Trojan.NSIS.StartPage_431ce28a13
not-a-virus:AdWare.Win32.OpenCandy.aq (Kaspersky), Trojan.NSIS.StartPage.FD, Trojan.Win32.BHO.FD, Trojan.Win32.Ransom.FD, Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS) Behaviour: Ransom, Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: 431ce28a13c102f094e0ddd1e6c8a023
SHA1: c0ac53c76f25a1c4adb02360b998e2de163f8aa9
SHA256: fb7933db75604bfe00dc9e2dd533e122f350e39fa29c23a1e26905b69f7519fe
SSDeep: 393216:8VylAQ4kOJxPVtDn3Xej2NjLMs2MqdWTkXr0kIHGbZ:8glApjPv6aNKWgXdIw
Size: 12732963 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2011-05-28 19:04:29
Analyzed on: Windows7 SP1 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
DAEMONLite4.41.exe:3616
sidebar.exe:1808
%original file name%.exe:1796
rundll32.exe:3972
DrvInst.exe:2628
DrvInst.exe:3532
DrvInst.exe:4052
SetupHelper.exe:2904
regsvr32.exe:1428
The Trojan injects its code into the following process(es):
DT_free_Rus_YandexBar1022.exe:2792
DTLite4413-0173.exe:1672
irsetup.exe:2296
Mutexes
The following mutexes were created/opened: No objects were found.
File activity
The process DAEMONLite4.41.exe:3616 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)
The process %original file name%.exe:1796 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\à ¹€à ¸„à ¸£à ¸â€Ã ¸´à ¸•.txt (133 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\__tmp_rar_sfx_access_check_337648 (0 bytes)
The process DrvInst.exe:2628 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\inf\setupapi.dev.log (478 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Windows\Temp\Tar4716.tmp (2712 bytes)
C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
C:\Windows\Temp\Tar4659.tmp (2712 bytes)
C:\Windows\Temp\Tar4598.tmp (2712 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab45E7.tmp (48 bytes)
C:\Windows\Temp\Tar4628.tmp (2712 bytes)
C:\Windows\Temp\Cab4658.tmp (48 bytes)
C:\Windows\Temp\Cab4627.tmp (48 bytes)
C:\Windows\Temp\Cab4715.tmp (48 bytes)
C:\Windows\inf\oem10.PNF (7501 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
C:\Windows\Temp\Cab4597.tmp (48 bytes)
The Trojan deletes the following file(s):
C:\Windows\Temp\Tar4716.tmp (0 bytes)
C:\Windows\Temp\Tar45E8.tmp (0 bytes)
C:\Windows\Temp\Tar4659.tmp (0 bytes)
C:\Windows\Temp\Tar4598.tmp (0 bytes)
C:\Windows\Temp\Cab45E7.tmp (0 bytes)
C:\Windows\Temp\Tar4628.tmp (0 bytes)
C:\Windows\Temp\Cab4658.tmp (0 bytes)
C:\Windows\Temp\Cab4627.tmp (0 bytes)
C:\Windows\Temp\Cab4715.tmp (0 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (0 bytes)
C:\Windows\Temp\Cab4597.tmp (0 bytes)
The process DrvInst.exe:3532 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
C:\Windows\System32\DriverStore\infpub.dat (252 bytes)
C:\Windows\Temp\Tar415A.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
C:\Windows\Temp\Tar4127.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (4 bytes)
C:\Windows\Temp\Tar417B.tmp (2712 bytes)
C:\Windows\inf\oem10.inf (1 bytes)
C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
C:\Windows\Temp\Tar4139.tmp (2712 bytes)
C:\Windows\Temp\Cab417A.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab4138.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
C:\Windows\Temp\Cab4126.tmp (48 bytes)
C:\Windows\Temp\Cab40C7.tmp (48 bytes)
C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
C:\Windows\Temp\Cab4159.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)
The Trojan deletes the following file(s):
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (0 bytes)
C:\Windows\Temp\Tar415A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (0 bytes)
C:\Windows\Temp\Tar4127.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b} (0 bytes)
C:\Windows\Temp\Tar417B.tmp (0 bytes)
C:\Windows\Temp\Tar4139.tmp (0 bytes)
C:\Windows\Temp\Cab417A.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.sys (0 bytes)
C:\Windows\Temp\Cab4138.tmp (0 bytes)
C:\Windows\Temp\Cab4126.tmp (0 bytes)
C:\Windows\Temp\Cab40C7.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.inf (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\dtsoftbus01.cat (0 bytes)
C:\Windows\Temp\Tar40C8.tmp (0 bytes)
C:\Windows\Temp\Cab4159.tmp (0 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (0 bytes)
The process DrvInst.exe:4052 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Windows\inf\setupapi.dev.log (2324 bytes)
The process DTLite4413-0173.exe:1672 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
%Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
%Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
%Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (844 bytes)
%Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
%Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
%Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
%Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
%Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
%Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
%Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
%Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
%Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.sys (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a} (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.inf (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\dtsoftbus01.cat (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (0 bytes)
The process irsetup.exe:2296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes)
The Trojan deletes the following file(s):
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (0 bytes)
Registry activity
The process DAEMONLite4.41.exe:3616 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process sidebar.exe:1808 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings]
"ShowGadgets" = "1"
The process %original file name%.exe:1796 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process rundll32.exe:3972 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process DrvInst.exe:2628 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Security" = "01 00 04 90 00 00 00 00 00 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"dtsoftbus01.sys" = "5"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"ClassGUID" = "{4d36e97d-e325-11ce-bfc1-08002be10318}"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI Miniport" = "42 00 00 00 00 01 00 00 01 01 00 00 19 00 00 00"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Service" = "dtsoftbus01"
"DeviceCharacteristics" = "256"
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\root#dtsoftbus01]
"Exclusive"
"DeviceType"
"LowerFilters"
"UpperFilters"
The process DrvInst.exe:3532 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD]
"Blob" = "0F 00 00 00 01 00 00 00 20 00 00 00 52 29 BA 15"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "0F 00 00 00 01 00 00 00 14 00 00 00 03 F5 5B 4D"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates]
"D69B561148F01C77C54578C10926DF5B856976AD"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
The process DrvInst.exe:4052 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultRequestFlags" = "8"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDAAccurate" = "1"
[HKU\.DEFAULT\SOFTWARE\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"TypesSupported" = "7"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"CDDASupported" = "1"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"SCSI CDROM Class" = "03 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles\%SystemPath%\system32\DRIVERS]
"cdrom.sys" = "1"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"SettingsFromDevice" = "1"
[HKLM\System\CurrentControlSet\services\eventlog\System\cdrom]
"EventMessageFile" = "%SystemRoot%\System32\IoLogMsg.dll"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"ClassGUID" = "{4d36e965-e325-11ce-bfc1-08002be10318}"
"Service" = "cdrom"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters]
"DefaultDvdRegion" = "1"
[HKLM\System\CurrentControlSet\Enum\DTSOFTBUS&Rev1\DTCDROM&Rev1\1&79f5d87&0&00\Device Parameters\DigitalAudio]
"ReadSizesSupported" = "4294967295"
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"DeviceType"
"DeviceCharacteristics"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\PnPSysprep\ServiceStartTypeBackup]
"cdrom"
[HKLM\System\CurrentControlSet\Control\CriticalDeviceDatabase\GenCdRom]
"LowerFilters"
"UpperFilters"
"Exclusive"
"Security"
The process SetupHelper.exe:2904 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
The process DTLite4413-0173.exe:1672 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit30]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit62]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit124]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit117]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit114]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit28]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit13]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit40]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit58]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit60]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit17]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit50]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit18]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit82]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.app.log" = "4096"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit113]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"Class" = "dtsoftbus01"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit90]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit120]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdx]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayName" = "DAEMON Tools Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit39]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit111]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\CancelAutoplay\CLSID]
"B67DE95D-274B-0C7D-C784-82C002ECA45C" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit26]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite\DefaultIcon]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe,0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit53]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}\Properties]
"Security" = "01 00 0C 90 00 00 00 00 00 00 00 00 00 00 00 00"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit77]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoDisplayClass" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit103]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit81]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit91]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit93]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Minor" = "41"
"Version Release" = "3"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit67]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit97]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit108]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit34]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit101]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mdx]
"(Default)" = "DAEMON.Tools.Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit23]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit116]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit1]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit66]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit2]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit63]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit10]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit96]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit36]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit92]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayIcon" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit5]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit12]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"Path" = "%Program Files%\DAEMON Tools Lite\"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit118]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit4]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit70]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit41]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit7]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit107]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit76]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit71]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit121]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mdf]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit119]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit35]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit38]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit25]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit126]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit14]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit110]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit98]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Control\Class\{9D3039DD-CCA5-4B4D-B33D-E2DDC8A8C52E}]
"NoUseClass" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit83]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit49]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Version Major" = "4"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit99]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\Config]
"AdapterStateDT" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit42]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit46]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit15]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\DTLite.exe]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit44]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit48]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit54]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit68]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit86]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\5557C0953FBD9F93745B214FB2483E9369B597F0]
"Blob" = "03 00 00 00 01 00 00 00 14 00 00 00 55 57 C0 95"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit21]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit80]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite]
"(Default)" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit102]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit84]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit73]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit89]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit106]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit51]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit45]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit75]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit55]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit16]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit20]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit57]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mds]
"(Default)" = "DAEMON.Tools.Lite"
[HKCU\Software\Classes\Local Settings\MuiCache\2D\52C64B7E]
"LanguageList" = "en-US, en"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit69]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit19]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit65]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit85]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit22]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro\FileTypesSave\.mds]
"Type" = "Type: REG_SZ, Length: 0"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit95]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"DisplayVersion" = "4.41.3.0173"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit123]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit6]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit0]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit9]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit105]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit115]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit94]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit78]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit56]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit61]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"Publisher" = "DT Soft Ltd"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit32]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit72]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SYSTEM\Setup\SetupapiLogStatus]
"setupapi.dev.log" = "4096"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit104]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\DAEMON.Tools.Lite\shell\open\command]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -shellmount %1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit100]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit88]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\DT Soft\DAEMON Tools Pro]
"Path" = "%Program Files%\DAEMON Tools Lite\"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit11]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"AdapterStatus" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit29]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer]
"GlobalAssocChangedCounter" = "45"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"client" = "41 3B 13 40 37 80 B7 AF AB 63 56 48 3F BA 8E B6"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit59]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit37]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"URLInfoAbout" = "http://www.daemon-tools.cc/"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit33]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit122]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit31]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Lite]
"UninstallString" = "%Program Files%\DAEMON Tools Lite\uninst.exe"
[HKCU\Software\DT Soft\DAEMON Tools Pro\Config]
"AutoStart" = "1"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit64]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit47]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit79]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit74]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit43]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit109]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit27]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit24]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKCR\.mdf]
"(Default)" = "DAEMON.Tools.Lite"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit125]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit3]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit8]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit112]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit52]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
[HKLM\System\CurrentControlSet\Services\dtsoftbus01\unit87]
"data" = "3D 3E E9 B0 38 9B E1 76 C8 D3 2E 75 A4 BF 2D 40"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun"
The following driver will be automatically launched by the NT Native code (IoInitSystem method):
[HKLM\System\CurrentControlSet\Services\dtsoftbus01]
"Start" = "1"
The Trojan deletes the following value(s) in system registry:
[HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache\%Program Files%\DAEMON Tools Lite]
"DTLite.exe"
[HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates]
"5557C0953FBD9F93745B214FB2483E9369B597F0"
The process regsvr32.exe:1428 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCR\DTGadget.RSS.1]
"(Default)" = "RSS Class"
[HKCR\DTGadget.GadgetControl.1]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.GadgetControl\CurVer]
"(Default)" = "DTGadget.GadgetControl.1"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\HELPDIR]
"(Default)" = "%Program Files%\DAEMON Tools Lite"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
"(Default)" = "DTGadget.GadgetControl"
[HKCR\DTGadget.RSS\CurVer]
"(Default)" = "DTGadget.RSS.1"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\DTGadget.RSS.1\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"Version" = "1.0"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}]
"(Default)" = "IGadgetControl"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}]
"(Default)" = "IRSS"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0]
"(Default)" = "DTGadget 1.0 Type Library"
[HKCR\TypeLib\{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}\1.0\0\win32]
"(Default)" = "%Program Files%\DAEMON Tools Lite\DTGadget32.dll"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]
"(Default)" = "DTGadget.GadgetControl.1"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{FEC8A564-EF2C-4D4F-BDED-D01E03D9DDD1}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.GadgetControl.1\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\DTGadget.RSS\CLSID]
"(Default)" = "{46F8ADC5-0EA1-49d7-9657-56A50133CD42}"
[HKCR\Interface\{476B3CEC-34F4-4B44-800C-918202FABD51}\TypeLib]
"Version" = "1.0"
[HKCR\AppID\{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}]
"(Default)" = "DTGadget"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
"(Default)" = "DTGadget.RSS"
[HKCR\DTGadget.GadgetControl\CLSID]
"(Default)" = "{273C813F-46B0-4D2D-B522-73CB5D1C372A}"
[HKCR\AppID\DTGadget.DLL]
"AppID" = "{F574FC8D-EFB4-4DAB-AA18-B6C688A8CC58}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
"(Default)" = "RSS Class"
[HKCR\DTGadget.GadgetControl]
"(Default)" = "GadgetControl Class"
[HKCR\DTGadget.RSS]
"(Default)" = "RSS Class"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
"(Default)" = "{C6761050-EDA9-4F0B-B5B4-ECE680D3B17E}"
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
"(Default)" = "DTGadget.RSS.1"
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
"ThreadingModel" = "Apartment"
The Trojan deletes the following registry key(s):
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\InprocServer32]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\ProgID]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\VersionIndependentProgID]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\Programmable]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\TypeLib]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\Programmable]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}]
[HKCR\CLSID\{46F8ADC5-0EA1-49d7-9657-56A50133CD42}\InprocServer32]
[HKCR\CLSID\{273C813F-46B0-4D2D-B522-73CB5D1C372A}\ProgID]
Dropped PE files
| MD5 | File path |
|---|---|
| fd5b3fbfe4346f45d3764d149afc761a | c:\Program Files\DAEMON Tools Lite\DTCommonRes.dll |
| 00d0a111a66f1e531f849727a528036b | c:\Program Files\DAEMON Tools Lite\DTGadget32.dll |
| 62f4fda5c8db21799ca4c30c10046ca7 | c:\Program Files\DAEMON Tools Lite\DTGadget64.dll |
| 252ff12c709418a7792b593605188cb6 | c:\Program Files\DAEMON Tools Lite\DTHelper.exe |
| cea0461aae4b8b6216f164501b1b5a10 | c:\Program Files\DAEMON Tools Lite\DTLite.exe |
| f9803b1b1fa3e9d34f309d2dd8db30b5 | c:\Program Files\DAEMON Tools Lite\DTShellHlp.exe |
| 1bc6ff991384848c588e4ec94512a2fc | c:\Program Files\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe |
| f605346de44da5e5037392616d3b919d | c:\Program Files\DAEMON Tools Lite\Engine.dll |
| e52159020ed1fe44684f8aa003f2dd40 | c:\Program Files\DAEMON Tools Lite\InstallGadget.exe |
| cf0ba43ae03d5dc57e96fa583d26f506 | c:\Program Files\DAEMON Tools Lite\Lang\AFK.dll |
| 92749b95321bf93e7e285537229feaad | c:\Program Files\DAEMON Tools Lite\Lang\ARA.dll |
| c1286d50ea59268af55eb7bc72e9fd30 | c:\Program Files\DAEMON Tools Lite\Lang\BGR.dll |
| 9d692d85639d0d9fcc8fd8428cb8ff2c | c:\Program Files\DAEMON Tools Lite\Lang\BIH.dll |
| 98b5f8d3c7f45937fa6b920e51e83782 | c:\Program Files\DAEMON Tools Lite\Lang\CHS.dll |
| 44def48444c237ca2455b12f020a41d6 | c:\Program Files\DAEMON Tools Lite\Lang\CHT.dll |
| 1838b84c7cc7529319dd704759d4273e | c:\Program Files\DAEMON Tools Lite\Lang\CSY.dll |
| 49dfb5b9bc3b193a847f96f72ba7deab | c:\Program Files\DAEMON Tools Lite\Lang\DAN.dll |
| 7305e2e252ec3ca9809fd3172dd63a68 | c:\Program Files\DAEMON Tools Lite\Lang\DEU.dll |
| 27d9823928ab2be476b6f07ead03c33c | c:\Program Files\DAEMON Tools Lite\Lang\ELL.dll |
| ae1efc111af8c51865f7982cf6563178 | c:\Program Files\DAEMON Tools Lite\Lang\ENU.dll |
| e1a42e5f8460ccbd8cd0a389a8798cc7 | c:\Program Files\DAEMON Tools Lite\Lang\ESN.dll |
| 7731e2156769c740f8a2c31b5e4df534 | c:\Program Files\DAEMON Tools Lite\Lang\FIN.dll |
| 614fcda9095d370e39209d6d42958fb3 | c:\Program Files\DAEMON Tools Lite\Lang\FRA.dll |
| 4211100519c955e423215e9a3a08c1d7 | c:\Program Files\DAEMON Tools Lite\Lang\HEB.dll |
| 9731e2fe05e3da9a66067908f6d3be07 | c:\Program Files\DAEMON Tools Lite\Lang\HRV.dll |
| b5ec9c8bb10b4d032c1362463758a25e | c:\Program Files\DAEMON Tools Lite\Lang\HUN.dll |
| 61c46b0a6fa7e2d189dc104632800be6 | c:\Program Files\DAEMON Tools Lite\Lang\HYE.dll |
| 70f07f8cc1a4b5fc982df281c543f2a8 | c:\Program Files\DAEMON Tools Lite\Lang\IND.dll |
| 95b38c347abd82b8b87408434bd16077 | c:\Program Files\DAEMON Tools Lite\Lang\ITA.dll |
| d0b2fed29ef162a3a8d736fd40961b3b | c:\Program Files\DAEMON Tools Lite\Lang\JPN.dll |
| b3eaa9d656acff1824c20c8248c35e76 | c:\Program Files\DAEMON Tools Lite\Lang\KAT.dll |
| 5765c1d93c810fa191b2603952d0534f | c:\Program Files\DAEMON Tools Lite\Lang\KOR.dll |
| 85fa1b1123c4b48671e0da25dacf246b | c:\Program Files\DAEMON Tools Lite\Lang\LTH.dll |
| e4d780ef46b04d4e79baf5148f3d8dd9 | c:\Program Files\DAEMON Tools Lite\Lang\LVI.dll |
| d02efd07e77c06b994430065b69d2c2f | c:\Program Files\DAEMON Tools Lite\Lang\NLB.dll |
| 89906933894f18cde773b2325e6bb042 | c:\Program Files\DAEMON Tools Lite\Lang\NOR.dll |
| 2b58f578d140b24e70ef8382223263b6 | c:\Program Files\DAEMON Tools Lite\Lang\PLK.dll |
| f10f25b99d119f70d033aaf1f6e1b172 | c:\Program Files\DAEMON Tools Lite\Lang\PTB.dll |
| 4e1d52f4c97d3c47325c0e7eea53427a | c:\Program Files\DAEMON Tools Lite\Lang\ROM.dll |
| 9477befb435d7e49a495785b9e12af0f | c:\Program Files\DAEMON Tools Lite\Lang\RUS.dll |
| bbcb4687f9d735db1999e4e3541c2561 | c:\Program Files\DAEMON Tools Lite\Lang\SKY.dll |
| 0c6d4a502a4a7da18b170d80711ba345 | c:\Program Files\DAEMON Tools Lite\Lang\SLV.dll |
| 60f3def51db1fb1cb6f0cdd26c517f6f | c:\Program Files\DAEMON Tools Lite\Lang\SRL.dll |
| c24c9fc4ac8f4bd44f8e89746cf97cc4 | c:\Program Files\DAEMON Tools Lite\Lang\SVE.dll |
| 43baa07c3f4326d6783fc05c0f620e8f | c:\Program Files\DAEMON Tools Lite\Lang\TRK.dll |
| e29dd8fc5f137994c80629a7ad002d5c | c:\Program Files\DAEMON Tools Lite\Lang\UKR.dll |
| d2adc3ee87c7983b34c1d284aad2d163 | c:\Program Files\DAEMON Tools Lite\SPTDinst-x64.exe |
| fd62e3b8d7e193ab19e71f26c1fc81b6 | c:\Program Files\DAEMON Tools Lite\SPTDinst-x86.exe |
| c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Program Files\DAEMON Tools Lite\dtsoftbus01.sys |
| d6cd851869a9a3fbeb2254d3766a9aba | c:\Program Files\DAEMON Tools Lite\imgengine.dll |
| 92e541cb724a8a0ee3f04469b8099c04 | c:\Program Files\DAEMON Tools Lite\uninst.exe |
| a20431e552a37ab90e6cc98ce5ed82d1 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe |
| d74a7db367d407dec2fcbbd22043a91b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll |
| ee6d5584f593fab1c5d3d8e548b7203b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe |
| e808a6b7751f6f980f97008d1aeb8036 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe |
| cdec84efa7e61e09f8f344f1a151ba59 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe |
| 4f88bef9204d347c0d1c99d7be7baae8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe |
| cf0ba43ae03d5dc57e96fa583d26f506 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll |
| 92749b95321bf93e7e285537229feaad | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll |
| c1286d50ea59268af55eb7bc72e9fd30 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll |
| 9d692d85639d0d9fcc8fd8428cb8ff2c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll |
| 98b5f8d3c7f45937fa6b920e51e83782 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll |
| 44def48444c237ca2455b12f020a41d6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll |
| 1838b84c7cc7529319dd704759d4273e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll |
| 49dfb5b9bc3b193a847f96f72ba7deab | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll |
| 7305e2e252ec3ca9809fd3172dd63a68 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll |
| 27d9823928ab2be476b6f07ead03c33c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll |
| ae1efc111af8c51865f7982cf6563178 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll |
| e1a42e5f8460ccbd8cd0a389a8798cc7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll |
| 7731e2156769c740f8a2c31b5e4df534 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll |
| 614fcda9095d370e39209d6d42958fb3 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll |
| 4211100519c955e423215e9a3a08c1d7 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll |
| 9731e2fe05e3da9a66067908f6d3be07 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll |
| b5ec9c8bb10b4d032c1362463758a25e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll |
| 61c46b0a6fa7e2d189dc104632800be6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll |
| 70f07f8cc1a4b5fc982df281c543f2a8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll |
| 95b38c347abd82b8b87408434bd16077 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll |
| d0b2fed29ef162a3a8d736fd40961b3b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll |
| b3eaa9d656acff1824c20c8248c35e76 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll |
| 5765c1d93c810fa191b2603952d0534f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll |
| 85fa1b1123c4b48671e0da25dacf246b | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll |
| e4d780ef46b04d4e79baf5148f3d8dd9 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll |
| d02efd07e77c06b994430065b69d2c2f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll |
| 89906933894f18cde773b2325e6bb042 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll |
| 2b58f578d140b24e70ef8382223263b6 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll |
| f10f25b99d119f70d033aaf1f6e1b172 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll |
| 4e1d52f4c97d3c47325c0e7eea53427a | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll |
| 9477befb435d7e49a495785b9e12af0f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll |
| bbcb4687f9d735db1999e4e3541c2561 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll |
| 0c6d4a502a4a7da18b170d80711ba345 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll |
| 60f3def51db1fb1cb6f0cdd26c517f6f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll |
| c24c9fc4ac8f4bd44f8e89746cf97cc4 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll |
| 43baa07c3f4326d6783fc05c0f620e8f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll |
| e29dd8fc5f137994c80629a7ad002d5c | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll |
| 7fbc1cd7de7bc2dc40e9960bd3d3ecc8 | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe |
| 959ea64598b9a3e494c00e8fa793be7e | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll |
| 9adb3f7c3d4b623f74c4a17ee665d65f | c:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll |
| c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.sys |
| c0c7ceccb6c85994c2bc92d58e52d3f2 | c:\Windows\System32\drivers\dtsoftbus01.sys |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
DAEMONLite4.41.exe:3616
sidebar.exe:1808
%original file name%.exe:1796
rundll32.exe:3972
DrvInst.exe:2628
DrvInst.exe:3532
DrvInst.exe:4052
SetupHelper.exe:2904
regsvr32.exe:1428 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe (1151 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe (5340 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.url (198 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\zone-it.com.nfo (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\KOB.dll (77 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\x.bat (964 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\Readme2.vbs (75 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\RUN.exe (2192 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\à ¹€à ¸„à ¸£à ¸â€Ã ¸´à ¸•.txt (133 bytes)
C:\Windows\inf\setupapi.dev.log (478 bytes)
C:\Windows\System32\DriverStore\infpub.dat (248 bytes)
C:\Windows\Temp\Tar4716.tmp (2712 bytes)
C:\Windows\Temp\Tar45E8.tmp (2712 bytes)
C:\Windows\Temp\Tar4659.tmp (2712 bytes)
C:\Windows\Temp\Tar4598.tmp (2712 bytes)
C:\Windows\System32\DriverStore\infstrng.dat (1036 bytes)
C:\Windows\Temp\Cab45E7.tmp (48 bytes)
C:\Windows\Temp\Tar4628.tmp (2712 bytes)
C:\Windows\Temp\Cab4658.tmp (48 bytes)
C:\Windows\Temp\Cab4627.tmp (48 bytes)
C:\Windows\Temp\Cab4715.tmp (48 bytes)
C:\Windows\inf\oem10.PNF (7501 bytes)
C:\Windows\System32\drivers\SET46FE.tmp (1281 bytes)
C:\Windows\Temp\Cab4597.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F62.tmp (1281 bytes)
C:\Windows\System32\DriverStore\FileRepository\dtsoftbus01.inf_x86_neutral_1cc2711e3c419337\dtsoftbus01.PNF (14978 bytes)
C:\Windows\Temp\Tar415A.tmp (2712 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F50.tmp (7 bytes)
C:\Windows\Temp\Tar4127.tmp (2712 bytes)
C:\Windows\Temp\Tar417B.tmp (2712 bytes)
C:\Windows\inf\oem10.inf (1 bytes)
C:\Windows\System32\DriverStore\INFCACHE.0 (1523 bytes)
C:\Windows\Temp\Tar4139.tmp (2712 bytes)
C:\Windows\Temp\Cab417A.tmp (48 bytes)
C:\Windows\Temp\Cab4138.tmp (48 bytes)
C:\Windows\System32\DriverStore\infstor.dat (308 bytes)
C:\Windows\Temp\Cab4126.tmp (48 bytes)
C:\Windows\Temp\Cab40C7.tmp (48 bytes)
C:\Windows\Temp\Tar40C8.tmp (2712 bytes)
C:\Windows\Temp\Cab4159.tmp (48 bytes)
C:\Windows\System32\DriverStore\Temp\{50980cec-0f8c-0ba4-4c14-8b02a1465e5b}\SET3F51.tmp (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider.png (131 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives4.png (576 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll (267063 bytes)
%Program Files%\DAEMON Tools Lite\DTLite.exe (316919 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_slot.png (906 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_controls.png (10 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SLV.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHS.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_bottom.png (627 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ESN.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\virtual_drive.js (226 bytes)
%Program Files%\DAEMON Tools Lite\imgengine.dll (11663 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_slot.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NLB.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\TRK.dll (2461 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_out.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_dadget_loader.png (1640 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive_disable.png (505 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SRL.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning_48.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives0.png (547 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_top.gif (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar43EA.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives0.png (23 bytes)
C:\Windows\System32\catroot2\dberr.txt (1255 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_2.png (209 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab2.png (1340 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x86.exe (21234 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HYE.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_out.png (893 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_left.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\RUS.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\content_bottom.gif (207 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED3.tmp (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_9.png (502 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HRV.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window.png (11 bytes)
%Program Files%\DAEMON Tools Lite\DT.gadget (33248 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab3.png (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3_pro.jpg (1873 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\style.css (851 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_right.png (137 bytes)
%Program Files%\DAEMON Tools Lite\DTCommonRes.dll (109567 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsc341B.tmp (799348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_tab.gif (535 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_selected.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab3.png (1155 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BIH.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_right.png (168 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\DTGadget_icon.png (1910 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dell_slot.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives2.png (8 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ARA.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_bottom.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SVE.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_window.png (824 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KOR.dll (1597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\read.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\unmounted.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar438B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DEU.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_controls.png (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabgrey.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_selected.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_hint.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_window.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives2.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unmounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\DTSetupHelper.exe (6532 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_over.png (744 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\IND.dll (1592 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_news_display_top.gif (134 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PLK.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BGR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FRA.dll (5114 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drive_controls.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\no_drive_select.png (1 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DTGadget.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\make_img.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_out.png (811 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drag.png (1359 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SKY.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_right.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_selected.png (606 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3EE5.tmp (1281 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ITA.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\KAT.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Grabbing.ico (1 bytes)
%Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe (84187 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives3.png (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_selected.png (871 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives4.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\prop_.png (1096 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HUN.dll (3312 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HEB.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_unmounted.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHT.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\inf.png (686 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_7.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_over.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_right.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LTH.dll (3722 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CSY.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_3.png (338 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab438A.tmp (51 bytes)
%Program Files%\DAEMON Tools Lite\Lang\NOR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_1.png (311 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_bottom.gif (424 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\content_bottom.gif (282 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_pro.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_6.png (171 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget_lite.xml (913 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SKY.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives1.png (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\settings.html (856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DEU.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\tab2.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives0.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_top.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\skin_gallery.js (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive.png (943 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ELL.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar4379.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\{6f414ad4-98be-023d-7954-f5554fe6846a}\SET3ED4.tmp (1 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LTH.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\skin_select.gif (295 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_over.png (402 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_dadget_loader.png (500 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ENU.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar44EC.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_top.png (523 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\MNDManager.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\add_drive.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_out.png (471 bytes)
%Program Files%\DAEMON Tools Lite\Lang\TRK.dll (2392 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab44EB.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\settings.css (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab448B.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Grabbing.ico (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.png (122 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KOR.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_out.png (797 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\error.png (809 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FRA.dll (4992 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount_n_drive.html (2 bytes)
%Program Files%\DAEMON Tools Lite\uninst.exe (66912 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive.png (903 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_dadget_loader.png (1536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_left.png (145 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\message.html (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_selected.png (362 bytes)
%Program Files%\DAEMON Tools Lite\DTShellHlp.exe (98771 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\main_controls_icons.png (964 bytes)
%Program Files%\DAEMON Tools Lite\Lang\UKR.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button1.gif (859 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar448C.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_news_display_middle.gif (59 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HUN.dll (3398 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_middle.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives3.png (211 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive_hover.png (348 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\Uninstall.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\drives1.png (7 bytes)
%Program Files%\DAEMON Tools Lite\Lang\PTB.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\Gadjet_bottom_links_news.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_out.png (597 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\links_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss.gif (635 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2.jpg (633 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\links_selected.png (385 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_bottom.png (627 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\JPN.dll (1921 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_over.png (642 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ESN.dll (5110 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\mounted.png (433 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ARA.dll (3398 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ROM.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_bottom_left.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\Gadjet_middle.png (206 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ENU.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\close.png (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\IND.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\DTGadget_icon.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab3.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_news_display_top.gif (134 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\drive_slotes.js (1309 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\popup_window.css (103 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\feedback.png (761 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.png (122 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PLK.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\left_right_butts.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slot_button.gif (852 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss.css (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\down_drive_hover.png (348 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_read_selected.png (750 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drive_select.png (593 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CHT.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\01_attached_mounted.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\up_down_drive_disable.png (904 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_bottom.png (140 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_drive_disable.png (505 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\SetupHelper.exe (1856 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.sys (232 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_icon.png (911 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab2.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_refresh.png (759 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\global_settings.js (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\chenge_view.png (575 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_left.png (135 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\rss.html (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_out.png (3 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HRV.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_refresh.png (800 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_divider_right.png (135 bytes)
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\unread.png (4 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\jquery-1.3.1.min.js (2333 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\drives2.png (1724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\make_img.css (103 bytes)
%Program Files%\DAEMON Tools Lite\InstallGadget.exe (12536 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin3.jpg (578 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\FIN.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_middle.gif (97 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\unmounted.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTHelper.exe (19152 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_pro_over.png (157 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ITA.dll (3730 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab441A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadget.js (454 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window_small.png (21 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_over.png (374 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\ROM.dll (3406 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\links_selected.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\lines.png (119 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\shortcut_hover.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar447B.tmp (2712 bytes)
%Program Files%\DAEMON Tools Lite\Lang\LVI.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tabblue.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SRL.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_out.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_window_small.png (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\help.png (896 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\news_over.png (642 bytes)
%Program Files%\DAEMON Tools Lite\Lang\KAT.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\json_parse.js (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_top.gif (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_corner_top_left.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin2_pro.jpg (10 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message_window.png (1162 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\add_image.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\no_drive_select.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.xml (913 bytes)
C:\ProgramData\DAEMON Tools Lite\license.dat (2156 bytes)
%Program Files%\DAEMON Tools Lite\Engine.dll (132485 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab43E9.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_icon_pro.png (960 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_controls_icons.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\mounted.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\message_butt.png (1 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget32.dll (10136 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives3.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\prop_.png (804 bytes)
%Program Files%\DAEMON Tools Lite\Lang\AFK.dll (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\main_controls_icons.png (11 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_down_drive.png (903 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.inf (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\drives4.png (962 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_divider_right.png (139 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1_pro.jpg (13 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_top.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\DAN.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_selected.png (465 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\dtcom.js (12 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\rss_controls_icons.png (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab4378.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\LVI.dll (1601 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\gadjet_scripts.js (8 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\settings_box_left.png (137 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\message.css (995 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\down_drive.png (343 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\up_drive_hover.png (366 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\System.dll (11 bytes)
%Program Files%\DAEMON Tools Lite\SPTDinst-x64.exe (24832 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_selected.png (465 bytes)
%Program Files%\DAEMON Tools Lite\Lang\BIH.dll (3616 bytes)
%Program Files%\DAEMON Tools Lite\Lang\SVE.dll (3616 bytes)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite\SPTD Setup.lnk (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\dtsetup.ini (1358 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.png (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\chenge_view.png (677 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\skins_gallery_but.gif (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\slots_window_8.png (166 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\message_butt.png (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Cab447A.tmp (51 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\AFK.dll (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\Tar441B.tmp (2712 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\tab1.ico (16 bytes)
%Program Files%\DAEMON Tools Lite\DTGadget64.dll (12088 bytes)
%Program Files%\DAEMON Tools Lite\Lang\FIN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\MNDManager.ico (1150 bytes)
%Program Files%\DAEMON Tools Lite\Lang\DAN.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_pro_over.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\previews\skin1.jpg (14 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\dt_selected.png (5 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\css\style.css (6 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\news_out.png (669 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\img\warning.png (3 bytes)
%Program Files%\DAEMON Tools Lite\Lang\RUS.dll (3616 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\dt_out.png (3 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\Gadjet_bottom.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\HEB.dll (2473 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\up_down_butts.gif (724 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\news_read_over.png (891 bytes)
%Program Files%\DAEMON Tools Lite\Lang\ELL.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\photoshop.png (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\display_middle.gif (897 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\prop_.png (804 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NLB.dll (3410 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\mount.html (2 bytes)
%Program Files%\DAEMON Tools Lite\Lang\JPN.dll (1856 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\CSY.dll (3718 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin2\style.css (1093 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\rss_unread.png (776 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\tab1.ico (16 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\UKR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\js\rss.js (988 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\settings_over.png (464 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\1.gif (43 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\PTB.dll (3722 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\BGR.dll (3730 bytes)
%Program Files%\DAEMON Tools Lite\Lang\HYE.dll (3312 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\SLV.dll (1921 bytes)
%Program Files%\DAEMON Tools Lite\dtsoftbus01.cat (7 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\display_bottom.gif (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\Lang\NOR.dll (3726 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\skins\skin1\main_controls_icons.png (488 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Gadgets\DT.gadget\gadget.html (9 bytes)
%Program Files%\DAEMON Tools Lite\Lang\CHS.dll (1552 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe (187244 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG1.JPG (2 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\IRIMG2.JPG (29 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.dat (2712 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite" = "%Program Files%\DAEMON Tools Lite\DTLite.exe -autorun" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
No information is available.
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 72088 | 72192 | 4.546 | 984dfeff737935f78877d3d08b82ef95 |
| .rdata | 77824 | 7189 | 7680 | 3.37138 | 0fb0a72395723950e1915d6bf373f506 |
| .data | 86016 | 65324 | 512 | 2.43883 | 11ffdfc240c81dfe9d957f6bf1761f00 |
| .CRT | 151552 | 16 | 512 | 0.147711 | a5ba361df79e0a565f00bd42dc501625 |
| .rsrc | 155648 | 16504 | 16896 | 2.78807 | 4a42d4a1c79a481d4a049c0bb7911c60 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Network Activity
URLs
| URL | IP |
|---|---|
| hxxp://dt.web-search-home.com/getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A== | |
| hxxp://dt.web-search-home.com/download/yandexdtLite | |
| hxxp://mirror23.mountspace.com/getfile.php?p=hxxp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe | |
| hxxp://web-search-home.com/download/yandexdtLite |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
GET /getsettings?query=GNNfZQWUSUiqIdLnKNvMCWONHmmtB4GyN1neWQ5Hrhcs97W0l3CNcge3IKypSpg5kSHNUNN1OsEkUhQ3B+tZ2A== HTTP/1.1
Connection: Keep-Alive
Host: dt.web-search-home.com
HTTP/1.1 200 OK
Server: nginx/1.0.15
Date: Sun, 19 Mar 2017 20:50:07 GMT
Content-Type: text/html; charset=utf-8
Connection: close
X-Powered-By: PHP/5.3.29
Set-Cookie: PHPSESSID=tmtd9mej8682qtd5kn84kdgja7; path=/; domain=web-search-home.com
Content-Length: 3904
Jhz9HA/OCm0GW6fp9ZcSPDN34A485s78WSH2Jd SS2e96LkhrSzsfWe/aniircng kpRLoZsqhAQv8vCVpKIf08MvKSvlWND8pTpxJea euCVcbwqRQCtsUE vavGJoC630cVWj/iIQHNtvbMPDN9ChUZ66FNi6Cn0I5sEQsCRCGAwt5Tjkb1rnTGMV hGpIrOtC1q924swB3 7RaNPOkIYAco8kr9kFVuFmXRs0sD9UmV13VFwenUxK0H1bbFve5xHdkhoGDFDUDC5adsSfz43jS/TmKtIQm7GEjMZFE7EKZ qAlIjCRV3BBhX /VpWDS4TO9aXEtdHbJq7bsR RldNXvJjl9y du67xyCIwYdaw WJbMzBRGQA fW/WOmpdzUDaY44j5mm1T89qA8UbM18s998P9YW4zZAqmfOAU16hWoG3v/ixsNPAMnKnEzFTdcWLDTD32iNGzbbhPMrB AslbUUtWrqoUvhd/neRJWKWFU4L2roLbhRI0qNGMtKe7YXF9p3EVFCy hSXE5HAV88AV4z0vw4rVop2baNVxyrwrrd8RN9tHVBsVvRvGR5RVb7MeOAX bmXo7d2kPm6n4mLUZWnGLdpojnYK4J70mRW7DL9KStSF2iHuZnUrGTvgSCVlKgT31eba02Ho6iK7AbIYzImgScRxdnNoJzvnnVgH9C8K99Y03AQLBiByudppCDFVxmk IDSxiIF5x5EwKkj2zjZ5h94RsqGB63KFNOmMmowv8s/EZSHGP7lJuLyscLN7rl6qttro6lHpGe6HtT8W3UCKn60EMERHisGRpCFV u3YcdVYSctQrHSwIlZ0Hy1rPNq8iGRrQjpIG/bNBiEd dYIFH7WYyDVsts6 iFDJklN18/Fuw7xXDGm8IPlumykb4ufaT6a/4OstjcX3c9dychuaghoNWiGEXI1QRgzdT6r2T5fvfV4pd0kg9JXIMOTbi62fIikQj9ZnCEo67fG3H0NXE0ZKklKmdjSUaIlGZkKkANicWsbCrKYA3zuKPDJv0lD7WQrP7m8s7Hbv5TawxpRVPSOj2ay1rjIkrSSkXVJECoqEVjloZzYctZJ0D60AoCN4GyxkC8cIwxK4ho/wG8T2mPi31H3iYw0WzSTmkadHNcZggYo6qZOhWOEPPMJJW3uCH5oJs0Loccx OiRChZ2EvQ22jKrM40EPkNEZyNt6ILjRYIZDgJIp4tfq5AMpCwRd24d5TmdVTvlbE43TMuPkP4suVvVKjxGQcLxsQfDSyU7EPSxVS39HgQqsMkAMhXbdoVSGS4Kbrob97ByKsz//02CMpGIA54QOlNEs0nfdhtRBPJwD2tVCW6AYlhUis/1ctmqWJ5pG1rncAPBn8CRTMEpQmBit9T/IjYmPOYB/GgvKFuePlfx1kYTVqP Bb3SIevwVIsMdefhBHn29Ub4KEo9esQiNQ47bpFxpnINyaseLMDvYUx4lR22L1oed4s0a9cJcpokLK/ e5QBRb7frT6ljCDUw lFLrqNjX07iOMJ/0cxdS/tWi
<<< skipped >>>
GET /getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe HTTP/1.1
Connection: Keep-Alive
Host: mirror23.mountspace.com
HTTP/1.1 200 OK
Server: nginx/0.8.55
Date: Sun, 19 Mar 2017 20:50:22 GMT
Content-Type: application/octet-stream
Connection: close
X-Powered-By: PHP/5.3.19
Cache-Control:
Pragma:
Content-Disposition: attachment; filename="DT_free_Rus_YandexBar1022.exe"
Content-Transfer-Encoding: binary
Accept-Ranges: bytes
Content-Length: 878208
MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^".u.C.&.C.&.C.&..S&.C.&..g&kC.&..f&3C.&.;^&.C.&.C.&.C.&..b&.C.&..W&.C.&..P&.C.&Rich.C.&........................PE..L....v.P.............................O............@..................................Z....@.....................................x....p...............R.......p..$...`...............................p...@............................................text............................... ..`.rdata...V.......X..................@..@.data....1...0......................@....rsrc........p.......,..............@..@.reloc...$...p...&...,..............@..B................................................................................................................................................................................................................................................................................................................................................U..W....9w@t5.G....w].$...@...tR.F..I..tI.F.P.A.P....@..5..t5.F..,..t,.F..#......w6......s...Nt%......u...t.....uJ.M............_].........2...r...8...v.......u....H...v..A......RP....@...VS... ..WP....@._]....I...@.%.@.9.@.l.@.l.@.........................U....$.U..M.SV.u..^..F.W.}..U.3.R.U..U..U..U..U.R.U.RQ.]..]..^...W.E..M.P.....E.$....E......}....M....N...tK..9w.t....r'../v...7u..]..<......t...1...v...8...v..F..u..U..F.Rj.P....@.........u..N...F...t .~..u..N.......F..B.Q...F......._^..[..]...........
<<< skipped >>>
GET /download/yandexdtLite HTTP/1.1
Connection: Keep-Alive
Host: web-search-home.com
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.0.15
Date: Sun, 19 Mar 2017 20:50:22 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
X-Powered-By: PHP/5.3.29
Set-Cookie: PHPSESSID=qq11dd7q3ss3td1dp3d1v6kch6; path=/; domain=web-search-home.com
Location: hXXp://mirror23.mountspace.com/getfile.php?p=hXXp://eu-uk7.disk-tools.com/f8c73ad1ae1a2b396bd63e8855c2017a/DT_free_Rus_YandexBar1022.exe
0..
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_1796:
.text
.text
`.rdata
`.rdata
@.data
@.data
@.rsrc
@.rsrc
VSSSSh
VSSSSh
^SShq
^SShq
%.*s(%d)%s
%.*s(%d)%s
COMCTL32.dll
COMCTL32.dll
SHLWAPI.dll
SHLWAPI.dll
GetProcessHeap
GetProcessHeap
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
COMDLG32.dll
COMDLG32.dll
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
ADVAPI32.dll
ADVAPI32.dll
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
WINRAR.SFX
WINRAR.SFX
d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
version="1.0.0.0"
version="1.0.0.0"
name="Microsoft.Windows.Common-Controls" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" r%.*s(%d)%s r%.*s(%d)%s rtmp%d rtmp%d Shell.Explorer %s %s %s %s %s %s %s %s %s %s GETPASSWORD1 GETPASSWORD1 %s%s%d %s%s%d Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion %s.%d.tmp %s.%d.tmp winrarsfxmappingfile.tmp winrarsfxmappingfile.tmp -el -s2 "-d%s" "-p%s" "-sp%s" -el -s2 "-d%s" "-p%s" "-sp%s" __tmp_rar_sfx_access_check_%u __tmp_rar_sfx_access_check_%u sfxcmd sfxcmd riched20.dll riched20.dll riched32.dll riched32.dll Extracting %s Extracting %s c:\%original file name%.exe c:\%original file name%.exe Enter password Enter password &Enter password for the encrypted file: &Enter password for the encrypted file: Skipping %s Skipping %s The file "%s" header is corrupt%The archive comment header is corrupt The file "%s" header is corrupt%The archive comment header is corrupt Unknown method in %s Unknown method in %s Cannot open %s Cannot open %s Cannot create %s Cannot create %s Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password. Cannot create folder %sDCRC failed in the encrypted file %s. Corrupt file or wrong password. CRC failed in %s CRC failed in %s Packed data CRC failed in %s Packed data CRC failed in %s Wrong password for %s5Write error in the file %s. Probably the disk is full Wrong password for %s5Write error in the file %s. Probably the disk is full Read error in the file %s Read error in the file %s Extracting from %s Extracting from %s ErroraErrors encountered while performing the operation ErroraErrors encountered while performing the operation Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt. Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt. Extracting files to %s folder$Extracting files to temporary folder Extracting files to %s folder$Extracting files to temporary folder =Total path and file name length must not exceed %d characters =Total path and file name length must not exceed %d characters conhost.exe_3496:
.text .text `.data `.data .rsrc .rsrc @.reloc @.reloc GDI32.dll GDI32.dll USER32.dll USER32.dll msvcrt.dll msvcrt.dll ntdll.dll ntdll.dll API-MS-Win-Core-LocalRegistry-L1-1-0.dll API-MS-Win-Core-LocalRegistry-L1-1-0.dll KERNEL32.dll KERNEL32.dll IMM32.dll IMM32.dll ole32.dll ole32.dll OLEAUT32.dll OLEAUT32.dll PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected Invalid message 0x%x Invalid message 0x%x InitExtendedEditKeys: Unsupported version number(%d) InitExtendedEditKeys: Unsupported version number(%d) Console init failed with status 0x%x Console init failed with status 0x%x CreateWindowsWindow failed with status 0x%x, gle = 0x%x CreateWindowsWindow failed with status 0x%x, gle = 0x%x InitWindowsStuff failed with status 0x%x (gle = 0x%x) InitWindowsStuff failed with status 0x%x (gle = 0x%x) InitSideBySide failed create an activation context. Error: %d InitSideBySide failed create an activation context. Error: %d GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1. GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1. GetModuleFileNameW failed %d. GetModuleFileNameW failed %d. Invalid EventType: 0x%x Invalid EventType: 0x%x Dup handle failed for %d of %d (Status = 0x%x) Dup handle failed for %d of %d (Status = 0x%x) Couldn't grow input buffer, Status == 0x%x Couldn't grow input buffer, Status == 0x%x InitializeScrollBuffer failed, Status = 0x%x InitializeScrollBuffer failed, Status = 0x%x CreateWindow failed with gle = 0x%x CreateWindow failed with gle = 0x%x Opening Font file failed with error 0x%x Opening Font file failed with error 0x%x \ega.cpi \ega.cpi NtReplyWaitReceivePort failed with Status 0x%x NtReplyWaitReceivePort failed with Status 0x%x ConsoleOpenWaitEvent failed with Status 0x%x ConsoleOpenWaitEvent failed with Status 0x%x NtCreatePort failed with Status 0x%x NtCreatePort failed with Status 0x%x GetCharWidth32 failed with error 0x%x GetCharWidth32 failed with error 0x%x GetTextMetricsW failed with error 0x%x GetTextMetricsW failed with error 0x%x GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x RtlStringCchCopy failed with Status 0x%x RtlStringCchCopy failed with Status 0x%x Cannot allocate 0n%d bytes Cannot allocate 0n%d bytes |%SWj |%SWj O.fBf; O.fBf; ReCreateDbcsScreenBuffer failed. Restoring to CP=%d ReCreateDbcsScreenBuffer failed. Restoring to CP=%d Invalid Parameter: 0x%x, 0x%x, 0x%x Invalid Parameter: 0x%x, 0x%x, 0x%x ConsoleKeyInfo buffer is full ConsoleKeyInfo buffer is full Invalid screen buffer size (0x%x, 0x%x) Invalid screen buffer size (0x%x, 0x%x) SetROMFontCodePage: failed to memory allocation %d bytes SetROMFontCodePage: failed to memory allocation %d bytes FONT.NT FONT.NT Failed to set font image. wc=x, sz=(%x,%x) Failed to set font image. wc=x, sz=(%x,%x) Failed to set font image. wc=x sz=(%x, %x). Failed to set font image. wc=x sz=(%x, %x). Failed to set font image. wc=x sz=(%x,%x) Failed to set font image. wc=x sz=(%x,%x) FullscreenControlSetColors failed - Status = 0x%x FullscreenControlSetColors failed - Status = 0x%x FullscreenControlSetPalette failed - Status = 0x%x FullscreenControlSetPalette failed - Status = 0x%x WriteCharsFromInput failed 0x%x WriteCharsFromInput failed 0x%x WriteCharsFromInput failed %x WriteCharsFromInput failed %x RtlStringCchCopyW failed with Status 0x%x RtlStringCchCopyW failed with Status 0x%x CreateFontCache failed with Status 0x%x CreateFontCache failed with Status 0x%x FTPh FTPh \>.Sj \>.Sj GetKeyboardLayout GetKeyboardLayout MapVirtualKeyW MapVirtualKeyW VkKeyScanW VkKeyScanW GetKeyboardState GetKeyboardState UnhookWindowsHookEx UnhookWindowsHookEx SetWindowsHookExW SetWindowsHookExW GetKeyState GetKeyState ActivateKeyboardLayout ActivateKeyboardLayout GetKeyboardLayoutNameA GetKeyboardLayoutNameA GetKeyboardLayoutNameW GetKeyboardLayoutNameW _amsg_exit _amsg_exit _acmdln _acmdln ShipAssert ShipAssert NtReplyWaitReceivePort NtReplyWaitReceivePort NtCreatePort NtCreatePort NtEnumerateValueKey NtEnumerateValueKey NtQueryValueKey NtQueryValueKey NtOpenKey NtOpenKey NtAcceptConnectPort NtAcceptConnectPort NtReplyPort NtReplyPort SetProcessShutdownParameters SetProcessShutdownParameters GetCPInfo GetCPInfo conhost.pdb conhost.pdb %$%a%b%V%U%c%Q%W%]%\%[% %$%a%b%V%U%c%Q%W%]%\%[% %
%
version="5.1.0.0" version="5.1.0.0" name="Microsoft.Windows.ConsoleHost" name="Microsoft.Windows.ConsoleHost" name="Microsoft.Windows.ConsoleHost.SystemDefault" name="Microsoft.Windows.ConsoleHost.SystemDefault" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" name="Microsoft.Windows.SystemCompatible" name="Microsoft.Windows.SystemCompatible" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" :>@> :>@> 2%2X2 2%2X2 %SystemRoot% %SystemRoot% \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen WindowSize WindowSize ColorTableu ColorTableu ExtendedEditkeyCustom ExtendedEditkeyCustom ExtendedEditKey ExtendedEditKey Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion \ !:=/.;|& \ !:=/.;|& %d/%d %d/%d cmd.exe cmd.exe desktop.ini desktop.ini \console.dll \console.dll %d/%d %d/%d 6.1.7601.17641 (win7sp1_gdr.110623-1503) 6.1.7601.17641 (win7sp1_gdr.110623-1503) CONHOST.EXE CONHOST.EXE Windows Windows Operating System Operating System 6.1.7601.17641 6.1.7601.17641 DAEMONLite4.41.exe_3616:
.text .text `.rdata `.rdata @.data @.data .rsrc .rsrc diu2.iu diu2.iu Advapi32.dll Advapi32.dll irsetup.exe irsetup.exe Could not determine a temp directory name. Try running setup.exe /T: Could not determine a temp directory name. Try running setup.exe /T: c:\temp c:\temp %s\irsetup.exe %s\irsetup.exe %s%s_%d %s%s_%d "__IRSID:%s" "__IRSID:%s" "__IRCT:%d" "__IRCT:%d" "__IRAFN:%s" "__IRAFN:%s" __IRAOFF:%u __IRAOFF:%u KERNEL32.DLL KERNEL32.DLL mscoree.dll mscoree.dll Please contact the application's support team for more information. Please contact the application's support team for more information. - Attempt to initialize the CRT more than once. - Attempt to initialize the CRT more than once. - CRT not initialized - CRT not initialized kernel32.dll kernel32.dll GetProcessWindowStation GetProcessWindowStation USER32.DLL USER32.DLL operator operator KERNEL32.dll KERNEL32.dll MsgWaitForMultipleObjects MsgWaitForMultipleObjects USER32.dll USER32.dll ADVAPI32.dll ADVAPI32.dll ShellExecuteExA ShellExecuteExA SHELL32.dll SHELL32.dll GetProcessHeap GetProcessHeap GetCPInfo GetCPInfo C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe C:\Users\"%CurrentUserName%"\AppData\Local\Temp\RarSFX0\DAEMONLite4.41.exe %xERRj3cqZQ %xERRj3cqZQ ! !!####0 ! !!####0 ;;;9551%%0 ;;;9551%%0 ! !!565665@ ! !!565665@ version="8.1.1000.0" version="8.1.1000.0" name="setup.exe"/> name="setup.exe"/> name="Microsoft.Windows.Common-Controls" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" 04090000 04090000 VVV.u-soft.org VVV.u-soft.org 0.0.0.0 0.0.0.0 suf80_launch.exe suf80_launch.exe irsetup.exe_2296:
`.rsrc `.rsrc FtPh FtPh FtPhu FtPhu SSSSh SSSSh SSh`UQ SSh`UQ SSh4UQ SSh4UQ SShlTQ SShlTQ SShDTQ SShDTQ u1SSh u1SSh Su%Sh Su%Sh SShx`Q SShx`Q txSSh
txSSh
SSh _Q SSh _Q @ SSh @ SSh .hPsQ .hPsQ SSShDxQ SSShDxQ 9^$u&SSSSh? 9^$u&SSSSh? u SSSSh? u SSSSh? 9^$u)SSSSh? 9^$u)SSSSh? u.VWS u.VWS WSSh|DQ WSSh|DQ udPQ udPQ t.Ht Ht(Ht t.Ht Ht(Ht y2SSh y2SSh FHSSh FHSSh GHSSh GHSSh GTSSh GTSSh G\SSh G\SSh FlSSh FlSSh Nt.Nt Nt.Nt SShlSR SShlSR tjSShHSR tjSShHSR t;SSh$SR t;SSh$SR F
F
t'SShl t'SShl u$SShe u$SShe aSSSh aSSSh .VVVVVSRSSj .VVVVVSRSSj FTPjK FTPjK FtPj; FtPj; C.PjRV C.PjRV diu2.iuz diu2.iuz MSG_ERROR MSG_ERROR %s %d. %s %s %d. %s MSG_ASK_FOR_DISK MSG_ASK_FOR_DISK MSG_NEW_LOCATION MSG_NEW_LOCATION MSG_CONFIRM_ABORT MSG_CONFIRM_ABORT MSG_CONFIRM MSG_CONFIRM A%s.%d A%s.%d %s, Line %d: %s %s, Line %d: %s File condition evaluation for file "%s" File condition evaluation for file "%s" C:\temp\SUF_SFX_TEST\ C:\temp\SUF_SFX_TEST\ msi.dll msi.dll \msi.dll \msi.dll Software\Microsoft\Windows\CurrentVersion\Installer Software\Microsoft\Windows\CurrentVersion\Installer MSG_INITIALIZING MSG_INITIALIZING 16670749 16670749 [%d]: %s [%d]: %s *** LOCATION: %s *** LOCATION: %s __NOREPORT__ __NOREPORT__ Script: %s, %s (%s) Script: %s, %s (%s) __ir_eval_value = %s; __ir_eval_value = %s; %s (%s:%d) %s (%s:%d) F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl %Copyright%. All rights reserved. %CompanyURL% %Copyright%. All rights reserved. %CompanyURL% WindowStyle WindowStyle MainWindowSettings MainWindowSettings %s at offset %d unterminated %s at offset %d unterminated Incorrect %s at offset %d Incorrect %s at offset %d Element '%s' at offset %d not ended Element '%s' at offset %d not ended End tag '%s' at offset %d does not match start tag '%s' at offset %d End tag '%s' at offset %d does not match start tag '%s' at offset %d No start tag for end tag '%s' at offset %d No start tag for end tag '%s' at offset %d %s%d bytes %s%d bytes %s%d wide chars to %d bytes %s%d wide chars to %d bytes %d bytes to %s%d wide chars %d bytes to %s%d wide chars MSG_SEARCH_FILE MSG_SEARCH_FILE (*.*)|*.*|| (*.*)|*.*|| MSG_SEARCH_ALL MSG_SEARCH_ALL MSG_SEARCH_MASK MSG_SEARCH_MASK MSG_INSERTDISK MSG_INSERTDISK MSG_CANCEL MSG_CANCEL MSG_OK MSG_OK MSG_BROWSE MSG_BROWSE MSG_PATH MSG_PATH Windows Server 2008 Windows Server 2008 Windows Vista Windows Vista Windows Server 2003 Windows Server 2003 Windows XP Windows XP Windows 2000 Windows 2000 Windows NT4 Windows NT4 Windows NT3 Windows NT3 Windows ME Windows ME Windows 98 Windows 98 Windows 95 Windows 95 CPasswordData CPasswordData -- Defined in _SUF70_Global_Functions.lua -- Defined in _SUF70_Global_Functions.lua number e_ErrorCode, string e_ErrorMsgID number e_ErrorCode, string e_ErrorMsgID %WindowsFolder%\%ProductName% Setup Log.txt %WindowsFolder%\%ProductName% Setup Log.txt %StartupFolder% %StartupFolder% %StartFolder% %StartFolder% %StartProgramsFolder% %StartProgramsFolder% ÞsktopFolder% ÞsktopFolder% %s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %CommonFilesFolder%\Microsoft Shared\DAO %CommonFilesFolder%\Microsoft Shared\DAO Software\Microsoft\Shared Tools\DAO350.dll Software\Microsoft\Shared Tools\DAO350.dll Software\Microsoft\Shared Tools\DAO360.dll Software\Microsoft\Shared Tools\DAO360.dll ÚOPath% ÚOPath% Software\Microsoft\Windows NT\CurrentVersion Software\Microsoft\Windows NT\CurrentVersion Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion %SourceFolder% %SourceFolder% %SystemDrive% %SystemDrive% _WindowsFolder _WindowsFolder %WindowsFolder% %WindowsFolder% %SystemFolder% %SystemFolder% %CommonFilesFolder% %CommonFilesFolder% %CommonFilesFolder64% %CommonFilesFolder64% %CommonProgramW6432% %CommonProgramW6432% %CommonDocumentsFolder% %CommonDocumentsFolder% %StartupFolderCommon% %StartupFolderCommon% %StartProgramsFolderCommon% %StartProgramsFolderCommon% %StartFolderCommon% %StartFolderCommon% %FontsFolder% %FontsFolder% ÞsktopFolderCommon% ÞsktopFolderCommon% UninstallSupportFiles UninstallSupportFiles CPRegKey CPRegKey Run extra uninstall script: %d Run extra uninstall script: %d %SourceDrive% %SourceDrive% %SourceFilename% %SourceFilename% \irsetup.dat \irsetup.dat Support file added to uninstall list: Support file added to uninstall list: Registry key added to uninstall list: Registry key added to uninstall list: Remove uninstall support file: Remove uninstall support file: Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\ Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\ Register font: %s, %s Register font: %s, %s %sbk%d %sbk%d MSG_NO MSG_NO MSG_YES_TOALL MSG_YES_TOALL MSG_YES MSG_YES MSG_UNINSTALL_OK_REMOVE MSG_UNINSTALL_OK_REMOVE MSG_UNINSTALL_NO_APP_USE MSG_UNINSTALL_NO_APP_USE MSG_UNINSTALL_REMOVE_SHARED MSG_UNINSTALL_REMOVE_SHARED Decrement shared file count: %s (New count = %d) Decrement shared file count: %s (New count = %d) SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs : %s (#%d) : %s (#%d) Global include script: %s Global include script: %s RegisterTypeLib: %s RegisterTypeLib: %s RegisterTypeLib: %s - %s RegisterTypeLib: %s - %s Register COM file: %s Register COM file: %s Register COM file: %s - System Error # %u Register COM file: %s - System Error # %u Register COM file on reboot: %s Register COM file on reboot: %s regsvr32.exe /s %s regsvr32.exe /s %s SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce Increment usage count: %s Increment usage count: %s Increment usage count: %s (New count = %d) Increment usage count: %s (New count = %d) %s\%s %s\%s %s (%d) %s (%d) local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d; local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d; MSG_SYSREQ_WARN MSG_SYSREQ_WARN MSG_NOTICE MSG_NOTICE MSG_SYSREQ_ABORT MSG_SYSREQ_ABORT %s: %s %s: %s MSG_SYSREQ_USERPERMISSION MSG_SYSREQ_USERPERMISSION MSG_SYSREQ_SYSTEMADMIN MSG_SYSREQ_SYSTEMADMIN MSG_SYSREQ_COLORDEPTH MSG_SYSREQ_COLORDEPTH MSG_BITSPERPIXEL MSG_BITSPERPIXEL MSG_SYSREQ_SCREENHEIGHT MSG_SYSREQ_SCREENHEIGHT MSG_SYSREQ_SCREENWIDTH MSG_SYSREQ_SCREENWIDTH %s: %d %s: %d %s: %d %s %s: %d %s MSG_SYSREQ_RAM MSG_SYSREQ_RAM MSG_SIZE_MEGABYTES MSG_SIZE_MEGABYTES Operating System Operating System MSG_SYSREQ_OS MSG_SYSREQ_OS MSG_OS_PART_ORNEWER MSG_OS_PART_ORNEWER MSG_OS_PART_NOSERVPACK MSG_OS_PART_NOSERVPACK MSG_OS_PART_SERVPACK MSG_OS_PART_SERVPACK MSG_OS_PART_SE MSG_OS_PART_SE MSG_OS_PART_C MSG_OS_PART_C MSG_OS_PART_B MSG_OS_PART_B MSG_OS_PART_A MSG_OS_PART_A MSG_OS_ALL MSG_OS_ALL MSG_OS_NONE MSG_OS_NONE MSG_OS_WSRV2008 MSG_OS_WSRV2008 MSG_OS_WVISTA MSG_OS_WVISTA MSG_OS_WSRV2003 MSG_OS_WSRV2003 MSG_OS_WXP MSG_OS_WXP MSG_OS_W2000 MSG_OS_W2000 MSG_OS_WNT4 MSG_OS_WNT4 MSG_OS_WNT3 MSG_OS_WNT3 MSG_OS_WME MSG_OS_WME MSG_OS_W98 MSG_OS_W98 MSG_OS_W95 MSG_OS_W95 MSG_OS_UNKNOWN MSG_OS_UNKNOWN MSG_SYSREQ_NOTMET MSG_SYSREQ_NOTMET MSG_EXP_USESLEFT MSG_EXP_USESLEFT MSG_EXP_USESLEFT2 MSG_EXP_USESLEFT2 %s %d %s %s %d %s MSG_EXP_DAYSLEFT MSG_EXP_DAYSLEFT MSG_EXP_DAYSLEFT2 MSG_EXP_DAYSLEFT2 Software\Microsoft\Windows\CurrentVersion\I652R9823\ Software\Microsoft\Windows\CurrentVersion\I652R9823\ MSG_EXP_CONTACT_START MSG_EXP_CONTACT_START MSG_SEEKING MSG_SEEKING Dependency Detection Passed Dependency Detection Passed Arc: %s Arc: %s FN: %s FN: %s %s (#%d) %s (#%d) MSG_SKIPPING MSG_SKIPPING MSG_INSTALLING MSG_INSTALLING Run project event: %s Run project event: %s local e_ErrorCode=%d; local e_ErrorMsgID = "%s" local e_ErrorCode=%d; local e_ErrorMsgID = "%s" Start project event: %s Start project event: %s MSG_UNINSTALLFILE_NOREMOVE MSG_UNINSTALLFILE_NOREMOVE MSG_UNINSTALLFILE_INUSE MSG_UNINSTALLFILE_INUSE %s (%s: %u) %s (%s: %u) \WININIT.INI \WININIT.INI MSG_FILE_EXISTS_INUSE MSG_FILE_EXISTS_INUSE MSG_FILE_EXISTS_RETRY MSG_FILE_EXISTS_RETRY MSG_FILE_EXISTS_ANY MSG_FILE_EXISTS_ANY MSG_FILE_EXISTS_NEWER MSG_FILE_EXISTS_NEWER MSG_FILE_OVERWRITE_CONFIRM MSG_FILE_OVERWRITE_CONFIRM %s\%s.lnk %s\%s.lnk %s (Return code: %d) %s (Return code: %d) Product: %s, version %s Product: %s, version %s %s (%d): %s (%d): MSG_PROG_UNINSTALL_CREATECONTROLFILE MSG_PROG_UNINSTALL_CREATECONTROLFILE ERR_CREATEUNINSTALL_OPEN_EXE_READ ERR_CREATEUNINSTALL_OPEN_EXE_READ ERR_CREATEUNINSTALL_OPEN_EXE_WRITE ERR_CREATEUNINSTALL_OPEN_EXE_WRITE Overwrite uninstall executable: Overwrite uninstall executable: MSG_PROG_UNINSTALL_CREATEEXE MSG_PROG_UNINSTALL_CREATEEXE @MSG_PROG_UNINSTALL_CREATEDATFILE @MSG_PROG_UNINSTALL_CREATEDATFILE ?MSG_PROG_UNINSTALL_CREATEFOLDER ?MSG_PROG_UNINSTALL_CREATEFOLDER "/U:%s" "/U:%s" MSG_PROG_UNINSTALL_CREATESC MSG_PROG_UNINSTALL_CREATESC Create uninstall CP entry key Create uninstall CP entry key ERR_CREATEUNINSTALL_CREATEREGKEY ERR_CREATEUNINSTALL_CREATEREGKEY "%s",%d "%s",%d Uninstall CP entry: URLUpdateInfo = Uninstall CP entry: URLUpdateInfo = URLUpdateInfo URLUpdateInfo Uninstall CP entry: URLInfoAbout = Uninstall CP entry: URLInfoAbout = URLInfoAbout URLInfoAbout "%s" "/U:%s" "%s" "/U:%s" HKEY_LOCAL_MACHINE\ HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ MSG_PROG_UNINSTALL_CREATECPENTRY MSG_PROG_UNINSTALL_CREATECPENTRY MSG_PROG_UNINSTALL_COPYSUPPORTFILES MSG_PROG_UNINSTALL_COPYSUPPORTFILES MSG_PROG_UNINSTALL_COPYPLUGINS MSG_PROG_UNINSTALL_COPYPLUGINS %s %s %s %s MSG_REQUIRED_DRIVE MSG_REQUIRED_DRIVE MSG_AVAILABLE_DRIVE MSG_AVAILABLE_DRIVE MSG_PROG_CHECKING_DRIVESPACE MSG_PROG_CHECKING_DRIVESPACE MSG_PROG_CHECKING_FILES MSG_PROG_CHECKING_FILES %A, %B %d, %Y %A, %B %d, %Y [%s] %s [%s] %s %m/%d/%Y %H:%M:%S %m/%d/%Y %H:%M:%S MsgFile MsgFile ERR_MSI_PATCH_REMOVAL_UNSUPPORTED ERR_MSI_PATCH_REMOVAL_UNSUPPORTED ERR_MSI_PATCH_PACKAGE_UNSUPPORTED ERR_MSI_PATCH_PACKAGE_UNSUPPORTED ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED ERR_MSI_UNSUPPORTED_TYPE ERR_MSI_UNSUPPORTED_TYPE ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE ERR_ODBC_INVALID_KEYWORD_VALUE ERR_ODBC_INVALID_KEYWORD_VALUE ERR_WEB_503 ERR_WEB_503 ERR_WEB_500 ERR_WEB_500 ERR_WEB_404 ERR_WEB_404 ERR_WEB_403 ERR_WEB_403 ERR_WEB_400 ERR_WEB_400 ERR_WEB_SET_PROXY_PASSWORD ERR_WEB_SET_PROXY_PASSWORD ERR_WEB_SET_PROXY_USERNAME ERR_WEB_SET_PROXY_USERNAME ERR_WEB_WRITE_MEMORY ERR_WEB_WRITE_MEMORY ERR_WEB_FTP_FILE_OPEN ERR_WEB_FTP_FILE_OPEN ERR_WEB_USER_ABORT ERR_WEB_USER_ABORT ERR_WEB_FILE_WRITE ERR_WEB_FILE_WRITE ERR_WEB_DOWNLOAD_FILE_ERROR ERR_WEB_DOWNLOAD_FILE_ERROR ERR_WEB_INVALID_HTTP_RESPONSE ERR_WEB_INVALID_HTTP_RESPONSE ERR_WEB_DESTINATION_FILE_OPEN ERR_WEB_DESTINATION_FILE_OPEN ERR_WEB_SEND_REQUEST ERR_WEB_SEND_REQUEST ERR_WEB_OPEN_REQUEST ERR_WEB_OPEN_REQUEST ERR_WEB_CREATE_HTTP_CONNECTION ERR_WEB_CREATE_HTTP_CONNECTION ERR_WEB_CREATE_INTERNET_SESSION ERR_WEB_CREATE_INTERNET_SESSION ERR_REG_GET_SUB_KEY_NAME ERR_REG_GET_SUB_KEY_NAME ERR_REG_NON_EXISTANT_SUB_KEY ERR_REG_NON_EXISTANT_SUB_KEY ERR_REG_DELETE_KEY ERR_REG_DELETE_KEY ERR_REG_CREATE_KEY ERR_REG_CREATE_KEY ERR_FILE_EXECUTION_FAILED_ELEVATION ERR_FILE_EXECUTION_FAILED_ELEVATION ERR_KEY_RUN_ON_REBOOT_FAILED ERR_KEY_RUN_ON_REBOOT_FAILED ERR_USER_ABORTED_OPERATION ERR_USER_ABORTED_OPERATION ERR_NON_EXISTANT_VIEWER_EXE ERR_NON_EXISTANT_VIEWER_EXE ERR_FILE_EXECUTION_FAILED ERR_FILE_EXECUTION_FAILED ERR_SPECIFIED_EXE_FILE_INVALID ERR_SPECIFIED_EXE_FILE_INVALID MSG_SUCCESS MSG_SUCCESS Language set: Primary = %d, Secondary = %d Language set: Primary = %d, Secondary = %d %CompanyURL% %CompanyURL% %CompanyName% %CompanyName% UxTheme.dll UxTheme.dll %Copyright% %CompanyName%. All rights reserved. %CompanyURL% %Copyright% %CompanyName%. All rights reserved. %CompanyURL% %WindowsFolder%\%ProductName% Uninstall Log.txt %WindowsFolder%\%ProductName% Uninstall Log.txt %CompanyName% Support Department %CompanyName% Support Department %WindowsFolder%\%ProductName%\uninstall.exe %WindowsFolder%\%ProductName%\uninstall.exe uninstall.xml uninstall.xml CWebBrowser2 CWebBrowser2 Confirm Operation Confirm Operation kernel32.dll kernel32.dll KERNEL32.DLL KERNEL32.DLL PSAPI.DLL PSAPI.DLL Kernel32.dll Kernel32.dll WS2_32.DLL WS2_32.DLL Copying "%s" Copying "%s" "%s" %s "%s" %s %d.%d.%d.%d %d.%d.%d.%d \StringFileInfo\xx\ProductVersion \StringFileInfo\xx\ProductVersion \StringFileInfo\xx\PrivateBuild \StringFileInfo\xx\PrivateBuild .bak%d .bak%d Windows NT 4 Windows NT 4 Windows NT 3 Windows NT 3 %s\shell\open\command %s\shell\open\command NUL=%s NUL=%s Software\Microsoft\Windows NT\CurrentVersion\Fonts Software\Microsoft\Windows NT\CurrentVersion\Fonts Software\Microsoft\Windows\CurrentVersion\Fonts Software\Microsoft\Windows\CurrentVersion\Fonts ***!!!***@@ ***!!!***@@ Advapi32.dll Advapi32.dll Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %s\%s.url %s\%s.url %s\%s.pif %s\%s.pif srclient.dll srclient.dll %s_%d %s_%d %s\_ir_tmpfnt_%d %s\_ir_tmpfnt_%d /\:*?"| /\:*?"| jsproxy.dll jsproxy.dll DetectAutoProxyUrl DetectAutoProxyUrl wininet.dll wininet.dll %%x %%x d:d d:d WinINet.dll WinINet.dll Could not create Internet session: %u Could not create Internet session: %u Error downloading file: %u Error downloading file: %u Error writing the destination file: %d-%u Error writing the destination file: %d-%u Could not create HTTP connection: %u Could not create HTTP connection: %u Could not create HTTP connection Could not create HTTP connection Incorrect HTTP status returned by server: %d Incorrect HTTP status returned by server: %d Send request failed: %u Send request failed: %u Content-Type: application/x-www-form-urlencoded Content-Type: application/x-www-form-urlencoded Could not open HTTP file: %s Could not open HTTP file: %s PTF:// PTF:// hXXps:// hXXps:// hXXp:// hXXp:// Could not open request: %u Could not open request: %u Could not HTTP file: %u Could not HTTP file: %u MSG_STATUS_HANDLE_CREATED MSG_STATUS_HANDLE_CREATED MSG_STATUS_HANDLE_CLOSING MSG_STATUS_HANDLE_CLOSING MSG_STATUS_REQUEST_COMPLETE MSG_STATUS_REQUEST_COMPLETE MSG_REDIRECTING MSG_REDIRECTING MSG_CONNECTION_CLOSED MSG_CONNECTION_CLOSED MSG_RESOLVING_HOST_NAME MSG_RESOLVING_HOST_NAME MSG_HOST_NAME_RESOLVED MSG_HOST_NAME_RESOLVED MSG_CONNECTING_TO_SERVER MSG_CONNECTING_TO_SERVER MSG_CONNECTED_TO_SERVER MSG_CONNECTED_TO_SERVER MSG_CLOSING_CONNECTION MSG_CLOSING_CONNECTION TRACE: LastError = %d ("%s") TRACE: LastError = %d ("%s") Script: %s, %s Script: %s, %s Script: %s, Line %d Script: %s, Line %d All Files (*.*)|*.*| All Files (*.*)|*.*| PasswordInput PasswordInput MSG_MOVING MSG_MOVING MSG_COPYING MSG_COPYING MSG_FROM MSG_FROM MSG_TO MSG_TO MSG_DELETING MSG_DELETING MSG_SEARCHING MSG_SEARCHING \StringFileInfo\xx\SpecialBuild \StringFileInfo\xx\SpecialBuild \StringFileInfo\xx\OriginalFilename \StringFileInfo\xx\OriginalFilename \StringFileInfo\xx\Comments \StringFileInfo\xx\Comments \StringFileInfo\xx\LegalTrademarks \StringFileInfo\xx\LegalTrademarks \StringFileInfo\xx\LegalCopyright \StringFileInfo\xx\LegalCopyright \StringFileInfo\xx\ProductName \StringFileInfo\xx\ProductName \StringFileInfo\xx\InternalName \StringFileInfo\xx\InternalName \StringFileInfo\xx\FileDescription \StringFileInfo\xx\FileDescription \StringFileInfo\xx\CompanyName \StringFileInfo\xx\CompanyName ErrorMsg ErrorMsg %Y-%m-%dT%H:%M:%S %Y-%m-%dT%H:%M:%S MSG_INSTALL_DO_YOU_WANT_OVERWRITE MSG_INSTALL_DO_YOU_WANT_OVERWRITE MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG MSG_INSTALL_FILE_OLDER_MSG MSG_INSTALL_FILE_OLDER_MSG OpenURL OpenURL \msiexec.exe \msiexec.exe RunMsiexec RunMsiexec SQLInstallerError SQLInstallerError SQLRemoveDriverManager SQLRemoveDriverManager odbccp32.dll odbccp32.dll SQLConfigDataSource SQLConfigDataSource SQLInstallDriverEx SQLInstallDriverEx SQLInstallDriverManager SQLInstallDriverManager SQLRemoveDriver SQLRemoveDriver \Kernel32.dll \Kernel32.dll GetKeyNames GetKeyNames DoesKeyExist DoesKeyExist DeleteKey DeleteKey CreateKey CreateKey ShortcutKey ShortcutKey keycode keycode SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders MSG_SIZE_BYTES MSG_SIZE_BYTES P?MSG_SIZE_KILOBYTES P?MSG_SIZE_KILOBYTES >MSG_SIZE_GIGABYTES >MSG_SIZE_GIGABYTES xxxxxx xxxxxx %s-%s-%s %s-%s-%s %s/%s/%s %s/%s/%s %s:%s:%s %s:%s:%s %d:%s:%s AM %d:%s:%s AM %d:%s:%s PM %d:%s:%s PM MSG_REBOOT_FAILED MSG_REBOOT_FAILED WININET.DLL WININET.DLL PPassword PPassword Password Password %s %s %s %s (%0.2f %s) %s %s %s %s (%0.2f %s) %0.1f %s/%0.1f %s %0.1f %s/%0.1f %s %I64u %s/%I64u %s %I64u %s/%I64u %s MSG_KB_PER_SEC MSG_KB_PER_SEC MSG_ESTIMATED_TIME_LEFT MSG_ESTIMATED_TIME_LEFT MSG_SAVING MSG_SAVING MSG_DOWNLOADING MSG_DOWNLOADING %s %s %s %s %s %s %s %s MSG_QUERYING_INTERNET MSG_QUERYING_INTERNET MSG_READING MSG_READING GetHTTPErrorInfo GetHTTPErrorInfo %s > %s %s > %s local e_CtrlID=%d; local e_MsgID=%d; local e_CtrlID=%d; local e_MsgID=%d; Button%d Button%d Check%d Check%d ComboBox%d ComboBox%d Edit%d Edit%d Space available on selected drive: %SpaceAvailable% Space available on selected drive: %SpaceAvailable% Space required: %SpaceRequired% Space required: %SpaceRequired% Error: The specified file: '%s' could not be found. Error: The specified file: '%s' could not be found. Error: The specified file: '%s' could not be opened. Error: The specified file: '%s' could not be opened. Error: The specified file: '%s' is too large to read. Error: The specified file: '%s' is too large to read. Error: The specified file: '%s' could not be read. Error: The specified file: '%s' could not be read. number e_CtrlID, number e_MsgID, table e_Details number e_CtrlID, number e_MsgID, table e_Details Application.Exit(); Application.Exit(); Screen.Next(); Screen.Next(); Screen.Back(); Screen.Back(); Radio%d Radio%d Total space required: %SpaceRequired% Total space required: %SpaceRequired% IDS_CTRL_CHECK_BOX_d IDS_CTRL_CHECK_BOX_d IDS_CTRL_BUTTON_d IDS_CTRL_BUTTON_d IDS_CTRL_STATICTEXT_LABEL_d IDS_CTRL_STATICTEXT_LABEL_d IDS_CTRL_COMBOBOX_d_DEFAULT IDS_CTRL_COMBOBOX_d_DEFAULT IDS_CTRL_EDIT_d IDS_CTRL_EDIT_d IDS_CTRL_RADIO_BUTTON_d IDS_CTRL_RADIO_BUTTON_d IDS_CTRL_LISTBOX_d IDS_CTRL_LISTBOX_d IDS_CTRL_SCROLLTEXT_BODY_d IDS_CTRL_SCROLLTEXT_BODY_d IDS_CTRL_PROGRESS_BAR_d IDS_CTRL_PROGRESS_BAR_d IDS_CTRL_GROUP_BOX_d IDS_CTRL_GROUP_BOX_d IDS_CTRL_SELECT_PACKAGE_TREE_d IDS_CTRL_SELECT_PACKAGE_TREE_d CTRL_CHECK_BOX_d CTRL_CHECK_BOX_d CTRL_BUTTON_d CTRL_BUTTON_d CTRL_STATICTEXT_LABEL_d CTRL_STATICTEXT_LABEL_d CTRL_COMBOBOX_d CTRL_COMBOBOX_d CTRL_EDIT_d CTRL_EDIT_d CTRL_RADIO_BUTTON_d CTRL_RADIO_BUTTON_d CTRL_LIST_BOX_d CTRL_LIST_BOX_d CTRL_SCROLLTEXT_BODY_d CTRL_SCROLLTEXT_BODY_d CTRL_PROGRESS_BAR_d CTRL_PROGRESS_BAR_d CTRL_GROUP_BOX_d CTRL_GROUP_BOX_d CTRL_SELECT_PACKAGE_TREE_d CTRL_SELECT_PACKAGE_TREE_d IDS_CTRL_COMBOBOX_d_ITEMS IDS_CTRL_COMBOBOX_d_ITEMS IDS_CTRL_SCROLLTEXT_FILE_d IDS_CTRL_SCROLLTEXT_FILE_d WebWindow WebWindow IDS_CTRL_CATEGORY_NAME_d_%.3d IDS_CTRL_CATEGORY_NAME_d_%.3d IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d $Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $ $Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $ $URL: VVV.lua.org $ $URL: VVV.lua.org $ !"#$%&'()* ,-./012 !"#$%&'()* ,-./012 #*1892 $ #*1892 $ %,3:;4-& %,3:;4-& '.5? '.5? mgM mgM CNotSupportedException CNotSupportedException GDI32.DLL GDI32.DLL hhctrl.ocx hhctrl.ocx Afx:%p:%x:%p:%p:%p Afx:%p:%x:%p:%p:%p Afx:%p:%x Afx:%p:%x commctrl_DragListMsg commctrl_DragListMsg CCmdTarget CCmdTarget f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp MSWHEEL_ROLLMSG MSWHEEL_ROLLMSG comctl32.dll comctl32.dll comdlg32.dll comdlg32.dll Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Software\Microsoft\Windows\CurrentVersion\Policies\Network Software\Microsoft\Windows\CurrentVersion\Policies\Network Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32 Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32 ntdll.dll ntdll.dll %s.dll %s.dll mfcm80.dll mfcm80.dll CHttpConnection CHttpConnection CHttpFile CHttpFile HTTP/1.0 HTTP/1.0 user32.dll user32.dll f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp ole32.dll ole32.dll mscoree.dll mscoree.dll Visual C CRT: Not enough memory to complete call to strerror. Visual C CRT: Not enough memory to complete call to strerror. cmd.exe cmd.exe command.com command.com Please contact the application's support team for more information. Please contact the application's support team for more information. - Attempt to initialize the CRT more than once. - Attempt to initialize the CRT more than once. - CRT not initialized - CRT not initialized Broken pipe Broken pipe Inappropriate I/O control operation Inappropriate I/O control operation Operation not permitted Operation not permitted portuguese-brazilian portuguese-brazilian ?#%X.y ?#%X.y operator operator GetProcessWindowStation GetProcessWindowStation USER32.DLL USER32.DLL OLEACC.dll OLEACC.dll WININET.dll WININET.dll InternetCrackUrlA InternetCrackUrlA InternetCanonicalizeUrlA InternetCanonicalizeUrlA HttpQueryInfoA HttpQueryInfoA HttpSendRequestA HttpSendRequestA HttpOpenRequestA HttpOpenRequestA .?AVCCmdTarget@@ .?AVCCmdTarget@@ .PAVCFileException@@ .PAVCFileException@@ .PAVCException@@ .PAVCException@@ .?AVCMainWindowSettings@@ .?AVCMainWindowSettings@@ .?AVCMD5@@ .?AVCMD5@@ .?AVCPasswordData@@ .?AVCPasswordData@@ .?AVCRTSessionVarMgr@@ .?AVCRTSessionVarMgr@@ .?AVCScreenCrtrMeasure@@ .?AVCScreenCrtrMeasure@@ .?AVCWebBrowser2@@ .?AVCWebBrowser2@@ .PAVCInternetException@@ .PAVCInternetException@@ .PAVCMemoryException@@ .PAVCMemoryException@@ .PAVCResourceException@@ .PAVCResourceException@@ .?AVCScreenCtrlMsg@@ .?AVCScreenCtrlMsg@@ .?AVCScreenCtrlMsgDetail@@ .?AVCScreenCtrlMsgDetail@@ Lua 5.0.2 Lua 5.0.2 attempt to %s a %s value attempt to %s a %s value attempt to %s %s `%s' (a %s value) attempt to %s %s `%s' (a %s value) attempt to compare %s with %s attempt to compare %s with %s attempt to compare two %s values attempt to compare two %s values %s:%d: %s %s:%d: %s system error %d system error %d file (%s) file (%s) `popen' not supported `popen' not supported field `%s' missing in date table field `%s' missing in date table ^$* ?.([%- ^$* ?.([%- missing `[' after `%%f' in pattern missing `[' after `%%f' in pattern no function environment for tail call at level %d no function environment for tail call at level %d could not load package `%s' from path `%s' could not load package `%s' from path `%s' error loading package `%s' (%s) error loading package `%s' (%s) ?;?.lua ?;?.lua bad argument #%d to `%s' (%s) bad argument #%d to `%s' (%s) calling `%s' on bad self (%s) calling `%s' on bad self (%s) %s expected, got %s %s expected, got %s %s:%d: %s:%d: stack overflow (%s) stack overflow (%s) cannot read %s: %s cannot read %s: %s `__pow' (`^' operator) is not a function `__pow' (`^' operator) is not a function invalid key for `next' invalid key for `next' too many %s (limit=%d) too many %s (limit=%d) %s:%d: %s near `%s' %s:%d: %s near `%s' char(%d) char(%d) `%s' expected (to close `%s' at line %d) `%s' expected (to close `%s' at line %d) `%s' expected `%s' expected bad code in %s bad code in %s unexpected end of file in %s unexpected end of file in %s bad integer in %s bad integer in %s bad nupvalues in %s: read %d; expected %d bad nupvalues in %s: read %d; expected %d bad constant type (%d) in %s bad constant type (%d) in %s unknown number format in %s unknown number format in %s %s too old: read version %d.%d; expected at least %d.%d %s too old: read version %d.%d; expected at least %d.%d %s too new: read version %d.%d; expected at most %d.%d %s too new: read version %d.%d; expected at most %d.%d bad signature in %s bad signature in %s virtual machine mismatch in %s: size of %s is %d but read %d virtual machine mismatch in %s: size of %s is %d but read %d .PAVCSimpleException@@ .PAVCSimpleException@@ .PAVCObject@@ .PAVCObject@@ .PAVCNotSupportedException@@ .PAVCNotSupportedException@@ .PAVCInvalidArgException@@ .PAVCInvalidArgException@@ .?AVCNotSupportedException@@ .?AVCNotSupportedException@@ .PAVCOleException@@ .PAVCOleException@@ .PAVCUserException@@ .PAVCUserException@@ .?AVCTestCmdUI@@ .?AVCTestCmdUI@@ .?AVCCmdUI@@ .?AVCCmdUI@@ .PAVCArchiveException@@ .PAVCArchiveException@@ .?AVCHttpConnection@@ .?AVCHttpConnection@@ .?AVCHttpFile@@ .?AVCHttpFile@@ .?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@ .?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@ .?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@ .?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@ .PAVCOleDispatchException@@ .PAVCOleDispatchException@@ zcÁ zcÁ C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe GetConsoleOutputCP GetConsoleOutputCP GetCPInfo GetCPInfo GetProcessHeap GetProcessHeap GetWindowsDirectoryA GetWindowsDirectoryA RegEnumKeyA RegEnumKeyA RegOpenKeyA RegOpenKeyA RegCloseKey RegCloseKey RegEnumKeyExA RegEnumKeyExA RegQueryInfoKeyA RegQueryInfoKeyA RegDeleteKeyA RegDeleteKeyA RegCreateKeyExA RegCreateKeyExA RegOpenKeyExA RegOpenKeyExA ScaleViewportExtEx ScaleViewportExtEx SetViewportExtEx SetViewportExtEx OffsetViewportOrgEx OffsetViewportOrgEx SetViewportOrgEx SetViewportOrgEx GetViewportExtEx GetViewportExtEx ShellExecuteA ShellExecuteA ShellExecuteExA ShellExecuteExA UrlUnescapeA UrlUnescapeA URLDownloadToFileA URLDownloadToFileA SetWindowsHookExA SetWindowsHookExA UnhookWindowsHookEx UnhookWindowsHookEx CreateDialogIndirectParamA CreateDialogIndirectParamA GetKeyState GetKeyState ExitWindowsEx ExitWindowsEx EnumWindows EnumWindows MsgWaitForMultipleObjects MsgWaitForMultipleObjects GetAsyncKeyState GetAsyncKeyState .text .text `.rdata `.rdata @.data @.data .rsrc .rsrc %xERRj3cqZQ %xERRj3cqZQ ! !!####0 ! !!####0 ;;;9551%%0 ;;;9551%%0 ! !!565665@ ! !!565665@ version="8.1.1000.0" version="8.1.1000.0" name="setup.exe"/> name="setup.exe"/> name="Microsoft.Windows.Common-Controls" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" ADVAPI32.dll ADVAPI32.dll COMCTL32.dll COMCTL32.dll GDI32.dll GDI32.dll NETAPI32.dll NETAPI32.dll OLEAUT32.dll OLEAUT32.dll oledlg.dll oledlg.dll SHELL32.dll SHELL32.dll SHLWAPI.dll SHLWAPI.dll urlmon.dll urlmon.dll USER32.dll USER32.dll VERSION.dll VERSION.dll WINMM.dll WINMM.dll WINSPOOL.DRV WINSPOOL.DRV accKeyboardShortcut accKeyboardShortcut Argument %d must be of type %s. Argument %d must be of type %s. %d arguments required. %d arguments required. All Files (*.*) All Files (*.*) No error message is available.'An unsupported operation was attempted.$A required resource was unavailable. No error message is available.'An unsupported operation was attempted.$A required resource was unavailable. Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1. Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1. #Unable to load mail system support. #Unable to load mail system support. Access to %1 was denied..An invalid file handle was associated with %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1. Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1. Disk full while accessing %1..An attempt was made to access %1 past its end. Disk full while accessing %1..An attempt was made to access %1 past its end. No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1. No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1. 8.1.1000.0 8.1.1000.0 2008 Indigo Rose Corporation (VVV.indigorose.com) 2008 Indigo Rose Corporation (VVV.indigorose.com) suf80_rt.exe suf80_rt.exe irsetup.exe_2296_rwx_00401000_00172000:
FtPhu FtPhu SSSSh SSSSh FtPh FtPh SSh`UQ SSh`UQ SSh4UQ SSh4UQ SShlTQ SShlTQ SShDTQ SShDTQ u1SSh u1SSh Su%Sh Su%Sh SShx`Q SShx`Q txSSh
txSSh
SSh _Q SSh _Q @ SSh @ SSh .hPsQ .hPsQ SSShDxQ SSShDxQ 9^$u&SSSSh? 9^$u&SSSSh? u SSSSh? u SSSSh? 9^$u)SSSSh? 9^$u)SSSSh? u.VWS u.VWS WSSh|DQ WSSh|DQ udPQ udPQ t.Ht Ht(Ht t.Ht Ht(Ht y2SSh y2SSh FHSSh FHSSh GHSSh GHSSh GTSSh GTSSh G\SSh G\SSh FlSSh FlSSh Nt.Nt Nt.Nt SShlSR SShlSR tjSShHSR tjSShHSR t;SSh$SR t;SSh$SR F
F
t'SShl t'SShl u$SShe u$SShe aSSSh aSSSh .VVVVVSRSSj .VVVVVSRSSj FTPjK FTPjK FtPj; FtPj; C.PjRV C.PjRV diu2.iuz diu2.iuz MSG_ERROR MSG_ERROR %s %d. %s %s %d. %s MSG_ASK_FOR_DISK MSG_ASK_FOR_DISK MSG_NEW_LOCATION MSG_NEW_LOCATION MSG_CONFIRM_ABORT MSG_CONFIRM_ABORT MSG_CONFIRM MSG_CONFIRM A%s.%d A%s.%d %s, Line %d: %s %s, Line %d: %s File condition evaluation for file "%s" File condition evaluation for file "%s" C:\temp\SUF_SFX_TEST\ C:\temp\SUF_SFX_TEST\ msi.dll msi.dll \msi.dll \msi.dll Software\Microsoft\Windows\CurrentVersion\Installer Software\Microsoft\Windows\CurrentVersion\Installer MSG_INITIALIZING MSG_INITIALIZING 16670749 16670749 [%d]: %s [%d]: %s *** LOCATION: %s *** LOCATION: %s __NOREPORT__ __NOREPORT__ Script: %s, %s (%s) Script: %s, %s (%s) __ir_eval_value = %s; __ir_eval_value = %s; %s (%s:%d) %s (%s:%d) F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl F:\Program Files\Microsoft Visual Studio 8\VC\atlmfc\include\afxwin2.inl %Copyright%. All rights reserved. %CompanyURL% %Copyright%. All rights reserved. %CompanyURL% WindowStyle WindowStyle MainWindowSettings MainWindowSettings %s at offset %d unterminated %s at offset %d unterminated Incorrect %s at offset %d Incorrect %s at offset %d Element '%s' at offset %d not ended Element '%s' at offset %d not ended End tag '%s' at offset %d does not match start tag '%s' at offset %d End tag '%s' at offset %d does not match start tag '%s' at offset %d No start tag for end tag '%s' at offset %d No start tag for end tag '%s' at offset %d %s%d bytes %s%d bytes %s%d wide chars to %d bytes %s%d wide chars to %d bytes %d bytes to %s%d wide chars %d bytes to %s%d wide chars MSG_SEARCH_FILE MSG_SEARCH_FILE (*.*)|*.*|| (*.*)|*.*|| MSG_SEARCH_ALL MSG_SEARCH_ALL MSG_SEARCH_MASK MSG_SEARCH_MASK MSG_INSERTDISK MSG_INSERTDISK MSG_CANCEL MSG_CANCEL MSG_OK MSG_OK MSG_BROWSE MSG_BROWSE MSG_PATH MSG_PATH Windows Server 2008 Windows Server 2008 Windows Vista Windows Vista Windows Server 2003 Windows Server 2003 Windows XP Windows XP Windows 2000 Windows 2000 Windows NT4 Windows NT4 Windows NT3 Windows NT3 Windows ME Windows ME Windows 98 Windows 98 Windows 95 Windows 95 CPasswordData CPasswordData -- Defined in _SUF70_Global_Functions.lua -- Defined in _SUF70_Global_Functions.lua number e_ErrorCode, string e_ErrorMsgID number e_ErrorCode, string e_ErrorMsgID %WindowsFolder%\%ProductName% Setup Log.txt %WindowsFolder%\%ProductName% Setup Log.txt %StartupFolder% %StartupFolder% %StartFolder% %StartFolder% %StartProgramsFolder% %StartProgramsFolder% ÞsktopFolder% ÞsktopFolder% %s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %CommonFilesFolder%\Microsoft Shared\DAO %CommonFilesFolder%\Microsoft Shared\DAO Software\Microsoft\Shared Tools\DAO350.dll Software\Microsoft\Shared Tools\DAO350.dll Software\Microsoft\Shared Tools\DAO360.dll Software\Microsoft\Shared Tools\DAO360.dll ÚOPath% ÚOPath% Software\Microsoft\Windows NT\CurrentVersion Software\Microsoft\Windows NT\CurrentVersion Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion %SourceFolder% %SourceFolder% %SystemDrive% %SystemDrive% _WindowsFolder _WindowsFolder %WindowsFolder% %WindowsFolder% %SystemFolder% %SystemFolder% %CommonFilesFolder% %CommonFilesFolder% %CommonFilesFolder64% %CommonFilesFolder64% %CommonProgramW6432% %CommonProgramW6432% %CommonDocumentsFolder% %CommonDocumentsFolder% %StartupFolderCommon% %StartupFolderCommon% %StartProgramsFolderCommon% %StartProgramsFolderCommon% %StartFolderCommon% %StartFolderCommon% %FontsFolder% %FontsFolder% ÞsktopFolderCommon% ÞsktopFolderCommon% UninstallSupportFiles UninstallSupportFiles CPRegKey CPRegKey Run extra uninstall script: %d Run extra uninstall script: %d %SourceDrive% %SourceDrive% %SourceFilename% %SourceFilename% \irsetup.dat \irsetup.dat Support file added to uninstall list: Support file added to uninstall list: Registry key added to uninstall list: Registry key added to uninstall list: Remove uninstall support file: Remove uninstall support file: Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\ Remove uninstall CP entry from Registry: HKEY_LOCAL_MACHINE\ Register font: %s, %s Register font: %s, %s %sbk%d %sbk%d MSG_NO MSG_NO MSG_YES_TOALL MSG_YES_TOALL MSG_YES MSG_YES MSG_UNINSTALL_OK_REMOVE MSG_UNINSTALL_OK_REMOVE MSG_UNINSTALL_NO_APP_USE MSG_UNINSTALL_NO_APP_USE MSG_UNINSTALL_REMOVE_SHARED MSG_UNINSTALL_REMOVE_SHARED Decrement shared file count: %s (New count = %d) Decrement shared file count: %s (New count = %d) SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs : %s (#%d) : %s (#%d) Global include script: %s Global include script: %s RegisterTypeLib: %s RegisterTypeLib: %s RegisterTypeLib: %s - %s RegisterTypeLib: %s - %s Register COM file: %s Register COM file: %s Register COM file: %s - System Error # %u Register COM file: %s - System Error # %u Register COM file on reboot: %s Register COM file on reboot: %s regsvr32.exe /s %s regsvr32.exe /s %s SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce Increment usage count: %s Increment usage count: %s Increment usage count: %s (New count = %d) Increment usage count: %s (New count = %d) %s\%s %s\%s %s (%d) %s (%d) local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d; local e_Stage = %d;local e_CurrentItemText=[[%s]];local e_CurrentItemPct=%d;local e_StagePct=%d; MSG_SYSREQ_WARN MSG_SYSREQ_WARN MSG_NOTICE MSG_NOTICE MSG_SYSREQ_ABORT MSG_SYSREQ_ABORT %s: %s %s: %s MSG_SYSREQ_USERPERMISSION MSG_SYSREQ_USERPERMISSION MSG_SYSREQ_SYSTEMADMIN MSG_SYSREQ_SYSTEMADMIN MSG_SYSREQ_COLORDEPTH MSG_SYSREQ_COLORDEPTH MSG_BITSPERPIXEL MSG_BITSPERPIXEL MSG_SYSREQ_SCREENHEIGHT MSG_SYSREQ_SCREENHEIGHT MSG_SYSREQ_SCREENWIDTH MSG_SYSREQ_SCREENWIDTH %s: %d %s: %d %s: %d %s %s: %d %s MSG_SYSREQ_RAM MSG_SYSREQ_RAM MSG_SIZE_MEGABYTES MSG_SIZE_MEGABYTES Operating System Operating System MSG_SYSREQ_OS MSG_SYSREQ_OS MSG_OS_PART_ORNEWER MSG_OS_PART_ORNEWER MSG_OS_PART_NOSERVPACK MSG_OS_PART_NOSERVPACK MSG_OS_PART_SERVPACK MSG_OS_PART_SERVPACK MSG_OS_PART_SE MSG_OS_PART_SE MSG_OS_PART_C MSG_OS_PART_C MSG_OS_PART_B MSG_OS_PART_B MSG_OS_PART_A MSG_OS_PART_A MSG_OS_ALL MSG_OS_ALL MSG_OS_NONE MSG_OS_NONE MSG_OS_WSRV2008 MSG_OS_WSRV2008 MSG_OS_WVISTA MSG_OS_WVISTA MSG_OS_WSRV2003 MSG_OS_WSRV2003 MSG_OS_WXP MSG_OS_WXP MSG_OS_W2000 MSG_OS_W2000 MSG_OS_WNT4 MSG_OS_WNT4 MSG_OS_WNT3 MSG_OS_WNT3 MSG_OS_WME MSG_OS_WME MSG_OS_W98 MSG_OS_W98 MSG_OS_W95 MSG_OS_W95 MSG_OS_UNKNOWN MSG_OS_UNKNOWN MSG_SYSREQ_NOTMET MSG_SYSREQ_NOTMET MSG_EXP_USESLEFT MSG_EXP_USESLEFT MSG_EXP_USESLEFT2 MSG_EXP_USESLEFT2 %s %d %s %s %d %s MSG_EXP_DAYSLEFT MSG_EXP_DAYSLEFT MSG_EXP_DAYSLEFT2 MSG_EXP_DAYSLEFT2 Software\Microsoft\Windows\CurrentVersion\I652R9823\ Software\Microsoft\Windows\CurrentVersion\I652R9823\ MSG_EXP_CONTACT_START MSG_EXP_CONTACT_START MSG_SEEKING MSG_SEEKING Dependency Detection Passed Dependency Detection Passed Arc: %s Arc: %s FN: %s FN: %s %s (#%d) %s (#%d) MSG_SKIPPING MSG_SKIPPING MSG_INSTALLING MSG_INSTALLING Run project event: %s Run project event: %s local e_ErrorCode=%d; local e_ErrorMsgID = "%s" local e_ErrorCode=%d; local e_ErrorMsgID = "%s" Start project event: %s Start project event: %s MSG_UNINSTALLFILE_NOREMOVE MSG_UNINSTALLFILE_NOREMOVE MSG_UNINSTALLFILE_INUSE MSG_UNINSTALLFILE_INUSE %s (%s: %u) %s (%s: %u) \WININIT.INI \WININIT.INI MSG_FILE_EXISTS_INUSE MSG_FILE_EXISTS_INUSE MSG_FILE_EXISTS_RETRY MSG_FILE_EXISTS_RETRY MSG_FILE_EXISTS_ANY MSG_FILE_EXISTS_ANY MSG_FILE_EXISTS_NEWER MSG_FILE_EXISTS_NEWER MSG_FILE_OVERWRITE_CONFIRM MSG_FILE_OVERWRITE_CONFIRM %s\%s.lnk %s\%s.lnk %s (Return code: %d) %s (Return code: %d) Product: %s, version %s Product: %s, version %s %s (%d): %s (%d): MSG_PROG_UNINSTALL_CREATECONTROLFILE MSG_PROG_UNINSTALL_CREATECONTROLFILE ERR_CREATEUNINSTALL_OPEN_EXE_READ ERR_CREATEUNINSTALL_OPEN_EXE_READ ERR_CREATEUNINSTALL_OPEN_EXE_WRITE ERR_CREATEUNINSTALL_OPEN_EXE_WRITE Overwrite uninstall executable: Overwrite uninstall executable: MSG_PROG_UNINSTALL_CREATEEXE MSG_PROG_UNINSTALL_CREATEEXE @MSG_PROG_UNINSTALL_CREATEDATFILE @MSG_PROG_UNINSTALL_CREATEDATFILE ?MSG_PROG_UNINSTALL_CREATEFOLDER ?MSG_PROG_UNINSTALL_CREATEFOLDER "/U:%s" "/U:%s" MSG_PROG_UNINSTALL_CREATESC MSG_PROG_UNINSTALL_CREATESC Create uninstall CP entry key Create uninstall CP entry key ERR_CREATEUNINSTALL_CREATEREGKEY ERR_CREATEUNINSTALL_CREATEREGKEY "%s",%d "%s",%d Uninstall CP entry: URLUpdateInfo = Uninstall CP entry: URLUpdateInfo = URLUpdateInfo URLUpdateInfo Uninstall CP entry: URLInfoAbout = Uninstall CP entry: URLInfoAbout = URLInfoAbout URLInfoAbout "%s" "/U:%s" "%s" "/U:%s" HKEY_LOCAL_MACHINE\ HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ MSG_PROG_UNINSTALL_CREATECPENTRY MSG_PROG_UNINSTALL_CREATECPENTRY MSG_PROG_UNINSTALL_COPYSUPPORTFILES MSG_PROG_UNINSTALL_COPYSUPPORTFILES MSG_PROG_UNINSTALL_COPYPLUGINS MSG_PROG_UNINSTALL_COPYPLUGINS %s %s %s %s MSG_REQUIRED_DRIVE MSG_REQUIRED_DRIVE MSG_AVAILABLE_DRIVE MSG_AVAILABLE_DRIVE MSG_PROG_CHECKING_DRIVESPACE MSG_PROG_CHECKING_DRIVESPACE MSG_PROG_CHECKING_FILES MSG_PROG_CHECKING_FILES %A, %B %d, %Y %A, %B %d, %Y [%s] %s [%s] %s %m/%d/%Y %H:%M:%S %m/%d/%Y %H:%M:%S MsgFile MsgFile ERR_MSI_PATCH_REMOVAL_UNSUPPORTED ERR_MSI_PATCH_REMOVAL_UNSUPPORTED ERR_MSI_PATCH_PACKAGE_UNSUPPORTED ERR_MSI_PATCH_PACKAGE_UNSUPPORTED ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED ERR_MSI_INSTALL_PLATFORM_UNSUPPORTED ERR_MSI_UNSUPPORTED_TYPE ERR_MSI_UNSUPPORTED_TYPE ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED ERR_MSI_INSTALL_LANGUAGE_UNSUPPORTED ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD ERR_SERVER_FILE_DOWNLOAD_SET_PROXY_PASSWORD ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_FTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE ERR_SERVER_FILE_DOWNLOAD_OPEN_HTTP_FILE ERR_ODBC_INVALID_KEYWORD_VALUE ERR_ODBC_INVALID_KEYWORD_VALUE ERR_WEB_503 ERR_WEB_503 ERR_WEB_500 ERR_WEB_500 ERR_WEB_404 ERR_WEB_404 ERR_WEB_403 ERR_WEB_403 ERR_WEB_400 ERR_WEB_400 ERR_WEB_SET_PROXY_PASSWORD ERR_WEB_SET_PROXY_PASSWORD ERR_WEB_SET_PROXY_USERNAME ERR_WEB_SET_PROXY_USERNAME ERR_WEB_WRITE_MEMORY ERR_WEB_WRITE_MEMORY ERR_WEB_FTP_FILE_OPEN ERR_WEB_FTP_FILE_OPEN ERR_WEB_USER_ABORT ERR_WEB_USER_ABORT ERR_WEB_FILE_WRITE ERR_WEB_FILE_WRITE ERR_WEB_DOWNLOAD_FILE_ERROR ERR_WEB_DOWNLOAD_FILE_ERROR ERR_WEB_INVALID_HTTP_RESPONSE ERR_WEB_INVALID_HTTP_RESPONSE ERR_WEB_DESTINATION_FILE_OPEN ERR_WEB_DESTINATION_FILE_OPEN ERR_WEB_SEND_REQUEST ERR_WEB_SEND_REQUEST ERR_WEB_OPEN_REQUEST ERR_WEB_OPEN_REQUEST ERR_WEB_CREATE_HTTP_CONNECTION ERR_WEB_CREATE_HTTP_CONNECTION ERR_WEB_CREATE_INTERNET_SESSION ERR_WEB_CREATE_INTERNET_SESSION ERR_REG_GET_SUB_KEY_NAME ERR_REG_GET_SUB_KEY_NAME ERR_REG_NON_EXISTANT_SUB_KEY ERR_REG_NON_EXISTANT_SUB_KEY ERR_REG_DELETE_KEY ERR_REG_DELETE_KEY ERR_REG_CREATE_KEY ERR_REG_CREATE_KEY ERR_FILE_EXECUTION_FAILED_ELEVATION ERR_FILE_EXECUTION_FAILED_ELEVATION ERR_KEY_RUN_ON_REBOOT_FAILED ERR_KEY_RUN_ON_REBOOT_FAILED ERR_USER_ABORTED_OPERATION ERR_USER_ABORTED_OPERATION ERR_NON_EXISTANT_VIEWER_EXE ERR_NON_EXISTANT_VIEWER_EXE ERR_FILE_EXECUTION_FAILED ERR_FILE_EXECUTION_FAILED ERR_SPECIFIED_EXE_FILE_INVALID ERR_SPECIFIED_EXE_FILE_INVALID MSG_SUCCESS MSG_SUCCESS Language set: Primary = %d, Secondary = %d Language set: Primary = %d, Secondary = %d %CompanyURL% %CompanyURL% %CompanyName% %CompanyName% UxTheme.dll UxTheme.dll %Copyright% %CompanyName%. All rights reserved. %CompanyURL% %Copyright% %CompanyName%. All rights reserved. %CompanyURL% %WindowsFolder%\%ProductName% Uninstall Log.txt %WindowsFolder%\%ProductName% Uninstall Log.txt %CompanyName% Support Department %CompanyName% Support Department %WindowsFolder%\%ProductName%\uninstall.exe %WindowsFolder%\%ProductName%\uninstall.exe uninstall.xml uninstall.xml CWebBrowser2 CWebBrowser2 Confirm Operation Confirm Operation kernel32.dll kernel32.dll KERNEL32.DLL KERNEL32.DLL PSAPI.DLL PSAPI.DLL Kernel32.dll Kernel32.dll WS2_32.DLL WS2_32.DLL Copying "%s" Copying "%s" "%s" %s "%s" %s %d.%d.%d.%d %d.%d.%d.%d \StringFileInfo\xx\ProductVersion \StringFileInfo\xx\ProductVersion \StringFileInfo\xx\PrivateBuild \StringFileInfo\xx\PrivateBuild .bak%d .bak%d Windows NT 4 Windows NT 4 Windows NT 3 Windows NT 3 %s\shell\open\command %s\shell\open\command NUL=%s NUL=%s Software\Microsoft\Windows NT\CurrentVersion\Fonts Software\Microsoft\Windows NT\CurrentVersion\Fonts Software\Microsoft\Windows\CurrentVersion\Fonts Software\Microsoft\Windows\CurrentVersion\Fonts ***!!!***@@ ***!!!***@@ Advapi32.dll Advapi32.dll Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders %s\%s.url %s\%s.url %s\%s.pif %s\%s.pif srclient.dll srclient.dll %s_%d %s_%d %s\_ir_tmpfnt_%d %s\_ir_tmpfnt_%d /\:*?"| /\:*?"| jsproxy.dll jsproxy.dll DetectAutoProxyUrl DetectAutoProxyUrl wininet.dll wininet.dll %%x %%x d:d d:d WinINet.dll WinINet.dll Could not create Internet session: %u Could not create Internet session: %u Error downloading file: %u Error downloading file: %u Error writing the destination file: %d-%u Error writing the destination file: %d-%u Could not create HTTP connection: %u Could not create HTTP connection: %u Could not create HTTP connection Could not create HTTP connection Incorrect HTTP status returned by server: %d Incorrect HTTP status returned by server: %d Send request failed: %u Send request failed: %u Content-Type: application/x-www-form-urlencoded Content-Type: application/x-www-form-urlencoded Could not open HTTP file: %s Could not open HTTP file: %s PTF:// PTF:// hXXps:// hXXps:// hXXp:// hXXp:// Could not open request: %u Could not open request: %u Could not HTTP file: %u Could not HTTP file: %u MSG_STATUS_HANDLE_CREATED MSG_STATUS_HANDLE_CREATED MSG_STATUS_HANDLE_CLOSING MSG_STATUS_HANDLE_CLOSING MSG_STATUS_REQUEST_COMPLETE MSG_STATUS_REQUEST_COMPLETE MSG_REDIRECTING MSG_REDIRECTING MSG_CONNECTION_CLOSED MSG_CONNECTION_CLOSED MSG_RESOLVING_HOST_NAME MSG_RESOLVING_HOST_NAME MSG_HOST_NAME_RESOLVED MSG_HOST_NAME_RESOLVED MSG_CONNECTING_TO_SERVER MSG_CONNECTING_TO_SERVER MSG_CONNECTED_TO_SERVER MSG_CONNECTED_TO_SERVER MSG_CLOSING_CONNECTION MSG_CLOSING_CONNECTION TRACE: LastError = %d ("%s") TRACE: LastError = %d ("%s") Script: %s, %s Script: %s, %s Script: %s, Line %d Script: %s, Line %d All Files (*.*)|*.*| All Files (*.*)|*.*| PasswordInput PasswordInput MSG_MOVING MSG_MOVING MSG_COPYING MSG_COPYING MSG_FROM MSG_FROM MSG_TO MSG_TO MSG_DELETING MSG_DELETING MSG_SEARCHING MSG_SEARCHING \StringFileInfo\xx\SpecialBuild \StringFileInfo\xx\SpecialBuild \StringFileInfo\xx\OriginalFilename \StringFileInfo\xx\OriginalFilename \StringFileInfo\xx\Comments \StringFileInfo\xx\Comments \StringFileInfo\xx\LegalTrademarks \StringFileInfo\xx\LegalTrademarks \StringFileInfo\xx\LegalCopyright \StringFileInfo\xx\LegalCopyright \StringFileInfo\xx\ProductName \StringFileInfo\xx\ProductName \StringFileInfo\xx\InternalName \StringFileInfo\xx\InternalName \StringFileInfo\xx\FileDescription \StringFileInfo\xx\FileDescription \StringFileInfo\xx\CompanyName \StringFileInfo\xx\CompanyName ErrorMsg ErrorMsg %Y-%m-%dT%H:%M:%S %Y-%m-%dT%H:%M:%S MSG_INSTALL_DO_YOU_WANT_OVERWRITE MSG_INSTALL_DO_YOU_WANT_OVERWRITE MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG MSG_INSTALL_ALWAYS_ASK_OVERWRITE_MSG MSG_INSTALL_FILE_OLDER_MSG MSG_INSTALL_FILE_OLDER_MSG OpenURL OpenURL \msiexec.exe \msiexec.exe RunMsiexec RunMsiexec SQLInstallerError SQLInstallerError SQLRemoveDriverManager SQLRemoveDriverManager odbccp32.dll odbccp32.dll SQLConfigDataSource SQLConfigDataSource SQLInstallDriverEx SQLInstallDriverEx SQLInstallDriverManager SQLInstallDriverManager SQLRemoveDriver SQLRemoveDriver \Kernel32.dll \Kernel32.dll GetKeyNames GetKeyNames DoesKeyExist DoesKeyExist DeleteKey DeleteKey CreateKey CreateKey ShortcutKey ShortcutKey keycode keycode SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders MSG_SIZE_BYTES MSG_SIZE_BYTES P?MSG_SIZE_KILOBYTES P?MSG_SIZE_KILOBYTES >MSG_SIZE_GIGABYTES >MSG_SIZE_GIGABYTES xxxxxx xxxxxx %s-%s-%s %s-%s-%s %s/%s/%s %s/%s/%s %s:%s:%s %s:%s:%s %d:%s:%s AM %d:%s:%s AM %d:%s:%s PM %d:%s:%s PM MSG_REBOOT_FAILED MSG_REBOOT_FAILED WININET.DLL WININET.DLL PPassword PPassword Password Password %s %s %s %s (%0.2f %s) %s %s %s %s (%0.2f %s) %0.1f %s/%0.1f %s %0.1f %s/%0.1f %s %I64u %s/%I64u %s %I64u %s/%I64u %s MSG_KB_PER_SEC MSG_KB_PER_SEC MSG_ESTIMATED_TIME_LEFT MSG_ESTIMATED_TIME_LEFT MSG_SAVING MSG_SAVING MSG_DOWNLOADING MSG_DOWNLOADING %s %s %s %s %s %s %s %s MSG_QUERYING_INTERNET MSG_QUERYING_INTERNET MSG_READING MSG_READING GetHTTPErrorInfo GetHTTPErrorInfo %s > %s %s > %s local e_CtrlID=%d; local e_MsgID=%d; local e_CtrlID=%d; local e_MsgID=%d; Button%d Button%d Check%d Check%d ComboBox%d ComboBox%d Edit%d Edit%d Space available on selected drive: %SpaceAvailable% Space available on selected drive: %SpaceAvailable% Space required: %SpaceRequired% Space required: %SpaceRequired% Error: The specified file: '%s' could not be found. Error: The specified file: '%s' could not be found. Error: The specified file: '%s' could not be opened. Error: The specified file: '%s' could not be opened. Error: The specified file: '%s' is too large to read. Error: The specified file: '%s' is too large to read. Error: The specified file: '%s' could not be read. Error: The specified file: '%s' could not be read. number e_CtrlID, number e_MsgID, table e_Details number e_CtrlID, number e_MsgID, table e_Details Application.Exit(); Application.Exit(); Screen.Next(); Screen.Next(); Screen.Back(); Screen.Back(); Radio%d Radio%d Total space required: %SpaceRequired% Total space required: %SpaceRequired% IDS_CTRL_CHECK_BOX_d IDS_CTRL_CHECK_BOX_d IDS_CTRL_BUTTON_d IDS_CTRL_BUTTON_d IDS_CTRL_STATICTEXT_LABEL_d IDS_CTRL_STATICTEXT_LABEL_d IDS_CTRL_COMBOBOX_d_DEFAULT IDS_CTRL_COMBOBOX_d_DEFAULT IDS_CTRL_EDIT_d IDS_CTRL_EDIT_d IDS_CTRL_RADIO_BUTTON_d IDS_CTRL_RADIO_BUTTON_d IDS_CTRL_LISTBOX_d IDS_CTRL_LISTBOX_d IDS_CTRL_SCROLLTEXT_BODY_d IDS_CTRL_SCROLLTEXT_BODY_d IDS_CTRL_PROGRESS_BAR_d IDS_CTRL_PROGRESS_BAR_d IDS_CTRL_GROUP_BOX_d IDS_CTRL_GROUP_BOX_d IDS_CTRL_SELECT_PACKAGE_TREE_d IDS_CTRL_SELECT_PACKAGE_TREE_d CTRL_CHECK_BOX_d CTRL_CHECK_BOX_d CTRL_BUTTON_d CTRL_BUTTON_d CTRL_STATICTEXT_LABEL_d CTRL_STATICTEXT_LABEL_d CTRL_COMBOBOX_d CTRL_COMBOBOX_d CTRL_EDIT_d CTRL_EDIT_d CTRL_RADIO_BUTTON_d CTRL_RADIO_BUTTON_d CTRL_LIST_BOX_d CTRL_LIST_BOX_d CTRL_SCROLLTEXT_BODY_d CTRL_SCROLLTEXT_BODY_d CTRL_PROGRESS_BAR_d CTRL_PROGRESS_BAR_d CTRL_GROUP_BOX_d CTRL_GROUP_BOX_d CTRL_SELECT_PACKAGE_TREE_d CTRL_SELECT_PACKAGE_TREE_d IDS_CTRL_COMBOBOX_d_ITEMS IDS_CTRL_COMBOBOX_d_ITEMS IDS_CTRL_SCROLLTEXT_FILE_d IDS_CTRL_SCROLLTEXT_FILE_d WebWindow WebWindow IDS_CTRL_CATEGORY_NAME_d_%.3d IDS_CTRL_CATEGORY_NAME_d_%.3d IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d IDS_CTRL_CATEGORY_DESCRIPTION_d_%.3d $Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $ $Lua: Lua 5.0.2 Copyright (C) 1994-2004 Tecgraf, PUC-Rio $ $URL: VVV.lua.org $ $URL: VVV.lua.org $ !"#$%&'()* ,-./012 !"#$%&'()* ,-./012 #*1892 $ #*1892 $ %,3:;4-& %,3:;4-& '.5? '.5? mgM mgM CNotSupportedException CNotSupportedException GDI32.DLL GDI32.DLL hhctrl.ocx hhctrl.ocx Afx:%p:%x:%p:%p:%p Afx:%p:%x:%p:%p:%p Afx:%p:%x Afx:%p:%x commctrl_DragListMsg commctrl_DragListMsg CCmdTarget CCmdTarget f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp MSWHEEL_ROLLMSG MSWHEEL_ROLLMSG comctl32.dll comctl32.dll comdlg32.dll comdlg32.dll Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Software\Microsoft\Windows\CurrentVersion\Policies\Explorer Software\Microsoft\Windows\CurrentVersion\Policies\Network Software\Microsoft\Windows\CurrentVersion\Policies\Network Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32 Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32 ntdll.dll ntdll.dll %s.dll %s.dll mfcm80.dll mfcm80.dll CHttpConnection CHttpConnection CHttpFile CHttpFile HTTP/1.0 HTTP/1.0 user32.dll user32.dll f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp f:\rtm\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp ole32.dll ole32.dll mscoree.dll mscoree.dll Visual C CRT: Not enough memory to complete call to strerror. Visual C CRT: Not enough memory to complete call to strerror. cmd.exe cmd.exe command.com command.com Please contact the application's support team for more information. Please contact the application's support team for more information. - Attempt to initialize the CRT more than once. - Attempt to initialize the CRT more than once. - CRT not initialized - CRT not initialized Broken pipe Broken pipe Inappropriate I/O control operation Inappropriate I/O control operation Operation not permitted Operation not permitted portuguese-brazilian portuguese-brazilian ?#%X.y ?#%X.y operator operator GetProcessWindowStation GetProcessWindowStation USER32.DLL USER32.DLL OLEACC.dll OLEACC.dll WININET.dll WININET.dll InternetCrackUrlA InternetCrackUrlA InternetCanonicalizeUrlA InternetCanonicalizeUrlA HttpQueryInfoA HttpQueryInfoA HttpSendRequestA HttpSendRequestA HttpOpenRequestA HttpOpenRequestA .?AVCCmdTarget@@ .?AVCCmdTarget@@ .PAVCFileException@@ .PAVCFileException@@ .PAVCException@@ .PAVCException@@ .?AVCMainWindowSettings@@ .?AVCMainWindowSettings@@ .?AVCMD5@@ .?AVCMD5@@ .?AVCPasswordData@@ .?AVCPasswordData@@ .?AVCRTSessionVarMgr@@ .?AVCRTSessionVarMgr@@ .?AVCScreenCrtrMeasure@@ .?AVCScreenCrtrMeasure@@ .?AVCWebBrowser2@@ .?AVCWebBrowser2@@ .PAVCInternetException@@ .PAVCInternetException@@ .PAVCMemoryException@@ .PAVCMemoryException@@ .PAVCResourceException@@ .PAVCResourceException@@ .?AVCScreenCtrlMsg@@ .?AVCScreenCtrlMsg@@ .?AVCScreenCtrlMsgDetail@@ .?AVCScreenCtrlMsgDetail@@ Lua 5.0.2 Lua 5.0.2 attempt to %s a %s value attempt to %s a %s value attempt to %s %s `%s' (a %s value) attempt to %s %s `%s' (a %s value) attempt to compare %s with %s attempt to compare %s with %s attempt to compare two %s values attempt to compare two %s values %s:%d: %s %s:%d: %s system error %d system error %d file (%s) file (%s) `popen' not supported `popen' not supported field `%s' missing in date table field `%s' missing in date table ^$* ?.([%- ^$* ?.([%- missing `[' after `%%f' in pattern missing `[' after `%%f' in pattern no function environment for tail call at level %d no function environment for tail call at level %d could not load package `%s' from path `%s' could not load package `%s' from path `%s' error loading package `%s' (%s) error loading package `%s' (%s) ?;?.lua ?;?.lua bad argument #%d to `%s' (%s) bad argument #%d to `%s' (%s) calling `%s' on bad self (%s) calling `%s' on bad self (%s) %s expected, got %s %s expected, got %s %s:%d: %s:%d: stack overflow (%s) stack overflow (%s) cannot read %s: %s cannot read %s: %s `__pow' (`^' operator) is not a function `__pow' (`^' operator) is not a function invalid key for `next' invalid key for `next' too many %s (limit=%d) too many %s (limit=%d) %s:%d: %s near `%s' %s:%d: %s near `%s' char(%d) char(%d) `%s' expected (to close `%s' at line %d) `%s' expected (to close `%s' at line %d) `%s' expected `%s' expected bad code in %s bad code in %s unexpected end of file in %s unexpected end of file in %s bad integer in %s bad integer in %s bad nupvalues in %s: read %d; expected %d bad nupvalues in %s: read %d; expected %d bad constant type (%d) in %s bad constant type (%d) in %s unknown number format in %s unknown number format in %s %s too old: read version %d.%d; expected at least %d.%d %s too old: read version %d.%d; expected at least %d.%d %s too new: read version %d.%d; expected at most %d.%d %s too new: read version %d.%d; expected at most %d.%d bad signature in %s bad signature in %s virtual machine mismatch in %s: size of %s is %d but read %d virtual machine mismatch in %s: size of %s is %d but read %d .PAVCSimpleException@@ .PAVCSimpleException@@ .PAVCObject@@ .PAVCObject@@ .PAVCNotSupportedException@@ .PAVCNotSupportedException@@ .PAVCInvalidArgException@@ .PAVCInvalidArgException@@ .?AVCNotSupportedException@@ .?AVCNotSupportedException@@ .PAVCOleException@@ .PAVCOleException@@ .PAVCUserException@@ .PAVCUserException@@ .?AVCTestCmdUI@@ .?AVCTestCmdUI@@ .?AVCCmdUI@@ .?AVCCmdUI@@ .PAVCArchiveException@@ .PAVCArchiveException@@ .?AVCHttpConnection@@ .?AVCHttpConnection@@ .?AVCHttpFile@@ .?AVCHttpFile@@ .?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@ .?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@ .?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@ .?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@ .PAVCOleDispatchException@@ .PAVCOleDispatchException@@ zcÁ zcÁ C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe GetConsoleOutputCP GetConsoleOutputCP GetCPInfo GetCPInfo GetProcessHeap GetProcessHeap GetWindowsDirectoryA GetWindowsDirectoryA RegEnumKeyA RegEnumKeyA RegOpenKeyA RegOpenKeyA RegCloseKey RegCloseKey RegEnumKeyExA RegEnumKeyExA RegQueryInfoKeyA RegQueryInfoKeyA RegDeleteKeyA RegDeleteKeyA RegCreateKeyExA RegCreateKeyExA RegOpenKeyExA RegOpenKeyExA ScaleViewportExtEx ScaleViewportExtEx SetViewportExtEx SetViewportExtEx OffsetViewportOrgEx OffsetViewportOrgEx SetViewportOrgEx SetViewportOrgEx GetViewportExtEx GetViewportExtEx ShellExecuteA ShellExecuteA ShellExecuteExA ShellExecuteExA UrlUnescapeA UrlUnescapeA URLDownloadToFileA URLDownloadToFileA SetWindowsHookExA SetWindowsHookExA UnhookWindowsHookEx UnhookWindowsHookEx CreateDialogIndirectParamA CreateDialogIndirectParamA GetKeyState GetKeyState ExitWindowsEx ExitWindowsEx EnumWindows EnumWindows MsgWaitForMultipleObjects MsgWaitForMultipleObjects GetAsyncKeyState GetAsyncKeyState .text .text `.rdata `.rdata @.data @.data .rsrc .rsrc accKeyboardShortcut accKeyboardShortcut Argument %d must be of type %s. Argument %d must be of type %s. %d arguments required. %d arguments required. All Files (*.*) All Files (*.*) No error message is available.'An unsupported operation was attempted.$A required resource was unavailable. No error message is available.'An unsupported operation was attempted.$A required resource was unavailable. Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s. Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1. Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1. #Unable to load mail system support. #Unable to load mail system support. Access to %1 was denied..An invalid file handle was associated with %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1. Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1. Disk full while accessing %1..An attempt was made to access %1 past its end. Disk full while accessing %1..An attempt was made to access %1 past its end. No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1. No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1. DTLite4413-0173.exe_1672:
.text .text `.rdata `.rdata @.data @.data .ndata .ndata .rsrc .rsrc RegDeleteKeyExW RegDeleteKeyExW Kernel32.DLL Kernel32.DLL PSAPI.DLL PSAPI.DLL %s=%s %s=%s GetWindowsDirectoryW GetWindowsDirectoryW KERNEL32.dll KERNEL32.dll ExitWindowsEx ExitWindowsEx USER32.dll USER32.dll GDI32.dll GDI32.dll SHFileOperationW SHFileOperationW ShellExecuteW ShellExecuteW SHELL32.dll SHELL32.dll RegDeleteKeyW RegDeleteKeyW RegCloseKey RegCloseKey RegEnumKeyW RegEnumKeyW RegOpenKeyExW RegOpenKeyExW RegCreateKeyExW RegCreateKeyExW ADVAPI32.dll ADVAPI32.dll COMCTL32.dll COMCTL32.dll ole32.dll ole32.dll VERSION.dll VERSION.dll %U/nE %U/nE q4*.rIY q4*.rIY .cr1h .cr1h ;$;(;,;0;4;8;
;$;(;,;0;4;8;
4 4@4\4`4 4 4@4\4`4 2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100. 2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100. 3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D 3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D hXXps://VVV.verisign.com/rpa0 hXXps://VVV.verisign.com/rpa0 hXXp://ocsp.verisign.com0? hXXp://ocsp.verisign.com0? 3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0 3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0 .Class 3 Public Primary Certification Authority0 .Class 3 Public Primary Certification Authority0 hXXps://VVV.verisign.com/cps0* hXXps://VVV.verisign.com/cps0* #hXXp://logo.verisign.com/vslogo.gif0 #hXXp://logo.verisign.com/vslogo.gif0 hXXp://ocsp.verisign.com01 hXXp://ocsp.verisign.com01 hXXp://crl.verisign.com/pca3.crl0) hXXp://crl.verisign.com/pca3.crl0) hXXp://ocsp.verisign.com0 hXXp://ocsp.verisign.com0 "hXXp://crl.verisign.com/tss-ca.crl0 "hXXp://crl.verisign.com/tss-ca.crl0 Thawte Certification1 Thawte Certification1 0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0 0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0 verifying installer: %d%% verifying installer: %d%% unpacking data: %d%% unpacking data: %d%% ... %d%% ... %d%% hXXp://nsis.sf.net/NSIS_Error hXXp://nsis.sf.net/NSIS_Error ~nsu.tmp ~nsu.tmp %u.%u%s%s %u.%u%s%s .DEFAULT\Control Panel\International .DEFAULT\Control Panel\International Software\Microsoft\Windows\CurrentVersion Software\Microsoft\Windows\CurrentVersion *?|/": *?|/": pData\Local\Temp\nsr342B.tmp\setuphlp.dll pData\Local\Temp\nsr342B.tmp\setuphlp.dll 0173.exe /S 0173.exe /S C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp\setuphlp.dll ON Tools Lite\DTGadget.lnk ON Tools Lite\DTGadget.lnk te.lnk te.lnk C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp C:\Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp 6.exe 6.exe Monkey's Audio! Monkey's Audio! Windows Media Audio Windows Media Audio `~!@#$^&*() =[]{}\:;'",|/ `~!@#$^&*() =[]{}\:;'",|/ nsr342B.tmp nsr342B.tmp \Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S \Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S 342B.tmp\Lang\ 342B.tmp\Lang\ \Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp \Users\"%CurrentUserName%"\AppData\Local\Temp\nsr342B.tmp C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe /S %Program Files%\DAEMON Tools Lite %Program Files%\DAEMON Tools Lite C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0 DTLite4413-0173.exe DTLite4413-0173.exe ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp ers\"%CurrentUserName%"\AppData\Local\Temp\nsc33CC.tmp C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ C:\Users\"%CurrentUserName%"\AppData\Local\Temp\ C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe C:\Users\"%CurrentUserName%"\AppData\Local\Temp\_ir_sf_temp_0\DTLite4413-0173.exe Windows Gadget Windows Gadget Integrate with Windows Explorer Integrate with Windows Explorer SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features. SCSI Pass Through Direct (SPTD) layer is needed for Advanced Emulation features. Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop. Windows Gadget for quick access to main DAEMON Tools functionalities from Desktop. 4.41.3.0173.0 4.41.3.0173.0 DAEMONSetup4.41.3.0173.exe DAEMONSetup4.41.3.0173.exe dinotify.exe_3912:
.text .text `.data `.data .rsrc .rsrc @.reloc @.reloc KERNEL32.dll KERNEL32.dll msvcrt.dll msvcrt.dll pnpui.dll pnpui.dll dinotify.pdb dinotify.pdb _amsg_exit _amsg_exit version="1.0.0.0" version="1.0.0.0" name="DINotify.exe" name="DINotify.exe" name="Microsoft.Windows.Common-Controls" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" pnpui.dll,SimplifiedDINotification pnpui.dll,SimplifiedDINotification Windows Device Installation Windows Device Installation 6.1.7600.16385 (win7_rtm.090713-1255) 6.1.7600.16385 (win7_rtm.090713-1255) dinotify.exe dinotify.exe Windows Windows Operating System Operating System 6.1.7600.16385 6.1.7600.16385 sidebar.exe_1808:
.text .text `.data `.data .rsrc .rsrc @.reloc @.reloc ADVAPI32.dll ADVAPI32.dll ntdll.DLL ntdll.DLL KERNEL32.dll KERNEL32.dll GDI32.dll GDI32.dll USER32.dll USER32.dll msvcrt.dll msvcrt.dll ATL.DLL ATL.DLL ole32.dll ole32.dll OLEAUT32.dll OLEAUT32.dll COMCTL32.dll COMCTL32.dll gdiplus.dll gdiplus.dll SHLWAPI.dll SHLWAPI.dll SHELL32.dll SHELL32.dll urlmon.dll urlmon.dll CRYPT32.dll CRYPT32.dll sfc_os.dll sfc_os.dll dwmapi.dll dwmapi.dll CRYPTUI.dll CRYPTUI.dll UxTheme.dll UxTheme.dll SSShZ SSShZ SSSSSSh SSSSSSh FTPQ FTPQ #SSSh #SSSh 1.1.4 1.1.4 1.3.6.1.4.1.311.2.1.12 1.3.6.1.4.1.311.2.1.12 DwmApplyWindowScaleFactor DwmApplyWindowScaleFactor FTPh FTPh SSShw SSShw PSSh| PSSh| tWHt;Ht.Ht tWHt;Ht.Ht sidebar.exe sidebar.exe WININET.dll WININET.dll WTSAPI32.dll WTSAPI32.dll WINMM.dll WINMM.dll IPHLPAPI.DLL IPHLPAPI.DLL WINTRUST.dll WINTRUST.dll PROPSYS.dll PROPSYS.dll Wlanapi.dll Wlanapi.dll wlanutil.dll wlanutil.dll OLEACC.dll OLEACC.dll COMDLG32.dll COMDLG32.dll InternetCreateUrlW InternetCreateUrlW InternetCrackUrlW InternetCrackUrlW GetUrlCacheEntryInfoW GetUrlCacheEntryInfoW PSGetPropertyKeyFromName PSGetPropertyKeyFromName ntdll.dll ntdll.dll RegCloseKey RegCloseKey RegOpenKeyExW RegOpenKeyExW RegNotifyChangeKeyValue RegNotifyChangeKeyValue RegDeleteKeyW RegDeleteKeyW ReportEventW ReportEventW GetProcessHeap GetProcessHeap RegEnumKeyExW RegEnumKeyExW GetSystemWindowsDirectoryW GetSystemWindowsDirectoryW RegCreateKeyExW RegCreateKeyExW SetViewportOrgEx SetViewportOrgEx GetKeyState GetKeyState GetKeyboardState GetKeyboardState UnregisterHotKey UnregisterHotKey RegisterHotKey RegisterHotKey MsgWaitForMultipleObjectsEx MsgWaitForMultipleObjectsEx GetAsyncKeyState GetAsyncKeyState _amsg_exit _amsg_exit _acmdln _acmdln GdipSetPenLineJoin GdipSetPenLineJoin GdipSetImageAttributesColorKeys GdipSetImageAttributesColorKeys GdiplusShutdown GdiplusShutdown PathIsURLW PathIsURLW UrlIsW UrlIsW UrlEscapeW UrlEscapeW PathCreateFromUrlW PathCreateFromUrlW UrlUnescapeW UrlUnescapeW ShellExecuteW ShellExecuteW SHFileOperationW SHFileOperationW ShellExecuteExW ShellExecuteExW URLOpenBlockingStreamW URLOpenBlockingStreamW CreateURLMoniker CreateURLMoniker CertCloseStore CertCloseStore CertFreeCertificateContext CertFreeCertificateContext CertGetNameStringW CertGetNameStringW CertFindCertificateInStore CertFindCertificateInStore CryptMsgGetParam CryptMsgGetParam CryptMsgClose CryptMsgClose CryptUIDlgViewCertificateW CryptUIDlgViewCertificateW sidebar.pdb sidebar.pdb name="Microsoft.Windows.Sidebar" name="Microsoft.Windows.Sidebar" version="1.0.0.0" version="1.0.0.0" name="Microsoft.Windows.Common-Controls" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" version="6.0.0.0" publicKeyToken="6595b64144ccf1df" publicKeyToken="6595b64144ccf1df" stdole2.tlbWWWp) stdole2.tlbWWWp) vOperationWW vOperationWW .ssid .ssid .backgroundWW .backgroundWW .lpbstrStdDisplayNameWD .lpbstrStdDisplayNameWD KEYWh KEYWh "" ,,/,**)(( "" ,,/,**)(( !
!
yuussHIBA@
yuussHIBA@
wfb=3/-A} wfb=3/-A} 444600,,)''%%$$ 444600,,)''%%$$ "
"
=55/** ('%%$$ =55/** ('%%$$ @
@
!!//---*)( !!//---*)( 62.*(&$# 62.*(&$# ,63.*)&$$## ,63.*)&$$## /963.*)&# /963.*)&# L[Q9930.*'$$&.LhmlEF L[Q9930.*'$$&.LhmlEF 7000--,,**'''' 7000--,,**'''' U$.eH~ U$.eH~ }#$##$$$ ! }#$##$$$ ! } / 0/01&&()# } / 0/01&&()# ];
];
@.lF!=^ @.lF!=^ *8
*8
6666666666 6666666666 .oeA( .oeA( l.GCc l.GCc "Cw%X "Cw%X %d%t3 %d%t3 %fLpX %fLpX %US7i %US7i ;w.VS]} ;w.VS]} .IDATx .IDATx &p.VM &p.VM j.ah@ j.ah@ g?.Vf g?.Vf Q.hH5 Q.hH5 )%uuu )%uuu d^pÇ d^pÇ {D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost' {D58F39FF-953E-4F45-898F-59F243B9A523} = s 'ghost' 'sidebar.EXE' 'sidebar.EXE' val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523} val AppID = s {D58F39FF-953E-4F45-898F-59F243B9A523} NoRemove 'Windows Sidebar' NoRemove 'Windows Sidebar' *021:1@1 *021:1@1 3 3$3(3,3034383
3 3$3(3,3034383
? ?$?(?,? ? ?$?(?,? 8 8$8(8,808 8 8$8(8,808 4 4'4.4;4 4 4'4.4;4 ="=)=0=7= ="=)=0=7= 6#6*61676 6#6*61676 =4=8=\=`= =4=8=\=`= 4 4
4 4
5 5
5 5
Section%d Section%d Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings Software\Microsoft\Windows\CurrentVersion\Sidebar\Settings Software\Microsoft\Windows Sidebar\IEOverride Software\Microsoft\Windows Sidebar\IEOverride 00.00.00.02 00.00.00.02 Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility Software\Microsoft\Windows\CurrentVersion\Sidebar\Compatibility Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar Software\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar Microsoft\Windows Sidebar\Gadgets Microsoft\Windows Sidebar\Gadgets Settings.ini Settings.ini Microsoft\Windows Sidebar Microsoft\Windows Sidebar AnimationsTimerT%d AnimationsTimerT%d Gadget.xml Gadget.xml *.Gadget *.Gadget hXXp://go.microsoft.com/fwlink/?LinkId=124093 hXXp://go.microsoft.com/fwlink/?LinkId=124093 imageres.dll imageres.dll {557CF406-1A04-11D3-9A73-0000F81EF32E} {557CF406-1A04-11D3-9A73-0000F81EF32E} Windows Sidebar\Shared Gadgets Windows Sidebar\Shared Gadgets Msg_GadgetInstalled Msg_GadgetInstalled %d.%d.%d.%d %d.%d.%d.%d Wversion.dll Wversion.dll %s %s %s %s .0123456789 .0123456789 ddwmapi.dll ddwmapi.dll Msxml.DOMDocument Msxml.DOMDocument Windows Sidebar\Gadgets Windows Sidebar\Gadgets %s\%s %s\%s keywords keywords website website Software\Microsoft\Windows\CurrentVersion\Run Software\Microsoft\Windows\CurrentVersion\Run Section %d Section %d \\?\UNC\ \\?\UNC\ BurlyWood BurlyWood Windows Windows Keywords Keywords Windows Sidebar Windows Sidebar mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947 mshelp://windows/?id=3d5bb826-ed5d-421f-9411-8e0d6ee83947 hXXp:// hXXp:// .html .html .Gadget .Gadget Cert Cert mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b mshelp://windows/?id=6b046ae9-1434-4423-9303-400ff6fe686b url("gbackground:///%s") url("gbackground:///%s") SupportLink SupportLink SidebarExecute SidebarExecute {00000000-0000-0000-0000-000000000000} {00000000-0000-0000-0000-000000000000} \\?\Volume \\?\Volume style.backgroundImage style.backgroundImage style.width style.width style.height style.height Software\Microsoft\Windows\CurrentVersion\Sidebar Software\Microsoft\Windows\CurrentVersion\Sidebar style.backgroundColor style.backgroundColor %windir%\system32\schtasks.exe %windir%\system32\schtasks.exe /run /tn Microsoft\Windows\SideShow\GadgetManager /run /tn Microsoft\Windows\SideShow\GadgetManager HARDWARE\DESCRIPTION\System\CentralProcessor\%d HARDWARE\DESCRIPTION\System\CentralProcessor\%d Shell.Application Shell.Application SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones @tzres.dll, @tzres.dll, \tzres.dll \tzres.dll Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383} Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383} .\%s.mui .\%s.mui .\%s\%s.mui .\%s\%s.mui %s\%s.mui %s\%s.mui %s\%s\%s.mui %s\%s\%s.mui &C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini &C:\Users\"%CurrentUserName%"\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Windows Desktop Gadgets Windows Desktop Gadgets 6.1.7601.17514 (win7sp1_rtm.101119-1850) 6.1.7601.17514 (win7sp1_rtm.101119-1850) sidebar.EXE sidebar.EXE Windows Windows Operating System Operating System 1.0.7601.17514 1.0.7601.17514 Microsoft-Windows-Sidebar/Diagnostic Microsoft-Windows-Sidebar/Diagnostic DT_free_Rus_YandexBar1022.exe_2792:
.text .text `.rdata `.rdata @.data @.data .rsrc .rsrc @.reloc @.reloc operator operator GetProcessWindowStation GetProcessWindowStation %d %d %d %d %d %d %d %d inflate 1.1.3 Copyright 1995-1998 Mark Adler inflate 1.1.3 Copyright 1995-1998 Mark Adler -DTLite.exe -DTLite.exe YandexSetup.exe YandexSetup.exe SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON_Tools_Bar Toolbar --distr /passive /msicl " --distr /passive /msicl " E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb E:\Projects\toolbars\YandexToolbar\Release\ToolbarSetup.pdb KERNEL32.dll KERNEL32.dll EnumChildWindows EnumChildWindows EnumThreadWindows EnumThreadWindows USER32.dll USER32.dll GDI32.dll GDI32.dll RegOpenKeyExA RegOpenKeyExA RegCloseKey RegCloseKey RegCreateKeyExA RegCreateKeyExA ADVAPI32.dll ADVAPI32.dll ShellExecuteExW ShellExecuteExW ShellExecuteExA ShellExecuteExA SHELL32.dll SHELL32.dll GetProcessHeap GetProcessHeap GetCPInfo GetCPInfo t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD t~}q{{oyylwvitsfqqdoobnn_ll^jj[hhZhhZhhZggYhhZhgZggYggYffXffXffXefXefXfeXeeWeeXddWddWddVddVddVcdVbcUbcTbcUabTabTabTaaTaaT``T``T``T``S``S__R__R^^Q^^Q^^Q^^Q]]Q]]P]\P\\P\\O\\O[[O[[O[[N[[N[ZNZZMZZLZZLZYLYYLYYKYWKYWKYWKYXKXWKWVJWWJXVIWVHWVHWVIWVHVUGVUGVUGVUGVTGUSGVTFVTEVTFVSEUSETSETSDURETRETRETRDTRDSRDTRDTQCTQCTRD BYL
BYL
k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>, k`LOB WJ4XK5WJ4WJ4WK5WK5VJ4VJ4VI4UI4UI4TI4TI3UH3UH3TH3RG2RG2RG2RG2QF1QF1QF2QF2PE1PE1PE1OD0OD0OD0NC/MB.MB/LA.LA.LA.KA.K@.J?-J?-I?-I?,H>, PD.XK5RD.xm[ PD.XK5RD.xm[ RE.VI3PC, RE.VI3PC, NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F
NB,QF1SG3RG2RG1RF1RF1QF1RF1QE1QF2QF2PE1PD1QD1PD0OD0NC/OC/NC/NC.MB.MC/MB.MA.LA.LA.L@.K@,K@,J@,J?,J>,I>,I>,H>,G= G= G= F
G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G
G;&OD0OD0OD0OC.NC.NC.NB.MB.MB/MB/MB.LB.LA.LA.LA.K@-K@.J?-MC1MC1I>,J?-I>,I>,I>,G= G=*G=*G=*G
OC.TI6RG3MA-NB.MA-K?* OC.TI6RG3MA-NB.MA-K?* ?5$?5$>4#>4#=4#=3"=4#=3"
?5$?5$>4#>4#=4#=3"=4#=3"
8/!:2$4, 8/!:2$4, @6$>4"8, @6$>4"8,
8/!8/!8/!8.!7. 7. 7. 7. 6- 8/!8/!8/!8.!7. 7. 7. 7. 6- 80 90"2( 80 90"2( 6- 6- 6- 6- 6- 6- JJJ...SSS JJJ...SSS /,)/,)?:7 /,)/,)?:7 tGHt.Ht& tGHt.Ht& Please contact the application's support team for more information. Please contact the application's support team for more information. - Attempt to initialize the CRT more than once. - Attempt to initialize the CRT more than once. - CRT not initialized - CRT not initialized - floating point support not loaded - floating point support not loaded USER32.DLL USER32.DLL Seed: %d Seed: %d D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb D:\build\autobuild\e957a850ea619703\downloader\Release\downloader.pdb RegOpenKeyExW RegOpenKeyExW ole32.dll ole32.dll OLEAUT32.dll OLEAUT32.dll URLOpenBlockingStreamW URLOpenBlockingStreamW urlmon.dll urlmon.dll WINTRUST.dll WINTRUST.dll VERSION.dll VERSION.dll GetConsoleOutputCP GetConsoleOutputCP zcÁ zcÁ 3.44484
3.44484
"hXXp://crl.verisign.com/tss-ca.crl0 "hXXp://crl.verisign.com/tss-ca.crl0 hXXp://ocsp.verisign.com0 hXXp://ocsp.verisign.com0 Thawte Certification1 Thawte Certification1 0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0 0hXXp://crl.verisign.com/ThawteTimestampingCA.crl0 2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100. 2Terms of use at hXXps://VVV.verisign.com/rpa (c)09100. 3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D 3hXXp://csc3-2009-2-crl.verisign.com/CSC3-2009-2.crl0D hXXps://VVV.verisign.com/rpa0 hXXps://VVV.verisign.com/rpa0 hXXp://ocsp.verisign.com0? hXXp://ocsp.verisign.com0? 3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0 3hXXp://csc3-2009-2-aia.verisign.com/CSC3-2009-2.cer0 .Class 3 Public Primary Certification Authority0 .Class 3 Public Primary Certification Authority0 hXXps://VVV.verisign.com/cps0* hXXps://VVV.verisign.com/cps0* #hXXp://logo.verisign.com/vslogo.gif0 #hXXp://logo.verisign.com/vslogo.gif0 hXXp://ocsp.verisign.com01 hXXp://ocsp.verisign.com01 hXXp://crl.verisign.com/pca3.crl0) hXXp://crl.verisign.com/pca3.crl0) hXXp://VVV.yandex.ru0 hXXp://VVV.yandex.ru0 4O4 4O4 3:3?3!4.444`4 3:3?3!4.444`4 2(3,3034383 2(3,3034383 mscoree.dll mscoree.dll KERNEL32.DLL KERNEL32.DLL WUSER32.DLL WUSER32.DLL dhXXp://legal.yandex.ru/elements_agreement/ dhXXp://legal.yandex.ru/elements_agreement/ _Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF} _Hyperlink_Object_Pointer_\{AFEED740-CC6D-47c5-831D-9848FD916EEF} %Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe %Program Files%\DAEMON Tools Lite\DT_free_Rus_YandexBar1022.exe DAEMON Tools Lite ve Yandex.Bar DAEMON Tools Lite ve Yandex.Bar Yandex.Bar Yandex.Bar Instalovat Yandex.Bar Seznam Edition Instalovat Yandex.Bar Seznam Edition Nastavit Seznam.cz jako domovskou str Nastavit Seznam.cz jako domovskou str m Yandex.Baru Seznam Edition souhlas m Yandex.Baru Seznam Edition souhlas Yandex.Bar v barv Yandex.Bar v barv tu Yandex.Bar v barv tu Yandex.Bar v barv by Seznam.cz by Seznam.cz The file "%s" is signed and the signature was verified. The file "%s" is signed and the signature was verified. The file "%s" is not signed. The file "%s" is not signed. An unknown error occurred trying to verify the signature of the "%s" file. An unknown error occurred trying to verify the signature of the "%s" file. Error is: 0x%x. Error is: 0x%x. For using type: downloader.exe --partner For using type: downloader.exe --partner Oops after %d bytes. Oops after %d bytes. File downloading complete: %s, size: %d File downloading complete: %s, size: %d Speed: %dKBs Speed: %dKBs File doesn't exist: %s File doesn't exist: %s Can't create file '%s' Can't create file '%s' Error: 0x%x Error: 0x%x Exit code: 0x%x Exit code: 0x%x Can't get exit code. Error: 0x%x Can't get exit code. Error: 0x%x Downloading installer: %s Downloading installer: %s try %d try %d HRESULT: 0xX HRESULT: 0xX Distr: %s Distr: %s Try to run: %s %s Try to run: %s %s %d.%d.%d %d.%d.%d Val: %d Val: %d templ: %s templ: %s %s: %s %s: %s New partner name: %s New partner name: %s url: %s url: %s name: %s name: %s fb: %s fb: %s lt: %s lt: %s \downloader.log \downloader.log cmd: %s cmd: %s ver: %s ver: %s os: %s os: %s elevated: %s elevated: %s \seed.txt \seed.txt Params: '%s' Params: '%s' hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss hXXp://downloader.yandex.net/yandex-pack/downloader/info.rss hXXp://download.yandex.ru/yandex-pack/downloader/info.rss hXXp://download.yandex.ru/yandex-pack/downloader/info.rss hXXp://downloader.yandex.net/yandex-pack/ hXXp://downloader.yandex.net/yandex-pack/ YandexPackSetup.exe YandexPackSetup.exe YandexSearch.exe YandexSearch.exe DebugURL DebugURL downloader.yandex.net downloader.yandex.net download.yandex.ru download.yandex.ru suffix: %s suffix: %s %d.%d.%d.%d %d.%d.%d.%d 0.1.0.16 0.1.0.16 download.exe download.exe DT Yandex Setup.exe DT Yandex Setup.exe WMIADAP.EXE_3440:
.text .text `.data `.data .rsrc .rsrc @.reloc @.reloc ADVAPI32.dll ADVAPI32.dll ntdll.DLL ntdll.DLL KERNEL32.dll KERNEL32.dll USER32.dll USER32.dll msvcrt.dll msvcrt.dll wbemcomn.dll wbemcomn.dll OLEAUT32.dll OLEAUT32.dll ole32.dll ole32.dll loadperf.dll loadperf.dll `.bik `.bik PSSSSSSh PSSSSSSh WMIADAP.exe WMIADAP.exe ?CloseSubKey@CRegistry@@AAEXXZ ?CloseSubKey@CRegistry@@AAEXXZ ?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z ?CreateOpen@CRegistry@@QAEJPAUHKEY__@@PBGPAGKKPAU_SECURITY_ATTRIBUTES@@PAK@Z ?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z ?DeleteCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBG@Z ?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z ?DeleteCurrentKeyValue@CRegistry@@QAEKPBG@Z ?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z ?DeleteKey@CRegistry@@QAEJPAVCHString@@@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGPAEPAK@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z ?GetCurrentBinaryKeyValue@CRegistry@@QAEKPBGPAEPAK@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z ?GetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z ?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z ?GetCurrentRawKeyValue@CRegistry@@AAEKPAUHKEY__@@PBGPAXPAK3@Z ?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z ?GetCurrentRawSubKeyValue@CRegistry@@AAEKPBGPAXPAK2@Z ?GetCurrentSubKeyCount@CRegistry@@QAEKXZ ?GetCurrentSubKeyCount@CRegistry@@QAEKXZ ?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z ?GetCurrentSubKeyName@CRegistry@@QAEKAAVCHString@@@Z ?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z ?GetCurrentSubKeyPath@CRegistry@@QAEKAAVCHString@@@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAK@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z ?GetCurrentSubKeyValue@CRegistry@@QAEKPBGPAXPAK@Z ?GetLongestSubKeySize@CRegistry@@QAEKXZ ?GetLongestSubKeySize@CRegistry@@QAEKXZ ?GethKey@CRegistry@@QAEPAUHKEY__@@XZ ?GethKey@CRegistry@@QAEPAUHKEY__@@XZ ?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z ?LocateKeyByNameOrValueName@CRegistrySearch@@QAEHPAUHKEY__@@PBG1PAPBGKAAVCHString@@3@Z ?NextSubKey@CRegistry@@QAEKXZ ?NextSubKey@CRegistry@@QAEKXZ ?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z ?Open@CRegistry@@QAEJPAUHKEY__@@PBGK@Z ?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z ?OpenAndEnumerateSubKeys@CRegistry@@QAEJPAUHKEY__@@PBGK@Z ?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z ?OpenLocalMachineKeyAndReadValue@CRegistry@@QAEJPBG0AAVCHString@@@Z ?OpenSubKey@CRegistry@@AAEKXZ ?OpenSubKey@CRegistry@@AAEKXZ ?RewindSubKeys@CRegistry@@QAEXXZ ?RewindSubKeys@CRegistry@@QAEXXZ ?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z ?SearchAndBuildList@CRegistrySearch@@QAEHVCHString@@AAVCHPtrArray@@00HPAUHKEY__@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAK@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHStringArray@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAK@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHString@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z ?SetCurrentKeyValue@CRegistry@@QAEKPBGAAVCHStringArray@@@Z ?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?SetCurrentKeyValueExpand@CRegistry@@QAEKPAUHKEY__@@PBGAAVCHString@@@Z ?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z ?myRegCreateKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKPAGKKQAU_SECURITY_ATTRIBUTES@@PAPAU2@PAK@Z ?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z ?myRegDeleteKey@CRegistry@@AAEJPAUHKEY__@@PBG@Z ?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z ?myRegDeleteValue@CRegistry@@AAEJPAUHKEY__@@PBG@Z ?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z ?myRegEnumKey@CRegistry@@AAEJPAUHKEY__@@KPAGK@Z ?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z ?myRegEnumValue@CRegistry@@AAEJPAUHKEY__@@KPAGPAK22PAE2@Z ?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z ?myRegOpenKeyEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPAPAU2@@Z ?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z ?myRegQueryInfoKey@CRegistry@@AAEJPAUHKEY__@@PAGPAK22222222PAU_FILETIME@@@Z ?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z ?myRegQueryValueEx@CRegistry@@AAEJPAUHKEY__@@PBGPAK2PAE2@Z ?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z ?myRegSetValueEx@CRegistry@@AAEJPAUHKEY__@@PBGKKPBEK@Z QSSh0 QSSh0 Invalid parameter passed to C runtime function. Invalid parameter passed to C runtime function. ntdll.dll ntdll.dll RegCloseKey RegCloseKey RegOpenKeyExW RegOpenKeyExW RegCreateKeyExW RegCreateKeyExW RegEnumKeyW RegEnumKeyW RegDeleteKeyW RegDeleteKeyW RegQueryInfoKeyW RegQueryInfoKeyW _amsg_exit _amsg_exit _acmdln _acmdln ?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z ?Report@CEventLog@@QAEHGKVCInsertionString@@000000000@Z WMIADAP.pdb WMIADAP.pdb 5m6z6 5m6z6 %s_x %s_x %s_x_ %s_x_ Global\WMI_SysEvent_Semaphore_%d Global\WMI_SysEvent_Semaphore_%d WinMSGWMIADAP WinMSGWMIADAP \\.\root\cimv2 \\.\root\cimv2 WMIADAP Msg window WMIADAP Msg window \\.\root\wmi \\.\root\wmi PSAPI.DLL PSAPI.DLL x=%s x=%s Describes all the counters supported via WMI Hi-Performance providers Describes all the counters supported via WMI Hi-Performance providers _new.ini _new.ini xx %s%s.ini xx %s%s.ini xx %s xx %s \\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\"" \\.\ROOT\cimv2:__ClassProviderRegistration.provider="\\\\.\\root\\cimv2:__Win32Provider.Name=\"WmiPerfClass\"" WmiApRes.dll WmiApRes.dll %s\%s %s\%s 6.1.7600.16385 (win7_rtm.090713-1255) 6.1.7600.16385 (win7_rtm.090713-1255) wmicookr.dll wmicookr.dll Windows Windows Operating System Operating System 6.1.7600.16385 6.1.7600.16385