Trojan-Banker.Win32.Brasil.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, GenericEmailWorm.YR (Lavasoft MAS)Behaviour: Banker, Trojan, Worm, EmailWorm, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 16fd87484867798b7e64984fbabd1077
SHA1: e52255c6f23e297c24f20e800cf75827d4a7ed5a
SHA256: 1332406d7548c7e3aef73a06baa32a0f6ebd02b704271a1c68b531474acb2703
SSDeep: 196608:HZhe5lVDbc/iPRuwK vfSjKJACwq1HhCp KxhbQKBzeA7dlyFh0:iVtRuwKQsKJA01BCQYhbQKBZhli2
Size: 10615200 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphiv60v70_v2, BorlandDelphi30, BorlandDelphiv30, UPolyXv05_v6
Company: PC Utilities Software Limited
Created at: 1992-06-20 01:22:17
Analyzed on: WindowsXP SP3 32-bit
Summary: Banker. Steals data relating to online banking systems, e-payment systems and credit card systems.
Dynamic Analysis
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The Trojan-Banker creates the following process(es):
Driver_Pro.exe:1680
DPSchedule.exe:1976
DriverPro.exe:828
DriverPro.exe:516
%original file name%.exe:1108
Driver_Pro.tmp:2000
DPStartScan.exe:1512
The Trojan-Banker injects its code into the following process(es):
DriverPro.exe:1368
Mutexes
The following mutexes were created/opened:No objects were found.
File activity
The process Driver_Pro.exe:1680 makes changes in the file system.
The Trojan-Banker creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-495IU.tmp\Driver_Pro.tmp (7386 bytes)
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-495IU.tmp\Driver_Pro.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-495IU.tmp (0 bytes)
The process DPSchedule.exe:1976 makes changes in the file system.
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\DPSchedule.madExcept (0 bytes)
The process DriverPro.exe:828 makes changes in the file system.
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\DriverPro.madExcept (0 bytes)
The process DriverPro.exe:1368 makes changes in the file system.
The Trojan-Banker creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Driver Pro\Scan.ini (599 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Devices.ini (26 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\PCInfo.ini (175 bytes)
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\DriverPro.madExcept (0 bytes)
The process DriverPro.exe:516 makes changes in the file system.
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\DriverPro.madExcept (0 bytes)
The process %original file name%.exe:1108 makes changes in the file system.
The Trojan-Banker creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Driver_Pro.exe (75554 bytes)
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Driver_Pro.exe (0 bytes)
The process Driver_Pro.tmp:2000 makes changes in the file system.
The Trojan-Banker creates and/or writes to the following file(s):
%Program Files%\Driver Pro\is-4V94R.tmp (30427 bytes)
%Documents and Settings%\%current user%\Desktop\Driver Pro.lnk (701 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-6QHE4.tmp\_isetup\_shfoldr.dll (23 bytes)
%Program Files%\Driver Pro\is-25G8B.tmp (7433 bytes)
%Program Files%\Driver Pro\is-DFL92.tmp (31891 bytes)
%Program Files%\Driver Pro\is-220VD.tmp (56 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Help.lnk (713 bytes)
%Program Files%\Driver Pro\is-U1KU1.tmp (5873 bytes)
%Program Files%\Driver Pro\is-VHECN.tmp (54 bytes)
%Program Files%\Driver Pro\is-5NL22.tmp (12 bytes)
%Program Files%\Driver Pro\is-KHQQ8.tmp (26 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-T10AK.tmp (526038 bytes)
%Program Files%\Driver Pro\unins000.dat (5536 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Uninstall Driver Pro.lnk (708 bytes)
%Program Files%\Driver Pro\is-0D1IA.tmp (547 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro.lnk (713 bytes)
%Program Files%\Driver Pro\unins000.msg (646 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro on the Web.lnk (708 bytes)
%Program Files%\Driver Pro\is-VTLVF.tmp (3361 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-G7FF6.tmp (61 bytes)
%Program Files%\Driver Pro\is-3EFK5.tmp (3073 bytes)
%Program Files%\Driver Pro\is-ET54V.tmp (7433 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-0J1RE.tmp (558848 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-FJQ75.tmp (4 bytes)
%Program Files%\Driver Pro\is-OSVAV.tmp (5873 bytes)
The Trojan-Banker deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\is-6QHE4.tmp\_isetup (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-6QHE4.tmp\_isetup\_shfoldr.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-6QHE4.tmp (0 bytes)
The process DPStartScan.exe:1512 makes changes in the file system.
The Trojan-Banker creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
Registry activity
The process Driver_Pro.exe:1680 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A4 F8 B6 55 B9 8C 43 2A 20 33 04 4D 76 52 A3 84"
The process DPSchedule.exe:1976 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AE 6B 15 E7 EF B3 03 60 F9 8C 33 B8 E8 94 76 B4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Driver Pro]
"s_Date" = "00 00 00 00 C0 6F E4 40"
"s_Exec" = "1"
The Trojan-Banker modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-Banker modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan-Banker modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process DriverPro.exe:828 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CC 25 D6 62 C0 01 B2 43 B3 D5 4B 6D 39 F3 99 FC"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Templates" = "%Documents and Settings%\%current user%\Templates"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The process DriverPro.exe:1368 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Driver Pro]
"s_Enable" = "1"
"CloseToTray" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Driver Pro]
"UpdateWindowShown" = "0"
"InstallStat" = "1"
"BackupPath" = "%Documents and Settings%\%current user%\My Documents\Driver Pro\Backup\"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKCU\Software\Driver Pro]
"s_SmartScan" = "1"
"Feedback1" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Driver Pro]
"ShowAlertMessages" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Driver Pro]
"ShowUpdateWindow" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Driver Pro]
"QuerryDate" = "B3 18 C5 89 D4 6F E4 40"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKCU\Software\Driver Pro]
"ProxyPassword" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Driver Pro]
"s_SmartMode" = "2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Driver Pro]
"LastScan" = "82 88 C0 89 D4 6F E4 40"
"TotalDrivers" = "65"
"DownloadPath" = "%Documents and Settings%\%current user%\My Documents\Driver Pro\Drivers\"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Templates" = "%Documents and Settings%\%current user%\Templates"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Driver Pro]
"ProxyPort" = ""
"LastUpdate" = "9B 4C A0 89 D4 6F E4 40"
"ScanAtStartup" = "0"
"ForceUpdate" = "0"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Driver Pro]
"ProxyAddress" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Driver Pro]
"OutdatedDrivers" = "1"
"nDownloads" = "3"
"LastDatabaseCheck" = "9B 4C A0 89 D4 6F E4 40"
"DatabaseDate" = "00 00 00 00 80 52 E4 40"
"ShowSRPMessage" = "1"
"ScanExecuted" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Driver Pro]
"s_Mode" = "0"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A7 92 66 79 BC E0 F2 43 01 29 A0 42 2E B3 6B CF"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Driver Pro]
"DPSchedule.exe" = "Driver Pro Schedule"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Driver Pro]
"AppStart" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Driver Pro]
"UseProxy" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Driver Pro]
"ShowRebootMessage" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
[HKCU\Software\Driver Pro]
"ProxyLogin" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
The Trojan-Banker modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-Banker modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Banker modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-Banker deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process DriverPro.exe:516 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D1 AD 27 5D E0 B7 DC 36 AA 24 20 44 79 E5 E7 9A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Templates" = "%Documents and Settings%\%current user%\Templates"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The process %original file name%.exe:1108 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "39 64 07 C8 92 83 F2 99 A2 84 1D AB EC DC 72 50"
[HKCU\Software\Driver Pro]
"setupname" = "c:\%original file name%.exe"
The process Driver_Pro.tmp:2000 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"DisplayVersion" = "3.1"
"NoRepair" = "1"
"Inno Setup: Language" = "en"
"MajorVersion" = "3"
"Inno Setup: Deselected Tasks" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"URLUpdateInfo" = "http://www.pcutilitiespro.com"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Inno Setup: Icon Group" = "Driver Pro"
"Inno Setup: Setup Version" = "5.5.3 (u)"
"Inno Setup: User" = "%CurrentUserName%"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"UninstallString" = "%Program Files%\Driver Pro\unins000.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"DisplayName" = "Driver Pro v3.1"
"Inno Setup: App Path" = "%Program Files%\Driver Pro"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"InstallLocation" = "%Program Files%\Driver Pro\"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"URLInfoAbout" = "http://www.pcutilitiespro.com"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKCU\Software\Driver Pro]
"Language" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"HelpLink" = "http://www.pcutilitiespro.com"
"InstallDate" = "20140803"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Publisher" = "PC Utilities Software Limited"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "73 DB 40 55 22 46 20 70 AC ED A6 57 7D 3E 0A 5D"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"Inno Setup: Selected Tasks" = "desktopicon"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Driver Pro_is1]
"QuietUninstallString" = "%Program Files%\Driver Pro\unins000.exe /SILENT"
"NoModify" = "1"
"MinorVersion" = "1"
To automatically run itself each time Windows is booted, the Trojan-Banker adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Driver Pro" = "%Program Files%\Driver Pro\DPLauncher.exe"
The process DPStartScan.exe:1512 makes changes in the system registry.
The Trojan-Banker creates and/or sets the following values in system registry:
[HKCU\Software\Driver Pro]
"SupportURL" = "http://support.pcutilitiespro.com/"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Driver Pro]
"MachineGuid" = "C88A84FF-17F0-E943-F851-07DAA06E63E0"
"UninstallURL" = "https://safecart.com/pcutilitiespro/.dp-xsell-special/purchase?sid=121001231-GB-003"
"DelayedStart" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Driver Pro]
"UseAds" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Driver Pro]
"QuerryDate" = "7F EB 89 89 D4 6F E4 40"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCU\Software\Driver Pro]
"OS" = "102"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Driver Pro]
"BuyNowURL" = "http://pcup26b2.pcutilitiespro.revenuewire.net/driverpro/xsell?121001231-GB-003_C88A84FF-17F0-E943-F851-07DAA06E63E0"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Driver Pro]
"Querry" = "http://bi.softservers.net/t/dp?sid=121001231-GB-003&dt=%dt%&gid=%GID%&tz=%tz%&ln=%ln%&lc=%lc%&bis=%bis%&bief=%bief%&biefx=%biefx%&bif=%bif%&os=%os%&f=1510085629"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Driver Pro]
"homepageurl" = "http://www.pcutilitiespro.com/"
"AppStart" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "84 DF E4 F0 1F 40 0B CE 9A E7 9F 06 E3 68 8B 9E"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Driver Pro]
"DriverPro.exe" = "Driver Pro"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Driver Pro]
"InstallDate" = "06 2C 7E 89 D4 6F E4 40"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
The Trojan-Banker modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan-Banker modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan-Banker modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan-Banker deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
84ceb93407bd2df6e758d57cc8e6da47 | c:\Program Files\Driver Pro\DPLauncher.exe |
b9dcf8ec0fcb6c9acae61c4bca3675ac | c:\Program Files\Driver Pro\DPSchedule.exe |
060ba8f552e6d9502d0a73ab9f1d4025 | c:\Program Files\Driver Pro\DPSmartScan.exe |
aa4789ba11e54360f6ee26fc8d79cbb8 | c:\Program Files\Driver Pro\DPStartScan.exe |
4a1ae76d0634c7b8f575a446d9b7bdf3 | c:\Program Files\Driver Pro\DPUninstaller.exe |
25d29176ebb0e5f54b75cadd3ec225a6 | c:\Program Files\Driver Pro\DriverPro.exe |
0f66e8e2340569fb17e774dac2010e31 | c:\Program Files\Driver Pro\sqlite3.dll |
fe547eb408703b1f8e98643180b48f55 | c:\Program Files\Driver Pro\unins000.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
Driver_Pro.exe:1680
DPSchedule.exe:1976
DriverPro.exe:828
DriverPro.exe:516
%original file name%.exe:1108
Driver_Pro.tmp:2000
DPStartScan.exe:1512 - Delete the original Trojan-Banker file.
- Delete or disinfect the following files created/modified by the Trojan-Banker:
%Documents and Settings%\%current user%\Local Settings\Temp\is-495IU.tmp\Driver_Pro.tmp (7386 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Scan.ini (599 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\Devices.ini (26 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\PCInfo.ini (175 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Driver_Pro.exe (75554 bytes)
%Program Files%\Driver Pro\is-4V94R.tmp (30427 bytes)
%Documents and Settings%\%current user%\Desktop\Driver Pro.lnk (701 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\is-6QHE4.tmp\_isetup\_shfoldr.dll (23 bytes)
%Program Files%\Driver Pro\is-25G8B.tmp (7433 bytes)
%Program Files%\Driver Pro\is-DFL92.tmp (31891 bytes)
%Program Files%\Driver Pro\is-220VD.tmp (56 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Help.lnk (713 bytes)
%Program Files%\Driver Pro\is-U1KU1.tmp (5873 bytes)
%Program Files%\Driver Pro\is-VHECN.tmp (54 bytes)
%Program Files%\Driver Pro\is-5NL22.tmp (12 bytes)
%Program Files%\Driver Pro\is-KHQQ8.tmp (26 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-T10AK.tmp (526038 bytes)
%Program Files%\Driver Pro\unins000.dat (5536 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Uninstall Driver Pro.lnk (708 bytes)
%Program Files%\Driver Pro\is-0D1IA.tmp (547 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro.lnk (713 bytes)
%Program Files%\Driver Pro\unins000.msg (646 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\Driver Pro\Driver Pro on the Web.lnk (708 bytes)
%Program Files%\Driver Pro\is-VTLVF.tmp (3361 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-G7FF6.tmp (61 bytes)
%Program Files%\Driver Pro\is-3EFK5.tmp (3073 bytes)
%Program Files%\Driver Pro\is-ET54V.tmp (7433 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-0J1RE.tmp (558848 bytes)
%Documents and Settings%\%current user%\Application Data\Driver Pro\is-FJQ75.tmp (4 bytes)
%Program Files%\Driver Pro\is-OSVAV.tmp (5873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Driver Pro" = "%Program Files%\Driver Pro\DPLauncher.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: PC Utilities Software Limited
Product Name: DriverPro
Product Version: 3.1.0.0
Legal Copyright: PC Utilities Software Limited
Legal Trademarks:
Original Filename:
Internal Name: DriverPro
File Version:
File Description: DriverPro
Comments:
Language: English (United States)
Company Name: PC Utilities Software LimitedProduct Name: DriverProProduct Version: 3.1.0.0Legal Copyright: PC Utilities Software LimitedLegal Trademarks: Original Filename: Internal Name: DriverProFile Version: File Description: DriverProComments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
CODE | 4096 | 75644 | 75776 | 4.45296 | 341f60451089865a24c3c84ec3821c82 |
DATA | 81920 | 1428 | 1536 | 2.76929 | f76f4515a2e2b60cda146361ff2e6e44 |
BSS | 86016 | 2185 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.idata | 90112 | 2862 | 3072 | 3.11744 | 3a510b9194a87490600faea96f544b5a |
.tls | 94208 | 12 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 98304 | 24 | 512 | 0.14174 | 6b2b783af3ecd764905292c9b75d8ea4 |
.reloc | 102400 | 6084 | 6144 | 4.57315 | 5b58562521fe8470d3ba9da0f91e605b |
.rsrc | 110592 | 10520576 | 10520576 | 5.52698 | 545e100ee294189abc22493808e3a4a6 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 10
6a47bb51997f1bae446c3bafb640ab74
0277a8488e21336ba6837ddb8667cc4c
10c046644095f6559e2ddd2cfe70fd03
cd047c070fd6d4e0ebcb011b248a168c
d0e6a7164e04419cffc764c3c2bbe3cb
b71de35f0ce797d8de50891f11003cbd
fb23f3836be89d88085a9713c903d5b3
88669a0972341a0bdeadb024e0d5e5a9
b3c3159e99ba1a65607247f496503cf2
0231df9ee0b3fdb9f14672d9490c5bf6
Network Activity
URLs
URL | IP |
---|---|
hxxp://bi.softservers.net/t/dp?sid=121001231-GB-003&dt=1407079450&gid=C88A84FF-17F0-E943-F851-07DAA06E63E0&tz=2&ln=1&lc=0&bis=0&bief=0&biefx=0&bif=0&os=102&f=1510085629 | 107.6.170.117 |
hxxp://service.smartpcupdate.com/rpc/sendinstall?partner=PCUtilitiesPro&build=3.1 | 176.9.2.105 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /t/dp?sid=121001231-GB-003&dt=1407079450&gid=C88A84FF-17F0-E943-F851-07DAA06E63E0&tz=2&ln=1&lc=0&bis=0&bief=0&biefx=0&bif=0&os=102&f=1510085629 HTTP/1.1
Host: bi.softservers.net
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.4.1
Date: Sun, 03 Aug 2014 12:23:59 GMT
Content-Type: application/octet-stream
Content-Length: 0
Connection: keep-alive
content-type: text/html
GET /rpc/sendinstall?partner=PCUtilitiesPro&build=3.1 HTTP/1.1
Host: service.smartpcupdate.com
Accept: text/html, */*
User-Agent: Mozilla/3.0 (compatible; Indy Library)
HTTP/1.1 200 OK
Server: nginx/1.0.4
Date: Sun, 03 Aug 2014 12:24:00 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.3.14
12..{"ok":1,"error":0}..0..
Map
The Trojan-Banker connects to the servers at the folowing location(s):
Strings from Dumps
DriverPro.exe_1368:
.idata
.idata
.edata
.edata
P.tls
P.tls
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
HKEY
HKEY
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
;!199{199
;!199{199
;0!8&2{199
;0!8&2{199
"<;=!!%{199
"<;=!!%{199
Windows 95
Windows 95
Windows 95 OSR-2
Windows 95 OSR-2
Windows 98
Windows 98
Windows 98 SE
Windows 98 SE
Windows ME
Windows ME
Windows 9x New
Windows 9x New
Windows NT 3
Windows NT 3
Windows NT 4
Windows NT 4
Windows 2000
Windows 2000
Windows XP
Windows XP
Windows 2003
Windows 2003
Windows Vista
Windows Vista
Windows 2008
Windows 2008
Windows 7
Windows 7
Windows 2008 R2
Windows 2008 R2
Windows 8
Windows 8
Windows Server 8
Windows Server 8
Windows NT New
Windows NT New
user.exe
user.exe
TMsgHandlers
TMsgHandlers
madToolsMsgHandlerWindow
madToolsMsgHandlerWindow
user32.dll
user32.dll
>0';0974&0{199
>0';0974&0{199
cmovÌ
cmovÌ
setÌ
setÌ
pop %seg
pop %seg
push %seg
push %seg
msvcrt.dll
msvcrt.dll
www.madshi.net
www.madshi.net
dbghelp.dll
dbghelp.dll
comctl32.dll
comctl32.dll
4.0.9
4.0.9
ntdll.dll
ntdll.dll
The import table is invalid.
The import table is invalid.
shell32.dll
shell32.dll
WindowsLogo
WindowsLogo
ReportLeaks
ReportLeaks
UploadViaHttp
UploadViaHttp
HttpServer
HttpServer
HttpSsl
HttpSsl
HttpPort
HttpPort
HttpAccount
HttpAccount
HttpPassword
HttpPassword
BugTrPassword
BugTrPassword
MailAsSmtpServer
MailAsSmtpServer
MailAsSmtpClient
MailAsSmtpClient
SmtpServer
SmtpServer
SmtpSsl
SmtpSsl
SmtpTls
SmtpTls
SmtpPort
SmtpPort
SmtpAccount
SmtpAccount
SmtpPassword
SmtpPassword
bugreport.mbr
bugreport.mbr
screenshot.png
screenshot.png
ExceptMsg
ExceptMsg
FrozenMsg
FrozenMsg
BitFaultMsg
BitFaultMsg
send bug report
send bug report
save bug report
save bug report
print bug report
print bug report
show bug report
show bug report
%appname%, %exceptMsg%
%appname%, %exceptMsg%
bug report
bug report
please find the bug report attached
please find the bug report attached
Sending bug report...
Sending bug report...
PrepAttMsg
PrepAttMsg
MxLookMsg
MxLookMsg
ConnMsg
ConnMsg
SendMailMsg
SendMailMsg
FieldMsg
FieldMsg
SendAttMsg
SendAttMsg
SendFinalMsg
SendFinalMsg
SendFailMsg
SendFailMsg
Sorry, sending the bug report didn't work.
Sorry, sending the bug report didn't work.
TDABugReportCallback
TDABugReportCallback
TDABugReportCallbackOO
TDABugReportCallbackOO
ShellExecuteExW
ShellExecuteExW
madExceptIde_.bpl
madExceptIde_.bpl
wininet.dll
wininet.dll
www.google.com
www.google.com
SMTP:
SMTP:
mapi32.dll
mapi32.dll
IpHlpApi.dll
IpHlpApi.dll
A.ROOT-SERVERS.NET
A.ROOT-SERVERS.NET
K.ROOT-SERVERS.NET
K.ROOT-SERVERS.NET
www.madshi.net_multipart_boundary
www.madshi.net_multipart_boundary
TSmtpU
TSmtpU
LOGIN
LOGIN
AUTH LOGIN
AUTH LOGIN
security.dll
security.dll
secur32.dll
secur32.dll
TWinHttp
TWinHttp
winhttp.dll
winhttp.dll
WinHttpOpen
WinHttpOpen
WinHttpConnect
WinHttpConnect
WinHttpOpenRequest
WinHttpOpenRequest
WinHttpAddRequestHeaders
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpSendRequest
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetIEProxyConfigForCurrentUser
WinHttpGetProxyForUrl
WinHttpGetProxyForUrl
WinHttpSetOption
WinHttpSetOption
WinHttpWriteData
WinHttpWriteData
WinHttpReceiveResponse
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpQueryHeaders
WinHttpQueryAuthSchemes
WinHttpQueryAuthSchemes
WinHttpSetCredentials
WinHttpSetCredentials
WinHttpQueryDataAvailable
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReadData
WinHttpCloseHandle
WinHttpCloseHandle
/api.xml
/api.xml
<url></url>
<url></url>
password
password
?cmd=
?cmd=
/xmlrpc.cgi
/xmlrpc.cgi
Bugzilla.version
Bugzilla.version
Product.get_enterable_products
Product.get_enterable_products
Product.get
Product.get
Bug.fields
Bug.fields
Bugzilla_login
Bugzilla_login
Bugzilla_password
Bugzilla_password
Bug.create
Bug.create
Bug.add_attachment
Bug.add_attachment
/api/soap/mantisconnect.php
/api/soap/mantisconnect.php
<?xml version="1.0" encoding="UTF-8"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"><SOAP-ENV:Body><ns1:><pre><password xsi:type="xsd:string"></password></pre><pre></pre><pre>*.txt</pre><pre>TSendBugReportExRec</pre><pre>advapi32.dll</pre><pre>wtsapi32.dll</pre><pre>idapi32.dll</pre><pre>kernelbase.dll</pre><pre>madExcept32.dll</pre><pre>c:\sources\madshi\madExcept32.dll</pre><pre>ReportLeaksNow</pre><pre>GetLeakReport</pre><pre>ShowLeakReport</pre><pre>madExcept32.dll has the wrong version.</pre><pre>coreide70.bpl</pre><pre>ReportFault</pre><pre>FaultRep.dll</pre><pre>internal error. please notify bug@madshi.net</pre><pre>@System@@StartExe$qqrp23System@PackageInfoTablep17System@TLibModule</pre><pre>HardWareKey</pre><pre>setupapi.dll</pre><pre>$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)</pre><pre>oleaut32.dll</pre><pre>EVariantBadIndexError</pre><pre>ssShift</pre><pre>htKeyword</pre><pre>EInvalidOperation</pre><pre>u%CNu</pre><pre>%s[%d]</pre><pre>%s_%d</pre><pre>.Owner</pre><pre>EInvalidGraphicOperation</pre><pre>USER32.DLL</pre><pre>uxtheme.dll</pre><pre>PasswordChar</pre><pre>OnKeyDown</pre><pre>OnKeyPressPbJ</pre><pre>OnKeyUptaJ</pre><pre>ssHorizontal</pre><pre>OnKeyUp</pre><pre>Proportional</pre><pre>%s%s%s%s%s%s%s%s%s%s</pre><pre>IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")</pre><pre>JumpID("","%s")</pre><pre>TKeyEvent</pre><pre>TKeyPressEvent</pre><pre>HelpKeyword`</pre><pre>crSQLWait</pre><pre>%s (%s)</pre><pre>imm32.dll</pre><pre>HelpKeyword|</pre><pre>OnExecute</pre><pre>AutoHotkeys</pre><pre>ssHotTrack</pre><pre>TWindowState</pre><pre>poProportional</pre><pre>TWMKey</pre><pre>KeyPreview</pre><pre>WindowState</pre><pre>tagMSG</pre><pre>System\CurrentControlSet\Control\Keyboard Layouts\%.8x</pre><pre>vcltest3.dll</pre><pre>User32.dll</pre><pre>MAPI32.DLL</pre><pre>vsReport</pre><pre>TComboBoxExEnumerator</pre><pre>ole32.dll</pre><pre>OnActionExecute</pre><pre>%s, ClassID: %s</pre><pre>%s, ProgID: "%s"</pre><pre>WNNC_NET_FTP_NFS</pre><pre>olepro32.dll</pre><pre>\\.\vwin32</pre><pre>shlwapi.dll</pre><pre>Mpr.dll</pre><pre>D:\SmartPC\Components\EasyListview\Common Library\Source\MPShellUtilities.pas</pre><pre>To show a Context Menu using TNamespace you must pass a valid Owner TWinControl</pre><pre>THKeyArray</pre><pre>TCommonShellExecuteThreadU</pre><pre>D:\SmartPC\Components\EasyListview\Common Library\Source\MPThreadManager.pas</pre><pre>TCommonKeyState</pre><pre>cksShift</pre><pre>TCommonKeyStates</pre><pre>D:\SmartPC\Components\EasyListview\Common Library\Source\MPCommonUtilities.pas</pre><pre>gdi32.dll</pre><pre>Userenv.dll</pre><pre>ShellExecuteW</pre><pre>GetWindowsDirectoryW</pre><pre>RegOpenKeyW</pre><pre>RegOpenKeyExW</pre><pre>SHFileOperationW</pre><pre>D:\SmartPC\Components\EasyListview\Source\EasyListviewAccessible.pas</pre><pre>TEasyAccessibleManager.Create not a TCustomEasyListview type</pre><pre>TEasyGroupAccessibleManager.Create not a TEasyGroup type</pre><pre>TEasyItemAccessibleManager.Create not a TEasyItem type</pre><pre>TEasyColumnAccessibleManager.Create not a TEasyColumn type</pre><pre>TEasyHeaderAccessibleManager.Create not a TEasyHeader type</pre><pre>elsReport</pre><pre>elsReportThumb</pre><pre>TAutoGroupGetKeyEvent</pre><pre>TColumnGetImageIndexEvent</pre><pre>TColumnSetImageIndexEvent</pre><pre>KeyState</pre><pre>KeyStates</pre><pre>TGroupGetImageIndexEvent</pre><pre>TGroupSetImageIndexEvent</pre><pre>HintWindowShown</pre><pre>TItemGetGroupKeyEvent</pre><pre>GroupKey</pre><pre>TItemGetImageIndexEvent</pre><pre>TItemSetGroupKeyEvent</pre><pre>TItemSetImageIndexEvent</pre><pre>MouseMsg</pre><pre>TEasyKeyActionEvent</pre><pre>EscapeKeyPressed</pre><pre>TEasyViewReportItem</pre><pre>TEasyViewReportItem0</pre><pre>TEasyViewReportThumbItem</pre><pre>TEasyViewReportThumbItemh</pre><pre>TEasyGridReportGroup</pre><pre>TEasyGridReportThumbGroup</pre><pre>TEasyGridReportThumbGroup`</pre><pre>TEasyCellSizeReport</pre><pre>TEasyCellSizeReportThumb</pre><pre>ReportThumb</pre><pre>Reportd)Q</pre><pre>AlwaysShow</pre><pre>OnAutoGroupGetKeyP</pre><pre>OnItemGetGroupKey<</pre><pre>OnItemSetGroupKey</pre><pre>OnKeyActionD</pre><pre>Uh.dR</pre><pre>D:\SmartPC\Components\EasyListview\Source\EasyListview.pas</pre><pre>Can not find TEasyGroups.AdjacentItem of an Invisible Item</pre><pre>EasyListview.Header</pre><pre>LeftPopup</pre><pre>TNT Internal Error: TWideComponentHelper.Create should never be encountered.</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntClasses.pas</pre><pre>!"#$%&*;<=>@[]^_`{|}</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntControls.pas</pre><pre>Internal Error: SubClassUnicodeControl.Control is not Unicode.</pre><pre>.UnicodeClass</pre><pre>TntUnicodeVcl.DestroyWindow</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntActnList.pas</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntStdCtrls.pas</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntForms.pas</pre><pre>D:\SmartPC\Components\Delphi Unicode Controls\Source\TntMenus.pas</pre><pre>Internal Error: SyncHotKeyPosition Failed ("%s" <> "%s").</pre><pre>ESQLiteException</pre><pre>TSQLiteDatabase</pre><pre>TSQLiteTable</pre><pre>Failed to open database "%s" : %s</pre><pre>Failed to open database "%s" : unknown error</pre><pre>"%s" : %s</pre><pre>Error executing SQL</pre><pre>Could not prepare SQL statement</pre><pre>Error executing SQL statement</pre><pre>SQLite is Busy</pre><pre><%s> invalid zipfile</%s></pre><pre>Shell.Application</pre><pre><%s> invalid source</%s></pre><pre><%s> invalid target folder</%s></pre><pre>3333333</pre><pre>hKeY</pre><pre>getservbyport</pre><pre>WSAAsyncGetServByPort</pre><pre>WSAJoinLeaf</pre><pre>WS2_32.DLL</pre><pre>127.0.0.1</pre><pre>TIdSocketListWindows</pre><pre>TIdStackWindowsU</pre><pre>IdStackWindows</pre><pre>%s, %.2d %s %.4d %s %s</pre><pre>%s, %d %s %d %s %s</pre><pre>.aiff=audio/x-aiff</pre><pre>.au=audio/basic</pre><pre>.mid=midi/mid</pre><pre>.mp3=audio/x-mpg</pre><pre>.m3u=audio/x-mpegurl</pre><pre>.qcp=audio/vnd.qcelp</pre><pre>.ra=audio/x-realaudio</pre><pre>.wav=audio/x-wav</pre><pre>.gsm=audio/x-gsm</pre><pre>.wax=audio/x-ms-wax</pre><pre>.wma=audio/x-ms-wma</pre><pre>.ram=audio/x-pn-realaudio</pre><pre>.mjf=audio/x-vnd.AudioExplosion.MjuiceMediaFile</pre><pre>.bmp=image/bmp</pre><pre>.gif=image/gif</pre><pre>.jpg=image/jpeg</pre><pre>.jpeg=image/jpeg</pre><pre>.jpe=image/jpeg</pre><pre>.pict=image/x-pict</pre><pre>.png=image/x-png</pre><pre>.svg=image/svg-xml</pre><pre>.tif=image/x-tiff</pre><pre>.rf=image/vnd.rn-realflash</pre><pre>.rp=image/vnd.rn-realpix</pre><pre>.ico=image/x-icon</pre><pre>.art=image/x-jg</pre><pre>.pntg=image/x-macpaint</pre><pre>.qtif=image/x-quicktime</pre><pre>.sgi=image/x-sgi</pre><pre>.targa=image/x-targa</pre><pre>.xbm=image/xbm</pre><pre>.psd=image/x-psd</pre><pre>.pnm=image/x-portable-anymap</pre><pre>.pbm=image/x-portable-bitmap</pre><pre>.pgm=image/x-portable-graymap</pre><pre>.ppm=image/x-portable-pixmap</pre><pre>.rgb=image/x-rgb</pre><pre>.xbm=image/x-xbitmap</pre><pre>.xpm=image/x-xpixmap</pre><pre>.xwd=image/x-xwindowdump</pre><pre>.xml=text/xml</pre><pre>.uls=text/iuls</pre><pre>.txt=text/plain</pre><pre>.rtx=text/richtext</pre><pre>.wsc=text/scriptlet</pre><pre>.rt=text/vnd.rn-realtext</pre><pre>.htt=text/webviewhtml</pre><pre>.htc=text/x-component</pre><pre>.vcf=text/x-vcard</pre><pre>.avi=video/x-msvideo</pre><pre>.flc=video/flc</pre><pre>.mpeg=video/x-mpeg2a</pre><pre>.mov=video/quicktime</pre><pre>.rv=video/vnd.rn-realvideo</pre><pre>.ivf=video/x-ivf</pre><pre>.wm=video/x-ms-wm</pre><pre>.wmp=video/x-ms-wmp</pre><pre>.wmv=video/x-ms-wmv</pre><pre>.wmx=video/x-ms-wmx</pre><pre>.wvx=video/x-ms-wvx</pre><pre>.rms=video/vnd.rn-realvideo-secure</pre><pre>.asx=video/x-ms-asf-plugin</pre><pre>.movie=video/x-sgi-movie</pre><pre>.wmd=application/x-ms-wmd</pre><pre>.wms=application/x-ms-wms</pre><pre>.wmz=application/x-ms-wmz</pre><pre>.p7b=application/x-pkcs7-certificates</pre><pre>.p7r=application/x-pkcs7-certreqresp</pre><pre>.qtl=application/x-quicktimeplayer</pre><pre>.rtsp=application/x-rtsp</pre><pre>.swf=application/x-shockwave-flash</pre><pre>.sit=application/x-stuffit</pre><pre>.tar=application/x-tar</pre><pre>.man=application/x-troff-man</pre><pre>.urls=application/x-url-list</pre><pre>.zip=application/x-zip-compressed</pre><pre>.cdf=application/x-cdf</pre><pre>.fml=application/x-file-mirror-list</pre><pre>.fif=application/fractals</pre><pre>.spl=application/futuresplash</pre><pre>.hta=application/hta</pre><pre>.hqx=application/mac-binhex40</pre><pre>.doc=application/msword</pre><pre>.pdf=application/pdf</pre><pre>.cer=application/x-x509-ca-cert</pre><pre>.crl=application/pkix-crl</pre><pre>.ps=application/postscript</pre><pre>.sdp=application/x-sdp</pre><pre>.setpay=application/set-payment-initiation</pre><pre>.setreg=application/set-registration-initiation</pre><pre>.smil=application/smil</pre><pre>.ssm=application/streamingmedia</pre><pre>.xfdf=application/vnd.adobe.xfdf</pre><pre>.fdf=application/vnd.fdf</pre><pre>.xls=application/x-msexcel</pre><pre>.sst=application/vnd.ms-pki.certstore</pre><pre>.pko=application/vnd.ms-pki.pko</pre><pre>.cat=application/vnd.ms-pki.seccat</pre><pre>.stl=application/vnd.ms-pki.stl</pre><pre>.rmf=application/vnd.rmf</pre><pre>.rm=application/vnd.rn-realmedia</pre><pre>.rnx=application/vnd.rn-realplayer</pre><pre>.rjs=application/vnd.rn-realsystem-rjs</pre><pre>.rmx=application/vnd.rn-realsystem-rmx</pre><pre>.rmp=application/vnd.rn-rn_music_package</pre><pre>.rsml=application/vnd.rn-rsml</pre><pre>.vsl=application/x-cnet-vsl</pre><pre>.tgz=application/x-compressed</pre><pre>.dir=application/x-director</pre><pre>.gz=application/x-gzip</pre><pre>.uin=application/x-icq</pre><pre>.hpf=application/x-icq-hpf</pre><pre>.pnq=application/x-icq-pnq</pre><pre>.scm=application/x-icq-scm</pre><pre>.ins=application/x-internet-signup</pre><pre>.iii=application/x-iphone</pre><pre>.latex=application/x-latex</pre><pre>.nix=application/x-mix-transfer</pre><pre>.wbmp=image/vnd.wap.wbmp</pre><pre>.wml=text/vnd.wap.wml</pre><pre>.wmlc=application/vnd.wap.wmlc</pre><pre>.wmls=text/vnd.wap.wmlscript</pre><pre>.wmlsc=application/vnd.wap.wmlscriptc</pre><pre>.css=text/css</pre><pre>.htm=text/html</pre><pre>.html=text/html</pre><pre>.shtml=server-parsed-html</pre><pre>.sgm=text/sgml</pre><pre>.sgml=text/sgml</pre><pre>ftpTransfer</pre><pre>ftpReady</pre><pre>ftpAborted</pre><pre>ClientPortMinl</pre><pre>ClientPortMax</pre><pre>Port</pre><pre>EIdCanNotBindPortInRange</pre><pre>EIdInvalidPortRangeSVW</pre><pre>saUsernamePassword</pre><pre>Passwordl</pre><pre>0.0.0.1</pre><pre>TIdTCPStream</pre><pre>End of stream: %s at %d</pre><pre>TIdTCPConnection</pre><pre>TIdTCPConnection`</pre><pre>IdTCPConnection</pre><pre>EIdTCPConnectionError</pre><pre>EIdObjectTypeNotSupported</pre><pre>Password</pre><pre>IdHTTPHeaderInfo</pre><pre>ProxyPasswordl</pre><pre>ProxyPort</pre><pre>Mozilla/3.0 (compatible; Indy Library)</pre><pre>libeay32.dll</pre><pre>ssleay32.dll</pre><pre>SSL_CTX_use_PrivateKey_file</pre><pre>SSL_CTX_use_certificate_file</pre><pre>SSL_get_peer_certificate</pre><pre>SSL_CTX_set_default_passwd_cb</pre><pre>SSL_CTX_set_default_passwd_cb_userdata</pre><pre>SSL_CTX_check_private_key</pre><pre>X509_STORE_CTX_get_current_cert</pre><pre>des_set_key</pre><pre>sslvrfFailIfNoPeerCert</pre><pre>TPasswordEvent</pre><pre>Certificate</pre><pre>RootCertFile</pre><pre>CertFile</pre><pre>KeyFile</pre><pre>OnGetPassword0b[</pre><pre>EIdOSSLLoadingRootCertErrortl[</pre><pre>EIdOSSLLoadingCertError</pre><pre>EIdOSSLLoadingKeyError</pre><pre>TIdTCPClient</pre><pre>TIdTCPClientH</pre><pre>IdTCPClient</pre><pre>BoundPort</pre><pre>PortU</pre><pre>CommentURL</pre><pre>Unsupported operation.</pre><pre>Content-Disposition: form-data; name="%s"; filename="%s"</pre><pre>Content-Type: %s</pre><pre>Content-Disposition: form-data; name="%s"</pre><pre>TIdHTTPMethod</pre><pre>IdHTTP</pre><pre>TIdHTTPOption</pre><pre>TIdHTTPOptions</pre><pre>TIdHTTPProtocolVersion</pre><pre>IdHTTP|</pre><pre>TIdHTTPOnHeadersAvailable</pre><pre>TIdHTTPOnRedirectEvent</pre><pre>TIdHTTPResponse</pre><pre>TIdHTTPRequest</pre><pre>TIdHTTPRequesth</pre><pre>TIdHTTPProtocol|</pre><pre>TIdCustomHTTP</pre><pre>TIdCustomHTTP|</pre><pre>TIdHTTPd</pre><pre>TIdHTTP</pre><pre>HTTPOptionsx</pre><pre>PortX</pre><pre>EIdHTTPProtocolException</pre><pre>HTTPS</pre><pre>https</pre><pre>This request method is supported in HTTP 1.1</pre><pre>HTTP/1.0 200 OK</pre><pre>HTTP/</pre><pre>TMonochromeLookup</pre><pre>SetupApi.dll</pre><pre>SetupDiOpenClassRegKey</pre><pre>SetupDiOpenClassRegKeyExA</pre><pre>SetupDiOpenClassRegKeyExW</pre><pre>SetupDiCreateDeviceInterfaceRegKeyA</pre><pre>SetupDiCreateDeviceInterfaceRegKeyW</pre><pre>SetupDiOpenDeviceInterfaceRegKey</pre><pre>SetupDiDeleteDeviceInterfaceRegKey</pre><pre>SetupDiCreateDevRegKeyA</pre><pre>SetupDiCreateDevRegKeyW</pre><pre>SetupDiOpenDevRegKey</pre><pre>SetupDiDeleteDevRegKey</pre><pre>cfgmgr32.dll</pre><pre>CM_Delete_Class_Key</pre><pre>CM_Delete_Class_Key_Ex</pre><pre>CM_Delete_DevNode_Key</pre><pre>CM_Delete_DevNode_Key_Ex</pre><pre>CM_Get_Class_Key_NameA</pre><pre>CM_Get_Class_Key_NameW</pre><pre>CM_Get_Class_Key_Name_ExA</pre><pre>CM_Get_Class_Key_Name_ExW</pre><pre>CM_Open_Class_KeyA</pre><pre>CM_Open_Class_KeyW</pre><pre>CM_Open_Class_Key_ExA</pre><pre>CM_Open_Class_Key_ExW</pre><pre>CM_Open_DevNode_Key</pre><pre>CM_Open_DevNode_Key_Ex</pre><pre>7z.dll</pre><pre>Error loading library %s</pre><pre>%s is not a 7z library</pre><pre>%s is not a Format library</pre><pre>PSAPI.dll</pre><pre>Common.LoggerWindow</pre><pre>_prev.log</pre><pre>DriverUpdater.dpr</pre><pre>Common.Logger</pre><pre>c:\debug.pc</pre><pre>ERROR (%s): %s</pre><pre>MESS: %s</pre><pre>PARAMS: %s</pre><pre>LAST_ERR (%d -> %s): %s</pre><pre>LAST_ERR (%d, %s): %s</pre><pre>%s%s%s%s</pre><pre>%s: %s</pre><pre>%s: %s PARAMS: %s</pre><pre>program.log</pre><pre>program_error.log</pre><pre>Multiple errors: %s Count: %d</pre><pre>Multiple logs: %s Count: %d</pre><pre>%s %s</pre><pre>XLog.Execute</pre><pre>IsThereVisibleWindows</pre><pre>XSettings.GetDebugPrivilege</pre><pre>XProcess.IsWow64Process</pre><pre>XFile.LogicalDriveStringsInit</pre><pre>XFile.ExpandRawPath</pre><pre>Psapi.dll</pre><pre>XProcess.GetProcessStartTime</pre><pre>XFile.DeleteFolder</pre><pre>SHFileOperation fail:</pre><pre>CERTANCE</pre><pre>%d.%d.%d.%d</pre><pre>Setupapi.dll</pre><pre>CM_PROB_DRIVER_SERVICE_KEY_INVALID</pre><pre>CM_DEVCAP_LOCKSUPPORTED</pre><pre>CM_DEVCAP_EJECTSUPPORTED</pre><pre>FILE_CHARACTERISTIC_WEBDAV_DEVICE</pre><pre>DNF_INDEXED_DRIVER</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSettings\</pre><pre>DriverKey=</pre><pre>OpenKey fail</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion</pre><pre>EnumKey</pre><pre>ClassKey</pre><pre>0.0.0.0</pre><pre>DevWebSite</pre><pre>OpenKeyReadOnly 3 fail</pre><pre>OpenKeyReadOnly 3 fail</pre><pre>OpenKeyReadOnly 2 fail</pre><pre>OpenKeyReadOnly 2 fail</pre><pre>{8ECC055D-047F-11D1-A537-0000F8753ED1}</pre><pre>5.2.3790.</pre><pre>5.1.2600.</pre><pre>6.0.6000.</pre><pre>6.0.6001.</pre><pre>6.0.6002.</pre><pre>6.1.6002.</pre><pre>6.1.7100.</pre><pre>6.1.7600.</pre><pre>6.1.7601.</pre><pre>6.2.8400.</pre><pre>6.2.9200.</pre><pre>6.3.9600.</pre><pre>6.3.9431.</pre><pre>EnumKey=</pre><pre>SELECT * FROM hardids JOIN drivers ON hardids.id = drivers.hardid_full_index JOIN files ON files.id = drivers.file_id JOIN vendors ON vendors.id = drivers.vendor_id JOIN versions ON versions.id = drivers.version_id LEFT JOIN installers ON installers.id = drivers.installer_id JOIN devices_descriptions ON devices_descriptions.id = drivers.device_id WHERE hardids.hardid = "%s"</pre><pre>SELECT * FROM hardids JOIN drivers ON hardids.id = drivers.hardid_index JOIN files ON files.id = drivers.file_id JOIN vendors ON vendors.id = drivers.vendor_id JOIN versions ON versions.id = drivers.version_id LEFT JOIN installers ON installers.id = drivers.installer_id JOIN devices_descriptions ON devices_descriptions.id = drivers.device_id WHERE hardids.hardid = "%s"</pre><pre>AND os=%s</pre><pre>Drivers64.db</pre><pre>Drivers32.db</pre><pre>Devices.ini</pre><pre>DevicesPlus.ini</pre><pre>Cannot delete and rename DevicesPlus.ini file</pre><pre>Scan.ini</pre><pre>Cannot delete and rename Scan.ini file</pre><pre>D:\SmartPC\#Core\WbemScripting_TLB.pas</pre><pre>DefaultInterface is NULL. Component is not connected to Server. You must call 'Connect' or 'ConnectTo' before this operation</pre><pre>Common.RestorePointLz_</pre><pre>Common.RestorePoint</pre><pre>TSWbemLocator.Create fail</pre><pre>EOleException %s %x</pre><pre>wmiLocator.ConnectServer fail</pre><pre>wmiLocator.ConnectServer 2 fail</pre><pre>%s%s%s%s%s%s</pre><pre>%s%s%s</pre><pre>%s%s%s%s%s%s%s%s</pre><pre>TSchedulerStartupRegularItem.ItemRead</pre><pre>SrClient.dll</pre><pre>service.smartpcupdate.com</pre><pre>http://service.smartpcupdate.com/rpc/senddriverstats</pre><pre>TUploadThread.Execute</pre><pre>GetCurrentSnapshot.FindDevice fail:</pre><pre>Temp.ini</pre><pre>GetCurrentSnapshot.GetDriverParameters fail:</pre><pre>Windows=</pre><pre>Devices.Count = 0</pre><pre>setupapi.log</pre><pre>Inf\setupapi.app.log</pre><pre>Inf\setupapi.dev.log</pre><pre>C:\Intel\Logs\IntelChipset.log</pre><pre>explorer.exe</pre><pre>firefox.exe</pre><pre>chrome.exe</pre><pre>iexplore.exe</pre><pre>opera.exe</pre><pre>WaitForChildProcessesEx.IsThereAnyChild</pre><pre>No visible windows</pre><pre>There are visible windows:</pre><pre>ShellExecuteAndWait: begin: Path=</pre><pre>ShellExecuteAndWait: GetProcessId fail:</pre><pre>ShellExecuteAndWait: lpExecInfo.hProcess = 0:</pre><pre>ShellExecuteAndWait: ShellExecuteEx fail:</pre><pre>readme.txt</pre><pre>installmanagerapp.exe</pre><pre>InstallExeOrMsiDriver: begin: FName=</pre><pre>InstallExeOrMsiDriver: File not found:</pre><pre>InstallExeOrMsiDriver: Install disabled:</pre><pre>msiexec.exe</pre><pre>autorun.exe</pre><pre>InstallExeOrMsiDriver: CreateProcessAndWait failed</pre><pre>InstallExeOrMsiDriver: ShellExecuteAndWait failed</pre><pre>stub64.exe</pre><pre>newdev.dll</pre><pre>advpack.dll</pre><pre>IncompatibleWindowsLogoError</pre><pre>NonSupportedMethod</pre><pre>rundll32.exe</pre><pre>advpack.dll,LaunchINFSectionEx "</pre><pre>InstallInfDriver: Direct install advpack.dll,LaunchINFSectionEx success, for</pre><pre>InstallInfDriver: Direct install advpack.dll,LaunchINFSectionEx success but nothing changed, for</pre><pre>InfDefaultInstall.exe</pre><pre>.status</pre><pre>isInstalling exe/msi from zip: Cancelled</pre><pre>isInstalling exe/msi: Cancelled</pre><pre>empty EnumKey field</pre><pre>Restart of Windows detected</pre><pre>CreateBaseIndexes</pre><pre>*.dul</pre><pre>report.zip</pre><pre>TGenerateThread.Execute</pre><pre>TInstallThread.Execute</pre><pre>http://www.pcutilitiespro.com</pre><pre>pcspeedmaximizer.exe</pre><pre>PC Speed Maximizer\PCSpeedMaximizer.exe</pre><pre>PC Speed Maximizer Pro\PCSpeedMaximizerPro.exe</pre><pre>HomePageURL</pre><pre>AfterInstallURL</pre><pre>SupportURL</pre><pre>BuyNowURL</pre><pre>AdsDownloadURL</pre><pre>AdsBuyNowURL</pre><pre>https://safecart.com/pcutilitiespro/.driverpro</pre><pre>http://support.pcutilitiespro.com</pre><pre>http://dejebel.pcutilitiespro.revenuewire.net/optimizerpro/xsell</pre><pre>http://filecdn.avanquest.com/rw/xsell/pcutilitiespro/dejebel/OptimizerPro.exe</pre><pre>optimizerpro.exe</pre><pre>Optimizer Pro\OptimizerPro.exe</pre><pre>EInvalidGridOperation</pre><pre>goAlwaysShowEditor</pre><pre>doKeyColFixed</pre><pre>TKeyOption</pre><pre>keyEdit</pre><pre>keyAdd</pre><pre>keyDelete</pre><pre>keyUnique</pre><pre>TKeyOptions</pre><pre>KeyName</pre><pre>KeyValue</pre><pre>KeyOptions</pre><pre>KeyDescl</pre><pre>%s=%s</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Settings\Driver Pro</pre><pre>PCInfo.ini</pre><pre>FormKeyDown</pre><pre>http://service.smartpcupdate.com/rpc/sendspmpurchase</pre><pre>http://service.smartpcupdate.com/rpc/sendpurchase</pre><pre>&key=</pre><pre>http://service.smartpcupdate.com/rpc/sendspminstall</pre><pre>http://service.smartpcupdate.com/rpc/sendspmuninstall</pre><pre>http://service.smartpcupdate.com/rpc/sendinstall</pre><pre>http://service.smartpcupdate.com/rpc/senduninstall</pre><pre>IdHTTP10</pre><pre>Do you have a License Key?</pre><pre>If you already have a License Key, please enter it in the form below and click "Activate Now".</pre><pre>License key</pre><pre>Do you need a License Key?</pre><pre>We recommend that you upgrade to the full version of %s</pre><pre>To purchase %s and obtain a license key click</pre><pre>Licensing key has reached its usage limit!</pre><pre>LicenseKey</pre><pre>Thank you for registering %s!</pre><pre>Register %s now to download and install new drivers.</pre><pre>Would you like to register %s?</pre><pre>Current Windows version</pre><pre>Backuped driver Windows version</pre><pre>We NOT reccomend your use this driver for current Windows version.</pre><pre>5 (Windows XP)</pre><pre>6 (Windows Vista)</pre><pre>7 (Windows 7)</pre><pre>8 (Windows 8)</pre><pre>IdHTTP18</pre><pre>HTTPWorkBegin</pre><pre>HTTPWork</pre><pre>HTTPWorkEnd</pre><pre>ProxyLogin</pre><pre>ProxyPassword</pre><pre>http://service.smartpcupdate.com/rpc/getdatabasecxw?arch=%d&os=%d</pre><pre>http://service.smartpcupdate.com/rpc/getdatabasex%d_wd</pre><pre>Drivers32prev.db</pre><pre>Drivers64prev.db</pre><pre>Drivers.db</pre><pre>SetupFiles.txt</pre><pre>%s <%s></%s></pre><pre>=?WINDOWS</pre><pre>atLogin</pre><pre>IdSMTP</pre><pre>TIdSMTP</pre><pre>LOGIN</pre><pre>IdSMTP1<</pre><pre>Report a problem with a new driver!</pre><pre>mail.smartpctools.com</pre><pre>apps@smartpctools.com</pre><pre>support@smartpctools.com</pre><pre>IdHTTP1</pre><pre>Thank you for trying %s!</pre><pre>Your feedback is very valuable and will help us create better products. Please let us know why you did not register %s:</pre><pre>%s did not find the driver I was looking for</pre><pre>http://service.smartpcupdate.com/rpc/feedback?reason=</pre><pre>Keyboard</pre><pre>Ports</pre><pre>MultiPortSerial</pre><pre>SELECT * FROM drivers WHERE hardid="%s"</pre><pre>Devices-ng.ini</pre><pre>d2.smartpcupdate.com</pre><pre>http://d2.smartpcupdate.com/rpc/send_ini</pre><pre>Snapshot.ini</pre><pre>http://d2.smartpcupdate.com/rpc/sendsnapshot</pre><pre>IdHTTP0</pre><pre>IdHTTP11</pre><pre>HTTP0Work</pre><pre>HTTP1Start</pre><pre>HTTP2Start</pre><pre>HTTP3Start</pre><pre>HTTP4Start</pre><pre>HTTP5Start</pre><pre>HTTP1Work</pre><pre>HTTP2Work</pre><pre>HTTP3Work</pre><pre>HTTP4Work</pre><pre>HTTP5Work</pre><pre>InstallExeDriver</pre><pre>update1.smartpcupdate.com</pre><pre>http://service.smartpcupdate.com/rpc/candownloadfiles?partner=</pre><pre>Windows</pre><pre>English.ini</pre><pre>French.ini</pre><pre>German.ini</pre><pre>Spanish.ini</pre><pre>Italian.ini</pre><pre>Portuguese.ini</pre><pre>Danish.ini</pre><pre>Dutch.ini</pre><pre>Swedish.ini</pre><pre>Polish.ini</pre><pre>Russian.ini</pre><pre>Brazilian.ini</pre><pre>Finnish.ini</pre><pre>Norwegian.ini</pre><pre>Japanese.ini</pre><pre>Chinese.ini</pre><pre>Czech.ini</pre><pre>Arabic.ini</pre><pre>UninstallURL</pre><pre>Welcome to %s</pre><pre>%s found</pre><pre>On Exit send %s to the system tray</pre><pre>Login</pre><pre>Product information and support link</pre><pre>Support</pre><pre>InstallLog.ini</pre><pre>UpdateWindowShown</pre><pre>Backups.ini</pre><pre>Schedule.exe</pre><pre>Software\Microsoft\Windows\CurrentVersion\Settings\</pre><pre>UserKey</pre><pre>TForm1a.WMQueryEndSession</pre><pre>Vendors.txt</pre><pre>ScanExecuted</pre><pre>http://</pre><pre>\Scan.gif</pre><pre>TForm1a.Callback: incorrect Status</pre><pre>Exclusions.txt</pre><pre>1.0.0.0</pre><pre>%d new drivers in %d driver packages found for your computer</pre><pre>http://update1.smartpcupdate.com/rpc/getlastupdate</pre><pre>http://service.smartpcupdate.com/rpc/getstatus?exedate=</pre><pre>http://update1.smartpcupdate.com/rpc/sendinstall?partner=</pre><pre>http://update1.smartpcupdate.com/rpc/sendreport?filename=</pre><pre>http://update1.smartpcupdate.com/rpc/sendstats?partner=</pre><pre>This version is no longer supported!</pre><pre>UpdateList.txt</pre><pre>SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore</pre><pre>http://www.google.com/search?hl=en&q=</pre><pre>.SYS.DLL.INF.CAT.NFO.EXE.REG.AX.DRV.CPL</pre><pre>RUNDLL32.EXE</pre><pre>LAYOUT.INF</pre><pre>regedit.exe</pre><pre>\Enum.reg" "HKEY_LOCAL_MACHINE\</pre><pre>\Classes.reg" "HKEY_LOCAL_MACHINE\</pre><pre>\*.inf</pre><pre>\Log.txt</pre><pre>backups.ini</pre><pre>/s zipfldr.dll</pre><pre>regsvr32.exe</pre><pre>\.zip\CompressedFolder\ShellNew</pre><pre>\Classes.reg</pre><pre>\Classes.reg"</pre><pre>\Enum.reg</pre><pre>\Enum.reg"</pre><pre>*.exe</pre><pre>AUTORUN.EXE</pre><pre>32.EXE</pre><pre>64.EXE</pre><pre>*.inf</pre><pre>*.status</pre><pre>01-01-2012</pre><pre>TForm1a.InstallCallback</pre><pre>RunExe</pre><pre>TForm1a.HTTP1Start</pre><pre>http://service.smartpcupdate.com/downloads/</pre><pre>Form1a.HTTP1Start</pre><pre>TForm1a.HTTP2Start</pre><pre>Form1a.HTTP2Start</pre><pre>TForm1a.HTTP3Start</pre><pre>Form1a.HTTP3Start</pre><pre>TForm1a.HTTP4Start</pre><pre>Form1a.HTTP4Start</pre><pre>TForm1a.HTTP5Start</pre><pre>Form1a.HTTP5Start</pre><pre>s_Exec</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><pre>Launcher.exe</pre><pre>SmartScan.exe</pre><pre>Register %s</pre><pre>CreateBaseIndexes fail</pre><pre>6666666666666666</pre><pre>1.1.2</pre><pre>#!V!W!"!&!r%!%#%%%'%)%c%e%g%C%<!><pre>!"#$%&'()* ,-./0123456789:;<=>?</pre><pre>&'()* ,-./0123456789:;<=>?</pre><pre>GetKeyboardType</pre><pre>RegOpenKeyExA</pre><pre>RegCloseKey</pre><pre>RegQueryInfoKeyA</pre><pre>RegFlushKey</pre><pre>RegEnumKeyA</pre><pre>RegEnumKeyExA</pre><pre>RegCreateKeyExW</pre><pre>RegCreateKeyExA</pre><pre>GetWindowsDirectoryA</pre><pre>GetCPInfo</pre><pre>CreatePipe</pre><pre>version.dll</pre><pre>SetViewportOrgEx</pre><pre>SetViewportExtEx</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookExW</pre><pre>SetWindowsHookExA</pre><pre>SetKeyboardState</pre><pre>MsgWaitForMultipleObjects</pre><pre>MapVirtualKeyW</pre><pre>MapVirtualKeyA</pre><pre>LoadKeyboardLayoutA</pre><pre>GetKeyboardState</pre><pre>GetKeyboardLayoutList</pre><pre>GetKeyboardLayout</pre><pre>GetKeyState</pre><pre>GetKeyNameTextW</pre><pre>GetKeyNameTextA</pre><pre>GetAsyncKeyState</pre><pre>ExitWindowsEx</pre><pre>EnumWindows</pre><pre>EnumThreadWindows</pre><pre>ActivateKeyboardLayout</pre><pre>ShellExecuteExA</pre><pre>ShellExecuteA</pre><pre>SHFileOperationA</pre><pre>comdlg32.dll</pre><pre>wsock32.dll</pre><pre>oleacc.dll</pre><pre>sqlite3.dll</pre><pre>sqlite3_finalize</pre><pre>sqlite3_column_type</pre><pre>sqlite3_column_text</pre><pre>sqlite3_column_int</pre><pre>sqlite3_column_double</pre><pre>sqlite3_column_bytes</pre><pre>sqlite3_column_blob</pre><pre>sqlite3_step</pre><pre>sqlite3_column_decltype</pre><pre>sqlite3_column_name</pre><pre>sqlite3_column_count</pre><pre>sqlite3_prepare</pre><pre>sqlite3_free</pre><pre>sqlite3_errcode</pre><pre>sqlite3_errmsg</pre><pre>sqlite3_close</pre><pre>sqlite3_open</pre><pre>shfolder.dll</pre><pre>winmm.dll</pre><pre>MainProgram.exe</pre><pre>7,7<7><pre>:);/;7;`;</pre><pre>2&2.262>2`2</pre><pre>=(=>=`=$></pre><pre>=$=,=8=@=</pre><pre>8 828:8`8</pre><pre>?!?*?/?7?</pre><pre>7 8=8_8|8</pre><pre>1$1,181@1</pre><pre>?#?6?>?}?</pre><pre>/090_0{0</pre><pre>>!>%>)>->1>=></pre><pre>5T6i6:o:</pre><pre>5 5$5(5,505</pre><pre>4!4%4)4-41454o4}4</pre><pre>1-1I1S1c1i1}1</pre><pre>2$3/3=3}3</pre><pre>1"161[1~1</pre><pre>?#?'? ?/?3?</pre><pre>0u0</pre><pre>5S5S5p5</pre><pre>2 2$2(2,2</pre><pre>3D4d4</pre><pre><6>1>>></6></pre><pre>01</pre><pre>6 6$6(6,606</pre><pre>;-<1><pre>.02060<0><pre>2#3'3 303</pre><pre>3%4)4-41484</pre><pre>=0>4>8>@></pre><pre>6"6&6*606</pre><pre>#0'0 000</pre><pre>0%1)1-11181</pre><pre>43575;5@5</pre><pre>6,7074787<7><pre>= =$=(=,=</pre><pre>>!?%?)?-?4?</pre><pre>5&6*6.646</pre><pre>< <$<(<,<:><pre>1(1,1014181<1><pre>7 7$7(7,7074787<7><pre>5l6</pre><pre>607-8=8/9</pre><pre>< <$<(<,<0><pre>7 7$7(7,7074787<7><pre>2.2.3j3</pre><pre>:!:?:]:{:</pre><pre>< <$<(<6><pre>0 0$0(0,020</pre><pre>8 8$8(8,80848:8</pre><pre>= =-=5=<=</pre><pre>11s1</pre><pre>> >%><>]></pre><pre>666>6[6~6</pre><pre>0%1S1b1</pre><pre>2 2%2,2\2</pre><pre>:):2:9:>:</pre><pre>4 4$4(4,4044484<4><pre>7-7B7h7}7</pre><pre>>#><>_>~></pre><pre>5_5Q5[5j5{5</pre><pre>2)3.3[3`3</pre><pre>:!:,:4:9:|:</pre><pre>: :$:(:,:0:4:</pre><pre>333333333333333333</pre><pre>33333833</pre><pre>3333339</pre><pre>3333333333333338</pre><pre>:*"*"$3338</pre><pre>33333333</pre><pre>33333333333</pre><pre>3333333333338</pre><pre>33338?383</pre><pre>333333333333</pre><pre>:*3:"$3338</pre><pre>333333333333333</pre><pre>@000///1111*$&</pre><pre>Paint.NET v3.5.100</pre><pre>Paint.NET v3.5.11G</pre><pre>xyT%U</pre><pre>5F.VR</pre><pre>=UN.EN.</pre><pre>Wj.zY</pre><pre>}0(*.pw</pre><pre>pm%C\rlR</pre><pre>t%DMM</pre><pre>Pegg.UjF|jFbZzbj</pre><pre>%cPn:</pre><pre>7:5221>8=</pre><pre>gOÝe</pre><pre>%XzVSoMx</pre><pre> h.FG</pre><pre>t.ESZH'p</pre><pre>K.kf]Q</pre><pre>.Xpeg</pre><pre>r%SKI</pre><pre>H.uuu</pre><pre>.nl#]cS-</pre><pre>4IP%u</pre><pre>5;1% >)#6!-*6%<*14</pre><pre>{&#:%9.;</pre><pre>Q.tHJJ\</pre><pre>nmr.M2.Mb6</pre><pre>7-'7-&5.$5,&</pre><pre>|^}<^}\^</pre><pre>eeA%u</pre><pre>4/%7.&5,%</pre><pre>w.WMl</pre><pre>WG,.gr</pre><pre>@70".0*>2)#&9;6)'1</pre><pre>30,*<,>6>52-)"'>4#</pre><pre>2)!%1&%)1.!!</pre><pre>$KU%uM5</pre><pre>2214652</pre><pre>x~~avv.tU</pre><pre>.vqI18</pre><pre>k...ii)</pre><pre>KWindows</pre><pre>#IdSMTP</pre><pre>IdTCPStream</pre><pre>UrlMon</pre><pre>Driver.CoreInstall</pre><pre>}Common.Params</pre><pre>CCommon.Utils</pre><pre>eCommon.LoggerWindow</pre><pre>oDriver.Utils</pre><pre>Driver.CoreDevicesHelpers</pre><pre>SQLiteTable3</pre><pre>SQLite3</pre><pre>Driver.CoreResult</pre><pre>Driver.Core</pre><pre>]Driver.CoreDevices</pre><pre>0IdHTTPHeaderInfo</pre><pre> IdTCPServer</pre><pre>TntWindows</pre><pre>bDriver.CoreSnapshot</pre><pre>geacmd</pre><pre>.cCSmM]</pre><pre>d;%%%C</pre><pre>cg.Br</pre><pre>Font.Charset</pre><pre>Font.Color</pre><pre>Font.Height</pre><pre>Font.Name</pre><pre>Font.Style</pre><pre>All windows</pre><pre>%Select name, location and backup type</pre><pre>Items.Strings</pre><pre>%Driver backup successfully completed!</pre><pre>%Select the drivers you wish to backup</pre><pre>EditManager.Font.Charset</pre><pre>EditManager.Font.Color</pre><pre>EditManager.Font.Height</pre><pre>EditManager.Font.Name</pre><pre>EditManager.Font.Style</pre><pre>GroupFont.Charset</pre><pre>GroupFont.Color</pre><pre>GroupFont.Height</pre><pre>GroupFont.Name</pre><pre>GroupFont.Style</pre><pre>Header.Columns.Items</pre><pre>Header.Font.Charset</pre><pre>Header.Font.Color</pre><pre>Header.Font.Height</pre><pre>Header.Font.Name</pre><pre>Header.Font.Style</pre><pre>Header.Height</pre><pre>ImageList1)PaintInfoGroup.MarginBottom.CaptionIndent</pre><pre>Selection.FullRowSelect</pre><pre>$Product information and support link</pre><pre>Support:</pre><pre>Version: %s</pre><pre>%Save downloded drivers to this folder</pre><pre>"On Exit send %s to the system tray</pre><pre>Webcam drivers</pre><pre>Windows system drivers</pre><pre>Keyboard drivers</pre><pre>Picture.Data</pre><pre>Header.ShowInAllViews</pre><pre>Header.Visible</pre><pre>PaintInfoGroup.Expandable</pre><pre>)PaintInfoGroup.MarginBottom.CaptionIndent</pre><pre>Icon.Data</pre><pre>ProxyParams.BasicAuthentication</pre><pre>ProxyParams.ProxyPort</pre><pre>Request.ContentLength</pre><pre>Request.ContentRangeEnd</pre><pre>Request.ContentRangeStart</pre><pre>Request.ContentType</pre><pre>Request.Accept</pre><pre>Request.BasicAuthentication</pre><pre>Request.UserAgent</pre><pre>&Mozilla/3.0 (compatible; Indy Library)</pre><pre>HTTPOptions</pre><pre>.NN outdated drivers have been found on your PC</pre><pre>"Would you like to register %s now?</pre><pre>FTo immediately download and fix these drivers you need to register %s.</pre><pre>]If you already have a License Key, please enter it in the form below and click "Activate Now"</pre><pre>.To purchase %s and obtain a license key click</pre><pre>YCheck the email you received after you purchased the product for the correct license key.</pre><pre>&Your license key will look like this:</pre><pre>BWe NOT reccomend your use this driver for current Windows version.</pre><pre>Current Windows version:</pre><pre>Backuped driver Windows version:</pre><pre>"Report a problem with a new driver</pre><pre>IdSMTP1</pre><pre>xYour feedback is very valuable and will help us create better products. Please let us know why you did not register %s:</pre><pre>,%s did not find the driver I was looking for</pre><pre><assemblyIdentity version="1.0.0.0"><pre>name="program.exe"</pre><pre><requestedExecutionLevel><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" /></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" /></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" /></pre><pre>name="Microsoft.Windows.Common-Controls"</pre><pre>version="6.0.0.0"</pre><pre>publicKeyToken="6595b64144ccf1df"</pre><pre>.jdbg</pre><pre>madExcept.HandleContactForm</pre><pre>madExcept.HandleScreenshotForm</pre><pre>.madExcept</pre><pre>%exceptMsg%</pre><pre>%bugReport%</pre><pre>Úte%</pre><pre>Útetime%</pre><pre>%computerName%</pre><pre>Þsktop%</pre><pre>%userappdata%</pre><pre>%commonappdata%</pre><pre>screenShot.bmp</pre><pre>Tcpip\Parameters</pre><pre>VxD\MSTCP</pre><pre>.jpeg</pre><pre>https://</pre><pre>%userappdata%\</pre><pre>BugReport</pre><pre>screenShot.png</pre><pre>operating system</pre><pre><tr><td><button onClick="history.back();" style="height:19.5pt;"> </button></td></tr></pre><pre><button onClick="document.getElementById('bugReport').style.visibility='visible';this.style.visibility='hidden';" style="height:19.5pt;"> </button></pre><pre><textarea id="bugReport" readonly cols="80" rows="20" style="width:100%;height:100%;</pre><pre>Software\Microsoft\Windows</pre><pre>GetThreadReport</pre><pre>GetCpuRegisters</pre><pre>\madExcept\Dlls\madExcept32.dll</pre><pre>psapi.dll</pre><pre>suser32.dll</pre><pre>PIDLs to operate on are not siblings of the Namespace doing the operation.</pre><pre>Unable to find RegSvr32.exe executable.</pre><pre>RegSvr32.exe</pre><pre>Unspecified error (%d) from %s.</pre><pre>miranda32.exe</pre><pre>66006666</pre><pre>Unsupported PixelFormat</pre><pre>Invalid stream operation</pre><pre>Unsupported GIF version7Invalid number of colors specified in Screen Descriptor6Invalid number of colors specified in Image Descriptor</pre><pre>Invalid extension introducerúiled to allocate memory for GIF DIB</pre><pre>Invalid Image trailerAInternal error: Extension Instance does not match Extension Label,Unsupported Application Extension block size</pre><pre>Unknown GIF block type'Object type not supported for operation</pre><pre>Could not load certificate.#Could not load key, check password.</pre><pre>SSL status: " %s><pre>Protocol family not supported.0Address family not supported by protocol family.</pre><pre>DThis authentication method is already registered with class name %s.</pre><pre>%s is not a valid service.</pre><pre>Socket Error # %d</pre><pre>%s is not a valid IP address.</pre><pre>Operation would block.</pre><pre>Operation now in progress.</pre><pre>Operation already in progress.</pre><pre>Socket operation on non-socket.</pre><pre>&Error on loading Winsock2 library (%s)</pre><pre>Resolving hostname %s.</pre><pre>Connecting to %s.</pre><pre>File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed</pre><pre>Object type not supported.</pre><pre>No data to read.$Can not bind in port range (%d - %d)</pre><pre>Invalid Port Range (%d - %d)</pre><pre>@ Outside address*Error on call Winsock2 library function %s</pre><pre>Bogus JPEG tables field.%Fractional JPEG scanline unsupported.</pre><pre>Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.</pre><pre>Stream read error in %s file.1Cannot load image. %s not supported for %s files..Cannot load image. CRC error found in %s file.6Cannot load image. Compression error found in %s file.:Cannot load image. Extra compressed data found in %s file.1Cannot load image. Palette in %s file is invalid.>Cannot load PNG image. Unexpected but critical chunk detected.</pre><pre>The compression scheme isJConversion between indexed and non-indexed pixel formats is not supported.8Color conversion failed. Could not find a proper method.AColor depth is invalid. Bits per sample must be 1, 2, 4, 8 or 16.ESample count per pixel does not correspond to the given color scheme.5Subsampling value is invalid. Allowed are 1, 2 and 4.CVertical subsampling value must be <= horizontal subsampling value.</pre><pre>Portable map images</pre><pre>Portable pixel map images</pre><pre>Portable gray map images</pre><pre>Portable bitmap images</pre><pre>Portable network graphic images9Cannot load image. Invalid or unexpected %s image format. Invalid color format in %s file.</pre><pre>Windows icons</pre><pre>Windows metafiles</pre><pre>Windows enhanced meta files</pre><pre>Attempt to register %s twice.</pre><pre>Windows bitmaps"Run length encoded Windows bitmaps"Device independant Windows bitmaps</pre><pre>JPEG error #%d</pre><pre>#Failed to set calendar date or timeúiled to set maximum selection range$Failed to set calendar min/max rangeúiled to set calendar selected range</pre><pre>OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters</pre><pre>OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s</pre><pre>No help keyword specified.</pre><pre>RichEdit line insertion error=This control requires version 4.70 or greater of COMCTL32.DLL</pre><pre>Date exceeds maximum of %s</pre><pre>Date is less than minimum of %s4You must be in ShowCheckbox mode to set to this date</pre><pre>Key "%s" not found%goColMoving is not a supported option%Key may not contain equals sign ("=")</pre><pre>Error setting %s.Count8Listbox (%s) style must be virtual in order to set Count#No OnGetItem event handler assigned"Unable to find a Table of Contents</pre><pre>No help found for %s#No context-sensitive help installed$No topic-based help system installed</pre><pre>Value must be between %d and %d</pre><pre>Invalid clipboard format Clipboard does not support Icons</pre><pre>Text exceeds memo capacity/Menu '%s' is already being used by another form</pre><pre>Value*A key with the name of "%s" already exists</pre><pre>Invalid input value7Invalid input value. Use escape key to abandon changes</pre><pre>Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window</pre><pre>Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic</pre><pre>Unsupported clipboard format</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to get data for '%s'</pre><pre>Failed to set data for '%s'</pre><pre>Resource %s not found</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list Too many rows or columns deleted$%s not in a class registration group</pre><pre>Property %s does not exist</pre><pre>Thread creation error: %s</pre><pre>Thread Error: %s (%d)</pre><pre>?#''%s'' is not a valid date and time</pre><pre>Cannot open file "%s". %s</pre><pre>Grid too large for operation</pre><pre>Unable to write to %s</pre><pre>Invalid stream format$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>List count out of bounds (%d)</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread</pre><pre>Class %s not found</pre><pre>A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Cannot create file "%s". %s</pre><pre>Operation not supported</pre><pre>External exception %x</pre><pre>Interface not supported</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>(Exception %s in module %s at %p.</pre><pre>Application Error1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'"Variant method calls not supported</pre><pre>Invalid variant operation</pre><pre>Invalid NULL variant operation%Invalid variant operation (%s%.8x)</pre><pre>%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)</pre><pre>Integer overflow Invalid floating point operation</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Operation aborted</pre><pre>!'%s' is not a valid integer value('%s' is not a valid floating point value</pre><pre>'%s' is not a valid date</pre><pre>'%s' is not a valid time!'%s' is not a valid date and time</pre><pre>'%s' is not a valid GUID value</pre><pre>I/O error %d</pre><pre>3.1.0.5</pre></textarea></pre></requestedExecutionLevel></pre></assemblyIdentity></pre></4></pre></6></pre></7></pre></0></pre></7></pre></1></pre></:></pre></7></pre></0></pre></1></pre></7></pre></!></pre></pre></pre></ns1:></SOAP-ENV:Body></SOAP-ENV:Envelope>