not-a-virus:AdWare.Win32.Agent.aeph (Kaspersky), Backdoor.Win32.PcClient.FD, mzpefinder_pcap_file.YR, SearchProtectToolbar.YR, GenericInjector.YR (Lavasoft MAS)Behaviour: Backdoor
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 50b2a4e2b05f1a96cb606980e48cc21e
SHA1: 2a335a090157ddee7ce0dc3236bb1f8fade44e56
SHA256: 4f6017f9f7cacec1bbe0254f5f65be53532e8da7fb5421aef74469dcfb18e2f0
SSDeep: 6144:vrkT6Y0JQBkQRl7174NpNUM UHs CpgOUaNo8187yAMiC50RjBtC7QIh:vrkT63yRl1uqM gs zOUad87f2gjDuQ0
Size: 291648 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2013-03-12 10:51:45
Analyzed on: WindowsXP SP3 32-bit
Summary: Backdoor. Malware that enables a remote control of victim's machine.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Backdoor creates the following process(es):
nshBF.exe:2008
putfu.exe:2928
sp-downloader.exe:1716
CltMngSvc.exe:1784
CltMngSvc.exe:1640
nsoBA.tmp:2012
cltmng.exe:996
usetup.exe:3420
cltmngui.exe:1296
rundll32.exe:3116
rundll32.exe:3052
%original file name%.exe:312
nsuB5.exe:516
nsuC3.exe:2608
UpdateSoftware.exe:3512
UpdateSoftware.exe:3456
The Backdoor injects its code into the following process(es):No processes have been created.
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process nshBF.exe:2008 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsoC1.tmp\inetc.dll (30 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsoC1.tmp\a.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsoC1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsoC1.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsyC0.tmp (0 bytes)
The process putfu.exe:2928 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Program Files%\ProgramUpdater\Assistant.dll (264574 bytes)
%Program Files%\ProgramUpdater\AssistantSvc.dll (174 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\tf00294823.dll (30622 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\tf00294823.dll (0 bytes)
The process sp-downloader.exe:1716 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsuB5.exe (11736 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nseB6.tmp (52 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\MiniStubUtils.dll (7192 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\downloadstub[1] (52 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nstB3.tmp (7189 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\inetc.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\spstub[1].exe (11736 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\inet.txt1_M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nseB6.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\MiniStubUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsuB5.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsdB2.tmp (0 bytes)
The process CltMngSvc.exe:1784 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (9 bytes)
The process nsoBA.tmp:2012 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (360 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\v.png (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64.dll (103387 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32.dll (287458 bytes)
%Program Files%\SearchProtect\EULA.txt (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (2 bytes)
%Program Files%\SearchProtect\Main\bin\uninstall.exe (33747 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsuC3.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (3 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\x.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (886 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\main.js (10 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (378 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (933 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (12 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPTool64.exe (50351 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (983 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (256 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (859 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\bin\cltmngui.exe (100378 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\style.css (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (9 bytes)
%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (96792 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\SPtool.dll (81046 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (170836 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\browsers32.sdb (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\inetc.dll (784 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (3 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings.html (8 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (9 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (12 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (5 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (1552 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (7 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (1 bytes)
%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (2221 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nshBF.exe (5520 bytes)
%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (4 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (274 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (1 bytes)
%Program Files%\SearchProtect\Main\bin\SPTool.dll (81046 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (478 bytes)
%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\C2.tmp (1 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (1 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (6584 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (2 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nszBE.tmp (649 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\System.dll (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CT3309297[1] (649 bytes)
%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (11 bytes)
%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqBC.tmp (698645 bytes)
%Program Files%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (8560 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\SPtool.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsgBB.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp (0 bytes)
The process cltmng.exe:996 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserSettings.dat (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (1761 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\STG\Init_C2.tmp (0 bytes)
The process usetup.exe:3420 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\SoftSafe\UpdateSoftware\UpdateSoftware.exe (33792 bytes)
The process cltmngui.exe:1296 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI\rep\UIRepository.dat (1057 bytes)
The process %original file name%.exe:312 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\general_logo.bmp.tmp (808 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.1.ini (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\agup[1].exe (33536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\general_logo[1].bmp (784 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll (61 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_tin57DE.bat (84 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe (15 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll (673 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.dat (14184 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\TsuDll.dll (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3EFFE146.dat (13584 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2[1].txt (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_2.ini (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\4_3[1].txt (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sp-downloader[1].exe (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_3.ini (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\50b2a4e2b05f1a96cb606980e48cc21e.log (3036232 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\3[1].txt (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\4_2[1].txt (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x86\regsvr32.exe (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tpq[1].exe (163934 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.ico (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_tin3D45.bat (88 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tsu905D28F2.dll (2569 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Readme.txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.3.ini (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7306_appcompat.txt (214 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.ico (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x64\regsvr32.exe (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1[1].txt (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.2.ini (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.sp-downloader.exe (5064 bytes)
%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Readme.txt (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.putfu.exe (163934 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.usetup.exe (33536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6} (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.3.ini.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.usetup.exe.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_2.ini.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\3EFFE146.dat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x64 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\general_logo.bmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.1.ini.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tsu905D28F2.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.putfu.exe.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Readme.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_3.ini.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\r2.monitorbox1[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_tin3D45.bat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x86\regsvr32.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\putfu.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.ico (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\usetup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.sp-downloader.exe.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\sp-downloader.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~DFA459.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\down.312.2.ini.part (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x64\regsvr32.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_tin57DE.bat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6} (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x86 (0 bytes)
The process nsuB5.exe:516 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SPSetup[1].exe (433592 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsaB8.tmp (10114 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\inetc.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsoBA.tmp (433592 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\StubUtils.dll (9320 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsoBA.txt (70 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\inet.txt2_M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8_{0EB51FE4-C139-4E92-9149-3A3205829D57} (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nslB7.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\StubUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsoBA.txt (0 bytes)
The process nsuC3.exe:2608 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nskC5.tmp\inetc.dll (30 bytes)
The Backdoor deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nskC5.tmp\a.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nskC5.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nskC5.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsuC4.tmp (0 bytes)
The process UpdateSoftware.exe:3456 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):
%WinDir%\Tasks\UpdateSoftware-S-3956077583.job (692 bytes)
%Documents and Settings%\All Users\Application Data\SoftSafe\UpdateSoftware\3956077583.ini (42494 bytes)
Registry activity
The process nshBF.exe:2008 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsoC1.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 18 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BE C4 47 58 4B 6B EF 17 22 59 EB 24 D5 C4 58 D8"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process putfu.exe:2928 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"27ddcf6f" = "///%"
"8b9e4cbc" = "V/////%%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c6c5dd44" = "V/////%%"
"e46c271e" = "///%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"InstallDate" = "20130802"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"6185d035" = "VP/h/CP/V//l////"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"340d3099" = "/P////%%"
"f0bf0bde" = "///%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"NoModify" = "1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"0dc3ee96" = "/P////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c99a5f5c" = "///%"
"72758a5d" = "///%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"65114b36" = "Vl/l////"
[HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}]
"n" = "1"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"Install_Dir" = "%Program Files%\\ProgramUpdater"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"3c09c42b" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"bbf88800" = "///%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"data.0" = "EhAzvh69FPBF1QQIKEjFslfY7xq75BgUTdENBz6WBESt9QV5qGgSD3aWu9scPyVfS42NVZxh9/XZ"
"data.1" = "TQIce3jgQ9cnvcdefAVs2 yFbmPebjlTQbyxYAVXHkfV3t2SIFS7gu2beWuShY3y1X4jBDu77eFg9"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"uuid" = "3c84ccde-8cba38c6-a8a67a25"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"dbaf3ce3" = "/P////%%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}]
"6a096ac0" = "%Program Files%\ProgramUpdater\Assistant.dll"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"uuid" = "3c84ccde-8cba38c6-a8a67a25"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"37b7a6d8" = "UlAr/XJ/c//k////"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"QuietUninstallString" = "%System%\RUNDLL32.EXE C:\PROGRA~1\PROGRA~1\ASSIST~1.DLL,_uninstall /un /uq"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"3efeb33e" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c24899a6" = "MP/f/CF/Mx/l/C/////%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"Mode" = "4026531840"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"Version" = "22021985"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"dlpath" = "c:\progra~1\progra~1\assist~1.dll"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"0c230bcb" = "///%"
"7367429f" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"38583bc3" = "N//e/Ct/Vx/l/C/////%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c24899a6" = "MP/f/CF/Mx/l/C/////%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"Publisher" = "Certified Publisher"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"060df2cd" = "G/Ay/YP/FPAt/X6/clAj/Xl/alAy/XP/blAs/XD/ax/j/Xt/axAv/X6////%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"UninstallString" = "%System%\RUNDLL32.EXE C:\PROGRA~1\PROGRA~1\ASSIST~1.DLL,_uninstall /un"
"DisplayName" = "ProgramUpdater 1.80"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"2d71d5ab" = "V/////%%"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs" = "c:\progra~1\searchprotect\searchprotect\bin\spvc32loader.dll c:\progra~1\progra~1\assist~1.dll"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"a1dcff5b" = "V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"37b7a6d8" = "UlAr/XJ/c//k////"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"svi" = "0"
"svpath" = "c:\progra~1\progra~1\AssistantSvc.dll"
"svn" = "ProgramUpdater"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"1c311243" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"svx" = ""
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"493c7345" = ""
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"usr.0" = "SDlOIyTVNPRJLFHwys"
"usr.1" = "OoAzvzVNPRJLFHwysu"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"587b5709" = "V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"svt" = "1406946132"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DB 1F B8 5B 36 4A 20 5F 06 0C BD 69 70 B6 95 50"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"370856c7" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"370856c7" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c99a5f5c" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"State" = "0"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"7367429f" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"LRTS" = "0"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"LRTS" = "0"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"d94388d2" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"date" = "1406946131"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"f0bf0bde" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"0c230bcb" = "///%"
"f2c53c49" = "UlAr/XJ/c//k////"
"a1dcff5b" = "V/////%%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"38583bc3" = "N//e/Ct/Vx/l/C/////%"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"65114b36" = "Vl/l////"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"f2c53c49" = "UlAr/XJ/c//k////"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"d1abcdb6" = "///%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"CategoryName" = ""
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"f1f24e29" = "Vl/l/C/////%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"340d3099" = "///%"
"1520c6f1" = "V/////%%"
[HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}]
"n" = "1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"414bc593" = "///%"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"2d71d5ab" = "V/////%%"
"e8f9dcc7" = "UlAr/XJ/c//k////"
"51d2f2ea" = "J/Af/X6/GlAf/XD/aPAK/Y//G/Ay/YP/GPAf/B//VP/j/Cx/V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"1c311243" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"data.1" = "TQIce3jgQ9cnvcdefAVs2 yFbmPebjlTQbyxYAVXHkfV3t2SIFS7gu2beWuShY3y1X4jBDu77eFg9"
"data.0" = "EhAzvh69FPBF1QQIKEjFslfY7xq75BgUTdENBz6WBESt9QV5qGgSD3aWu9scPyVfS42NVZxh9/XZ"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c6c5dd44" = "V/////%%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c5705860" = "Vx////%%"
"27ddcf6f" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"d94388d2" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
"414bc593" = "///%"
"e8f9dcc7" = "UlAr/XJ/c//k////"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"iiid" = "1"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"Mode" = "4026531840"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"d1abcdb6" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"a0743acc" = "N/////%%"
"a2e3b941" = "///%"
"0e93c3f3" = "///%"
"51d2f2ea" = "J/Af/X6/GlAf/XD/aPAK/Y//G/Ay/YP/GPAf/B//VP/j/Cx/V/////%%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"a2e3b941" = "///%"
"a0743acc" = "N/////%%"
"7f69fa1f" = "///%"
"fe94ce1e" = "V/////%%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{6a096ac0}]
"NoRepair" = "1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"587b5709" = "V/////%%"
"0e93c3f3" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"0dc3ee96" = "/P////%%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"8b9e4cbc" = "V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"fe94ce1e" = "V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"493c7345" = ""
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"7f69fa1f" = "///%"
"e46c271e" = "///%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"72758a5d" = "///%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"3c09c42b" = "///%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"3efeb33e" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"c5705860" = "Vx////%%"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"usr.1" = "OoAzvzVNPRJLFHwysu"
"usr.0" = "SDlOIyTVNPRJLFHwys"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"060df2cd" = "G/Ay/YP/FPAt/X6/clAj/Xl/alAy/XP/blAs/XD/ax/j/Xt/axAv/X6////%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"1520c6f1" = "V/////%%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"iiid" = "1"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"bbf88800" = "///%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"f1f24e29" = "Vl/l/C/////%"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"6185d035" = "VP/h/CP/V//l////"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"date" = "1406946131"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Backdoor deletes the following registry key(s):
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
[HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process sp-downloader.exe:1716 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsoC1.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nskC5.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsqB9.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsjB4.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7A 2A E2 A9 81 84 36 BD 7B 42 E1 78 3D 42 64 38"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process CltMngSvc.exe:1784 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BB CD 84 90 AB DA D3 E6 6F 05 ED 27 A4 02 3E E1"
The process CltMngSvc.exe:1640 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "00 E0 2D 82 B3 B2 7D 21 1F F6 1C 23 7A AF 28 6C"
The process nsoBA.tmp:2012 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\SearchProtect]
"SPID" = "SP02A809A1-AD66-49FC-9E31-72DC6687025A"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs" = "C:\PROGRA~1\SearchProtect\SearchProtect\bin\SPVC32Loader.dll"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"Publisher" = "Client Connect LTD"
[HKLM\SOFTWARE\SearchProtect]
"Environment" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"UninstallString" = "C:\PROGRA~1\SearchProtect\Main\bin\uninstall.exe /S"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayVersion" = "2.16.10.61"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\SearchProtect]
"InstallDir" = "C:\PROGRA~1\SearchProtect"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect]
"DisplayIcon" = "C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe"
"DisplayName" = "Search Protect"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 DA 6C A1 E0 05 3D D3 D8 D5 21 6B 59 96 9D 16"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The Backdoor disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpUninstallCleanUp"
The process cltmng.exe:996 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 19 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9E F0 AD EC 9C A6 77 BE 21 CC 85 3C DC 12 40 F2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process usetup.exe:3420 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7F 25 DA DC 41 BA AA D7 AC 4B 80 45 A4 DD 4F 07"
The process cltmngui.exe:1296 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "40 37 E4 E8 13 07 42 4F 4F 78 A3 10 64 4B E3 73"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process rundll32.exe:3116 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "21 FA 11 E2 5E 53 E4 C1 73 DA B3 5D FE 3D 30 D1"
The process rundll32.exe:3052 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1F 3F CC 15 8A C9 CA 4E 0E B0 CA 44 2A A8 13 38"
The process %original file name%.exe:312 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"TSAware" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Favorites" = "%Documents and Settings%\All Users\Favorites"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ReceiveTimeout" = "600000"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"NetHood" = "%Documents and Settings%\%current user%\NetHood"
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"QuietUninstallString" = "C:\DOCUME~1\ALLUSE~1\APPLIC~1\INSTAL~1\{735B0~1\Setup.exe /remove /q"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons]
"usetup.exe" = "usetup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"TizPath" = "c:\%original file name%.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"Version" = "16777216"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Administrative Tools" = "%Documents and Settings%\All Users\Start Menu\Programs\Administrative Tools"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Templates" = "%Documents and Settings%\%current user%\Templates"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsoC1.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nskC5.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsqB9.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsjB4.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\Tsu905D28F2.dll,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"UninstallString" = "C:\DOCUME~1\ALLUSE~1\APPLIC~1\INSTAL~1\{735B0~1\Setup.exe /remove /q0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Administrative Tools" = ""
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"SendTo" = "%Documents and Settings%\%current user%\SendTo"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"EstimatedSize" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 14 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"Language" = "1033"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Fonts" = "%WinDir%\Fonts"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D5 04 7A 4A 78 41 5C DF 3E 0F 79 36 78 73 78 0E"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons]
"sp-downloader.exe" = "Search Protect"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Recent" = "%Documents and Settings%\%current user%\Recent"
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\571c756e-656d-49bc-97e6-a0b536b2c4a3]
"VersionMinor" = "0"
"VersionMajor" = "1"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following registry key(s):
[HKLM\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW]
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
[HKLM\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW]
"DWFileTreeRoot"
The process nsuB5.exe:516 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsoC1.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nskC5.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsqB9.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "28 32 54 8B C3 55 8B 70 52 06 34 A2 32 66 E1 2F"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process nsuC3.exe:2608 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsoC1.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nskC5.tmp\,"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A7 FB 67 E2 0C 17 C8 6F ED 0A 12 1D 56 87 F2 06"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Backdoor modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Backdoor modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Backdoor modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Backdoor deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process UpdateSoftware.exe:3512 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"1c311243" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
"060df2cd" = "G/Ay/YP/FPAt/X6/clAj/Xl/alAy/XP/blAs/XD/ax/j/Xt/axAv/X6////%"
"0dc3ee96" = "/P////%%"
"7367429f" = "///%"
"e8f9dcc7" = "UlAr/XJ/c//k////"
"2d71d5ab" = "V/////%%"
"7f69fa1f" = "///%"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"493c7345" = ""
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"587b5709" = "V/////%%"
"340d3099" = "/P////%%"
"72758a5d" = "///%"
"6185d035" = "VP/h/CP/V//l////"
"0e93c3f3" = "///%"
"51d2f2ea" = "J/Af/X6/GlAf/XD/aPAK/Y//G/Ay/YP/GPAf/B//VP/j/Cx/V/////%%"
"c24899a6" = "MP/f/CF/Mx/l/C/////%"
"d1abcdb6" = "///%"
"37b7a6d8" = "UlAr/XJ/c//k////"
"0c230bcb" = "///%"
"d94388d2" = "GxAy/YV/c/At/XD/c/Ay/XF/cPAj/YV/FlAy/X2/UxAp/X2/GxAk////"
"f0bf0bde" = "///%"
"65114b36" = "Vl/l////"
"f1f24e29" = "Vl/l/C/////%"
"a0743acc" = "N/////%%"
"c6c5dd44" = "V/////%%"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0]
"iiid" = "1"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"3efeb33e" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"3c09c42b" = "///%"
"c5705860" = "Vx////%%"
"c99a5f5c" = "///%"
"414bc593" = "///%"
"a2e3b941" = "///%"
"e46c271e" = "///%"
"fe94ce1e" = "V/////%%"
"1520c6f1" = "V/////%%"
"a1dcff5b" = "V/////%%"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D4 89 44 CE BF E0 60 7D B3 BB 03 65 70 EE BC 05"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"f2c53c49" = "UlAr/XJ/c//k////"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\00000000]
"370856c7" = "p01e07x0qx1A06h0n01 06l0nU1Z06t0mU1g0640nl0S06h0nl1A06E0, p01e07x0qx1D06I0mU1O0640n01Y06t0ml1N06b0qx1S02I0ox1S06q0nU0%, p01e07x0qx1N06t0nl1h06O0jx1P06Y0mU1g0640nl0S06h0nl1A06E0, p01T07m0nl1Y06E0qx1h06x0qx1O0640mU1g0640nl0S06h0nl1A06E0"
[HKU\.DEFAULT\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}\_6a096ac0\eae10f9d]
"27ddcf6f" = "///%"
"8b9e4cbc" = "V/////%%"
"bbf88800" = "///%"
"38583bc3" = "N//e/Ct/Vx/l/C/////%"
The process UpdateSoftware.exe:3456 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 jyYwQburpniZRRB5FiXXl0Nh4RV" = "NP6yu5 qaAnCQDWYSUGOC2EC0BO122uP"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"URLUpdateInfo" = ""
"URLInfoAbout" = ""
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 iI0lv89/XZTpmaWCAW6XiF/xIowoplYxrEc" = "NP6yu5 op/1ESUMOQIiA/"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"Publisher" = "PremiumSoft"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 rK2YdOCDWYSo sSZJb0LFNMK7umzJ4f" = "NP6yu5 o4IdosRJLFHmfwN6K"
"NP6yu5 obHhU6789/Xu3lMQKQBU9v0o8l1 pwHGQ7a" = "NP6yu5 ire7AFHwysu7daGH/1I 8/fYQTHvbDbfbFpsZR9hg1ZLTwQJfCgwjG"
"NP6yu5 jnTHsfABCDWtWkUM/W1aPBtS1 VQW3XAfac" = "NP6yu5 su8YtQ34567VnKOTlN"
"NP6yu5 t4SMY89/XZTo241UBcL1FgCdQgO" = "NP6yu5 jnxjzOdefABNqu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"SilentUninstall" = "c:\documents and settings\all users\application data\softsafe\updatesoftware\updatesoftware.exe /uninstall"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 oRN6utIKEG digPng1ySOBlAVHvZrTks5X3JZ0jUs" = "NP6yu5 o4IdosRJLFHmfwN6K"
"NP6yu5 t p YmhabcdJfHSAepXR5o1j1c DKl8GWf2QPTqLd" = "NP6yu5 ppjyvMvqomje35V 1BvjxcvmJzQBT"
"NP6yu5 qnt FxztvqoDfBtS/GCPHJVoOIo2SDnPtKi" = "NP6yu5 yZKZjefABCDz76N9UmHe0p0kgH5NGRfwxzCZGcCt9/G/oGfA6jw"
"NP6yu5 kq14RlhabcdIjFSyg16YzyLsH" = "NP6yu5 kdK38OABCDWIHtWKZ5PJuKDRJ"
"NP6yu5 qCEj2JrpnikTXYRb/hjk8pv2i7" = "NP6yu5 ire7AFHwysu7daGH/1I 8/fYQTHvbDbfbFpsZR9hg1ZLTwQJfCgwjG"
"NP6yu5 mGMVNpnikg0UES4we2P15TB9y" = "NP6yu5 zbMgbIcdefAUN"
"NP6yu5 kzHwZuJLFHw5Fr3FSOzPpISE/F" = "NP6yu5 vnNnZzG xztBe7qNMhrU5nv7p2jg3MSoGKR2AOifGjaisEzPiKveJre7eC2osjAxko/vUyvZtN4IYuES3zz9TinpNYuYzUZrmzq09xRJjuTq5AlcMd3b9ymQA4IBVY581FGF0U3Y qvoIHd3yitOyzlhhUG9isJtU cLS4On UnxKakKxqiq7s2UoJE3nd3krWq 9v5e1lcOEFzZuwR0C5G0Buk1ekwXnca4/GyWLQ0RKA9/gnyRwN doQEiqxnReBKT7HtpltL5cigNEXkGeb6N3PGb6 KyXobYwYER8wYBbGekIO59ZF2 v3RA rA9WcH4txlPPE9YV8gwJ1qDAFwj/PZPKgcu2OOVdZjePKZtQKwHQzU0RtDHELJESORhEr2Tb bhyJwiujYtSlzFVmWr9noi3dhI8YGcrw XL7KqDHuJCUbSKlV3Y4qrbtWHvv8m5nZ93LHYjJcoiD3QD8ZTuqjowIP0PH1FyNY3/n"
"NP6yu5 jJE/mnBCDWYvA42sczUv9SClfrqvZXt8sBARO" = "NP6yu5 qaAnCQDWYSUGOC2EC0BO122uP"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"NoModify" = "1"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 mA7A/0RJLFH3oCqCND9QOs7c7LJLxGmTX4Y5fn0nd" = "NP6yu5 xztvqomjlha"
"NP6yu5 zUPS3jlhabcQDMNIScd6AO3aDxmTq1WIaX6" = "NP6yu5 tQ3dtOHwysu7dAPo9rWzs6Cz73val5GwlYqnEmAXyKRiEzz 0sbZtS5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"DisplayName" = "UpdateSoftware"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 tJp3sbqomjlSvJfgkDPgofAaSAq8LeS0XEI" = "NP6yu5 nsOVqgsurpn3luw"
"NP6yu5 imD09G789/XrRUo/jOxMoD5p8s7z6" = "NP6yu5 owmZMztvqom44"
"NP6yu5 y9R/xAztvqoWETd7yHx7kCFYzD24sLA" = "NP6yu5 xztvqomjlha"
"NP6yu5 rOHR67habcdI6oQitBZylEDlKv" = "NP6yu5 ookVA701234YHM8"
"NP6yu5 pNrKTFbcdefEjL8Z1TlnENCpBpb" = "NP6yu5 p97ufSUMOQItTzRI6FRPyp"
"NP6yu5 m493B1JLFHwfSLP0cq" = "NP6yu5 p97ufSUMOQItTzRI6FRPyp"
"NP6yu5 t5w/eBhabcdLg7/sFSAaTxRvG" = "NP6yu5 xvTqlqdefABK 80Gq2mWBC1o0 "
"NP6yu5 qAAIJrpnikgVSUoLaz3mK8u RgKbxPY" = "NP6yu5 ms6Kogvqomje5FgkwM"
"NP6yu5 o/JAuurpnikZzc72iod641QVSkWTqJSu5zR" = "NP6yu5 rk50XvKEG xeKLvesJcI/uDaKRkMWR2hnutqmBtZdkaLX2fgHL"
"NP6yu5 q2cpRx789/XueIe5iLgmR36Hi9ZR5HNZs2A" = "NP6yu5 p2g4ahLFHwykW"
"NP6yu5 mPpwLQDWYSUoj8v7lBa0 8W0MSmWN4ClWM7" = "NP6yu5 mAzKd789/XZzLMPPGMuVLt9zIJASWw"
"NP6yu5 me6uTVNPRJL13Jfl4Pkq3 KZkkBGDuDhpPPquV" = "NP6yu5 owmZMztvqom44"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"CategoryName" = "Apps"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 sFynDebcdef tMD" = "NP6yu5 zbMgbIcdefAUN"
"NP6yu5 vGPjjAfABCDtsHMzvqSfT7E4si" = "NP6yu5 nsOVqgsurpn3luw"
"NP6yu5 u2C5SlhabcdKYXGD2X5Dtp " = "NP6yu5 vCEet 9/XZTFWNaRVti08X5GA"
"NP6yu5 yEFhrM xztvBTqybYrHCKZLQDEDd77yDa71" = "NP6yu5 nWYONZWYSUMmKdWHSyBsxoIXlq8L0acxfPYSvuyukjdQWYOTbm8kHsQ"
"NP6yu5 xyxzUr xztv8XRDd4dOlw/ 0eLrMM" = "NP6yu5 p/RcQikg012CPtvY0JqomLb"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"NoRepair" = "1"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 s2TbxEefABCxJ0DAXr /fsJdEdZsSHr HV" = "NP6yu5 kdK38OABCDWIHtWKZ5PJuKDRJ"
"NP6yu5 ow1rR56789/ue1sByvUf4kVuix" = "NP6yu5 p2g4ahLFHwykW"
"NP6yu5 jxu9x/ztvqoWwAvzzG1eDHhjPa" = "NP6yu5 mAzKd789/XZzLMPPGMuVLt9zIJASWw"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"InstallDate" = "20130802"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 q83XdcabcdeK18vAC0H9NVFErZY89qziqz" = "NP6yu5 xvTqlqdefABK 80Gq2mWBC1o0 "
"NP6yu5 xegqyZTVNPRhap40RL5nzk9RVF fIgeuX" = "NP6yu5 ouLGsR/XZTVHZg6"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "16 95 24 04 27 14 9F F1 15 0F 02 1A D1 03 90 0A"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"_In" = "20140802"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 upBrs456789yYTFdDrzVA0PJHl5GUN4cRRU6I0 /b" = "NP6yu5 ms6Kogvqomje5FgkwM"
"NP6yu5 mGooxrikg01VravP7V/5b68FyY" = "NP6yu5 su8YtQ34567VnKOTlN"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"DisplayIcon" = "C:\Windows\System32\msiexec.exe"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 t3BD56789/Xu4TF4qCfDCBTHm9BO81oA/UPCl" = "NP6yu5 jnxjzOdefABNqu"
"NP6yu5 vbNHYCDWYSUoiK7bPU/LiTlOXXB/Y/8ZsgUeDPvDrC" = "NP6yu5 ouLGsR/XZTVHZg6"
"NP6yu5 sH9 Y xztvq/XYWHIi jTIOMPd" = "NP6yu5 nWYONZWYSUMmKdWHSyBsxoIXlq8L0acxfPYSvuyukjdQWYOTbm8kHsQ"
"NP6yu5 iqFGhLqomjlSrvHfNHJ3oZIgyJwy44WgZ8t" = "NP6yu5 vnNnZzG xztBe7qNMhrU5nv7p2jg3MSoGKR2AOifGjaisEzPiKveJre7eC2osjAxko/vUyvZtN4IYuES3zz9TinpNYuYzUZrmzq09xRJjuTq5AlcMd3b9ymQA4IBVY581FGF0U3Y qvoIHd3yitOyzlhhUG9isJtU cLS4On UnxKakKxqiq7s2UoJE3nd3krWq 9v5e1lcOEFzZuwR0C5G0Buk1ekwXnca4/GyWLQ0RKA9/gnyRwN doQEiqxnReBKT7HtpltL5cigNEXkGeb6N3PGb6 KyXobYwYER8wYBbGekIO59ZF2 v3RA rA9WcH4txlPPE9YV8gwJ1qDAFwj/PZPKgcu2OOVdZjePKZtQKwHQzU0RtDHELJESORhEr2Tb bhyJwiujYtSlzFVmWr9noi3dhI8YGcrw XL7KqDHuJCUbSKlV3Y4qrbtWHvv8m5nZ93LHYjJcoiD3QD8ZTuqjowIP0PH1FyNY3/n"
"NP6yu5 jO7cksRJLFHdItgO4" = "NP6yu5 ookVA701234YHM8"
"NP6yu5 kMSXeBMOQIKhE69m1QE674UDEx" = "NP6yu5 op/1ESUMOQIiA/"
"NP6yu5 qwDMhUjlhabRi95gdx9wB Kt8h" = "NP6yu5 rk50XvKEG xeKLvesJcI/uDaKRkMWR2hnutqmBtZdkaLX2fgHL"
"NP6yu5 s/N9q2LFHwy5Ge3vWafDDyM0XgIXL/SocfUpBEc2iz" = "NP6yu5 xKYF 812345Z1"
"NP6yu5 oFUvMDbcdefHBbxrMluGJ9Aygj" = "NP6yu5 yZKZjefABCDz76N9UmHe0p0kgH5NGRfwxzCZGcCt9/G/oGfA6jw"
"NP6yu5 qmagWavqomjYke3rg3RaIWgtRR6ly542b" = "NP6yu5 vCEet 9/XZTFWNaRVti08X5GA"
"NP6yu5 oxTCwROQIKEbfoQmXOVq3pyCV" = "NP6yu5 zbMgbIcdefAUN"
"NP6yu5 u4W7I3FHwysfpPWVEc640Vgj7vuI5FRvR" = "NP6yu5 xKYF 812345Z1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"UninstallString" = "c:\documents and settings\all users\application data\softsafe\updatesoftware\updatesoftware.exe /uninstall"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 uGnmtBCDWYSqb6jM/jZxaHmJs4bb/qRin 8" = "NP6yu5 zuPIYS89/XZFjB3nocNRH61"
"NP6yu5 xh2uW4Hwysu7Ssr8oWZx2xW2hDd4djxqbX" = "NP6yu5 zbMgbIcdefAUN"
"NP6yu5 r 8G2h34567HEDrcOMl 7 u93c" = "NP6yu5 zuPIYS89/XZFjB3nocNRH61"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-3956077583]
"DisplayVersion" = "3.3.0.1309"
[HKLM\SOFTWARE\UpdateSoftware\3956077583\NP6yu5 tnZZH0OQIKE1/gD3hJMqT/]
"NP6yu5 xGCT2oqomjlV2gRnCoLMWn7nyn" = "NP6yu5 tQ3dtOHwysu7dAPo9rWzs6Cz73val5GwlYqnEmAXyKRiEzz 0sbZtS5"
Dropped PE files
MD5 | File path |
---|---|
af7ce801c8471c5cd19b366333c153c4 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Tsu905D28F2.dll |
02c162fd7706e887624dfcc410979355 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nshBF.exe |
7f6b1c9c1e9b1b936b8a6c44e7588063 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsoBA.tmp |
02c162fd7706e887624dfcc410979355 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsuC3.exe |
23912df27a61ea0463c5509ba6a97579 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\putfu.exe |
0b813086a3400aafa1639d08823fbd46 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\sp-downloader.exe |
9dfbb035592ea044a4b29977a3f272ff | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Addons\usetup.exe |
d1f319803ffc36548f3a2a3078db5fe3 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll |
e717f6ce3a7429bfa6d7f3cf66737a4b | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe |
b4ef2fa4426becd8ef546258ceb206b7 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll |
6fd673efd6e4d460318c4f9ee43367c8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\spstub[1].exe |
23912df27a61ea0463c5509ba6a97579 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tpq[1].exe |
7f6b1c9c1e9b1b936b8a6c44e7588063 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SPSetup[1].exe |
9dfbb035592ea044a4b29977a3f272ff | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\agup[1].exe |
0b813086a3400aafa1639d08823fbd46 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sp-downloader[1].exe |
d4d1cc69e363813c14f289694756aa1e | c:\Program Files\ProgramUpdater\Assistant.dll |
348bd6c1565bd5f85ed13b56d2401f05 | c:\Program Files\ProgramUpdater\AssistantSvc.dll |
fe11b14440be254f685acbb7fd62a966 | c:\Program Files\SearchProtect\Main\bin\CltMngSvc.exe |
437467dfb9cf21c183acf3e67a9e424c | c:\Program Files\SearchProtect\Main\bin\SPTool.dll |
aaec330e1fb52dae0d09a73d522e8c9a | c:\Program Files\SearchProtect\Main\bin\uninstall.exe |
b5f8de75260f7113d5191270cb557da9 | c:\Program Files\SearchProtect\SearchProtect\bin\SPTool64.exe |
0321511cbfb7315afe0108fbd0b80df1 | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32.dll |
8898fee7a02e3d3bf63167d068af6ac3 | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC32Loader.dll |
4b65a420b108f3418fe6d3cdb64a226e | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC64.dll |
6c5c6ae63ee4d7e88eb846e36b06eace | c:\Program Files\SearchProtect\SearchProtect\bin\SPVC64Loader.dll |
f179d39cdc9c25f28f0a2510fc96266c | c:\Program Files\SearchProtect\SearchProtect\bin\cltmng.exe |
ffe156d694dd7583948cb96dcfac5a3d | c:\Program Files\SearchProtect\UI\bin\cltmngui.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Static Analysis
VersionInfo
Company Name: SoftSafe
Product Name: SoftSafe
Product Version: 1.0.0.1
Legal Copyright: Copyright (c) 2012 SoftSafe
Legal Trademarks:
Original Filename: TSULoader.exe
Internal Name: TSULoader
File Version: 2013.4.21.1505
File Description: Installer for SoftSafe
Comments: WinNT (x86) Unicode Lib Rel
Language: Language Neutral
Company Name: SoftSafeProduct Name: SoftSafeProduct Version: 1.0.0.1Legal Copyright: Copyright (c) 2012 SoftSafeLegal Trademarks: Original Filename: TSULoader.exeInternal Name: TSULoaderFile Version: 2013.4.21.1505File Description: Installer for SoftSafeComments: WinNT (x86) Unicode Lib RelLanguage: Language Neutral
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 7672 | 7680 | 4.5056 | b1ae6dcdc3a7ba319c6d5e0b1a2eadbc |
.rdata | 12288 | 1794 | 2048 | 3.26018 | cd4f20f041a2da05dfe5974fe61bd4ec |
.data | 16384 | 1040 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 20480 | 8288 | 8704 | 3.02754 | 7fb2e9f5274919825402377c03c83fed |
.reloc | 32768 | 348 | 512 | 2.09579 | 938152484b33bca77bd622973abb524e |
.tsustub | 36864 | 120955 | 121344 | 5.54288 | 9c583a14d4612420371a949372873fe7 |
.tsuarch | 159744 | 144896 | 144896 | 5.54321 | 880ff51a584fe29f2de4fa39efe3d924 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 5772
0d247883949c00d2cf6b602c27f4916d
e412e2bcbf16e7c9139c83fda4e36f5b
98b18296e3c8a52e1f1e8f7f20cd9fb8
4166ff38501f8c7b5402097cafc922fb
7fc38e45fbf6a4242857bfbb5f774be7
ed1b5c70c1ece7fd2d360754577ab278
7bee12648483a51960e73c2b3d2a77e1
170fce66d866070c75d12413d51ec860
99d19113c1ebe160c802234c58568fe4
8a7144f7f454d2aade092229821ae6a8
790af56970b0d1771791447c9a6b8671
1531a7b66260649808e2c6fb21e582d6
207600d2996289ce5f7307e8ea48492a
e1f955ea38bafa3630513c770e0e7389
dffa8b3cb8b5ab4239e433ba5ec4e34c
befdc049baa90e1f7f3872e5e7494304
21b7d36e5544e155c28fc10283b3861c
3f77c4b2c50bc7655aeb3fc620f5afc0
2a9cc014326a3f4ca20bb6c7195d0584
8e81de065a044ea2e2f5f639877ed86f
757d48107f1be738bf017ede2cc278ad
e2ff66ea955bcd40da4eddb3cf2ea52a
be9f1cd4fa01014b7e9505ff31af2e45
175b6fd90870700f1bd91fcae8d55c63
fe2e08e45a75cca4ad42e8a61598ac8a
Network Activity
URLs
URL | IP |
---|---|
hxxp://installbox1.info/?step_id=1&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | |
hxxp://installbox1.info/?step_id=2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | |
hxxp://installbox1.info/images/general_logo.bmp | |
hxxp://installbox1.info/?step_id=3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | |
hxxp://e6337.g.akamaiedge.net/sp-downloader.exe | |
hxxp://Jazz-1846647836.us-east-1.elb.amazonaws.com/ | |
hxxp://e9287.g.akamaiedge.net/stub/spstub.exe | |
hxxp://sp-download.va.spccint.com/download/CarrierId/CT3309297/CarrierVersion/DEFAULT/CarrierType/ctid/Brand/SP | |
hxxp://e9287.g.akamaiedge.net/Installer/2.16.10.61/SPSetup.exe | |
hxxp://e3937.g.akamaiedge.net/spinstallersettings/2.16.10.61/test/ABTEST_SETTINGS_ID/carrierId/CT3309297 | |
hxxp://installbox1.info/?report_version=5& | |
hxxp://sp-ip2location.va.spccint.com/ip/?client=sp | |
hxxp://a1015.g1.akamai.net/UP/settings/?ctid=CT3309297&UM=&c=CA&DUM=2 | |
hxxp://installbox1.info/?step_id=4_2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | |
hxxp://installbox1.info/addons/dfndr/180/tpq.exe | |
hxxp://datadownloadscan.info/get/?data=0BIqmZDY2uCNUO3ZTV47GddPvdyzkDVy+7LVMeiWPYiBnCaj7k5VmXKWI1PAmmSZgMSm0PBWd+AnT1E+ZQB16S/DiF+4fQvCbJ4VtAbtEkcTRdGLtOnGtxlnAjTmF29P02pymuZ0juTFPgy+HLQK909FbEdw4mVH+2P0HYsvyvhUPv375adfwI9Jyas2SEptJZhWja+RPXUMh0JkfAV4d311MD3ax3iE83oTL5ZzvJIdGyqIVbcsAi9qZyFbes0e/tD4t4SKs6wr2H8DmWcO67q38oNx+Sjmb80MxaLStTzP1sNUuKGHBdH9rZgNB/p3YWcakrG4mxDarwAZZ7JqQr4iPemyDeSdNKOq9UylOMsaP3dc7dVWAfI8hWCSqeWPOYtijjdt4KTWGFQP3jLhEKYt6QCilzBXEsdQbQMSoK1j0a0U2CN8xbl5wn1OzIZjkg4hgbatgSr13yPyusR/RI7SKQ50xtOKstDtw/AOpESdJvqcHU60CYuxZTVN&version=4 | 162.210.192.21 |
hxxp://installbox1.info/?step_id=4_3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | |
hxxp://installbox1.info/addons/agup.exe | |
hxxp://sp-storage.spccinta.com/Installer/2.16.10.61/SPSetup.exe | 23.9.111.99 |
hxxp://c1.installbox1.info/?step_id=2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | 54.191.186.103 |
hxxp://sp-download.spccint.com/download/CarrierId/CT3309297/CarrierVersion/DEFAULT/CarrierType/ctid/Brand/SP | 199.101.114.124 |
hxxp://i1.installbox1.info/images/general_logo.bmp | 54.191.186.103 |
hxxp://i1.installbox1.info/addons/dfndr/180/tpq.exe | 54.191.186.103 |
hxxp://c1.installbox1.info/?step_id=4_3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | 54.191.186.103 |
hxxp://r2.monitorbox1.info/?report_version=5& | 54.191.186.103 |
hxxp://c1.installbox1.info/?step_id=3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | 54.191.186.103 |
hxxp://sp-storage.conduit-services.com/sp-downloader.exe | 23.9.99.152 |
hxxp://c.api.seccint.com/UP/settings/?ctid=CT3309297&UM=&c=CA&DUM=2 | 184.84.243.35 |
hxxp://i1.installbox1.info/addons/agup.exe | 54.191.186.103 |
hxxp://sp-alive-msg.databssint.com/ | 184.72.217.85 |
hxxp://c1.installbox1.info/?step_id=4_2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | 54.191.186.103 |
hxxp://sp-ip2location.spccint.com/ip/?client=sp | 199.101.114.209 |
hxxp://c1.installbox1.info/?step_id=1&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* | 54.191.186.103 |
hxxp://sp-installer.databssint.com/ | 54.243.179.104 |
hxxp://sp-settings.spccint.com/spinstallersettings/2.16.10.61/test/ABTEST_SETTINGS_ID/carrierId/CT3309297 | 23.9.97.214 |
hxxp://sp-storage.spccinta.com/stub/spstub.exe | 23.9.111.99 |
r1.reportbox1.info | 95.211.169.207 |
c-sp-download.spccint.com | 23.9.97.214 |
sp-autoupdate.spccint.com | 23.9.97.214 |
servicemap.spccint.com | 23.9.97.214 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 1062
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"install_completed","SP_ID":"SP02A809A1-AD66-49FC-9E31-72DC6687025A","SP_version":"2.16.10.61","OS_name":"Microsoft Windows XP Professional Service Pack 3 (build 2600)","OS_version":"5.1","browser":"InternetExplorer","browser_version":"6.0.2900.5512","carrier_type":"ctid","carrier_ID":"CT3309297","carrier_version":"","carrier_userid":"","carrier_UM":"","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","hp_takeover":"true","other_takeover":"true","environment":"","sequence_timestamp":"1406946115024","profile_number":"1","user_number":"1", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8", "download_length": 3172, "install_type": "install", "result": "success", "reason": "0","v_env_tests":{"10_ProcessesExists":"0","10_ModuleInjected":"0","10_FakeSPServiceParent":"0","12_ProcessesExists":"0","12_StatusKeyExists":"0"},"v_env_codes":{"10":"0","12":"0"},"channel_id": "", "brand": "SP" , "previous_brand":"", "brand_install_type":"cleanmachine","Experiment":"","Variant":""}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:20:02 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
HTTP/1.1 202 Accepted..Date: Sat, 02 Aug 2014 07:20:02 GMT..P3P: CP="NOI ADM DEV COM NAV OUR STP"..Server: Apache-Coyote/1.1..Content-Length: 0..Connection: keep-alive..
POST /?report_version=5& HTTP/1.1
Accept: */*
Content-Type: application/x-www-form-urlencoded
User-Agent: TixDll
Host: r2.monitorbox1.info
Content-Length: 547
Cache-Control: no-cache
data=A3EmlG/I75WJLly89/0yV5rzHXMaYBH5s1RblGeLdTQm7lO5//cpa9b/FrrftHzeCbhgmgcg7YlcCHRMxmiUmqEq4L6TSniNwnf5MFdxM6DGWyia2UCU8DIglw06O5NlVr6NsvTUORcnD1k3oOwe36bvzOQY0ALPK9/9hxuY+hJO4Gq1kEuTaqddJp891b2jJ0/dKXaPMcTfOWtTMT/h+ERcYwOhzYZZXf5N7Y0+ZhObUttuvUMTzA+AC9XkLi23QCTILN+ysIb5R3IBTJ9GD9WXuFIzmK+ZvCs90/swyNt2aITeduHF6PkLVKEoMpcSEyuGIIaTDc6smg3cujTmHNW56VnsvGtNZJXGO5Wfl9qK9Ru+TJIoZARKTC8e8dqFtNseO40PhKJl+XlzYxiTkIDlE1kYHfJPSy1LuDa2yf/+5CkgIdZGgbTui0Z1eRsVnkd9HNHgr3HifZciV0ld7qksCLq0RORmFp/M50MkXOU86sto8+AK+F1TIG249JNTmPfoKtbc
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:19:44 GMT
Content-Type: application/json; charset=UTF-8
Content-Length: 2
Connection: close
{}..
GET /?step_id=4_2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: c1.installbox1.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:20:04 GMT
Content-Type: text/html
Content-Length: 9090
Connection: close
Content-Disposition: attachment; filename="4_2.txt"
..[.I.n.s.t.a.l.l.e.r.]...P.r.o.d.u.c.t.N.a.m.e.=.".S.e.t.u.p."...P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.".1...0."...P.r.o.d.u.c.t.C.o.d.e.=.".3.4.a.0.9.f.3.2.-.9.9.0.6.-.4.5.1.5.-.9.4.3.a.-.8.7.7.9.5.d.0.b.a.a.6.d."...P.u.b.l.i.s.h.e.r.I.D.=.".3.8.8."...S.o.u.r.c.e.I.D.=.".0."...P.a.g.e.I.D.=.".0."...A.f.f.i.l.i.a.t.e.I.D.=.".1._.e.x.e."...I.n.s.t.a.l.l.e.r.I.D.=.".9.3.2.4.4.7.4.0.4."...L.o.c.a.l.e.=.".<.L.a.n.g.u.a.g.e.>."...D.a.t.e.=.".2.0.1.4./.0.8./.0.2."...T.i.m.e.=.".7.:.2.0.:.0.4."...S.h.o.w.I.n.T.a.s.k.b.a.r.=.".1."...H.i.d.e.S.c.r.e.e.n.s.=.".0."...R.u.n.O.n.c.e.=.".1."...L.o.g.U.r.l.=."."...L.o.g.S.t.a.r.t.e.d.=."."...L.o.g.F.i.n.i.s.h.e.d.=."."...L.o.g.B.e.f.o.r.e.S.e.n.d.R.e.p.o.r.t.=."."...L.o.g.A.f.t.e.r.S.e.n.d.R.e.p.o.r.t.=.".".....[.S.e.r.v.e.r.]...I.D.=.".3."...L.o.c.a.t.i.o.n.=.".D.E.".....[.U.s.e.r.I.n.f.o.]...C.o.u.n.t.r.y.C.o.d.e.=.".U.S."...I.P.A.d.d.r.e.s.s.=.".1.8.4...1.0.7...3.8...3.8."...W.e.b.B.r.o.w.s.e.r.=.".4.".....[.R.n.d.G.e.n.]...P.e.r.c.e.n.t.a.g.e.=.".9.".....[.S.c.r.e.e.n.7.6.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".T.r.y. .A.g.a.i.n."...B.u.t.t.o.n.2.=.".C.a.n.c.e.l."...L.a.b.e.l.1.=.".W.e.'.r.e. .s.o.r.r.y.:. .t.h.e. .d.o.w.n.l.o.a.d. .l.i.n.k. .s.e.e.m.s. .t.o. .b.e. .b.r.o.k.e.n... .P.l.e.a.s.e. .v.i.s.i.t. .t.h.e. .a.u.t.h.o.r.'.s. .h.o.m.e.p.a.g.e. .f.o.r. .f.u.r.t.h.e.r. .i.n.f.o.r.m.a.t.i.o.n..."...[.S.c.r.e.e.n.7.5.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".Y.e.s."...B.u.t.t.o.n.2.=.".N.o."...L.a.b.e.l.1.=.".A.r.e. .y.o.u. .s.u.r.e.?."...[.S.e.l.e.c.t.
<<< skipped >>>
GET /spinstallersettings/2.16.10.61/test/ABTEST_SETTINGS_ID/carrierId/CT3309297 HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-settings.spccint.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Content-Type: application/json; charset=text/plain
Last-Modified: Sat, 02 Aug 2014 07:18:17 GMT
ETag: "a55e817ccf82b7815aa0fbb683e056ce"
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Content-Length: 649
Cache-Control: private, max-age=900
Expires: Sat, 02 Aug 2014 07:34:39 GMT
Date: Sat, 02 Aug 2014 07:19:39 GMT
Connection: keep-alive
{"InstallerSettings":{"CHExtension_Id":null,"CHExtension_LandingPage":null,"CHExtension_Name":null,"DEFAULT_CMD":null,"DUM":"2","InstallSPPDriver":null,"IsAUAllowednoTB":"true","LOST_USERS":"false","PING":"false","SERVICE_LOST_USERS":null,"TbExternalAssetsEnable":"true","UNINSTALL_PING":"false"},"AbTestSettings":{"Experiment":"","Variant":"","TestParameter":""},"CarrierSettings":{"CHExtensionMode":"false","v_env":"true","v_env_10":"true","v_env_12":"false"},"signature":"fI88PfOLh/cwPkDn6hWVaZZz5NmGlTLB/IX tlldXGPz/A16uO6j6bRrMZ gxZol5x97RJDaVTQa7kkp48CVU4agw9/18mr b0KoBkbYs13i mPnJ xVcrlMWIryxcOvXr/CW0KNatxjsXax0OmD9Aw0SayyFJFEUpJYYEpp4hc="}..
GET /?step_id=3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: c1.installbox1.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:19:24 GMT
Content-Type: text/html
Content-Length: 6822
Connection: close
Content-Disposition: attachment; filename="3.txt"
..[.I.n.s.t.a.l.l.e.r.]...P.r.o.d.u.c.t.N.a.m.e.=.".S.e.t.u.p."...P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.".1...0."...P.r.o.d.u.c.t.C.o.d.e.=.".3.e.b.b.3.d.8.c.-.0.5.f.4.-.4.0.e.3.-.9.c.b.e.-.2.8.e.d.5.e.1.d.3.2.6.4."...P.u.b.l.i.s.h.e.r.I.D.=.".3.8.8."...S.o.u.r.c.e.I.D.=.".0."...P.a.g.e.I.D.=.".0."...A.f.f.i.l.i.a.t.e.I.D.=.".1._.e.x.e."...I.n.s.t.a.l.l.e.r.I.D.=.".9.3.2.4.4.7.4.0.4."...L.o.c.a.l.e.=.".<.L.a.n.g.u.a.g.e.>."...D.a.t.e.=.".2.0.1.4./.0.8./.0.2."...T.i.m.e.=.".7.:.1.9.:.2.4."...S.h.o.w.I.n.T.a.s.k.b.a.r.=.".1."...H.i.d.e.S.c.r.e.e.n.s.=.".0."...R.u.n.O.n.c.e.=.".1."...L.o.g.U.r.l.=."."...L.o.g.S.t.a.r.t.e.d.=."."...L.o.g.F.i.n.i.s.h.e.d.=."."...L.o.g.B.e.f.o.r.e.S.e.n.d.R.e.p.o.r.t.=."."...L.o.g.A.f.t.e.r.S.e.n.d.R.e.p.o.r.t.=.".".....[.S.e.r.v.e.r.]...I.D.=.".3."...L.o.c.a.t.i.o.n.=.".D.E.".....[.U.s.e.r.I.n.f.o.]...C.o.u.n.t.r.y.C.o.d.e.=.".U.S."...I.P.A.d.d.r.e.s.s.=.".1.8.4...1.0.7...3.8...3.8."...W.e.b.B.r.o.w.s.e.r.=.".4.".....[.R.n.d.G.e.n.]...P.e.r.c.e.n.t.a.g.e.=.".6.4.".....[.S.c.r.e.e.n.7.5.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".Y.e.s."...B.u.t.t.o.n.2.=.".N.o."...L.a.b.e.l.1.=.".A.r.e. .y.o.u. .s.u.r.e.?."...[.S.c.r.e.e.n.7.6.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".T.r.y. .A.g.a.i.n."...B.u.t.t.o.n.2.=.".C.a.n.c.e.l."...L.a.b.e.l.1.=.".W.e.'.r.e. .s.o.r.r.y.:. .t.h.e. .d.o.w.n.l.o.a.d. .l.i.n.k. .s.e.e.m.s. .t.o. .b.e. .b.r.o.k.e.n... .P.l.e.a.s.e. .v.i.s.i.t. .t.h.e. .a.u.t.h.o.r.'.s. .h.o.m.e.p.a.g.e. .f.o.r. .f.u.r.t.h.e.r. .i.n.f.o.r.m.a.t.i.o.n..."...[.S.e.l.e.c.
<<< skipped >>>
GET /images/general_logo.bmp HTTP/1.1
Accept: */*
Host: i1.installbox1.info
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:19:23 GMT
Content-Type: image/x-ms-bmp
Content-Length: 21616
Last-Modified: Wed, 30 Jul 2014 00:07:05 GMT
Connection: close
ETag: "53d83729-5470"
Accept-Ranges: bytes
BMpT......6...(.......:...........:P..........................................................u]`.!!!.%!).))).511.==9.NFD.VNJ.ZYY.nRS.u]`.lig..cg.~~s..kk..ks..ss..s{...w..........sw.................................J...|.h.y.....s...............z...........................g.........................................................c...w...k...u...........{.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...................................................................................................................................
<<< skipped >>>
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 687
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"Stub_Init", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8", "environment":"", "command_line":"-carrier_type=ctid -carrier_id=CT3309297 -platform=all -local=en-us -startpage=true -defaultsearch=true -sessionid=M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8 -downloadlength=688 -EXT_ISID=false", "download_length": "688", "carrier_ID": "CT3309297", "carrier_type": "ctid", "carrier_version": "DEFAULT", "brand": "SP", "EXT_ISID":"false","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","installer_version":"2.4.2.5", "OS_name":"Microsoft Windows XP Professional Service Pack 3 (build 2600)", "OS_version":"5.1"}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:19:31 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
....
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 883
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"Stub_DownloadComplete", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8", "environment":"", "command_line":"-carrier_type=ctid -carrier_id=CT3309297 -platform=all -local=en-us -startpage=true -defaultsearch=true -sessionid=M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8 -downloadlength=688 -EXT_ISID=false", "download_length": "688", "carrier_ID": "CT3309297", "carrier_type": "ctid", "carrier_version": "DEFAULT", "brand": "SP", "EXT_ISID":"false","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","installer_version":"2.4.2.5","result":"success","reason":"0" , "log":"10#6-0#", "OS_name":"Microsoft Windows XP Professional Service Pack 3 (build 2600)", "OS_version":"5.1", "Installer_download_time_sec":"4", "Installer_url":"hXXp://sp-storage.spccinta.com/Installer/2.16.10.61/SPSetup.exe", "ExtraData":""}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:19:35 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
....
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 792
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"Stub_Complete", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8", "environment":"", "command_line":"-carrier_type=ctid -carrier_id=CT3309297 -platform=all -local=en-us -startpage=true -defaultsearch=true -sessionid=M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8 -downloadlength=688 -EXT_ISID=false", "download_length": "688", "carrier_ID": "CT3309297", "carrier_type": "ctid", "carrier_version": "DEFAULT", "brand": "SP", "EXT_ISID":"false","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","installer_version":"2.4.2.5","result":"success","reason":"0" , "log":"10#6-0#8#9-0-0#", "OS_name":"Microsoft Windows XP Professional Service Pack 3 (build 2600)", "OS_version":"5.1", "Installer_time_sec":"27", "ExtraData":""}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:20:03 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
POST / HTTP/1.1
Content-Type: application/json
Accept: */*
User-Agent: SearchProtect;2.16.10.61;Microsoft Windows XP;SP02A809A1-AD66-49FC-9E31-72DC6687025A
Host: sp-alive-msg.databssint.com
Content-Length: 435
Connection: Keep-Alive
Cache-Control: no-cache
{"SP_ID":"SP02A809A1-AD66-49FC-9E31-72DC6687025A","SP_version":"2.16.10.61","OS_name":"Microsoft Windows XP","OS_version":"5.1","install_date":"20140802","environment":"","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","Experiment":"","Variant":"","driver_enabled":"false","action_type":"alive","type":"","brand":"SP","browser":"InternetExplorer","browser_version":"6.0.2900.5512"}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:19:57 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
HTTP/1.1 202 Accepted..Date: Sat, 02 Aug 2014 07:19:57 GMT..P3P: CP="NOI ADM DEV COM NAV OUR STP"..Server: Apache-Coyote/1.1..Content-Length: 0..Connection: keep-alive..
GET /Installer/2.16.10.61/SPSetup.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-storage.spccinta.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Last-Modified: Sat, 02 Aug 2014 10:02:31 GMT
Accept-Ranges: bytes
ETag: "9f6bb1485a2ed847d63f1614f5d9b70f"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 6824512
Date: Sat, 02 Aug 2014 07:19:32 GMT
Connection: keep-alive
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#yd.B.7.B.7.B.7..z7.B.7..l7.B.7.B.7.B.7.:.7.B.7...7.B.7.:.7.B.7Rich.B.7........................PE..L....q.N.................d.......B..K5............@..........................`).......h...............................................'..y............h..............................................................................................text....c.......d.................. ..`.rdata...............h..............@..@.data....f..........................@....ndata.... ..............................rsrc....y....'..z..................@..@................................................................................................................................................................................................................................................................................................................................................................U....\.}..t .}.F.E.u..H......G..H.P.u..u..u...|.@..K...SV.5..G.W.E.P.u.....@..e...E..E.P.u.....@..}..e....D.@........FR..VV..U... M..........M........E...FQ.....NU..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.P.u.....@..u....E..9}...n....~X.te.v4..L.@..E...tU.}.j.W.E......E.......P.@..vXW..T.@..u..5X.@.W..h ....E..E.Pj.h..F.W....@..u.W...u....E.P.u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ.U.
<<< skipped >>>
GET /download/CarrierId/CT3309297/CarrierVersion/DEFAULT/CarrierType/ctid/Brand/SP HTTP/1.1
Accept: application/sp-download-v2
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-download.spccint.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: application/json; charset=utf-8
Expires: -1
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Sat, 02 Aug 2014 07:18:10 GMT
Content-Length: 70
"http:\/\/sp-storage.spccinta.com\/Installer\/2.16.10.61\/SPSetup.exe"..
GET /?step_id=2&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: c1.installbox1.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:19:23 GMT
Content-Type: text/html
Content-Length: 4416
Connection: close
Content-Disposition: attachment; filename="2.txt"
..[.I.n.s.t.a.l.l.e.r.]...P.r.o.d.u.c.t.N.a.m.e.=.".S.e.t.u.p."...P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.".1...0."...P.r.o.d.u.c.t.C.o.d.e.=.".b.d.c.4.6.c.3.7.-.a.0.7.2.-.4.6.8.0.-.a.1.5.5.-.4.e.b.1.f.5.c.7.e.e.5.5."...P.u.b.l.i.s.h.e.r.I.D.=.".3.8.8."...S.o.u.r.c.e.I.D.=.".0."...P.a.g.e.I.D.=.".0."...A.f.f.i.l.i.a.t.e.I.D.=.".1._.e.x.e."...I.n.s.t.a.l.l.e.r.I.D.=.".9.3.2.4.4.7.4.0.4."...L.o.c.a.l.e.=.".<.L.a.n.g.u.a.g.e.>."...D.a.t.e.=.".2.0.1.4./.0.8./.0.2."...T.i.m.e.=.".7.:.1.9.:.2.3."...S.h.o.w.I.n.T.a.s.k.b.a.r.=.".1."...H.i.d.e.S.c.r.e.e.n.s.=.".0."...R.u.n.O.n.c.e.=.".1."...L.o.g.U.r.l.=."."...L.o.g.S.t.a.r.t.e.d.=."."...L.o.g.F.i.n.i.s.h.e.d.=."."...L.o.g.B.e.f.o.r.e.S.e.n.d.R.e.p.o.r.t.=."."...L.o.g.A.f.t.e.r.S.e.n.d.R.e.p.o.r.t.=.".".....[.S.e.r.v.e.r.]...I.D.=.".3."...L.o.c.a.t.i.o.n.=.".D.E.".....[.U.s.e.r.I.n.f.o.]...C.o.u.n.t.r.y.C.o.d.e.=.".U.S."...I.P.A.d.d.r.e.s.s.=.".1.8.4...1.0.7...3.8...3.8."...W.e.b.B.r.o.w.s.e.r.=.".4.".....[.R.n.d.G.e.n.]...P.e.r.c.e.n.t.a.g.e.=.".2.1.".....[.S.c.r.e.e.n.7.6.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".T.r.y. .A.g.a.i.n."...B.u.t.t.o.n.2.=.".C.a.n.c.e.l."...L.a.b.e.l.1.=.".W.e.'.r.e. .s.o.r.r.y.:. .t.h.e. .d.o.w.n.l.o.a.d. .l.i.n.k. .s.e.e.m.s. .t.o. .b.e. .b.r.o.k.e.n... .P.l.e.a.s.e. .v.i.s.i.t. .t.h.e. .a.u.t.h.o.r.'.s. .h.o.m.e.p.a.g.e. .f.o.r. .f.u.r.t.h.e.r. .i.n.f.o.r.m.a.t.i.o.n..."...[.S.c.r.e.e.n.7.5.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".Y.e.s."...B.u.t.t.o.n.2.=.".N.o."...L.a.b.e.l.1.=.".A.r.e. .y.o.u. .s.u.r.e.?."...[.S.e.l.e.c.
<<< skipped >>>
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 951
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"install_start","SP_ID":"SP02A809A1-AD66-49FC-9E31-72DC6687025A","SP_version":"2.16.10.61","OS_name":"Microsoft Windows XP Professional Service Pack 3 (build 2600)","OS_version":"5.1","browser":"InternetExplorer","browser_version":"6.0.2900.5512","carrier_type":"ctid","carrier_ID":"CT3309297","carrier_version":"","carrier_userid":"","carrier_UM":"","machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG","hp_takeover":"true","other_takeover":"true","environment":"","sequence_timestamp":"1406946097618","profile_number":"1","user_number":"1", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8", "download_length": 3172, "install_type": "install", "result": "SP_RESULT", "reason": "SP_FAIL_REASON","v_env_tests":"V_ENV_TESTS_ALIAS","v_env_codes":"V_ENV_CODES_ALIAS","channel_id": "", "brand": "SP" , "previous_brand":"", "brand_install_type":"","Experiment":"","Variant":""}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:19:45 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
GET /UP/settings/?ctid=CT3309297&UM=&c=CA&DUM=2 HTTP/1.1
User-Agent: SearchProtect;2.16.10.61;Microsoft Windows XP;SP02A809A1-AD66-49FC-9E31-72DC6687025A
Accept: */*
Host: c.api.seccint.com
HTTP/1.1 200 OK
Content-Type: application/json; charset=utf-8
Server: Microsoft-IIS/7.5
X-AspNetMvc-Version: 3.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Content-Length: 4227
Cache-Control: private, max-age=3600
Expires: Sat, 02 Aug 2014 08:19:58 GMT
Date: Sat, 02 Aug 2014 07:19:58 GMT
Connection: keep-alive
{"GeneralId":null,"Ctid":"CT3309297","ProviderId":2,"ProviderName":"Bing","UserIP":""%local server IP%"","UserLanguage":"en","ToolbarLanguage":"en","EntityLanguage":"en","CountryShortCode":"CA","IsUserRTL":false,"IsToolbarRTL":false,"IsEntityRTL":false,"ShowClientDialog":true,"HomePageUrl":"hXXp://VVV.trovi.com/?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=55&CUI=SB_CUI&UM=6&UP=UP_ID","IsCustomizedHomepage":false,"HomePageButtonUrl":"hXXp://VVV.trovi.com/?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=55&CUI=SB_CUI&UM=6&UP=UP_ID&SAT=HPB","UM":"","SearchDomain":"VVV.trovi.com","ToolbarSearchBox":{"History":{"IsEnabled":true,"Position":1,"MaxAmount":5,"Label":{"Text":"History"}},"Verticals":[{"Name":"SearchImages","SearchUrl":"hXXp://VVV.trovi.com/?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&SearchType=SearchImages&CUI=SB_CUI&UM=6&UP=UP_ID&q=UCM_SEARCH_TERM","EmptySearchUrl":"hXXp://VVV.trovi.com/?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&SearchType=SearchImages&CUI=SB_CUI&UM=6&UP=UP_ID"}],"EmptySearchUrl":"http://VVV.trovi.com/?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&CUI=SB_CUI&UM=6&UP=UP_ID","SearchUrl":"hXXp://VVV.trovi.com/Results.aspx?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&CUI=SB_CUI&UM=6&UP=UP_ID&q=UCM_SEARCH_TERM","Suggest":{"SearchResultsUrl":"hXXp://VVV.trovi.com/Results.aspx?gd=&ctid=CT3309297&octid=EB_ORIGINAL_CTID&ISID=ISID_ID&SearchSource=67&Sugg
<<< skipped >>>
GET /sp-downloader.exe HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: sp-storage.conduit-services.com
HTTP/1.1 200 OK
Last-Modified: Sat, 02 Aug 2014 10:18:02 GMT
Accept-Ranges: bytes
ETag: "32b94cf0ed04298eaab31147eadd7760"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 145928
Cache-Control: private, max-age=900
Expires: Sat, 02 Aug 2014 07:34:24 GMT
Date: Sat, 02 Aug 2014 07:19:24 GMT
Connection: keep-alive
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#yd.B.7.B.7.B.7..z7.B.7..l7.B.7.B.7.B.7.:.7.B.7...7.B.7.:.7.B.7Rich.B.7........................PE..L....q.N.................d.......B..K5............@..........................p......wA...............................................`..(...........8"...............................................................................................text....c.......d.................. ..`.rdata...............h..............@..@.data....f..........................@....ndata...P...............................rsrc...(....`......................@..@................................................................................................................................................................................................................................................................................................................................................................U....\.}..t .}.F.E.u..H......G..H.P.u..u..u...|.@..K...SV.5..G.W.E.P.u.....@..e...E..E.P.u.....@..}..e....D.@........FR..VV..U... M..........M........E...FQ.....NU..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.P.u.....@..u....E..9}...n....~X.te.v4..L.@..E...tU.}.j.W.E......E.......P.@..vXW..T.@..u..5X.@.W..h ....E..E.Pj.h..F.W....@..u.W...u....E.P.u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ.U.
<<< skipped >>>
GET /ip/?client=sp HTTP/1.1
User-Agent: SearchProtect;2.16.10.61;Microsoft Windows XP;SP02A809A1-AD66-49FC-9E31-72DC6687025A
Accept: */*
Host: sp-ip2location.spccint.com
HTTP/1.1 200 OK
Cache-Control: private
Content-Length: 167
Content-Type: application/json; charset=text/plain
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Date: Sat, 02 Aug 2014 07:18:35 GMT
{"Location":{"City":"MONTREAL","Country":"CANADA","CountryCode":"CA","IP":""%local server IP%"","Latitude":45.50884,"Longitude":-73.58781,"Region":"QUEBEC"},"Language":"en"}..
GET /addons/agup.exe HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: i1.installbox1.info
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:20:24 GMT
Content-Type: application/octet-stream
Content-Length: 1082880
Last-Modified: Wed, 30 Jul 2014 00:07:01 GMT
Connection: close
ETag: "53d83725-108600"
Accept-Ranges: bytes
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........G..[G..[G..[!i([D..[.A*[]..[N.c[F..[.A([...[.A)[...[N.d[B..[N.t[H..[G..[...[G..[E..[!i4[N..[!i.[F..[!i [F..[RichG..[................PE..L......S.................d..........Cd...............................................K...............................................................................................................9..@...............D............................text....c.......d.................. ..`.rdata..f".......$...h..............@..@.data....K..........................@....rsrc...............................@..@.....................................................................................................................................................................................................................................................................................................................................................................i..C.....&....%...........U...E..8.u.3.].P..B..Y].U...}..u.3.]..E..u....P.u..JC.....].j... ....U.....u..M.... ...E..t.V.X...Y....U.....j... ....U...M..M.... ...vU....J...j...d....U...5.............u..F..t.j..........u.......t.3..../U....M..G ...e...E.$....M..h.K...E.P..T...j...d....U...5.............u..F..t.j....).....u.......t.3.....T....M.......e...E.$....M..h.K...E.P.FT...j...d....T...5.............u..F..t.j..........u.......t.3...._T....M..w....e...E.$....M..h.K...E.P..S...j...d...^T...5...........
<<< skipped >>>
GET /addons/dfndr/180/tpq.exe HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: i1.installbox1.info
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:20:04 GMT
Content-Type: application/octet-stream
Content-Length: 4983808
Last-Modified: Wed, 30 Jul 2014 00:07:02 GMT
Connection: close
ETag: "53d83726-4c0c00"
Accept-Ranges: bytes
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........U...U...U....fB.K....f@......fA.....\...P...U.......U...T....L\.X....LF.T....LC.T...RichU...................PE..L......R.....................0D...................@..........................PL.....k.L...@..................................3..<.......0.A..................pK..E......................................@............................................text............................... ..`.rdata..t-..........................@..@.data... ....@...h...2..............@....rsrc...0.A.......A.................@..@.reloc.......pK......,K.............@..B................................................................................................................................................................................................................................................................................................................................................U......E......E......E......e.....E.@.E..E.;E.s..E..E....3E..E..E.i......E....E...U..].U......}..u..e...r.E..E..E..E..E..E..E..E....E.@@.E..E.@@.E..E.H.E..}..v7.E.....M....;.t%.E.....M....;.}..M.....E......E..E......e...E...U......M..E..M...;.u..P.E..8.t6.E......E..}..u.j..M..H....M.........E....E..E..M.....j..M.."....M..v....E.....U..Q.M...U......M..E..x..r..E..E..E....E....E..E..E..E..E.P.M.......E...D!H..E.....U..Q.M..M..O....E....t..u......Y.E.....U..Q.M..M..(.....U..j.h..G.d.....Pd.%......,.M.j..M..
<<< skipped >>>
GET /?step_id=4_3&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: c1.installbox1.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:20:22 GMT
Content-Type: text/html
Content-Length: 6882
Connection: close
Content-Disposition: attachment; filename="4_3.txt"
..[.I.n.s.t.a.l.l.e.r.]...P.r.o.d.u.c.t.N.a.m.e.=.".S.e.t.u.p."...P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.".1...0."...P.r.o.d.u.c.t.C.o.d.e.=.".d.e.9.b.0.8.8.d.-.4.e.a.d.-.4.1.b.f.-.a.e.2.8.-.d.e.f.b.4.7.5.5.c.0.1.8."...P.u.b.l.i.s.h.e.r.I.D.=.".3.8.8."...S.o.u.r.c.e.I.D.=.".0."...P.a.g.e.I.D.=.".0."...A.f.f.i.l.i.a.t.e.I.D.=.".1._.e.x.e."...I.n.s.t.a.l.l.e.r.I.D.=.".9.3.2.4.4.7.4.0.4."...L.o.c.a.l.e.=.".<.L.a.n.g.u.a.g.e.>."...D.a.t.e.=.".2.0.1.4./.0.8./.0.2."...T.i.m.e.=.".7.:.2.0.:.2.2."...S.h.o.w.I.n.T.a.s.k.b.a.r.=.".1."...H.i.d.e.S.c.r.e.e.n.s.=.".0."...R.u.n.O.n.c.e.=.".1."...L.o.g.U.r.l.=."."...L.o.g.S.t.a.r.t.e.d.=."."...L.o.g.F.i.n.i.s.h.e.d.=."."...L.o.g.B.e.f.o.r.e.S.e.n.d.R.e.p.o.r.t.=."."...L.o.g.A.f.t.e.r.S.e.n.d.R.e.p.o.r.t.=.".".....[.S.e.r.v.e.r.]...I.D.=.".3."...L.o.c.a.t.i.o.n.=.".D.E.".....[.U.s.e.r.I.n.f.o.]...C.o.u.n.t.r.y.C.o.d.e.=.".U.S."...I.P.A.d.d.r.e.s.s.=.".1.8.4...1.0.7...3.8...3.8."...W.e.b.B.r.o.w.s.e.r.=.".4.".....[.R.n.d.G.e.n.]...P.e.r.c.e.n.t.a.g.e.=.".5.3.".....[.S.c.r.e.e.n.7.6.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".T.r.y. .A.g.a.i.n."...B.u.t.t.o.n.2.=.".C.a.n.c.e.l."...L.a.b.e.l.1.=.".W.e.'.r.e. .s.o.r.r.y.:. .t.h.e. .d.o.w.n.l.o.a.d. .l.i.n.k. .s.e.e.m.s. .t.o. .b.e. .b.r.o.k.e.n... .P.l.e.a.s.e. .v.i.s.i.t. .t.h.e. .a.u.t.h.o.r.'.s. .h.o.m.e.p.a.g.e. .f.o.r. .f.u.r.t.h.e.r. .i.n.f.o.r.m.a.t.i.o.n..."...[.S.c.r.e.e.n.7.5.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".Y.e.s."...B.u.t.t.o.n.2.=.".N.o."...L.a.b.e.l.1.=.".A.r.e. .y.o.u. .s.u.r.e.?."...[.S.e.l.e.c.
<<< skipped >>>
GET /?step_id=1&installer_id=932447404&publisher_id=388&source_id=0&page_id=0&affiliate_id=1_exe&country_code=US&locale=EN&browser_id=4&download_id=3886750425&external_id=0&session_id=3218678628&hardware_id=1508444704&installer_file_name=setup&uuid=* HTTP/1.1
Accept: */*
User-Agent: TixDll
Host: c1.installbox1.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: openresty
Date: Sat, 02 Aug 2014 07:19:22 GMT
Content-Type: text/html
Content-Length: 6810
Connection: close
Content-Disposition: attachment; filename="1.txt"
..[.I.n.s.t.a.l.l.e.r.]...P.r.o.d.u.c.t.N.a.m.e.=.".S.e.t.u.p."...P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.".1...0."...P.r.o.d.u.c.t.C.o.d.e.=.".5.7.1.c.7.5.6.e.-.6.5.6.d.-.4.9.b.c.-.9.7.e.6.-.a.0.b.5.3.6.b.2.c.4.a.3."...P.u.b.l.i.s.h.e.r.I.D.=.".3.8.8."...S.o.u.r.c.e.I.D.=.".0."...P.a.g.e.I.D.=.".0."...A.f.f.i.l.i.a.t.e.I.D.=.".1._.e.x.e."...I.n.s.t.a.l.l.e.r.I.D.=.".9.3.2.4.4.7.4.0.4."...L.o.c.a.l.e.=.".<.L.a.n.g.u.a.g.e.>."...D.a.t.e.=.".2.0.1.4./.0.8./.0.2."...T.i.m.e.=.".7.:.1.9.:.2.2."...S.h.o.w.I.n.T.a.s.k.b.a.r.=.".1."...H.i.d.e.S.c.r.e.e.n.s.=.".0."...R.u.n.O.n.c.e.=.".1."...L.o.g.U.r.l.=."."...L.o.g.S.t.a.r.t.e.d.=."."...L.o.g.F.i.n.i.s.h.e.d.=."."...L.o.g.B.e.f.o.r.e.S.e.n.d.R.e.p.o.r.t.=."."...L.o.g.A.f.t.e.r.S.e.n.d.R.e.p.o.r.t.=.".".....[.S.e.r.v.e.r.]...I.D.=.".3."...L.o.c.a.t.i.o.n.=.".D.E.".....[.U.s.e.r.I.n.f.o.]...C.o.u.n.t.r.y.C.o.d.e.=.".U.S."...I.P.A.d.d.r.e.s.s.=.".1.8.4...1.0.7...3.8...3.8."...W.e.b.B.r.o.w.s.e.r.=.".4.".....[.R.n.d.G.e.n.]...P.e.r.c.e.n.t.a.g.e.=.".6.3.".....[.S.c.r.e.e.n.7.6.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".T.r.y. .A.g.a.i.n."...B.u.t.t.o.n.2.=.".C.a.n.c.e.l."...L.a.b.e.l.1.=.".W.e.'.r.e. .s.o.r.r.y.:. .t.h.e. .d.o.w.n.l.o.a.d. .l.i.n.k. .s.e.e.m.s. .t.o. .b.e. .b.r.o.k.e.n... .P.l.e.a.s.e. .v.i.s.i.t. .t.h.e. .a.u.t.h.o.r.'.s. .h.o.m.e.p.a.g.e. .f.o.r. .f.u.r.t.h.e.r. .i.n.f.o.r.m.a.t.i.o.n..."...[.S.c.r.e.e.n.7.5.]...T.i.t.l.e.=.".S.e.t.u.p."...B.u.t.t.o.n.1.=.".Y.e.s."...B.u.t.t.o.n.2.=.".N.o."...L.a.b.e.l.1.=.".A.r.e. .y.o.u. .s.u.r.e.?."...[.S.e.l.e.c.
<<< skipped >>>
GET /get/?data=0BIqmZDY2uCNUO3ZTV47GddPvdyzkDVy+7LVMeiWPYiBnCaj7k5VmXKWI1PAmmSZgMSm0PBWd+AnT1E+ZQB16S/DiF+4fQvCbJ4VtAbtEkcTRdGLtOnGtxlnAjTmF29P02pymuZ0juTFPgy+HLQK909FbEdw4mVH+2P0HYsvyvhUPv375adfwI9Jyas2SEptJZhWja+RPXUMh0JkfAV4d311MD3ax3iE83oTL5ZzvJIdGyqIVbcsAi9qZyFbes0e/tD4t4SKs6wr2H8DmWcO67q38oNx+Sjmb80MxaLStTzP1sNUuKGHBdH9rZgNB/p3YWcakrG4mxDarwAZZ7JqQr4iPemyDeSdNKOq9UylOMsaP3dc7dVWAfI8hWCSqeWPOYtijjdt4KTWGFQP3jLhEKYt6QCilzBXEsdQbQMSoK1j0a0U2CN8xbl5wn1OzIZjkg4hgbatgSr13yPyusR/RI7SKQ50xtOKstDtw/AOpESdJvqcHU60CYuxZTVN&version=4 HTTP/1.1
Accept: */*
User-Agent: win32
Host: datadownloadscan.info
Cache-Control: no-cache
HTTP/1.1 200 OK
Server: ngx_openresty
Date: Sat, 02 Aug 2014 07:21:34 GMT
Content-Length: 0
Connection: close
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 429
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"MiniStub_Init", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8","environment":"", "command_line":"-carrier_type=ctid -carrier_id=CT3309297 -platform=all -local=en-us -startpage=true -defaultsearch=true", "EXT_ISID":"false", "carrier_ID":"CT3309297", "machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG", "installer_version":"1.1.2.4", "origin":""}
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:19:29 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
....
POST / HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-installer.databssint.com
Content-Length: 469
Connection: Keep-Alive
Cache-Control: no-cache
{"event_type":"MiniStub_Complete", "installation_session_id":"M11D4A9CB-E657-4E77-A7EC-BC51D31B00E8","environment":"", "command_line":"-carrier_type=ctid -carrier_id=CT3309297 -platform=all -local=en-us -startpage=true -defaultsearch=true", "EXT_ISID":"false", "carrier_ID":"CT3309297", "machine_ID":"SYMSEKIOXZBUAJHS1WVTWMFHOKY3NXHGTN4I0LTE/5O9BOIYIVKIMF3CSRVRMX8UX35IMHZ46IKGV8D2XDOQXG", "installer_version":"1.1.2.4", "origin":"", "result":"success", "reason": "0" }
HTTP/1.1 202 Accepted
Date: Sat, 02 Aug 2014 07:20:03 GMT
P3P: CP="NOI ADM DEV COM NAV OUR STP"
Server: Apache-Coyote/1.1
Content-Length: 0
Connection: keep-alive
GET /stub/spstub.exe HTTP/1.1
User-Agent: NSIS_Inetc (Mozilla)
Host: sp-storage.spccinta.com
Connection: Keep-Alive
Cache-Control: no-cache
HTTP/1.1 200 OK
Last-Modified: Sat, 02 Aug 2014 10:01:12 GMT
Accept-Ranges: bytes
ETag: "8089503af264c1568a46208aea546eff"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 175208
Date: Sat, 02 Aug 2014 07:19:29 GMT
Connection: keep-alive
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#yd.B.7.B.7.B.7..z7.B.7..l7.B.7.B.7.B.7.:.7.B.7...7.B.7.:.7.B.7Rich.B.7........................PE..L....q.N.................d.......B..K5............@..........................0!...................................................... !.0............................................................................................................text....c.......d.................. ..`.rdata...............h..............@..@.data....f..........................@....ndata...................................rsrc...0.... !.....................@..@................................................................................................................................................................................................................................................................................................................................................................U....\.}..t .}.F.E.u..H......G..H.P.u..u..u...|.@..K...SV.5..G.W.E.P.u.....@..e...E..E.P.u.....@..}..e....D.@........FR..VV..U... M..........M........E...FQ.....NU..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.P.u.....@..u....E..9}...n....~X.te.v4..L.@..E...tU.}.j.W.E......E.......P.@..vXW..T.@..u..5X.@.W..h ....E..E.Pj.h..F.W....@..u.W...u....E.P.u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ.U.
<<< skipped >>>
Map
The Backdoor connects to the servers at the folowing location(s):
Strings from Dumps
CltMngSvc.exe_1784:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
.EKSWU
.EKSWU
\$$;\$0|
\$$;\$0|
DlSHA512 block transform for x86, CRYPTOGAMS by <appro></appro>
DlSHA512 block transform for x86, CRYPTOGAMS by <appro></appro>
Camellia for x86 by <appro></appro>
Camellia for x86 by <appro></appro>
AES for Intel AES-NI, CRYPTOGAMS by <appro></appro>
AES for Intel AES-NI, CRYPTOGAMS by <appro></appro>
6-9'6-9'
6-9'6-9'
$6.:$6.:
$6.:$6.:
*?#1*?#1
*?#1*?#1
>8$4,8$4,
>8$4,8$4,
AES for x86, CRYPTOGAMS by <appro></appro>
AES for x86, CRYPTOGAMS by <appro></appro>
RC4 for x86, CRYPTOGAMS by <appro></appro>
RC4 for x86, CRYPTOGAMS by <appro></appro>
Montgomery Multiplication for x86, CRYPTOGAMS by <appro></appro>
Montgomery Multiplication for x86, CRYPTOGAMS by <appro></appro>
SHA1 block transform for x86, CRYPTOGAMS by <appro></appro>
SHA1 block transform for x86, CRYPTOGAMS by <appro></appro>
SHA256 block transform for x86, CRYPTOGAMS by <appro></appro>
SHA256 block transform for x86, CRYPTOGAMS by <appro></appro>
GHASH for x86, CRYPTOGAMS by <appro></appro>
GHASH for x86, CRYPTOGAMS by <appro></appro>
GF(2^m) Multiplication for x86, CRYPTOGAMS by <appro></appro>
GF(2^m) Multiplication for x86, CRYPTOGAMS by <appro></appro>
FtPS
FtPS
D$@j.Xf
D$@j.Xf
t.JuG
t.JuG
PSSSSSSh
PSSSSSSh
t.VVW
t.VVW
<1%u5><pre>FTPj</pre><pre>tCPQ</pre><pre>,4,56,789</pre><pre>j.Yf;</pre><pre>_tcPVj@</pre><pre>.PjRW</pre><pre>broken pipe</pre><pre>inappropriate io control operation</pre><pre>not supported</pre><pre>operation in progress</pre><pre>operation not permitted</pre><pre>operation not supported</pre><pre>operation would block</pre><pre>protocol not supported</pre><pre>function not supported</pre><pre>operation canceled</pre><pre>address_family_not_supported</pre><pre>operation_in_progress</pre><pre>operation_not_supported</pre><pre>protocol_not_supported</pre><pre>operation_would_block</pre><pre>address family not supported</pre><pre>0123456789-</pre><pre>%b %d %H : %M : %S %Y</pre><pre>%m / %d / %y</pre><pre>%I : %M : %S %p</pre><pre>%d / %m / %y</pre><pre>boost thread: trying joining itself</pre><pre>Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>Operation not permitted</pre><pre>Inappropriate I/O control operation</pre><pre>Broken pipe</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>kernel32.dll</pre><pre>left-curly-bracket</pre><pre>right-curly-bracket</pre><pre>RSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>ssl_sess_cert</pre><pre>ssl_cert</pre><pre>evp_pkey</pre><pre>x509_pkey</pre><pre>%s(%d): OpenSSL internal error, assertion failed: %s</pre><pre>passed a null parameter</pre><pre>DSO support routines</pre><pre>x509 certificate routines</pre><pre>?456789:;<=</pre><pre>!"#$%&'()* ,-./0123</pre><pre>Big Number part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>pubkey</pre><pre>PEM part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>enc_key</pre><pre>key_enc_algor</pre><pre>cert</pre><pre>d.encrypted</pre><pre>d.digest</pre><pre>d.signed_and_enveloped</pre><pre>d.enveloped</pre><pre>d.sign</pre><pre>d.data</pre><pre>d.other</pre><pre>NETSCAPE_CERT_SEQUENCE</pre><pre>certs</pre><pre>X509_PUBKEY</pre><pre>public_key</pre><pre>.\crypto\asn1\x_pubkey.c</pre><pre>DSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>priv_key</pre><pre>pub_key</pre><pre>.\crypto\ec\ec_key.c</pre><pre>EC_PRIVATEKEY</pre><pre>publicKey</pre><pre>privateKey</pre><pre>value.implicitlyCA</pre><pre>value.parameters</pre><pre>value.named_curve</pre><pre>p.char_two</pre><pre>p.prime</pre><pre>p.ppBasis</pre><pre>p.tpBasis</pre><pre>p.onBasis</pre><pre>p.other</pre><pre>Any Extended Key Usage</pre><pre>anyExtendedKeyUsage</pre><pre>supportedAlgorithms</pre><pre>crossCertificatePair</pre><pre>certificateRevocationList</pre><pre>cACertificate</pre><pre>userCertificate</pre><pre>userPassword</pre><pre>supportedApplicationContext</pre><pre>Microsoft Local Key set</pre><pre>LocalKeySet</pre><pre>id-Gost28147-89-None-KeyMeshing</pre><pre>id-Gost28147-89-CryptoPro-KeyMeshing</pre><pre>password based MAC</pre><pre>id-PasswordBasedMAC</pre><pre>X509v3 Certificate Issuer</pre><pre>certificateIssuer</pre><pre>certicom-arc</pre><pre>Proxy Certificate Information</pre><pre>proxyCertInfo</pre><pre>Microsoft Smartcardlogin</pre><pre>msSmartcardLogin</pre><pre>joint-iso-itu-t</pre><pre>JOINT-ISO-ITU-T</pre><pre>set-rootKeyThumb</pre><pre>setAttr-Cert</pre><pre>setCext-cCertRequired</pre><pre>setCext-certType</pre><pre>setct-CertResTBE</pre><pre>setct-CertReqTBEX</pre><pre>setct-CertReqTBE</pre><pre>setct-AcqCardCodeMsgTBE</pre><pre>setct-CertInqReqTBS</pre><pre>setct-CertResData</pre><pre>setct-CertReqTBS</pre><pre>setct-CertReqData</pre><pre>setct-PCertResTBS</pre><pre>setct-PCertReqData</pre><pre>setct-AcqCardCodeMsg</pre><pre>certificate extensions</pre><pre>set-certExt</pre><pre>set-msgExt</pre><pre>id-ecPublicKey</pre><pre>id-cmc-confirmCertAcceptance</pre><pre>id-cmc-getCert</pre><pre>id-regInfo-certReq</pre><pre>id-regCtrl-protocolEncrKey</pre><pre>id-regCtrl-oldCertID</pre><pre>id-it-revPassphrase</pre><pre>id-it-keyPairParamRep</pre><pre>id-it-keyPairParamReq</pre><pre>id-it-unsupportedOIDs</pre><pre>id-it-caKeyUpdateInfo</pre><pre>id-it-encKeyPairTypes</pre><pre>id-it-signKeyPairTypes</pre><pre>id-it-caProtEncCert</pre><pre>id-mod-attribute-cert</pre><pre>id-mod-qualified-cert-93</pre><pre>id-mod-qualified-cert-88</pre><pre>id-smime-aa-ets-certCRLTimestamp</pre><pre>id-smime-aa-ets-certValues</pre><pre>id-smime-aa-ets-CertificateRefs</pre><pre>id-smime-aa-ets-otherSigCert</pre><pre>id-smime-aa-smimeEncryptCerts</pre><pre>id-smime-aa-signingCertificate</pre><pre>id-smime-aa-encrypKeyPref</pre><pre>id-smime-aa-msgSigDigest</pre><pre>id-smime-ct-publishCert</pre><pre>id-smime-mod-msg-v3</pre><pre>sdsiCertificate</pre><pre>x509Certificate</pre><pre>localKeyID</pre><pre>certBag</pre><pre>pkcs8ShroudedKeyBag</pre><pre>keyBag</pre><pre>pbeWithSHA1And2-KeyTripleDES-CBC</pre><pre>pbeWithSHA1And3-KeyTripleDES-CBC</pre><pre>TLS Web Client Authentication</pre><pre>TLS Web Server Authentication</pre><pre>X509v3 Extended Key Usage</pre><pre>extendedKeyUsage</pre><pre>X509v3 Authority Key Identifier</pre><pre>authorityKeyIdentifier</pre><pre>X509v3 Certificate Policies</pre><pre>certificatePolicies</pre><pre>X509v3 Private Key Usage Period</pre><pre>privateKeyUsagePeriod</pre><pre>X509v3 Key Usage</pre><pre>keyUsage</pre><pre>X509v3 Subject Key Identifier</pre><pre>subjectKeyIdentifier</pre><pre>Netscape Certificate Sequence</pre><pre>nsCertSequence</pre><pre>Netscape CA Policy Url</pre><pre>nsCaPolicyUrl</pre><pre>Netscape Renewal Url</pre><pre>nsRenewalUrl</pre><pre>Netscape CA Revocation Url</pre><pre>nsCaRevocationUrl</pre><pre>Netscape Revocation Url</pre><pre>nsRevocationUrl</pre><pre>Netscape Base Url</pre><pre>nsBaseUrl</pre><pre>Netscape Cert Type</pre><pre>nsCertType</pre><pre>Netscape Certificate Extension</pre><pre>nsCertExt</pre><pre>extendedCertificateAttributes</pre><pre>challengePassword</pre><pre>dhKeyAgreement</pre><pre>%'%1%=%C%K%O%s%</pre><pre>.%.-.3.7.9.?.W.[.o.y.</pre><pre>C%C'C3C7C9COCWCiC</pre><pre>RAND part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>You need to read the OpenSSL FAQ, http://www.openssl.org/support/faq.html</pre><pre>lhash part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Stack part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.single</pre><pre>value.set</pre><pre>EVP part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>name.relativename</pre><pre>name.fullname</pre><pre>certificateHold</pre><pre>Certificate Hold</pre><pre>cessationOfOperation</pre><pre>Cessation Of Operation</pre><pre>keyCompromise</pre><pre>Key Compromise</pre><pre>%*s%s:</pre><pre>%*sOnly Attribute Certificates</pre><pre>%*sOnly CA Certificates</pre><pre>%*sOnly User Certificates</pre><pre>ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>d.registeredID</pre><pre>d.iPAddress</pre><pre>d.uniformResourceIdentifier</pre><pre>d.ediPartyName</pre><pre>d.directoryName</pre><pre>d.dNSName</pre><pre>d.rfc822Name</pre><pre>d.otherName</pre><pre>AUTHORITY_KEYID</pre><pre>keyid</pre><pre>cert_info</pre><pre>PKCS8_PRIV_KEY_INFO</pre><pre>pkey</pre><pre>pkeyalg</pre><pre>EC part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>USER32.DLL</pre><pre>NETAPI32.DLL</pre><pre>KERNEL32.DLL</pre><pre>ADVAPI32.DLL</pre><pre>.\crypto\dh\dh_key.c</pre><pre>%s: (%d bit)</pre><pre>Public-Key</pre><pre>Private-Key</pre><pre>recommended-private-length: %d bits</pre><pre>public-key:</pre><pre>private-key:</pre><pre>PKCS#3 DH Public-Key</pre><pre>PKCS#3 DH Private-Key</pre><pre>Public-Key: (%d bit)</pre><pre>Private-Key: (%d bit)</pre><pre>SHA1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD5 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD4 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>AES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>CAST part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Blowfish part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>:RC2 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>.pp@0</pre><pre>aEÐ</pre><pre> (#EÚ</pre><pre>ÚE<<0</pre><pre>IDEA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>libdes part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>DES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>\X</pre><pre>ddddddZ</pre><pre>ddddddZ</pre><pre>%d.%d.%d.%d</pre><pre><unsupported></unsupported></pre><pre>IP Address:%d.%d.%d.%d</pre><pre>URI:%s</pre><pre>DNS:%s</pre><pre>email:%s</pre><pre>EdiPartyName:<unsupported></unsupported></pre><pre>X400Name:<unsupported></unsupported></pre><pre>othername:<unsupported></unsupported></pre><pre>%d.%d.%d.%d/%d.%d.%d.%d</pre><pre>X509_CERT_PAIR</pre><pre>X509_CERT_AUX</pre><pre>X.509 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>x%s</pre><pre>%s - d:d:d%.*s %d%s</pre><pre>keylen <= sizeof key</pre><pre>EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)</pre><pre>ECDSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Basis Type: %s</pre><pre>Field Type: %s</pre><pre>ASN1 OID: %s</pre><pre>%s %s%lu (%s0x%lx)</pre><pre>'() ,-./:=?</pre><pre>Verifying - %s</pre><pre>%*sPolicy Text: %s</pre><pre>%*scrlUrl:</pre><pre>EXTENDED_KEY_USAGE</pre><pre>%*sZone: %s, User:</pre><pre>.\crypto\x509v3\v3_akey.c</pre><pre>d.usernotice</pre><pre>d.cpsuri</pre><pre>CERTIFICATEPOLICIES</pre><pre>%*sExplicit Text: %s</pre><pre>%*sNumber%s:</pre><pre>%*sOrganization: %s</pre><pre>%*sCPS: %s</pre><pre>PKEY_USAGE_PERIOD</pre><pre>keyCertSign</pre><pre>Certificate Sign</pre><pre>keyAgreement</pre><pre>Key Agreement</pre><pre>keyEncipherment</pre><pre>Key Encipherment</pre><pre>.\crypto\x509v3\v3_skey.c</pre><pre>CONF part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>PROXY_CERT_INFO_EXTENSION</pre><pre>hexkey</pre><pre>rsa_keygen_pubexp</pre><pre>rsa_keygen_bits</pre><pre>keylength</pre><pre>keyfunc</pre><pre>len>=0 && len<=(int)sizeof(ctx->key)</pre><pre>j <= (int)sizeof(ctx->key)</pre><pre>.\crypto\pkcs12\p12_key.c</pre><pre>d.receiptList</pre><pre>d.allOrFirstTier</pre><pre>d.compressedData</pre><pre>d.authenticatedData</pre><pre>d.encryptedData</pre><pre>d.digestedData</pre><pre>d.envelopedData</pre><pre>d.signedData</pre><pre>d.ori</pre><pre>d.pwri</pre><pre>d.kekri</pre><pre>d.kari</pre><pre>d.ktri</pre><pre>CMS_PasswordRecipientInfo</pre><pre>keyDerivationAlgorithm</pre><pre>keyIdentifier</pre><pre>CMS_KeyAgreeRecipientInfo</pre><pre>recipientEncryptedKeys</pre><pre>CMS_OriginatorIdentifierOrKey</pre><pre>d.originatorKey</pre><pre>CMS_OriginatorPublicKey</pre><pre>CMS_RecipientEncryptedKey</pre><pre>CMS_KeyAgreeRecipientIdentifier</pre><pre>d.rKeyId</pre><pre>CMS_RecipientKeyIdentifier</pre><pre>CMS_OtherKeyAttribute</pre><pre>keyAttr</pre><pre>keyAttrId</pre><pre>CMS_KeyTransRecipientInfo</pre><pre>encryptedKey</pre><pre>keyEncryptionAlgorithm</pre><pre>certificates</pre><pre>d.crl</pre><pre>d.subjectKeyIdentifier</pre><pre>d.issuerAndSerialNumber</pre><pre>CMS_CertificateChoices</pre><pre>d.v2AttrCert</pre><pre>d.v1AttrCert</pre><pre>d.extendedCertificate</pre><pre>d.certificate</pre><pre>CMS_OtherCertificateFormat</pre><pre>otherCert</pre><pre>otherCertFormat</pre><pre>crlUrl</pre><pre>certStatus</pre><pre>certId</pre><pre>OCSP_CERTSTATUS</pre><pre>value.unknown</pre><pre>value.revoked</pre><pre>value.good</pre><pre>value.byKey</pre><pre>value.byName</pre><pre>reqCert</pre><pre>OCSP_CERTID</pre><pre>issuerKeyHash</pre><pre>CONF_def part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>[[%s]]</pre><pre>[%s] %s=%s</pre><pre>ECDH part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.bag</pre><pre>value.safes</pre><pre>value.shkeybag</pre><pre>value.keybag</pre><pre>value.sdsicert</pre><pre>value.x509cert</pre><pre>value.other</pre><pre>%s.dll</pre><pre>@7@!@)@4@</pre><pre>@4@!@ @%@/@6@%@2@</pre><pre>@%@6@%@.@4@</pre><pre>A%@%C%D%P%I%Q%v%@%D%W%F%M%</pre><pre>S6S%S6S!S'S6S7S</pre><pre>8U4U-UuU4U!U!U0U8U%U!U&UuU'U0U4U6U=U0U1U</pre><pre>(\=\7\9\3\*\9\.\</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp</pre><pre>{{{$1044}}}</pre><pre>{{{$1047}}}</pre><pre>{{{$1048}}}</pre><pre>{{{$626}}}</pre><pre>{{{$1049}}}</pre><pre>[>[)[-[2[8[>[{[</pre><pre>]8]/] ]4]>]8]}]</pre><pre>S6S!S%S6S!S</pre><pre>{{{$1055}}}</pre><pre>{{{$1058}}}</pre><pre>{{{$1057}}}</pre><pre>{{{$1060}}}</pre><pre>{{{$1059}}}</pre><pre>{{{$1062}}}</pre><pre>{{{$1061}}}</pre><pre>{{{$1064}}}</pre><pre>{{{$1063}}}</pre><pre>{{{$1066}}}</pre><pre>{{{$1065}}}</pre><pre>{{{$1068}}}</pre><pre>{{{$1067}}}</pre><pre>{{{$1070}}}</pre><pre>{{{$1069}}}</pre><pre>{{{$1072}}}</pre><pre>{{{$1071}}}</pre><pre>{{{$1073}}}</pre><pre>{{{$1101}}}</pre><pre>{{{$1102}}}</pre><pre>{{{$1104}}}</pre><pre>{{{$1103}}}</pre><pre>{{{$1106}}}</pre><pre>{{{$1105}}}</pre><pre>{{{$1108}}}</pre><pre>{{{$1107}}}</pre><pre>{{{$1109}}}</pre><pre>{{{$1111}}}</pre><pre>{{{$1110}}}</pre><pre>{{{$1113}}}</pre><pre>{{{$1112}}}</pre><pre>{{{$1116}}}</pre><pre>{{{$1117}}}</pre><pre>{{{$1114}}}</pre><pre>{{{$1115}}}</pre><pre>{{{$1123}}}</pre><pre>{{{$1122}}}</pre><pre>{{{$1125}}}</pre><pre>{{{$1124}}}</pre><pre>{{{$1126}}}</pre><pre>{{{$1127}}}</pre><pre>{{{$1129}}}</pre><pre>{{{$1128}}}</pre><pre>{{{$1130}}}</pre><pre>{{{$1131}}}</pre><pre>{{{$1132}}}</pre><pre>{{{$139}}}</pre><pre>{{{$138}}}</pre><pre>{{{$141}}}</pre><pre>{{{$140}}}</pre><pre>{{{$142}}}</pre><pre>{{{$144}}}</pre><pre>{{{$143}}}</pre><pre>{{{$146}}}</pre><pre>{{{$145}}}</pre><pre>{{{$124}}}</pre><pre>{{{$127}}}</pre><pre>{{{$128}}}</pre><pre>{{{$125}}}</pre><pre>{{{$126}}}</pre><pre>{{{$131}}}</pre><pre>{{{$132}}}</pre><pre>{{{$129}}}</pre><pre>{{{$130}}}</pre><pre>{{{$133}}}</pre><pre>{{{$134}}}</pre><pre>{{{$135}}}</pre><pre>J%V%I%J%F%D%I%@%</pre><pre>{{{$471}}}</pre><pre>{{{$473}}}</pre><pre>{{{$468}}}</pre><pre>{{{$461}}}</pre><pre>c%W%J%H%l%K%V%Q%D%I%I%</pre><pre>D%D/D!D D2D!D6D</pre><pre>DÐD%D</pre><pre>_6_<_-_0_><pre>_6_1_;_0_(_,_</pre><pre>_*_-_-_:_1_ _</pre><pre>_:_-_,_6_0_1_</pre><pre>_2_>_8_:_</pre><pre>_'_:_<_><pre>_/_ _6_0_1_,_</pre><pre>I,I$I9I,I;I I'I.IiIdIiI</pre><pre>{{{$483}}}</pre><pre>{{{$484}}}</pre><pre>{{{$486}}}</pre><pre>{{{$487}}}</pre><pre>{{{$485}}}</pre><pre>{{{$488}}}</pre><pre>{{{$489}}}</pre><pre>{{{$494}}}</pre><pre>{{{$495}}}</pre><pre>{{{$498}}}</pre><pre>{{{$496}}}</pre><pre>{{{$497}}}</pre><pre>{{{$499}}}</pre><pre>{{{$501}}}</pre><pre>{{{$502}}}</pre><pre>{{{$500}}}</pre><pre>{{{$503}}}</pre><pre>{{{$504}}}</pre><pre>{{{$505}}}</pre><pre>{{{$508}}}</pre><pre>{{{$506}}}</pre><pre>{{{$507}}}</pre><pre>{{{$509}}}</pre><pre>{{{$510}}}</pre><pre>{{{$511}}}</pre><pre>{{{$512}}}</pre><pre>{{{$513}}}</pre><pre>{{{$514}}}</pre><pre>{{{$515}}}</pre><pre>{{{$518}}}</pre><pre>{{{$519}}}</pre><pre>{{{$516}}}</pre><pre>{{{$517}}}</pre><pre>{{{$520}}}</pre><pre>{{{$521}}}</pre><pre>{{{$523}}}</pre><pre>{{{$522}}}</pre><pre>4|7|?|?|</pre><pre>{{{$609}}}</pre><pre>{{{$610}}}</pre><pre>{{{$613}}}</pre><pre>{{{$614}}}</pre><pre>{{{$611}}}</pre><pre>{{{$612}}}</pre><pre>_3_0_=_>_3_</pre><pre>_(_6_1_;_0_(_,_</pre><pre>_8_3_0_=_>_3_</pre><pre>_<_0_><pre>S6S!S>S S.SuS</pre><pre>cCc%c</pre><pre>{{{$404}}}</pre><pre>{{{$402}}}</pre><pre>{{{$403}}}</pre><pre>{{{$405}}}</pre><pre>Z.Z#Z*Z?ZgZ}Z.Z?Z"Z.ZuZ2Z.Z7Z6Z}Z</pre><pre>{{{$406}}}</pre><pre>[([>[:[)[8[3[</pre><pre>[>[)[6[&[</pre><pre>{{{$408}}}</pre><pre>{{{$409}}}</pre><pre>{{{$410}}}</pre><pre>F5F#F'F4F%F.F6F*F3F!F/F(F5F</pre><pre>B0B.BbB6B;B2B'B</pre><pre>PUADQ@%%h`qdv%V@Q%vu`flclfv8:4)%v`ws`wZvu`flclfv8:7%RM@W@%kjkZpkltp`Zkdh`%iln`%"mjh`udb`ZlvZk`rqdgudb`"%DKA%v`ws`wZkjkZpkltp`Zkdh`%%iln`%"mjh`udb`ZlvZk`rqdgudb`"</pre><pre>{{{$312}}}</pre><pre>{{{$313}}}</pre><pre>{{{$314}}}</pre><pre>{{{$334}}}</pre><pre>a!-dc}xyRhcnbidcj~!-~xjjh~yRx</pre><pre>U&U!U4U'U!U U%U</pre><pre>{{{$357}}}</pre><pre>{{{$358}}}</pre><pre>{{{$359}}}</pre><pre>{{{$360}}}</pre><pre>CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);</pre><pre>insert into ItemTable (key, value) VALUES ('%s', '%s');</pre><pre>1d'd)d;d7d!dÖd'd,d;d0d!d6d)d</pre><pre>\/\/\9\(\</pre><pre>{{{$629}}}</pre><pre>{{{$632}}}</pre><pre>{{{$631}}}</pre><pre>{{{$630}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h</pre><pre>(more frames truncated from call stack report)</pre><pre>\StringFileInfo\xx\%s</pre><pre>Module %d</pre><pre>%d/%d/%d d:d:d</pre><pre>File Size: %-10d File Time: %s</pre><pre>Checksum: 0xx Time Stamp: 0xx</pre><pre>Image Base: 0xx Image Size: 0xx</pre><pre>FileVer: %d.%d.%d.%d</pre><pre>FileDesc: %s</pre><pre>Product: %s</pre><pre>Company: %s</pre><pre>ProdVer: %d.%d.%d.%d</pre><pre>Windows 7</pre><pre>Windows Server 2008</pre><pre>Windows Vista</pre><pre>Windows 9</pre><pre>Windows Server 2012</pre><pre>Windows 8</pre><pre>Windows Server 2008 R2</pre><pre>Web Edition</pre><pre>Windows XP</pre><pre>Windows Server 9</pre><pre>Windows 2000</pre><pre>(build %d)</pre><pre>Error occurred at %s.</pre><pre>This sample does not support this version of Windows.</pre><pre>%d%% memory in use.</pre><pre>%d processor(s), type %d.</pre><pre>Operating system: Could not Determine</pre><pre>Operating system: %s</pre><pre>%d MBytes paging file free.</pre><pre>%d MBytes paging file.</pre><pre>%d MBytes physical memory free.</pre><pre>%d MBytes user address space free.</pre><pre>Windows Home Server</pre><pre>Windows Storage Server 2003</pre><pre>Windows Server 2003 R2</pre><pre>Web Server Edition</pre><pre>Windows Server 2003</pre><pre>Windows XP Professional x64 Edition</pre><pre>a Float Denormal Operand</pre><pre>%d MBytes user address space.</pre><pre>a Float Invalid Operation</pre><pre>%d MBytes physical memory.</pre><pre>0xx:</pre><pre>EBX: 0xx ECX: 0xx EDX: 0xx</pre><pre>EDI: 0xx ESI: 0xx EAX: 0xx</pre><pre>%s\CRASH_REPORT_%s.txt</pre><pre>EFlags: 0xx ESP: 0xx SegSs: 0xx</pre><pre>EIP: 0xx EBP: 0xx SegCs: 0xx</pre><pre>%s caused %s (0xx)</pre><pre>in module %s at x:x.</pre><pre>%s location x caused an access violation.</pre><pre>Exception code is 0xX</pre><pre>Crash dump file: %s</pre><pre>Crash report file :%s</pre><pre>%s\CRASH_DUMP_%s.dmp</pre><pre>===== [end of %s] =====</pre><pre>Error creating dump file, err=%d</pre><pre>P%d_T%d_Dld_ld_ld_Tld_ld_ld</pre><pre>code: %x</pre><pre>code: %x, addr: %x, module: %s</pre><pre>00:00:00.</pre><pre>NtQueryKey</pre><pre>{{{$615}}}</pre><pre>{{{$618}}}</pre><pre>{{{$617}}}</pre><pre>{{{$616}}}</pre><pre>{{{$624}}}</pre><pre>{{{$623}}}</pre><pre>{{{$691}}}</pre><pre>{{{$690}}}</pre><pre>{{{$693}}}</pre><pre>{{{$692}}}</pre><pre>%s 0x%I64x %s [file:%s(%u)]</pre><pre>ftp://</pre><pre>https://</pre><pre>http://</pre><pre>wininet.dll</pre><pre>[%u, 0xx] %s</pre><pre>https</pre><pre>HTTP/1.0</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>request HttpSendRequestA failed...</pre><pre>Content-Length: %u</pre><pre>response failed...last error %d</pre><pre>1.1.3</pre><pre>gen_codes: max_code %d</pre><pre>code %d bits %d->%d</pre><pre>bl code -</pre><pre>opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u</pre><pre>last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)</pre><pre>{{{$717}}}</pre><pre>{{{$718}}}</pre><pre>{{{$719}}}</pre><pre>{{{$720}}}</pre><pre>{{{$723}}}</pre><pre>{{{$722}}}</pre><pre>{{{$721}}}</pre><pre>{{{$724}}}</pre><pre>{{{$725}}}</pre><pre>{{{$728}}}</pre><pre>{{{$727}}}</pre><pre>{{{$726}}}</pre><pre>{{{$729}}}</pre><pre>{{{$730}}}</pre><pre>{{{$731}}}</pre><pre>{{{$733}}}</pre><pre>{{{$732}}}</pre><pre>{{{$735}}}</pre><pre>{{{$734}}}</pre><pre>{{{$744}}}</pre><pre>{{{$743}}}</pre><pre>{{{$742}}}</pre><pre>{{{$747}}}</pre><pre>{{{$746}}}</pre><pre>%{{{$667}}}</pre><pre>{{{$669}}}</pre><pre>{{{$668}}}</pre><pre>SQLite format 3</pre><pre>REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY</pre><pre>CREATE TABLE sqlite_master(</pre><pre>sql text</pre><pre>3.7.16</pre><pre>CREATE TEMP TABLE sqlite_temp_master(</pre><pre>{{{$101}}}</pre><pre>{{{$103}}}</pre><pre>{{{$102}}}</pre><pre>{{{$108}}}</pre><pre>{{{$107}}}</pre><pre>{{{$110}}}</pre><pre>{{{$109}}}</pre><pre>{{{$104}}}</pre><pre>{{{$106}}}</pre><pre>{{{$105}}}</pre><pre>{{{$112}}}</pre><pre>{{{$111}}}</pre><pre>{{{$113}}}</pre><pre>{{{$114}}}</pre><pre>{{{$118}}}</pre><pre>{{{$119}}}</pre><pre>{{{$115}}}</pre><pre>{{{$117}}}</pre><pre>{{{$116}}}</pre><pre>{{{$121}}}</pre><pre>{{{$123}}}</pre><pre>{{{$122}}}</pre><pre>{{{$120}}}</pre><pre>{{{$100}}}</pre><pre>{{{$685}}}</pre><pre>{{{$684}}}</pre><pre>{{{$687}}}</pre><pre>{{{$686}}}</pre><pre>{{{$681}}}</pre><pre>{{{$683}}}</pre><pre>{{{$682}}}</pre><pre>{{{$688}}}</pre><pre>%A%@%S%Q%W%J%S%L%B%J%</pre><pre>%F%J%H%</pre><pre>*F'F$FhF5F#F'F4F%F.FhF%F)F(F"F3F/F2FhF%F)F F</pre><pre>boost::too_few_args: format-string referred to more arguments than were passed</pre><pre>boost::too_many_args: format-string referred to less arguments than were passed</pre><pre>{{{$137}}}</pre><pre>Content-Disposition: form-data; name="%s"; filename="%s"</pre><pre>Content-Disposition: form-data; name="%s"</pre><pre>_0_9_ _(_>_-_:_</pre><pre>_:_>_-_<_7_><pre>_-_0_ _:_<_ _><pre>SQLITE_</pre><pre>d-d-d d:d:d</pre><pre>d:d:d</pre><pre>d-d-d</pre><pre>failed to allocate %u bytes of memory</pre><pre>failed memory resize %u to %u bytes</pre><pre>API call with %s database connection pointer</pre><pre>922337203685477580</pre><pre>RowKey</pre><pre>OsError 0x%x (%u)</pre><pre>os_win.c:%d: (%d) %s(%s) - %s</pre><pre>GetProcessHeap</pre><pre>delayed %dms for lock/sharing conflict</pre><pre>%s-shm</pre><pre>%s\etilqs_</pre><pre>%s\%s</pre><pre>Recovered %d frames from WAL file %s</pre><pre>cannot limit WAL size: %s</pre><pre>invalid page number %d</pre><pre>Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)</pre><pre>%d of %d pages missing from overflow list starting at %d</pre><pre>2nd reference to page %d</pre><pre>Failed to read ptrmap key=%d</pre><pre>Page %d:</pre><pre>unable to get the page. error code=%d</pre><pre>failed to get page %d</pre><pre>freelist leaf count too big on page %d</pre><pre>btreeInitPage() returns error code %d</pre><pre>On tree page %d cell %d:</pre><pre>On page %d at right child:</pre><pre>Multiple uses for byte %d of page %d</pre><pre>Fragmentation of %d bytes reported as %d on page %d</pre><pre>Corruption detected in cell %d on page %d</pre><pre>Page %d is never used</pre><pre>Pointer map page %d is referenced</pre><pre>unknown database %s</pre><pre>Outstanding page count goes from %d to %d during this analysis</pre><pre>keyinfo(%d</pre><pre>%s(%d)</pre><pre>MJ delete: %s</pre><pre>MJ collide: %s</pre><pre>%s-mjXXXXXX9XXz</pre><pre>-mjX9X</pre><pre>foreign key constraint failed</pre><pre>bind on a busy prepared statement: [%s]</pre><pre>unable to use function %s in the requested context</pre><pre>zeroblob(%d)</pre><pre>constraint failed at %d in [%s]</pre><pre>cannot open savepoint - SQL statements in progress</pre><pre>abort at %d in [%s]: %s</pre><pre>cannot commit transaction - SQL statements in progress</pre><pre>no such savepoint: %s</pre><pre>cannot release savepoint - SQL statements in progress</pre><pre>sqlite_temp_master</pre><pre>sqlite_master</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid</pre><pre>database table is locked: %s</pre><pre>statement aborts at %d: [%s] %s</pre><pre>cannot change %s wal mode from within a transaction</pre><pre>cannot open value of type %s</pre><pre>cannot open view: %s</pre><pre>no such column: "%s"</pre><pre>cannot open virtual table: %s</pre><pre>cannot open %s column for writing</pre><pre>foreign key</pre><pre>indexed</pre><pre>misuse of aliased aggregate %s</pre><pre>%s: %s</pre><pre>not authorized to use function: %s</pre><pre>%s: %s.%s.%s</pre><pre>%s: %s.%s</pre><pre>%r %s BY term out of range - should be between 1 and %d</pre><pre>too many terms in %s BY clause</pre><pre>variable number must be between ?1 and ?%d</pre><pre>too many SQL variables</pre><pre>Expression tree is too large (maximum depth %d)</pre><pre>too many columns in %s</pre><pre>EXECUTE %s%s SUBQUERY %d</pre><pre>%.*s"%w"%s</pre><pre>misuse of aggregate: %s()</pre><pre>sqlite_rename_trigger</pre><pre>sqlite_rename_parent</pre><pre>%s%.*s"%w"</pre><pre>sqlite_rename_table</pre><pre>type='trigger' AND (%s)</pre><pre>%s OR name=%Q</pre><pre>there is already another table or index with this name: %s</pre><pre>view %s may not be altered</pre><pre>sqlite_</pre><pre>table %s may not be altered</pre><pre>sqlite_sequence</pre><pre>UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q</pre><pre>UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;</pre><pre>UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');</pre><pre>UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;</pre><pre>Cannot add a PRIMARY KEY column</pre><pre>UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q</pre><pre>sqlite_stat1</pre><pre>sqlite_altertab_%s</pre><pre>CREATE TABLE %Q.%s(%s)</pre><pre>DELETE FROM %Q.%s WHERE %s=%Q</pre><pre>SELECT tbl,idx,stat FROM %Q.sqlite_stat1</pre><pre>database %s is already in use</pre><pre>invalid name: "%s"</pre><pre>too many attached databases - max %d</pre><pre>unable to open database: %s</pre><pre>no such database: %s</pre><pre>database %s is locked</pre><pre>sqlite_detach</pre><pre>cannot detach database %s</pre><pre>access to %s.%s.%s is prohibited</pre><pre>sqlite_attach</pre><pre>%s %T cannot reference objects in database %s</pre><pre>access to %s.%s is prohibited</pre><pre>object name reserved for internal use: %s</pre><pre>too many columns on %s</pre><pre>duplicate column name: %s</pre><pre>there is already an index named %s</pre><pre>AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY</pre><pre>default value of column [%s] is not constant</pre><pre>table "%s" has more than one primary key</pre><pre>CREATE %s %.*s</pre><pre>UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d</pre><pre>view %s is circularly defined</pre><pre>CREATE TABLE %Q.sqlite_sequence(name,seq)</pre><pre>DELETE FROM %Q.sqlite_sequence WHERE name=%Q</pre><pre>DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'</pre><pre>UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d</pre><pre>sqlite_stat%d</pre><pre>use DROP TABLE to delete table %s</pre><pre>use DROP VIEW to delete view %s</pre><pre>sqlite_stat</pre><pre>table %s may not be dropped</pre><pre>unknown column "%s" in foreign key definition</pre><pre>indexed columns are not unique</pre><pre>foreign key on %s should reference only one column of table %T</pre><pre>number of columns in foreign key does not match the number of columns in the referenced table</pre><pre>table %s may not be indexed</pre><pre>views may not be indexed</pre><pre>index %s already exists</pre><pre>sqlite_autoindex_%s_%d</pre><pre>virtual tables may not be indexed</pre><pre>there is already a table named %s</pre><pre>table %s has no column named %s</pre><pre>no such index: %S</pre><pre>CREATE%s INDEX %.*s</pre><pre>INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);</pre><pre>index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped</pre><pre>DELETE FROM %Q.%s WHERE name=%Q AND type='index'</pre><pre>a JOIN clause is required before %s</pre><pre>unable to identify the object to be reindexed</pre><pre>no such collation sequence: %s</pre><pre>table %s may not be modified</pre><pre>cannot modify %s because it is a view</pre><pre>sqlite_version</pre><pre>sqlite_source_id</pre><pre>sqlite_compileoption_get</pre><pre>sqlite_log</pre><pre>sqlite_compileoption_used</pre><pre>foreign key mismatch - "%w" referencing "%w"</pre><pre>%d values for %d columns</pre><pre>table %S has no column named %s</pre><pre>table %S has %d columns but %d values were supplied</pre><pre>constraint %s failed</pre><pre>PRIMARY KEY must be unique</pre><pre>%s.%s may not be NULL</pre><pre>unable to open shared library [%s]</pre><pre>no entry point [%s] in shared library [%s]</pre><pre>sqlite3_extension_init</pre><pre>error during initialization: %s</pre><pre>automatic extension loading failed: %s</pre><pre>foreign_keys</pre><pre>foreign_key_list</pre><pre>foreign_key_check</pre><pre>*** in database %s ***</pre><pre>unsupported encoding: %s</pre><pre>malformed database schema (%s)</pre><pre>unsupported file format</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid</pre><pre>%s - %s</pre><pre>database schema is locked: %s</pre><pre>RIGHT and FULL OUTER JOINs are not currently supported</pre><pre>a NATURAL join may not have an ON or USING clause</pre><pre>unknown or unsupported join type: %T %T%s%T</pre><pre>cannot have both ON and USING clauses in the same join</pre><pre>cannot join using column %s - column not present in both tables</pre><pre>USE TEMP B-TREE FOR %s</pre><pre>%s.%s</pre><pre>%s:%d</pre><pre>COMPOUND SUBQUERIES %d AND %d %s(%s)</pre><pre>SELECTs to the left and right of %s do not have the same number of result columns</pre><pre>ORDER BY clause should come after %s not before</pre><pre>LIMIT clause should come after %s not before</pre><pre>too many references to "%s": max 65535</pre><pre>%s.%s.%s</pre><pre>no such index: %s</pre><pre>sqlite_subquery_%p_</pre><pre>no such table: %s</pre><pre>SCAN TABLE %s %s%s(~%d rows)</pre><pre>sqlite3_get_table() called with two or more incompatible queries</pre><pre>cannot create %s trigger on view: %S</pre><pre>cannot create INSTEAD OF trigger on table: %S</pre><pre>no such trigger: %S</pre><pre>-- TRIGGER %s</pre><pre>INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')</pre><pre>no such column: %s</pre><pre>PRAGMA vacuum_db.synchronous=OFF</pre><pre>cannot VACUUM - SQL statements in progress</pre><pre>SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'</pre><pre>SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'</pre><pre>SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';</pre><pre>INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'</pre><pre>vtable constructor failed: %s</pre><pre>UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d</pre><pre>no such module: %s</pre><pre>vtable constructor did not declare schema: %s</pre><pre>table %s: xBestIndex returned an invalid plan</pre><pre>%s TABLE %s</pre><pre>%s AS %s</pre><pre>%s SUBQUERY %d</pre><pre>%s USING %s%sINDEX%s%s%s</pre><pre>%s USING INTEGER PRIMARY KEY</pre><pre>%s (rowid>?)</pre><pre>%s (rowid<?php)</pre><pre>%s (rowid=?)</pre><pre>%s (rowid>? AND rowid<?)</pre><pre>at most %d tables in a join</pre><pre>cannot use index: %s</pre><pre>%s VIRTUAL TABLE INDEX %d:%s</pre><pre>%s (~%lld rows)</pre><pre>the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>SQL logic error or missing database</pre><pre>unknown operation</pre><pre>large file support is disabled</pre><pre>unknown database: %s</pre><pre>no such %s mode: %s</pre><pre>%s mode not allowed: %s</pre><pre>no such vfs: %s</pre><pre>cannot open file at line %d of [%.10s]</pre><pre>database corruption at line %d of [%.10s]</pre><pre>misuse at line %d of [%.10s]</pre><pre>{{{$705}}}</pre><pre>{{{$703}}}</pre><pre>{{{$704}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\SearchProtector\Dev\2.16.10\Output\Release_32\CltMngSvc.pdb</pre><pre>WTSAPI32.dll</pre><pre>USERENV.dll</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>ReportEventW</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>I_RpcBindingInqTransportType</pre><pre>RPCRT4.dll</pre><pre>PSAPI.DLL</pre><pre>VERSION.dll</pre><pre>HttpOpenRequestA</pre><pre>HttpAddRequestHeadersA</pre><pre>HttpSendRequestW</pre><pre>HttpSendRequestA</pre><pre>HttpSendRequestExW</pre><pre>HttpEndRequestW</pre><pre>HttpQueryInfoA</pre><pre>WININET.dll</pre><pre>CryptMsgClose</pre><pre>CertGetNameStringW</pre><pre>CertFreeCertificateContext</pre><pre>CertFindCertificateInStore</pre><pre>CertCloseStore</pre><pre>CryptMsgGetParam</pre><pre>CRYPT32.dll</pre><pre>dbghelp.dll</pre><pre>GetCPInfo</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegEnumKeyExW</pre><pre>RegCreateKeyExW</pre><pre>RegNotifyChangeKeyValue</pre><pre>ReportEventA</pre><pre>zcÁ</pre><pre>C:\PROGRA~1\SearchProtect\</pre><pre>;74/, (%#</pre><pre>~{xrpfa\ZSM@;3-%U</pre><pre>function k(a) { return a < 10 ? "0" a : a } function o(a) { p.lastIndex = 0; return p.test(a) ? '"' a.replace(p, function (a) { var c = r[a]; return typeof c === "string" ? c : "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) }) '"' : '"' a '"' } function l(a, j) {</pre><pre>var c, d, h, m, g = e, f, b = j[a]; b && typeof b === "object" && typeof b.toJSON === "function" && (b = b.toJSON(a)); typeof i === "function" && (b = i.call(j, a, b)); switch (typeof b) {</pre><pre>e = n; f = []; if (Object.prototype.toString.apply(b) === "[object Array]") { m = b.length; for (c = 0; c < m; c = 1) f[c] = l(c, b) || "null"; h = f.length === 0 ? "[]" : e ? "[\n" e f.join(",\n" e) "\n" g "]" : "[" f.join(",") "]"; e = g; return h } if (i && typeof i === "object") { m = i.length; for (c = 0; c < m; c = 1) typeof i[c] === "string" && (d = i[c], (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h)) } else for (d in b) Object.prototype.hasOwnProperty.call(b, d) && (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h); h = f.length === 0 ? "{}" : e ? "{\n" e f.join(",\n" e) "\n" g "}" : "{" f.join(",") </pre><pre>} if (typeof Date.prototype.toJSON !== "function") Date.prototype.toJSON = function () { return isFinite(this.valueOf()) ? this.getUTCFullYear() "-" k(this.getUTCMonth() 1) "-" k(this.getUTCDate()) "T" k(this.getUTCHours()) ":" k(this.getUTCMinutes()) ":" k(this.getUTCSeconds()) "Z" : null }, String.prototype.toJSON = Number.prototype.toJSON = Boolean.prototype.toJSON = function () { return this.valueOf() }; var q = /[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,</pre><pre>p = /[\\\"\x00-\x1f\x7f-\x9f\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g, e, n, r = { "\u0008": "\\b", "\t": "\\t", "\n": "\\n", "\u000c": "\\f", "\r": "\\r", '"': '\\"', "\\": "\\\\" }, i; if (typeof JSON.stringify !== "function") JSON.stringify = function (a, j, c) {</pre><pre>var d; n = e = ""; if (typeof c === "number") for (d = 0; d < c; d = 1) n = " "; else typeof c === "string" && (n = c); if ((i = j) && typeof j !== "function" && (typeof j !== "object" || typeof j.length !== "number")) throw Error("JSON.stringify"); return l("",</pre><pre>}; if (typeof JSON.parse !== "function") JSON.parse = function (a, e) {</pre><pre>function c(a, d) { var g, f, b = a[d]; if (b && typeof b === "object") for (g in b) Object.prototype.hasOwnProperty.call(b, g) && (f = c(b, g), f !== void 0 ? b[g] = f : delete b[g]); return e.call(a, d, b) } var d, a = String(a); q.lastIndex = 0; q.test(a) && (a = a.replace(q, function (a) { return "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) })); if (/^[\],:{}\s]*$/.test(a.replace(/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g, "@").replace(/"[^"\\\n\r]*"|true|false|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,</pre><pre>"]").replace(/(?:^|:|,)(?:\s*\[) /g, ""))) return d = eval("(" a ")"), typeof e === "function" ? c({ "": d }, "") : d; throw new SyntaxError("JSON.parse");</pre><pre>ws.api = ws.api || {};</pre><pre>ws.api.FunctionsEnum = {</pre><pre>SET_KEY: 1,</pre><pre>GET_KEY: 2,</pre><pre>REMOVE_KEY: 3,</pre><pre>ws.api.StatusEnum = {</pre><pre>SP_RESULT_KEY_DOES_NOT_EXIST: -2,</pre><pre>ws.api.RESULT_TIMOUET = 3000;</pre><pre>ws.api.storage = ws.api.storage || {};</pre><pre>ws.api.storage.setKey =</pre><pre>function (pluginId, key, value, callback, options) {</pre><pre>if (typeof (pluginId) !== 'string' || pluginId === "" || typeof (key) !== 'string' || key === "" || typeof (callback) !== 'function') {</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_INVALID_PARAMS);</pre><pre>// Construct an object which will be passed to the VC holding all the parameters</pre><pre>data.funcId = ws.api.FunctionsEnum.SET_KEY;</pre><pre>data.pluginId = pluginId;</pre><pre>data.key = key;</pre><pre>data.value = value;</pre><pre>data.options = options; // Currently not used - this is for future use, if we will want to add more parameters we will</pre><pre>var resultObj = JSON.parse(result);</pre><pre>callback(resultObj.status);</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE);</pre><pre>}, ws.api.RESULT_TIMOUET);</pre><pre>ws.internal.SendStringToVC(JSON.stringify(data), myCallback);</pre><pre>ws.api.storage.getKey =</pre><pre>function (pluginId, key, callback, options) {</pre><pre>data.funcId = ws.api.FunctionsEnum.GET_KEY;</pre><pre>var value = resultObj.value;</pre><pre>if (resultObj.status != ws.api.StatusEnum.SP_RESULT_SUCCESS) {</pre><pre>callback(resultObj.status, value);</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE, "");</pre><pre>ws.api.storage.removeKey =</pre><pre>data.funcId = ws.api.FunctionsEnum.REMOVE_KEY;</pre><pre>ws.api.system = ws.api.system || {};</pre><pre>ws.api.system.remove =</pre><pre>data.funcId = ws.api.FunctionsEnum.REMOVE;</pre><pre>data.shouldCallUninstaller = shouldCallUninstaller;</pre><pre>ws.internal = ws.internal || {};</pre><pre>if (ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID === undefined) {</pre><pre>ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID = true;</pre><pre><requestedExecutionLevel level='asInvoker' uiAccess='false' /></pre><pre>; ;$;(;,;0;4;8;<;</pre><pre>; ;$;(;,;0;4;</pre><pre>4%5x5</pre><pre>6$6-666d6k6t6}6</pre><pre>9 9$9(9,9094989<9@9[9</pre><pre>393U3o3</pre><pre>7Â8u8</pre><pre>1-2</pre><pre>1 1$1(1,101</pre><pre>11C1R1a1p1</pre><pre>7t7C7R7a7p7</pre><pre>4 4$4(4,404</pre><pre>;&;6; <2<</pre><pre>1 2$2(2,202</pre><pre>1%1X1e1</pre><pre>253C3K3R3</pre><pre>2 2$2(2,2024282<2</pre><pre>< <$<(<,<0<4<8<<<</pre><pre>4 4$4(4,4044484</pre><pre>3)353:3^3</pre><pre>223F3i3~3</pre><pre>7 7;7@7_7</pre><pre>= =$=(=,=0=4=8=</pre><pre>7 7$7(7,7|7</pre><pre>4(5,5\5`5</pre><pre>?$?(?@?\?</pre><pre>>$>(>@>\>`>|></pre><pre>14181\1`1</pre><pre>3 3(30383</pre><pre>? ?$?(?,?0?4?8?</pre><pre>0 0$0(0,0004080<0</pre><pre>2 2$2(2,20242</pre><pre>6$6,646<6</pre><pre>hmscoree.dll</pre><pre>Vkernel32.dll</pre><pre>combase.dll</pre><pre>- floating point support not loaded</pre><pre>- CRT not initialized</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>portuguese-brazilian</pre><pre>8.0.0.0-11.999.999.999</pre><pre>33.0.0.0-36.999.999.999</pre><pre>16.0.0.0-31.999.999.999</pre><pre>Failed to execute installer :</pre><pre>SPSetup.exe</pre><pre>}{{{$663}}}</pre><pre>{{{$664}}}</pre><pre>{{{$665}}}</pre><pre>}{{{$666}}}</pre><pre>{{{$663}}}</pre><pre>{{{$666}}}</pre><pre>%s (Error: %d)</pre><pre>{{{SP#Conduit::SearchProtector::Service::ServiceBase::ReportEventW#SP}}}</pre><pre>*.dmp</pre><pre>{{{$1053}}}</pre><pre>}{{{$665}}}</pre><pre>{{{$1120}}}</pre><pre>{{{$1121}}}</pre><pre>}WindowsSessionManagerThread</pre><pre>2.16.10.61</pre><pre>UIRepository.dat</pre><pre>UserRepository.dat</pre><pre>SystemRepository.dat</pre><pre>{{{$607}}}</pre><pre> {{{$665}}}</pre><pre>36.0.0.0</pre><pre>{{{$291}}}</pre><pre>{{{$290}}}</pre><pre>{{{$294}}}</pre><pre>{{{$293}}}</pre><pre>{{{$297}}}</pre><pre>{{{$296}}}</pre><pre>Failed to set Url</pre><pre>{{{$303}}}</pre><pre>{{{$307}}}</pre><pre>{{{$304}}}</pre><pre>{{{$305}}}</pre><pre>{{{$306}}}</pre><pre>{{{$310}}}</pre><pre>{{{$309}}}</pre><pre>{{{$317}}}</pre><pre>{{{$316}}}</pre><pre>{{{$322}}}</pre><pre>{{{$321}}}</pre><pre>{{{$325}}}</pre><pre>{{{$330}}}</pre><pre>{{{$329}}}</pre><pre>{{{$333}}}</pre><pre>{{{$332}}}</pre><pre>{{{$345}}}</pre><pre>{{{$344}}}</pre><pre>{{{$350}}}</pre><pre>{{{$351}}}</pre><pre>{{{$355}}}</pre><pre>{{{$354}}}</pre><pre>chrome-extension_</pre><pre>;{{{$252}}}</pre><pre>_0.localstorage</pre><pre>{{{$251}}}</pre><pre>{{{$254}}}</pre><pre>;{{{$666}}}</pre><pre>{{{$255}}}</pre><pre>32.0.0.0</pre><pre>{{{$380}}}</pre><pre>{{{$381}}}</pre><pre>{{{$378}}}</pre><pre>{{{$366}}}</pre><pre>{{{$367}}}</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_PERFORMANCE_NLSTEXT</pre><pre>HKEY_PERFORMANCE_TEXT</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_USERS</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_USER_LOCAL_SETTINGS</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>{{{$707}}}</pre><pre>user32.dll</pre><pre>ieframe.dll</pre><pre>Windows Server 2008</pre><pre>Windows 7</pre><pre>Windows Vista</pre><pre>Windows 8.1</pre><pre>Windows Server 2012</pre><pre>Windows 8</pre><pre>Windows Server 2008 R2</pre><pre>%x %x[%s] %I64x %x %x</pre><pre>{{{$697}}}</pre><pre>{{{$698}}}</pre><pre>SELECT * FROM __InstanceCreationEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>SELECT * FROM __InstanceDeletionEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>yntdll.dll</pre><pre>%s%s%s</pre><pre>Correct password required</pre><pre>{{{SP#Conduit::SearchProtector::Utils::WMIAgentJob::Join#SP}}}</pre><pre>{{{$715}}}</pre><pre>888816666554443</pre><pre>6666554443</pre><pre>!6666554443</pre><pre>{{{$369}}}</pre><pre>{{{$368}}}</pre><pre>{{{$370}}}</pre><pre>{{{$625}}}</pre><pre>HIDispatch error #%d</pre><pre>IWindowsSessionManagerException</pre><pre>01234567</pre><pre>RpcTransportException</pre><pre>N8.0.0.0-11.999.999.999</pre><pre>Kernel32.dll</pre><pre>C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe</pre><b>cltmng.exe_996:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>.EKSWU</pre><pre>\$$;\$0|</pre><pre>DlSHA512 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>Camellia for x86 by <appro@openssl.org></pre><pre>AES for Intel AES-NI, CRYPTOGAMS by <appro@openssl.org></pre><pre>6-9'6-9'</pre><pre>$6.:$6.:</pre><pre>*?#1*?#1</pre><pre>>8$4,8$4,</pre><pre>AES for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>RC4 for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>Montgomery Multiplication for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>SHA1 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>SHA256 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>GHASH for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>GF(2^m) Multiplication for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>FtPS</pre><pre>D$@j.Xf</pre><pre>t;j.Yf</pre><pre>j.Xf9</pre><pre>!\$0!\$4</pre><pre><1%u5</pre><pre>FTPj</pre><pre>tCPQ</pre><pre>,4,56,789</pre><pre>PSSSSSSh</pre><pre> FTPj</pre><pre>F\ FTP</pre><pre>j.Yf;</pre><pre>_tcPVj@</pre><pre>.PjRW</pre><pre>r%f;M</pre><pre>broken pipe</pre><pre>inappropriate io control operation</pre><pre>not supported</pre><pre>operation in progress</pre><pre>operation not permitted</pre><pre>operation not supported</pre><pre>operation would block</pre><pre>protocol not supported</pre><pre>function not supported</pre><pre>operation canceled</pre><pre>address_family_not_supported</pre><pre>operation_in_progress</pre><pre>operation_not_supported</pre><pre>protocol_not_supported</pre><pre>operation_would_block</pre><pre>address family not supported</pre><pre>0123456789-</pre><pre>%b %d %H : %M : %S %Y</pre><pre>%m / %d / %y</pre><pre>%I : %M : %S %p</pre><pre>%d / %m / %y</pre><pre>kernel32.dll</pre><pre>boost::filesystem::directory_iterator::operator </pre><pre>The repeat operator "*" cannot start a regular expression.</pre><pre>The repeat operator "?" cannot start a regular expression.</pre><pre>The repeat operator " " cannot start a regular expression.</pre><pre>Found a closing repetition operator } with no corresponding {.</pre><pre>Can't terminate a sub-expression with an alternation operator |.</pre><pre>The \c and \C escape sequences are not supported by POSIX basic regular expressions: try the Perl syntax instead.</pre><pre>A regular expression can start with the alternation operator |.</pre><pre>Invalid alternation operators within (?...) block.</pre><pre>More than one alternation operator | was encountered inside a conditional expression.</pre><pre>Alternation operators are not allowed inside a DEFINE block.</pre><pre>A repetition operator cannot be applied to a zero-width assertion.</pre><pre>left-curly-bracket</pre><pre>right-curly-bracket</pre><pre>0123456789</pre><pre>Unmatched quantified repeat operator { or \{.</pre><pre>Invalid preceding regular expression prior to repetition operator.</pre><pre>boost thread: trying joining itself</pre><pre>Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>Operation not permitted</pre><pre>Inappropriate I/O control operation</pre><pre>Broken pipe</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>CERTIFICATE REQUEST</pre><pre>NEW CERTIFICATE REQUEST</pre><pre>CERTIFICATE</pre><pre>PUBLIC KEY</pre><pre>RSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>ssl_sess_cert</pre><pre>ssl_cert</pre><pre>evp_pkey</pre><pre>x509_pkey</pre><pre>%s(%d): OpenSSL internal error, assertion failed: %s</pre><pre>passed a null parameter</pre><pre>DSO support routines</pre><pre>x509 certificate routines</pre><pre>error:lX:%s:%s:%s</pre><pre>?456789:;<=</pre><pre>!"#$%&'()* ,-./0123</pre><pre>Big Number part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>pubkey</pre><pre>PEM part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>phrase is too short, needs to be at least %d chars</pre><pre>Enter PEM pass phrase:</pre><pre>TRUSTED CERTIFICATE</pre><pre>X509 CERTIFICATE</pre><pre>PRIVATE KEY</pre><pre>ENCRYPTED PRIVATE KEY</pre><pre>ANY PRIVATE KEY</pre><pre>enc_key</pre><pre>key_enc_algor</pre><pre>cert</pre><pre>d.encrypted</pre><pre>d.digest</pre><pre>d.signed_and_enveloped</pre><pre>d.enveloped</pre><pre>d.sign</pre><pre>d.data</pre><pre>d.other</pre><pre>NETSCAPE_CERT_SEQUENCE</pre><pre>certs</pre><pre>X509_PUBKEY</pre><pre>public_key</pre><pre>.\crypto\asn1\x_pubkey.c</pre><pre>DSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>priv_key</pre><pre>pub_key</pre><pre>.\crypto\ec\ec_key.c</pre><pre>EC_PRIVATEKEY</pre><pre>publicKey</pre><pre>privateKey</pre><pre>value.implicitlyCA</pre><pre>value.parameters</pre><pre>value.named_curve</pre><pre>p.char_two</pre><pre>p.prime</pre><pre>p.ppBasis</pre><pre>p.tpBasis</pre><pre>p.onBasis</pre><pre>p.other</pre><pre>Any Extended Key Usage</pre><pre>anyExtendedKeyUsage</pre><pre>supportedAlgorithms</pre><pre>crossCertificatePair</pre><pre>certificateRevocationList</pre><pre>cACertificate</pre><pre>userCertificate</pre><pre>userPassword</pre><pre>supportedApplicationContext</pre><pre>Microsoft Local Key set</pre><pre>LocalKeySet</pre><pre>id-Gost28147-89-None-KeyMeshing</pre><pre>id-Gost28147-89-CryptoPro-KeyMeshing</pre><pre>password based MAC</pre><pre>id-PasswordBasedMAC</pre><pre>X509v3 Certificate Issuer</pre><pre>certificateIssuer</pre><pre>certicom-arc</pre><pre>Proxy Certificate Information</pre><pre>proxyCertInfo</pre><pre>Microsoft Smartcardlogin</pre><pre>msSmartcardLogin</pre><pre>joint-iso-itu-t</pre><pre>JOINT-ISO-ITU-T</pre><pre>set-rootKeyThumb</pre><pre>setAttr-Cert</pre><pre>setCext-cCertRequired</pre><pre>setCext-certType</pre><pre>setct-CertResTBE</pre><pre>setct-CertReqTBEX</pre><pre>setct-CertReqTBE</pre><pre>setct-AcqCardCodeMsgTBE</pre><pre>setct-CertInqReqTBS</pre><pre>setct-CertResData</pre><pre>setct-CertReqTBS</pre><pre>setct-CertReqData</pre><pre>setct-PCertResTBS</pre><pre>setct-PCertReqData</pre><pre>setct-AcqCardCodeMsg</pre><pre>certificate extensions</pre><pre>set-certExt</pre><pre>set-msgExt</pre><pre>id-ecPublicKey</pre><pre>id-cmc-confirmCertAcceptance</pre><pre>id-cmc-getCert</pre><pre>id-regInfo-certReq</pre><pre>id-regCtrl-protocolEncrKey</pre><pre>id-regCtrl-oldCertID</pre><pre>id-it-revPassphrase</pre><pre>id-it-keyPairParamRep</pre><pre>id-it-keyPairParamReq</pre><pre>id-it-unsupportedOIDs</pre><pre>id-it-caKeyUpdateInfo</pre><pre>id-it-encKeyPairTypes</pre><pre>id-it-signKeyPairTypes</pre><pre>id-it-caProtEncCert</pre><pre>id-mod-attribute-cert</pre><pre>id-mod-qualified-cert-93</pre><pre>id-mod-qualified-cert-88</pre><pre>id-smime-aa-ets-certCRLTimestamp</pre><pre>id-smime-aa-ets-certValues</pre><pre>id-smime-aa-ets-CertificateRefs</pre><pre>id-smime-aa-ets-otherSigCert</pre><pre>id-smime-aa-smimeEncryptCerts</pre><pre>id-smime-aa-signingCertificate</pre><pre>id-smime-aa-encrypKeyPref</pre><pre>id-smime-aa-msgSigDigest</pre><pre>id-smime-ct-publishCert</pre><pre>id-smime-mod-msg-v3</pre><pre>sdsiCertificate</pre><pre>x509Certificate</pre><pre>localKeyID</pre><pre>certBag</pre><pre>pkcs8ShroudedKeyBag</pre><pre>keyBag</pre><pre>pbeWithSHA1And2-KeyTripleDES-CBC</pre><pre>pbeWithSHA1And3-KeyTripleDES-CBC</pre><pre>TLS Web Client Authentication</pre><pre>TLS Web Server Authentication</pre><pre>X509v3 Extended Key Usage</pre><pre>extendedKeyUsage</pre><pre>X509v3 Authority Key Identifier</pre><pre>authorityKeyIdentifier</pre><pre>X509v3 Certificate Policies</pre><pre>certificatePolicies</pre><pre>X509v3 Private Key Usage Period</pre><pre>privateKeyUsagePeriod</pre><pre>X509v3 Key Usage</pre><pre>keyUsage</pre><pre>X509v3 Subject Key Identifier</pre><pre>subjectKeyIdentifier</pre><pre>Netscape Certificate Sequence</pre><pre>nsCertSequence</pre><pre>Netscape CA Policy Url</pre><pre>nsCaPolicyUrl</pre><pre>Netscape Renewal Url</pre><pre>nsRenewalUrl</pre><pre>Netscape CA Revocation Url</pre><pre>nsCaRevocationUrl</pre><pre>Netscape Revocation Url</pre><pre>nsRevocationUrl</pre><pre>Netscape Base Url</pre><pre>nsBaseUrl</pre><pre>Netscape Cert Type</pre><pre>nsCertType</pre><pre>Netscape Certificate Extension</pre><pre>nsCertExt</pre><pre>extendedCertificateAttributes</pre><pre>challengePassword</pre><pre>dhKeyAgreement</pre><pre>%'%1%=%C%K%O%s%</pre><pre>.%.-.3.7.9.?.W.[.o.y.</pre><pre>C%C'C3C7C9COCWCiC</pre><pre>RAND part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>You need to read the OpenSSL FAQ, http://www.openssl.org/support/faq.html</pre><pre>lhash part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Stack part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.single</pre><pre>value.set</pre><pre>.\crypto\evp\evp_key.c</pre><pre>nkey <= EVP_MAX_KEY_LENGTH</pre><pre>EVP part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>name.relativename</pre><pre>name.fullname</pre><pre>certificateHold</pre><pre>Certificate Hold</pre><pre>cessationOfOperation</pre><pre>Cessation Of Operation</pre><pre>keyCompromise</pre><pre>Key Compromise</pre><pre>%*s%s:</pre><pre>%*sOnly Attribute Certificates</pre><pre>%*sOnly CA Certificates</pre><pre>%*sOnly User Certificates</pre><pre>ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>d.registeredID</pre><pre>d.iPAddress</pre><pre>d.uniformResourceIdentifier</pre><pre>d.ediPartyName</pre><pre>d.directoryName</pre><pre>d.dNSName</pre><pre>d.rfc822Name</pre><pre>d.otherName</pre><pre>AUTHORITY_KEYID</pre><pre>keyid</pre><pre>cert_info</pre><pre>PKCS8_PRIV_KEY_INFO</pre><pre>pkey</pre><pre>pkeyalg</pre><pre>EC part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>USER32.DLL</pre><pre>NETAPI32.DLL</pre><pre>KERNEL32.DLL</pre><pre>ADVAPI32.DLL</pre><pre>.\crypto\dh\dh_key.c</pre><pre>%s: (%d bit)</pre><pre>Public-Key</pre><pre>Private-Key</pre><pre>recommended-private-length: %d bits</pre><pre>public-key:</pre><pre>private-key:</pre><pre>PKCS#3 DH Public-Key</pre><pre>PKCS#3 DH Private-Key</pre><pre>Public-Key: (%d bit)</pre><pre>Private-Key: (%d bit)</pre><pre>SHA1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD5 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD4 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>AES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>CAST part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Blowfish part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>:RC2 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>.pp@0</pre><pre>aEÐ</pre><pre> (#EÚ</pre><pre>ÚE<<0</pre><pre>IDEA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>libdes part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>DES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>\X</pre><pre>ddddddZ</pre><pre>ddddddZ</pre><pre>%d.%d.%d.%d</pre><pre><unsupported></pre><pre>IP Address:%d.%d.%d.%d</pre><pre>URI:%s</pre><pre>DNS:%s</pre><pre>email:%s</pre><pre>EdiPartyName:<unsupported></pre><pre>X400Name:<unsupported></pre><pre>othername:<unsupported></pre><pre>%d.%d.%d.%d/%d.%d.%d.%d</pre><pre>X509_CERT_PAIR</pre><pre>X509_CERT_AUX</pre><pre>X.509 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>x%s</pre><pre>%s - d:d:d%.*s %d%s</pre><pre>keylen <= sizeof key</pre><pre>EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)</pre><pre>ECDSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Basis Type: %s</pre><pre>Field Type: %s</pre><pre>ASN1 OID: %s</pre><pre>%s %s%lu (%s0x%lx)</pre><pre>'() ,-./:=?</pre><pre>%lu:%s:%s:%d:%s</pre><pre>Verifying - %s</pre><pre>%*sPolicy Text: %s</pre><pre>%*scrlUrl:</pre><pre>EXTENDED_KEY_USAGE</pre><pre>%*sZone: %s, User:</pre><pre>.\crypto\x509v3\v3_akey.c</pre><pre>d.usernotice</pre><pre>d.cpsuri</pre><pre>CERTIFICATEPOLICIES</pre><pre>%*sExplicit Text: %s</pre><pre>%*sNumber%s:</pre><pre>%*sOrganization: %s</pre><pre>%*sCPS: %s</pre><pre>PKEY_USAGE_PERIOD</pre><pre>keyCertSign</pre><pre>Certificate Sign</pre><pre>keyAgreement</pre><pre>Key Agreement</pre><pre>keyEncipherment</pre><pre>Key Encipherment</pre><pre>.\crypto\x509v3\v3_skey.c</pre><pre>CONF part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>PROXY_CERT_INFO_EXTENSION</pre><pre>hexkey</pre><pre>rsa_keygen_pubexp</pre><pre>rsa_keygen_bits</pre><pre>keylength</pre><pre>keyfunc</pre><pre>len>=0 && len<=(int)sizeof(ctx->key)</pre><pre>j <= (int)sizeof(ctx->key)</pre><pre>.\crypto\pkcs12\p12_key.c</pre><pre>d.receiptList</pre><pre>d.allOrFirstTier</pre><pre>d.compressedData</pre><pre>d.authenticatedData</pre><pre>d.encryptedData</pre><pre>d.digestedData</pre><pre>d.envelopedData</pre><pre>d.signedData</pre><pre>d.ori</pre><pre>d.pwri</pre><pre>d.kekri</pre><pre>d.kari</pre><pre>d.ktri</pre><pre>CMS_PasswordRecipientInfo</pre><pre>keyDerivationAlgorithm</pre><pre>keyIdentifier</pre><pre>CMS_KeyAgreeRecipientInfo</pre><pre>recipientEncryptedKeys</pre><pre>CMS_OriginatorIdentifierOrKey</pre><pre>d.originatorKey</pre><pre>CMS_OriginatorPublicKey</pre><pre>CMS_RecipientEncryptedKey</pre><pre>CMS_KeyAgreeRecipientIdentifier</pre><pre>d.rKeyId</pre><pre>CMS_RecipientKeyIdentifier</pre><pre>CMS_OtherKeyAttribute</pre><pre>keyAttr</pre><pre>keyAttrId</pre><pre>CMS_KeyTransRecipientInfo</pre><pre>encryptedKey</pre><pre>keyEncryptionAlgorithm</pre><pre>certificates</pre><pre>d.crl</pre><pre>d.subjectKeyIdentifier</pre><pre>d.issuerAndSerialNumber</pre><pre>CMS_CertificateChoices</pre><pre>d.v2AttrCert</pre><pre>d.v1AttrCert</pre><pre>d.extendedCertificate</pre><pre>d.certificate</pre><pre>CMS_OtherCertificateFormat</pre><pre>otherCert</pre><pre>otherCertFormat</pre><pre>crlUrl</pre><pre>certStatus</pre><pre>certId</pre><pre>OCSP_CERTSTATUS</pre><pre>value.unknown</pre><pre>value.revoked</pre><pre>value.good</pre><pre>value.byKey</pre><pre>value.byName</pre><pre>reqCert</pre><pre>OCSP_CERTID</pre><pre>issuerKeyHash</pre><pre>CONF_def part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>[[%s]]</pre><pre>[%s] %s=%s</pre><pre>ECDH part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.bag</pre><pre>value.safes</pre><pre>value.shkeybag</pre><pre>value.keybag</pre><pre>value.sdsicert</pre><pre>value.x509cert</pre><pre>value.other</pre><pre>%s.dll</pre><pre>%A%@%S%Q%W%J%S%L%B%J%</pre><pre>%F%J%H%</pre><pre>*F'F$FhF5F#F'F4F%F.FhF%F)F(F"F3F/F2FhF%F)F F</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp</pre><pre>{{{$626}}}</pre><pre>{{{$759}}}</pre><pre>{{{$760}}}</pre><pre>{{{$761}}}</pre><pre>{{{$762}}}</pre><pre>{{{$765}}}</pre><pre>{{{$766}}}</pre><pre>@7@!@)@4@</pre><pre>@4@!@ @%@/@6@%@2@</pre><pre>@%@6@%@.@4@</pre><pre>A%@%C%D%P%I%Q%v%@%D%W%F%M%</pre><pre>S6S%S6S!S'S6S7S</pre><pre>8U4U-UuU4U!U!U0U8U%U!U&UuU'U0U4U6U=U0U1U</pre><pre>(\=\7\9\3\*\9\.\</pre><pre>J%V%I%J%F%D%I%@%</pre><pre>{{{$461}}}</pre><pre>{{{$468}}}</pre><pre>{{{$471}}}</pre><pre>{{{$473}}}</pre><pre>_3_0_=_>_3_</pre><pre>_(_6_1_;_0_(_,_</pre><pre>_8_3_0_=_>_3_</pre><pre>_<_0_*_1_ _:_-_,_</pre><pre>S6S!S>S S.SuS</pre><pre>cCc%c</pre><pre>{{{$402}}}</pre><pre>{{{$403}}}</pre><pre>{{{$404}}}</pre><pre>{{{$405}}}</pre><pre>Z.Z#Z*Z?ZgZ}Z.Z?Z"Z.ZuZ2Z.Z7Z6Z}Z</pre><pre>{{{$406}}}</pre><pre>[([>[:[)[8[3[</pre><pre>[>[)[6[&[</pre><pre>{{{$408}}}</pre><pre>{{{$409}}}</pre><pre>{{{$410}}}</pre><pre>F5F#F'F4F%F.F6F*F3F!F/F(F5F</pre><pre>B0B.BbB6B;B2B'B</pre><pre>CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);</pre><pre>insert into ItemTable (key, value) VALUES ('%s', '%s');</pre><pre>PUADQ@%%h`qdv%V@Q%vu`flclfv8:4)%v`ws`wZvu`flclfv8:7%RM@W@%kjkZpkltp`Zkdh`%iln`%"mjh`udb`ZlvZk`rqdgudb`"%DKA%v`ws`wZkjkZpkltp`Zkdh`%%iln`%"mjh`udb`ZlvZk`rqdgudb`"</pre><pre>{{{$312}}}</pre><pre>{{{$313}}}</pre><pre>{{{$314}}}</pre><pre>{{{$334}}}</pre><pre>a!-dc}xyRhcnbidcj~!-~xjjh~yRx</pre><pre>U&U!U4U'U!U U%U</pre><pre>{{{$357}}}</pre><pre>{{{$358}}}</pre><pre>{{{$359}}}</pre><pre>{{{$360}}}</pre><pre>1d'd)d;d7d!dÖd'd,d;d0d!d6d)d</pre><pre>\/\/\9\(\</pre><pre>\StringFileInfo\xx\%s</pre><pre>(more frames truncated from call stack report)</pre><pre>Module %d</pre><pre>%d/%d/%d d:d:d</pre><pre>Image Base: 0xx Image Size: 0xx</pre><pre>File Size: %-10d File Time: %s</pre><pre>Checksum: 0xx Time Stamp: 0xx</pre><pre>Company: %s</pre><pre>FileDesc: %s</pre><pre>Product: %s</pre><pre>ProdVer: %d.%d.%d.%d</pre><pre>FileVer: %d.%d.%d.%d</pre><pre>Windows Server 2008</pre><pre>Windows Vista</pre><pre>Windows 7</pre><pre>Windows Server 2008 R2</pre><pre>Windows 8</pre><pre>Windows 9</pre><pre>Windows Server 2012</pre><pre>Web Edition</pre><pre>Windows Server 9</pre><pre>Windows XP</pre><pre>Windows 2000</pre><pre>(build %d)</pre><pre>This sample does not support this version of Windows.</pre><pre>Error occurred at %s.</pre><pre>Operating system: %s</pre><pre>%d processor(s), type %d.</pre><pre>Operating system: Could not Determine</pre><pre>%d%% memory in use.</pre><pre>%d MBytes paging file.</pre><pre>%d MBytes physical memory free.</pre><pre>%d MBytes user address space free.</pre><pre>%d MBytes user address space.</pre><pre>Web Server Edition</pre><pre>Windows Storage Server 2003</pre><pre>Windows Server 2003 R2</pre><pre>Windows XP Professional x64 Edition</pre><pre>Windows Home Server</pre><pre>Windows Server 2003</pre><pre>a Float Denormal Operand</pre><pre>%d MBytes paging file free.</pre><pre>a Float Invalid Operation</pre><pre>%d MBytes physical memory.</pre><pre>0xx:</pre><pre>EDI: 0xx ESI: 0xx EAX: 0xx</pre><pre>EIP: 0xx EBP: 0xx SegCs: 0xx</pre><pre>EBX: 0xx ECX: 0xx EDX: 0xx</pre><pre>%s\CRASH_REPORT_%s.txt</pre><pre>EFlags: 0xx ESP: 0xx SegSs: 0xx</pre><pre>%s caused %s (0xx)</pre><pre>in module %s at x:x.</pre><pre>%s location x caused an access violation.</pre><pre>%s\CRASH_DUMP_%s.dmp</pre><pre>===== [end of %s] =====</pre><pre>Error creating dump file, err=%d</pre><pre>Exception code is 0xX</pre><pre>Crash dump file: %s</pre><pre>Crash report file :%s</pre><pre>P%d_T%d_Dld_ld_ld_Tld_ld_ld</pre><pre>code: %x</pre><pre>code: %x, addr: %x, module: %s</pre><pre>{{{$629}}}</pre><pre>{{{$631}}}</pre><pre>{{{$630}}}</pre><pre>{{{$632}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h</pre><pre>NtQueryKey</pre><pre>{{{$616}}}</pre><pre>{{{$615}}}</pre><pre>{{{$618}}}</pre><pre>{{{$617}}}</pre><pre>{{{$624}}}</pre><pre>{{{$623}}}</pre><pre>{{{$690}}}</pre><pre>{{{$692}}}</pre><pre>{{{$691}}}</pre><pre>{{{$693}}}</pre><pre>%s 0x%I64x %s [file:%s(%u)]</pre><pre>https://</pre><pre>ftp://</pre><pre>http://</pre><pre>[%u, 0xx] %s</pre><pre>wininet.dll</pre><pre>https</pre><pre>HTTP/1.0</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>request HttpSendRequestA failed...</pre><pre>Content-Length: %u</pre><pre>response failed...last error %d</pre><pre>{{{$668}}}</pre><pre>{{{$669}}}</pre><pre>{{{$667}}}</pre><pre>{{{$770}}}</pre><pre>{{{$771}}}</pre><pre>{{{$768}}}</pre><pre>{{{$769}}}</pre><pre>@`@'@/@%@3@`@$@/@7@.@</pre><pre>{{{$927}}}</pre><pre>{{{$926}}}</pre><pre>`%K%D%G%I%@%A%</pre><pre>{{{$862}}}</pre><pre>{{{$863}}}</pre><pre>E*E E1E E E1EeExExEeE E0E)E)E5E1E7E</pre><pre>D,D%D*D#D!D</pre><pre>D0D0D!D)D4D0DdD7D0DÖD0D</pre><pre>C&C%C"C6C/C7C</pre><pre>4D0D%D/D!D D2D!D6D</pre><pre>S6S!S%S6S!S</pre><pre>{{{$774}}}</pre><pre>{{{$775}}}</pre><pre>{{{$958}}}</pre><pre>{{{$957}}}</pre><pre>{{{$756}}}</pre><pre>{{{$755}}}</pre><pre>{{{$758}}}</pre><pre>{{{$757}}}</pre><pre>9!0!6*33</pre><pre>(22 3"3$8!!</pre><pre>22"3'8!1</pre><pre>22"0-%2(</pre><pre>==$<-< 7.;</pre><pre>==-<(7.></pre><pre>==-<(7.2</pre><pre>=7.==='44='</pre><pre>!!8 1 7 2'</pre><pre>!!1 4 2"</pre><pre>>>'?.? 4-8</pre><pre>>>.? 4-=</pre><pre>>>.? 4-1</pre><pre>>4->>>$77>$</pre><pre>22 3:"3'8!1</pre><pre>22"3'8!=</pre><pre>22"06;"3$$</pre><pre>%<9.#0!:##</pre><pre>))0(!9(<#:*</pre><pre>))9(<#:&</pre><pre>))9 - 9(??</pre><pre>66/7.&7#<%5</pre><pre>66&7&7#<%9</pre><pre>99 8&7)8,3*:</pre><pre>99)8/3*6</pre><pre>93*9993*999#</pre><pre> 2*#;*>!8(</pre><pre> ;*=!8$</pre><pre> !8 !8 1</pre><pre>??&>/>)5,0</pre><pre>:OVZSdip`QjJgo`fqEE\DZKUDPOVFjkq`}qEES:!Mdkai`ESSdip`EOVEEEOVEES:!Hpqdgi`Mdkai`EUDSOVJgo`fqEEE6EE_</pre><pre>00)1/> 1%:#3</pre><pre>0:#00 1 1&:#?</pre><pre>)#:))9(9(<#:&</pre><pre>;9$5& 91:</pre><pre>''>&7&1-4!</pre><pre>''7&2-4$</pre><pre>8:'6%#:29#</pre><pre>((1)8)>";.</pre><pre>((8)="; </pre><pre>(";(((";(((2</pre><pre>:OVZFjhupq`QmlvEE\D:DSSdip`EOVEEUDPOVFjkq`}qEEUDS47EE_</pre><pre><='2:=6!</pre><pre>00)18 1%:#3</pre><pre>00 1%:#?</pre><pre>:OVZ@kq`wFjhudwqh`kqEE\DUDPOVFjhudwqh`kqEEUDPOVFjkq`}qEEUDSOVJgo`fqEEE_</pre><pre>*(5* 1</pre><pre>9!(0!5*3#</pre><pre>$$=%4%2.77</pre><pre>$$4%1.7'</pre><pre>$.7$$$.7$$$></pre><pre>'RKG\}~qv}Hjwh}jlaXXAYGVHYMRK[wvl}`lXXHYNRKWzr}{lXXHZ\NNytm}XRKXXH.YGV(N'<Pyv|t}XHYNRKWzr}{lXXX,XN'<Pyv|t}XPX,XN'<Umlyzt}Pyv|t}XNNytm}XRKXXX,XXBH.YGV(,-GV.XBQXB</pre><pre> [7[.[<[2[5[</pre><pre>[.[([>[)[</pre><pre>[.[5[2[5[([/[:[7[7[>[?[</pre><pre>]2];])]*]<]/]8]</pre><pre>]0]<]/])]</pre><pre>5@.@)@.@3@4@!@,@,@</pre><pre>@4@9@0@%@</pre><pre>spx.params</pre><pre>spx.assets</pre><pre>*_1_6_1_,_ _>_3_3_</pre><pre>4@2@5@%@</pre><pre>SQLite format 3</pre><pre>REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY</pre><pre>CREATE TABLE sqlite_master(</pre><pre>sql text</pre><pre>3.7.16</pre><pre>CREATE TEMP TABLE sqlite_temp_master(</pre><pre>{{{$101}}}</pre><pre>{{{$105}}}</pre><pre>{{{$106}}}</pre><pre>{{{$107}}}</pre><pre>{{{$108}}}</pre><pre>{{{$102}}}</pre><pre>{{{$103}}}</pre><pre>{{{$104}}}</pre><pre>{{{$113}}}</pre><pre>{{{$109}}}</pre><pre>{{{$110}}}</pre><pre>{{{$111}}}</pre><pre>{{{$112}}}</pre><pre>{{{$100}}}</pre><pre>{{{$116}}}</pre><pre>{{{$117}}}</pre><pre>{{{$114}}}</pre><pre>{{{$115}}}</pre><pre>{{{$120}}}</pre><pre>{{{$121}}}</pre><pre>{{{$118}}}</pre><pre>{{{$119}}}</pre><pre>{{{$122}}}</pre><pre>{{{$123}}}</pre><pre>{{{$537}}}</pre><pre>{{{$538}}}</pre><pre>{{{$524}}}</pre><pre>{{{$525}}}</pre><pre>{{{$526}}}</pre><pre>{{{$527}}}</pre><pre>{{{$528}}}</pre><pre>{{{$533}}}</pre><pre>{{{$534}}}</pre><pre>{{{$536}}}</pre><pre>{{{$529}}}</pre><pre>{{{$530}}}</pre><pre>{{{$531}}}</pre><pre>{{{$532}}}</pre><pre>{{{$237}}}</pre><pre>{{{$238}}}</pre><pre>{{{$561}}}</pre><pre>{{{$560}}}</pre><pre>{{{$564}}}</pre><pre>{{{$565}}}</pre><pre>{{{$566}}}</pre><pre>{{{$562}}}</pre><pre>{{{$563}}}</pre><pre>{{{$568}}}</pre><pre>{{{$569}}}</pre><pre>{{{$570}}}</pre><pre>{{{$571}}}</pre><pre>{{{$567}}}</pre><pre>{{{$573}}}</pre><pre>{{{$574}}}</pre><pre>{{{$575}}}</pre><pre>{{{$572}}}</pre><pre>{{{$577}}}</pre><pre>{{{$578}}}</pre><pre>{{{$576}}}</pre><pre>{{{$580}}}</pre><pre>{{{$579}}}</pre><pre>{{{$583}}}</pre><pre>{{{$581}}}</pre><pre>{{{$582}}}</pre><pre>{{{$586}}}</pre><pre>{{{$587}}}</pre><pre>{{{$584}}}</pre><pre>{{{$590}}}</pre><pre>{{{$589}}}</pre><pre>{{{$593}}}</pre><pre>{{{$591}}}</pre><pre>{{{$592}}}</pre><pre>{{{$595}}}</pre><pre>{{{$596}}}</pre><pre>{{{$594}}}</pre><pre>{{{$598}}}</pre><pre>{{{$597}}}</pre><pre>{{{$601}}}</pre><pre>{{{$599}}}</pre><pre>{{{$600}}}</pre><pre>{{{$603}}}</pre><pre>{{{$604}}}</pre><pre>{{{$602}}}</pre><pre>{{{$606}}}</pre><pre>{{{$605}}}</pre><pre>c%W%J%H%l%K%V%Q%D%I%I%</pre><pre>D%D/D!D D2D!D6D</pre><pre>DÐD%D</pre><pre>{{{$505}}}</pre><pre>{{{$509}}}</pre><pre>{{{$506}}}</pre><pre>{{{$507}}}</pre><pre>{{{$508}}}</pre><pre>{{{$510}}}</pre><pre>{{{$513}}}</pre><pre>{{{$511}}}</pre><pre>{{{$512}}}</pre><pre>{{{$514}}}</pre><pre>{{{$515}}}</pre><pre>{{{$516}}}</pre><pre>{{{$517}}}</pre><pre>{{{$518}}}</pre><pre>{{{$519}}}</pre><pre>{{{$520}}}</pre><pre>{{{$521}}}</pre><pre>{{{$522}}}</pre><pre>{{{$523}}}</pre><pre>4|7|?|?|</pre><pre>{{{$613}}}</pre><pre>{{{$614}}}</pre><pre>{{{$609}}}</pre><pre>{{{$610}}}</pre><pre>{{{$611}}}</pre><pre>{{{$612}}}</pre><pre>{{{$717}}}</pre><pre>{{{$719}}}</pre><pre>{{{$718}}}</pre><pre>{{{$720}}}</pre><pre>{{{$724}}}</pre><pre>{{{$722}}}</pre><pre>{{{$721}}}</pre><pre>{{{$723}}}</pre><pre>{{{$725}}}</pre><pre>{{{$726}}}</pre><pre>{{{$728}}}</pre><pre>{{{$727}}}</pre><pre>{{{$730}}}</pre><pre>{{{$729}}}</pre><pre>{{{$731}}}</pre><pre>{{{$735}}}</pre><pre>{{{$734}}}</pre><pre>{{{$733}}}</pre><pre>{{{$732}}}</pre><pre>{{{$742}}}</pre><pre>{{{$744}}}</pre><pre>{{{$743}}}</pre><pre>{{{$746}}}</pre><pre>{{{$747}}}</pre><pre>{{{$638}}}</pre><pre>{{{$643}}}</pre><pre>{{{$640}}}</pre><pre>{{{$639}}}</pre><pre>{{{$642}}}</pre><pre>{{{$641}}}</pre><pre>00:00:00.</pre><pre>1.1.3</pre><pre>gen_codes: max_code %d</pre><pre>code %d bits %d->%d</pre><pre>bl code -</pre><pre>last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)</pre><pre>opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u</pre><pre>{{{$141}}}</pre><pre>{{{$140}}}</pre><pre>{{{$139}}}</pre><pre>{{{$138}}}</pre><pre>{{{$146}}}</pre><pre>{{{$145}}}</pre><pre>{{{$142}}}</pre><pre>{{{$144}}}</pre><pre>{{{$143}}}</pre><pre>{{{$128}}}</pre><pre>{{{$127}}}</pre><pre>{{{$130}}}</pre><pre>{{{$129}}}</pre><pre>{{{$124}}}</pre><pre>{{{$126}}}</pre><pre>{{{$125}}}</pre><pre>{{{$132}}}</pre><pre>{{{$131}}}</pre><pre>{{{$134}}}</pre><pre>{{{$133}}}</pre><pre>{{{$135}}}</pre><pre>boost::too_many_args: format-string referred to less arguments than were passed</pre><pre>boost::too_few_args: format-string referred to more arguments than were passed</pre><pre>Union operator has to be applied to node sets</pre><pre>Content-Disposition: form-data; name="%s"</pre><pre>Content-Disposition: form-data; name="%s"; filename="%s"</pre><pre>Conduit::SearchProtector::Utils::Singleton<class Conduit::SearchProtector::SPM::Services::LoginManager>::GetInstance</pre><pre>invalid map<K, T> key</pre><pre>%s[%d]: %s</pre><pre>SQLITE_OK</pre><pre>SQLITE_INTERNAL</pre><pre>SQLITE_ERROR</pre><pre>SQLITE_ABORT</pre><pre>SQLITE_PERM</pre><pre>SQLITE_LOCKED</pre><pre>SQLITE_BUSY</pre><pre>SQLITE_READONLY</pre><pre>SQLITE_NOMEM</pre><pre>SQLITE_IOERR</pre><pre>SQLITE_INTERRUPT</pre><pre>SQLITE_NOTFOUND</pre><pre>SQLITE_CORRUPT</pre><pre>SQLITE_CANTOPEN</pre><pre>SQLITE_FULL</pre><pre>SQLITE_EMPTY</pre><pre>SQLITE_PROTOCOL</pre><pre>SQLITE_TOOBIG</pre><pre>SQLITE_SCHEMA</pre><pre>SQLITE_MISMATCH</pre><pre>SQLITE_CONSTRAINT</pre><pre>SQLITE_NOLFS</pre><pre>SQLITE_MISUSE</pre><pre>SQLITE_FORMAT</pre><pre>SQLITE_AUTH</pre><pre>SQLITE_ROW</pre><pre>SQLITE_RANGE</pre><pre>CPPSQLITE_ERROR</pre><pre>SQLITE_DONE</pre><pre>SQLITE_</pre><pre>d:d:d</pre><pre>d-d-d d:d:d</pre><pre>d-d-d</pre><pre>failed to allocate %u bytes of memory</pre><pre>failed memory resize %u to %u bytes</pre><pre>API call with %s database connection pointer</pre><pre>922337203685477580</pre><pre>RowKey</pre><pre>GetProcessHeap</pre><pre>OsError 0x%x (%u)</pre><pre>delayed %dms for lock/sharing conflict</pre><pre>os_win.c:%d: (%d) %s(%s) - %s</pre><pre>%s-shm</pre><pre>%s\etilqs_</pre><pre>%s\%s</pre><pre>Recovered %d frames from WAL file %s</pre><pre>cannot limit WAL size: %s</pre><pre>2nd reference to page %d</pre><pre>invalid page number %d</pre><pre>Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)</pre><pre>Failed to read ptrmap key=%d</pre><pre>failed to get page %d</pre><pre>%d of %d pages missing from overflow list starting at %d</pre><pre>Page %d:</pre><pre>freelist leaf count too big on page %d</pre><pre>btreeInitPage() returns error code %d</pre><pre>unable to get the page. error code=%d</pre><pre>On tree page %d cell %d:</pre><pre>On page %d at right child:</pre><pre>Multiple uses for byte %d of page %d</pre><pre>Corruption detected in cell %d on page %d</pre><pre>Fragmentation of %d bytes reported as %d on page %d</pre><pre>Page %d is never used</pre><pre>Outstanding page count goes from %d to %d during this analysis</pre><pre>Pointer map page %d is referenced</pre><pre>unknown database %s</pre><pre>keyinfo(%d</pre><pre>%s(%d)</pre><pre>MJ delete: %s</pre><pre>%s-mjXXXXXX9XXz</pre><pre>-mjX9X</pre><pre>MJ collide: %s</pre><pre>foreign key constraint failed</pre><pre>bind on a busy prepared statement: [%s]</pre><pre>unable to use function %s in the requested context</pre><pre>zeroblob(%d)</pre><pre>constraint failed at %d in [%s]</pre><pre>abort at %d in [%s]: %s</pre><pre>no such savepoint: %s</pre><pre>cannot open savepoint - SQL statements in progress</pre><pre>cannot commit transaction - SQL statements in progress</pre><pre>cannot release savepoint - SQL statements in progress</pre><pre>sqlite_master</pre><pre>sqlite_temp_master</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid</pre><pre>database table is locked: %s</pre><pre>cannot change %s wal mode from within a transaction</pre><pre>statement aborts at %d: [%s] %s</pre><pre>cannot open value of type %s</pre><pre>cannot open view: %s</pre><pre>cannot open virtual table: %s</pre><pre>foreign key</pre><pre>no such column: "%s"</pre><pre>cannot open %s column for writing</pre><pre>indexed</pre><pre>misuse of aliased aggregate %s</pre><pre>%s: %s.%s.%s</pre><pre>%s: %s</pre><pre>%s: %s.%s</pre><pre>not authorized to use function: %s</pre><pre>%r %s BY term out of range - should be between 1 and %d</pre><pre>too many terms in %s BY clause</pre><pre>variable number must be between ?1 and ?%d</pre><pre>Expression tree is too large (maximum depth %d)</pre><pre>too many columns in %s</pre><pre>too many SQL variables</pre><pre>misuse of aggregate: %s()</pre><pre>EXECUTE %s%s SUBQUERY %d</pre><pre>%s%.*s"%w"</pre><pre>%.*s"%w"%s</pre><pre>sqlite_rename_trigger</pre><pre>sqlite_rename_table</pre><pre>sqlite_rename_parent</pre><pre>type='trigger' AND (%s)</pre><pre>%s OR name=%Q</pre><pre>sqlite_</pre><pre>there is already another table or index with this name: %s</pre><pre>table %s may not be altered</pre><pre>UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;</pre><pre>view %s may not be altered</pre><pre>sqlite_sequence</pre><pre>UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');</pre><pre>UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;</pre><pre>UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q</pre><pre>Cannot add a PRIMARY KEY column</pre><pre>UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q</pre><pre>sqlite_stat1</pre><pre>sqlite_altertab_%s</pre><pre>CREATE TABLE %Q.%s(%s)</pre><pre>DELETE FROM %Q.%s WHERE %s=%Q</pre><pre>invalid name: "%s"</pre><pre>SELECT tbl,idx,stat FROM %Q.sqlite_stat1</pre><pre>too many attached databases - max %d</pre><pre>database %s is already in use</pre><pre>unable to open database: %s</pre><pre>cannot detach database %s</pre><pre>no such database: %s</pre><pre>database %s is locked</pre><pre>sqlite_attach</pre><pre>sqlite_detach</pre><pre>%s %T cannot reference objects in database %s</pre><pre>access to %s.%s is prohibited</pre><pre>access to %s.%s.%s is prohibited</pre><pre>object name reserved for internal use: %s</pre><pre>too many columns on %s</pre><pre>there is already an index named %s</pre><pre>default value of column [%s] is not constant</pre><pre>duplicate column name: %s</pre><pre>table "%s" has more than one primary key</pre><pre>AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY</pre><pre>CREATE %s %.*s</pre><pre>CREATE TABLE %Q.sqlite_sequence(name,seq)</pre><pre>UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d</pre><pre>UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d</pre><pre>view %s is circularly defined</pre><pre>DELETE FROM %Q.sqlite_sequence WHERE name=%Q</pre><pre>sqlite_stat%d</pre><pre>sqlite_stat</pre><pre>DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'</pre><pre>use DROP TABLE to delete table %s</pre><pre>table %s may not be dropped</pre><pre>foreign key on %s should reference only one column of table %T</pre><pre>use DROP VIEW to delete view %s</pre><pre>unknown column "%s" in foreign key definition</pre><pre>number of columns in foreign key does not match the number of columns in the referenced table</pre><pre>indexed columns are not unique</pre><pre>table %s may not be indexed</pre><pre>virtual tables may not be indexed</pre><pre>views may not be indexed</pre><pre>index %s already exists</pre><pre>there is already a table named %s</pre><pre>table %s has no column named %s</pre><pre>sqlite_autoindex_%s_%d</pre><pre>CREATE%s INDEX %.*s</pre><pre>INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);</pre><pre>index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped</pre><pre>no such index: %S</pre><pre>DELETE FROM %Q.%s WHERE name=%Q AND type='index'</pre><pre>a JOIN clause is required before %s</pre><pre>unable to identify the object to be reindexed</pre><pre>table %s may not be modified</pre><pre>no such collation sequence: %s</pre><pre>cannot modify %s because it is a view</pre><pre>sqlite_version</pre><pre>sqlite_log</pre><pre>sqlite_source_id</pre><pre>sqlite_compileoption_get</pre><pre>sqlite_compileoption_used</pre><pre>foreign key mismatch - "%w" referencing "%w"</pre><pre>%d values for %d columns</pre><pre>table %S has %d columns but %d values were supplied</pre><pre>table %S has no column named %s</pre><pre>constraint %s failed</pre><pre>%s.%s may not be NULL</pre><pre>PRIMARY KEY must be unique</pre><pre>unable to open shared library [%s]</pre><pre>sqlite3_extension_init</pre><pre>error during initialization: %s</pre><pre>no entry point [%s] in shared library [%s]</pre><pre>automatic extension loading failed: %s</pre><pre>foreign_keys</pre><pre>foreign_key_list</pre><pre>foreign_key_check</pre><pre>*** in database %s ***</pre><pre>unsupported encoding: %s</pre><pre>%s - %s</pre><pre>malformed database schema (%s)</pre><pre>unsupported file format</pre><pre>database schema is locked: %s</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid</pre><pre>RIGHT and FULL OUTER JOINs are not currently supported</pre><pre>unknown or unsupported join type: %T %T%s%T</pre><pre>cannot have both ON and USING clauses in the same join</pre><pre>a NATURAL join may not have an ON or USING clause</pre><pre>cannot join using column %s - column not present in both tables</pre><pre>USE TEMP B-TREE FOR %s</pre><pre>%s.%s</pre><pre>COMPOUND SUBQUERIES %d AND %d %s(%s)</pre><pre>ORDER BY clause should come after %s not before</pre><pre>%s:%d</pre><pre>LIMIT clause should come after %s not before</pre><pre>no such index: %s</pre><pre>SELECTs to the left and right of %s do not have the same number of result columns</pre><pre>too many references to "%s": max 65535</pre><pre>sqlite_subquery_%p_</pre><pre>no such table: %s</pre><pre>%s.%s.%s</pre><pre>SCAN TABLE %s %s%s(~%d rows)</pre><pre>sqlite3_get_table() called with two or more incompatible queries</pre><pre>cannot create %s trigger on view: %S</pre><pre>INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')</pre><pre>cannot create INSTEAD OF trigger on table: %S</pre><pre>no such trigger: %S</pre><pre>no such column: %s</pre><pre>-- TRIGGER %s</pre><pre>cannot VACUUM - SQL statements in progress</pre><pre>PRAGMA vacuum_db.synchronous=OFF</pre><pre>SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'</pre><pre>SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';</pre><pre>SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'</pre><pre>INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)</pre><pre>UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d</pre><pre>vtable constructor did not declare schema: %s</pre><pre>vtable constructor failed: %s</pre><pre>no such module: %s</pre><pre>table %s: xBestIndex returned an invalid plan</pre><pre>%s TABLE %s</pre><pre>%s SUBQUERY %d</pre><pre>%s AS %s</pre><pre>%s USING %s%sINDEX%s%s%s</pre><pre>%s (rowid=?)</pre><pre>%s USING INTEGER PRIMARY KEY</pre><pre>%s (rowid>?)</pre><pre>%s (rowid>? AND rowid<?)</pre><pre>%s VIRTUAL TABLE INDEX %d:%s</pre><pre>%s (rowid<?)</pre><pre>at most %d tables in a join</pre><pre>%s (~%lld rows)</pre><pre>cannot use index: %s</pre><pre>the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>SQL logic error or missing database</pre><pre>unknown operation</pre><pre>large file support is disabled</pre><pre>unknown database: %s</pre><pre>%s mode not allowed: %s</pre><pre>no such %s mode: %s</pre><pre>no such vfs: %s</pre><pre>database corruption at line %d of [%.10s]</pre><pre>cannot open file at line %d of [%.10s]</pre><pre>misuse at line %d of [%.10s]</pre><pre>D*D7D0D%D(D(D</pre><pre>DÐD!D</pre><pre>D!D0D0D-D*D#DdD7D!D6D2D-D'D!DdD"D%D-D(D!D DjDdD</pre><pre>{{{$703}}}</pre><pre>{{{$704}}}</pre><pre>{{{$705}}}</pre><pre>{{{$137}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\SearchProtector\Dev\2.16.10\Output\Release_32\cltmng.pdb</pre><pre>KERNEL32.dll</pre><pre>MsgWaitForMultipleObjects</pre><pre>USER32.dll</pre><pre>VERSION.dll</pre><pre>PSAPI.DLL</pre><pre>InternetCrackUrlW</pre><pre>HttpOpenRequestA</pre><pre>HttpAddRequestHeadersA</pre><pre>HttpSendRequestW</pre><pre>HttpSendRequestA</pre><pre>HttpSendRequestExW</pre><pre>HttpEndRequestW</pre><pre>HttpQueryInfoA</pre><pre>WININET.dll</pre><pre>dbghelp.dll</pre><pre>CryptMsgClose</pre><pre>CertGetNameStringW</pre><pre>CertFreeCertificateContext</pre><pre>CertFindCertificateInStore</pre><pre>CertCloseStore</pre><pre>CryptMsgGetParam</pre><pre>CRYPT32.dll</pre><pre>UrlUnescapeW</pre><pre>SHLWAPI.dll</pre><pre>CreateIoCompletionPort</pre><pre>GetCPInfo</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegEnumKeyExW</pre><pre>RegCreateKeyExW</pre><pre>RegQueryInfoKeyW</pre><pre>RegNotifyChangeKeyValue</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteExW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>ReportEventA</pre><pre>I_RpcBindingInqTransportType</pre><pre>RPCRT4.dll</pre><pre>zcÁ</pre><pre>%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect</pre><pre>function k(a) { return a < 10 ? "0" a : a } function o(a) { p.lastIndex = 0; return p.test(a) ? '"' a.replace(p, function (a) { var c = r[a]; return typeof c === "string" ? c : "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) }) '"' : '"' a '"' } function l(a, j) {</pre><pre>var c, d, h, m, g = e, f, b = j[a]; b && typeof b === "object" && typeof b.toJSON === "function" && (b = b.toJSON(a)); typeof i === "function" && (b = i.call(j, a, b)); switch (typeof b) {</pre><pre>e = n; f = []; if (Object.prototype.toString.apply(b) === "[object Array]") { m = b.length; for (c = 0; c < m; c = 1) f[c] = l(c, b) || "null"; h = f.length === 0 ? "[]" : e ? "[\n" e f.join(",\n" e) "\n" g "]" : "[" f.join(",") "]"; e = g; return h } if (i && typeof i === "object") { m = i.length; for (c = 0; c < m; c = 1) typeof i[c] === "string" && (d = i[c], (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h)) } else for (d in b) Object.prototype.hasOwnProperty.call(b, d) && (h = l(d, b)) && f.push(o(d) (e ? ": " : ":") h); h = f.length === 0 ? "{}" : e ? "{\n" e f.join(",\n" e) "\n" g "}" : "{" f.join(",") </pre><pre>} if (typeof Date.prototype.toJSON !== "function") Date.prototype.toJSON = function () { return isFinite(this.valueOf()) ? this.getUTCFullYear() "-" k(this.getUTCMonth() 1) "-" k(this.getUTCDate()) "T" k(this.getUTCHours()) ":" k(this.getUTCMinutes()) ":" k(this.getUTCSeconds()) "Z" : null }, String.prototype.toJSON = Number.prototype.toJSON = Boolean.prototype.toJSON = function () { return this.valueOf() }; var q = /[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,</pre><pre>p = /[\\\"\x00-\x1f\x7f-\x9f\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g, e, n, r = { "\u0008": "\\b", "\t": "\\t", "\n": "\\n", "\u000c": "\\f", "\r": "\\r", '"': '\\"', "\\": "\\\\" }, i; if (typeof JSON.stringify !== "function") JSON.stringify = function (a, j, c) {</pre><pre>var d; n = e = ""; if (typeof c === "number") for (d = 0; d < c; d = 1) n = " "; else typeof c === "string" && (n = c); if ((i = j) && typeof j !== "function" && (typeof j !== "object" || typeof j.length !== "number")) throw Error("JSON.stringify"); return l("",</pre><pre>}; if (typeof JSON.parse !== "function") JSON.parse = function (a, e) {</pre><pre>function c(a, d) { var g, f, b = a[d]; if (b && typeof b === "object") for (g in b) Object.prototype.hasOwnProperty.call(b, g) && (f = c(b, g), f !== void 0 ? b[g] = f : delete b[g]); return e.call(a, d, b) } var d, a = String(a); q.lastIndex = 0; q.test(a) && (a = a.replace(q, function (a) { return "\\u" ("0000" a.charCodeAt(0).toString(16)).slice(-4) })); if (/^[\],:{}\s]*$/.test(a.replace(/\\(?:["\\\/bfnrt]|u[0-9a-fA-F]{4})/g, "@").replace(/"[^"\\\n\r]*"|true|false|null|-?\d (?:\.\d*)?(?:[eE][ \-]?\d )?/g,</pre><pre>"]").replace(/(?:^|:|,)(?:\s*\[) /g, ""))) return d = eval("(" a ")"), typeof e === "function" ? c({ "": d }, "") : d; throw new SyntaxError("JSON.parse");</pre><pre>ws.api = ws.api || {};</pre><pre>ws.api.FunctionsEnum = {</pre><pre>SET_KEY: 1,</pre><pre>GET_KEY: 2,</pre><pre>REMOVE_KEY: 3,</pre><pre>ws.api.StatusEnum = {</pre><pre>SP_RESULT_KEY_DOES_NOT_EXIST: -2,</pre><pre>ws.api.RESULT_TIMOUET = 3000;</pre><pre>ws.api.storage = ws.api.storage || {};</pre><pre>ws.api.storage.setKey =</pre><pre>function (pluginId, key, value, callback, options) {</pre><pre>if (typeof (pluginId) !== 'string' || pluginId === "" || typeof (key) !== 'string' || key === "" || typeof (callback) !== 'function') {</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_INVALID_PARAMS);</pre><pre>// Construct an object which will be passed to the VC holding all the parameters</pre><pre>data.funcId = ws.api.FunctionsEnum.SET_KEY;</pre><pre>data.pluginId = pluginId;</pre><pre>data.key = key;</pre><pre>data.value = value;</pre><pre>data.options = options; // Currently not used - this is for future use, if we will want to add more parameters we will</pre><pre>var resultObj = JSON.parse(result);</pre><pre>callback(resultObj.status);</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE);</pre><pre>}, ws.api.RESULT_TIMOUET);</pre><pre>ws.internal.SendStringToVC(JSON.stringify(data), myCallback);</pre><pre>ws.api.storage.getKey =</pre><pre>function (pluginId, key, callback, options) {</pre><pre>data.funcId = ws.api.FunctionsEnum.GET_KEY;</pre><pre>var value = resultObj.value;</pre><pre>if (resultObj.status != ws.api.StatusEnum.SP_RESULT_SUCCESS) {</pre><pre>callback(resultObj.status, value);</pre><pre>callback(ws.api.StatusEnum.SP_RESULT_SP_UNRESPONSIVE, "");</pre><pre>ws.api.storage.removeKey =</pre><pre>data.funcId = ws.api.FunctionsEnum.REMOVE_KEY;</pre><pre>ws.api.system = ws.api.system || {};</pre><pre>ws.api.system.remove =</pre><pre>data.funcId = ws.api.FunctionsEnum.REMOVE;</pre><pre>data.shouldCallUninstaller = shouldCallUninstaller;</pre><pre>ws.internal = ws.internal || {};</pre><pre>if (ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID === undefined) {</pre><pre>ws.internal.injectedSP_PLUGIN_ID_SP_TASK_ID = true;</pre><pre>;74/, (%#</pre><pre>~{xrpfa\ZSM@;3-%U</pre><pre><requestedExecutionLevel level='asInvoker' uiAccess='false' /></pre><pre>; ;$;(;,;0;4;8;<;</pre><pre>7 7$7(7,707</pre><pre>0$0(020\0</pre><pre>1%2s2</pre><pre>14282<2@2</pre><pre>7%7S7Z7c7l7</pre><pre>5m6</pre><pre>5 5$5(5,505</pre><pre>343C3R3a3p3</pre><pre>0%0,070\0</pre><pre>67w7</pre><pre>;#;3;~;,<</pre><pre>0 0$0(0,00040;0</pre><pre>6 6$6(6,6064638</pre><pre>5#707 9-9</pre><pre>>$>)?=?\?</pre><pre>6m6</pre><pre>8Œ8S8Z8r8x899=:</pre><pre>6g6X6</pre><pre>0-0A0U0i0}0</pre><pre>7y7S7m7</pre><pre>8œ9</pre><pre>3&363 424</pre><pre>? ?$?(?,?0?</pre><pre>9(:,:0:4:8:<:</pre><pre>>$?,?4?<?</pre><pre>6 6$6(6,6064686<6</pre><pre>0 0$0(0,0004080<0</pre><pre>1 1$1(1,10141</pre><pre>2#2X2</pre><pre>7|8U8</pre><pre>3#545&686</pre><pre>= =$=(=,=0=4=</pre><pre>353F3O3Z3o3}3</pre><pre>9$9-999E9Q9t9}9</pre><pre>5_5</pre><pre>2-2P2}2</pre><pre>0%1U1</pre><pre>1!292?2</pre><pre>9 9$9(949</pre><pre>7 7$707@7</pre><pre>= =(=\=`=</pre><pre>>$>(>,>0>4>8><></pre><pre>9 9(90989</pre><pre>< <$<(<,<0<</pre><pre>= =$=(=,=</pre><pre>9 9$9(9,9|;</pre><pre>? ?(?4?\?</pre><pre>mmscoree.dll</pre><pre>nkernel32.dll</pre><pre>combase.dll</pre><pre>- floating point support not loaded</pre><pre>- CRT not initialized</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>portuguese-brazilian</pre><pre>8.0.0.0-11.999.999.999</pre><pre>33.0.0.0-36.999.999.999</pre><pre>16.0.0.0-31.999.999.999</pre><pre>{{{$663}}}</pre><pre>{{{$664}}}</pre><pre>{{{$665}}}</pre><pre>{{{$666}}}</pre><pre>2.16.10.61</pre><pre>UserRepository.dat</pre><pre>SystemRepository.dat</pre><pre>UIRepository.dat</pre><pre>_0.localstorage</pre><pre>chrome-extension_</pre><pre>{{{$251}}}</pre><pre>{{{$252}}}</pre><pre>{{{$254}}}</pre><pre>{{{$255}}}</pre><pre>36.0.0.0</pre><pre>32.0.0.0</pre><pre>{{{$291}}}</pre><pre>{{{$290}}}</pre><pre>{{{$294}}}</pre><pre>{{{$293}}}</pre><pre>{{{$297}}}</pre><pre>{{{$296}}}</pre><pre>kFailed to set Url</pre><pre>{{{$303}}}</pre><pre>{{{$304}}}</pre><pre>{{{$306}}}</pre><pre>{{{$307}}}</pre><pre>{{{$305}}}</pre><pre>{{{$310}}}</pre><pre>{{{$309}}}</pre><pre>{{{$317}}}</pre><pre>{{{$316}}}</pre><pre>{{{$322}}}</pre><pre>{{{$321}}}</pre><pre>{{{$325}}}</pre><pre>{{{$330}}}</pre><pre>{{{$329}}}</pre><pre>{{{$333}}}</pre><pre>{{{$332}}}</pre><pre>{{{$345}}}</pre><pre>{{{$344}}}</pre><pre>{{{$350}}}</pre><pre>{{{$351}}}</pre><pre>{{{$354}}}</pre><pre>{{{$355}}}</pre><pre>{{{$378}}}</pre><pre>{{{$380}}}</pre><pre>{{{$381}}}</pre><pre>{{{$367}}}</pre><pre>{{{$366}}}</pre><pre>Yuser32.dll</pre><pre>ieframe.dll</pre><pre>Windows Server 2008</pre><pre>Windows Vista</pre><pre>Windows Server 2008 R2</pre><pre>Windows 7</pre><pre>Windows Server 2012</pre><pre>Windows 8</pre><pre>Windows 8.1</pre><pre>%x %x[%s] %I64x %x %x</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_NLSTEXT</pre><pre>HKEY_PERFORMANCE_TEXT</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>HKEY_CURRENT_USER_LOCAL_SETTINGS</pre><pre>ntdll.dll</pre><pre>{{{$698}}}</pre><pre>{{{$697}}}</pre><pre>{{{$868}}}</pre><pre>{{{SP#Conduit::SearchProtector::SPM::SPMAssetsManager::MapAssets#SP}}}</pre><pre>{{{$888}}}</pre><pre>{{{SP#Conduit::SearchProtector::SPM::SPMAssetsManager::ExecuteAssetChangeAttemptDecision#SP}}}</pre><pre>SPSetup.exe</pre><pre>{{{SP#Conduit::SearchProtector::SPM::Services::LoginManager::CheckForCompetitors#SP}}}</pre><pre>{{{SP#Conduit::SearchProtector::SPM::Services::LoginManager::RequestService#SP}}}</pre><pre>{{{SP#Conduit::SearchProtector::SPM::Services::LoginManager::RequestServiceByBrowser#SP}}}</pre><pre>{{{SP#Conduit::SearchProtector::SPM::Services::LoginManager::HttpAsyncCallBack#SP}}}</pre><pre>http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul</pre><pre>Plugin Id: %s, Plugin Name: %s, Plugin version: %s</pre><pre>chrome.exe</pre><pre>%s\script_%d.dat</pre><pre>888816666554443</pre><pre>6666554443</pre><pre>!6666554443</pre><pre>{{{$535}}}</pre><pre>{{{$371}}}</pre><pre>{{{$372}}}</pre><pre>{{{$373}}}</pre><pre>{{{$368}}}</pre><pre>{{{$369}}}</pre><pre>{{{$370}}}</pre><pre>{{{$374}}}</pre><pre>{{{$607}}}</pre><pre>{{{$548}}}</pre><pre>{{{$549}}}</pre><pre>{{{$707}}}</pre><pre>{{{SP#Conduit::SearchProtector::Utils::WMIAgentJob::Join#SP}}}</pre><pre>{{{$715}}}</pre><pre>SELECT * FROM __InstanceCreationEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>SELECT * FROM __InstanceDeletionEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>%s%s%s</pre><pre>Correct password required</pre><pre>IDispatch error #%d</pre><pre>{{{$625}}}</pre><pre>[%s\%s.exe</pre><pre>01234567</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::ServiceManager::HttpAsyncCallBack#SP}}}</pre><pre>UserSettings.dat</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::ServiceHandler::HttpAsyncCallBack#SP}}}</pre><pre>e8.0.0.0-11.999.999.999</pre><pre>{{{$77}}}</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::TimerBasedServiceHandler::HttpAsyncCallBack#SP}}}</pre><pre>iRpcTransportException</pre><pre>C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe</pre><b>cltmngui.exe_1296:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>.EKSWU</pre><pre>\$$;\$0|</pre><pre>DlSHA512 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>Camellia for x86 by <appro@openssl.org></pre><pre>AES for Intel AES-NI, CRYPTOGAMS by <appro@openssl.org></pre><pre>6-9'6-9'</pre><pre>$6.:$6.:</pre><pre>*?#1*?#1</pre><pre>>8$4,8$4,</pre><pre>AES for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>RC4 for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>Montgomery Multiplication for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>SHA1 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>SHA256 block transform for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>GHASH for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>GF(2^m) Multiplication for x86, CRYPTOGAMS by <appro@openssl.org></pre><pre>FtPS</pre><pre>D$@j.Xf</pre><pre>tcPVWQ</pre><pre><1%u5</pre><pre>FTPj</pre><pre>tCPQ</pre><pre>,4,56,789</pre><pre>PSSSSSSh</pre><pre>j.Yf;</pre><pre>_tcPVj@</pre><pre>.PjRW</pre><pre>broken pipe</pre><pre>inappropriate io control operation</pre><pre>not supported</pre><pre>operation in progress</pre><pre>operation not permitted</pre><pre>operation not supported</pre><pre>operation would block</pre><pre>protocol not supported</pre><pre>function not supported</pre><pre>operation canceled</pre><pre>address_family_not_supported</pre><pre>operation_in_progress</pre><pre>operation_not_supported</pre><pre>protocol_not_supported</pre><pre>operation_would_block</pre><pre>address family not supported</pre><pre>0123456789-</pre><pre>%b %d %H : %M : %S %Y</pre><pre>%m / %d / %y</pre><pre>%I : %M : %S %p</pre><pre>%d / %m / %y</pre><pre>kernel32.dll</pre><pre>left-curly-bracket</pre><pre>right-curly-bracket</pre><pre>boost thread: trying joining itself</pre><pre>Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>Operation not permitted</pre><pre>Inappropriate I/O control operation</pre><pre>Broken pipe</pre><pre>GetProcessWindowStation</pre><pre>operator</pre><pre>CERTIFICATE REQUEST</pre><pre>NEW CERTIFICATE REQUEST</pre><pre>CERTIFICATE</pre><pre>PUBLIC KEY</pre><pre>RSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-512 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>ssl_sess_cert</pre><pre>ssl_cert</pre><pre>evp_pkey</pre><pre>x509_pkey</pre><pre>%s(%d): OpenSSL internal error, assertion failed: %s</pre><pre>passed a null parameter</pre><pre>DSO support routines</pre><pre>x509 certificate routines</pre><pre>error:lX:%s:%s:%s</pre><pre>?456789:;<=</pre><pre>!"#$%&'()* ,-./0123</pre><pre>Big Number part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>pubkey</pre><pre>PEM part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>phrase is too short, needs to be at least %d chars</pre><pre>Enter PEM pass phrase:</pre><pre>TRUSTED CERTIFICATE</pre><pre>X509 CERTIFICATE</pre><pre>PRIVATE KEY</pre><pre>ENCRYPTED PRIVATE KEY</pre><pre>ANY PRIVATE KEY</pre><pre>enc_key</pre><pre>key_enc_algor</pre><pre>cert</pre><pre>d.encrypted</pre><pre>d.digest</pre><pre>d.signed_and_enveloped</pre><pre>d.enveloped</pre><pre>d.sign</pre><pre>d.data</pre><pre>d.other</pre><pre>NETSCAPE_CERT_SEQUENCE</pre><pre>certs</pre><pre>X509_PUBKEY</pre><pre>public_key</pre><pre>.\crypto\asn1\x_pubkey.c</pre><pre>DSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>priv_key</pre><pre>pub_key</pre><pre>.\crypto\ec\ec_key.c</pre><pre>EC_PRIVATEKEY</pre><pre>publicKey</pre><pre>privateKey</pre><pre>value.implicitlyCA</pre><pre>value.parameters</pre><pre>value.named_curve</pre><pre>p.char_two</pre><pre>p.prime</pre><pre>p.ppBasis</pre><pre>p.tpBasis</pre><pre>p.onBasis</pre><pre>p.other</pre><pre>Any Extended Key Usage</pre><pre>anyExtendedKeyUsage</pre><pre>supportedAlgorithms</pre><pre>crossCertificatePair</pre><pre>certificateRevocationList</pre><pre>cACertificate</pre><pre>userCertificate</pre><pre>userPassword</pre><pre>supportedApplicationContext</pre><pre>Microsoft Local Key set</pre><pre>LocalKeySet</pre><pre>id-Gost28147-89-None-KeyMeshing</pre><pre>id-Gost28147-89-CryptoPro-KeyMeshing</pre><pre>password based MAC</pre><pre>id-PasswordBasedMAC</pre><pre>X509v3 Certificate Issuer</pre><pre>certificateIssuer</pre><pre>certicom-arc</pre><pre>Proxy Certificate Information</pre><pre>proxyCertInfo</pre><pre>Microsoft Smartcardlogin</pre><pre>msSmartcardLogin</pre><pre>joint-iso-itu-t</pre><pre>JOINT-ISO-ITU-T</pre><pre>set-rootKeyThumb</pre><pre>setAttr-Cert</pre><pre>setCext-cCertRequired</pre><pre>setCext-certType</pre><pre>setct-CertResTBE</pre><pre>setct-CertReqTBEX</pre><pre>setct-CertReqTBE</pre><pre>setct-AcqCardCodeMsgTBE</pre><pre>setct-CertInqReqTBS</pre><pre>setct-CertResData</pre><pre>setct-CertReqTBS</pre><pre>setct-CertReqData</pre><pre>setct-PCertResTBS</pre><pre>setct-PCertReqData</pre><pre>setct-AcqCardCodeMsg</pre><pre>certificate extensions</pre><pre>set-certExt</pre><pre>set-msgExt</pre><pre>id-ecPublicKey</pre><pre>id-cmc-confirmCertAcceptance</pre><pre>id-cmc-getCert</pre><pre>id-regInfo-certReq</pre><pre>id-regCtrl-protocolEncrKey</pre><pre>id-regCtrl-oldCertID</pre><pre>id-it-revPassphrase</pre><pre>id-it-keyPairParamRep</pre><pre>id-it-keyPairParamReq</pre><pre>id-it-unsupportedOIDs</pre><pre>id-it-caKeyUpdateInfo</pre><pre>id-it-encKeyPairTypes</pre><pre>id-it-signKeyPairTypes</pre><pre>id-it-caProtEncCert</pre><pre>id-mod-attribute-cert</pre><pre>id-mod-qualified-cert-93</pre><pre>id-mod-qualified-cert-88</pre><pre>id-smime-aa-ets-certCRLTimestamp</pre><pre>id-smime-aa-ets-certValues</pre><pre>id-smime-aa-ets-CertificateRefs</pre><pre>id-smime-aa-ets-otherSigCert</pre><pre>id-smime-aa-smimeEncryptCerts</pre><pre>id-smime-aa-signingCertificate</pre><pre>id-smime-aa-encrypKeyPref</pre><pre>id-smime-aa-msgSigDigest</pre><pre>id-smime-ct-publishCert</pre><pre>id-smime-mod-msg-v3</pre><pre>sdsiCertificate</pre><pre>x509Certificate</pre><pre>localKeyID</pre><pre>certBag</pre><pre>pkcs8ShroudedKeyBag</pre><pre>keyBag</pre><pre>pbeWithSHA1And2-KeyTripleDES-CBC</pre><pre>pbeWithSHA1And3-KeyTripleDES-CBC</pre><pre>TLS Web Client Authentication</pre><pre>TLS Web Server Authentication</pre><pre>X509v3 Extended Key Usage</pre><pre>extendedKeyUsage</pre><pre>X509v3 Authority Key Identifier</pre><pre>authorityKeyIdentifier</pre><pre>X509v3 Certificate Policies</pre><pre>certificatePolicies</pre><pre>X509v3 Private Key Usage Period</pre><pre>privateKeyUsagePeriod</pre><pre>X509v3 Key Usage</pre><pre>keyUsage</pre><pre>X509v3 Subject Key Identifier</pre><pre>subjectKeyIdentifier</pre><pre>Netscape Certificate Sequence</pre><pre>nsCertSequence</pre><pre>Netscape CA Policy Url</pre><pre>nsCaPolicyUrl</pre><pre>Netscape Renewal Url</pre><pre>nsRenewalUrl</pre><pre>Netscape CA Revocation Url</pre><pre>nsCaRevocationUrl</pre><pre>Netscape Revocation Url</pre><pre>nsRevocationUrl</pre><pre>Netscape Base Url</pre><pre>nsBaseUrl</pre><pre>Netscape Cert Type</pre><pre>nsCertType</pre><pre>Netscape Certificate Extension</pre><pre>nsCertExt</pre><pre>extendedCertificateAttributes</pre><pre>challengePassword</pre><pre>dhKeyAgreement</pre><pre>%'%1%=%C%K%O%s%</pre><pre>.%.-.3.7.9.?.W.[.o.y.</pre><pre>C%C'C3C7C9COCWCiC</pre><pre>RAND part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>You need to read the OpenSSL FAQ, http://www.openssl.org/support/faq.html</pre><pre>lhash part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Stack part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Diffie-Hellman part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.single</pre><pre>value.set</pre><pre>.\crypto\evp\evp_key.c</pre><pre>nkey <= EVP_MAX_KEY_LENGTH</pre><pre>EVP part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>name.relativename</pre><pre>name.fullname</pre><pre>certificateHold</pre><pre>Certificate Hold</pre><pre>cessationOfOperation</pre><pre>Cessation Of Operation</pre><pre>keyCompromise</pre><pre>Key Compromise</pre><pre>%*s%s:</pre><pre>%*sOnly Attribute Certificates</pre><pre>%*sOnly CA Certificates</pre><pre>%*sOnly User Certificates</pre><pre>ASN.1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>d.registeredID</pre><pre>d.iPAddress</pre><pre>d.uniformResourceIdentifier</pre><pre>d.ediPartyName</pre><pre>d.directoryName</pre><pre>d.dNSName</pre><pre>d.rfc822Name</pre><pre>d.otherName</pre><pre>AUTHORITY_KEYID</pre><pre>keyid</pre><pre>cert_info</pre><pre>PKCS8_PRIV_KEY_INFO</pre><pre>pkey</pre><pre>pkeyalg</pre><pre>EC part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>USER32.DLL</pre><pre>NETAPI32.DLL</pre><pre>KERNEL32.DLL</pre><pre>ADVAPI32.DLL</pre><pre>.\crypto\dh\dh_key.c</pre><pre>%s: (%d bit)</pre><pre>Public-Key</pre><pre>Private-Key</pre><pre>recommended-private-length: %d bits</pre><pre>public-key:</pre><pre>private-key:</pre><pre>PKCS#3 DH Public-Key</pre><pre>PKCS#3 DH Private-Key</pre><pre>Public-Key: (%d bit)</pre><pre>Private-Key: (%d bit)</pre><pre>SHA1 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA-256 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>RIPE-MD160 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>SHA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD5 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>MD4 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>AES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>CAST part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Blowfish part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>:RC2 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>.pp@0</pre><pre>aEÐ</pre><pre> (#EÚ</pre><pre>ÚE<<0</pre><pre>IDEA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>libdes part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>DES part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>\X</pre><pre>ddddddZ</pre><pre>ddddddZ</pre><pre>%d.%d.%d.%d</pre><pre><unsupported></pre><pre>IP Address:%d.%d.%d.%d</pre><pre>URI:%s</pre><pre>DNS:%s</pre><pre>email:%s</pre><pre>EdiPartyName:<unsupported></pre><pre>X400Name:<unsupported></pre><pre>othername:<unsupported></pre><pre>%d.%d.%d.%d/%d.%d.%d.%d</pre><pre>X509_CERT_PAIR</pre><pre>X509_CERT_AUX</pre><pre>X.509 part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>x%s</pre><pre>%s - d:d:d%.*s %d%s</pre><pre>keylen <= sizeof key</pre><pre>EVP_CIPHER_key_length(cipher) <= (int)sizeof(md_tmp)</pre><pre>ECDSA part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>Basis Type: %s</pre><pre>Field Type: %s</pre><pre>ASN1 OID: %s</pre><pre>%s %s%lu (%s0x%lx)</pre><pre>'() ,-./:=?</pre><pre>%lu:%s:%s:%d:%s</pre><pre>Verifying - %s</pre><pre>%*sPolicy Text: %s</pre><pre>%*scrlUrl:</pre><pre>EXTENDED_KEY_USAGE</pre><pre>%*sZone: %s, User:</pre><pre>.\crypto\x509v3\v3_akey.c</pre><pre>d.usernotice</pre><pre>d.cpsuri</pre><pre>CERTIFICATEPOLICIES</pre><pre>%*sExplicit Text: %s</pre><pre>%*sNumber%s:</pre><pre>%*sOrganization: %s</pre><pre>%*sCPS: %s</pre><pre>PKEY_USAGE_PERIOD</pre><pre>keyCertSign</pre><pre>Certificate Sign</pre><pre>keyAgreement</pre><pre>Key Agreement</pre><pre>keyEncipherment</pre><pre>Key Encipherment</pre><pre>.\crypto\x509v3\v3_skey.c</pre><pre>CONF part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>PROXY_CERT_INFO_EXTENSION</pre><pre>hexkey</pre><pre>rsa_keygen_pubexp</pre><pre>rsa_keygen_bits</pre><pre>keylength</pre><pre>keyfunc</pre><pre>len>=0 && len<=(int)sizeof(ctx->key)</pre><pre>j <= (int)sizeof(ctx->key)</pre><pre>.\crypto\pkcs12\p12_key.c</pre><pre>d.receiptList</pre><pre>d.allOrFirstTier</pre><pre>d.compressedData</pre><pre>d.authenticatedData</pre><pre>d.encryptedData</pre><pre>d.digestedData</pre><pre>d.envelopedData</pre><pre>d.signedData</pre><pre>d.ori</pre><pre>d.pwri</pre><pre>d.kekri</pre><pre>d.kari</pre><pre>d.ktri</pre><pre>CMS_PasswordRecipientInfo</pre><pre>keyDerivationAlgorithm</pre><pre>keyIdentifier</pre><pre>CMS_KeyAgreeRecipientInfo</pre><pre>recipientEncryptedKeys</pre><pre>CMS_OriginatorIdentifierOrKey</pre><pre>d.originatorKey</pre><pre>CMS_OriginatorPublicKey</pre><pre>CMS_RecipientEncryptedKey</pre><pre>CMS_KeyAgreeRecipientIdentifier</pre><pre>d.rKeyId</pre><pre>CMS_RecipientKeyIdentifier</pre><pre>CMS_OtherKeyAttribute</pre><pre>keyAttr</pre><pre>keyAttrId</pre><pre>CMS_KeyTransRecipientInfo</pre><pre>encryptedKey</pre><pre>keyEncryptionAlgorithm</pre><pre>certificates</pre><pre>d.crl</pre><pre>d.subjectKeyIdentifier</pre><pre>d.issuerAndSerialNumber</pre><pre>CMS_CertificateChoices</pre><pre>d.v2AttrCert</pre><pre>d.v1AttrCert</pre><pre>d.extendedCertificate</pre><pre>d.certificate</pre><pre>CMS_OtherCertificateFormat</pre><pre>otherCert</pre><pre>otherCertFormat</pre><pre>crlUrl</pre><pre>certStatus</pre><pre>certId</pre><pre>OCSP_CERTSTATUS</pre><pre>value.unknown</pre><pre>value.revoked</pre><pre>value.good</pre><pre>value.byKey</pre><pre>value.byName</pre><pre>reqCert</pre><pre>OCSP_CERTID</pre><pre>issuerKeyHash</pre><pre>CONF_def part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>[[%s]]</pre><pre>[%s] %s=%s</pre><pre>ECDH part of OpenSSL 1.0.1e 11 Feb 2013</pre><pre>value.bag</pre><pre>value.safes</pre><pre>value.shkeybag</pre><pre>value.keybag</pre><pre>value.sdsicert</pre><pre>value.x509cert</pre><pre>value.other</pre><pre>%s.dll</pre><pre>%A%@%S%Q%W%J%S%L%B%J%</pre><pre>%F%J%H%</pre><pre>*F'F$FhF5F#F'F4F%F.FhF%F)F(F"F3F/F2FhF%F)F F</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>A%@%C%D%P%I%Q%v%@%D%W%F%M%</pre><pre>(\=\7\9\3\*\9\.\</pre><pre>{{{$1274}}}</pre><pre>{{{$626}}}</pre><pre>{{{$1275}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\Boost\boost_1_55_0\boost/exception/detail/exception_ptr.hpp</pre><pre>J%V%I%J%F%D%I%@%</pre><pre>@7@!@)@4@</pre><pre>@4@!@ @%@/@6@%@2@</pre><pre>@%@6@%@.@4@</pre><pre>S6S%S6S!S'S6S7S</pre><pre>8U4U-UuU4U!U!U0U8U%U!U&UuU'U0U4U6U=U0U1U</pre><pre>{{{$461}}}</pre><pre>{{{$468}}}</pre><pre>{{{$471}}}</pre><pre>{{{$473}}}</pre><pre>\StringFileInfo\xx\%s</pre><pre>(more frames truncated from call stack report)</pre><pre>%d/%d/%d d:d:d</pre><pre>Module %d</pre><pre>Image Base: 0xx Image Size: 0xx</pre><pre>Checksum: 0xx Time Stamp: 0xx</pre><pre>File Size: %-10d File Time: %s</pre><pre>Company: %s</pre><pre>Product: %s</pre><pre>FileDesc: %s</pre><pre>FileVer: %d.%d.%d.%d</pre><pre>ProdVer: %d.%d.%d.%d</pre><pre>Windows Vista</pre><pre>Windows 7</pre><pre>Windows Server 2008</pre><pre>Windows 8</pre><pre>Windows Server 2008 R2</pre><pre>Windows 9</pre><pre>Web Edition</pre><pre>Windows Server 2012</pre><pre>Windows XP</pre><pre>Windows Server 9</pre><pre>Windows 2000</pre><pre>(build %d)</pre><pre>This sample does not support this version of Windows.</pre><pre>Error occurred at %s.</pre><pre>Operating system: %s</pre><pre>Operating system: Could not Determine</pre><pre>%d processor(s), type %d.</pre><pre>%d%% memory in use.</pre><pre>%d MBytes paging file.</pre><pre>%d MBytes physical memory free.</pre><pre>%d MBytes user address space free.</pre><pre>%d MBytes paging file free.</pre><pre>%d MBytes user address space.</pre><pre>Web Server Edition</pre><pre>Windows Server 2003 R2</pre><pre>Windows Storage Server 2003</pre><pre>Windows Home Server</pre><pre>a Float Denormal Operand</pre><pre>Windows XP Professional x64 Edition</pre><pre>Windows Server 2003</pre><pre>a Float Invalid Operation</pre><pre>0xx:</pre><pre>%s\CRASH_REPORT_%s.txt</pre><pre>%d MBytes physical memory.</pre><pre>EDI: 0xx ESI: 0xx EAX: 0xx</pre><pre>EBX: 0xx ECX: 0xx EDX: 0xx</pre><pre>EIP: 0xx EBP: 0xx SegCs: 0xx</pre><pre>EFlags: 0xx ESP: 0xx SegSs: 0xx</pre><pre>%s caused %s (0xx)</pre><pre>in module %s at x:x.</pre><pre>%s location x caused an access violation.</pre><pre>===== [end of %s] =====</pre><pre>%s\CRASH_DUMP_%s.dmp</pre><pre>Error creating dump file, err=%d</pre><pre>Exception code is 0xX</pre><pre>Crash dump file: %s</pre><pre>Crash report file :%s</pre><pre>P%d_T%d_Dld_ld_ld_Tld_ld_ld</pre><pre>code: %x, addr: %x, module: %s</pre><pre>code: %x</pre><pre>{{{$629}}}</pre><pre>{{{$631}}}</pre><pre>{{{$630}}}</pre><pre>{{{$632}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\3rdParty\google\gtest\gtest-1.6.0\include\gtest/internal/gtest-port.h</pre><pre>%s 0x%I64x %s [file:%s(%u)]</pre><pre>{{{$101}}}</pre><pre>{{{$102}}}</pre><pre>{{{$108}}}</pre><pre>{{{$109}}}</pre><pre>{{{$106}}}</pre><pre>{{{$107}}}</pre><pre>{{{$104}}}</pre><pre>{{{$105}}}</pre><pre>{{{$103}}}</pre><pre>{{{$112}}}</pre><pre>{{{$113}}}</pre><pre>{{{$110}}}</pre><pre>{{{$111}}}</pre><pre>{{{$100}}}</pre><pre>{{{$118}}}</pre><pre>{{{$117}}}</pre><pre>{{{$116}}}</pre><pre>{{{$115}}}</pre><pre>{{{$114}}}</pre><pre>{{{$121}}}</pre><pre>{{{$120}}}</pre><pre>{{{$119}}}</pre><pre>{{{$123}}}</pre><pre>{{{$122}}}</pre><pre>{{{$525}}}</pre><pre>{{{$524}}}</pre><pre>{{{$526}}}</pre><pre>{{{$532}}}</pre><pre>{{{$531}}}</pre><pre>{{{$530}}}</pre><pre>{{{$529}}}</pre><pre>{{{$528}}}</pre><pre>{{{$527}}}</pre><pre>{{{$536}}}</pre><pre>{{{$534}}}</pre><pre>{{{$533}}}</pre><pre>{{{$538}}}</pre><pre>{{{$537}}}</pre><pre>{{{$483}}}</pre><pre>{{{$487}}}</pre><pre>{{{$486}}}</pre><pre>{{{$485}}}</pre><pre>{{{$484}}}</pre><pre>{{{$489}}}</pre><pre>{{{$488}}}</pre><pre>{{{$495}}}</pre><pre>{{{$494}}}</pre><pre>{{{$499}}}</pre><pre>{{{$498}}}</pre><pre>{{{$497}}}</pre><pre>{{{$496}}}</pre><pre>{{{$504}}}</pre><pre>{{{$503}}}</pre><pre>{{{$502}}}</pre><pre>{{{$501}}}</pre><pre>{{{$500}}}</pre><pre>{{{$560}}}</pre><pre>{{{$564}}}</pre><pre>{{{$563}}}</pre><pre>{{{$562}}}</pre><pre>{{{$561}}}</pre><pre>{{{$568}}}</pre><pre>{{{$567}}}</pre><pre>{{{$566}}}</pre><pre>{{{$565}}}</pre><pre>{{{$572}}}</pre><pre>{{{$571}}}</pre><pre>{{{$570}}}</pre><pre>{{{$569}}}</pre><pre>{{{$577}}}</pre><pre>{{{$576}}}</pre><pre>{{{$575}}}</pre><pre>{{{$574}}}</pre><pre>{{{$573}}}</pre><pre>{{{$580}}}</pre><pre>{{{$579}}}</pre><pre>{{{$578}}}</pre><pre>{{{$582}}}</pre><pre>{{{$581}}}</pre><pre>{{{$586}}}</pre><pre>{{{$584}}}</pre><pre>{{{$583}}}</pre><pre>{{{$590}}}</pre><pre>{{{$589}}}</pre><pre>{{{$587}}}</pre><pre>{{{$592}}}</pre><pre>{{{$591}}}</pre><pre>{{{$595}}}</pre><pre>{{{$594}}}</pre><pre>{{{$593}}}</pre><pre>{{{$598}}}</pre><pre>{{{$597}}}</pre><pre>{{{$596}}}</pre><pre>{{{$600}}}</pre><pre>{{{$599}}}</pre><pre>{{{$603}}}</pre><pre>{{{$602}}}</pre><pre>{{{$601}}}</pre><pre>{{{$606}}}</pre><pre>{{{$605}}}</pre><pre>{{{$604}}}</pre><pre>{{{$238}}}</pre><pre>{{{$237}}}</pre><pre>\/\/\9\(\</pre><pre>c%W%J%H%l%K%V%Q%D%I%I%</pre><pre>D%D/D!D D2D!D6D</pre><pre>DÐD%D</pre><pre>1d'd)d;d7d!dÖd'd,d;d0d!d6d)d</pre><pre>{{{$507}}}</pre><pre>{{{$506}}}</pre><pre>{{{$505}}}</pre><pre>{{{$509}}}</pre><pre>{{{$508}}}</pre><pre>{{{$510}}}</pre><pre>{{{$513}}}</pre><pre>{{{$512}}}</pre><pre>{{{$511}}}</pre><pre>{{{$515}}}</pre><pre>{{{$514}}}</pre><pre>{{{$519}}}</pre><pre>{{{$518}}}</pre><pre>{{{$517}}}</pre><pre>{{{$516}}}</pre><pre>{{{$521}}}</pre><pre>{{{$520}}}</pre><pre>{{{$522}}}</pre><pre>{{{$523}}}</pre><pre>4|7|?|?|</pre><pre>{{{$614}}}</pre><pre>{{{$613}}}</pre><pre>{{{$612}}}</pre><pre>{{{$611}}}</pre><pre>{{{$610}}}</pre><pre>{{{$609}}}</pre><pre>_3_0_=_>_3_</pre><pre>_(_6_1_;_0_(_,_</pre><pre>_8_3_0_=_>_3_</pre><pre>_<_0_*_1_ _:_-_,_</pre><pre>S6S!S>S S.SuS</pre><pre>cCc%c</pre><pre>{{{$404}}}</pre><pre>{{{$403}}}</pre><pre>{{{$402}}}</pre><pre>{{{$405}}}</pre><pre>Z.Z#Z*Z?ZgZ}Z.Z?Z"Z.ZuZ2Z.Z7Z6Z}Z</pre><pre>{{{$406}}}</pre><pre>[([>[:[)[8[3[</pre><pre>[>[)[6[&[</pre><pre>{{{$408}}}</pre><pre>{{{$410}}}</pre><pre>{{{$409}}}</pre><pre>F5F#F'F4F%F.F6F*F3F!F/F(F5F</pre><pre>B0B.BbB6B;B2B'B</pre><pre>CREATE TABLE ItemTable (key TEXT UNIQUE ON CONFLICT REPLACE, value TEXT NOT NULL ON CONFLICT FAIL);</pre><pre>insert into ItemTable (key, value) VALUES ('%s', '%s');</pre><pre>PUADQ@%%h`qdv%V@Q%vu`flclfv8:4)%v`ws`wZvu`flclfv8:7%RM@W@%kjkZpkltp`Zkdh`%iln`%"mjh`udb`ZlvZk`rqdgudb`"%DKA%v`ws`wZkjkZpkltp`Zkdh`%%iln`%"mjh`udb`ZlvZk`rqdgudb`"</pre><pre>{{{$313}}}</pre><pre>{{{$312}}}</pre><pre>{{{$314}}}</pre><pre>{{{$334}}}</pre><pre>a!-dc}xyRhcnbidcj~!-~xjjh~yRx</pre><pre>U&U!U4U'U!U U%U</pre><pre>{{{$359}}}</pre><pre>{{{$358}}}</pre><pre>{{{$357}}}</pre><pre>{{{$360}}}</pre><pre>00:00:00.</pre><pre>NtQueryKey</pre><pre>{{{$618}}}</pre><pre>{{{$617}}}</pre><pre>{{{$616}}}</pre><pre>{{{$615}}}</pre><pre>{{{$624}}}</pre><pre>{{{$623}}}</pre><pre>{{{$692}}}</pre><pre>{{{$691}}}</pre><pre>{{{$690}}}</pre><pre>{{{$693}}}</pre><pre>1.1.3</pre><pre>gen_codes: max_code %d</pre><pre>code %d bits %d->%d</pre><pre>bl code -</pre><pre>opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %u</pre><pre>last_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)</pre><pre>wininet.dll</pre><pre>ftp://</pre><pre>https://</pre><pre>http://</pre><pre>[%u, 0xx] %s</pre><pre>https</pre><pre>HTTP/1.0</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>request HttpSendRequestA failed...</pre><pre>Content-Length: %u</pre><pre>response failed...last error %d</pre><pre>{{{$718}}}</pre><pre>{{{$717}}}</pre><pre>{{{$719}}}</pre><pre>{{{$720}}}</pre><pre>{{{$722}}}</pre><pre>{{{$721}}}</pre><pre>{{{$724}}}</pre><pre>{{{$723}}}</pre><pre>{{{$725}}}</pre><pre>{{{$729}}}</pre><pre>{{{$728}}}</pre><pre>{{{$727}}}</pre><pre>{{{$726}}}</pre><pre>{{{$730}}}</pre><pre>{{{$733}}}</pre><pre>{{{$732}}}</pre><pre>{{{$731}}}</pre><pre>{{{$735}}}</pre><pre>{{{$734}}}</pre><pre>{{{$744}}}</pre><pre>{{{$743}}}</pre><pre>{{{$742}}}</pre><pre>{{{$747}}}</pre><pre>{{{$746}}}</pre><pre>{{{$667}}}</pre><pre>{{{$669}}}</pre><pre>{{{$668}}}</pre><pre>SQLite format 3</pre><pre>REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY</pre><pre>CREATE TABLE sqlite_master(</pre><pre>sql text</pre><pre>0123456789ABCDEF3.7.16</pre><pre>CREATE TEMP TABLE sqlite_temp_master(</pre><pre>{{{$138}}}</pre><pre>{{{$141}}}</pre><pre>{{{$140}}}</pre><pre>{{{$139}}}</pre><pre>{{{$146}}}</pre><pre>{{{$145}}}</pre><pre>{{{$144}}}</pre><pre>{{{$143}}}</pre><pre>{{{$142}}}</pre><pre>{{{$129}}}</pre><pre>{{{$128}}}</pre><pre>{{{$127}}}</pre><pre>{{{$126}}}</pre><pre>{{{$125}}}</pre><pre>{{{$124}}}</pre><pre>{{{$134}}}</pre><pre>{{{$133}}}</pre><pre>{{{$132}}}</pre><pre>{{{$131}}}</pre><pre>{{{$130}}}</pre><pre>{{{$135}}}</pre><pre>{{{$1283}}}</pre><pre>(]3]4]3].])]<]1]1]</pre><pre>])]8]%])]</pre><pre>S6S!S%S6S!S</pre><pre>{{{$1285}}}</pre><pre>{{{$1284}}}</pre><pre>{{{$1292}}}</pre><pre>{{{$1291}}}</pre><pre>`%K%D%G%I%@%A%</pre><pre>F%F)F(F</pre><pre>D!D"DÑD(D0D</pre><pre>D!DÖD'D,D</pre><pre>U,U%U0U</pre><pre>x%xXx</pre><pre>x%xZxTxXxZx</pre><pre>uUu%u</pre><pre>uKu.u4u!u!u4u6u>u0u'u*u1u0u!u4u<u9u&u*u%u9u4u6u0u*u=u:u9u1u0u'u(uWuYuWu</pre><pre>uWuOuUuWu%u</pre><pre>D*D7D0D%D(D(D</pre><pre>DÐD!D</pre><pre>D!D0D0D-D*D#DdD7D!D6D2D-D'D!DdD"D%D-D(D!D DjDdD</pre><pre>{{{$705}}}</pre><pre>{{{$704}}}</pre><pre>{{{$703}}}</pre><pre>Content-Disposition: form-data; name="%s"</pre><pre>Content-Disposition: form-data; name="%s"; filename="%s"</pre><pre>SQLITE_</pre><pre>d-d-d</pre><pre>d:d:d</pre><pre>d-d-d d:d:d</pre><pre>failed memory resize %u to %u bytes</pre><pre>failed to allocate %u bytes of memory</pre><pre>API call with %s database connection pointer</pre><pre>922337203685477580</pre><pre>RowKey</pre><pre>OsError 0x%x (%u)</pre><pre>GetProcessHeap</pre><pre>delayed %dms for lock/sharing conflict</pre><pre>os_win.c:%d: (%d) %s(%s) - %s</pre><pre>%s-shm</pre><pre>%s\etilqs_</pre><pre>%s\%s</pre><pre>Recovered %d frames from WAL file %s</pre><pre>cannot limit WAL size: %s</pre><pre>Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)</pre><pre>Failed to read ptrmap key=%d</pre><pre>2nd reference to page %d</pre><pre>invalid page number %d</pre><pre>Page %d:</pre><pre>freelist leaf count too big on page %d</pre><pre>failed to get page %d</pre><pre>%d of %d pages missing from overflow list starting at %d</pre><pre>On tree page %d cell %d:</pre><pre>btreeInitPage() returns error code %d</pre><pre>unable to get the page. error code=%d</pre><pre>On page %d at right child:</pre><pre>Multiple uses for byte %d of page %d</pre><pre>Corruption detected in cell %d on page %d</pre><pre>Page %d is never used</pre><pre>Fragmentation of %d bytes reported as %d on page %d</pre><pre>unknown database %s</pre><pre>Outstanding page count goes from %d to %d during this analysis</pre><pre>Pointer map page %d is referenced</pre><pre>keyinfo(%d</pre><pre>%s(%d)</pre><pre>MJ delete: %s</pre><pre>%s-mjXXXXXX9XXz</pre><pre>foreign key constraint failed</pre><pre>-mjX9X</pre><pre>MJ collide: %s</pre><pre>bind on a busy prepared statement: [%s]</pre><pre>unable to use function %s in the requested context</pre><pre>zeroblob(%d)</pre><pre>constraint failed at %d in [%s]</pre><pre>abort at %d in [%s]: %s</pre><pre>cannot commit transaction - SQL statements in progress</pre><pre>cannot release savepoint - SQL statements in progress</pre><pre>no such savepoint: %s</pre><pre>cannot open savepoint - SQL statements in progress</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid</pre><pre>sqlite_master</pre><pre>sqlite_temp_master</pre><pre>database table is locked: %s</pre><pre>cannot change %s wal mode from within a transaction</pre><pre>statement aborts at %d: [%s] %s</pre><pre>cannot open view: %s</pre><pre>cannot open virtual table: %s</pre><pre>cannot open value of type %s</pre><pre>cannot open %s column for writing</pre><pre>indexed</pre><pre>foreign key</pre><pre>no such column: "%s"</pre><pre>misuse of aliased aggregate %s</pre><pre>%s: %s</pre><pre>%s: %s.%s</pre><pre>%s: %s.%s.%s</pre><pre>not authorized to use function: %s</pre><pre>%r %s BY term out of range - should be between 1 and %d</pre><pre>too many terms in %s BY clause</pre><pre>variable number must be between ?1 and ?%d</pre><pre>Expression tree is too large (maximum depth %d)</pre><pre>too many columns in %s</pre><pre>too many SQL variables</pre><pre>misuse of aggregate: %s()</pre><pre>EXECUTE %s%s SUBQUERY %d</pre><pre>sqlite_rename_trigger</pre><pre>sqlite_rename_table</pre><pre>%s%.*s"%w"</pre><pre>%.*s"%w"%s</pre><pre>type='trigger' AND (%s)</pre><pre>%s OR name=%Q</pre><pre>sqlite_rename_parent</pre><pre>there is already another table or index with this name: %s</pre><pre>table %s may not be altered</pre><pre>sqlite_</pre><pre>sqlite_sequence</pre><pre>UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');</pre><pre>UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;</pre><pre>view %s may not be altered</pre><pre>Cannot add a PRIMARY KEY column</pre><pre>UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;</pre><pre>UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q</pre><pre>UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q</pre><pre>sqlite_stat1</pre><pre>sqlite_altertab_%s</pre><pre>DELETE FROM %Q.%s WHERE %s=%Q</pre><pre>CREATE TABLE %Q.%s(%s)</pre><pre>too many attached databases - max %d</pre><pre>invalid name: "%s"</pre><pre>SELECT tbl,idx,stat FROM %Q.sqlite_stat1</pre><pre>unable to open database: %s</pre><pre>database %s is already in use</pre><pre>database %s is locked</pre><pre>cannot detach database %s</pre><pre>no such database: %s</pre><pre>%s %T cannot reference objects in database %s</pre><pre>sqlite_attach</pre><pre>sqlite_detach</pre><pre>access to %s.%s is prohibited</pre><pre>access to %s.%s.%s is prohibited</pre><pre>object name reserved for internal use: %s</pre><pre>too many columns on %s</pre><pre>there is already an index named %s</pre><pre>table "%s" has more than one primary key</pre><pre>default value of column [%s] is not constant</pre><pre>duplicate column name: %s</pre><pre>AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY</pre><pre>CREATE %s %.*s</pre><pre>CREATE TABLE %Q.sqlite_sequence(name,seq)</pre><pre>UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d</pre><pre>DELETE FROM %Q.sqlite_sequence WHERE name=%Q</pre><pre>sqlite_stat%d</pre><pre>UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d</pre><pre>view %s is circularly defined</pre><pre>use DROP TABLE to delete table %s</pre><pre>table %s may not be dropped</pre><pre>sqlite_stat</pre><pre>DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'</pre><pre>unknown column "%s" in foreign key definition</pre><pre>number of columns in foreign key does not match the number of columns in the referenced table</pre><pre>foreign key on %s should reference only one column of table %T</pre><pre>use DROP VIEW to delete view %s</pre><pre>table %s may not be indexed</pre><pre>indexed columns are not unique</pre><pre>index %s already exists</pre><pre>there is already a table named %s</pre><pre>virtual tables may not be indexed</pre><pre>views may not be indexed</pre><pre>table %s has no column named %s</pre><pre>sqlite_autoindex_%s_%d</pre><pre>INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);</pre><pre>CREATE%s INDEX %.*s</pre><pre>DELETE FROM %Q.%s WHERE name=%Q AND type='index'</pre><pre>index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped</pre><pre>no such index: %S</pre><pre>a JOIN clause is required before %s</pre><pre>unable to identify the object to be reindexed</pre><pre>cannot modify %s because it is a view</pre><pre>table %s may not be modified</pre><pre>no such collation sequence: %s</pre><pre>sqlite_version</pre><pre>sqlite_compileoption_get</pre><pre>sqlite_compileoption_used</pre><pre>sqlite_log</pre><pre>sqlite_source_id</pre><pre>%d values for %d columns</pre><pre>table %S has %d columns but %d values were supplied</pre><pre>foreign key mismatch - "%w" referencing "%w"</pre><pre>constraint %s failed</pre><pre>%s.%s may not be NULL</pre><pre>table %S has no column named %s</pre><pre>PRIMARY KEY must be unique</pre><pre>unable to open shared library [%s]</pre><pre>sqlite3_extension_init</pre><pre>automatic extension loading failed: %s</pre><pre>error during initialization: %s</pre><pre>no entry point [%s] in shared library [%s]</pre><pre>foreign_keys</pre><pre>foreign_key_list</pre><pre>foreign_key_check</pre><pre>*** in database %s ***</pre><pre>unsupported encoding: %s</pre><pre>unsupported file format</pre><pre>%s - %s</pre><pre>malformed database schema (%s)</pre><pre>database schema is locked: %s</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid</pre><pre>RIGHT and FULL OUTER JOINs are not currently supported</pre><pre>unknown or unsupported join type: %T %T%s%T</pre><pre>cannot join using column %s - column not present in both tables</pre><pre>cannot have both ON and USING clauses in the same join</pre><pre>a NATURAL join may not have an ON or USING clause</pre><pre>%s.%s</pre><pre>COMPOUND SUBQUERIES %d AND %d %s(%s)</pre><pre>USE TEMP B-TREE FOR %s</pre><pre>LIMIT clause should come after %s not before</pre><pre>ORDER BY clause should come after %s not before</pre><pre>%s:%d</pre><pre>too many references to "%s": max 65535</pre><pre>sqlite_subquery_%p_</pre><pre>no such index: %s</pre><pre>SELECTs to the left and right of %s do not have the same number of result columns</pre><pre>no such table: %s</pre><pre>%s.%s.%s</pre><pre>SCAN TABLE %s %s%s(~%d rows)</pre><pre>sqlite3_get_table() called with two or more incompatible queries</pre><pre>cannot create %s trigger on view: %S</pre><pre>no such trigger: %S</pre><pre>INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')</pre><pre>cannot create INSTEAD OF trigger on table: %S</pre><pre>no such column: %s</pre><pre>-- TRIGGER %s</pre><pre>cannot VACUUM - SQL statements in progress</pre><pre>SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'</pre><pre>SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>PRAGMA vacuum_db.synchronous=OFF</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';</pre><pre>SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'</pre><pre>UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d</pre><pre>INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)</pre><pre>vtable constructor did not declare schema: %s</pre><pre>vtable constructor failed: %s</pre><pre>table %s: xBestIndex returned an invalid plan</pre><pre>no such module: %s</pre><pre>%s TABLE %s</pre><pre>%s SUBQUERY %d</pre><pre>%s USING %s%sINDEX%s%s%s</pre><pre>%s AS %s</pre><pre>%s (rowid>?)</pre><pre>%s (rowid>? AND rowid<?)</pre><pre>%s (rowid=?)</pre><pre>%s USING INTEGER PRIMARY KEY</pre><pre>at most %d tables in a join</pre><pre>%s (~%lld rows)</pre><pre>%s VIRTUAL TABLE INDEX %d:%s</pre><pre>%s (rowid<?)</pre><pre>cannot use index: %s</pre><pre>the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>SQL logic error or missing database</pre><pre>unknown operation</pre><pre>large file support is disabled</pre><pre>unknown database: %s</pre><pre>no such vfs: %s</pre><pre>%s mode not allowed: %s</pre><pre>no such %s mode: %s</pre><pre>cannot open file at line %d of [%.10s]</pre><pre>misuse at line %d of [%.10s]</pre><pre>database corruption at line %d of [%.10s]</pre><pre>{{{$137}}}</pre><pre>C:\Builds\113\Search Protector\SP-2.16.10-Production\Sources\SearchProtector\Dev\2.16.10\Output\Release_32\cltmngui.pdb</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>RegCreateKeyExW</pre><pre>RegQueryInfoKeyW</pre><pre>RegDeleteKeyW</pre><pre>RegOpenKeyExW</pre><pre>RegEnumKeyExW</pre><pre>RegCloseKey</pre><pre>ADVAPI32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>PSAPI.DLL</pre><pre>VERSION.dll</pre><pre>dbghelp.dll</pre><pre>GetCPInfo</pre><pre>GDI32.dll</pre><pre>SHELL32.dll</pre><pre>HttpOpenRequestA</pre><pre>HttpAddRequestHeadersA</pre><pre>HttpSendRequestW</pre><pre>HttpSendRequestA</pre><pre>HttpSendRequestExW</pre><pre>HttpEndRequestW</pre><pre>HttpQueryInfoA</pre><pre>WININET.dll</pre><pre>RegisterHotKey</pre><pre>ReportEventA</pre><pre>I_RpcBindingInqTransportType</pre><pre>RPCRT4.dll</pre><pre>zcÁ</pre><pre>%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI</pre><pre>;74/, (%#</pre><pre>~{xrpfa\ZSM@;3-%U</pre><pre><requestedExecutionLevel level='asInvoker' uiAccess='false' /></pre><pre>; ;$;(;,;0;4;8;<;</pre><pre>7 7$7(7,707</pre><pre>;_;#<\=|=</pre><pre>8 8$8(8,8{8</pre><pre>0$0(0,00040{0</pre><pre>< <$<(<,<0<4<8<</pre><pre>6 6$6(6,606</pre><pre>0,0004080<0</pre><pre>5$5-565d5k5t5}5</pre><pre>9‘9F9U9h9r9</pre><pre>8 8$8(8,8084888<8@8[8</pre><pre>00j0</pre><pre>00C0R0a0p0</pre><pre>3%4X4h4</pre><pre>5 6$6(6,606</pre><pre>7q7D7S7e7s7<8I8</pre><pre>5#565@5{5</pre><pre>"010?0'1</pre><pre>:,:0:4:8:</pre><pre>; <$<(<,<</pre><pre>: ;6;>;*<3>_></pre><pre>8 <0<6<=<</pre><pre>9Â9</pre><pre>> >$>(>,>0>4>8><></pre><pre>:(;,;\;`;</pre><pre>3 3$3(3,30343</pre><pre>; ;$;(;,;0;4;8;</pre><pre>3 3$3(3,3@3</pre><pre>8 8<8@8`8</pre><pre>Zmscoree.dll</pre><pre>Zkernel32.dll</pre><pre>combase.dll</pre><pre>- floating point support not loaded</pre><pre>- CRT not initialized</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>portuguese-brazilian</pre><pre>8.0.0.0-11.999.999.999</pre><pre>33.0.0.0-36.999.999.999</pre><pre>16.0.0.0-31.999.999.999</pre><pre>{{{$625}}}</pre><pre>Advapi32.dll</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>}{{{$663}}}</pre><pre>{{{$664}}}</pre><pre>{{{$665}}}</pre><pre>{{{$666}}}</pre><pre>{{{$663}}}</pre><pre>UserRepository.dat</pre><pre>SystemRepository.dat</pre><pre>UIRepository.dat</pre><pre>%x %x[%s] %I64x %x %x</pre><pre>Yuser32.dll</pre><pre>ieframe.dll</pre><pre>Windows Server 2008</pre><pre>Windows Vista</pre><pre>Windows Server 2008 R2</pre><pre>Windows 7</pre><pre>Windows Server 2012</pre><pre>Windows 8</pre><pre>Windows 8.1</pre><pre>HKEY_PERFORMANCE_TEXT</pre><pre>HKEY_PERFORMANCE_NLSTEXT</pre><pre>HKEY_CURRENT_USER_LOCAL_SETTINGS</pre><pre>{{{$697}}}</pre><pre>{{{$698}}}</pre><pre>{{{$535}}}</pre><pre>{{{$367}}}</pre><pre>{{{$366}}}</pre><pre>2.16.10.61</pre><pre>{{{$607}}}</pre><pre>{{{$381}}}</pre><pre>{{{$380}}}</pre><pre>_0.localstorage</pre><pre>chrome-extension_</pre><pre>{{{$254}}}</pre><pre>{{{$255}}}</pre><pre>{{{$251}}}</pre><pre>{{{$252}}}</pre><pre>36.0.0.0</pre><pre>32.0.0.0</pre><pre>{{{$290}}}</pre><pre>{{{$291}}}</pre><pre>{{{$293}}}</pre><pre>{{{$294}}}</pre><pre>{{{$296}}}</pre><pre>{{{$297}}}</pre><pre>Failed to set Url</pre><pre>{{{$305}}}</pre><pre>{{{$306}}}</pre><pre>{{{$307}}}</pre><pre>{{{$303}}}</pre><pre>{{{$304}}}</pre><pre>{{{$309}}}</pre><pre>{{{$310}}}</pre><pre>{{{$316}}}</pre><pre>{{{$317}}}</pre><pre>{{{$321}}}</pre><pre>{{{$322}}}</pre><pre>{{{$325}}}</pre><pre>{{{$333}}}</pre><pre>{{{$329}}}</pre><pre>{{{$330}}}</pre><pre>{{{$332}}}</pre><pre>{{{$345}}}</pre><pre>{{{$344}}}</pre><pre>{{{$350}}}</pre><pre>{{{$351}}}</pre><pre>{{{$354}}}</pre><pre>{{{$355}}}</pre><pre>{{{$378}}}</pre><pre>{{{$369}}}</pre><pre>{{{$368}}}</pre><pre>{{{$370}}}</pre><pre>{{{$549}}}</pre><pre>{{{$548}}}</pre><pre>{{{$707}}}</pre><pre>SELECT * FROM __InstanceDeletionEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>SELECT * FROM __InstanceCreationEvent WITHIN %1% WHERE TargetInstance ISA 'Win32_Process' And TargetInstance.Name = '%2%'</pre><pre>ntdll.dll</pre><pre>%s%s%s</pre><pre>Correct password required</pre><pre>{{{SP#Conduit::SearchProtector::Utils::WMIAgentJob::Join#SP}}}</pre><pre>{{{$715}}}</pre><pre>888816666554443</pre><pre>6666554443</pre><pre>!6666554443</pre><pre>{{{$1282}}}</pre><pre>01234567</pre><pre>UserSettings.dat</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::ServiceManager::HttpAsyncCallBack#SP}}}</pre><pre>{{{$77}}}</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::TimerBasedServiceHandler::HttpAsyncCallBack#SP}}}</pre><pre>{{{SP#Conduit::SearchProtector::Application::Services::ServiceHandler::HttpAsyncCallBack#SP}}}</pre><pre>RpcTransportException</pre><pre>C:\PROGRA~1\SearchProtect\UI\bin\cltmngui.exe</pre><b>rundll32.exe_3116:</b><pre>.text</pre><pre>`.data</pre><pre>.rsrc</pre><pre>msvcrt.dll</pre><pre>KERNEL32.dll</pre><pre>NTDLL.DLL</pre><pre>GDI32.dll</pre><pre>USER32.dll</pre><pre>IMAGEHLP.dll</pre><pre>rundll32.pdb</pre><pre>.....eZXnnnnnnnnnnnn3</pre><pre>....eDXnnnnnnnnnnnn3</pre><pre>...eDXnnnnnnnnnnnn,</pre><pre>.eDXnnnnnnnnnnnn,</pre><pre>%Xnnnnnnnnnnnnnnn1</pre><pre>O3$dS7"%U9</pre><pre>.manifest</pre><pre>5.1.2600.5512 (xpsp.080413-2105)</pre><pre>RUNDLL.EXE</pre><pre>Windows</pre><pre>Operating System</pre><pre>5.1.2600.5512</pre><pre>YThere is not enough memory to run the file %s.</pre><pre>Please close other windows and try again.</pre><pre>9The file %s or one of its components could not be opened.</pre><pre>0The file %s or one of its components cannot run.</pre><pre>MThe file %s or one of its components requires a different version of Windows.</pre><pre>UThe file %s or one of its components cannot run in standard or enhanced mode Windows.3Another instance of the file %s is already running./An exception occurred while trying to run "%s"</pre><pre>Error in %s</pre><pre>Missing entry:%s</pre><pre>Error loading %s</pre><b>UpdateSoftware.exe_3512:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>9>t.hT</pre><pre>QSShD</pre><pre>j%Xf;</pre><pre>QSSSSSSh</pre><pre>FTPh@z</pre><pre>j.Yf;</pre><pre>_tcPVj@</pre><pre>.PjRW</pre><pre>function not supported</pre><pre>operation canceled</pre><pre>address_family_not_supported</pre><pre>operation_in_progress</pre><pre>operation_not_supported</pre><pre>protocol_not_supported</pre><pre>operation_would_block</pre><pre>address family not supported</pre><pre>broken pipe</pre><pre>inappropriate io control operation</pre><pre>not supported</pre><pre>operation in progress</pre><pre>operation not permitted</pre><pre>operation not supported</pre><pre>operation would block</pre><pre>protocol not supported</pre><pre>GetProcessWindowStation</pre><pre>operator</pre><pre>load x</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>F%D,3</pre><pre>GetProcessHeap</pre><pre>KERNEL32.dll</pre><pre>MsgWaitForMultipleObjects</pre><pre>EnumWindows</pre><pre>USER32.dll</pre><pre>RegCreateKeyExW</pre><pre>RegQueryInfoKeyW</pre><pre>RegDeleteKeyW</pre><pre>RegOpenKeyExW</pre><pre>RegEnumKeyExW</pre><pre>RegCloseKey</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>GetCPInfo</pre><pre>zcÁ</pre><pre>[]@%~!#$^&*()_-?|{}=:</pre><pre>/vABmeRfAuIUlkvobQhxXiDGwS02xn6H0U6DZCDHvIATNlPbpqpPOz1QGiLGMhTuXinBPsG7pT5nQKg97KEjbWMXt6UeZQ3NNhWSkbs0PFUOXeu7qBezPy6gssSHDhGJ</pre><pre>Zi2nQbACamsG9bYrezMYBG3eON3SpKpgzmFFwAsx8WzYYuXO8ZwU2xMK0BCbIKOiUywLca74 gTLzQrOE9P3oQjJEb C7MeedGvEN057jMkcN43fYSsHUuXHHGHuDW1l</pre><pre>sNv1rYp5b/fBarCcNVs6LI8Cre5Wy9rfgs65w5W4Ps ImrpT7AvUE7W3IG5n2sF8zuDpVgyctb0YqIS cJL9fK3PBojg0jf2T2boMheAoSIYOafBkNiGxzjAZk7Z6Wzf</pre><pre>20120606</pre><pre>.qsfU</pre><pre>.rt(i</pre><pre>.oQ<t</pre><pre>!YUDp</pre><pre>.Qgdi</pre><pre>.rvNS</pre><pre>.bMc5</pre><pre>%cM`M</pre><pre>%fQ#~</pre><pre>.dzNH</pre><pre>%cjGH</pre><pre>.qSN{</pre><pre>.Zqa|</pre><pre>.ggHI</pre><pre>.QiGf</pre><pre>.qQA:</pre><pre>.HSip</pre><pre>.ar\t</pre><pre>/kUrL</pre><pre>ECmD|</pre><pre>.re0:</pre><pre>.QxF[</pre><pre>.hjgJ</pre><pre>.qi(></pre><pre>.ozm9</pre><pre>.Zmm_</pre><pre>%ct/x</pre><pre>.Zz(I</pre><pre>.Zg#n</pre><pre>.qZ,M</pre><pre>.nwF5</pre><pre>.IRIl</pre><pre>.Np\L</pre><pre>.rj.}</pre><pre>.QQLr</pre><pre>.rl_R</pre><pre>.re.6</pre><pre>.pp)=</pre><pre>.hu@W</pre><pre>.pWD;</pre><pre>*zkEY</pre><pre>.jjd}</pre><pre>Ý96</pre><pre>.ZMNm</pre><pre>%dx1x</pre><pre>$ftpI</pre><pre>.rn/7</pre><pre>.QrrX</pre><pre>.aoHL</pre><pre>.hRo{</pre><pre>%C|0v</pre><pre>.im9N</pre><pre>.KTC]</pre><pre>.NhQn</pre><pre>%CwEF</pre><pre>.aMmU</pre><pre>.rvcl</pre><pre>.lg-R</pre><pre>.Yd#H</pre><pre>.pzrP</pre><pre>.kWO]</pre><pre>.fn^<</pre><pre>.Po/j</pre><pre>%cxnr</pre><pre>.OqL]</pre><pre>.rvGy</pre><pre>.Ho\></pre><pre>.np^></pre><pre>.qhRm</pre><pre>.rnoO</pre><pre>.Gt.m</pre><pre>.Phip</pre><pre>.ehML</pre><pre>.LXeG</pre><pre>.cQ0u</pre><pre>.ylaU</pre><pre>.Yq,Y</pre><pre>.rv>Q</pre><pre>.zx[o</pre><pre>.qsHI</pre><pre>.JZf<</pre><pre>.Qxmr</pre><pre>.qlkv</pre><pre>.Psf9</pre><pre>.rqO4</pre><pre>.dg9></pre><pre>.Cyp5</pre><pre>.qi;7</pre><pre>.jl?H</pre><pre>%fRg7</pre><pre>.ayA\</pre><pre>.rvFp</pre><pre>.LtpP</pre><pre>%dpDs</pre><pre>.kw>M</pre><pre>.bh'R</pre><pre>.GpRH</pre><pre>%dri5</pre><pre>.IgDm</pre><pre>.pvfs</pre><pre>.gp_J</pre><pre>.MW-;</pre><pre>.jgp\</pre><pre>.Gnb9</pre><pre>.KoZ[</pre><pre>.zM)n</pre><pre>.rtZN</pre><pre>.Ke`i</pre><pre>.rvGU</pre><pre>.dMmv</pre><pre>.mR1Y</pre><pre>.rh#v</pre><pre>.iV9L</pre><pre>.rrF[</pre><pre>.Qf?M</pre><pre>.nRlf</pre><pre>.jr1;</pre><pre>.MZ-x</pre><pre>.rvEQ</pre><pre>.rmA\</pre><pre>-eqJ}</pre><pre>.MX/=</pre><pre>.iVBs</pre><pre>.rtaI</pre><pre>.lW^<</pre><pre>.iTAP</pre><pre>.nx*9</pre><pre>.pT>h</pre><pre>.jR]y</pre><pre>.Ckov</pre><pre>.YW@9</pre><pre>.Qk==</pre><pre>.zw@<</pre><pre>.gx>F</pre><pre>%fm]k</pre><pre>.kvfJ</pre><pre>.Iw'S</pre><pre>.bsn[</pre><pre>.eq;M</pre><pre>.rh;f</pre><pre>.fmbZ</pre><pre>%fw<Q</pre><pre>.Pqnu</pre><pre>.OZe8</pre><pre>.rvGX</pre><pre>.fTY7</pre><pre>.geEK</pre><pre>%fZit</pre><pre>.PZEJ</pre><pre>.pt-J</pre><pre>.lUgn</pre><pre>%fgLp</pre><pre>.ZyIw</pre><pre>.rR][</pre><pre>.Pieq</pre><pre>.Znfl</pre><pre>.krft</pre><pre>.fuYP</pre><pre>.Lp0o</pre><pre>.OYD4</pre><pre>.qsMF</pre><pre>.id;I</pre><pre>.Kr_t</pre><pre>.Nsq4</pre><pre>.bsr:</pre><pre>.QfkQ</pre><pre>.rhe4</pre><pre>.rh<H</pre><pre>.ZWZf</pre><pre>.pzmn</pre><pre>.yiJh</pre><pre>.bjRf</pre><pre>.qo9i</pre><pre>.Yy<\</pre><pre>%cSPL</pre><pre>.ltQl</pre><pre>.dZRK</pre><pre>.pkn\</pre><pre>.KV.y</pre><pre>.qVRh</pre><pre>.KpQu</pre><pre>.yfbs</pre><pre>.cgJn</pre><pre>.rZ.j</pre><pre>.lnfl</pre><pre>.rep7</pre><pre>.rs-N</pre><pre>.fxL;</pre><pre>.Mv;l</pre><pre>.duY:</pre><pre>.jf@;</pre><pre>.IYKJ</pre><pre>%coE\</pre><pre>'LkEY</pre><pre>.rt(G</pre><pre>.dc1x</pre><pre>.bqHg</pre><pre>.oS^_</pre><pre>.mQ[t</pre><pre>.Nc\I</pre><pre>.mu,N</pre><pre>.CfR]</pre><pre>.NSgw</pre><pre>.mv]m</pre><pre>.rjrn</pre><pre>%cm#z</pre><pre>.Yv`s</pre><pre>.rhoT</pre><pre>.QifO</pre><pre>%dlYM</pre><pre>.iwmt</pre><pre>.eoZt</pre><pre>.qlHv</pre><pre>.GlL^</pre><pre>.if=L</pre><pre>.rx)j</pre><pre>.rx<R</pre><pre>.rrP8</pre><pre>%doFT</pre><pre>.awDK</pre><pre>%fn;G</pre><pre>.qr14</pre><pre>.OzRY</pre><pre>%ciI7</pre><pre>.gh0u</pre><pre>.rqQX</pre><pre>.qwry</pre><pre>.qwqx</pre><pre>.rweo</pre><pre>.PSOp</pre><pre>.btY9</pre><pre>.rv:x</pre><pre>.QvGf</pre><pre>.pvEi</pre><pre>.IT 9</pre><pre>.YyL[</pre><pre>.rr_^</pre><pre>.pp\s</pre><pre>.ltmO</pre><pre>.kqg5</pre><pre>.roKX</pre><pre>.QgkR</pre><pre>.dj@Z</pre><pre>.ri \</pre><pre>.rkD8</pre><pre>.dxA<</pre><pre>.yno4</pre><pre>.rp/F</pre><pre>.Ccrf</pre><pre>.frJO</pre><pre>.rokz</pre><pre>%Ck1></pre><pre>.rsJO</pre><pre>.rpNp</pre><pre>%dMQX</pre><pre>.ks>K</pre><pre>.Qp(6</pre><pre>.Go\{</pre><pre>.bhNX</pre><pre>.rpjM</pre><pre>.Yd;I</pre><pre>.HS*8</pre><pre>.OzET</pre><pre>.ro(m</pre><pre>.agnk</pre><pre>.ro 9</pre><pre>.Ne?0</pre><pre>.PuC^</pre><pre>.oo=j</pre><pre>.qw-4</pre><pre>.yWD4</pre><pre>.rpMh</pre><pre>.oo\h</pre><pre>.qq9N</pre><pre>.lqY{</pre><pre>.aM,T</pre><pre>%fkO^</pre><pre>%fhoh</pre><pre>.rmM5</pre><pre>.quMR</pre><pre>.rmEH</pre><pre>.rr@6</pre><pre>.rmOS</pre><pre>.zmRW</pre><pre>.rweP</pre><pre>.monF</pre><pre>.ri#5</pre><pre>.rxaf</pre><pre>.rhE7</pre><pre>.OZ14</pre><pre>%CXG=</pre><pre>.roLQ</pre><pre>.kwIt</pre><pre>.es94</pre><pre>.rvHK</pre><pre>.rr'q</pre><pre>.ae<\</pre><pre>.HS _</pre><pre>.rvB_</pre><pre>.rqKU</pre><pre>.JqLs</pre><pre>.qZng</pre><pre>.rqaT</pre><pre>.rvc8</pre><pre>.jQP_</pre><pre>.rvHN</pre><pre>.deIP</pre><pre>.hc:l</pre><pre>.ifO^</pre><pre>.rsGH</pre><pre>.pR]{</pre><pre>.ph-;</pre><pre>.ri;Z</pre><pre>.am=L</pre><pre>.rx(W</pre><pre>.rxYN</pre><pre>.rxZP</pre><pre>.inhS</pre><pre>.mt\]</pre><pre>.riB0</pre><pre>.Qnpg</pre><pre>.qxrm</pre><pre>%Cwp4</pre><pre>.rs;Y</pre><pre>.rvG_</pre><pre>.Qo*;</pre><pre>.fr<:</pre><pre>.pq9n</pre><pre>%Cz9r</pre><pre>.YY)w</pre><pre>.dT1l</pre><pre>.ySMU</pre><pre>.PYf]</pre><pre>.mmdV</pre><pre>.Oy)]</pre><pre>%Cmq[</pre><pre>.dTl~</pre><pre>.rha<</pre><pre>.Ol?J</pre><pre>.ro?x</pre><pre>.nn`H</pre><pre>.mi(y</pre><pre><|uDP</pre><pre>.pZm8</pre><pre>.QkfJ</pre><pre>.koAY</pre><pre>-ywm}</pre><pre>$HsqL</pre><pre>%dZgm</pre><pre>.oz\q</pre><pre>.NUZo</pre><pre>.zQ<r</pre><pre>.moIk</pre><pre>.Gm#s</pre><pre>.kopG</pre><pre>.GQn8</pre><pre>.ri)j</pre><pre>.ogaJ</pre><pre>.Pi>R</pre><pre>.opjq</pre><pre>.QqZ></pre><pre>.nYMF</pre><pre>.bo:y</pre><pre>Î^F</pre><pre>.Pi\P</pre><pre>.ZT=7</pre><pre>.QzbH</pre><pre>.qTl[</pre><pre>.reb|</pre><pre>.Jl.6</pre><pre>.QlgU</pre><pre>.Phb{</pre><pre>.qhKP</pre><pre>.cm\j</pre><pre>.LQ<Z</pre><pre>.Hm^Z</pre><pre>.ogaQ</pre><pre>.jY,U</pre><pre>%cqd{</pre><pre>.ne-~</pre><pre>.ey(w</pre><pre>c:\documents and settings\all users\application data\softsafe\updatesoftware\UpdateSoftware.exe</pre><pre>?456789:;<=</pre><pre>!"#$%&'()* ,-./0123</pre><pre>'()*#$%&</pre><pre>>?:;<=9876540123,-./</pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></pre><pre><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></pre><pre>kernel32.dll</pre><pre>mscoree.dll</pre><pre>- CRT not initialized</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- floating point support not loaded</pre><pre>portuguese-brazilian</pre><pre>USER32.DLL</pre><pre>5476476</pre><pre>4740740</pre><pre>10001000</pre><pre>2303303</pre><pre>6874874</pre><pre>7144144</pre><pre>5%s\%s</pre><pre>Advapi32.dll</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>_dlsys->%s is null</pre><pre>ProductSupport</pre><pre>log.txt</pre><pre>AG%d%s</pre><pre>access out of bounds index %d not in 0..%d</pre><pre>UInfoURL</pre><pre>E:%u LookupPrivValue</pre><pre>E:%u AdjustTokenPriv</pre><pre>AdjustTokenPriv() return: %u (0==success)</pre><pre>E:%u OpProcTkn</pre><pre>(lpCmdLine==NULL)</pre><pre>result=%s</pre><pre>E: empty key; ignored</pre><pre>Except 0x%0.8x @0x%0.8x (%.30s) hmod=0xx</pre><pre>E:%d enc</pre><pre>8808808</pre><pre>6174174</pre><pre>4364364</pre><pre>8129129</pre><pre>5673673</pre><pre>6281281</pre><pre>5175175</pre><pre>7869869</pre><pre>PendingFileRenameOperations</pre><pre>PendingFileRenameOperations2</pre><pre>FileRenameOperations</pre><pre>c:\temp\winnie-pooh\piglet-rules.tmp</pre><pre>DeleteFile('%s') OK (not exist)</pre><pre>DeleteFile('%s') E1:%d;E2:%d</pre><pre>DeleteFile('%s') OK (scheduled; immediate E:%d); pending ops found:%d</pre><pre>DeleteFile('%s') OK</pre><pre>'%.256s~': E:%d</pre><pre>C:\Users</pre><pre>C:\Doc</pre><pre>\qmgr.dll</pre><pre>major version %d looks bogus</pre><pre>minor ver %d looks bogus</pre><pre>s-pack %d looks bogus</pre><pre>E:%d creating Runtime; OS-ver=%d</pre><pre>DLL LogPath='%s'</pre><pre>DL%d_%s</pre><pre>E:%d create HTML document; OS-ver=%d, IE-ver=%s</pre><pre>E:%d bind runtime to HTML window; OS-ver=%d, IE-ver=%s</pre><pre>E:%d LoadScr(BOOT)</pre><pre>E:%d LoadScr(JSO)</pre><pre>FROMAGENT_URLMON_IS_PRIMARY</pre><pre>FROMAGENT_NO_FALLBACK_ON_HTTP_ERRORS</pre><pre>E:%x execScript(JSON)</pre><pre>E:%x execScript(BOOTSTRAP)</pre><pre>execScript(BOOTSTRAP) done; m_eExitCode not set, assumed %d (E_SUCCESS=%d)</pre><pre>execScript(BOOTSTRAP) done; EC:{%d,%d}</pre><pre>execScript(BOOTSTRAP): script ended: VT_%d (VT_INT=%d)</pre><pre>worker about to end - calling spRuntime.Release();</pre><pre>%s-%s</pre><pre>Global\%s</pre><pre>E:%d CreateEvent '%s'</pre><pre>/schedule /profile "%s"</pre><pre>E:%d installing task '%.256s~'</pre><pre>E:%d removing task '%.256s~'</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\BITS</pre><pre>E:%d open BITS registry at '%s'</pre><pre>CAgentModule::CheckAndSetBITSRegistry(samWow64Select=%d): Adjusting BITS FGND retries to %d (in registry)</pre><pre>CAgentModule::CheckAndSetBITSRegistry(samWow64Select=%d): BITS FGND retries (in registry) = %d</pre><pre>Refresh enth set to %d sec</pre><pre>%ds[to-wait]-%ds[since-last];keep>0 ==>%ds</pre><pre>Waiting %ds</pre><pre>"%s" /%s "%s"</pre><pre>E appdaemon.Start '%.256s~'</pre><pre>%d.%d.%d.d</pre><pre>: E:%d open agent key '%.50s>'</pre><pre>E:%d delete module key '%.256s~'</pre><pre>: InitializeSecurityDescriptor failed; Error %u</pre><pre>: SetSecurityDescriptorDacl failed; Error %u</pre><pre>%s\%s\%s</pre><pre>%s\%s</pre><pre>E:%d open agent key'%.256s~'</pre><pre>WriteRegistryProfile E open module key '%.50s>' E:%d</pre><pre>WriteRegistryProfile E create section key '%.50s>' E:%d</pre><pre>WriteRegistryProfile E write section='%.50s>' value='%.50s>'; E:%d</pre><pre>['%.50s>']('%.50s>')<=='%.50s>'; E:%d; %s</pre><pre>: {sec'%.50s>',key'%.50s>'} E val-len %d>%d truncated</pre><pre>['%.256s~']('%.256s~')='%.256s~'; E %d too long, max=%d</pre><pre>E:%d start worker watchdog</pre><pre>CAgentModule::WatchdogThreadMain: Watchdog active. no event; waiting %d sec</pre><pre>.ini.bak</pre><pre>(%s,%s): E:%d open key</pre><pre>E:%d CoCreateInst</pre><pre>E:%d: ITaskSched::NewWItem</pre><pre>SetApplicationName E:%d</pre><pre>E:%d SetParameters</pre><pre>SetWorkingDirectory E:%d</pre><pre>SetAccountInformation E:%d</pre><pre>SetComment E:%d</pre><pre>SetFlags E:%d</pre><pre>CreateTrigger E:%d</pre><pre>SetTrigger E:%d</pre><pre>SetMaxRunTime E:%d</pre><pre>QueryInterface(IPersistFile) E:%d</pre><pre>E:%d save task in scheduler (IPersistFile::Save)</pre><pre>E:%d activate task (ITask::Run)</pre><pre>CoCreateInstance TaskScheduler failed %d</pre><pre>ITaskScheduler::Delete failed %d</pre><pre>E:%d OpSCMan</pre><pre>OpenService failed %d</pre><pre>ChangeServiceConfig failed %d</pre><pre>E:%d GetUserName</pre><pre>: E:%d LoadUserProfile (hTok=0x%x)</pre><pre>E:%d CreateEnvironmentBlock (hTok=0x%x)</pre><pre>"%s" %s</pre><pre>E:0xx CreateProcessAsUser; cannot start '%.256s~'; attempt CreateProcess</pre><pre>E:0xx CreateProcess; cannot start worker</pre><pre>E:0x%x CreateProcess OK but (hProcess==NULL); cannot start worker</pre><pre>: PHY %dmb<%dmb; E start command'%.256s~'</pre><pre>: VIRT %dmb<%dmb; E start command'%.256s~'</pre><pre>E:0x%0x WTSQUserTken</pre><pre>: E:0x%0x DupToken(Impers); continue;</pre><pre>: E:0x%0x DupToken(Ident); continue;</pre><pre>: E:0x%0x GetTokenInfo; continue;</pre><pre>E:0x%0x ImpersLOU</pre><pre>non admin user, os-ver=%d ==> do not execute</pre><pre>E:%d FndNxtFile: source is a folder</pre><pre>DeleteDirectory('%s') OK</pre><pre>DeleteDirectory('%s') E:%d</pre><pre>RemoveFileTree('%s') OK</pre><pre>RemoveFileTree('%s') E:%d</pre><pre>E:%d '%.256s~'->'%.256s~'</pre><pre>E:%d encrypting; cont unencrypted</pre><pre>E:%d Prepare()</pre><pre>ShellExecuteEx</pre><pre>E:%d (info.hInstance=%d)</pre><pre>Notepad.exe</pre><pre>Software\Microsoft\Windows\Current</pre><pre>ddeexec</pre><pre>.aHTML</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall</pre><pre>ddd</pre><pre>%d.%d.0.%d</pre><pre>URLInfoAbout</pre><pre>URLUpdateInfo</pre><pre>C:\Windows\System32\msiexec.exe</pre><pre>PID%d.TID%d</pre><pre>CEventLogger::LogEventV: vsprintf error %d with pszFormat='%s'</pre><pre>E:%d create memlog</pre><pre>{"entry_counter":"%u","entry_time":"%s","entry_type":"%llu","message":"%.256s"},</pre><pre>file not reported</pre><pre>JScr E:'%.50s>' F:'%.30s>',L:%d</pre><pre>E:NULL desc) (F='%.30s>',L=%d)</pre><pre>JScr: ExitP(%d)</pre><pre>JScr: ExitP(no code=%d)</pre><pre>E:%d data='%.256s~'</pre><pre>E:%d GetDisID'%.256s~'</pre><pre>ver=%d.%d.%d(%s)</pre><pre>os_id=%d.%d.%d sp%d</pre><pre>aid=%s</pre><pre>hid=%s (old crc32=0xx)</pre><pre>timestamp now=0x%s</pre><pre>IPv4_long=%d 0xx</pre><pre>E:%d folder '%s'</pre><pre>killed %d '%.256s~'</pre><pre>E:%d copy to '%.256s~'</pre><pre>E:%d ShellExec '%.256s~''%.256s~'</pre><pre>E:%d CreateProc '%.256s~'</pre><pre>E:%d GetExitCodProc(pid=%d)</pre><pre>E:%d inst to '%.256s~'</pre><pre>/instal E not adm. (OSVer=%d)</pre><pre>/install E not admin. (OSVer=%d) Cannot run</pre><pre>/Install <path> E:%d; continue as worker to report</pre><pre>/inst E not admin. (OSVer=%d)</pre><pre>/install E:%d schedule logon task (OSVer=%d); continue as worker to report</pre><pre>/install OK, but uninstaller(this=0x%x) E:%d.</pre><pre>/install OK. (will be reported by self)</pre><pre>/install E:%d. (is reported by parent)</pre><pre>/schedule E not admin. (OSVer=%d) Cannot run</pre><pre>New Scheduler v%d.%d.%d %s</pre><pre>Scheduler exits C:0x%x</pre><pre>/uninstall requires admin privileges. (OSVer=%d) Cannot run</pre><pre>Disable OK; %d killed</pre><pre>UNINST REPORT STARTS</pre><pre>UNINST REPORT ENDS</pre><pre>New Wker v%d.%d.%d %s</pre><pre>Worker exits C:0x%x</pre><pre>E:0x%x create: '%.256s~'</pre><pre>7382382</pre><pre>(%s,%s): OK</pre><pre>(%s,%s): E:%d setting value</pre><pre>E:%d open key '%.256s~'</pre><pre>RegDeleteKeyEx</pre></div><div class="blog_tab" id="tab3"><p><strong class="font_20"><span style="font-size:medium;">Remove it with Ad-Aware</span></strong></p><ol><li>Click (<a href="http://lavasoft.com/thankyou.php?internal=true&inter=encyclopedia"><span style="color: #0000ff;">here</span></a>) to download and install Ad-Aware Free Antivirus.</li><li>Update the definition files.</li><li>Run a full scan of your computer.</li></ol><p><strong class="font_20"><span style="font-size:medium;">Manual removal*</span></strong></p><ol><li>Terminate malicious process(es) (<a href="http://www.lavasoft.com/mylavasoft/malware-removal-support/blog/how-to-end-a-process-with-the-task-manager"><span style="color: #0000ff;">How to End a Process With the Task Manager</span></a>):<p style="padding-left: 30px; font-size: x-small; color: #ff0000;">nshBF.exe:2008<br>putfu.exe:2928<br>sp-downloader.exe:1716<br>CltMngSvc.exe:1784<br>CltMngSvc.exe:1640<br>nsoBA.tmp:2012<br>cltmng.exe:996<br>usetup.exe:3420<br>cltmngui.exe:1296<br>rundll32.exe:3116<br>rundll32.exe:3052<br>%original file name%.exe:312<br>nsuB5.exe:516<br>nsuC3.exe:2608<br>UpdateSoftware.exe:3512<br>UpdateSoftware.exe:3456</p></li><li>Delete the original Backdoor file.<br></li><li>Delete or disinfect the following files created/modified by the Backdoor:<p style="padding-left: 30px; font-size: x-small; color: #ff0000;">%Documents and Settings%\%current user%\Local Settings\Temp\nsoC1.tmp\inetc.dll (30 bytes)<br>%Program Files%\ProgramUpdater\Assistant.dll (264574 bytes)<br>%Program Files%\ProgramUpdater\AssistantSvc.dll (174 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\tf00294823.dll (30622 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\System.dll (11 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsuB5.exe (11736 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nseB6.tmp (52 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\MiniStubUtils.dll (7192 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\downloadstub[1] (52 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nstB3.tmp (7189 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsjB4.tmp\inetc.dll (784 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\spstub[1].exe (11736 bytes)<br>%Program Files%\SearchProtect\Main\rep\SystemRepository.dat (9 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\close-win-def.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_checked.png (360 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bgUninstall.png (784 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\v.png (1 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\SPVC64.dll (103387 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\SPVC32.dll (287458 bytes)<br>%Program Files%\SearchProtect\EULA.txt (784 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.html (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\Apply-onclick.png (2 bytes)<br>%Program Files%\SearchProtect\Main\bin\uninstall.exe (33747 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.css (4 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsuC3.exe (5520 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.css (5 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\menu-selected.png (3 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\x.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\radio-button2.png (886 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\btnSilver.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\main.js (10 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\checkbox.png (378 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\btnClose.png (933 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protectionDS\protectionDS.js (7 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\json2.min.js (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bgSettings.png (12 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\SPTool64.exe (50351 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\hez-def.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\defaults.js (983 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\hez.png (256 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\close-win-over-click.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\radio-button.png (859 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bg.png (784 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\uninstall\defaults.js (1 bytes)<br>%Program Files%\SearchProtect\UI\bin\cltmngui.exe (100378 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\gray-bg.png (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\style.css (7 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bgSettingsDS.png (9 bytes)<br>%Program Files%\SearchProtect\Main\bin\CltMngSvc.exe (96792 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\SPtool.dll (81046 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\cltmng.exe (170836 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bg-uninstall.png (11 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\info-icon.png (424 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\browsers32.sdb (1 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\inetc.dll (784 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.js (5 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-def.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\SPDialogAPI.js (3 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\settings.html (8 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bgNotif.png (9 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protection\protection.html (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\settings\settings.html (12 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protection\defaults.js (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\uninstall\uninstall.html (5 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\Settings-icon.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\bg-with-logo.png (1552 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\radio-button-selected.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\Apply-Rollover.png (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protection\protection.js (7 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\menu-rollover.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\text-field.png (1 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nshBF.exe (5520 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protection\protection.css (4 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\checkbox_def.png (274 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\icon-win.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\dialogUtils.js (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\btnBlue.png (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\button-bg.png (1 bytes)<br>%Program Files%\SearchProtect\Main\bin\SPTool.dll (81046 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserRepository.dat (478 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js (3312 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\C2.tmp (1 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\settings\defaults.js (1 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (6584 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\Apply-default.png (2 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\settings\settings.css (8 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nszBE.tmp (649 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsbBD.tmp\System.dll (11 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\Images\hez-selected.png (1 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\CT3309297[1] (649 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\settings\settings.js (11 bytes)<br>%Program Files%\SearchProtect\UI\dialogs\protectionDS\defaults.js (1 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsqBC.tmp (698645 bytes)<br>%Program Files%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (8560 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\SearchProtect\rep\UserSettings.dat (1 bytes)<br>%Documents and Settings%\All Users\Application Data\SoftSafe\UpdateSoftware\UpdateSoftware.exe (33792 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Application Data\SearchProtect\UI\rep\UIRepository.dat (1057 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\general_logo.bmp.tmp (808 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.1.ini (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\agup[1].exe (33536 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\general_logo[1].bmp (784 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll (61 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\_tin57DE.bat (84 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe (15 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll (673 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.dat (14184 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\TsuDll.dll (1425 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.exe (15 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\3EFFE146.dat (13584 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\_Setup.dll (5520 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2[1].txt (4 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_2.ini (9 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\4_3[1].txt (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\sp-downloader[1].exe (5064 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.4_3.ini (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\50b2a4e2b05f1a96cb606980e48cc21e.log (3036232 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\3[1].txt (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Custom.dll (1856 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\4_2[1].txt (9 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x86\regsvr32.exe (12 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\tpq[1].exe (163934 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.ico (4 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\_tin3D45.bat (88 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\Tsu905D28F2.dll (2569 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Readme.txt (2 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.3.ini (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\7306_appcompat.txt (214 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Setup.ico (4 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\x64\regsvr32.exe (12 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1[1].txt (6 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.2.ini (4 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.sp-downloader.exe (5064 bytes)<br>%Documents and Settings%\All Users\Application Data\InstallMate\{735B0250-8ADE-493A-ABD1-C2FCA8B820A6}\Readme.txt (2 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.putfu.exe (163934 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\down.312.usetup.exe (33536 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SPSetup[1].exe (433592 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsaB8.tmp (10114 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\System.dll (11 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\inetc.dll (784 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsoBA.tmp (433592 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsqB9.tmp\StubUtils.dll (9320 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nsoBA.txt (70 bytes)<br>%Documents and Settings%\%current user%\Local Settings\Temp\nskC5.tmp\inetc.dll (30 bytes)<br>%WinDir%\Tasks\UpdateSoftware-S-3956077583.job (692 bytes)<br>%Documents and Settings%\All Users\Application Data\SoftSafe\UpdateSoftware\3956077583.ini (42494 bytes)</p></li><li>Clean the Temporary Internet Files folder, which may contain infected files (<a href="http://www.lavasoft.com/mylavasoft/malware-removal-support/blog/how-to-clean-the-temporary-internet-files-folder"><span style="color: #0000ff;">How to clean Temporary Internet Files folder</span></a>).<br></li></ol>*Manual removal may cause unexpected system behaviour and should be performed at your own risk.</div></di?></pre></_></pre></_7_></pre></_0_></pre></_></pre></_-_0_></pre></1%u5>