Trojan.Win32.Foxhiex.agk (Kaspersky), Gen:Variant.Zusy.64166 (B) (Emsisoft), Gen:Variant.Zusy.64166 (AdAware), HackTool.Win32.PassView.FD, Trojan-PSW.Win32.MSNPassword.FD, GenericAutorunWorm.YR, HackToolPassView.YR (Lavasoft MAS)Behaviour: Trojan-PSW, Trojan, Worm, HackTool, WormAutorun
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 764e4ab259d8778c35e877c9fbbf94c5
SHA1: 07132d068502c8529b2bdbf5e49716e768e779dd
SHA256: c728ee6ed89de2a663e529afcffaadfa7f0a61b4f519fdcb7acf0cbca7940d9e
SSDeep: 49152:4urAaucSPcXX4JtZUyOBqSZI/S 0crzqWWhblm/mj3U:jr5ucSPc2ftOjZIj0crqblm/6k
Size: 2408448 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: Plus HD
Created at: 2014-06-19 17:10:18
Analyzed on: WindowsXP SP3 32-bit
Summary: HackTool. Can be used to investigate, analyze or compromise the system security. Some HackTools are multi-purpose programs, while others may have legitimate uses.
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
WormAutorun | A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the HackTool's file once a user opens a drive's folder in Windows Explorer. |
Process activity
The HackTool creates the following process(es):
xpsrchvw.exe:1712
IDMan.exe:2012
%original file name%.exe:1380
vbc.exe:2060
vbc.exe:2248
The HackTool injects its code into the following process(es):
xpsrchvw.exe:1188
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process xpsrchvw.exe:1712 makes changes in the file system.
The HackTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\csrss.exe (16158 bytes)
The process xpsrchvw.exe:1188 makes changes in the file system.
The HackTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\pid.txt (4 bytes)
%System%\wbem\Logs\wbemprox.log (152 bytes)
%Documents and Settings%\%current user%\Application Data\pidloc.txt (23 bytes)
The HackTool deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@ssl.bing[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@hit.gemius[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@money.ca.msn[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\holderwb.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msnportal.112.2o7[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kaspersky[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.msn[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\holdermail.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@aaa[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@bing[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@twitter[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@auto.search.msn[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@microsoft[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@c.msn[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@abmr[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@rambler[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@c.bing[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@pass.yandex[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@atdmt[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kaspersky.122.2o7[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@c.ca.msn[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@doubleclick[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@adnxs[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@hm.baidu[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@adgear[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@c.atdmt[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@yandex[3].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@yandex[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@msn[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@yandex[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.bing[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@tns-counter[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (0 bytes)
The process %original file name%.exe:1380 makes changes in the file system.
The HackTool creates and/or writes to the following file(s):
%WinDir%\xpsrchvw.exe (16158 bytes)
%Documents and Settings%\%current user%\Application Data\IDMan.exe (25429 bytes)
The process vbc.exe:2248 makes changes in the file system.
The HackTool creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\holderwb.txt (2 bytes)
Registry activity
The process xpsrchvw.exe:1712 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "53 A9 F2 56 18 CD 3E B2 84 CA AE 9B 04 6B 60 C2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Application Data]
"csrss.exe" = "Internet Download Manager (IDM)"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The HackTool modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The HackTool modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the HackTool adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"xpsrchvw" = "%WinDir%\xpsrchvw.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xpsrchvw" = "%WinDir%\xpsrchvw.exe"
The HackTool modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The process xpsrchvw.exe:1188 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\ESENT\Process\xpsrchvw\DEBUG]
"Trace Level" = ""
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"EventMessageFile" = "%System%\ESENT.dll"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryCount" = "16"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"Hidden" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "45 C5 66 94 34 D3 A7 E2 B6 DA 95 C9 19 BA CE A4"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"CategoryMessageFile" = "%System%\ESENT.dll"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\System\CurrentControlSet\Services\Eventlog\Application\ESENT]
"TypesSupported" = "7"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
The HackTool deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\ESENT\Process\xpsrchvw\DEBUG]
"Trace Level"
The process IDMan.exe:2012 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0A 51 2F B0 0A 11 5C FE B4 4B AC 18 B6 2C 3E 19"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process %original file name%.exe:1380 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9A 28 C2 C9 8B EB 55 4B 78 D5 55 84 6A E5 A1 D4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\Application Data]
"IDMan.exe" = "Internet Download Manager (IDM)"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%WinDir%]
"xpsrchvw.exe" = "Internet Download Manager (IDM)"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The HackTool modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The HackTool modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The HackTool modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process vbc.exe:2060 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "28 B4 9A EC D7 E6 24 4B E0 AD 48 52 CE 7B 89 6F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
The process vbc.exe:2248 makes changes in the system registry.
The HackTool creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "44 51 AE A8 C6 71 FD 5C 58 78 2F A2 8E 32 92 98"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
Dropped PE files
MD5 | File path |
---|---|
3c7cb7c033b7a0596d27d067606d506e | c:\Documents and Settings\"%CurrentUserName%"\Application Data\IDMan.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
A worm can spread via removable drives. It writes its executable and creates "autorun.inf" scripts on all removable drives. The autorun script will execute the HackTool's file once a user opens a drive's folder in Windows Explorer.
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
xpsrchvw.exe:1712
IDMan.exe:2012
%original file name%.exe:1380
vbc.exe:2060
vbc.exe:2248 - Delete the original HackTool file.
- Delete or disinfect the following files created/modified by the HackTool:
%Documents and Settings%\%current user%\Application Data\csrss.exe (16158 bytes)
%Documents and Settings%\%current user%\Application Data\pid.txt (4 bytes)
%System%\wbem\Logs\wbemprox.log (152 bytes)
%Documents and Settings%\%current user%\Application Data\pidloc.txt (23 bytes)
%WinDir%\xpsrchvw.exe (16158 bytes)
%Documents and Settings%\%current user%\Application Data\IDMan.exe (25429 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\holderwb.txt (2 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"xpsrchvw" = "%WinDir%\xpsrchvw.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xpsrchvw" = "%WinDir%\xpsrchvw.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Find and delete all copies of the worm's file together with "autorun.inf" scripts on removable drives.
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Tonec Inc.
Product Name: Internet Download Manager (IDM)
Product Version: 6, 20, 3, 3
Legal Copyright: Tonec Inc., Copyright (c) 1999 - 2014
Legal Trademarks: Internet Download Manager
Original Filename: IDMan.exe
Internal Name: Internet Download Manager
File Version: 6, 20, 3, 3
File Description: Internet Download Manager (IDM)
Comments: http://www.internetdownloadmanager.com
Language: Language Neutral
Company Name: Tonec Inc.Product Name: Internet Download Manager (IDM)Product Version: 6, 20, 3, 3Legal Copyright: Tonec Inc., Copyright (c) 1999 - 2014Legal Trademarks: Internet Download ManagerOriginal Filename: IDMan.exeInternal Name: Internet Download ManagerFile Version: 6, 20, 3, 3File Description: Internet Download Manager (IDM)Comments: http://www.internetdownloadmanager.comLanguage: Language Neutral
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 8192 | 2375780 | 2379776 | 5.54169 | d729d3bb98500a3184d978a07e344b19 |
.rsrc | 2392064 | 16512 | 20480 | 3.16418 | f3a2ff1587776db204de95da8850528e |
.reloc | 2416640 | 12 | 4096 | 0.011035 | ce88a6025c904059f66934f629ef88ac |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://whatismyipaddress.com/ | 66.171.248.172 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET / HTTP/1.1
Host: whatismyipaddress.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 26 Jun 2014 21:07:59 GMT
Server: Apache/2.2.26 (Unix) DAV/2 PHP/5.4.24 mod_ssl/2.2.26 OpenSSL/0.9.8y
X-Powered-By: PHP/5.4.24
Set-Cookie: pt=52a533fb9072f56deb269777248b02a5; expires=Fri, 27-Jun-2014 21:07:59 GMT
Cache-Control: max-age=15
MS-Author-Via: DAV
Vary: Accept-Encoding
Keep-Alive: timeout=15, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html
29a9..<!doctype html>.<html lang="en">.<head>..<meta charset="windows-1252">..<meta name="robots" content="noarchive">..<title>What Is My IP Address? IP Address Tools and More</title>..<meta name="description" content="IP address lookup, location, proxy detection, email tracing, IP hiding tips, blacklist check, speed test, and forums. Find, get, and show my IP address.">..<meta name="keywords" content="my ip ,ip, address, my, what, is, find, get, show, locate, change, location, how, do, i, ip address, proxy, server, anonymous, hide, conceal, stealth, surf, web, anonymizer, anonymize, changer, privacy, geolocation, geolocate, lookup, look up, locate, trace, track, email, source, headers">..<meta property="fb:admins" content="607824267" />..<link rel="shortcut icon" href="hXXp://cdn.whatismyipaddress.com/favicon.ico">..<link rel="stylesheet" type="text/css" href="hXXp://cdn.whatismyipaddress.com/css/myip_v4_3.css">..<link rel="publisher" href="hXXps://plus.google.com/ whatismyipaddress">..<link rel="canonical" href="hXXp://whatismyipaddress.com">..<script type="text/javascript">if (top.location!= self.location) {top.location = self.location.href;}</script>..<script type='text/javascript'>...var googletag = googletag || {};...googletag.cmd = googletag.cmd || [];...(function() {...var gads = document.createElement('script');...gads.async = true;...gads.type = 'text/javascript';...var useSSL = 'https:' == document.
<<
<<< skipped >>>
Map
The HackTool connects to the servers at the folowing location(s):
Strings from Dumps
IDMan.exe_2012:
`.BRD
`.BRD
@.BRD
@.BRD
UxSSh
UxSSh
SSSh,#i
SSSh,#i
QSSSh #i
QSSSh #i
QPSSh #i
QPSSh #i
L$4PQSSh
L$4PQSSh
FxSSh
FxSSh
t%Fj"V
t%Fj"V
RPSSh
RPSSh
T$TQRSSh
T$TQRSSh
QRSSh
QRSSh
PQSSh
PQSSh
QRSShh6i
QRSShh6i
RPSShT6i
RPSShT6i
RPSSh<6i
RPSSh<6i
PQSSh,6i
PQSSh,6i
SSSht5i
SSSht5i
PQSSh@5i
PQSSh@5i
T$dQRSSh07i
T$dQRSSh07i
D$8RPSSh
D$8RPSSh
T$LQRSSh
T$LQRSSh
PQSShTBi
PQSShTBi
PQSShlUi
PQSShlUi
SSSSSh
SSSSSh
jCSSSShP0l
jCSSSShP0l
PSSSh
PSSSh
SSSSh
SSSSh
PVSSh
PVSSh
PQSSh|`i
PQSSh|`i
SSSShx"i
SSSShx"i
SSSSh,"i
SSSSh,"i
SSSSh$Mi
SSSSh$Mi
SSh0wi
SSh0wi
tdSSh
tdSSh
PQSSh|
PQSSh|
PWSSh
PWSSh
T$DQRSSh
T$DQRSSh
T$\QRSSh
T$\QRSSh
T$HQRSSh
T$HQRSSh
L$HPQSSh
L$HPQSSh
RSSSh
RSSSh
RVSSh
RVSSh
PSSSht
PSSSht
QPSSht
QPSSht
QRSSht
QRSSht
RSSShl
RSSShl
QPSShl
QPSShl
L$TPQSSh
L$TPQSSh
D$<RPSSh><pre>D$,RPSSh</pre><pre>PQSShh"i</pre><pre>!"#$%&'()* ,-./0123</pre><pre>456789:;<=>?@</pre><pre>PQSSh,</pre><pre>t~9.tz</pre><pre>T$0QRSSh</pre><pre>FtPh</pre><pre>U,RWSShl</pre><pre>tCPWh<</pre><pre>>"u.Fj"V</pre><pre>QRSSh\</pre><pre>T$4QRSSh</pre><pre>D$HRPSSh0</pre><pre>PQSShl</pre><pre>u$SShe</pre><pre>commctrl_DragListMsg</pre><pre>COMCTL32.DLL</pre><pre>CCmdTarget</pre><pre>GDI32.DLL</pre><pre>%*.*f</pre><pre>windows</pre><pre>CNotSupportedException</pre><pre>MSWHEEL_ROLLMSG</pre><pre>KERNEL32.DLL</pre><pre>ole32.dll</pre><pre>__MSVCRT_HEAP_SELECT</pre><pre>user32.dll</pre><pre>WSOCK32.dll</pre><pre>GetWindowsDirectoryA</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>PeekNamedPipe</pre><pre>KERNEL32.dll</pre><pre>ExitWindowsEx</pre><pre>MsgWaitForMultipleObjects</pre><pre>EnumWindows</pre><pre>GetKeyState</pre><pre>CreateDialogIndirectParamA</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookExA</pre><pre>GetAsyncKeyState</pre><pre>USER32.dll</pre><pre>SetViewportOrgEx</pre><pre>OffsetViewportOrgEx</pre><pre>SetViewportExtEx</pre><pre>ScaleViewportExtEx</pre><pre>GetViewportExtEx</pre><pre>GDI32.dll</pre><pre>comdlg32.dll</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExA</pre><pre>RegCreateKeyExA</pre><pre>RegEnumKeyA</pre><pre>RegQueryInfoKeyA</pre><pre>RegDeleteKeyA</pre><pre>RegEnumKeyExA</pre><pre>RegNotifyChangeKeyValue</pre><pre>RegFlushKey</pre><pre>RegCreateKeyExW</pre><pre>RegLoadKeyA</pre><pre>RegRestoreKeyA</pre><pre>RegSaveKeyA</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteA</pre><pre>ShellExecuteExW</pre><pre>ShellExecuteExA</pre><pre>FindExecutableW</pre><pre>ShellExecuteW</pre><pre>SHFileOperationA</pre><pre>SHFileOperationW</pre><pre>SHELL32.dll</pre><pre>COMCTL32.dll</pre><pre>oledlg.dll</pre><pre>OLEPRO32.DLL</pre><pre>OLEAUT32.dll</pre><pre>InternetCombineUrlA</pre><pre>InternetCrackUrlA</pre><pre>InternetCanonicalizeUrlA</pre><pre>GetUrlCacheEntryInfoW</pre><pre>InternetCanonicalizeUrlW</pre><pre>WININET.dll</pre><pre>https://secure.</pre><pre>http://www.</pre><pre>%s&lng=%s</pre><pre>.internetdownloadmanager.com/</pre><pre>AboutD.htm</pre><pre>.xn--</pre><pre>ftp://</pre><pre>https://</pre><pre>http://</pre><pre>http://%s</pre><pre>Unknown error during CAddUrlDlg::CAddUrlDlg()</pre><pre>Unknown error during CAddUrlDlg::OnInitDialog()</pre><pre>UnkErr in AddUrl 299</pre><pre>Unknown error during CAddUrlDlg::OnClose()</pre><pre>Unknown error during CAddUrlDlg::OnVerify()</pre><pre>Unknown error during CAddUrlDlg::OnCancel()</pre><pre>https</pre><pre>Unknown error during CAddUrlDlg::OnEditchangeUrl()</pre><pre>FtpPasword</pre><pre>FtpEncPassword</pre><pre>FtpUserName</pre><pre>UseFtpProxy</pre><pre>FtpPort</pre><pre>FtpProxy</pre><pre>HttpPasword</pre><pre>HttpEncPassword</pre><pre>HttpUserName</pre><pre>UseHttpProxy</pre><pre>HttpPort</pre><pre>HttpProxy</pre><pre>HttpsPasword</pre><pre>HttpsEncPassword</pre><pre>HttpsUserName</pre><pre>UseHttpsProxy</pre><pre>HttpsPort</pre><pre>HttpsProxy</pre><pre>http=</pre><pre>https=</pre><pre>Software\Microsoft\Windows\CurrentVersion\Internet Settings</pre><pre>%%0Ý</pre><pre>%s %s</pre><pre>fceb7191-46c6-4fb2-bc5f-a10317cd4b1a</pre><pre>fc21ec12-91cc-4546-8ce9-0fea34ce5ad9</pre><pre>f1b17826-2437-4a4d-a9d0-97ee5c76c164</pre><pre>db47a145-d5cc-424d-885d-7a305ebc25b0</pre><pre>d177c6d9-1454-476c-bcc3-1195d036d6e0</pre><pre>cf2d8c1d-bb0e-4cdc-9e97-3cc6da9f48c7</pre><pre>cb6498f3-91f5-4e72-bdd3-35e5a6dc6d5f</pre><pre>851aba31-d661-4825-a37f-5bd0faeb4d88</pre><pre>80993b9b-0cd0-4b2d-864c-88151c635fe5</pre><pre>77e27bc6-988a-4b45-bdf1-85a8928f86ea</pre><pre>6528e7db-f86d-4398-a3df-abf0e7b70aa2</pre><pre>64a72197-bda2-449e-ba78-8e0335442661</pre><pre>205801ea-84b1-4085-b818-b1c6fb567bd7</pre><pre>179619ba-deeb-4436-abaf-82eeaf2f3816</pre><pre>144323b7-20c3-4b5f-b2a5-1cd0d6996dbc</pre><pre>02c1811b-6b25-416a-aca8-dc671d68056d</pre><pre>00645ccd-b777-44a2-9b36-1fb3f423b559</pre><pre>Cannot open regkey in CBrInt constr</pre><pre>Cannot open(/create) registry subkey during CBrowsersIntegration::Save().</pre><pre>Mozilla</pre><pre>Google Chrome</pre><pre>chrome</pre><pre>Opera</pre><pre>OPERA</pre><pre>Mozilla firefox</pre><pre>Firefox</pre><pre>fceb7191-46c6-4fb2-bc5f-000000000000</pre><pre>webHancer</pre><pre>New.net</pre><pre>rpcrt4.dll</pre><pre>%s%s%s</pre><pre>%s\%s</pre><pre>sporder.dll</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</pre><pre>%s%sGoogle\Chrome\User Data\Default\Extensions</pre><pre>Software\Mozilla\Firefox\Extensions</pre><pre>Software\Mozilla</pre><pre>Software\Mozilla\Waterfox</pre><pre>Software\Mozilla\Aurora</pre><pre>Software\Mozilla\Mozilla Firefox</pre><pre>manifest.json</pre><pre>SOFTWARE\Google\Chrome\Extensions</pre><pre>SOFTWARE\Google\Chrome\Extensions\%s</pre><pre>Software\Google\Chrome</pre><pre>Software\Google\Chrome\Extensions</pre><pre>Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{19129CDA-AFC0-4330-99BC-C5A834F89006}</pre><pre>Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A}</pre><pre>Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4}</pre><pre>"%s" "%s"</pre><pre>isExtensionSupported</pre><pre>MozillaFirebird</pre><pre>Mozilla Firebird</pre><pre>seamonkey</pre><pre>SeaMonkey</pre><pre>mozilla</pre><pre>firefox</pre><pre>Mozilla Firefox</pre><pre>{7D11E719-FF90-479C-B0D7-96EB43EE55D7}</pre><pre>%sIDMGrHlp.exe</pre><pre>%sUninstall.exe</pre><pre>Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</pre><pre>http://www.internetdownloadmanager.com/register/new_faq/enableBFE.html</pre><pre>\\.\IDMTDI</pre><pre>New.net Startup</pre><pre>Software\Microsoft\Windows\CurrentVersion\Run</pre><pre>StEnableBFEMsg</pre><pre>net.exe</pre><pre>\\.\IDMWFP</pre><pre>1.2.0.13</pre><pre>kltdi.sys</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects</pre><pre>https\</pre><pre>http\</pre><pre>{0055C089-8582-441B-A0BF-17B458C2A3A8}</pre><pre>Software\Opera Software</pre><pre>IntegrateOpera</pre><pre>Unknown error during CBrowsersIntegrator::GetMozillaInstallDir()</pre><pre>SOFTWARE\mozilla.org\Mozilla</pre><pre>IntegrateMozilla</pre><pre>MozillaFirebird.exe</pre><pre>%sPlugins\</pre><pre>Mozilla.exe</pre><pre>SOFTWARE\FullCircle\TalkBack\%s</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome</pre><pre>%s%s\chrome.manifest</pre><pre>%s%s\chrome\idmmzcc.jar</pre><pre>%s%s\components2\iIDMMzCC.xpt</pre><pre>%s%s\components\iIDMMzCC.xpt</pre><pre>%s%s\components10\idmmzcc64.dll</pre><pre>%s%s\components10\idmmzcc.dll</pre><pre>%s%s\components2\idmcchandler2_64.dll</pre><pre>%s%s\components2\idmcchandler2.dll</pre><pre>%s%s\components2\idmmzcc64.dll</pre><pre>%s%s\components2\idmmzcc.dll</pre><pre>%s%s\components\idmmzcc.dll</pre><pre>%s\drivers\idmwfp.sys</pre><pre>%s\drivers\idmtdi.sys</pre><pre>\WinInit.Ini</pre><pre>PendingFileRenameOperations</pre><pre>PSAPI.DLL</pre><pre>%stmp_test.html</pre><pre>%s\Main</pre><pre>%sOpera.exe</pre><pre>%s\flock.exe</pre><pre>SOFTWARE\Mozilla\SeaMonkey</pre><pre>SOFTWARE\Mozilla\Netscape Navigator</pre><pre>Software\mozilla.org\Mozilla Firefox</pre><pre>\StringFileInfo\xx\%s</pre><pre>\StringFileInfo\xx\FileVersion</pre><pre>idmcchandler2_64.dll</pre><pre>idmcchandler2.dll</pre><pre>%s%s\%s</pre><pre>%sNP_IDM%d.dll</pre><pre></pre><pre><em:updateURL></em:updateURL></pre><pre>%s%s\install.rdf</pre><pre>%sidmmzcc03</pre><pre>%sidmmzcc02</pre><pre>%sidmmzcc01</pre><pre>%sidmmzcc3</pre><pre>%sidmmzcc2</pre><pre>%sidmmzcc</pre><pre>Software\Mozilla\SeaMonkey</pre><pre>Software\Mozilla\SeaMonkey\Extensions</pre><pre>Software\Mozilla\Firefox</pre><pre>Cannot create regkey in CBrIntr:SaveBIA, s2</pre><pre>Cannot create regkey in CBrIntr:SaveBIA</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>%s (*.exe)|*.exe||</pre><pre>%s executable file (%s.exe)|%s.exe||</pre><pre>%scnlurllist.dat</pre><pre>%s*%s</pre><pre>%s://*.%s%s</pre><pre>%sdefextmap.dat</pre><pre>%surlexclist.dat</pre><pre>%s (5)</pre><pre>www.internetdownloadmanager.com</pre><pre>testing.html</pre><pre>%s (%d)</pre><pre>idmbrbtn.dll</pre><pre>.youtube.com</pre><pre>secure%s</pre><pre>www%s</pre><pre>.com/fillregform.html?d=</pre><pre>.com/autoreg.html?d=</pre><pre>%s?v=%s</pre><pre>idmupdt2.exe</pre><pre>idmupdt.exe</pre><pre>%s?%s</pre><pre>update.cgi</pre><pre>CURRENT_USER\%s</pre><pre>Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}</pre><pre>Update.htm</pre><pre>application/vnd.lumberjack.manifest</pre><pre>image/x-windows-bmp</pre><pre>application/x-winexe</pre><pre>%sGrabber\</pre><pre>%stemplate%s.dat</pre><pre>%stemplate*.dat</pre><pre>%sToolbar\%s</pre><pre>%sToolbar\*.tbi</pre><pre>Connect.dll</pre><pre>%s%ld</pre><pre>http://www.internetdownloadmanager.com/support/firefox_integration.html</pre><pre>http://www.internetdownloadmanager.com/support/firefox8_integration.html</pre><pre>http://www.internetdownloadmanager.com/register/new_faq/chrome_extension2.html</pre><pre>%d%sd %s</pre><pre>%d %s</pre><pre>%s (*.*)</pre><pre>chrome.exe</pre><pre>Firefox/</pre><pre>firefox.exe</pre><pre>%s\Downloads\%s</pre><pre>%s%s%s%s</pre><pre>bShTipWEBMPlayer</pre><pre>.webm</pre><pre>%s. %s.</pre><pre>WEBM</pre><pre>http://www.internetdownloadmanager.com/flv_player.html</pre><pre>CompleteDlg.htm</pre><pre>http://www%s/uptateidm.cgi?v=%s</pre><pre>https://secure%s/subscription.html?v=%s</pre><pre>http://www%s/contact_us.html?v=%s</pre><pre>06/17/14</pre><pre>%sidmvs.dll</pre><pre>RegCreateKeyEx() failed during OpenGlobalIDMRegKey(), errCode = %ld</pre><pre>%s%sIDM</pre><pre>%s%sIDM\%s</pre><pre>Internet Download Manager detected that its registry keys had been damaged since the last run. It's possible that you run a flaky spyware remover program which corrupted system registry. Internet Download Manager will try to restore all damaged data, but some data may remain corrupted.</pre><pre>http://www.internetdownloadmanager.com/support/damaged_keys.html</pre><pre>Internet Download Manager detected that its registry keys had been damaged since the last run. It's possible that you run a flaky spyware remover program like Spyhunter which corrupted system registry. Internet Download Manager will try to restore all damaged data, but some data may remain corrupted.</pre><pre>%Program Files%\Spyhunter</pre><pre>SHCopyKeyA</pre><pre>shlwapi.dll</pre><pre>%s\settings.bak</pre><pre>%s%sDMCache\%s</pre><pre>%s%sDMCache</pre><pre>SpecialKeys</pre><pre>Passwords</pre><pre>%s%sDownloads\</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\</pre><pre>LastFileCmdLine</pre><pre>LastDirCmdLine</pre><pre>LastUrlCmdLine</pre><pre>Unknown error during CDownloaderApp::InitInstance(), downloaderDlg.DoModal()</pre><pre>IDMShellExt.dll</pre><pre>%sIDMShellExt.dll</pre><pre>%sIDMIntegrator64.exe</pre><pre>/s "%sdownlWithIDM64.dll"</pre><pre>/s "%sIDMGetAll64.dll"</pre><pre>/s "%sIDMIECC64.dll"</pre><pre>%sIDMShellExt64.dll</pre><pre>CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}\InProcServer32</pre><pre>/s "%sIDMShellExt64.dll"</pre><pre>idmfsa.dll</pre><pre>downlWithIDM.dll</pre><pre>IDMIECC.dll</pre><pre>IDMGetAll.dll</pre><pre>RichEd32.Dll</pre><pre>Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}</pre><pre>FtpPasive</pre><pre>MonitorUrlClipboard</pre><pre>%s /onboot</pre><pre>%s Full</pre><pre>%s Trial</pre><pre>3GP 7Z AAC ACE AIF ARJ ASF AVI BIN BZ2 EXE GZ GZIP IMG ISO LZH M4A M4V MKV MOV MP3 MP4 MPA MPE MPEG MPG MSI MSU OGG OGV PDF PLJ PPS PPT QT R0* R1* RA RAR RM RMVB SEA SIT SITX TAR TIF TIFF WAV WMA WMV Z ZIP</pre><pre>SOFTWARE\Classes\AppID\%s</pre><pre>AppID\%s</pre><pre>CLSID\{AC746233-E9D3-49CD-862F-068F7B7CCCA4}</pre><pre>{AC746233-E9D3-49CD-862F-068F7B7CCCA4}</pre><pre>IDMan.CIDMLinkTransmitter</pre><pre>Kernel32.DLL</pre><pre>IDMan.exe</pre><pre>VDMDBG.DLL</pre><pre>DownloaderCmdLine::ParseParam(LPCTSTR lpszParam, BOOL bFlag, BOOL bLast)</pre><pre>rbmsg</pre><pre>Invalid URL</pre><pre>%sLanguages\%s</pre><pre>lang0xx.txt</pre><pre>lng0x%x.txt</pre><pre>Unknown error during SetIconsOnUrlListProc()</pre><pre>comctl32.dll</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System</pre><pre>%sMediumILStart.exe</pre><pre>ecom.cimetz.com</pre><pre>siteseal.thawte.com</pre><pre>CDownloaderDlg::CreateColumnInUrlList(): inserted index != sent parameter</pre><pre>506938841</pre><pre>.testingext</pre><pre>URL::set_fileName(): Not enough memory!</pre><pre>URL::set_Referer(): Not enough memory!</pre><pre>URL::set_serverPath(): Not enough memory!</pre><pre>URL::set_serverName(): Not enough memory!</pre><pre>URL::set_Cookie(): Not enough memory!</pre><pre>%%s" /ch %ld /w %I64d</pre><pre>DntShMsgOnCNTOOHtml4</pre><pre>%d%sd%%</pre><pre>%s %s/%s</pre><pre>%s/%s</pre><pre>ProcessOnNewUrl()</pre><pre>Unknown error during CDownloaderDlg::ProcessOnNewUrl()</pre><pre>/fillregform.html?d=</pre><pre>shell32.dll OpenAs_RunDLL %s</pre><pre>Unknown error during CDownloaderDlg::OnKeydownUrllist()</pre><pre>Unknown error during CDownloaderDlg::OnItemchangedUrllist()</pre><pre>Unknown error during CDownloaderDlg::OnColumnclickUrlList()</pre><pre>http://www.internetdownloadmanager.com/support/damaged_keys2.html</pre><pre>Internet Download Manager found out that you had Spyhunter software installed. This is a low quality spyware remover that mixes registry keys, and may screw up installations of spyware clean products. For example, Spyhunter misidentifies one of IDM registry keys as SideSearch, and deletes it. It doesn't affect IDM work in any way, nor its installation, but may damage IDM downloads. We tried to contact creators of Spyhunter, but couldn</pre><pre>bshexmsg</pre><pre>MIME\Database\Content Type\%s</pre><pre>.gzip</pre><pre>.test</pre><pre>tmp1%s</pre><pre>tmp1.%s</pre><pre>Unkerr in maindlg:GetStrUrl</pre><pre>ExportListToFile()</pre><pre>Unknown error during CDownloaderDlg::ExportListToFile()</pre><pre>%s (*.ef2)|*.ef2||</pre><pre>%s (*.txt)|*.txt|%s (*.*)|*.*||</pre><pre>ImportListFromFile()</pre><pre>Unknown error during CDownloaderDlg::ImportListFromFile()</pre><pre>%s (*.ef2; *.ief)|*.ef2;*.ief||</pre><pre>OnCommandLineUrl()</pre><pre>Unknown error during CDownloaderDlg::OnCommandLineUrl()</pre><pre>ProcessOnNewUrl2()</pre><pre>Unknown error during CDownloaderDlg::ProcessOnNewUrl2()</pre><pre>explorer.exe</pre><pre>/n,/select,"%s"</pre><pre>\SpyHunter.exe</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE5B8E34-973C-4FBE-AC83-99F064009FC7}</pre><pre>%Program Files%\SpyHunter\SpyHunter.exe</pre><pre>http://www.internetdownloadmanager.com/support/toolbar2.html</pre><pre>%sgrprdb</pre><pre>index.html</pre><pre>%s*.%s</pre><pre>%s%sIDMGrHlp.exe</pre><pre>name=%s</pre><pre>IDM_queues.htm</pre><pre>SourceURL:</pre><pre>updatevm.txt</pre><pre>%s\Scheduler\q_%s.dt</pre><pre>Operation {new char[...]} returned 0 during CDownloadQueue constructor.</pre><pre>Cannot open(/create) registry queue subkey.</pre><pre>%s\Scheduler</pre><pre>%s\Scheduler\s_%s.dt</pre><pre>%s%s:%d/%s</pre><pre>%s%s/%s</pre><pre>Unknown error during CSessionsArray::GetIndexIfUrlInArray()</pre><pre>Unkerr in CDPrgDlg SetURL</pre><pre>Unkerr in CDwnlPrDlg, OnCmd, wP=%ld</pre><pre>%s/%s %s</pre><pre>%s ( %d%sd %% )</pre><pre>%s (%s)</pre><pre>%d%sd %s</pre><pre>Software\DownloadManager\IDMBI\Firefox\DwnlPanel</pre><pre>CEditMozillaMenutab</pre><pre>Advapi32.dll</pre><pre>*.update.microsoft.com download.windowsupdate.com siteseal.thawte.com ecom.cimetz.com *.voice2page.com</pre><pre>Options.htm</pre><pre>http-equiv</pre><pre>%s://%s%s%s</pre><pre>%d; URL=%s</pre><pre>update_dq.txt?v=%s</pre><pre>update608.txt</pre><pre>%s:%ld</pre><pre>jsproxy.dll</pre><pre>SocksPass</pre><pre>SocksPort</pre><pre>%d %d:%d:%d %d</pre><pre>default.htm</pre><pre>www.sharingmatrix.com</pre><pre>sharingmatrix.com</pre><pre>www.filesonic.</pre><pre>http://api.filesonic.com/%s</pre><pre>link?method=getDownloadLink&ids=%s&u=%s&redirect=true</pre><pre>api.filesonic.com</pre><pre>%s-%s</pre><pre>Right_click_IE.htm</pre><pre>Cannot open(/create) registry GetAllDlgLS subkey.</pre><pre>%s, Time: %.15s.%hu %s</pre><pre>GrbFsDlg::OnAddF:RegCrKey failed, err=%ld</pre><pre>%sproject%s.gsd</pre><pre>%sGrabber\Projects\</pre><pre>%s*.gsd</pre><pre>\\.\%s:</pre><pre>%s[%s]%s</pre><pre>\\.\PhysicalDrive%d</pre><pre>avi mpg mpe mpeg asf wmv mov qt rm mp4 flv m4v webm ogv ogg</pre><pre>Cannot open(/create) registry subkey during CIDMFoldersTree constructor.</pre><pre>Cannot open(/create) registry subkey during CIDMFoldersTree::Save().</pre><pre>Cannot open(/create) registry key during CIDMFoldersTree::Save().</pre><pre>Cannot open(/create) registry key during CIDMFoldersTree::DeleteItem().</pre><pre>Cannot open(/create) registry key during CIDMFoldersTree::SetVisiblity().</pre><pre>Cannot open(/create) registry key during CIDMFoldersTree::CheckQAU().</pre><pre>Cannot open(/create) registry key during CIDMFoldersTree::DeleteQAU().</pre><pre>HHCtrl.ocx</pre><pre>idman.chm</pre><pre>tutor.chm</pre><pre>grabber.chm</pre><pre>scheduler.chm</pre><pre>Cannot open(/create) registry listsettings subkey.</pre><pre>Cannot open(/create) registry key during CIDMMainDlgTree::OnEditItem().</pre><pre>%sproxy.pac</pre><pre>EncPassword</pre><pre>Software\DownloadManager\ProxyPac\%s</pre><pre>VERSION.dll</pre><pre>Gr GetWW:CrTh2 failed, err %ld</pre><pre>Gr GetWW:CrTh failed, err %ld</pre><pre>Gr AsyncMsgHandler:CrWnd failed, err %ld</pre><pre>Gr AsyncMsgHandler:RegCl failed, err %ld</pre><pre>Unk err in AsyncWndProc, uMsg=%ld, wParam=%ld, lParam=%ld</pre><pre>%sempty.html</pre><pre>%s %s error %ld</pre><pre>%s_%s%s</pre><pre>Unk err in Gr CrTmpF</pre><pre>%s_%s.pdb</pre><pre>logoutUrl=</pre><pre>manualLoginUrl=</pre><pre>useManualLogin=</pre><pre>password=</pre><pre>login=</pre><pre>isSPC=%d</pre><pre>tmpFolder=%s</pre><pre>manualLoginUrl=%s</pre><pre>useManualLogin=%d</pre><pre>logoutUrl=%s</pre><pre>denyLogout=%d</pre><pre>password=%s</pre><pre>login=%s</pre><pre>useAuthorization=%d</pre><pre>startingPage=%s</pre><pre>template=%s</pre><pre>version=%d</pre><pre>%smanuallogin.html</pre><pre>"%%s" /a 1 /w %I64d /i 2000000000 /%s "%%s" /ct "%s" /u "%s"</pre><pre>"%%s" /a 1 /w %I64d /i 2000000000 /%s "%%s" /ct "%s" /u "%s" /cp "%s" /lb "%s" /ok "%s" /cb "%s"</pre><pre>Gr SetPID:RegCrKey failed, err=%ld</pre><pre>excFP=%s</pre><pre>useExcFP=%d</pre><pre>incFP=%s</pre><pre>useIncFP=%d</pre><pre>excSP=%s</pre><pre>useExcSP=%d</pre><pre>incSP=%s</pre><pre>useIncSP=%d</pre><pre>maxSzU=%d</pre><pre>maxSzA=%d</pre><pre>useMaxSz=%d</pre><pre>minSzU=%d</pre><pre>minSzA=%d</pre><pre>useMinSz=%d</pre><pre>overwrEx=%d</pre><pre>replHtmlLnk=%d</pre><pre>usesubf=%d</pre><pre>wsaveto=%s</pre><pre>category=%d</pre><pre>saveMode=%d</pre><pre>useIEC=%d</pre><pre>useDescr=%d</pre><pre>autoAdd=%d</pre><pre>goTSF=%d</pre><pre>prJava=%d</pre><pre>dnp=%d</pre><pre>dntAddMrrs=%d</pre><pre>dwnlAO=%d</pre><pre>igPp=%d</pre><pre>allSOMD=%d</pre><pre>nLevelOS=%d</pre><pre>nLevel=%d</pre><pre>wholeSite=%d</pre><pre>nDATSTF=%d</pre><pre>nEATSTF=%d</pre><pre>SHDeleteKeyA</pre><pre>Shlwapi.dll</pre><pre>%sproject%s_%s.igp</pre><pre>%sproject%s.igp</pre><pre>"%%s" /a 2 /w %I64d /fl %ld /i %ld /%s "%%s" /ct "%s" /u "%s"</pre><pre>%s%sa%s\</pre><pre>wininet.dll</pre><pre>%sChList</pre><pre>%ld %ld %ld %d %d %d p%s</pre><pre>%s_fda.pdb</pre><pre>%ld %ld %ld %d %d %d</pre><pre>%s*f*</pre><pre>%s%s%s\</pre><pre>action.html</pre><pre>filters.html</pre><pre>wheretosearch.html</pre><pre>saveto.html</pre><pre>starting.html</pre><pre>http://www.internetdownloadmanager.com/welcome2.html?%s%s</pre><pre>http://www.internetdownloadmanager.com/welcome.html?%s%s</pre><pre>http://www.internetdownloadmanager.com/?%s%s</pre><pre>%sbuy1.html?%s%s</pre><pre>%sbuy_idm.html?%s%s</pre><pre>mailto:?subject=Internet Download Manager - very cool application!!!&body=download from http://www.internetdownloadmanager.com</pre><pre>download from </pre><pre>Internet Download Manager - very cool application!!!</pre><pre>http://www%s/welcome2.html?%s</pre><pre>http://www%s/welcome.html?%s</pre><pre>http://www%s/?%s</pre><pre>%sbuy1.html?%s</pre><pre>%sbuy_idm.html?%s</pre><pre>https://secure%s/</pre><pre>mailto:support@internetdownloadmanager.com?subject=IDM_%s</pre><pre>IDM's temporary directory for storing file parts during download is located on drive "%s", this drive has %s file system. The files larger than %d GBytes cannot be written on this file system.</pre><pre>The size of "%s" file is %.1f GBytes.</pre><pre>The drive "%s" where you want to save this file has %s file system. The files larger than %d GBytes cannot be written on this file system.</pre><pre>1. Please RESTART Google Chrome and press on Chrome menu (arrow 1 on the image)</pre><pre>5. If you use incognito mode in Chrome, you need to enable "Allow in incognito" checkbox (arrow 5 on the image).</pre><pre>IDM extension has been successfully installed into (or updated in) Google Chrome browser.</pre><pre>You must enable "IDM Integration module" extension in Google Chrome settings if you want IDM to work with Chrome properly</pre><pre>This version of IDM does not support this type of downloading. Try to update IDM to the latest version.</pre><pre>If automatically updating your Kaspersky product does not help, please contact Kaspersky support to get an update for the "kltdi" driver.</pre><pre>You need to restart the Chrome to apply changes</pre><pre>In order to update a part of IDM extension for Firefox please close Firefox (or SeaMonkey) and then press "Retry" button</pre><pre>IDM cannot check for updates because an important system file is damaged on your computer. Repair this file?</pre><pre>Your browser may not open IDM website because an important system file is damaged on your computer. Repair this file?</pre><pre>IDM cannot engage Advanced Browser Integration because "Base Filtering Engine" Windows service is missing. This could happen because of your system being damaged by a computer malware.</pre><pre>Click OK to open a web page with recovery instructions.</pre><pre>IDM cannot engage Advanced Browser Integration because "Base Filtering Engine" Windows service is not running. Please right-click the Computer icon, select "Manage", navigate to "Services and Applications -> Services", then find "Base Filtering Engine" in the list and right-click on it to open Properties. Change Startup type to "Automatic", click "Start" and confirm changes.</pre><pre>Click OK to visit a web page for additional information.</pre><pre>Cannot connect to the socks server %s</pre><pre>Socks server cannot connect to %s</pre><pre>Import links to IDM</pre><pre>It's possible that you need to change VPN connection that is set in IDM options, or turn off "Use Windows Dial Up / VPN Networking" checkbox in IDM options -> "Dial Up / VPN" tab</pre><pre>IDM cannot download this protected stream for legal reasons. The download of such streams is not supported because IDM may not bypass the technological measures which are made for the protection of audio, video and data content.</pre><pre>These settings are unavailable when "%s" is turned on</pre><pre>%s is a product key of Internet Download Manager.</pre><pre>Please press "%s" button to buy IDM.</pre><pre>What is the "%s"?</pre><pre>1. You do not have Administrator rights or you did not allow IDM helper program to execute as Administrator.</pre><pre>IDM has intercepted this file from web media player because of the disabled download panel for the respective file type in IDM Options.</pre><pre>If you want IDM to refrain from intercepting such files please go to the "General" tab in IDM Options, click "Edit..." button for download panels in browsers and turn on "Don't capture downloads from web-players automatically" checkbox in the pop-up window.</pre><pre>Internet Download Manager will install a new network driver, which significantly improves integration with web players and changes old integration with several browsers like Chrome or Opera. If you encounter any problems with your browser, please open IDM options and turn off "Use advanced browser integration" checkbox on General tab. It will turn off the new driver.</pre><pre>IDM shows a download panel instead of capturing downloads in web players when %s integration is working correctly.</pre><pre>You have an obsolete %s browser integration, or %s integration is not installed. Would you like to read how to fix it?</pre><pre>Sometimes when you click on a link, your browser requests other files AT THE SAME TIME like Java scripts, web pages, pictures, etc. When you press and hold down a special key, IDM intercepts these files, and the browser may not request the necessary file because it will not run a Javascript, which has been intercepted by IDM erroneously. If you want to intercept and download only the necessary files with IDM, please turn on the option below:</pre><pre>IDM executable is on desktop</pre><pre>You have placed IDM's executable file on the desktop. IDM cannot work correctly without its other files, please move IDMan.exe back to programs, and create a shortcut to IDM on Desktop instead. To create a shortcut, open IDM folder in Programs, right click on IDMan.exe file and use "Send To -> Desktop (create shortcut)" popup menu item.</pre><pre>Would you like to know how to download files from %s site with IDM?</pre><pre>%s video has been downloaded</pre><pre>IDM found out that you computer might not have a player that would play %s videos. You will need to install any %s player.</pre><pre>Would you like to read about a %s player?</pre><pre>It will install a new network driver, which significantly improves integration with web players and changes old integration with several browsers like Chrome or Opera. If you encounter any problems when connecting to the Internet, for example, a system freezing, or crashes, etc., please open IDM options and turn off "Use advanced browser integration" checkbox on General tab. It will turn off the new driver.</pre><pre>IDM will download a web-page instead of a file.</pre><pre>(Currently this feature works for Internet Explorer, IE based browsers, Firefox and Mozilla-based browsers)</pre><pre>For web-players</pre><pre>You have entered a space after the password. If the space was entered by mistake, would you like IDM to delete the space?</pre><pre>You have entered a space before the password. If the space was entered by mistake, would you like IDM to delete the space?</pre><pre>Cannot find any web address in the clipboard!</pre><pre>Several URLs found in clipboard. Do you want to download them?</pre><pre>If you don't want to download anything please close "%s" dialog using "Cancel" button.</pre><pre>Checking address: %s</pre><pre>The web site sent a web page instead of a file when IDM requested this file second time. Probably this site uses temporary links and does not allow requesting the same address twice.</pre><pre>Downloading owner web page to refresh link address</pre><pre>IDM will open a web page in your browser where it captured this download. Please start the download of the same file from your browser again, and IDM will try to capture a new address or new session data to resume this download</pre><pre>Note: If you uncheck a file type on the list above and if the file type is in the list on "Options->File Types" tab, downloads of this file type are captured by IDM automatically and won't be played in the web-player. If you want to prevent it, check the box below:</pre><pre>Download this %s</pre><pre>A CRC error occurred while downloading. That means that you had some problem with your hard disk. You should scan your disk for errors by using "Error-checking" on disk properties->tools Windows dialog.</pre><pre>Firefox and other Mozilla based</pre><pre>The data transfer has been interrupted and the server does not support "resume". It's only possible to download this file from the beginning.</pre><pre>"IDM CC" extension for Mozilla based browsers has changed in this version of IDM. You will need to reinstall the extension to use new features. Do you want to install the new "IDM CC" extension for browsers which have an old "IDM CC" extension?</pre><pre>"IDM CC" extension for Mozilla based browsers has changed in this version of IDM. You will need to reinstall the extension to use new features. Do you want to reinstall the extension for %s %s browser?</pre><pre>Stop %s</pre><pre>Start %s</pre><pre>Do you really want to delete %s?</pre><pre>The browser made the first request of "%s" file and then when IDM tried to request the same file again, the site sent a web page to IDM instead of the download.</pre><pre>To take over this download you can set a special key in "IDM Options->General->Keys...". Press and hold this key while clicking on download link/button so that IDM could take over the download before the first browser request. Note that "Ins" key should work for most browsers.</pre><pre>The requested file looks like html web page.</pre><pre>You'll need to provide administrator permissions to perform this operation</pre><pre>This feature is not available for Windows Vista, but it should be implemented soon. Please check for IDM updates.</pre><pre>Drag this icon to start the drag and drop operation for the downloaded file.</pre><pre>Netscape 7.xx and 6.xx</pre><pre>Please confirm the installation of idmmzcc.xpi extension from Tonec Inc. on corresponding browser dialog and restart the browser after the installation.</pre><pre>IDM detected that %s %s browser had been also installed on your computer.</pre><pre>Cannot install plugins for %s %s browser!</pre><pre>%s %s browser will be opened now to install the extension for integration with IDM.</pre><pre>Cannot install idmmzcc.xpi browser extension!</pre><pre>IDM has detected that %s %s browser is default browser on your computer.</pre><pre>IDM has been successfully integrated into Mozilla Firefox.</pre><pre>You need to restart the Firefox browser to apply changes</pre><pre>Cannot install idmmzcc.xpi browser extension for Mozilla Firefox!</pre><pre>Please locate the browser executable file on the next dialog.</pre><pre>Plugins for %s browser have been removed.</pre><pre>Plugins for %s %s browser have been installed.</pre><pre>Plugins for %s browser have been installed.</pre><pre>IDM cannot find %s browser on your computer. Please locate the browser executable file on the next dialog.</pre><pre>Note: Opera and OLD Mozilla based browsers can be integrated with IDM using plugins. This integration type does not support server exceptions list to prevent downloading with IDM. Also when you change file types list you need to restart these browsers to reload plugins.</pre><pre>Note: Opera and OLD Mozilla based browsers can be integrated with IDM using plugins. This integration type does not support special keys to prevent or force downloading with IDM from these browsers. If you want to prevent or force downloading with IDM by pressing special keys, you should use "Advanced browser integration".</pre><pre>Rebooting in %d seconds</pre><pre>Automatically put in "%s" category the following file types:</pre><pre>Remember this path for "%s" category</pre><pre>Downloaded %s (%I64d Bytes)</pre><pre>Restore all download windows</pre><pre>t be deleted. The grabber will parse all web pages on the site again, and it may take a while.</pre><pre>The Java-script will not be processed for the web pages which have been already explored/processed. If you want to process Java-script for these pages you will need to press "Update all" toolbar button on the Grabber Action dialog.</pre><pre>The scheduled grabber project could not be started at %d:d because the project settings were being edited at this time.</pre><pre>The scheduled grabber project could not be started at %d:d because the project was running at this time.</pre><pre>Cannot start downloading the manual login page. Please check the URL syntax.</pre><pre>Downloading the manual login page</pre><pre>There is not enough free space on drive %s to open the grabber project. Please free some space and try again.</pre><pre>There is not enough free space on drive %s to process the grabber project. Please free some space and try again.</pre><pre>There is no asterisk wildcard in URL to create a download file list!</pre><pre>Press the OK button when login process completes</pre><pre>IDM Site Grabber. Step %d --- %s</pre><pre>Cannot open the file "%s"</pre><pre>Do you want to delete the "%s" grabber project?</pre><pre>The project with "%s" name already exists. Please select another name.</pre><pre>Manual login page</pre><pre>Please enter manual login page or uncheck the corresponding checkbox</pre><pre>Please enter login and password or uncheck the "Use Authorization" checkbox</pre><pre>Web content</pre><pre>If these events did not occur, please send %s file (if it exists) to Internet Download Manager support department for analysis.</pre><pre>When trying to resume the download, Internet Download Manager got a response from the server that it doesn't support resuming the download.</pre><pre>The whole web site</pre><pre>All files of the web site except web pages and images</pre><pre>All Video files of the web site</pre><pre>All Pictures of the web site</pre><pre>The filter with "%s" name already exists. Please choose another name.</pre><pre>When Advanced Browser Integration is turned on, IDM can catch those downloads which were impossible to catch before in IDM, or in any other download manager. Also when using the integration, IDM can be integrated into any browsers and Internet applications to take over your FTP/HTTP downloads.</pre><pre>We have created a configuration report that you can send us. Please send us the following information to help us to fix this problem in future versions of IDM. This data is of technical kind. We don't collect your personal information, and we will treat this report as confidential and anonymous.</pre><pre>You have turned off advanced browser integration. If you found a problem with advanced browser integration, we would like to fix the problem for you. In order to fix the problem, we need to collect and analyze some technical information about your computer configuration and installed Internet applications. IDM will collect and show you this information on the next stage before sending it to our support department.</pre><pre>IDM has detected that you are using Windows DialUp networking to connect your modem to the Internet. Would you like to use these settings in IDM?</pre><pre>IDM cannot find %d file(s) that are necessary for browser and system integration. Would you like to download them?</pre><pre>The key(s) to prevent downloading should not be contained in the key(s) to force downloading.</pre><pre>Please choose others keys.</pre><pre>"%s" data transmission protocol is not supported by IDM at this time. Or it might be a spelling error, therefore please check the spelling, and try again.</pre><pre>The name to save the file was "%s", but the server sent the following file type "%s", and the file should be saved as "%s". Would you like to save the file with the name matched the file type received from the server?</pre><pre>Password</pre><pre>%d sec</pre><pre>%d min %d sec</pre><pre>%ld hour(s) %d min</pre><pre>IDM Export Files</pre><pre>From %d:d to %d:d you downloaded %ld MB. All IDM downloads have been stopped at %d:d because you had exceeded your download limits set in IDM Scheduler (or 'Options->Connections')!</pre><pre>All stopped downloads will be resumed automatically at d:d. If you want to resume downloads immediately, change settings in Download Limits and press on Resume.</pre><pre>From %d:d to %d:d you downloaded %ld MB. All IDM downloads will be stopped because you have exceeded your download limits set in in IDM Scheduler (or 'Options->Connections')!</pre><pre>%s, total %ld files</pre><pre>MPEG: Res. %dx%d, %.1f samp per sec, %d bits per samp</pre><pre>WAV: %d samp per sec, %d bits per samp, Length: %s</pre><pre>AVI: Res. %dx%d, %d samp per sec, Length %s</pre><pre>Cannot create folder %s, error code = %ld</pre><pre>Warning: This computer program is protected by copyright laws and international treaties. Unauthorized reproduction or distribution of this program, or any portion of it, may result in severe civil and criminal penalties, and will be prosecuted to the maximum extent possible under law.</pre><pre>Add URL</pre><pre>Please enter login name.</pre><pre>The file with this URL already exists in your list and waits for download to complete. Do you want to resume file?</pre><pre>The file with this URL has been already downloaded by Internet Download Manager. Do you want to download it again?</pre><pre>Invalid URL entered. Please correct.</pre><pre>User names and passwords for servers/sites</pre><pre>Logins</pre><pre>Sites Logins</pre><pre>Change folder for "%s" category on last selected</pre><pre>Default download directory for "%s" category</pre><pre>Would you like to place all old downloads with "%s" file types to this category? The files won't be moved on the hard drive, but will be associated with this category.</pre><pre>The folder "%s" doesn't exist.</pre><pre>Do you really want to delete "%s" category from IDM categories list?</pre><pre>You have %d days left to use Internet Download Manager. Do you want to register your copy of IDM now?</pre><pre>An error occured while loading security dll. Cannot create https connectin.</pre><pre>An error occured while creating security connection to %s.</pre><pre>Cannot find HHCtrl.ocx to display help file!</pre><pre>File %s download complete.</pre><pre>This m3u file contains one or more web links to mp3 files. Would you like to add these mp3 files to your download list?</pre><pre>This m3u file contains a web link to one mp3 file. Would you like to download this mp3 file?</pre><pre>The name to save the file was "%s%s", but the server sent the following name "%s". Would you like to save the file with the file name that was received from the server?</pre><pre>Cannot download this file, maybe this ftp server doesn't support download resume. Would you like to add the same file and download it from the beginning?</pre><pre>An unknown error occured while executing the operation!</pre><pre>The file doesn't have any web links</pre><pre>The file is not a valid IDM export file or the file is corrupted</pre><pre>Import to IDM</pre><pre>The %s file has been moved.</pre><pre>The downloaded file looks like html web page.</pre><pre>If this download was taken over from your browser automatically when you clicked on a link, try to hold Alt key when clicking on the link to let IE open the page.</pre><pre>QuickUpdate for IDM from www.internetdownloadmanager.com. Receiving new files...</pre><pre>Cannot download this file. Invalid http server reply.</pre><pre>File %s - downloaded %s (%I64d Bytes). The file may not have been downloaded completely, because the file size is unknown.</pre><pre>File saved as %s</pre><pre>There is no disk space left on drive '%s'.</pre><pre>The size of %s is %I64d bytes.</pre><pre>There is no disk space left on drive '%s' to store downloaded file parts.</pre><pre>Probably the server does not support command pipelining.</pre><pre>Restarting at the beginning because local file has been erased. Restarting from arbitrary position is not supported in this case.</pre><pre>PORT OK</pre><pre>Sending PORT command...</pre><pre>The server does not support PASV.</pre><pre>Password OK</pre><pre>Password failed</pre><pre>Sending password...</pre><pre>Cannot find the end of string in ftp server reply.</pre><pre>Server sent new location and the file name %s has changed to %s.</pre><pre>The size of file %s has not been found in server reply</pre><pre>Cannot open data connection because ftp server does not support PASV command and checkbox 'Use FTP in PASV mode' in Options->Proxy/Firewall is turned on.</pre><pre>PORT command failed.</pre><pre>Cannot send PORT command.</pre><pre>Cannot open ftp data socket</pre><pre>Error occurred while receiving ftp server reply: Invalid reply format</pre><pre>Error occurred while receiving ftp server reply.</pre><pre>Ftp server doesn't allow connections.</pre><pre>Cannot find this file on ftp server.</pre><pre>Cannot login to ftp server.</pre><pre>Fatal read error occurred while joining downloaded parts into one file</pre><pre>Fatal write error occurred while joining downloaded parts into one file</pre><pre>Virtual memory allocation error while joining downloaded parts into one file</pre><pre>Cannot get the size of next part while joining downloaded parts into one file</pre><pre>Cannot open local file for writing while joining downloaded parts into one file</pre><pre>An unknown error occurred while joining downloaded parts into one file</pre><pre>An unknown error occurred while appending files or joining downloaded parts into one file</pre><pre>Cannot connect to proxy server %s:%ld</pre><pre>Cannot connect to %s:%ld</pre><pre>Cannot find proxy server %s</pre><pre>Cannot find server %s</pre><pre>The size of "%s" file is %I64d bytes.</pre><pre>There is no disk space left on drive "%s"' where you want to save this file.</pre><pre>A socket operation encountered a dead network. This could indicate a serious failure of the network system (i.e. the protocol stack that the WinSock DLL runs over), the network interface, or the local network itself.</pre><pre>A socket operation was attempted to an unreachable network. This usually means the local software knows no route to reach the remote host.</pre><pre>A socket operation failed because the destination host was down. A socket operation encountered a dead host. Networking activity on the local host has not been initiated.</pre><pre>Proxy authorization is required for this proxy server. You can change proxy username and password in "Options/Proxy"</pre><pre>Authorization is required for this site/path. You can set login information for this download by selecting properties item in a right click context menu. Or add login information to "Options/Sites passwords" to use these login/password every time you are downloading files from this site.</pre><pre>You have changed the "site/path field." The login information for this new site/path already exists in your password list.</pre><pre>The login information hasn't been changed. You may want to edit the existing one.</pre><pre>The login information for this site/path already exists in your password list.</pre><pre>The new login information hasn't been added. You may want to edit the existing one.</pre><pre>Change username and password of this download to "anonymous" ?</pre><pre>Apply these username and password to this download?</pre><pre>Are you sure you want to delete login information for this site?</pre><pre>Password field has not been filled!</pre><pre>Password verification failed! Please try again.</pre><pre>Cannot rename downloaded file from temp folder (%s) to %s. The file has been saved in temp folder.</pre><pre>mailto:?subject=%s&body=%s% http://www.internetdownloadmanager.com</pre><pre>mailto:support@internetdownloadmanager.com?subject=IDM_%s&body=%s</pre><pre>mailto:idm@archisoftint.com</pre><pre>%sLanguages\idm_*.lng</pre><pre>%sLanguages\inst_*.lng</pre><pre>%ld %s</pre><pre>http://cache*-music*.myspacecdn.com/*/std_*.mp3?bandid=*&songid=*&token=*</pre><pre>http://*.*/*.swf*</pre><pre>http://lads.myspace.com/*.swf?*</pre><pre>%s://%s</pre><pre>youtube.com</pre><pre>location.href</pre><pre>window.navigate</pre><pre>window.open</pre><pre>\winhlp32.exe</pre><pre>Software\DownloadManager\MCN\%s</pre><pre>Software\DownloadManager\MCN\%s%s</pre><pre>scheduler.htm</pre><pre>https:/</pre><pre>http:/</pre><pre>MozillaWindowClass</pre><pre>AutoConfigURL</pre><pre>0.0.0.</pre><pre>127.0.0.</pre><pre>\StringFileInfo\xx\ProductName</pre><pre>drwebwcl</pre><pre>*.exe</pre><pre>COptSitesPasswords</pre><pre>%s (*.wav)|*.wav||</pre><pre>Software\DownloadManager\Passwords\</pre><pre>Software\DownloadManager\Passwords</pre><pre>www.filesonic.tw</pre><pre>*.filesonic.tw</pre><pre>filesonic.tw</pre><pre>www.filesonic.jp</pre><pre>*.filesonic.jp</pre><pre>filesonic.jp</pre><pre>*.sharingmatrix.com</pre><pre>www.filesonic.com</pre><pre>*.filesonic.com</pre><pre>filesonic.com</pre><pre>www.fileserve.com</pre><pre>*.fileserve.com</pre><pre>fileserve.com</pre><pre>www.hotfile.com</pre><pre>*.hotfile.com</pre><pre>hotfile.com</pre><pre>www.mediafire.com</pre><pre>*.mediafire.com</pre><pre>mediafire.com</pre><pre>.megaupload.com</pre><pre>www.megaupload.com</pre><pre>*.megaupload.com</pre><pre>megaupload.com</pre><pre>.rapidshare.com</pre><pre>ssl.rapidshare.com</pre><pre>www.rapidshare.com</pre><pre>*.rapidshare.com</pre><pre>rapidshare.com</pre><pre>URL::set_password: Not enough memory!</pre><pre>URL::set_userName: Not enough memory!</pre><pre>%s. %s</pre><pre>%d %%</pre><pre>%d%sd%% %s</pre><pre>%s (%I64d %s)</pre><pre>Properties.htm</pre><pre>CAllControlsSheet</pre><pre>%sScheduler\</pre><pre>%sq_*.dt</pre><pre>%d %s</pre><pre>%s.%s%s%s</pre><pre>RegistrationD.htm</pre><pre>%sprojects.dat</pre><pre>%sprojects2.dat</pre><pre>%sfoldresHistory.txt</pre><pre>%s (*.*)|*.*||</pre><pre>scheduler.html</pre><pre>%s{%s}</pre><pre>Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}</pre><pre>%s\%s{%s}</pre><pre>E8CF4E59-B7A3-41F2-86C7-82B03334F22A</pre><pre>9C9D53D4-A978-43FC-93E2-1C21B529E6D7</pre><pre>http://www.internetdownloadmanager.com/support/updateblocked.html</pre><pre>add_exception28.html</pre><pre>url=%s</pre><pre>webpage=%s</pre><pre>dll=%s</pre><pre>firstCT=%s</pre><pre>secondCT=%s</pre><pre>ref=%s</pre><pre>user_agent=%s</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><pre>%d:%d build %d %d-bit</pre><pre>%d:%d build %d</pre><pre>Windows 3.1</pre><pre>Windows 95</pre><pre>Windows 98</pre><pre>Windows NT</pre><pre>Windows version:</pre><pre>Configuration report:</pre><pre>Unk err --- GetRegistrySubkeys</pre><pre>Cannot open key for reading.</pre><pre>Unk err --- SaveAllSubkeys</pre><pre>Cannot read information about subkey's.</pre><pre>Unk err --- SaveKeyValuesEx</pre><pre>Unk err --- SaveKeyValues</pre><pre>Cannot read information about this key.</pre><pre>send_adv_int_rep2.html</pre><pre>mail=%s</pre><pre>winmm.dll</pre><pre>bUseControlKey</pre><pre>bUseAltKey</pre><pre>ShiftP</pre><pre>UseKeyToForce</pre><pre>UseKeyToPrevent</pre><pre>settings.html</pre><pre>%s >></pre><pre>%s <<</pre><pre>*.html,*.htm,*.js,*.css,*.gif,*.jpg,*.jpeg,*.jpe,*.bmp,*.png,*.tif</pre><pre>%s,*.js,*.css,*.gif,*.jpg,*.jpeg,*.jpe,*.bmp,*.png,*.swf</pre><pre>*.zip,*.rar,*.tar,*.gz,*.tgz</pre><pre>*.pdf</pre><pre>*.mp3,*.wma,*.waw</pre><pre>*.mpg,*.mp4,*.mpeg,*.avi,*mov,*qt,*.wmv</pre><pre>*.gif,*.jpg,*.jpeg,*.jpe,*.bmp,*.png,*.tif</pre><pre>%s ( %s )</pre><pre>*.%s %s</pre><pre>%s_tvlda.pdb</pre><pre>nlevels.html</pre><pre>prJava.html</pre><pre>StImmMsg</pre><pre>*.uploaded.to</pre><pre>www.uploading.com</pre><pre>*.easy-share.com</pre><pre>zshare.net</pre><pre>uploaded.to</pre><pre>uploading.com</pre><pre>sendspace.com</pre><pre>filefactory.com</pre><pre>depositfiles.com</pre><pre>Software\DownloadManager\DwnlSelPanel\%s</pre><pre>Shell32.dll</pre><pre>%stips.txt</pre><pre>Unknown error during CUrlExporter::CUrlExporter()</pre><pre>CreateFile error %ld during CUrlExporter::CUrlExporter()</pre><pre>Unknown error during CUrlExporter::WriteInELFFile()</pre><pre>Unknown error during CUrlExporter::ReadFromIEFFile()</pre><pre>Unknown error during CUrlExporter::ReadFromTextFile()</pre><pre>Err1 in SetSmUrl</pre><pre>UrlUnescapeA</pre><pre>3GP 7Z AAC ACE AIF ARJ ASF AVI BIN BZ2 DOC DOCX EXE FLV GZ GZIP IMG ISO LZH M4A M4V MKV MOV MP3 MP4 MPA MPE MPEG MPG MSI MSU OGG OGV PDF PLJ PPS PPT QT R0* R1* RA RAR RM RMVB SEA SIT SITX TAR TIF TIFF WAV WEBM WMA WMV Z ZIP</pre><pre>Unknown error during CUrlHistory::CUrlHistory()</pre><pre>UrlHistory</pre><pre>Unknown error during CUrlHistory::~CUrlHistory()</pre><pre>Unknown error during CUrlHistory::OnAddUrl()</pre><pre>Unk err in CUrlHistory2::CUrlHistory2</pre><pre>UxTheme.dll</pre><pre>dwmapi.dll</pre><pre>%s %s</pre><pre>Deleting temp file %s</pre><pre>Could not delete temp file %s</pre><pre>%ld,%f</pre><pre>%sSeg%%ld-Frag%%ld</pre><pre>first listitem id = %d, startpos = %I64d, file %s, endpos = %I64d</pre><pre>Error opening file %s, errcode = %ld.</pre><pre>Updating record with num %s: set ID %d, startPos %I64d, nextID %d</pre><pre>Error reading registry, errCode = %d.</pre><pre>Adding record to registry with ID %d, startPos %I64d, nextID %d</pre><pre>%s.tmp</pre><pre>Unknown error during ChunksList::JoinFile()</pre><pre>Updating record with ID 0, set nextID %d</pre><pre>Deleting record %s from registry</pre><pre>Size of %s is %I64d</pre><pre>Error during GetFileSize(), errcode = %d.</pre><pre>Skip first bytes via temp file %s.</pre><pre>Step5, can not rename temp file %s to %s, errno = %ld</pre><pre>%s_tmp</pre><pre>Rename temp file %s to %s.</pre><pre>Can not rename temp file %s to %s, errno = %ld</pre><pre>Can not create folder %s, error = %ld</pre><pre>Can not rename temp file %s to %s, error = %ld</pre><pre>Rename2 temp file %s to %s.</pre><pre>Delete old file %s</pre><pre>Assembling all downloaded portions into one file...</pre><pre>Fatal Read Error %d</pre><pre>Fatal Write Error %d</pre><pre>VirtualAlloc/malloc failed, error %d</pre><pre>Values counter in the registry subkey = %d</pre><pre>Cannot find registry subkeys counter.</pre><pre>Set curID %d, curPos %I64d</pre><pre>No keyframe found</pre><pre>Adding record with ID %d, startPos %I64d, nextID %d</pre><pre>error!!! No keyframe found(0)</pre><pre>this file %s, size %I64d</pre><pre>Read record num. %s from registry: ID = %d, startPos = %I64d, nextID = %d</pre><pre>Error reading registry, errCode = %d. End rebuilding.</pre><pre>Err 1231, f=%s, e=%ld.</pre><pre>Loading duration from registry: %f sec</pre><pre>error in chlist, id=%d, next=%d, starttime=%ld, ts=%ld</pre><pre>Chunk order violation error, cInf.ID %d, startPos %I64d</pre><pre>Error opening file %s.</pre><pre>next file %s, size %I64d</pre><pre>Error reading first chunk, errcode = %d.</pre><pre>new listitem id=%d, startpos=%I64d, file %ls,</pre><pre>error reading registry %d</pre><pre>Error opening file %s to get size, errcode = %ld.</pre><pre>insert from reg, ID = %d</pre><pre>Error closing file %s</pre><pre>Error reading saved last part, errcode = %d.</pre><pre>Adding record %s to registry with ID %d, startPos %I64d, nextID %d</pre><pre>Add alternative connection (%d) for connection %d</pre><pre>Error during deleting record with num %s, errcode = %ld</pre><pre>Apply alternative for connection %d</pre><pre>Getting file size error during check alternative for record %d, errcode = %ld</pre><pre>Opening file error during check alternative for record %d, errcode = %ld</pre><pre>Unknown error during ChunksListItem::JoinWithNext().</pre><pre>Deleting record with num %s</pre><pre>C%d:%s</pre><pre>Error during call to %s, err = %d</pre><pre>/%s%s</pre><pre>Dnsapi.dll</pre><pre>Error code = %d</pre><pre>Sock ver = %d, reply = %d</pre><pre>Error code = %ld, socks ret code = %d</pre><pre>%s %s</pre><pre>Select failed, err code = %d, socket = %d</pre><pre>Select error code = %d, socket = %d</pre><pre>Checking connect, socket = %d</pre><pre>File write error! Received %d bytes, wrote %d bytes, errCode = %ld</pre><pre>Error code = %d, socket = %d</pre><pre>sqlite3_blob_read</pre><pre>sqlite3_blob_bytes</pre><pre>sqlite3_blob_close</pre><pre>sqlite3_blob_open</pre><pre>sqlite3_free</pre><pre>sqlite3_exec</pre><pre>sqlite3_close</pre><pre>sqlite3_open</pre><pre>%sidmindex.dll</pre><pre>%s%sGoogle\Chrome\User Data\Default\cookies</pre><pre>%s%sMozilla\Firefox\Profiles\%s\cookies.sqlite</pre><pre>%s%sMozilla\Firefox\Profiles\*</pre><pre>SELECT creation_utc, name, value, path, host_key, secure FROM cookies WHERE host_key like '%%%s'</pre><pre>SELECT name, value, path, host, isSecure FROM moz_cookies WHERE host like '%%%s'</pre><pre>host_key</pre><pre>Crypt32.dll</pre><pre>d:d:d</pre><pre>ddd d:d:d GMT</pre><pre>dddddd</pre><pre>Unknown error during FTPConnection::FTPConnection() constructor.</pre><pre>Unknown error during FTPConnection::set_sequence_cpbl().</pre><pre>Unknown error during FTPConnection::try_set_pasv_cpbl().</pre><pre>Unknown error during FTPConnection::GetReply().</pre><pre>Unknown error during FTPConnection::Disconnect().</pre><pre>Unknown error during FTPConnection::SendQuit().</pre><pre>Unknown error during FTPConnection::TryConnect().</pre><pre>Unknown error during FTPConnection::CloseDataConnection().</pre><pre>Unknown error during FTPConnection::CheckConnectReply().</pre><pre>Initial response from FTP server:</pre><pre>Unknown error during FTPConnection::SendUser().</pre><pre>USER %s%s</pre><pre>%s@%s%s</pre><pre>Unknown error during FTPConnection::SendPassword().</pre><pre>send() PASS</pre><pre>PASS %s%s</pre><pre>send() proxy PASS</pre><pre>Unknown error during FTPConnection::CheckUserReply().</pre><pre>Unknown error during FTPConnection::CheckPasswordReply().</pre><pre>Reply on password:</pre><pre>recv() PASS</pre><pre>Unknown error during FTPConnection::SendPasv().</pre><pre>PASV%s</pre><pre>Unknown error during FTPConnection::ProcessPasvReply().</pre><pre>%u,%u,%u,%u,%u,%u</pre><pre>Unknown error during FTPConnection::BindSocket().</pre><pre>Unknown error during FTPConnection::Accept().</pre><pre>Unknown error during FTPConnection::SendPort().</pre><pre>send() PORT</pre><pre>PORT %d,%d,%d,%d,%d,%d</pre><pre>Unknown error during FTPConnection::CheckPortReply().</pre><pre>Reply on PORT:</pre><pre>recv() PORT</pre><pre>Unknown error during FTPConnection::SendCWD().</pre><pre>CWD %s%s</pre><pre>Unknown error during FTPConnection::CheckCWDReply().</pre><pre>Unknown error during FTPConnection::CheckOthersReplies().</pre><pre>Unknown error during FTPConnection::SendType().</pre><pre>TYPE %s%s</pre><pre>Unknown error during FTPConnection::CheckTypeReply().</pre><pre>Unknown error during FTPConnection::SendRest().</pre><pre>REST %I64d%s</pre><pre>Unknown error during FTPConnection::CheckRestReply().</pre><pre>Unknown error during FTPConnection::SendRetr().</pre><pre>RETR %s%s%s</pre><pre>Unknown error during FTPConnection::SendNoop().</pre><pre>Unknown error during FTPConnection::CheckRetrReply().</pre><pre>Unknown error during FTPConnection::FindSizeInRetrReply().</pre><pre>%I64d%s</pre><pre>Unknown error during FTPConnection::SendSize().</pre><pre>SIZE %s%s%s</pre><pre>Unknown error during FTPConnection::SendListFile().</pre><pre>LIST %s%s%s</pre><pre>Unknown error during FTPConnection::CheckListReply().</pre><pre>Unknown error during FTPConnection::CheckTransferEndReply().</pre><pre>Unknown error during FTPConnection::CheckSizeReply().</pre><pre>Unknown error during FTPConnection::OpenDataConnection().</pre><pre>ftp server doesn't support PASV</pre><pre>Unknown error during FTPConnection::StartRetr().</pre><pre>Unknown error during FTPConnection::RecvListData().</pre><pre>time %s, sizetype %d, size %I64d, name %s, namelen %d, flagtryretr %d</pre><pre>UNk err FTPCn2597</pre><pre>Unknown error during FTPConnection::GetFileSize().</pre><pre>Unknown error during FTPConnection::ProcessReply().</pre><pre>Unknown error during FTPConnection::ProcessReplyQueue().</pre><pre>Unknown error during FTPConnection::RollBack().</pre><pre>Unknown error during FTPConnection::Restart().</pre><pre>Unknown error during FTPConnection::OnSendError().</pre><pre>Unknown error during FTPConnection::StartGetChunk().</pre><pre>Unknown error during FTPConnection::ProcessWaitConn().</pre><pre>Unknown error during FTPConnection::ProcessWaitReply().</pre><pre>Unknown error during FTPConnection::SendInAddition().</pre><pre>Unkerr in FTPC2980</pre><pre>Unknown error during FTPConnection::ProcessPasvOK().</pre><pre>Unknown error during FTPConnection::InsInChunksList().</pre><pre>Unknown error during FTPConnection::SendTestSequences().</pre><pre>TYPE I%sNOOP%s</pre><pre>CWD %s%sTYPE I%s</pre><pre>Unknown error during FTPConnection::ProcessWaitTestSequ().</pre><pre>Unknown error during FTPConnection::ProcessWaitSecSeqReply().</pre><pre>Unknown error during FTPConnection::AuditForRestart().</pre><pre>Unknown error during FTPConnection::SetCompleted().</pre><pre>next %d</pre><pre>Sendig QUIT for connection %d...</pre><pre>The file chunk of connection %d is reassigned to connection %d.</pre><pre>conn. %d dowload completed</pre><pre>time %I64d, status %d,</pre><pre>Unknown error during FTPConnection::HandleStatus().</pre><pre>Error during FTPConnection::OnNewLastModified()</pre><pre>Unk err in FTPC::SMDTM().</pre><pre>MDTM %s%s%s</pre><pre>Unk err in FTPC::CMDTMR</pre><pre>Unknown error in FTPSession constructor.</pre><pre>Unknown error in FTPSession destructor.</pre><pre>Unknown error during FTPSession::InitSession().</pre><pre>Unknown error during FTPSession::set_sequence_cpbl_ok().</pre><pre>Unknown error during FTPSession::set_rest_cpbl().</pre><pre>Unknown error during FTPSession::set_pasv_cpbl().</pre><pre>Unknown error during FTPSession::CreateOptionalConnections().</pre><pre>Unknown error during FTPSession::getFile()</pre><pre>User : %s, password : xxx</pre><pre>%s %s Time: %.19s.%hu %.4s (%ld sec)</pre><pre>Url: ftp://</pre><pre>Windows %d.%d</pre><pre>Unknown error during FTPSession::ReceiveData()</pre><pre>Unknown error during FTPSession::set_fds()</pre><pre>Probably the server does not support command sequences.</pre><pre>Unkerr in FTPSss:AlQt</pre><pre>Unkerr in FTPSss:SndAlCnInf</pre><pre>Unknown error during FTPSession::TryStartNewOptionalConnections()</pre><pre>Cannot download this file, maybe this ftp server doesn't support download resume. Would you like to download the file from the beginning?</pre><pre>1.1.4</pre><pre>ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789 /http://www.internetdownloadmanager.com/support/data_corruption.html</pre><pre>nShMsgCrData</pre><pre>Unknown error in HTTPConnection constructor.</pre><pre>Unknown error in HTTPConnection destructor.</pre><pre>conn. %d dowload complete</pre><pre>Unknown error during HTTPConnection::Disconnect().</pre><pre>Error during HTTPConnection::SetBasicAuthStr()</pre><pre>Authorization: Basic %s</pre><pre>%s:%s</pre><pre>Error during HTTPConnection::GetNextReplyLine()</pre><pre>Error during HTTPConnection::GetReplyIntoStorage()</pre><pre>Error during HTTPConnection::GetRetrRangeReply()</pre><pre>.dailymotion.com</pre><pre>emusic.com</pre><pre>Error during HTTPConnection::setNewLocation()</pre><pre>.html</pre><pre>/* Old URL: %s%s */</pre><pre>rapidshare.de</pre><pre>Err in HTTPC::AFR</pre><pre>Error during HTTPConnection::ProcessState()</pre><pre>UNk err HTTPCn2597</pre><pre>Error during HTTPConnection::GetInfo()</pre><pre>.googlevideo.com</pre><pre>%s.mnft</pre><pre>.dmcdn.net</pre><pre>sciencedirect.com</pre><pre>Error during HTTPConnection::GetState()</pre><pre>Error during HTTPConnection::SendGet()</pre><pre>%I64d-%I64d, %s</pre><pre>%s %s HTTP/1.1</pre><pre>User-Agent: %s</pre><pre>Host: %s%s</pre><pre>Accept: %s</pre><pre>%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s</pre><pre>Accept-Charset: %s</pre><pre>Origin: %s</pre><pre>Accept-Language: %s</pre><pre>Cookie2: %s</pre><pre>Content-Type: %s</pre><pre>Content-Length: %d</pre><pre>application/x-www-form-urlencoded</pre><pre>If-Modified-Since: %s</pre><pre>Referer: %s</pre><pre>Authorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", %sresponse="%s"%s</pre><pre>, opaque="%s"</pre><pre>qop=%s, nc=%s, cnonce="%s",</pre><pre>Unknown error during HTTPConnection::HttpsProxyConnect()</pre><pre>CONNECT %s:%ld HTTP/1.1</pre><pre>User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)</pre><pre>Proxy-Authorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", %sresponse="%s"%s</pre><pre>Error during HTTPConnection::RecvAllHeaders()</pre><pre>Error during HTTPConnection::SkipAllHeaders()</pre><pre>Error during HTTPConnection::SkipAllHeaders2()</pre><pre>Error during HTTPConnection::RecvState()</pre><pre>HHTTP/</pre><pre>HTTP/</pre><pre>Error during HTTPConnection::ProcessHeader()</pre><pre>policyref="http://p3p.yahoo.com/w3c/</pre><pre>windows-125</pre><pre>HTTPS</pre><pre>Server: MediaFire-HTTP-lrbd</pre><pre>Server: BestHop 2.4.4</pre><pre>Unkerr HTTPC:OnCnt</pre><pre>Error during HTTPConnection::HandleStatus()</pre><pre>.mail.yahoo.com/</pre><pre>Unkerr HTTPC 5571</pre><pre>UnkErr in HTTPC6234</pre><pre>No memory, s httpc6172</pre><pre>No memory, s httpc6154</pre><pre>Ieframe.dll</pre><pre>Error during HTTPConnection::Set_szURL()</pre><pre>Error during HTTPConnection::OnNewLastModified()</pre><pre>Error during HTTPConnection::ProcessSetCookieHeader()</pre><pre>Not enough memory in cookieURL = new char[...]</pre><pre>Unknown error during HTTPConnection::Restart().</pre><pre>Error %d during HTTPConnection::MNSP(), step1.</pre><pre>Error %d during HTTPConnection::MNSP(), step2.</pre><pre>Unkerr in HTTP:RestartOnNLM</pre><pre>Unknown error in HTTPSession constructor.</pre><pre>Unknown error in HTTPSession destructor.</pre><pre>Unknown error during HTTPSession::InitSession().</pre><pre>Unknown error during HTTPSession::getFile()</pre><pre>The server does not support transfer restarts.</pre><pre>User : %s, password :xxx</pre><pre>password=***</pre><pre>register.cgi</pre><pre>HTTPSess err 960</pre><pre>Try original url</pre><pre>Unknown error during HTTPSession::ReceiveData()</pre><pre>Unknown error during HTTPSession::set_fds()</pre><pre>Unknown error during HTTPSession::AuditForRestart()</pre><pre>Unknown error during HTTPSession::SendAllConnInfo()</pre><pre>Unknown error during HTTPSession::TryStartNewOptionalConnections()</pre><pre>Cannot download this file, maybe this server doesn't support download resume. Would you like to download the file from the beginning?</pre><pre>#EXT-X-KEY:</pre><pre>https://secure.internetdownloadmanager.com/buy.html</pre><pre>https://secure.internetdownloadmanager.com/buy1.html</pre><pre>http://www.internetdownloadmanager.com/</pre><pre>http://www.internetdownloadmanager.com/welcome.html</pre><pre>http://www.internetdownloadmanager.com/welcome2.html</pre><pre>Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}</pre><pre>sending %x command, res = %ld</pre><pre>send mms cmd</pre><pre>NSPlayer/9.0.0.2980; {%s}; Host: %s</pre><pre>954afa31-d601-4525-ae7f-57d44aeb4d34</pre><pre>\\%d.%d.%d.%d\%s\%ld</pre><pre>recv %x command</pre><pre>Recv cmd failed, error = %ld</pre><pre>Recv cmd failed, connection closed by server.</pre><pre>errCode 0x%x</pre><pre>err code = 0x%x</pre><pre>xxxx-xx-xx-xx-xxxxxx</pre><pre>75B22636-668E-11CF-A6D9-00AA0062CE6C</pre><pre>14E6A5CB-C672-4332-8399-A96952065B5A</pre><pre>5FBF03B5-A92E-11CF-8EE3-00C00C205365</pre><pre>75B22633-668E-11CF-A6D9-00AA0062CE6C</pre><pre>BC19EFC0-5B4D-11CF-A8FD-00805F5C442B</pre><pre>B7DC0791-A9B7-11CF-8EE6-00C00C205365</pre><pre>8CABDCA1-A947-11CF-8EE4-00C00C205365</pre><pre>75B22630-668E-11CF-A6D9-00AA0062CE6C</pre><pre>Packets number %ld, packet length %ld, media length %I64d, streams count %d, file size %I64d</pre><pre>%s, %s%s%s, Length: %s</pre><pre>Connection %d, downloaded %I64d.</pre><pre>Unk err in MMSCn::HndlSt, time %I64d, status %d</pre><pre>%s Time: %.19s.%hu %.4s (%ld sec)</pre><pre>%I64d-%I64d, %s%s</pre><pre>%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>Proxy-Authorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", %sresponse="%s"%s%s</pre><pre>, charset=utf-8, hashed-dirs="service-name,channel-binding", service-name="%s", channel-binding="%s"</pre><pre>Unknown error during ProxyConnection::Set_szURL()</pre><pre>Not enough memory during szURL = new char[...]</pre><pre>Proxy-Authorization: Basic %s</pre><pre>Unkerr in RTMPConn, 12, time %I64d, status %d</pre><pre>OneKeyFrameBack failed, Erase outfile</pre><pre>Recieved ID: %s</pre><pre>POST /fcs/ident2 HTTP/1.1</pre><pre>Host: %s</pre><pre>POST /open/1 HTTP/1.1</pre><pre>POST /%s/%s/%ld HTTP/1.1</pre><pre>Version: %d.%d.%d.%d</pre><pre>recv handshake, type = X</pre><pre>SendPacket failed! Header type: 0xx</pre><pre>pageUrl</pre><pre>tcUrl</pre><pre>swfUrl</pre><pre>Key frame doesn't match! (c3)</pre><pre>Key frame doesn't match! (c2)</pre><pre>Key frame doesn't match!</pre><pre>The file chunk %d is reassigned to connection %d.</pre><pre>Join with next, deleting record with num %s</pre><pre>error 2099, id=%d, next=%d, starttime=%ld, ts=%ld</pre><pre>Delete temp file %s</pre><pre>cmpkfcount > MAX_CMP_KEYFRAMES, set NO_REST</pre><pre>Sending ping, type=0xx</pre><pre>Unknown packet type received: 0xx</pre><pre>Report: received</pre><pre>Sending play, stime=%f, file=%s</pre><pre>NetConnection.Connect.InvalidApp</pre><pre>NetStream.Play.UnpublishNotify</pre><pre>NetConnection.Connect.Rejected</pre><pre>NetStream.Play.StreamNotFound</pre><pre>NetStream.Play.Stop</pre><pre>NetStream.Play.Failed</pre><pre>NetStream.Failed</pre><pre>onStatus: %s</pre><pre>Server sent result for %s</pre><pre>Server invoking %s</pre><pre>Duration = %f</pre><pre>Duration dont match! New duration = %f</pre><pre>OneKeyFrameBack</pre><pre>Join all (1).</pre><pre>Cannot find Winsock v%d.%d or later!</pre><pre>Ss::InfMsg err</pre><pre>Unknown error during Session::CheckFormat(), ctc.Check(...)</pre><pre>%a, %d %b %Y %H:%M:%S GMT</pre><pre>http://www.internetdownloadmanager.com/register/new_faq/How_to_configure_Firewalls_for_IDM.html</pre><pre>downlResult = %ldsetting new login</pre><pre>Unknown error during SessionManager::SetURL()</pre><pre>Unknown error during SessionManager::SetLogin()</pre><pre>%s://%s%s%s%s</pre><pre>simtel.net</pre><pre>Unknown error during SessionManager::LoadUrlFromReg()</pre><pre>URL::set_lastResult(): Not enough memory!</pre><pre>anonymous@r.com</pre><pre>Port</pre><pre>Can not delete subkey %s from registry, error code = %ld</pre><pre>Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)</pre><pre>UrlUnescapeW</pre><pre>%s.%s</pre><pre>%s_%s.%s</pre><pre>%s_default.html</pre><pre>%s%s%s.%s</pre><pre>.docx</pre><pre>.mpeg</pre><pre>easy-share.com</pre><pre>googlevideo.com</pre><pre>%s&signature=%s</pre><pre>&url=</pre><pre>\u0026url=</pre><pre>url_encoded_fmt_stream_map</pre><pre>%s...</pre><pre>Downloading owner web page</pre><pre>googlevideo.com/api_video_info?</pre><pre>googlevideo.com/get_video_info?</pre><pre>youtube.com/api_video_info?</pre><pre>youtube.com/get_video_info?</pre><pre>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)</pre><pre>Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)</pre><pre>Mozilla/4.0 (compatible; MSIE 7.0; Windows 98)</pre><pre>Unknown error in URL destructor</pre><pre>%s?lng=%s</pre><pre>http://www.internetdownloadmanager.com/support/shsdownload.html</pre><pre>http://www.internetdownloadmanager.com/articles/flv_downloading.html</pre><pre>http://www.internetdownloadmanager.com/support/filesonic_dwnl.html</pre><pre>http://www.internetdownloadmanager.com/support/rsdownload.html</pre><pre>showHTDlFsnMsg</pre><pre>showHTDlShSMsg</pre><pre>4shared.com</pre><pre>.filesonic.</pre><pre>showHTDlYtMsg</pre><pre>showHTDlRSMsg</pre><pre>%ld%s</pre><pre>URL::set_localPath(): Not enough memory!</pre><pre>Folder %s was created.</pre><pre>Unknown error during URL::SaveToReg()</pre><pre>capabilities=%f&audioCodecs=%f&videoCodecs=%f&videoFunction=%f&duration=%I64d%s%s</pre><pre>&tcUrl=%s</pre><pre>&userArgs=%s</pre><pre>Unknown error during URL::set_LastModified()</pre><pre>URL::set_LastModified(): Not enough memory!</pre><pre>Unknown error during URL::DeleteFileChunks()</pre><pre>Error read registry, errCode = %d. End rebuilding.</pre><pre>Unknown error during URL::LoadLocalNamesFromReg()</pre><pre>URL::set_localFileName(): Not enough memory!</pre><pre>URL::set_description(): Not enough memory!</pre><pre>%s\idmftype.dll</pre><pre>idmcheckedtype/%s</pre><pre>Urlmon.dll</pre><pre>%s%s%s.html</pre><pre>%s %s|*.%s|%s (*.*)|*.*||</pre><pre>Error %ld opening registry key in URL::OpenDMRegSubKey()</pre><pre>EM = 0x%x, 0x%x,</pre><pre>DM = 0x%x, 0x%x.</pre><pre>Error 0x%x reading security interface.</pre><pre>Error 0x%x reading InitSecurityInterface entry point.</pre><pre>Error 0x%x loading %s.</pre><pre>secur32.dll</pre><pre>security.dll</pre><pre>schannel.dll,</pre><pre>Error %ld opening Key during CheckRegSecurityProvider()</pre><pre>schannel.dll</pre><pre>Unk err in URL::set_MDTM()</pre><pre>.MPEG</pre><pre>Unknown error during CFormatParsing::%s</pre><pre>new operator error %ld in CFormatParsing::FillZipFormatStruct()</pre><pre>Joint Stereo</pre><pre>d %s %d d:d</pre><pre>CertFreeCertificateContext</pre><pre>Error 0x%x returned by AcquireCredentialsHandle</pre><pre>Error 0x%x returned by CertFindCertificateInStore</pre><pre>CertFindCertificateInStore</pre><pre>Error 0x%x returned by CertOpenSystemStore</pre><pre>CertOpenSystemStoreA</pre><pre>Error %d sending data to server (1)</pre><pre>%d bytes of handshake data sent</pre><pre>Error %d returned by InitializeSecurityContext (1)</pre><pre>Error 0x%x returned by InitializeSecurityContext (2)</pre><pre>%d bytes of app data was bundled with handshake data</pre><pre>Error %d sending data to server (2)</pre><pre>Error %d reading data from server</pre><pre>Key exchange strength: %d</pre><pre>Key exchange: KEA</pre><pre>Key exchange: 0x%x</pre><pre>Key exchange: DH Ephemeral</pre><pre>Key exchange: RSA</pre><pre>Hash strength: %d</pre><pre>Hash: 0x%x</pre><pre>Cipher strength: %d</pre><pre>Cipher: 0x%x</pre><pre>Protocol: 0x%x</pre><pre>Error 0x%x querying connection info</pre><pre>Error 0x%x finding cert chain</pre><pre>**** Error 0x%x returned by AcquireCredentialsHandle</pre><pre>certificate chain found</pre><pre>CertFindChainInStore</pre><pre>1.3.6.1.5.5.7.3.2</pre><pre>Error 0x%x querying issuer list info</pre><pre>Error during HTTPConnection::SendHTTPSGet()</pre><pre>%d bytes of request sent</pre><pre>Error %d sending data to server (3)</pre><pre>Error 0x%x returned by EncryptMessage</pre><pre>Header: %d, Trailer: %d, MaxMessage: %d</pre><pre>Error 0x%x reading SECPKG_ATTR_STREAM_SIZES</pre><pre>Error during HTTPConnection::RecvHTTPSData()</pre><pre>**** Error 0x%x returned by DecryptMessage</pre><pre>%d bytes of handshake data received</pre><pre>%c%c%c%c%c%c%c%c%c%c</pre><pre>%s.cdb2</pre><pre>%s.pdb</pre><pre>%s_ssi.pdb</pre><pre>%s_szi.pdb</pre><pre>%s_di.pdb</pre><pre>%s_sfti.pdb</pre><pre>%s_lni2.pdb</pre><pre>%s_lni.pdb</pre><pre>%s_dni.pdb</pre><pre>%s_ui.pdb</pre><pre>%s_mi.pdb</pre><pre>.?AVCCmdTarget@@</pre><pre>.PAVCException@@</pre><pre>.?AVCCmdUI@@</pre><pre>.?AVCTestCmdUI@@</pre><pre>.PAVCUserException@@</pre><pre>.PAVCObject@@</pre><pre>.PAVCSimpleException@@</pre><pre>.PAVCResourceException@@</pre><pre>.PAVCArchiveException@@</pre><pre>.?AVCToolCmdUI@@</pre><pre>.PAVCOleException@@</pre><pre>.PAVCOleDispatchException@@</pre><pre>.PAVCMemoryException@@</pre><pre>.PAVCNotSupportedException@@</pre><pre>.?AVCNotSupportedException@@</pre><pre>.PAVCFileException@@</pre><pre>zcÁ</pre><pre>%Documents and Settings%\%current user%\Application Data\IDMan.exe</pre><pre>version="1.0.0.0"</pre><pre>name="Tonec.IDM.IDMan"</pre><pre>name="Microsoft.Windows.Common-Controls"</pre><pre>version="6.0.0.0"</pre><pre>publicKeyToken="6595b64144ccf1df"</pre><pre><requestedExecutionLevel level="asInvoker" /></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" /></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" /></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" /></pre><pre><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" /></pre><pre><asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings"></asmv3:windowsSettings></pre><pre></pre><pre>^.ovs</pre><pre>^.ovs[cX:</pre><pre>w'R.siZ</pre><pre>2:3:3:/:/\/\/</pre><pre>2:3:3:3:3</pre><pre>Rn-N)N)N)N)M)M)-%-%-%,%,%uN</pre><pre>.ZduB</pre><pre>keYb</pre><pre>6.vFo)</pre><pre>ZL%FV</pre><pre>.)7)7(3'/</pre><pre>uN-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%-%uN</pre><pre>{.wGZ</pre><pre>o{-{,{,w,w,w,w,w,w-w-w-w.wNwNwNwNwN{N{N{N{o{o{q{</pre><pre>{/{,{,{,{,{,{,w,w,w.wPw</pre><pre>w.wGZ</pre><pre>O{-{,w,w,w,w,w,w,w-w-w-w.wNwNwNwNwN{N{N{n{n{o{q{</pre><pre>{.{,{,w,w,w,w,w,w,w.wPw</pre><pre>2*;*;*7)7</pre><pre>2 ; ; ;*7</pre><pre>p{N{M{-{-{-{,{,{,{-w-w-w.wNwNwNw</pre><pre>"?'?#?#?</pre><pre>7_3_/_ _'?#</pre><pre>?=?=;=;^;</pre><pre>._/_/_/?/? </pre><pre>3_3?3?/? ? </pre><pre>;=;=;=;^7</pre><pre>"?'?'?'?#?#</pre><pre>&? ?'?'?#</pre><pre>{4Fp)o%uF</pre><pre>7\3\3\ \'<</pre><pre>.GNGnGMCK;(3</pre><pre>{.KoKoKnGL?)7</pre><pre>-%-)-)-%</pre><pre>;;;7;7;7;7;7:7:7:3:3</pre><pre>N.siZ</pre><pre>R.siZ</pre><pre>;?;?7?/? </pre><pre>.ZW9W9W8W8W9[9_Z_</pre><pre>6>;_7?7?3? ?'</pre><pre>-xB}ouF\#o</pre><pre>)QO(b</pre><pre>tcp D</pre><pre>.lffn]XX</pre><pre>L/%XN3'4S7)</pre><pre>& #!!!!&</pre><pre>Ku.sL</pre><pre>z%X8></pre><pre> ].vh</pre><pre>'%7u%g</pre><pre>'()* ,-./</pre><pre>0123456789</pre><pre>idmmbc.dll</pre><pre>nIDMGCExt.crx</pre><pre>IEMonitor.exe</pre><pre>idmmzcc.xpi</pre><pre>Uninstall.exe</pre><pre>iRUNDLL32.EXE</pre><pre>SETUPAPI.DLL,InstallHinfSection DefaultUninstall 128 %s</pre><pre>SETUPAPI.DLL,InstallHinfSection DefaultInstall 128 %s</pre><pre>idmtdi.inf</pre><pre>idmtdi32.sys</pre><pre>NPIDMan2.dll</pre><pre>NPIDMan1.dll</pre><pre>lidmbrbtn64.dll</pre><pre>IDMShellExt64.dll</pre><pre>IDMNetMon64.dll</pre><pre>IDMNetMon.dll</pre><pre>IEGetAll.htm</pre><pre>IEExt.htm</pre><pre>IDManTypeInfo.tlb</pre><pre>idmmkb.dll</pre><pre>IDMIECC64.dll</pre><pre>lhttp</pre><pre>iseamonkey.exe</pre><pre>orca.exe</pre><pre>MozillaFireBird.exe</pre><pre>NETSCP.exe</pre><pre>Flock.exe</pre><pre>navigator.exe</pre><pre>NETSCAPE.exe</pre><pre>OPERA.exe</pre><pre>Firefox.exe</pre><pre>iexplore.exe</pre><pre>PathToExe</pre><pre>~idmcchandler2_64.dll</pre><pre>defexclist.txt</pre><pre>idmvs.dll</pre><pre>regsvr32.exe</pre><pre>index.htm</pre><pre>IDMGrHlp.exe</pre><pre>rundll32.exe</pre><pre>downlWithIDM64.dll</pre><pre>IDMGetAll64.dll</pre><pre>%s%s%s_%ld%s</pre><pre>Elevation:Administrator!new:%s</pre><pre>temp.htm</pre><pre>GlobalErrors.log</pre><pre>s%sGlobalErrors.log</pre><pre>mgrabber.chm</pre><pre>%s%lda%ld\</pre><pre>%s%s%s\default_user\</pre><pre>%s%s%s\%s\</pre><pre>idmpldr.ini</pre><pre>IEGetVL2.htm</pre><pre>IEGetVL.htm</pre><pre>dnlbtmn.txt</pre><pre>%s%sSounds\%s</pre><pre>%sSounds\%s</pre><pre>%s%sSounds\</pre><pre>%sSounds\</pre><pre>sts_list.dat</pre><pre>tips.txt</pre><pre>UrlHistory.txt</pre><pre>UrlHistory2.txt</pre><pre>%s%s_%ld.log</pre><pre>manuallogin.html</pre><pre>default.html</pre><pre>%s%ld\</pre><pre>%s%s_%ld\</pre><pre>:?!#&*-<>\$%@</pre><pre>"'/[]^|~</pre><pre>Login</pre><pre>The web page from which this file was obtained:</pre><pre>http://www.internetdownloadmanager.com</pre><pre>Support Team:</pre><pre>internetdownloadmanager.com/contact_us.html</pre><pre>Password:</pre><pre>Save password</pre><pre>IDM drop target. Drop web-links for downloading here</pre><pre>Export download list</pre><pre>Export download queue</pre><pre>Export selected files</pre><pre>Export all files</pre><pre>Site login</pre><pre>Note: Type the path only if you have different login names for different server directories.</pre><pre>Use Windows Dial Up / VPN Networking</pre><pre>Automatically start downloading of URLs placed to clipboard</pre><pre>Customize keys to prevent or force downloading with IDM</pre><pre>Keys...</pre><pre>Use FTP in &PASV mode</pre><pre>Hide images located on this web page</pre><pre>Using special keys</pre><pre>Use the following key(s) to prevent downloading with IDM for any links:</pre><pre>Use the following key(s) to force downloading with IDM for any links:</pre><pre>Note: Sometimes after you click on a download link, a web page will load telling that the download starts in X seconds. In this case you will need to uncheck the following option to force downloading with IDM.</pre><pre>Check for left mouse button clicked on a link along with the special key(s) pressed to force downloading the link</pre><pre>While holding down a special key DO NOT take over the downloads</pre><pre>which are web-pages, pictures, scripts and etc.</pre><pre>Internet Download Manager Problem Report</pre><pre>We have created a configuration report that you can send us.</pre><pre>Press Advanced button to enable manual login or to disable a logout page</pre><pre>Enter login and password manually at the following web page:</pre><pre>Please note that a web server may reject requests if you set a large number of files to explore (download) at the same time.</pre><pre>At this step you should specify what web pages to explore to find the required files. At the next step, you will be able to set file types, location, and other filters.</pre><pre>Ignore popup windows</pre><pre>Explore web pages within the following paths/domains only:</pre><pre>Don't explore web pages within the following paths/domains:</pre><pre>Web pages processed</pre><pre>Type your user name and password.</pre><pre>Save this password in IDM password list</pre><pre>It's possible to add a group of sequential file names like img001.jpg, img002.jpg, etc., img100.jpg to IDM download queue. Use the asterisk wildcard for the file name pattern.</pre><pre>For example: http://www.internetdownloadmanager.com/pictures/img*.jpg</pre><pre>Report for IDM developers</pre><pre>You can send a report to IDM developers about the downloads that were taken over by mistake to make a workaround for this site in the future versions of IDM</pre><pre>The referrer URL from which the download was taken over by mistake:</pre><pre>Note: Internet servers may break connection when the speed is too limited! Thus it's not recommened to use Speed Limiter to download from servers that do not support "resume" feature.</pre><pre>IDM can show its Download panel on a web-player in a browser when IDM detects a multimedia request from the web-player</pre><pre>Don't capture downloads from web-players automatically</pre><pre>IDM can show Download panel on a web-page when you select a text that contains download links.</pre><pre>FileUrl</pre><pre>Use &HTTP Proxy</pre><pre>Use HTTP&S Proxy</pre><pre>Use &FTP Proxy</pre><pre>Google Chrome Integration</pre><pre>E&xport</pre><pre>To IDM export &file</pre><pre>&Import</pre><pre>&From IDM export file</pre><pre>C&ustomize URL List...</pre><pre>&Contact IDM Support</pre><pre>6, 20, 3, 3</pre><pre>1999 - 2014</pre><pre>>Check for available updates on www.internetdownloadmanager.com</pre><pre>'Register IDM with your registration key</pre><pre>Contact IDM support team</pre><pre>EMake an attempt to find HTTP proxy in Internet Explorer configuration</pre><pre>:Use FTP protocol in passive mode (needed behind firewalls)</pre><pre>Stop all downloads%Remove selected file(s) from the list(Remove all completed files from the listDBrowsers/System integration, File types, Proxy, Passwords and others</pre><pre>Opening Port</pre><pre>Port Opened</pre><pre>Change Password Requested</pre><pre>Password Expired</pre><pre>All Files (*.*)</pre><pre>No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.</pre><pre>Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.</pre><pre>Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.</pre><pre>Access to %1 was denied..An invalid file handle was associated with %1.<%1 could not be removed because it is the current directory.6%1 could not be created because the directory is full.</pre><pre>Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.</pre><pre>Disk full while accessing %1..An attempt was made to access %1 past its end.</pre><pre>No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.</pre><pre>#Unable to load mail system support.</pre><b>xpsrchvw.exe_1188:</b><pre>.text</pre><pre>`.rsrc</pre><pre>@.reloc</pre><pre>lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet</pre><pre>v2.0.50727</pre><pre>CMemoryExecute.dll</pre><pre>CMemoryExecute</pre><pre>PAGE_EXECUTE_READWRITE</pre><pre>.ctor</pre><pre>System.Reflection</pre><pre>System.Runtime.InteropServices</pre><pre>System.Security.Permissions</pre><pre>System.Diagnostics</pre><pre>System.Runtime.CompilerServices</pre><pre>DllImportAttribute</pre><pre>kernel32.dll</pre><pre>ntdll.dll</pre><pre>System.Security</pre><pre>$8fcd4931-91a2-4e18-849b-70de34ab75df</pre><pre>1.0.0.0</pre><pre>System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</pre><pre>C:\Users\Jovan\Documents\Visual Studio 2010\Projects\Stealer\CMemoryExecute\CMemoryExecute\obj\Release\CMemoryExecute.pdb</pre><pre>mscoree.dll</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>D$.SPf</pre><pre> 2 34 567</pre><pre>com.apple.Safari</pre><pre>com.apple.WebKit2WebProcess</pre><pre>SELECT origin_url, action_url, username_element, username_value, password_element, password_value, signon_realm, date_created from logins</pre><pre>"Account","Login Name","Password","Web Site","Comments"</pre><pre>3.7.5</pre><pre>SQLite format 3</pre><pre>CREATE TABLE sqlite_master(</pre><pre>sql text</pre><pre>REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY</pre><pre>SELECT id, hostname, httpRealm, formSubmitURL, usernameField, passwordField, encryptedUsername, encryptedPassword FROM moz_logins</pre><pre>PK11_GetInternalKeySlot</pre><pre>PK11_CheckUserPassword</pre><pre>large file support is disabled</pre><pre>unknown operation</pre><pre>SQL logic error or missing database</pre><pre>foreign_keys</pre><pre>sqlite_compileoption_get</pre><pre>sqlite_compileoption_used</pre><pre>sqlite_source_id</pre><pre>sqlite_version</pre><pre>sqlite_attach</pre><pre>sqlite_detach</pre><pre>sqlite_stat1</pre><pre>sqlite_rename_parent</pre><pre>sqlite_rename_trigger</pre><pre>sqlite_rename_table</pre><pre>%Y-%m-%d %H:%M:%S</pre><pre>%Y-%m-%d</pre><pre>%H:%M:%S</pre><pre>SQLITE_</pre><pre>failed to allocate %u bytes of memory</pre><pre>failed memory resize %u to %u bytes</pre><pre>922337203685477580</pre><pre>API call with %s database connection pointer</pre><pre>%s-shm</pre><pre>%s\etilqs_</pre><pre>OsError 0x%x (%u)</pre><pre>Recovered %d frames from WAL file %s</pre><pre>%s-mjX</pre><pre>foreign key constraint failed</pre><pre>unable to use function %s in the requested context</pre><pre>abort at %d in [%s]: %s</pre><pre>constraint failed at %d in [%s]</pre><pre>cannot open savepoint - SQL statements in progress</pre><pre>no such savepoint: %s</pre><pre>cannot %s savepoint - SQL statements in progress</pre><pre>cannot rollback transaction - SQL statements in progress</pre><pre>cannot commit transaction - SQL statements in progress</pre><pre>sqlite_master</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid</pre><pre>cannot change %s wal mode from within a transaction</pre><pre>statement aborts at %d: [%s] %s</pre><pre>misuse of aliased aggregate %s</pre><pre>%s: %s.%s.%s</pre><pre>%s: %s.%s</pre><pre>%s: %s</pre><pre>%r %s BY term out of range - should be between 1 and %d</pre><pre>too many terms in %s BY clause</pre><pre>Expression tree is too large (maximum depth %d)</pre><pre>variable number must be between ?1 and ?%d</pre><pre>too many SQL variables</pre><pre>too many columns in %s</pre><pre>oversized integer: %s%s</pre><pre>misuse of aggregate: %s()</pre><pre>%.*s"%w"%s</pre><pre>%s%.*s"%w"</pre><pre>%s OR name=%Q</pre><pre>type='trigger' AND (%s)</pre><pre>there is already another table or index with this name: %s</pre><pre>sqlite_</pre><pre>table %s may not be altered</pre><pre>view %s may not be altered</pre><pre>UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;</pre><pre>UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');</pre><pre>UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;</pre><pre>Cannot add a PRIMARY KEY column</pre><pre>UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q</pre><pre>sqlite_altertab_%s</pre><pre>CREATE TABLE %Q.%s(%s)</pre><pre>DELETE FROM %Q.%s WHERE tbl=%Q</pre><pre>SELECT tbl, idx, stat FROM %Q.sqlite_stat1</pre><pre>invalid name: "%s"</pre><pre>too many attached databases - max %d</pre><pre>database %s is already in use</pre><pre>unable to open database: %s</pre><pre>no such database: %s</pre><pre>cannot detach database %s</pre><pre>database %s is locked</pre><pre>%s %T cannot reference objects in database %s</pre><pre>object name reserved for internal use: %s</pre><pre>there is already an index named %s</pre><pre>too many columns on %s</pre><pre>duplicate column name: %s</pre><pre>default value of column [%s] is not constant</pre><pre>table "%s" has more than one primary key</pre><pre>no such collation sequence: %s</pre><pre>CREATE %s %.*s</pre><pre>UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d</pre><pre>view %s is circularly defined</pre><pre>table %s may not be dropped</pre><pre>use DROP TABLE to delete table %s</pre><pre>use DROP VIEW to delete view %s</pre><pre>DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'</pre><pre>DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q</pre><pre>foreign key on %s should reference only one column of table %T</pre><pre>number of columns in foreign key does not match the number of columns in the referenced table</pre><pre>unknown column "%s" in foreign key definition</pre><pre>indexed columns are not unique</pre><pre>table %s may not be indexed</pre><pre>views may not be indexed</pre><pre>virtual tables may not be indexed</pre><pre>there is already a table named %s</pre><pre>index %s already exists</pre><pre>sqlite_autoindex_%s_%d</pre><pre>table %s has no column named %s</pre><pre>CREATE%s INDEX %.*s</pre><pre>INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);</pre><pre>no such index: %S</pre><pre>index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped</pre><pre>DELETE FROM %Q.%s WHERE name=%Q AND type='index'</pre><pre>DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q</pre><pre>a JOIN clause is required before %s</pre><pre>unable to identify the object to be reindexed</pre><pre>table %s may not be modified</pre><pre>cannot modify %s because it is a view</pre><pre>foreign key mismatch</pre><pre>table %S has %d columns but %d values were supplied</pre><pre>%d values for %d columns</pre><pre>table %S has no column named %s</pre><pre>%s.%s may not be NULL</pre><pre>PRIMARY KEY must be unique</pre><pre>automatic extension loading failed: %s</pre><pre>foreign_key_list</pre><pre>malformed database schema (%s)</pre><pre>%s - %s</pre><pre>unsupported file format</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid</pre><pre>unknown or unsupported join type: %T %T%s%T</pre><pre>RIGHT and FULL OUTER JOINs are not currently supported</pre><pre>a NATURAL join may not have an ON or USING clause</pre><pre>cannot have both ON and USING clauses in the same join</pre><pre>cannot join using column %s - column not present in both tables</pre><pre>%s.%s</pre><pre>%s:%d</pre><pre>no such index: %s</pre><pre>sqlite_subquery_%p_</pre><pre>no such table: %s</pre><pre>cannot create %s trigger on view: %S</pre><pre>cannot create INSTEAD OF trigger on table: %S</pre><pre>INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')</pre><pre>no such trigger: %S</pre><pre>no such column: %s</pre><pre>cannot VACUUM - SQL statements in progress</pre><pre>PRAGMA vacuum_db.synchronous=OFF</pre><pre>SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'</pre><pre>SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';</pre><pre>INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)</pre><pre>UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d</pre><pre>vtable constructor failed: %s</pre><pre>vtable constructor did not declare schema: %s</pre><pre>no such module: %s</pre><pre>table %s: xBestIndex returned an invalid plan</pre><pre>at most %d tables in a join</pre><pre>cannot use index: %s</pre><pre>the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>unable to close due to unfinished backup operation</pre><pre>unknown database: %s</pre><pre>no such vfs: %s</pre><pre>database corruption at line %d of [%.10s]</pre><pre>misuse at line %d of [%.10s]</pre><pre>cannot open file at line %d of [%.10s]</pre><pre>sqlite3_open</pre><pre>sqlite3_prepare</pre><pre>sqlite3_step</pre><pre>sqlite3_column_text</pre><pre>sqlite3_column_int</pre><pre>sqlite3_column_int64</pre><pre>sqlite3_finalize</pre><pre>sqlite3_close</pre><pre>sqlite3_exec</pre><pre>f:\Projects\VS2005\WebBrowserPassView\Release\WebBrowserPassView.pdb</pre><pre>msvcrt.dll</pre><pre>_wcmdln</pre><pre>COMCTL32.dll</pre><pre>VERSION.dll</pre><pre>FindCloseUrlCache</pre><pre>FindNextUrlCacheEntryW</pre><pre>FindFirstUrlCacheEntryW</pre><pre>WININET.dll</pre><pre>GetWindowsDirectoryW</pre><pre>KERNEL32.dll</pre><pre>EnumChildWindows</pre><pre>USER32.dll</pre><pre>GDI32.dll</pre><pre>comdlg32.dll</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegEnumKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>5JEw%Xg</pre><pre><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></pre><pre>http://www.usertrust.com1</pre><pre>3http://crl.usertrust.com/AddTrustExternalCARoot.crl05</pre><pre>http://ocsp.usertrust.com0</pre><pre>1http://crl.usertrust.com/UTN-USERFirst-Object.crl05</pre><pre>1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t</pre><pre>1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%</pre><pre>https://secure.comodo.net/CPS0A</pre><pre>0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r</pre><pre>0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$</pre><pre>http://ocsp.comodoca.com0</pre><pre>support@nirsoft.net0</pre><pre>t{SSh</pre><pre>v%SSW</pre><pre>Mail PassView</pre><pre>Mozilla\Profiles</pre><pre>Software\Mozilla\Mozilla Thunderbird</pre><pre>%s\Main</pre><pre>sqlite3.dll</pre><pre>nss3.dll</pre><pre>%programfiles%\Mozilla Thunderbird</pre><pre>AddExportHeaderLine</pre><pre>%s %s %s</pre><pre>HTTPMail User Name</pre><pre>SMTP USer Name</pre><pre>HTTPMail Server</pre><pre>SMTP Server</pre><pre>POP3 Password2</pre><pre>IMAP Password2</pre><pre>HTTPMail Password2</pre><pre>SMTP Password2</pre><pre>POP3 Port</pre><pre>IMAP Port</pre><pre>HTTPMail Port</pre><pre>SMTP Port</pre><pre>HTTPMail Secure Connection</pre><pre>SMTP Secure Connection</pre><pre>SMTP Display Name</pre><pre>SMTP Email Address</pre><pre>POP3 Password</pre><pre>IMAP Password</pre><pre>HTTP Password</pre><pre>SMTP Password</pre><pre>HTTP User</pre><pre>SMTP User</pre><pre>HTTP Server URL</pre><pre>HTTP Port</pre><pre>HTTPMail Use SSL</pre><pre>SMTP Use SSL</pre><pre>%s\%s</pre><pre>PopPort</pre><pre>PopPassword</pre><pre>SMTPAccount</pre><pre>SMTPServer</pre><pre>SMTPPort</pre><pre>SMTPLogSecure</pre><pre>SMTPPassword</pre><pre>%s\Accounts</pre><pre>LoginName</pre><pre>SavePasswordText</pre><pre>ESMTPUsername</pre><pre>ESMTPPassword</pre><pre>POP3Password</pre><pre>fb.dat</pre><pre>%s@gmail.com</pre><pre>%s@yahoo.com</pre><pre>Software\Microsoft\Windows Messaging Subsystem\Profiles</pre><pre>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles</pre><pre><meta http-equiv="content-type" content="text/html;charset=%s" /></pre><pre><br /><h4>%s <a href="http://www.nirsoft.net/" target="newwin">%s</a></h4><p></p></pre><pre>smtp</pre><pre>advapi32.dll</pre><pre>comctl32.dll</pre><pre>*.ini</pre><pre>netmsg.dll</pre><pre>Error %d: %s</pre><pre>%s (%s)</pre><pre>menu_%d</pre><pre>dialog_%d</pre><pre>TranslatorURL</pre><pre>_lng.ini</pre><pre>%-18s: %s</pre><pre>%%-%d.%ds</pre><pre><td bgcolor="s" nowrap>%s</td></pre><pre><td bgcolor="s">%s</td></pre><pre><tr><td%s nowrap><b>%s</b><td bgcolor="s">%s</td></td%s></tr></pre><pre>bgcolor="%s"</pre><pre><font color="%s">%s</font></pre><pre><%s>%s</pre><pre></pre><pre>report.html</pre><pre>*.txt</pre><pre>*.htm;*.html</pre><pre>*.xml</pre><pre>*.csv</pre><pre>Software\NirSoft\MailPassView</pre><pre>MailPassView</pre><pre>/skeepass</pre><pre>/deleteregkey</pre><pre>Failed to load the executable file !</pre><pre>mail.account.account</pre><pre>mail.server</pre><pre>port</pre><pre>mail.identity</pre><pre>signon.signonfilename</pre><pre>mailbox://%s@%s</pre><pre>imap://%s@%s</pre><pre>mailbox://%s</pre><pre>imap://%s</pre><pre>signons.txt</pre><pre>signons.sqlite</pre><pre>prefs.js</pre><pre>Password.NET Messenger Service</pre><pre>User.NET Messenger Service</pre><pre>Passport.Net\*</pre><pre>ps:password</pre><pre>windowslive:name=</pre><pre>Exception %8.8X at address %8.8X in module %s</pre><pre>Stack Data: %s</pre><pre>Code Data: %s</pre><pre>mozsqlite3.dll</pre><pre>psapi.dll</pre><pre>pstorec.dll</pre><pre>5e7e8100-9138-11d1-945a-00c04fc308ff</pre><pre>00000000-0000-0000-0000-000000000000</pre><pre>220D5CD0-853A-11D0-84BC-00C04FD43F8F</pre><pre>220D5CD1-853A-11D0-84BC-00C04FD43F8F</pre><pre>220D5CC1-853A-11D0-84BC-00C04FD43F8F</pre><pre>417E2D75-84BD-11D0-84BB-00C04FD43F8F</pre><pre>shell32.dll</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</pre><pre>shlwapi.dll</pre><pre><html><head>%s<title>%s</title></head></html></pre><pre>%s <h3>%s</h3></pre><pre>size="%d"</pre><pre>color="#%s"</pre><pre><font color="%s"></font></pre><pre><table border="1" cellpadding="5"><tr%s></tr%s></table></pre><pre>width="%s"</pre><pre><th%s>%s%s%s</th%s></pre><pre>SOFTWARE\Mozilla</pre><pre>mozilla</pre><pre>%s\bin</pre><pre>PathToExe</pre><pre>\sqlite3.dll</pre><pre>\mozsqlite3.dll</pre><pre>Software\Microsoft\Windows Mail</pre><pre>Software\Microsoft\Windows Live Mail</pre><pre>SMTP_Server</pre><pre>SMTP_User_Name</pre><pre>POP3_Password2</pre><pre>IMAP_Password2</pre><pre>NNTP_Password2</pre><pre>SMTP_Password2</pre><pre>SMTP_Email_Address</pre><pre>SMTP_Port</pre><pre>NNTP_Port</pre><pre>IMAP_Port</pre><pre>POP3_Port</pre><pre>SMTP_Secure_Connection</pre><pre>*.oeaccount</pre><pre>\Microsoft\Windows Mail</pre><pre>\Microsoft\Windows Live Mail</pre><pre>f:\Projects\VS2005\mailpv\Release\mailpv.pdb</pre><pre>_acmdln</pre><pre>RPCRT4.dll</pre><pre>GetWindowsDirectoryA</pre><pre>RegDeleteKeyA</pre><pre>RegOpenKeyExA</pre><pre>RegEnumKeyA</pre><pre>RegEnumKeyExA</pre><pre>ShellExecuteA</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="NirSoft" type="win32"></assemblyIdentity><description>NirSoft</description><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD</pre><pre>Debugger.exe</pre><pre>Microsoft.VisualBasic</pre><pre>System.Windows.Forms</pre><pre>System.Drawing</pre><pre>System.Management</pre><pre>tapi32.dll</pre><pre>rtm.dll</pre><pre>user32.dll</pre><pre>Debugger.Debugger.resources</pre><pre>Debugger.Resources.resources</pre><pre>Debugger.My</pre><pre>WindowsFormsApplicationBase</pre><pre>Microsoft.VisualBasic.ApplicationServices</pre><pre>System.ComponentModel</pre><pre>System.CodeDom.Compiler</pre><pre>Microsoft.VisualBasic.Devices</pre><pre>m_MyWebServicesObjectProvider</pre><pre>.cctor</pre><pre>get_WebServices</pre><pre>HelpKeywordAttribute</pre><pre>System.ComponentModel.Design</pre><pre>WebServices</pre><pre>Microsoft.VisualBasic.CompilerServices</pre><pre>System.Collections</pre><pre>ContainsKey</pre><pre>InvalidOperationException</pre><pre>MyWebServices</pre><pre>encryptedpassstring</pre><pre>encryptedsmtpstring</pre><pre>portstring</pre><pre>fakeMSGholder</pre><pre>encryptedftphost</pre><pre>encryptedftpuser</pre><pre>encryptedftppass</pre><pre>useftp</pre><pre>websitevisitor</pre><pre>websiteblocker</pre><pre>passstring</pre><pre>smtpstring</pre><pre>ftphost</pre><pre>ftpuser</pre><pre>ftppass</pre><pre>WM_KEYUP</pre><pre>WM_KEYDOWN</pre><pre>WM_SYSKEYDOWN</pre><pre>WM_SYSKEYUP</pre><pre>KeyboardHandle</pre><pre>KeyLog</pre><pre>CleanedPasswordsMAIL</pre><pre>CleanedPasswordsWB</pre><pre>System.IO</pre><pre>get_ExecutablePath</pre><pre>WindowsIdentity</pre><pre>System.Security.Principal</pre><pre>set_WindowState</pre><pre>FormWindowState</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookEx</pre><pre>SetWindowsHookExA</pre><pre>GetAsyncKeyState</pre><pre>vKey</pre><pre>HookKeyboard</pre><pre>UnhookKeyboard</pre><pre>Operators</pre><pre>get_Keyboard</pre><pre>Keyboard</pre><pre>get_CtrlKeyDown</pre><pre>get_AltKeyDown</pre><pre>KeyboardCallback</pre><pre>System.Threading</pre><pre>System.Collections.Generic</pre><pre>Microsoft.VisualBasic.MyServices</pre><pre>System.Collections.ObjectModel</pre><pre>MsgBox</pre><pre>MsgBoxResult</pre><pre>MsgBoxStyle</pre><pre>set_WindowStyle</pre><pre>ProcessWindowStyle</pre><pre>ForceSteamLogin</pre><pre>System.Net.NetworkInformation</pre><pre>get_OperationalStatus</pre><pre>OperationalStatus</pre><pre>FakemsgInstall</pre><pre>System.Net.Mail</pre><pre>SmtpClient</pre><pre>System.Globalization</pre><pre>set_Port</pre><pre>System.Net</pre><pre>Microsoft.Win32</pre><pre>RegistryKey</pre><pre>OpenSubKey</pre><pre>System.Security.Cryptography</pre><pre>System.Text</pre><pre>set_Key</pre><pre>stealWebroswers</pre><pre>WebClient</pre><pre>readweb</pre><pre>System.IO.Compression</pre><pre>SendLogsFTP</pre><pre>FtpWebRequest</pre><pre>WebRequest</pre><pre>UploadFTP</pre><pre>secretKey</pre><pre>set_KeySize</pre><pre>get_KeySize</pre><pre>System.Net.Sockets</pre><pre>virtualKey</pre><pre>KeyboardHookDelegate</pre><pre>get_Msg</pre><pre>Debugger.My.Resources</pre><pre>System.Resources</pre><pre>get_CMemoryExecute</pre><pre>get_WebBrowserPassView</pre><pre>WebBrowserPassView</pre><pre>System.Configuration</pre><pre>8.0.0.0</pre><pre>My.Computer</pre><pre>My.Application</pre><pre>My.User</pre><pre>My.Forms</pre><pre>My.WebServices</pre><pre>System.Windows.Forms.Form</pre><pre>My.MyProject.Forms</pre><pre>4System.Web.Services.Protocols.SoapHttpClientProtocol</pre><pre>3System.Resources.Tools.StronglyTypedResourceBuilder</pre><pre>4.0.0.0</pre><pre>KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator</pre><pre>10.0.0.0</pre><pre>My.Settings</pre><pre>$e48811ca-8af8-4e73-85dd-2045b9cca73a</pre><pre>_CorExeMain</pre><pre><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /></pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false" /></pre><pre>%%0.ß</pre><pre>Apple Computer\Preferences\keychain.plist</pre><pre>LoadPasswordsIE</pre><pre>LoadPasswordsFirefox</pre><pre>LoadPasswordsChrome</pre><pre>LoadPasswordsOpera</pre><pre>LoadPasswordsSafari</pre><pre>LoadPasswordsSeaMonkey</pre><pre>UseFirefoxProfileFolder</pre><pre>UseFirefoxInstallFolder</pre><pre>UseChromeProfileFolder</pre><pre>UseOperaPasswordFile</pre><pre>FirefoxProfileFolder</pre><pre>FirefoxInstallFolder</pre><pre>ChromeProfileFolder</pre><pre>OperaPasswordFile</pre><pre>Aadvapi32.dll</pre><pre>crypt32.dll</pre><pre>777705555443332</pre><pre>5555443332</pre><pre>5555443332</pre><pre>wand.dat</pre><pre>@nss3.dll</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe</pre><pre>%programfiles%\Sea Monkey</pre><pre>%programfiles%\Mozilla Firefox</pre><pre>-signons.txt</pre><pre>signons2.txt</pre><pre>signons3.txt</pre><pre>@dllhost.exe</pre><pre>taskhost.exe</pre><pre>taskhostex.exe</pre><pre>Microsoft\Windows\WebCache\WebCacheV01.dat</pre><pre>Microsoft\Windows\WebCache\WebCacheV24.dat</pre><pre>index.dat</pre><pre>https://www.google.com/accounts/servicelogin</pre><pre>http://www.facebook.com/</pre><pre>https://login.yahoo.com/config/login</pre><pre>http://</pre><pre>https://</pre><pre>ftp://</pre><pre>@history.dat</pre><pre>places.sqlite</pre><pre>Mozilla\Firefox\Profiles</pre><pre>Mozilla\SeaMonkey\Profiles</pre><pre>Mozilla\SeaMonkey</pre><pre>Mozilla\Firefox</pre><pre>profiles.ini</pre><pre>Profile%d</pre><pre>tntdll.dll</pre><pre>sWeb Data</pre><pre>Login Data</pre><pre>Google\Chrome\User Data</pre><pre>Google\Chrome SxS\User Data</pre><pre>Opera\Opera\wand.dat</pre><pre>Opera\Opera7\profile\wand.dat</pre><pre>Opera</pre><pre>@"%s"</pre><pre>Ashell32.dll</pre><pre>\nss3.dll</pre><pre>.save</pre><pre>vaultcli.dll</pre><pre>abe2869f-9b47-4cd9-a358-c22904dba7f7</pre><pre>Copy &Password</pre><pre>&HTML Report - All Items</pre><pre>HTML R&eport - Selected Items</pre><pre>HTML Report - All Items</pre><pre>HTML Report - Selected Items</pre><pre>Load Passwords From...</pre><pre>Google Chrome</pre><pre>Mozilla Firefox</pre><pre>SeaMonkey</pre><pre>Firefox Options</pre><pre>Master password:</pre><pre>Firefox Profile:</pre><pre>Firefox Installation:</pre><pre>Chrome Options</pre><pre>Opera Options</pre><pre>wand.dat file:</pre><pre>%d Passwords</pre><pre>, %d Selected</pre><pre>Web Browser Passwords%Choose another Firefox profile folder)Choose the installation folder of Firefox,Choose another profile of Chrome Web browser,Choose the password file of Opera (wand.dat)</pre><pre>Loading... %d</pre><pre>KeePass csv file</pre><pre>Opera Password File</pre><pre>Firefox 1.x</pre><pre>Firefox 2.x</pre><pre>Firefox 3.0</pre><pre>Firefox</pre><pre>Chrome</pre><pre>Web Browser</pre><pre>Password</pre><pre>Password Strength</pre><pre>Password Field</pre><pre>WebBrowserPassView.exe</pre><pre>www.google.com/Please log in to your Gmail account</pre><pre>www.google.com:443/Please log in to your Gmail account</pre><pre>www.google.com/Please log in to your Google Account</pre><pre>www.google.com:443/Please log in to your Google Account</pre><pre>www.google.com</pre><pre>dWindowsLive:name=*</pre><pre>82BD0E67-9FEA-4748-8672-D5EFE5B779B0</pre><pre>Copy Password</pre><pre>%d items</pre><pre>Select Eudora.ini filename/Select the location of Thunderbird installation</pre><pre>Eudora.ini file</pre><pre>SMTP</pre><pre>Windows Mail</pre><pre>Windows Live Mail</pre><pre>Server Port</pre><pre>SMTP Server Port</pre><pre>Mail Password Recovery</pre><pre>mailpv.exe</pre><pre>3, 7 #,)</pre><pre>MessageBoxIcon.Error</pre><pre>noftp</pre><pre>filename.exe</pre><pre>http://www.example.com/directory/file.exe</pre><pre>Disablecmd</pre><pre>\Windows Update.exe</pre><pre>\WindowsUpdate.exe</pre><pre>SysInfo.txt</pre><pre>\pid.txt</pre><pre>\pidloc.txt</pre><pre>\Mozilla\Firefox\Profiles</pre><pre>127.0.0.1</pre><pre>ping -n 1 -w 3000 1.1.1.1</pre><pre>cmd.exe</pre><pre>\SteamAppData.vdf</pre><pre>\ClientRegistry.blob</pre><pre>MessageBoxIcon.Exclamation</pre><pre>Keylogger Enabled:</pre><pre>Operating System:</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced</pre><pre>autorun.inf</pre><pre>open=Sys.exe</pre><pre>Sys.exe</pre><pre>Software\Microsoft\Windows\CurrentVersion\Run</pre><pre>Windows Update</pre><pre>C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>\bitcoin\wallet.dat</pre><pre>_wallet.dat</pre><pre>wallet.dat</pre><pre>Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>holdermail.txt"</pre><pre>holdermail.txt</pre><pre>Operating System Intel Recovery</pre><pre>Operating System Platform:</pre><pre>Operating System Version:</pre><pre>WEB Browser Password Recovery</pre><pre>Mail Messenger Password Recovery</pre><pre>Jdownloader Password Recovery</pre><pre>holderwb.txt"</pre><pre>holderwb.txt</pre><pre>C:\Users\</pre><pre>_Pin0.jpeg</pre><pre>_Pin1.jpeg</pre><pre>_Pin2.jpeg</pre><pre>_Pin3.jpeg</pre><pre>_Pin4.jpeg</pre><pre>Steals the Wallet.DAT file that holds the users bitcoin currency</pre><pre>\.minecraft\lastlogin</pre><pre>There is a file attached to this email containing Minecraft username and password download it then decrypt the login information with my Minecraft Decryptor</pre><pre>Predator Pain v14 - Key Recorder - [</pre><pre>Keylogger Log</pre><pre>.jpeg</pre><pre>Predator_Pain_v14_KeyLog_</pre><pre>http://whatismyipaddress.com/</pre><pre>Debugger.Resources</pre><pre>:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>6.3.9600.16384 (winblue_rtm.130821-1623)</pre><pre>xpsrchvw.exe</pre><pre>Windows</pre><pre>Operating System</pre><pre>6.3.9600.16384</pre><b>xpsrchvw.exe_1188_rwx_00400000_00084000:</b><pre>.text</pre><pre>`.rsrc</pre><pre>@.reloc</pre><pre>lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet</pre><pre>v2.0.50727</pre><pre>CMemoryExecute.dll</pre><pre>CMemoryExecute</pre><pre>PAGE_EXECUTE_READWRITE</pre><pre>.ctor</pre><pre>System.Reflection</pre><pre>System.Runtime.InteropServices</pre><pre>System.Security.Permissions</pre><pre>System.Diagnostics</pre><pre>System.Runtime.CompilerServices</pre><pre>DllImportAttribute</pre><pre>kernel32.dll</pre><pre>ntdll.dll</pre><pre>System.Security</pre><pre>$8fcd4931-91a2-4e18-849b-70de34ab75df</pre><pre>1.0.0.0</pre><pre>System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</pre><pre>C:\Users\Jovan\Documents\Visual Studio 2010\Projects\Stealer\CMemoryExecute\CMemoryExecute\obj\Release\CMemoryExecute.pdb</pre><pre>mscoree.dll</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>D$.SPf</pre><pre> 2 34 567</pre><pre>com.apple.Safari</pre><pre>com.apple.WebKit2WebProcess</pre><pre>SELECT origin_url, action_url, username_element, username_value, password_element, password_value, signon_realm, date_created from logins</pre><pre>"Account","Login Name","Password","Web Site","Comments"</pre><pre>3.7.5</pre><pre>SQLite format 3</pre><pre>CREATE TABLE sqlite_master(</pre><pre>sql text</pre><pre>REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY</pre><pre>SELECT id, hostname, httpRealm, formSubmitURL, usernameField, passwordField, encryptedUsername, encryptedPassword FROM moz_logins</pre><pre>PK11_GetInternalKeySlot</pre><pre>PK11_CheckUserPassword</pre><pre>large file support is disabled</pre><pre>unknown operation</pre><pre>SQL logic error or missing database</pre><pre>foreign_keys</pre><pre>sqlite_compileoption_get</pre><pre>sqlite_compileoption_used</pre><pre>sqlite_source_id</pre><pre>sqlite_version</pre><pre>sqlite_attach</pre><pre>sqlite_detach</pre><pre>sqlite_stat1</pre><pre>sqlite_rename_parent</pre><pre>sqlite_rename_trigger</pre><pre>sqlite_rename_table</pre><pre>%Y-%m-%d %H:%M:%S</pre><pre>%Y-%m-%d</pre><pre>%H:%M:%S</pre><pre>SQLITE_</pre><pre>failed to allocate %u bytes of memory</pre><pre>failed memory resize %u to %u bytes</pre><pre>922337203685477580</pre><pre>API call with %s database connection pointer</pre><pre>%s-shm</pre><pre>%s\etilqs_</pre><pre>OsError 0x%x (%u)</pre><pre>Recovered %d frames from WAL file %s</pre><pre>%s-mjX</pre><pre>foreign key constraint failed</pre><pre>unable to use function %s in the requested context</pre><pre>abort at %d in [%s]: %s</pre><pre>constraint failed at %d in [%s]</pre><pre>cannot open savepoint - SQL statements in progress</pre><pre>no such savepoint: %s</pre><pre>cannot %s savepoint - SQL statements in progress</pre><pre>cannot rollback transaction - SQL statements in progress</pre><pre>cannot commit transaction - SQL statements in progress</pre><pre>sqlite_master</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid</pre><pre>cannot change %s wal mode from within a transaction</pre><pre>statement aborts at %d: [%s] %s</pre><pre>misuse of aliased aggregate %s</pre><pre>%s: %s.%s.%s</pre><pre>%s: %s.%s</pre><pre>%s: %s</pre><pre>%r %s BY term out of range - should be between 1 and %d</pre><pre>too many terms in %s BY clause</pre><pre>Expression tree is too large (maximum depth %d)</pre><pre>variable number must be between ?1 and ?%d</pre><pre>too many SQL variables</pre><pre>too many columns in %s</pre><pre>oversized integer: %s%s</pre><pre>misuse of aggregate: %s()</pre><pre>%.*s"%w"%s</pre><pre>%s%.*s"%w"</pre><pre>%s OR name=%Q</pre><pre>type='trigger' AND (%s)</pre><pre>there is already another table or index with this name: %s</pre><pre>sqlite_</pre><pre>table %s may not be altered</pre><pre>view %s may not be altered</pre><pre>UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;</pre><pre>UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');</pre><pre>UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;</pre><pre>Cannot add a PRIMARY KEY column</pre><pre>UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q</pre><pre>sqlite_altertab_%s</pre><pre>CREATE TABLE %Q.%s(%s)</pre><pre>DELETE FROM %Q.%s WHERE tbl=%Q</pre><pre>SELECT tbl, idx, stat FROM %Q.sqlite_stat1</pre><pre>invalid name: "%s"</pre><pre>too many attached databases - max %d</pre><pre>database %s is already in use</pre><pre>unable to open database: %s</pre><pre>no such database: %s</pre><pre>cannot detach database %s</pre><pre>database %s is locked</pre><pre>%s %T cannot reference objects in database %s</pre><pre>object name reserved for internal use: %s</pre><pre>there is already an index named %s</pre><pre>too many columns on %s</pre><pre>duplicate column name: %s</pre><pre>default value of column [%s] is not constant</pre><pre>table "%s" has more than one primary key</pre><pre>no such collation sequence: %s</pre><pre>CREATE %s %.*s</pre><pre>UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d</pre><pre>view %s is circularly defined</pre><pre>table %s may not be dropped</pre><pre>use DROP TABLE to delete table %s</pre><pre>use DROP VIEW to delete view %s</pre><pre>DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'</pre><pre>DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q</pre><pre>foreign key on %s should reference only one column of table %T</pre><pre>number of columns in foreign key does not match the number of columns in the referenced table</pre><pre>unknown column "%s" in foreign key definition</pre><pre>indexed columns are not unique</pre><pre>table %s may not be indexed</pre><pre>views may not be indexed</pre><pre>virtual tables may not be indexed</pre><pre>there is already a table named %s</pre><pre>index %s already exists</pre><pre>sqlite_autoindex_%s_%d</pre><pre>table %s has no column named %s</pre><pre>CREATE%s INDEX %.*s</pre><pre>INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);</pre><pre>no such index: %S</pre><pre>index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped</pre><pre>DELETE FROM %Q.%s WHERE name=%Q AND type='index'</pre><pre>DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q</pre><pre>a JOIN clause is required before %s</pre><pre>unable to identify the object to be reindexed</pre><pre>table %s may not be modified</pre><pre>cannot modify %s because it is a view</pre><pre>foreign key mismatch</pre><pre>table %S has %d columns but %d values were supplied</pre><pre>%d values for %d columns</pre><pre>table %S has no column named %s</pre><pre>%s.%s may not be NULL</pre><pre>PRIMARY KEY must be unique</pre><pre>automatic extension loading failed: %s</pre><pre>foreign_key_list</pre><pre>malformed database schema (%s)</pre><pre>%s - %s</pre><pre>unsupported file format</pre><pre>SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid</pre><pre>unknown or unsupported join type: %T %T%s%T</pre><pre>RIGHT and FULL OUTER JOINs are not currently supported</pre><pre>a NATURAL join may not have an ON or USING clause</pre><pre>cannot have both ON and USING clauses in the same join</pre><pre>cannot join using column %s - column not present in both tables</pre><pre>%s.%s</pre><pre>%s:%d</pre><pre>no such index: %s</pre><pre>sqlite_subquery_%p_</pre><pre>no such table: %s</pre><pre>cannot create %s trigger on view: %S</pre><pre>cannot create INSTEAD OF trigger on table: %S</pre><pre>INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')</pre><pre>no such trigger: %S</pre><pre>no such column: %s</pre><pre>cannot VACUUM - SQL statements in progress</pre><pre>PRAGMA vacuum_db.synchronous=OFF</pre><pre>SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'</pre><pre>SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0</pre><pre>SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'</pre><pre>SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';</pre><pre>INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)</pre><pre>UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d</pre><pre>vtable constructor failed: %s</pre><pre>vtable constructor did not declare schema: %s</pre><pre>no such module: %s</pre><pre>table %s: xBestIndex returned an invalid plan</pre><pre>at most %d tables in a join</pre><pre>cannot use index: %s</pre><pre>the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers</pre><pre>unable to close due to unfinished backup operation</pre><pre>unknown database: %s</pre><pre>no such vfs: %s</pre><pre>database corruption at line %d of [%.10s]</pre><pre>misuse at line %d of [%.10s]</pre><pre>cannot open file at line %d of [%.10s]</pre><pre>sqlite3_open</pre><pre>sqlite3_prepare</pre><pre>sqlite3_step</pre><pre>sqlite3_column_text</pre><pre>sqlite3_column_int</pre><pre>sqlite3_column_int64</pre><pre>sqlite3_finalize</pre><pre>sqlite3_close</pre><pre>sqlite3_exec</pre><pre>f:\Projects\VS2005\WebBrowserPassView\Release\WebBrowserPassView.pdb</pre><pre>msvcrt.dll</pre><pre>_wcmdln</pre><pre>COMCTL32.dll</pre><pre>VERSION.dll</pre><pre>FindCloseUrlCache</pre><pre>FindNextUrlCacheEntryW</pre><pre>FindFirstUrlCacheEntryW</pre><pre>WININET.dll</pre><pre>GetWindowsDirectoryW</pre><pre>KERNEL32.dll</pre><pre>EnumChildWindows</pre><pre>USER32.dll</pre><pre>GDI32.dll</pre><pre>comdlg32.dll</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegEnumKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>5JEw%Xg</pre><pre><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></pre><pre>http://www.usertrust.com1</pre><pre>3http://crl.usertrust.com/AddTrustExternalCARoot.crl05</pre><pre>http://ocsp.usertrust.com0</pre><pre>1http://crl.usertrust.com/UTN-USERFirst-Object.crl05</pre><pre>1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t</pre><pre>1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%</pre><pre>https://secure.comodo.net/CPS0A</pre><pre>0http://crl.comodoca.com/COMODOCodeSigningCA2.crl0r</pre><pre>0http://crt.comodoca.com/COMODOCodeSigningCA2.crt0$</pre><pre>http://ocsp.comodoca.com0</pre><pre>support@nirsoft.net0</pre><pre>t{SSh</pre><pre>v%SSW</pre><pre>Mail PassView</pre><pre>Mozilla\Profiles</pre><pre>Software\Mozilla\Mozilla Thunderbird</pre><pre>%s\Main</pre><pre>sqlite3.dll</pre><pre>nss3.dll</pre><pre>%programfiles%\Mozilla Thunderbird</pre><pre>AddExportHeaderLine</pre><pre>%s %s %s</pre><pre>HTTPMail User Name</pre><pre>SMTP USer Name</pre><pre>HTTPMail Server</pre><pre>SMTP Server</pre><pre>POP3 Password2</pre><pre>IMAP Password2</pre><pre>HTTPMail Password2</pre><pre>SMTP Password2</pre><pre>POP3 Port</pre><pre>IMAP Port</pre><pre>HTTPMail Port</pre><pre>SMTP Port</pre><pre>HTTPMail Secure Connection</pre><pre>SMTP Secure Connection</pre><pre>SMTP Display Name</pre><pre>SMTP Email Address</pre><pre>POP3 Password</pre><pre>IMAP Password</pre><pre>HTTP Password</pre><pre>SMTP Password</pre><pre>HTTP User</pre><pre>SMTP User</pre><pre>HTTP Server URL</pre><pre>HTTP Port</pre><pre>HTTPMail Use SSL</pre><pre>SMTP Use SSL</pre><pre>%s\%s</pre><pre>PopPort</pre><pre>PopPassword</pre><pre>SMTPAccount</pre><pre>SMTPServer</pre><pre>SMTPPort</pre><pre>SMTPLogSecure</pre><pre>SMTPPassword</pre><pre>%s\Accounts</pre><pre>LoginName</pre><pre>SavePasswordText</pre><pre>ESMTPUsername</pre><pre>ESMTPPassword</pre><pre>POP3Password</pre><pre>fb.dat</pre><pre>%s@gmail.com</pre><pre>%s@yahoo.com</pre><pre>Software\Microsoft\Windows Messaging Subsystem\Profiles</pre><pre>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles</pre><pre><meta http-equiv="content-type" content="text/html;charset=%s" /></pre><pre><br /><h4>%s <a href="http://www.nirsoft.net/" target="newwin">%s</a></h4><p></p></pre><pre>smtp</pre><pre>advapi32.dll</pre><pre>comctl32.dll</pre><pre>*.ini</pre><pre>netmsg.dll</pre><pre>Error %d: %s</pre><pre>%s (%s)</pre><pre>menu_%d</pre><pre>dialog_%d</pre><pre>TranslatorURL</pre><pre>_lng.ini</pre><pre>%-18s: %s</pre><pre>%%-%d.%ds</pre><pre><td bgcolor="s" nowrap>%s</td></pre><pre><td bgcolor="s">%s</td></pre><pre><tr><td%s nowrap><b>%s</b><td bgcolor="s">%s</td></td%s></tr></pre><pre>bgcolor="%s"</pre><pre><font color="%s">%s</font></pre><pre><%s>%s</pre><pre></pre><pre>report.html</pre><pre>*.txt</pre><pre>*.htm;*.html</pre><pre>*.xml</pre><pre>*.csv</pre><pre>Software\NirSoft\MailPassView</pre><pre>MailPassView</pre><pre>/skeepass</pre><pre>/deleteregkey</pre><pre>Failed to load the executable file !</pre><pre>mail.account.account</pre><pre>mail.server</pre><pre>port</pre><pre>mail.identity</pre><pre>signon.signonfilename</pre><pre>mailbox://%s@%s</pre><pre>imap://%s@%s</pre><pre>mailbox://%s</pre><pre>imap://%s</pre><pre>signons.txt</pre><pre>signons.sqlite</pre><pre>prefs.js</pre><pre>Password.NET Messenger Service</pre><pre>User.NET Messenger Service</pre><pre>Passport.Net\*</pre><pre>ps:password</pre><pre>windowslive:name=</pre><pre>Exception %8.8X at address %8.8X in module %s</pre><pre>Stack Data: %s</pre><pre>Code Data: %s</pre><pre>mozsqlite3.dll</pre><pre>psapi.dll</pre><pre>pstorec.dll</pre><pre>5e7e8100-9138-11d1-945a-00c04fc308ff</pre><pre>00000000-0000-0000-0000-000000000000</pre><pre>220D5CD0-853A-11D0-84BC-00C04FD43F8F</pre><pre>220D5CD1-853A-11D0-84BC-00C04FD43F8F</pre><pre>220D5CC1-853A-11D0-84BC-00C04FD43F8F</pre><pre>417E2D75-84BD-11D0-84BB-00C04FD43F8F</pre><pre>shell32.dll</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</pre><pre>shlwapi.dll</pre><pre><html><head>%s<title>%s</title></head></html></pre><pre>%s <h3>%s</h3></pre><pre>size="%d"</pre><pre>color="#%s"</pre><pre><font color="%s"></font></pre><pre><table border="1" cellpadding="5"><tr%s></tr%s></table></pre><pre>width="%s"</pre><pre><th%s>%s%s%s</th%s></pre><pre>SOFTWARE\Mozilla</pre><pre>mozilla</pre><pre>%s\bin</pre><pre>PathToExe</pre><pre>\sqlite3.dll</pre><pre>\mozsqlite3.dll</pre><pre>Software\Microsoft\Windows Mail</pre><pre>Software\Microsoft\Windows Live Mail</pre><pre>SMTP_Server</pre><pre>SMTP_User_Name</pre><pre>POP3_Password2</pre><pre>IMAP_Password2</pre><pre>NNTP_Password2</pre><pre>SMTP_Password2</pre><pre>SMTP_Email_Address</pre><pre>SMTP_Port</pre><pre>NNTP_Port</pre><pre>IMAP_Port</pre><pre>POP3_Port</pre><pre>SMTP_Secure_Connection</pre><pre>*.oeaccount</pre><pre>\Microsoft\Windows Mail</pre><pre>\Microsoft\Windows Live Mail</pre><pre>f:\Projects\VS2005\mailpv\Release\mailpv.pdb</pre><pre>_acmdln</pre><pre>RPCRT4.dll</pre><pre>GetWindowsDirectoryA</pre><pre>RegDeleteKeyA</pre><pre>RegOpenKeyExA</pre><pre>RegEnumKeyA</pre><pre>RegEnumKeyExA</pre><pre>ShellExecuteA</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="NirSoft" type="win32"></assemblyIdentity><description>NirSoft</description><dependency><dependentAssembly><assemblyIdentity type="Win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD</pre><pre>Debugger.exe</pre><pre>Microsoft.VisualBasic</pre><pre>System.Windows.Forms</pre><pre>System.Drawing</pre><pre>System.Management</pre><pre>tapi32.dll</pre><pre>rtm.dll</pre><pre>user32.dll</pre><pre>Debugger.Debugger.resources</pre><pre>Debugger.Resources.resources</pre><pre>Debugger.My</pre><pre>WindowsFormsApplicationBase</pre><pre>Microsoft.VisualBasic.ApplicationServices</pre><pre>System.ComponentModel</pre><pre>System.CodeDom.Compiler</pre><pre>Microsoft.VisualBasic.Devices</pre><pre>m_MyWebServicesObjectProvider</pre><pre>.cctor</pre><pre>get_WebServices</pre><pre>HelpKeywordAttribute</pre><pre>System.ComponentModel.Design</pre><pre>WebServices</pre><pre>Microsoft.VisualBasic.CompilerServices</pre><pre>System.Collections</pre><pre>ContainsKey</pre><pre>InvalidOperationException</pre><pre>MyWebServices</pre><pre>encryptedpassstring</pre><pre>encryptedsmtpstring</pre><pre>portstring</pre><pre>fakeMSGholder</pre><pre>encryptedftphost</pre><pre>encryptedftpuser</pre><pre>encryptedftppass</pre><pre>useftp</pre><pre>websitevisitor</pre><pre>websiteblocker</pre><pre>passstring</pre><pre>smtpstring</pre><pre>ftphost</pre><pre>ftpuser</pre><pre>ftppass</pre><pre>WM_KEYUP</pre><pre>WM_KEYDOWN</pre><pre>WM_SYSKEYDOWN</pre><pre>WM_SYSKEYUP</pre><pre>KeyboardHandle</pre><pre>KeyLog</pre><pre>CleanedPasswordsMAIL</pre><pre>CleanedPasswordsWB</pre><pre>System.IO</pre><pre>get_ExecutablePath</pre><pre>WindowsIdentity</pre><pre>System.Security.Principal</pre><pre>set_WindowState</pre><pre>FormWindowState</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookEx</pre><pre>SetWindowsHookExA</pre><pre>GetAsyncKeyState</pre><pre>vKey</pre><pre>HookKeyboard</pre><pre>UnhookKeyboard</pre><pre>Operators</pre><pre>get_Keyboard</pre><pre>Keyboard</pre><pre>get_CtrlKeyDown</pre><pre>get_AltKeyDown</pre><pre>KeyboardCallback</pre><pre>System.Threading</pre><pre>System.Collections.Generic</pre><pre>Microsoft.VisualBasic.MyServices</pre><pre>System.Collections.ObjectModel</pre><pre>MsgBox</pre><pre>MsgBoxResult</pre><pre>MsgBoxStyle</pre><pre>set_WindowStyle</pre><pre>ProcessWindowStyle</pre><pre>ForceSteamLogin</pre><pre>System.Net.NetworkInformation</pre><pre>get_OperationalStatus</pre><pre>OperationalStatus</pre><pre>FakemsgInstall</pre><pre>System.Net.Mail</pre><pre>SmtpClient</pre><pre>System.Globalization</pre><pre>set_Port</pre><pre>System.Net</pre><pre>Microsoft.Win32</pre><pre>RegistryKey</pre><pre>OpenSubKey</pre><pre>System.Security.Cryptography</pre><pre>System.Text</pre><pre>set_Key</pre><pre>stealWebroswers</pre><pre>WebClient</pre><pre>readweb</pre><pre>System.IO.Compression</pre><pre>SendLogsFTP</pre><pre>FtpWebRequest</pre><pre>WebRequest</pre><pre>UploadFTP</pre><pre>secretKey</pre><pre>set_KeySize</pre><pre>get_KeySize</pre><pre>System.Net.Sockets</pre><pre>virtualKey</pre><pre>KeyboardHookDelegate</pre><pre>get_Msg</pre><pre>Debugger.My.Resources</pre><pre>System.Resources</pre><pre>get_CMemoryExecute</pre><pre>get_WebBrowserPassView</pre><pre>WebBrowserPassView</pre><pre>System.Configuration</pre><pre>8.0.0.0</pre><pre>My.Computer</pre><pre>My.Application</pre><pre>My.User</pre><pre>My.Forms</pre><pre>My.WebServices</pre><pre>System.Windows.Forms.Form</pre><pre>My.MyProject.Forms</pre><pre>4System.Web.Services.Protocols.SoapHttpClientProtocol</pre><pre>3System.Resources.Tools.StronglyTypedResourceBuilder</pre><pre>4.0.0.0</pre><pre>KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator</pre><pre>10.0.0.0</pre><pre>My.Settings</pre><pre>$e48811ca-8af8-4e73-85dd-2045b9cca73a</pre><pre>_CorExeMain</pre><pre><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /></pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false" /></pre><pre>%%0.ß</pre><pre>Apple Computer\Preferences\keychain.plist</pre><pre>LoadPasswordsIE</pre><pre>LoadPasswordsFirefox</pre><pre>LoadPasswordsChrome</pre><pre>LoadPasswordsOpera</pre><pre>LoadPasswordsSafari</pre><pre>LoadPasswordsSeaMonkey</pre><pre>UseFirefoxProfileFolder</pre><pre>UseFirefoxInstallFolder</pre><pre>UseChromeProfileFolder</pre><pre>UseOperaPasswordFile</pre><pre>FirefoxProfileFolder</pre><pre>FirefoxInstallFolder</pre><pre>ChromeProfileFolder</pre><pre>OperaPasswordFile</pre><pre>Aadvapi32.dll</pre><pre>crypt32.dll</pre><pre>777705555443332</pre><pre>5555443332</pre><pre>5555443332</pre><pre>wand.dat</pre><pre>@nss3.dll</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\seamonkey.exe</pre><pre>%programfiles%\Sea Monkey</pre><pre>%programfiles%\Mozilla Firefox</pre><pre>-signons.txt</pre><pre>signons2.txt</pre><pre>signons3.txt</pre><pre>@dllhost.exe</pre><pre>taskhost.exe</pre><pre>taskhostex.exe</pre><pre>Microsoft\Windows\WebCache\WebCacheV01.dat</pre><pre>Microsoft\Windows\WebCache\WebCacheV24.dat</pre><pre>index.dat</pre><pre>https://www.google.com/accounts/servicelogin</pre><pre>http://www.facebook.com/</pre><pre>https://login.yahoo.com/config/login</pre><pre>http://</pre><pre>https://</pre><pre>ftp://</pre><pre>@history.dat</pre><pre>places.sqlite</pre><pre>Mozilla\Firefox\Profiles</pre><pre>Mozilla\SeaMonkey\Profiles</pre><pre>Mozilla\SeaMonkey</pre><pre>Mozilla\Firefox</pre><pre>profiles.ini</pre><pre>Profile%d</pre><pre>tntdll.dll</pre><pre>sWeb Data</pre><pre>Login Data</pre><pre>Google\Chrome\User Data</pre><pre>Google\Chrome SxS\User Data</pre><pre>Opera\Opera\wand.dat</pre><pre>Opera\Opera7\profile\wand.dat</pre><pre>Opera</pre><pre>@"%s"</pre><pre>Ashell32.dll</pre><pre>\nss3.dll</pre><pre>.save</pre><pre>vaultcli.dll</pre><pre>abe2869f-9b47-4cd9-a358-c22904dba7f7</pre><pre>Copy &Password</pre><pre>&HTML Report - All Items</pre><pre>HTML R&eport - Selected Items</pre><pre>HTML Report - All Items</pre><pre>HTML Report - Selected Items</pre><pre>Load Passwords From...</pre><pre>Google Chrome</pre><pre>Mozilla Firefox</pre><pre>SeaMonkey</pre><pre>Firefox Options</pre><pre>Master password:</pre><pre>Firefox Profile:</pre><pre>Firefox Installation:</pre><pre>Chrome Options</pre><pre>Opera Options</pre><pre>wand.dat file:</pre><pre>%d Passwords</pre><pre>, %d Selected</pre><pre>Web Browser Passwords%Choose another Firefox profile folder)Choose the installation folder of Firefox,Choose another profile of Chrome Web browser,Choose the password file of Opera (wand.dat)</pre><pre>Loading... %d</pre><pre>KeePass csv file</pre><pre>Opera Password File</pre><pre>Firefox 1.x</pre><pre>Firefox 2.x</pre><pre>Firefox 3.0</pre><pre>Firefox</pre><pre>Chrome</pre><pre>Web Browser</pre><pre>Password</pre><pre>Password Strength</pre><pre>Password Field</pre><pre>WebBrowserPassView.exe</pre><pre>www.google.com/Please log in to your Gmail account</pre><pre>www.google.com:443/Please log in to your Gmail account</pre><pre>www.google.com/Please log in to your Google Account</pre><pre>www.google.com:443/Please log in to your Google Account</pre><pre>www.google.com</pre><pre>dWindowsLive:name=*</pre><pre>82BD0E67-9FEA-4748-8672-D5EFE5B779B0</pre><pre>Copy Password</pre><pre>%d items</pre><pre>Select Eudora.ini filename/Select the location of Thunderbird installation</pre><pre>Eudora.ini file</pre><pre>SMTP</pre><pre>Windows Mail</pre><pre>Windows Live Mail</pre><pre>Server Port</pre><pre>SMTP Server Port</pre><pre>Mail Password Recovery</pre><pre>mailpv.exe</pre><pre>3, 7 #,)</pre><pre>MessageBoxIcon.Error</pre><pre>noftp</pre><pre>filename.exe</pre><pre>http://www.example.com/directory/file.exe</pre><pre>Disablecmd</pre><pre>\Windows Update.exe</pre><pre>\WindowsUpdate.exe</pre><pre>SysInfo.txt</pre><pre>\pid.txt</pre><pre>\pidloc.txt</pre><pre>\Mozilla\Firefox\Profiles</pre><pre>127.0.0.1</pre><pre>ping -n 1 -w 3000 1.1.1.1</pre><pre>cmd.exe</pre><pre>\SteamAppData.vdf</pre><pre>\ClientRegistry.blob</pre><pre>MessageBoxIcon.Exclamation</pre><pre>Keylogger Enabled:</pre><pre>Operating System:</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced</pre><pre>autorun.inf</pre><pre>open=Sys.exe</pre><pre>Sys.exe</pre><pre>Software\Microsoft\Windows\CurrentVersion\Run</pre><pre>Windows Update</pre><pre>C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>\bitcoin\wallet.dat</pre><pre>_wallet.dat</pre><pre>wallet.dat</pre><pre>Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>holdermail.txt"</pre><pre>holdermail.txt</pre><pre>Operating System Intel Recovery</pre><pre>Operating System Platform:</pre><pre>Operating System Version:</pre><pre>WEB Browser Password Recovery</pre><pre>Mail Messenger Password Recovery</pre><pre>Jdownloader Password Recovery</pre><pre>holderwb.txt"</pre><pre>holderwb.txt</pre><pre>C:\Users\</pre><pre>_Pin0.jpeg</pre><pre>_Pin1.jpeg</pre><pre>_Pin2.jpeg</pre><pre>_Pin3.jpeg</pre><pre>_Pin4.jpeg</pre><pre>Steals the Wallet.DAT file that holds the users bitcoin currency</pre><pre>\.minecraft\lastlogin</pre><pre>There is a file attached to this email containing Minecraft username and password download it then decrypt the login information with my Minecraft Decryptor</pre><pre>Predator Pain v14 - Key Recorder - [</pre><pre>Keylogger Log</pre><pre>.jpeg</pre><pre>Predator_Pain_v14_KeyLog_</pre><pre>http://whatismyipaddress.com/</pre><pre>Debugger.Resources</pre><pre>:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe</pre><pre>6.3.9600.16384 (winblue_rtm.130821-1623)</pre><pre>xpsrchvw.exe</pre><pre>Windows</pre><pre>Operating System</pre><pre>6.3.9600.16384</pre><b>xpsrchvw.exe_1188_rwx_675A6000_00003000:</b><pre>.Qg<-Qg><pre>*Rg`.Rg|)RgL Rg</pre></-Qg></pre></pre></pre></RPSSh>