Trojan.Generic.11254560 (AdAware), Trojan-Banker.Win32.Banker.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericPhysicalDrive0.YR (Lavasoft MAS)Behaviour: Banker, Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: d1bf0daf141e99639e16c5ef7013914b
SHA1: b139df4aabedb0ac772cc4e7fc8fc50c032cab1e
SHA256: e47693010f6ce108168e0fe77839847ea4215bdf19445f9bba73bd1cf5364276
SSDeep: 98304:q/AWtxah7aSwIfeaG4u61Zje8tNJj669cERHEkN nCFKxmeVMj9nXT1x:ctwhOQe56188tUdkSCFKxmeV6nXTP
Size: 7562880 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: ASPackv212, UPolyXv05_v6
Company: AirInstaller
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:1156
The Trojan injects its code into the following process(es):
¡¡%original file name%.exe:1824
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:1156 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\¡¡%original file name%.exe (53149 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\lb.txt (7868 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\lb.txt (0 bytes)
Registry activity
The process %original file name%.exe:1156 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6B FA 8A F2 6B 47 D5 BF 49 BE FA CE E0 97 F9 73"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
The process ¡¡%original file name%.exe:1824 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FF EE A3 CD 1E 72 4A 8B DA 7F 94 A3 E5 AE 9D B4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
Dropped PE files
MD5 | File path |
---|---|
836a53fceadc0cc1ebbc9eb27f50f43b | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\¡¡%original file name%.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:1156
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\¡¡%original file name%.exe (53149 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\lb.txt (7868 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 557056 | 217600 | 5.54434 | 9197ec333d553ca5b84bfb2f83d2a53d |
DATA | 561152 | 8192 | 3584 | 5.38975 | 7623010a0e14ee92b8335bfbb09d150e |
BSS | 569344 | 8192 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 577536 | 12288 | 3584 | 5.4986 | bf9d4621b3631703e4022bbb3b4b5c74 |
.tls | 589824 | 4096 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 593920 | 4096 | 512 | 0.114206 | 505004ed096572432803172c2e65f1ff |
.reloc | 598016 | 45056 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 643072 | 36864 | 11776 | 4.9395 | ada09889014a5cc42bf27f497899538d |
.aspack | 679936 | 8192 | 7680 | 3.404 | 0c1ac3d9e0f49cc61d89e3735d4d97ab |
.adata | 688128 | 4096 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://www.lieyingdlq.com/ly.txt | 50.117.126.132 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /ly.txt HTTP/1.1
Content-Type: text/html
Host: VVV.lieyingdlq.com
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Content-Length: 2371
Content-Type: text/plain
Last-Modified: Thu, 19 Jun 2014 03:05:21 GMT
Accept-Ranges: bytes
ETag: "6cf46a4e6b8bcf1:39ca4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 20 Sep 2014 04:14:04 GMT
[Server]..;....:............|..........|..........|....|........=............ .. .. .. .. .. ....|............|127.0.0.1|7000|1.85=............................ [........]..|............|127.0.0.1|7000|1.85=............................ [........]..|............|127.0.0.1|7000|1.85=............................ [........]..|............|127.0.0.1|7000|1.85=............................ [........]..|............|127.0.0.1|7000|1.85=.................... .. .. .. .. .. ....|............|222.33.233.254|7000|1.85=.................... .. .. .. .. .. ....|........|121.199.43.221|7000|1.85=............................ [........]..|............|127.0.0.1|7001|1.85=............................ [........]..|............|121.12.172.70|7019|1.85=............................ [........]..|............|112.91.17.91|7019|1.85=............................ [........]..|............|127.0.0.1|7001|1.85=.................... .. .. .. .. .. ....|............|127.0.0.1|7003|1.85=..........................................|............|127.0.0.1|7003|1.85=.................... .. .. .. .. ...... |............|127.0.0.1|7003|1.85=..........................................|............|127.0.0.1|7003|1.85=.................K..VVV.lieyingdlq.com...L..|............|127.0.0.1|7002|1.85=...................K.K .............. .L.L..|............|127.0.0.1|7002|1.85=.....................K.K...........L.L......|............|127.0.0.1|7003|1.85=.................. .K....QQ:779389988.L ....|............|127.0.0.1|7003|1.85=..............
<<< skipped >>>
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
¡¡%original file name%.exe_1824:
.text
.text
.itext
.itext
.data
.data
.WFNOWL
.WFNOWL
.PUXJPA
.PUXJPA
.LMNMOY
.LMNMOY
.VWFMVD0
.VWFMVD0
.LXRAGM
.LXRAGM
.HHSQQF
.HHSQQF
.LQVCIE
.LQVCIE
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
%s[%d]
%s[%d]
%s_%d
%s_%d
USER32.DLL
USER32.DLL
comctl32.dll
comctl32.dll
EInvalidGraphicOperation
EInvalidGraphicOperation
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
ole32.dll
ole32.dll
uxtheme.dll
uxtheme.dll
DWMAPI.DLL
DWMAPI.DLL
PasswordCharH
PasswordCharH
OnKeyDown
OnKeyDown
OnKeyPress
OnKeyPress
OnKeyUp
OnKeyUp
OnKeyUplAC
OnKeyUplAC
Uh%XC
Uh%XC
clWebSnow
clWebSnow
clWebFloralWhite
clWebFloralWhite
clWebLavenderBlush
clWebLavenderBlush
clWebOldLace
clWebOldLace
clWebIvory
clWebIvory
clWebCornSilk
clWebCornSilk
clWebBeige
clWebBeige
clWebAntiqueWhite
clWebAntiqueWhite
clWebWheat
clWebWheat
clWebAliceBlue
clWebAliceBlue
clWebGhostWhite
clWebGhostWhite
clWebLavender
clWebLavender
clWebSeashell
clWebSeashell
clWebLightYellow
clWebLightYellow
clWebPapayaWhip
clWebPapayaWhip
clWebNavajoWhite
clWebNavajoWhite
clWebMoccasin
clWebMoccasin
clWebBurlywood
clWebBurlywood
clWebAzure
clWebAzure
clWebMintcream
clWebMintcream
clWebHoneydew
clWebHoneydew
clWebLinen
clWebLinen
clWebLemonChiffon
clWebLemonChiffon
clWebBlanchedAlmond
clWebBlanchedAlmond
clWebBisque
clWebBisque
clWebPeachPuff
clWebPeachPuff
clWebTan
clWebTan
clWebYellow
clWebYellow
clWebDarkOrange
clWebDarkOrange
clWebRed
clWebRed
clWebDarkRed
clWebDarkRed
clWebMaroon
clWebMaroon
clWebIndianRed
clWebIndianRed
clWebSalmon
clWebSalmon
clWebCoral
clWebCoral
clWebGold
clWebGold
clWebTomato
clWebTomato
clWebCrimson
clWebCrimson
clWebBrown
clWebBrown
clWebChocolate
clWebChocolate
clWebSandyBrown
clWebSandyBrown
clWebLightSalmon
clWebLightSalmon
clWebLightCoral
clWebLightCoral
clWebOrange
clWebOrange
clWebOrangeRed
clWebOrangeRed
clWebFirebrick
clWebFirebrick
clWebSaddleBrown
clWebSaddleBrown
clWebSienna
clWebSienna
clWebPeru
clWebPeru
clWebDarkSalmon
clWebDarkSalmon
clWebRosyBrown
clWebRosyBrown
clWebPaleGoldenrod
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebLightGoldenrodYellow
clWebOlive
clWebOlive
clWebForestGreen
clWebForestGreen
clWebGreenYellow
clWebGreenYellow
clWebChartreuse
clWebChartreuse
clWebLightGreen
clWebLightGreen
clWebAquamarine
clWebAquamarine
clWebSeaGreen
clWebSeaGreen
clWebGoldenRod
clWebGoldenRod
clWebKhaki
clWebKhaki
clWebOliveDrab
clWebOliveDrab
clWebGreen
clWebGreen
clWebYellowGreen
clWebYellowGreen
clWebLawnGreen
clWebLawnGreen
clWebPaleGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumAquamarine
clWebMediumSeaGreen
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkOliveGreen
clWebDarkgreen
clWebDarkgreen
clWebLimeGreen
clWebLimeGreen
clWebLime
clWebLime
clWebSpringGreen
clWebSpringGreen
clWebMediumSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebPaleTurquoise
clWebLightCyan
clWebLightCyan
clWebLightBlue
clWebLightBlue
clWebLightSkyBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebDarkBlue
clWebIndigo
clWebIndigo
clWebMediumTurquoise
clWebMediumTurquoise
clWebTurquoise
clWebTurquoise
clWebCyan
clWebCyan
clWebPowderBlue
clWebPowderBlue
clWebSkyBlue
clWebSkyBlue
clWebRoyalBlue
clWebRoyalBlue
clWebMediumBlue
clWebMediumBlue
clWebMidnightBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebDarkTurquoise
clWebCadetBlue
clWebCadetBlue
clWebDarkCyan
clWebDarkCyan
clWebTeal
clWebTeal
clWebDeepskyBlue
clWebDeepskyBlue
clWebDodgerBlue
clWebDodgerBlue
clWebBlue
clWebBlue
clWebNavy
clWebNavy
clWebDarkViolet
clWebDarkViolet
clWebDarkOrchid
clWebDarkOrchid
clWebMagenta
clWebMagenta
clWebDarkMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebMediumVioletRed
clWebPaleVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebBlueViolet
clWebMediumOrchid
clWebMediumOrchid
clWebMediumPurple
clWebMediumPurple
clWebPurple
clWebPurple
clWebDeepPink
clWebDeepPink
clWebLightPink
clWebLightPink
clWebViolet
clWebViolet
clWebOrchid
clWebOrchid
clWebPlum
clWebPlum
clWebThistle
clWebThistle
clWebHotPink
clWebHotPink
clWebPink
clWebPink
clWebLightSteelBlue
clWebLightSteelBlue
clWebMediumSlateBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebLightSlateGray
clWebWhite
clWebWhite
clWebLightgrey
clWebLightgrey
clWebGray
clWebGray
clWebSteelBlue
clWebSteelBlue
clWebSlateBlue
clWebSlateBlue
clWebSlateGray
clWebSlateGray
clWebWhiteSmoke
clWebWhiteSmoke
clWebSilver
clWebSilver
clWebDimGray
clWebDimGray
clWebMistyRose
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlateBlue
clWebDarkSlategray
clWebDarkSlategray
clWebGainsboro
clWebGainsboro
clWebDarkGray
clWebDarkGray
clWebBlack
clWebBlack
Proportional
Proportional
AutoHotkeys`
AutoHotkeys`
AutoHotkeys
AutoHotkeys
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
GlassFrame.Bottom
GlassFrame.Bottom
GlassFrame.Enabled
GlassFrame.Enabled
GlassFrame.Left
GlassFrame.Left
GlassFrame.Right
GlassFrame.Right
GlassFrame.SheetOfGlass
GlassFrame.SheetOfGlass
GlassFrame.Top
GlassFrame.Top
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
User32.dll
User32.dll
MAPI32.DLL
MAPI32.DLL
msShiftSelect
msShiftSelect
%s, ClassID: %s
%s, ClassID: %s
olepro32.dll
olepro32.dll
IWebBrowser
IWebBrowser
IWebBrowserApp
IWebBrowserApp
IWebBrowser2
IWebBrowser2
TWebBrowserStatusTextChange
TWebBrowserStatusTextChange
TWebBrowserProgressChange
TWebBrowserProgressChange
TWebBrowserCommandStateChange
TWebBrowserCommandStateChange
TWebBrowserTitleChange
TWebBrowserTitleChange
TWebBrowserPropertyChange
TWebBrowserPropertyChange
TWebBrowserBeforeNavigate2
TWebBrowserBeforeNavigate2
TWebBrowserNewWindow2
TWebBrowserNewWindow2
TWebBrowserNavigateComplete2
TWebBrowserNavigateComplete2
TWebBrowserDocumentComplete
TWebBrowserDocumentComplete
TWebBrowserOnVisible
TWebBrowserOnVisible
TWebBrowserOnToolBar
TWebBrowserOnToolBar
TWebBrowserOnMenuBar
TWebBrowserOnMenuBar
TWebBrowserOnStatusBar
TWebBrowserOnStatusBar
TWebBrowserOnFullScreen
TWebBrowserOnFullScreen
TWebBrowserOnTheaterMode
TWebBrowserOnTheaterMode
TWebBrowserWindowSetResizable
TWebBrowserWindowSetResizable
TWebBrowserWindowSetLeft
TWebBrowserWindowSetLeft
TWebBrowserWindowSetTop
TWebBrowserWindowSetTop
TWebBrowserWindowSetWidth
TWebBrowserWindowSetWidth
TWebBrowserWindowSetHeight
TWebBrowserWindowSetHeight
TWebBrowserWindowClosing
TWebBrowserWindowClosing
TWebBrowserClientToHostWindow
TWebBrowserClientToHostWindow
TWebBrowserSetSecureLockIcon
TWebBrowserSetSecureLockIcon
TWebBrowserFileDownload
TWebBrowserFileDownload
TWebBrowserNavigateError
TWebBrowserNavigateError
%TWebBrowserPrintTemplateInstantiation
%TWebBrowserPrintTemplateInstantiation
TWebBrowserPrintTemplateTeardown
TWebBrowserPrintTemplateTeardown
TWebBrowserUpdatePageStatus
TWebBrowserUpdatePageStatus
%TWebBrowserPrivacyImpactedStateChange
%TWebBrowserPrivacyImpactedStateChange
TWebBrowser
TWebBrowser
TWebBrowserD
TWebBrowserD
OnWindowSetResizable
OnWindowSetResizable
OnWindowSetLeft
OnWindowSetLeft
OnWindowSetTop
OnWindowSetTop
OnWindowSetWidth
OnWindowSetWidth
OnWindowSetHeightd
OnWindowSetHeightd
Port
Port
1.2.3
1.2.3
1.0.4
1.0.4
h.nOF
h.nOF
KERNEL32.DLL
KERNEL32.DLL
CommonalityKey
CommonalityKey
PrivateKey
PrivateKey
\Software\Microsoft\Windows\CurrentVersion
\Software\Microsoft\Windows\CurrentVersion
BuildImportTable: can't load library:
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
BTMemoryGetProcAddress: exported symbol not found
Unsupported Method
Unsupported Method
User canceled operation
User canceled operation
Password
Password
Could not load CreateObject function from 7za.dll
Could not load CreateObject function from 7za.dll
Perhaps 7za.dll not found
Perhaps 7za.dll not found
%s, %.2d %s %.4d %s %s
%s, %.2d %s %.4d %s %s
EIdCanNotBindPortInRange
EIdCanNotBindPortInRange
EIdInvalidPortRange
EIdInvalidPortRange
C:\Builds\TpAddons\IndyNet\System\IdStreamVCL.pas
C:\Builds\TpAddons\IndyNet\System\IdStreamVCL.pas
C:\Builds\TpAddons\IndyNet\System\IdGlobal.pas
C:\Builds\TpAddons\IndyNet\System\IdGlobal.pas
getservbyport
getservbyport
WSAAsyncGetServByPort
WSAAsyncGetServByPort
WSAJoinLeaf
WSAJoinLeaf
WS2_32.DLL
WS2_32.DLL
Wship6.dll
Wship6.dll
EIdIPVersionUnsupportedU
EIdIPVersionUnsupportedU
TIdSocketListWindows
TIdSocketListWindows
TIdStackWindowsU
TIdStackWindowsU
IdStackWindows
IdStackWindows
127.0.0.1
127.0.0.1
C:\builds\TpAddons\IndyNet\System\IdStack.pas
C:\builds\TpAddons\IndyNet\System\IdStack.pas
ftpTransfer
ftpTransfer
ftpReady
ftpReady
ftpAborted
ftpAborted
ClientPortMin
ClientPortMin
ClientPortMax
ClientPortMax
PortSVW
PortSVW
EIdPortRequired` L
EIdPortRequired` L
EIdTCPConnectionError
EIdTCPConnectionError
EIdObjectTypeNotSupported
EIdObjectTypeNotSupported
Port
Port
C:\builds\TpAddons\IndyNet\Core\IdIOHandler.pas
C:\builds\TpAddons\IndyNet\Core\IdIOHandler.pas
"EIdTransparentProxyUDPNotSupported
"EIdTransparentProxyUDPNotSupported
TIdTCPClientCustom
TIdTCPClientCustom
TIdTCPClientCustoml_L
TIdTCPClientCustoml_L
IdTCPClient
IdTCPClient
TIdTCPClient
TIdTCPClient
BoundPort
BoundPort
%EIdSocksUDPNotSupportedBySOCKSVersion
%EIdSocksUDPNotSupportedBySOCKSVersion
saUsernamePassword
saUsernamePassword
Password
Password
0.0.0.1
0.0.0.1
0.0.0.0
0.0.0.0
DefaultPort
DefaultPort
TIdTCPConnection
TIdTCPConnection
TIdTCPConnectionH
TIdTCPConnectionH
IdTCPConnection
IdTCPConnection
ISO_646.irv:1991
ISO_646.irv:1991
ISO_646.basic:1983
ISO_646.basic:1983
ISO_646.irv:1983
ISO_646.irv:1983
csISO16Portuguese
csISO16Portuguese
csISO84Portuguese2
csISO84Portuguese2
windows-936
windows-936
csShiftJIS
csShiftJIS
ISO-8859-1-Windows-3.0-Latin-1
ISO-8859-1-Windows-3.0-Latin-1
csWindows30Latin1
csWindows30Latin1
ISO-8859-1-Windows-3.1-Latin-1
ISO-8859-1-Windows-3.1-Latin-1
csWindows31Latin1
csWindows31Latin1
ISO-8859-2-Windows-Latin-2
ISO-8859-2-Windows-Latin-2
csWindows31Latin2
csWindows31Latin2
ISO-8859-9-Windows-Latin-5
ISO-8859-9-Windows-Latin-5
csWindows31Latin5
csWindows31Latin5
csMicrosoftPublishing
csMicrosoftPublishing
Windows-31J
Windows-31J
csWindows31J
csWindows31J
windows-1250
windows-1250
windows-1251
windows-1251
windows-1252
windows-1252
windows-1253
windows-1253
windows-1254
windows-1254
windows-1255
windows-1255
windows-1256
windows-1256
windows-1257
windows-1257
windows-1258
windows-1258
C:\builds\TpAddons\IndyNet\Protocols\IdCoder3to4.pas
C:\builds\TpAddons\IndyNet\Protocols\IdCoder3to4.pas
TIdEncoder3to4.Encode: Calculated length exceeded (expected
TIdEncoder3to4.Encode: Calculated length exceeded (expected
TIdEncoder3to4.Encode: Calculated length not met (expected
TIdEncoder3to4.Encode: Calculated length not met (expected
password
password
CommentURL
CommentURL
C:\builds\TpAddons\IndyNet\Protocols\IdZLibCompressorBase.pas
C:\builds\TpAddons\IndyNet\Protocols\IdZLibCompressorBase.pas
IdHTTPHeaderInfo
IdHTTPHeaderInfo
ProxyPassword
ProxyPassword
ProxyPort
ProxyPort
Mozilla/3.0 (compatible; Indy Library)
Mozilla/3.0 (compatible; Indy Library)
%d%s%d
%d%s%d
TIdHTTPOption
TIdHTTPOption
IdHTTP
IdHTTP
TIdHTTPOptions
TIdHTTPOptions
TIdHTTPProtocolVersion
TIdHTTPProtocolVersion
IdHTTP8
IdHTTP8
TIdHTTPOnRedirectEvent
TIdHTTPOnRedirectEvent
TIdHTTPOnHeadersAvailable
TIdHTTPOnHeadersAvailable
TIdHTTPResponse
TIdHTTPResponse
TIdHTTPResponsed
TIdHTTPResponsed
TIdHTTPRequest
TIdHTTPRequest
TIdHTTPProtocol8
TIdHTTPProtocol8
TIdCustomHTTP
TIdCustomHTTP
TIdCustomHTTP8
TIdCustomHTTP8
TIdHTTP
TIdHTTP
TIdHTTPh
TIdHTTPh
HTTPOptions
HTTPOptions
EIdHTTPProtocolException
EIdHTTPProtocolException
C:\builds\TpAddons\IndyNet\Protocols\IdHTTP.pas
C:\builds\TpAddons\IndyNet\Protocols\IdHTTP.pas
HTTPS
HTTPS
https
https
HTTP/1.0 200 OK
HTTP/1.0 200 OK
HTTP/
HTTP/
m_EdPasswdt
m_EdPasswdt
m_EdNewPasswd
m_EdNewPasswd
EdNewIdKeyPress
EdNewIdKeyPress
hXXp://VVV.LyDlq.com
hXXp://VVV.LyDlq.com
TFormLoadPass
TFormLoadPass
FrmLoadPass
FrmLoadPass
EditNewPass2p
EditNewPass2p
EditNewPasst
EditNewPasst
EditOldPassx
EditOldPassx
EditNameKeyPress
EditNameKeyPress
TFormChangePass
TFormChangePass
TFormChangePassL
TFormChangePassL
FrmChangePass
FrmChangePass
Data\Prguse.wil
Data\Prguse.wil
Data\Prguse.wzl
Data\Prguse.wzl
IdHTTP1t
IdHTTP1t
IdHTTP1WorkBegin
IdHTTP1WorkBegin
IdHTTP1Work
IdHTTP1Work
MaxKeySize
MaxKeySize
Invalid key size
Invalid key size
%UUUU1E
%UUUU1E
%UUUU3
%UUUU3
\\.\PhysicalDrive0
\\.\PhysicalDrive0
\\.\SMARTVSD
\\.\SMARTVSD
RzBmpButtonWebHome|
RzBmpButtonWebHome|
RzBmpButtonWeb
RzBmpButtonWeb
RzBmpButtonGetBakPassWord
RzBmpButtonGetBakPassWord
RzBmpButtonChgPassWord
RzBmpButtonChgPassWord
WebBrowser
WebBrowser
WebBrowserDownloadComplete
WebBrowserDownloadComplete
BtnLoadPassClick
BtnLoadPassClick
BtnEditPassClick
BtnEditPassClick
BtmLoginClick
BtmLoginClick
LoadGamesGuard.exe
LoadGamesGuard.exe
\drivers\mnfs.sys
\drivers\mnfs.sys
\drivers\1397hub.sys
\drivers\1397hub.sys
\drivers\1396hub.sys
\drivers\1396hub.sys
\GPgKb.sys
\GPgKb.sys
\drivers\dkcs.sys
\drivers\dkcs.sys
\drivers\sdcp.sys
\drivers\sdcp.sys
IEXPLORE.EXE
IEXPLORE.EXE
LoginUp
LoginUp
DownUrl
DownUrl
.\ServerList.ini
.\ServerList.ini
GameUrl
GameUrl
HomeUrl
HomeUrl
LogoUrl
LogoUrl
MoneyUrl
MoneyUrl
ShowInitialMsg
ShowInitialMsg
BoxWindows
BoxWindows
.Tn{@
.Tn{@
GamesGuard.dat
GamesGuard.dat
!Game.ini
!Game.ini
ServerPort
ServerPort
LoginNo
LoginNo
.\Client.ini
.\Client.ini
LoginVer
LoginVer
LoginPwd
LoginPwd
Data.dta
Data.dta
MBApTQm_VCEoURljYrah
MBApTQm_VCEoURljYrah
MBApTQm_VCEoURljYrat
MBApTQm_VCEoURljYrat
MBApTQm_VCEoURljYseh
MBApTQm_VCEoURljYseh
hXXp://
hXXp://
.update
.update
ClientList.Dta
ClientList.Dta
Mir2.exe
Mir2.exe
*.Wil
*.Wil
*.exe
*.exe
\SystemRoot\system32\drivers\wimfilter.sys
\SystemRoot\system32\drivers\wimfilter.sys
\drivers\wimfilter.sys
\drivers\wimfilter.sys
Portable Network Graphics
Portable Network Graphics
ntdll.dll
ntdll.dll
\SystemRoot\SysWOW64\ntdll.dll
\SystemRoot\SysWOW64\ntdll.dll
\SystemRoot\System32\ntdll.dll
\SystemRoot\System32\ntdll.dll
\SystemRoot\SysWOW64\kernel32.dll
\SystemRoot\SysWOW64\kernel32.dll
\SystemRoot\System32\kernel32.dll
\SystemRoot\System32\kernel32.dll
Kernel32.dll
Kernel32.dll
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.2.3 Copyright 1995-2005 Mark Adler
inflate 1.0.4 Copyright 1995-1996 Mark Adler
inflate 1.0.4 Copyright 1995-1996 Mark Adler
;3 #>6.&
;3 #>6.&
'2, / 0&7!4-)1#
'2, / 0&7!4-)1#
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutNameA
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
EnumChildWindows
EnumChildWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
GetViewportOrgEx
GetViewportOrgEx
version.dll
version.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
RegOpenKeyA
RegOpenKeyA
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
shell32.dll
shell32.dll
ShellExecuteA
ShellExecuteA
comdlg32.dll
comdlg32.dll
wsock32.dll
wsock32.dll
gdiplus.dll
gdiplus.dll
GdiplusShutdown
GdiplusShutdown
ADVAPI32.DLL
ADVAPI32.DLL
iphlpapi.dll
iphlpapi.dll
H0%Dh
H0%Dh
K%x-p
K%x-p
#.UZG
#.UZG
xh.OHZ
xh.OHZ
.Qv,Jp
.Qv,Jp
9,.CAF
9,.CAF
p.Xhk
p.Xhk
C.qo]d
C.qo]d
9p.ef
9p.ef
hE.ni
hE.ni
' %C#E
' %C#E
:.xg#6
:.xg#6
.cC2!
.cC2!
$Ex6'%S
$Ex6'%S
D$$.cz
D$$.cz
/.Xeb
/.Xeb
%uK-2
%uK-2
333333333333333333
333333333333333333
33333833
33333833
3333339
3333339
3333333333333338
3333333333333338
:*"*"$3338
:*"*"$3338
3333333
3333333
33333333
33333333
33333333333
33333333333
3333333333338
3333333333338
33338?383
33338?383
333333333333
333333333333
:*3:"$3338
:*3:"$3338
333333333333333
333333333333333
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
t.hPL
t.hPL
__MSVCRT_HEAP_SELECT
__MSVCRT_HEAP_SELECT
USER32.dll
USER32.dll
OLEAUT32.dll
OLEAUT32.dll
KERNEL32.dll
KERNEL32.dll
7za.dll
7za.dll
000000000
000000000
:#
:#
1(14104
1(14104
Mir2Login2
Mir2Login2
KWindows
KWindows
0IdHTTPHeaderInfo
0IdHTTPHeaderInfo
UrlMon
UrlMon
]FrmChangePass
]FrmChangePass
FormChangePass
FormChangePass
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
Picture.Data
Picture.Data
2007:02:07 02:59:30
2007:02:07 02:59:30
urlTEXT
urlTEXT
MsgeTEXT
MsgeTEXT
HhXXp://ns.adobe.com/xap/1.0/
HhXXp://ns.adobe.com/xap/1.0/
xmlns:xapMM='hXXp://ns.adobe.com/xap/1.0/mm/'>
xmlns:xapMM='hXXp://ns.adobe.com/xap/1.0/mm/'>
adobe:docid:photoshop:a197521e-b60f-11db-b931-c8e8dfd9ba45
adobe:docid:photoshop:a197521e-b60f-11db-b931-c8e8dfd9ba45
EditOldPass
EditOldPass
PasswordChar
PasswordChar
EditNewPass
EditNewPass
EditNewPass2
EditNewPass2
PicIdle.Data
PicIdle.Data
PicDown.Data
PicDown.Data
PicUp.Data
PicUp.Data
FormLoadPass
FormLoadPass
2007:03:06 08:02:29
2007:03:06 08:02:29
adobe:docid:photoshop:ea54afaf-cb74-11db-9adb-a5021ffa588c
adobe:docid:photoshop:ea54afaf-cb74-11db-9adb-a5021ffa588c
:20111229
:20111229
Bitmaps.TransparentColor
Bitmaps.TransparentColor
RzBmpButtonWebHome
RzBmpButtonWebHome
7z.sfx
7z.sfx
.VZEbJ]\&
.VZEbJ]\&
Z%SEse
Z%SEse
ÃŒzN
ÃŒzN
ö[d.
ö[d.
}]g%1S
}]g%1S
.khi)
.khi)
.fL0_
.fL0_
2%"%C
2%"%C
.RTA)
.RTA)
.pX[3hOa(F
.pX[3hOa(F
d.Ewyr
d.Ewyr
:2.tO
:2.tO
_sssh0 `
_sssh0 `
-GF^%XW
-GF^%XW
c%Saz
c%Saz
.EOqdg
.EOqdg
%uyqAUD
%uyqAUD
-.UBaZ
-.UBaZ
Zocrtl
Zocrtl
Xp.hZWBe_x1
Xp.hZWBe_x1
q8%S)$
q8%S)$
.IS9Y
.IS9Y
.qyyy}}
.qyyy}}
ltY.NY
ltY.NY
R%di3
R%di3
TIdHTTP
TIdHTTP
IdHTTP1
IdHTTP1
ProxyParams.BasicAuthentication
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
ProxyParams.ProxyPort
Request.ContentLength
Request.ContentLength
Request.Accept
Request.Accept
Request.BasicAuthentication
Request.BasicAuthentication
Request.UserAgent
Request.UserAgent
2Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
2Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
2007:02:07 02:59:57
2007:02:07 02:59:57
adobe:docid:photoshop:2ef6df80-b614-11db-b931-c8e8dfd9ba45
adobe:docid:photoshop:2ef6df80-b614-11db-b931-c8e8dfd9ba45
%U}d4*hx
%U}d4*hx
m_EdPasswd
m_EdPasswd
650101-1455111
650101-1455111
2000/02/02
2000/02/02
The procedure entry point %s could not be located in the dynamic link library %s
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
TFORMCHANGEPASS
TFORMCHANGEPASS
TFORMLOADPASS
TFORMLOADPASS
Code: %d
Code: %d
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.
Transparent proxy cannot bind. UDP Not supported by this proxy.$Buffer terminator must be specified.!Buffer start position is invalid.
Reply Code is not valid: %s
Reply Code is not valid: %s
Unknown Protocol(Request method requires HTTP version 1.1DThis authentication method is already registered with class name %s.
Unknown Protocol(Request method requires HTTP version 1.1DThis authentication method is already registered with class name %s.
Command not supported.
Command not supported.
Address type not supported."%d: Circular links are not allowed
Address type not supported."%d: Circular links are not allowed
File "%s" not found
File "%s" not found
Object type not supported.
Object type not supported.
Invalid Port Range (%d - %d)
Invalid Port Range (%d - %d)
%s is not a valid service.
%s is not a valid service.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
%s is not a valid IPv6 address:The requested IPVersion / Address family is not supported.
Set Size Exceeded.)UDP is not support in this SOCKS version.
Set Size Exceeded.)UDP is not support in this SOCKS version.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Stack already created.1Only one TIdAntiFreeze can exist per application.&Cannot change IPVersion when connected$Can not bind in port range (%d - %d)
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.
Protocol not supported.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Protocol family not supported.0Address family not supported by protocol family.
Socket is not connected..Cannot send or receive after socket is closed.
Socket is not connected..Cannot send or receive after socket is closed.
Socket Error # %d
Socket Error # %d
Operation would block.
Operation would block.
Operation now in progress.
Operation now in progress.
Operation already in progress.
Operation already in progress.
Socket operation on non-socket.
Socket operation on non-socket.
OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
OThis operation is not valid because the current image contains no valid header.4The new size provided for image resizing is invalid.
Invalid stream operation
Invalid stream operation
JPEG error #%d
JPEG error #%d
JPEG Image File4Failed attempting to retrieve time zone information.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
JPEG Image File4Failed attempting to retrieve time zone information.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Resolving hostname %s.
Connecting to %s.
Connecting to %s.
Disconnected.jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Disconnected.jThis "Portable Network Graphics" image is not valid because it contains invalid pieces of data (crc error)yThe "Portable Network Graphics" image could not be loaded because one of its main piece of data (ihdr) might be corruptedUThis "Portable Network Graphics" image is invalid because it has missing image parts.[Could not decompress the image because it contains invalid compressed data.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
Description: BThe "Portable Network Graphics" image contains an invalid palette.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.nThis "Portable Network Graphics" image is not supported or it might be invalid.
The file being readed is not a valid "Portable Network Graphics" image because it contains an invalid header. This file may be corruped, try obtaining it again.nThis "Portable Network Graphics" image is not supported or it might be invalid.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
This "Portable Network Graphics" image is not supported because either it's width or height exceeds the maximum size, which is 65535 pixels length.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
There is no such palette entry.dThis "Portable Network Graphics" image contains an unknown critical part which could not be decoded.pThis "Portable Network Graphics" image is encoded with an unknown compression scheme which could not be decoded.cThis "Portable Network Graphics" image uses an unknown interlace scheme which could not be decoded.-The chunks must be compatible to be assigned.jThis "Portable Network Graphics" image is invalid because the decoder found an unexpected end of the file.8This "Portable Network Graphics" image contains no data.oSome operation could not be performed because the system is out of resources. Close some windows and try again.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Value must be between %d and %d
Value must be between %d and %d
Invalid clipboard format Clipboard does not support Icons
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Cannot open clipboard/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.,Multiselect mode must be on for this feature
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.,Multiselect mode must be on for this feature
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'
%s property out of range
%s property out of range
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
Unsupported clipboard format
Unsupported clipboard format
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)*Windows socket error: %s (%d), on API '%s'
Thread Error: %s (%d)*Windows socket error: %s (%d), on API '%s'
Asynchronous socket error %d
Asynchronous socket error %d
No help found for %s
No help found for %s
Invalid stream format$''%s'' is not a valid component name
Invalid stream format$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to get data for '%s'
Failed to get data for '%s'
Failed to set data for '%s'
Failed to set data for '%s'
Resource %s not found
Resource %s not found
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Unable to write to %s
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Operation aborted(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
I/O error %d
_ChangePassword
_ChangePassword
¡¡%original file name%.exe_1824_rwx_00155000_00001000:
NDOWS;%WinDir%\System32\Wbem;c:\Program Files\Wireshark
NDOWS;%WinDir%\System32\Wbem;c:\Program Files\Wireshark
%WinDir%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\
%WinDir%\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\
NDOWS;%WinDir%\System32\Wbem;c:\Program Files\Wiresh
NDOWS;%WinDir%\System32\Wbem;c:\Program Files\Wiresh
¡¡%original file name%.exe_1824_rwx_00158000_00002000:
rpcrt4.dll
rpcrt4.dll
%original file name%.exe
%original file name%.exe