HEUR:Worm.Script.Generic (Kaspersky), Trojan.Ciusky.Gen.12 (AdAware), Installer.Win32.InnoSetup.FD, Trojan.MSIL.Bladabindi.2.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, Trojan.Win32.Swrort.3.FD, VirTool.Win32.DelfInject.FD, Worm.Win32.AutoIt.FD, WormAutoItGen.YR (Lavasoft MAS)Behaviour: Trojan, Worm, Installer, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: b18b3112826835cc6b5bf05a545bc349
SHA1: f105d474b7f00419133083b96a44c0c29e53c15a
SHA256: 6e81fce8ea208b28c0aa19853880612e437d258657b32b5b68934256d8e6f861
SSDeep: 393216:ooEEhdxzKQI M2IPq5TYlkpIgciatJ7/Ky2k0CrjYWoB4UiCelHD3hL8p64lc:oopkQvIPyY wbCXCUNiColoe
Size: 19577477 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: AirInstaller
Created at: 2012-06-09 16:19:49
Analyzed on: WindowsXP SP3 32-bit
Summary: Worm. A program that is primarily replicating on networks or removable drives.
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Worm creates the following process(es):
PNLYA.exe:1244
PNLYA.exe:1900
%original file name%.exe:396
WScript.exe:1932
bitpro.exe:972
The Worm injects its code into the following process(es):
bitpro.tmp:1936
File activity
The process PNLYA.exe:1900 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\KFCUE\SQYLE (173 bytes)
The process %original file name%.exe:396 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\KFCUE\BCREM (237 bytes)
%Documents and Settings%\%current user%\KFCUE\4f97A63.vbe (7972 bytes)
%Documents and Settings%\%current user%\KFCUE\DBIYS (69539 bytes)
%Documents and Settings%\%current user%\KFCUE\YMQGIX (21 bytes)
%Documents and Settings%\%current user%\KFCUE\bitpro.exe (70955 bytes)
%Documents and Settings%\%current user%\KFCUE\RDYUC (236 bytes)
The Worm deletes the following file(s):
%Documents and Settings%\%current user%\KFCUE\__tmp_rar_sfx_access_check_834562 (0 bytes)
The process WScript.exe:1932 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\KFCUE\PNLYA.exe (186354 bytes)
The process bitpro.exe:972 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-6JGI0.tmp\bitpro.tmp (7386 bytes)
The process bitpro.tmp:1936 makes changes in the file system.
The Worm creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-U2VND.tmp\_isetup\_shfoldr.dll (23 bytes)
Registry activity
The process PNLYA.exe:1244 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"GlobalUserOffline" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AF C7 83 B7 08 94 3D CF 86 05 05 AF 28 82 0B 8B"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Worm adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ERRWQ" = "%Documents and Settings%\%current user%\KFCUE\4f97A63.vbe"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process PNLYA.exe:1900 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "04 7C 35 EB 84 26 D8 66 6B 0B 98 11 04 F6 AA 17"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process %original file name%.exe:396 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "76 95 A0 61 EF 3D 66 A4 FB 5F 72 D6 39 34 D9 43"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"wscript.exe" = "Microsoft (R) Windows Based Script Host"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Documents and Settings%\%current user%\KFCUE]
"bitpro.exe" = "BurnInTest Setup"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process WScript.exe:1932 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E1 C5 87 86 CC 5F DC 72 E6 CD 2C F7 8E 9F 75 8D"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\KFCUE]
"PNLYA.exe" = "AutoIt v3 Script"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Worm modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Worm modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Worm modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process bitpro.exe:972 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DB EA BE 5E 79 0A 6D 09 20 C9 78 B3 AC 56 38 3D"
The process bitpro.tmp:1936 makes changes in the system registry.
The Worm creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "29 89 F2 3A 90 9D A2 57 10 8D 00 3C BF F7 5F 26"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
Dropped PE files
MD5 | File path |
---|---|
71d8f6d5dc35517275bc38ebcc815f9f | c:\Documents and Settings\"%CurrentUserName%"\KFCUE\PNLYA.exe |
7ce3ab09e02ff77497ac63b5dcc1ec13 | c:\Documents and Settings\"%CurrentUserName%"\KFCUE\bitpro.exe |
930ff1ab4309e7c3c43205feade66eb1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-6JGI0.tmp\bitpro.tmp |
92dc6ef532fbb4a5c3201469a5b5eb63 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\is-U2VND.tmp\_isetup\_shfoldr.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
PNLYA.exe:1244
PNLYA.exe:1900
%original file name%.exe:396
WScript.exe:1932
bitpro.exe:972 - Delete the original Worm file.
- Delete or disinfect the following files created/modified by the Worm:
%Documents and Settings%\%current user%\KFCUE\SQYLE (173 bytes)
%Documents and Settings%\%current user%\KFCUE\BCREM (237 bytes)
%Documents and Settings%\%current user%\KFCUE\4f97A63.vbe (7972 bytes)
%Documents and Settings%\%current user%\KFCUE\DBIYS (69539 bytes)
%Documents and Settings%\%current user%\KFCUE\YMQGIX (21 bytes)
%Documents and Settings%\%current user%\KFCUE\bitpro.exe (70955 bytes)
%Documents and Settings%\%current user%\KFCUE\RDYUC (236 bytes)
%Documents and Settings%\%current user%\KFCUE\PNLYA.exe (186354 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-6JGI0.tmp\bitpro.tmp (7386 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-U2VND.tmp\_isetup\_shfoldr.dll (23 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ERRWQ" = "%Documents and Settings%\%current user%\KFCUE\4f97A63.vbe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Passmark Software
Product Name: BurnInTest
Product Version: 1,0,0,0
Legal Copyright: Copyright (c) 1999-2013 Passmark Software, Inc.
Legal Trademarks:
Original Filename:
Internal Name:
File Version:
File Description: BurnInTest Setup
Comments:
Language: English (United States)
Company Name: Passmark Software Product Name: BurnInTest Product Version: 1,0,0,0Legal Copyright: Copyright (c) 1999-2013 Passmark Software, Inc. Legal Trademarks: Original Filename: Internal Name: File Version: File Description: BurnInTest Setup Comments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 74526 | 74752 | 4.54396 | a8692f5ba740240ef0f9a827376f76f9 |
.rdata | 81920 | 7445 | 7680 | 3.46159 | d4f36accffde0bf520f52486679ccf0d |
.data | 90112 | 96036 | 512 | 2.46008 | b6c7edb5b7fec47a37a622cc5d71f3f4 |
.CRT | 188416 | 32 | 512 | 0.273198 | 439411041ee0b8261668525c5c132cd9 |
.rsrc | 192512 | 27136 | 27136 | 3.92322 | d416fa0fcd769d7ee9e63906e0f85e5c |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://actscentre.com/bookmarks/images/lib/airlines/UIMeter.exe | 100.42.55.220 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /bookmarks/images/lib/airlines/UIMeter.exe HTTP/1.1
User-Agent: AutoIt
Host: actscentre.com
HTTP/1.1 403 Forbidden
Date: Sun, 15 Jun 2014 03:39:11 GMT
Server: Apache/2.2.24 (Unix) mod_hive/3.6 mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 mod_qos/10.10 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.35
Content-Length: 362
Content-Type: text/html; charset=iso-8859-1
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access /bookmarks/images/lib/airlines/UIMeter.exe.on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>.HTTP/1.1 403 Forbidden..Date: Sun, 15 Jun 2014 03:39:11 GMT..Server: Apache/2.2.24 (Unix) mod_hive/3.6 mod_ssl/2.2.24 OpenSSL/0.9.8e-fips-rhel5 mod_qos/10.10 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 mod_jk/1.2.35..Content-Length: 362..Content-Type: text/html; charset=iso-8859-1..<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">.<html><head>.<title>403 Forbidden</title>.</head><body>.<h1>Forbidden</h1>.<p>You don't have permission to access /bookmarks/images/lib/airlines/UIMeter.exe.on this server.</p>.<p>Additionally, a 404 Not Found.error was encountered while trying to use an ErrorDocument to handle the request.</p>.</body></html>...
Map
The Worm connects to the servers at the folowing location(s):
Strings from Dumps
bitpro.exe_972:
.text
.text
`.itext
`.itext
`.data
`.data
.idata
.idata
.rdata
.rdata
@.rsrc
@.rsrc
ENoMonitorSupportException
ENoMonitorSupportException
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
EVariantBadIndexError
EVariantBadIndexError
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Setup Data (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
Inno Setup Messages (5.5.0) (u)
oleaut32.dll
oleaut32.dll
advapi32.dll
advapi32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
kernel32.dll
kernel32.dll
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
ExitWindowsEx
ExitWindowsEx
GetWindowsDirectoryW
GetWindowsDirectoryW
GetCPInfo
GetCPInfo
comctl32.dll
comctl32.dll
KWindows
KWindows
UrlMon
UrlMon
6MsgIDs
6MsgIDs
Msgs
Msgs
name="JR.Inno.Setup"
name="JR.Inno.Setup"
version="1.0.0.0"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<windowsSettings></windowsSettings>
<windowsSettings></windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
File I/O error %d
File I/O error %d
lzmadecompsmall: Compressed data is corrupted (%d)
lzmadecompsmall: Compressed data is corrupted (%d)
lzmadecompsmall: %s
lzmadecompsmall: %s
LzmaDecode failed (%d)
LzmaDecode failed (%d)
shell32.dll
shell32.dll
/SL5="$%x,%d,%d,
/SL5="$%x,%d,%d,
Invalid file name - %s
Invalid file name - %s
Wed(Monitor support function not initialized
Wed(Monitor support function not initialized
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Operation aborted(Exception %s in module %s at %p.
Operation aborted(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
I/O error %d
I/O error %d
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Passmark Software
Passmark Software
1999-2013 Passmark Software, Inc.
1999-2013 Passmark Software, Inc.
WScript.exe_1932:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
OLEAUT32.dll
OLEAUT32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
wscript.exe
wscript.exe
advapi32.dll
advapi32.dll
kernel32.dll
kernel32.dll
%s%s.DLL
%s%s.DLL
wintrust.dll
wintrust.dll
%d.%d
%d.%d
Invalid parameter passed to C runtime function.
Invalid parameter passed to C runtime function.
SOFTWARE\Classes\%s\%s
SOFTWARE\Classes\%s\%s
0x%8X
0x%8X
CreateURLMonikerEx
CreateURLMonikerEx
urlmon.dll
urlmon.dll
@@8X%u
@@8X%u
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
RegOpenKeyA
RegOpenKeyA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExW
RegCreateKeyExW
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExW
RegOpenKeyExW
ReportEventW
ReportEventW
RegEnumKeyExA
RegEnumKeyExA
RegOpenKeyExA
RegOpenKeyExA
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
EnumThreadWindows
EnumThreadWindows
wscript.pdb
wscript.pdb
stdole2.tlbWWW
stdole2.tlbWWW
.ObjectWW
.ObjectWW
KeyW
KeyW
WindowsFolderWWW4
WindowsFolderWWW4
%CopyFolderWWL
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Application InterfaceW%
Windows Script Host Object
Windows Script Host Object
ebstrCmdLineW
ebstrCmdLineW
7Â8t8x8
7Â8t8x8
5Q5F5
5Q5F5
Software\Microsoft\Windows Script Host\Settings
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
Windows Script Host
WScript.CreateObject
WScript.CreateObject
WSHRemote.Execute
WSHRemote.Execute
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s.mui
.\%s\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s\%s.mui
%s\%s
%s\%s
Microsoft (R) Windows Based Script Host
Microsoft (R) Windows Based Script Host
5.7.0.16599
5.7.0.16599
Microsoft (R) Windows Script Host
Microsoft (R) Windows Script Host
(Windows Script Host (debugging disabled)
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Error
Windows Script Host Input Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
Please use the ANSI version of Windows Script Host."
WScript execution time was exceeded on script "%1!ls!".
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled><pre>Missing job name.*Unicode is not supported on this platform.</pre><pre><The Windows Script Host settings have been reset to default><pre>Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.</pre><pre>Win32 Error 0x%X</pre><pre>Windows Script Host(Windows Script Host (debugging disabled)</pre><pre>Usage: WScript scriptname.extension [option...] [arguments...]</pre><pre>Use engine for executing script</pre><pre>Changes the default script host to CScript.exe</pre><pre>Changes the default script host to WScript.exe (default)</pre><pre>Prevent logo display: No banner will be shown at execution time</pre><pre>#WScript Error - Windows Script Host!Input Error - Windows Script HostlThis Unicode version of WScript will only execute under Windows NT.</pre><pre>%6!ls! WScript - Script Execution Error!Windows Script Host Remote Script/Remote script object can only be executed once. Unable to execute remote script.</pre><b>bitpro.tmp_1936:</b><pre>.text</pre><pre>`.itext</pre><pre>`.data</pre><pre>.idata</pre><pre>.rdata</pre><pre>@.rsrc</pre><pre>Windows</pre><pre>ENoMonitorSupportException</pre><pre>.uvCOu</pre><pre>$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)</pre><pre>EVariantBadIndexError</pre><pre>ssShift</pre><pre>htKeyword</pre><pre>EInvalidOperation</pre><pre>Uh.pB</pre><pre>EInvalidGraphicOperation</pre><pre>Uhf%C</pre><pre>PasswordChar</pre><pre>OnKeyDown</pre><pre>OnKeyPress</pre><pre>OnKeyUp</pre><pre>ssHorizontal</pre><pre>TCustomButton.TButtonStyle</pre><pre>AutoHotkeys</pre><pre>TKeyEvent</pre><pre>TKeyPressEvent</pre><pre>HelpKeyword</pre><pre>ssHotTrack</pre><pre>TWindowState</pre><pre>poProportional</pre><pre>TWMKey</pre><pre>KeyPreviewPJE</pre><pre>WindowState</pre><pre>EXPORT</pre><pre>TPSExec</pre><pre>TPSRuntimeClassImporterP;P</pre><pre>TPSExportedVar</pre><pre>TPSCustomDebugExec</pre><pre>TPSDebugExec</pre><pre>t.Htb</pre><pre>1.2.1</pre><pre>TPasswordEdit</pre><pre>TPasswordEdit,</pre><pre>PasswordEdit(</pre><pre>Password</pre><pre>PasswordPage</pre><pre>PasswordLabel</pre><pre>PasswordEdit</pre><pre>PasswordEditLabel</pre><pre>CheckPassword</pre><pre><requestedExecutionLevel level="</pre><pre>IMsg</pre><pre>FormKeyDown</pre><pre>PasswordCheckHash</pre><pre>TKeyNameConst</pre><pre>TOutputMsgWizardPage</pre><pre>TOutputMsgWizardPage|>N</pre><pre>TOutputMsgMemoWizardPage</pre><pre>TOutputMsgMemoWizardPage`?N</pre><pre>MsgLabel</pre><pre>Msg1Label</pre><pre>Msg2Label</pre><pre>function CreateOutputMsgPage(const AfterID: Integer; const ACaption, ADescription, AMsg: String): TOutputMsgWizardPage;</pre><pre>function CreateOutputMsgMemoPage(const AfterID: Integer; const ACaption, ADescription, ASubCaption: String; const AMsg: AnsiString): TOutputMsgMemoWizardPage;</pre><pre>function MsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons: Integer): Integer;</pre><pre>function GetIniString(const Section, Key, Default, Filename: String): String;</pre><pre>function GetIniInt(const Section, Key: String; const Default, Min, Max: Longint; const Filename: String): Longint;</pre><pre>function GetIniBool(const Section, Key: String; const Default: Boolean; const Filename: String): Boolean;</pre><pre>function IniKeyExists(const Section, Key, Filename: String): Boolean;</pre><pre>function SetIniString(const Section, Key, Value, Filename: String): Boolean;</pre><pre>function SetIniInt(const Section, Key: String; const Value: Longint; const Filename: String): Boolean;</pre><pre>function SetIniBool(const Section, Key: String; const Value: Boolean; const Filename: String): Boolean;</pre><pre>procedure DeleteIniEntry(const Section, Key, Filename: String);</pre><pre>function GetCmdTail: String;</pre><pre>function StringChangeEx(var S: String; const FromStr, ToStr: String; const SupportDBCS: Boolean): Integer;</pre><pre>function RegValueExists(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;</pre><pre>function RegQueryStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;</pre><pre>function RegQueryMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: String): Boolean;</pre><pre>function RegDeleteKeyIncludingSubkeys(const RootKey: Integer; const SubkeyName: String): Boolean;</pre><pre>function RegDeleteKeyIfEmpty(const RootKey: Integer; const SubkeyName: String): Boolean;</pre><pre>function RegKeyExists(const RootKey: Integer; const SubKeyName: String): Boolean;</pre><pre>function RegDeleteValue(const RootKey: Integer; const SubKeyName, ValueName: String): Boolean;</pre><pre>function RegGetSubkeyNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;</pre><pre>function RegGetValueNames(const RootKey: Integer; const SubKeyName: String; var Names: TArrayOfString): Boolean;</pre><pre>function RegQueryDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultDWord: Cardinal): Boolean;</pre><pre>function RegQueryBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; var ResultStr: AnsiString): Boolean;</pre><pre>function RegWriteStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;</pre><pre>function RegWriteExpandStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;</pre><pre>function RegWriteMultiStringValue(const RootKey: Integer; const SubKeyName, ValueName, Data: String): Boolean;</pre><pre>function RegWriteDWordValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: Cardinal): Boolean;</pre><pre>function RegWriteBinaryValue(const RootKey: Integer; const SubKeyName, ValueName: String; const Data: AnsiString): Boolean;</pre><pre>function CheckForMutexes(Mutexes: String): Boolean;</pre><pre>function Exec(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;</pre><pre>function ExecAsOriginalUser(const Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ResultCode: Integer): Boolean;</pre><pre>function ShellExec(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;</pre><pre>function ShellExecAsOriginalUser(const Verb, Filename, Params, WorkingDir: String; const ShowCmd: Integer; const Wait: TExecWait; var ErrorCode: Integer): Boolean;</pre><pre>function MakePendingFileRenameOperationsChecksum: String;</pre><pre>function CreateShellLink(const Filename, Description, ShortcutTo, Parameters, WorkingDir, IconFilename: String; const IconIndex, ShowCmd: Integer): String;</pre><pre>function ExitSetupMsgBox: Boolean;</pre><pre>function GetWindowsVersion: Cardinal;</pre><pre>procedure GetWindowsVersionEx(var Version: TWindowsVersion);</pre><pre>function GetWindowsVersionString: String;</pre><pre>function SuppressibleMsgBox(const Text: String; const Typ: TMsgBoxType; const Buttons, Default: Integer): Integer;</pre><pre>function CustomMessage(const MsgName: String): String;</pre><pre>function SendMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Longint;</pre><pre>function PostMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;</pre><pre>function SendNotifyMessage(const Wnd: HWND; const Msg, WParam, LParam: Longint): Boolean;</pre><pre>function SendBroadcastMessage(const Msg, WParam, LParam: Longint): Longint;</pre><pre>function PostBroadcastMessage(const Msg, WParam, LParam: Longint): Boolean;</pre><pre>function SendBroadcastNotifyMessage(const Msg, WParam, LParam: Longint): Boolean;</pre><pre>procedure RaiseException(const Msg: String);</pre><pre>function SetPreviousData(const PreviousDataKey: Integer; const ValueName, ValueData: String): Boolean;</pre><pre>CREATEOUTPUTMSGPAGE</pre><pre>CREATEOUTPUTMSGMEMOPAGE</pre><pre>MSGBOX</pre><pre>INIKEYEXISTS</pre><pre>GETCMDTAIL</pre><pre>REGKEYEXISTS</pre><pre>REGDELETEKEYINCLUDINGSUBKEYS</pre><pre>REGDELETEKEYIFEMPTY</pre><pre>REGGETSUBKEYNAMES</pre><pre>CHECKFORMUTEXES</pre><pre>SHELLEXEC</pre><pre>SHELLEXECASORIGINALUSER</pre><pre>MAKEPENDINGFILERENAMEOPERATIONSCHECKSUM</pre><pre>EXITSETUPMSGBOX</pre><pre>GETWINDOWSVERSION</pre><pre>GETWINDOWSVERSIONSTRING</pre><pre>SUPPRESSIBLEMSGBOX</pre><pre>GetWindowsVersionEx</pre><pre>IMsgt</pre><pre>Inno Setup Setup Data (5.5.0) (u)</pre><pre>Inno Setup Messages (5.5.0) (u)</pre><pre>oleaut32.dll</pre><pre>advapi32.dll</pre><pre>RegOpenKeyExW</pre><pre>RegCloseKey</pre><pre>user32.dll</pre><pre>GetKeyboardType</pre><pre>kernel32.dll</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookExW</pre><pre>MsgWaitForMultipleObjectsEx</pre><pre>MsgWaitForMultipleObjects</pre><pre>MapVirtualKeyW</pre><pre>LoadKeyboardLayoutW</pre><pre>GetKeyboardState</pre><pre>GetKeyboardLayoutNameW</pre><pre>GetKeyboardLayoutList</pre><pre>GetKeyboardLayout</pre><pre>GetKeyState</pre><pre>GetKeyNameTextW</pre><pre>ExitWindowsEx</pre><pre>EnumWindows</pre><pre>EnumThreadWindows</pre><pre>EnumChildWindows</pre><pre>ActivateKeyboardLayout</pre><pre>msimg32.dll</pre><pre>gdi32.dll</pre><pre>SetViewportOrgEx</pre><pre>version.dll</pre><pre>mpr.dll</pre><pre>TransactNamedPipe</pre><pre>SetNamedPipeHandleState</pre><pre>GetWindowsDirectoryW</pre><pre>GetCPInfo</pre><pre>CreateNamedPipeW</pre><pre>RegQueryInfoKeyW</pre><pre>RegFlushKey</pre><pre>RegEnumKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCreateKeyExW</pre><pre>ole32.dll</pre><pre>comctl32.dll</pre><pre>shell32.dll</pre><pre>ShellExecuteExW</pre><pre>ShellExecuteW</pre><pre>comdlg32.dll</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.pdata</pre><pre>COMCTL32.dll</pre><pre>SHLWAPI.dll</pre><pre>SetProcessShutdownParameters</pre><pre>KERNEL32.dll</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>OLEAUT32.dll</pre><pre>name=" Microsoft><pre>version="6.0.0.0"</pre><pre>publicKeyToken="6595b64144ccf1df"</pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false" /></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" /></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" /></pre><pre>KWindows</pre><pre>UrlMon</pre><pre>6MsgIDs</pre><pre>Msgs</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</pre><pre>shlwapi.dll</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>Software\Microsoft\Windows\CurrentVersion\ProfileReconciliation</pre><pre>RegKey</pre><pre>GetWindowsDirectoryA</pre><pre>RegOpenKeyA</pre><pre>RegCreateKeyExA</pre><pre>SHFOLDER.dll</pre><pre>dll\shfolder.dbg</pre><pre>Font.Color</pre><pre>Font.Height</pre><pre>Font.Name</pre><pre>Font.Style</pre><pre>Lines.Strings</pre><pre>name="JR.Inno.Setup"</pre><pre>version="1.0.0.0"</pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false" /></pre><pre><windowsSettings></windowsSettings></pre><pre><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware></pre><pre></pre><pre>MSWHEEL_ROLLMSG</pre><pre>MSH_WHEELSUPPORT_MSG</pre><pre>MSH_SCROLL_LINES_MSG</pre><pre>%s_%d</pre><pre>USER32.DLL</pre><pre>SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes</pre><pre>uxtheme.dll</pre><pre>DWMAPI.DLL</pre><pre>clWebSnow</pre><pre>clWebFloralWhite</pre><pre>clWebLavenderBlush</pre><pre>clWebOldLace</pre><pre>clWebIvory</pre><pre>clWebCornSilk</pre><pre>clWebBeige</pre><pre>clWebAntiqueWhite</pre><pre>clWebWheat</pre><pre>clWebAliceBlue</pre><pre>clWebGhostWhite</pre><pre>clWebLavender</pre><pre>clWebSeashell</pre><pre>clWebLightYellow</pre><pre>clWebPapayaWhip</pre><pre>clWebNavajoWhite</pre><pre>clWebMoccasin</pre><pre>clWebBurlywood</pre><pre>clWebAzure</pre><pre>clWebMintcream</pre><pre>clWebHoneydew</pre><pre>clWebLinen</pre><pre>clWebLemonChiffon</pre><pre>clWebBlanchedAlmond</pre><pre>clWebBisque</pre><pre>clWebPeachPuff</pre><pre>clWebTan</pre><pre>clWebYellow</pre><pre>clWebDarkOrange</pre><pre>clWebRed</pre><pre>clWebDarkRed</pre><pre>clWebMaroon</pre><pre>clWebIndianRed</pre><pre>clWebSalmon</pre><pre>clWebCoral</pre><pre>clWebGold</pre><pre>clWebTomato</pre><pre>clWebCrimson</pre><pre>clWebBrown</pre><pre>clWebChocolate</pre><pre>clWebSandyBrown</pre><pre>clWebLightSalmon</pre><pre>clWebLightCoral</pre><pre>clWebOrange</pre><pre>clWebOrangeRed</pre><pre>clWebFirebrick</pre><pre>clWebSaddleBrown</pre><pre>clWebSienna</pre><pre>clWebPeru</pre><pre>clWebDarkSalmon</pre><pre>clWebRosyBrown</pre><pre>clWebPaleGoldenrod</pre><pre>clWebLightGoldenrodYellow</pre><pre>clWebOlive</pre><pre>clWebForestGreen</pre><pre>clWebGreenYellow</pre><pre>clWebChartreuse</pre><pre>clWebLightGreen</pre><pre>clWebAquamarine</pre><pre>clWebSeaGreen</pre><pre>clWebGoldenRod</pre><pre>clWebKhaki</pre><pre>clWebOliveDrab</pre><pre>clWebGreen</pre><pre>clWebYellowGreen</pre><pre>clWebLawnGreen</pre><pre>clWebPaleGreen</pre><pre>clWebMediumAquamarine</pre><pre>clWebMediumSeaGreen</pre><pre>clWebDarkGoldenRod</pre><pre>clWebDarkKhaki</pre><pre>clWebDarkOliveGreen</pre><pre>clWebDarkgreen</pre><pre>clWebLimeGreen</pre><pre>clWebLime</pre><pre>clWebSpringGreen</pre><pre>clWebMediumSpringGreen</pre><pre>clWebDarkSeaGreen</pre><pre>clWebLightSeaGreen</pre><pre>clWebPaleTurquoise</pre><pre>clWebLightCyan</pre><pre>clWebLightBlue</pre><pre>clWebLightSkyBlue</pre><pre>clWebCornFlowerBlue</pre><pre>clWebDarkBlue</pre><pre>clWebIndigo</pre><pre>clWebMediumTurquoise</pre><pre>clWebTurquoise</pre><pre>clWebCyan</pre><pre>clWebPowderBlue</pre><pre>clWebSkyBlue</pre><pre>clWebRoyalBlue</pre><pre>clWebMediumBlue</pre><pre>clWebMidnightBlue</pre><pre>clWebDarkTurquoise</pre><pre>clWebCadetBlue</pre><pre>clWebDarkCyan</pre><pre>clWebTeal</pre><pre>clWebDeepskyBlue</pre><pre>clWebDodgerBlue</pre><pre>clWebBlue</pre><pre>clWebNavy</pre><pre>clWebDarkViolet</pre><pre>clWebDarkOrchid</pre><pre>clWebMagenta</pre><pre>clWebDarkMagenta</pre><pre>clWebMediumVioletRed</pre><pre>clWebPaleVioletRed</pre><pre>clWebBlueViolet</pre><pre>clWebMediumOrchid</pre><pre>clWebMediumPurple</pre><pre>clWebPurple</pre><pre>clWebDeepPink</pre><pre>clWebLightPink</pre><pre>clWebViolet</pre><pre>clWebOrchid</pre><pre>clWebPlum</pre><pre>clWebThistle</pre><pre>clWebHotPink</pre><pre>clWebPink</pre><pre>clWebLightSteelBlue</pre><pre>clWebMediumSlateBlue</pre><pre>clWebLightSlateGray</pre><pre>clWebWhite</pre><pre>clWebLightgrey</pre><pre>clWebGray</pre><pre>clWebSteelBlue</pre><pre>clWebSlateBlue</pre><pre>clWebSlateGray</pre><pre>clWebWhiteSmoke</pre><pre>clWebSilver</pre><pre>clWebDimGray</pre><pre>clWebMistyRose</pre><pre>clWebDarkSlateBlue</pre><pre>clWebDarkSlategray</pre><pre>clWebGainsboro</pre><pre>clWebDarkGray</pre><pre>clWebBlack</pre><pre>\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\</pre><pre>crSQLWait</pre><pre>%s (%s)</pre><pre>imm32.dll</pre><pre>System\CurrentControlSet\Control\Keyboard Layouts\%.8x</pre><pre>RegDeleteKeyExW</pre><pre>.DEFAULT\Control Panel\International</pre><pre>%s, ClassID: %s</pre><pre>%s, ProgID: "%s"</pre><pre>oleacc.dll</pre><pre>MSFTEDIT.DLL</pre><pre>RICHED20.DLL</pre><pre>Rstrtmgr.dll</pre><pre>File I/O error %d</pre><pre>Messages file "%s" is missing. Please correct the problem or obtain a new copy of the program.</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_USERS</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>HKEY_DYN_DATA</pre><pre>WININIT.INI</pre><pre>Software\Microsoft\Windows\CurrentVersion\SharedDLLs</pre><pre>RegCreateKeyEx</pre><pre>RegOpenKeyEx</pre><pre>sfc.dll</pre><pre>cmd.exe" /C "</pre><pre>COMMAND.COM" /C</pre><pre>PendingFileRenameOperations</pre><pre>PendingFileRenameOperations2</pre><pre>@Software\Microsoft\Windows\CurrentVersion\Fonts</pre><pre>Software\Microsoft\Windows NT\CurrentVersion\Fonts</pre><pre>IPropertyStore::SetValue(PKEY_AppUserModel_PreventPinning)</pre><pre>IPropertyStore::SetValue(PKEY_AppUserModel_ID)</pre><pre>IPropertyStore::SetValue(PKEY_AppUserModel_ExcludeFromShowInNewInstall)</pre><pre>OLEAUT32.DLL</pre><pre>Log opened. (Time zone: UTC%s%.2u:%.2u)</pre><pre>%s Log %s #%.3u.txt</pre><pre>regsvr32.exe"</pre><pre>Cannot register 64-bit DLLs on this version of Windows</pre><pre>HELPER_EXE_AMD64</pre><pre>Cannot utilize 64-bit features on this version of Windows</pre><pre>64-bit helper EXE wasn't extracted</pre><pre>\\.\pipe\InnoSetup64BitHelper-%.8x-%.8x-%.8x-%.8x%.8x</pre><pre>CreateNamedPipe</pre><pre>helper %d 0x%x</pre><pre>Helper process PID: %u</pre><pre>Stopping 64-bit helper process. (PID: %u)</pre><pre>Helper process exited with failure code: 0x%x</pre><pre>TransactNamedPipe/GetOverlappedResult</pre><pre>Helper: Command did not execute</pre><pre>SOFTWARE\Microsoft\.NETFramework</pre><pre>.NET Framework not found</pre><pre>SOFTWARE\Microsoft\.NETFramework\Policy\v4.0</pre><pre>v4.0.30319</pre><pre>SOFTWARE\Microsoft\.NETFramework\Policy\v2.0</pre><pre>v2.0.50727</pre><pre>SOFTWARE\Microsoft\.NETFramework\Policy\v1.1</pre><pre>v1.1.4322</pre><pre>.NET Framework version %s not found</pre><pre>Fusion.dll</pre><pre>Failed to load .NET Framework DLL "%s"</pre><pre>Failed to get address of .NET Framework CreateAssemblyCache function</pre><pre>.NET Framework CreateAssemblyCache function failed</pre><pre>MoveFileEx failed (%d).</pre><pre>Deleting directory: %s</pre><pre>Failed to delete directory (%d). Will retry later.</pre><pre>Failed to delete directory (%d). Will delete on restart (if empty).</pre><pre>Failed to delete directory (%d).</pre><pre>Deleting file: %s</pre><pre>Failed to delete the file; it may be in use (%d).</pre><pre>The file appears to be in use (%d). Will delete on restart.</pre><pre>Decrementing shared count (%d-bit): %s</pre><pre>Unregistering 64-bit DLL/OCX: %s</pre><pre>Unregistering 32-bit DLL/OCX: %s</pre><pre>Not unregistering DLL/OCX again: %s</pre><pre>Unregistering 64-bit type library: %s</pre><pre>Unregistering 32-bit type library: %s</pre><pre>Uninstalling from GAC: %s</pre><pre>Running Exec filename:</pre><pre>Running Exec parameters:</pre><pre>CreateProcess failed (%d).</pre><pre>Process exit code: %u</pre><pre>Running ShellExec filename:</pre><pre>Running ShellExec parameters:</pre><pre>ShellExecuteEx failed (%d).</pre><pre>Skipping RunOnceId "%s" filename: %s</pre><pre>Unregistering font: %s</pre><pre>zlib: Internal error. Code %d</pre><pre>bzlib: Internal error. Code %d</pre><pre>lzmadecomp: %s</pre><pre>lzmadecomp: Compressed data is corrupted (%d)</pre><pre>DecodeToBuf failed (%d)</pre><pre>c:\directory</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced</pre><pre>Could not find page with ID %d</pre><pre>Software\Microsoft\Windows\CurrentVersion\Uninstall</pre><pre>%s\%s_is1</pre><pre>RestartManager found an application using one of our files: %s</pre><pre>Can use RestartManager to avoid reboot? %s (%d)</pre><pre>PrepareToInstall failed: %s</pre><pre>Need to restart Windows? %s</pre><pre>/:*?"<>|</pre><pre>\/:*?"<>|</pre><pre>%s-%d.bin</pre><pre>%s-%d%s.bin</pre><pre>..\DISK%d\</pre><pre>Asking user for new disk containing "%s".</pre><pre>Cannot read an encrypted file before the key has been set</pre><pre>LoggedMsgBox returned an unexpected value. Assuming Abort.</pre><pre>Software\Microsoft\Windows\CurrentVersion\Fonts</pre><pre>Software\Microsoft\Windows\CurrentVersion\Uninstall\</pre><pre>5.5.1 (u)</pre><pre>URLInfoAbout</pre><pre>URLUpdateInfo</pre><pre>Creating directory: %s</pre><pre>Setting permissions on directory: %s</pre><pre>Failed to set permissions on directory (%d).</pre><pre>Setting NTFS compression on directory: %s</pre><pre>Unsetting NTFS compression on directory: %s</pre><pre>Failed to set NTFS compression state (%d).</pre><pre>Failed to set value in Fonts registry key.</pre><pre>Failed to open Fonts registry key.</pre><pre>Setting permissions on file: %s</pre><pre>Failed to set permissions on file (%d).</pre><pre>Setting NTFS compression on file: %s</pre><pre>Unsetting NTFS compression on file: %s</pre><pre>Dest filename: %s</pre><pre>Dest file is protected by Windows File Protection.</pre><pre>Time stamp of our file: %s</pre><pre>Time stamp of existing file: %s</pre><pre>Version of our file: %u.%u.%u.%u</pre><pre>Version of existing file: %u.%u.%u.%u</pre><pre>Existing file is protected by Windows File Protection. Skipping.</pre><pre>Uninstaller requires administrator: %s</pre><pre>The existing file appears to be in use (%d). Will replace on restart.</pre><pre>The existing file appears to be in use (%d). Retrying.</pre><pre>Registering file as a font ("%s")</pre><pre>Cannot install files to 64-bit locations on this version of Windows</pre><pre>desktop.ini</pre><pre>.ShellClassInfo</pre><pre>{0AFACED1-E828-11D1-9187-B532F1E9575D}</pre><pre>target.lnk</pre><pre>Filename: %s</pre><pre>Desktop.ini</pre><pre>Software\Microsoft\Windows\CurrentVersion\App Paths\</pre><pre>Setting permissions on registry key: %s\%s</pre><pre>Could not set permissions on the registry key because it currently does not exist.</pre><pre>Failed to set permissions on registry key (%d).</pre><pre>Cannot access 64-bit registry keys on this version of Windows</pre><pre>Registration executable created: %s</pre><pre>Software\Microsoft\Windows\CurrentVersion\RunOnce</pre><pre>Registering 64-bit DLL/OCX: %s</pre><pre>Registering 32-bit DLL/OCX: %s</pre><pre>Registering 64-bit type library: %s</pre><pre>Registering 32-bit type library: %s</pre><pre>Directory for uninstall files: %s</pre><pre>Will append to existing uninstall log: %s</pre><pre>Will overwrite existing uninstall log: %s</pre><pre>Creating new uninstall log: %s</pre><pre>LoggedMsgBox returned an unexpected value. Assuming Cancel.</pre><pre>RmShutdown returned an error: %d</pre><pre>Fatal exception during installation process (%s):</pre><pre>ExtractTemporaryFile: The file "%s" was not found</pre><pre>Invalid symbol '%s' found</pre><pre>Invalid token '%s' found</pre><pre>QuerySpawnServer: Unexpected response: $%x</pre><pre>CallSpawnServer: Unexpected response: $%x</pre><pre>CallSpawnServer: Unexpected status: %d</pre><pre>ShellExecuteEx</pre><pre>ShellExecuteEx returned hProcess=0</pre><pre>Wnd=$%x</pre><pre>Expression error '%s'</pre><pre>srcexe</pre><pre>Cannot evaluate "%s" constant during Uninstall</pre><pre>Cannot access a 64-bit key in a "reg" constant on this version of Windows</pre><pre>Unknown custom message name "%s" in "cm" constant</pre><pre>Cannot expand "pf64" constant on this version of Windows</pre><pre>Cannot expand "cf64" constant on this version of Windows</pre><pre>uninstallexe</pre><pre>Cannot expand "dotnet2064" constant on this version of Windows</pre><pre>Cannot expand "dotnet4064" constant on this version of Windows</pre><pre>Failed to expand shell folder constant "%s"</pre><pre>Unknown constant "%s"</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>SOFTWARE\Microsoft\Windows NT\CurrentVersion</pre><pre>cmd.exe</pre><pre>COMMAND.COM</pre><pre>\_setup64.tmp</pre><pre>_isetup\_shfoldr.dll</pre><pre>Failed to get version numbers of _shfoldr.dll</pre><pre>shfolder.dll</pre><pre>Failed to load DLL "%s"</pre><pre>Found pending rename or delete that matches one of our files: %s</pre><pre>Windows version: %u.%u.%u%s (NT platform: %s)</pre><pre>64-bit Windows: %s</pre><pre>Processor architecture: %s</pre><pre>Defaulting to %s for suppressed message box (%s):</pre><pre>Message box (%s):</pre><pre>User chose %s.</pre><pre>MsgBox failed.</pre><pre>/SPAWNWND=$%x /NOTIFYWND=$%x</pre><pre>64-bit install mode: %s</pre><pre>_isetup\_isdecmp.dll</pre><pre>_isetup\_iscrypt.dll</pre><pre>/Password=</pre><pre>/SuppressMsgBoxes</pre><pre>/DETACHEDMSG</pre><pre>-0.bin</pre><pre>Setup version: Inno Setup version 5.5.1 (u)</pre><pre>Original Setup EXE:</pre><pre>Not restarting Windows because Setup is being run from the debugger.</pre><pre>Restarting Windows.</pre><pre>Inno Setup version 5.5.1 (u)</pre><pre>Portions Copyright (C) 2000-2012 Martijn Laan</pre><pre>http://www.innosetup.com/</pre><pre>http://www.remobjects.com/ps</pre><pre>Cannot run files in 64-bit locations on this version of Windows</pre><pre>Type: Exec</pre><pre>Type: ShellExec</pre><pre>RmRestart returned an error: %d</pre><pre>Need to restart Windows, not attempting to restart applications</pre><pre>Will not restart Windows automatically.</pre><pre>RegDeleteKeyExA</pre><pre>System\CurrentControlSet\Control\Windows</pre><pre>Cannot call "%s" function during Setup</pre><pre>Cannot call "%s" function during Uninstall</pre><pre>Invalid RootKey value</pre><pre>Unknown custom message name "%s"</pre><pre>%u.%.2u.%u</pre><pre>%u.%u.%u.%u</pre><pre>Cannot disable FS redirection on this version of Windows</pre><pre>Runtime Error (at %d:%d):</pre><pre>Exception "%s" at address %p</pre><pre>TScriptRunner.SetPSExecParameters: Invalid type</pre><pre>TScriptRunner.LoadScript failed</pre><pre>Remove shared file %s? User chose %s%s</pre><pre>/INITPROCWND=$%x</pre><pre>/SECONDPHASE="%s" /FIRSTPHASEWND=$%x</pre><pre>Original Uninstall EXE:</pre><pre>Install was done in 64-bit mode but not running 64-bit Windows now</pre><pre>Removed all? %s</pre><pre>Not restarting Windows because Uninstall is being run from the debugger.</pre><pre>isRS-???.tmp</pre><pre>isRS-%.3u.tmp</pre><pre>DisableProcessWindowsGhosting</pre><pre>Interface not supported</pre><pre>7Dispatch methods do not support more than 64 parameters</pre><pre>Exception: %s</pre><pre>Cannot Import %s</pre><pre>Unable to insert a line Clipboard does not support Icons</pre><pre>Text exceeds memo capacity/Menu '%s' is already being used by another form</pre><pre>- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.</pre><pre>Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count</pre><pre>OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object</pre><pre>Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window$Parent given is not a parent of '%s'</pre><pre>No help found for %s</pre><pre>Unsupported clipboard format</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group</pre><pre>Property %s does not exist</pre><pre>Thread creation error: %s</pre><pre>Thread Error: %s (%d)-Cannot terminate an externally created thread,Cannot wait for an externally created thread$No help viewer that supports filters#''%s'' is not a valid integer value</pre><pre>Cannot open file "%s". %s</pre><pre>Invalid file name - %s</pre><pre>Invalid stream format$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>List count out of bounds (%d)</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to get data for '%s'</pre><pre>Resource %s not found"Character index out of bounds (%d)</pre><pre>Start index out of bounds (%d)</pre><pre>Invalid count (%d)</pre><pre>Invalid destination index (%d)</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread</pre><pre>Class %s not found</pre><pre>A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Cannot create file "%s". %s</pre><pre>Object lock not owned(Monitor support function not initialized</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>Invalid variant operation</pre><pre>Invalid NULL variant operation%Invalid variant operation (%s%.8x)</pre><pre>%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)</pre><pre>Operation not supported</pre><pre>External exception %x</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Operation aborted(Exception %s in module %s at %p.</pre><pre>Application Error1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'"Variant method calls not supported</pre><pre>I/O error %d</pre><pre>Integer overflow Invalid floating point operation</pre><pre>n%USERPROFILE%</pre><pre>r%SYSTEMROOT%</pre><pre>5.50.4807.2300</pre><pre>Microsoft(R) Windows (R) 2000 Operating System</pre><pre>Datos de programa%Configuraci</pre><pre>51.1052.0.0</pre><b>PNLYA.exe_1244:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>s%j.Zf</pre><pre>8crtsu</pre><pre>:crts</pre><pre>crts</pre><pre>GetProcessWindowStation</pre><pre>operator</pre><pre>uxtheme.dll</pre><pre>kernel32.dll</pre><pre>operand of unlimited repeat could match the empty string</pre><pre>POSIX named classes are supported only within a class</pre><pre>erroffset passed as NULL</pre><pre>POSIX collating elements are not supported</pre><pre>this version of PCRE is not compiled with PCRE_UTF8 support</pre><pre>PCRE does not support \L, \l, \N{name}, \U, or \u</pre><pre>support for \P, \p, and \X has not been compiled</pre><pre>this version of PCRE is not compiled with PCRE_UCP support</pre><pre>ICMP.DLL</pre><pre>advapi32.dll</pre><pre>RegDeleteKeyExW</pre><pre>Error text not found (please report)</pre><pre>WSOCK32.dll</pre><pre>VERSION.dll</pre><pre>WINMM.dll</pre><pre>COMCTL32.dll</pre><pre>MPR.dll</pre><pre>InternetCrackUrlW</pre><pre>HttpQueryInfoW</pre><pre>HttpOpenRequestW</pre><pre>HttpSendRequestW</pre><pre>FtpOpenFileW</pre><pre>FtpGetFileSize</pre><pre>InternetOpenUrlW</pre><pre>WININET.dll</pre><pre>PSAPI.DLL</pre><pre>USERENV.dll</pre><pre>GetProcessHeap</pre><pre>CreatePipe</pre><pre>GetWindowsDirectoryW</pre><pre>KERNEL32.dll</pre><pre>OpenWindowStationW</pre><pre>SetProcessWindowStation</pre><pre>CloseWindowStation</pre><pre>MapVirtualKeyW</pre><pre>EnumChildWindows</pre><pre>EnumWindows</pre><pre>VkKeyScanW</pre><pre>GetKeyState</pre><pre>GetKeyboardState</pre><pre>SetKeyboardState</pre><pre>GetAsyncKeyState</pre><pre>keybd_event</pre><pre>EnumThreadWindows</pre><pre>ExitWindowsEx</pre><pre>UnregisterHotKey</pre><pre>RegisterHotKey</pre><pre>GetKeyboardLayoutNameW</pre><pre>USER32.dll</pre><pre>SetViewportOrgEx</pre><pre>GDI32.dll</pre><pre>COMDLG32.dll</pre><pre>RegOpenKeyExW</pre><pre>RegCloseKey</pre><pre>RegCreateKeyExW</pre><pre>RegEnumKeyExW</pre><pre>RegDeleteKeyW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteW</pre><pre>SHFileOperationW</pre><pre>ShellExecuteExW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>GetCPInfo</pre><pre>zcÁ</pre><pre>L.aVFY)</pre><pre>.ijjrc</pre><pre>g%D`-</pre><pre>sssh6</pre><pre>uW.MW</pre><pre><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></pre><pre><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity></pre><pre>3.3/464(5,5054585</pre><pre>8 8$8(8,808</pre><pre>= =$=(=,=0=4=8=<=@=</pre><pre>0 0$0(0,0004080<0</pre><pre>:*;3;?;|;</pre><pre>11</pre><pre>2 323[3.5</pre><pre>? ?<?@?`?</pre><pre>= =$=(=,=0=4=</pre><pre>5 5$5(5,5054585</pre><pre>CADjD%D<D><pre>mscoree.dll</pre><pre>nKERNEL32.DLL</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>WUSER32.DLL</pre><pre>CMDLINERAW</pre><pre>CMDLINE</pre><pre>/AutoIt3ExecuteLine</pre><pre>/AutoIt3ExecuteScript</pre><pre>%s (%d) : ==> %s.:</pre><pre>Line %d:</pre><pre>Line %d (File "%s"):</pre><pre>%s (%d) : ==> %s:</pre><pre>AutoIt script files (*.au3, *.a3x)</pre><pre>*.au3;*.a3x</pre><pre>All files (*.*)</pre><pre>#NoAutoIt3Execute</pre><pre>APPSKEY</pre><pre>Line %d:</pre><pre>04090000</pre><pre>%u.%u.%u.%u</pre><pre>0.0.0.0</pre><pre>Mddddd</pre><pre>%s (%d) : ==> %s:</pre><pre>UDPSTARTUP</pre><pre>UDPSHUTDOWN</pre><pre>UDPSEND</pre><pre>UDPRECV</pre><pre>UDPOPEN</pre><pre>UDPCLOSESOCKET</pre><pre>UDPBIND</pre><pre>TRAYGETMSG</pre><pre>TCPSTARTUP</pre><pre>TCPSHUTDOWN</pre><pre>TCPSEND</pre><pre>TCPRECV</pre><pre>TCPNAMETOIP</pre><pre>TCPLISTEN</pre><pre>TCPCONNECT</pre><pre>TCPCLOSESOCKET</pre><pre>TCPACCEPT</pre><pre>SHELLEXECUTEWAIT</pre><pre>SHELLEXECUTE</pre><pre>REGENUMKEY</pre><pre>MSGBOX</pre><pre>ISKEYWORD</pre><pre>HTTPSETUSERAGENT</pre><pre>HTTPSETPROXY</pre><pre>HOTKEYSET</pre><pre>GUIREGISTERMSG</pre><pre>GUIGETMSG</pre><pre>GUICTRLSENDMSG</pre><pre>GUICTRLRECVMSG</pre><pre>FTPSETPROXY</pre><pre>\??\%s</pre><pre>GUI_RUNDEFMSG</pre><pre>SendKeyDelay</pre><pre>SendKeyDownDelay</pre><pre>TCPTimeout</pre><pre>AUTOITCALLVARIABLE%d</pre><pre>255.255.255.255</pre><pre>Keyword</pre><pre>AutoIt.Error</pre><pre>Null Object assignment in FOR..IN loop</pre><pre>Incorrect Object type in FOR..IN loop</pre><pre>HOTKEYPRESSED</pre><pre>AUTOITEXE</pre><pre>WINDOWSDIR</pre><pre>3, 3, 8, 1</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_USERS</pre><pre>%d/d/d</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\KFCUE\PNLYA.exe</pre><pre>AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.</pre><pre>Missing operator in expression."Unbalanced brackets in expression.</pre><pre>Error parsing function call.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.)Array variable subscript badly formatted.'Subscript used with non-Array variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.</pre><pre>Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.</pre><pre>Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.</pre><pre>3This keyword cannot be used after a "Then" keyword.>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.</pre><pre>Can not redeclare a constant.5Can not redeclare a parameter inside a user function.HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.</pre><pre>String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.</pre><pre>http://www.autoitscript.com/autoit3/</pre><pre>AutoIt3.exe</pre><b>cmd.exe_1432:</b><pre>.text</pre><pre>`.data</pre><pre>.rsrc</pre><pre>KERNEL32.dll</pre><pre>NTDLL.DLL</pre><pre>msvcrt.dll</pre><pre>USER32.dll</pre><pre>SetConsoleInputExeNameW</pre><pre>APerformUnaryOperation: '%c'</pre><pre>APerformArithmeticOperation: '%c'</pre><pre>ADVAPI32.dll</pre><pre>SHELL32.dll</pre><pre>MPR.dll</pre><pre>RegEnumKeyW</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>RegOpenKeyW</pre><pre>RegCreateKeyExW</pre><pre>RegOpenKeyExW</pre><pre>ShellExecuteExW</pre><pre>CmdBatNotification</pre><pre>GetWindowsDirectoryW</pre><pre>GetProcessHeap</pre><pre>GetCPInfo</pre><pre>GetConsoleOutputCP</pre><pre>_pipe</pre><pre>GetProcessWindowStation</pre><pre>cmd.pdb</pre><pre>CMD Internal Error %s</pre><pre>)(&&())))(&))</pre><pre>)&((&)&))&())</pre><pre>)&((&)&)&()))</pre><pre>)(&&()))&))))</pre><pre>CMD.EXE</pre><pre>()|&=,;"</pre><pre>COPYCMD</pre><pre>\XCOPY.EXE</pre><pre>CMDCMDLINE</pre><pre>WKERNEL32.DLL</pre><pre>Software\Policies\Microsoft\Windows\System</pre><pre>0123456789</pre><pre>cmd.exe</pre><pre>DIRCMD</pre><pre>%d.%d.d</pre><pre>Ungetting: '%s'</pre><pre>DisableCMD</pre><pre>GeToken: (%x) '%s'</pre><pre>%s\Shell\Open\Command</pre><pre>%x %c</pre><pre>*** Unknown type: %x</pre><pre>Args: `%s'</pre><pre>Cmd: %s Type: %x</pre><pre>%s (%s) %s</pre><pre>Start C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\UIMeter.exe</pre><pre>:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\UIMeter.exe</pre><pre>UME~1\"%CurrentUserName%"\LOCALS~1\Temp\UIMeter.exe</pre><pre>.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH</pre><pre>%WinDir%;%WinDir%\System32\Wbem;c:\Program Files\Wireshark</pre><pre>CMDEXTVERSION</pre><pre>KEYS</pre><pre>%Documents and Settings%\%current user%\KFCUE</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp</pre><pre>%s %s</pre><pre>(%s) %s</pre><pre>%s %s%s</pre><pre>&()[]{}^=;!%' ,`~</pre><pre>d%sd%s</pre><pre>-%sd%sd%sd</pre><pre>d%sd%sd</pre><pre>%s=%s</pre><pre>X-X</pre><pre>.COM;.EXE;.BAT;.CMD;.VBS;.JS;.WS</pre><pre><> -*/%()|^&=,</pre><pre>\CMD.EXE</pre><pre>Windows Command Processor</pre><pre>5.1.2600.5512 (xpsp.080413-2111)</pre><pre>Cmd.Exe</pre><pre>Windows</pre><pre>Operating System</pre><pre>5.1.2600.5512</pre><pre>Press any key to continue . . . %0</pre><pre>operable program or batch file.</pre><pre>The system cannot execute the specified program.</pre><pre>and press any key when ready. %0</pre><pre>Microsoft Windows XP [Version %1]%0</pre><pre>a pipe operation.</pre><pre>KEYS is on.</pre><pre>KEYS is off.</pre><pre>The process tried to write to a nonexistent pipe.</pre><pre>The switch /Y may be preset in the COPYCMD environment variable.</pre><pre>to prompt on overwrites unless COPY command is being executed from</pre><pre>Switches may be preset in the DIRCMD environment variable. Override</pre><pre>Quits the CMD.EXE program (command interpreter) or the current batch</pre><pre>CMD.EXE. If executed from outside a batch script, it</pre><pre>will quit CMD.EXE</pre><pre>ERRORLEVEL that number. If quitting CMD.EXE, sets the process</pre><pre>Displays or sets a search path for executable files.</pre><pre>Type PATH ; to clear all search-path settings and direct cmd.exe to search</pre><pre>Changes the cmd.exe command prompt.</pre><pre>$B | (pipe)</pre><pre>$V Windows XP version number</pre><pre>Displays, sets, or removes cmd.exe environment variables.</pre><pre>Displays the Windows XP version.</pre><pre>Tells cmd.exe whether to verify that your files are written correctly to a</pre><pre>Records comments (remarks) in a batch file or CONFIG.SYS.</pre><pre>Press any key to continue . . . %0</pre><pre>Directs cmd.exe to a labeled line in a batch program.</pre><pre>NOT Specifies that Windows XP should carry out</pre><pre>will execute the command after the ELSE keyword if the</pre><pre>I The new environment will be the original environment passed</pre><pre>to the cmd.exe and not the current environment.</pre><pre>SEPARATE Start 16-bit Windows program in separate memory space</pre><pre>SHARED Start 16-bit Windows program in shared memory space</pre><pre>If it is an internal cmd command or a batch file then</pre><pre>the command processor is run with the /K switch to cmd.exe.</pre><pre>If it is not an internal cmd command or batch file then</pre><pre>parameters These are the parameters passed to the command/program</pre><pre>under Windows XP.</pre><pre>Starts a new instance of the Windows XP command interpreter</pre><pre>CMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]</pre><pre>/D Disable execution of AutoRun commands from registry (see below)</pre><pre>/A Causes the output of internal commands to a pipe or file to be ANSI</pre><pre>/U Causes the output of internal commands to a pipe or file to be</pre><pre>variable var at execution time. The %var% syntax expands variables</pre><pre>of an executable file.</pre><pre>If /D was NOT specified on the command line, then when CMD.EXE starts, it</pre><pre>either or both are present, they are executed first.</pre><pre>HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\AutoRun</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun</pre><pre>can enable or disable extensions for all invocations of CMD.EXE on a</pre><pre>following REG_DWORD values in the registry using REGEDT32.EXE:</pre><pre>HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\EnableExtensions</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions</pre><pre>particular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You</pre><pre>can enable or disable completion for all invocations of CMD.EXE on a</pre><pre>HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DelayedExpansion</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion</pre><pre>at execution time.</pre><pre>CMD.EXE with the /F:ON or /F:OFF switch. You can enable or disable</pre><pre>completion for all invocations of CMD.EXE on a machine and/or user logon</pre><pre>the registry using REGEDT32.EXE:</pre><pre>HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\CompletionChar</pre><pre>HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\PathCompletionChar</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar</pre><pre>HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar</pre><pre>Shift key with the control character will move through the list</pre><pre>&()[]{}^=;!%' ,`~</pre><pre>Command Processor Extensions enabled by default. Use CMD /? for details.</pre><pre>ASSOC [.ext[=[fileType]]]</pre><pre>.ext Specifies the file extension to associate the file type with</pre><pre>ASSOC .pl=PerlScript</pre><pre>FTYPE PerlScript=perl.exe %%1 %%*</pre><pre>script.pl 1 2 3</pre><pre>set PATHEXT=.pl;%%PATHEXT%%</pre><pre>The restartable option to the COPY command is not supported by</pre><pre>this version of the operating system.</pre><pre>The following usage of the path operator in batch-parameter</pre><pre>The unicode output option to CMD.EXE is not supported by this</pre><pre>version of the operating system.</pre><pre>If Command Extensions are enabled the DATE command supports</pre><pre>If Command Extensions are enabled the TIME command supports</pre><pre>If Command Extensions are enabled the PROMPT command supports</pre><pre>is pretty simple and supports the following operations, in decreasing</pre><pre>! ~ - - unary operators</pre><pre>* / %% - arithmetic operators</pre><pre> - - arithmetic operators</pre><pre>&= ^= |= <<= >>=</pre><pre>If you use any of the logical or modulus operators, you will need to</pre><pre>values. If SET /A is executed from the command line outside of a</pre><pre>assignment operator requires an environment variable name to the left of</pre><pre>the assignment operator. Numeric values are decimal numbers, unless</pre><pre>occurrence of the remaining portion of str1.</pre><pre>Finally, support for delayed environment variable expansion has been</pre><pre>added. This support is always disabled by default, but may be</pre><pre>enabled/disabled via the /V command line switch to CMD.EXE. See CMD /?</pre><pre>of text is read, not when it is executed. The following example</pre><pre>So the actual FOR loop we are executing is:</pre><pre>%Í%% - expands to the current directory string.</pre><pre>%ÚTE%% - expands to current date using same format as DATE command.</pre><pre>%%CMDEXTVERSION%% - expands to the current Command Processor Extensions</pre><pre>%%CMDCMDLINE%% - expands to the original command line that invoked the</pre><pre>If Command Extensions are enabled the SHIFT command supports</pre><pre>control is passed to the statement after the label specified. You must</pre><pre>%%4 %%5 ...)</pre><pre>CMD /? for details.</pre><pre>This works because on old versions of CMD.EXE, SETLOCAL does NOT</pre><pre>command execution.</pre><pre>non-executable files may be invoked through their file association just</pre><pre>by typing the name of the file as a command. (e.g. WORD.DOC would</pre><pre>launch the application associated with the .DOC file extension).</pre><pre>When executing an application that is a 32-bit GUI application, CMD.EXE</pre><pre>the command prompt. This new behavior does NOT occur if executing</pre><pre>When executing a command line whose first token is the string "CMD "</pre><pre>without an extension or path qualifier, then "CMD" is replaced with</pre><pre>the value of the COMSPEC variable. This prevents picking up CMD.EXE</pre><pre>When executing a command line whose first token does NOT contain an</pre><pre>extension, then CMD.EXE uses the value of the PATHEXT</pre><pre>.COM;.EXE;.BAT;.CMD</pre><pre>When searching for an executable, if there is no match on any extension,</pre><pre>If Command Extensions are enabled, and running on the Windows XP</pre><pre>forms of the FOR command are supported:</pre><pre>Walks the directory tree rooted at [drive:]path, executing the FOR</pre><pre>passes the first blank separated token from each line of each file.</pre><pre>is a quoted string which contains one or more keywords to specify</pre><pre>different parsing options. The keywords are:</pre><pre>be passed to the for body for each iteration.</pre><pre>where a back quoted string is executed as a</pre><pre>FOR /F "eol=; tokens=2,3* delims=, " %%i in (myfile.txt) do @echo %%i %%j %%k</pre><pre>would parse each line in myfile.txt, ignoring lines that begin with</pre><pre>a semicolon, passing the 2nd and 3rd token from each line to the for</pre><pre>line, which is passed to a child CMD.EXE and the output is captured</pre><pre>IF CMDEXTVERSION number command</pre><pre>The CMDEXTVERSION conditional works just like ERRORLEVEL, except it is</pre><pre>CMDEXTVERSION conditional is never true when Command Extensions are</pre><pre>%%CMDCMDLINE%% will expand into the original command line passed to</pre><pre>CMD.EXE prior to any processing by CMD.EXE, provided that there is not</pre><pre>already an environment variable with the name CMDCMDLINE, in which case</pre><pre>%%CMDEXTVERSION%% will expand into a string representation of the</pre><pre>current value of CMDEXTVERSION, provided that there is not already</pre><pre>an environment variable with the name CMDEXTVERSION, in which case you</pre><pre>under Windows XP, as command line editing is always enabled.</pre><pre>CMD.EXE was started with the above path as the current directory.</pre><pre>UNC paths are not supported. Defaulting to Windows directory.</pre><pre>CMD does not support UNC paths as current directories.</pre><pre>UNC paths not supported for current directory. Using</pre><pre>to create temporary drive letter to support UNC current</pre><pre>Missing operand.</pre><pre>Missing operator.</pre><pre>The COMSPEC environment variable does not point to CMD.EXE.</pre><pre>The FAT File System only support Last Write Times</pre><pre>of a batch script is reached, an implied ENDLOCAL is executed for any</pre><pre>application execution.</pre><pre>The switch /Y may be present in the COPYCMD environment variable.</pre><pre>to prompt on overwrites unless MOVE command is being executed from</pre><pre>when CMD.EXE started. This value either comes from the current console</pre><pre>The COLOR command sets ERRORLEVEL to 1 if an attempt is made to execute</pre></D></pre></requestedExecutionLevel></pre></The></pre></Attempt>