abstract Error?Access violation at address %p in module '%s'. %s of address %pSystem Error. Code: %d.Invalid variant operation%Invalid variant operation (%s%.8x)%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)Operation not supportedExternal exception %xInterface not supportedInvalid pointer operationInvalid class typecast0Access violation at address %p. %s of address %pPrivileged instruction(Exception %s in module %s at %p.Application Error1Format '%s' invalid or incompatible with argumentNo argument for format '%s'"Variant method calls not supported!'%s' is not a valid integer valueI/O error %dInteger overflow Invalid floating point operationexplorer.exe_3164_rwx_10480000_00070000:`.rsrckernel32.dllPortions Copyright (c) 1999,2003 Avenger by NhTSHFileOperationAshell32.dllURLDownloadToFileAurlmon.dllShellExecuteASOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersGetWindowsDirectoryASOFTWARE\Microsoft\Windows\CurrentVersion\Internet Explorer\iexplore.exe####@####AVKWCtlX64.exeAVKWCtl.exeavgnt.exeavp.exembam.exea2service.exeVba32arkit.exeClamWin.exeavesvc.exeashdisp.exeavgcc.exebdss.exespider.exekavsvc.exenod32krn.execclaw.exedvpapi.exeewidoctrl.exemcshield.exepavfires.exealmon.execcapp.exepccntmon.exefssm32.exeekrn.execcSvcHst.exeavgrsx.exeegui.exePSUNMAIN.exeSSScheduler.exeDr.WebGDFwSvcx64.exeGDFwSvc.exeavfwsvc.exeoacat.exeissvc.exevsmon.execpf.execa.exetnbutil.exekavpf.exempfservice.exenpfmsg.exeoutpost.exetpsrv.exekpf4ss.exepersfw.exevsserv.exesmc.exeop_mon.exe$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)PortugalTurkeyFirstExecutionWindows 3.1Windows 95 (Release 2)Windows 95Windows 98 SEWindows 98Windows MEWindows 7Windows Vista%s %sWindows XP Professional x64Windows XP HomeWindows XP ProfessionalWindows 2000 ProfessionalWindows NT %d.%dWindows 2008%s %s ServerWindows 2003 Server DatacenterWindows 2003 Server EnterpriseWindows 2003 Server Web EditionWindows 2003 ServerWindows Home ServerWindows 2003 Server (Release 2)Windows 2000 Server DatacenterWindows 2000 Server EnterpriseWindows 2000 Server Web EditionWindows 2000 ServerWindows NT 4.0 Server DatacenterWindows NT 4.0 Server EnterpriseWindows NT 4.0 Server Web EditionWindows NT 4.0 ServerUnknown Platform ID (%d)%d.%d%s (Build: %d- Service Pack: %sKERNEL32.DLLv3.4.2.2Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)Set objFileSystem = CreateObject("Scripting.fileSystemObject")Set objFile = objFileSystem.CreateTextFile("Info = Info & "F" & CountFw & ") " & objFirewall.displayName & EnterInfo = Info & "A" & CountAV & ") " & objAntiVirus.displayName & EnterobjFile.WriteLine(Info)objFile.Closecscript.exeAVICAP32.dllBuildImportTable: can't load library:BuildImportTable: ReallocMemory failedBuildImportTable: GetProcAddress failedBTMemoryLoadLibary: BuildImportTable failedBTMemoryGetProcAddress: no export table foundBTMemoryGetProcAddress: DLL doesn't export anythingBTMemoryGetProcAddress: exported symbol not foundSetupApi.dllSetupDiOpenClassRegKeySetupDiOpenClassRegKeyExASetupDiOpenClassRegKeyExWSetupDiCreateDeviceInterfaceRegKeyASetupDiCreateDeviceInterfaceRegKeyWSetupDiOpenDeviceInterfaceRegKeySetupDiDeleteDeviceInterfaceRegKeySetupDiCreateDevRegKeyASetupDiCreateDevRegKeyWSetupDiOpenDevRegKeySetupDiDeleteDevRegKeyCM_DEVCAP_LOCKSUPPORTEDCM_DEVCAP_EJECTSUPPORTEDPDCAP_D0_SUPPORTEDPDCAP_D1_SUPPORTEDPDCAP_D2_SUPPORTEDPDCAP_D3_SUPPORTEDPDCAP_WAKE_FROM_D0_SUPPORTEDPDCAP_WAKE_FROM_D1_SUPPORTEDPDCAP_WAKE_FROM_D2_SUPPORTEDPDCAP_WAKE_FROM_D3_SUPPORTEDPDCAP_WARM_EJECT_SUPPORTEDHKEY_CLASSES_ROOTHKEY_CURRENT_CONFIGHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_USERS127.0.0.1iphlpapi.dllAllocateAndGetTcpExTableFromStackAllocateAndGetUdpExTableFromStackSetTcpEntryGetExtendedTcpTableGetExtendedUdpTableConnectWebcamDisconnectWebcamListWebcamsCaptureWebcamIsWebcamConnectedStartHttpProxy1.2.3keyboardkeywebcaminactivewebcamgetbufferwebcamwebcamstartcheckwebcamfilecheckwebcamfilebackwebcamdllloadedenviarexecnormalenviarexechiddenopenwebopenwebpageopenwebhiddendownexecsendftpkeyloggerkeyloggergetlogkeyloggereraselogkeyloggerativarkeyloggerdesativarrenamekeywindowsfecharwindowsmaxwindowsminwindowsmostrarwindowsocultarwindowsmintodaswindowscaptionlistarportaslistarportasdnsfinalizarprocessoportaswebcamsettingschatmsggetpasswordupdateservidorwebkeyloggersearchurlredirecturlredirecttrueonlinekeyloggereraselogonlinekeyloggerstartonlinekeyloggerstoponlinekeyloggererrorkeyloggerlisttFtpAccessonlinekeyloggerstart|onlinekeyloggerstart|SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAPI.dll%SYS%ÞSKTOP%TPasswordItemTArrayPasswodsqlite3_opensqlite3_prepare_v2sqlite3_column_textsqlite3_stepsqlite3_closesqlite3_column_blobsqlite3_column_bytesCrypt32.dllole32.dllAdvapi32.dllSOFTWARE\Wow6432Node\Mozilla\Mozilla FirefoxSOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\SOFTWARE\MOZILLA\MOZILLA FIREFOXSOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Mainmozcrt19.dllmozglue.dllnspr4.dllplc4.dllplds4.dllnssutil3.dllmozsqlite3.dllnss3.dllPK11_GetInternalKeySlot\Mozilla\Firefox\profiles.ini\Mozilla\Firefox\signons.sqliteselect * from moz_loginsFirefoxSOFTWARE\MOZILLA\MOZILLA FIREFOX\sqlite3.dll\Flock\Browser\profiles.iniFlock-Firefox\1-abc\personal calendar\sqlite3.dll\clipdiary\sqlite3.dll\conceptworld\recentx\sqlite3.dll\darq software\transmute\sqlite3.dll\delphish\sqlite3.dll\ditto\sqlite3.dll\du meter\sqlite3.dll\fcleaner\sqlite3.dll\file seeker\sqlite3.dll\flashnote\sqlite3.dll\flashpaste\sqlite3.dll\gorecord\sqlite3.dll\gorecord2\sqlite3.dll\linkcollector portable\sqlite3.dll\ma-config.com\sqlite3.dll\macrovirus\sqlite3.dll\msnsniffer2\sqlite3.dll\notecable\sqlite3.dll\nzbleecher\sqlite3.dll\outlook express\sqlite3.dll\page update watcher\sqlite3.dll\pipi\sqlite3.dll\qloud\sqlite3.dll\qloud\winamp\sqlite3.dll\qloud\windows media player\sqlite3.dll\recordtheradio\sqlite3.dll\rightload\sqlite3.dll\smm\funny sms10\sqlite3.dll\smm\simple mail 7\sqlite3.dll\spiceworks\bin\sqlite3.dll\spyware-secure\sqlite3.dll\timelog\sqlite3.dll\video2webcam\sqlite3.dll\webmarkers\sqlite3.dll\webmediaplayer\sqlite3.dll\windows media player\plugins\qloud\sqlite3.dll\Mozilla Firefox\sqlite3.dll\VirusGuardPlus\sqlite3.dll\Safari\sqlite3.dll\AIMP2\sqlite3.dll\Live-Player\sqlite3.dll\TrustedProtection\sqlite3.dll\PCTotalDefender\sqlite3.dll\Common Files\eEye Digital Security\Application Bus\sqlite3.dllSELECT * FROM loginsGoogle ChromeFlock-Chrome\Mozilla Firefox\mozcrt19.dllGoogle\Chrome\User Data\Default\Login DataWeb DataWindowsLive:name=*Windows Live MessengerPasswordDynDNS\Updater\config.dyndnsPassword=Software\DownloadManager\PasswordsSoftware\DownloadManager\Passwords\EncPasswordYLoginWndFileZilla\recentservers.xmlFileZilla\sitemanager.xmlFileZilla\filezilla.xml.purple\accounts.xmlabe2869f-9b47-4cd9-a358-c22904dba7f7%UUUU1E%UUUU3U_GrabOperaOpera|WandData :wand.datOpera\trillian.iniaccounts.inipasswordprofiles.iniSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrillianTrillian\trillian.exeTPasswordGrabSV%s|%s|%s|%s|%s|chatmsg|xXx_key_xXx-wchelper.dllSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Runlistarjanelas|windowsfechar|listarjanelas|windowsmax|listarjanelas|windowsmin|listarjanelas|windowsmostrar|listarjanelas|windowsocultar|listarjanelas|windowsmintodas|listarjanelas|windowscaption|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstalllistarportas|listadeportaspronta|listarportas|finalizarconexao|listarportas|finalizarprocessoportas|Y|listarportas|finalizarprocessoportas|N|URL_VISITORregistro|renamekey|Key name has been successfully changedUnable to change key nameregistro|registro|Key name has been successfully changed|"registro|registro|Unable to change key name|"registro|registro|The key or value has been deleted successfully|"registro|registro|Unable to delete key or value|"registro|registro|The key was created successfully|"registro|registro|Could not create key|"keylogger|keyloggerlist|ak.tmponlinekeyloggerstart|onlinekeyloggererror|keylogger|keylogger|keyloggerativar|keylogger|keylogger|keyloggerdesativar|keylogger|keyloggergetlog|keylogger|keylogger|keyloggervazio|keyloggersearchok|checkwebcamfileback|webcamdlltransferdone|webcam|webcaminactive|webcamdllloaded|checkwebcamfile|no|webcam|webcamactive|webcam|webcamstop|getpassword|getpasswordlist|USER32.DLLC:\Windows\System32\drivers\etc\hoststemp.vbsliststartup|renamekey|liststartup|liststartup|Key name has been successfully changed|"liststartup|liststartup|Unable to change key name|"liststartup|liststartup|The key or value has been deleted successfully|"liststartup|liststartup|Unable to delete key or value|"liststartup|liststartup|The key was created successfully|"liststartup|liststartup|Could not create key|"deflate 1.2.3 Copyright 1995-2005 Jean-loup Gaillyinflate 1.2.3 Copyright 1995-2005 Mark AdlerKWindowsU_GrabPassword8U_GrabOpera\U_GrabChrome6U_GrabFirefox.UnitBytesSizeYU_GrabFirefox8U_GrabFirefox10UnitExecutarComandosUrlMonuftpUnitListarPortasAtivasUnitKeyloggerGetProcessHeapWinExecSetNamedPipeHandleStateCreatePipeRegOpenKeyExARegOpenKeyARegEnumKeyExARegDeleteKeyARegCreateKeyARegCloseKeyGdiplusShutdownShellExecuteExAkeybd_eventMsgWaitForMultipleObjectsMapVirtualKeyExAMapVirtualKeyAGetKeyboardStateGetKeyboardLayoutNameAGetKeyboardLayoutGetKeyStateGetAsyncKeyStateExitWindowsExEnumWindowsInternetOpenUrlAFtpGetFileSizeFtpSetCurrentDirectoryAFtpOpenFileA9!!!$'')#&!!$'''#.idata.relocP.rsrcadvapi32.dllgdi32.dllgdiplus.dllmpr.dllmsacm32.dllntdll.dlloleaut32.dllpowrprof.dlluser32.dllversion.dllwininet.dllwinmm.dllwsock32.dllserver.exe_3420_rwx_00608000_0006C000:.idata.rdataP.relocP.rsrc####@####kernel32.dllShellExecuteAshell32.dllSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersGetWindowsDirectoryASOFTWARE\Microsoft\Windows\CurrentVersionC:\default.htmlPSAPI.dllVBoxService.exeSbieDll.dlldbghelp.dllSoftware\Microsoft\Windows\CurrentVersion55274-640-2673064-2395076487-644-3177037-2351076487-337-8429955-22614\\.\Syser\\.\SyserDbgMsg\\.\SyserBoot\\.\SICE\\.\NTICESoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunSoftware\Microsoft\Windows\CurrentVersion\Runexplorer.exeuser32.dllGetKeyboardTypeadvapi32.dllRegOpenKeyExARegCloseKeyoleaut32.dllRegDeleteKeyARegCreateKeyExARegCreateKeyAMsgWaitForMultipleObjectsFindExecutableA?*?/?]?}?####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@########@#### ####@########@#### ####@#### ####@#### ####@########@#### ####@#### ####@########@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@#### ####@####y.YZJOnr.AQE.naM$T.GNR:\JDR%fLJg>.RW$Az.ScQw>%UPRiz<.mj>2X.jtL\X%X,``%XXTTD*/.TdiL.In:|kNd/.zkKWindowsExplorer.EXE_1948_rwx_01100000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_01340000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_01BA0000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_01C40000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_02220000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_022E0000_00001000:KERNEL32.DLLExplorer.EXE_1948_rwx_02510000_00001000:advapi32.dllExplorer.EXE_1948_rwx_02640000_00001000:RegOpenKeyAExplorer.EXE_1948_rwx_02650000_00001000:advapi32.dllExplorer.EXE_1948_rwx_02680000_00001000:gdi32.dllExplorer.EXE_1948_rwx_027C0000_00001000:gdi32.dllExplorer.EXE_1948_rwx_027F0000_00001000:gdiplus.dllExplorer.EXE_1948_rwx_02930000_00001000:gdiplus.dllExplorer.EXE_1948_rwx_02960000_00001000:mpr.dllExplorer.EXE_1948_rwx_02AA0000_00001000:mpr.dllExplorer.EXE_1948_rwx_02AD0000_00001000:msacm32.dllExplorer.EXE_1948_rwx_02C10000_00001000:msacm32.dllExplorer.EXE_1948_rwx_02C40000_00001000:ntdll.dllExplorer.EXE_1948_rwx_02D80000_00001000:ntdll.dllExplorer.EXE_1948_rwx_02DB0000_00001000:ole32.dllExplorer.EXE_1948_rwx_02EF0000_00001000:ole32.dllExplorer.EXE_1948_rwx_02F20000_00001000:oleaut32.dllExplorer.EXE_1948_rwx_03060000_00001000:oleaut32.dllExplorer.EXE_1948_rwx_03090000_00001000:powrprof.dllExplorer.EXE_1948_rwx_031D0000_00001000:powrprof.dllExplorer.EXE_1948_rwx_03200000_00001000:shell32.dllExplorer.EXE_1948_rwx_03340000_00001000:shell32.dllExplorer.EXE_1948_rwx_03370000_00001000:user32.dllExplorer.EXE_1948_rwx_034B0000_00001000:user32.dllExplorer.EXE_1948_rwx_034E0000_00001000:version.dllExplorer.EXE_1948_rwx_03620000_00001000:version.dllExplorer.EXE_1948_rwx_03650000_00001000:wininet.dllExplorer.EXE_1948_rwx_03780000_00001000:FtpOpenFileAExplorer.EXE_1948_rwx_03790000_00001000:wininet.dllExplorer.EXE_1948_rwx_037C0000_00001000:winmm.dllExplorer.EXE_1948_rwx_03900000_00001000:winmm.dllExplorer.EXE_1948_rwx_03930000_00001000:wsock32.dllExplorer.EXE_1948_rwx_03A70000_00001000:wsock32.dllExplorer.EXE_1948_rwx_10410000_00070000:`.rsrckernel32.dllPortions Copyright (c) 1999,2003 Avenger by NhTSHFileOperationAshell32.dllURLDownloadToFileAurlmon.dllShellExecuteASOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersGetWindowsDirectoryASOFTWARE\Microsoft\Windows\CurrentVersion\Internet Explorer\iexplore.exe####@####AVKWCtlX64.exeAVKWCtl.exeavgnt.exeavp.exembam.exea2service.exeVba32arkit.exeClamWin.exeavesvc.exeashdisp.exeavgcc.exebdss.exespider.exekavsvc.exenod32krn.execclaw.exedvpapi.exeewidoctrl.exemcshield.exepavfires.exealmon.execcapp.exepccntmon.exefssm32.exeekrn.execcSvcHst.exeavgrsx.exeegui.exePSUNMAIN.exeSSScheduler.exeDr.WebGDFwSvcx64.exeGDFwSvc.exeavfwsvc.exeoacat.exeissvc.exevsmon.execpf.execa.exetnbutil.exekavpf.exempfservice.exenpfmsg.exeoutpost.exetpsrv.exekpf4ss.exepersfw.exevsserv.exesmc.exeop_mon.exe$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)PortugalTurkeyFirstExecutionWindows 3.1Windows 95 (Release 2)Windows 95Windows 98 SEWindows 98Windows MEWindows 7Windows Vista%s %sWindows XP Professional x64Windows XP HomeWindows XP ProfessionalWindows 2000 ProfessionalWindows NT %d.%dWindows 2008%s %s ServerWindows 2003 Server DatacenterWindows 2003 Server EnterpriseWindows 2003 Server Web EditionWindows 2003 ServerWindows Home ServerWindows 2003 Server (Release 2)Windows 2000 Server DatacenterWindows 2000 Server EnterpriseWindows 2000 Server Web EditionWindows 2000 ServerWindows NT 4.0 Server DatacenterWindows NT 4.0 Server EnterpriseWindows NT 4.0 Server Web EditionWindows NT 4.0 ServerUnknown Platform ID (%d)%d.%d%s (Build: %d- Service Pack: %sKERNEL32.DLLv3.4.2.2Set colFirewall = objSecurityCenter.ExecQuery("SELECT * FROM FirewallProduct","WQL",0)Set colAntiVirus = objSecurityCenter.ExecQuery("SELECT * FROM AntiVirusProduct","WQL",0)Set objFileSystem = CreateObject("Scripting.fileSystemObject")Set objFile = objFileSystem.CreateTextFile("Info = Info & "F" & CountFw & ") " & objFirewall.displayName & EnterInfo = Info & "A" & CountAV & ") " & objAntiVirus.displayName & EnterobjFile.WriteLine(Info)objFile.Closecscript.exeAVICAP32.dllBuildImportTable: can't load library:BuildImportTable: ReallocMemory failedBuildImportTable: GetProcAddress failedBTMemoryLoadLibary: BuildImportTable failedBTMemoryGetProcAddress: no export table foundBTMemoryGetProcAddress: DLL doesn't export anythingBTMemoryGetProcAddress: exported symbol not foundSetupApi.dllSetupDiOpenClassRegKeySetupDiOpenClassRegKeyExASetupDiOpenClassRegKeyExWSetupDiCreateDeviceInterfaceRegKeyASetupDiCreateDeviceInterfaceRegKeyWSetupDiOpenDeviceInterfaceRegKeySetupDiDeleteDeviceInterfaceRegKeySetupDiCreateDevRegKeyASetupDiCreateDevRegKeyWSetupDiOpenDevRegKeySetupDiDeleteDevRegKeyCM_DEVCAP_LOCKSUPPORTEDCM_DEVCAP_EJECTSUPPORTEDPDCAP_D0_SUPPORTEDPDCAP_D1_SUPPORTEDPDCAP_D2_SUPPORTEDPDCAP_D3_SUPPORTEDPDCAP_WAKE_FROM_D0_SUPPORTEDPDCAP_WAKE_FROM_D1_SUPPORTEDPDCAP_WAKE_FROM_D2_SUPPORTEDPDCAP_WAKE_FROM_D3_SUPPORTEDPDCAP_WARM_EJECT_SUPPORTEDHKEY_CLASSES_ROOTHKEY_CURRENT_CONFIGHKEY_CURRENT_USERHKEY_LOCAL_MACHINEHKEY_USERS127.0.0.1iphlpapi.dllAllocateAndGetTcpExTableFromStackAllocateAndGetUdpExTableFromStackSetTcpEntryGetExtendedTcpTableGetExtendedUdpTableConnectWebcamDisconnectWebcamListWebcamsCaptureWebcamIsWebcamConnectedStartHttpProxy1.2.3keyboardkeywebcaminactivewebcamgetbufferwebcamwebcamstartcheckwebcamfilecheckwebcamfilebackwebcamdllloadedenviarexecnormalenviarexechiddenopenwebopenwebpageopenwebhiddendownexecsendftpkeyloggerkeyloggergetlogkeyloggereraselogkeyloggerativarkeyloggerdesativarrenamekeywindowsfecharwindowsmaxwindowsminwindowsmostrarwindowsocultarwindowsmintodaswindowscaptionlistarportaslistarportasdnsfinalizarprocessoportaswebcamsettingschatmsggetpasswordupdateservidorwebkeyloggersearchurlredirecturlredirecttrueonlinekeyloggereraselogonlinekeyloggerstartonlinekeyloggerstoponlinekeyloggererrorkeyloggerlisttFtpAccessonlinekeyloggerstart|onlinekeyloggerstart|SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSAPI.dll%SYS%ÞSKTOP%TPasswordItemTArrayPasswodsqlite3_opensqlite3_prepare_v2sqlite3_column_textsqlite3_stepsqlite3_closesqlite3_column_blobsqlite3_column_bytesCrypt32.dllole32.dllAdvapi32.dllSOFTWARE\Wow6432Node\Mozilla\Mozilla FirefoxSOFTWARE\Wow6432Node\Mozilla\Mozilla Firefox\SOFTWARE\MOZILLA\MOZILLA FIREFOXSOFTWARE\MOZILLA\MOZILLA FIREFOX\version.dll\Mainmozcrt19.dllmozglue.dllnspr4.dllplc4.dllplds4.dllnssutil3.dllmozsqlite3.dllnss3.dllPK11_GetInternalKeySlot\Mozilla\Firefox\profiles.ini\Mozilla\Firefox\signons.sqliteselect * from moz_loginsFirefoxSOFTWARE\MOZILLA\MOZILLA FIREFOX\sqlite3.dll\Flock\Browser\profiles.iniFlock-Firefox\1-abc\personal calendar\sqlite3.dll\clipdiary\sqlite3.dll\conceptworld\recentx\sqlite3.dll\darq software\transmute\sqlite3.dll\delphish\sqlite3.dll\ditto\sqlite3.dll\du meter\sqlite3.dll\fcleaner\sqlite3.dll\file seeker\sqlite3.dll\flashnote\sqlite3.dll\flashpaste\sqlite3.dll\gorecord\sqlite3.dll\gorecord2\sqlite3.dll\linkcollector portable\sqlite3.dll\ma-config.com\sqlite3.dll\macrovirus\sqlite3.dll\msnsniffer2\sqlite3.dll\notecable\sqlite3.dll\nzbleecher\sqlite3.dll\outlook express\sqlite3.dll\page update watcher\sqlite3.dll\pipi\sqlite3.dll\qloud\sqlite3.dll\qloud\winamp\sqlite3.dll\qloud\windows media player\sqlite3.dll\recordtheradio\sqlite3.dll\rightload\sqlite3.dll\smm\funny sms10\sqlite3.dll\smm\simple mail 7\sqlite3.dll\spiceworks\bin\sqlite3.dll\spyware-secure\sqlite3.dll\timelog\sqlite3.dll\video2webcam\sqlite3.dll\webmarkers\sqlite3.dll\webmediaplayer\sqlite3.dll\windows media player\plugins\qloud\sqlite3.dll\Mozilla Firefox\sqlite3.dll\VirusGuardPlus\sqlite3.dll\Safari\sqlite3.dll\AIMP2\sqlite3.dll\Live-Player\sqlite3.dll\TrustedProtection\sqlite3.dll\PCTotalDefender\sqlite3.dll\Common Files\eEye Digital Security\Application Bus\sqlite3.dllSELECT * FROM loginsGoogle ChromeFlock-Chrome\Mozilla Firefox\mozcrt19.dllGoogle\Chrome\User Data\Default\Login DataWeb DataWindowsLive:name=*Windows Live MessengerPasswordDynDNS\Updater\config.dyndnsPassword=Software\DownloadManager\PasswordsSoftware\DownloadManager\Passwords\EncPasswordYLoginWndFileZilla\recentservers.xmlFileZilla\sitemanager.xmlFileZilla\filezilla.xml.purple\accounts.xmlabe2869f-9b47-4cd9-a358-c22904dba7f7%UUUU1E%UUUU3U_GrabOperaOpera|WandData :wand.datOpera\trillian.iniaccounts.inipasswordprofiles.iniSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TrillianTrillian\trillian.exeTPasswordGrabSV%s|%s|%s|%s|%s|chatmsg|xXx_key_xXx-wchelper.dllSoftware\Microsoft\Windows\CurrentVersion\RunSoftware\Microsoft\Windows\CurrentVersion\Policies\Explorer\Runlistarjanelas|windowsfechar|listarjanelas|windowsmax|listarjanelas|windowsmin|listarjanelas|windowsmostrar|listarjanelas|windowsocultar|listarjanelas|windowsmintodas|listarjanelas|windowscaption|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstalllistarportas|listadeportaspronta|listarportas|finalizarconexao|listarportas|finalizarprocessoportas|Y|listarportas|finalizarprocessoportas|N|URL_VISITORregistro|renamekey|Key name has been successfully changedUnable to change key nameregistro|registro|Key name has been successfully changed|"registro|registro|Unable to change key name|"registro|registro|The key or value has been deleted successfully|"registro|registro|Unable to delete key or value|"registro|registro|The key was created successfully|"registro|registro|Could not create key|"keylogger|keyloggerlist|ak.tmponlinekeyloggerstart|onlinekeyloggererror|keylogger|keylogger|keyloggerativar|keylogger|keylogger|keyloggerdesativar|keylogger|keyloggergetlog|keylogger|keylogger|keyloggervazio|keyloggersearchok|checkwebcamfileback|webcamdlltransferdone|webcam|webcaminactive|webcamdllloaded|checkwebcamfile|no|webcam|webcamactive|webcam|webcamstop|getpassword|getpasswordlist|USER32.DLLC:\Windows\System32\drivers\etc\hoststemp.vbsliststartup|renamekey|liststartup|liststartup|Key name has been successfully changed|"liststartup|liststartup|Unable to change key name|"liststartup|liststartup|The key or value has been deleted successfully|"liststartup|liststartup|Unable to delete key or value|"liststartup|liststartup|The key was created successfully|"liststartup|liststartup|Could not create key|"deflate 1.2.3 Copyright 1995-2005 Jean-loup Gaillyinflate 1.2.3 Copyright 1995-2005 Mark AdlerKWindowsU_GrabPassword8U_GrabOpera\U_GrabChrome6U_GrabFirefox.UnitBytesSizeYU_GrabFirefox8U_GrabFirefox10UnitExecutarComandosUrlMonuftpUnitListarPortasAtivasUnitKeyloggerGetProcessHeapWinExecSetNamedPipeHandleStateCreatePipeRegOpenKeyExARegOpenKeyARegEnumKeyExARegDeleteKeyARegCreateKeyARegCloseKeyGdiplusShutdownShellExecuteExAkeybd_eventMsgWaitForMultipleObjectsMapVirtualKeyExAMapVirtualKeyAGetKeyboardStateGetKeyboardLayoutNameAGetKeyboardLayoutGetKeyStateGetAsyncKeyStateExitWindowsExEnumWindowsInternetOpenUrlAFtpGetFileSizeFtpSetCurrentDirectoryAFtpOpenFileA9!!!$'')#&!!$'''#.idata.relocP.rsrcadvapi32.dllgdi32.dllgdiplus.dllmpr.dllmsacm32.dllntdll.dlloleaut32.dllpowrprof.dlluser32.dllversion.dllwininet.dllwinmm.dllwsock32.dll3>