Lines Matching full:like
37 # version like: 5.2 5.5 (typical)
74 # Unknown; probably a version indicator like: 0000000Ah 0000000Ch
76 # Unknown2; probably a version indicator like: 1 0
80 # number of item entries/columns/properties value like: 17h
86 # Reserved like: 0013FD90h
88 # value data array/Irrelevant Union like: 0000000004E31A80h
92 # unicode string bytes like: 2Ch
94 # unicode string value PT_UNICODE like: janesmith@contoso.org
105 # and verified by like Windows Kit `Dumpchk.exe 043022-18703-01.dmp`
113 # like: Mini111013-01.dmp
115 # major version like: 15
117 # minor version like: 2600
119 # DirectoryTableBase like: 709000
121 # PfnDatabase like: 805620c8
123 # PsLoadedModuleList like: 8055d720
125 # PsActiveProcessHead like:805638b8
127 # MachineImageType like: 14c (intel x86)
129 # NumberProcessors like: 2
131 # BugcheckCode like: e2
133 # BugcheckParameter1 like: 0
135 # BugcheckParameter2 like: 0
137 # BugcheckParameter3 like: 0
139 # BugcheckParameter4 like: 0
141 # VersionUser[32]; like "PAGEPAGEPAGEPAGEPAGEPAGEPAGEPAGE" ""
143 # uint32_t reserved0 like: 45474101
147 # KdDebuggerDataBlock like: 8054d2e0
150 # WinDumpPhyMemDesc32 NumberOfRuns like: 45474150
152 # WinDumpPhyMemDesc32 uint32_t NumberOfPages like: 1162297680
165 # like: 4
167 # WinDumpPhyMemDesc32 uint32_t NumberOfPages like: 1162297680
177 # like: c:\Windows\Minidump\020322-18890-01.dmp c:\Windows\MEMORY.DMP
179 # major version like: 15
181 # minor version like: 9600 19041 22621
183 # DirectoryTableBase like: 001ab000
185 # PfnDatabase like: fffffa8000000000
187 # PsLoadedModuleList like: fffff800c553f650
189 # PsActiveProcessHead like: fffff800c5525400
191 # MachineImageType like: 00008664
193 # NumberProcessors like: 2 4
195 # BugcheckCode like: 1000007e
199 # BugcheckParameter1 like: ffffffffc0000005
201 # BugcheckParameter2 like: fffff801abb2158f
203 # BugcheckParameter3 like: ffffd000290d4288
205 # BugcheckParameter4 like: ffffd000290d3aa0
207 # VersionUser[32]; like "" "PAGEPAGEPAGEPAGEPAGEPAGEPAGEPAGE" ""
209 # KdDebuggerDataBlock like: fffff800c550c530
212 # WinDumpPhyMemDesc64 NumberOfRuns like: 6 7 0x45474150
214 # WinDumpPhyMemDesc64 unused like: 0 0x45474150
216 # WinDumpPhyMemRun64 Run[43] BasePage like: 1
218 # WinDumpPhyMemRun64 Run[43] PageCount like: 57h
220 # uint8_t ContextBuffer[3000] like: "" "\001" "\0207J\266\001\340\377\377&8\007\312"
237 # but DumpType like: 4~small 5~full (MEMORY.DMP) 6~kernel (MEMORY.DMP)
245 # WinDumpPhyMemDesc64 uint64_t NumberOfPages like: 3142425 8341923 8366500 1162297680 4992030524978970960
284 # look for corresponding encoded as UTF-16 file name extension like in: boot_BASE+CSWITCH_1.etl
295 # look for DOS drive letter part of log file name like: PhotosAppTracing_startedInBGMode.etl
297 # like: "c:\Windows\Logs\NetSetup\service.0.etl" "C:\Windows\System32\LogFiles\WMI\Wifi.etl"
380 # apparently a version number: 2 for older like Vista, 3, 4 Windows 10
499 # to complete message string like "MS Windows 3.x help file"
501 # HLP or few MVB like NOTEPLAY.MVB
534 # look for @VERSION bmf.. like IBMAVW.ANN
540 # sometimes at little higher offset like in corelap.GID
638 # GRR: offset is not reachable in few samples like STMMHLP.MVB because probably damaged file
649 # start with colon or semicolon for comment line like Back2Life.cnt
657 # look for other keyword Title like in putty.cnt
677 # path of corresponding MS Windows help like: "C:\CDCREATR\creatr32.hlp" "C:\PROGRAMME\IPHOTO PLUS 4\PROGRAMS\Guide.hlp"
685 # path of corresponding FTS like: "C:\Windows\Help\winhlp32.FTS"
711 # partly verified by command like `lnkinfo AOL.lnk`
740 # like: "%windir%\system32\calc.exe"
763 # like: "%SystemDrive%\Program Files\YaCy\addon\YaCy.ico"
840 # ShowCommand; 1~SW_SHOWNORMAL 3~SW_SHOWMAXIMIZED HerzlichMEDION.lnk 7~SW_SHOWMINNOACTIVE YaCy.lnk Privoxy.lnk; All other values like 2 MUST be treated as SW_SHOWNORMAL
898 # like: "26EE0668-A00A-44D7-9371-BEB064C98683" Control Panel
903 # like: "C:\" "D:\"
918 # LocalBasePathOffset; location of LocalBasePath field like "C:\test\a.txt" inside LinkInfo structure
977 # wVerClient; client file format version like: 19 22
1009 # bidUnused; Unused 8 bytes padding (Unicode only); sometimes like: 0x0000000100000004
1019 # bCryptMethod; Encryption type like: 0 1 2 16
1051 # skip ASCII text like "REGEDITor.txt" but match
1074 # instead binary hiv structure like Windows
1091 # like: WINDOW_95_CD/TOOLS/RESKIT/netadmin/poledit/conf.adm
1110 # but sometimes total commander directory tree file "treeinfo.wc" with lines like
1180 # second word often Latin but sometimes Cyrillic like in 12510866.CPX
1184 # like: 12510866.CPX
1193 # like: channels.scf desktop.scf explorer.scf "Desktop anzeigen.scf"
1205 # like: SETUP.SCF
1210 # Note: contain also 3 keywords like: count Default key0
1214 # like: SETUP.LID
1219 # Note: contain also keywords like: Application Category Company Misc Version
1224 # like: DATA.TAG
1276 # like: wuau.adm
1288 # like: hdaudio.inf iscsi.inf spaceport.inf tpm.inf usbhub3.inf UVncVirtualDisplay.inf
1292 # like: arduino_gemma.inf iis.inf MSM8960.inf
1296 # like: atiixpag.inf mdmnokia.inf netefe32.inf rdpbus.inf
1302 # like: defltwk.inf netvwifibus.inf WSDPrint.inf
1311 # Note: typically stored in directory like: %WINDIR%\system32\GroupPolicy\ADM
1312 # worst case ASCII variant starting with remark line like: inetset.adm
1362 # major version 1 for older Windows like XP and 3 since about Windows Vista
1428 # like 58h, which means direct after PNF header
1468 # for newer Windows like Vista, 7 , 8.1 , 10
1482 # language string like: de-DE en-US
1485 # Summary: backup file created with utility like NTBACKUP.EXE shipped with Windows NT/2K/XP/2003
1600 # Note: created by like "InnoSetup self-extracting archive" inside ./msdos
1609 # AppName[0x80] like "Minimal SYStem", ClamWin Free Antivirus , ...
1612 # GUID like {4BB0DCDC-BC24-49EC-8937-72956C33A470} start with left brace
1630 # directory like C:\Program Files (x86)\GnuWin32
1641 # directory like C:\Program Files\GIMP 2
1653 # version like 5.1.1 5.1.11 5.5.0 5.5.3 6.0.0
1679 # Note: verified by like `7z t boot.wim` `wiminfo install.esd --header`
1689 # TO avoid in file version 5.36 error like
1706 # look for archive member RunTime.xml like in Microsoft.Windows.Cosa.Desktop.Client.ppkg
1714 # cbSize size of the WIM header in bytes like 208
1788 # probably first file name length like 178, ...
1790 # URL like File\C:\Users\nutzer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
1813 # metric type like: "BrowserMetrics" "CrashpadMetrics" "SetupMetrics"
1819 # Note: contain also keywords like: BATCH_INSTALL ISVERSION LOGHANDLE SRCDIR SRCDISK WINDIR WINSYSDISK
1823 # like test.ins Setup.ins
1825 # UNKNOWN like: 160034121de07e00 1600341260befe00 16003412e0783700
1828 # copyright text like: "Stirling Technologies, Inc. (c) 1990-1994"
1833 # 1st like: SRCDIR
1836 # 2nd like: SRCDISK
1839 # 3rd like: TARGETDISK
1842 # 4th like: TARGETDIR
1845 # 5th like: WINDIR
1848 # 6th like: WINDISK
1851 # 7th like: WINSYSDIR