Gen.Variant.Strictor.115561_76f5fcd989

by malwarelabrobot on November 7th, 2016 in Malware Descriptions.

HEUR:Trojan.Script.Generic (Kaspersky), Gen:Variant.Strictor.115561 (AdAware), Worm.Win32.AutoIt.FD, WormAutoItGen.YR (Lavasoft MAS)
Behaviour: Trojan, Worm


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 76f5fcd9899c4c07825ad1a6399fef5b
SHA1: fb2f9b68b0d80bf4a9e8a9cadf3936fad9cb2f44
SHA256: dbc7b6bcf0c438edd758cac336309ca920229924f1ea17f687a7fe4b23e67de5
SSDeep: 49152:aKE3JzqtsnnUZ3kw8vgylWsnblNkWx cP2erVfM7bcqYiNSFgG8It1Ba:4Jmt0mBUjnbfkWAinVYbho2pIb
Size: 2738176 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Borland Software Corp.
Created at: 2014-10-31 05:28:47
Analyzed on: Windows7 SP1 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

wmplayer.exe:4020
bSXA.exe:3956
ONThSCDifK.exe:3624
%original file name%.exe:3836

The Trojan injects its code into the following process(es):

setup_wm.exe:3740
RegSvcs.exe:3932

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process setup_wm.exe:3740 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp08997.WMC\allservices.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp15050.WMC\serviceinfo.xml (908 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wmsetup.log (10294 bytes)

The process RegSvcs.exe:3932 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\88DCD395-B062-45B3-A6CD-79F37C0EBA08\run.dat (8 bytes)

The process bSXA.exe:3956 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iVMVEUYYdfUT.lnk (846 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\iVMVEUYYdfUT.mp4 (1 bytes)

The process ONThSCDifK.exe:3624 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\autE57E.tmp (196 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\bSXA.exe (937 bytes)
C:\Users\"%CurrentUserName%"\AppData\Roaming\FHeOM.au3 (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tfgtgho (980 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\autE57E.tmp (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tfgtgho (0 bytes)

The process %original file name%.exe:3836 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ONThSCDifK.exe (73353 bytes)

The Trojan deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP (0 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ONThSCDifK.exe (0 bytes)

Registry activity

The process setup_wm.exe:3740 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"ImageLargeURL" = "http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_CurrentDialog" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"Type" = "1"

[HKCU\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache]
"0" = "8C 53 00 00 65 68 63 66 00 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_MaxInstall" = "1"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services]
"NoServices" = "0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"ImageMenuURL" = "http://images.windowsmedia.com/svcswitch/media_guide_16x16.png"
"ColorPlayer" = "#0063B0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_MaxDialog" = "6"
"Progress_CurrentInstall" = "0"
"InstallResult" = "0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"Task1ButtonText" = "Media Guide"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 38 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\MediaPlayer\Setup\UserOptions]
"DesktopShortcut" = "no"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"FriendlyName" = "Media Guide"
"Task1ButtonTip" = "Media Guide"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Preferences]
"DefaultSubscriptionService" = "MediaGuide"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"SystemUptime"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"SQMLaunchIndex"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache]
"1"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD]
"RequiredFile"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS]
"RequiredFile"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"ForceUsageTracking"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\DVD]
"RequiredFile"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"UsageTracking"

The process wmplayer.exe:4020 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process bSXA.exe:3956 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached]
"{ED1D0FDF-4414-470A-A56D-CFB68623FC58} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF" = "01 00 00 00 00 00 00 00 7F 01 E4 0C FA 37 D2 01"

The process %original file name%.exe:3836 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"

The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0"

Dropped PE files

MD5 File path
b06e67f9767e5023892d9698703ad098 c:\Users\"%CurrentUserName%"\hEwZdpDIBtjH1BSo\bSXA.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name:
Product Version:
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version:
File Description:
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 26980 27136 4.40175 22c7cbc7745692002dbdf65a4bc48e63
.data 32768 6796 1024 2.20139 317f8a934ee443eee01c2a315bde9ca1
.idata 40960 4220 4608 3.49841 a5d9b0c8d0d0e35bcbb5219dda1a3075
.rsrc 49152 2701643 2701824 5.51689 60b1cacbaf4a24e0b6dceb8c3457f405
.reloc 2752512 2240 2560 4.41763 7772c8e6ff71410862c324630aac5515

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://a1095.g2.akamai.net/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
hxxp://a177.g.akamai.net/serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
hxxp://a1076.g.akamai.net/svcswitch/MG_en-us.xml
hxxp://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86 212.30.134.177
hxxp://redir.metaservices.microsoft.com/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86 212.30.134.204
hxxp://images.windowsmedia.com/svcswitch/MG_en-us.xml 87.245.196.88
dns.msftncsi.com 131.107.255.255


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

GET /svcswitch/MG_en-us.xml HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C; Windows-Media-Player/12.0.7601.17514)
Host: images.windowsmedia.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/xml
Last-Modified: Fri, 11 Oct 2013 20:47:48 GMT
Accept-Ranges: bytes
ETag: "1e2dfa24c3c6ce1:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Content-Length: 908
Date: Sun, 06 Nov 2016 06:50:23 GMT
Connection: keep-alive
Cache-Control: max-age=1296000
...<ServiceInfo Version="1.0" Key="MediaGuide">..  <FriendlyN
ame>Media Guide</FriendlyName>.. <Color MediaPlayer="#006
3B0" />.. <Image MenuURL="hXXp://images.windowsmedia.com/svcswi
tch/media_guide_16x16.png" ServiceLargeURL="hXXp://images.windowsmedia
.com/svcswitch/mg4_wmp12_30x30_2.png"/>.. <ServiceTask1 URL="ht
tp://go.microsoft.com/fwlink/?LinkID=324773">.. <ButtonText&g
t;Media Guide</ButtonText>.. <ButtonTip>Media Guide<
/ButtonTip>.. </ServiceTask1>.. <Navigate BaseURL="http:
//go.microsoft.com/fwlink/?LinkID=324773" />.. <AlbumInfo URL="
hXXp://go.microsoft.com/fwlink/?LinkID=324773" />.. <InfoCenter
URL="hXXp://images.windowsmedia.com/svcswitch/MGinfocenter.htm" />
.. <BuyCD MediaPlayerURL="hXXp://go.microsoft.com/fwlink/?LinkId=3
27758" MediaCenterURL="hXXp://go.microsoft.com/fwlink/?LinkId=327758"
BrowserURL="hXXp://go.microsoft.com/fwlink/?LinkId=327758" />..<
/ServiceInfo>....HTTP/1.1 200 OK..Content-Type: text/xml..Last-Modi
fied: Fri, 11 Oct 2013 20:47:48 GMT..Accept-Ranges: bytes..ETag: "1e2d
fa24c3c6ce1:0"..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Cont
ent-Length: 908..Date: Sun, 06 Nov 2016 06:50:23 GMT..Connection: keep
-alive..Cache-Control: max-age=1296000.....<ServiceInfo Version="1.
0" Key="MediaGuide">.. <FriendlyName>Media Guide</Friendl
yName>.. <Color MediaPlayer="#0063B0" />.. <Image MenuUR
L="hXXp://images.windowsmedia.com/svcswitch/media_guide_16x16.png"

<<< skipped >>>

GET /redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C; Windows-Media-Player/12.0.7601.17514)
Host: redir.metaservices.microsoft.com
Connection: Keep-Alive
Cookie: WT_FPC=id=282925e51d781c135341384917303239:lv=1384918396916:ss=1384917303239


HTTP/1.1 302 Moved Temporarily
Server: AkamaiGHost
Content-Length: 0
Location: hXXp://onlinestores.metaservices.microsoft.com/serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
Date: Sun, 06 Nov 2016 06:50:19 GMT
Connection: keep-alive
HTTP/1.1 302 Moved Temporarily..Server: AkamaiGHost..Content-Length: 0
..Location: hXXp://onlinestores.metaservices.microsoft.com/serviceswit
ching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userloc
ale=409&geoid=f4&parch=x86&arch=x86..Date: Sun, 06 Nov 2016 06:50:19 G
MT..Connection: keep-alive..


GET /serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86 HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0E; .NET4.0C; Windows-Media-Player/12.0.7601.17514)
Host: onlinestores.metaservices.microsoft.com
Connection: Keep-Alive
Cookie: msid=7795e9b2-569b-45e5-9c01-dd2317500705; WT_FPC=id=282925e51d781c135341384917303239:lv=1384918396916:ss=1384917303239


HTTP/1.1 200 OK
Server: Apache
ETag: "757f8c512569f6bfc8334860ca30b6fc:1441230490"
Last-Modified: Wed, 02 Sep 2015 21:48:10 GMT
Accept-Ranges: bytes
Content-Length: 1705
Content-Type: application/xml
Date: Sun, 06 Nov 2016 06:50:22 GMT
Connection: keep-alive
...<?xml version="1.0" encoding="utf-8"?>.<Services Version="
3.00" BackoffDuration="PT24H" ordering="random" xmlns="urn:allservices
-schema">. <Default Key="MediaGuide" />. <Browse URL="ht
tp://go.microsoft.com/fwlink/?LinkId=28433&SV=5" />. <Servi
ce Type="1" Key="Audible" XMLURL="hXXp://go.microsoft.com/fwlink/?Link
Id=63546" ServiceDropDown="false" Featured="false" LRM="0" Pos="1">
. <FriendlyName>Audible.com</FriendlyName>. <Imag
e MenuURL="hXXp://wmp.audible.com/serviceInfo/wmp_16x16.png" />. &
lt;/Service>. <Service Type="2" Key="emusic" XMLURL="hXXp://go.
microsoft.com/fwlink/?LinkId=56498" ServiceDropDown="false" Featured="
false" LRM="0" Pos="5">. <FriendlyName>eMusic</Friendly
Name>. <Image MenuURL="hXXp://wmp.emusic.com/images/framework
s/wmp10/logo-15x15.png" />. </Service>. <Service Type="2
" Key="FaroLatino11_EN" XMLURL="hXXp://go.microsoft.com/fwlink/?LinkId
=155814" ServiceDropDown="false" Featured="false" LRM="0" Pos="2">.
<FriendlyName>FaroLatino Music and Video</FriendlyName>
;. <Image MenuURL="hXXp://xml12es.farolatino.com/wmp/IMAGES/icon
-orange-16.png" />. </Service>. <Service Type="1" Key="M
ediaGuide" XMLURL="hXXp://images.windowsmedia.com/svcswitch/MG_en-us.x
ml" ServiceDropDown="true" Featured="false" LRM="0" Pos="4">. &l
t;FriendlyName>Media Guide</FriendlyName>. <Image MenuU
RL="hXXp://images.windowsmedia.com/svcswitch/media_guide_16x16.png

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

bSXA.exe_3956:

.text
`.rdata
@.data
.rsrc
@.reloc
j.Yf;
r%f;M
j.Xf;
j.Zf;
PSSSSSSh
Gt.Ht$
.Jw`8Hw~fHw
kernel32.dll
?#%X.y
GetProcessWindowStation
operator
operand of unlimited repeat could match the empty string
POSIX named classes are supported only within a class
erroffset passed as NULL
POSIX collating elements are not supported
this version of PCRE is compiled without UTF support
PCRE does not support \L, \l, \N{name}, \U, or \u
support for \P, \p, and \X has not been compiled
this version of PCRE is not compiled with Unicode property support
\N is not supported in a class
RegDeleteKeyExW
advapi32.dll
Error text not found (please report)
WSOCK32.dll
VERSION.dll
WINMM.dll
COMCTL32.dll
MPR.dll
InternetCrackUrlW
HttpQueryInfoW
HttpOpenRequestW
HttpSendRequestW
FtpOpenFileW
FtpGetFileSize
InternetOpenUrlW
WININET.dll
PSAPI.DLL
IPHLPAPI.DLL
USERENV.dll
UxTheme.dll
GetProcessHeap
CreatePipe
GetWindowsDirectoryW
KERNEL32.dll
OpenWindowStationW
SetProcessWindowStation
CloseWindowStation
MapVirtualKeyW
EnumChildWindows
EnumWindows
VkKeyScanW
GetKeyState
GetKeyboardState
SetKeyboardState
GetAsyncKeyState
keybd_event
EnumThreadWindows
ExitWindowsEx
UnregisterHotKey
RegisterHotKey
GetKeyboardLayoutNameW
USER32.dll
SetViewportOrgEx
GDI32.dll
COMDLG32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
RegEnumKeyExW
RegDeleteKeyW
ADVAPI32.dll
ShellExecuteW
SHFileOperationW
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
GetCPInfo
zcÁ
UQ.WP
mI.Us
\.gGL
.FFF<
,.bh9
].Whjj*
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" language="*" processorArchitecture="*" publicKeyToken="6595b64144ccf1df"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
? ?$?(?,?0?4?8?
2 2$2(2,2024282
<#<'< </<
4F4s4
4D4C4R4e4u4
2!2%2)2-2125292=2
01s1
2=22393@3[3
?&?-?4?:?
8Ÿ94:
8!9*919<9
> >$>(>,>
? ?$?(?,?0?
/AutoIt3ExecuteScript
/AutoIt3ExecuteLine
CMDLINE
CMDLINERAW
FTPSETPROXY
GUICTRLRECVMSG
GUICTRLSENDMSG
GUIGETMSG
GUIREGISTERMSG
HOTKEYSET
HTTPSETPROXY
HTTPSETUSERAGENT
ISKEYWORD
MAPKEYS
MSGBOX
REGENUMKEY
SHELLEXECUTE
SHELLEXECUTEWAIT
TCPACCEPT
TCPCLOSESOCKET
TCPCONNECT
TCPLISTEN
TCPNAMETOIP
TCPRECV
TCPSEND
TCPSHUTDOWN
TCPSTARTUP
TRAYGETMSG
UDPBIND
UDPCLOSESOCKET
UDPOPEN
UDPRECV
UDPSEND
UDPSHUTDOWN
UDPSTARTUP
SendKeyDownDelay
SendKeyDelay
TCPTimeout
mscoree.dll
combase.dll
- floating point support not loaded
- CRT not initialized
- Attempt to initialize the CRT more than once.
USER32.DLL
789:;<=>?
APPSKEY
WINDOWSDIR
AUTOITEXE
HOTKEYPRESSED
%s (%d) : ==> %s.:
Line %d:
Line %d (File "%s"):
%s (%d) : ==> %s:
AutoIt script files (*.au3, *.a3x)
*.au3;*.a3x
All files (*.*)
KEYS
Line %d:
\\?\UNC\
04090000
%u.%u.%u.%u
0.0.0.0
Mddddd
"%s" (%d) : ==> %s:
\??\%s
GUI_RUNDEFMSG
AUTOITCALLVARIABLE%d
255.255.255.255
Keyword
AUTOIT.ERROR
Null Object assignment in FOR..IN loop
Incorrect Object type in FOR..IN loop
3, 3, 14, 2
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
HKEY_USERS
%d/d/d
C:\Users\"%CurrentUserName%"\AppData\Roaming\bSXA.exe
hXXp://VVV.autoitscript.com/autoit3/
AutoIt3.exe
AutoIt supports the __stdcall (WINAPI) and __cdecl calling conventions. The __stdcall (WINAPI) convention is used by default but __cdecl can be used instead. See the DllCall() documentation for details on changing the calling convention.
Missing operator in expression."Unbalanced brackets in expression.
>"Select" statement is missing "EndSelect" or "Case" statement. "If" statements must have a "Then" keyword. Badly formated Struct statement."Cannot assign values to constants..Cannot make existing variables into constants.9Only Object-type variables allowed in a "With" statement.v"long_ptr", "int_ptr" and "short_ptr" DllCall() types have been deprecated. Use "long*", "int*" and "short*" instead.-Object referenced outside a "With" statement.)Nested "With" statements are not allowed."Variable must be of type "Object".1The requested action with this object has failed.8Variable appears more than once in function declaration.2ReDim array can not be initialized in this manner.1An array variable can not be used in this manner.
Invalid file filter given.*Expected a variable in user function call.1"Do" statement has no matching "Until" statement.2"Until" statement with no matching "Do" statement.#"For" statement is badly formatted.2"Next" statement with no matching "For" statement.N"ExitLoop/ContinueLoop" statements only valid from inside a For/Do/While loop.1"For" statement has no matching "Next" statement.@"Case" statement with no matching "Select"or "Switch" statement.:"EndSelect" statement with no matching "Select" statement.ORecursion level has been exceeded - AutoIt will quit to prevent stack overflow.&Cannot make existing variables static.4Cannot make static variables into regular variables.
3This keyword cannot be used after a "Then" keyword.
0Expected a "=" operator in assignment statement.*Invalid keyword at the start of this line.
Invalid element in a DllStruct.*Unknown option or bad parameter specified.&Unable to load the internet libraries./"Struct" statement has no matching "EndStruct".HUnable to open file, the maximum number of open files has been exceeded.K"ContinueLoop" statement with no matching "While", "Do" or "For" statement.0Incorrect number of parameters in function call.'"ReDim" used without an array variable.>Illegal text at the end of statement (one statement per line).1"If" statement has no matching "EndIf" statement.1"Else" statement with no matching "If" statement.2"EndIf" statement with no matching "If" statement.7Too many "Else" statements for matching "If" statement.3"While" statement has no matching "Wend" statement.4"Wend" statement with no matching "While" statement.%Variable used without being declared.XArray variable has incorrect number of subscripts or subscript dimension range exceeded.#Variable subscript badly formatted.*Subscript used on non-accessible variable.&Too many subscripts used for an array.0Missing subscript dimensions in "Dim" statement.NNo variable given for "Dim", "Local", "Global", "Struct" or "Const" statement.
HCan pass constants by reference only to parameters with "Const" keyword.*Can not initialize a variable with itself.$Incorrect way to use this parameter.:"EndSwitch" statement with no matching "Switch" statement.>"Switch" statement is missing "EndSwitch" or "Case" statement.H"ContinueCase" statement with no matching "Select"or "Switch" statement.
String missing closing quote.!Badly formated variable or macro.*Missing separator character after keyword.

setup_wm.exe_3740:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
GDI32.dll
USER32.dll
msvcrt.dll
ATL.DLL
pdh.dll
ole32.dll
OLEAUT32.dll
COMCTL32.dll
SHELL32.dll
gdiplus.dll
WININET.dll
SETUPAPI.dll
WINTRUST.dll
urlmon.dll
SHLWAPI.dll
CRYPT32.dll
USERENV.dll
Secur32.dll
SSPICLI.DLL
VERSION.dll
MPR.dll
MF.dll
?ERROR: This functionality not supported on Vista.
Done importing library.
Calling import library.
DoMediaLibraryImport returned 0x%x.
ERROR: Note that Windows Update failures are tracked in %windir%\WindowsUpdate.log
ERROR: Could not load data for client '%S': '0x%x'.
%d updates were attempted. %d updates have been successfully downloaded and installed. %d updates failed to install
ERROR: Failed to get result code for Installation result:'0x%x'.
ERROR: Failed to get installation result :'0x%x'.
ERROR: Failed to use WUA API to download and install updates: '0x%x'.
ERROR: Failed to get updates ready for download and install: '0x%x'.
ERROR: Failed to include an update in the queue: '0x%x'.
ERROR: Failed to retrieve update type: '0x%x'.
ERROR: Failed to retrieve update title: '0x%x'.
ERROR: Failed to retrieve update by index: '0x%x'.
ERROR: Failed to count updates from Windows Update Site: '0x%x'.
ERROR: Failed to retrieve updates from Windows Update Site: '0x%x'.
ERROR: An error occured when scanning Windows Update Site for new updates: Error %lu.
ERROR: Failed to retrieve result code after scanning Windows Update Site for new updates: '0x%x'
ERROR: Failed to scan Windows Update Site for new updates.
ERROR: Failed to scan Windows Update Site for new updates: '0x%x'.
ERROR: Failed to set Windows Update top query offline catalog: '0x%x'.
ERROR: Could not create Update Collection: '0x%x'.
Could not create Update Installer: '0x%x'. This is expected for non-admins.
4dt ERROR: Could not create Update Searcher: '0x%x'.
Starting to scan WU Site for new updates for client %S.
?Another Update.exe package is running on the box.
Install denied: Unsupported OS.
Install denied: Unsupported Media Center OS. Version is %#1.1lf.
NOTICE: Windows Media Player is currently running.
Media Library import completed.
Uninstall has failed: 0x%x.
ERROR: Web Help URL could not be generated.
Setup has failed: '0x%x'.
ERROR: Registration for restart event for setup_wm.exe failed.
Setup commandlines are %S.
ERROR: Invalid control launching privacy URL.
XML default %S matches currently selected OEM service %S - service dialog not shown.
Finished building install list. Result: '0x%x'.
Download complete. Result: '0x%x'.
Could not set system restore end point: error 0x%x.
%S Setup complete. Result: '0x%x'.
Launching %S Install.
Windows Update Setup complete. Result: '0x%x'.
Setup complete. Result: '0x%x'.
ERROR: Could not set system restore point: error 0x%x.
System restore is not supported on this system.
Installed %S
=====Installing Install list. Last result: 0x%x.
CreateEvent For ExitSyncEvent failed. LastError: '0x%x'.
%d updates have been successfully downloaded and installed.
Service '%S' is either not installed or has not been used yet.
Service '%S' is already installed.
ERROR: XML for service '%S' is invalid and missing either the EULA or Privacy URL.
ERROR: Service key is not defined.
Service '%S' should be shown to user.
Default service is now set to: '%S'.
Could not retrieve service information URL: '0x%x'.
Services information URL is : '%S'.
XML Parser: Failed to Load DOM. Result: '0x%x'.
XML Parser: Parsing Element '%S': '%S'.
ERROR: Code URL specified but no InstallApp indicated. Install is not possible.
XML Parser: Parsing child element '%S': '%S'.
XML Parser: Parsing element '%S': '%S'.
XML Parser: Parsing element '%S: '%S''.
The XML default service is: '%S'.
OEM service override is: '%S'.
Previous service is: '%S'.
Legacy service is: '%S'.
ERROR: Package download failure has occured. Result: 0x%x.
ERROR: Download failed. Result: '0x%x'.
Unable to establish connection: 0x%x.
ERROR: Catalog download failed because '%S' could not be created. Error '0x%x'.
ERROR: Catalog download failed: '0x%x'.
XML Parser: AddService returned '0x%x'.
XML Parser: ServiceNameFromXML: '%S'.
XML-specified default service is: '%S'.
XML Parser: PopulateFromXML returned: '0x%x'.
XML Parser: LoadFile for service xml failed. Result: '0x%x'.
XML Parser: loading root element from xml failed. Result: '0x%x'.
XML Parser: Loading nodes from xml element failed. Result: '0x%x'.
XML Service content partner status: '%S'.
XML Service key name is: '%S'.
XML Service key name '%S' is already set as '%S'.
Command line-specified default service is: '%S'.
Specified service is not valid: '0x%x'.
Service added from command line: 0x%x.
ERROR: Cab extraction failed for '%S'. Error 0x%x.
Install for %S returned 0x%x.
Service install returned 0x%x.
Executing: %S %S.
Cab extraction succeeded for '%S'.
ERROR: Service information could not be retrieved for '%S': 0x%x.
Retrieving key files for '%S'.
Service data gathering returned 0x%x.
Service data gathering complete: %lu interesting service(s) found. Result 0x%x.
control.xml
Component '%S' can not be installed: file '%S' not found.
Component '%S' can not be installed: No install package available.
Component '%S' can not be uninstalled: file '%S' not found.
Component '%S' can not be uninstalled: No uninstall package available.
ERROR: Unable to obtain base URL for UDB file. Result: '0x%x'.
LANG=%s&
UDBBaseURL
XML Parser: Found value '%S' for attribute '%S'.
Reg Parser: Obtained value '%S' for attribute '%S'.
ERROR: XML Parser: Failed to add dependency information from XML. Last result: 0x%x.
XML Parser: No data available for Dependency attribute '%S'.
ERROR: XML Parser: Could not set Dependency attribute '%S'.
ERROR: XML Parser: Missing required Dependency attribute '%S'.
ERROR: Reg Parser: Failed to add dependency information from reg. Result: 0x%x.
ERROR: Reg Parser: Missing required Dependency attribute '%S'.
Reg parser: Adding dependency '%S'.
Adding dependency type '%S' to registry.
Package clean-up: Cleaning up files at '%S'.
WARNING: Base URL is not set. All packages must be available locally.
ERROR: Package download failure for '%S'. Result: 0x%x.
%stmpd.WMC\%s
%stmpd.WMC
Package install complete. Last result 0x%x.
ERROR: Execution of %S failed. Setup will not fail because of this issue.
ERROR: %S was not executed as the WMP11 install check was -ve. Setup will not fail because of this issue.
wmdbexport.exe was not run as wmp11 installs did not complete.
ERROR: Install of %S failed. Setup will not fail because of this issue.
ERROR: Install for package was halted. RunDll32.exe was not found on the system.
Uninstall for component '%S' required reboot.
Uninstall commandline for component '%S' is %S.
Uninstall for component '%S' not available.
Uninstall of component '%S' returned 0x%x.
Beginning Uninstall of component '%S'.
Removing component database for '%S'.
ERROR: Reg Parser: Failed to add uninstall information from reg. Last result: 0x%x.
ERROR: Setup missing uninstall file: '%S'.
ERROR: Reg Parser: Missing required Package attribute '%S'.
ERROR: XML Parser: Failed to add package information from XML. Result: 0x%x.
ERROR: XML Parser: No install available locally, URL not provided.
ERROR: XML Parser: Missing required Package attribute '%S'.
Created instance of download manager. Now converting URL to ANSI.
DownloadFileFromURL: We '%hs' force a connection.
ERROR: UDB file not downloaded. Result: '0x%x'.
Beginning download of component '%S'.
A download will be required for component '%S' from URL '%S'.
ERROR: Component '%S' is NOT available for install.
Component '%S' may be installable from URL: '%S'.
ERROR: XML Parser: Failed to add component from XML. Result: 0x%x.
ERROR: XML Parser: Missing required component attribute '%S'.
ERROR: Reg Parser: Failed to add component from reg. Result: 0x%x.
ERROR: Reg Parser: Missing required component attribute '%S'.
Added Component %S to Uninstall.
Failed to Add Component %S to Uninstall.
Package '%S' is not currently installed: no version of it appears to be present on the system.
Package '%S' is version '%S'. This is '%S' than the version currently installed.
Package '%S' does not appear to be installed as there is no specific version to check against.
Warning: Base URL not defined in XML.
XML Parser: Parsing Element '%S'.
Install for component '%S' was halted. Ran out of disk space. Needed at least %lu kbytes more.
Install for component '%S' was halted. A required component was not available.
Install for component '%S' was halted. Component is not available for install.
Install for component '%S' was halted. It was deemed already installed.
======Installing component '%S'.
ERROR: Attempted to install '%S' which had been marked as noninstallable.
SUCCESS: Package '%S'. Result: 0x%x.
ERROR: Package '%S'. Result: 0x%x.
OS is %s. OSVer is %S.%lu. System Lang is %lu. Prev version system is %S. Setup version %S.]
wmsetup.log
lu:lu%:lu - %s
PendingFileRenameOperations
ERROR: Could not set AllowProtectedRename flag for SFP. Error: 0x%x
%S: File signature not validated: WinVerifyTrust on file '%S' returned 0x%x.
WinVerifyTrust on file '%S' returned 0x%x.
ERROR: Decryption failed for file '%S'. Last result: 0x%x.
Set DirSecurity on '%S'.
GetDiskFreeSpaceEx failed. Error: '%x'
ERROR: Could not create directory '%S'. Error: '0x%x'.
Reboot requested due to '%S' file clean-up.
Reboot required due to '%S' driver installation.
Reboot requested due to '%S' file copy.
ERROR: OLE Initialization failed: '0x%x'.
File replacement for '%S' queued in non-admin file cache.
ERROR: Could not store delayed file move for '%S': '0x%x'.
ERROR: Could not store delayed action for component '%S': '0x%x'.
ERROR: Process '%S' deadlocked. Terminated after '%lu'ms.
ERROR: Process '%S' failed. Error: '0x%x'.
Starting process '%S'.
ERROR: Application '%S' not found. Process could not be executed.
Dll UnRegistration: Could not find file '%S'.
ERROR: Dll Registration: Could not find file '%S': '0x%x'.
Dll Registration: Succeeded for file '%S'.
Delayed Dll Registration: Succeeded for file '%S'.
ERROR: Dll Registration: Failed for file '%S': '0x%x'.
ERROR: Failed delaying dll registration for file '%S': '0x%x'.
Registering DLL: '%S'.
ERROR: MoveFileEx failed for file '%S'. Error: '0x%x'.
WARNING: Reboot required due to file '%S'.
ERROR: Bad file destination '%S'.
Moved file '%S' to temp location for clean-up upon reboot.
ERROR: Replace file in place failed for '%S'. File still exists.
ERROR: ReplaceFileOnReboot: Could not move file '%S' to '%S'. Error 0x%x.
Copied file '%S' to DllCache.
WMC_CopyFile: File '%S' is newer than the installed version. This file will be installed.
WMC_CopyFile: File '%S' is newer than the version to be installed. No copy will occur.
ERROR: WMC_CopyFile: Could not find file version for '%S'. This file will not be copied.
WMC_CopyFile: Could not find file version for '%S'. This file will be overwritten.
WMC_CopyFile: Could not replace file '%S'. This file will be replaced on reboot.
WMC_CopyFile: File '%S' should always to be installed. This file will be installed.
WMC_CopyFile: File '%S' is not to be installed if already present on the system. It was present and thus will not be reinstalled.
WMC_CopyFile: File '%S' was only to be installed if already present on the system. It was not present and thus will not be installed.
ERROR: WMC_CopyFile: Could not find source file '%S'. Error: '0x%x'.
Stopping service '%S' %S.
Stopping service '%S'.
ERROR: %S, 2-queryservicestatus
Starting service '%S' %S.
ERROR: %S, timed out
ERROR: %S, 1-queryservicestatus
ERROR: Failed to start service: '%S'. Result: 0x%x.
ERROR: Failed to open service: '%S'. Result: 0x%x.
ERROR: Failed to open SCM: '%S'. Result: 0x%x.
Now starting service: '%S'.
ERROR: Failed to create service: '%S'. Result: 0x%x.
Creating service '%S' %S.
Could not open service : '%S'.
Deletion of service : '%S' succeeded.
ERROR: Failed to delete service : '%S'. Result: 0x%x.
Parsing StopServices section:'%S'.
Failed to get information from inf with error code '0x%x'.
Querying service '%S' %S.
Querying service '%S'.
Parsing DeleteServices section:'%S'.
Parsing CreateServices section:'%S'.
B?%Load user profile returned 0x%x.
Warning: User profile not fully loaded: 0x%x.
User name not found: '0x%x'.
Database path not found for user %S.
WMCv2 Migration: Migrating user '%S'.
InternetDial returned: '0x%x'.
InternetAutoDial returned: '0x%x' for connection '%lu'.
InternetDial returned: '0x%x' for connection '%lu'.
InternetHangup returned: '0x%x' for connection '%lu'.
ERROR: Could not start download. Result: '0x%x'.
ERROR: WriteFile failed. Result: '0x%x'.
ERROR: InternetReadFile failed. Result: '0x%x'.
Could not determine download size for URL.
ERROR: Could not open URL: '0x%x'.
ERROR: Could not obtain connection result: '0x%x'.
ERROR: Could not open URL. Result: '0x%x'.
ERROR: HTTPSendRequest failed. Result: '0x%x'.
Download manager now connecting to URL.
ERROR: Could not open request: '0x%x'.
ERROR: Could not connect to host: '0x%x'.
ERROR: Could not crack URL: '0x%x'.
Lxhttp\shell\open\command
ERROR: Initialization of CWMXDownload failed. Result: '0x%x'.
%S:%u
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
InternetCrackUrlA
InternetOpenUrlA
ERROR: Unsupported use of UpdateIni: '%S'.
Could not decode INF key name:'%S'
ERROR: Registry transaction failure for: '%S'.
GetNameForCatalogOnSystem returned '0x%x'.
Another version of catalog file '%S' was previously installed.
InfParser: Set source directory '%S'.
INF: Found section '%S'.
INF: Line '%S' not found in section: '%S'. Result: 0x%x.
Processed %S line: '%S', result 0x%x.
ERROR: Registry key change failed: lRes = 0x%x.
Parsing Reg section:'%S'.
Processed UpdateIni line: '%S'.
Parsing UpdateIni section:'%S'.
Trust on catalog '%S' complete. Result: 0x%x.
ERROR: Could not add catalog '%S'. Result: 0x%x.
Added catalog '%S'. Last result: 0x%x.
ERROR: Trust on catalog '%S' failed. Could not load Crypto Lib. Last result: 0x%x.
ERROR: Trust on catalog '%S' failed. Error: 0x%x.
Trust on catalog '%S' beginning. Last result: 0x%x.
TrustCatalogFile returned 0x%x.
Trusting Catalog: '%S'.
INF: INF requested error override for '%S'.
Parsing StartServices section:'%S'.
FireNamedEvent : OpenEvent returned 0x%x.
FireNamedEvent : SetEvent returned 0x%x.
Firing event: '%S'.
ERROR: Could not set CustomDestination '%S'. Result: 0x%x.
ERROR: Could not set CustomDestination '%lu'. Result: 0x%x.
Added CustomDestination '%lu' as '%S'.
ERROR: CustomDestination '%S' not settable: LDIDs require 8 characters previous to '=' due to setupapi.
Assigned destination: '%S' for section '%S'
Parsing CustomDestination INFSection:'%S'
Attempted to delete: '%S'.
Parsing DelDirs section:'%S'.
ERROR: ProcessSetupCommand failed for: '%S': 0x%x.
Success: Ran command: '%S'.
Parsing RunCommands section: '%S'.
Parsing RegisterOCX INFSection:'%S'.
ERROR: Failed to assign destination for: '%S'.
Deleted file '%S'.
ERROR: Could not delete '%S': 0x%x.
Copied file '%S' to '%S'.
ERROR: Could not find file '%S' at source '%S' for dest '%S': 0x%x.
Assigned destination: '%S' to '%S'.
Parsing '%S' INFSection:'%S'
Source location is:'%S'.
SUCCESS: GetInstallSizeEstimate for '%S': size: '%lu'.
FAILED: GetInstallSizeEstimate for '%S': Result: 0x%x.
WARNING: Could not get size for file '%S' for INF '%S'.
GetInstallSizeEstimate for '%S': size: '%lu'.
Parsing INFSection:'%S'.
Current directory is: '%S'.
ERROR: INF parser failed on: '%S'. Result: 0x%x.
ERROR: Failed to open INF: '%S'. Result: 0x%x.
INF: Error '0x%x' reported for '%S'. Honoring INF error override and continuing.
ERROR: Invalid arguments passed to AddDirectoryToList.
\\.\VWIN32
0%D[$
H$l%%u;
setup_wm.pdb
F9=\%F
9=\%F
uaSSSShhI?
SSSSh@I?
SSSh8
PSSh,J?
j.Xf;Dq
PSSSSSSh
~j.Yf;
PSSSSSSSSh
SSSSh
u3VSSSh
j.Yf;
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
RegDeleteKeyW
GetWindowsDirectoryW
GetSystemWindowsDirectoryW
_acmdln
_amsg_exit
ShellExecuteExW
ShellExecuteW
GdiplusShutdown
InternetCrackUrlW
UrlMkSetSessionOption
SHDeleteKeyW
CertVerifyCertificateChainPolicy
RegOpenKeyExA
RegEnumKeyW
GetWindowsDirectoryA
MFGetSupportedSchemes
version="11.0.0.0"
name="Microsoft.Windows.MediaPlayer.SetupWM"
<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
</asmv3:windowsSettings>
<description>Windows Media Player Setup</description>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
KEYW
_Xrruurlljbbljnnnnljbibb^^__^_w
lrrT?.==?===;=;.Geblyxwwn
fTppTOOPORWfuwutwt
vGD%S
.MEtG
1.pOLN
.Dqi,
:::@:::(:::3:::
()* ,-.FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.-, *)))))jj
7777777
()* ,-.FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.-, *))))
4444444
:5/-/---//04477===
===777440..   25
4999999999
3333>:%%
;;<<<<9<9
'-Xjiiji}
$(0., **)
710., **)'
!<?64410.,  *)$,
246<"98">4321
/3<99;30//
.qBk'
,1#:>2.KP
10<>=.KP
/0><#.KP
23444555566
4455555666
6666666665
46666666561
6665555443*
.,    ,---
00000000
000000000
< <$<(<,<0<
3 3$3(3,303
7v7F7X7s7
11181>1]1
2!3'3/3|3
?%?8?\?|?
2?2]283\3
>1>6><>}>
5m6O6t6
Windows Media Player
e31e09cb-b1d4-4b2c-b088-0aa51c598562
hXXp://go.microsoft.com/fwlink/?LinkId=120764&mpver=%s&id=%x&contextid=%lu&originalid=%x
hXXp://go.microsoft.com/fwlink/?LinkId=120764&mpver=%s&id=%x&contextid=%lu&originalid=%lu
11.0.0.0
\\.\System\System Up Time
Software\Microsoft\Windows\CurrentVersion\Setup\WindowsFeatures
Software\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\WindowsFeatures\WindowsMediaVersion
CLASSES_ROOT\%s
wmplayer.ocx.7
wmplayer.ocx
\wmploc.dll
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\WindowsMedia\Setup\BlockingRefCounts\%s
Software\Microsoft\MediaPlayer\Setup\BlockingRefCounts\%s
9.0.0.0
%s\%s\wmvcore.dll
%s\%s\wmploc.dll
%s.bak
\wmpband.dll
\wmdband.dll
\wmvcore.dll
\wmp.dll
setup_wm.exe
%s\%s
eula.txt
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Windows Media Player 10
Windows Media Player 9
Windows Media Player 8
Windows Media Format SDK
e88a19fb-a847-4e3d-9ae2-13c2b84f58a6
DeploymentAction='Installation' AND IsInstalled=0 AND CategoryIDs contains '%s'
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\MTPMediaPlayerArrival
Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers
%lu|%lu|%lu|%lu|%s
\notepad.exe
5.1.2600.2096
5.1.2600.2180
5.1.2700.2180
5.1.2710.2732
\ehome\ehshell.exe
%s (%lu of %lu items)
%s %s
%s /HideWMP /SetShowState
Software\Microsoft\Windows\CurrentVersion\Run
408|420|80|22
wmplayer.exe
Microsoft.Windows.MediaPlayer32
::/htm/nomoreinformationisavailable.htm
wmp11.chm
HHCTRL.OCX
hXXp://
Software\Policies\Microsoft\WindowsMediaPlayer
mshelp://windows/?id=%s
\wmplayer.exe
ginetcpl.cpl
%s%lu
E33D49A9-409C-4acd-A1F5-DA7DBB99EB30
Windows Media Player 11
\wmp11.exe
\wmp11-64.exe
sfc.dll
%s\cmd.exe /c """""%s"" /ShowWMP"""
Obtaining Updates For Windows Media Player
.WMC\
MenuURL
ServiceSmallURL
ServiceLargeURL
SetupURL
CodeURL
CatalogURL
EULAURL
EulaURL
PrivacyInfoURL
XMLURL
?hXXp://go.microsoft.com/fwlink/?LinkId=52492&sv=2
Software\Microsoft\Windows\CurrentVersion\Policies\System
C%stmpd%s
ImageSmallURL
ImageMenuURL
ImageLargeURL
Software\Microsoft\MediaPlayer\Services\%s
%s&partner=%lu
&geoid=%x
%s&version=%s&locale=%x&userlocale=%x
wmploc.dll
%sallservices.xml
%s%s.cab
Software\Microsoft\MediaPlayer\Preferences\ContentPartners\%s
\catalog.wmdb.lz
%s\Microsoft\Media Player\%s\%s
%s\Microsoft\Media Player\%s
"%s%s"
%swatermark.jpg
%slogo.jpg
%seula.txt
%sserviceinfo.xml
BASEURL
UDBSOURCEURL
SUPPORTEDRANGE
SOURCEURL
UPDATEEXE
Windows Media Setup
%s\drmupgds.exe
wmfdist11-64.exe
wmfdist11.exe
%s_NT
%s_NT%lu
1.0.0.0
0.0.0.0
%sWMC%4.4lu.tmp
wmp11-64.exe
wmp11.exe
WMC_WMPDBExport
\wmdbexport.exe
wmdbexport.exe
%s advpack.dll,LaunchINFSectionEx %s,%s,,%lu,N
\rundll32.exe
%stmpd.WMC\
\msdxm.ocx
%s_%s
%s\inf\%s
\msxml.dll
\kernel32.dll
advapi32.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Software\Clients\Media\Windows Media Player\InstallInfo
wmp.dll
\inf\unregmp2.exe
\unregmp2.exe
kernel32.dll
MP2.SaveDir
\regsvr32.exe
A%s\%s%d.wpl
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%s
%ssetb%lu.tmp
setupapi.dll
Kernel32.dll
?DisableWindowsUpdateAccess
Software\Microsoft\CurrentVersion\Policies\WindowsUpdate
Software\Policies\Microsoft\WindowsUpdate\AU
\mplayer2.exe
msdxm.ocx
%s\Groups\%s
SOFTWARE\Microsoft\Windows Media Player NSS\3.0\MAC Access Control
SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Devices
SOFTWARE\Microsoft\Windows Media Player NSS\3.0
SOFTWARE\Microsoft\Windows Media Connect 2\Shares
SOFTWARE\Microsoft\Windows Media Connect 2\Devices
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\Local Settings\Application Data\Microsoft\Media Player
Software\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
%USERNAME%
%s\Microsoft\Media Player
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
\WMPNSCFG.exe
%s\Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\MediaPlayer\Preferences\HME\%s
Software\Microsoft\Windows Media Connect 2\Shares
msiexec.exe /uninstall %s /qn /norestart
msiexec.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\WMCSetup
Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Connect
EMS_WebcheckMonitor
%s\old%s
\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\
%s.NT%lu.%lu
%s.NT
%s.NT4
%s.NT5
\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\wmsocm.cat
MediaPlayerV2.dll
%s,%s
hXXps://
{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
%s\ddeexec.bak
%s\ddeexec
%s\command
%s\shell
%s\shell\open\ddeexec.bak
%s\shell\open\ddeexec
%s\shell\open\command
%s\shell\%s\command
tmscat32.dll
12.0.7601.17514
Windows-Media-Player/
https
vnd.ms.wmhtml
OCXLayoutInvisible.wsz
OCXLayoutFull.wsz
OCXLayoutMini.wsz
OCXLayoutNone.wsz
DRMHeader.SubscriptionContentID
DRMHeader.ContentDistributor
DRMHeader.SECURITYVERSION
DRMHeader.CID
DRMHeader.LAINFO
DRMHeader.KID
BaseLAURL
\\?\GLOBALROOT%s\
dw15.exe
WMPlayer/%s
DVD.bookmark
DVD.lastSPPref
DVD.lastAudioPref
DVD.title
DVD.chapter
%c:\video_ts\video_ts.ifo
video_ts.ifo
AVSEQ%d.dat
MUSIC%d.dat
AlbumArtSmall.jpg
Folder.jpg
_Small.jpg
_Large.jpg
ContentPartnerKeyName
WPD/PassthroughPropertyValues
WMDM/DestinationURL
WMDM/SourceURL
WMDM/Webmaster
WMDM/FormatsSupportedAreOrdered
WMDM/FormatsSupported
WMDM/SupportedDeviceProperties
WMDM/KeyFrameDistance
vnd.ms.wmpcp
Eshell32.dll
\\.\%c:
wmploc.dll/
wmploc.dll\
%c%s=%s
%s://
%d/%d
%s://%c?contentdir=%s
%s://%c/%d?contentdir=%s
eAllServicesUrl_Win7
eAllServicesUrl_Vista
eAllServicesUrl
eLicenseManagementUrl
eHDCDUrl
eCDFormatsUrl
eDRMFileBurnDataCDUrl
eDeviceCantSyncUrl
eSyncBurnRightsUrl
eTransport9SeriesUrl
eMediaGuideFirstRunUrl
eIndividualizationUrl
eGettingStartedUrl
ePluginGalleryUrl
eVizGalleryUrl
eSkinGalleryUrl
eWindowsMediaLogoUrl
ePlayerUpgradeUrl
eMacroMediaUrl
eRequiresSP1Url
eNoDVDDecoderUrl
eCompareWMAUrl
eAddDevicesUrl
eSecurityUrl
eFindPluginsUrl
eTroubleShootingUrl
ePrivacyStatementUrl
hXXp://go.microsoft.com/fwlink/
ws2_32.dll
iphlpapi.dll
res://wmploc/RT_TEXT/corporate.wsz
res://wmploc/RT_TEXT/player.wsz
BuyMusicURL
CLSID\{FA10746C-9B63-4b6c-BC49-FC300EA5F256}\InprocServer32
SOFTWARE\Microsoft\MediaPlayer\Player\Schemes\%s
SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\%s
SOFTWARE\Microsoft\MediaPlayer\Player\Extensions\.%s
SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.%s
Software\Microsoft\Windows Media Foundation\ByteStreamHandlers
Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\
.dvr-ms
@http
Ehttp
Software\Policies\Microsoft\WindowsMediaPlayer\
Software\Policies\Microsoft\WindowsMediaPlayer\Protocols\
Software\Microsoft\Windows\CurrentVersion\Policies\
video/vnd.dlna.mpeg-tts
image/vnd.ms-photo
audio/x-mpegurl
audio/vnd.dlna.adts
application/vnd.ms-wpl
application/vnd.ms-search
vnd.ms-wpl
vnd.ms-photo
vnd.ms-search
x-mpegurl
vnd.dlna.mpeg-tts
vnd.dlna.adts
WM/UserWebURL
WM/PromotionURL
WM/InitialKey
WM/AuthorURL
WM/AudioSourceURL
WM/AudioFileURL
WM/AlbumCoverURL
SupportsVideo
SupportsPhoto
SupportsAudio
SourceURL
RadioLogoURL
ProviderURL
ProviderLogoURL
LinkedFileURL
LastSyncKey
InitialKey
ErrorURL
DTCPIPPort
DTCPIPHost
DRMKeyID
DeviceSyncSupportFlags
AlternateSourceURL
Video.Writer.Name
Track.Writer.Name
Track.WMContentId
Album.WMCollectionId
Album.WMCollectionGroupId
Video.VideoWidth
Photo.Width
Video.VideoHeight
Photo.Height
Video.FrameRate
Track.UniqueFileIdentifiers
DeviceMedia.TrackNumber
Track.TrackNumber
Video.SubtitleDescription
Video.Subtitle
Track.SubTitle
Playlist.ContentDistributorListID
Video.SubscriptionContentID
Track.SubscriptionContentID
Video.Publisher.Name
Track.Publisher.Name
Video.ProviderStyle
Album.ProviderStyle
Video.ProviderRating
Album.ProviderRating
Radio.ProviderName
Video.ProviderName
Album.ProviderName
Video.ProtectionType
Track.ProtectionType
Video.Producer.Name
Track.Period
Album.PartOfSet
Video.ParentalRating
Track.ParentalRating
Track.Mood
Video.MediaStationName
Video.MediaOriginalChannel
Video.MediaOriginalBroadcastDateTime
Radio.MediaClassSecondaryId
Other.MediaClassSecondaryId
Playlist.MediaClassSecondaryId
Video.MediaClassSecondaryId
Photo.MediaClassSecondaryId
Track.MediaClassSecondaryId
Radio.MediaClassPrimaryId
Other.MediaClassPrimaryId
Playlist.MediaClassPrimaryId
Video.MediaClassPrimaryId
Photo.MediaClassPrimaryId
Track.MediaClassPrimaryId
Album.TOC
Radio.Language
Video.Language.Name
Track.Language.Name
Track.InitialKey
DeviceMedia.TrackGenre
Genre.Name
DeviceMedia.DateTranscoded
Playlist.CreationTime
Video.EncodingTime
Track.EncodingTime
Video.Director.Name
Track.ContentGroupDescriptio
Playlist.ContentDistributor
Video.ContentDistributor
Track.ContentDistributor
Track.Conductor.Name
Composer.Name
Other.Category.Name
Playlist.Category.Name
Video.Category.Name
Track.Category.Name
DeviceMedia.AlbumTitle
Album.Title
DeviceMedia.AlbumArtist
Album.AlbumArtist
DeviceMedia.WasTranscoded
Video.VideoFormat
Video.VideoBitrate
Device.Version
User.ServiceRating
DeviceMedia.UserRating
User.Rating
User.Playcount.Weekend
User.Playcount.Weekday
User.Playcount.Night
User.Playcount.Morning
User.Playcount.Evening
User.Playcount.Afternoon
DeviceMedia.PlayCount
User.Playcount.Total
User.LastPlayedTime
User.EffectiveRating
User.Custom2
User.Custom1
Device.UpsellPrompt
DeviceMedia.UpdateTime
Other.UpdateTime
Playlist.UpdateTime
Video.UpdateTime
Photo.UpdateTime
Track.UpdateTime
Device.TranscodingEnabled
Device.TranscodeTriggerEventIndex
DeviceMedia.TranscodedFilename
DeviceMedia.TrackingId
Radio.TrackingId
Other.TrackingId
Playlist.TrackingId
Video.TrackingId
Photo.TrackingId
Track.TrackingId
Device.TotalSpace
DeviceMedia.TrackTitle
Device.Name
Radio.Title
Other.Title
Playlist.Title
Video.Title
Photo.Title
Track.Title
Device.SyncTriggerEventIndex
Device.SyncToRoot
Other.SyncState2
Video.SyncState2
Photo.SyncState2
Track.SyncState2
Other.SyncState
Video.SyncState
Photo.SyncState
Track.SyncState
Device.SyncShuffle
Device.SyncRelationship
Device.SyncPercentComplete
Playlist.SyncOnly
Device.SyncOnConnect
Device.SyncItemCount
Other.SyncInfo
Video.SyncInfo
Photo.SyncInfo
Track.SyncInfo
DeviceMedia.SyncIndex
Device.SyncIndex
Playlist.Sync16
Playlist.Sync15
Playlist.Sync14
Playlist.Sync13
Playlist.Sync12
Playlist.Sync11
Playlist.Sync10
Playlist.Sync09
Playlist.Sync08
Playlist.Sync07
Playlist.Sync06
Playlist.Sync05
Playlist.Sync04
Playlist.Sync03
Playlist.Sync02
Playlist.Sync01
Device.SupportsVideo
Device.SupportsPhoto
Device.SupportsAudio
Photo.Subject
DeviceMedia.NameOnDevice
Radio.StreamUrl
Other.FileUrl
Playlist.FileUrl
Video.FileUrl
Photo.FileUrl
Track.FileUrl
Playlist.SharingStatus
Video.SharingStatus
Photo.SharingStatus
Track.SharingStatus
Video.ShadowFileSourceFileType
Track.ShadowFileSourceFileType
Video.ShadowFileSourceDRMType
Track.ShadowFileSourceDRMType
Device.SerialNumber
Device.ResyncVideo
Device.ResyncAudio
Track.MetadataProviderRequestState
DeviceMedia.TrackReleaseDate
Video.ReleaseTime
Track.ReleaseTime
Device.RelationshipID
Track.RecordingTime
Radio.LogoURL
Radio.Genre
Album.ProviderUrl
Album.ProviderLogoUrl
Device.Protocol
Video.Profile
Device.PreferredVdeoBitrate
Device.PreferredAudioBitrate
Video.PixelAspectRatioY
Video.PixelAspectRatioX
Device.PercentSpaceReserved
Device.PendingActions
Track.PeakValue
DeviceMedia.OnDevice
DeviceMedia.NeedsResync
Radio.MediaType
Other.MediaType
Playlist.MediaType
Video.MediaType
Photo.MediaType
Track.MediaType
Playlist.MediaContentTypes
DeviceMedia.MarkedForDeletion
Radio.Location
Other.LinkedFileURL
Video.LinkedFileURL
Photo.LinkedFileURL
Track.LinkedFileURL
Device.LastSyncTime
Device.LastSyncNoFitCount
Device.LastSyncKey
Device.LastSyncErrorCount
Device.LastConnectTime
Album.IsCompilation
Video.Protected
Track.Protected
Photo.Category.Name
Track.HMEAlbumTitle
Video.HasHMEACL
Photo.HasHMEACL
Track.HasHMEACL
Device.GuestPrompt
Device.FriendlyNameGenerated
Device.FriendlyName
Radio.Frequency
Device.FreeSpaceLastSync
Device.FreeSpace
Video.FourCC
Device.FirmwareVersion
Radio.FileType
Other.FileType
Playlist.FileType
Video.FileType
Photo.FileType
Track.FileType
DeviceMedia.SizeOnDevice
Other.FileSize
Video.FileSize
Photo.FileSize
Track.FileSize
Video.FakeSubscriptionContentID
Track.FakeSubscriptionContentID
Video.FakeContentDistributor
Track.FakeContentDistributor
Video.DVDID
Other.Duration
Video.Duration
Track.Duration
Video.DRMKeyID
Track.DRMKeyID
Video.DRMIndividualizedVersion
Track.DRMIndividualizedVersion
Video.DLNAProfileID
Photo.DLNAProfileID
Track.DLNAProfileID
DisplayArtist.Name
Device.DeviceSyncSupportFlags
DeviceMedia.Type
Device.DeviceID
Device.Capabilities
Device.DesiresVideo
Device.DesiresPhoto
Device.DesiresAudio
Video.RecordingTime
Photo.DateTimeTaken
Track.DefaultDate
Playlist.Count
Video.Copyright
Photo.Copyright
Track.Copyright
Other.ContentDistributorDuration
Track.ContentDistributorDuration
Playlist.ContainsLISLContent
Device.Connected
Photo.Comment
Device.CheckDeviceMediaSize
Device.CanSync
Radio.CanonicalFileType
Other.CanonicalFileType
Playlist.CanonicalFileType
Video.CanonicalFileType
Photo.CanonicalFileType
Track.CanonicalFileType
Photo.CameraModel.Name
Photo.CameraManufacturer.Name
Radio.CallSign
Radio.Bitrate
Other.Bitrate
Video.Bitrate
Track.Bitrate
Track.AverageLevel
Device.AutoSyncDefaultRules
DeviceMedia.TrackArtist
Radio.Author
Playlist.Author
Actor.Name
Photo.Author
Artist.Name
Video.AudioFormat
Track.AudioFormat
Video.AudioBitrate
Track.ArtInFile
DeviceMedia.AlbumPUOID
Album.AlbumId
Radio.AcquisitonTime
Other.AcquisitonTime
Playlist.AcquisitonTime
Video.AcquisitonTime
Photo.AcquisitonTime
Track.AcquisitonTime
Device.AcquiredContentRetrievalTransactionID
Radio.Abstract
DRM_KeyID
Title=res://wmploc.dll/RT_STRING/#1700;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;MediaType=res://wmploc.dll/RT_STRING/#1715;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;Label=res://wmploc.dll/RT_STRING/#1742;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/ContentGroupDescription=res://wmploc.dll/RT_STRING/#1920;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/PartOfSet=res://wmploc.dll/RT_STRING/#1759;WM/Language=res://wmploc.dll/RT_STRING/#1735;WM/InitialKey=res://wmploc.dll/RT_STRING/#1753;WM/Mood=res://wmploc.dll/RT_STRING/#1819;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/Period=res://wmploc.dll/RT_STRING/#1765;RequestState=res://wmploc.dll/RT_STRING/#1930;SyncInfo=res://wmploc.dll/RT_STRING/#5423;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;Label=res://wmploc.dll/RT_STRING/#1742;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;RequestState=res://wmploc.dll/RT_STRING/#1930;
WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;Title=res://wmploc.dll/RT_STRING/#1700;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;Actor=res://wmploc.dll/RT_STRING/#2341;UserRating=res://wmploc.dll/RT_STRING/#1731;Duration=res://wmploc.dll/RT_STRING/#1710;Bitrate=res://wmploc.dll/RT_STRING/#1711;FileSize=res://wmploc.dll/RT_STRING/#881;FileType=res://wmploc.dll/RT_STRING/#1723;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;
RecordingTime=res://wmploc.dll/RT_STRING/#1751;Series=res://wmploc.dll/RT_STRING/#1935;Episode=res://wmploc.dll/RT_STRING/#1936;Duration=res://wmploc.dll/RT_STRING/#1710;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Series=res://wmploc.dll/RT_STRING/#1935;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;Episode=res://wmploc.dll/RT_STRING/#1936;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Series=res://wmploc.dll/RT_STRING/#1935;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Episode=res://wmploc.dll/RT_STRING/#1936;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;
DateTaken=res://wmploc.dll/RT_STRING/#1757;Caption=res://wmploc.dll/RT_STRING/#1758;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Category=res://wmploc.dll/RT_STRING/#1764;Author=res://wmploc.dll/RT_STRING/#1701;
Caption=res://wmploc.dll/RT_STRING/#1758;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;FileSize=res://wmploc.dll/RT_STRING/#881;DateTaken=res://wmploc.dll/RT_STRING/#1757;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;WM/Category=res://wmploc.dll/RT_STRING/#1764;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;
Caption=res://wmploc.dll/RT_STRING/#1758;Author=res://wmploc.dll/RT_STRING/#1701;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;DateTaken=res://wmploc.dll/RT_STRING/#1757;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Category=res://wmploc.dll/RT_STRING/#1764;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;Subject=res://wmploc.dll/RT_STRING/#1706;CameraManufacturer=res://wmploc.dll/RT_STRING/#1756;CameraModel=res://wmploc.dll/RT_STRING/#1862;
Title=res://wmploc.dll/RT_STRING/#1700;UserRating=res://wmploc.dll/RT_STRING/#1731;Duration=res://wmploc.dll/RT_STRING/#1710;Bitrate=res://wmploc.dll/RT_STRING/#1711;FileSize=res://wmploc.dll/RT_STRING/#881;FileType=res://wmploc.dll/RT_STRING/#1723;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;WM/Category=res://wmploc.dll/RT_STRING/#1764;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;MediaType=res://wmploc.dll/RT_STRING/#1715;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Author=res://wmploc.dll/RT_STRING/#1701;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;MediaType=res://wmploc.dll/RT_STRING/#1715;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/ContentGroupDescription=res://wmploc.dll/RT_STRING/#1920;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/PartOfSet=res://wmploc.dll/RT_STRING/#1759;WM/Language=res://wmploc.dll/RT_STRING/#1735;WM/InitialKey=res://wmploc.dll/RT_STRING/#1753;WM/Mood=res://wmploc.dll/RT_STRING/#1819;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/Period=res://wmploc.dll/RT_STRING/#1765;RequestState=res://wmploc.dll/RT_STRING/#1930;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Title=res://wmploc.dll/RT_STRING/#1700;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;WM/Category=res://wmploc.dll/RT_STRING/#1764;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;
Title=res://wmploc.dll/RT_STRING/#1700;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Category=res://wmploc.dll/RT_STRING/#1764;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Copyright=res://wmploc.dll/RT_STRING/#1705;
Title=res://wmploc.dll/RT_STRING/#1700;CallLetters=res://wmploc.dll/RT_STRING/#1738;Bitrate=res://wmploc.dll/RT_STRING/#1711;Frequency=res://wmploc.dll/RT_STRING/#1732;Location=res://wmploc.dll/RT_STRING/#1734;WM/Language=res://wmploc.dll/RT_STRING/#1735;Abstract=res://wmploc.dll/RT_STRING/#1717;Author=res://wmploc.dll/RT_STRING/#1701;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;SourceURL=res://wmploc.dll/RT_STRING/#1713;WM/Provider=res://wmploc.dll/RT_STRING/#914;Frequency=res://wmploc.dll/RT_STRING/#1732;CallLetters=res://wmploc.dll/RT_STRING/#1738;RadioLogoURL=res://wmploc.dll/RT_STRING/#1699;Location=res://wmploc.dll/RT_STRING/#1734;RadioGenre=res://wmploc.dll/RT_STRING/#1869;Abstract=res://wmploc.dll/RT_STRING/#1717;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;FileType=res://wmploc.dll/RT_STRING/#1723;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
OriginalIndexLeft=res://wmploc.dll/RT_STRING/#926;Title=res://wmploc.dll/RT_STRING/#1700;Duration=res://wmploc.dll/RT_STRING/#1710;Status=res://wmploc.dll/RT_STRING/#912;Artist=res://wmploc.dll/RT_STRING/#1707;WM/Composer=res://wmploc.dll/RT_STRING/#1724;WM/Genre=res://wmploc.dll/RT_STRING/#1709;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/Provider=res://wmploc.dll/RT_STRING/#914;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;OriginalIndexLeft=res://wmploc.dll/RT_STRING/#926;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;Label=res://wmploc.dll/RT_STRING/#1742;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Period=res://wmploc.dll/RT_STRING/#1765;Status=res://wmploc.dll/RT_STRING/#912;
Title=res://wmploc.dll/RT_STRING/#1700;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Producer=res://wmploc.dll/RT_STRING/#1748;Studio=res://wmploc.dll/RT_STRING/#1743;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;Copyright=res://wmploc.dll/RT_STRING/#1705;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;
/:*?"<>|
?http
Microsoft Windows Media Configuration Utility
12.0.7601.17514 (win7sp1_rtm.101119-1850)
Windows
Operating System

RegSvcs.exe_3932:

.text
`.rsrc
@.reloc
c.Va8o
g .GZa8
;.Za8
{m.MZ &
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
System.Drawing.Size
A third party is requesting access to remotely control this system, if this was not initialized by the system administrator, please click Decline. Please contact support@nanocore.io for more information.
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
2.Lt?
'B@%F
X.Wf9
~-.VR;|w
Kh.gb
%xl|66
w#.MG /4
v2.0.50727
Client.exe
Microsoft.VisualBasic
System.Windows.Forms
System.Drawing
dnsapi.dll
kernel32.dll
ntdll.dll
advapi32.dll
W>B/f4tSiy"7W7h#h\]|ReLf#-.resources
6sG:tBn\&6NqDbuV:1 kT4j\ ^!.resources
Data.bin
.cctor
System.IO
.ctor
System.Runtime.CompilerServices
System.Text
System.Diagnostics
Microsoft.VisualBasic.ApplicationServices
System.ComponentModel
System.CodeDom.Compiler
Microsoft.VisualBasic.Devices
HelpKeywordAttribute
System.ComponentModel.Design
Microsoft.VisualBasic.CompilerServices
System.Collections
System.Reflection
ContainsKey
InvalidOperationException
System.Runtime.InteropServices
System.Net
System.Net.Sockets
System.Collections.Generic
System.Threading
get_Port
get_LastOperation
SocketAsyncOperation
CreatePipe
PipeCreated
NanoCore.ClientPlugin
NanoCore.ClientPluginHost
Operators
System.Security.Cryptography
set_Key
System.IO.Compression
set_WindowState
FormWindowState
System.Globalization
System.Resources
OperatingSystem
KeyValuePair`2
get_Key
GetExecutingAssembly
get_ExecutablePath
RegistryKey
Microsoft.Win32
OpenSubKey
WindowsIdentity
System.Security.Principal
WindowsPrincipal
WindowsBuiltInRole
set_UseShellExecute
set_WindowStyle
ProcessWindowStyle
MsgBox
MsgBoxResult
MsgBoxStyle
ClosePipe
pipeName
PipeExists
PipeClosed
System.Security.AccessControl
SetThreadExecutionState
RegOpenKeyEx
RegCloseKey
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
CopyKeyToolStripMenuItem
1.3.1.0
2013-2017
$cdeb5371-7680-4d79-96d9-2733150e1362
NanoCore.io
ConfuserEx v1.0.0
_CorExeMain
mscoree.dll
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="hXXp://VVV.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
compatibility then delete the requestedExecutionLevel node.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<!-- A list of all Windows versions that this application is designed to work with.
Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows Vista, uncomment the following supportedOS node-->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
<!-- If your application is designed to work with Windows 8, uncomment the following supportedOS node-->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>-->
<!-- If your application is designed to work with Windows 8.1, uncomment the following supportedOS node-->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>-->
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
$this.Icon
Label2.Text
NotifyIcon1.Icon

RegSvcs.exe_3932_rwx_00070000_0005C000:

.text
`.rsrc
@.reloc
c.Va8o
g .GZa8
;.Za8
{m.MZ &
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
QSystem.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
System.Drawing.Size
A third party is requesting access to remotely control this system, if this was not initialized by the system administrator, please click Decline. Please contact support@nanocore.io for more information.
fSystem.Drawing.Icon, System.Drawing, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
2.Lt?
'B@%F
X.Wf9
~-.VR;|w
Kh.gb
%xl|66
w#.MG /4
v2.0.50727
Client.exe
Microsoft.VisualBasic
System.Windows.Forms
System.Drawing
dnsapi.dll
kernel32.dll
ntdll.dll
advapi32.dll
W>B/f4tSiy"7W7h#h\]|ReLf#-.resources
6sG:tBn\&6NqDbuV:1 kT4j\ ^!.resources
Data.bin
.cctor
System.IO
.ctor
System.Runtime.CompilerServices
System.Text
System.Diagnostics
Microsoft.VisualBasic.ApplicationServices
System.ComponentModel
System.CodeDom.Compiler
Microsoft.VisualBasic.Devices
HelpKeywordAttribute
System.ComponentModel.Design
Microsoft.VisualBasic.CompilerServices
System.Collections
System.Reflection
ContainsKey
InvalidOperationException
System.Runtime.InteropServices
System.Net
System.Net.Sockets
System.Collections.Generic
System.Threading
get_Port
get_LastOperation
SocketAsyncOperation
CreatePipe
PipeCreated
NanoCore.ClientPlugin
NanoCore.ClientPluginHost
Operators
System.Security.Cryptography
set_Key
System.IO.Compression
set_WindowState
FormWindowState
System.Globalization
System.Resources
OperatingSystem
KeyValuePair`2
get_Key
GetExecutingAssembly
get_ExecutablePath
RegistryKey
Microsoft.Win32
OpenSubKey
WindowsIdentity
System.Security.Principal
WindowsPrincipal
WindowsBuiltInRole
set_UseShellExecute
set_WindowStyle
ProcessWindowStyle
MsgBox
MsgBoxResult
MsgBoxStyle
ClosePipe
pipeName
PipeExists
PipeClosed
System.Security.AccessControl
SetThreadExecutionState
RegOpenKeyEx
RegCloseKey
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
CopyKeyToolStripMenuItem
1.3.1.0
2013-2017
$cdeb5371-7680-4d79-96d9-2733150e1362
NanoCore.io
ConfuserEx v1.0.0
_CorExeMain
mscoree.dll
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="hXXp://VVV.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
compatibility then delete the requestedExecutionLevel node.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<!-- A list of all Windows versions that this application is designed to work with.
Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows Vista, uncomment the following supportedOS node-->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS>-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
<!-- If your application is designed to work with Windows 8, uncomment the following supportedOS node-->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS>-->
<!-- If your application is designed to work with Windows 8.1, uncomment the following supportedOS node-->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>-->
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
$this.Icon
Label2.Text
NotifyIcon1.Icon

RegSvcs.exe_3932_rwx_00410000_00010000:

O-]

SearchProtocolHost.exe_3696:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
MSSHooks.dll
IMM32.dll
SHLWAPI.dll
SrchCollatorCatalogInfo
SrchDSSLogin
SrchDSSPortManager
SrchPHHttp
SrchIndexerQuery
SrchIndexerProperties
SrchIndexerPlugin
SrchIndexerClient
SrchIndexerSchema
Msidle.dll
Failed to get REGKEY_FLTRDMN_MS_TO_IDLE, using default
pfps->psProperty.ulKind is LPWSTR but psProperty.lpwstr is NULL or empty
d:\win7sp1_gdr\enduser\mssearch2\common\utils\crchash.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrdmn\fltrdaemon.cxx
d:\win7sp1_gdr\enduser\mssearch2\search\common\include\secutil.hxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracerhelpers.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
</MSG></TRC>
<MSG>
<ERR> 0xx=
<LOC> %s(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%s"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%s"
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
SHELL32.dll
PROPSYS.dll
ntdll.dll
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
MsgWaitForMultipleObjects
SearchProtocolHost.pdb
2 2(20282|2
4%5S5
Software\Microsoft\Windows Search
https
kernel32.dll
msTracer.dll
msfte.dll
lX-X-X-XX-XXXXXX
SOFTWARE\Microsoft\Windows Search
tquery.dll
%s\%s
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
advapi32.dll
WAPI-MS-Win-Core-LocalRegistry-L1-1-0.dll
winhttp.dll
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<LOC> %S(%d) </LOC>
tagname="%S"
logname="%S"
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
Microsoft Windows Search Protocol Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchProtocolHost.exe
Windows
7.00.7601.17610

SearchFilterHost.exe_4088:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
msvcrt.dll
USER32.dll
ole32.dll
OLEAUT32.dll
TQUERY.DLL
IMM32.dll
MSSHooks.dll
mscoree.dll
SHLWAPI.dll
d:\win7sp1_gdr\enduser\mssearch2\search\search\gather\fltrhost\bufstm.cxx
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\mutex.cpp
RegDeleteKeyW
RegDeleteKeyExW
8%uiP
d:\win7sp1_gdr\enduser\mssearch2\common\include\srchxcpt.hxx
Invalid parameter passed to C runtime function.
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracersecutil.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.cpp
-d-d-d-d-d-d-d-%d
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\tracmain.h
d:\win7sp1_gdr\enduser\mssearch2\common\tracer\sysimprs.cxx
RegCloseKey
RegCreateKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ReportEventW
_amsg_exit
SearchFilterHost.pdb
version="5.1.0.0"
name="Microsoft.Windows.Search.MSSFH"
<requestedExecutionLevel
3 3(30383|3
kernel32.dll
Software\Microsoft\Windows Search
SOFTWARE\Microsoft\Windows Search
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Windows Search Service
tquery.dll
advapi32.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
<Exception><HR>0xx</HR><eip>%p</eip><module>%S</module><line>%d</line></Exception>
Software\Microsoft\Windows Search\Tracing
Software\Microsoft\Windows Search\Tracing\EventThrottleLastReported
Software\Microsoft\Windows Search\Tracing\EventThrottleState
<MSG>
<ERR> 0xx=
<LOC> %S(%d) </LOC>
tid="0x%x"
pid="0x%x"
tagname="%S"
tagid="0x%x"
el="0x%x"
time="d/d/d d:d:d.d"
logname="%S"
</MSG></TRC>
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
winhttp.dll
Microsoft Windows Search Filter Host
7.00.7601.17610 (win7sp1_gdr.110503-1502)
SearchFilterHost.exe
Windows
7.00.7601.17610


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    wmplayer.exe:4020
    bSXA.exe:3956
    ONThSCDifK.exe:3624
    %original file name%.exe:3836

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp08997.WMC\allservices.xml (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp15050.WMC\serviceinfo.xml (908 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wmsetup.log (10294 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\88DCD395-B062-45B3-A6CD-79F37C0EBA08\run.dat (8 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iVMVEUYYdfUT.lnk (846 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\iVMVEUYYdfUT.mp4 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\autE57E.tmp (196 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\bSXA.exe (937 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Roaming\FHeOM.au3 (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tfgtgho (980 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\ONThSCDifK.exe (73353 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "wextract_cleanup0" = "rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 C:\Users\"%CurrentUserName%"\AppData\Local\Temp\IXP000.TMP\"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now