Rixstep
 About | ACP | Buy | Industry Watch | Learning Curve | News | Search | Test
Home » Learning Curve » A Christmas Carol

A Christmas Carol:
A Day in the Life of Windows Losers -
WinFixerScannerInstall.exe.xstrings

I surfed the Web today oh boy.
 - John Winston Yoko

000000000000004d !This program cannot be run in DOS mode.
00000000000000e8 Rich,
0000000000000200 .text
0000000000000227 `.rdata
000000000000024f @.data
0000000000000278 .rsrc
00000000000116f0 NIMainWindow
0000000000011714 kernel32.dll
0000000000011724 CreateMutexA
0000000000011750  -nag
0000000000011758 open
0000000000011764 setup.exe
0000000000011770 HEAD
0000000000011780 Range: bytes=%i-
000000000001179c Eula
00000000000117a4 /BEFOREINSTALL
00000000000117b4 Abbr
00000000000117bc Software\Microsoft\Windows\CurrentVersion\Run
00000000000117ec InstallPath
0000000000011800 TaskbarCreated
0000000000011830 Delete
0000000000011838 NoRemove
0000000000011844 ForceRemove
0000000000011874 socks
000000000001187c mailto
0000000000011884 news
000000000001188c file
0000000000011894 https
000000000001189c http
00000000000118a4 gopher
0000000000011910 %s %s GMT
000000000001191c HH':'mm':'ss
000000000001192c ddd', 'dd'-'MMM'-'yyyy
0000000000011944 ; secure
0000000000011950 ; path=%s
000000000001195c ; domain=%s
0000000000011968 %s = %s; expires = %s
0000000000011998 FALSE
00000000000119a0 TRUE
00000000000119ac sdfsdfsdfsdf
00000000000119bc directory
00000000000119c8 registry.dat
00000000000119d8 Mozilla
00000000000119e0 \cookies.txt
00000000000119f0 Path
00000000000119f8 profiles.ini
0000000000011a08 Netscape\NSB
0000000000011a18 Mozilla\FireFox
0000000000011a28 # HTTP Cookie File
0000000000011a3c # http://www.netscape.com/newsref/std/cookie_spec.html
0000000000011a74 # This is a generated file!  Do not edit.
0000000000011a9f # To delete cookies, use the Cookie Manager.
0000000000011ad0 http://
0000000000011af8 Opera\Opera
0000000000011b04 System
0000000000011b0c Multi User
0000000000011b18 operadef6.ini
0000000000011b28 Last Directory3
0000000000011b38 Software\Opera Software
0000000000011b50 profile\cookies4.dat
0000000000011b68 WinSoftware NetInstaller
0000000000011b84 https://secure.winantivirus.com
0000000000011ba4 http://www.billingnow.com
0000000000011bc0 https://secure.billingnow.com
0000000000011c00 &abbr=
0000000000011c10 &pc_id=
0000000000011c20 &type=
0000000000011c28 &aff_id=
0000000000011c34 ?action=%d
0000000000011c40 &action=%d
0000000000011c4c ?order_id=
0000000000011c58 affid
0000000000011c60 actn_order_id
0000000000011c70 643AC3B53A3B46339633DD8E6FD0AE8F
0000000000011c94  License Agreement
0000000000011ca8 Close
0000000000011cb0 Verdana
0000000000011cb8 Riched20.dll
0000000000011cd0 WININET.dll
0000000000011d1b F(7A
0000000000011dc4 CorExitProcess
0000000000011dd4 mscoree.dll
0000000000011e0c SunMonTueWedThuFriSat
0000000000011e24 JanFebMarAprMayJunJulAugSepOctNovDec
0000000000012389  (8PX
0000000000012391 700WP
00000000000123a1 `h````
00000000000123a9 ppxxxx
00000000000123d4 (null)
00000000000123ec runtime error
0000000000012400 TLOSS error
0000000000012410 SING error
0000000000012420 DOMAIN error
0000000000012430 R6029
0000000000012437 - This application cannot run using the active version of the Microsoft .NET Runtime
000000000001248c Please contact the application's support team for more information.
00000000000124d4 R6028
00000000000124db - unable to initialize heap
00000000000124fc R6027
0000000000012503 - not enough space for lowio initialization
0000000000012534 R6026
000000000001253b - not enough space for stdio initialization
000000000001256c R6025
0000000000012573 - pure virtual function call
0000000000012594 R6024
000000000001259b - not enough space for _onexit/atexit table
00000000000125cc R6019
00000000000125d3 - unable to open console device
00000000000125f8 R6018
00000000000125ff - unexpected heap error
000000000001261c R6017
0000000000012623 - unexpected multithread lock error
000000000001264c R6016
0000000000012653 - not enough space for thread data
000000000001267a This application has requested the Runtime to terminate it in an unusual way.
00000000000126c8 Please contact the application's support team for more information.
0000000000012710 R6009
0000000000012717 - not enough space for environment
000000000001273c R6008
0000000000012743 - not enough space for arguments
0000000000012768 R6002
000000000001276f - floating point not loaded
0000000000012790 Microsoft Visual C++ Runtime Library
00000000000127bc Runtime Error!
00000000000127cc Program:
00000000000127dc <program name unknown>
0000000000012824 Program:
0000000000012830 A buffer overrun has been detected which has corrupted the program's
0000000000012875 internal state.  The program cannot safely continue execution and must
00000000000128bc now be terminated.
00000000000128d0 Buffer overrun detected!
00000000000128f0 A security error of unknown cause has been detected which has
000000000001292e corrupted the program's internal state.  The program cannot safely
0000000000012971 continue execution and must now be terminated.
00000000000129a4 Unknown security failure detected!
00000000000129d4 GetProcessWindowStation
00000000000129ec GetUserObjectInformationA
0000000000012a08 GetLastActivePopup
0000000000012a1c GetActiveWindow
0000000000012a2c MessageBoxA
0000000000012a38 user32.dll
0000000000012a71 =L9o<
00000000000134e6 InternetCheckConnectionA
0000000000013502 InternetCrackUrlA
0000000000013516 InternetCloseHandle
000000000001352c HttpQueryInfoA
000000000001353e HttpSendRequestA
0000000000013552 HttpOpenRequestA
0000000000013566 InternetReadFile
000000000001357a HttpAddRequestHeadersA
0000000000013594 InternetConnectA
00000000000135a8 InternetOpenA
00000000000135b8 InternetSetCookieA
00000000000135ce InternetGetCookieA
00000000000139e6 InitCommonControlsEx
00000000000139fc COMCTL32.dll
0000000000013a0a WS2_32.dll
0000000000013a18 StrCmpW
0000000000013a22 StrStrA
0000000000013a2c StrFormatByteSizeA
0000000000013a42 StrChrA
0000000000013a4c StrToIntA
0000000000013a58 StrRChrA
0000000000013a64 PathAppendA
0000000000013a70 SHLWAPI.dll
0000000000013a7e GetAdaptersInfo
0000000000013a8e iphlpapi.dll
0000000000013a9e SHGetFolderPathA
0000000000013ab0 SHFOLDER.dll
0000000000013ac0 GetLastError
0000000000013ad0 GetProcAddress
0000000000013ae2 GetModuleHandleA
0000000000013af6 CloseHandle
0000000000013b04 CreateMutexA
0000000000013b14 lstrlenA
0000000000013b20 Sleep
0000000000013b28 lstrcpyA
0000000000013b34 lstrcatA
0000000000013b40 GetCommandLineA
0000000000013b52 GetModuleFileNameA
0000000000013b68 ExitProcess
0000000000013b76 lstrcmpA
0000000000013b82 InitializeCriticalSection
0000000000013b9e DeleteCriticalSection
0000000000013bb6 LeaveCriticalSection
0000000000013bce EnterCriticalSection
0000000000013be6 CreateDirectoryA
0000000000013bfa lstrcpynA
0000000000013c06 GetTempPathA
0000000000013c16 ReadFile
0000000000013c22 CreateFileA
0000000000013c30 GetFileAttributesA
0000000000013c46 WriteFile
0000000000013c52 GetFileSize
0000000000013c60 SetFilePointer
0000000000013c72 DeleteFileA
0000000000013c80 CreateThread
0000000000013c90 TerminateThread
0000000000013ca2 WaitForSingleObject
0000000000013cb8 GetExitCodeProcess
0000000000013cce CreateProcessA
0000000000013ce0 GetSystemTimeAsFileTime
0000000000013cfa InterlockedExchange
0000000000013d10 GetACP
0000000000013d1a GetLocaleInfoA
0000000000013d2c GetThreadLocale
0000000000013d3e GetVersionExA
0000000000013d4e MultiByteToWideChar
0000000000013d64 WideCharToMultiByte
0000000000013d7a RaiseException
0000000000013d8c SizeofResource
0000000000013d9e LockResource
0000000000013dae LoadResource
0000000000013dbe FindResourceA
0000000000013dce FindResourceExA
0000000000013de0 MapViewOfFileEx
0000000000013df2 CreateFileMappingA
0000000000013e08 UnmapViewOfFile
0000000000013e1a CompareStringA
0000000000013e2c CompareStringW
0000000000013e3e GetPrivateProfileSectionNamesA
0000000000013e60 GetPrivateProfileStringA
0000000000013e7c GetTimeFormatA
0000000000013e8e GetDateFormatA
0000000000013ea0 GetPrivateProfileIntA
0000000000013eb8 ResumeThread
0000000000013ec8 SetEvent
0000000000013ed4 GetVolumeInformationA
0000000000013eec CreateEventA
0000000000013efc FreeResource
0000000000013f0c FreeLibrary
0000000000013f1a LoadLibraryA
0000000000013f28 KERNEL32.dll
0000000000013f38 RegisterClassExA
0000000000013f4c GetSysColorBrush
0000000000013f60 LoadCursorA
0000000000013f6e LoadIconA
0000000000013f7a PostMessageA
0000000000013f8a RegisterWindowMessageA
0000000000013fa4 LoadStringA
0000000000013fb2 MessageBoxA
0000000000013fc0 DispatchMessageA
0000000000013fd4 TranslateMessage
0000000000013fe8 IsDialogMessageA
0000000000013ffc GetMessageA
000000000001400a UpdateWindow
000000000001401a ShowWindow
0000000000014028 CreateDialogParamA
000000000001403e wsprintfA
000000000001404a KillTimer
0000000000014056 SetTimer
0000000000014062 DestroyWindow
0000000000014072 SetDlgItemTextA
0000000000014084 GetDlgItemTextA
0000000000014096 SendMessageA
00000000000140a6 IsWindowVisible
00000000000140b8 GetDlgItem
00000000000140c6 SetWindowTextA
00000000000140d8 DeleteMenu
00000000000140e6 GetSystemMenu
00000000000140f6 SetForegroundWindow
000000000001410c IsWindow
0000000000014118 DefWindowProcA
000000000001412a PostQuitMessage
000000000001413c LoadImageA
000000000001414a CheckDlgButton
000000000001415c EndDialog
0000000000014168 IsDlgButtonChecked
000000000001417e DialogBoxParamA
0000000000014190 PostThreadMessageA
00000000000141a6 PeekMessageA
00000000000141b6 SetWindowPos
00000000000141c6 GetWindowTextLengthA
00000000000141de GetSysColor
00000000000141ea USER32.dll
00000000000141f8 RegCloseKey
0000000000014206 RegDeleteValueA
0000000000014218 RegSetValueExA
000000000001422a RegCreateKeyExA
000000000001423c RegQueryValueExA
0000000000014250 RegOpenKeyExA
000000000001425e ADVAPI32.dll
000000000001426e ShellExecuteA
000000000001427e SHFileOperationA
0000000000014292 Shell_NotifyIconA
00000000000142a6 SHGetSpecialFolderPathA
00000000000142be SHELL32.dll
00000000000142cc CoUninitialize
00000000000142de CoGetClassObject
00000000000142f2 CoInitialize
0000000000014300 ole32.dll
000000000001430a OLEAUT32.dll
000000000001431a RtlUnwind
0000000000014326 HeapAlloc
0000000000014332 HeapFree
000000000001433e VirtualProtect
0000000000014350 VirtualAlloc
0000000000014360 GetSystemInfo
0000000000014370 VirtualQuery
0000000000014380 GetStartupInfoA
0000000000014392 HeapDestroy
00000000000143a0 HeapCreate
00000000000143ae VirtualFree
00000000000143bc HeapReAlloc
00000000000143ca IsBadWritePtr
00000000000143da TerminateProcess
00000000000143ee GetCurrentProcess
0000000000014402 GetOEMCP
000000000001440e GetCPInfo
000000000001441a LCMapStringA
000000000001442a LCMapStringW
000000000001443a SetUnhandledExceptionFilter
0000000000014458 GetTimeZoneInformation
0000000000014472 GetStringTypeA
0000000000014484 GetStringTypeW
0000000000014496 HeapSize
00000000000144a2 GetStdHandle
00000000000144b2 UnhandledExceptionFilter
00000000000144ce FreeEnvironmentStringsA
00000000000144e8 GetEnvironmentStrings
0000000000014500 FreeEnvironmentStringsW
000000000001451a GetEnvironmentStringsW
0000000000014534 SetHandleCount
0000000000014546 GetFileType
0000000000014554 IsBadReadPtr
0000000000014564 IsBadCodePtr
0000000000014574 QueryPerformanceCounter
000000000001458e GetTickCount
000000000001459e GetCurrentThreadId
00000000000145b4 GetCurrentProcessId
00000000000145ca SetStdHandle
00000000000145da SetEnvironmentVariableA
00000000000145f4 FlushFileBuffers
0000000000014608 GetProcessHeap
000000000001461a LocalAlloc
0000000000014858 83609468248B40A8A3DC1E40B3893D60
00000000000149a8 www.
00000000000149b0 cookies.txt
00000000000149c8 .?AVCAtlException@ATL@@
0000000000014a0c .?AVtype_info@@
0000000000017248 p`_^www
00000000000172bc rhmkj
0000000000017320 ~uh_
000000000001741b N)mP>c_]www
0000000000017431 |ppp
0000000000017484 B"gL>
000000000001752f U'~Z+
000000000001755d xutt
00000000000175bd vjih
0000000000017736 rHnN=
0000000000017791 ptsA
00000000000177f2 Bi"ke3
0000000000019058 <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
0000000000019091 <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
00000000000190dd <assemblyIdentity
00000000000190f1     version="1.0.0.0"
0000000000019109     processorArchitecture="X86"
000000000001912b     name="NetInstaller"
0000000000019144     type="win32"
000000000001915c <description>Net Installer</description>
0000000000019187 <dependency>
0000000000019196     <dependentAssembly>
00000000000191b0         <assemblyIdentity
00000000000191cc             type="win32"
00000000000191e7             name="Microsoft.Windows.Common-Controls"
000000000001921e             version="6.0.0.0"
000000000001923e             processorArchitecture="X86"
0000000000019268             publicKeyToken="6595b64144ccf1df"
0000000000019298             language="*"
00000000000192b3         />
00000000000192c0     </dependentAssembly>
00000000000192db </dependency>
00000000000192eb </assembly>
000000000001acd9 Western Cape1
000000000001acf0 Cape Town1
000000000001ad04 Thawte Consulting cc1(0&
000000000001ad23 Certification Services Division1!0
000000000001ad4d Thawte Premium Server CA1(0&
000000000001ad76 premium-server@thawte.com0
000000000001ad93 960801000000Z
000000000001ada2 201231235959Z0
000000000001adca Western Cape1
000000000001ade1 Cape Town1
000000000001adf5 Thawte Consulting cc1(0&
000000000001ae14 Certification Services Division1!0
000000000001ae3e Thawte Premium Server CA1(0&
000000000001ae67 premium-server@thawte.com0
000000000001aeba H5:R
000000000001af5d x`^^n7c"w6~
000000000001b004 Western Cape1
000000000001b01b Cape Town1
000000000001b02f Thawte Consulting cc1(0&
000000000001b04e Certification Services Division1!0
000000000001b078 Thawte Premium Server CA1(0&
000000000001b0a1 premium-server@thawte.com0
000000000001b0be 030806000000Z
000000000001b0cd 130805235959Z0U1
000000000001b0e7 ZA1%0#
000000000001b0f4 Thawte Consulting (Pty) Ltd.1
000000000001b11b Thawte Code Signing CA0
000000000001b1ad d{cE
000000000001b1f5 90705
000000000001b1ff /http://crl.thawte.com/ThawtePremiumServerCA.crl0
000000000001b278 PrivateLabel2-1440
000000000001b2de SS7F
000000000001b2eb El@!
000000000001b2f1 ]uvf0
000000000001b365 Western Cape1
000000000001b37c Durbanville1
000000000001b392 Thawte1
000000000001b3a3 Thawte Certification1
000000000001b3c2 Thawte Timestamping CA0
000000000001b3dc 031204000000Z
000000000001b3eb 131203235959Z0S1
000000000001b412 VeriSign, Inc.1+0)
000000000001b42a "VeriSign Time Stamping Services CA0
000000000001b4de _zj1.
000000000001b50a XWou
000000000001b586 (0&0$
000000000001b597 http://ocsp.verisign.com0
000000000001b5cb :0806
000000000001b5d5 0http://crl.verisign.com/ThawteTimestampingCA.crl0
000000000001b645 TSA2048-1-530
000000000001b69c ?7!Op1
000000000001b712 ZA1%0#
000000000001b71f Thawte Consulting (Pty) Ltd.1
000000000001b746 Thawte Code Signing CA0
000000000001b760 050801131331Z
000000000001b76f 060801131331Z0
000000000001b797 Roseau1
000000000001b7a8 Roseau1&0$
000000000001b7b9 WinSoftware Corporation, Inc.1"0
000000000001b7e1 Administrative Department1&0$
000000000001b805 WinSoftware Corporation, Inc.0
000000000001b860 '9mc
000000000001b920 y@19_6
000000000001b9ae www.winsoftware.com0>
000000000001b9c9 70503
000000000001b9d3 -http://crl.thawte.com/ThawteCodeSigningCA.crl02
000000000001ba0e &0$0"
000000000001ba1f http://ocsp.thawte.com0
000000000001ba75 UOv[
000000000001baa8 3Kd2
000000000001bb1e VeriSign, Inc.1+0)
000000000001bb36 "VeriSign Time Stamping Services CA0
000000000001bb5d 031204000000Z
000000000001bb6c 081203235959Z0W1
000000000001bb93 VeriSign, Inc.1/0-
000000000001bbab &VeriSign Time Stamping Services Signer0
000000000001bbfd Dfu]~
000000000001bc22 UV!a
000000000001bc3a \|f5_
000000000001bc56 "7LB
000000000001bcdc )t~B
000000000001bd0b (0&0$
000000000001bd1c http://ocsp.verisign.com0
000000000001bd4a ,0*0(
000000000001bd54 "http://crl.verisign.com/tss-ca.crl0
000000000001bdb9 TSA2048-1-540
000000000001be55 )qM.u
000000000001be9a 4.I@
000000000001beba OG05!
000000000001bee4 0\0U1
000000000001bef3 ZA1%0#
000000000001bf00 Thawte Consulting (Pty) Ltd.1
000000000001bf27 Thawte Code Signing CA
000000000001c00e 1H2
000000000001c03f Nfr}XYi
000000000001c09b x!k)
000000000001c0ca r4GO
000000000001c0ef 0g0S1
000000000001c10b VeriSign, Inc.1+0)
000000000001c123 "VeriSign Time Stamping Services CA
000000000001c193 051129104919Z0
000000000001c1d6 $k3X
000000000001c239 :[vWB
About | ACP | Buy | Industry Watch | Learning Curve | News | Products | Search | Substack
Copyright © Rixstep. All rights reserved.