About contagio exchange

CONTAGIO EXCHANGE Contagio exchange was created to absorb malware samples shared by readers of Contagio. This is meant to be a community driven malware collection.
Edit Aug 2013 - The community is busy and Mila too so this was not a very active site (my fault probably) so I will be just dumping malware strings here - it often helps in malware identification and googling is the best way.
With just strings, not exactly a fun blog to read but might become s useful resource over time.
I will not be posting samples here, just md5. You can find the corresponding samples on contagio or ping me if you can't find
M
P.S. Robot pictures delivered by Robohash.com (generated from file hashes)

Saturday, August 10, 2013

Bitcoinminer strings - CRIME

File: Bitcoinminer_F865C199024105A2FFDF5FA98F391D74_syu.exe_
MD5:  f865c199024105a2ffdf5fa98f391d74
Size: 589798





Ascii Strings:
---------------------------------------------------------------------------
!This program cannot be run in DOS mode.
Rich
.text
`.rdata
@.data
.rsrc
9RuA
SVW3
8RuK
hhdB
_^[d
hhdB
tRVf
j_^f
j_^f
j\^f
0@@f
'WWWW
_t+Nt
_^[d
+Ex;G
Udup
9Etr
9Etr
Wt'ho
v*hp
_^[d
E PW
EL@t
_^[d
SUVW
_^][
d$Pf
\$$f
\$0f
\$,f
\$8f
nl$ f
D$<f
\$(f
\$ f
n|$0f
\$(f
n|$8
\$4f
n|$,f
n\$$f
\$,f
\$4f
\$ f
\$(f
\$$f
\$8f
\$0f
\$4f
\$ f
\$$f
\$0f
\$,f
\$(f
\$8f
\$(f
\$$f
\$4f
\$0f
\$ f
\$,f
\$$f
\$4f
\$8f
\$,f
\$(f
\$0f
\$ f
\$0f
\$,f
\$8f
\$ f
\$(f
\$4f
\$$f
\$$f
\$,f
\$ f
\$(f
\$0f
\$4f
\$8f
\$4f
\$0f
\$$f
\$(f
\$8f
\$ f
\$,f
\$8f
L$ f
L$$f
L$(f
D$,f
D$0f
D$4f
oL$4f
oL$Df
H@QP
@WvB
G@PW
3j@P
^_][Y
tQ9}
WhaN@
j@XP
[j W
hPeB
hPeB
t(j.Xj\f
_^[]
u&Vj
QSVWh
hTeB
SVW3
Y9u|t
udVS
@u;j'Yj
E@Ph
j@[;
ulWj@X;
j ^V
j ^V
9] t
j ^V
QVWh
t(Ou<
~?;E
G_^[
G@BB
PhXeB
u_SV
Ph\eB
Pj 3
t!SSS
_^[d
hdeB
hdeB
u2j\Xf
Xu+j:
j\Xf
_^[]
6Sjy
QQSV
hTeB
VWj@
PtEf
It>f
ut8E
_^[d
h fB
_^[d
u\VS
WhDfB
_^[d
u PS
tAVW
u\8^
tW9^
t$8^
u)9^
5h`B
5l`B
:t2W
_u%V
htfB
hlfB
_^][
u$VW
?t"f;
_^[]
@;D$
t~Wj
j_Xf
j_Xf
j_Xf
Y;D$
V@@AAf
VWj;
t'WPV
>\u,f
t:VW
vINN
h fB
j0Xf
j1Xf
j0Zf
jAYf
YY_^[
YWj\_f9>uOf9~
{_^[
=t`B
j Y+L$
j Y+M
0@;E
9P$u
_^[]
HtFHt8Ht*Ht
8;D$
_^[]
vCW+
QQSUV
_^][YY
R@Pj
QQSV
;F$|
;F v
F$u'8
w%WS
N0WS
;*u%
h$gB
;*u,
;Ru)
OOu$j
Ph4gB
j"Wf
YY_^[
PhTeB
@_^[
8SVWj
G$PV
@u!j Y
v SW
$SVW
htgB
h\gB
tKSP
Y@PW
VhTeB
VVVV
t!VVV
u1jd
j\Zf
@@AAf
(SVW3
5D`B
5P`B
5X`B
u'Vj
u'Vj
`SVWjh
hTeB
QPhD
h$hB
t4Hu
@_^]
VVh8hB
tSHu
PjeW
h\hB
tjHu
HtHHt:
VjeW
@_^]
1t#Ht
Lu%f
uPhlfB
{tcf
j%Zf
tmf9
tdVh
SSShthB
hthB
j"Zf;
GGFF
8"tVVWS
VtiH
jtMHt
HtCHt<Ht5H
^SShq
PjeW
EXPj
EXPSV
ugj2
EXPj
EXPj
tEj2
SVWt
Vh8hB
hTeB
t@VW
VhThB
YYhPeB
h\hB
Wj<_W
<F"t
j Yf
<F t
HtOHt^HtBHu#
h$hB
=h`B
u[!E
h`iB
h<iB
Ht#H
h4iB
"YYuH
j/Xf
7GGf
SVW3
PWhr
PWhC
@_[]
HtiHt>
PjfV
PjfV
hTeB
uh8]
PhdkB
Ph(kB
SSSj
jgGV
SjfV
WjiV
hTeB
PShr
PjkV
u Sht
SjgV
SjfV
\SVWj
t3VSSj
5\`B
SVWt
?vYj@_+
F\PV
F\PV
_^[]
F(SW
F(j0_
j@X+
_^[]
QQSV
|7,X
<B@II;
j"Yf
wFBB
YY_^[
h(mB
-,bB
SQSS
SWWS
PSVh
SSWVj
FAA;t$
FAA;u
Wj?_S
H_H^]
0r3SUf
QQSVW
_^[]
_^][
G@#E
[_^]
ucSj
Wj@3
f98t
D>*;
_^[]
 SVW
uCVj
t<9E
_^[]
QSVW
QQSVW
9_ u
hM"A
h5"A
_^[d
t'WhM"A
HtFHt8Ht*Ht
_^[]
;Gx~
|5;E
4s)j
t;F0r
j$Y+
j Y+M
@v-9G
@v-9G
Ft_^[
+st#
;CHs
;KHr
9CHvX
;CHr
CH+E
FTSP
K@A#
K@A#
K@A#
|5;E
4s)j
t;C0r
j$Y+
j Y+M
Gp9M
Op9GTsU
Wp+U
Op9E
_^[d
G`t=
;F||k
j$Y+
j Y+
9NTsK
Np9E
F +F
AxH9
_^[d
_^[d
;F|~
Np9E
Np9E
Np9FTsP
Np9E
 Sj|
VhHqB
Rh(qB
WVWj
WVWj
WVWj
w5WWWW
<H>t
_CFFf
t<SSSS
ufh8qB
hXqB
hHqB
hpoB
hPoB
h@oB
t-PP
 tSj X
&u#3
GGFF
h,pB
u-f9
hPpB
QhhqB
^ S;
h8pB
SVWj
@WhppB
u=9}
t[9~
RhxqB
QP9]
hTeB
QD9] t
Q,9]
QQVW
%hcB
QQSVWd
QSVW
wIVSP
FVSj
BBFF
BBFFf
AABBf
SSSSS
SSSSS
HH_^[
WVS3
Sj Z
0;1t|
8csm
QSVW
GGBBf
AABB
^_[3
SVWf
_^[]
=HbB
tR:Q
t<:Q
t&:Q
BBFFf
WVU3
N+D$
_^[]
YQPVh
@_^]
=MOC
=csm
8csm
9csm
~SSV
~@;H
>csm
taSV
YYPV
t)SV
Hu4j
>MOC
s[S;7|G;w
9>u&
tR99u2
r,9Y
@_^[]
h8rB
F\ yB
h8rB
F\= yB
hhrB
h\rB
hPrB
hHrB
ueSj
@_^[
 VW}
j?^;
Y__^[
9csm
WWWW
j0Xf
RPSW
90tN
j Xf
WSj0
PPPPP
oV f
o^0f
of@f
onPf
ov`f
o~pf
u,9E
WWWWW
htrB
t&:a
URPQQh
L$,3
UVWS
[_^]
SVWj
_^[]
hxxB
VVVVV
u&h`xB
PPPPP
<v8V
h\xB
VVVVV
hXxB
VVVVV
VVVVV
h0xB
0A@@Ju
Y_^[]
_^[]
Fpt"
u8SS3
9] u
5$aB
9]$SS
t)9]
t"SS9]
9] u
0SSSSS
_^[]
8csm
S99t
t$<"u
>=Yt1j
tNVSP
PPPPP
Y[_^
>"u&
< tK<
5paB
@@f9
@@f9
5 aB
SSS+
@PWSS
t!SS
j@j ^V
[j@j
SVWUj
]_^[
;t$,v-
UQPXY]Y[
_^[]
Y_^[
Y_^[
WWWWW
WWWWW
VVVVV
VVVVV
VVhU
WWWWW
VVVVV
VVVVV
~%9M
r 8^
N+D$
WWWWW
uaVj
uL9=(
j hp
t+Ht
PPPPP
~,WPV
98t^
tVPV
t/9U
0SSSSS
_^[]
_^[]
0SSSSS
VVVVV
5$aB
9] SS
v$;5,
PPPPPPPP
PPPPPPPP
5DbB
WWWWV
t<Vj
t+WWVPV
VW|[;
_^[]
VVVVV
^SSSSS
j"^SSSSS
QSWVj
WWWWW
u+9u
WWWWW
_^[]
WWWWW
SSSSS
WWWWW
5,bB
%TbB
hFV@
YNANRC
bad allocation
*messages***
CryptUnprotectMemory
CryptProtectMemory
vRQ>
8STs
LwH'
SetDllDirectoryW
Z2fQ`
Unknown exception
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
R6034
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
R6033
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
R6032
- not enough space for locale information
R6031
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
R6030
- CRT not initialized
R6028
- unable to initialize heap
R6027
- not enough space for lowio initialization
R6026
- not enough space for stdio initialization
R6025
- pure virtual function call
R6024
- not enough space for _onexit/atexit table
R6019
- unable to open console device
R6018
- unexpected heap error
R6017
- unexpected multithread lock error
R6016
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
R6009
- not enough space for environment
R6008
- not enough space for arguments
R6002
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
( 8PX
700WP
`h````
xpxxxx
('8PW
700PP
`h`hhh
xppwpp
 Complete Object Locator'
 Class Hierarchy Descriptor'
 Base Class Array'
 Base Class Descriptor at (
 Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
 delete[]
 new[]
`local vftable constructor closure'
`local vftable'
`RTTI
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
 delete
 new
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
July
June
April
March
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CONOUT$
RSDS
d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
InitCommonControlsEx
COMCTL32.dll
SHAutoComplete
SHLWAPI.dll
GetCurrentDirectoryW
GetLastError
SetLastError
CreateHardLinkW
CloseHandle
GetCurrentProcess
SetFileTime
DeviceIoControl
CreateFileW
FindClose
FindFirstFileW
DeleteFileW
RemoveDirectoryW
CreateDirectoryW
MoveFileW
GetShortPathNameW
GetLongPathNameW
FlushFileBuffers
WriteFile
GetStdHandle
SetFilePointer
SetEndOfFile
GetFileType
ReadFile
GetFileAttributesW
SetFileAttributesW
FindNextFileW
GetFullPathNameW
GetModuleFileNameW
FindResourceW
GetModuleHandleW
FreeLibrary
GetProcAddress
LoadLibraryW
GetCurrentProcessId
GetLocaleInfoW
GetNumberFormatW
ExpandEnvironmentStringsW
WaitForSingleObject
DosDateTimeToFileTime
GetDateFormatW
GetTimeFormatW
FileTimeToSystemTime
FileTimeToLocalFileTime
GetExitCodeProcess
GetTempPathW
MoveFileExW
Sleep
UnmapViewOfFile
MapViewOfFile
GetCommandLineW
CreateFileMappingW
GetTickCount
SetEnvironmentVariableW
OpenFileMappingW
CreateThread
EnterCriticalSection
LeaveCriticalSection
GetProcessAffinityMask
ReleaseSemaphore
ResetEvent
DeleteCriticalSection
SetEvent
SetThreadPriority
InitializeCriticalSection
CreateEventW
CreateSemaphoreW
SystemTimeToFileTime
GetSystemTime
LocalFileTimeToFileTime
WideCharToMultiByte
MultiByteToWideChar
CompareStringW
IsDBCSLeadByte
GetCPInfo
GlobalAlloc
SetCurrentDirectoryW
KERNEL32.dll
EnableWindow
GetDlgItem
ShowWindow
MessageBoxW
SetWindowLongW
GetWindowLongW
GetWindow
GetSystemMetrics
SetWindowTextW
GetWindowTextW
SetWindowPos
GetClientRect
GetWindowRect
LoadStringW
DispatchMessageW
TranslateMessage
GetMessageW
PeekMessageW
ReleaseDC
GetDC
SendMessageW
wvsprintfW
SetDlgItemTextW
GetDlgItemTextW
EndDialog
SendDlgItemMessageW
GetClassNameW
SetFocus
DestroyIcon
DialogBoxParamW
IsWindowVisible
WaitForInputIdle
SetForegroundWindow
GetSysColor
PostMessageW
LoadBitmapW
LoadIconW
OemToCharBuffA
CharUpperW
IsWin
CopyRect
DestroyWindow
DefWindowProcW
RegisterClassExW
LoadCursorW
UpdateWindow
CreateWindowExW
MapWindowPoints
GetParent
FindWindowExW
USER32.dll
DeleteDC
StretchBlt
SelectObject
CreateCompatibleBitmap
GetObjectW
CreateCompatibleDC
GetDeviceCaps
DeleteObject
GDI32.dll
CommDlgExtendedError
GetSaveFileNameW
GetOpenFileNameW
COMDLG32.dll
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegCloseKey
RegSetValueExW
RegCreateKeyExW
RegQueryValueExW
RegOpenKeyExW
ADVAPI32.dll
SHGetPathFromIDListW
SHBrowseForFolderW
SHGetMalloc
SHGetSpecialFolderLocation
SHFileOperationW
SHGetFileInfoW
ShellExecuteExW
SHChangeNotify
SHELL32.dll
OleUninitialize
OleInitialize
CoCreateInstance
CLSIDFromString
CreateStreamOnHGlobal
ole32.dll
OLEAUT32.dll
RtlUnwind
HeapFree
HeapReAlloc
HeapAlloc
GetSystemTimeAsFileTime
RaiseException
GetCommandLineA
GetStartupInfoA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
GetCurrentThreadId
InterlockedDecrement
HeapCreate
VirtualFree
VirtualAlloc
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapSize
ExitProcess
GetModuleFileNameA
GetACP
GetOEMCP
IsValidCodePage
LCMapStringA
LCMapStringW
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
QueryPerformanceCounter
InitializeCriticalSectionAndSpinCount
GetConsoleCP
GetConsoleMode
LoadLibraryA
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
SetStdHandle
WriteConsoleA
GetConsoleOutputCP
WriteConsoleW
CreateFileA
WINRAR.SFX
.?AW4RAR_EXIT@@
OxfB
FFF))EE
FFFF))))))
FFFE
.?AVbad_alloc@std@@
.?AVexception@std@@
 (08@P`p
.?AVtype_info@@
.?AVbad_exception@std@@
                       
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                       
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcd
/'[,\\0]^_\\\Q
RSTU0VWXYZH
IJKL=MNOPQ
'A,4;BC
>>DE9
:(,4;<=>;?@
3,45657879
,++-.
.-+++
()))*
*))*+
 !"#$%&
{{{p
{{{{0
{{{p
{{{{
{{wp
w{{{
{{{p
{{{{
{{{{{{{{{
wwwwwwww
8888888888{x7
8888888888887
"g$D
8880
"j$LL
8"j$D
8880
"j$L
"btD
USq88
UU888
ddddddd
dddddddd
rrrrrrr
rrrrrrr
rrrrrrr
~vrrrrr
rrrrrrr
~vrrrrs
rrrrrrr
~vrrrrs
rrrrrmm
mmrrrrs
~~vd
rrrr
~yrs
~~~vd
rrrrr
yrrs
~~~|v
rrrrrr
yrrrs
~~~{z
rrrrrrr
yrrrps
~~{zz
rrrrrrrr
yrrrpps
~{zzz
rrrrrrrrrrrrrppps
tzzzz
kkkkkkkkkkkjhjjjo
tqmxzz
aaaaaaaaaaaaaaaaaaaaf~leQmux
JJJJJJJJJJJJJJJJJJJaieQRamu
''''''''''''''''''DaJKHPam
"(GLOa
*-/0
)LUa
+.2=
$CFNa
+.2>
V\^V
ELMa
1.2?
V\_V%
$BFID
+.2@
\\`Ve}b
YVXc~c
A##AD
 ##
33!D
03%D
/3'D
,3+D
+3-D
(31D
gwgw`
WwS7'u
gwS37%w`
WwS3
r%wP
gwS3
r"Wv
WwS3
r"%wP
gwS3
WwS3
gwS3
WwS3
gwS3
WwS3
gwS3
WwR"'P
Wwgu"'P
wR'P
Wu'P
g33WwQ
g3WwQ
gWwQ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
  version="1.0.0.0"
  processorArchitecture="*"
  name="WinRAR SFX"
  type="win32"/>
<description>WinRAR SFX module</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
  <security>
    <requestedPrivileges>
      <requestedExecutionLevel level="asInvoker"          
      uiAccess="false"/>
    </requestedPrivileges>
  </security>
</trustInfo>
<dependency>
  <dependentAssembly>
    <assemblyIdentity
      type="win32"
      name="Microsoft.Windows.Common-Controls"
      version="6.0.0.0"
      processorArchitecture="*"
      publicKeyToken="6595b64144ccf1df"
      language="*"/>
  </dependentAssembly>
</dependency>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
  <application>
    <!--The ID below indicates application support for Windows Vista -->
      <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
    <!--The ID below indicates application support for Windows 7 -->
      <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
  </application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3">
  <asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
    <dpiAware>true</dpiAware>
  </asmv3:windowsSettings>
</asmv3:application>
</assembly>
Rar!
critical\antivirus.bat
critical\libcurl.dll
j[O}
A&g2kZ
ax*l
u+o7
By~2
cqBZ-

------------------------------snip
Bgj@
H ]A
|))*
$K:D
XY2M=
O]"#
CIF@5z/;
H>u8
%ZaT/XK8
9eBS
Sgi9
N(J>y
bC:x
?SY@
oEXA
ICVr"p
;J~u
*-}X+
4PZ[U
fqY_
c:<-4,
jvO;
Bu[]
';]%'
Qr>k
[px>~3
k^fau
KkOL
0MeW
}&(9
j*@W
4WJ}
mviX
XFUv
GY{SDF
/k&T
`qpT{
f#>V
{*],
]!th
Etzfpz

Unicode Strings:
---------------------------------------------------------------------------
jjjjj
Maximum allowed array size (%u) is exceeded
SeRestorePrivilege
SeSecurityPrivilege
UNC\
\??\
SeCreateSymbolicLinkPrivilege
%.*ls(%u)%ls
rtmp%d
__rar_
?*<>|"
.rar
%c:\
\\?\
*messages***
%08x
Crypt32.dll
CryptUnprotectMemory failed
CryptProtectMemory failed
RarSFX
RENAMEDLG
GETPASSWORD1
ASKNEXTVOL
Software\WinRAR SFX
STATIC
%s %s
%s %s %s
REPLACEFILEDLG
.exe
Install
.inf
.lnk
%s%s%d
ProgramFilesDir
Software\Microsoft\Windows\CurrentVersion
<br>
%s.%d.tmp
Delete
Text
Title
Path
Silent
Overwrite
Setup
TempMode
License
Presetup
Shortcut
SavePath
Update
SetupCode
LICENSEDLG
"%s"
runas
winrarsfxmappingfile.tmp
-el -s2 "-d%s" "-p%s" "-sp%s"
__tmp_rar_sfx_access_check_%u
STARTDLG
sfxname
sfxcmd
kernel32
CreateThread failed
WaitForMultipleObjects error %d, GetLastError %d
Thread pool initialization failed.
A&nbsp;
<style>body{font-family:"Arial";font-size:12;}</style>
</html>
utf-8"></head>
<head><meta http-equiv="content-type" content="text/html; charset=
<html>
</style>
<style>
</p>
about:blank
Shell.Explorer
RarHtmlClassName
EDIT
riched20.dll
riched32.dll
KERNEL32.DLL
mscoree.dll
UTF-8
UTF-16LE
UNICODE
D(null)
         (((((                  H
         h((((                  H
                                 H
STARTDLG
REPLACEFILEDLG
RENAMEDLG
GETPASSWORD1
LICENSEDLG
ASKNEXTVOL
ccpp
WinRAR self-extracting archive
MS Shell Dlg 2
&Destination folder
Bro&wse...
hRichEdit20W
Installation progress
jmsctls_progress32
Install
Cancel
Confirm file replace
MS Shell Dlg 2
The following file already exists
Would you like to replace the existing file
with this one?
&Yes
Yes to &All
&Rename
No to A&ll
&Cancel
Rename
MS Shell Dlg 2
Cancel
Rename file
Enter password
MS Shell Dlg 2
&Enter password for the encrypted file:
Cancel
License
MS Shell Dlg 2
Accept
Decline
Next volume is required
MS Shell Dlg 2
You need to have the following volume to continue extraction:
&Browse...
Insert a disk with this volume and press "OK" to try again or press "Cancel" to break extraction
Cancel
Select destination folder
Extracting %s
Skipping %s
Unexpected end of archive
The file "%s" header is corrupt
Corrupt header is found
Main archive header is corrupt
%The archive comment header is corrupt
The archive comment is corrupt
Not enough memory
Unknown method in %s
Cannot open %s
Cannot create %s
Cannot create folder %sHChecksum error in the encrypted file %s. Corrupt file or wrong password.
Checksum error in %s Packed data checksum error in %s
Wrong password for %s5Write error in the file %s. Probably the disk is full
Read error in the file %s
File close error
The required volume is absent
2The archive is either in unknown format or damaged
Extracting from %s
Next volume
The archive header is corrupt
Close
ErroraErrors encountered while performing the operation
Look at the information window for more details
bytes
modified on
folder is not accessible
lSome files could not be created.
Please close all applications, reboot Windows and restart this installation\Some installation files are corrupt.
Please download a fresh copy and retry the installation
All files
E<ul><li>Press <b>Install</b> button to start extraction.</li><br><br>E<ul><li>Press <b>Extract</b> button to start extraction.</li><br><br>6<li>Use <b>Browse</b> button to select the destination4folder from the folders tree. It can be also entered
manually.</li><br><br>8<li>If the destination folder does not exist, it will be
2created automatically before extraction.</li></ul>
The archive is corrupt
Extracting files to %s folder$Extracting files to temporary folder
Extract
Extraction progress
=Total path and file name length must not exceed %d characters
Unknown encryption method in %s$The specified password is incorrect.
Cannot copy %s to %s.
Cannot create symbolic link %s
Cannot create hard link %s
AYou may need to run this self-extracting archive as administrator