Analysis Date2015-01-29 02:41:49
MD53e7dae3359ab696553a57d34215f800c
SHA11d7ed66774864715c67dd85fe7f24d73d2334fe5

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
SectionCODE md5: 425c62a04f1391f90868f4141c2c71c5 sha1: d56510814dc88f7e80ac070a56386b87371c9657 size: 65024
SectionDATA md5: d46ae37617157b653a04b717783fc3aa sha1: ac6c91453c2d1e531c56e9e0312b10e1547b5fc5 size: 1024
SectionBSS md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.idata md5: c5cd0aefcedaae0cb737278bd3df0358 sha1: c40ac4187149fae6939ff7f9acabb7ff7932764b size: 3584
Section.tls md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rdata md5: 579364ae8208398f3889afb03ff6f7b1 sha1: ecbd03e1fe61dc7f0394dd1f8d949e1fd5238f07 size: 512
Section.reloc md5: d2a70550489de356a2cd6bfc40711204 sha1: 02ec1f60b2e76741dd9848ac432057ff9d58d750 size: 3072
Section.rsrc md5: 87c39fb8fd64ca9a8e290f15808aa75e sha1: a7f9bde3a3952fd0008590ce96d1c6e3901809ce size: 20992
Timestamp1992-06-19 22:22:17
VersionLegalCopyright:
InternalName:
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename:
PackerAHTeam EP Protector 0.3 (fake PCGuard 4.03-4.15) -> FEUERRADER
PEhash7c88bbb02d6a8a4eff0aa5711c322b255ac3c2b3
IMPhash8548db8f60c204814dcfae0b498b2735
AV360 SafeVirus.Win32.Viking.D
AVAd-AwareWin32.Worm.Viking.NCO
AVAlwil (avast)Malware-gen:Lineage-TB [Trj]:Win32:Malware-gen
AVArcabit (arcavir)Win32.Worm.Viking.NCO:Trojan.Generic.3209190
AVAuthentiumW32/DelfInject.A.gen!Eldorado
AVAvira (antivir)Worm/Viking.DLL.1
AVBullGuardWin32.Worm.Viking.NCO
AVCA (E-Trust Ino)Win32/Looked.KD
AVCAT (quickheal)W32.Viking.LU
AVClamAVW32.Philis-115
AVDr. WebWin32.HLLW.Gavir.72
AVEmsisoftWin32.Worm.Viking.NCO
AVEset (nod32)Win32/Viking.LW virus
AVFortinetW32/Viking.fam!worm
AVFrisk (f-prot)W32/DelfInject.A.gen!Eldorado
AVF-SecureWin32.Worm.Viking.NCO
AVGrisoft (avg)Worm/Viking.E
AVIkarusMalwareScope.Worm.Viking
AVK7Trojan ( 7000000f1 )
AVKasperskyWorm.Win32.Viking.mc
AVMalwareBytesWorm.Viking
AVMcafeeW32/HLLP.Philis.ku
AVMicrosoft Security EssentialsVirus:Win32/Viking.JB
AVMicroWorld (escan)Win32.Worm.Viking.NCO
AVRisingWorm.Win32.Viking.ib
AVSophosW32/Looked-EB
AVSymantecW32.Looked.BK
AVTrend MicroPE_LOOKED.ACX
AVVirusBlokAda (vba32)MalwareScope.Worm.Viking.4

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\load ➝
C:\WINDOWS\uninstall\rundl132.exe
Creates FileC:\malware.exe.exe
Creates FileC:\WINDOWS\system32\drivers\etc\hosts
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\$$a1.bat
Creates FileC:\WINDOWS\Logo1_.exe
Creates FileC:\WINDOWS\uninstall\rundl132.exe
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\$$a1.bat
Creates Processnet stop "Kingsoft AntiVirus Service"
Creates ProcessC:\WINDOWS\Logo1_.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\$$a1.bat

Creates Process"C:\malware.exe"

Process
↳ net stop "Kingsoft AntiVirus Service"

Creates Processnet1 stop "Kingsoft AntiVirus Service"

Process
↳ C:\WINDOWS\Logo1_.exe

RegistryHKEY_LOCAL_MACHINE\Software\Soft\DownloadWWW\auto ➝
1
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\load ➝
C:\WINDOWS\uninstall\rundl132.exe
Creates FileUNC\192.168.1.1\shared\temp\files\MSCDEXNT.EXE
Creates FileUNC\192.168.1.1\shared\temp\files\userinit.exe
Creates FileUNC\192.168.1.1\shared\temp\files\malware.exe.Exe
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
Creates FileUNC\192.168.1.1\shared\temp\files\RCX9.tmp
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\acroaum.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\cmd.exe
Creates FileUNC\192.168.1.1\shared\temp\files\DOSX.EXE.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\DOSX.EXE
Creates FilePIPE\wkssvc
Creates FileUNC\192.168.1.1\shared\temp\files\AcroRd32.exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\RCXB.tmp
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\AcroRd32Info.exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\acroaum.exe
Creates FileUNC\192.168.1.1\shared\temp\files\AdobeUpdateManager.exe.Exe
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\setup.exe.Exe
Creates FileC:\malware.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\net.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\RCXC.tmp
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\RCXA.tmp
Creates FileC:\WINDOWS\system32\drivers\etc\hosts
Creates FileUNC\192.168.1.1\shared\temp\files\cmd.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\REDIR.EXE
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\RCX5.tmp
Creates FileUNC\192.168.1.1\shared\temp\files\malware.exe
Creates FileUNC\192.168.1.1\shared\temp\files\AdobeUpdateManager.exe
Creates FileUNC\192.168.1.1\shared\temp\files\1D7ED6~1.EXE
Creates Filec:\_desktop.ini
Creates FileUNC\192.168.1.1\shared\temp\files\REDIR.EXE.Exe
Creates FileC:\WINDOWS\uninstall\rundl132.exe
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\RCXD.tmp
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\setup.exe
Creates FileUNC\192.168.1.1\shared\temp\files\RCX4.tmp
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\RCXF.tmp
Creates FileUNC\192.168.1.1\shared\temp\files\userinit.exe.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\1D7ED6~1.EXE.Exe
Creates FileUNC\192.168.1.1\shared\temp\files\AcroRd32Info.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
Creates FileUNC\192.168.1.1\shared\temp\files\net.exe
Creates FileUNC\192.168.1.1\shared\temp\files\RCXE.tmp
Creates FileC:\malware.exe
Creates FileUNC\192.168.1.1\shared\temp\files\AcroRd32.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe
Creates FileUNC\192.168.1.1\shared\temp\files\RCX8.tmp
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\RCX7.tmp
Creates FileUNC\192.168.1.1\shared\temp\files\MSCDEXNT.EXE.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe.Exe
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\RCX6.tmp
Creates FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
Creates FileC:\WINDOWS\RichDll.dll
Creates FileUNC\192.168.1.1\shared\temp\files\Logo1_.exe
Creates FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
Creates FileUNC\192.168.1.1\PIPE\srvsvc
Deletes File\\192.168.1.1\shared\temp\files\malware.exe
Deletes File\\192.168.1.1\shared\temp\files\cmd.exe
Deletes FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\acroaum.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\setup.exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe.Exe
Deletes File\\192.168.1.1\shared\temp\files\MSCDEXNT.EXE
Deletes File\\192.168.1.1\shared\temp\files\AdobeUpdateManager.exe.Exe
Deletes File\\192.168.1.1\shared\temp\files\1D7ED6~1.EXE
Deletes File\\192.168.1.1\shared\temp\files\DOSX.EXE
Deletes File\\192.168.1.1\shared\temp\files\cmd.exe.Exe
Deletes File\\192.168.1.1\shared\temp\files\AcroRd32.exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
Deletes File\\192.168.1.1\shared\temp\files\net.exe
Deletes File\\192.168.1.1\shared\temp\files\AcroRd32Info.exe
Deletes File\\192.168.1.1\shared\temp\files\AcroRd32Info.exe.Exe
Deletes FileC:\malware.exe
Deletes File\\192.168.1.1\shared\temp\files\REDIR.EXE
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
Deletes FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\acroaum.exe
Deletes File\\192.168.1.1\shared\temp\files\AcroRd32.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
Deletes File\\192.168.1.1\shared\temp\files\userinit.exe
Deletes File\\192.168.1.1\shared\temp\files\AdobeUpdateManager.exe
Deletes FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe.Exe
Deletes FileC:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
Deletes File\\192.168.1.1\shared\temp\files\malware.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig709\ENU\setup.exe.Exe
Deletes FileC:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe.Exe
Creates Processnet stop "Kingsoft AntiVirus Service"
Creates Processnet stop "Kingsoft AntiVirus Service"

Process
↳ "C:\malware.exe"

Creates FileC:\WINDOWS\SYSTEM32\REDIR.EXE
Creates FileC:\WINDOWS\SYSTEM32\COMMAND.COM
Creates FileC:\1D7ED6~1.EXE
Creates FileC:\WINDOWS\TEMP\scs2.tmp
Creates FileC:\WINDOWS\SYSTEM32\HIMEM.SYS
Creates FileC:\WINDOWS\SYSTEM32\DOSX.EXE
Creates FileC:\WINDOWS\SYSTEM32\MSCDEXNT.EXE
Creates FileC:\WINDOWS\TEMP\scs3.tmp
Deletes FileC:\WINDOWS\TEMP\scs3.tmp
Deletes FileC:\WINDOWS\TEMP\scs2.tmp

Process
↳ net1 stop "Kingsoft AntiVirus Service"

Process
↳ net stop "Kingsoft AntiVirus Service"

Creates Processnet1 stop "Kingsoft AntiVirus Service"

Process
↳ net stop "Kingsoft AntiVirus Service"

Creates Processnet1 stop "Kingsoft AntiVirus Service"

Process
↳ C:\WINDOWS\Explorer.EXE

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
Creates File\Device\Afd\Endpoint
Creates File\Device\Afd\AsyncConnectHlp
Winsock DNSpu.puma163.com
Winsock URLhttp://pu.puma163.com/163b.txt
Winsock URLhttp://pu.puma163.com/1639.txt
Winsock URLhttp://pu.puma163.com/1635.txt
Winsock URLhttp://pu.puma163.com/163c.txt
Winsock URLhttp://pu.puma163.com/1638.txt
Winsock URLhttp://pu.puma163.com/1636.txt
Winsock URLhttp://pu.puma163.com/163g.txt
Winsock URLhttp://pu.puma163.com/163i.txt
Winsock URLhttp://pu.puma163.com/1631.txt
Winsock URLhttp://pu.puma163.com/163j.txt
Winsock URLhttp://pu.puma163.com/1632.txt
Winsock URLhttp://pu.puma163.com/1637.txt
Winsock URLhttp://pu.puma163.com/1633.txt
Winsock URLhttp://pu.puma163.com/163f.txt
Winsock URLhttp://pu.puma163.com/163a.txt
Winsock URLhttp://pu.puma163.com/163d.txt
Winsock URLhttp://pu.puma163.com/1634.txt
Winsock URLhttp://pu.puma163.com/163h.txt
Winsock URLhttp://pu.puma163.com/163e.txt
Winsock URLhttp://pu.puma163.com/1630.txt

Process
↳ net1 stop "Kingsoft AntiVirus Service"

Process
↳ net1 stop "Kingsoft AntiVirus Service"

Network Details:

DNSpu.puma163.com
Type: A
208.73.211.244
DNSpu.puma163.com
Type: A
208.73.211.250
DNSpu.puma163.com
Type: A
208.73.210.211
DNSpu.puma163.com
Type: A
208.73.211.167
HTTP GEThttp://pu.puma163.com/1630.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1631.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1632.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1633.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1634.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1635.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1636.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1637.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1638.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/1639.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163a.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163b.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163c.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163d.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163e.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163f.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163g.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163h.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163i.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://pu.puma163.com/163j.txt
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Flows TCP192.168.1.1:1032 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1033 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1034 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1035 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1036 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1037 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1038 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1039 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1040 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1041 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1042 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1043 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1044 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1045 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1046 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1047 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1048 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1049 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1050 ➝ 208.73.211.244:80
Flows TCP192.168.1.1:1051 ➝ 208.73.211.244:80

Raw Pcap
0x00000000 (00000)   47455420 2f313633 302e7478 74204854   GET /1630.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 312e7478 74204854   GET /1631.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 322e7478 74204854   GET /1632.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 332e7478 74204854   GET /1633.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 342e7478 74204854   GET /1634.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 352e7478 74204854   GET /1635.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 362e7478 74204854   GET /1636.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 372e7478 74204854   GET /1637.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 382e7478 74204854   GET /1638.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 392e7478 74204854   GET /1639.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 612e7478 74204854   GET /163a.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 622e7478 74204854   GET /163b.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 632e7478 74204854   GET /163c.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 642e7478 74204854   GET /163d.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 652e7478 74204854   GET /163e.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 662e7478 74204854   GET /163f.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 672e7478 74204854   GET /163g.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 682e7478 74204854   GET /163h.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 692e7478 74204854   GET /163i.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....

0x00000000 (00000)   47455420 2f313633 6a2e7478 74204854   GET /163j.txt HT
0x00000010 (00016)   54502f31 2e310d0a 41636365 70743a20   TP/1.1..Accept: 
0x00000020 (00032)   2a2f2a0d 0a416363 6570742d 456e636f   */*..Accept-Enco
0x00000030 (00048)   64696e67 3a20677a 69702c20 6465666c   ding: gzip, defl
0x00000040 (00064)   6174650d 0a557365 722d4167 656e743a   ate..User-Agent:
0x00000050 (00080)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x00000060 (00096)   6d706174 69626c65 3b204d53 49452036   mpatible; MSIE 6
0x00000070 (00112)   2e303b20 57696e64 6f777320 4e542035   .0; Windows NT 5
0x00000080 (00128)   2e313b20 5356313b 202e4e45 5420434c   .1; SV1; .NET CL
0x00000090 (00144)   5220322e 302e3530 37323729 0d0a486f   R 2.0.50727)..Ho
0x000000a0 (00160)   73743a20 70752e70 756d6131 36332e63   st: pu.puma163.c
0x000000b0 (00176)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000c0 (00192)   4b656570 2d416c69 76650d0a 0d0a       Keep-Alive....


Strings
@
..V9.

;;;;;;;;;;
;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
!   
0.0.0.0000
0042
0102
0106
010A
0112
0116
0122
0126
0152
0156
015A
015E
0162
0166
%02d/%02d/%d %02d:%02d
040904b0
%04X - %s
080403A8
0x%X: %s
1.0.0.0
1, 4, 28 0
1, 4, 28, 0
2000
2003
2008
2008 R2
; 2.0 32bit uninstall
; 2.0 64bit uninstall
2804
2805
2880
2881
; 3.0 32bit uninstall
; 3.0 64bit uninstall
; 32 bit
3321-3705
3705
4.0.0
4.5.0
{4D36E968-E325-11CE-BFC1-08002BE10318}
{4D36E96C-E325-11CE-BFC1-08002BE10318}
{4D36E97D-E325-11CE-BFC1-08002BE10318}
4ID check OK
; 64 bit
; Action list for audio-only install
; Action list for GFX coinstaller
; Action list for MSDK install
ACTIONS
Adding registry value = %s
Adding '%s' to '%s' env variable
AddPowerSetting
Admin rights OK
allowmulti
allowmulti=
amd64
AMD64
AND 
An error occurred during driver scan so the extracted files may not be complete [0x%X]
apiversion
  APIVersion = %s
ARP=1
Attempting to update previous uninstall info
AUDIO
AUDIO	COINSTALL
; Audio driver
AudioVer=%getdriverversion(HDMI)%
auto
autorun.inf
B016A
B3.0.1 (IIF2++)
{B32CB6D5-61BD-49c8-AA8A-8B790D3B9008}
Badly formed MUI name
Badly formed MUI name on %s
Base destination folder: %s
B%d.%d.%d.%d
;; Begin Media SDK
bin=
bin=igfxsrvc.exe
bin=igfxtray.exe
bin=%MSDKDEST20%\mfx_mft_h264vd_32.dll
bin=%MSDKDEST20%\mfx_mft_h264ve_32.dll
bin=%MSDKDEST20%\mfx_mft_mp2vd_32.dll
bin=%MSDKDEST20%\mfx_mft_vc1vd_32.dll
bin=%MSDKDEST20%\mfx_mft_vpp_32.dll
bin=%MSDKDEST30%\mfx_mft_h264vd_32.dll
bin=%MSDKDEST30%\mfx_mft_h264ve_32.dll
bin=%MSDKDEST30%\mfx_mft_mp2vd_32.dll
bin=%MSDKDEST30%\mfx_mft_vc1vd_32.dll
bin=%MSDKDEST30%\mfx_mft_vpp_32.dll
;bin=%ProgFilesDir%\Intel\Intel(R) Integrated Clock Controller Service\Uninstall\Setup.exe
;bin=%source%\ICCS\SetupICCS.exe
bin=%system64%\regsvr32.exe
BService did not respond to the stop command. Will force close
.cab
Check Fail.  
Check Fail.  Found ID: %d , Min ID: %d
Checking 4 part DID's
Checking driver store for driver package
Checking for admin rights
Checking for downgrading
Checking for existing power profiles
Checking for previously installed driver package
Checking INF versions
Checking .NET configuration
Checking OS
Checking requirements
Check Pass.  
Check Pass.  Found ID: %d , Min ID: %d
Chipset
ClassGUID
ClassGUID = %s
Cleanup
; Cleanup 1.5 in case it was previously installed
; Cleanup 2.0 in case it was previously installed
Cleanup is being skipped
Code
coin
-coin
COINSTALL
command
command=%installDir%\Uninstall\setup.exe -uninstall
commandline
commandline=
commandline=/s "%MSDKDEST2064%\mfx_mft_h264vd_64.dll"
commandline=/s "%MSDKDEST2064%\mfx_mft_h264ve_64.dll"
commandline=/s "%MSDKDEST2064%\mfx_mft_mp2vd_64.dll"
commandline=/s "%MSDKDEST2064%\mfx_mft_vc1vd_64.dll"
commandline=/s "%MSDKDEST2064%\mfx_mft_vpp_64.dll"
commandline=/s "%MSDKDEST3064%\mfx_mft_h264vd_64.dll"
commandline=/s "%MSDKDEST3064%\mfx_mft_h264ve_64.dll"
commandline=/s "%MSDKDEST3064%\mfx_mft_mp2vd_64.dll"
commandline=/s "%MSDKDEST3064%\mfx_mft_vc1vd_64.dll"
commandline=/s "%MSDKDEST3064%\mfx_mft_vpp_64.dll"
commandline=/s /u "%MSDKDEST2064%\mfx_mft_h264vd_64.dll"
commandline=/s /u "%MSDKDEST2064%\mfx_mft_h264ve_64.dll"
commandline=/s /u "%MSDKDEST2064%\mfx_mft_mp2vd_64.dll"
commandline=/s /u "%MSDKDEST2064%\mfx_mft_vc1vd_64.dll"
commandline=/s /u "%MSDKDEST2064%\mfx_mft_vpp_64.dll"
commandline=/s /u "%MSDKDEST3064%\mfx_mft_h264vd_64.dll"
commandline=/s /u "%MSDKDEST3064%\mfx_mft_h264ve_64.dll"
commandline=/s /u "%MSDKDEST3064%\mfx_mft_mp2vd_64.dll"
commandline=/s /u "%MSDKDEST3064%\mfx_mft_vc1vd_64.dll"
commandline=/s /u "%MSDKDEST3064%\mfx_mft_vpp_64.dll"
;commandline=/uninstall
Comments
commonappsdir
commonappsdir64
commonappsdircuros
commondesktop
CommonProgramW6432
CommonStartMenu
CompanyName
Compile date = %s
condition
condition=Is64
condition=Is64 AND IsOS(VISTA,0x060001FF)
condition=Is64 AND IsOS(WIN7,MAXOS)
condition=IsOS(VISTA,0x060001FF)
condition=IsOS(WIN7,MAXOS)
config.ini
config.ini not found
Configuring uninstallation
copy
; Copy all files on Win7+
  Copy file error (0X%X) on source = %s. Trying again.
Copy file error on source = %s, aborting
  Copying file %s
  Copying to folder: %s
copyonly
Copyright 2011, Intel Corporation
Core Version = %s
  Could not retrieve existing installation path. Installation may be broken
Courier New
; CPHS removal
create
Created MUI localized name for %s
createonly
Creating folder %s
Custom
Custom action
Custom action is NULL
custom.ini
{%%%d}
<<< %d/%02d/%d %02d:%02d:%02d:%03d
>>> %d/%02d/%d %02d:%02d:%02d:%03d
{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}
data
data=%MSDKDEST2064%\libmfxhw64-s1.dll
data=%MSDKDEST20%\libmfxhw32-s1.dll
data=%MSDKDEST3064%\libmfxhw64-i2.dll
data=%MSDKDEST30%\libmfxhw32-i2.dll
data=%system%
data=x1
data=x8086
data=x%GFX_HWID%
data=x%MSDK_APIVERSION%
data=x%MSDK_MERIT%
Date = %s
DAUDIO
decompress
Decompressing %s to destination
(default)
delay
Deleted a shortcut; checking for empty parent folders
Deleted folder %s
  Delete error 0x%X
Delete error 0x%X, marking for delete on next reboot
delete_if_not_empty
delete_if_not_empty=
delete_if_not_empty=no
delete_if_not_empty=yes
delete_if_not_empty=YES
deleteoninstall
deleteonuninstall
Deleting file %s
Deleting file: %s
Deleting folder %s
Deleting Key = %s
Deleting [%s]
Deleting %s
Deleting service: %s
Deleting value = %s
demand
dependencies
description
description_mui
Description = %s
Description: %s
desktop.ini
  Dest file time: %s
destination
destination=%commonappsdir64%\Intel
destination=%commonappsdir64%\Intel\Media SDK
destination=%commonappsdir64%\Intel\Media SDK\i1
destination=%commonappsdir64%\Intel\Media SDK\i2
destination=%commonappsdir64%\Intel\Media SDK\s1
destination=%commonappsdir%\Intel
destination=%commonappsdir%\Intel\Media SDK
destination=%commonappsdir%\Intel\Media SDK\i1
destination=%commonappsdir%\Intel\Media SDK\i2
destination=%commonappsdir%\Intel\Media SDK\s1
  Destination file is read-only, clearing attributes
destination=%installDir%\uninstall
destination=%installDir%\uninstall\Setup.exe
destination=%installDir%\uninstall\x64
destination=%installDir%\uninstall\x64\Drv64.exe
destination=%MSDKDEST15%
destination=%MSDKDEST1564%
destination=%MSDKDEST20%
destination=%MSDKDEST2064%
destination=%MSDKDEST2064%\libmfxhw64-s1.dll
destination=%MSDKDEST20%\libmfxhw32-s1.dll
destination=%MSDKDEST30%
destination=%MSDKDEST3064%
destination=%MSDKDEST3064%\libmfxhw64-i2.dll
destination=%MSDKDEST30%\libmfxhw32-i2.dll
    Destination: %s
Destination = %s
destination=%system64%\difxapi.dll
destination=%system%\difxapi.dll
destination=%system%\igfxsrvc.exe
destination=%system%\igfxtray.exe
destination=%windir%\system32\iglhcp32.dll
destination=%windir%\system32\IntelCpHeciSvc.exe
  Dest version: %s
Detected a downgrade
DEV_
Device found. Full HWID is %s
Device removed succesfully
Device was not found
Dialog creation error 0x%X. Resource file may be missing or corrupt
Didn't find any INF's that match active hardware
disabled
display
DisplayIcon
display_mui
display_mui=@%installDir%\Uninstall\Setup.exe,-1166
display_mui=@%installDir%\Uninstall\Setup.exe,-2550
DisplayName
DisplayName_Localized
display=%product%
DisplayVersion
DLL1
Does not exist, skipping
DPPE
Driver
DriverDate
DriverDesc
 -driverinf "
Driver install was cancelled, continuing with the rest of the installation.
DriverPackageInstall error 0x%X
DriverPackageInstall - Platform not Vista or higher
Driver package not found in driver store (0x%X)
Driver package successfully removed from driver store
Driver %s not found, ignoring
Driver uninstalled successfully: %s
Driver uninstall error 0x%X
DriverVer
DriverVersion
dump
Dumping action list to %s
duringinstall
duringuninstall
DVCLAL
Eccs=
Effective command line = %s
; End Media SDK ;;
en-US
Environment
Environment variable
EnvVar
error
error=
  Error: 0x%X
Error 0x%X
Error 0x%X creating service
Error 0x%X creating value
Error 0x%X deleting %s
Error 0x%X from SetupGetLineText(), ignoring
Error 0x%X installing service
Error 0x%X launching Drv64.exe
Error 0x%X. Marking %s for deletion after reboot
Error 0x%X occurred while setting MUI name
Error 0x%X opening
Error 0x%X opening service %s
Error 0x%X removing service
Error 0x%X retrieving a Manufacturer line. Skipping inf
  Error 0x%X retrieving folder contents
Error 0x%X updating service
Error 0x%X while creating progress dialog box
Error 0x%X while creating uninstall progress dialog box
Error 0x%X while deleting
Error 0x%X while starting service
Error 0x%X while stopping service
Error creating uninstall key 0x%X
Error during decompressing %d
Error enumerating GFX devices (0x%X)
*Error extracting files. (0x%X)
;error=ignore
error=ignore
Error in command line: %s
Error in Manufacturer section, ignoring
Error in preparing to remove device. Error=0x%X
Error loading action file
Error loading resource action file
Error loading string ID %d
Error locating a device section. Skipping inf
Error obtaining attached HW device list (0x%X)
Error obtaining device data. Error=0x%X
Error occured while uninstalling driver package (0x%X)
Error removing device. Error=0x%X
Error removing service (0x%X)
  Error retrieving GFX install info. Error: 0x%X
  Error retrieving ICC install path. Error: 0x%X
Error retrieving service configuration (0x%X)
  Error while attempting to register (0x%X)
Error while updating environment variable. (0x%X)
estimatedsize
EstimatedSize
estimatedsize=76000
Execute command: %s
Execute failed 0x%X
Executing '%s %s'
    Existing installed INF is Inbox/Chipset INF/NULL driver. Skipping version check
Exit code = 0x%X
Exit code: 0x%X
Exit test mode
extract
Extract
extract_all
extractdrivers
Extract error 0x%X
  Extracting %S
Extracting to %s
{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
Failed to create DC. Error code: %lu
failure
{FEA3413E-7E05-4911-9A71-7003-31F1-C294}
File
[File]
FileDescription
file.dll
  File exists, skipping
file.inf
  File in use, setting copy on boot
  File locked, marked for delete on next reboot (Error = 0x%X)
  File skipped, destination file is same or newer
FileVersion
Filter Active
Filter conditions
Filtering components per group
Finding drivers
FindNextFile returned an unexpected error. Ignoring error
Firmware Recovery Agent\UpdateAgent-setup.msi
Fjjj
 -flags 
Flags: Wait=%s Hidden=%s
Folder
[Folder]
^ folder already deleted
Force closing the service
forcetbt
Found INF = %s
Found inf uninstall entry. Replacing [%s]
getdriverversion
getstring
getswitch
gfile.abc
GFX=1
GFX_HWID
GFX HWID could not be located
GFX HWID detect
GFX HWID: %s
GFX HW not found; disabling HDMI driver install
GFXVer=%getdriverversion(GFX)%
Global\IIF-
group
group=
group=HDMI
;group=ICCS
group=MSDK20
group=MSDK30
groups
[Groups]
Groups: %s
                                 H
         (((((                  H
HardwareID = %s
HasNET
HDAUDIO
HDMI
HDMI=1
Hex string should be even
         h((((                  H
hide
hide=
;hide=yes
hive
hive=
hive=64
HKCR
HKCU
HKLM
HKLM\SOFTWARE\TEST\value=data
hwid
hwid=
 -hwnd 
ia64\Drv64.exe
ICC installer found at: %s
ICC installer not found
; ICCS   ;
ICC\setupICC.exe
ICC\SetupICC.exe
ICCS=IfExists("%source%"\ICCS\SetupICCS.exe) AND IsOS(VISTA,MAXOS)
ICCS installer exit code: %d
ICCS installer launch failure: 0x%X
\..\ICCS\SetupICCS.exe
ICC will be installed
ICC will NOT be installed
icon
icon=%installDir%\Uninstall\Setup.exe,0
IfDrvExists
IfExists
ifnewer
ifnotexists
ifNotexists
ignore
IIF will NOT initiate reboot
iips
IIPS
IIPS driver install
IIPS filter
IIPS is already installed and will be uninstalled
.inf
[inf]
\inf\
inf=
inf20000
  INF does not contain DPPE settings
INF has wrong INF style
INF Info
InfPath
INF = %s
INF: %s
InfSection
Inf supports 64 bit.
inf=%s|usequence=20000|group=GFX||
Initiating reboot
install
 -install
Install
install.cfg
InstallConfig
Install Configuration
installDir
installDir=%ProgFilesDir%\Intel\%product%
installeddir
Installed driver is better match for the device
Installed Driver = %s
Installed driver uses 4IDs and installing driver uses less. Get driver from manufacturer website.
    Installed INF info: Name=%s, Provider=%s, Section=%s
Installed Package = %s
    Installed version: %s
Installer Version: %s
InstallICC
Installing %s
Installing service %s
InstallLocation
InstallPath
InstallSuccess
Intel Control Center\setupICC.exe
Intel Control Center\SetupICC.exe
Intel Corporation
Intel\ExtremeGraphics
Intel\ExtremeGraphics\CUI\Resource
IntelGFX.log
Intel\Logs
Intel(R) HD Graphics
Intel(R) HD Graphics installer
InternalName
Invalid OS
Invalid path in command '%s'
Invalid service type
Invalid start type
Is64
IsCmd
IsGroupSel
IsIA64
IsLang
IsOS
IsVar
IsWinN
jjjj
jjjjj
kernel32
Kernel32.dll
 -keypath "
lang
Lang
langid
Languages
Launching %s
Launching with command line:%s
LegalCopyright
LegalTrademarks
LICENSE
license.txt
.lnk
Loaded language %04X
location
location=%installDir%
LogPath
Looking for existing IIPS-only installation
Looking for ICC installer
Looking for MediaSDK configuration %s
LRCDATA
MAINICON
MAINICON(
Manufacturer
Manufacturer = %s
Marking folder %s for delete on uninstall
Marking folder %s for deletion after reboot (result=0x%X)
Marking registry value %s for deletion during uninstallation
Marking service %s for stop on uninstall
Marking %s for delete during uninstallation
Marking [%s] for deletion on reboot
Marking %s to run when uninstalled
Marking %s to terminate when uninstalled
Matched HardwareID = %s
MAXOS
MediaSDK
; Media SDK 2.0 ;;
; Media SDK 3.0 ;;
merit
  Merit = %s
Microsoft
mode
mode=ifnewer
mode=overwrite
modify
modify=no
Mon Oct  3 17:09:30 2011
msdk
MSDK
MSDK15=IsVar(MSDK_SRC,ILK)
MSDK20=IsVar(MSDK_SRC,SNB)
MSDK30=IsVar(MSDK_SRC,IVB)
MSDK_APIVERSION
MSDKDEST1564=%commonappsdir64%\Intel\Media SDK\i1\1.5
MSDKDEST15=%commonappsdir%\Intel\Media SDK\i1\1.5
MSDKDEST2064=%commonappsdir64%\Intel\Media SDK\s1\2.0
MSDKDEST20=%commonappsdir%\Intel\Media SDK\s1\2.0
MSDKDEST3064=%commonappsdir64%\Intel\Media SDK\i2\3.0
MSDKDEST30=%commonappsdir%\Intel\Media SDK\i2\3.0
MSDK_MERIT
MSDK_SRC
MSDKSRC64=%source%\MediaSDK\%MSDK_SRC%\x64
MSDKSRC=%source%\MediaSDK\%MSDK_SRC%\win32
msls31.dll
mui%d
myService
name
name=
Name
name=CPHS
name={F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}
name=HDMI
Name = %s
.NET check failed
.NET check OK
NetRange
noarp
No devices found for driver. Skipping uninstall of previous driver.
nodncheck
nodrv
NO_DRV
nodrv switch specified, skipping install of %s
nodrv switch specified, skipping removal of %s
No existing IIPS-only installation found
nogfxdrv
nohwfilter
noicc
-noicc switch found, skipping ICC install
-noicc switch found, skipping ICC uninstall
noinfscan
noinstall
nolic
NoModify
nooscheck
  No power profiles found
No previous INF was found
  No previous version found
noread
NoRepair
nosc
NOT 
Not in silent mode, ignoring -b switch
nowel
nowinsat
(null)
okernel32.dll
; On Vista copy main DLL only
operation
operation=
operation=copy
operation=copyonly
operation=create
operation=createonly
operation=deleteoninstall
operation=deleteonuninstall
operation=reg
operation=regonly
operation=removeonuninstall
;operation=runonly
operation=runonly
;operation=runonuninstall
operation=runonuninstall
Operation = %s
operation=stoponuninstall
OriginalFilename
OS check OK
OS command line = %s
OS not Vista or better, ICC would not be installed
OS not Vista or better, skipping ICC install
OS not Vista or better; skipping MUI localizing
over4id
overwrite
-overwrite switch found; forcing downgrade
Package does not contain ICCS installer
Package error
PackageInfo
PACKAGEINFO
PackageInfo.Name = %s
PackageInfo.Sequence = %d
Package Requires Reboot = %s
Parsing %s for power settings
path
path=
pathmui
Path = %s
path=SOFTWARE\Intel
path=SOFTWARE\Intel\Display
path=SOFTWARE\Intel\MediaSDK
path=SOFTWARE\Intel\MediaSDK\Dispatch
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw32-i1-1
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw32-i2-1
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw32-s1-1
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw64-i1-1
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw64-i2-1
path=SOFTWARE\Intel\MediaSDK\Dispatch\hw64-s1-1
path=SOFTWARE\Microsoft\Windows\CurrentVersion\Run
path=SOFTWARE\Microsoft\Windows Media Foundation\HardwareMFT
path=System\CurrentControlSet\Control\Windows
path=System\CurrentControlSet\Services\ialm\Device0
path=System\CurrentControlSet\Services\ialm\Device1
pause
Pause
Pausing for %d ms
period
period=
Platform = 32 bit
Platform = 64 bit
Platform = Itanium
Platform: %s
PowrProf.dll
Preparing to remove device
Previous INF is not on disk
Previous INF = %s
process
process=
Process
;[Process]
[Process]
Processing -v switch
Process is not running
Process returned 0x%X
Process %s is not active
Process still active, terminating
Process won't terminate
product=Intel(R) Display Audio Driver
product=Intel(R) Processor Graphics
Production
Product key: %s
ProductName
ProductVersion
progdata
progfilescuros
progfilesdir
progfilesdir64
programstartmenu
ProgramW6432
ProviderName
publisher
Publisher
publisher=Intel Corporation
 -rdev "
Reading action file %s
Reading action list from resource: %s
Reading config.ini
Reading section %s
readme.txt
Reboot
Recursively deleting folder %s
RegisterCOM
[RegisterCOM]
Register COM
Registering DLL '%s'
registry
Registry
[Registry]
regonly
remove
removedevice
Removed INF = %s
Removed %s
removeonuninstall
Removing device %s
Removing existing IIPS installation
Removing existing IIPS-only installation folder
Removing existing IIPS product registry key
Removing existing IIPS product uninstall entry
Removing ICC
  Removing power profile:
Removing service %s
Removing '%s' from '%s' env variable
repair
repair=no
report
 -report 
RequestedBPP
RequestedRate
RequestedXRes
RequestedYRes
RequestSig
r  Error while attempting to unregister (0x%8X)
Resolution switch format incorrect
Resolved Manufacturer = %s
resource
ResultCode = %d
Riched20.dll
root
root=
root=HKLM
.rtf
runonly
runonuninstall
  %s
[%s]
'%s' at line %d. Condition = %s
'%s' at line %d. Group = %s
  Saved DPPE settings not configured correctly
Scanning drivers
Scheduling %d ms pause to occur during uninstallation
[%s - %d]
%s%d
  SDK version = %s
Section <%s> Key <%s> not found in INF
Sending quit message
Sending quit message to process %s
sequence
Sequence
sequence=100
sequence=105
;sequence=1061
sequence=110
sequence=115
sequence=120
sequence=200
sequence=260
sequence=265
sequence=270
sequence=275
sequence=280
sequence=285
sequence=290
sequence=295
sequence=297
sequence=-3
sequence=300
sequence=305
sequence=310
sequence=315
sequence=320
sequence=325
sequence=400
sequence=405
sequence=410
sequence=415
sequence=420
sequence=425
sequence=485
sequence=490
sequence=495
sequence=500
sequence=505
sequence=510
sequence=515
sequence=520
sequence=525
service
Service
[Service]
Service already exists. Updating configuration
Service is not running
servicename
servicename=
servicetype
SeShutdownPrivilege
setting
    Setting: %s
  Setting: %s
setup
Setup
setup2.if2
SetupDiGetClassDevs generated an unexpected error. Ignoring error
SetupDiGetINFClass generated an unexpected error. Ignoring error
Setup.exe
SetupGetLineText generated an unexpected error. Ignoring error
SetupGetStringField generated an unexpected error. Ignoring error
setup.if2
shared
shell32.dll
Shortcut
Shortcut error 0x%X
Silent mode does not allow downgrade
SOFTWARE\Intel
Software\Intel\Difx64
SOFTWARE\Intel\Display\igfxcui\igfxsrvc\FactoryInstall
Software\Intel\GFX
SOFTWARE\Intel\GFX\Uninstall
Software\Intel\ICCInst
Software\Intel\IIPS
SOFTWARE\Microsoft\.NETFramework\policy\v1.0
SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322
SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727
SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.0\Setup
SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5
SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client
SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
Software\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}
Sorting action list for installation
source
  Source file time: %s
source=%MSDKSRC%
source=%MSDKSRC64%
source=%MSDKSRC64%\libmfxhw64-i2.dll
source=%MSDKSRC64%\libmfxhw64-s1.dll
source=%MSDKSRC%\libmfxhw32-i2.dll
source=%MSDKSRC%\libmfxhw32-s1.dll
    Source: %s
  Source: %s
Source = %s
source=%setup%
source=%source%\difx32.dll
source=%source%\difx64.dll
source=%source%\Difx64.exe
source=%source%\difxapi.dll
source=%source%\igxpun.exe
source=%source%\lang
source=%source%\x64\difxapi.dll
source=%source%\x64\Drv64.exe
  Source version: %s
Spawn result: 0x%X
start
Starting service %s
startmenu
starttype
stop
stoponinstall
stoponuninstall
Stopping process %s
Stopping service %s
Store location (%s)
StorePath
StringFileInfo
Subgroup
  Subgroup: {FEA3413E-7E05-4911-9A71-7003-31F1-C294} (Default)
    Subgroup: %s
  Subgroup: %s
success
'%s' will be removed from '%s' env variable during uninstallation
Switchable graphics; skipping 4 part ID check
Syntax error found in condition
system
system64
systemcuros
System\CurrentControlSet\Control\Class\
SYSTEM\CurrentControlSet\Control\Session Manager\Environment
SYSTEM\CurrentControlSet\Services\ialm\device0
System up time = %d sec
SysWOW64\Kernel32.dll
Tahoma
target
Target = %s
Target: %s
TargetVersion
temp
Test mode
; These actions run on uninstall ;;
The version of the driver just installed is the same as the one that was previously installed. Skipping uninstall of previous driver
This is DT (%s), IIPS install disabled
    Transfering source file security
Translation
type
type=dw
type=sz
  Unable to find entry point
  Unable to load DLL (0x%X)
UNICODE
uninst
uninstall
 -uninstall
Uninstall
[Uninstall]
\Uninstall
Uninstall does not require a reboot
uninstaller\SetupICC.exe
Uninstalling previous driver package, if any
Uninstalling previous driver package (%s)
Uninstall key format error
Uninstall key: %s
Uninstall requires a reboot
Uninstall\Setup.exe
UninstallString
<Unknown>
(Unknown)
Unknown variable [%s], ignoring
Unrecognized OS name in condition
Unregister COM
Unregistering DLL '%s'
Unsupported root key
usequence
usequence=
usequence=-10
usequence=10001
usequence=11000
usequence=12000
usequence=200
usequence=20010
usequence=20020
usequence=20040
usequence=20060
usequence=20080
usequence=20100
usequence=205
usequence=210
usequence=213
usequence=215
usequence=220
usequence=225
usequence=230
usequence=235
usequence=240
usequence=245
usequence=250
usequence=310
usequence=325
usequence=330
usequence=335
usequence=340
usequence=345
usequence=350
usequence=355
usequence=405
usequence=410
usequence=415
usequence=420
usequence=425
usequence=450
usequence=455
usequence=460
usequence=465
usequence=470
;usequence=471
usequence=510
usequence=515
usequence=520
usequence=525
usequence=530
usequence=535
usequence=540
usequence=545
usequence=-9
User canceled wizard
User cancelled dialog
userdata
User default LangID: 0x%X
User default UI language: 0x%X
User is not an admin
User refused downgrade
Using setup.exe for strings
UTF-16LE
UTF-8
-v "
/v "
value
value=
value=APIVersion
value=DeviceID
value=EnableDecoders
value=EnableEncoders
value=EnableVideoProcessors
value=HotKeysCmds
value=IgfxTray
value=Merit
value=Path
value=Persistence
value=SystemDirectory
value=VendorID
VarFileInfo
variables
[Variables]
VEN_8086
version
Version
version=%AudioVer%
version=%GFXVer%
    Version in package: %s
versionmajor
VersionMajor
versionminor
VersionMinor
Version = %s
Vista
VISTA
VISTA_MAXSP
VISTA_SP1
Vista-x64
Vista-x86
VS_VERSION_INFO
W2K3-x64
W2K3-x86
W2K8-x64
W2K8-x86
Wadvapi32.dll
wait
wait=
;wait=yes
wait=yes
Warning: Folder %s still exists after delete
WIN2003
WIN2008
WIN2008_MAXSP
WIN2008_R2
WIN2008_R2_MAXSP
WIN2008_SP1
WIN2K
WIN2K_SP1
WIN2K_SP2
WIN2K_SP3
WIN2K_SP4
WIN7
WIN7_MAXSP
WIN7_SP1
WIN8
WIN8_MAXSP
windir
Windows 
Windows7-x64
Windows7-x86
Windows Version = %s
Winsat will NOT run on reboot
Winsat will run on reboot
WINXP
WINXP64
WINXP_SP1
WINXP_SP2
WINXP_SP3
workdir
workdir=
workingdir
Writing resolution parameters to factory location
Writing resolution parameters to services key
x64\Drv64.exe
XP64
XP-x64
XP-x86
                          
                                                           
                                                                                  
                        />
,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,
........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
	#<$%'&"
0123456789ABCDEF
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 0?42024
0A@@Ju
0CHJ@$
0DASJ#H
0e4JH2G
0m4D*EQp
0SSSSS
0USize
0VVVVV
0WWWWW
[0Y0W0U
100208000000Z
110308000000Z
121018000000Z
121221000000Z
*1+=3v
140131002202Z0#
140422235959Z0
1%(6>%
1a"+}Z
<1#+c~
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
1cSZ&a
1#QNAN
1#SNAN
200207235959Z0
201229235959Z0b1
201230235959Z0^1
2Q/=c$
2Terms of use at https://www.verisign.com/rpa (c)101.0,
3Uin_2k
.(!+41jjDL^
^49n,r
4~f9.u
4kL433{
4P9L$`
4P9L$8
4P9L$D
4P9L$T
|$4tAj
5Digital ID Class 3 - Microsoft Software Validation v21
_?5FLj|3
5jKV=F
'5{RRM
5UInject
'6"08z
6I{W{+
6uCXC<G
=% <76"<
:77-B>>
=7@/[F
.'(8/)
8^K9VK9
8lLrQ|gy
8\$Lt1j
8mlhkQ3
!8\$pt
;8u(Vj
;8u+Vj
8VVVVV
8Z<uB9|$L
|$$9|$
9^8t#8^=u
9D$ }>
9D$0r	
9D$,r	
9l$hr6
9l$Ltj9|$P
9l$`rH
9Mzw(d
^@9n8r
^\9nTr
9Q<u#P
9t$ }B
	9t$Tr
9t$,uB
AAf91u
AAGGf;
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AdjustTokenPrivileges
AdjustWindowRect
advapi32.dll
ADVAPI32.dll
%aL16cL
america
american
american english
american-english
An application has made an attempt to load the C runtime library incorrectly.
    </application>
    <application>
</assembly>
                        <assemblyIdentity
  <assemblyIdentity version="1.0.0.0"
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> 
<at9<rt,<wt
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
.?AUctype_base@std@@
August
aUnitHookType
australian
.?AVbad_alloc@std@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AV?$basic_filebuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ofstream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AVCCabinetExtract@@
.?AVCCabinetExtractBase@@
.?AVCCabinetExtractLog@@
.?AVCCabinetMemoryExtract@@
.?AVCExtractThread@@
.?AVCFindLanguages@@
.?AVCFolderRecurse@@
.?AVCGFXInstaller@@
.?AVCInstaller@@
.?AVCInstallExtractor@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@_WDH@std@@
.?AVCSafeDeleteTree@@
.?AVCShellFileCount@@
.?AV?$ctype@_W@std@@
.?AVexception@std@@
.?AVfacet@locale@std@@
.?AVfailure@ios_base@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AVlength_error@std@@
.?AV_Locimp@locale@std@@
.?AVlogic_error@std@@
.?AV?$numpunct@_W@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AVout_of_range@std@@
.?AVruntime_error@std@@
.?AVtype_info@@
AXGk3xU
bad allocation
bad cast
bad exception
 Base Class Array'
 Base Class Descriptor at (
__based(
@@BBf;
BBFFf;
BeginUpdateResourceA
belgian
B;/>jD
-bom	.
BOoIo{u
britain
b*-u<\#*
b{Vk0DjV
#&%&!@@C
C0)0)t$0
C4)0)t$,
Cabinet.dll
California1
canadian
Cardinal
 CCGGf
__cdecl
cE^-A]"
,Cgh;e71\
ChangeServiceConfig2W
ChangeServiceConfigW
CharNextA
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
 {*'`CJ
 Class Hierarchy Descriptor'
CloseHandle
CloseServiceHandle
__clrcall
CLSIDFromString
 CO;72
CoCreateInstance
CoInitialize
CommandLineToArgvW
CompareFileTime
CompareStringA
  </compatibility>
	<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
 Complete Object Locator'
CONOUT$
ControlService
ConvertDefaultLocale
`copy constructor closure'
CopyFileA
CopyFileW
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
CorExitProcess
Corrupt Data!
CoUninitialize
C PjPV
C$PjQV
C.PjRV
C/PjSV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
cPR&tgb
CreateCompatibleDC
CreateDirectoryA
CreateEventW
CreateFileA
CreateFileMappingA
CreateFileW
CreateFontW
CreateMutexW
CreateProcessA
CreateProcessW
CreateServiceW
CreateThread
CreateToolhelp32Snapshot
CreateWindowExA
- CRT not initialized
CSendMail
C<"u1S
c_yFl-
D$0Ph`
D$0Ph 
D$0Ph,
D$0PVh
D$0PWWh
D$0SUVW
D$0SVW
D$0VSj
D$0XeE
D$4PWWh
D6(1Pb
D$8deE
D$8QPh
D$8SVW
D$8XeE
D$$9|$(
D$$9D$
D$(9\$\r
D$$9t$T
@.data
" dCcnaT4
d:\ccViews\autobuild1_BR-1401-003D_14.56_Snapshot\WorkingDirectory1\HDMIInstaller\1.4.28\Installer\HDMI\Release\setup.pdb
D$ ;D$$
D$ +D$
D$,+D$$
dddd, MMMM dd, yyyy
D$dPWUSU
D$DQVRPW
D$dSUVW
D$DSUVW
December
DecodePointer
`default constructor closure'
DefWindowProcA
 delete
 delete[]
DeleteCriticalSection
DeleteDC
DeleteFileA
DeleteFileW
DeleteObject
DeleteService
<dependency>
        </dependency>
                </dependentAssembly>
                <dependentAssembly>
D$HPjA
D$HQRP
D$hSUVW
D$HSUVW
D$HSUVWh
D$HSVW
DialogBoxIndirectParamW
DialogBoxParamW
diFHSjc
DIFXAPI.dll
DIFXAPISetLogCallbackW
DispatchMessageA
"DJozS=
D$,j V
DllRegisterServer
DllUnregisterServer
D$lPhH
D$LPhh
D$LSUVW
DOMAIN error
DosDateTimeToFileTime
D$<Ph 
D$$Ph?
D$\Ph(
D$ Pj@h
D$<PQR
D$,PQVW
D$ PSh?
D$(PSSh
D$pSUVW
D$PSUVW
D$PSVW
D$ pTC
D$<PUj
D$ PVUj
D$\PVUWU
D$$PVVh
D$`QPh
D$(QRP
D$*QRPh(
D> _^r
DrawTextW
DriverPackageGetPathW
DriverPackageInstallW
DriverPackageUninstallW
D$<SUV
D$$SUV
D$ SUVW
D$(SUVW
D$@SUVW
D$`SUW
D$(SVW
D$@SVW
D$$SVW
D$TUUP
D$ u@9\$|r
DuplicateHandle
Durbanville1
dutch-belgian
D$\UUVU
D$ UVW
D$,UVW
D$$WPWU
D$,XeE
D$(XeE
D$XPh(
D$XSUVW
D$xSVW
`dynamic atexit destructor for '
`dynamic initializer for '
|`E6:9
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
EnableWindow
EncodePointer
EndDialog
EndUpdateResourceA
england
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
EnterCriticalSection
EnumProcessModules
EnumResourceLanguagesW
EnumSystemLocalesA
EnumWindows
ERROR!
^eTz,|c}Ol
ExitProcess
ExitWindowsEx
`f	_[ 
)F:5&/ '
@@f90u
@@f98u
__fastcall
February
f			f	
FileTimeToDosDateTime
FileTimeToLocalFileTime
FileTimeToSystemTime
Filtered = 
FindClose
FindFirstFileA
FindFirstFileW
FindNextFileA
FindNextFileW
FindResourceA
FindResourceW
FindWindowA
FindWindowExA
Fi!\WJ<
fjr&ZJ
- floating point not loaded
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
Folsom1
F@^o{*s
FPUMaskValue
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
FreeResource
FreeSid
french-belgian
french-canadian
french-luxembourg
french-swiss
Friday
(f;)u$
)f;*u%
fvH3;Z
fvvggd
	"=':!*G
G0L0t0
GAIsProcessorFeaturePresent
GDI32.dll
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
GetACP
GetActiveWindow
GetClientRect
GetCommandLineA
GetCommandLineW
GetComputerNameA
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetCPInfo
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetDlgItem
GetDriveTypeA
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableW
GetExitCodeProcess
GetFileAttributesA
GetFileAttributesW
GetFileSize
GetFileTime
GetFileType
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFileVersionInfoSizeW
GetFileVersionInfoW
gethostbyname
gethostname
GetKeyboardType
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetLocalTime
GetMessageA
GetModuleFileNameA
GetModuleFileNameExW
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetMonitorInfoW
GetNamedSecurityInfoW
GetNativeSystemInfo
GetOEMCP
GetPrivateProfileStringW
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetProductInfo
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStockObject
GetStringTypeA
GetStringTypeW
GetSystemDirectoryA
GetSystemDirectoryW
GetSystemInfo
GetSystemTimeAsFileTime
GetSystemWow64DirectoryW
GetTempFileNameA
GetTempFileNameW
GetTempPathA
GetTempPathW
GetTextExtentPoint32W
GetThreadContext
GetThreadLocale
GetTickCount
GetUserDefaultLangID
GetUserDefaultLCID
GetUserDefaultUILanguage
GetUserObjectInformationA
GetVersion
GetVersionExA
GetVersionExW
GetWindowLongW
GetWindowModuleFileNameW
GetWindowRect
GetWindowsDirectoryA
GetWindowsDirectoryW
GetWindowTextA
GetWindowThreadProcessId
	gg1+l
 GGBBf;
	ggg4M
Gggfv@
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
GMMSystem
Gnow;9<<
 goto try1
 goto try2
gpI`wnskG[|Fz
`~GPMu
great britain
`h````
H49|$l
<H9l$X
hD,Z?u2JL}
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
hfdjk|T(
`h`hhh
HH:mm:ss
HHtAHHt
hiY|vd
|$H;|$L
\$$h N
holland
hong-kong
.http://crl.thawte.com/ThawteTimestampingCA.crl0
#http://crl.verisign.com/pca3-g5.crl04
/http://csc3-2010-aia.verisign.com/CSC3-2010.cer0
/http://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
#http://logo.verisign.com/vslogo.gif04
http://ocsp.thawte.com0
http://ocsp.verisign.com0
http://ocsp.verisign.com0;
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
http://ts-ocsp.ws.symantec.com07
Hu(xsR
.idata
IDATkT
  <!-- Identify the application security requirements. -->
if exist "
ihg'--,D
&I}	j3
(i@KXpZ@S[A
	image/gif0!0
inet_ntoa
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
Intel Corporation0
Intel Corporation1>0<
InterlockedCompareExchange
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
invalid map/set<T> iterator
invalid string position
IO:#J"4sMxBg
ios_base::badbit set
ios_base::eofbit set
ios_base::failbit set
irish-english
IsBadReadPtr
IsDebuggerPresent
IsTextUnicode
IsValidCodePage
IsValidLocale
IsWow64Process
ISWQL1
italian-swiss
JanFebMarAprMayJunJulAugSepOctNovDec
January
/@JHBCKB`
j`hh!F
j(j ^V
J`Ka{v@
j@PQRj@j
j"^SSSSS
jThP$F
&@&jU{*
\$$jxQ
@:k+3?
K#89RN%p
[kDbJm
KERNEL32
kernel32.dll
KERNEL32.dll
KERNEL32.DLL
KillTimer
k)lBG<
KmXwF*
!k _#u
KWindows
~KxI[)
L$0Qh?
L$0QSS
L$8QRV
^l9ndr
L$|9|$t
\lang\*
                                language="*"
LC_ALL
LC_COLLATE
LC_CTYPE
LCMapStringA
LCMapStringW
LC_MONETARY
LC_NUMERIC
LC_TIME
L$dQhl
LeaveCriticalSection
Lec Ep*
          level="requireAdministrator"
,LH%#1
lhgBQPO
Line = 
list<T> too long
L$ j@Q
l$ jxQ
L$,+L$$+
l$l9D$d
L$LRPQ
[[[lnn
L'#NOO)
LoadCursorA
LoadIconW
LoadImageW
LoadLibraryA
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LoadResource
LoadStringW
LocalAlloc
LocalFileTimeToFileTime
LocalFree
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
LockResource
LookupPrivilegeValueW
L$$Qh?
L$|QRP
L$$QRPS
L$ QRPV
L$,QSS
L$(QSSh
L$$QUh?
L$(QUS
L$$QVVh
L$ QWPh 
L$(RPQ
;l$,t 
L$t9Y8
ltDL!<
l$(t	P
l$@t	P
L$tPVP
;L$,tq
)\$L;t$<v	
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
map/set<T> too long
MapViewOfFile
.~^:me|	
MessageBoxA
MessageBoxIndirectW
MessageBoxW
|m#F9F`
Microsoft Visual C++ Runtime Library
MM/dd/yy
mNXm*s!
Module32First
Module32Next
Monday
MonitorFromWindow
MoveFileA
MoveFileExW
MoveFileW
mpr.dll
mscoree.dll
mTiZCTWf"
MultiByteToWideChar
     name="Installer"
                                name="Microsoft.Windows.Common-Controls"
N`#Df$M
 new[]
new-zealand
NIGHVPN
norwegian
norwegian-bokmal
norwegian-nynorsk
Norwegian-Nynorsk
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
NY>~@y
nyy8|}
>,O8e/
October
OffsetRect
ogbl~us
ole32.dll
oleaut32.dll
`omni callsig'
OpenFileMappingA
OpenProcess
OpenProcessToken
OpenSCManagerW
OpenServiceW
OpenThread
operator
_ _?osQ
@Other
OY8F<s
;\p48\
P5tSU	zQ
<P9l$t
^P9nHr
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGMZ
PAD&=O8
__pascal
PathAddBackslashA
PathAddBackslashW
PathAppendA
PathAppendW
PathCombineW
PathFileExistsW
PathFindExtensionW
PathFindFileNameA
PathFindFileNameW
PathIsDirectoryW
PathIsRootW
PathIsSystemFolderW
PathMatchSpecA
PathRemoveBackslashW
PathRemoveFileSpecA
PathRemoveFileSpecW
PathRenameExtensionW
PathStripPathW
PathStripToRootW
PeekMessageA
P'eId8g
.petite
`placement delete closure'
`placement delete[] closure'
Please contact the application's support team for more information.
portuguese-brazilian
PostMessageA
PostMessageW
PostThreadMessageA
PowerRemovePowerSetting
PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD8
PPPPPPPP
pr china
pr-china
P.reloc
Process32First
Process32FirstW
Process32Next
Process32NextW
                                processorArchitecture="X86"
Program: 
<program name unknown>
P.rsrc
PSAPI.DLL
__ptr64
                                publicKeyToken="6595b64144ccf1df"
puerto-rico
PUhost
- pure virtual function call
pvRE7l
pZDj"r
@Q[#f@
:^QL[Oa
Q			Q			Q
QQQQQ3
QQQQQQ3
QQQQQQS3
QQQQQS3
QQQQSVW3
QQSVWd
QQSVWh
Q<"u8S
QueryPerformanceCounter
QueryServiceConfigW
QueryServiceStatus
qUX\Mz
-@q].xS
^qy#}]
RaiseException
`.rdata
.rdata
ReadFile
RegCloseKey
RegCreateKeyExA
RegCreateKeyExW
RegDeleteKeyExW
RegDeleteKeyW
RegDeleteValueW
RegEnumKeyExW
RegEnumValueW
RegisterClassA
RegOpenKeyExA
RegOpenKeyExW
RegQueryInfoKeyW
RegQueryValueExA
RegQueryValueExW
RegSetValueExA
RegSetValueExW
ReleaseDC
RemoveDirectoryW
        <requestedExecutionLevel
      <requestedPrivileges>
        </requestedPrivileges>
__restrict
ResumeThread
$*;*rI
RSSSSSSPS
RtlUnwind
runtime error 
Runtime Error!
Runtime error     at 00000000
RvrPAD(
RWWWWWWPW
s33333
Saturday
Sb@AB>
`scalar deleting destructor'
s+D6zr
    <security>
       </security>
SelectObject
SendDlgItemMessageW
SendMail
SENdMail
SendMessageA
SendMessageTimeoutW
SendMessageW
September
Sequence = 
SetBkMode
SetDlgItemTextW
SetEndOfFile
SetErrorMode
SetEvent
SetFileAttributesA
SetFileAttributesW
SetFilePointer
SetFileTime
SetFocus
SetHandleCount
SetLastError
SetNamedSecurityInfoW
SetRectEmpty
SetStdHandle
SetTextColor
SetThreadContext
SetTimer
SetUnhandledExceptionFilter
SETUPAPI.dll
\setup.cfg
SetupCloseInfFile
SetupDiCallClassInstaller
SetupDiDestroyDeviceInfoList
SetupDiEnumDeviceInfo
SetupDiGetClassDevsW
SetupDiGetDeviceInstallParamsW
SetupDiGetDeviceRegistryPropertyW
SetupDiGetINFClassW
SetupDiSetClassInstallParamsW
SetupFindFirstLineW
SetupFindNextLine
SetupGetLineTextW
SetupGetStringFieldW
SetupOpenInfFileW
SetWindowPos
SetWindowTextW
SHCreateDirectoryExA
SHCreateDirectoryExW
SHDeleteKeyW
SHELL32.dll
SHGetFolderPathW
SHLWAPI.dll
ShowWindow
SHSetLocalizedName
SING error
SizeofResource
slovak
SOFTWARE\Borland\Delphi\RTL
south africa
south-africa
south korea
south-korea
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
|}?Sqy<
s[S;7|G;w
^SSSSS
StartServiceW
__stdcall
`string'
String
string too long
Sunday
SunMonTueWedThuFriSat
      <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
SuspendThread
SUVWh8
SUVWhl
SUVWj>3
&SuY;Q
swedish-finland
sxxxvfvv@
Symantec Corporation100.
Symantec Corporation1402
'Symantec Time Stamping Services CA - G2
'Symantec Time Stamping Services CA - G20
+Symantec Time Stamping Services Signer - G40
SysAllocStringLen
SysFreeString
SysInit
SysReAllocStringLen
System
SystemTimeToTzSpecificLocalTime
SysUtils2
t09t$(
t0WWWWW
t3$Vhd
T$4RPQ3
T$4RVW
T7TuK!
T$89|$0
T$8RSSSP
;t$8s	
t8v8d3"l(
t$9|$0r
t$,9~4r
t(9|$l
t$,9~lr
t>9l$$t
t*9l$ v
t%9l$$v
t$,9~Pr
t$9|$,r
t^9(uZ
t	@AA;D$
\$(tAj
TArrayString
tb9} u
tcSUVW
t_+D$4
tD9(u@
TerminateProcess
tF9\$hr
t,FMO>
!|th}|
Thawte1
Thawte Certification1
Thawte Timestamping CA0
      <!--The ID below indicates application support for Windows 7 -->
+t HHt
This application has requested the Runtime to terminate it in an unusual way.
__thiscall
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
!This program cannot be run in DOS mode.
This program must be run under Win32
Thread32First
Thread32Next
t>Ht2Ht&
Thursday
TimeStamp-2048-10
TimeStamp-2048-20
Ti+wDE
;|$<tj
tj9\$h
T$$j@R
TlHelp32
TLOSS error
T$LPQR
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
TNKma[Y
TNL:^YV
T$*PQRh
T$P;:r
T$pRUP
t$PWPh|
|$TPWU
tQMBa{zS
tqVUhP
tR99u2
TranslateMessage
trinidad & tobago
T$,Rj<
T$ RPh
T$$RPh?
T$$RPP
T$$RPQ
T$<RPU
T$$RSj
T$ RSSh
T$(RSSh
T$<RSSSP
  </trustInfo>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
T$$RVVh
T$ RWW
T$ RWWh
T$\SPWQR
\$TSWP
<+t(<-t$:
T$ +T$
T$$+T$
<+t'<-t#<0u
t$tPWP
T$TQVRVWV
t$<;t$ u/
t$<;t$ u'
t$<;t$ u(
;t$ u-
;t$ u;
;t$ u.
Tuesday
T$(UQR
;t$,v-
T?vWmf1
t+WWVPV
T$XjlR
T$xRPQ
t$x+t$p3
Type = 
 Type Descriptor'
`typeof'
                                type="win32"
     type="win32"/> 
u89\$ t
u$9]4t
u(9|$hr
u,9]$r
|UaC`V
Uaddress
ub9|$t
Uconst
`udt returning'
#\]>ue
UekgKr
u&f!;f;
#`U%i[
          uiAccess="false"/>
- unable to initialize heap
- unable to open console device
__unaligned
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
UNICODE
uninstall\
united-kingdom
united-states
Unknown exception
UpdateResourceA
UpdateWindow
UQPXY]Y[
URPQQh
user32.dll
USER32.dll
USER32.DLL
UTF-16LE
UTypes
uu9l$D
UUh,eE
u|Vj@h
u,VVWV
v,9l$t
`vbase destructor'
`vbtable'
`vcall'
Vcz^_DEDE
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
vector<T> too long
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
VerifyVersionInfoW
%VeriSign Class 3 Code Signing 2010 CA
%VeriSign Class 3 Code Signing 2010 CA0
<VeriSign Class 3 Public Primary Certification Authority - G50
VeriSign, Inc.1
VeriSignMPKI-2-80
VeriSign Trust Network1:08
VeriSign Trust Network1;09
VerQueryValueA
VerQueryValueW
VerSetConditionMask
                                version="6.0.0.0"
version.dll
VERSION.dll
`vftable'
VirtualAlloc
VirtualAllocEx
`virtual displacement map'
VirtualFree
VirtualFreeEx
VirtualProtect
~virus
v	N+D$
Vr,LsHU
\VS^lec
vVLUIr{=y7se
_VVVVV
W[4M@}
WaitForSingleObject
waveOutGetVolume
waveOutSetVolume
Wednesday
Western Cape1
WideCharToMultiByte
WinExec
winmm.dll
WinSock
}^w{jD
WNetAddConnection2A
WNetCancelConnection2A
WNetCancelConnectionA
WNetCloseEnum
WNetEnumResourceA
WNetOpenEnumA
Wow64EnableWow64FsRedirection
W	,*pL
WriteConsoleA
WriteConsoleW
WriteFile
WriteProcessMemory
WSACleanup
WSAStartup
wsock32.dll
wsprintfA
wsprintfW
wU%)lH#E
wws333
wwwws0
^WWWWW
^x9npr
xiYU~f
xiYU|f
xiYUzf
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
xppwpp
xpxxxx
XRP^oig
!X=|t.
xxgfvt
Y`4.Ox
Y9>t7j
^y@)*b
>=Yt/j
YVmgjYgr
(YXYXZt
_^[YY]
YYu-9D$
YYu	9F
YYuTVWh
YZ]_^[
zdP?U	5Q
ZrutR`
ZRu$XR<#B
zukSSS
|zy%PONu(((~
ZZ@qmOB