Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: d3e0d7a52b022b043f657ae22d8aba84
SHA1: 3fd52d6685168c5afdc47160ceaaf2f39b2a7f72
SHA256: 3956d851b33900ac6850e7c535e7e5938c1cd85816002952d0b6d8633b139007
SSDeep: 12288:b1OgLdanv50/kxr3uzA qnSbr/KY9RObYJ4nIK ymRo OSZTN2TBxx696O:b1OYdaqNayr/X9sRGymC TTN2Nb6EO
Size: 779744 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6, MicrosoftVisualC, MicrosoftVisualCv50v60MFC, MicrosoftVisualC50, Armadillov171
Company: Symantec
Created at: 2010-11-18 18:27:35
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
%original file name%.exe:972
The Trojan injects its code into the following process(es):
SymCCISExe.exe:1560
SymInstallStub.exe:1788
nssSetup.exe:704
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process %original file name%.exe:972 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymCCIS.dll (1302 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymCCISExe.exe (9907 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp (0 bytes)
The process SymCCISExe.exe:1560 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SCC[1].dll (22747 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.dll (167 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SCC.config[1].txt (1504 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymInstallStub.exe (35252 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SymInstallStub[1].exe (44299 bytes)
%System%\wbem\Logs\wbemprox.log (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.config (1 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.config (0 bytes)
The process SymInstallStub.exe:1788 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS2.tmp (698 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS3.tmp (2556018 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\SymInstallStub.state.dat (790 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS3.tmp (0 bytes)
The process nssSetup.exe:704 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstUI.dll (40137 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccSet.dll (3388 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsBrand.loc (11 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcp100.dll (3194 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsMUI.loc (3249 bytes)
%Documents and Settings%\All Users\Application Data\NortonInstaller\Logs\2014-07-05-09h23m10s\NortonInstall-2014-07-05-09h23m10s.log (69780 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\SKU.dll (10 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccL120U.dll (6441 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Engine.dll (22617 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstStub.exe (42359 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ProdCbk.dll (1258 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Install.mft (1209 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Images\InsImage.dll (10217 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\fallback.dat (4 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcr100.dll (6854 bytes)
The Trojan deletes the following file(s):
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28 (0 bytes)
Registry activity
The process %original file name%.exe:972 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "33 B2 95 AC BB 1D E3 F9 EC 99 CF 4C CD 7A B5 AC"
The process SymCCISExe.exe:1560 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2C 35 A0 D0 49 E7 70 B9 A4 7C FB 4E 76 6B DB 04"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp]
"SymInstallStub.exe" = "SymInstallStub"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process SymInstallStub.exe:1788 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "58 88 46 B0 B7 01 70 17 AD 1D 59 C1 E8 69 E6 9E"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Symantec\NPInstaller\AffID\AID_estorecj]
"NSS" = "aff_softonic-e"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Symantec\Install_Stub]
"UID" = "01839ae7-8a82-407b-924e-9b7ff1a41474"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Symantec\Install_Stub\estorecj3.6.1.16]
"LaunchCount" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\Symantec\Install_Stub\estorecj3.6.1.16]
"InstallDate" = "07/05/2014"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\SymInstallStub\estorecj]
"nssSetup.exe" = "Norton Security Scan"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SymInstallStub" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymInstallStub.exe /partnerid=estorecj /productlist=nss /staging=false /affid=softonic-e /dist=webbanner /delay=5 /launchedby=7 /fallback"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The process nssSetup.exe:704 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CD D6 74 62 EC 4C 0F AA C6 FB CF E3 DE 9A 6C 42"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSS" = "%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstStub.exe /RELAUNCH /RUNONCE /PRODID NSS"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NSS]
"MEDIA" = "%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\nssSetup.exe"
Dropped PE files
MD5 | File path |
---|---|
6bec059e9f70b59873807c4f2a72a8b5 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\7zS1.tmp\SymCCIS.dll |
0c302654dfad0b2053f75d66484b395f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\7zS1.tmp\SymCCISExe.exe |
55d95cf2c2164ea7f95c089c1015036f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\7zS1.tmp\SymInstallStub.exe |
e17c3f4045655cfaeb2137c205748c1e | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SymInstallStub\estorecj\nssSetup.exe |
38212789a0f996c9f49d2646446c02f3 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SCC[1].dll |
55d95cf2c2164ea7f95c089c1015036f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SymInstallStub[1].exe |
639a95f0949e4e16cf7c7ce50238514e | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsBrand.loc |
089f07db762bced9f7b8f5ea99c62730 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsMUI.loc |
87c0b4d56f0cf17eecd766ad1fc87f41 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Engine.dll |
618fd2c559aa376b8d2b3571170885c2 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Images\InsImage.dll |
3ad22c9eca55ce3c2517fbedc5c689db | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstStub.exe |
df9a3bccea5bcfa0c4d393384fbdfe08 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstUI.dll |
3916eba7d9b15eff854d0ae8f5351542 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ProdCbk.dll |
1966473ef34e2c106bdea6e29e01776c | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\SKU.dll |
472965795f8aa4e5725237c444f3954e | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccL120U.dll |
9cb33dae32aa959bb8c4b2779d302b62 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccSet.dll |
e3c817f7fe44cc870ecdbcbc3ea36132 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcp100.dll |
bf38660a9125935658cfa3e53fdc7d65 | c:\Program Files\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcr100.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
%original file name%.exe:972
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymCCIS.dll (1302 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymCCISExe.exe (9907 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SCC[1].dll (22747 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.dll (167 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SCC.config[1].txt (1504 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SymInstallStub.exe (35252 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SymInstallStub[1].exe (44299 bytes)
%System%\wbem\Logs\wbemprox.log (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7zS1.tmp\SCC.config (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS2.tmp (698 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\IS3.tmp (2556018 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\SymInstallStub.state.dat (790 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstUI.dll (40137 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccSet.dll (3388 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsBrand.loc (11 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcp100.dll (3194 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\09\01\InsMUI.loc (3249 bytes)
%Documents and Settings%\All Users\Application Data\NortonInstaller\Logs\2014-07-05-09h23m10s\NortonInstall-2014-07-05-09h23m10s.log (69780 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\SKU.dll (10 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ccL120U.dll (6441 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Engine.dll (22617 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstStub.exe (42359 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\ProdCbk.dll (1258 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Install.mft (1209 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\Images\InsImage.dll (10217 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\fallback.dat (4 bytes)
%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\msvcr100.dll (6854 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SymInstallStub" = "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymInstallStub.exe /partnerid=estorecj /productlist=nss /staging=false /affid=softonic-e /dist=webbanner /delay=5 /launchedby=7 /fallback"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSS" = "%Program Files%\NortonInstaller\{397E31AA-0D78-4649-A01C-339D73A2ED35}\NSS\LicenseType\4.1.0.28\InstStub.exe /RELAUNCH /RUNONCE /PRODID NSS"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NSS]
"MEDIA" = "%Documents and Settings%\%current user%\Local Settings\Temp\SymInstallStub\estorecj\nssSetup.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Symantec
Product Name: Norton Product Installer
Product Version: 2.1
Legal Copyright: Copyright (c) 2014 Symantec Corporation.
Legal Trademarks:
Original Filename: SymCCIS
Internal Name: SymCCIS
File Version: 2.1
File Description: SymCCIS
Comments:
Language: English (United States)
Company Name: SymantecProduct Name: Norton Product InstallerProduct Version: 2.1Legal Copyright: Copyright (c) 2014 Symantec Corporation.Legal Trademarks: Original Filename: SymCCISInternal Name: SymCCISFile Version: 2.1File Description: SymCCISComments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 104938 | 104960 | 4.58066 | 8c9346b8cd91e8d7aa2e1586eb1a1b30 |
.rdata | 110592 | 17556 | 17920 | 3.02768 | 5e256dc61db6deff01801e77de19d038 |
.data | 131072 | 23112 | 12800 | 0.949986 | 1d347e5500f0d4c5672ba18282b866f7 |
.sxdata | 155648 | 4 | 512 | 0.014135 | 35925cfdc1176bd9ffc634a58b40ec17 |
.rsrc | 159744 | 147184 | 147456 | 3.5244 | fd862b60471bc337e6525b153aa97b6a |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 1
c4ad635a13cfa197788e87065319409e
Network Activity
URLs
URL | IP |
---|---|
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/SCC.dll | |
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/SCC/estorecj/ENG.SCC.config.txt | |
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/SCC/estorecj/SCC.config.txt | |
hxxp://stats.norton.com/n/p?module=9160&product=SCC&version=4.6.0.11&language=09.01&os=5.1.2600.3.0&y=1033&a=estorecj&b=false&c=nss=install&d=nss=1000&e=0x0&error=0&n=0&j=0&k=0&l=none&m=none&o=none&q=none&t=none&u=-1&v=none | 63.245.197.112 |
hxxp://stats.norton.com/n/p?module=9151&product=SymCCIS&version=2.1.0.20&language=09.01&os=5.1.2600.3.0&y=1033&b=estorecj&a=CallCriteriaChecker&f=10&c=false&d=false&e=0x0&error=0&j=nss=install&k=nss=1000&g=0.954&l=2.726&q=&t=&u= | 63.245.197.112 |
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/SymInstallStub.exe | |
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/IS/estorecj/SymInstallStub.config.txt | |
hxxp://a568.d.akamai.net/upgrade/NSS/SymCCIS/Production/IS/nss/USEnglish/estorecj/Setup.exe | |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/SCC/estorecj/ENG.SCC.config.txt | 212.30.134.160 |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/SCC.dll | 212.30.134.160 |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/SymInstallStub.exe | 212.30.134.160 |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/IS/nss/USEnglish/estorecj/Setup.exe | 212.30.134.160 |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/IS/estorecj/SymInstallStub.config.txt | 212.30.134.160 |
hxxp://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/SCC/estorecj/SCC.config.txt | 212.30.134.160 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
HEAD /upgrade/NSS/SymCCIS/Production/IS/nss/USEnglish/estorecj/Setup.exe HTTP/1.1
User-Agent: SymInstallStub
Host: liveupdate.symantecliveupdate.com
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "e17c3f4045655cfaeb2137c205748c1e:1398688555"
Last-Modified: Mon, 28 Apr 2014 12:33:08 GMT
Accept-Ranges: bytes
Content-Length: 10679800
Content-Type: application/octet-stream
Cache-Control: max-age=94
Expires: Sat, 05 Jul 2014 06:24:22 GMT
Date: Sat, 05 Jul 2014 06:22:48 GMT
Connection: close
GET /upgrade/NSS/SymCCIS/Production/SCC.dll HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: liveupdate.symantecliveupdate.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
ETag: "38212789a0f996c9f49d2646446c02f3:1402650668"
Last-Modified: Fri, 13 Jun 2014 09:09:28 GMT
Accept-Ranges: bytes
Content-Length: 167264
Content-Type: application/octet-stream
Cache-Control: max-age=1637
Expires: Sat, 05 Jul 2014 06:50:00 GMT
Date: Sat, 05 Jul 2014 06:22:43 GMT
Connection: keep-alive
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........r.................................E...............................Q...................................Rich............PE..L......S...........!.........>.......z....................................................@.........................Ew......tx..{....p..=............t..`........... ................................................................................text....`.......T......PEC2TO...... ....rsrc.... ...p.......X.............. ....reloc...............r..............@.....................................................................................................................................................................................................................................................................................................................................................................................................................................*..U..9k3e..O.U...-.[O?wV|.........Uk .B..u3g5.I...jUi..c#.d.N.k.....jxf....f.....M..k./K.>.'S(..8.......Wz.j.....Q.Q.z p...F.....Z...A.n..&...Id.......>o...5.1...&?.....cA.!.}L...>..u......D...c.~3.:.M%.d.......BU.....o4[.$..|..n..$.vL<..~...Jd...uV.}....Q."..e..........Q...z..O.P..;...R.qlm.z.......4.'..O.._.C..[..C...].._..`r.;[.c.9@2..,6..m1...x.f=....d...9HR..?...A..?.f........>GUa..Q=^#\....<.e..e@r.)..y.Q.J...{..<`*....~f.Q......p..V....P.BP...y..=...?.....>O.f.?.
<<
<<< skipped >>>
GET /upgrade/NSS/SymCCIS/Production/SCC/estorecj/ENG.SCC.config.txt HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: liveupdate.symantecliveupdate.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Content-Length: 292
Content-Type: text/html
Expires: Sat, 05 Jul 2014 06:52:31 GMT
Date: Sat, 05 Jul 2014 06:22:44 GMT
Connection: keep-alive
Cache-Control: public,must-revalidate,max-age=1800
<HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html;charset=ISO-8859-1"><TITLE>Not Found</TITLE></HEAD>.<H1>Not Found</H1> The requested object does not exist on this server. The link you followed is either outdated, inaccurate, or the server has been instructed not to let you have it. ....
GET /upgrade/NSS/SymCCIS/Production/SCC/estorecj/ENG.SCC.config.txt HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: liveupdate.symantecliveupdate.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Content-Length: 292
Content-Type: text/html
Expires: Sat, 05 Jul 2014 06:52:31 GMT
Date: Sat, 05 Jul 2014 06:22:44 GMT
Connection: keep-alive
Cache-Control: public,must-revalidate,max-age=1800
<HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html;charset=ISO-8859-1"><TITLE>Not Found</TITLE></HEAD>.<H1>Not Found</H1> The requested object does not exist on this server. The link you followed is either outdated, inaccurate, or the server has been instructed not to let you have it. ....
GET /upgrade/NSS/SymCCIS/Production/SCC/estorecj/SCC.config.txt HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: liveupdate.symantecliveupdate.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
ETag: "1fdaaca32d5a43947ca17e1f4c2a63b0:1382649161"
Last-Modified: Thu, 24 Oct 2013 21:10:26 GMT
Accept-Ranges: bytes
Content-Length: 1504
Content-Type: text/plain
Cache-Control: max-age=1407
Expires: Sat, 05 Jul 2014 06:46:12 GMT
Date: Sat, 05 Jul 2014 06:22:45 GMT
Connection: keep-alive
<<< skipped >>>
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: liveupdate.symantecliveupdate.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache
ETag: "55d95cf2c2164ea7f95c089c1015036f:1403535622"
Last-Modified: Mon, 23 Jun 2014 14:59:33 GMT
Accept-Ranges: bytes
Content-Length: 358752
Content-Type: application/octet-stream
Cache-Control: max-age=1309
Expires: Sat, 05 Jul 2014 06:44:35 GMT
Date: Sat, 05 Jul 2014 06:22:46 GMT
<<< skipped >>>
HEAD /upgrade/NSS/SymCCIS/Production/IS/estorecj/SymInstallStub.config.txt HTTP/1.1
User-Agent: SymInstallStub
Host: liveupdate.symantecliveupdate.com
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "00973789929a9f033841dd706229c87d:1357702423"
Last-Modified: Wed, 09 Jan 2013 01:15:20 GMT
Accept-Ranges: bytes
Content-Length: 1864
Content-Type: text/plain
Cache-Control: max-age=1791
Expires: Sat, 05 Jul 2014 06:52:38 GMT
Date: Sat, 05 Jul 2014 06:22:47 GMT
Connection: close
GET /upgrade/NSS/SymCCIS/Production/IS/nss/USEnglish/estorecj/Setup.exe HTTP/1.1
User-Agent: SymInstallStub
Host: liveupdate.symantecliveupdate.com
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "e17c3f4045655cfaeb2137c205748c1e:1398688555"
Last-Modified: Mon, 28 Apr 2014 12:33:08 GMT
Accept-Ranges: bytes
Content-Length: 10679800
Content-Type: application/octet-stream
Cache-Control: max-age=427
Expires: Sat, 05 Jul 2014 06:29:55 GMT
Date: Sat, 05 Jul 2014 06:22:48 GMT
<<< skipped >>>
HEAD /upgrade/NSS/SymCCIS/Production/IS/nss/USEnglish/estorecj/Setup.exe HTTP/1.1
User-Agent: SymInstallStub
Host: liveupdate.symantecliveupdate.com
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "e17c3f4045655cfaeb2137c205748c1e:1398688555"
Last-Modified: Mon, 28 Apr 2014 12:33:08 GMT
Accept-Ranges: bytes
Content-Length: 10679800
Content-Type: application/octet-stream
Cache-Control: max-age=94
Expires: Sat, 05 Jul 2014 06:24:22 GMT
Date: Sat, 05 Jul 2014 06:22:48 GMT
Connection: close
GET /upgrade/NSS/SymCCIS/Production/IS/estorecj/SymInstallStub.config.txt HTTP/1.1
User-Agent: SymInstallStub
Host: liveupdate.symantecliveupdate.com
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "00973789929a9f033841dd706229c87d:1357702423"
Last-Modified: Wed, 09 Jan 2013 01:15:20 GMT
Accept-Ranges: bytes
Content-Length: 1864
Content-Type: text/plain
Cache-Control: max-age=867
Expires: Sat, 05 Jul 2014 06:37:15 GMT
Date: Sat, 05 Jul 2014 06:22:48 GMT
<<< skipped >>>
GET /n/p?module=9160&product=SCC&version=4.6.0.11&language=09.01&os=5.1.2600.3.0&y=1033&a=estorecj&b=false&c=nss=install&d=nss=1000&e=0x0&error=0&n=0&j=0&k=0&l=none&m=none&o=none&q=none&t=none&u=-1&v=none HTTP/1.1
User-Agent: Install Stub
Accept: */*
Host: stats.norton.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/plain;charset=ISO-8859-1
Content-Length: 13
Date: Sat, 05 Jul 2014 06:22:45 GMT1404541365801....GET /n/p?module=9151&product=SymCCIS&version=2.1.0.20&language=09.01&os=5.1.2600.3.0&y=1033&b=estorecj&a=CallCriteriaChecker&f=10&c=false&d=false&e=0x0&error=0&j=nss=install&k=nss=1000&g=0.954&l=2.726&q=&t=&u= HTTP/1.1
User-Agent: Install Stub
Accept: */*
Host: stats.norton.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Cache-Control: no-cache
Pragma: no-cache
Content-Type: text/plain;charset=ISO-8859-1
Content-Length: 13
Date: Sat, 05 Jul 2014 06:22:45 GMT1404541365936HTTP/1.1 200 OK..Server: Apache-Coyote/1.1..Cache-Control: no-cache..Pragma: no-cache..Content-Type: text/plain;charset=ISO-8859-1..Content-Length: 13..Date: Sat, 05 Jul 2014 06:22:45 GMT..1404541365936..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_972:
.text
.text
`.rdata
`.rdata
@.data
@.data
.sxdata
.sxdata
.rsrc
.rsrc
<x><pre>__MSVCRT_HEAP_SELECT</pre><pre>user32.dll</pre><pre>OLEAUT32.dll</pre><pre>USER32.dll</pre><pre>ShellExecuteExA</pre><pre>SHELL32.dll</pre><pre>GetWindowsDirectoryA</pre><pre>GetCPInfo</pre><pre>KERNEL32.dll</pre><pre>c:\%original file name%.exe</pre><pre>--YY})</pre><pre>-p%uG</pre><pre>(c,%sZ</pre><pre>J.VEe</pre><pre><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="SYMCCIS.exe" type="win32"></assemblyIdentity></pre><pre><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></pre><pre><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></pre><pre><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></pre><pre>Can not find setup.exe</pre><pre>setup.exe</pre><pre>BUnsupported Method</pre><b>SymCCISExe.exe_1560:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>RPQSShd</pre><pre>8%u:j</pre><pre>QSSSSSSh</pre><pre>t%SWh4rI</pre><pre>xSSSh</pre><pre>FTPjKS</pre><pre>FtPj;S</pre><pre>C.PjRV</pre><pre>NRTN_OfferEngine_CheckCriteria_Web</pre><pre>2.1.0.20</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>1.3.6.1.4.1.311.10.3.5</pre><pre>1.3.6.1.4.1.311.10.3.6</pre><pre>1.3.6.1.5.5.7.3.3</pre><pre>2.5.4.6</pre><pre>2.5.4.8</pre><pre>2.5.4.7</pre><pre>2.5.4.10</pre><pre>2.5.4.11</pre><pre>2.5.4.3</pre><pre>WINTRUST.dll</pre><pre>CRYPT32.dll</pre><pre>{X-X-X-XX-XXXXXX}</pre><pre>operator</pre><pre>portuguese-brazilian</pre><pre>GetProcessWindowStation</pre><pre>C:\bld_area\SymCCIS_r2.1.0_20\bin\bin.iru\SymCCISExe.pdb</pre><pre>CryptCATCatalogInfoFromContext</pre><pre>CryptMsgClose</pre><pre>CertCloseStore</pre><pre>CertFreeCertificateContext</pre><pre>CertFindCertificateInStore</pre><pre>CryptMsgGetParam</pre><pre>CertGetEnhancedKeyUsage</pre><pre>CertNameToStrW</pre><pre>CertGetNameStringW</pre><pre>KERNEL32.dll</pre><pre>CreateDialogIndirectParamW</pre><pre>USER32.dll</pre><pre>GDI32.dll</pre><pre>RegOpenKeyExW</pre><pre>RegCloseKey</pre><pre>RegCreateKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegQueryInfoKeyW</pre><pre>RegEnumKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>COMCTL32.dll</pre><pre>GdiplusShutdown</pre><pre>gdiplus.dll</pre><pre>HttpSendRequestW</pre><pre>HttpAddRequestHeadersW</pre><pre>HttpOpenRequestW</pre><pre>WININET.dll</pre><pre>USERENV.dll</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>SHDeleteKeyW</pre><pre>SHDeleteEmptyKeyW</pre><pre>.?AV?$_Ref_count@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@tr1@std@@</pre><pre>zcÁ</pre><pre><x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 4.2.2-c063 53.351735, 2008/07/22-18:11:12 "></x:xmpmeta></pre><pre><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"></rdf:RDF></pre><pre>xmlns:xmp="http://ns.adobe.com/xap/1.0/"></pre><pre>xmlns:dc="http://purl.org/dc/elements/1.1/"></pre><pre>:9876543210/.-, *)('&%$#"!</pre><pre>--YY})</pre><pre>-p%uG</pre><pre>(c,%sZ</pre><pre>J.VEe</pre><pre>PA<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"></compatibility></assembly></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre>8"83888=8</pre><pre>:};*=7=?=</pre><pre>2,2w2</pre><pre>7%7X7o7</pre><pre>7&7 7>7\7</pre><pre>= =%=8=[=</pre><pre>1&111^1|1</pre><pre>5*6064686<6</pre><pre>0 0$0(0,0</pre><pre>3!3%3)3-3135393</pre><pre>8œ9</pre><pre>8!8,80858</pre><pre>PartnerID passed as genericnss --> Changed it to --> symantecnss</pre><pre>%s\SymCCIS.dll</pre><pre>Launch browser URL:</pre><pre>Help URL:</pre><pre>Base URL:</pre><pre>&staging=%s</pre><pre>&partnerid=%s</pre><pre>&localeID=%d</pre><pre>&os=%u.%u.%u.%u.%u</pre><pre>&langID=X.X</pre><pre>&version=%s</pre><pre>&product=%s</pre><pre>msgid=%s</pre><pre>symccis::Controller::formatMessageURL</pre><pre>symccis::Controller::showErrorMsg</pre><pre>symccis::Controller::launchURL</pre><pre>Inside DoWord - Worker thread exit code b4 ping = %d</pre><pre>Inside DoWord - Worker thread exit code b4 post msg =</pre><pre>ICHttpRequest::CHttpRequest</pre><pre>CHttpRequest::~CHttpRequest</pre><pre>CHttpRequest::GetResponse</pre><pre>https</pre><pre>CHttpRequest::ParseURLW</pre><pre>CHttpRequest::RequestPage</pre><pre>[s d, d - d:d:d:d]</pre><pre>%s %ld</pre><pre>%s %s</pre><pre>%s 0x%x</pre><pre>Advapi32.dll</pre><pre>BACKGROUND.PNG</pre><pre>http://www.norton.com</pre><pre>CMainDlg::OnLaunchURL</pre><pre>Link URL =</pre><pre>CMainDlg::UrlCmdHandler</pre><pre>Link URL = %s</pre><pre>&linkurl=</pre><pre>Command = %s</pre><pre>URL =</pre><pre>Unable to get SDK path registry key</pre><pre>Unable to open SDK registry key</pre><pre>I&y=%d</pre><pre>&language=X.X</pre><pre>module=%s</pre><pre>http://stats.norton.com/n/p?</pre><pre>Ping URL =</pre><pre>&o=%s</pre><pre>&n=%d</pre><pre>&m=%s</pre><pre>&f=%d</pre><pre>&d=%s</pre><pre>&b=%s</pre><pre>&a=%s</pre><pre>SymCCISExe</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>SymCCISExe.txt</pre><pre>GetCmdLineOpt</pre><pre>http://liveupdate.symantecliveupdate.com</pre><pre>IsCmdlineSwitchPassed</pre><pre>GetCmdArgValue</pre><pre>GetExePath</pre><pre>OpenURL</pre><pre>%SymEFA%</pre><pre>EFACli.dll</pre><pre>0xX</pre><pre>..\Source\ccVerifyTrustStatic.cpp</pre><pre>FCLSID\%s\LocalServer32</pre><pre>CLSID\%s\InprocServer32</pre><pre>BNTDLL.DLL</pre><pre>..\Source\ccVerifyTrustImpl.cpp</pre><pre>..\Source\FileCache.cpp</pre><pre>B..\Source\VerifyFile.cpp</pre><pre>..\Source\ccVerifyTrustPolicy.cpp</pre><pre>..\Source\CatalogIterator.cpp</pre><pre>..\Source\CatalogFileHash.cpp</pre><pre>WinTrust.dll</pre><pre>..\Source\CatalogContext.cpp</pre><pre>..\Source\ccSymModuleLifetimeMgrImpl.cpp</pre><pre>C%s, %s, %s, %s(%ld)</pre><pre>C..\Source\ccModule.cpp</pre><pre>C..\Source\ccSystemInfo.cpp</pre><pre>C..\Source\ccRegistry.cpp</pre><pre>..\Source\ccStringConvert.cpp</pre><pre>CSIDL_WINDOWS</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>..\Source\ccPathExpansion.cpp</pre><pre>\\?\UNC</pre><pre>C..\Source\ccSplitPath.cpp</pre><pre>C..\Source\ccOSInfo.cpp</pre><pre>\wpeutil.dll</pre><pre>\FACTORY.exe</pre><pre>\wpeinit.exe</pre><pre>C..\Source\ccMemory.cpp</pre><pre>C..\Source\ccFile.cpp</pre><pre>..\Source\ccWow64FsRedirection.cpp</pre><pre>%s\%s</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED</pre><pre>isolate.ini</pre><pre>%COMMON_SILO_DATA%</pre><pre>D..\Source\ccEncryptedString.cpp</pre><pre>D..\Source\ccSymDllLifetimeMgr.cpp</pre><pre>F..\Source\ccSynchronize.cpp</pre><pre>t..\Source\ccMessageLock.cpp</pre><pre>kernel32.dll</pre><pre>KERNEL32.DLL</pre><pre>DPSAPI.DLL</pre><pre>..\Source\ccPEBReader.cpp</pre><pre>D..\Source\ccPrivilege.cpp</pre><pre>..\Source\ccSymIndexValueCollectionImpl.cpp</pre><pre>AWTSAPI32.DLL</pre><pre>B..\Source\ccSymDllLifetimeMgrLocal.cpp</pre><pre>..\Source\ccSymIndexValueCollection.cpp</pre><pre>..\Source\ccSymValueCollection.cpp</pre><pre>EÌROOT%</pre><pre>rcPFRes.dll</pre><pre>rcPxyEvt.dll</pre><pre>rcProxy.dll</pre><pre>rcSvcHst.dll</pre><pre>rcEmlPxy.dll</pre><pre>rcLgView.dll</pre><pre>rcErrDsp.dll</pre><pre>rcAlert.dll</pre><pre>rcApp.dll</pre><pre>ccEmlPxy.dll</pre><pre>ccGLog.dll</pre><pre>ccJobMgr.dll</pre><pre>ccGEvt.dll</pre><pre>ccIPC.dll</pre><pre>ccRkSn.dll</pre><pre>PFPriv.dll</pre><pre>ccPxyIns.dll</pre><pre>ccPxyEvt.dll</pre><pre>ccInst64.dll</pre><pre>ccEvtCli.dll</pre><pre>ccTrstPc.dll</pre><pre>ccSvc.dll</pre><pre>ccEraser.dll</pre><pre>OEHeur.dll</pre><pre>ccCharCv.dll</pre><pre>ccInst.dll</pre><pre>DefUtDCD.dll</pre><pre>ccScanw.dll</pre><pre>ccScan.dll</pre><pre>dec_abi.dll</pre><pre>ccDec.dll</pre><pre>ccALEng.dll</pre><pre>ccErrDsp.dll</pre><pre>ccProSub.dll</pre><pre>ccVrTrst.dll</pre><pre>ccSetEvt.dll</pre><pre>ccSet.dll</pre><pre>ccAlert.dll</pre><pre>F..\Source\ccArchive.cpp</pre><pre>E..\Source\ccDummyArchive.cpp</pre><pre>..\Source\ccInstanceFactory.cpp</pre><pre>..\Source\ccSymValueCollectionConvert.cpp</pre><pre>E..\Source\ccSymStreamArchive.cpp</pre><pre>Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>JÌROOT%\</pre><pre>ÌDATA%\</pre><pre>..\Source\ccSymInstalledApps.cpp</pre><pre>E..\Source\ccSymDigest.cpp</pre><pre>..\Source\ccSymKeyValueCollectionImpl.cpp</pre><pre>..\Source\ccSymMemoryImpl.cpp</pre><pre>Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE</pre><pre>Archive.Read(nVersion) == FALSE</pre><pre>..\Source\ccSymStringImpl.cpp</pre><pre>Archive.Write(CStringImpl::Version) == FALSE</pre><pre>..\Source\ccSymInstanceFactoryImpl.cpp</pre><pre>..\Source\ccSymKeyValueCollection.cpp</pre><pre>..\Source\ccSymPersist.cpp</pre><pre>ÌROOT%\ccSet.dll</pre><pre>F..\Source\ccSymObjectRepository.cpp</pre><pre>CommonClient\OBJID\%s</pre><pre>F..\Source\ccMemoryArchive.cpp</pre><pre>F..\Source\ccSymMemoryStreamImpl.cpp</pre><pre>mscoree.dll</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>ADVAPI32.DLL</pre><pre>WUSER32.DLL</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymCCISExe.exe</pre><pre>{8856F961-340A-11D0-A96B-00C04FD705A2}</pre><pre>Exit.Norton Product Installer encountered an error.</pre><pre>Install Complete!]Norton Safe Web Lite will provide website safety information next time you open your browser.</pre><pre>We cannot download this product because your system did not meet the installation requirements or you are not logged in as an Administrator.CNorton Product Installer could not start your default web browser.</pre><pre>You already have %s on your computer. This protection exceeds that provided by Norton Security Scan. Please continue to use your %s_We cannot download this product because your system did not meet the installation requirements.</pre><b>SymCCISExe.exe_1560_rwx_09E10000_00002000:</b><pre>The procedure %s could not be located in the DLL %s.</pre><pre>The ordinal %d could not be located in the DLL %s.</pre><b>SymCCISExe.exe_1560_rwx_0A4E0000_00002000:</b><pre>The procedure %s could not be located in the DLL %s.</pre><pre>The ordinal %d could not be located in the DLL %s.</pre><b>SymInstallStub.exe_1788:</b><pre>.text</pre><pre>`.rsrc</pre><pre>.reloc</pre><pre>8%u,j</pre><pre>QSSSSSSh</pre><pre>t.HuX</pre><pre>t%SWh</pre><pre>xSSSh</pre><pre>FTPjKS</pre><pre>FtPj;S</pre><pre>C.PjRV</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>3.6.1.16</pre><pre>1.3.6.1.4.1.311.10.3.5</pre><pre>1.3.6.1.4.1.311.10.3.6</pre><pre>1.3.6.1.5.5.7.3.3</pre><pre>2.5.4.6</pre><pre>2.5.4.8</pre><pre>2.5.4.7</pre><pre>2.5.4.10</pre><pre>2.5.4.11</pre><pre>2.5.4.3</pre><pre>WINTRUST.dll</pre><pre>CRYPT32.dll</pre><pre>{X-X-X-XX-XXXXXX}</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>GetProcessWindowStation</pre><pre>portuguese-brazilian</pre><pre>Broken pipe</pre><pre>Inappropriate I/O control operation</pre><pre>Operation not permitted</pre><pre>operator</pre><pre>CryptCATCatalogInfoFromContext</pre><pre>CertFreeCertificateContext</pre><pre>CertCompareIntegerBlob</pre><pre>CryptHashCertificate</pre><pre>CryptMsgClose</pre><pre>CertCloseStore</pre><pre>CertFindCertificateInStore</pre><pre>CryptMsgGetParam</pre><pre>CertGetEnhancedKeyUsage</pre><pre>CertNameToStrW</pre><pre>CertGetNameStringW</pre><pre>RPCRT4.dll</pre><pre>Secur32.dll</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>RegOpenKeyExW</pre><pre>RegCreateKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>RegQueryInfoKeyW</pre><pre>RegEnumKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteExW</pre><pre>SHFileOperationW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>COMCTL32.dll</pre><pre>GdiplusShutdown</pre><pre>gdiplus.dll</pre><pre>WinHttpConnect</pre><pre>WinHttpSetOption</pre><pre>WinHttpOpen</pre><pre>WinHttpQueryOption</pre><pre>WinHttpAddRequestHeaders</pre><pre>WinHttpReceiveResponse</pre><pre>WinHttpReadData</pre><pre>WinHttpQueryDataAvailable</pre><pre>WinHttpQueryHeaders</pre><pre>WinHttpWriteData</pre><pre>WinHttpCloseHandle</pre><pre>WinHttpSetStatusCallback</pre><pre>WinHttpSetCredentials</pre><pre>WinHttpGetProxyForUrl</pre><pre>WinHttpSendRequest</pre><pre>WinHttpOpenRequest</pre><pre>WinHttpCrackUrl</pre><pre>WINHTTP.dll</pre><pre>USERENV.dll</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>SHDeleteKeyW</pre><pre>SHDeleteEmptyKeyW</pre><pre>.?AUWinHTTPProgressCallback@DING@@</pre><pre>.?AVCWinHTTPClient@installstub@@</pre><pre>.?AVCWinHTTPClient@DING@@</pre><pre>.?AUProgressCallback@CWinHTTPEngine@installstub@@</pre><pre>zcÁ</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"></compatibility></assembly></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre>kernel32.dll</pre><pre>SymInstallStub.config.txt</pre><pre>SymInstallStub.state.dat</pre><pre>MSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/IS/</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Staging/IS/</pre><pre>http://cps.qalabs.symantec.com/teams/ISP/SymCCIS/IS/</pre><pre>Connections\Proxy\HTTP</pre><pre>Connections\Proxy\HTTPS</pre><pre>Connections\Proxy\FTP</pre><pre>Manual_Proxy_Port</pre><pre>Password</pre><pre>Auto_Config_URL</pre><pre>Proxy_Bypass</pre><pre>Advapi32.dll</pre><pre>C:\bld_area\NSSInstallStub_r3.6.1\SDK\CC\include\SymInterface.h</pre><pre>&y=%d</pre><pre>&q=%s</pre><pre>&m=%s</pre><pre>&j=%s</pre><pre>&i=%s</pre><pre>&g=%d</pre><pre>&f=%s</pre><pre>&e=%d</pre><pre>&b=%s</pre><pre>&a=%s</pre><pre>&MID=%s</pre><pre>&language=X.X</pre><pre>&os=%u.%u.%u.%u.%u</pre><pre>&version=%s</pre><pre>&product=%s</pre><pre>?module=%s</pre><pre>http://stats.norton.com/n/p</pre><pre>pVerifyTrust->VerifyFile failed, error = %d</pre><pre>pVerifyTrust->Create failed, error = %d</pre><pre>Failed to open AFF_ID reg key</pre><pre>strProductID = %s ; strRegAffID=%s</pre><pre>Affiliate ID was not passed</pre><pre>Not able to open SWL root key : SOFTWARE\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}</pre><pre>NSSInstall key created, Not able to set NSSInstall=1</pre><pre>Create NSSInstall key for SWL</pre><pre>installstub::Controller::setSWLBundledWithNSSRegKey</pre><pre>NSSInstall key already exists!</pre><pre>SOFTWARE\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}</pre><pre>Failed to open reg key</pre><pre>installstub::Controller::getProductListFromCmdLine</pre><pre>PartnerID passed as generic. Updating it to be symantec</pre><pre>installstub::Controller::getPartnerIDFromCmdLine</pre><pre>rinstallstub::PINGPACKET::ReportProductInstallResults</pre><pre>Sending Product Install Ping Event for, Product ID = %s, Ping URL = %s</pre><pre>&d=%s</pre><pre>&t=%s</pre><pre>&l=%s</pre><pre>&h=%d</pre><pre>&o=0xx</pre><pre>&n=0xx</pre><pre>&k=%s</pre><pre>&error=%d</pre><pre>&v=%d</pre><pre>&z=%d</pre><pre>installstub::PINGPACKET::ReportInstallstubResult</pre><pre>Sending InstallStub Exit Ping Event, Ping URL = %s</pre><pre>Source URL is empty</pre><pre>/%s=%s</pre><pre>/%s=%d</pre><pre>Delay = %d minutes</pre><pre>Could not open affid partner registry key: %s.</pre><pre>Could not open affid registry key: %s.</pre><pre>Failed to delete partners affid subkey: %s.</pre><pre>Failed to delete affid product: %s.</pre><pre>Sucessfully built Source URL</pre><pre>installstub::Controller::buildSourceURL</pre><pre>Sucessfully built Dest URL</pre><pre>Product ID = %s, State = %d</pre><pre>Failed to get Product object = %s</pre><pre>Command line passed in =</pre><pre>safeweblite</pre><pre>Install was successful for Product ID= %s. Updating Product Install Count registry entry.</pre><pre>Succcessfully downloaded %s from %s</pre><pre>Failed to delete unsigned File, hr = 0xx, GetLastError() = %ld</pre><pre>File already downloaded, not Symantec signed, Path : %s</pre><pre>File already downloaded, Symantec signed, Path %s</pre><pre>installstub::Controller::ValidateCmdLineForProduct</pre><pre>There were no products to download - vecProducts.size() = 0</pre><pre>Failed to download product: %s, hr = 0xx</pre><pre>Third attempt : Error downloading Product ID = %s from Default folder, hr = 0xx</pre><pre>Second attempt : Error downloading Product ID = %s, hr = 0xx</pre><pre>First attempt : Error downloading Product ID = %s, hr = 0xx</pre><pre>Downloading Product ID = %s</pre><pre>There were no products to install - vecProducts.size() = 0</pre><pre>Successfully installed product: %s, dwResult = %lu</pre><pre>Failed to install product: %s, return code = %lu</pre><pre>Failed to install product: %s, HRESULT = 0xx</pre><pre>Installing, Product ID = %s</pre><pre>Skipping Delete. FileExists returned false: %s</pre><pre>FileExists returned true. Deleting file: %s</pre><pre>Attempting to Delete: %s</pre><pre>Runonce key not present</pre><pre>Run once key deleted</pre><pre>Failed to delete run once key</pre><pre>FATAL error occurred, installStubErrorCode = %d</pre><pre>Delay download by = %d minutes</pre><pre>Recoverable error occurred, installStubErrorCode = %d</pre><pre>SymInstallStub exe</pre><pre>SymInstallStubIdle exe</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>Fallback key successfully deleted.</pre><pre>Failed to delete Fallback key.</pre><pre>Fallback key present. Deleting.</pre><pre>Run once key already exists.</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</pre><pre>Cookie: %s</pre><pre>Mozilla\Firefox\%s</pre><pre>Mozilla\Firefox\Profiles.ini</pre><pre>%s:%lu</pre><pre>%s://%s%s</pre><pre>https</pre><pre>0xX</pre><pre>DING_WinHttpClient.cpp</pre><pre>http=</pre><pre>AutoConfigURL</pre><pre>X-Symc-Local-User-Id: %s</pre><pre>X-Symc-Machine-Id: %s</pre><pre>network.proxy.autoconfig_url</pre><pre>network.proxy.http_port</pre><pre>network.proxy.http</pre><pre>network.proxy.type</pre><pre>network.proxy</pre><pre>prefs.js</pre><pre>user.js</pre><pre>FIREFOX</pre><pre>http\shell\open\command</pre><pre>CDownloadManager.DownloadFile returned</pre><pre>Starting HTTP engine</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>IbPortuguese</pre><pre>BrPortuguese</pre><pre>GUID set to: %s</pre><pre>Not able to create install count for %s</pre><pre>Not able to set install count for %s</pre><pre>First time, create the key and write the value for %s</pre><pre>%s -- Not able to set install count for %s</pre><pre>Not able to open install date. Either it does not exist or regkey open failed.</pre><pre>Getting install date from: %s</pre><pre>First time, create the key and write the value</pre><pre>Unable to read retry count key.</pre><pre>Unable to delete file: %s =</pre><pre>%m/%d/%Y</pre><pre>Cc:\bld_area\nssinstallstub_r3.6.1\sdk\cc\include\SymInterface.h</pre><pre>installstub::HTTPDownloadData::CloseFileStream</pre><pre>installstub::HTTPDownloadData::Initialize</pre><pre>WinHttpReadData failed</pre><pre>WinHttpQueryDataAvailable failed</pre><pre>installstub::CWinHTTPClient::GetResponse</pre><pre>Destroying CWinHTTPEngine</pre><pre>installstub::CWinHTTPEngine::~CWinHTTPEngine</pre><pre>installstub::CWinHTTPEngine::Initialize</pre><pre>DeleteFile failed to delete %s, dwResult = %lu</pre><pre>installstub::CWinHTTPEngine::getTempFilePath</pre><pre>Server supports partial download resuming download</pre><pre>Error Unexpected http response status %d</pre><pre>Received HTTP STATUS = %d while expecting partial response</pre><pre>installstub::CWinHTTPEngine::prepareResponseData</pre><pre>Creating CWinHTTPEngine...</pre><pre>installstub::CWinHTTPEngine::CWinHTTPEngine</pre><pre>Failed to move %s to %s, hr=0xX</pre><pre>File Name %s[size %I64u]</pre><pre>Remaining download content - %I64u, downloaded - %I64u for file %s</pre><pre>Download for %s was already started, bytes - %I64u</pre><pre>installstub::CWinHTTPEngine::Download</pre><pre>SymInstallStub.txt</pre><pre>C%s%s</pre><pre>[ %s ] ... %s</pre><pre>[s d, d - d:d:d:d]</pre><pre>%s = %s</pre><pre>%s , HR = 0xX</pre><pre>%s , dwResult = %lu</pre><pre>%s , HR = 0xX, dwResult = %lu</pre><pre>%s = %s, HR = 0xX, dwResult = %lu</pre><pre>installstub::ProcessLauncher::launchProcessWithShellExecute</pre><pre>Scheduled Task File: %s</pre><pre>Total nodes validated : %d</pre><pre>Succeeded nodes : %d</pre><pre>Failed nodes : %d</pre><pre>%s[%d]-></pre><pre>..\..\SDK\JSONCPP\src\json_reader.cpp</pre><pre>Line %d, Column %d</pre><pre>..\..\SDK\JSONCPP\src\json_value.cpp</pre><pre>(*it).type() == Json::stringValue</pre><pre>int(indentString_.size()) >= indentSize_</pre><pre>..\..\SDK\JSONCPP\src\json_writer.cpp</pre><pre>childValues_.size() == size</pre><pre>%SymEFA%</pre><pre>EFACli.dll</pre><pre>..\Source\ccVerifyTrustStatic.cpp</pre><pre>ICLSID\%s\LocalServer32</pre><pre>CLSID\%s\InprocServer32</pre><pre>ENTDLL.DLL</pre><pre>..\Source\ccVerifyTrustImpl.cpp</pre><pre>..\Source\FileCache.cpp</pre><pre>E..\Source\VerifyFile.cpp</pre><pre>..\Source\ccVerifyTrustPolicy.cpp</pre><pre>..\Source\CatalogIterator.cpp</pre><pre>..\Source\CatalogFileHash.cpp</pre><pre>WinTrust.dll</pre><pre>..\Source\CatalogContext.cpp</pre><pre>..\Source\ccSymModuleLifetimeMgrImpl.cpp</pre><pre>E..\Source\ccMemory.cpp</pre><pre>E..\Source\ccFile.cpp</pre><pre>EÌROOT%</pre><pre>rcPFRes.dll</pre><pre>rcPxyEvt.dll</pre><pre>rcProxy.dll</pre><pre>rcSvcHst.dll</pre><pre>rcEmlPxy.dll</pre><pre>rcLgView.dll</pre><pre>rcErrDsp.dll</pre><pre>rcAlert.dll</pre><pre>rcApp.dll</pre><pre>ccEmlPxy.dll</pre><pre>ccGLog.dll</pre><pre>ccJobMgr.dll</pre><pre>ccGEvt.dll</pre><pre>ccIPC.dll</pre><pre>ccRkSn.dll</pre><pre>PFPriv.dll</pre><pre>ccPxyIns.dll</pre><pre>ccPxyEvt.dll</pre><pre>ccInst64.dll</pre><pre>ccEvtCli.dll</pre><pre>ccTrstPc.dll</pre><pre>ccSvc.dll</pre><pre>ccEraser.dll</pre><pre>OEHeur.dll</pre><pre>ccCharCv.dll</pre><pre>ccInst.dll</pre><pre>DefUtDCD.dll</pre><pre>ccScanw.dll</pre><pre>ccScan.dll</pre><pre>dec_abi.dll</pre><pre>ccDec.dll</pre><pre>ccALEng.dll</pre><pre>ccErrDsp.dll</pre><pre>ccProSub.dll</pre><pre>ccVrTrst.dll</pre><pre>ccSetEvt.dll</pre><pre>ccSet.dll</pre><pre>ccAlert.dll</pre><pre>..\Source\ccStringConvert.cpp</pre><pre>..\Source\ccSymMemoryStreamImpl.cpp</pre><pre>F%s, %s, %s, %s(%ld)</pre><pre>F..\Source\ccRegistry.cpp</pre><pre>%s\%s</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED</pre><pre>isolate.ini</pre><pre>%COMMON_SILO_DATA%</pre><pre>F..\Source\ccOSInfo.cpp</pre><pre>\wpeutil.dll</pre><pre>\FACTORY.exe</pre><pre>\wpeinit.exe</pre><pre>\\?\UNC</pre><pre>F..\Source\ccSplitPath.cpp</pre><pre>F..\Source\ccSymFileStreamImpl.cpp</pre><pre>F..\Source\ccModule.cpp</pre><pre>F..\Source\ccSystemInfo.cpp</pre><pre>CSIDL_WINDOWS</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>..\Source\ccPathExpansion.cpp</pre><pre>..\Source\ccWow64FsRedirection.cpp</pre><pre>..\Source\ccEncryptedString.cpp</pre><pre>G..\Source\ccSymDllLifetimeMgr.cpp</pre><pre>I..\Source\ccSynchronize.cpp</pre><pre>Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>NÌROOT%\</pre><pre>ÌDATA%\</pre><pre>..\Source\ccSymInstalledApps.cpp</pre><pre>t..\Source\ccMessageLock.cpp</pre><pre>..\Source\ccSymIndexValueCollectionImpl.cpp</pre><pre>AWTSAPI32.DLL</pre><pre>KERNEL32.DLL</pre><pre>GPSAPI.DLL</pre><pre>..\Source\ccPEBReader.cpp</pre><pre>G..\Source\ccPrivilege.cpp</pre><pre>E..\Source\ccSymDllLifetimeMgrLocal.cpp</pre><pre>..\Source\ccSymIndexValueCollection.cpp</pre><pre>..\Source\ccSymValueCollection.cpp</pre><pre>I..\Source\ccArchive.cpp</pre><pre>H..\Source\ccDummyArchive.cpp</pre><pre>..\Source\ccInstanceFactory.cpp</pre><pre>..\Source\ccSymValueCollectionConvert.cpp</pre><pre>H..\Source\ccSymStreamArchive.cpp</pre><pre>H..\Source\ccSymDigest.cpp</pre><pre>..\Source\ccSymKeyValueCollectionImpl.cpp</pre><pre>..\Source\ccSymMemoryImpl.cpp</pre><pre>Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE</pre><pre>Archive.Read(nVersion) == FALSE</pre><pre>..\Source\ccSymStringImpl.cpp</pre><pre>Archive.Write(CStringImpl::Version) == FALSE</pre><pre>..\Source\ccSymInstanceFactoryImpl.cpp</pre><pre>..\Source\ccSymKeyValueCollection.cpp</pre><pre>..\Source\ccSymPersist.cpp</pre><pre>ÌROOT%\ccSet.dll</pre><pre>I..\Source\ccSymObjectRepository.cpp</pre><pre>CommonClient\OBJID\%s</pre><pre>I..\Source\ccMemoryArchive.cpp</pre><pre>mscoree.dll</pre><pre>WUSER32.DLL</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>ADVAPI32.DLL</pre><pre>Assertion failed: %s, file %s, line %d</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymInstallStub.exe</pre><pre>/* Symantec Watermark: CB70-2826-1157-06-15-1 */</pre><pre>(0-3-000082</pre><pre>9VfL6qO3;J8HB.hwJ?l</pre><b>SymCCISExe.exe_1560_rwx_10001000_00082000:</b><pre>SSSSh</pre><pre>tcPW</pre><pre>QSSSSSSh</pre><pre>t%SWh</pre><pre>1.3.6.1.4.1.311.10.3.5</pre><pre>1.3.6.1.4.1.311.10.3.6</pre><pre>1.3.6.1.5.5.7.3.3</pre><pre>2.5.4.6</pre><pre>2.5.4.8</pre><pre>2.5.4.7</pre><pre>2.5.4.10</pre><pre>2.5.4.11</pre><pre>2.5.4.3</pre><pre>WINTRUST.dll</pre><pre>CRYPT32.dll</pre><pre>{X-X-X-XX-XXXXXX}</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>SCC_CheckCriteria_Web</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>2.1.0.20</pre><pre>CryptCATCatalogInfoFromContext</pre><pre>CryptMsgClose</pre><pre>CertCloseStore</pre><pre>CertFreeCertificateContext</pre><pre>CertFindCertificateInStore</pre><pre>CryptMsgGetParam</pre><pre>CertGetEnhancedKeyUsage</pre><pre>CertNameToStrW</pre><pre>CertGetNameStringW</pre><pre>URLOpenStreamW</pre><pre>urlmon.dll</pre><pre>DeleteUrlCacheEntryW</pre><pre>HttpOpenRequestW</pre><pre>HttpAddRequestHeadersW</pre><pre>HttpSendRequestW</pre><pre>WININET.dll</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCreateKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteExW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>SHLWAPI.dll</pre><pre>USERENV.dll</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>RegEnumKeyExW</pre><pre>RegQueryInfoKeyW</pre><pre>OLEAUT32.dll</pre><pre>SHDeleteKeyW</pre><pre>SHDeleteEmptyKeyW</pre><pre>SYMCCIS.dll</pre><pre>zcÁ</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymCCISExe.exe</pre><pre>0xX</pre><pre>..\Source\ccVerifyTrustStatic.cpp</pre><pre>%SymEFA%</pre><pre>EFACli.dll</pre><pre>CLSID\%s\LocalServer32</pre><pre>CLSID\%s\InprocServer32</pre><pre>NTDLL.DLL</pre><pre>..\Source\ccVerifyTrustImpl.cpp</pre><pre>..\Source\FileCache.cpp</pre><pre>g..\Source\VerifyFile.cpp</pre><pre>..\Source\ccVerifyTrustPolicy.cpp</pre><pre>..\Source\CatalogIterator.cpp</pre><pre>..\Source\CatalogFileHash.cpp</pre><pre>WinTrust.dll</pre><pre>..\Source\CatalogContext.cpp</pre><pre>..\Source\ccSymModuleLifetimeMgrImpl.cpp</pre><pre>%s, %s, %s, %s(%ld)</pre><pre>..\Source\ccModule.cpp</pre><pre>..\Source\ccSystemInfo.cpp</pre><pre>..\Source\ccRegistry.cpp</pre><pre>..\Source\ccStringConvert.cpp</pre><pre>CSIDL_WINDOWS</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>..\Source\ccPathExpansion.cpp</pre><pre>\\?\UNC</pre><pre>..\Source\ccSplitPath.cpp</pre><pre>..\Source\ccOSInfo.cpp</pre><pre>\wpeutil.dll</pre><pre>\FACTORY.exe</pre><pre>\wpeinit.exe</pre><pre>..\Source\ccMemory.cpp</pre><pre>..\Source\ccFile.cpp</pre><pre>..\Source\ccWow64FsRedirection.cpp</pre><pre>%s\%s</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED</pre><pre>isolate.ini</pre><pre>%COMMON_SILO_DATA%</pre><pre>..\Source\ccEncryptedString.cpp</pre><pre>..\Source\ccSynchronize.cpp</pre><pre>..\Source\ccSymDllLifetimeMgr.cpp</pre><pre>kernel32.dll</pre><pre>KERNEL32.DLL</pre><pre>PSAPI.DLL</pre><pre>..\Source\ccPEBReader.cpp</pre><pre>..\Source\ccPrivilege.cpp</pre><pre>..\Source\ccSymIndexValueCollectionImpl.cpp</pre><pre>AWTSAPI32.DLL</pre><pre>..\Source\ccSymDllLifetimeMgrLocal.cpp</pre><pre>..\Source\ccSymIndexValueCollection.cpp</pre><pre>..\Source\ccSymValueCollection.cpp</pre><pre>ÌROOT%</pre><pre>rcPFRes.dll</pre><pre>rcPxyEvt.dll</pre><pre>rcProxy.dll</pre><pre>rcSvcHst.dll</pre><pre>rcEmlPxy.dll</pre><pre>rcLgView.dll</pre><pre>rcErrDsp.dll</pre><pre>rcAlert.dll</pre><pre>rcApp.dll</pre><pre>ccEmlPxy.dll</pre><pre>ccGLog.dll</pre><pre>ccJobMgr.dll</pre><pre>ccGEvt.dll</pre><pre>ccIPC.dll</pre><pre>ccRkSn.dll</pre><pre>PFPriv.dll</pre><pre>ccPxyIns.dll</pre><pre>ccPxyEvt.dll</pre><pre>ccInst64.dll</pre><pre>ccEvtCli.dll</pre><pre>ccTrstPc.dll</pre><pre>ccSvc.dll</pre><pre>ccEraser.dll</pre><pre>OEHeur.dll</pre><pre>ccCharCv.dll</pre><pre>ccInst.dll</pre><pre>DefUtDCD.dll</pre><pre>ccScanw.dll</pre><pre>ccScan.dll</pre><pre>dec_abi.dll</pre><pre>ccDec.dll</pre><pre>ccALEng.dll</pre><pre>ccErrDsp.dll</pre><pre>ccProSub.dll</pre><pre>ccVrTrst.dll</pre><pre>ccSetEvt.dll</pre><pre>ccSet.dll</pre><pre>ccAlert.dll</pre><pre>..\Source\ccArchive.cpp</pre><pre>..\Source\ccDummyArchive.cpp</pre><pre>..\Source\ccInstanceFactory.cpp</pre><pre>..\Source\ccSymValueCollectionConvert.cpp</pre><pre>..\Source\ccSymStreamArchive.cpp</pre><pre>Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>ÌROOT%\</pre><pre>ÌDATA%\</pre><pre>..\Source\ccSymInstalledApps.cpp</pre><pre>..\Source\ccSymDigest.cpp</pre><pre>..\Source\ccSymKeyValueCollectionImpl.cpp</pre><pre>..\Source\ccSymMemoryImpl.cpp</pre><pre>Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE</pre><pre>Archive.Read(nVersion) == FALSE</pre><pre>..\Source\ccSymStringImpl.cpp</pre><pre>Archive.Write(CStringImpl::Version) == FALSE</pre><pre>..\Source\ccSymInstanceFactoryImpl.cpp</pre><pre>t..\Source\ccMessageLock.cpp</pre><pre>..\Source\ccSymKeyValueCollection.cpp</pre><pre>..\Source\ccSymPersist.cpp</pre><pre>ÌROOT%\ccSet.dll</pre><pre>..\Source\ccSymObjectRepository.cpp</pre><pre>CommonClient\OBJID\%s</pre><pre>..\Source\ccMemoryArchive.cpp</pre><pre>..\Source\ccSymMemoryStreamImpl.cpp</pre><pre>mscoree.dll</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>WUSER32.DLL</pre><pre>FileDownloader::callURLOpenStream</pre><pre>CHttpRequest::CHttpRequest</pre><pre>CHttpRequest::~CHttpRequest</pre><pre>CHttpRequest::RequestPage</pre><pre>CHttpRequest::ParseURLW</pre><pre>https</pre><pre>[s d, d - d:d:d:d]</pre><pre>%s %ld</pre><pre>%s %s</pre><pre>%s 0x%x</pre><pre>http://cps.qalabs.symantec.com/teams/isp/symccis</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Staging</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production</pre><pre>SymCCIS.dll</pre><pre>SCC.dll</pre><pre>OfferUI.dll</pre><pre>SymInstallStub.exe</pre><pre>SymCCISDll.txt</pre><pre>Total CheckCriteria execution time in seconds =</pre><pre>NortonOfferEngineImpl::CheckCriteria_Web</pre><pre>downloadStubInstallerExe() failed, HR =</pre><pre>Failed to delete downloaded SCC.dll, GetLastError =</pre><pre>Failed to delete existing SCC.dll, GetLastError =</pre><pre>NortonOfferEngineImpl::downloadStubInstallerExe</pre><pre>Failed to delete existing SymInstallStub.exe, GetLastError =</pre><pre>NortonOfferEngineImpl::buildComponentDownloadURL</pre><pre>NortonOfferEngineImpl::getTestEnvironmentRootURL</pre><pre>NortonOfferEngineImpl::getISExeDestPath</pre><pre>getISExeDestPath() returned =</pre><pre>NortonOfferEngineImpl::sendPingForCheckCriteriaWeb</pre><pre>NortonOfferEngineImpl::getCheckCriteriaPingDataWeb</pre><pre>NortonOfferEngineImpl::getStubInstallerCmdLine</pre><pre>getStubInstallerCmdLine() returned =</pre><pre>NortonOfferEngineImpl::deleteDeclineCountRegKeyForThisProduct</pre><pre>NortonOfferEngineImpl::deleteDeclineCountParentKeyIfNoMoreProductsExist</pre><pre>Deleting DeclineCount subkey for partner =</pre><pre>Failed to create/open DECLINE_COUNT_REG_KEY</pre><pre>Advapi32.dll</pre><pre>http://stats.norton.com/n/p?</pre><pre>PingData::SendCheckCriteriaWebPing</pre><pre>PingData::createBaseURL</pre><pre>PingData::getCheckCriteriaPingURL</pre><pre>PingData::getCheckCriteriaWebPingURL</pre><pre>PingData::getInstallProductsPingURL</pre><pre>PingData::getOfferAcceptancePingURL</pre><pre>pingURL =</pre><pre>X.X</pre><pre>%u.%u.%u.%u.%u</pre><pre>Utility::LaunchProcessWithShellExecute</pre><pre>ShellExecuteEx failed, GetLastError =</pre><pre>---8#-8-@</pre><b>SymCCISExe.exe_1560_rwx_10084000_00002000:</b><pre><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></pre><pre>NRTN_OfferEngine_CheckCriteria_Web</pre><pre>kernel32.dll</pre><pre>urlmon.dll</pre><pre>URLOpenStreamW</pre><pre>WININET.dll</pre><pre>USER32.dll</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>SHLWAPI.dll</pre><pre>USERENV.dll</pre><pre>OLEAUT32.dll</pre><pre>2.1.0.20</pre><b>SymInstallStub.exe_1788_rwx_00401000_00116000:</b><pre>8%u,j</pre><pre>QSSSSSSh</pre><pre>t.HuX</pre><pre>t%SWh</pre><pre>xSSSh</pre><pre>FTPjKS</pre><pre>FtPj;S</pre><pre>C.PjRV</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>3.6.1.16</pre><pre>1.3.6.1.4.1.311.10.3.5</pre><pre>1.3.6.1.4.1.311.10.3.6</pre><pre>1.3.6.1.5.5.7.3.3</pre><pre>2.5.4.6</pre><pre>2.5.4.8</pre><pre>2.5.4.7</pre><pre>2.5.4.10</pre><pre>2.5.4.11</pre><pre>2.5.4.3</pre><pre>WINTRUST.dll</pre><pre>CRYPT32.dll</pre><pre>{X-X-X-XX-XXXXXX}</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>GetProcessWindowStation</pre><pre>portuguese-brazilian</pre><pre>Broken pipe</pre><pre>Inappropriate I/O control operation</pre><pre>Operation not permitted</pre><pre>operator</pre><pre>CryptCATCatalogInfoFromContext</pre><pre>CertFreeCertificateContext</pre><pre>CertCompareIntegerBlob</pre><pre>CryptHashCertificate</pre><pre>CryptMsgClose</pre><pre>CertCloseStore</pre><pre>CertFindCertificateInStore</pre><pre>CryptMsgGetParam</pre><pre>CertGetEnhancedKeyUsage</pre><pre>CertNameToStrW</pre><pre>CertGetNameStringW</pre><pre>RPCRT4.dll</pre><pre>Secur32.dll</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>RegOpenKeyExW</pre><pre>RegCreateKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>RegQueryInfoKeyW</pre><pre>RegEnumKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteExW</pre><pre>SHFileOperationW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>COMCTL32.dll</pre><pre>GdiplusShutdown</pre><pre>gdiplus.dll</pre><pre>WinHttpConnect</pre><pre>WinHttpSetOption</pre><pre>WinHttpOpen</pre><pre>WinHttpQueryOption</pre><pre>WinHttpAddRequestHeaders</pre><pre>WinHttpReceiveResponse</pre><pre>WinHttpReadData</pre><pre>WinHttpQueryDataAvailable</pre><pre>WinHttpQueryHeaders</pre><pre>WinHttpWriteData</pre><pre>WinHttpCloseHandle</pre><pre>WinHttpSetStatusCallback</pre><pre>WinHttpSetCredentials</pre><pre>WinHttpGetProxyForUrl</pre><pre>WinHttpSendRequest</pre><pre>WinHttpOpenRequest</pre><pre>WinHttpCrackUrl</pre><pre>WINHTTP.dll</pre><pre>USERENV.dll</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>SHDeleteKeyW</pre><pre>SHDeleteEmptyKeyW</pre><pre>.?AUWinHTTPProgressCallback@DING@@</pre><pre>.?AVCWinHTTPClient@installstub@@</pre><pre>.?AVCWinHTTPClient@DING@@</pre><pre>.?AUProgressCallback@CWinHTTPEngine@installstub@@</pre><pre>zcÁ</pre><pre>SymInstallStub.config.txt</pre><pre>SymInstallStub.state.dat</pre><pre>MSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Production/IS/</pre><pre>http://liveupdate.symantecliveupdate.com/upgrade/NSS/SymCCIS/Staging/IS/</pre><pre>http://cps.qalabs.symantec.com/teams/ISP/SymCCIS/IS/</pre><pre>Connections\Proxy\HTTP</pre><pre>Connections\Proxy\HTTPS</pre><pre>Connections\Proxy\FTP</pre><pre>Manual_Proxy_Port</pre><pre>Password</pre><pre>Auto_Config_URL</pre><pre>Proxy_Bypass</pre><pre>Advapi32.dll</pre><pre>C:\bld_area\NSSInstallStub_r3.6.1\SDK\CC\include\SymInterface.h</pre><pre>&y=%d</pre><pre>&q=%s</pre><pre>&m=%s</pre><pre>&j=%s</pre><pre>&i=%s</pre><pre>&g=%d</pre><pre>&f=%s</pre><pre>&e=%d</pre><pre>&b=%s</pre><pre>&a=%s</pre><pre>&MID=%s</pre><pre>&language=X.X</pre><pre>&os=%u.%u.%u.%u.%u</pre><pre>&version=%s</pre><pre>&product=%s</pre><pre>?module=%s</pre><pre>http://stats.norton.com/n/p</pre><pre>pVerifyTrust->VerifyFile failed, error = %d</pre><pre>pVerifyTrust->Create failed, error = %d</pre><pre>Failed to open AFF_ID reg key</pre><pre>strProductID = %s ; strRegAffID=%s</pre><pre>Affiliate ID was not passed</pre><pre>Not able to open SWL root key : SOFTWARE\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}</pre><pre>NSSInstall key created, Not able to set NSSInstall=1</pre><pre>Create NSSInstall key for SWL</pre><pre>installstub::Controller::setSWLBundledWithNSSRegKey</pre><pre>NSSInstall key already exists!</pre><pre>SOFTWARE\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}</pre><pre>Failed to open reg key</pre><pre>installstub::Controller::getProductListFromCmdLine</pre><pre>PartnerID passed as generic. Updating it to be symantec</pre><pre>installstub::Controller::getPartnerIDFromCmdLine</pre><pre>rinstallstub::PINGPACKET::ReportProductInstallResults</pre><pre>Sending Product Install Ping Event for, Product ID = %s, Ping URL = %s</pre><pre>&d=%s</pre><pre>&t=%s</pre><pre>&l=%s</pre><pre>&h=%d</pre><pre>&o=0xx</pre><pre>&n=0xx</pre><pre>&k=%s</pre><pre>&error=%d</pre><pre>&v=%d</pre><pre>&z=%d</pre><pre>installstub::PINGPACKET::ReportInstallstubResult</pre><pre>Sending InstallStub Exit Ping Event, Ping URL = %s</pre><pre>Source URL is empty</pre><pre>/%s=%s</pre><pre>/%s=%d</pre><pre>Delay = %d minutes</pre><pre>Could not open affid partner registry key: %s.</pre><pre>Could not open affid registry key: %s.</pre><pre>Failed to delete partners affid subkey: %s.</pre><pre>Failed to delete affid product: %s.</pre><pre>Sucessfully built Source URL</pre><pre>installstub::Controller::buildSourceURL</pre><pre>Sucessfully built Dest URL</pre><pre>Product ID = %s, State = %d</pre><pre>Failed to get Product object = %s</pre><pre>Command line passed in =</pre><pre>safeweblite</pre><pre>Install was successful for Product ID= %s. Updating Product Install Count registry entry.</pre><pre>Succcessfully downloaded %s from %s</pre><pre>Failed to delete unsigned File, hr = 0xx, GetLastError() = %ld</pre><pre>File already downloaded, not Symantec signed, Path : %s</pre><pre>File already downloaded, Symantec signed, Path %s</pre><pre>installstub::Controller::ValidateCmdLineForProduct</pre><pre>There were no products to download - vecProducts.size() = 0</pre><pre>Failed to download product: %s, hr = 0xx</pre><pre>Third attempt : Error downloading Product ID = %s from Default folder, hr = 0xx</pre><pre>Second attempt : Error downloading Product ID = %s, hr = 0xx</pre><pre>First attempt : Error downloading Product ID = %s, hr = 0xx</pre><pre>Downloading Product ID = %s</pre><pre>There were no products to install - vecProducts.size() = 0</pre><pre>Successfully installed product: %s, dwResult = %lu</pre><pre>Failed to install product: %s, return code = %lu</pre><pre>Failed to install product: %s, HRESULT = 0xx</pre><pre>Installing, Product ID = %s</pre><pre>Skipping Delete. FileExists returned false: %s</pre><pre>FileExists returned true. Deleting file: %s</pre><pre>Attempting to Delete: %s</pre><pre>Runonce key not present</pre><pre>Run once key deleted</pre><pre>Failed to delete run once key</pre><pre>FATAL error occurred, installStubErrorCode = %d</pre><pre>Delay download by = %d minutes</pre><pre>Recoverable error occurred, installStubErrorCode = %d</pre><pre>SymInstallStub exe</pre><pre>SymInstallStubIdle exe</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>Fallback key successfully deleted.</pre><pre>Failed to delete Fallback key.</pre><pre>Fallback key present. Deleting.</pre><pre>Run once key already exists.</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings</pre><pre>Cookie: %s</pre><pre>Mozilla\Firefox\%s</pre><pre>Mozilla\Firefox\Profiles.ini</pre><pre>%s:%lu</pre><pre>%s://%s%s</pre><pre>https</pre><pre>0xX</pre><pre>DING_WinHttpClient.cpp</pre><pre>http=</pre><pre>AutoConfigURL</pre><pre>X-Symc-Local-User-Id: %s</pre><pre>X-Symc-Machine-Id: %s</pre><pre>network.proxy.autoconfig_url</pre><pre>network.proxy.http_port</pre><pre>network.proxy.http</pre><pre>network.proxy.type</pre><pre>network.proxy</pre><pre>prefs.js</pre><pre>user.js</pre><pre>FIREFOX</pre><pre>http\shell\open\command</pre><pre>CDownloadManager.DownloadFile returned</pre><pre>Starting HTTP engine</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>IbPortuguese</pre><pre>BrPortuguese</pre><pre>GUID set to: %s</pre><pre>Not able to create install count for %s</pre><pre>Not able to set install count for %s</pre><pre>First time, create the key and write the value for %s</pre><pre>%s -- Not able to set install count for %s</pre><pre>Not able to open install date. Either it does not exist or regkey open failed.</pre><pre>Getting install date from: %s</pre><pre>First time, create the key and write the value</pre><pre>Unable to read retry count key.</pre><pre>Unable to delete file: %s =</pre><pre>%m/%d/%Y</pre><pre>Cc:\bld_area\nssinstallstub_r3.6.1\sdk\cc\include\SymInterface.h</pre><pre>installstub::HTTPDownloadData::CloseFileStream</pre><pre>installstub::HTTPDownloadData::Initialize</pre><pre>WinHttpReadData failed</pre><pre>WinHttpQueryDataAvailable failed</pre><pre>installstub::CWinHTTPClient::GetResponse</pre><pre>Destroying CWinHTTPEngine</pre><pre>installstub::CWinHTTPEngine::~CWinHTTPEngine</pre><pre>installstub::CWinHTTPEngine::Initialize</pre><pre>DeleteFile failed to delete %s, dwResult = %lu</pre><pre>installstub::CWinHTTPEngine::getTempFilePath</pre><pre>Server supports partial download resuming download</pre><pre>Error Unexpected http response status %d</pre><pre>Received HTTP STATUS = %d while expecting partial response</pre><pre>installstub::CWinHTTPEngine::prepareResponseData</pre><pre>Creating CWinHTTPEngine...</pre><pre>installstub::CWinHTTPEngine::CWinHTTPEngine</pre><pre>Failed to move %s to %s, hr=0xX</pre><pre>File Name %s[size %I64u]</pre><pre>Remaining download content - %I64u, downloaded - %I64u for file %s</pre><pre>Download for %s was already started, bytes - %I64u</pre><pre>installstub::CWinHTTPEngine::Download</pre><pre>SymInstallStub.txt</pre><pre>C%s%s</pre><pre>[ %s ] ... %s</pre><pre>[s d, d - d:d:d:d]</pre><pre>%s = %s</pre><pre>%s , HR = 0xX</pre><pre>%s , dwResult = %lu</pre><pre>%s , HR = 0xX, dwResult = %lu</pre><pre>%s = %s, HR = 0xX, dwResult = %lu</pre><pre>installstub::ProcessLauncher::launchProcessWithShellExecute</pre><pre>Scheduled Task File: %s</pre><pre>Total nodes validated : %d</pre><pre>Succeeded nodes : %d</pre><pre>Failed nodes : %d</pre><pre>%s[%d]-></pre><pre>..\..\SDK\JSONCPP\src\json_reader.cpp</pre><pre>Line %d, Column %d</pre><pre>..\..\SDK\JSONCPP\src\json_value.cpp</pre><pre>(*it).type() == Json::stringValue</pre><pre>int(indentString_.size()) >= indentSize_</pre><pre>..\..\SDK\JSONCPP\src\json_writer.cpp</pre><pre>childValues_.size() == size</pre><pre>%SymEFA%</pre><pre>EFACli.dll</pre><pre>..\Source\ccVerifyTrustStatic.cpp</pre><pre>ICLSID\%s\LocalServer32</pre><pre>CLSID\%s\InprocServer32</pre><pre>ENTDLL.DLL</pre><pre>..\Source\ccVerifyTrustImpl.cpp</pre><pre>..\Source\FileCache.cpp</pre><pre>E..\Source\VerifyFile.cpp</pre><pre>..\Source\ccVerifyTrustPolicy.cpp</pre><pre>..\Source\CatalogIterator.cpp</pre><pre>..\Source\CatalogFileHash.cpp</pre><pre>WinTrust.dll</pre><pre>..\Source\CatalogContext.cpp</pre><pre>..\Source\ccSymModuleLifetimeMgrImpl.cpp</pre><pre>E..\Source\ccMemory.cpp</pre><pre>E..\Source\ccFile.cpp</pre><pre>EÌROOT%</pre><pre>rcPFRes.dll</pre><pre>rcPxyEvt.dll</pre><pre>rcProxy.dll</pre><pre>rcSvcHst.dll</pre><pre>rcEmlPxy.dll</pre><pre>rcLgView.dll</pre><pre>rcErrDsp.dll</pre><pre>rcAlert.dll</pre><pre>rcApp.dll</pre><pre>ccEmlPxy.dll</pre><pre>ccGLog.dll</pre><pre>ccJobMgr.dll</pre><pre>ccGEvt.dll</pre><pre>ccIPC.dll</pre><pre>ccRkSn.dll</pre><pre>PFPriv.dll</pre><pre>ccPxyIns.dll</pre><pre>ccPxyEvt.dll</pre><pre>ccInst64.dll</pre><pre>ccEvtCli.dll</pre><pre>ccTrstPc.dll</pre><pre>ccSvc.dll</pre><pre>ccEraser.dll</pre><pre>OEHeur.dll</pre><pre>ccCharCv.dll</pre><pre>ccInst.dll</pre><pre>DefUtDCD.dll</pre><pre>ccScanw.dll</pre><pre>ccScan.dll</pre><pre>dec_abi.dll</pre><pre>ccDec.dll</pre><pre>ccALEng.dll</pre><pre>ccErrDsp.dll</pre><pre>ccProSub.dll</pre><pre>ccVrTrst.dll</pre><pre>ccSetEvt.dll</pre><pre>ccSet.dll</pre><pre>ccAlert.dll</pre><pre>..\Source\ccStringConvert.cpp</pre><pre>..\Source\ccSymMemoryStreamImpl.cpp</pre><pre>F%s, %s, %s, %s(%ld)</pre><pre>F..\Source\ccRegistry.cpp</pre><pre>%s\%s</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED</pre><pre>isolate.ini</pre><pre>%COMMON_SILO_DATA%</pre><pre>F..\Source\ccOSInfo.cpp</pre><pre>\wpeutil.dll</pre><pre>\FACTORY.exe</pre><pre>\wpeinit.exe</pre><pre>\\?\UNC</pre><pre>F..\Source\ccSplitPath.cpp</pre><pre>F..\Source\ccSymFileStreamImpl.cpp</pre><pre>F..\Source\ccModule.cpp</pre><pre>F..\Source\ccSystemInfo.cpp</pre><pre>CSIDL_WINDOWS</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>..\Source\ccPathExpansion.cpp</pre><pre>..\Source\ccWow64FsRedirection.cpp</pre><pre>..\Source\ccEncryptedString.cpp</pre><pre>G..\Source\ccSymDllLifetimeMgr.cpp</pre><pre>I..\Source\ccSynchronize.cpp</pre><pre>Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>NÌROOT%\</pre><pre>ÌDATA%\</pre><pre>..\Source\ccSymInstalledApps.cpp</pre><pre>t..\Source\ccMessageLock.cpp</pre><pre>..\Source\ccSymIndexValueCollectionImpl.cpp</pre><pre>AWTSAPI32.DLL</pre><pre>kernel32.dll</pre><pre>KERNEL32.DLL</pre><pre>GPSAPI.DLL</pre><pre>..\Source\ccPEBReader.cpp</pre><pre>G..\Source\ccPrivilege.cpp</pre><pre>E..\Source\ccSymDllLifetimeMgrLocal.cpp</pre><pre>..\Source\ccSymIndexValueCollection.cpp</pre><pre>..\Source\ccSymValueCollection.cpp</pre><pre>I..\Source\ccArchive.cpp</pre><pre>H..\Source\ccDummyArchive.cpp</pre><pre>..\Source\ccInstanceFactory.cpp</pre><pre>..\Source\ccSymValueCollectionConvert.cpp</pre><pre>H..\Source\ccSymStreamArchive.cpp</pre><pre>H..\Source\ccSymDigest.cpp</pre><pre>..\Source\ccSymKeyValueCollectionImpl.cpp</pre><pre>..\Source\ccSymMemoryImpl.cpp</pre><pre>Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE</pre><pre>Archive.Read(nVersion) == FALSE</pre><pre>..\Source\ccSymStringImpl.cpp</pre><pre>Archive.Write(CStringImpl::Version) == FALSE</pre><pre>..\Source\ccSymInstanceFactoryImpl.cpp</pre><pre>..\Source\ccSymKeyValueCollection.cpp</pre><pre>..\Source\ccSymPersist.cpp</pre><pre>ÌROOT%\ccSet.dll</pre><pre>I..\Source\ccSymObjectRepository.cpp</pre><pre>CommonClient\OBJID\%s</pre><pre>I..\Source\ccMemoryArchive.cpp</pre><pre>mscoree.dll</pre><pre>WUSER32.DLL</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>ADVAPI32.DLL</pre><pre>Assertion failed: %s, file %s, line %d</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\7zS1.tmp\SymInstallStub.exe</pre><pre>/* Symantec Watermark: CB70-2826-1157-06-15-1 */</pre><pre>(0-3-000082</pre><pre>9VfL6qO3;J8HB.hwJ?l</pre><b>nssSetup.exe_704:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>8%uEP3</pre><pre>9>t.hD</pre><pre>t%SWh</pre><pre>FTPh</pre><pre>FtPh</pre><pre>\$,9^0~9</pre><pre>WTSAPI32.dll</pre><pre>USER32.dll</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>SHLWAPI.dll</pre><pre>{X-X-X-XX-XXXXXX}</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>USERENV.dll</pre><pre>VERSION.dll</pre><pre>WINHTTP.dll</pre><pre>9.1.0.26</pre><pre>RegOpenKeyTransactedW</pre><pre>RegCreateKeyTransactedW</pre><pre>RegDeleteKeyTransactedW</pre><pre>RegDeleteKeyExW</pre><pre>C:\bld_area\InstallToolBox_r9.1_26\VS10\Bin\Win32\Release\MiniStub.pdb</pre><pre>ExitWindowsEx</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>RegQueryInfoKeyW</pre><pre>RegEnumKeyExW</pre><pre>RegOpenKeyExW</pre><pre>RegCreateKeyExW</pre><pre>ShellExecuteExW</pre><pre>UrlCanonicalizeW</pre><pre>WinHttpReceiveResponse</pre><pre>WinHttpQueryHeaders</pre><pre>WinHttpQueryDataAvailable</pre><pre>WinHttpReadData</pre><pre>WinHttpCrackUrl</pre><pre>WinHttpOpen</pre><pre>WinHttpSetOption</pre><pre>WinHttpConnect</pre><pre>WinHttpOpenRequest</pre><pre>WinHttpCloseHandle</pre><pre>WinHttpSetStatusCallback</pre><pre>WinHttpAddRequestHeaders</pre><pre>WinHttpSendRequest</pre><pre>WinHttpGetProxyForUrl</pre><pre>WinHttpSetCredentials</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>SHDeleteKeyW</pre><pre>SHDeleteEmptyKeyW</pre><pre>Secur32.dll</pre><pre>KERNEL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>imagehlp.dll</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>zcÁ</pre><pre>.PA_W</pre><pre>("(,%%)|#"'</pre><pre>18%U<%</pre><pre>.nN\I</pre><pre>q:\ssF</pre><pre>Oÿ2</pre><pre>l7cmD</pre><pre>P%xiZ</pre><pre>.'#)/"&0</pre><pre>r.IOOO</pre><pre>bh.kn@</pre><pre>CDQ.Ef</pre><pre><(.bp9Fe</pre><pre>R.OFd</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3"><assemblyIdentity version="1.0.0.0" processorArchitecture="x86" name="MiniStub" type="win32"></assemblyIdentity><description>Symantec MiniStub application.</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><asmv3:application><asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings"><ms_windowsSettings:dpiAware xmlns:ms_windowsSettings="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</ms_windowsSettings:dpiAware></asmv3:windowsSettings></asmv3:application><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"></compatibility></assembly></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></pre><pre><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></pre><pre><%=*===~=</pre><pre>0 1%1X1</pre><pre><!><pre>6%7X7~7</pre><pre>> >$>(>,>0>4>8><>@></pre><pre>4 4$4(4,4044484</pre><pre>6 6$6(6,60646</pre><pre>9,989@9\9|9</pre><pre>@..\Source\ccOSInfo.cpp</pre><pre>\wpeutil.dll</pre><pre>\FACTORY.exe</pre><pre>\wpeinit.exe</pre><pre>@..\Source\ccMemory.cpp</pre><pre>..\Source\ccStringConvert.cpp</pre><pre>A..\Source\ccRegistry.cpp</pre><pre>A%s, %s, %s, %s(%ld)</pre><pre>ANTDLL.DLL</pre><pre>A..\Source\ccSystemInfo.cpp</pre><pre>A..\Source\ccThread.cpp</pre><pre>t..\Source\ccMessageLock.cpp</pre><pre>E..\Source\ccSynchronize.cpp</pre><pre>..\Source\ccSymFileStreamImpl.cpp</pre><pre>A..\Source\ccFile.cpp</pre><pre>..\Source\ccSymKeyValueCollectionImpl.cpp</pre><pre>A..\Source\ccSymMemoryStreamImpl.cpp</pre><pre>..\Source\ccSymValueCollectionConvert.cpp</pre><pre>A..\Source\ccMemoryArchive.cpp</pre><pre>\\?\UNC</pre><pre>A..\Source\ccSplitPath.cpp</pre><pre>E..\Source\ccArchive.cpp</pre><pre>B..\Source\ccSingleInstance.cpp</pre><pre>0xX :</pre><pre>d-d-d-d-d-d-d :</pre><pre>-0xX</pre><pre>fallback.dat</pre><pre>maplngid.dat</pre><pre>Langver.map</pre><pre>%s\%s\%s</pre><pre>..\Source\ccSymResourceModuleLocatorBase.cpp</pre><pre>%s\*.*</pre><pre>B..\Source\ccModule.cpp</pre><pre>B..\Source\ccPrivilege.cpp</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_FILE_NOT_FOUND</pre><pre>CIsolation::GetRegistryHive(): RegOpenKeyEx() returned ERROR_ACCESS_DENIED</pre><pre>isolate.ini</pre><pre>%COMMON_SILO_DATA%</pre><pre>rcPFRes.dll</pre><pre>rcPxyEvt.dll</pre><pre>rcProxy.dll</pre><pre>rcSvcHst.dll</pre><pre>rcEmlPxy.dll</pre><pre>rcLgView.dll</pre><pre>rcErrDsp.dll</pre><pre>rcAlert.dll</pre><pre>rcApp.dll</pre><pre>ccEmlPxy.dll</pre><pre>ccGLog.dll</pre><pre>ccJobMgr.dll</pre><pre>ccGEvt.dll</pre><pre>ccIPC.dll</pre><pre>ccRkSn.dll</pre><pre>PFPriv.dll</pre><pre>ccPxyIns.dll</pre><pre>ccPxyEvt.dll</pre><pre>ccInst64.dll</pre><pre>ccEvtCli.dll</pre><pre>ccTrstPc.dll</pre><pre>ccSvc.dll</pre><pre>ccEraser.dll</pre><pre>OEHeur.dll</pre><pre>ccCharCv.dll</pre><pre>ccInst.dll</pre><pre>DefUtDCD.dll</pre><pre>ccScanw.dll</pre><pre>ccScan.dll</pre><pre>dec_abi.dll</pre><pre>ccDec.dll</pre><pre>ccALEng.dll</pre><pre>ccErrDsp.dll</pre><pre>ccProSub.dll</pre><pre>ccVrTrst.dll</pre><pre>ccSetEvt.dll</pre><pre>ccSet.dll</pre><pre>ccAlert.dll</pre><pre>HÌROOT%</pre><pre>CSIDL_WINDOWS</pre><pre>..\Source\ccPathExpansion.cpp</pre><pre>B..\Source\ccCommandLine.cpp</pre><pre>..\Source\ccSymDebugOptions.cpp</pre><pre>\%s.dmp</pre><pre>Cx86\DbgHelp.dll</pre><pre>DbgHelp.dll</pre><pre>B..\Source\ccVersionInfo.cpp</pre><pre>\StringFileInfo\xx\%s</pre><pre>..\Source\ccSymIndexValueCollectionImpl.cpp</pre><pre>A..\Source\ccSymModuleLifetimeMgrImpl.cpp</pre><pre>AWTSAPI32.DLL</pre><pre>KERNEL32.DLL</pre><pre>CPSAPI.DLL</pre><pre>..\Source\ccPEBReader.cpp</pre><pre>..\Source\ccSymKeyValueCollection.cpp</pre><pre>..\Source\ccSymValueCollection.cpp</pre><pre>C..\Source\ccDummyArchive.cpp</pre><pre>..\Source\ccDACL.cpp</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>IÌROOT%\</pre><pre>ÌDATA%\</pre><pre>..\Source\ccSymInstalledApps.cpp</pre><pre>I..\Source\ccSymLanguageInfoBase.cpp</pre><pre>C%s%s.dmp</pre><pre>C..\Source\ccCrashHandler.cpp</pre><pre>%s %u</pre><pre>"%s" %s %u</pre><pre>%sSE_GROUP_RESOURCE</pre><pre>%sSE_GROUP_LOGON_ID</pre><pre>%sSE_GROUP_USE_FOR_DENY_ONLY</pre><pre>%sSE_GROUP_OWNER</pre><pre>%sSE_GROUP_ENABLED</pre><pre>%sSE_GROUP_ENABLED_BY_DEFAULT</pre><pre>%sSE_GROUP_MANDATORY</pre><pre>%sSE_PRIVILEGE_USED_FOR_ACCESSR</pre><pre>%sSE_PRIVILEGE_REMOVED</pre><pre>%sSE_PRIVILEGE_ENABLED</pre><pre>%sSE_PRIVILEGE_ENABLED_BY_DEFAULT</pre><pre>-d-d-d-d-d-d-d</pre><pre>DBGHELP.DLL</pre><pre>IMM32.DLL</pre><pre>..\Source\ccSymIndexValueCollection.cpp</pre><pre>..\Source\ccSymDllLifetimeMgr.cpp</pre><pre>D..\Source\ccSymStreamArchive.cpp</pre><pre>..\Source\ccInstanceFactory.cpp</pre><pre>..\Source\ccSymDllLifetimeMgrLocal.cpp</pre><pre>A..\Source\ccSymDigest.cpp</pre><pre>..\Source\ccSymMemoryImpl.cpp</pre><pre>Archive.Write(CMemoryImpl::CSerializeImpl::Version) == FALSE</pre><pre>Archive.Read(nVersion) == FALSE</pre><pre>..\Source\ccSymStringImpl.cpp</pre><pre>Archive.Write(CStringImpl::Version) == FALSE</pre><pre>A..\Source\ccSymInstanceFactoryImpl.cpp</pre><pre>..\Source\ccSymPersist.cpp</pre><pre>ÌROOT%\ccSet.dll</pre><pre>@..\Source\ccSymObjectRepository.cpp</pre><pre>CommonClient\OBJID\%s</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>mscoree.dll</pre><pre>WUSER32.DLL</pre><pre>CUserLaunch::IsValidSession(86) : WTSEnumerateSessions Failed : (%d)</pre><pre>CUserLaunch::Initialize(98) : session id: %lu, elevated: %d</pre><pre>CUserLaunch::Initialize(131) : WTSQueryUserToken failed for User: %s error: %d</pre><pre>CUserLaunch::Initialize(197) : GetTokenInformation() == FALSE, 0xx</pre><pre>CUserLaunch::Initialize(206) : mem.NewAlloc() == NULL</pre><pre>CUserLaunch::Initialize(213) : GetTokenInformation() == FALSE, 0xx</pre><pre>CUserLaunch::Initialize(280) : Initialized... session id: %lu, elevated: %d</pre><pre>CUserLaunch::LaunchProcess(319) : Launching CreateProcessAsUser(%s), attempt %d (timeout: %lu)</pre><pre>Process returned: 0xx</pre><pre>winlogon.exe</pre><pre>FindProcess for winlogon.exe failed: 0xx</pre><pre>FindShellProcessForSession failed: 0xx</pre><pre>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon</pre><pre>..\include\UserLaunch.cpp</pre><pre>0xX</pre><pre>explorer.exe</pre><pre>Tokenizing shell failed (%s)</pre><pre>FindShellProcess failed for %s 0xx</pre><pre>%s - %s</pre><pre>@IDispatch error #%d</pre><pre>DING::CSecurityDescriptorParser::Parse(236) : CSecurityDescriptorParser parsing security DACL[%ls] for - non-DACL elements are not supported!</pre><pre>DING::CSecurityDescriptorParser::Parse(239) : CSecurityDescriptorParser parsing security DACL[%ls] for - unsupported access right!</pre><pre>DING::CSecurityDescriptorParser::Parse(240) : CSecurityDescriptorParser parsing security DACL[%ls] for - unsupported user!</pre><pre>DING::CServiceSecurityProcessor::ApplyAccessRights(92) : ConvertStringSidToSid() for user SID: %ls failed. GetLastError() reports: %d</pre><pre>DING::CServiceSecurityProcessor::ApplyAccessRights(122) : SetSecurityInfo() for service: %ls failed with return value: %d</pre><pre>DING::CServiceSecurityProcessor::ApplyAccessRights(128) : SetEntriesInAcl() for service: %ls failed with return value: %d</pre><pre>DING::CServiceSecurityProcessor::ApplyAccessRights(140) : GetSecurityInfo() for service: %ls failed with return value: %d</pre><pre>BB::CProcessPrioritySetterMgr::CNativeProcessInfo::Initialize(188) : Unable to retrieve NTDLL module handle, last error 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CNativeProcessInfo::Initialize(199) : Unable to retrieve ZwQueryInformationProcess function pointer, error returned 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CNativeProcessInfo::Initialize(211) : Unable to retrieve ZwSetInformationProcess function pointer, error returned 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::Apply(289) : Unable to get process priority class, last error 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::Apply(294) : Priority class for process 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::Apply(312) : Unable to set process priority class, last error 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::Apply(321) : Successfully set process priority class to 0xx, but retrieved value 0xx differs!!!</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::Apply(326) : Successfully set process 0xx priority class to 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU::IsUpdateRequired(374) : Current process priority class 0xx, Requested process priority class 0xx</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetter_CPU_Native::Apply(429) : Successfully set process priority class for current process to %s, %lu</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(618) : Created PRIMITIVE CPrioritySetter_CPU</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(625) : Created PRIMITIVE CPrioritySetter_CPU_Native</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(632) : Created PRIMITIVE CPrioritySetter_CPU_Native</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(639) : Created PRIMITIVE CPrioritySetter_IO</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(646) : Created PRIMITIVE CPrioritySetter_Page</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(652) : switch(info.eType == %lu) default</pre><pre>BB::CProcessPrioritySetterMgr::CPrioritySetterFactory::operator ()(656) : Create the primitive based on identifier DONE</pre><pre>bbProcessStartupPriorityMgr.cpp</pre><pre>BB::CProcessPrioritySetterMgr::Start(765) : DuplicateHandle(...) == FALSE, last error 0xx</pre><pre>BB::CProcessPrioritySetterMgr::Run(859) : !m_hProcess.IsHandle()</pre><pre>BB::CProcessPrioritySetterMgr::Run(954) : Result updated to 0xx</pre><pre>BB::CProcessPrioritySetterMgr::Run(957) : Closing process handle 0xx</pre><pre>BB::CProcessPrioritySetterMgr::start(1088) : Create(NULL, 0, 0) == FALSE, last error 0xx</pre><pre>BB::CProcessStartupPriorityMgr::AddPrioritySetter(1144) : !m_cfg.GetEnabled()</pre><pre>BB::CProcessStartupPriorityMgr::Start(1163) : !m_cfg.GetEnabled()</pre><pre>BB::CProcessStartupPriorityMgr::Stop(1211) : !m_cfg.GetEnabled()</pre><pre>DING::CArchivingFileStreamImpl::~CArchivingFileStreamImpl(58) : DeleteFile failed %s (%lu)</pre><pre>DING::CArchivingFileStreamImpl::SetFileNameFormat(142) : failed to create file: %s (%lu)</pre><pre>..\include\DING_ArchivingFileStreamImpl.cpp</pre><pre>DING::CFileDataExtender::Initialize(124) : SetFileAttributes Failed on %s.</pre><pre>DING::CFileDataExtender::Initialize(167) : file is larger than 4GB, which is not supported by this tool</pre><pre>DING::CFileDataExtender::Export(467) : invalid pointer... need to initialize...</pre><pre>DING::CFileDataExtender::Export(476) : out of memory</pre><pre>DING::CFileDataExtender::Export(484) : failed to open: %ls (%lu)</pre><pre>DING::CFileDataExtender::Export(492) : failed to QI for ISerialize</pre><pre>DING::CFileDataExtender::Export(498) : failed to save kvc to stream</pre><pre>DING::CFileDataExtender::Import(519) : out of memory</pre><pre>DING::CFileDataExtender::Import(535) : out of memory</pre><pre>DING::CFileDataExtender::Import(543) : failed to QI for ISerialize</pre><pre>DING::CFileDataExtender::Import(554) : failed to QI for IClone</pre><pre>DING::CFileDataExtender::Import(576) : failed to QI for IClone</pre><pre>DING::CFileDataExtender::GetCollection(990) : invalid parameter - must pass a valid kvc</pre><pre>AddFile: %s %s %d</pre><pre>DING::CFilePacker::AddFile(417) : failed to open: %s (0xx)</pre><pre>..\include\DING_FilePacker.cpp</pre><pre>Index added: %s (eFileType_Extract)</pre><pre>adding file: %s as %s (0xx)</pre><pre>DING::CFilePacker::ContainsPackage(553) : packed file does not exist: %s</pre><pre>End of EXE module: %lu</pre><pre>REAL End of EXE module: %lu</pre><pre>DING::CFilePacker::Extract(633) : packed file does not exist: %s</pre><pre>DING::CFilePacker::Extract(855) : invalid extract type: %d</pre><pre>DING::CFilePacker::WriteStreamToDisk(889) : failed to create directory: %s (%lu)</pre><pre>DING::CFilePacker::WriteStreamToDisk(933) : failed attempting to extract: %s</pre><pre>DING::CFilePacker::WriteStreamToDisk(942) : failed attempting to extract: %s</pre><pre>..\include\DING_FileStreamImpl.cpp</pre><pre>DING::CPEFileHelper::ReadHeaders(95) : CSignedPEFile::ReadHeaders() : buffer.Alloc() == NULL</pre><pre>DING::CPEFileHelper::ReadHeaders(160) : CSignedPEFile::ReadHeaders() : m_dwWinCertificateLength > m_dwMaxCertificateSize</pre><pre>OpenService(%s, 0x%x)</pre><pre>OpenService failed: %s (%lu)</pre><pre>..\include\DING_servicewrapper.cpp</pre><pre>Waiting for %s service to start.</pre><pre>DING::CService::RemediateService(684) : EnsureAccess %s threw an exception: %d</pre><pre>DING::CService::RemediateService(689) : EnsureAccess %s threw an exception: (0xx)</pre><pre>SYSTEM\CurrentControlSet\Services\%s</pre><pre>failed to open: %s (%lu)</pre><pre>RegistryEnsureAccess %s threw an exception: %d</pre><pre>RegistryEnsureAccess %s threw an exception: (0xx)</pre><pre>SetNamedSecurityInfo(%s) != ERROR_SUCCESS: %lu</pre><pre>%s-d-d-d-dhdmds</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>..\include\DING_Utils.cpp</pre><pre>%s %s</pre><pre>Launching: %s</pre><pre>DING::CUtils::ExecuteProgramEx(304) : GetExitCodeProcess failed: 0xx</pre><pre>DING::CUtils::ExecuteProgramEx(314) : failed to launch: 0xx</pre><pre>DING::CUtils::DeleteFolder(325) : invalid path: %s</pre><pre>delete on reboot: %s</pre><pre>DING::CUtils::DeleteFolder(347) : MoveFileEx failed to delete folder: %s (%lu)</pre><pre>DING::CUtils::DeleteFolder(361) : failed to delete folder: %s (%lu)</pre><pre>DING::CUtils::DeleteFolderOnReboot(380) : invalid path: %s</pre><pre>DING::CUtils::CopyFiles(472) : invalid path: %s</pre><pre>DING::CUtils::CopyFiles(497) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::CopyFiles(501) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::CopyFiles(505) : CreateDirectory failed: %s (%lu)</pre><pre>DING::CUtils::DeleteEmptyFolders(600) : invalid path: %s</pre><pre>DING::CUtils::DeleteEmptyFolders(618) : MoveFileEx failed to delete folder: %s (%lu)</pre><pre>DING::CUtils::DeleteHandler(668) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::DeleteHandler(672) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::DeleteHandler(681) : MoveFileEx failed to delete folder: %s (%lu)</pre><pre>DeleteFile: %s</pre><pre>DING::CUtils::DeleteHandler(719) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::DeleteHandler(723) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::DeleteHandler(729) : MoveFileEx failed to delete file: %s (%lu)</pre><pre>DING::CUtils::DeleteHandler(750) : failed to delete file: %s (%lu)</pre><pre>DING::CUtils::DeleteEmptyFolderHandler(832) : MoveFileEx failed to delete folder: %s (%lu)</pre><pre>DING::CUtils::DeleteFileW(953) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::DeleteFileW(957) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::DeleteFileW(964) : MoveFileEx failed to delete file: %s (%lu)</pre><pre>DING::CUtils::DeleteFileW(992) : failed to delete file: %s (%lu)</pre><pre>DING::CUtils::DeleteFileW(1004) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::DeleteFileW(1008) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>SDDL: %s (%s)</pre><pre>LoadResourceModule(): %s, X</pre><pre>DING::CUtils::LoadResourceModule(1101) : Error: %d, Unable to load resource module: %s</pre><pre>%s created for %s</pre><pre>DING::CUtils::SetRebootFlag(1193) : failed to create reboot key (%lu)</pre><pre>DING::CUtils::SetRebootFlag(1200) : failed to open Norton key (%lu)</pre><pre>DING::CUtils::SetRebootFlag(1208) : failed to create reboot key (%lu)</pre><pre>reboot key found (need to reboot before running install)</pre><pre>DING::CUtils::CopySubFolderHandler(1290) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::CopySubFolderHandler(1294) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::CopySubFolderHandler(1298) : CreateDirectory failed: %s (%lu)</pre><pre>DING::CUtils::CopyFolderHandler(1360) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::CopyFolderHandler(1364) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::CopyFolderHandler(1369) : CreateDirectory failed: %s (%lu)</pre><pre>DING::CUtils::CopyFolderHandler(1418) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::CopyFolderHandler(1422) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::CopyFolderHandler(1429) : CopyFile failed: %s (%lu)</pre><pre>DING::CUtils::CopyFolderHandler(1435) : CopyFile failed: %s (%lu) -- copy on reboot</pre><pre>DING::CUtils::CopyFolderHandler(1454) : failed to copy: %s -> %s (%lu)</pre><pre>DING::CUtils::CopyFolderHandler(1462) : MoveFileEx failed: %s -> %s (%lu)</pre><pre>MoveFile: %s -> %s</pre><pre>DING::CUtils::CopyFolderHandler(1471) : CopyFile failed: %s (%lu) -- move on reboot</pre><pre>DING::CUtils::CopyFolderHandler(1476) : MoveFileEx failed: %s -> %s (%lu)</pre><pre>DING::CUtils::CopyFilesHandler(1681) : FileEnsureAccess %s threw an exception: %d</pre><pre>DING::CUtils::CopyFilesHandler(1685) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CUtils::CopyFilesHandler(1689) : CreateDirectory failed: %s (%lu)</pre><pre>DING::CUtils::CopyFilesHandler(1698) : CopyFile failed: %s -> %s (%lu)</pre><pre>Copy: %s -> %s</pre><pre>%lsX</pre><pre>http://stats.norton.com/n/p?%s</pre><pre>http://stats.norton.com/n/p%s</pre><pre>DING::CUtils::CanonicalizePartialURL(2010) : UrlCanonicalizeW failed: 0xx</pre><pre>DING::CUtils::CanonicalizePartialURL(2021) : UrlCanonicalizeW failed: 0xx</pre><pre>Protecting Folder (%s): %s</pre><pre>!!!!Found known folder do not DELETE!!!: %s</pre><pre>@kernel32.dll</pre><pre>shell32.dll</pre><pre>Connections\Proxy\HTTP</pre><pre>Manual_Proxy_Port</pre><pre>Password</pre><pre>Auto_Config_URL</pre><pre>Secure connection failed 0xx</pre><pre>WinHttpReceiveResponse call failed, ErrorCode=%lu</pre><pre>WinHttpQueryHeaders call failed HR =0xx</pre><pre>Unexpected error during WinHTTPQueryHeaders (0xx)</pre><pre>WinHttpQueryDataAvailable failed: 0xx</pre><pre>Attack/Buffer Overflow guard for dwAvailableBytes:0xx.</pre><pre>WinHttpReadData failed: %lu</pre><pre>WinHttpQueryDataAvailable failed: %lu</pre><pre>Received WINHTTP_CALLBACK_STATUS_HANDLE_CLOSING</pre><pre>WinHttpCrackUrl failed: %lu</pre><pre>DING/0.0.0.0/Win</pre><pre>InitializeWinHttp failed - unable to initialize WinHTTP services</pre><pre>LoadProxySettings failed with 0xx assuming no proxy</pre><pre>WinHttpOpen call failed, Error=%lu</pre><pre>WinHttpConnect call failed, Error=%lu</pre><pre>..\include\DING_WinHttpClient.cpp</pre><pre>Registry open failed for SILO %s with error %lu</pre><pre>DING::CWinHTTPClient::Query(624) : Unable to create Request Id GUID: 0xx</pre><pre>%s-%s</pre><pre>DING::CWinHTTPClient::Query(638) : Unable to create Request Id GUID</pre><pre>Request Id: %s</pre><pre>WinHttpOpenRequest call failed, ErrorCode=%d</pre><pre>WinHttpSetOption succeeded, invalid or out of date certificates allowed</pre><pre>Could not set relaxed SSL requirements, WinHttpSetOption failed: 0xx</pre><pre>DING::CWinHTTPClient::Query(688) : Failed to allocate memory for request context</pre><pre>callback can't be NULL for async operation</pre><pre>WinHttpSetStatusCallback call failed, ErrorCode=%lu</pre><pre>DING::CWinHTTPClient::Query(757) : Couldn't add request to map %s</pre><pre>WinHttpSetOption(WINHTTP_DISABLE_KEEP_ALIVE) failed: %lu</pre><pre>failed to open isolation key: %lu</pre><pre>failed to open Identifiers key: %lu</pre><pre>X-Symc-Local-User-Id: %s</pre><pre>X-Symc-Machine-Id: %s</pre><pre>X-Symc-Request-Id: %s</pre><pre>WinHttpAddRequestHeaders failed: %lu, Request ID=%s</pre><pre>WinHttpSendRequest call failed, ErrorCode=%lu</pre><pre>WinHttpReceiveResponse failed: %lu</pre><pre>WinHttpQueryHeaders failed: %lu</pre><pre>Getting response for the Request Id %s</pre><pre>failed to create settings Manager: 0xx</pre><pre>failed to get http settings</pre><pre>could not get AutoConfig URL</pre><pre>failed to get server: 0xx</pre><pre>Server is specified, but no port, assuming port 80</pre><pre>failed to get port: 0xx</pre><pre>Server: %s, Port: %lu, User: %s</pre><pre>https</pre><pre>%s://%s%s</pre><pre>WinHTTPSetOption Failed setting AutoProxy: %lu</pre><pre>WinHttpSetOption failed setting AutoProxyURL: %lu</pre><pre>Proxy port and proxy server must be set to use this option</pre><pre>%s:%lu</pre><pre>WinHttpSetOption failed setting manual proxy URL: %lu</pre><pre>WinHttpSetCredentials(WINHTTP_AUTH_TARGET_PROXY) failed: %lu</pre><pre>gengine.dll</pre><pre>CEngineWrapper::Load(68) : failed to initialize Engine: %s (0xx)</pre><pre>CEngineWrapper::Load(87) : failed to create EngineManager object (0xx)</pre><pre>@%s\Install.%%d.mft</pre><pre>DING_{737118AA-7857-4554-A6FD-B2F2718AD7E9}</pre><pre>DING_{4467AB8F-68C8-4ab5-9B48-B3E6EB65F6A1}</pre><pre>DING_{66F78E3E-B9A1-4723-A090-E48BBECF7802}</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><pre>layout.dat</pre><pre>extract.dat</pre><pre>complete.dat</pre><pre>finalzed.dat</pre><pre>install.dat</pre><pre>Install.mft</pre><pre>InstStub.exe</pre><pre>InsMUI.loc</pre><pre>Software\Microsoft\Windows\CurrentVersion\explorer\Shell Folders</pre><pre>CInstallManager::Initialize(144) : failed to create CKeyValueCollectionImpl</pre><pre>CInstallManager::Initialize(175) : InitializeEmbeddedData failed (0xx)</pre><pre>Service Control Manager failed to open: %d</pre><pre>Service %s failed to open: %d</pre><pre>StartService failed: %d</pre><pre>%s failed to start</pre><pre>AcceptEULA failed: 0xx</pre><pre>ForceLoad failed: 0xx</pre><pre>CInstallManager::Initialize(306) : InitializeEmbeddedData failed (0xx)</pre><pre>%s_CleanUp</pre><pre>Uninstall Key found</pre><pre>Setup path to Isolate.ini</pre><pre>\isolate.ini</pre><pre>%s_disabled</pre><pre>Unable to create path to isolate.ini</pre><pre>Disabling isolate.ini so that our IPC calls will go to the correct silo for the patch controller</pre><pre>Unable to disable %s</pre><pre>Couldn't connect to rebootless patch controller: 0xx</pre><pre>Couldn't send patch status, not rebootless patching? :0xx</pre><pre>Restored Isolate.ini</pre><pre>Unable to create %s semaphore</pre><pre>Finished: Extract Package: 0xx</pre><pre>CInstallManager::Initialize(515) : CreateUIFrame failed (0xx)</pre><pre>CInstallManager::Initialize(526) : GetFrame failed (0xx)</pre><pre>Finished: Extract Package (media retry): 0xx</pre><pre>CInstallManager::Initialize(601) : failed to import embedded data</pre><pre>CInstallManager::Initialize(631) : InitializeOutputManifest failed (0xx)</pre><pre>Stage cmd set</pre><pre>CInstallManager::Initialize(710) : CreateUIFrame failed (0xx)</pre><pre>CInstallManager::Initialize(738) : GetFrame failed (0xx)</pre><pre>CInstallManager::Initialize(771) : GetInstallUI failed (0xx)</pre><pre>CInstallManager::Initialize(870) : Unable to execute %s</pre><pre>Launching: %s %s</pre><pre>CInstallManager::Initialize(968) : failed to launch "%s" in tray mode (%lu), use this process for tray mode</pre><pre>engine returned: 0xx (reboot: %d)</pre><pre>change return code so initial setup doesn't delete its cache: 0xx</pre><pre>%s /%s</pre><pre>InstallManager.cpp</pre><pre>CInstallManager::RunOnceRelaunch(1197) : failed to open RunOnce subkey (%s): %lu</pre><pre>/%s "%s"</pre><pre>CInstallManager::RunOnceRelaunch(1242) : ShellExecuteEx failed (%lu), continue installing</pre><pre>CInstallManager::CheckValidationMode(1277) : failed to load engine: 0xx</pre><pre>CInstallManager::CheckValidationMode(1294) : failed to Initialize engine: 0xx</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System</pre><pre>d-d-d-dhdmds</pre><pre>CInstallManager::CreateDirectories(1426) : failed to create directory (%s) (0xx)</pre><pre>command line: %s</pre><pre>base install folder: %s</pre><pre>install log folder: %s</pre><pre>install temp folder: %s</pre><pre>CInstallManager::CreateDirectories(1440) : failed to create directory (%s) (0xx)</pre><pre>attempting to fix access denied error: %s</pre><pre>CInstallManager::EnsureCreateDirectory(1498) : FileEnsureAccess %s threw an exception: %d</pre><pre>CInstallManager::EnsureCreateDirectory(1503) : FileEnsureAccess %s threw an exception: (0xx)</pre><pre>CInstallManager::InitializeLogging(1543) : g_CrashHandler.SetOptions() == FALSE</pre><pre>CInstallManager::GetCommonInstallFolder(1569) : reg.Open() == FALSE</pre><pre>CInstallManager::InitializeEmbeddedData(1640) : SetSiloID failed: %s</pre><pre>CInstallManager::InitializeEmbeddedData(1655) : SetSiloRegistryRoot failed: %s</pre><pre>CInstallManager::InitializeEmbeddedData(1673) : failed to create directory (%s) (0xx)</pre><pre>Install Cache: %s</pre><pre>CInstallManager::InitializeEmbeddedData(1758) : failed to create directory: %s (0xx)</pre><pre>CInstallManager::InitializeEmbeddedData(1775) : unable to import external settings</pre><pre>deleting folder: %s (reboot: %d)</pre><pre>deleting folder (reboot): %s</pre><pre>deleting empty folders: %s</pre><pre>delete file: %s</pre><pre>CInstallManager::Run(2037) : ExtractLayout failed (0xx)</pre><pre>CInstallManager::IsDepPatchWaiting(2065) : failed to open isolation key: %lu</pre><pre>CInstallManager::IsDepPatchWaiting(2075) : failed to open patch key: %lu</pre><pre>CInstallManager::IsDepPatchWaiting(2085) : failed to open engine key: %lu</pre><pre>Dependent patch waiting - delete patch key</pre><pre>CInstallManager::ExtractLayout(2136) : Initialize failed (0xx)</pre><pre>CInstallManager::ExtractLayout(2153) : Open failed (0xx)</pre><pre>CInstallManager::ExtractLayout(2161) : ExtractFolder failed (0xx)</pre><pre>Finished: Extracting Layout (%s</pre><pre>CopyBaseFiles: %s</pre><pre>CInstallManager::ExtractLayout(2181) : failed to write layout.dat</pre><pre>CInstallManager::LaunchEngine(2219) : failed to load engine: 0xx</pre><pre>CInstallManager::LaunchEngine(2228) : failed to get UI frame: 0xx</pre><pre>CInstallManager::LaunchEngine(2309) : failed to initialize engine: 0xx</pre><pre>Unable to delete return code %s/%s</pre><pre>CInstallManager::LaunchEngine(2360) : ReturnCode: failed to set "%s" = "%d": %lu</pre><pre>Unable to open SILO key</pre><pre>%s\%s</pre><pre>CInstallManager::LaunchEngine(2382) : ReturnCode: failed to set "%s" = "%d": %lu</pre><pre>CInstallManager::LaunchEngine(2393) : engine failed: 0xx</pre><pre>CInstallManager::DeleteCompleteAndExtract(2448) : failed to delete %s: 0xx</pre><pre>CInstallManager::DeleteCompleteAndExtract(2454) : failed to delete %s: 0xx</pre><pre>CInstallManager::ShowMB(2532) : failed to set the isolation reg key</pre><pre>CInstallManager::ShowMB(2555) : failed to LoadString Message %d];</pre><pre>CInstallManager::ShowMB(2560) : failed to LoadString Message %d];</pre><pre>CInstallManager::ShowMB(2597) : failed to LoadString Message %d];</pre><pre>CInstallManager::ShowMB(2602) : failed to LoadString Message %d];</pre><pre>NortonInstall\temp.loc</pre><pre>NortonInstall\%s.loc</pre><pre>ExtractResource returned 0xx</pre><pre>Removing languages: %s</pre><pre>delete folder: %s</pre><pre>delete empty folder: %s</pre><pre>CInstallManager::UpdateDefaultLanguageFromDisk(3038) : failed to open: %s (%lu)</pre><pre>CInstallManager::UpdateDefaultLanguageFromDisk(3046) : fallback.dat is corrupt</pre><pre>CInstallManager::UpdateDefaultLanguageFromDisk(3052) : failed to read: %s (%lu)</pre><pre>fallback language id: %x</pre><pre>LocaleIDToLangString for language ID %x failed</pre><pre>%s_%s_%d.exe</pre><pre>CInstallManager::SetupAndLaunchRemovalProcess(3153) : CopyFile failed (%s -> %s): %lu</pre><pre>CInstallManager::SetupAndLaunchRemovalProcess(3200) : collection import failed</pre><pre>set DeleteMode for: %s</pre><pre>set deletemode for empty folders: %s</pre><pre>/%s /%s "%s"</pre><pre>deleting folder: %s</pre><pre>deleting file: %s</pre><pre>CInstallManager::CheckAndSignalOtherInstance(3374) : GetFrame failed (0xx)</pre><pre>CInstallManager::CheckAndSignalOtherInstance(3386) : GetInstallTray failed (0xx)</pre><pre>CInstallManager::ShowRebootTray(3451) : CreateUIFrame failed (0xx)</pre><pre>CInstallManager::ShowRebootTray(3459) : failed to get ui frame: 0xx</pre><pre>CInstallManager::CRelaunchThread::Run(3566) : ShellExecuteEx failed: %lu</pre><pre>%INSTALLCACHEDIR%\inststub.exe</pre><pre>initialzed embedded data: %s</pre><pre>CInstallManager::GetLicenseType(3666) : failed to export to FDE data to install.dat</pre><pre>failed to initialze embedded data: %s</pre><pre>FAILURE: Hint: %d, HR: 0xx</pre><pre>failed to set DING 9003 failure count: %s = %lu (%lu)</pre><pre>does not meet winhttp requirements do not ping</pre><pre>%u.%u.%u.%u.%u.%u</pre><pre>?module=%s&error=%s</pre><pre>&%s=%s</pre><pre>URL: %ls</pre><pre>&zzz=%s</pre><pre>http://stats.qalabs.symantec.com/n/p</pre><pre>http://stats.norton.com/n/p</pre><pre>CInstallManager::SendPing(3897) : Initializing winhttpclient failed: 0xx</pre><pre>ccIPC::ccIPCMgd_IComLib::CreateObject failed: 0xx</pre><pre>CreateClient(MASTERSERVICE_CHANNEL) failed: 0xx</pre><pre>SendCommand(CMDID_MASTERSERVICE_COMMAND_FORCELOAD) failed: E_INVALIDARG (not available, service is already started or BTP enabled)</pre><pre>SendCommand(CMDID_MASTERSERVICE_COMMAND_FORCELOAD) failed: 0xx</pre><pre>SendCommand(CMDID_MASTERSERVICE_COMMAND_ACCEPTEULA) failed: E_INVALIDARG (not available, service is already started or BTP enabled)</pre><pre>SendCommand(CMDID_MASTERSERVICE_COMMAND_ACCEPTEULA) failed: 0xx</pre><pre>readding run once. Old Commandline: %s</pre><pre>Failed to open runonce (0xx</pre><pre>writing new commandline %s to run key</pre><pre>CInstallManager::LogUserName(4202) : Session(%d) UserName: %s</pre><pre>CInstallManager::GetInteractiveSessions(4280) : Session: %lu, "%s", %lu - %s</pre><pre>CInstallManager::GetInteractiveSessions(4342) : UserName(%lu): %s</pre><pre>CInstallManager::LaunchTrayInActiveSessions(4376) : Running as SYSTEM - Attempting to launch multiple instances of: %s</pre><pre>CInstallManager::LaunchTrayInActiveSessions(4421) : Unable to launch for session %lu: 0xx</pre><pre>CInstallManager::LaunchTrayInActiveSessions(4426) : Launching for session %lu: 0xx</pre><pre>@InstUI.dll</pre><pre>CInstallUIWrapper::Load(58) : failed to initialize InstallUI: %s (0xx)</pre><pre>CInstallUIWrapper::Load(80) : failed to create install UI frame object (0xx)</pre><pre>CInstallUIWrapper::Load(88) : engine IInstallUIFrame::Initialize failed (0xx)</pre><pre>CInstallUnpacker::ExtractPackage(49) : failed to create directory: %s (%lu)</pre><pre>Finish: extract stub (0xx)</pre><pre>CInstallUnpacker::HandleStub(223) : failed to open file: %s (%lu)</pre><pre>CInstallUnpacker::HandleUIPackage(285) : archive.Initialize failed: 0xx</pre><pre>CInstallUnpacker::HandleUIPackage(292) : archive.Open failed: 0xx</pre><pre>CInstallUnpacker::HandleUIPackage(299) : archive.ExtractArchive failed: 0xx</pre><pre>CInstallUnpacker::HandleStream(312) : failed to add stream at key %d</pre><pre>CMediaCheck::Show(45) : GetInstallUI failed (0xx)</pre><pre>CMediaCheck::Show(65) : SetStartPage failed (0xx)</pre><pre>CMediaCheck::Show(77) : DisplayFrame failed (0xx)</pre><pre>GHKEY_CURRENT_CONFIG</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_USERS</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_CLASSES_ROOT</pre><pre>wWinMain(65) : g_CrashHandler.SetOptions() == FALSE</pre><pre>wWinMain(104) : failed to coinitialize (0xx)</pre><pre>wWinMain(113) : CoInitializeSecurity() != S_OK, 0xX</pre><pre>MiniStub: Returned (0xx)</pre><pre>Advapi32.dll</pre><pre>CRebootTray::Show(45) : failed to get InstallTray: 0xx</pre><pre>CRebootTray::OnTrayClick(138) : failed to get InstallUI: 0xx</pre><pre>Patch reboot key was not found, not watching key for close</pre><pre>Patch reboot key has been cleared, closing down tray</pre><pre>FExtracting: %s %I64d (eFileType_UIPackage)</pre><pre>CResourceUnpacker::OnExtractStream(54) : archive.Initialize failed: 0xx</pre><pre>CResourceUnpacker::OnExtractStream(61) : archive.Open failed: 0xx</pre><pre>CResourceUnpacker::OnExtractStream(68) : archive.ExtractFile(%s, %s) failed: 0xx</pre><pre>Done Extracting: %s</pre><pre>CTestModeUnpacker::OnExtractStream(74) : failed to initialize archive: 0xx</pre><pre>CTestModeUnpacker::OnExtractStream(80) : failed to open archive: 0xx</pre><pre>CTestModeUnpacker::OnExtractStream(126) : failed to initialize archive: 0xx</pre><pre>CTestModeUnpacker::OnExtractStream(132) : failed to open archive: 0xx</pre><pre>DING::CRegistry::ForceOpenKey(125) : failed to open key: %s at %s (0xx)</pre><pre>DING::CRegistry::EnsureOpen(206) : RegistryEnsureAccess %s threw an exception: %d</pre><pre>DING::CRegistry::EnsureOpen(211) : RegistryEnsureAccess %s threw an exception: (0xx)</pre><pre>DING::CRightsChecker::ChangeAccess(228) : CRightsChecker::ChangeAccess: %s</pre><pre>C7zArchive::Open(151) : failed to open archive: 0xx</pre><pre>C7zArchive::Open(168) : failed to open archive (file not found): %s</pre><pre>C7zArchive::Open(191) : failed to open file: %s (%lu)</pre><pre>C7zArchive::Open(203) : failed to open archive: %s (0xx)</pre><pre>C7zArchive::Open(208) : failed to open file archive: %s (S_FALSE)</pre><pre>..\Source\7zArchive.cpp</pre><pre>C7zArchive::GetStream(802) : failed to open file: %s (%lu)</pre><pre>C7zArchive::SetOperationResult(836) : CRC check failed</pre><pre>C7zArchive::SetOperationResult(841) : Data Error</pre><pre>C7zArchive::SetOperationResult(846) : Data Error2</pre><pre>C7zArchive::SetOperationResult(851) : Data Error3</pre><pre>C7zArchive::SetOperationResult(855) : Unsupported function</pre><pre>C7zArchive::GetProperty(1003) : unexpected type (BSTR): %u</pre><pre>C7zArchive::GetProperty(1029) : unexpected type (bool): %u</pre><pre>C7zArchive::GetProperty(1052) : unexpected type (DWORD): %u</pre><pre>C7zArchive::GetProperty(1075) : unexpected type (filetime): %u</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\SymInstallStub\estorecj\nssSetup.exe</pre><pre>4.1.0.28</pre><pre>Setup.exe</pre><pre>10/7/2013</pre><b>SymInstallStub.exe_1788_rwx_0051B000_00002000:</b><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"></compatibility></assembly></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre>kernel32.dll</pre><pre>RPCRT4.dll</pre><pre>Secur32.dll</pre><pre>USER32.dll</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>COMCTL32.dll</pre><pre>gdiplus.dll</pre><pre>WINHTTP.dll</pre><pre>WinHttpReceiveResponse</pre><pre>USERENV.dll</pre><pre>3.6.1.16</pre><b>SymInstallStub.exe_1788_rwx_00B20000_00002000:</b><pre>The procedure %s could not be located in the DLL %s.</pre><pre>The ordinal %d could not be located in the DLL %s.</pre></!></pre></x>