Analysis Date2014-03-10 02:28:33
MD519a917cc96808851c332b37df15003d5
SHA1fb3a74ff4ded7ed91aa03126696f27d7df487910

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: e75af9431e119ddb814611dfdeca25c1 sha1: ab8389b992c080f6f4eb0f9a19fea4bb4d273a20 size: 11264
Section.data md5: bd8c5cd346a9f53dc0dbc69260ab2240 sha1: 90b229c22487b42cbe5df78bddab66b7c6a8f02f size: 512
Section.rsrc md5: 32c660509abcbefb521d4bd2b88fe0fc sha1: ea84d8e327cb9a141c00a641ddb113f3298c64bb size: 2560
Timestamp2004-08-04 06:02:34
Pdb pathctfmon.pdb
VersionLegalCopyright: © Microsoft Corporation. All rights reserved.
InternalName: CTFMON
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
OleSelfRegister:
ProductVersion: 5.1.2600.2180
FileDescription: CTF Loader
OriginalFilename: CTFMON.EXE
PackerMicrosoft Visual C++ v7.0
PEhashc767bc2abe0954bff968458d9293a3579af2dd02
IMPhash8b1fc5c989964e6fc1675250748f63dc
AVclamavTrojan.Genome-14

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ctfmon.exe ➝
C:\WINDOWS\system32\ctfmon.exe
RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\LangBar\ExtraIconsOnMinimized ➝
1
RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}\Enable ➝
NULL
RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\Sapilayr\ProfileInitialized ➝
1
Creates MutexCTF.TimListCache.FMPDefaultS-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-500MUTEX.DefaultS-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-500
Creates MutexMSCTF.GCompartListMUTEX.DefaultS-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-500
Creates MutexCtfmonInstMutexDefaultS-1-5-21-XXXXXXXXXX-XXXXXXXXXX-XXXXXXXXXX-500

Network Details:


Raw Pcap

Strings
.
\

002400000480000094000000060200000024000052534131000400000100010007D1FA57C4AED9F0A32E84AA0FAEFD0DE9E8FD6AEC8F87FB03766C834C99921EB23BE79AD9D5DCC1DD9AD236132102900B723CF980957FC4E177108FC607774F29E8320E92EA05ECE4E821C0A5EFE8F1645C4C0C93C1AB99285D622CAA652C1DFAD63D745D6F2DE5F17E5EAF0FC4963D261C8A12436518206DC093344D5AD293
0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
0123456789ABCDEF
040904B0
1001
1002
1003
1004
1      /MACHINE:{ARM|EBC|IA64|IPS|MIPS16|MIPSFPU|
 2005
2.0.50727.1433
2.0.50727.1433 (REDBITS.050727-1400)
3.0.6920.0
3.0.6920.1109 (lh_tools_devdiv_wpf.071009-1109)
31bf3856ad364e35
3.5.0.0
3.5.21022.8
3.5.21022.8 built by: RTM
5.1.2600.2180
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
6duplicate resource.  type:%s, name:%s, language:0x%04X
8.00.50727.1433
8.00.50727.1433 (REDBITS.050727-1400)
&About Console IME...
ACCELERATOR
Access &Violation on Console IME
AddInProcess:
$AddInProcess32.ex
AddInProcess32.exe
AddInProcess.exe
AddInServer
AMD64
ANICURSOR
ANIICON
ASP.BrowserCapsFactory, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b7bd7678b977bd8f
ASPCONFIG
aspnet_regbrowsers
aspnet_regbrowsers.exe
aspnet_regbrowsers [-? | -i | -u]
ASPPARSE
ASPRUNTIME
b03f5f7f11d50a3a
b77a5c561934e089
b7bd7678b977bd8f
\BaseNamedObjects\FontCachePort3.0.0.0
BITMAP
Brepro
*.browser
BrowserAssembly_Not_Installed
cannot get location in file
cannot open '%s' for reading out of memory; %u bytes required
cannot open %s for writing!target machine "%s" requires "%s"3resource type or name string exceeds limit of 65535
cannot read file
cannot seek in file
Cannot write BITMAPINFOHEADER
@Cannot write color table
cannot write to file
Comments
CompanyName
\config\browsers
ConIme
CONIME.EXE
Console
Console IME
ConsoleIMEClass
Console IME control
ConsoleIME_StartUp_Event
 converting %dbpp %s to %dbpp %s
Copyright
Copyright?
;Copyright (C) Microsoft Corporation.  All rights reserved.
CTF Loader
CTFMON
CTFMON.EXE
CURSOR
cvtres.ex
CVTRES.EXE
CVTRES : fatal error CVT%04d:%c
CVTRES : fatal error CVT%04u: 
CVTRES : warning CVT%04d:%c>Microsoft (R) Windows Resource To Object Converter Version %s
CVTRES : warning CVT%04u: 
DDBLD634
&Debug
	DebugMenu
	DEBUGMENU
define:
      /DEFINE:symbol
DIALOG
DIALOGEX
Directory_does_not_exist
Directory_has_no_browser_files
DLGINCLUDE
EnableConImeOnSystemProcess
en-US
E&xit Console IME
FileDescription
FileVersion
Flavor=Retail
FONT
FontCache3.0.0.0
\FontCache3.0.0.0.dat
FONTDIR
Full
Global\Font Cache Mapping 
GROUP_CURSOR
GROUP_ICON
/guid:
Hadding resource. type:%s, name:%s, language:0x%04X, flags:0x%X, size:%u
Header_text
HTML
I386
IA64
ICON
InternalName
IX86
layout text
LegalCopyright
machine:
&machine type not specified; assumed %s
MANIFEST
MENU
MENUEX
MESSAGETABLE
Microsoft
Microsoft Corporation
 Microsoft Corporation.  All rights reserved.
 Microsoft Corporation. All rights reserved.
Microsoft.JScript, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Microsoft.VisualStudio.Web, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Microsoft.VSDesigner.Mobile, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Microsoft.VSDesigner, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
Microsoft.Web.Design.Client, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
MIPS
MIPS16
MIPSFPU
MIPSFPU16
-                MIPSFPU16|SH4|THUMB|X64|X86}
name
 .NET Framework
nologo
      /NOLOGO
.obj
OleSelfRegister
 Operating System
   options:
OriginalFilename
out:
      /OUT:filename
/pid:
PLUGPLAY
portName
PresentationCFFRasterizerNative_v0300.dll
PresentationCFFRasterizer, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationCore, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFontCache
PresentationFontCache.exe
PresentationFontCache, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFramework.Aero, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFramework.Classic, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFramework.Luna, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFramework, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationFramework.Royale, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PresentationUI, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
PrivateBuild
prntvpt.dll
ProductName
ProductVersion
questionmark_help
RCDATA
ReachFramework, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
readonly
      /READONLY
RegBrowser_installed
RegBrowser_install_usage
RegBrowser_uninstalled
RegBrowser_uninstall_usage
.res
 Resource File To COFF Object Conversion Utility
ServerChannel
Short_usage_text
'%s' is corrupt
Software\Microsoft\Windows NT\CurrentVersion\Console
STRING
StringFileInfo
System.AddIn.Hosting.AddInServer
SYSTEM\CurrentControlSet\Control\Keyboard Layouts
System.Printing, PublicKey=0024000004800000940000000602000000240000525341310004000001000100b5fc90e7027f67871e773a8fde8938c81dd402ba65b9201d60593e96c492651e889cc13f1415ebb53fac1131ae0bd333c5ee6021672d9718ea31a8aebd0da0072f25d87dba6fc90ffd598ed4da35e44c398c454307e8e33b8426143daec9f596836f97c8f74750e5975c64e2189f45def46b2a2b1247adc3652bf5c308055da9
System.Windows.Presentation, PublicKey=00000000000000000400000000000000
THUMB
Translation
typeFilterLevel
Uninstallation_failed
Usage
!usage: CVTRES [options] [files]
_v0300
VarFileInfo
verbose
      /VERBOSE
VERSION
 Visual Studio
VS_VERSION_INFO
 Windows
windowsce
/WINDOWSCE
windowsce:convert
'      /WINDOWSCE[:{CONVERT|EMULATION}]
windowsce:emulation
WindowsCodecsExt.dll
Windows Presentation Foundation Font Cache Service
Wininet.dll
        />
0123456789ABCDEF
060916010447Z
060916015300Z
060916015522Z
070612235451Z
070822223102Z
070823002313Z
071024091352Z0#
071108030115Z0#
090223003313Z0t1
0hQb_JSb_u
0p1+0)
110916020300Z0
110916020522Z0
120613000451Z0
120825070000Z0y1
190915070000Z0y1
2.0.0.0
201231070000Z0p1+0)
2.0.50727.1433
2YBKVj
3.5.0.0
3.5.21022.8
3http://crl.microsoft.com/pki/crl/products/CSPCA.crl0H
3http://crl.microsoft.com/pki/crl/products/tspca.crl0H
6.0.6001.17014
8Run 'aspnet_regbrowsers -?' for a list of valid options.
970110070000Z
9Copyright (c) Microsoft Corporation. All rights reserved.
9Copyright (C) Microsoft Corporation. All rights reserved.
#9v+G9v
9vS#:v
AccessPermissions
AceFlags
_acmdln
ActivateKeyboardLayout
AddAccessAllowedAce
AddFrequentlyUsedData
AddGlyph
AddInBinaryClientFormaterSink
AddInBinaryClientFormaterSinkProvider
AddInBinaryServerFormaterSinkProvider
AddInBinaryServerSink
AddInIpcChannel
AddInProcess32
AddInProcess32.exe
AddInProcess32.pdb
AddInStore
_adjust_fdiv
advapi32.dll
ADVAPI32.dll
_amsg_exit
ArgumentException
ArgumentOutOfRangeException
ASPBrowserCapsFactory
ASPBrowserCapsPublicKey
aspnet_regbrowsers
aspnet_regbrowsers.exe
aspnet_regbrowsers.pdb
aspnet_regbrowsers.resources
</assembly>
    </assembly>
Assembly
AssemblyCompanyAttribute
AssemblyCopyrightAttribute
AssemblyDefaultAliasAttribute
AssemblyDelaySignAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
        <assemblyIdentity
<assemblyIdentity name="ctfmon" processorArchitecture="x86" version="5.1.0.0" type="win32"/>
AssemblyInformationalVersionAttribute
AssemblyKeyFileAttribute
AssemblyProductAttribute
AssemblyRef
AssemblyTitleAttribute
AssemblyVersionAttribute
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> 
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="cvtres" type="win32" publicKeyToken="000000000000000"></assemblyIdentity><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.VC80.CRT" version="8.0.50608.0" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
Assert
AsyncProcessMessage
AsyncProcessRequest
AsyncProcessResponse
AttachThreadInput
AttributeTargets
AttributeUsageAttribute
BaseGlyphElement
B@comp.id'
BinaryClientFormatterSinkProvider
BinaryServerFormatterSinkProvider
Binder
BindingFlags
BrowserAssembly_Not_Installed
BrowserCapabilitiesCodeGenerator
BuildInfo
CacheGrowthFactor
_cacheKeyComparer
CacheKeyComparer
_cacheKeyTable
_cacheManagerThread
calloc
Cannot uninstall the browser capabilities assembly, make sure it's not used by other processes. This operation might require other privileges.
category
CategoryAttribute
.cctor
_cexit
_c_exit
channel
channelData
ChannelServices
CheckedPointer
_chsize
CicLoaderWndClass
client
clientInfo
ClientInfo
CloseHandle
ClosePopupTipbar
CLSCompliantAttribute
CoCreateInstance
CodeAccessPermission
CompareExchange
CompilationRelaxationsAttribute
ComVisibleAttribute
Concat
_configthreadlocale
ConfigurationException
conime.pdb
ConnectionInstance
Console
ConstructElement
ConstructorInfo
ContainsKey
_controlfp
_controlfp_s
Control Panel\Appearance
Control Panel\Colors
Control Panel\Desktop\WindowMetrics
Convert
Copyright
"Copyright (c) 1997 Microsoft Corp.1
_CorExeMain
_cputws
Create
=Create and install the runtime browser capabilities assembly.
CreateElementFromKey
CreateEventA
CreateFileMappingA
CreateFromKey
CreateProcessA
CreateSink
CreateWindowExA
CreateWindowExW
CRicho
_crt_debugger_hook
CryptAcquireContextA
CryptCreateHash
CryptDestroyHash
CryptGetHashParam
CryptHashData
\ctfmon.exe
ctfmon.exe
ctfmon.pdb
Culture
CultureInfo
_currentCache
_currentCacheLock
_currentCacheName
currentOffset
cvtres.pdb
__CxxFrameHandler3
'%'<'d'
DailyBuildNumber
`.data
DebuggableAttribute
DebuggingModes
.debug$S
_decode_pointer
DefaultAlias
DefWindowProcA
DefWindowProcW
Delete
DeleteCriticalSection
</dependency>
<dependency>
    </dependentAssembly>
    <dependentAssembly>
description
Description
DescriptionAttribute
<description>Ctfmon</description>
DestroyWindow
Directory_does_not_exist
 Directory does not exist: '{0}'.
Directory_has_no_browser_files
'Directory has no browser files:: '{0}'.
DirectoryInfo
DispatchMessageA
DispatchMessageW
DisplaySwitchWithHelp
DisplayWordWrappedString
Dispose
DllImport
DllImportAttribute
__dllonexit
=d:\sp1.public.x86fre\internal\strongnamekeys\fake\windows.snk
DThe browser capabilities assembly has been successfully uninstalled.
DumpError
dwFlags
EcmaPublicKey
EcmaPublicKeyFull
EcmaPublicKeyToken
eFlv!@r
ElementCacher
ElementFactory
EnableWindow
_encode_pointer
Encoding
EnumWindows
Environment
Equals
eQW[9h
eQW[9hgQ
eQW[9h'Y
errorCode
errorNumber
EventResetMode
EventWaitHandle
_except_handler3
_except_handler4_common
Exception
Exists
ExplicitAccessList
FamilyCollection
fclose
_fcloseall
Fc?u(~1
$f:\dd\tools\devdiv\EcmaPublicKey.snk
@feat.00
FFGCC;Y
FileAccess
FileFormatException
FileInfo
FileMapping
FileMode
filename
_fileno
FileNotFoundException
FileStream
FileSystemInfo
FindClose
FindFirstFileA
FindNextFileA
FindResourceA
FindWindowA
folder
FontCacheAdapter
FontCacheConfig
FontCacheConstants
FontCacheFullException
FontCachePortName
FontCacheService
FontCacheServiceName
FontCacheSinglePortLPCServer
ForceCreate
Format
fputwc
fputws
*f:\RedBits\Tools\devdiv\FinalPublicKey.snk
FreeLibrary
_fsopen
fwrite
FX20Assembly
FX35Assembly
FXAssembly
GDI32.dll
GetACP
get_ANSICodePage
get_Assembly
get_BareMessage
GetBaseGlyph
get_BufferWidth
GetCacheName
GetCacheNameMessage
GetChannelData
get_Chars
GetClassNameA
get_ClientProcessId
get_ClientProtocol
get_ClrInstallDirectory
get_CodePage
GetConsoleFallbackUICulture
GetConsoleMode
GetConsoleOutputCP
GetConstructor
get_Count
GetCPInfo
get_Culture
get_Current
GetCurrentCache
get_CurrentCulture
GetCurrentProcess
GetCurrentProcessId
get_CurrentSize
get_CurrentThread
GetCurrentThreadId
get_CurrentUICulture
get_Data
get_Description
get_Exists
GetFileAttributesA
get_Filename
GetFiles
GetFileType
GetFolderPath
get_FontCacheConfig
GetFontCacheSecurityDescriptor
GetFormattableException
GetHashCode
get_InnerException
get_InternalSyncObject
get_InvariantCulture
get_Item
GetKeyboardLayoutList
GetKeyboardLayoutNameW
GetKeyState
get_Length
get_Line
GetLoader
GetLocaleInfoA
GetLocalizedString
get_Lock
__getmainargs
get_MaxCacheSize
GetMaxDataSize
GetMaxMessageSize
get_Message
GetMessageA
GetMessageW
GetModuleFileNameA
GetModuleHandleA
get_Next
GetNextCacheName
get_NextChannelSink
get_NextSink
GetObject
get_OEMCodePage
_get_osfhandle
get_OutputEncoding
GetPopupTipbar
GetPrefetchFileName
GetProcAddress
GetProcessById
get_Properties
GetRequestStream
get_Resources
GetResponseStream
GetServerInstanceCapacity
get_ShutdownTimeout
get_Size
GetStartupInfoA
GetStockObject
GetString
GetSystemDefaultLangID
GetSystemDirectoryA
GetSystemDirectoryW
GetSystemInfo
GetSystemMetrics
GetSystemTimeAsFileTime
GetSystemWindowsDirectoryA
GetSystemWow64DirectoryA
get_TextInfo
GetTickCount
GetType
GetTypeFromHandle
GetUserDefaultUILanguage
GetVersion
GetVersionExA
get_VirtualPath
get_WindowsFontsUriObject
HandleMissReport
HashFn
HashMemory
HashScramble
Hashtable
headers
Header_text
HHt`HtPHt@Ht.Ht!HHt
%+&H&O&b&m&
}h><PE
hQB0JSv
hToken
http://microsoft.com0
HttpParseException
HttpRuntime
,http://www.microsoft.com/pki/certs/CSPCA.crt0
,http://www.microsoft.com/pki/certs/tspca.crt0
hwndOwner
IChannel
IChannelDataStore
IChannelReceiver
IChannelSender
IChannelSinkBase
IClientChannelSink
IClientChannelSinkProvider
IClientChannelSinkStack
IClientResponseChannelSinkStack
IDictionary
IDisposable
IEqualityComparer
IFontCacheElement
IFormatProvider
Il/$>e
\IME\sptip.dll
IMessage
IMessageCtrl
IMessageSink
IMM32.dll
ImmAssociateContext
ImmCallImeConsoleIME
ImmCreateContext
ImmDestroyContext
ImmDisableTextFrameService
ImmEscapeW
ImmGetCandidateListW
ImmGetCompositionStringW
ImmGetContext
ImmGetConversionStatus
ImmGetGuideLineW
ImmGetIMEFileNameW
ImmGetOpenStatus
ImmGetProperty
ImmIsIME
ImmNotifyIME
ImmReleaseContext
ImmSetActiveContextConsoleIME
ImmSetConversionStatus
ImmSetOpenStatus
ImmSimulateHotKey
ImmTranslateMessage
Indicator
InformationalVersion
InitFromCacheImage
InitFromPreviousCache
InitializeCriticalSectionAndSpinCount
InitializeSharedCache
InitialLocalCacheSize
InitialSharedCacheSize
_initterm
_initterm_e
_installMode
_instanceCapacity
Interlocked
InterlockedCompareExchange
InterlockedExchange
InternalSyncObject
internat.exe
IntPtr
Invoke
_invoke_watson
__iob_func
IOException
IpcChannel
ipfx'f
IsDebuggerPresent
IServerChannelSink
IServerChannelSinkProvider
IServerChannelSinkStack
IServerResponseChannelSinkStack
IsGlyphCached
IsObsolete
IsVolatile
IsWindowEnabled
ITransportHeaders
j(hx`@
kernel32.dll
KERNEL32.dll
KERNEL32.DLL
keyboard layout
keyboard layout\Preload
Keyboard Layout\Toggle
KillTimer
            language="*"
\LanguageProfile
leftMargin
                    level="asInvoker"
              level="asInvoker" 
LoadCursorA
LoadCursorW
loader
LoaderOptimization
LoaderOptimizationAttribute
LoadIconW
LoadLibraryA
LoadLibraryExA
LoadResource
LoadStringW
LocalAlloc
LocalFree
LookupAndAdd
LPCMessage
LPCServer
lpszPath
lstrcatA
lstrcatW
lstrcmpiA
lstrcpynA
lstrcpynW
lstrcpyW
lstrlenA
lstrlenW
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
MainPortListen
_makepath
MapViewOfFileEx
MarkObsolete
Marshal
MarshalByRefObject
MaxCacheKeyTableSize
_maxDataSize
MaximumLocalCacheSize
MaximumPrefetchCacheSize
MaximumSharedCacheSize
maxLineLength
_maxMessageSize
memcpy
memmove
MemoryBarrier
memset
message
Microsoft
Microsoft Base Cryptographic Provider v1.0
Microsoft Code Signing PCA
Microsoft Code Signing PCA0
Microsoft Corporation
Microsoft Corporation0
Microsoft Corporation1
Microsoft Corporation1!0
Microsoft Corporation1'0%
Microsoft Corporation1#0!
 Microsoft Corporation.  All rights reserved.
Microsoft.Internal
MicrosoftJScript
MicrosoftPublicKey
MicrosoftPublicKeyFull
MicrosoftPublicKeyToken
Microsoft (R) CVTRES
Microsoft Root Authority
Microsoft Root Authority0
*Microsoft (R) Windows (R) Operating System
Microsoft Timestamping PCA
Microsoft Timestamping PCA0
Microsoft Timestamping Service0
MicrosoftVisualStudio
MicrosoftVisualStudioWeb
MicrosoftVisualStudioWindowsForms
MicrosoftVSDesigner
MicrosoftVSDesignerMobile
MicrosoftWebDesign
MilCore
MIL_VERSION_SUFFIX
MinimumNumberOfMissReportsToCacheAnElement
<Module>
Monitor
mscoree.dll
mscorlib
Mscorlib
MSCTF.dll
MsgWaitForMultipleObjects
_mSink
MS.Internal.FontCache
MS.Internal.FontCache.Service
MS.Internal.IO.Packaging
MSUTB.dll
MSVCR80.dll
msvcrt.dll
            name="Microsoft.Windows.Common-Controls"
nCipher DSE ESN:10D8-5847-CBF81'0%
nCipher DSE ESN:27F4-D440-54F31'0%
nCipher DSE ESN:D8A9-CFCC-579C1'0%
 .NET Framework
NeutralResourcesLanguageAttribute
NewGuid
NextChannelSink
NextSink
nFolder
N+"\hE
NtClose
ntdll.dll
NTDLL.DLL
NtOpenProcessToken
NtQueryInformationProcess
NtQueryInformationToken
NtQueryVirtualMemory
	,&	o!
Object
ObjRef
oldCache
ole32.dll
_onexit
OnShutdown
OnStart
OnStop
op_Addition
OpenEventA
OpenEventW
op_Explicit
OutAttribute
OutOfMemoryException
OVLOVLOVLOVLOVL!
OVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLOVLO
PackagingUtilities
PADPADPxg
ParamArrayAttribute
ParameterizedThreadStart
ParameterModifier
ParseArguments
__p__commode
PeekMessageA
PersistCache
__p__fmode
pMLq,Z9
PostMessageA
PostMessageW
PostQuitMessage
PPPPPPh
_prefetchFileName
PresentationCFFRasterizer
PresentationCFFRasterizerNative
PresentationCore
PresentationFontCache
PresentationFontCache.exe
PresentationFontCache.pdb
PresentationFramework
PresentationFrameworkAero
PresentationFrameworkClassic
PresentationFrameworkLuna
PresentationFrameworkRoyale
PresentationNative
PresentationUI
Prints this help text.
PrntvPt
Process
ProcessDatagramData
ProcessMessage
            processorArchitecture="x86" 
ProcessRequestData
ProfileInitialized
Program
Properties
protocol
Protocol
provider
_provider
PSSSSSS
            publicKeyToken="6595b64144ccf1df"
_putwch
pVSSSj
QueryPerformanceCounter
questionmark_help
R0000000
$R%06X
r0p1+0)
ReachFramework
ReadInt32
RealStop
Redmond1
RegBrowser_installed
RegBrowser_install_usage
RegBrowsers
RegBrowser_uninstalled
RegBrowser_uninstall_usage
RegCloseKey
RegCreateKeyA
RegCreateKeyExA
RegDeleteValueA
RegisterChannel
RegisterClassExA
RegisterClassW
RegisterConsoleIME
RegNotifyChangeKeyValue
RegOpenKeyExA
RegOpenKeyExW
RegQueryValueExW
RegSetValueExA
ReliableRead
@.reloc
remoteChannelData
RemotingServices
remove
Remove
RenewCache
replaced
replySink
            <requestedExecutionLevel 
                <requestedExecutionLevel
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
      <requestedPrivileges>
          </requestedPrivileges> 
          <requestedPrivileges> 
            </requestedPrivileges>
            <requestedPrivileges>
requestHeaders
requestMsg
requestStream
ResetEvent
ResourceManager
resources
Resources
responseHeaders
responseMsg
responseStream
RichtS
RSDSl6y
`.rsrc
.rsrc$01
@.rsrc$01
.rsrc$02
@.rsrc$02
rtcjsti
RtlCopyLuid
RtlEnterCriticalSection
RtlInitializeCriticalSection
RtlLeaveCriticalSection
RtlUnicodeToMultiByteSize
RtlUnwind
RuntimeCompatibilityAttribute
RuntimeTypeHandle
SapiTipWorkerClass
SatelliteContractVersionAttribute
    </security>
    <security>
        </security>
        </security> 
        <security>
        <security> 
SecurityAction
SecurityCriticalAttribute
SecurityCriticalScope
SecurityDescriptor
SecurityPermission
SecurityPermissionAttribute
SecurityPermissionFlag
SendMessageTimeoutW
SendMissReportMessage
SendShutdownMessage
_sep01_
server
_server
ServerProcessing
ServerShutdownMessage
ServiceBase
ServiceCacheManager
__set_app_type
set_AutoLog
set_CanShutdown
SetCurrentDirectoryW
set_CurrentUICulture
set_DescriptionValue
SetErrorMode
SetEvent
SetForegroundWindow
set_IsServer
set_Item
SetLastMessage
setlocale
set_MaxCacheSize
set_Next
SetProcessShutdownParameters
set_ServiceName
SetThreadUICulture
SetTimer
set_TypeFilterLevel
SetUnhandledExceptionFilter
__setusermatherr
SetWindowPos
SharedLibPublicKey
SharedLibPublicKeyFull
SharedLibPublicKeyToken
shfolder.dll
SHGetFolderPath
SHGFP_TYPE_CURRENT
Short_usage_text
ShouldAccept
_showDetailUsage
ShowUsage
_shutdownConn
_shutdownProtocol
_shutdownTimeout
_sinkProvider
sinkStack
s_InternalSyncObject
SkipVerification
SOFTWARE\Microsoft\CTF\Assemblies\
SOFTWARE\Microsoft\CTF\Sapilayr\
SOFTWARE\Microsoft\CTF\TIP\
Software\Microsoft\Speech
Software\Microsoft\Windows\CurrentVersion\Run
SpecialFolder
_splitpath
sprintf
SRCategoryAttribute
SRDescriptionAttribute
StartPrefetchCache
StartsWith
stream
Stream
String
StringBuilder
StringComparison
stringHelpString
#Strings
StringToByteArray
strncat
strncat_s
strncpy
strncpy_s
Substring
switchString
SyncProcessMessage
System
System.AddIn
System.AddIn.Hosting
System.Collections
System.Collections.IEqualityComparer.Equals
System.ComponentModel
SystemConfiguration
System.Configuration
SystemConfigurationInstall
SystemData
SystemDataOracleClient
SystemDeployment
SystemDesign
System.Diagnostics
SystemDirectoryServices
SystemDrawing
SystemDrawingDesign
SystemEnterpriseServices
System.Globalization
System.IO
SystemManagement
SystemMessaging
System.Net
SystemPrinting
System.Reflection
System.Resources
System.Runtime.CompilerServices
System.Runtime.InteropServices
SystemRuntimeRemoting
System.Runtime.Remoting
System.Runtime.Remoting.Channels
System.Runtime.Remoting.Channels.Ipc
System.Runtime.Remoting.Messaging
System.Runtime.Serialization.Formatters
SystemRuntimeSerializationFormattersSoap
SystemSecurity
System.Security
System.Security.Permissions
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SystemServiceProcess
System.ServiceProcess
System.Text
System.Threading
SystemWeb
System.Web
System.Web.Configuration
SystemWebExtensions
SystemWebExtensionsDesign
SystemWebMobile
System.Web.RegBrowsers
SystemWebRegularExpressions
SystemWebServices
SystemWindowsForms
SystemWindowsPresentation
SystemXml
TerminateProcess
?terminate@@YAXXZ
TextInfo
TF_CreateCicLoadMutex
TF_CreateLangProfileUtil
TF_GetGlobalCompartment
TF_InitSystem
TF_InvalidAssemblyListCache
TF_InvalidAssemblyListCacheIfExist
TF_PostAllThreadMsg
TF_UninitSystem
]The browser capabilities assembly ASP.BrowserCapsFactory.dll has been successfully installed.
=The browser capabilities assembly is not currently installed.
t;HHt0-
ThisAssembly
!This program cannot be run in DOS mode.
Thread
ThreadMain
ThreadPool
ThrowExceptionForHR
_time64
ToArray
ToInt32
ToString
TranslateMessage
    </trustInfo>
      </trustInfo> 
  </trustInfo></assembly>PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
    <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
      <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"> 
TryCloseInstance
TryClosePort
TryConnectToServer
TryCreatePort
TrySendRequest
tSLN/[
;t$(v(
tWSSSSj
TypeFilterLevel
            type="win32"
_tzset
                    uiAccess="false"/>
              uiAccess="false"/> 
UI.DLL
_ultow
UnauthorizedAccessException
UnhandledExceptionFilter
Uninstall
Uninstallation_failed
Uninstall the browser capabilities assembly from the Global Assembly Cache. The default runtime browser capabilities will be used instead.
_unlock
UnmapViewOfFile
uN_n|R
UnregisterClassW
UnregisterConsoleIME
UnsafeQueueUserWorkItem
UnverifiableCodeAttribute
UQPXY]Y[
UriFormatException
Usage:
USER32.dll
)Utility to compile ASP.Net browser files.
v2.0.50727
{V43 D
VC20XC00U
_vcwprintf
Version
            version="6.0.0.0"
VersionUpToDate
vfwprintf
^Vh<`@
VJSharpCodeProvider
VsOf8t2
WaitCallback
WaitForExit
WaitHandle
Washington1
WCP_PUBLIC_KEY_STRING
WCP_PUBLIC_KEY_TOKEN
WCP_VERSION
WCP_VERSION_SUFFIX
_wcsdup
_wcsicmp
_wcsnicmp
WebException
WellKnownSid
WellKnownSidType
_wfsopen
_wfullpath
__wgetmainargs
WideCharToMultiByte
WindowsBase
WindowsCodecs
WindowsCodecsExt
Wininet
__winitenv
WinSta0_DesktopSwitch
_wmakepath
WrapNonExceptionThrows
_wremove
WriteInt32
WriteLine
_wsplitpath
wwwwwwwwwwwwwwp
_XcptFilter
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>