• Stay aware

    Inquietari sueti praenturis et stationibus servabantur agrariis

  • How to get the best

    Inquietari sueti praenturis et stationibus servabantur agrariis

  • Help us

    Inquietari sueti praenturis et stationibus servabantur agrariis

  • Forum

    Inquietari sueti praenturis et stationibus servabantur agrariis

Mon, 03/20/2017 - 04:08

Trojan.NSIS.StartPage_431ce28a13

not-a-virus:AdWare.Win32.OpenCandy.aq (Kaspersky), Trojan.NSIS.StartPage.FD, Trojan.Win32.BHO.FD, Trojan.Win32.Ransom.FD, Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS) Behaviour: Ransom, Trojan, Adware

The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

Summary

MD5: 431ce28a13c102f094e0ddd1e6c8a023

SHA1: c0ac53c76f25a1c4adb02360b998e2de163f8aa9

SHA256: fb7933db75604bfe00dc9e2dd533e122f350e39fa29c23a1e26905b69f7519fe

SSDeep: 393216:8VylAQ4kOJxPVtDn3Xej2NjLMs2MqdWTkXr0kIHGbZ:8glApjPv6aNKWgXdIw

Size: 12732963 bytes

File type: EXE

Platform: WIN32

Entropy: Packed

PEID: UPolyXv05_v6

Company: no certificate found

Created at: 2011-05-28 19:04:29

Analyzed on: Windows7 SP1 32-bit

Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Dynamic Analysis

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

DAEMONLite4.41.exe:3616
sidebar.exe:1808
%original file name%.exe:1796
rundll32.exe:3972
DrvInst.exe:2628
DrvInst.exe:3532
DrvInst.exe:4052
SetupHelper.exe:2904
regsvr32.exe:1428

The Trojan injects its code into the following process(es):

DT_free_Rus_YandexBar1022.exe:2792
DTLite4413-0173.exe:1672
irsetup.exe:2296

Mutexes

The following mutexes were created/opened: No objects were found.

File activity

The process DAEMONLite4.41.exe:3616 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)

The process %original file name%.exe:1796 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\เครดิต.txt (133 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_337648 (0 bytes)

The process DrvInst.exe:2628 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Windows\inf\setupapi.dev.log (478 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Windows\Temp\Tar4716.tmp (2712 bytes)
C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
C:\Windows\Temp\Tar4659.tmp (2712 bytes)
C:\Windows\Temp\Tar4598.tmp (2712 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab45E7.tmp (48 bytes)
C:\Windows\Temp\Tar4628.tmp (2712 bytes)
C:\Windows\Temp\Cab4658.tmp (48 bytes)
C:\Windows\Temp\Cab4627.tmp (48 bytes)
C:\Windows\Temp\Cab4715.tmp (48 bytes)
C:\Windows\inf\oem10.PNF (7501 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
C:\Windows\Temp\Cab4597.tmp (48 bytes)

The Trojan deletes the following file(s):

C:\Windows\Temp\Tar4716.tmp (0 bytes)
C:\Windows\Temp\Tar45E8.tmp (0 bytes)
C:\Windows\Temp\Tar4659.tmp (0 bytes)
C:\Windows\Temp\Tar4598.tmp (0 bytes)
C:\Windows\Temp\Cab45E7.tmp (0 bytes)
C:\Windows\Temp\Tar4628.tmp (0 bytes)
C:\Windows\Temp\Cab4658.tmp (0 bytes)
C:\Windows\Temp\Cab4627.tmp (0 bytes)
C:\Windows\Temp\Cab4715.tmp (0 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (0 bytes)
C:\Windows\Temp\Cab4597.tmp (0 bytes)

The process DrvInst.exe:3532 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
C:\Windows\System32\DriverStore\infpub.dat (252 bytes)
C:\Windows\Temp\Tar415A.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
C:\Windows\Temp\Tar4127.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (4 bytes)
C:\Windows\Temp\Tar417B.tmp (2712 bytes)
C:\Windows\inf\oem10.inf (1 bytes)
C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
C:\Windows\Temp\Tar4139.tmp (2712 bytes)
C:\Windows\Temp\Cab417A.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab4138.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
C:\Windows\Temp\Cab4126.tmp (48 bytes)
C:\Windows\Temp\Cab40C7.tmp (48 bytes)
C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
C:\Windows\Temp\Cab4159.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)

The Trojan deletes the following file(s):

C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (0 bytes)
C:\Windows\Temp\Tar415A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (0 bytes)
C:\Windows\Temp\Tar4127.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (0 bytes)
C:\Windows\Temp\Tar417B.tmp (0 bytes)
C:\Windows\Temp\Tar4139.tmp (0 bytes)
C:\Windows\Temp\Cab417A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.sys (0 bytes)
C:\Windows\Temp\Cab4138.tmp (0 bytes)
C:\Windows\Temp\Cab4126.tmp (0 bytes)
C:\Windows\Temp\Cab40C7.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.inf (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.cat (0 bytes)
C:\Windows\Temp\Tar40C8.tmp (0 bytes)
C:\Windows\Temp\Cab4159.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (0 bytes)

The process DrvInst.exe:4052 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Windows\inf\setupapi.dev.log (2324 bytes)

The process DTLite4413-0173.exe:1672 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
%Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
%Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
%Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (844 bytes)
%Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
%Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
%Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
%Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
%Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
%Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
%Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
%Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
%Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.sys (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.inf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.cat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (0 bytes)

The process irsetup.exe:2296 makes changes in the file system.


The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (0 bytes)

Registry activity

The process DAEMONLite4.41.exe:3616 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process sidebar.exe:1808 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings]
"ShowGadgets" = "1"

The process %original file name%.exe:1796 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process rundll32.exe:3972 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process DrvInst.exe:2628 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Security" = "01 00 04 90 00 00 00 00 00 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"dtsoftbus01.sys" = "5"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"ClassGUID" = "{4d36e97d-e325-11ce-bfc1-08002be10318}"

[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI Miniport" = "42 00 00 00 00 01 00 00 01 01 00 00 19 00 00 00"

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Service" = "dtsoftbus01"
"DeviceCharacteristics" = "256"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Exclusive"
"DeviceType"
"LowerFilters"
"UpperFilters"

The process DrvInst.exe:3532 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD]
"Blob" = "0F 00 00 00 01 00 00 00 20 00 00 00 52 29 BA 15"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"D69B561148F01C77C54578C10926DF5B856976AD"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"

The process DrvInst.exe:4052 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultRequestFlags" = "8"

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDAAccurate" = "1"

[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"TypesSupported" = "7"

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDASupported" = "1"

[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI CDROM Class" = "03 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"cdrom.sys" = "1"

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"SettingsFromDevice" = "1"

[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"EventMessageFile" = "%SystemRoot%\System32\IoLogMsg.dll"

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"ClassGUID" = "{4d36e965-e325-11ce-bfc1-08002be10318}"
"Service" = "cdrom"

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultDvdRegion" = "1"

[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"ReadSizesSupported" = "4294967295"

The Trojan deletes the following value(s) in system registry:

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"DeviceType"
"DeviceCharacteristics"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PnPSysprep\ServiceStartTypeBackup]
"cdrom"

[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"LowerFilters"
"UpperFilters"
"Exclusive"
"Security"

The process SetupHelper.exe:2904 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process DTLite4413-0173.exe:1672 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit30]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit62]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit124]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit117]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit114]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit28]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit13]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit40]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit58]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit60]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit17]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit50]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit18]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit82]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.app.log" = "4096"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit113]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"Class" = "dtsoftbus01"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit90]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit120]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdx]
"Type" = "Type: REG_SZ, Length: 0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayName" = "DAEMON Tools Lite"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit39]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit111]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"B67DE95D-274B-0C7D-C784-82C002ECA45C" = "Type: REG_SZ, Length: 0"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit26]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\DAEMON.Tools.Lite\DefaultIcon]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe,0"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit53]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}\Properties]
"Security" = "01 00 0C 90 00 00 00 00 00 00 00 00 00 00 00 00"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit77]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoDisplayClass" = "1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit103]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit81]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit91]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit93]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Minor" = "41"
"Version Release" = "3"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit67]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit97]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit108]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit34]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit101]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\.mdx]
"(Default)" = "DAEMON.Tools.Lite"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit23]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit116]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit1]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit66]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit2]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit63]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit10]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit96]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit36]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit92]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayIcon" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit5]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit12]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"Path" = "%Program Files%\DAEMON Tools Lite\"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit118]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit4]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit70]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit41]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit7]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit107]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit76]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit71]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit121]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdf]
"Type" = "Type: REG_SZ, Length: 0"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit119]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit35]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit38]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit25]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit126]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit14]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit110]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit98]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoUseClass" = "1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit83]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit49]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Major" = "4"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit99]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\Config]
"AdapterStateDT" = "1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit42]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit46]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit15]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit44]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit48]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit54]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit68]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit86]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit21]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit80]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\DAEMON.Tools.Lite]
"(Default)" = "Type: REG_SZ, Length: 0"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit102]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit84]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit73]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit89]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit106]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit51]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit45]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit75]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit55]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit16]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit20]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit57]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\.mds]
"(Default)" = "DAEMON.Tools.Lite"

[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit69]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit19]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit65]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit85]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit22]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mds]
"Type" = "Type: REG_SZ, Length: 0"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit95]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayVersion" = "4.41.3.0173"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit123]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit6]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit0]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit9]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit105]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit115]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit94]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit78]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit56]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit61]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"Publisher" = "DT Soft Ltd"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit32]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit72]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.dev.log" = "4096"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit104]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\DAEMON.Tools.Lite\shell\open\command]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -shellmount %1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit100]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit88]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Path" = "%Program Files%\DAEMON Tools Lite\"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit11]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"AdapterStatus" = "1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit29]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "45"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"client" = "41 3B 13 40 37 80 B7 AF AB 63 56 48 3F BA 8E B6"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit59]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit37]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"URLInfoAbout" = "http://www.daemon-tools.cc/"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit33]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit122]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit31]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"UninstallString" = "%Program Files%\DAEMON Tools Lite\uninst.exe"

[HKCU\Software\DT Soft\DAEMON Tools Pro\Config]
"AutoStart" = "1"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit64]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit47]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit79]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit74]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit43]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit109]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit27]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit24]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKCR\.mdf]
"(Default)" = "DAEMON.Tools.Lite"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit125]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit3]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit8]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit112]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit52]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit87]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun"

The following driver will be automatically launched by the NT Native code (IoInitSystem method):

[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"Start" = "1"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"

[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\%Program Files%\DAEMON Tools Lite]
"DTLite.exe"

[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"

The process regsvr32.exe:1428 makes changes in the system registry.


The Trojan creates and/or sets the following values in system registry:

[HKCR\DTGadget.RSS.1]
"(Default)" = "RSS Class"

[HKCR\DTGadget.GadgetControl.1]
"(Default)" = "GadgetControl Class"

[HKCR\DTGadget.GadgetControl\CurVer]
"(Default)" = "DTGadget.GadgetControl.1"

[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"

[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\HELPDIR]
"(Default)" = "%Program Files%\DAEMON Tools Lite"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
"(Default)" = "DTGadget.GadgetControl"

[HKCR\DTGadget.RSS\CurVer]
"(Default)" = "DTGadget.RSS.1"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"

[HKCR\DTGadget.RSS.1\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"

[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}]
"(Default)" = "IGadgetControl"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}]
"(Default)" = "IRSS"

[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0]
"(Default)" = "DTGadget 1.0 Type Library"

[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\0\win32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]
"(Default)" = "DTGadget.GadgetControl.1"

[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"(Default)" = "GadgetControl Class"

[HKCR\DTGadget.GadgetControl.1\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"

[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"

[HKCR\DTGadget.RSS\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"

[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"Version" = "1.0"

[HKCR\AppID\{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}]
"(Default)" = "DTGadget"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
"(Default)" = "DTGadget.RSS"

[HKCR\DTGadget.GadgetControl\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"

[HKCR\AppID\DTGadget.DLL]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"(Default)" = "RSS Class"

[HKCR\DTGadget.GadgetControl]
"(Default)" = "GadgetControl Class"

[HKCR\DTGadget.RSS]
"(Default)" = "RSS Class"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"

[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
"(Default)" = "DTGadget.RSS.1"

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"ThreadingModel" = "Apartment"

The Trojan deletes the following registry key(s):

[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\Programmable]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\Programmable]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]

Dropped PE files

MD5 File path
fd5b3fbfe4346f45d3764d149afc761ac:\Program Files\DAEMON Tools Lite\DTCommonRes.dll
00d0a111a66f1e531f849727a528036bc:\Program Files\DAEMON Tools Lite\DTGadget32.dll
62f4fda5c8db21799ca4c30c10046ca7c:\Program Files\DAEMON Tools Lite\DTGadget64.dll
252ff12c709418a7792b593605188cb6c:\Program Files\DAEMON Tools Lite\DTHelper.exe
cea0461aae4b8b6216f164501b1b5a10c:\Program Files\DAEMON Tools Lite\DTLite.exe
f9803b1b1fa3e9d34f309d2dd8db30b5c:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
1bc6ff991384848c588e4ec94512a2fcc:\Program Files\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe
f605346de44da5e5037392616d3b919dc:\Program Files\DAEMON Tools Lite\Engine.dll
e52159020ed1fe44684f8aa003f2dd40c:\Program Files\DAEMON Tools Lite\InstallGadget.exe
cf0ba43ae03d5dc57e96fa583d26f506c:\Program Files\DAEMON Tools Lite\Lang\AFK.dll
92749b95321bf93e7e285537229feaadc:\Program Files\DAEMON Tools Lite\Lang\ARA.dll
c1286d50ea59268af55eb7bc72e9fd30c:\Program Files\DAEMON Tools Lite\Lang\BGR.dll
9d692d85639d0d9fcc8fd8428cb8ff2cc:\Program Files\DAEMON Tools Lite\Lang\BIH.dll
98b5f8d3c7f45937fa6b920e51e83782c:\Program Files\DAEMON Tools Lite\Lang\CHS.dll
44def48444c237ca2455b12f020a41d6c:\Program Files\DAEMON Tools Lite\Lang\CHT.dll
1838b84c7cc7529319dd704759d4273ec:\Program Files\DAEMON Tools Lite\Lang\CSY.dll
49dfb5b9bc3b193a847f96f72ba7deabc:\Program Files\DAEMON Tools Lite\Lang\DAN.dll
7305e2e252ec3ca9809fd3172dd63a68c:\Program Files\DAEMON Tools Lite\Lang\DEU.dll
27d9823928ab2be476b6f07ead03c33cc:\Program Files\DAEMON Tools Lite\Lang\ELL.dll
ae1efc111af8c51865f7982cf6563178c:\Program Files\DAEMON Tools Lite\Lang\ENU.dll
e1a42e5f8460ccbd8cd0a389a8798cc7c:\Program Files\DAEMON Tools Lite\Lang\ESN.dll
7731e2156769c740f8a2c31b5e4df534c:\Program Files\DAEMON Tools Lite\Lang\FIN.dll
614fcda9095d370e39209d6d42958fb3c:\Program Files\DAEMON Tools Lite\Lang\FRA.dll
4211100519c955e423215e9a3a08c1d7c:\Program Files\DAEMON Tools Lite\Lang\HEB.dll
9731e2fe05e3da9a66067908f6d3be07c:\Program Files\DAEMON Tools Lite\Lang\HRV.dll
b5ec9c8bb10b4d032c1362463758a25ec:\Program Files\DAEMON Tools Lite\Lang\HUN.dll
61c46b0a6fa7e2d189dc104632800be6c:\Program Files\DAEMON Tools Lite\Lang\HYE.dll
70f07f8cc1a4b5fc982df281c543f2a8c:\Program Files\DAEMON Tools Lite\Lang\IND.dll
95b38c347abd82b8b87408434bd16077c:\Program Files\DAEMON Tools Lite\Lang\ITA.dll
d0b2fed29ef162a3a8d736fd40961b3bc:\Program Files\DAEMON Tools Lite\Lang\JPN.dll
b3eaa9d656acff1824c20c8248c35e76c:\Program Files\DAEMON Tools Lite\Lang\KAT.dll
5765c1d93c810fa191b2603952d0534fc:\Program Files\DAEMON Tools Lite\Lang\KOR.dll
85fa1b1123c4b48671e0da25dacf246bc:\Program Files\DAEMON Tools Lite\Lang\LTH.dll
e4d780ef46b04d4e79baf5148f3d8dd9c:\Program Files\DAEMON Tools Lite\Lang\LVI.dll
d02efd07e77c06b994430065b69d2c2fc:\Program Files\DAEMON Tools Lite\Lang\NLB.dll
89906933894f18cde773b2325e6bb042c:\Program Files\DAEMON Tools Lite\Lang\NOR.dll
2b58f578d140b24e70ef8382223263b6c:\Program Files\DAEMON Tools Lite\Lang\PLK.dll
f10f25b99d119f70d033aaf1f6e1b172c:\Program Files\DAEMON Tools Lite\Lang\PTB.dll
4e1d52f4c97d3c47325c0e7eea53427ac:\Program Files\DAEMON Tools Lite\Lang\ROM.dll
9477befb435d7e49a495785b9e12af0fc:\Program Files\DAEMON Tools Lite\Lang\RUS.dll
bbcb4687f9d735db1999e4e3541c2561c:\Program Files\DAEMON Tools Lite\Lang\SKY.dll
0c6d4a502a4a7da18b170d80711ba345c:\Program Files\DAEMON Tools Lite\Lang\SLV.dll
60f3def51db1fb1cb6f0cdd26c517f6fc:\Program Files\DAEMON Tools Lite\Lang\SRL.dll
c24c9fc4ac8f4bd44f8e89746cf97cc4c:\Program Files\DAEMON Tools Lite\Lang\SVE.dll
43baa07c3f4326d6783fc05c0f620e8fc:\Program Files\DAEMON Tools Lite\Lang\TRK.dll
e29dd8fc5f137994c80629a7ad002d5cc:\Program Files\DAEMON Tools Lite\Lang\UKR.dll
d2adc3ee87c7983b34c1d284aad2d163c:\Program Files\DAEMON Tools Lite\SPTDinst-x64.exe
fd62e3b8d7e193ab19e71f26c1fc81b6c:\Program Files\DAEMON Tools Lite\SPTDinst-x86.exe
c0c7ceccb6c85994c2bc92d58e52d3f2c:\Program Files\DAEMON Tools Lite\dtsoftbus01.sys
d6cd851869a9a3fbeb2254d3766a9abac:\Program Files\DAEMON Tools Lite\imgengine.dll
92e541cb724a8a0ee3f04469b8099c04c:\Program Files\DAEMON Tools Lite\uninst.exe
a20431e552a37ab90e6cc98ce5ed82d1c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe
d74a7db367d407dec2fcbbd22043a91bc:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll
ee6d5584f593fab1c5d3d8e548b7203bc:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe
e808a6b7751f6f980f97008d1aeb8036c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe
cdec84efa7e61e09f8f344f1a151ba59c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe
4f88bef9204d347c0d1c99d7be7baae8c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe
cf0ba43ae03d5dc57e96fa583d26f506c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll
92749b95321bf93e7e285537229feaadc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll
c1286d50ea59268af55eb7bc72e9fd30c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll
9d692d85639d0d9fcc8fd8428cb8ff2cc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll
98b5f8d3c7f45937fa6b920e51e83782c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll
44def48444c237ca2455b12f020a41d6c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll
1838b84c7cc7529319dd704759d4273ec:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll
49dfb5b9bc3b193a847f96f72ba7deabc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll
7305e2e252ec3ca9809fd3172dd63a68c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll
27d9823928ab2be476b6f07ead03c33cc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll
ae1efc111af8c51865f7982cf6563178c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll
e1a42e5f8460ccbd8cd0a389a8798cc7c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll
7731e2156769c740f8a2c31b5e4df534c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll
614fcda9095d370e39209d6d42958fb3c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll
4211100519c955e423215e9a3a08c1d7c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll
9731e2fe05e3da9a66067908f6d3be07c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll
b5ec9c8bb10b4d032c1362463758a25ec:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll
61c46b0a6fa7e2d189dc104632800be6c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll
70f07f8cc1a4b5fc982df281c543f2a8c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll
95b38c347abd82b8b87408434bd16077c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll
d0b2fed29ef162a3a8d736fd40961b3bc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll
b3eaa9d656acff1824c20c8248c35e76c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll
5765c1d93c810fa191b2603952d0534fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll
85fa1b1123c4b48671e0da25dacf246bc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll
e4d780ef46b04d4e79baf5148f3d8dd9c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll
d02efd07e77c06b994430065b69d2c2fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll
89906933894f18cde773b2325e6bb042c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll
2b58f578d140b24e70ef8382223263b6c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll
f10f25b99d119f70d033aaf1f6e1b172c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll
4e1d52f4c97d3c47325c0e7eea53427ac:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll
9477befb435d7e49a495785b9e12af0fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll
bbcb4687f9d735db1999e4e3541c2561c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll
0c6d4a502a4a7da18b170d80711ba345c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll
60f3def51db1fb1cb6f0cdd26c517f6fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll
c24c9fc4ac8f4bd44f8e89746cf97cc4c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll
43baa07c3f4326d6783fc05c0f620e8fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll
e29dd8fc5f137994c80629a7ad002d5cc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll
7fbc1cd7de7bc2dc40e9960bd3d3ecc8c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe
959ea64598b9a3e494c00e8fa793be7ec:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll
9adb3f7c3d4b623f74c4a17ee665d65fc:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll
c0c7ceccb6c85994c2bc92d58e52d3f2c:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.sys
c0c7ceccb6c85994c2bc92d58e52d3f2c:\Windows\System32\drivers\dtsoftbus01.sys

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

Removals

Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.

Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    DAEMONLite4.41.exe:3616
    sidebar.exe:1808
    %original file name%.exe:1796
    rundll32.exe:3972
    DrvInst.exe:2628
    DrvInst.exe:3532
    DrvInst.exe:4052
    SetupHelper.exe:2904
    regsvr32.exe:1428

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\เครดิต.txt (133 bytes)
    C:\Windows\inf\setupapi.dev.log (478 bytes)
    C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
    C:\Windows\Temp\Tar4716.tmp (2712 bytes)
    C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
    C:\Windows\Temp\Tar4659.tmp (2712 bytes)
    C:\Windows\Temp\Tar4598.tmp (2712 bytes)
    C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
    C:\Windows\Temp\Cab45E7.tmp (48 bytes)
    C:\Windows\Temp\Tar4628.tmp (2712 bytes)
    C:\Windows\Temp\Cab4658.tmp (48 bytes)
    C:\Windows\Temp\Cab4627.tmp (48 bytes)
    C:\Windows\Temp\Cab4715.tmp (48 bytes)
    C:\Windows\inf\oem10.PNF (7501 bytes)
    C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
    C:\Windows\Temp\Cab4597.tmp (48 bytes)
    C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
    C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
    C:\Windows\Temp\Tar415A.tmp (2712 bytes)
    C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
    C:\Windows\Temp\Tar4127.tmp (2712 bytes)
    C:\Windows\Temp\Tar417B.tmp (2712 bytes)
    C:\Windows\inf\oem10.inf (1 bytes)
    C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
    C:\Windows\Temp\Tar4139.tmp (2712 bytes)
    C:\Windows\Temp\Cab417A.tmp (48 bytes)
    C:\Windows\Temp\Cab4138.tmp (48 bytes)
    C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
    C:\Windows\Temp\Cab4126.tmp (48 bytes)
    C:\Windows\Temp\Cab40C7.tmp (48 bytes)
    C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
    C:\Windows\Temp\Cab4159.tmp (48 bytes)
    C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
    %Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
    %Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
    C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
    %Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
    %Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
    %Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
    %Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
    %Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
    %Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
    %Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
    C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
    %Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
    %Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
    C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
    %Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
    %Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
    %Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
    %Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
    %Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
    %Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
    %Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

Static Analysis

VersionInfo

No information is available.

No information is available.

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text409672088721924.546984dfeff737935f78877d3d08b82ef95
.rdata77824718976803.371380fb0a72395723950e1915d6bf373f506
.data86016653245122.4388311ffdfc240c81dfe9d957f6bf1761f00
.CRT151552165120.147711a5ba361df79e0a565f00bd42dc501625
.rsrc15564816504168962.788074a42d4a1c79a481d4a049c0bb7911c60

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

Network Activity

URLs

URL IP
hxxp://dt.web-search-home.com/getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A==198.16.77.12
hxxp://dt.web-search-home.com/download/yandexdtLite198.16.77.12
hxxp://mirror23.mountspace.com/getfile.php?p=hxxp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe188.120.245.109
hxxp://web-search-home.com/download/yandexdtLite198.16.77.12

IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A== HTTP/1.1

Connection: Keep-Alive

Host: dt.web-search-home.com

HTTP/1.1 200 OK

Server: nginx/1.0.15

Date: Sun, 19 Mar 2017 20:50:07 GMT

Content-Type: text/html; charset=utf-8

Connection: close

X-Powered-By: PHP/5.3.29

Set-Cookie: PHPSESSID=tmtd9mej8682qtd5kn84kdgja7; path=/; domain=web-search-home.com

Content-Length: 3904

Jhz9HA/OCm0GW6fp9ZcSPDN34A485s78WSH2Jd SS2e96LkhrSzsfWe/aniircng kpRLoZsqhAQv8vCVpKIf08MvKSvlWND8pTpxJea euCVcbwqRQCtsUE vavGJoC630cVWj/iIQHNtvbMPDN9ChUZ66FNi6Cn0I5sEQsCRCGAwt5Tjkb1rnTGMV hGpIrOtC1q924swB3 7RaNPOkIYAco8kr9kFVuFmXRs0sD9UmV13VFwenUxK0H1bbFve5xHdkhoGDFDUDC5adsSfz43jS/TmKtIQm7GEjMZFE7EKZ qAlIjCRV3BBhX /VpWDS4TO9aXEtdHbJq7bsR RldNXvJjl9y du67xyCIwYdaw WJbMzBRGQA fW/WOmpdzUDaY44j5mm1T89qA8UbM18s998P9YW4zZAqmfOAU16hWoG3v/ixsNPAMnKnEzFTdcWLDTD32iNGzbbhPMrB AslbUUtWrqoUvhd/neRJWKWFU4L2roLbhRI0qNGMtKe7YXF9p3EVFCy hSXE5HAV88AV4z0vw4rVop2baNVxyrwrrd8RN9tHVBsVvRvGR5RVb7MeOAX bmXo7d2kPm6n4mLUZWnGLdpojnYK4J70mRW7DL9KStSF2iHuZnUrGTvgSCVlKgT31eba02Ho6iK7AbIYzImgScRxdnNoJzvnnVgH9C8K99Y03AQLBiByudppCDFVxmk IDSxiIF5x5EwKkj2zjZ5h94RsqGB63KFNOmMmowv8s/EZSHGP7lJuLyscLN7rl6qttro6lHpGe6HtT8W3UCKn60EMERHisGRpCFV u3YcdVYSctQrHSwIlZ0Hy1rPNq8iGRrQjpIG/bNBiEd dYIFH7WYyDVsts6 iFDJklN18/Fuw7xXDGm8IPlumykb4ufaT6a/4OstjcX3c9dychuaghoNWiGEXI1QRgzdT6r2T5fvfV4pd0kg9JXIMOTbi62fIikQj9ZnCEo67fG3H0NXE0ZKklKmdjSUaIlGZkKkANicWsbCrKYA3zuKPDJv0lD7WQrP7m8s7Hbv5TawxpRVPSOj2ay1rjIkrSSkXVJECoqEVjloZzYctZJ0D60AoCN4GyxkC8cIwxK4ho/wG8T2mPi31H3iYw0WzSTmkadHNcZggYo6qZOhWOEPPMJJW3uCH5oJs0Loccx OiRChZ2EvQ22jKrM40EPkNEZyNt6ILjRYIZDgJIp4tfq5AMpCwRd24d5TmdVTvlbE43TMuPkP4suVvVKjxGQcLxsQfDSyU7EPSxVS39HgQqsMkAMhXbdoVSGS4Kbrob97ByKsz//02CMpGIA54QOlNEs0nfdhtRBPJwD2tVCW6AYlhUis/1ctmqWJ5pG1rncAPBn8CRTMEpQmBit9T/IjYmPOYB/GgvKFuePlfx1kYTVqP Bb3SIevwVIsMdefhBHn29Ub4KEo9esQiNQ47bpFxpnINyaseLMDvYUx4lR22L1oed4s0a9cJcpokLK/ e5QBRb7frT6ljCDUw lFLrqNjX07iOMJ/0cxdS/tWi

<<< skipped >>>

GET /getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe HTTP/1.1

Connection: Keep-Alive

Host: mirror23.mountspace.com

HTTP/1.1 200 OK

Server: nginx/0.8.55

Date: Sun, 19 Mar 2017 20:50:22 GMT

Content-Type: application/octet-stream

Connection: close

X-Powered-By: PHP/5.3.19

Cache-Control:

Pragma:

Content-Disposition: attachment; filename="DT_free_Rus_YandexBar1022.exe"

Content-Transfer-Encoding: binary

Accept-Ranges: bytes

Content-Length: 878208

MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^".u.C.&.C.&.C.&..S&.C.&..g&kC.&..f&3C.&.;^&.C.&.C.&.C.&..b&.C.&..W&.C.&..P&.C.&Rich.C.&........................PE..L....v.P.............................O............@..................................Z....@.....................................x....p...............R.......p..$...`...............................p...@............................................text............................... ..`.rdata...V.......X..................@..@.data....1...0......................@....rsrc........p.......,..............@..@.reloc...$...p...&...,..............@..B................................................................................................................................................................................................................................................................................................................................................U..W....9w@t5.G....w].$...@...tR.F..I..tI.F.P.A.P....@..5..t5.F..,..t,.F..#......w6......s...Nt%......u...t.....uJ.M............_].........2...r...8...v.......u....H...v..A......RP....@...VS... ..WP....@._]....I...@.%.@.9.@.l.@.l.@.........................U....$.U..M.SV.u..^..F.W.}..U.3.R.U..U..U..U..U.R.U.RQ.]..]..^...W.E..M.P.....E.$....E......}....M....N...tK..9w.t....r'../v...7u..]..<......t...1...v...8...v..F..u..U..F.Rj.P....@.........u..N...F...t .~..u..N.......F..B.Q...F......._^..[..]...........

<<< skipped >>>

GET /download/yandexdtLite HTTP/1.1

Connection: Keep-Alive

Host: web-search-home.com

HTTP/1.1 302 Moved Temporarily

Server: nginx/1.0.15

Date: Sun, 19 Mar 2017 20:50:22 GMT

Content-Type: text/html; charset=utf-8

Transfer-Encoding: chunked

Connection: close

X-Powered-By: PHP/5.3.29

Set-Cookie: PHPSESSID=qq11dd7q3ss3td1dp3d1v6kch6; path=/; domain=web-search-home.com

Location: hXXp://mirror23.mountspace.com/getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe

0..

Map

The Trojan connects to the servers at the folowing location(s):

Strings from Dumps

%original file name%.exe_1796:

.text

.text

`.rdata

`.rdata

@.data

@.data

@.rsrc

@.rsrc

VSSSSh

VSSSSh

^SShq

^SShq

%.*s(%d)%s

%.*s(%d)%s

COMCTL32.dll

COMCTL32.dll

SHLWAPI.dll

SHLWAPI.dll

GetProcessHeap

GetProcessHeap

GetCPInfo

GetCPInfo

KERNEL32.dll

KERNEL32.dll

USER32.dll

USER32.dll

GDI32.dll

GDI32.dll

COMDLG32.dll

COMDLG32.dll

RegCloseKey

RegCloseKey

RegCreateKeyExW

RegCreateKeyExW

RegOpenKeyExW

RegOpenKeyExW

ADVAPI32.dll

ADVAPI32.dll

SHFileOperationW

SHFileOperationW

ShellExecuteExW

ShellExecuteExW

SHELL32.dll

SHELL32.dll

ole32.dll

ole32.dll

OLEAUT32.dll

OLEAUT32.dll

WINRAR.SFX

WINRAR.SFX

d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb

d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb

version="1.0.0.0"

version="1.0.0.0"

name="Microsoft.Windows.Common-Controls"

name="Microsoft.Windows.Common-Controls"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

r%.*s(%d)%s

r%.*s(%d)%s

rtmp%d

rtmp%d

Shell.Explorer

Shell.Explorer

%s %s

%s %s

%s %s %s

%s %s %s

GETPASSWORD1

GETPASSWORD1

%s%s%d

%s%s%d

Software\Microsoft\Windows\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

%s.%d.tmp

%s.%d.tmp

winrarsfxmappingfile.tmp

winrarsfxmappingfile.tmp

-el -s2 "-d%s" "-p%s" "-sp%s"

-el -s2 "-d%s" "-p%s" "-sp%s"

__tmp_rar_sfx_access_check_%u

__tmp_rar_sfx_access_check_%u

sfxcmd

sfxcmd

riched20.dll

riched20.dll

riched32.dll

riched32.dll

Extracting %s

Extracting %s

c:\%original file name%.exe

c:\%original file name%.exe

Enter password

Enter password

&Enter password for the encrypted file:

&Enter password for the encrypted file:

Skipping %s

Skipping %s

The file "%s" header is corrupt%The archive comment header is corrupt

The file "%s" header is corrupt%The archive comment header is corrupt

Unknown method in %s

Unknown method in %s

Cannot open %s

Cannot open %s

Cannot create %s

Cannot create %s

Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password.

Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password.

CRC failed in %s

CRC failed in %s

Packed data CRC failed in %s

Packed data CRC failed in %s

Wrong password for %s5Write error in the file %s. Probably the disk is full

Wrong password for %s5Write error in the file %s. Probably the disk is full

Read error in the file %s

Read error in the file %s

Extracting from %s

Extracting from %s

ErroraErrors encountered while performing the operation

ErroraErrors encountered while performing the operation

Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt.

Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt.

Extracting files to %s folder$Extracting files to temporary folder

Extracting files to %s folder$Extracting files to temporary folder

=Total path and file name length must not exceed %d characters

=Total path and file name length must not exceed %d characters

conhost.exe_3496:

.text

.text

`.data

`.data

.rsrc

.rsrc

@.reloc

@.reloc

GDI32.dll

GDI32.dll

USER32.dll

USER32.dll

msvcrt.dll

msvcrt.dll

ntdll.dll

ntdll.dll

API-MS-Win-Core-LocalRegistry-L1-1-0.dll

API-MS-Win-Core-LocalRegistry-L1-1-0.dll

KERNEL32.dll

KERNEL32.dll

IMM32.dll

IMM32.dll

ole32.dll

ole32.dll

OLEAUT32.dll

OLEAUT32.dll

PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected

PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected

Invalid message 0x%x

Invalid message 0x%x

InitExtendedEditKeys: Unsupported version number(%d)

InitExtendedEditKeys: Unsupported version number(%d)

Console init failed with status 0x%x

Console init failed with status 0x%x

CreateWindowsWindow failed with status 0x%x, gle = 0x%x

CreateWindowsWindow failed with status 0x%x, gle = 0x%x

InitWindowsStuff failed with status 0x%x (gle = 0x%x)

InitWindowsStuff failed with status 0x%x (gle = 0x%x)

InitSideBySide failed create an activation context. Error: %d

InitSideBySide failed create an activation context. Error: %d

GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.

GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.

GetModuleFileNameW failed %d.

GetModuleFileNameW failed %d.

Invalid EventType: 0x%x

Invalid EventType: 0x%x

Dup handle failed for %d of %d (Status = 0x%x)

Dup handle failed for %d of %d (Status = 0x%x)

Couldn't grow input buffer, Status == 0x%x

Couldn't grow input buffer, Status == 0x%x

InitializeScrollBuffer failed, Status = 0x%x

InitializeScrollBuffer failed, Status = 0x%x

CreateWindow failed with gle = 0x%x

CreateWindow failed with gle = 0x%x

Opening Font file failed with error 0x%x

Opening Font file failed with error 0x%x

\ega.cpi

\ega.cpi

NtReplyWaitReceivePort failed with Status 0x%x

NtReplyWaitReceivePort failed with Status 0x%x

ConsoleOpenWaitEvent failed with Status 0x%x

ConsoleOpenWaitEvent failed with Status 0x%x

NtCreatePort failed with Status 0x%x

NtCreatePort failed with Status 0x%x

GetCharWidth32 failed with error 0x%x

GetCharWidth32 failed with error 0x%x

GetTextMetricsW failed with error 0x%x

GetTextMetricsW failed with error 0x%x

GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x

GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x

RtlStringCchCopy failed with Status 0x%x

RtlStringCchCopy failed with Status 0x%x

Cannot allocate 0n%d bytes

Cannot allocate 0n%d bytes

|%SWj

|%SWj

O.fBf;

O.fBf;

ReCreateDbcsScreenBuffer failed. Restoring to CP=%d

ReCreateDbcsScreenBuffer failed. Restoring to CP=%d

Invalid Parameter: 0x%x, 0x%x, 0x%x

Invalid Parameter: 0x%x, 0x%x, 0x%x

ConsoleKeyInfo buffer is full

ConsoleKeyInfo buffer is full

Invalid screen buffer size (0x%x, 0x%x)

Invalid screen buffer size (0x%x, 0x%x)

SetROMFontCodePage: failed to memory allocation %d bytes

SetROMFontCodePage: failed to memory allocation %d bytes

FONT.NT

FONT.NT

Failed to set font image. wc=x, sz=(%x,%x)

Failed to set font image. wc=x, sz=(%x,%x)

Failed to set font image. wc=x sz=(%x, %x).

Failed to set font image. wc=x sz=(%x, %x).

Failed to set font image. wc=x sz=(%x,%x)

Failed to set font image. wc=x sz=(%x,%x)

FullscreenControlSetColors failed - Status = 0x%x

FullscreenControlSetColors failed - Status = 0x%x

FullscreenControlSetPalette failed - Status = 0x%x

FullscreenControlSetPalette failed - Status = 0x%x

WriteCharsFromInput failed 0x%x

WriteCharsFromInput failed 0x%x

WriteCharsFromInput failed %x

WriteCharsFromInput failed %x

RtlStringCchCopyW failed with Status 0x%x

RtlStringCchCopyW failed with Status 0x%x

CreateFontCache failed with Status 0x%x

CreateFontCache failed with Status 0x%x

FTPh

FTPh

\>.Sj

\>.Sj

GetKeyboardLayout

GetKeyboardLayout

MapVirtualKeyW

MapVirtualKeyW

VkKeyScanW

VkKeyScanW

GetKeyboardState

GetKeyboardState

UnhookWindowsHookEx

UnhookWindowsHookEx

SetWindowsHookExW

SetWindowsHookExW

GetKeyState

GetKeyState

ActivateKeyboardLayout

ActivateKeyboardLayout

GetKeyboardLayoutNameA

GetKeyboardLayoutNameA

GetKeyboardLayoutNameW

GetKeyboardLayoutNameW

_amsg_exit

_amsg_exit

_acmdln

_acmdln

ShipAssert

ShipAssert

NtReplyWaitReceivePort

NtReplyWaitReceivePort

NtCreatePort

NtCreatePort

NtEnumerateValueKey

NtEnumerateValueKey

NtQueryValueKey

NtQueryValueKey

NtOpenKey

NtOpenKey

NtAcceptConnectPort

NtAcceptConnectPort

NtReplyPort

NtReplyPort

SetProcessShutdownParameters

SetProcessShutdownParameters

GetCPInfo

GetCPInfo

conhost.pdb

conhost.pdb

%$%a%b%V%U%c%Q%W%]%\%[%

%$%a%b%V%U%c%Q%W%]%\%[%

%

%

version="5.1.0.0"

version="5.1.0.0"

name="Microsoft.Windows.ConsoleHost"

name="Microsoft.Windows.ConsoleHost"

name="Microsoft.Windows.ConsoleHost.SystemDefault"

name="Microsoft.Windows.ConsoleHost.SystemDefault"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

name="Microsoft.Windows.SystemCompatible"

name="Microsoft.Windows.SystemCompatible"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

:>@>

:>@>

2%2X2

2%2X2

%SystemRoot%

%SystemRoot%

\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont

\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont

\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen

\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen

WindowSize

WindowSize

ColorTableu

ColorTableu

ExtendedEditkeyCustom

ExtendedEditkeyCustom

ExtendedEditKey

ExtendedEditKey

Software\Microsoft\Windows\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

\ !:=/.;|&

\ !:=/.;|&

%d/%d

%d/%d

cmd.exe

cmd.exe

desktop.ini

desktop.ini

\console.dll

\console.dll

%d/%d

%d/%d

6.1.7601.17641 (win7sp1_gdr.110623-1503)

6.1.7601.17641 (win7sp1_gdr.110623-1503)

CONHOST.EXE

CONHOST.EXE

Windows

Windows

Operating System

Operating System

6.1.7601.17641

6.1.7601.17641

DAEMONLite4.41.exe_3616:

.text

.text

`.rdata

`.rdata

@.data

@.data

.rsrc

.rsrc

diu2.iu

diu2.iu

Advapi32.dll

Advapi32.dll

irsetup.exe

irsetup.exe

Could not determine a temp directory name. Try running setup.exe /T:

Could not determine a temp directory name. Try running setup.exe /T:

c:\temp

c:\temp

%s\irsetup.exe

%s\irsetup.exe

%s%s_%d

%s%s_%d

"__IRSID:%s"

"__IRSID:%s"

"__IRCT:%d"

"__IRCT:%d"

"__IRAFN:%s"

"__IRAFN:%s"

__IRAOFF:%u

__IRAOFF:%u

KERNEL32.DLL

KERNEL32.DLL

mscoree.dll

mscoree.dll

Please contact the application's support team for more information.

Please contact the application's support team for more information.

- Attempt to initialize the CRT more than once.

- Attempt to initialize the CRT more than once.

- CRT not initialized

- CRT not initialized

kernel32.dll

kernel32.dll

GetProcessWindowStation

GetProcessWindowStation

USER32.DLL

USER32.DLL

operator

operator

KERNEL32.dll

KERNEL32.dll

MsgWaitForMultipleObjects

MsgWaitForMultipleObjects

USER32.dll

USER32.dll

ADVAPI32.dll

ADVAPI32.dll

ShellExecuteExA

ShellExecuteExA

SHELL32.dll

SHELL32.dll

GetProcessHeap

GetProcessHeap

GetCPInfo

GetCPInfo

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe

%xERRj3cqZQ

%xERRj3cqZQ

! !!####0

! !!####0

;;;9551%%0

;;;9551%%0

! !!565665@

! !!565665@

version="8.1.1000.0"

version="8.1.1000.0"

name="setup.exe"/>

name="setup.exe"/>

name="Microsoft.Windows.Common-Controls"

name="Microsoft.Windows.Common-Controls"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

04090000

04090000

VVV.u-soft.org

VVV.u-soft.org

0.0.0.0

0.0.0.0

suf80_launch.exe

suf80_launch.exe

irsetup.exe_2296:

`.rsrc

`.rsrc

FtPh

FtPh

FtPhu

FtPhu

SSSSh

SSSSh

SSh`UQ

SSh`UQ

SSh4UQ

SSh4UQ

SShlTQ

SShlTQ

SShDTQ

SShDTQ

u1SSh

u1SSh

Su%Sh

Su%Sh

SShx`Q

SShx`Q

txSSh

txSSh

SSh _Q

SSh _Q

@ SSh

@ SSh

.hPsQ

.hPsQ

SSShDxQ

SSShDxQ

9^$u&SSSSh?

9^$u&SSSSh?

u SSSSh?

u SSSSh?

9^$u)SSSSh?

9^$u)SSSSh?

u.VWS

u.VWS

WSSh|DQ

WSSh|DQ

udPQ

udPQ

t.Ht Ht(Ht

t.Ht Ht(Ht

y2SSh

y2SSh

FHSSh

FHSSh

GHSSh

GHSSh

GTSSh

GTSSh

G\SSh

G\SSh

FlSSh

FlSSh

Nt.Nt

Nt.Nt

SShlSR

SShlSR

tjSShHSR

tjSShHSR

t;SSh$SR

t;SSh$SR

F

F

t'SShl

t'SShl

u$SShe

u$SShe

aSSSh

aSSSh

.VVVVVSRSSj

.VVVVVSRSSj

FTPjK

FTPjK

FtPj;

FtPj;

C.PjRV

C.PjRV

diu2.iuz

diu2.iuz

MSG_ERROR

MSG_ERROR

%s %d. %s

%s %d. %s

MSG_ASK_FOR_DISK

MSG_ASK_FOR_DISK

MSG_NEW_LOCATION

MSG_NEW_LOCATION

MSG_CONFIRM_ABORT

MSG_CONFIRM_ABORT

MSG_CONFIRM

MSG_CONFIRM

A%s.%d

A%s.%d

%s, Line %d: %s

%s, Line %d: %s

File condition evaluation for file "%s"

File condition evaluation for file "%s"

C:\temp\SUF_SFX_TEST\

C:\temp\SUF_SFX_TEST\

msi.dll

msi.dll

\msi.dll

\msi.dll

Software\Microsoft\Windows\CurrentVersion\Installer

Software\Microsoft\Windows\CurrentVersion\Installer

MSG_INITIALIZING

MSG_INITIALIZING

16670749

16670749

[%d]: %s

[%d]: %s

*** LOCATION: %s

*** LOCATION: %s

__NOREPORT__

__NOREPORT__

Script: %s, %s (%s)

Script: %s, %s (%s)

__ir_eval_value = %s;

__ir_eval_value = %s;

%s (%s:%d)

%s (%s:%d)

F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl

F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl

%Copyright%. All rights reserved. %CompanyURL%

%Copyright%. All rights reserved. %CompanyURL%

WindowStyle

WindowStyle

MainWindowSettings

MainWindowSettings

%s at offset %d unterminated

%s at offset %d unterminated

Incorrect %s at offset %d

Incorrect %s at offset %d

Element '%s' at offset %d not ended

Element '%s' at offset %d not ended

End tag '%s' at offset %d does not match start tag '%s' at offset %d

End tag '%s' at offset %d does not match start tag '%s' at offset %d

No start tag for end tag '%s' at offset %d

No start tag for end tag '%s' at offset %d

%s%d bytes

%s%d bytes

%s%d wide chars to %d bytes

%s%d wide chars to %d bytes

%d bytes to %s%d wide chars

%d bytes to %s%d wide chars

MSG_SEARCH_FILE

MSG_SEARCH_FILE

(*.*)|*.*||

(*.*)|*.*||

MSG_SEARCH_ALL

MSG_SEARCH_ALL

MSG_SEARCH_MASK

MSG_SEARCH_MASK

MSG_INSERTDISK

MSG_INSERTDISK

MSG_CANCEL

MSG_CANCEL

MSG_OK

MSG_OK

MSG_BROWSE

MSG_BROWSE

MSG_PATH

MSG_PATH

Windows Server 2008

Windows Server 2008

Windows Vista

Windows Vista

Windows Server 2003

Windows Server 2003

Windows XP

Windows XP

Windows 2000

Windows 2000

Windows NT4

Windows NT4

Windows NT3

Windows NT3

Windows ME

Windows ME

Windows 98

Windows 98

Windows 95

Windows 95

CPasswordData

CPasswordData

-- Defined in _SUF70_Global_Functions.lua

-- Defined in _SUF70_Global_Functions.lua

number e_ErrorCode, string e_ErrorMsgID

number e_ErrorCode, string e_ErrorMsgID

%WindowsFolder%\%ProductName% Setup Log.txt

%WindowsFolder%\%ProductName% Setup Log.txt

%StartupFolder%

%StartupFolder%

%StartFolder%

%StartFolder%

%StartProgramsFolder%

%StartProgramsFolder%

ÞsktopFolder%

ÞsktopFolder%

%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%CommonFilesFolder%\Microsoft Shared\DAO

%CommonFilesFolder%\Microsoft Shared\DAO

Software\Microsoft\Shared Tools\DAO350.dll

Software\Microsoft\Shared Tools\DAO350.dll

Software\Microsoft\Shared Tools\DAO360.dll

Software\Microsoft\Shared Tools\DAO360.dll

ÚOPath%

ÚOPath%

Software\Microsoft\Windows NT\CurrentVersion

Software\Microsoft\Windows NT\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

%SourceFolder%

%SourceFolder%

%SystemDrive%

%SystemDrive%

_WindowsFolder

_WindowsFolder

%WindowsFolder%

%WindowsFolder%

%SystemFolder%

%SystemFolder%

%CommonFilesFolder%

%CommonFilesFolder%

%CommonFilesFolder64%

%CommonFilesFolder64%

%CommonProgramW6432%

%CommonProgramW6432%

%CommonDocumentsFolder%

%CommonDocumentsFolder%

%StartupFolderCommon%

%StartupFolderCommon%

%StartProgramsFolderCommon%

%StartProgramsFolderCommon%

%StartFolderCommon%

%StartFolderCommon%

%FontsFolder%

%FontsFolder%

ÞsktopFolderCommon%

ÞsktopFolderCommon%

UninstallSupportFiles

UninstallSupportFiles

CPRegKey

CPRegKey

Run extra uninstall script: %d

Run extra uninstall script: %d

%SourceDrive%

%SourceDrive%

%SourceFilename%

%SourceFilename%

\irsetup.dat

\irsetup.dat

Support file added to uninstall list:

Support file added to uninstall list:

Registry key added to uninstall list:

Registry key added to uninstall list:

Remove uninstall support file:

Remove uninstall support file:

Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\

Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\

Register font: %s, %s

Register font: %s, %s

%sbk%d

%sbk%d

MSG_NO

MSG_NO

MSG_YES_TOALL

MSG_YES_TOALL

MSG_YES

MSG_YES

MSG_UNINSTALL_OK_REMOVE

MSG_UNINSTALL_OK_REMOVE

MSG_UNINSTALL_NO_APP_USE

MSG_UNINSTALL_NO_APP_USE

MSG_UNINSTALL_REMOVE_SHARED

MSG_UNINSTALL_REMOVE_SHARED

Decrement shared file count: %s (New count = %d)

Decrement shared file count: %s (New count = %d)

SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs

SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs

: %s (#%d)

: %s (#%d)

Global include script: %s

Global include script: %s

RegisterTypeLib: %s

RegisterTypeLib: %s

RegisterTypeLib: %s - %s

RegisterTypeLib: %s - %s

Register COM file: %s

Register COM file: %s

Register COM file: %s - System Error # %u

Register COM file: %s - System Error # %u

Register COM file on reboot: %s

Register COM file on reboot: %s

regsvr32.exe /s %s

regsvr32.exe /s %s

SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Increment usage count: %s

Increment usage count: %s

Increment usage count: %s (New count = %d)

Increment usage count: %s (New count = %d)

%s\%s

%s\%s

%s (%d)

%s (%d)

local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;

local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;

MSG_SYSREQ_WARN

MSG_SYSREQ_WARN

MSG_NOTICE

MSG_NOTICE

MSG_SYSREQ_ABORT

MSG_SYSREQ_ABORT

%s: %s

%s: %s

MSG_SYSREQ_USERPERMISSION

MSG_SYSREQ_USERPERMISSION

MSG_SYSREQ_SYSTEMADMIN

MSG_SYSREQ_SYSTEMADMIN

MSG_SYSREQ_COLORDEPTH

MSG_SYSREQ_COLORDEPTH

MSG_BITSPERPIXEL

MSG_BITSPERPIXEL

MSG_SYSREQ_SCREENHEIGHT

MSG_SYSREQ_SCREENHEIGHT

MSG_SYSREQ_SCREENWIDTH

MSG_SYSREQ_SCREENWIDTH

%s: %d

%s: %d

%s: %d %s

%s: %d %s

MSG_SYSREQ_RAM

MSG_SYSREQ_RAM

MSG_SIZE_MEGABYTES

MSG_SIZE_MEGABYTES

Operating System

Operating System

MSG_SYSREQ_OS

MSG_SYSREQ_OS

MSG_OS_PART_ORNEWER

MSG_OS_PART_ORNEWER

MSG_OS_PART_NOSERVPACK

MSG_OS_PART_NOSERVPACK

MSG_OS_PART_SERVPACK

MSG_OS_PART_SERVPACK

MSG_OS_PART_SE

MSG_OS_PART_SE

MSG_OS_PART_C

MSG_OS_PART_C

MSG_OS_PART_B

MSG_OS_PART_B

MSG_OS_PART_A

MSG_OS_PART_A

MSG_OS_ALL

MSG_OS_ALL

MSG_OS_NONE

MSG_OS_NONE

MSG_OS_WSRV2008

MSG_OS_WSRV2008

MSG_OS_WVISTA

MSG_OS_WVISTA

MSG_OS_WSRV2003

MSG_OS_WSRV2003

MSG_OS_WXP

MSG_OS_WXP

MSG_OS_W2000

MSG_OS_W2000

MSG_OS_WNT4

MSG_OS_WNT4

MSG_OS_WNT3

MSG_OS_WNT3

MSG_OS_WME

MSG_OS_WME

MSG_OS_W98

MSG_OS_W98

MSG_OS_W95

MSG_OS_W95

MSG_OS_UNKNOWN

MSG_OS_UNKNOWN

MSG_SYSREQ_NOTMET

MSG_SYSREQ_NOTMET

MSG_EXP_USESLEFT

MSG_EXP_USESLEFT

MSG_EXP_USESLEFT2

MSG_EXP_USESLEFT2

%s %d %s

%s %d %s

MSG_EXP_DAYSLEFT

MSG_EXP_DAYSLEFT

MSG_EXP_DAYSLEFT2

MSG_EXP_DAYSLEFT2

Software\Microsoft\Windows\CurrentVersion\I652R9823\

Software\Microsoft\Windows\CurrentVersion\I652R9823\

MSG_EXP_CONTACT_START

MSG_EXP_CONTACT_START

MSG_SEEKING

MSG_SEEKING

Dependency Detection Passed

Dependency Detection Passed

Arc: %s

Arc: %s

FN: %s

FN: %s

%s (#%d)

%s (#%d)

MSG_SKIPPING

MSG_SKIPPING

MSG_INSTALLING

MSG_INSTALLING

Run project event: %s

Run project event: %s

local e_ErrorCode=%d; local e_ErrorMsgID = "%s"

local e_ErrorCode=%d; local e_ErrorMsgID = "%s"

Start project event: %s

Start project event: %s

MSG_UNINSTALLFILE_NOREMOVE

MSG_UNINSTALLFILE_NOREMOVE

MSG_UNINSTALLFILE_INUSE

MSG_UNINSTALLFILE_INUSE

%s (%s: %u)

%s (%s: %u)

\WININIT.INI

\WININIT.INI

MSG_FILE_EXISTS_INUSE

MSG_FILE_EXISTS_INUSE

MSG_FILE_EXISTS_RETRY

MSG_FILE_EXISTS_RETRY

MSG_FILE_EXISTS_ANY

MSG_FILE_EXISTS_ANY

MSG_FILE_EXISTS_NEWER

MSG_FILE_EXISTS_NEWER

MSG_FILE_OVERWRITE_CONFIRM

MSG_FILE_OVERWRITE_CONFIRM

%s\%s.lnk

%s\%s.lnk

%s (Return code: %d)

%s (Return code: %d)

Product: %s, version %s

Product: %s, version %s

%s (%d):

%s (%d):

MSG_PROG_UNINSTALL_CREATECONTROLFILE

MSG_PROG_UNINSTALL_CREATECONTROLFILE

ERR_CREATEUNINSTALL_OPEN_EXE_READ

ERR_CREATEUNINSTALL_OPEN_EXE_READ

ERR_CREATEUNINSTALL_OPEN_EXE_WRITE

ERR_CREATEUNINSTALL_OPEN_EXE_WRITE

Overwrite uninstall executable:

Overwrite uninstall executable:

MSG_PROG_UNINSTALL_CREATEEXE

MSG_PROG_UNINSTALL_CREATEEXE

@MSG_PROG_UNINSTALL_CREATEDATFILE

@MSG_PROG_UNINSTALL_CREATEDATFILE

?MSG_PROG_UNINSTALL_CREATEFOLDER

?MSG_PROG_UNINSTALL_CREATEFOLDER

"/U:%s"

"/U:%s"

MSG_PROG_UNINSTALL_CREATESC

MSG_PROG_UNINSTALL_CREATESC

Create uninstall CP entry key

Create uninstall CP entry key

ERR_CREATEUNINSTALL_CREATEREGKEY

ERR_CREATEUNINSTALL_CREATEREGKEY

"%s",%d

"%s",%d

Uninstall CP entry: URLUpdateInfo =

Uninstall CP entry: URLUpdateInfo =

URLUpdateInfo

URLUpdateInfo

Uninstall CP entry: URLInfoAbout =

Uninstall CP entry: URLInfoAbout =

URLInfoAbout

URLInfoAbout

"%s" "/U:%s"

"%s" "/U:%s"

HKEY_LOCAL_MACHINE\

HKEY_LOCAL_MACHINE\

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

MSG_PROG_UNINSTALL_CREATECPENTRY

MSG_PROG_UNINSTALL_CREATECPENTRY

MSG_PROG_UNINSTALL_COPYSUPPORTFILES

MSG_PROG_UNINSTALL_COPYSUPPORTFILES

MSG_PROG_UNINSTALL_COPYPLUGINS

MSG_PROG_UNINSTALL_COPYPLUGINS

%s %s

%s %s

MSG_REQUIRED_DRIVE

MSG_REQUIRED_DRIVE

MSG_AVAILABLE_DRIVE

MSG_AVAILABLE_DRIVE

MSG_PROG_CHECKING_DRIVESPACE

MSG_PROG_CHECKING_DRIVESPACE

MSG_PROG_CHECKING_FILES

MSG_PROG_CHECKING_FILES

%A, %B %d, %Y

%A, %B %d, %Y

[%s] %s

[%s] %s

%m/%d/%Y %H:%M:%S

%m/%d/%Y %H:%M:%S

MsgFile

MsgFile

ERR_MSI_PATCH_REMOVAL_UNSUPPORTED

ERR_MSI_PATCH_REMOVAL_UNSUPPORTED

ERR_MSI_PATCH_PACKAGE_UNSUPPORTED

ERR_MSI_PATCH_PACKAGE_UNSUPPORTED

ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED

ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED

ERR_MSI_UNSUPPORTED_TYPE

ERR_MSI_UNSUPPORTED_TYPE

ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED

ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED

ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD

ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD

ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE

ERR_ODBC_INVALID_KEYWORD_VALUE

ERR_ODBC_INVALID_KEYWORD_VALUE

ERR_WEB_503

ERR_WEB_503

ERR_WEB_500

ERR_WEB_500

ERR_WEB_404

ERR_WEB_404

ERR_WEB_403

ERR_WEB_403

ERR_WEB_400

ERR_WEB_400

ERR_WEB_SET_PROXY_PASSWORD

ERR_WEB_SET_PROXY_PASSWORD

ERR_WEB_SET_PROXY_USERNAME

ERR_WEB_SET_PROXY_USERNAME

ERR_WEB_WRITE_MEMORY

ERR_WEB_WRITE_MEMORY

ERR_WEB_FTP_FILE_OPEN

ERR_WEB_FTP_FILE_OPEN

ERR_WEB_USER_ABORT

ERR_WEB_USER_ABORT

ERR_WEB_FILE_WRITE

ERR_WEB_FILE_WRITE

ERR_WEB_DOWNLOAD_FILE_ERROR

ERR_WEB_DOWNLOAD_FILE_ERROR

ERR_WEB_INVALID_HTTP_RESPONSE

ERR_WEB_INVALID_HTTP_RESPONSE

ERR_WEB_DESTINATION_FILE_OPEN

ERR_WEB_DESTINATION_FILE_OPEN

ERR_WEB_SEND_REQUEST

ERR_WEB_SEND_REQUEST

ERR_WEB_OPEN_REQUEST

ERR_WEB_OPEN_REQUEST

ERR_WEB_CREATE_HTTP_CONNECTION

ERR_WEB_CREATE_HTTP_CONNECTION

ERR_WEB_CREATE_INTERNET_SESSION

ERR_WEB_CREATE_INTERNET_SESSION

ERR_REG_GET_SUB_KEY_NAME

ERR_REG_GET_SUB_KEY_NAME

ERR_REG_NON_EXISTANT_SUB_KEY

ERR_REG_NON_EXISTANT_SUB_KEY

ERR_REG_DELETE_KEY

ERR_REG_DELETE_KEY

ERR_REG_CREATE_KEY

ERR_REG_CREATE_KEY

ERR_FILE_EXECUTION_FAILED_ELEVATION

ERR_FILE_EXECUTION_FAILED_ELEVATION

ERR_KEY_RUN_ON_REBOOT_FAILED

ERR_KEY_RUN_ON_REBOOT_FAILED

ERR_USER_ABORTED_OPERATION

ERR_USER_ABORTED_OPERATION

ERR_NON_EXISTANT_VIEWER_EXE

ERR_NON_EXISTANT_VIEWER_EXE

ERR_FILE_EXECUTION_FAILED

ERR_FILE_EXECUTION_FAILED

ERR_SPECIFIED_EXE_FILE_INVALID

ERR_SPECIFIED_EXE_FILE_INVALID

MSG_SUCCESS

MSG_SUCCESS

Language set: Primary = %d, Secondary = %d

Language set: Primary = %d, Secondary = %d

%CompanyURL%

%CompanyURL%

%CompanyName%

%CompanyName%

UxTheme.dll

UxTheme.dll

%Copyright% %CompanyName%. All rights reserved. %CompanyURL%

%Copyright% %CompanyName%. All rights reserved. %CompanyURL%

%WindowsFolder%\%ProductName% Uninstall Log.txt

%WindowsFolder%\%ProductName% Uninstall Log.txt

%CompanyName% Support Department

%CompanyName% Support Department

%WindowsFolder%\%ProductName%\uninstall.exe

%WindowsFolder%\%ProductName%\uninstall.exe

uninstall.xml

uninstall.xml

CWebBrowser2

CWebBrowser2

Confirm Operation

Confirm Operation

kernel32.dll

kernel32.dll

KERNEL32.DLL

KERNEL32.DLL

PSAPI.DLL

PSAPI.DLL

Kernel32.dll

Kernel32.dll

WS2_32.DLL

WS2_32.DLL

Copying "%s"

Copying "%s"

"%s" %s

"%s" %s

%d.%d.%d.%d

%d.%d.%d.%d

\StringFileInfo\xx\ProductVersion

\StringFileInfo\xx\ProductVersion

\StringFileInfo\xx\PrivateBuild

\StringFileInfo\xx\PrivateBuild

.bak%d

.bak%d

Windows NT 4

Windows NT 4

Windows NT 3

Windows NT 3

%s\shell\open\command

%s\shell\open\command

NUL=%s

NUL=%s

Software\Microsoft\Windows NT\CurrentVersion\Fonts

Software\Microsoft\Windows NT\CurrentVersion\Fonts

Software\Microsoft\Windows\CurrentVersion\Fonts

Software\Microsoft\Windows\CurrentVersion\Fonts

***!!!***@@

***!!!***@@

Advapi32.dll

Advapi32.dll

Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%s\%s.url

%s\%s.url

%s\%s.pif

%s\%s.pif

srclient.dll

srclient.dll

%s_%d

%s_%d

%s\_ir_tmpfnt_%d

%s\_ir_tmpfnt_%d

/\:*?"|

/\:*?"|

jsproxy.dll

jsproxy.dll

DetectAutoProxyUrl

DetectAutoProxyUrl

wininet.dll

wininet.dll

%%x

%%x

d:d

d:d

WinINet.dll

WinINet.dll

Could not create Internet session: %u

Could not create Internet session: %u

Error downloading file: %u

Error downloading file: %u

Error writing the destination file: %d-%u

Error writing the destination file: %d-%u

Could not create HTTP connection: %u

Could not create HTTP connection: %u

Could not create HTTP connection

Could not create HTTP connection

Incorrect HTTP status returned by server: %d

Incorrect HTTP status returned by server: %d

Send request failed: %u

Send request failed: %u

Content-Type: application/x-www-form-urlencoded

Content-Type: application/x-www-form-urlencoded

Could not open HTTP file: %s

Could not open HTTP file: %s

PTF://

PTF://

hXXps://

hXXps://

hXXp://

hXXp://

Could not open request: %u

Could not open request: %u

Could not HTTP file: %u

Could not HTTP file: %u

MSG_STATUS_HANDLE_CREATED

MSG_STATUS_HANDLE_CREATED

MSG_STATUS_HANDLE_CLOSING

MSG_STATUS_HANDLE_CLOSING

MSG_STATUS_REQUEST_COMPLETE

MSG_STATUS_REQUEST_COMPLETE

MSG_REDIRECTING

MSG_REDIRECTING

MSG_CONNECTION_CLOSED

MSG_CONNECTION_CLOSED

MSG_RESOLVING_HOST_NAME

MSG_RESOLVING_HOST_NAME

MSG_HOST_NAME_RESOLVED

MSG_HOST_NAME_RESOLVED

MSG_CONNECTING_TO_SERVER

MSG_CONNECTING_TO_SERVER

MSG_CONNECTED_TO_SERVER

MSG_CONNECTED_TO_SERVER

MSG_CLOSING_CONNECTION

MSG_CLOSING_CONNECTION

TRACE: LastError = %d ("%s")

TRACE: LastError = %d ("%s")

Script: %s, %s

Script: %s, %s

Script: %s, Line %d

Script: %s, Line %d

All Files (*.*)|*.*|

All Files (*.*)|*.*|

PasswordInput

PasswordInput

MSG_MOVING

MSG_MOVING

MSG_COPYING

MSG_COPYING

MSG_FROM

MSG_FROM

MSG_TO

MSG_TO

MSG_DELETING

MSG_DELETING

MSG_SEARCHING

MSG_SEARCHING

\StringFileInfo\xx\SpecialBuild

\StringFileInfo\xx\SpecialBuild

\StringFileInfo\xx\OriginalFilename

\StringFileInfo\xx\OriginalFilename

\StringFileInfo\xx\Comments

\StringFileInfo\xx\Comments

\StringFileInfo\xx\LegalTrademarks

\StringFileInfo\xx\LegalTrademarks

\StringFileInfo\xx\LegalCopyright

\StringFileInfo\xx\LegalCopyright

\StringFileInfo\xx\ProductName

\StringFileInfo\xx\ProductName

\StringFileInfo\xx\InternalName

\StringFileInfo\xx\InternalName

\StringFileInfo\xx\FileDescription

\StringFileInfo\xx\FileDescription

\StringFileInfo\xx\CompanyName

\StringFileInfo\xx\CompanyName

ErrorMsg

ErrorMsg

%Y-%m-%dT%H:%M:%S

%Y-%m-%dT%H:%M:%S

MSG_INSTALL_DO_YOU_WANT_OVERWRITE

MSG_INSTALL_DO_YOU_WANT_OVERWRITE

MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG

MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG

MSG_INSTALL_FILE_OLDER_MSG

MSG_INSTALL_FILE_OLDER_MSG

OpenURL

OpenURL

\msiexec.exe

\msiexec.exe

RunMsiexec

RunMsiexec

SQLInstallerError

SQLInstallerError

SQLRemoveDriverManager

SQLRemoveDriverManager

odbccp32.dll

odbccp32.dll

SQLConfigDataSource

SQLConfigDataSource

SQLInstallDriverEx

SQLInstallDriverEx

SQLInstallDriverManager

SQLInstallDriverManager

SQLRemoveDriver

SQLRemoveDriver

\Kernel32.dll

\Kernel32.dll

GetKeyNames

GetKeyNames

DoesKeyExist

DoesKeyExist

DeleteKey

DeleteKey

CreateKey

CreateKey

ShortcutKey

ShortcutKey

keycode

keycode

SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

MSG_SIZE_BYTES

MSG_SIZE_BYTES

P?MSG_SIZE_KILOBYTES

P?MSG_SIZE_KILOBYTES

>MSG_SIZE_GIGABYTES

>MSG_SIZE_GIGABYTES

xxxxxx

xxxxxx

%s-%s-%s

%s-%s-%s

%s/%s/%s

%s/%s/%s

%s:%s:%s

%s:%s:%s

%d:%s:%s AM

%d:%s:%s AM

%d:%s:%s PM

%d:%s:%s PM

MSG_REBOOT_FAILED

MSG_REBOOT_FAILED

WININET.DLL

WININET.DLL

PPassword

PPassword

Password

Password

%s %s %s %s (%0.2f %s)

%s %s %s %s (%0.2f %s)

%0.1f %s/%0.1f %s

%0.1f %s/%0.1f %s

%I64u %s/%I64u %s

%I64u %s/%I64u %s

MSG_KB_PER_SEC

MSG_KB_PER_SEC

MSG_ESTIMATED_TIME_LEFT

MSG_ESTIMATED_TIME_LEFT

MSG_SAVING

MSG_SAVING

MSG_DOWNLOADING

MSG_DOWNLOADING

%s %s %s %s

%s %s %s %s

MSG_QUERYING_INTERNET

MSG_QUERYING_INTERNET

MSG_READING

MSG_READING

GetHTTPErrorInfo

GetHTTPErrorInfo

%s > %s

%s > %s

local e_CtrlID=%d; local e_MsgID=%d;

local e_CtrlID=%d; local e_MsgID=%d;

Button%d

Button%d

Check%d

Check%d

ComboBox%d

ComboBox%d

Edit%d

Edit%d

Space available on selected drive: %SpaceAvailable%

Space available on selected drive: %SpaceAvailable%

Space required: %SpaceRequired%

Space required: %SpaceRequired%

Error: The specified file: '%s' could not be found.

Error: The specified file: '%s' could not be found.

Error: The specified file: '%s' could not be opened.

Error: The specified file: '%s' could not be opened.

Error: The specified file: '%s' is too large to read.

Error: The specified file: '%s' is too large to read.

Error: The specified file: '%s' could not be read.

Error: The specified file: '%s' could not be read.

number e_CtrlID, number e_MsgID, table e_Details

number e_CtrlID, number e_MsgID, table e_Details

Application.Exit();

Application.Exit();

Screen.Next();

Screen.Next();

Screen.Back();

Screen.Back();

Radio%d

Radio%d

Total space required: %SpaceRequired%

Total space required: %SpaceRequired%

IDS_CTRL_CHECK_BOX_d

IDS_CTRL_CHECK_BOX_d

IDS_CTRL_BUTTON_d

IDS_CTRL_BUTTON_d

IDS_CTRL_STATICTEXT_LABEL_d

IDS_CTRL_STATICTEXT_LABEL_d

IDS_CTRL_COMBOBOX_d_DEFAULT

IDS_CTRL_COMBOBOX_d_DEFAULT

IDS_CTRL_EDIT_d

IDS_CTRL_EDIT_d

IDS_CTRL_RADIO_BUTTON_d

IDS_CTRL_RADIO_BUTTON_d

IDS_CTRL_LISTBOX_d

IDS_CTRL_LISTBOX_d

IDS_CTRL_SCROLLTEXT_BODY_d

IDS_CTRL_SCROLLTEXT_BODY_d

IDS_CTRL_PROGRESS_BAR_d

IDS_CTRL_PROGRESS_BAR_d

IDS_CTRL_GROUP_BOX_d

IDS_CTRL_GROUP_BOX_d

IDS_CTRL_SELECT_PACKAGE_TREE_d

IDS_CTRL_SELECT_PACKAGE_TREE_d

CTRL_CHECK_BOX_d

CTRL_CHECK_BOX_d

CTRL_BUTTON_d

CTRL_BUTTON_d

CTRL_STATICTEXT_LABEL_d

CTRL_STATICTEXT_LABEL_d

CTRL_COMBOBOX_d

CTRL_COMBOBOX_d

CTRL_EDIT_d

CTRL_EDIT_d

CTRL_RADIO_BUTTON_d

CTRL_RADIO_BUTTON_d

CTRL_LIST_BOX_d

CTRL_LIST_BOX_d

CTRL_SCROLLTEXT_BODY_d

CTRL_SCROLLTEXT_BODY_d

CTRL_PROGRESS_BAR_d

CTRL_PROGRESS_BAR_d

CTRL_GROUP_BOX_d

CTRL_GROUP_BOX_d

CTRL_SELECT_PACKAGE_TREE_d

CTRL_SELECT_PACKAGE_TREE_d

IDS_CTRL_COMBOBOX_d_ITEMS

IDS_CTRL_COMBOBOX_d_ITEMS

IDS_CTRL_SCROLLTEXT_FILE_d

IDS_CTRL_SCROLLTEXT_FILE_d

WebWindow

WebWindow

IDS_CTRL_CATEGORY_NAME_d_%.3d

IDS_CTRL_CATEGORY_NAME_d_%.3d

IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d

IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d

$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $

$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $

$URL: VVV.lua.org $

$URL: VVV.lua.org $

!"#$%&'()* ,-./012

!"#$%&'()* ,-./012

#*1892 $

#*1892 $

%,3:;4-&

%,3:;4-&

'.5?

'.5?

mgM

mgM

CNotSupportedException

CNotSupportedException

GDI32.DLL

GDI32.DLL

hhctrl.ocx

hhctrl.ocx

Afx:%p:%x:%p:%p:%p

Afx:%p:%x:%p:%p:%p

Afx:%p:%x

Afx:%p:%x

commctrl_DragListMsg

commctrl_DragListMsg

CCmdTarget

CCmdTarget

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp

MSWHEEL_ROLLMSG

MSWHEEL_ROLLMSG

comctl32.dll

comctl32.dll

comdlg32.dll

comdlg32.dll

Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Software\Microsoft\Windows\CurrentVersion\Policies\Network

Software\Microsoft\Windows\CurrentVersion\Policies\Network

Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32

Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32

ntdll.dll

ntdll.dll

%s.dll

%s.dll

mfcm80.dll

mfcm80.dll

CHttpConnection

CHttpConnection

CHttpFile

CHttpFile

HTTP/1.0

HTTP/1.0

user32.dll

user32.dll

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp

ole32.dll

ole32.dll

mscoree.dll

mscoree.dll

Visual C CRT: Not enough memory to complete call to strerror.

Visual C CRT: Not enough memory to complete call to strerror.

cmd.exe

cmd.exe

command.com

command.com

Please contact the application's support team for more information.

Please contact the application's support team for more information.

- Attempt to initialize the CRT more than once.

- Attempt to initialize the CRT more than once.

- CRT not initialized

- CRT not initialized

Broken pipe

Broken pipe

Inappropriate I/O control operation

Inappropriate I/O control operation

Operation not permitted

Operation not permitted

portuguese-brazilian

portuguese-brazilian

?#%X.y

?#%X.y

operator

operator

GetProcessWindowStation

GetProcessWindowStation

USER32.DLL

USER32.DLL

OLEACC.dll

OLEACC.dll

WININET.dll

WININET.dll

InternetCrackUrlA

InternetCrackUrlA

InternetCanonicalizeUrlA

InternetCanonicalizeUrlA

HttpQueryInfoA

HttpQueryInfoA

HttpSendRequestA

HttpSendRequestA

HttpOpenRequestA

HttpOpenRequestA

.?AVCCmdTarget@@

.?AVCCmdTarget@@

.PAVCFileException@@

.PAVCFileException@@

.PAVCException@@

.PAVCException@@

.?AVCMainWindowSettings@@

.?AVCMainWindowSettings@@

.?AVCMD5@@

.?AVCMD5@@

.?AVCPasswordData@@

.?AVCPasswordData@@

.?AVCRTSessionVarMgr@@

.?AVCRTSessionVarMgr@@

.?AVCScreenCrtrMeasure@@

.?AVCScreenCrtrMeasure@@

.?AVCWebBrowser2@@

.?AVCWebBrowser2@@

.PAVCInternetException@@

.PAVCInternetException@@

.PAVCMemoryException@@

.PAVCMemoryException@@

.PAVCResourceException@@

.PAVCResourceException@@

.?AVCScreenCtrlMsg@@

.?AVCScreenCtrlMsg@@

.?AVCScreenCtrlMsgDetail@@

.?AVCScreenCtrlMsgDetail@@

Lua 5.0.2

Lua 5.0.2

attempt to %s a %s value

attempt to %s a %s value

attempt to %s %s `%s' (a %s value)

attempt to %s %s `%s' (a %s value)

attempt to compare %s with %s

attempt to compare %s with %s

attempt to compare two %s values

attempt to compare two %s values

%s:%d: %s

%s:%d: %s

system error %d

system error %d

file (%s)

file (%s)

`popen' not supported

`popen' not supported

field `%s' missing in date table

field `%s' missing in date table

^$* ?.([%-

^$* ?.([%-

missing `[' after `%%f' in pattern

missing `[' after `%%f' in pattern

no function environment for tail call at level %d

no function environment for tail call at level %d

could not load package `%s' from path `%s'

could not load package `%s' from path `%s'

error loading package `%s' (%s)

error loading package `%s' (%s)

?;?.lua

?;?.lua

bad argument #%d to `%s' (%s)

bad argument #%d to `%s' (%s)

calling `%s' on bad self (%s)

calling `%s' on bad self (%s)

%s expected, got %s

%s expected, got %s

%s:%d:

%s:%d:

stack overflow (%s)

stack overflow (%s)

cannot read %s: %s

cannot read %s: %s

`__pow' (`^' operator) is not a function

`__pow' (`^' operator) is not a function

invalid key for `next'

invalid key for `next'

too many %s (limit=%d)

too many %s (limit=%d)

%s:%d: %s near `%s'

%s:%d: %s near `%s'

char(%d)

char(%d)

`%s' expected (to close `%s' at line %d)

`%s' expected (to close `%s' at line %d)

`%s' expected

`%s' expected

bad code in %s

bad code in %s

unexpected end of file in %s

unexpected end of file in %s

bad integer in %s

bad integer in %s

bad nupvalues in %s: read %d; expected %d

bad nupvalues in %s: read %d; expected %d

bad constant type (%d) in %s

bad constant type (%d) in %s

unknown number format in %s

unknown number format in %s

%s too old: read version %d.%d; expected at least %d.%d

%s too old: read version %d.%d; expected at least %d.%d

%s too new: read version %d.%d; expected at most %d.%d

%s too new: read version %d.%d; expected at most %d.%d

bad signature in %s

bad signature in %s

virtual machine mismatch in %s: size of %s is %d but read %d

virtual machine mismatch in %s: size of %s is %d but read %d

.PAVCSimpleException@@

.PAVCSimpleException@@

.PAVCObject@@

.PAVCObject@@

.PAVCNotSupportedException@@

.PAVCNotSupportedException@@

.PAVCInvalidArgException@@

.PAVCInvalidArgException@@

.?AVCNotSupportedException@@

.?AVCNotSupportedException@@

.PAVCOleException@@

.PAVCOleException@@

.PAVCUserException@@

.PAVCUserException@@

.?AVCTestCmdUI@@

.?AVCTestCmdUI@@

.?AVCCmdUI@@

.?AVCCmdUI@@

.PAVCArchiveException@@

.PAVCArchiveException@@

.?AVCHttpConnection@@

.?AVCHttpConnection@@

.?AVCHttpFile@@

.?AVCHttpFile@@

.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@

.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@

.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@

.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@

.PAVCOleDispatchException@@

.PAVCOleDispatchException@@

zcÁ

zcÁ

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe

GetConsoleOutputCP

GetConsoleOutputCP

GetCPInfo

GetCPInfo

GetProcessHeap

GetProcessHeap

GetWindowsDirectoryA

GetWindowsDirectoryA

RegEnumKeyA

RegEnumKeyA

RegOpenKeyA

RegOpenKeyA

RegCloseKey

RegCloseKey

RegEnumKeyExA

RegEnumKeyExA

RegQueryInfoKeyA

RegQueryInfoKeyA

RegDeleteKeyA

RegDeleteKeyA

RegCreateKeyExA

RegCreateKeyExA

RegOpenKeyExA

RegOpenKeyExA

ScaleViewportExtEx

ScaleViewportExtEx

SetViewportExtEx

SetViewportExtEx

OffsetViewportOrgEx

OffsetViewportOrgEx

SetViewportOrgEx

SetViewportOrgEx

GetViewportExtEx

GetViewportExtEx

ShellExecuteA

ShellExecuteA

ShellExecuteExA

ShellExecuteExA

UrlUnescapeA

UrlUnescapeA

URLDownloadToFileA

URLDownloadToFileA

SetWindowsHookExA

SetWindowsHookExA

UnhookWindowsHookEx

UnhookWindowsHookEx

CreateDialogIndirectParamA

CreateDialogIndirectParamA

GetKeyState

GetKeyState

ExitWindowsEx

ExitWindowsEx

EnumWindows

EnumWindows

MsgWaitForMultipleObjects

MsgWaitForMultipleObjects

GetAsyncKeyState

GetAsyncKeyState

.text

.text

`.rdata

`.rdata

@.data

@.data

.rsrc

.rsrc

%xERRj3cqZQ

%xERRj3cqZQ

! !!####0

! !!####0

;;;9551%%0

;;;9551%%0

! !!565665@

! !!565665@

version="8.1.1000.0"

version="8.1.1000.0"

name="setup.exe"/>

name="setup.exe"/>

name="Microsoft.Windows.Common-Controls"

name="Microsoft.Windows.Common-Controls"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

ADVAPI32.dll

ADVAPI32.dll

COMCTL32.dll

COMCTL32.dll

GDI32.dll

GDI32.dll

NETAPI32.dll

NETAPI32.dll

OLEAUT32.dll

OLEAUT32.dll

oledlg.dll

oledlg.dll

SHELL32.dll

SHELL32.dll

SHLWAPI.dll

SHLWAPI.dll

urlmon.dll

urlmon.dll

USER32.dll

USER32.dll

VERSION.dll

VERSION.dll

WINMM.dll

WINMM.dll

WINSPOOL.DRV

WINSPOOL.DRV

accKeyboardShortcut

accKeyboardShortcut

Argument %d must be of type %s.

Argument %d must be of type %s.

%d arguments required.

%d arguments required.

All Files (*.*)

All Files (*.*)

No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.

No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.

Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.

Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.

Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.

Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.

#Unable to load mail system support.

#Unable to load mail system support.

Access to %1 was denied..An invalid file handle was associated with %1.

Access to %1 was denied..An invalid file handle was associated with %1.

Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.

Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.

Disk full while accessing %1..An attempt was made to access %1 past its end.

Disk full while accessing %1..An attempt was made to access %1 past its end.

No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.

No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.

8.1.1000.0

8.1.1000.0

2008 Indigo Rose Corporation (VVV.indigorose.com)

2008 Indigo Rose Corporation (VVV.indigorose.com)

suf80_rt.exe

suf80_rt.exe

irsetup.exe_2296_rwx_00401000_00172000:

FtPhu

FtPhu

SSSSh

SSSSh

FtPh

FtPh

SSh`UQ

SSh`UQ

SSh4UQ

SSh4UQ

SShlTQ

SShlTQ

SShDTQ

SShDTQ

u1SSh

u1SSh

Su%Sh

Su%Sh

SShx`Q

SShx`Q

txSSh

txSSh

SSh _Q

SSh _Q

@ SSh

@ SSh

.hPsQ

.hPsQ

SSShDxQ

SSShDxQ

9^$u&SSSSh?

9^$u&SSSSh?

u SSSSh?

u SSSSh?

9^$u)SSSSh?

9^$u)SSSSh?

u.VWS

u.VWS

WSSh|DQ

WSSh|DQ

udPQ

udPQ

t.Ht Ht(Ht

t.Ht Ht(Ht

y2SSh

y2SSh

FHSSh

FHSSh

GHSSh

GHSSh

GTSSh

GTSSh

G\SSh

G\SSh

FlSSh

FlSSh

Nt.Nt

Nt.Nt

SShlSR

SShlSR

tjSShHSR

tjSShHSR

t;SSh$SR

t;SSh$SR

F

F

t'SShl

t'SShl

u$SShe

u$SShe

aSSSh

aSSSh

.VVVVVSRSSj

.VVVVVSRSSj

FTPjK

FTPjK

FtPj;

FtPj;

C.PjRV

C.PjRV

diu2.iuz

diu2.iuz

MSG_ERROR

MSG_ERROR

%s %d. %s

%s %d. %s

MSG_ASK_FOR_DISK

MSG_ASK_FOR_DISK

MSG_NEW_LOCATION

MSG_NEW_LOCATION

MSG_CONFIRM_ABORT

MSG_CONFIRM_ABORT

MSG_CONFIRM

MSG_CONFIRM

A%s.%d

A%s.%d

%s, Line %d: %s

%s, Line %d: %s

File condition evaluation for file "%s"

File condition evaluation for file "%s"

C:\temp\SUF_SFX_TEST\

C:\temp\SUF_SFX_TEST\

msi.dll

msi.dll

\msi.dll

\msi.dll

Software\Microsoft\Windows\CurrentVersion\Installer

Software\Microsoft\Windows\CurrentVersion\Installer

MSG_INITIALIZING

MSG_INITIALIZING

16670749

16670749

[%d]: %s

[%d]: %s

*** LOCATION: %s

*** LOCATION: %s

__NOREPORT__

__NOREPORT__

Script: %s, %s (%s)

Script: %s, %s (%s)

__ir_eval_value = %s;

__ir_eval_value = %s;

%s (%s:%d)

%s (%s:%d)

F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl

F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl

%Copyright%. All rights reserved. %CompanyURL%

%Copyright%. All rights reserved. %CompanyURL%

WindowStyle

WindowStyle

MainWindowSettings

MainWindowSettings

%s at offset %d unterminated

%s at offset %d unterminated

Incorrect %s at offset %d

Incorrect %s at offset %d

Element '%s' at offset %d not ended

Element '%s' at offset %d not ended

End tag '%s' at offset %d does not match start tag '%s' at offset %d

End tag '%s' at offset %d does not match start tag '%s' at offset %d

No start tag for end tag '%s' at offset %d

No start tag for end tag '%s' at offset %d

%s%d bytes

%s%d bytes

%s%d wide chars to %d bytes

%s%d wide chars to %d bytes

%d bytes to %s%d wide chars

%d bytes to %s%d wide chars

MSG_SEARCH_FILE

MSG_SEARCH_FILE

(*.*)|*.*||

(*.*)|*.*||

MSG_SEARCH_ALL

MSG_SEARCH_ALL

MSG_SEARCH_MASK

MSG_SEARCH_MASK

MSG_INSERTDISK

MSG_INSERTDISK

MSG_CANCEL

MSG_CANCEL

MSG_OK

MSG_OK

MSG_BROWSE

MSG_BROWSE

MSG_PATH

MSG_PATH

Windows Server 2008

Windows Server 2008

Windows Vista

Windows Vista

Windows Server 2003

Windows Server 2003

Windows XP

Windows XP

Windows 2000

Windows 2000

Windows NT4

Windows NT4

Windows NT3

Windows NT3

Windows ME

Windows ME

Windows 98

Windows 98

Windows 95

Windows 95

CPasswordData

CPasswordData

-- Defined in _SUF70_Global_Functions.lua

-- Defined in _SUF70_Global_Functions.lua

number e_ErrorCode, string e_ErrorMsgID

number e_ErrorCode, string e_ErrorMsgID

%WindowsFolder%\%ProductName% Setup Log.txt

%WindowsFolder%\%ProductName% Setup Log.txt

%StartupFolder%

%StartupFolder%

%StartFolder%

%StartFolder%

%StartProgramsFolder%

%StartProgramsFolder%

ÞsktopFolder%

ÞsktopFolder%

%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%CommonFilesFolder%\Microsoft Shared\DAO

%CommonFilesFolder%\Microsoft Shared\DAO

Software\Microsoft\Shared Tools\DAO350.dll

Software\Microsoft\Shared Tools\DAO350.dll

Software\Microsoft\Shared Tools\DAO360.dll

Software\Microsoft\Shared Tools\DAO360.dll

ÚOPath%

ÚOPath%

Software\Microsoft\Windows NT\CurrentVersion

Software\Microsoft\Windows NT\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

%SourceFolder%

%SourceFolder%

%SystemDrive%

%SystemDrive%

_WindowsFolder

_WindowsFolder

%WindowsFolder%

%WindowsFolder%

%SystemFolder%

%SystemFolder%

%CommonFilesFolder%

%CommonFilesFolder%

%CommonFilesFolder64%

%CommonFilesFolder64%

%CommonProgramW6432%

%CommonProgramW6432%

%CommonDocumentsFolder%

%CommonDocumentsFolder%

%StartupFolderCommon%

%StartupFolderCommon%

%StartProgramsFolderCommon%

%StartProgramsFolderCommon%

%StartFolderCommon%

%StartFolderCommon%

%FontsFolder%

%FontsFolder%

ÞsktopFolderCommon%

ÞsktopFolderCommon%

UninstallSupportFiles

UninstallSupportFiles

CPRegKey

CPRegKey

Run extra uninstall script: %d

Run extra uninstall script: %d

%SourceDrive%

%SourceDrive%

%SourceFilename%

%SourceFilename%

\irsetup.dat

\irsetup.dat

Support file added to uninstall list:

Support file added to uninstall list:

Registry key added to uninstall list:

Registry key added to uninstall list:

Remove uninstall support file:

Remove uninstall support file:

Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\

Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\

Register font: %s, %s

Register font: %s, %s

%sbk%d

%sbk%d

MSG_NO

MSG_NO

MSG_YES_TOALL

MSG_YES_TOALL

MSG_YES

MSG_YES

MSG_UNINSTALL_OK_REMOVE

MSG_UNINSTALL_OK_REMOVE

MSG_UNINSTALL_NO_APP_USE

MSG_UNINSTALL_NO_APP_USE

MSG_UNINSTALL_REMOVE_SHARED

MSG_UNINSTALL_REMOVE_SHARED

Decrement shared file count: %s (New count = %d)

Decrement shared file count: %s (New count = %d)

SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs

SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs

: %s (#%d)

: %s (#%d)

Global include script: %s

Global include script: %s

RegisterTypeLib: %s

RegisterTypeLib: %s

RegisterTypeLib: %s - %s

RegisterTypeLib: %s - %s

Register COM file: %s

Register COM file: %s

Register COM file: %s - System Error # %u

Register COM file: %s - System Error # %u

Register COM file on reboot: %s

Register COM file on reboot: %s

regsvr32.exe /s %s

regsvr32.exe /s %s

SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

Increment usage count: %s

Increment usage count: %s

Increment usage count: %s (New count = %d)

Increment usage count: %s (New count = %d)

%s\%s

%s\%s

%s (%d)

%s (%d)

local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;

local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d;

MSG_SYSREQ_WARN

MSG_SYSREQ_WARN

MSG_NOTICE

MSG_NOTICE

MSG_SYSREQ_ABORT

MSG_SYSREQ_ABORT

%s: %s

%s: %s

MSG_SYSREQ_USERPERMISSION

MSG_SYSREQ_USERPERMISSION

MSG_SYSREQ_SYSTEMADMIN

MSG_SYSREQ_SYSTEMADMIN

MSG_SYSREQ_COLORDEPTH

MSG_SYSREQ_COLORDEPTH

MSG_BITSPERPIXEL

MSG_BITSPERPIXEL

MSG_SYSREQ_SCREENHEIGHT

MSG_SYSREQ_SCREENHEIGHT

MSG_SYSREQ_SCREENWIDTH

MSG_SYSREQ_SCREENWIDTH

%s: %d

%s: %d

%s: %d %s

%s: %d %s

MSG_SYSREQ_RAM

MSG_SYSREQ_RAM

MSG_SIZE_MEGABYTES

MSG_SIZE_MEGABYTES

Operating System

Operating System

MSG_SYSREQ_OS

MSG_SYSREQ_OS

MSG_OS_PART_ORNEWER

MSG_OS_PART_ORNEWER

MSG_OS_PART_NOSERVPACK

MSG_OS_PART_NOSERVPACK

MSG_OS_PART_SERVPACK

MSG_OS_PART_SERVPACK

MSG_OS_PART_SE

MSG_OS_PART_SE

MSG_OS_PART_C

MSG_OS_PART_C

MSG_OS_PART_B

MSG_OS_PART_B

MSG_OS_PART_A

MSG_OS_PART_A

MSG_OS_ALL

MSG_OS_ALL

MSG_OS_NONE

MSG_OS_NONE

MSG_OS_WSRV2008

MSG_OS_WSRV2008

MSG_OS_WVISTA

MSG_OS_WVISTA

MSG_OS_WSRV2003

MSG_OS_WSRV2003

MSG_OS_WXP

MSG_OS_WXP

MSG_OS_W2000

MSG_OS_W2000

MSG_OS_WNT4

MSG_OS_WNT4

MSG_OS_WNT3

MSG_OS_WNT3

MSG_OS_WME

MSG_OS_WME

MSG_OS_W98

MSG_OS_W98

MSG_OS_W95

MSG_OS_W95

MSG_OS_UNKNOWN

MSG_OS_UNKNOWN

MSG_SYSREQ_NOTMET

MSG_SYSREQ_NOTMET

MSG_EXP_USESLEFT

MSG_EXP_USESLEFT

MSG_EXP_USESLEFT2

MSG_EXP_USESLEFT2

%s %d %s

%s %d %s

MSG_EXP_DAYSLEFT

MSG_EXP_DAYSLEFT

MSG_EXP_DAYSLEFT2

MSG_EXP_DAYSLEFT2

Software\Microsoft\Windows\CurrentVersion\I652R9823\

Software\Microsoft\Windows\CurrentVersion\I652R9823\

MSG_EXP_CONTACT_START

MSG_EXP_CONTACT_START

MSG_SEEKING

MSG_SEEKING

Dependency Detection Passed

Dependency Detection Passed

Arc: %s

Arc: %s

FN: %s

FN: %s

%s (#%d)

%s (#%d)

MSG_SKIPPING

MSG_SKIPPING

MSG_INSTALLING

MSG_INSTALLING

Run project event: %s

Run project event: %s

local e_ErrorCode=%d; local e_ErrorMsgID = "%s"

local e_ErrorCode=%d; local e_ErrorMsgID = "%s"

Start project event: %s

Start project event: %s

MSG_UNINSTALLFILE_NOREMOVE

MSG_UNINSTALLFILE_NOREMOVE

MSG_UNINSTALLFILE_INUSE

MSG_UNINSTALLFILE_INUSE

%s (%s: %u)

%s (%s: %u)

\WININIT.INI

\WININIT.INI

MSG_FILE_EXISTS_INUSE

MSG_FILE_EXISTS_INUSE

MSG_FILE_EXISTS_RETRY

MSG_FILE_EXISTS_RETRY

MSG_FILE_EXISTS_ANY

MSG_FILE_EXISTS_ANY

MSG_FILE_EXISTS_NEWER

MSG_FILE_EXISTS_NEWER

MSG_FILE_OVERWRITE_CONFIRM

MSG_FILE_OVERWRITE_CONFIRM

%s\%s.lnk

%s\%s.lnk

%s (Return code: %d)

%s (Return code: %d)

Product: %s, version %s

Product: %s, version %s

%s (%d):

%s (%d):

MSG_PROG_UNINSTALL_CREATECONTROLFILE

MSG_PROG_UNINSTALL_CREATECONTROLFILE

ERR_CREATEUNINSTALL_OPEN_EXE_READ

ERR_CREATEUNINSTALL_OPEN_EXE_READ

ERR_CREATEUNINSTALL_OPEN_EXE_WRITE

ERR_CREATEUNINSTALL_OPEN_EXE_WRITE

Overwrite uninstall executable:

Overwrite uninstall executable:

MSG_PROG_UNINSTALL_CREATEEXE

MSG_PROG_UNINSTALL_CREATEEXE

@MSG_PROG_UNINSTALL_CREATEDATFILE

@MSG_PROG_UNINSTALL_CREATEDATFILE

?MSG_PROG_UNINSTALL_CREATEFOLDER

?MSG_PROG_UNINSTALL_CREATEFOLDER

"/U:%s"

"/U:%s"

MSG_PROG_UNINSTALL_CREATESC

MSG_PROG_UNINSTALL_CREATESC

Create uninstall CP entry key

Create uninstall CP entry key

ERR_CREATEUNINSTALL_CREATEREGKEY

ERR_CREATEUNINSTALL_CREATEREGKEY

"%s",%d

"%s",%d

Uninstall CP entry: URLUpdateInfo =

Uninstall CP entry: URLUpdateInfo =

URLUpdateInfo

URLUpdateInfo

Uninstall CP entry: URLInfoAbout =

Uninstall CP entry: URLInfoAbout =

URLInfoAbout

URLInfoAbout

"%s" "/U:%s"

"%s" "/U:%s"

HKEY_LOCAL_MACHINE\

HKEY_LOCAL_MACHINE\

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\

MSG_PROG_UNINSTALL_CREATECPENTRY

MSG_PROG_UNINSTALL_CREATECPENTRY

MSG_PROG_UNINSTALL_COPYSUPPORTFILES

MSG_PROG_UNINSTALL_COPYSUPPORTFILES

MSG_PROG_UNINSTALL_COPYPLUGINS

MSG_PROG_UNINSTALL_COPYPLUGINS

%s %s

%s %s

MSG_REQUIRED_DRIVE

MSG_REQUIRED_DRIVE

MSG_AVAILABLE_DRIVE

MSG_AVAILABLE_DRIVE

MSG_PROG_CHECKING_DRIVESPACE

MSG_PROG_CHECKING_DRIVESPACE

MSG_PROG_CHECKING_FILES

MSG_PROG_CHECKING_FILES

%A, %B %d, %Y

%A, %B %d, %Y

[%s] %s

[%s] %s

%m/%d/%Y %H:%M:%S

%m/%d/%Y %H:%M:%S

MsgFile

MsgFile

ERR_MSI_PATCH_REMOVAL_UNSUPPORTED

ERR_MSI_PATCH_REMOVAL_UNSUPPORTED

ERR_MSI_PATCH_PACKAGE_UNSUPPORTED

ERR_MSI_PATCH_PACKAGE_UNSUPPORTED

ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED

ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED

ERR_MSI_UNSUPPORTED_TYPE

ERR_MSI_UNSUPPORTED_TYPE

ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED

ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED

ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD

ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD

ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE

ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE

ERR_ODBC_INVALID_KEYWORD_VALUE

ERR_ODBC_INVALID_KEYWORD_VALUE

ERR_WEB_503

ERR_WEB_503

ERR_WEB_500

ERR_WEB_500

ERR_WEB_404

ERR_WEB_404

ERR_WEB_403

ERR_WEB_403

ERR_WEB_400

ERR_WEB_400

ERR_WEB_SET_PROXY_PASSWORD

ERR_WEB_SET_PROXY_PASSWORD

ERR_WEB_SET_PROXY_USERNAME

ERR_WEB_SET_PROXY_USERNAME

ERR_WEB_WRITE_MEMORY

ERR_WEB_WRITE_MEMORY

ERR_WEB_FTP_FILE_OPEN

ERR_WEB_FTP_FILE_OPEN

ERR_WEB_USER_ABORT

ERR_WEB_USER_ABORT

ERR_WEB_FILE_WRITE

ERR_WEB_FILE_WRITE

ERR_WEB_DOWNLOAD_FILE_ERROR

ERR_WEB_DOWNLOAD_FILE_ERROR

ERR_WEB_INVALID_HTTP_RESPONSE

ERR_WEB_INVALID_HTTP_RESPONSE

ERR_WEB_DESTINATION_FILE_OPEN

ERR_WEB_DESTINATION_FILE_OPEN

ERR_WEB_SEND_REQUEST

ERR_WEB_SEND_REQUEST

ERR_WEB_OPEN_REQUEST

ERR_WEB_OPEN_REQUEST

ERR_WEB_CREATE_HTTP_CONNECTION

ERR_WEB_CREATE_HTTP_CONNECTION

ERR_WEB_CREATE_INTERNET_SESSION

ERR_WEB_CREATE_INTERNET_SESSION

ERR_REG_GET_SUB_KEY_NAME

ERR_REG_GET_SUB_KEY_NAME

ERR_REG_NON_EXISTANT_SUB_KEY

ERR_REG_NON_EXISTANT_SUB_KEY

ERR_REG_DELETE_KEY

ERR_REG_DELETE_KEY

ERR_REG_CREATE_KEY

ERR_REG_CREATE_KEY

ERR_FILE_EXECUTION_FAILED_ELEVATION

ERR_FILE_EXECUTION_FAILED_ELEVATION

ERR_KEY_RUN_ON_REBOOT_FAILED

ERR_KEY_RUN_ON_REBOOT_FAILED

ERR_USER_ABORTED_OPERATION

ERR_USER_ABORTED_OPERATION

ERR_NON_EXISTANT_VIEWER_EXE

ERR_NON_EXISTANT_VIEWER_EXE

ERR_FILE_EXECUTION_FAILED

ERR_FILE_EXECUTION_FAILED

ERR_SPECIFIED_EXE_FILE_INVALID

ERR_SPECIFIED_EXE_FILE_INVALID

MSG_SUCCESS

MSG_SUCCESS

Language set: Primary = %d, Secondary = %d

Language set: Primary = %d, Secondary = %d

%CompanyURL%

%CompanyURL%

%CompanyName%

%CompanyName%

UxTheme.dll

UxTheme.dll

%Copyright% %CompanyName%. All rights reserved. %CompanyURL%

%Copyright% %CompanyName%. All rights reserved. %CompanyURL%

%WindowsFolder%\%ProductName% Uninstall Log.txt

%WindowsFolder%\%ProductName% Uninstall Log.txt

%CompanyName% Support Department

%CompanyName% Support Department

%WindowsFolder%\%ProductName%\uninstall.exe

%WindowsFolder%\%ProductName%\uninstall.exe

uninstall.xml

uninstall.xml

CWebBrowser2

CWebBrowser2

Confirm Operation

Confirm Operation

kernel32.dll

kernel32.dll

KERNEL32.DLL

KERNEL32.DLL

PSAPI.DLL

PSAPI.DLL

Kernel32.dll

Kernel32.dll

WS2_32.DLL

WS2_32.DLL

Copying "%s"

Copying "%s"

"%s" %s

"%s" %s

%d.%d.%d.%d

%d.%d.%d.%d

\StringFileInfo\xx\ProductVersion

\StringFileInfo\xx\ProductVersion

\StringFileInfo\xx\PrivateBuild

\StringFileInfo\xx\PrivateBuild

.bak%d

.bak%d

Windows NT 4

Windows NT 4

Windows NT 3

Windows NT 3

%s\shell\open\command

%s\shell\open\command

NUL=%s

NUL=%s

Software\Microsoft\Windows NT\CurrentVersion\Fonts

Software\Microsoft\Windows NT\CurrentVersion\Fonts

Software\Microsoft\Windows\CurrentVersion\Fonts

Software\Microsoft\Windows\CurrentVersion\Fonts

***!!!***@@

***!!!***@@

Advapi32.dll

Advapi32.dll

Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

%s\%s.url

%s\%s.url

%s\%s.pif

%s\%s.pif

srclient.dll

srclient.dll

%s_%d

%s_%d

%s\_ir_tmpfnt_%d

%s\_ir_tmpfnt_%d

/\:*?"|

/\:*?"|

jsproxy.dll

jsproxy.dll

DetectAutoProxyUrl

DetectAutoProxyUrl

wininet.dll

wininet.dll

%%x

%%x

d:d

d:d

WinINet.dll

WinINet.dll

Could not create Internet session: %u

Could not create Internet session: %u

Error downloading file: %u

Error downloading file: %u

Error writing the destination file: %d-%u

Error writing the destination file: %d-%u

Could not create HTTP connection: %u

Could not create HTTP connection: %u

Could not create HTTP connection

Could not create HTTP connection

Incorrect HTTP status returned by server: %d

Incorrect HTTP status returned by server: %d

Send request failed: %u

Send request failed: %u

Content-Type: application/x-www-form-urlencoded

Content-Type: application/x-www-form-urlencoded

Could not open HTTP file: %s

Could not open HTTP file: %s

PTF://

PTF://

hXXps://

hXXps://

hXXp://

hXXp://

Could not open request: %u

Could not open request: %u

Could not HTTP file: %u

Could not HTTP file: %u

MSG_STATUS_HANDLE_CREATED

MSG_STATUS_HANDLE_CREATED

MSG_STATUS_HANDLE_CLOSING

MSG_STATUS_HANDLE_CLOSING

MSG_STATUS_REQUEST_COMPLETE

MSG_STATUS_REQUEST_COMPLETE

MSG_REDIRECTING

MSG_REDIRECTING

MSG_CONNECTION_CLOSED

MSG_CONNECTION_CLOSED

MSG_RESOLVING_HOST_NAME

MSG_RESOLVING_HOST_NAME

MSG_HOST_NAME_RESOLVED

MSG_HOST_NAME_RESOLVED

MSG_CONNECTING_TO_SERVER

MSG_CONNECTING_TO_SERVER

MSG_CONNECTED_TO_SERVER

MSG_CONNECTED_TO_SERVER

MSG_CLOSING_CONNECTION

MSG_CLOSING_CONNECTION

TRACE: LastError = %d ("%s")

TRACE: LastError = %d ("%s")

Script: %s, %s

Script: %s, %s

Script: %s, Line %d

Script: %s, Line %d

All Files (*.*)|*.*|

All Files (*.*)|*.*|

PasswordInput

PasswordInput

MSG_MOVING

MSG_MOVING

MSG_COPYING

MSG_COPYING

MSG_FROM

MSG_FROM

MSG_TO

MSG_TO

MSG_DELETING

MSG_DELETING

MSG_SEARCHING

MSG_SEARCHING

\StringFileInfo\xx\SpecialBuild

\StringFileInfo\xx\SpecialBuild

\StringFileInfo\xx\OriginalFilename

\StringFileInfo\xx\OriginalFilename

\StringFileInfo\xx\Comments

\StringFileInfo\xx\Comments

\StringFileInfo\xx\LegalTrademarks

\StringFileInfo\xx\LegalTrademarks

\StringFileInfo\xx\LegalCopyright

\StringFileInfo\xx\LegalCopyright

\StringFileInfo\xx\ProductName

\StringFileInfo\xx\ProductName

\StringFileInfo\xx\InternalName

\StringFileInfo\xx\InternalName

\StringFileInfo\xx\FileDescription

\StringFileInfo\xx\FileDescription

\StringFileInfo\xx\CompanyName

\StringFileInfo\xx\CompanyName

ErrorMsg

ErrorMsg

%Y-%m-%dT%H:%M:%S

%Y-%m-%dT%H:%M:%S

MSG_INSTALL_DO_YOU_WANT_OVERWRITE

MSG_INSTALL_DO_YOU_WANT_OVERWRITE

MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG

MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG

MSG_INSTALL_FILE_OLDER_MSG

MSG_INSTALL_FILE_OLDER_MSG

OpenURL

OpenURL

\msiexec.exe

\msiexec.exe

RunMsiexec

RunMsiexec

SQLInstallerError

SQLInstallerError

SQLRemoveDriverManager

SQLRemoveDriverManager

odbccp32.dll

odbccp32.dll

SQLConfigDataSource

SQLConfigDataSource

SQLInstallDriverEx

SQLInstallDriverEx

SQLInstallDriverManager

SQLInstallDriverManager

SQLRemoveDriver

SQLRemoveDriver

\Kernel32.dll

\Kernel32.dll

GetKeyNames

GetKeyNames

DoesKeyExist

DoesKeyExist

DeleteKey

DeleteKey

CreateKey

CreateKey

ShortcutKey

ShortcutKey

keycode

keycode

SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders

MSG_SIZE_BYTES

MSG_SIZE_BYTES

P?MSG_SIZE_KILOBYTES

P?MSG_SIZE_KILOBYTES

>MSG_SIZE_GIGABYTES

>MSG_SIZE_GIGABYTES

xxxxxx

xxxxxx

%s-%s-%s

%s-%s-%s

%s/%s/%s

%s/%s/%s

%s:%s:%s

%s:%s:%s

%d:%s:%s AM

%d:%s:%s AM

%d:%s:%s PM

%d:%s:%s PM

MSG_REBOOT_FAILED

MSG_REBOOT_FAILED

WININET.DLL

WININET.DLL

PPassword

PPassword

Password

Password

%s %s %s %s (%0.2f %s)

%s %s %s %s (%0.2f %s)

%0.1f %s/%0.1f %s

%0.1f %s/%0.1f %s

%I64u %s/%I64u %s

%I64u %s/%I64u %s

MSG_KB_PER_SEC

MSG_KB_PER_SEC

MSG_ESTIMATED_TIME_LEFT

MSG_ESTIMATED_TIME_LEFT

MSG_SAVING

MSG_SAVING

MSG_DOWNLOADING

MSG_DOWNLOADING

%s %s %s %s

%s %s %s %s

MSG_QUERYING_INTERNET

MSG_QUERYING_INTERNET

MSG_READING

MSG_READING

GetHTTPErrorInfo

GetHTTPErrorInfo

%s > %s

%s > %s

local e_CtrlID=%d; local e_MsgID=%d;

local e_CtrlID=%d; local e_MsgID=%d;

Button%d

Button%d

Check%d

Check%d

ComboBox%d

ComboBox%d

Edit%d

Edit%d

Space available on selected drive: %SpaceAvailable%

Space available on selected drive: %SpaceAvailable%

Space required: %SpaceRequired%

Space required: %SpaceRequired%

Error: The specified file: '%s' could not be found.

Error: The specified file: '%s' could not be found.

Error: The specified file: '%s' could not be opened.

Error: The specified file: '%s' could not be opened.

Error: The specified file: '%s' is too large to read.

Error: The specified file: '%s' is too large to read.

Error: The specified file: '%s' could not be read.

Error: The specified file: '%s' could not be read.

number e_CtrlID, number e_MsgID, table e_Details

number e_CtrlID, number e_MsgID, table e_Details

Application.Exit();

Application.Exit();

Screen.Next();

Screen.Next();

Screen.Back();

Screen.Back();

Radio%d

Radio%d

Total space required: %SpaceRequired%

Total space required: %SpaceRequired%

IDS_CTRL_CHECK_BOX_d

IDS_CTRL_CHECK_BOX_d

IDS_CTRL_BUTTON_d

IDS_CTRL_BUTTON_d

IDS_CTRL_STATICTEXT_LABEL_d

IDS_CTRL_STATICTEXT_LABEL_d

IDS_CTRL_COMBOBOX_d_DEFAULT

IDS_CTRL_COMBOBOX_d_DEFAULT

IDS_CTRL_EDIT_d

IDS_CTRL_EDIT_d

IDS_CTRL_RADIO_BUTTON_d

IDS_CTRL_RADIO_BUTTON_d

IDS_CTRL_LISTBOX_d

IDS_CTRL_LISTBOX_d

IDS_CTRL_SCROLLTEXT_BODY_d

IDS_CTRL_SCROLLTEXT_BODY_d

IDS_CTRL_PROGRESS_BAR_d

IDS_CTRL_PROGRESS_BAR_d

IDS_CTRL_GROUP_BOX_d

IDS_CTRL_GROUP_BOX_d

IDS_CTRL_SELECT_PACKAGE_TREE_d

IDS_CTRL_SELECT_PACKAGE_TREE_d

CTRL_CHECK_BOX_d

CTRL_CHECK_BOX_d

CTRL_BUTTON_d

CTRL_BUTTON_d

CTRL_STATICTEXT_LABEL_d

CTRL_STATICTEXT_LABEL_d

CTRL_COMBOBOX_d

CTRL_COMBOBOX_d

CTRL_EDIT_d

CTRL_EDIT_d

CTRL_RADIO_BUTTON_d

CTRL_RADIO_BUTTON_d

CTRL_LIST_BOX_d

CTRL_LIST_BOX_d

CTRL_SCROLLTEXT_BODY_d

CTRL_SCROLLTEXT_BODY_d

CTRL_PROGRESS_BAR_d

CTRL_PROGRESS_BAR_d

CTRL_GROUP_BOX_d

CTRL_GROUP_BOX_d

CTRL_SELECT_PACKAGE_TREE_d

CTRL_SELECT_PACKAGE_TREE_d

IDS_CTRL_COMBOBOX_d_ITEMS

IDS_CTRL_COMBOBOX_d_ITEMS

IDS_CTRL_SCROLLTEXT_FILE_d

IDS_CTRL_SCROLLTEXT_FILE_d

WebWindow

WebWindow

IDS_CTRL_CATEGORY_NAME_d_%.3d

IDS_CTRL_CATEGORY_NAME_d_%.3d

IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d

IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d

$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $

$Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $

$URL: VVV.lua.org $

$URL: VVV.lua.org $

!"#$%&'()* ,-./012

!"#$%&'()* ,-./012

#*1892 $

#*1892 $

%,3:;4-&

%,3:;4-&

'.5?

'.5?

mgM

mgM

CNotSupportedException

CNotSupportedException

GDI32.DLL

GDI32.DLL

hhctrl.ocx

hhctrl.ocx

Afx:%p:%x:%p:%p:%p

Afx:%p:%x:%p:%p:%p

Afx:%p:%x

Afx:%p:%x

commctrl_DragListMsg

commctrl_DragListMsg

CCmdTarget

CCmdTarget

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp

MSWHEEL_ROLLMSG

MSWHEEL_ROLLMSG

comctl32.dll

comctl32.dll

comdlg32.dll

comdlg32.dll

Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

Software\Microsoft\Windows\CurrentVersion\Policies\Network

Software\Microsoft\Windows\CurrentVersion\Policies\Network

Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32

Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32

ntdll.dll

ntdll.dll

%s.dll

%s.dll

mfcm80.dll

mfcm80.dll

CHttpConnection

CHttpConnection

CHttpFile

CHttpFile

HTTP/1.0

HTTP/1.0

user32.dll

user32.dll

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp

f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp

ole32.dll

ole32.dll

mscoree.dll

mscoree.dll

Visual C CRT: Not enough memory to complete call to strerror.

Visual C CRT: Not enough memory to complete call to strerror.

cmd.exe

cmd.exe

command.com

command.com

Please contact the application's support team for more information.

Please contact the application's support team for more information.

- Attempt to initialize the CRT more than once.

- Attempt to initialize the CRT more than once.

- CRT not initialized

- CRT not initialized

Broken pipe

Broken pipe

Inappropriate I/O control operation

Inappropriate I/O control operation

Operation not permitted

Operation not permitted

portuguese-brazilian

portuguese-brazilian

?#%X.y

?#%X.y

operator

operator

GetProcessWindowStation

GetProcessWindowStation

USER32.DLL

USER32.DLL

OLEACC.dll

OLEACC.dll

WININET.dll

WININET.dll

InternetCrackUrlA

InternetCrackUrlA

InternetCanonicalizeUrlA

InternetCanonicalizeUrlA

HttpQueryInfoA

HttpQueryInfoA

HttpSendRequestA

HttpSendRequestA

HttpOpenRequestA

HttpOpenRequestA

.?AVCCmdTarget@@

.?AVCCmdTarget@@

.PAVCFileException@@

.PAVCFileException@@

.PAVCException@@

.PAVCException@@

.?AVCMainWindowSettings@@

.?AVCMainWindowSettings@@

.?AVCMD5@@

.?AVCMD5@@

.?AVCPasswordData@@

.?AVCPasswordData@@

.?AVCRTSessionVarMgr@@

.?AVCRTSessionVarMgr@@

.?AVCScreenCrtrMeasure@@

.?AVCScreenCrtrMeasure@@

.?AVCWebBrowser2@@

.?AVCWebBrowser2@@

.PAVCInternetException@@

.PAVCInternetException@@

.PAVCMemoryException@@

.PAVCMemoryException@@

.PAVCResourceException@@

.PAVCResourceException@@

.?AVCScreenCtrlMsg@@

.?AVCScreenCtrlMsg@@

.?AVCScreenCtrlMsgDetail@@

.?AVCScreenCtrlMsgDetail@@

Lua 5.0.2

Lua 5.0.2

attempt to %s a %s value

attempt to %s a %s value

attempt to %s %s `%s' (a %s value)

attempt to %s %s `%s' (a %s value)

attempt to compare %s with %s

attempt to compare %s with %s

attempt to compare two %s values

attempt to compare two %s values

%s:%d: %s

%s:%d: %s

system error %d

system error %d

file (%s)

file (%s)

`popen' not supported

`popen' not supported

field `%s' missing in date table

field `%s' missing in date table

^$* ?.([%-

^$* ?.([%-

missing `[' after `%%f' in pattern

missing `[' after `%%f' in pattern

no function environment for tail call at level %d

no function environment for tail call at level %d

could not load package `%s' from path `%s'

could not load package `%s' from path `%s'

error loading package `%s' (%s)

error loading package `%s' (%s)

?;?.lua

?;?.lua

bad argument #%d to `%s' (%s)

bad argument #%d to `%s' (%s)

calling `%s' on bad self (%s)

calling `%s' on bad self (%s)

%s expected, got %s

%s expected, got %s

%s:%d:

%s:%d:

stack overflow (%s)

stack overflow (%s)

cannot read %s: %s

cannot read %s: %s

`__pow' (`^' operator) is not a function

`__pow' (`^' operator) is not a function

invalid key for `next'

invalid key for `next'

too many %s (limit=%d)

too many %s (limit=%d)

%s:%d: %s near `%s'

%s:%d: %s near `%s'

char(%d)

char(%d)

`%s' expected (to close `%s' at line %d)

`%s' expected (to close `%s' at line %d)

`%s' expected

`%s' expected

bad code in %s

bad code in %s

unexpected end of file in %s

unexpected end of file in %s

bad integer in %s

bad integer in %s

bad nupvalues in %s: read %d; expected %d

bad nupvalues in %s: read %d; expected %d

bad constant type (%d) in %s

bad constant type (%d) in %s

unknown number format in %s

unknown number format in %s

%s too old: read version %d.%d; expected at least %d.%d

%s too old: read version %d.%d; expected at least %d.%d

%s too new: read version %d.%d; expected at most %d.%d

%s too new: read version %d.%d; expected at most %d.%d

bad signature in %s

bad signature in %s

virtual machine mismatch in %s: size of %s is %d but read %d

virtual machine mismatch in %s: size of %s is %d but read %d

.PAVCSimpleException@@

.PAVCSimpleException@@

.PAVCObject@@

.PAVCObject@@

.PAVCNotSupportedException@@

.PAVCNotSupportedException@@

.PAVCInvalidArgException@@

.PAVCInvalidArgException@@

.?AVCNotSupportedException@@

.?AVCNotSupportedException@@

.PAVCOleException@@

.PAVCOleException@@

.PAVCUserException@@

.PAVCUserException@@

.?AVCTestCmdUI@@

.?AVCTestCmdUI@@

.?AVCCmdUI@@

.?AVCCmdUI@@

.PAVCArchiveException@@

.PAVCArchiveException@@

.?AVCHttpConnection@@

.?AVCHttpConnection@@

.?AVCHttpFile@@

.?AVCHttpFile@@

.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@

.?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@

.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@

.?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@

.PAVCOleDispatchException@@

.PAVCOleDispatchException@@

zcÁ

zcÁ

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe

GetConsoleOutputCP

GetConsoleOutputCP

GetCPInfo

GetCPInfo

GetProcessHeap

GetProcessHeap

GetWindowsDirectoryA

GetWindowsDirectoryA

RegEnumKeyA

RegEnumKeyA

RegOpenKeyA

RegOpenKeyA

RegCloseKey

RegCloseKey

RegEnumKeyExA

RegEnumKeyExA

RegQueryInfoKeyA

RegQueryInfoKeyA

RegDeleteKeyA

RegDeleteKeyA

RegCreateKeyExA

RegCreateKeyExA

RegOpenKeyExA

RegOpenKeyExA

ScaleViewportExtEx

ScaleViewportExtEx

SetViewportExtEx

SetViewportExtEx

OffsetViewportOrgEx

OffsetViewportOrgEx

SetViewportOrgEx

SetViewportOrgEx

GetViewportExtEx

GetViewportExtEx

ShellExecuteA

ShellExecuteA

ShellExecuteExA

ShellExecuteExA

UrlUnescapeA

UrlUnescapeA

URLDownloadToFileA

URLDownloadToFileA

SetWindowsHookExA

SetWindowsHookExA

UnhookWindowsHookEx

UnhookWindowsHookEx

CreateDialogIndirectParamA

CreateDialogIndirectParamA

GetKeyState

GetKeyState

ExitWindowsEx

ExitWindowsEx

EnumWindows

EnumWindows

MsgWaitForMultipleObjects

MsgWaitForMultipleObjects

GetAsyncKeyState

GetAsyncKeyState

.text

.text

`.rdata

`.rdata

@.data

@.data

.rsrc

.rsrc

accKeyboardShortcut

accKeyboardShortcut

Argument %d must be of type %s.

Argument %d must be of type %s.

%d arguments required.

%d arguments required.

All Files (*.*)

All Files (*.*)

No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.

No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.

Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.

Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.

Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.

Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.

#Unable to load mail system support.

#Unable to load mail system support.

Access to %1 was denied..An invalid file handle was associated with %1.

Access to %1 was denied..An invalid file handle was associated with %1.

Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.

Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.

Disk full while accessing %1..An attempt was made to access %1 past its end.

Disk full while accessing %1..An attempt was made to access %1 past its end.

No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.

No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.

DTLite4413-0173.exe_1672:

.text

.text

`.rdata

`.rdata

@.data

@.data

.ndata

.ndata

.rsrc

.rsrc

RegDeleteKeyExW

RegDeleteKeyExW

Kernel32.DLL

Kernel32.DLL

PSAPI.DLL

PSAPI.DLL

%s=%s

%s=%s

GetWindowsDirectoryW

GetWindowsDirectoryW

KERNEL32.dll

KERNEL32.dll

ExitWindowsEx

ExitWindowsEx

USER32.dll

USER32.dll

GDI32.dll

GDI32.dll

SHFileOperationW

SHFileOperationW

ShellExecuteW

ShellExecuteW

SHELL32.dll

SHELL32.dll

RegDeleteKeyW

RegDeleteKeyW

RegCloseKey

RegCloseKey

RegEnumKeyW

RegEnumKeyW

RegOpenKeyExW

RegOpenKeyExW

RegCreateKeyExW

RegCreateKeyExW

ADVAPI32.dll

ADVAPI32.dll

COMCTL32.dll

COMCTL32.dll

ole32.dll

ole32.dll

VERSION.dll

VERSION.dll

%U/nE

%U/nE

q4*.rIY

q4*.rIY

.cr1h

.cr1h

;$;(;,;0;4;8;

;$;(;,;0;4;8;

4 4@4\4`4

4 4@4\4`4

2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.

2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.

3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

hXXps://VVV.verisign.com/rpa0

hXXps://VVV.verisign.com/rpa0

hXXp://ocsp.verisign.com0?

hXXp://ocsp.verisign.com0?

3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

.Class 3 Public Primary Certification Authority0

.Class 3 Public Primary Certification Authority0

hXXps://VVV.verisign.com/cps0*

hXXps://VVV.verisign.com/cps0*

#hXXp://logo.verisign.com/vslogo.gif0

#hXXp://logo.verisign.com/vslogo.gif0

hXXp://ocsp.verisign.com01

hXXp://ocsp.verisign.com01

hXXp://crl.verisign.com/pca3.crl0)

hXXp://crl.verisign.com/pca3.crl0)

hXXp://ocsp.verisign.com0

hXXp://ocsp.verisign.com0

"hXXp://crl.verisign.com/tss-ca.crl0

"hXXp://crl.verisign.com/tss-ca.crl0

Thawte Certification1

Thawte Certification1

0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0

0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0

Nullsoft Install System v2.46-Unicode

Nullsoft Install System v2.46-Unicode

verifying installer: %d%%

verifying installer: %d%%

unpacking data: %d%%

unpacking data: %d%%

... %d%%

... %d%%

hXXp://nsis.sf.net/NSIS_Error

hXXp://nsis.sf.net/NSIS_Error

~nsu.tmp

~nsu.tmp

%u.%u%s%s

%u.%u%s%s

.DEFAULT\Control Panel\International

.DEFAULT\Control Panel\International

Software\Microsoft\Windows\CurrentVersion

Software\Microsoft\Windows\CurrentVersion

*?|/":

*?|/":

pData\Local\Temp\nsr342B.tmp\setuphlp.dll

pData\Local\Temp\nsr342B.tmp\setuphlp.dll

0173.exe /S

0173.exe /S

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll

ON Tools Lite\DTGadget.lnk

ON Tools Lite\DTGadget.lnk

te.lnk

te.lnk

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp

6.exe

6.exe

Monkey's Audio!

Monkey's Audio!

Windows Media Audio

Windows Media Audio

`~!@#$^&*() =[]{}\:;'",|/

`~!@#$^&*() =[]{}\:;'",|/

nsr342B.tmp

nsr342B.tmp

\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S

\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S

342B.tmp\Lang\

342B.tmp\Lang\

\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp

\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S

%Program Files%\DAEMON Tools Lite

%Program Files%\DAEMON Tools Lite

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0

DTLite4413-0173.exe

DTLite4413-0173.exe

ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp

ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe

Windows Gadget

Windows Gadget

Integrate with Windows Explorer

Integrate with Windows Explorer

SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features.

SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features.

Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop.

Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop.

4.41.3.0173.0

4.41.3.0173.0

DAEMONSetup4.41.3.0173.exe

DAEMONSetup4.41.3.0173.exe

dinotify.exe_3912:

.text

.text

`.data

`.data

.rsrc

.rsrc

@.reloc

@.reloc

KERNEL32.dll

KERNEL32.dll

msvcrt.dll

msvcrt.dll

pnpui.dll

pnpui.dll

dinotify.pdb

dinotify.pdb

_amsg_exit

_amsg_exit

version="1.0.0.0"

version="1.0.0.0"

name="DINotify.exe"

name="DINotify.exe"

name="Microsoft.Windows.Common-Controls"

name="Microsoft.Windows.Common-Controls"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

pnpui.dll,SimplifiedDINotification

pnpui.dll,SimplifiedDINotification

Windows Device Installation

Windows Device Installation

6.1.7600.16385 (win7_rtm.090713-1255)

6.1.7600.16385 (win7_rtm.090713-1255)

dinotify.exe

dinotify.exe

Windows

Windows

Operating System

Operating System

6.1.7600.16385

6.1.7600.16385

sidebar.exe_1808:

.text

.text

`.data

`.data

.rsrc

.rsrc

@.reloc

@.reloc

ADVAPI32.dll

ADVAPI32.dll

ntdll.DLL

ntdll.DLL

KERNEL32.dll

KERNEL32.dll

GDI32.dll

GDI32.dll

USER32.dll

USER32.dll

msvcrt.dll

msvcrt.dll

ATL.DLL

ATL.DLL

ole32.dll

ole32.dll

OLEAUT32.dll

OLEAUT32.dll

COMCTL32.dll

COMCTL32.dll

gdiplus.dll

gdiplus.dll

SHLWAPI.dll

SHLWAPI.dll

SHELL32.dll

SHELL32.dll

urlmon.dll

urlmon.dll

CRYPT32.dll

CRYPT32.dll

sfc_os.dll

sfc_os.dll

dwmapi.dll

dwmapi.dll

CRYPTUI.dll

CRYPTUI.dll

UxTheme.dll

UxTheme.dll

SSShZ

SSShZ

SSSSSSh

SSSSSSh

FTPQ

FTPQ

#SSSh

#SSSh

1.1.4

1.1.4

1.3.6.1.4.1.311.2.1.12

1.3.6.1.4.1.311.2.1.12

DwmApplyWindowScaleFactor

DwmApplyWindowScaleFactor

FTPh

FTPh

SSShw

SSShw

PSSh|

PSSh|

tWHt;Ht.Ht

tWHt;Ht.Ht

sidebar.exe

sidebar.exe

WININET.dll

WININET.dll

WTSAPI32.dll

WTSAPI32.dll

WINMM.dll

WINMM.dll

IPHLPAPI.DLL

IPHLPAPI.DLL

WINTRUST.dll

WINTRUST.dll

PROPSYS.dll

PROPSYS.dll

Wlanapi.dll

Wlanapi.dll

wlanutil.dll

wlanutil.dll

OLEACC.dll

OLEACC.dll

COMDLG32.dll

COMDLG32.dll

InternetCreateUrlW

InternetCreateUrlW

InternetCrackUrlW

InternetCrackUrlW

GetUrlCacheEntryInfoW

GetUrlCacheEntryInfoW

PSGetPropertyKeyFromName

PSGetPropertyKeyFromName

ntdll.dll

ntdll.dll

RegCloseKey

RegCloseKey

RegOpenKeyExW

RegOpenKeyExW

RegNotifyChangeKeyValue

RegNotifyChangeKeyValue

RegDeleteKeyW

RegDeleteKeyW

ReportEventW

ReportEventW

GetProcessHeap

GetProcessHeap

RegEnumKeyExW

RegEnumKeyExW

GetSystemWindowsDirectoryW

GetSystemWindowsDirectoryW

RegCreateKeyExW

RegCreateKeyExW

SetViewportOrgEx

SetViewportOrgEx

GetKeyState

GetKeyState

GetKeyboardState

GetKeyboardState

UnregisterHotKey

UnregisterHotKey

RegisterHotKey

RegisterHotKey

MsgWaitForMultipleObjectsEx

MsgWaitForMultipleObjectsEx

GetAsyncKeyState

GetAsyncKeyState

_amsg_exit

_amsg_exit

_acmdln

_acmdln

GdipSetPenLineJoin

GdipSetPenLineJoin

GdipSetImageAttributesColorKeys

GdipSetImageAttributesColorKeys

GdiplusShutdown

GdiplusShutdown

PathIsURLW

PathIsURLW

UrlIsW

UrlIsW

UrlEscapeW

UrlEscapeW

PathCreateFromUrlW

PathCreateFromUrlW

UrlUnescapeW

UrlUnescapeW

ShellExecuteW

ShellExecuteW

SHFileOperationW

SHFileOperationW

ShellExecuteExW

ShellExecuteExW

URLOpenBlockingStreamW

URLOpenBlockingStreamW

CreateURLMoniker

CreateURLMoniker

CertCloseStore

CertCloseStore

CertFreeCertificateContext

CertFreeCertificateContext

CertGetNameStringW

CertGetNameStringW

CertFindCertificateInStore

CertFindCertificateInStore

CryptMsgGetParam

CryptMsgGetParam

CryptMsgClose

CryptMsgClose

CryptUIDlgViewCertificateW

CryptUIDlgViewCertificateW

sidebar.pdb

sidebar.pdb

name="Microsoft.Windows.Sidebar"

name="Microsoft.Windows.Sidebar"

version="1.0.0.0"

version="1.0.0.0"

Windows Sidebar

Windows Sidebar

name="Microsoft.Windows.Common-Controls"

name="Microsoft.Windows.Common-Controls"

version="6.0.0.0"

version="6.0.0.0"

publicKeyToken="6595b64144ccf1df"

publicKeyToken="6595b64144ccf1df"

stdole2.tlbWWWp)

stdole2.tlbWWWp)

vOperationWW

vOperationWW

.ssid

.ssid

.backgroundWW

.backgroundWW

.lpbstrStdDisplayNameWD

.lpbstrStdDisplayNameWD

KEYWh

KEYWh

"" ,,/,**)((

"" ,,/,**)((

!

!

yuussHIBA@

yuussHIBA@

wfb=3/-A}

wfb=3/-A}

444600,,)''%%$$

444600,,)''%%$$

"

"

=55/** ('%%$$

=55/** ('%%$$

@

@

!!//---*)(

!!//---*)(

62.*(&$#

62.*(&$#

,63.*)&$$##

,63.*)&$$##

/963.*)&#

/963.*)&#

L[Q9930.*'$$&.LhmlEF

L[Q9930.*'$$&.LhmlEF

7000--,,**''''

7000--,,**''''

U$.eH~

U$.eH~

}#$##$$$ !

}#$##$$$ !

} / 0/01&&()#

} / 0/01&&()#

];

];

@.lF!=^

@.lF!=^

*8

*8

6666666666

6666666666

.oeA(

.oeA(

l.GCc

l.GCc

"Cw%X

"Cw%X

%d%t3

%d%t3

%fLpX

%fLpX

%US7i

%US7i

;w.VS]}

;w.VS]}

.IDATx

.IDATx

&p.VM

&p.VM

j.ah@

j.ah@

g?.Vf

g?.Vf

Q.hH5

Q.hH5

)%uuu

)%uuu

d^pÇ

d^pÇ

{D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost'

{D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost'

'sidebar.EXE'

'sidebar.EXE'

val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523}

val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523}

NoRemove 'Windows Sidebar'

NoRemove 'Windows Sidebar'

*021:1@1

*021:1@1

3 3$3(3,3034383

3 3$3(3,3034383

? ?$?(?,?

? ?$?(?,?

8 8$8(8,808

8 8$8(8,808

4 4'4.4;4

4 4'4.4;4

="=)=0=7=

="=)=0=7=

6#6*61676

6#6*61676

=4=8=\=`=

=4=8=\=`=

4 4

4 4

5 5

5 5

Section%d

Section%d

Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings

Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings

Software\Microsoft\Windows Sidebar\IEOverride

Software\Microsoft\Windows Sidebar\IEOverride

00.00.00.02

00.00.00.02

Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility

Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility

Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar

Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar

Microsoft\Windows Sidebar\Gadgets

Microsoft\Windows Sidebar\Gadgets

Settings.ini

Settings.ini

Microsoft\Windows Sidebar

Microsoft\Windows Sidebar

AnimationsTimerT%d

AnimationsTimerT%d

Gadget.xml

Gadget.xml

*.Gadget

*.Gadget

hXXp://go.microsoft.com/fwlink/?LinkId=124093

hXXp://go.microsoft.com/fwlink/?LinkId=124093

imageres.dll

imageres.dll

{557CF406-1A04-11D3-9A73-0000F81EF32E}

{557CF406-1A04-11D3-9A73-0000F81EF32E}

Windows Sidebar\Shared Gadgets

Windows Sidebar\Shared Gadgets

Msg_GadgetInstalled

Msg_GadgetInstalled

%d.%d.%d.%d

%d.%d.%d.%d

Wversion.dll

Wversion.dll

%s %s

%s %s

.0123456789

.0123456789

ddwmapi.dll

ddwmapi.dll

Msxml.DOMDocument

Msxml.DOMDocument

Windows Sidebar\Gadgets

Windows Sidebar\Gadgets

%s\%s

%s\%s

keywords

keywords

website

website

Software\Microsoft\Windows\CurrentVersion\Run

Software\Microsoft\Windows\CurrentVersion\Run

Section %d

Section %d

\\?\UNC\

\\?\UNC\

BurlyWood

BurlyWood

Windows

Windows

Keywords

Keywords

Windows Sidebar

Windows Sidebar

mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947

mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947

hXXp://

hXXp://

.html

.html

.Gadget

.Gadget

%s

%s

%s

%s

%s

%s

Cert

Cert

mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b

mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b

url("gbackground:///%s")

url("gbackground:///%s")

SupportLink

SupportLink

SidebarExecute

SidebarExecute

{00000000-0000-0000-0000-000000000000}

{00000000-0000-0000-0000-000000000000}

\\?\Volume

\\?\Volume

style.backgroundImage

style.backgroundImage

style.width

style.width

style.height

style.height

Software\Microsoft\Windows\CurrentVersion\Sidebar

Software\Microsoft\Windows\CurrentVersion\Sidebar

style.backgroundColor

style.backgroundColor

%windir%\system32\schtasks.exe

%windir%\system32\schtasks.exe

/run /tn Microsoft\Windows\SideShow\GadgetManager

/run /tn Microsoft\Windows\SideShow\GadgetManager

HARDWARE\DESCRIPTION\System\CentralProcessor\%d

HARDWARE\DESCRIPTION\System\CentralProcessor\%d

Shell.Application

Shell.Application

SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones

SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones

@tzres.dll,

@tzres.dll,

\tzres.dll

\tzres.dll

Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}

Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}

.\%s.mui

.\%s.mui

.\%s\%s.mui

.\%s\%s.mui

%s\%s.mui

%s\%s.mui

%s\%s\%s.mui

%s\%s\%s.mui

&C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini

&C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini

Windows Desktop Gadgets

Windows Desktop Gadgets

6.1.7601.17514 (win7sp1_rtm.101119-1850)

6.1.7601.17514 (win7sp1_rtm.101119-1850)

sidebar.EXE

sidebar.EXE

Windows

Windows

Operating System

Operating System

1.0.7601.17514

1.0.7601.17514

Microsoft-Windows-Sidebar/Diagnostic

Microsoft-Windows-Sidebar/Diagnostic

DT_free_Rus_YandexBar1022.exe_2792:

.text

.text

`.rdata

`.rdata

@.data

@.data

.rsrc

.rsrc

@.reloc

@.reloc

operator

operator

GetProcessWindowStation

GetProcessWindowStation

%d %d %d %d

%d %d %d %d

inflate 1.1.3 Copyright 1995-1998 Mark Adler

inflate 1.1.3 Copyright 1995-1998 Mark Adler

-DTLite.exe

-DTLite.exe

YandexSetup.exe

YandexSetup.exe

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar

SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar

--distr /passive /msicl "

--distr /passive /msicl "

E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb

E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb

KERNEL32.dll

KERNEL32.dll

EnumChildWindows

EnumChildWindows

EnumThreadWindows

EnumThreadWindows

USER32.dll

USER32.dll

GDI32.dll

GDI32.dll

RegOpenKeyExA

RegOpenKeyExA

RegCloseKey

RegCloseKey

RegCreateKeyExA

RegCreateKeyExA

ADVAPI32.dll

ADVAPI32.dll

ShellExecuteExW

ShellExecuteExW

ShellExecuteExA

ShellExecuteExA

SHELL32.dll

SHELL32.dll

GetProcessHeap

GetProcessHeap

GetCPInfo

GetCPInfo

t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD

t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD

BYL

BYL

k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>,

k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>,

PD.XK5RD.xm[

PD.XK5RD.xm[

RE.VI3PC,

RE.VI3PC,

NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F

NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F

G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G

G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G

OC.TI6RG3MA-NB.MA-K?*

OC.TI6RG3MA-NB.MA-K?*

?5$?5$>4#>4#=4#=3"=4#=3"

?5$?5$>4#>4#=4#=3"=4#=3"

8/!:2$4,

8/!:2$4,

@6$>4"8,

@6$>4"8,

8/!8/!8/!8.!7. 7. 7. 7. 6-

8/!8/!8/!8.!7. 7. 7. 7. 6-

80 90"2(

80 90"2(

6- 6- 6-

6- 6- 6-

JJJ...SSS

JJJ...SSS

/,)/,)?:7

/,)/,)?:7

tGHt.Ht&

tGHt.Ht&

Please contact the application's support team for more information.

Please contact the application's support team for more information.

- Attempt to initialize the CRT more than once.

- Attempt to initialize the CRT more than once.

- CRT not initialized

- CRT not initialized

- floating point support not loaded

- floating point support not loaded

USER32.DLL

USER32.DLL

Seed: %d

Seed: %d

D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb

D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb

RegOpenKeyExW

RegOpenKeyExW

ole32.dll

ole32.dll

OLEAUT32.dll

OLEAUT32.dll

URLOpenBlockingStreamW

URLOpenBlockingStreamW

urlmon.dll

urlmon.dll

WINTRUST.dll

WINTRUST.dll

VERSION.dll

VERSION.dll

GetConsoleOutputCP

GetConsoleOutputCP

zcÁ

zcÁ

3.44484

3.44484

"hXXp://crl.verisign.com/tss-ca.crl0

"hXXp://crl.verisign.com/tss-ca.crl0

hXXp://ocsp.verisign.com0

hXXp://ocsp.verisign.com0

Thawte Certification1

Thawte Certification1

0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0

0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0

2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.

2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100.

3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D

hXXps://VVV.verisign.com/rpa0

hXXps://VVV.verisign.com/rpa0

hXXp://ocsp.verisign.com0?

hXXp://ocsp.verisign.com0?

3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0

.Class 3 Public Primary Certification Authority0

.Class 3 Public Primary Certification Authority0

hXXps://VVV.verisign.com/cps0*

hXXps://VVV.verisign.com/cps0*

#hXXp://logo.verisign.com/vslogo.gif0

#hXXp://logo.verisign.com/vslogo.gif0

hXXp://ocsp.verisign.com01

hXXp://ocsp.verisign.com01

hXXp://crl.verisign.com/pca3.crl0)

hXXp://crl.verisign.com/pca3.crl0)

hXXp://VVV.yandex.ru0

hXXp://VVV.yandex.ru0

4O4

4O4

3:3?3!4.444`4

3:3?3!4.444`4

2(3,3034383

2(3,3034383

mscoree.dll

mscoree.dll

KERNEL32.DLL

KERNEL32.DLL

WUSER32.DLL

WUSER32.DLL

dhXXp://legal.yandex.ru/elements_agreement/

dhXXp://legal.yandex.ru/elements_agreement/

_Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF}

_Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF}

%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe

%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe

DAEMON Tools Lite ve Yandex.Bar

DAEMON Tools Lite ve Yandex.Bar

Yandex.Bar

Yandex.Bar

Instalovat Yandex.Bar Seznam Edition

Instalovat Yandex.Bar Seznam Edition

Nastavit Seznam.cz jako domovskou str

Nastavit Seznam.cz jako domovskou str

m Yandex.Baru Seznam Edition souhlas

m Yandex.Baru Seznam Edition souhlas

Yandex.Bar v barv

Yandex.Bar v barv

tu Yandex.Bar v barv

tu Yandex.Bar v barv

by Seznam.cz

by Seznam.cz

The file "%s" is signed and the signature was verified.

The file "%s" is signed and the signature was verified.

The file "%s" is not signed.

The file "%s" is not signed.

An unknown error occurred trying to verify the signature of the "%s" file.

An unknown error occurred trying to verify the signature of the "%s" file.

Error is: 0x%x.

Error is: 0x%x.

For using type: downloader.exe --partner [--distr ] [--try] [--sync]

For using type: downloader.exe --partner [--distr ] [--try] [--sync]

Oops after %d bytes.

Oops after %d bytes.

File downloading complete: %s, size: %d

File downloading complete: %s, size: %d

Speed: %dKBs

Speed: %dKBs

File doesn't exist: %s

File doesn't exist: %s

Can't create file '%s'

Can't create file '%s'

Error: 0x%x

Error: 0x%x

Exit code: 0x%x

Exit code: 0x%x

Can't get exit code. Error: 0x%x

Can't get exit code. Error: 0x%x

Downloading installer: %s

Downloading installer: %s

try %d

try %d

HRESULT: 0xX

HRESULT: 0xX

Distr: %s

Distr: %s

Try to run: %s %s

Try to run: %s %s

%d.%d.%d

%d.%d.%d

Val: %d

Val: %d

templ: %s

templ: %s

%s: %s

%s: %s

New partner name: %s

New partner name: %s

url: %s

url: %s

name: %s

name: %s

fb: %s

fb: %s

lt: %s

lt: %s

\downloader.log

\downloader.log

cmd: %s

cmd: %s

ver: %s

ver: %s

os: %s

os: %s

elevated: %s

elevated: %s

\seed.txt

\seed.txt

Params: '%s'

Params: '%s'

hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss

hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss

hXXp://download.yandex.ru/yandex-pack/downloader/info.rss

hXXp://download.yandex.ru/yandex-pack/downloader/info.rss

hXXp://downloader.yandex.net/yandex-pack/

hXXp://downloader.yandex.net/yandex-pack/

YandexPackSetup.exe

YandexPackSetup.exe

YandexSearch.exe

YandexSearch.exe

DebugURL

DebugURL

downloader.yandex.net

downloader.yandex.net

download.yandex.ru

download.yandex.ru

suffix: %s

suffix: %s

%d.%d.%d.%d

%d.%d.%d.%d

0.1.0.16

0.1.0.16

download.exe

download.exe

DT Yandex Setup.exe

DT Yandex Setup.exe

WMIADAP.EXE_3440:

.text

.text

`.data

`.data

.rsrc

.rsrc

@.reloc

@.reloc

ADVAPI32.dll

ADVAPI32.dll

ntdll.DLL

ntdll.DLL

KERNEL32.dll

KERNEL32.dll

USER32.dll

USER32.dll

msvcrt.dll

msvcrt.dll

wbemcomn.dll

wbemcomn.dll

OLEAUT32.dll

OLEAUT32.dll

ole32.dll

ole32.dll

loadperf.dll

loadperf.dll

`.bik

`.bik

PSSSSSSh

PSSSSSSh

WMIADAP.exe

WMIADAP.exe

?CloseSubKey@CRegistry@@AAEXXZ

?CloseSubKey@CRegistry@@AAEXXZ

?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z

?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z

?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z

?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z

?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z

?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z

?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z

?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z

?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z

?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z

?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z

?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z

?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z

?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z

?GetCurrentSubKeyCount@CRegistry@@QAEKXZ

?GetCurrentSubKeyCount@CRegistry@@QAEKXZ

?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z

?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z

?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z

?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z

?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z

?GetLongestSubKeySize@CRegistry@@QAEKXZ

?GetLongestSubKeySize@CRegistry@@QAEKXZ

?GethKey@CRegistry@@QAEPAUHKEY__@@XZ

?GethKey@CRegistry@@QAEPAUHKEY__@@XZ

?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z

?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z

?NextSubKey@CRegistry@@QAEKXZ

?NextSubKey@CRegistry@@QAEKXZ

?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z

?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z

?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z

?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z

?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z

?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z

?OpenSubKey@CRegistry@@AAEKXZ

?OpenSubKey@CRegistry@@AAEKXZ

?RewindSubKeys@CRegistry@@QAEXXZ

?RewindSubKeys@CRegistry@@QAEXXZ

?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z

?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z

?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z

?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z

?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z

?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z

?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z

?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z

?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z

?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z

?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z

?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z

?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z

?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z

?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z

?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z

?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z

?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z

?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z

?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z

?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z

?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z

QSSh0

QSSh0

Invalid parameter passed to C runtime function.

Invalid parameter passed to C runtime function.

ntdll.dll

ntdll.dll

RegCloseKey

RegCloseKey

RegOpenKeyExW

RegOpenKeyExW

RegCreateKeyExW

RegCreateKeyExW

RegEnumKeyW

RegEnumKeyW

RegDeleteKeyW

RegDeleteKeyW

RegQueryInfoKeyW

RegQueryInfoKeyW

_amsg_exit

_amsg_exit

_acmdln

_acmdln

?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z

?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z

WMIADAP.pdb

WMIADAP.pdb

5m6z6

5m6z6

%s_x

%s_x

%s_x_

%s_x_

Global\WMI_SysEvent_Semaphore_%d

Global\WMI_SysEvent_Semaphore_%d

WinMSGWMIADAP

WinMSGWMIADAP

\\.\root\cimv2

\\.\root\cimv2

WMIADAP Msg window

WMIADAP Msg window

\\.\root\wmi

\\.\root\wmi

PSAPI.DLL

PSAPI.DLL

x=%s

x=%s

Describes all the counters supported via WMI Hi-Performance providers

Describes all the counters supported via WMI Hi-Performance providers

_new.ini

_new.ini

xx %s%s.ini

xx %s%s.ini

xx %s

xx %s

\\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\""

\\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\""

WmiApRes.dll

WmiApRes.dll

%s\%s

%s\%s

6.1.7600.16385 (win7_rtm.090713-1255)

6.1.7600.16385 (win7_rtm.090713-1255)

wmicookr.dll

wmicookr.dll

Windows

Windows

Operating System

Operating System

6.1.7600.16385

6.1.7600.16385