Analysis Date2014-12-21 19:22:10
MD51917a34482bc068bd8048c928bdb709c
SHA1103872131d65a825ebe0896ef96158af291a33e7

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: ac975158f8d1898ad53540a1b53ea3d8 sha1: b9785b186170a902d99fdad20d4c8f28b7026ff5 size: 29184
Section.data md5: da1c396bb89dec90f6f8fa739df5d086 sha1: c68707396ba0dee30ddb685595a4649e91b55a86 size: 512
Section.rsrc md5: da8d8355bcf131cf2af70fd8e574b698 sha1: 7396ab754c93e6b132fe466736cc44dedf39be4c size: 2560
SectionUPX0 md5: 1a41d9c8af69414556b0769b891e0b58 sha1: e3d6e94c5402b68bef2bb2825de3e4d02dad5d71 size: 147456
Timestamp2004-08-04 06:05:51
Pdb pathCLIPSRV.pdb
VersionLegalCopyright: © Microsoft Corporation. All rights reserved.
InternalName: CLIPSRV.EXE
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
FileDescription: Windows NT DDE Server
OriginalFilename: CLIPSRV.EXE
PEhash0b505ecdd58a574f6857111fef34a45b897c455a
IMPhash39b39bbb163f0884f72ad82728d73a76
AV360 SafeVirus.Win32.Expiro.H
AVAd-AwareWin32.Expiro.Gen.2
AVAlwil (avast)Expiro-AC:Win32:Expiro-AC
AVArcabit (arcavir)Win32.Expiro.Gen.2
AVAuthentiumW32/Expiro.T
AVAvira (antivir)W32/Expiro.X
AVBullGuardWin32.Expiro.Gen.2
AVCA (E-Trust Ino)Win32/Expiro.J
AVCAT (quickheal)W32.Expiro.D
AVClamAVW32.Expiro-21
AVDr. WebWin32.Expiro.40
AVEmsisoftWin32.Expiro.Gen.2
AVEset (nod32)Win32/Expiro.X virus
AVFortinetW32/Expiro.W
AVFrisk (f-prot)W32/Expiro.T
AVF-SecureWin32.Expiro.Gen.2
AVGrisoft (avg)Win32/Expiro.X
AVIkarusTrojan.Win32.Spy
AVK7Virus ( 0022f7391 )
AVKasperskyVirus.Win32.Expiro.w
AVMalwareBytesVirus.Expiro
AVMcafeeW32/Expiro.gen.h
AVMicrosoft Security EssentialsVirus:Win32/Expiro.AL
AVMicroWorld (escan)Win32.Expiro.Gen.2
AVRisingWin32.Expiro.l
AVSophosW32/Expiro-H
AVSymantecW32.Xpiro.D
AVTrend MicroPE_EXPIRO.RAP
AVVirusBlokAda (vba32)Virus.Expiro.317

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates Filec:\windows\system32\clipsrv.exe
Creates Filec:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.exe
Creates Filec:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
Creates Filec:\windows\system32\clipsrv.vir
Creates Filec:\windows\system32\cisvc.vir
Creates Filec:\windows\system32\cisvc.exe
Creates FilePIPE\SfcApi
Creates Filec:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.vir
Creates Filec:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.vir
Deletes Filec:\windows\microsoft.net\framework\v2.0.50727\mscorsvw.vir
Deletes Filec:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.vir
Deletes Filec:\windows\system32\clipsrv.vir
Deletes Filec:\windows\system32\cisvc.vir
Creates Mutexkkq-vx_mtx1
Creates Mutexkkq-vx_mtx20
Starts ServiceAppMgmt

Process
↳ C:\WINDOWS\system32\cisvc.exe

Creates Filec:\windows\system32\imapi.vir
Creates Filec:\windows\system32\dllhost.vir
Creates FileC:\temp\files\mscorsvw.exe
Creates Filec:\windows\system32\ups.exe
Creates Filec:\windows\system32\locator.exe
Creates Filec:\windows\system32\mnmsrvc.vir
Creates Filec:\windows\system32\wbem\wmiapsrv.exe
Creates Filec:\windows\system32\smlogsvc.exe
Creates Filec:\windows\system32\msiexec.exe
Creates Filec:\windows\system32\vssvc.vir
Creates Filec:\windows\system32\netdde.vir
Creates Filec:\windows\system32\netdde.exe
Creates Filec:\windows\system32\sessmgr.exe
Creates Filec:\windows\microsoft.net\framework\v2.0.50727\aspnet_state.exe
Creates Filec:\windows\system32\dmadmin.exe
Creates Filec:\windows\system32\dmadmin.vir
Creates Filec:\windows\system32\msdtc.exe
Creates Filec:\windows\system32\msiexec.vir
Creates Filec:\windows\system32\sessmgr.vir
Creates Filec:\windows\system32\msdtc.vir
Creates FileC:\temp\files\lsass.vir
Creates Filec:\windows\system32\scardsvr.vir
Creates Filec:\windows\system32\scardsvr.exe
Creates Filec:\windows\system32\mnmsrvc.exe
Creates Filec:\windows\system32\clipsrv.exe
Creates Filec:\windows\system32\rsvp.exe
Creates Filec:\windows\system32\imapi.exe
Creates Filec:\windows\system32\smlogsvc.vir
Creates Filec:\windows\system32\tlntsvr.exe
Creates Filec:\windows\system32\tlntsvr.vir
Creates FileC:\malware.exe
Creates FileC:\temp\files\svchost.vir
Creates FileC:\temp\files\svchost.exe
Creates Filec:\windows\system32\wbem\wmiapsrv.vir
Creates Filepipe\net\NtControlPipe10
Creates FilePIPE\SfcApi
Creates Filec:\windows\system32\vssvc.exe
Creates FileC:\temp\files\lsass.exe
Creates Filec:\windows\system32\rsvp.vir
Creates Filec:\windows\system32\dllhost.exe
Creates Filec:\windows\system32\locator.vir
Deletes Filec:\windows\system32\imapi.vir
Deletes Filec:\windows\system32\dmadmin.vir
Deletes Filec:\windows\system32\dllhost.vir
Deletes Filec:\windows\system32\sessmgr.vir
Deletes Filec:\windows\system32\msiexec.vir
Deletes Filec:\windows\system32\mnmsrvc.vir
Deletes Filec:\windows\system32\msdtc.vir
Deletes FileC:\temp\files\lsass.vir
Deletes Filec:\windows\system32\scardsvr.vir
Deletes Filec:\windows\system32\smlogsvc.vir
Deletes Filec:\windows\system32\tlntsvr.vir
Deletes FileC:\temp\files\svchost.vir
Deletes Filec:\windows\system32\wbem\wmiapsrv.vir
Deletes Filec:\windows\system32\rsvp.vir
Deletes Filec:\windows\system32\vssvc.vir
Deletes Filec:\windows\system32\netdde.vir
Deletes Filec:\windows\system32\locator.vir
Creates Mutexgazavat-svc
Creates Mutexgazavat-svc_20

Process
↳ Pid 804

Process
↳ Pid 852

Process
↳ C:\WINDOWS\System32\svchost.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces ➝
NULL
Creates FilePIPE\lsarpc
Creates FileC:\WINDOWS\system32\WBEM\Repository\$WinMgmt.CFG
Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log

Process
↳ Pid 1112

Process
↳ Pid 1212

Process
↳ C:\WINDOWS\system32\spoolsv.exe

RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝
7
RegistryHKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝
NULL
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝
C:\WINDOWS\System32\spool\PRINTERS\\x00
Creates FileWMIDataDevice

Process
↳ Pid 1868

Process
↳ Pid 1164

Process
↳ C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

Creates Filepipe\net\NtControlPipe11
Creates FileC:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen_service.log
Creates FileC:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngenrootstorelock.dat
Creates FileC:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngen_service.lock
Creates FileC:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\ngenservicelock.dat
Creates Mutexgazavat-svc
Creates Mutexgazavat-svc_20

Network Details:


Raw Pcap

Strings
|\\$$\\
$$
..

040904B0
5.1.2600.2180
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
&Bitmap
CLIPSRV.EXE
CompanyName
&DIB Bitmap
&DIF
Displa&y Bitmap
Display En&hanced Metafile
Display Pict&ure
Disp&lay Text
&Enhanced Metafile
FileDescription
FileVersion
%hc%hs	
InternalName
LegalCopyright
Microsoft
Microsoft Corporation
 Microsoft Corporation. All rights reserved.
 Operating System
OriginalFilename
O&wner display
Pal&ette	Pe&n Data
&Picture
ProductName
ProductVersion
&RIFF
StringFileInfo
&Sylk
&Text
T&IFF	&OEM Text
Translation
&Unicode Text
VarFileInfo
VS_VERSION_INFO
&Wave Audio
 Windows
Windows NT DDE Server
0~:d3D$gxX0a>y N%~
0h1J=g;E}^}j-
0s%V#w$
1F!e)V,l5SJ^7i/F=vzF6j&e/Z
1!`M+ny
1O-Y5S
2#$A!jhUtU;$+J6c}Mp
3jqJaC%
~3kGh/!
"3v%{	D?.
}4Ev#rf}_:r8@*mg
4HF^cNwBH
+	`4<@igp
-4 ^!o%_-Cf>j
-4 ^!o+_-Cf>j
-4 ^!o)_%S;d0
~51B/P't0
520T;_0i5V
5g9F<auUvT-y"W$1-
5H6whVgBpE
5J:}}Za_0j~@<{~X~S
5|k	h^,j7A!(k
5M'fv^@d
5M'fv^;P?f5{
5^?n{\.Rp
5.+T$M2S
66}RzR6,0]j>~
66}RzR7,0]j>~
6@A:o8Jl*sS=P:k=N[
%6;O6]%N
[6TMW{>
,6=U[I
6w}Z=XwV`shyyK5[cc~\6
6y$^ 2r
~\7e?@>c{[eB
7I:}?J(S;`"Nli%Dx^>?m]a'
7J+D>?m]lhrPvD~7 H[ 1
7J*Dx$n
7!j\q_,h3Z:a
7$+S!jlLgX~N9
7!tVtR
7x$@`MvPiY7e=
7x$@`qjJ|Y"s9z
7X	rx^gK.{
88hLt6'\yY02;_lat
88hLt6']yY27;_lat
8+nF}O&r3
8-"UQ6
8V[uK<n8M*q;}\
*?_9+?
!96@9{qG`
"96P/a`
9u	W5^,
aaFw[<e:Q=wZ\MI:t>
AddAccessAllowedAce
AddAccessAllowedAce fail
AddCopiedFormat returning FALSE!
AddNetInfo: Already added
AddRecord: DdeCHSZ fail
AddRecord: LocalAlloc failed
~adFg/t
_adjust_fdiv
a!Ds,.
ADVAPI32.dll
Advise loop requested on item other than topiclist
Advise on topiclist OK
 aLggE7u#G
{|A"mK
aMk|dH8sw
A>MkoYtM#qX>B
)Aq	SM}
ArYdZ.a5Y
A?)ry_xM(
AVqHo.,>O?qfp}H0r4S*kzZ"
A={}Waf1a9M*!YzVs
ax9G>0#
[.azYG]2c)L,{/O{I6a)F
.B$[7N
Bad .CLP file
Bad file header.
Bad new format rd
Bad old format rd
^^bHjLR
\^bHjQ|
=BIeF^
bq1Oos+HgJ'E
BQYaMkrl
BSpKF3B
bV*}0X"
/@}C1G
{C2ayS0nlZ}
c:&(4>
C5h1j!0
*C7d=@l;~Vm_6b#
Cannot set file pointer to FILE_BEGIN
Can't open file
*c,c9f ``EkC"r!Vl2lJ(Omb(W'``G|B-wdH't-@&Y&t$A+qqMfLmv,X+G
|C*ccP"svWLN0s?Z>flKf
%ceMaG
_cexit
_c_exit
!/(_-Cf>j
Changing shared status
Clipbook Preview
Clipbook Service
ClipbrdMutex
ClipData
ClipSrv
ClipSrv: Closing Clipboard
CLIPSRV.EXE
Clipsrv: item to delete '%s' not found
ClipSrv: Opening Clipboard
CLIPSRV.pdb
clipsrv: returning format list >%cs<
clipsrv: returning format list >%ws<
ClipSrvWClass
CloseClipboard
CloseHandle
ClSrv\DdeCB: Client asked for topics in bad fmt
Clsrv\GetFormat:
ClSrv: InitApplication failed!
ClSrv\OpClpFile: can't open file!
ClSrv\RndrFmtFromFile: Opening file %s.
ClSrv\RndrRawFmtToDDE:
ClSrv\WM_RNDRALL rcvd
Comparing to %ls
Config
Confirming connect
_controlfp
cO;r2T~Ag
Could not make registry key to record %s
Could not open clipboard!!!
Couldn't access handle
Couldn't createdata handle
Couldn't delete key! #%ld
couldn't GET it though...
Couldn't get sec #%ld
Couldn't get to Clipbook root key
Couldn't get token handle or InitSD bad 
Couldn't get usertokeninfo
Couldn't initialize DDE
couldn't LOCK it though...
Couldn't open clipboard!
Couldn't open windowstation WinSta0
Couldn't register wclass
Couldn't regopen %s with %lx access - #%lx
Couldn't set file pointer
CountClipboardFormats
CreateBitmap
CreateBitmap failed
CreateBitmapIndirect
CreateCompatibleDC
CreateDIBitmap
CreateFileA
CreateFileW
CreateFontA
CreateMutexA
CreatePalette
CreateWindowExA
Creating ClSrv window
Csrv: NDde err %ld on delshare
CTbE|6V
C%U;B1
!/!_,Cw3{
d1fOiOg
d^4ej_61t
d^4ej_81t
@d:;B0K#I)
d,BcbA
DdeAccessData
DdeAccessData failed!!!
DdeAddData
<<<< DdeCallback
>>>> DdeCallback
DdeCmpStringHandles
DdeCreateDataHandle
DdeCreateDataHandle failed!!!
DdeCreateStringHandleA
DdeCreateStringHandle failed
DdeCreateStringHandleW
DdeFreeDataHandle
DdeFreeStringHandle
DdeGetData
DdeGetLastError
DdeImpersonateClient
DdeInitializeA
DdeInit OK...
DdeKeepStringHandle
DdeKSHandle fail in DdeCB
DdeNameService
DdePostAdvise
DdeQueryStringA
DdeUnaccessData
DdeUninitialize
-debug
[debug]
DefWindowProcA
[delete]
DeleteDC
DeleteFileA
DeleteFileW
DeleteObject
Deleting old name %ws
Deleting %s
Deleting share %s on %s
dfCs\<7k	>j}
%d formats found
|}dHdT"[,R/sx
DispatchMessageA
DrawTextA
DrawTextW
dr_qO8j<I.uMBy[yn*
{?dW`4#
dyDhOm+v
E21kUP]xE
e(?3.;
e9J,gv@wInn8T~off}_:r8@*mg
e+{\B8$
e\~C%Iw%|
eCTI_=`
|e?]'f|
EmptyClipboard
Entering MarkShare
Entering ReadClipboardFromFile
 Entering SaveClipboardToFile
EnumClipboardFormats
EOhE6j
error accessing data handle for topic list
error creating hddedata for topic list
Error opening clipboard file!
ERROR opening %ls
ERROR opening %s
Error reading file: %ld from lread
ErrorRequest
EstOj9U
_except_handler3
[exit]
:{>e/Z-jpQh
eZoxa> O,m}
Failed creating self-relative SD (%d).
fAnythingToRender = TRUE
F]aQ{XO
f<*[CJ"q,R/o
f<*[CJ"q,R/sdY,
fF;nkJ}}}]|D;n$G=h6KpR7
f[;h5]?akW{Gp5j_|**
FillRect
F:kgQ{O<r}I-"v[uK<n8M* 9WwU'r<@*KQ
FormatList
freeing cached format list
freeing cached preview bitmap
f,R	ssTeI.w(C/UnNxJ?`
fU6h=Kn2:QaB.~r
FuUjX'tAB>w
FxRiYc|pG&{v
GDI32.dll
GetAce
GetAce error %d
GetBitmapBits
GetBitmapBits failed
GetClipboardData
GetClipboardData fail on CF_ENHMETAFILE
GetClipboardFormatNameW
GetClipboardName on OwnerDisplay format!
GetClipboardNameW: bad alloc
GetClipboardNameW: bad lock
GetComputerNameA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDACL fail %ld
GetDIBits
GetEnhMetaFileBits
GetEnhMetaFileHeader
GetFormat: caching preview
GetFormatList:
GetFormatList: Topic not found
getformat: read >%ws<
GetFormat: requested format %s not found
GetLastError
GetLengthSid
__getmainargs
GetMessageA
GetMetaFileBitsEx
GetModuleHandleA
GetObjectA
GetPaletteEntries
GetRandShareFileName: More than 1000 clipbook file exist!
GetSecurityDescriptorDacl
GetSecurityDescriptorLength
GetStockObject
GetSystemTimeAsFileTime
GetTickCount
Getting data for %ws at offset %ld
Getting format list
Getting security %ld bytes
GetTokenInformation
GetWindowsDirectoryA
ggiwA|^1~m]=[FKf_&~9c!~lGq
g)gVmJ(m0
GlobalAlloc
GlobalAlloc failure in RenderFormat
GlobalFree
GlobalHandle
GlobalLock
GlobalLock failure in RenderFormat
GlobalReAlloc
GlobalSize
GlobalUnlock
Got format %ws
gqAfL 4h
,gq]j^0t2Qe37
`gQlN!n}`7,{GQx<n)F0vE[tR0ysb
gQuRWY
gS:d"K0{qWr
g-*U4"=
?`G.v-
Handler: Service stopped
Handler: stopping service
%hc%hs	
hData == NULL, bad
	HdQK"(x
~HEEW(
HfFm^9N0M
hFSHpKQ
?+hI4d+p>L3]vUl^4o/J;q/ocX2t8D1pl
Hidden Data Server
@'"Hq)Ni
h(S_cX
hUhDct9{
[h_wE:i\[(}
i3a4#OD;g
i[3=>G/`qQx	yd%Z=<ZW|J1d8Cf;>FzN"{vP/a`
i7&Ja1w
I7_y'p\
@i:;B1W-^	9?
ICdI,ED
ICdI-WI
i-eBa8:
I>=gY\QtI
 imIeKbW%@*Uk]
}iMkRmD
}iMkRmQ
Impersonating
__initenv
InitializeAcl
InitializeAcl fail
InitializeSecurityDescriptor
[initshare]
_initterm
Invalid ACE type!!!
Invalid execute
invalid item
Invalid magic member (not long enough?)
ipf[C`"q06j '
IsClipboardFormatAvailable
isM-KV[vO6n)s1n|Wafz}fU?p5vyH66iL,kr	cd8e$p*p
IsValidSecurityDescriptor
item = %s
Item to mark '%s' not found
item was %s
j; 2jK5	8`?
<.j2n]l}>
j2nOn!-
!j3hvS
%j7Mz3$
j9b!<Y,
j$hf[,
j hf+8
jIb@)z'Y$x
j@j@VVS
jmNEiJ
j'S~Sj
j"VVVVVVVh
:#"K7fj\vB7c7
:#"K7fj\vB7c7S6ck\nD;y%\=/[P;X-D
;k7nEPz
k>bL>}qYf
k>bRl2*E 
KChB,/VLz
KERNEL32.dll
^k_`F.p
K_g)ry_n@V
kmYpo7xxL9e
laQj]2c8
l%%*c1:1:
 = %ld
lf@yU0egE+lv@qT=(?
link data found
L!kf$<
l:n]jh L"
LnkCpy
LoadCursorA
LoadIconA
LoadStringW
LocalAlloc
LocalAlloc fail
LocalAlloc for pSD fail
LocalAllof for Acl fail
LocalFree
Looking for %ls
lstrcatA
lstrcmpA
lstrcmpiA
lstrcmpW
lstrcpyA
lstrcpyW
lstrlenA
lstrlenW
m?2x/sdEiJ"q0
Made page %ls with file %ls
MakeSelfRelativeSD
making APPOWNED data
Making page %s with file %s
Making registry key %ls from %ls, %d
Marking %s as shared
MarkShare: Couldn't open registry!
[markshared]
MarkShare: marking %s %d
[markunshared]
|@mEd3
M@fe?B
M*ggRyX6:
mi'_xYx3g
MOomW#]
msvcrt.dll
MultiByteToWideChar
MXalR?ssD;lpFyO6Q
m?x[W?&
/m-_ybiQ|>Q
n7gRnKg
nAZxnCm
N,BTK=Om
N,BuCtHz	C
NDdeApi.dll
N%`.G#n]vKu
N^+Iw%|
n=mHf=7
nOMXdSk
No window created
NTDLL.DLL
^nUh\(p<
|NuW%p,?B
n->Vg_9x"Bn-3{tE;;dA!f
o2_:JfHfE+n3z"ki
o3W;ladwW:c$
o3XNbUa
,O3Y*N
ObjectLink
objectlink data found
ObjLnkCpy
oh6IuD
oh6_sTje4=
oOOOxRh
[open]
OpenClipboard
OpenClipboardFile: %s 
OpenProcessToken
OpenThreadToken
OpenWindowStationA
opMb\#g
O?P;pcQj
'O{-Q td(
ORoCdF
OXcHbM]
oZ^EeTpL|
[paste]
[pasteshare]
PatBlt
__p__commode
pdPmL,b4~/|dCmYj+,
__p__fmode
pFnc6MzP7c4
;P(KH?b
pk(J}iIU U
PlayEnhMetaFile
PlayMetaFile
playmetafile failed
pMUOgKkVY
p@ne6JeS=#"K#cyZp
PN*RjM_
PostQuitMessage
PQRSTUVWU
pSEzB"~9z {q
)>>P&whA)
pX=b4K{e6JeS=$-M2{{Q=_wv-J}}}]|D;n$G=h%Bh
PXOdG8`'{5~hSy[
Q5bbBuW&U*O-n|Tz[
qe$Z#|'e/jqQ
<,q~l\# +
qMwIrEl
q,R/o!
q,R/oeHdJV0~
,qrs.9
q,R/sdEiVg<6
QueryPerformanceCounter
>qV}Nod?F+;xGi_ xeQgixY$D!c(A8w?B}E d$\ :f
qwJo^5p>W
<}q^|X?a
qXh`I0~?])g$vlI7c%F63GI`O,e
Q-YdEiJ")a
=|QzzX*h>Z
}R7n:Y;oy
RdFmtHdr got NULL pointer
Read %d pages
Read err
ReadFile
RealizePalette
RegCloseKey
RegCreateKeyExA
RegDeleteValueA
RegDeleteValueW
RegEnumValueA
RegisterClassA
RegisterClipboardFormatA
RegisterClipboardFormatW
RegisterServiceCtrlHandlerA
RegOpenKeyExA
RegSetValueExA
RegSetValueExW
ReleaseDC
ReleaseMutex
RenderFormat: Read err, expected %d bytes, got %d
rendering format %ws as %x
RestoreDC
Ret %lx
Returning %lx
Return %#x
RevertToSelf
'r(F#_9em^!y
!"RG{Hj	Q
R=HYM(
rMVv@r
rOr^yn
rs&2mX_
R/sdEiJ"q{
R/sdY,
<[,R/sx
[rTrZ*}sc
R?)TUdYa
s5L+nqdjT0e.Pdd`Z{O:o3
$S6]%N
[saveas]
[saveasold]
sAVEcLIPBOARDdATA: Copied name %s to name %s
SaveClipboardData: error writing format block
SaveClipboardData failed!
SaveDC
sA[XdJ$
%s\CBK%04d.CLP
SCD: Trouble in ReadClipboardFromFile
SClipboardData: writing %ls (#)%d
[Security]
sEH^F)}'D$pjNqM
SelectObject
SelectPalette
SendMessageA
__set_app_type
SetClipboardData
SetClipboardData fail
SetCursor
SetEnhMetaFileBits
SetFilePointer
SetFileSecurityW
SetFSec err %ld
SetMapMode
SetMetaFileBitsEx
SetProcessWindowStation
SetSecurityDescriptorDacl
SetServiceStatus
SetStretchBltMode
SetUnhandledExceptionFilter
Set up delayed render for format %d .
__setusermatherr
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
^S~G>f!
S)G}%{G:
ShowCursor
%s is being written...
Small Fonts
S_oEq)_
Software\Microsoft\Clipbook
Software\Microsoft\Clipbook Server
sprintf
\\%s\%s
StartServiceCtrlDispatcherA
sTOPPING...
StretchBlt
SuHm\7r<U1|OdYg
;s+vn&*>
SYc\`MG
System
System topic request
t4B_yDo9M
^T9!(@
td;|%K {WK|Q7cmMhk6KpR7
TerminateProcess
!This program cannot be run in DOS mode.
t*H#IyCrF
Told system we're running
Too many formats!!!
Topic list requested
Topics
Topic = %s, 
Topic was %s, 
`tPvOp_
TranslateMessage
tXvSve|B}{wKpF2l3Kz4u
txWWWV
u9c/`dI
u:(	(Dm#k]=ctQf
!u\~EfWk
"+$Uf0wAlB1u.G'|b
_;ULk}1
UnhandledExceptionFilter
unknown wType %#x
UnregisterClassA
$U^:q@
USER32.dll
uSNkZ1t:S
/vagi_&w"A7WkPzRk2.\ f`J|
V	c	K1y
VDfG>W
[Version]
vffff`
vHoSg@>zuX3di
Vj@j@S
v#jZa\h
[}VpT-v
V*{wAk_
v%x{z'0
{W2s.j
WaitForSingleObject
WBD1~eF
'W `"B-lzoCVP
}W_GjN6N
WideCharToMultiByte
WinSta0
~WnDm]}
w R3x#4
WriteDataBlock: couldn't get format data
WriteDataBlock: couldn't write CF_ENHMETAFILE
WriteFile
wsprintfA
wsprintfW
,WttpJk_*
wU3zY}
">@WzLt
xb@eB>lv	h~a@
XbV:z0P(n~1
_XcptFilter
X*HXH3
x)M(vj
/X[@*sgI;.8
XTYP_ADVREQ
XTYP_ADVSTART
XTYP_CONNECT
XTYP_CONNECT_CONFIRM
XTYP_DISCONNECT
XTYP_EXECUTE
XTYP_EXECUTE received on non-system topic
XTYP_REQUEST
xY,v$_+?dB|N1=.[/|bA*
y\FxnCm
y*]fx+WxN <9A;w,
Y_gBwCg2_.p
YjWhN&x
yM^EyB>
YohSv%I
y%rFv&3
y:	S3#
Y-S.{j@n@?
-	YV=[
YY*OvMK
YYSSWVj
YYu!j	
z:[8KSUb\'r-
zgiwA|^1~m]=[FKf_&~9c!~lGq
]Z	jA\#
=zjQdO
]zm/Rn
:Z#ppP*cg@mKq,.F,t|W}
Z-.tJ6R1@
zt"_lO>0d
`=zTuEg<6