HEUR:Trojan.Win32.Generic (Kaspersky), Trojan.Generic.11720688 (B) (Emsisoft), Trojan.Generic.11720688 (AdAware), Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericInjector.YR, TrojanDropperVtimrun.YR (Lavasoft MAS)Behaviour: Trojan-Dropper, Banker, Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: b7c53c4300b9b7d08848c270690e46e1
SHA1: 8a6ac22a8324689116e91b561a9e2fa3a3bfa3b3
SHA256: 73b33668dd01cb97450e216362f6791e85b7fa175e3f0cd74149ff5cf8807927
SSDeep: 6144:cQGCIIm qIKDTrb6r7RfcXUV29ry1GQQ/WyfXTjZejX9fluD91UVxXrTCGAXIcKT:cQlqrbu7lX0yG/3vcX1l0mj 3iZcC
Size: 492032 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-10-14 08:50:27
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1756
The Trojan injects its code into the following process(es):
MENDES~1.EXE:1772
Mutexes
The following mutexes were created/opened:
ShimCacheMutex
File activity
The process %original file name%.exe:1756 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\PBBR.exe (3286 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\MENDES~1.EXE (13304 bytes)
Registry activity
The process MENDES~1.EXE:1772 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "29 45 C0 4A 95 77 D4 9D 24 52 EF D6 5D 6B DB D1"
[HKCU\MendesDowns[www.MendesDowns.blogspot.com]]
"C-INJECTOR-1.1" = ""
The process %original file name%.exe:1756 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3D D8 7E 80 3B 34 12 8E C3 15 3F CC 94 54 7E 1C"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
Dropped PE files
MD5 | File path |
---|---|
7f0ed174dbf5456a17323cce1a7a16b7 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\MENDES~1.EXE |
9086552c724729a761cfad23b371a091 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\IXP000.TMP\PBBR.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1756
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\PBBR.exe (3286 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\MENDES~1.EXE (13304 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\" - Reboot the computer.
Static Analysis
VersionInfo
Company Name: Microsoft Corporation
Product Name: Internet Explorer
Product Version: 11.00.9600.16428
Legal Copyright: (c) Microsoft Corporation. All rights reserved.
Legal Trademarks:
Original Filename: WEXTRACT.EXE .MUI
Internal Name: Wextract
File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)
File Description: Win32 Cabinet Self-Extractor
Comments:
Language: English (United States)
Company Name: Microsoft CorporationProduct Name: Internet ExplorerProduct Version: 11.00.9600.16428Legal Copyright: (c) Microsoft Corporation. All rights reserved.Legal Trademarks: Original Filename: WEXTRACT.EXE .MUIInternal Name: Wextract File Version: 11.00.9600.16428 (winblue_gdr.131013-1700)File Description: Win32 Cabinet Self-Extractor Comments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 26060 | 26112 | 4.42567 | e9bf1a1e456a9a811b1b86e6602e3636 |
.data | 32768 | 6796 | 1024 | 2.20139 | 317f8a934ee443eee01c2a315bde9ca1 |
.idata | 40960 | 4216 | 4608 | 3.49941 | d8675ba112ef922c6057a02546757a1a |
.rsrc | 49152 | 454047 | 454144 | 5.46165 | f2665e742d33a9f359a1f226a8da638f |
.reloc | 503808 | 5038 | 5120 | 2.58043 | 83de2f9b2c95be6fea06bced7e8a058e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_1756:
.text
.text
`.data
`.data
.idata
.idata
@.rsrc
@.rsrc
@.reloc
@.reloc
Invalid parameter passed to C runtime function.
Invalid parameter passed to C runtime function.
advapi32.dll
advapi32.dll
setupx.dll
setupx.dll
setupapi.dll
setupapi.dll
advpack.dll
advpack.dll
wininit.ini
wininit.ini
Software\Microsoft\Windows\CurrentVersion\App Paths
Software\Microsoft\Windows\CurrentVersion\App Paths
ADMQCMD
ADMQCMD
USRQCMD
USRQCMD
FINISHMSG
FINISHMSG
IXPd.TMP
IXPd.TMP
msdownld.tmp
msdownld.tmp
TMP4351$.TMP
TMP4351$.TMP
wextract.pdb
wextract.pdb
PSSSSSSh
PSSSSSSh
SSSh
SSSh
PSSShp
PSSShp
PSShp
PSShp
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
System\CurrentControlSet\Control\Session Manager\FileRenameOperations
wextract_cleanup%d
wextract_cleanup%d
Command.com /c %s
Command.com /c %s
rundll32.exe %s,InstallHinfSection %s 128 %s
rundll32.exe %s,InstallHinfSection %s 128 %s
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\RunOnce
%s /D:%s
%s /D:%s
PendingFileRenameOperations
PendingFileRenameOperations
SHELL32.DLL
SHELL32.DLL
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
RegQueryInfoKeyA
RegQueryInfoKeyA
RegCloseKey
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
GDI32.dll
GDI32.dll
ExitWindowsEx
ExitWindowsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
USER32.dll
USER32.dll
_amsg_exit
_amsg_exit
_acmdln
_acmdln
msvcrt.dll
msvcrt.dll
COMCTL32.dll
COMCTL32.dll
Cabinet.dll
Cabinet.dll
VERSION.dll
VERSION.dll
MENDES~1.EXE
MENDES~1.EXE
PBBR.exe
PBBR.exe
d.HvZg
d.HvZg
2`.IM
2`.IM
.pD4TE
.pD4TE
Mm).qA_
Mm).qA_
Wk.RWXb
Wk.RWXb
.qcQ;
.qcQ;
l.vEj
l.vEj
u%FQ,z`
u%FQ,z`
5,t.xE
5,t.xE
:%fz?
:%fz?
y.DW`
y.DW`
}\5j.jLQY
}\5j.jLQY
xz2b/%Uq
xz2b/%Uq
f2:*%x#
f2:*%x#
=.ITV
=.ITV
.gQ^z
.gQ^z
.ejLC.
.ejLC.
5>u.Cw
5>u.Cw
v.vNP[u
v.vNP[u
{.UFFx
{.UFFx
\|.%D
\|.%D
.ZiDB
.ZiDB
83x-%s
83x-%s
:V.hOv
:V.hOv
-W6L%S
-W6L%S
^9.hE
^9.hE
Jb%0sR
Jb%0sR
CMd:h
CMd:h
X.Kkn
X.Kkn
i%U4RS
i%U4RS
]%F X
]%F X
q.Ay&
q.Ay&
-%SL&e2
-%SL&e2
.wcE*3
.wcE*3
zH'Q%7X
zH'Q%7X
F&;Us.pm
F&;Us.pm
f4%C@_
f4%C@_
-%PhF.Vb>
-%PhF.Vb>
L.jms
L.jms
cn8%F-
cn8%F-
mK%3SN
mK%3SN
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
Kernel32.dll
Kernel32.dll
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
Please read the following license agreement. Press the PAGE DOWN key to see the rest of the agreement.
CFailed to get disk space information from: %s.
CFailed to get disk space information from: %s.
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
System Message: %s.&A required resource cannot be located. Are you sure you want to cancel?
8Unable to retrieve operating system version information.!Memory allocation request failed.
8Unable to retrieve operating system version information.!Memory allocation request failed.
Filetable full.Ên not change to destination folder.
Filetable full.Ên not change to destination folder.
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.OFalha ao obter informa
Setup could not find a drive with %s KB free disk space to install the program. Please free up some space first and press RETRY or press CANCEL to exit setup.KThat folder is invalid. Please make sure the folder exists and is writable.IYou must specify a folder with fully qualified pathname or choose Cancel.OFalha ao obter informa
o em disco de: %s.
o em disco de: %s.
Mensagem do sistema: %s..Um recurso necess
Mensagem do sistema: %s..Um recurso necess
o pode ser encontrado.#Tem certeza de que deseja cancelar?
o pode ser encontrado.#Tem certeza de que deseja cancelar?
o do sistema operacional.'Falha do pedido de aloca
o do sistema operacional.'Falha do pedido de aloca
O arquivo de gabinete (.cab) n
O arquivo de gabinete (.cab) n
vel encontrar uma unidade com %s KB de espa
vel encontrar uma unidade com %s KB de espa
o.NPasta inv
o.NPasta inv
lida. Certifique-se de que a pasta existe e de que permite grava
lida. Certifique-se de que a pasta existe e de que permite grava
o.ZEspecifique uma pasta com um nome de caminho totalmente qualificado ou clique em Cancelar.
o.ZEspecifique uma pasta com um nome de caminho totalmente qualificado ou clique em Cancelar.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
!Could not update folder edit box.5Could not load functions required for browser dialog.7Could not load Shell32.dll required for browser dialog.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
(Error creating process . Reason: %s1The cluster size in this system is not supported.,A required resource appears to be corrupted.QWindows 95 or Windows NT 4.0 Beta 2 or greater is required for this installation.
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Error loading %shGetProcAddress() failed on function '%s'. Possible reason: incorrect version of advpack.dll being used./Windows 95 or Windows NT is required to install
Could not create folder '%s'
Could not create folder '%s'
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
To install this program, you need %s KB disk space on drive %s. It is recommended that you free up the required disk space before you continue.
o da pasta.QN
o da pasta.QN
logo do navegador.RN
logo do navegador.RN
vel carregar Shell32.dll, necess
vel carregar Shell32.dll, necess
)Erro ao criar o processo . Causa: %s7N
)Erro ao criar o processo . Causa: %s7N
suporte para o tamanho do cluster deste sistema..Um recurso necess
suporte para o tamanho do cluster deste sistema..Um recurso necess
rio parece estar corrompido.IA instala
rio parece estar corrompido.IA instala
o requer o Windows 95 ou o Windows NT 4.0 beta 2 ou posterior.
o requer o Windows 95 ou o Windows NT 4.0 beta 2 ou posterior.
Erro ao carregar %smFalha de GetProcAddress() na fun
Erro ao carregar %smFalha de GetProcAddress() na fun
o '%s'. Poss
o '%s'. Poss
o incorreta de advpack.dll est
o incorreta de advpack.dll est
sendo usada.>O Windows 95 ou o Windows NT
sendo usada.>O Windows 95 ou o Windows NT
vel criar a pasta '%s'
vel criar a pasta '%s'
precisa de %s KB de espa
precisa de %s KB de espa
o livre na unidade %s.
o livre na unidade %s.
Error retrieving Windows folder
Error retrieving Windows folder
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
$NT Shutdown: OpenProcessToken error.)NT Shutdown: AdjustTokenPrivileges error.!NT Shutdown: ExitWindowsEx error.}Extracting file failed. It is most likely caused by low memory (low disk space for swapping file) or corrupted Cabinet file.aThe setup program could not retrieve the volume information for drive (%s) .
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
System message: %s.xSetup could not find a drive with %s KB free disk space to install the program. Please free up some space and try again.eThe installation program appears to be damaged or corrupted. Contact the vendor of this application.
$Erro ao recuperar a pasta do Windows
$Erro ao recuperar a pasta do Windows
*Desligamento do NT: erro OpenProcessToken./Desligamento do NT: erro AdjustTokenPrivileges.'Desligamento do NT: erro ExitWindowsEx.
*Desligamento do NT: erro OpenProcessToken./Desligamento do NT: erro AdjustTokenPrivileges.'Desligamento do NT: erro ExitWindowsEx.
o em disco insuficiente para arquivo de permuta) ou arquivo de gabinete (.cab) corrompido._As informa
o em disco insuficiente para arquivo de permuta) ou arquivo de gabinete (.cab) corrompido._As informa
es de volume da unidade (%s) n
es de volume da unidade (%s) n
Mensagem do sistema: %s.
Mensagem do sistema: %s.
o e tente novamente.pO programa de instala
o e tente novamente.pO programa de instala
/C: -- Override Install Command defined by author.
/C: -- Override Install Command defined by author.
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
eAnother copy of the '%s' package is already running on your system. Do you want to run another copy?
Could not find the file: %s.
Could not find the file: %s.
pia do pacote '%s' j
pia do pacote '%s' j
sendo executada no sistema. Deseja executar outra c
sendo executada no sistema. Deseja executar outra c
vel encontrar o arquivo: %s.
vel encontrar o arquivo: %s.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
:The folder '%s' does not exist. Do you want to create it?hAnother copy of the '%s' package is already running on your system. You can only run one copy at a time.OThe '%s' package is not compatible with the version of Windows you are running.SThe '%s' package is not compatible with the version of the file: %s on your system.
xito quando executadas por um administrador.
xito quando executadas por um administrador.
(A pasta '%s' n
(A pasta '%s' n
sendo executada no sistema. Apenas uma c
sendo executada no sistema. Apenas uma c
pia pode ser executada de cada vez.PO pacote '%s' n
pia pode ser executada de cada vez.PO pacote '%s' n
o do Windows que est
o do Windows que est
sendo executada.FO pacote '%s' n
sendo executada.FO pacote '%s' n
o do arquivo: %s do sistema.
o do arquivo: %s do sistema.
11.00.9600.16428 (winblue_gdr.131013-1700)
11.00.9600.16428 (winblue_gdr.131013-1700)
WEXTRACT.EXE .MUI
WEXTRACT.EXE .MUI
11.00.9600.16428
11.00.9600.16428
MENDES~1.EXE_1772:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s_%d
%s_%d
EInvalidGraphicOperation
EInvalidGraphicOperation
USER32.DLL
USER32.DLL
windows
windows
comctl32.dll
comctl32.dll
uxtheme.dll
uxtheme.dll
%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s
Proportional
Proportional
MAPI32.DLL
MAPI32.DLL
OnKeyDown
OnKeyDown
OnKeyPressd
OnKeyPressd
OnKeyUp
OnKeyUp
UhV%C
UhV%C
Uh
Uh
RICHED32.DLL
RICHED32.DLL
PasswordChar
PasswordChar
ssHorizontal
ssHorizontal
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
AutoHotkeys
AutoHotkeys
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
tagMSG
tagMSG
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
Vh8%F
Vh8%F
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
1.2.3
1.2.3
Portable Network Graphics
Portable Network Graphics
ole32.dll
ole32.dll
olepro32.dll
olepro32.dll
OnActionExecute
OnActionExecute
opexeP
opexeP
MendesDowns[VVV.MendesDowns.blogspot.com]
MendesDowns[VVV.MendesDowns.blogspot.com]
em execu
em execu
Mendes DLL Injector * CMD *
Mendes DLL Injector * CMD *
VVV.MendesDowns.blogspot.com
VVV.MendesDowns.blogspot.com
sendo executado no Momento!!!
sendo executado no Momento!!!
NomeDoProcesso.exe
NomeDoProcesso.exe
hXXp://mendesdowns.blogspot.com
hXXp://mendesdowns.blogspot.com
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
GetCPInfo
GetCPInfo
version.dll
version.dll
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
winspool.drv
winspool.drv
shell32.dll
shell32.dll
ShellExecuteA
ShellExecuteA
comdlg32.dll
comdlg32.dll
VVV.mendesfiles.blogspot.com
VVV.mendesfiles.blogspot.com
0&0.060^0
0&0.060^0
5 6m6U6s6z6
5 6m6U6s6z6
= =$=(=,=0=4=8=
= =$=(=,=0=4=8=
: ;';];|;
: ;';];|;
;#;';=;`;
;#;';=;`;
52666:6@6
52666:6@6
2&3*3.363
2&3*3.363
0(1,10141
0(1,10141
? ?$?2?:?
? ?$?2?:?
5"5-525=5
5"5-525=5
333333333333333333
333333333333333333
33333833
33333833
3333339
3333339
3333333333333338
3333333333333338
:*"*"$3338
:*"*"$3338
3333333
3333333
33333333
33333333
33333333333
33333333333
3333333333338
3333333333338
33338?383
33338?383
333333333333
333333333333
:*3:"$3338
:*3:"$3338
333333333333333
333333333333333
KWindows
KWindows
UrlMon
UrlMon
' .:: VVV.MendesDowns.blogspot.com ::.
' .:: VVV.MendesDowns.blogspot.com ::.
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
Icon.Data
Icon.Data
Picture.Data
Picture.Data
fKa/-Au}
fKa/-Au}
&.moUB
&.moUB
Procurar por Execut
Procurar por Execut
Lines.Strings
Lines.Strings
opexe
opexe
Arquivos Execut
Arquivos Execut
veis [ *.exe ]|*.exe
veis [ *.exe ]|*.exe
!Arquivos tipo DLL [ *.dll ]|*.dll
!Arquivos tipo DLL [ *.dll ]|*.dll
Mendes CMD
Mendes CMD
Processo.exe
Processo.exe
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
UThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
UThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.nThis "Portable Network Graphics" image is not supported or it might be invalid.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.nThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.oSome operation could not be performed because the system is out of resources. Close some windows and try again.OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.oSome operation could not be performed because the system is out of resources. Close some windows and try again.OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
No help keyword specified.jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corrupted
No help keyword specified.jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corrupted
/Menu '%s' is already being used by another form
/Menu '%s' is already being used by another form
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Unable to insert a line Clipboard does not support Icons
Unable to insert a line Clipboard does not support Icons
Text exceeds memo capacity.There is no default printer currently selected
Text exceeds memo capacity.There is no default printer currently selected
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
%s on %s@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Invalid operation on TOleGraphic
Invalid operation on TOleGraphic
Unsupported clipboard format
Unsupported clipboard format
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Failed to set data for '%s'
Failed to set data for '%s'
Resource %s not found
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
!'%s' is not a valid integer value
!'%s' is not a valid integer value
I/O error %d
I/O error %d
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
1.1.0.0
1.1.0.0
1.0.0.0
1.0.0.0