Backdoor.Win32.Fynloski_76b289a2b6

by malwarelabrobot on May 28th, 2017 in Malware Descriptions.

Backdoor:Win32/Fynloski.A (Microsoft), Backdoor.Win32.DarkKomet.aaco (Kaspersky), Win32.HLLW.Autoruner.25074 (DrWeb), BackDoor-FBHS!76B289A2B6A4 (McAfee), Trojan-Dropper.MSIL (Ikarus), Dropper.Msil.CN (AVG), MSIL:GenMalicious-AOH [Trj] (Avast), Backdoor.Win32.Fynloski.FD, Trojan.Win32.Iconomon.FD, Trojan.Win32.Sasfis.FD, VirTool.Win32.DelfInject.FD, BackdoorFynloski.YR, GenericDownloader.YR, GenericInjector.YR, TrojanDownloaderAndromeda.YR (Lavasoft MAS)
Behaviour: Trojan-Dropper, Trojan-Downloader, Trojan, Backdoor, VirTool


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 76b289a2b6a486b5acdbc352faac6728
SHA1: d3f21697a18d99ff91823d06cf08855fed88e703
SHA256: 915e1ec8aa3c31b7fb81a3d56bc72ae297f4f568a47cdbcd999cd6ea1bd5b210
SSDeep: 98304:WbDUk5 QdQ/thuwac/2WLrd27V7 MQC5MrQU/:WbD95ps3Br87 MBIQ
Size: 4083712 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: MicrosoftVisualC, NETexecutable, UPolyXv05_v6
Company: no certificate found
Created at: 2017-04-22 17:45:28
Analyzed on: Windows7 SP1 32-bit


Summary:

Backdoor. Malware that enables a remote control of victim's machine.

Payload

No specific payload has been found.

Process activity

The Backdoor creates the following process(es):

wmplayer.exe:2776
notepad.exe:1956
%original file name%.exe:2928
LocalnJhGiFZrWl.exe:1780

The Backdoor injects its code into the following process(es):

setup_wm.exe:1492
msdcsc.exe:1916
notepad.exe:560

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process setup_wm.exe:1492 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wmsetup.log (7518 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp29642.WMC\allservices.xml (1 bytes)
C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp31061.WMC\serviceinfo.xml (908 bytes)

The process notepad.exe:1956 makes changes in the file system.
The Backdoor deletes the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalnJhGiFZrWl.exe (0 bytes)

The process %original file name%.exe:2928 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\AppData\LocalnJhGiFZrWl.exe (1350 bytes)
C:\Users\"%CurrentUserName%"\AppData\LocalMaMWGJRGaK.mp3 (3 bytes)

The process LocalnJhGiFZrWl.exe:1780 makes changes in the file system.
The Backdoor creates and/or writes to the following file(s):

C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe (5220 bytes)

Registry activity

The process setup_wm.exe:1492 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"ImageLargeURL" = "http://images.windowsmedia.com/svcswitch/mg4_wmp12_30x30_2.png"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_CurrentDialog" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"Type" = "1"

[HKCU\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache]
"0" = "8C 53 00 00 65 68 63 66 00 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_MaxInstall" = "1"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services]
"NoServices" = "0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"ImageMenuURL" = "http://images.windowsmedia.com/svcswitch/media_guide_16x16.png"
"ColorPlayer" = "#0063B0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"Progress_MaxDialog" = "6"
"Progress_CurrentInstall" = "0"
"InstallResult" = "0"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"Task1ButtonText" = "Media Guide"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 09 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Microsoft\MediaPlayer\Setup\UserOptions]
"DesktopShortcut" = "no"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Services\MediaGuide]
"FriendlyName" = "Media Guide"
"Task1ButtonTip" = "Media Guide"

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Preferences]
"DefaultSubscriptionService" = "MediaGuide"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Backdoor deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\MediaPlayer\Setup]
"SystemUptime"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"SQMLaunchIndex"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Multimedia\ActiveMovie\Filter Cache]
"1"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVD]
"RequiredFile"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Groups\Video\DVR-MS]
"RequiredFile"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"ForceUsageTracking"

[HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Devices\DVD]
"RequiredFile"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"

[HKCU\Software\Microsoft\MediaPlayer\Preferences]
"UsageTracking"

The process msdcsc.exe:1916 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:
To automatically run itself each time Windows is booted, the Backdoor adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"MicroUpdate" = "C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe"

User account control (UAC) is disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA" = "0"

Firewall notifications are enabled:

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = "0"

A firewall is disabled:

"EnableFirewall" = "0"

The process wmplayer.exe:2776 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
"UNCAsIntranet" = "0"

The Backdoor deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process %original file name%.exe:2928 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached]
"{ED1D0FDF-4414-470A-A56D-CFB68623FC58} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF" = "01 00 00 00 00 00 00 00 BA BE D4 35 E1 D6 D2 01"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

The Backdoor deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

The process LocalnJhGiFZrWl.exe:1780 makes changes in the system registry.
The Backdoor creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"AccessibilityCpl.dll,-10" = "Ease of Access Center"
"gameux.dll,-10082" = "Games Explorer"
"gameux.dll,-10061" = "Spider Solitaire"
"pmcsnap.dll,-700" = "Print Management"
"wdc.dll,-10021" = "Performance Monitor"
"mblctr.exe,-1008" = "Windows Mobility Center"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E]
"LanguageList" = "en-US, en"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"mycomput.dll,-300" = "Computer Management"
"SyncCenter.dll,-3000" = "Sync Center"
"msinfo32.exe,-100" = "System Information"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\WindowsPowerShell\v1.0]
"powershell.exe,-101" = "Windows PowerShell ISE"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10060" = "Solitaire"
"ie4uinit.exe,-737" = "Internet Explorer (No Add-ons)"
"odbcint.dll,-1310" = "Data Sources (ODBC)"
"gameux.dll,-10103" = "Internet Spades"
"MdSched.exe,-4001" = "Windows Memory Diagnostic"
"gameux.dll,-10059" = "Mahjong Titans"
"wucltux.dll,-1" = "Windows Update"
"dfrgui.exe,-103" = "Disk Defragmenter"
"filemgmt.dll,-2204" = "Services"
"gameux.dll,-10102" = "Internet Backgammon"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\migwiz]
"wet.dll,-588" = "Windows Easy Transfer"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"NetProjW.dll,-501" = "Connect to a Network Projector"
"rstrui.exe,-100" = "System Restore"
"SoundRecorder.exe,-100" = "Sound Recorder"
"gameux.dll,-10055" = "FreeCell"

"gameux.dll,-10209" = "More Games from Microsoft"
"wsecedit.dll,-718" = "Local Security Policy"
"gameux.dll,-10056" = "Hearts"
"gameux.dll,-10057" = "Minesweeper"
"gameux.dll,-10054" = "Chess Titans"
"comres.dll,-3410" = "Component Services"
"msra.exe,-100" = "Windows Remote Assistance"
"ntshrui.dll,-103" = "S&hare with"
"wdc.dll,-10030" = "Resource Monitor"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"ShapeCollector.exe,-298" = "Personalize Handwriting Recognition"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Windows Journal]
"Journal.exe,-3074" = "Windows Journal"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"FXSRESM.dll,-114" = "Windows Fax and Scan"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\DVD Maker]
"DVDMaker.exe,-61403" = "Windows DVD Maker"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\Speech\SpeechUX]
"sapi.cpl,-5555" = "Windows Speech Recognition"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"displayswitch.exe,-320" = "Connect to a Projector"
"iscsicpl.dll,-5001" = "iSCSI Initiator"
"sdcpl.dll,-101" = "Backup and Restore"
"msconfig.exe,-126" = "System Configuration"
"recdisc.exe,-2000" = "Create a System Repair Disc"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"mip.exe,-291" = "Math Input Panel"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Windows Sidebar]
"sidebar.exe,-1005" = "Desktop Gadget Gallery"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10058" = "Purble Place"
"AuthFWGP.dll,-20" = "Windows Firewall with Advanced Security"
"miguiresource.dll,-101" = "Event Viewer"
"XpsRchVw.exe,-102" = "XPS Viewer"
"miguiresource.dll,-201" = "Task Scheduler"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32\migwiz]
"wet.dll,-591" = "Windows Easy Transfer Reports"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@C:\Windows\system32]
"gameux.dll,-10101" = "Internet Checkers"

[HKCU\Software\Classes\Local Settings\MuiCache\30\52C64B7E\@%Program Files%\Common Files\Microsoft Shared\Ink]
"TipTsf.dll,-80" = "Tablet PC Input Panel"

The Backdoor adds the reference to itself to be executed when a user logs on:

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe"

To automatically run itself each time Windows is booted, the Backdoor adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"MicroUpdate" = "C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe"

The Backdoor deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
"IntranetName"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"

Dropped PE files

MD5 File path
a31a8fa934d74c88d5ad7b80347d23d1 c:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name:
Product Version: 0.0.0.0
Legal Copyright:
Legal Trademarks:
Original Filename: HISAR MT2 IFSA.Scr
Internal Name: HISAR MT2 IFSA.Scr
File Version: 0.0.0.0
File Description:
Comments:
Language: Chinese (Simplified, PRC)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 8192 4028388 4030464 5.43926 2e283b3b7d96699fdf5065e49bf1e981
.rsrc 4038656 41304 45056 4.48633 d4a896157515efad8dc787bcd221b563
.reloc 4087808 12 4096 0.011373 5cb4373056a1a8e0e2dc2d34951413b4

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://a1095.g2.akamai.net/redir/allservices/?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
hxxp://a177.g.akamai.net/serviceswitching/AllServices.aspx?sv=5&version=12.0.7601.17514&locale=409&userlocale=409&geoid=f4&parch=x86&arch=x86
hxxp://a1076.g.akamai.net/svcswitch/MG_en-us.xml


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

Traffic

The Backdoor connects to the servers at the folowing location(s):

conhost.exe_2972:

.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
Bv.SCv
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641

conhost.exe_2920:

.text
`.data
.rsrc
@.reloc
GDI32.dll
USER32.dll
msvcrt.dll
ntdll.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
KERNEL32.dll
IMM32.dll
ole32.dll
OLEAUT32.dll
Bv.SCv
PutInputInBuffer: EventsWritten != 1 (0x%x), 1 expected
Invalid message 0x%x
InitExtendedEditKeys: Unsupported version number(%d)
Console init failed with status 0x%x
CreateWindowsWindow failed with status 0x%x, gle = 0x%x
InitWindowsStuff failed with status 0x%x (gle = 0x%x)
InitSideBySide failed create an activation context. Error: %d
GetModuleFileNameW requires more than ScratchBufferSize(%d) - 1.
GetModuleFileNameW failed %d.
Invalid EventType: 0x%x
Dup handle failed for %d of %d (Status = 0x%x)
Couldn't grow input buffer, Status == 0x%x
InitializeScrollBuffer failed, Status = 0x%x
CreateWindow failed with gle = 0x%x
Opening Font file failed with error 0x%x
\ega.cpi
NtReplyWaitReceivePort failed with Status 0x%x
ConsoleOpenWaitEvent failed with Status 0x%x
NtCreatePort failed with Status 0x%x
GetCharWidth32 failed with error 0x%x
GetTextMetricsW failed with error 0x%x
GetSystemEUDCRangeW: RegOpenKeyExW(%ws) failed, error = 0x%x
RtlStringCchCopy failed with Status 0x%x
Cannot allocate 0n%d bytes
|%SWj
O.fBf;
ReCreateDbcsScreenBuffer failed. Restoring to CP=%d
Invalid Parameter: 0x%x, 0x%x, 0x%x
ConsoleKeyInfo buffer is full
Invalid screen buffer size (0x%x, 0x%x)
SetROMFontCodePage: failed to memory allocation %d bytes
FONT.NT
Failed to set font image. wc=x, sz=(%x,%x)
Failed to set font image. wc=x sz=(%x, %x).
Failed to set font image. wc=x sz=(%x,%x)
FullscreenControlSetColors failed - Status = 0x%x
FullscreenControlSetPalette failed - Status = 0x%x
WriteCharsFromInput failed 0x%x
WriteCharsFromInput failed %x
RtlStringCchCopyW failed with Status 0x%x
CreateFontCache failed with Status 0x%x
FTPh
\>.Sj
GetKeyboardLayout
MapVirtualKeyW
VkKeyScanW
GetKeyboardState
UnhookWindowsHookEx
SetWindowsHookExW
GetKeyState
ActivateKeyboardLayout
GetKeyboardLayoutNameA
GetKeyboardLayoutNameW
_amsg_exit
_acmdln
ShipAssert
NtReplyWaitReceivePort
NtCreatePort
NtEnumerateValueKey
NtQueryValueKey
NtOpenKey
NtAcceptConnectPort
NtReplyPort
SetProcessShutdownParameters
GetCPInfo
conhost.pdb
%$%a%b%V%U%c%Q%W%]%\%[%
%<%^%_%Z%T%i%f%`%P%l%g%h%d%e%Y%X%R%S%k%j%
version="5.1.0.0"
name="Microsoft.Windows.ConsoleHost"
<requestedExecutionLevel
name="Microsoft.Windows.ConsoleHost.SystemDefault"
publicKeyToken="6595b64144ccf1df"
name="Microsoft.Windows.SystemCompatible"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
< =$>:>@>
2%2X2
%SystemRoot%
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\TrueTypeFont
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Console\FullScreen
WindowSize
ColorTableu
ExtendedEditkeyCustom
ExtendedEditKey
Software\Microsoft\Windows\CurrentVersion
\ !:=/.<>;|&
%d/%d
cmd.exe
desktop.ini
\console.dll
%d/%d
6.1.7601.17641 (win7sp1_gdr.110623-1503)
CONHOST.EXE
Windows
Operating System
6.1.7601.17641

setup_wm.exe_1492:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
GDI32.dll
USER32.dll
msvcrt.dll
ATL.DLL
pdh.dll
ole32.dll
OLEAUT32.dll
COMCTL32.dll
SHELL32.dll
gdiplus.dll
WININET.dll
SETUPAPI.dll
WINTRUST.dll
urlmon.dll
SHLWAPI.dll
CRYPT32.dll
USERENV.dll
Secur32.dll
SSPICLI.DLL
VERSION.dll
MPR.dll
MF.dll
AEw.AEw
?ERROR: This functionality not supported on Vista.
Done importing library.
Calling import library.
DoMediaLibraryImport returned 0x%x.
ERROR: Note that Windows Update failures are tracked in %windir%\WindowsUpdate.log
ERROR: Could not load data for client '%S': '0x%x'.
%d updates were attempted. %d updates have been successfully downloaded and installed. %d updates failed to install
ERROR: Failed to get result code for Installation result:'0x%x'.
ERROR: Failed to get installation result :'0x%x'.
ERROR: Failed to use WUA API to download and install updates: '0x%x'.
ERROR: Failed to get updates ready for download and install: '0x%x'.
ERROR: Failed to include an update in the queue: '0x%x'.
ERROR: Failed to retrieve update type: '0x%x'.
ERROR: Failed to retrieve update title: '0x%x'.
ERROR: Failed to retrieve update by index: '0x%x'.
ERROR: Failed to count updates from Windows Update Site: '0x%x'.
ERROR: Failed to retrieve updates from Windows Update Site: '0x%x'.
ERROR: An error occured when scanning Windows Update Site for new updates: Error %lu.
ERROR: Failed to retrieve result code after scanning Windows Update Site for new updates: '0x%x'
ERROR: Failed to scan Windows Update Site for new updates.
ERROR: Failed to scan Windows Update Site for new updates: '0x%x'.
ERROR: Failed to set Windows Update top query offline catalog: '0x%x'.
ERROR: Could not create Update Collection: '0x%x'.
Could not create Update Installer: '0x%x'. This is expected for non-admins.
4dt ERROR: Could not create Update Searcher: '0x%x'.
Starting to scan WU Site for new updates for client %S.
?Another Update.exe package is running on the box.
Install denied: Unsupported OS.
Install denied: Unsupported Media Center OS. Version is %#1.1lf.
NOTICE: Windows Media Player is currently running.
Media Library import completed.
Uninstall has failed: 0x%x.
ERROR: Web Help URL could not be generated.
Setup has failed: '0x%x'.
ERROR: Registration for restart event for setup_wm.exe failed.
Setup commandlines are %S.
ERROR: Invalid control launching privacy URL.
XML default %S matches currently selected OEM service %S - service dialog not shown.
Finished building install list. Result: '0x%x'.
Download complete. Result: '0x%x'.
Could not set system restore end point: error 0x%x.
%S Setup complete. Result: '0x%x'.
Launching %S Install.
Windows Update Setup complete. Result: '0x%x'.
Setup complete. Result: '0x%x'.
ERROR: Could not set system restore point: error 0x%x.
System restore is not supported on this system.
Installed %S
=====Installing Install list. Last result: 0x%x.
CreateEvent For ExitSyncEvent failed. LastError: '0x%x'.
%d updates have been successfully downloaded and installed.
Service '%S' is either not installed or has not been used yet.
Service '%S' is already installed.
ERROR: XML for service '%S' is invalid and missing either the EULA or Privacy URL.
ERROR: Service key is not defined.
Service '%S' should be shown to user.
Default service is now set to: '%S'.
Could not retrieve service information URL: '0x%x'.
Services information URL is : '%S'.
XML Parser: Failed to Load DOM. Result: '0x%x'.
XML Parser: Parsing Element '%S': '%S'.
ERROR: Code URL specified but no InstallApp indicated. Install is not possible.
XML Parser: Parsing child element '%S': '%S'.
XML Parser: Parsing element '%S': '%S'.
XML Parser: Parsing element '%S: '%S''.
The XML default service is: '%S'.
OEM service override is: '%S'.
Previous service is: '%S'.
Legacy service is: '%S'.
ERROR: Package download failure has occured. Result: 0x%x.
ERROR: Download failed. Result: '0x%x'.
Unable to establish connection: 0x%x.
ERROR: Catalog download failed because '%S' could not be created. Error '0x%x'.
ERROR: Catalog download failed: '0x%x'.
XML Parser: AddService returned '0x%x'.
XML Parser: ServiceNameFromXML: '%S'.
XML-specified default service is: '%S'.
XML Parser: PopulateFromXML returned: '0x%x'.
XML Parser: LoadFile for service xml failed. Result: '0x%x'.
XML Parser: loading root element from xml failed. Result: '0x%x'.
XML Parser: Loading nodes from xml element failed. Result: '0x%x'.
XML Service content partner status: '%S'.
XML Service key name is: '%S'.
XML Service key name '%S' is already set as '%S'.
Command line-specified default service is: '%S'.
Specified service is not valid: '0x%x'.
Service added from command line: 0x%x.
ERROR: Cab extraction failed for '%S'. Error 0x%x.
Install for %S returned 0x%x.
Service install returned 0x%x.
Executing: %S %S.
Cab extraction succeeded for '%S'.
ERROR: Service information could not be retrieved for '%S': 0x%x.
Retrieving key files for '%S'.
Service data gathering returned 0x%x.
Service data gathering complete: %lu interesting service(s) found. Result 0x%x.
control.xml
Component '%S' can not be installed: file '%S' not found.
Component '%S' can not be installed: No install package available.
Component '%S' can not be uninstalled: file '%S' not found.
Component '%S' can not be uninstalled: No uninstall package available.
ERROR: Unable to obtain base URL for UDB file. Result: '0x%x'.
LANG=%s&
UDBBaseURL
XML Parser: Found value '%S' for attribute '%S'.
Reg Parser: Obtained value '%S' for attribute '%S'.
ERROR: XML Parser: Failed to add dependency information from XML. Last result: 0x%x.
XML Parser: No data available for Dependency attribute '%S'.
ERROR: XML Parser: Could not set Dependency attribute '%S'.
ERROR: XML Parser: Missing required Dependency attribute '%S'.
ERROR: Reg Parser: Failed to add dependency information from reg. Result: 0x%x.
ERROR: Reg Parser: Missing required Dependency attribute '%S'.
Reg parser: Adding dependency '%S'.
Adding dependency type '%S' to registry.
Package clean-up: Cleaning up files at '%S'.
WARNING: Base URL is not set. All packages must be available locally.
ERROR: Package download failure for '%S'. Result: 0x%x.
%stmpd.WMC\%s
%stmpd.WMC
Package install complete. Last result 0x%x.
ERROR: Execution of %S failed. Setup will not fail because of this issue.
ERROR: %S was not executed as the WMP11 install check was -ve. Setup will not fail because of this issue.
wmdbexport.exe was not run as wmp11 installs did not complete.
ERROR: Install of %S failed. Setup will not fail because of this issue.
ERROR: Install for package was halted. RunDll32.exe was not found on the system.
Uninstall for component '%S' required reboot.
Uninstall commandline for component '%S' is %S.
Uninstall for component '%S' not available.
Uninstall of component '%S' returned 0x%x.
Beginning Uninstall of component '%S'.
Removing component database for '%S'.
ERROR: Reg Parser: Failed to add uninstall information from reg. Last result: 0x%x.
ERROR: Setup missing uninstall file: '%S'.
ERROR: Reg Parser: Missing required Package attribute '%S'.
ERROR: XML Parser: Failed to add package information from XML. Result: 0x%x.
ERROR: XML Parser: No install available locally, URL not provided.
ERROR: XML Parser: Missing required Package attribute '%S'.
Created instance of download manager. Now converting URL to ANSI.
DownloadFileFromURL: We '%hs' force a connection.
ERROR: UDB file not downloaded. Result: '0x%x'.
Beginning download of component '%S'.
A download will be required for component '%S' from URL '%S'.
ERROR: Component '%S' is NOT available for install.
Component '%S' may be installable from URL: '%S'.
ERROR: XML Parser: Failed to add component from XML. Result: 0x%x.
ERROR: XML Parser: Missing required component attribute '%S'.
ERROR: Reg Parser: Failed to add component from reg. Result: 0x%x.
ERROR: Reg Parser: Missing required component attribute '%S'.
Added Component %S to Uninstall.
Failed to Add Component %S to Uninstall.
Package '%S' is not currently installed: no version of it appears to be present on the system.
Package '%S' is version '%S'. This is '%S' than the version currently installed.
Package '%S' does not appear to be installed as there is no specific version to check against.
Warning: Base URL not defined in XML.
XML Parser: Parsing Element '%S'.
Install for component '%S' was halted. Ran out of disk space. Needed at least %lu kbytes more.
Install for component '%S' was halted. A required component was not available.
Install for component '%S' was halted. Component is not available for install.
Install for component '%S' was halted. It was deemed already installed.
======Installing component '%S'.
ERROR: Attempted to install '%S' which had been marked as noninstallable.
SUCCESS: Package '%S'. Result: 0x%x.
ERROR: Package '%S'. Result: 0x%x.
OS is %s. OSVer is %S.%lu. System Lang is %lu. Prev version system is %S. Setup version %S.]
wmsetup.log
lu:lu%:lu - %s
PendingFileRenameOperations
ERROR: Could not set AllowProtectedRename flag for SFP. Error: 0x%x
%S: File signature not validated: WinVerifyTrust on file '%S' returned 0x%x.
WinVerifyTrust on file '%S' returned 0x%x.
ERROR: Decryption failed for file '%S'. Last result: 0x%x.
Set DirSecurity on '%S'.
GetDiskFreeSpaceEx failed. Error: '%x'
ERROR: Could not create directory '%S'. Error: '0x%x'.
Reboot requested due to '%S' file clean-up.
Reboot required due to '%S' driver installation.
Reboot requested due to '%S' file copy.
ERROR: OLE Initialization failed: '0x%x'.
File replacement for '%S' queued in non-admin file cache.
ERROR: Could not store delayed file move for '%S': '0x%x'.
ERROR: Could not store delayed action for component '%S': '0x%x'.
ERROR: Process '%S' deadlocked. Terminated after '%lu'ms.
ERROR: Process '%S' failed. Error: '0x%x'.
Starting process '%S'.
ERROR: Application '%S' not found. Process could not be executed.
Dll UnRegistration: Could not find file '%S'.
ERROR: Dll Registration: Could not find file '%S': '0x%x'.
Dll Registration: Succeeded for file '%S'.
Delayed Dll Registration: Succeeded for file '%S'.
ERROR: Dll Registration: Failed for file '%S': '0x%x'.
ERROR: Failed delaying dll registration for file '%S': '0x%x'.
Registering DLL: '%S'.
ERROR: MoveFileEx failed for file '%S'. Error: '0x%x'.
WARNING: Reboot required due to file '%S'.
ERROR: Bad file destination '%S'.
Moved file '%S' to temp location for clean-up upon reboot.
ERROR: Replace file in place failed for '%S'. File still exists.
ERROR: ReplaceFileOnReboot: Could not move file '%S' to '%S'. Error 0x%x.
Copied file '%S' to DllCache.
WMC_CopyFile: File '%S' is newer than the installed version. This file will be installed.
WMC_CopyFile: File '%S' is newer than the version to be installed. No copy will occur.
ERROR: WMC_CopyFile: Could not find file version for '%S'. This file will not be copied.
WMC_CopyFile: Could not find file version for '%S'. This file will be overwritten.
WMC_CopyFile: Could not replace file '%S'. This file will be replaced on reboot.
WMC_CopyFile: File '%S' should always to be installed. This file will be installed.
WMC_CopyFile: File '%S' is not to be installed if already present on the system. It was present and thus will not be reinstalled.
WMC_CopyFile: File '%S' was only to be installed if already present on the system. It was not present and thus will not be installed.
ERROR: WMC_CopyFile: Could not find source file '%S'. Error: '0x%x'.
Stopping service '%S' %S.
Stopping service '%S'.
ERROR: %S, 2-queryservicestatus
Starting service '%S' %S.
ERROR: %S, timed out
ERROR: %S, 1-queryservicestatus
ERROR: Failed to start service: '%S'. Result: 0x%x.
ERROR: Failed to open service: '%S'. Result: 0x%x.
ERROR: Failed to open SCM: '%S'. Result: 0x%x.
Now starting service: '%S'.
ERROR: Failed to create service: '%S'. Result: 0x%x.
Creating service '%S' %S.
Could not open service : '%S'.
Deletion of service : '%S' succeeded.
ERROR: Failed to delete service : '%S'. Result: 0x%x.
Parsing StopServices section:'%S'.
Failed to get information from inf with error code '0x%x'.
Querying service '%S' %S.
Querying service '%S'.
Parsing DeleteServices section:'%S'.
Parsing CreateServices section:'%S'.
B?%Load user profile returned 0x%x.
Warning: User profile not fully loaded: 0x%x.
User name not found: '0x%x'.
Database path not found for user %S.
WMCv2 Migration: Migrating user '%S'.
InternetDial returned: '0x%x'.
InternetAutoDial returned: '0x%x' for connection '%lu'.
InternetDial returned: '0x%x' for connection '%lu'.
InternetHangup returned: '0x%x' for connection '%lu'.
ERROR: Could not start download. Result: '0x%x'.
ERROR: WriteFile failed. Result: '0x%x'.
ERROR: InternetReadFile failed. Result: '0x%x'.
Could not determine download size for URL.
ERROR: Could not open URL: '0x%x'.
ERROR: Could not obtain connection result: '0x%x'.
ERROR: Could not open URL. Result: '0x%x'.
ERROR: HTTPSendRequest failed. Result: '0x%x'.
Download manager now connecting to URL.
ERROR: Could not open request: '0x%x'.
ERROR: Could not connect to host: '0x%x'.
ERROR: Could not crack URL: '0x%x'.
Lxhttp\shell\open\command
ERROR: Initialization of CWMXDownload failed. Result: '0x%x'.
%S:%u
HttpQueryInfoA
HttpSendRequestA
HttpOpenRequestA
InternetCrackUrlA
InternetOpenUrlA
ERROR: Unsupported use of UpdateIni: '%S'.
Could not decode INF key name:'%S'
ERROR: Registry transaction failure for: '%S'.
GetNameForCatalogOnSystem returned '0x%x'.
Another version of catalog file '%S' was previously installed.
InfParser: Set source directory '%S'.
INF: Found section '%S'.
INF: Line '%S' not found in section: '%S'. Result: 0x%x.
Processed %S line: '%S', result 0x%x.
ERROR: Registry key change failed: lRes = 0x%x.
Parsing Reg section:'%S'.
Processed UpdateIni line: '%S'.
Parsing UpdateIni section:'%S'.
Trust on catalog '%S' complete. Result: 0x%x.
ERROR: Could not add catalog '%S'. Result: 0x%x.
Added catalog '%S'. Last result: 0x%x.
ERROR: Trust on catalog '%S' failed. Could not load Crypto Lib. Last result: 0x%x.
ERROR: Trust on catalog '%S' failed. Error: 0x%x.
Trust on catalog '%S' beginning. Last result: 0x%x.
TrustCatalogFile returned 0x%x.
Trusting Catalog: '%S'.
INF: INF requested error override for '%S'.
Parsing StartServices section:'%S'.
FireNamedEvent : OpenEvent returned 0x%x.
FireNamedEvent : SetEvent returned 0x%x.
Firing event: '%S'.
ERROR: Could not set CustomDestination '%S'. Result: 0x%x.
ERROR: Could not set CustomDestination '%lu'. Result: 0x%x.
Added CustomDestination '%lu' as '%S'.
ERROR: CustomDestination '%S' not settable: LDIDs require 8 characters previous to '=' due to setupapi.
Assigned destination: '%S' for section '%S'
Parsing CustomDestination INFSection:'%S'
Attempted to delete: '%S'.
Parsing DelDirs section:'%S'.
ERROR: ProcessSetupCommand failed for: '%S': 0x%x.
Success: Ran command: '%S'.
Parsing RunCommands section: '%S'.
Parsing RegisterOCX INFSection:'%S'.
ERROR: Failed to assign destination for: '%S'.
Deleted file '%S'.
ERROR: Could not delete '%S': 0x%x.
Copied file '%S' to '%S'.
ERROR: Could not find file '%S' at source '%S' for dest '%S': 0x%x.
Assigned destination: '%S' to '%S'.
Parsing '%S' INFSection:'%S'
Source location is:'%S'.
SUCCESS: GetInstallSizeEstimate for '%S': size: '%lu'.
FAILED: GetInstallSizeEstimate for '%S': Result: 0x%x.
WARNING: Could not get size for file '%S' for INF '%S'.
GetInstallSizeEstimate for '%S': size: '%lu'.
Parsing INFSection:'%S'.
Current directory is: '%S'.
ERROR: INF parser failed on: '%S'. Result: 0x%x.
ERROR: Failed to open INF: '%S'. Result: 0x%x.
INF: Error '0x%x' reported for '%S'. Honoring INF error override and continuing.
ERROR: Invalid arguments passed to AddDirectoryToList.
\\.\VWIN32
0%D[$
H$l%%u;
setup_wm.pdb
uaSSSShhI
SSSSh@I
SSSh8
PSSh,J
j.Xf;Dq
PSSSSSSh
~j.Yf;
PSSSSSSSSh
SSSSh
u3VSSSh
j.Yf;
RegCloseKey
RegOpenKeyExW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
RegDeleteKeyW
GetWindowsDirectoryW
GetSystemWindowsDirectoryW
_acmdln
_amsg_exit
ShellExecuteExW
ShellExecuteW
GdiplusShutdown
InternetCrackUrlW
UrlMkSetSessionOption
SHDeleteKeyW
CertVerifyCertificateChainPolicy
RegOpenKeyExA
RegEnumKeyW
GetWindowsDirectoryA
MFGetSupportedSchemes
version="11.0.0.0"
name="Microsoft.Windows.MediaPlayer.SetupWM"
<asmv3:windowsSettings xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">
</asmv3:windowsSettings>
<description>Windows Media Player Setup</description>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel
KEYW
_Xrruurlljbbljnnnnljbibb^^__^_w
lrrT?.==?===;=;.Geblyxwwn
fTppTOOPORWfuwutwt
vGD%S
.MEtG
1.pOLN
.Dqi,
:::@:::(:::3:::
()* ,-.FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.-, *)))))jj
7777777
()* ,-.FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.-, *))))
4444444
:5/-/---//04477===
===777440..   25
4999999999
3333>:%%
;;<<<<9<9
'-Xjiiji}
$(0., **)
710., **)'
!<?64410.,  *)$,
246<"98">4321
/3<99;30//
.qBk'
,1#:>2.KP
10<>=.KP
/0><#.KP
23444555566
4455555666
6666666665
46666666561
6665555443*
.,    ,---
00000000
000000000
< <$<(<,<0<
3 3$3(3,303
7v7F7X7s7
11181>1]1
2!3'3/3|3
?%?8?\?|?
2?2]283\3
>1>6><>}>
5m6O6t6
Windows Media Player
e31e09cb-b1d4-4b2c-b088-0aa51c598562
hXXp://go.microsoft.com/fwlink/?LinkId=120764&mpver=%s&id=%x&contextid=%lu&originalid=%x
hXXp://go.microsoft.com/fwlink/?LinkId=120764&mpver=%s&id=%x&contextid=%lu&originalid=%lu
11.0.0.0
\\.\System\System Up Time
Software\Microsoft\Windows\CurrentVersion\Setup\WindowsFeatures
Software\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\WindowsFeatures\WindowsMediaVersion
CLASSES_ROOT\%s
wmplayer.ocx.7
wmplayer.ocx
\wmploc.dll
Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\WindowsMedia\Setup\BlockingRefCounts\%s
Software\Microsoft\MediaPlayer\Setup\BlockingRefCounts\%s
9.0.0.0
%s\%s\wmvcore.dll
%s\%s\wmploc.dll
%s.bak
\wmpband.dll
\wmdband.dll
\wmvcore.dll
\wmp.dll
setup_wm.exe
%s\%s
eula.txt
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Windows Media Player 10
Windows Media Player 9
Windows Media Player 8
Windows Media Format SDK
e88a19fb-a847-4e3d-9ae2-13c2b84f58a6
DeploymentAction='Installation' AND IsInstalled=0 AND CategoryIDs contains '%s'
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\MTPMediaPlayerArrival
Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers
%lu|%lu|%lu|%lu|%s
\notepad.exe
5.1.2600.2096
5.1.2600.2180
5.1.2700.2180
5.1.2710.2732
\ehome\ehshell.exe
%s (%lu of %lu items)
%s %s
%s /HideWMP /SetShowState
Software\Microsoft\Windows\CurrentVersion\Run
408|420|80|22
wmplayer.exe
Microsoft.Windows.MediaPlayer32
::/htm/nomoreinformationisavailable.htm
wmp11.chm
HHCTRL.OCX
hXXp://
Software\Policies\Microsoft\WindowsMediaPlayer
mshelp://windows/?id=%s
\wmplayer.exe
ginetcpl.cpl
%s%lu
E33D49A9-409C-4acd-A1F5-DA7DBB99EB30
Windows Media Player 11
\wmp11.exe
\wmp11-64.exe
sfc.dll
%s\cmd.exe /c """""%s"" /ShowWMP"""
Obtaining Updates For Windows Media Player
.WMC\
MenuURL
ServiceSmallURL
ServiceLargeURL
SetupURL
CodeURL
CatalogURL
EULAURL
EulaURL
PrivacyInfoURL
XMLURL
hXXp://go.microsoft.com/fwlink/?LinkId=52492&sv=2
Software\Microsoft\Windows\CurrentVersion\Policies\System
%stmpd%s
ImageSmallURL
ImageMenuURL
ImageLargeURL
Software\Microsoft\MediaPlayer\Services\%s
%s&partner=%lu
&geoid=%x
%s&version=%s&locale=%x&userlocale=%x
wmploc.dll
%sallservices.xml
%s%s.cab
Software\Microsoft\MediaPlayer\Preferences\ContentPartners\%s
\catalog.wmdb.lz
%s\Microsoft\Media Player\%s\%s
%s\Microsoft\Media Player\%s
"%s%s"
%swatermark.jpg
%slogo.jpg
%seula.txt
%sserviceinfo.xml
BASEURL
UDBSOURCEURL
SUPPORTEDRANGE
SOURCEURL
UPDATEEXE
Windows Media Setup
%s\drmupgds.exe
wmfdist11-64.exe
wmfdist11.exe
%s_NT
%s_NT%lu
1.0.0.0
0.0.0.0
%sWMC%4.4lu.tmp
wmp11-64.exe
wmp11.exe
WMC_WMPDBExport
\wmdbexport.exe
wmdbexport.exe
%s advpack.dll,LaunchINFSectionEx %s,%s,,%lu,N
\rundll32.exe
%stmpd.WMC\
\msdxm.ocx
%s_%s
%s\inf\%s
\msxml.dll
\kernel32.dll
advapi32.dll
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}
Software\Clients\Media\Windows Media Player\InstallInfo
wmp.dll
\inf\unregmp2.exe
\unregmp2.exe
kernel32.dll
MP2.SaveDir
\regsvr32.exe
A%s\%s%d.wpl
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%s
%ssetb%lu.tmp
setupapi.dll
Kernel32.dll
DisableWindowsUpdateAccess
Software\Microsoft\CurrentVersion\Policies\WindowsUpdate
Software\Policies\Microsoft\WindowsUpdate\AU
\mplayer2.exe
msdxm.ocx
%s\Groups\%s
SOFTWARE\Microsoft\Windows Media Player NSS\3.0\MAC Access Control
SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Devices
SOFTWARE\Microsoft\Windows Media Player NSS\3.0
SOFTWARE\Microsoft\Windows Media Connect 2\Shares
SOFTWARE\Microsoft\Windows Media Connect 2\Devices
Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
%s\Local Settings\Application Data\Microsoft\Media Player
Software\Microsoft\Windows NT\CurrentVersion\ProfileList\%s
%USERNAME%
%s\Microsoft\Media Player
%s\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
\WMPNSCFG.exe
%s\Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\MediaPlayer\Preferences\HME\%s
Software\Microsoft\Windows Media Connect 2\Shares
msiexec.exe /uninstall %s /qn /norestart
msiexec.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\WMCSetup
Software\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Connect
MS_WebcheckMonitor
%s\old%s
\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\
%s.NT%lu.%lu
%s.NT
%s.NT4
%s.NT5
\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\wmsocm.cat
MediaPlayerV2.dll
%s,%s
hXXps://
{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
%s\ddeexec.bak
%s\ddeexec
%s\command
%s\shell
%s\shell\open\ddeexec.bak
%s\shell\open\ddeexec
%s\shell\open\command
%s\shell\%s\command
tmscat32.dll
12.0.7601.17514
Windows-Media-Player/
https
vnd.ms.wmhtml
OCXLayoutInvisible.wsz
OCXLayoutFull.wsz
OCXLayoutMini.wsz
OCXLayoutNone.wsz
DRMHeader.SubscriptionContentID
DRMHeader.ContentDistributor
DRMHeader.SECURITYVERSION
DRMHeader.CID
DRMHeader.LAINFO
DRMHeader.KID
BaseLAURL
\\?\GLOBALROOT%s\
dw15.exe
WMPlayer/%s
DVD.bookmark
DVD.lastSPPref
DVD.lastAudioPref
DVD.title
DVD.chapter
%c:\video_ts\video_ts.ifo
video_ts.ifo
AVSEQ%d.dat
MUSIC%d.dat
AlbumArtSmall.jpg
Folder.jpg
_Small.jpg
_Large.jpg
ContentPartnerKeyName
WPD/PassthroughPropertyValues
WMDM/DestinationURL
WMDM/SourceURL
WMDM/Webmaster
WMDM/FormatsSupportedAreOrdered
WMDM/FormatsSupported
WMDM/SupportedDeviceProperties
WMDM/KeyFrameDistance
vnd.ms.wmpcp
shell32.dll
\\.\%c:
wmploc.dll/
wmploc.dll\
%c%s=%s
%s://
%d/%d
%s://%c?contentdir=%s
%s://%c/%d?contentdir=%s
eAllServicesUrl_Win7
eAllServicesUrl_Vista
eAllServicesUrl
eLicenseManagementUrl
eHDCDUrl
eCDFormatsUrl
eDRMFileBurnDataCDUrl
eDeviceCantSyncUrl
eSyncBurnRightsUrl
eTransport9SeriesUrl
eMediaGuideFirstRunUrl
eIndividualizationUrl
eGettingStartedUrl
ePluginGalleryUrl
eVizGalleryUrl
eSkinGalleryUrl
eWindowsMediaLogoUrl
ePlayerUpgradeUrl
eMacroMediaUrl
eRequiresSP1Url
eNoDVDDecoderUrl
eCompareWMAUrl
eAddDevicesUrl
eSecurityUrl
eFindPluginsUrl
eTroubleShootingUrl
ePrivacyStatementUrl
hXXp://go.microsoft.com/fwlink/
ws2_32.dll
iphlpapi.dll
res://wmploc/RT_TEXT/corporate.wsz
res://wmploc/RT_TEXT/player.wsz
BuyMusicURL
CLSID\{FA10746C-9B63-4b6c-BC49-FC300EA5F256}\InprocServer32
SOFTWARE\Microsoft\MediaPlayer\Player\Schemes\%s
SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\%s
SOFTWARE\Microsoft\MediaPlayer\Player\Extensions\.%s
SOFTWARE\Microsoft\Multimedia\WMPlayer\Extensions\.%s
Software\Microsoft\Windows Media Foundation\ByteStreamHandlers
Software\Microsoft\Windows\CurrentVersion\PropertySystem\PropertyHandlers\
.dvr-ms
Software\Policies\Microsoft\WindowsMediaPlayer\
Software\Policies\Microsoft\WindowsMediaPlayer\Protocols\
Software\Microsoft\Windows\CurrentVersion\Policies\
video/vnd.dlna.mpeg-tts
image/vnd.ms-photo
audio/x-mpegurl
audio/vnd.dlna.adts
application/vnd.ms-wpl
application/vnd.ms-search
vnd.ms-wpl
vnd.ms-photo
vnd.ms-search
x-mpegurl
vnd.dlna.mpeg-tts
vnd.dlna.adts
WM/UserWebURL
WM/PromotionURL
WM/InitialKey
WM/AuthorURL
WM/AudioSourceURL
WM/AudioFileURL
WM/AlbumCoverURL
SupportsVideo
SupportsPhoto
SupportsAudio
SourceURL
RadioLogoURL
ProviderURL
ProviderLogoURL
LinkedFileURL
LastSyncKey
InitialKey
ErrorURL
DTCPIPPort
DTCPIPHost
DRMKeyID
DeviceSyncSupportFlags
AlternateSourceURL
Video.Writer.Name
Track.Writer.Name
Track.WMContentId
Album.WMCollectionId
Album.WMCollectionGroupId
Video.VideoWidth
Photo.Width
Video.VideoHeight
Photo.Height
Video.FrameRate
Track.UniqueFileIdentifiers
DeviceMedia.TrackNumber
Track.TrackNumber
Video.SubtitleDescription
Video.Subtitle
Track.SubTitle
Playlist.ContentDistributorListID
Video.SubscriptionContentID
Track.SubscriptionContentID
Video.Publisher.Name
Track.Publisher.Name
Video.ProviderStyle
Album.ProviderStyle
Video.ProviderRating
Album.ProviderRating
Radio.ProviderName
Video.ProviderName
Album.ProviderName
Video.ProtectionType
Track.ProtectionType
Video.Producer.Name
Track.Period
Album.PartOfSet
Video.ParentalRating
Track.ParentalRating
Track.Mood
Video.MediaStationName
Video.MediaOriginalChannel
Video.MediaOriginalBroadcastDateTime
Radio.MediaClassSecondaryId
Other.MediaClassSecondaryId
Playlist.MediaClassSecondaryId
Video.MediaClassSecondaryId
Photo.MediaClassSecondaryId
Track.MediaClassSecondaryId
Radio.MediaClassPrimaryId
Other.MediaClassPrimaryId
Playlist.MediaClassPrimaryId
Video.MediaClassPrimaryId
Photo.MediaClassPrimaryId
Track.MediaClassPrimaryId
Album.TOC
Radio.Language
Video.Language.Name
Track.Language.Name
Track.InitialKey
DeviceMedia.TrackGenre
Genre.Name
DeviceMedia.DateTranscoded
Playlist.CreationTime
Video.EncodingTime
Track.EncodingTime
Video.Director.Name
Track.ContentGroupDescriptio
Playlist.ContentDistributor
Video.ContentDistributor
Track.ContentDistributor
Track.Conductor.Name
Composer.Name
Other.Category.Name
Playlist.Category.Name
Video.Category.Name
Track.Category.Name
DeviceMedia.AlbumTitle
Album.Title
DeviceMedia.AlbumArtist
Album.AlbumArtist
DeviceMedia.WasTranscoded
Video.VideoFormat
Video.VideoBitrate
Device.Version
User.ServiceRating
DeviceMedia.UserRating
User.Rating
User.Playcount.Weekend
User.Playcount.Weekday
User.Playcount.Night
User.Playcount.Morning
User.Playcount.Evening
User.Playcount.Afternoon
DeviceMedia.PlayCount
User.Playcount.Total
User.LastPlayedTime
User.EffectiveRating
User.Custom2
User.Custom1
Device.UpsellPrompt
DeviceMedia.UpdateTime
Other.UpdateTime
Playlist.UpdateTime
Video.UpdateTime
Photo.UpdateTime
Track.UpdateTime
Device.TranscodingEnabled
Device.TranscodeTriggerEventIndex
DeviceMedia.TranscodedFilename
DeviceMedia.TrackingId
Radio.TrackingId
Other.TrackingId
Playlist.TrackingId
Video.TrackingId
Photo.TrackingId
Track.TrackingId
Device.TotalSpace
DeviceMedia.TrackTitle
Device.Name
Radio.Title
Other.Title
Playlist.Title
Video.Title
Photo.Title
Track.Title
Device.SyncTriggerEventIndex
Device.SyncToRoot
Other.SyncState2
Video.SyncState2
Photo.SyncState2
Track.SyncState2
Other.SyncState
Video.SyncState
Photo.SyncState
Track.SyncState
Device.SyncShuffle
Device.SyncRelationship
Device.SyncPercentComplete
Playlist.SyncOnly
Device.SyncOnConnect
Device.SyncItemCount
Other.SyncInfo
Video.SyncInfo
Photo.SyncInfo
Track.SyncInfo
DeviceMedia.SyncIndex
Device.SyncIndex
Playlist.Sync16
Playlist.Sync15
Playlist.Sync14
Playlist.Sync13
Playlist.Sync12
Playlist.Sync11
Playlist.Sync10
Playlist.Sync09
Playlist.Sync08
Playlist.Sync07
Playlist.Sync06
Playlist.Sync05
Playlist.Sync04
Playlist.Sync03
Playlist.Sync02
Playlist.Sync01
Device.SupportsVideo
Device.SupportsPhoto
Device.SupportsAudio
Photo.Subject
DeviceMedia.NameOnDevice
Radio.StreamUrl
Other.FileUrl
Playlist.FileUrl
Video.FileUrl
Photo.FileUrl
Track.FileUrl
Playlist.SharingStatus
Video.SharingStatus
Photo.SharingStatus
Track.SharingStatus
Video.ShadowFileSourceFileType
Track.ShadowFileSourceFileType
Video.ShadowFileSourceDRMType
Track.ShadowFileSourceDRMType
Device.SerialNumber
Device.ResyncVideo
Device.ResyncAudio
Track.MetadataProviderRequestState
DeviceMedia.TrackReleaseDate
Video.ReleaseTime
Track.ReleaseTime
Device.RelationshipID
Track.RecordingTime
Radio.LogoURL
Radio.Genre
Album.ProviderUrl
Album.ProviderLogoUrl
Device.Protocol
Video.Profile
Device.PreferredVdeoBitrate
Device.PreferredAudioBitrate
Video.PixelAspectRatioY
Video.PixelAspectRatioX
Device.PercentSpaceReserved
Device.PendingActions
Track.PeakValue
DeviceMedia.OnDevice
DeviceMedia.NeedsResync
Radio.MediaType
Other.MediaType
Playlist.MediaType
Video.MediaType
Photo.MediaType
Track.MediaType
Playlist.MediaContentTypes
DeviceMedia.MarkedForDeletion
Radio.Location
Other.LinkedFileURL
Video.LinkedFileURL
Photo.LinkedFileURL
Track.LinkedFileURL
Device.LastSyncTime
Device.LastSyncNoFitCount
Device.LastSyncKey
Device.LastSyncErrorCount
Device.LastConnectTime
Album.IsCompilation
Video.Protected
Track.Protected
Photo.Category.Name
Track.HMEAlbumTitle
Video.HasHMEACL
Photo.HasHMEACL
Track.HasHMEACL
Device.GuestPrompt
Device.FriendlyNameGenerated
Device.FriendlyName
Radio.Frequency
Device.FreeSpaceLastSync
Device.FreeSpace
Video.FourCC
Device.FirmwareVersion
Radio.FileType
Other.FileType
Playlist.FileType
Video.FileType
Photo.FileType
Track.FileType
DeviceMedia.SizeOnDevice
Other.FileSize
Video.FileSize
Photo.FileSize
Track.FileSize
Video.FakeSubscriptionContentID
Track.FakeSubscriptionContentID
Video.FakeContentDistributor
Track.FakeContentDistributor
Video.DVDID
Other.Duration
Video.Duration
Track.Duration
Video.DRMKeyID
Track.DRMKeyID
Video.DRMIndividualizedVersion
Track.DRMIndividualizedVersion
Video.DLNAProfileID
Photo.DLNAProfileID
Track.DLNAProfileID
DisplayArtist.Name
Device.DeviceSyncSupportFlags
DeviceMedia.Type
Device.DeviceID
Device.Capabilities
Device.DesiresVideo
Device.DesiresPhoto
Device.DesiresAudio
Video.RecordingTime
Photo.DateTimeTaken
Track.DefaultDate
Playlist.Count
Video.Copyright
Photo.Copyright
Track.Copyright
Other.ContentDistributorDuration
Track.ContentDistributorDuration
Playlist.ContainsLISLContent
Device.Connected
Photo.Comment
Device.CheckDeviceMediaSize
Device.CanSync
Radio.CanonicalFileType
Other.CanonicalFileType
Playlist.CanonicalFileType
Video.CanonicalFileType
Photo.CanonicalFileType
Track.CanonicalFileType
Photo.CameraModel.Name
Photo.CameraManufacturer.Name
Radio.CallSign
Radio.Bitrate
Other.Bitrate
Video.Bitrate
Track.Bitrate
Track.AverageLevel
Device.AutoSyncDefaultRules
DeviceMedia.TrackArtist
Radio.Author
Playlist.Author
Actor.Name
Photo.Author
Artist.Name
Video.AudioFormat
Track.AudioFormat
Video.AudioBitrate
Track.ArtInFile
DeviceMedia.AlbumPUOID
Album.AlbumId
Radio.AcquisitonTime
Other.AcquisitonTime
Playlist.AcquisitonTime
Video.AcquisitonTime
Photo.AcquisitonTime
Track.AcquisitonTime
Device.AcquiredContentRetrievalTransactionID
Radio.Abstract
DRM_KeyID
Title=res://wmploc.dll/RT_STRING/#1700;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;MediaType=res://wmploc.dll/RT_STRING/#1715;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;Label=res://wmploc.dll/RT_STRING/#1742;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/ContentGroupDescription=res://wmploc.dll/RT_STRING/#1920;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/PartOfSet=res://wmploc.dll/RT_STRING/#1759;WM/Language=res://wmploc.dll/RT_STRING/#1735;WM/InitialKey=res://wmploc.dll/RT_STRING/#1753;WM/Mood=res://wmploc.dll/RT_STRING/#1819;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/Period=res://wmploc.dll/RT_STRING/#1765;RequestState=res://wmploc.dll/RT_STRING/#1930;SyncInfo=res://wmploc.dll/RT_STRING/#5423;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;Label=res://wmploc.dll/RT_STRING/#1742;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;RequestState=res://wmploc.dll/RT_STRING/#1930;
WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;Title=res://wmploc.dll/RT_STRING/#1700;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;Actor=res://wmploc.dll/RT_STRING/#2341;UserRating=res://wmploc.dll/RT_STRING/#1731;Duration=res://wmploc.dll/RT_STRING/#1710;Bitrate=res://wmploc.dll/RT_STRING/#1711;FileSize=res://wmploc.dll/RT_STRING/#881;FileType=res://wmploc.dll/RT_STRING/#1723;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;
RecordingTime=res://wmploc.dll/RT_STRING/#1751;Series=res://wmploc.dll/RT_STRING/#1935;Episode=res://wmploc.dll/RT_STRING/#1936;Duration=res://wmploc.dll/RT_STRING/#1710;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
Series=res://wmploc.dll/RT_STRING/#1935;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;Episode=res://wmploc.dll/RT_STRING/#1936;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Series=res://wmploc.dll/RT_STRING/#1935;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Episode=res://wmploc.dll/RT_STRING/#1936;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;
DateTaken=res://wmploc.dll/RT_STRING/#1757;Caption=res://wmploc.dll/RT_STRING/#1758;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Category=res://wmploc.dll/RT_STRING/#1764;Author=res://wmploc.dll/RT_STRING/#1701;
Caption=res://wmploc.dll/RT_STRING/#1758;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;FileSize=res://wmploc.dll/RT_STRING/#881;DateTaken=res://wmploc.dll/RT_STRING/#1757;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;WM/Category=res://wmploc.dll/RT_STRING/#1764;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;
Caption=res://wmploc.dll/RT_STRING/#1758;Author=res://wmploc.dll/RT_STRING/#1701;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;DateTaken=res://wmploc.dll/RT_STRING/#1757;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Category=res://wmploc.dll/RT_STRING/#1764;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;Subject=res://wmploc.dll/RT_STRING/#1706;CameraManufacturer=res://wmploc.dll/RT_STRING/#1756;CameraModel=res://wmploc.dll/RT_STRING/#1862;
Title=res://wmploc.dll/RT_STRING/#1700;UserRating=res://wmploc.dll/RT_STRING/#1731;Duration=res://wmploc.dll/RT_STRING/#1710;Bitrate=res://wmploc.dll/RT_STRING/#1711;FileSize=res://wmploc.dll/RT_STRING/#881;FileType=res://wmploc.dll/RT_STRING/#1723;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;WM/Category=res://wmploc.dll/RT_STRING/#1764;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;MediaType=res://wmploc.dll/RT_STRING/#1715;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Author=res://wmploc.dll/RT_STRING/#1701;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;MediaType=res://wmploc.dll/RT_STRING/#1715;WM/TrackNumber=res://wmploc.dll/RT_STRING/#926;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;Is_Protected=res://wmploc.dll/RT_STRING/#1714;SourceURL=res://wmploc.dll/RT_STRING/#1713;FileName=res://wmploc.dll/RT_STRING/#1799;Copyright=res://wmploc.dll/RT_STRING/#1705;WM/EncodingTime=res://wmploc.dll/RT_STRING/#1704;FileSize=res://wmploc.dll/RT_STRING/#881;Duration=res://wmploc.dll/RT_STRING/#1710;UserPlayCount=res://wmploc.dll/RT_STRING/#1712;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Conductor=res://wmploc.dll/RT_STRING/#1747;WM/Composer=res://wmploc.dll/RT_STRING/#1724;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;RecordingTime=res://wmploc.dll/RT_STRING/#1751;WM/ContentGroupDescription=res://wmploc.dll/RT_STRING/#1920;WM/SubTitle=res://wmploc.dll/RT_STRING/#1921;WM/PartOfSet=res://wmploc.dll/RT_STRING/#1759;WM/Language=res://wmploc.dll/RT_STRING/#1735;WM/InitialKey=res://wmploc.dll/RT_STRING/#1753;WM/Mood=res://wmploc.dll/RT_STRING/#1819;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;UserLastPlayedTime=res://wmploc.dll/RT_STRING/#1922;UserRating=res://wmploc.dll/RT_STRING/#1731;UserCustom1=res://wmploc.dll/RT_STRING/#1754;UserCustom2=res://wmploc.dll/RT_STRING/#1755;UserPlaycountMorning=res://wmploc.dll/RT_STRING/#1923;UserPlaycountAfternoon=res://wmploc.dll/RT_STRING/#1924;UserPlaycountEvening=res://wmploc.dll/RT_STRING/#1925;UserPlaycountNight=res://wmploc.dll/RT_STRING/#1926;UserPlaycountWeekday=res://wmploc.dll/RT_STRING/#1927;UserPlaycountWeekend=res://wmploc.dll/RT_STRING/#1928;WM/Category=res://wmploc.dll/RT_STRING/#1764;WM/ContentDistributor=res://wmploc.dll/RT_STRING/#1771;WM/Period=res://wmploc.dll/RT_STRING/#1765;RequestState=res://wmploc.dll/RT_STRING/#1930;WM/SubTitleDescription=res://wmploc.dll/RT_STRING/#2319;WM/MediaStationName=res://wmploc.dll/RT_STRING/#2320;WM/MediaOriginalChannel=res://wmploc.dll/RT_STRING/#2321;WM/MediaOriginalBroadcastDateTime=res://wmploc.dll/RT_STRING/#2322;Comment=res://wmploc.dll/RT_STRING/#2323;WM/VideoHeight=res://wmploc.dll/RT_STRING/#2325;WM/VideoWidth=res://wmploc.dll/RT_STRING/#2324;WM/VideoFrameRate=res://wmploc.dll/RT_STRING/#5420;SyncInfo=res://wmploc.dll/RT_STRING/#5423;FourCC=res://wmploc.dll/RT_STRING/#5421;VideoBitrate=res://wmploc.dll/RT_STRING/#5422;AudioBitrate=res://wmploc.dll/RT_STRING/#5424;
Title=res://wmploc.dll/RT_STRING/#1700;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;WM/Category=res://wmploc.dll/RT_STRING/#1764;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;
Title=res://wmploc.dll/RT_STRING/#1700;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Category=res://wmploc.dll/RT_STRING/#1764;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;Copyright=res://wmploc.dll/RT_STRING/#1705;
Title=res://wmploc.dll/RT_STRING/#1700;CallLetters=res://wmploc.dll/RT_STRING/#1738;Bitrate=res://wmploc.dll/RT_STRING/#1711;Frequency=res://wmploc.dll/RT_STRING/#1732;Location=res://wmploc.dll/RT_STRING/#1734;WM/Language=res://wmploc.dll/RT_STRING/#1735;Abstract=res://wmploc.dll/RT_STRING/#1717;Author=res://wmploc.dll/RT_STRING/#1701;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;MediaType=res://wmploc.dll/RT_STRING/#1715;FileType=res://wmploc.dll/RT_STRING/#1723;Bitrate=res://wmploc.dll/RT_STRING/#1711;SourceURL=res://wmploc.dll/RT_STRING/#1713;WM/Provider=res://wmploc.dll/RT_STRING/#914;Frequency=res://wmploc.dll/RT_STRING/#1732;CallLetters=res://wmploc.dll/RT_STRING/#1738;RadioLogoURL=res://wmploc.dll/RT_STRING/#1699;Location=res://wmploc.dll/RT_STRING/#1734;RadioGenre=res://wmploc.dll/RT_STRING/#1869;Abstract=res://wmploc.dll/RT_STRING/#1717;WM/Language=res://wmploc.dll/RT_STRING/#1735;AcquisitionTime=res://wmploc.dll/RT_STRING/#1772;
Title=res://wmploc.dll/RT_STRING/#1700;Author=res://wmploc.dll/RT_STRING/#1701;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;UserRating=res://wmploc.dll/RT_STRING/#1731;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Duration=res://wmploc.dll/RT_STRING/#1710;FileType=res://wmploc.dll/RT_STRING/#1723;Is_Protected=res://wmploc.dll/RT_STRING/#1714;
OriginalIndexLeft=res://wmploc.dll/RT_STRING/#926;Title=res://wmploc.dll/RT_STRING/#1700;Duration=res://wmploc.dll/RT_STRING/#1710;Status=res://wmploc.dll/RT_STRING/#912;Artist=res://wmploc.dll/RT_STRING/#1707;WM/Composer=res://wmploc.dll/RT_STRING/#1724;WM/Genre=res://wmploc.dll/RT_STRING/#1709;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/Provider=res://wmploc.dll/RT_STRING/#914;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Artist=res://wmploc.dll/RT_STRING/#1707;WM/AlbumArtist=res://wmploc.dll/RT_STRING/#1763;WM/AlbumTitle=res://wmploc.dll/RT_STRING/#1708;OriginalIndexLeft=res://wmploc.dll/RT_STRING/#926;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;WM/ProviderStyle=res://wmploc.dll/RT_STRING/#913;WM/ProviderRating=res://wmploc.dll/RT_STRING/#1770;Label=res://wmploc.dll/RT_STRING/#1742;WM/Composer=res://wmploc.dll/RT_STRING/#1724;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Period=res://wmploc.dll/RT_STRING/#1765;Status=res://wmploc.dll/RT_STRING/#912;
Title=res://wmploc.dll/RT_STRING/#1700;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Producer=res://wmploc.dll/RT_STRING/#1748;Studio=res://wmploc.dll/RT_STRING/#1743;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;
Title=res://wmploc.dll/RT_STRING/#1700;WM/Genre=res://wmploc.dll/RT_STRING/#1709;Actor=res://wmploc.dll/RT_STRING/#2341;Copyright=res://wmploc.dll/RT_STRING/#1705;Duration=res://wmploc.dll/RT_STRING/#1710;WM/Provider=res://wmploc.dll/RT_STRING/#914;Studio=res://wmploc.dll/RT_STRING/#1743;WM/Writer=res://wmploc.dll/RT_STRING/#1746;WM/Director=res://wmploc.dll/RT_STRING/#1749;WM/Producer=res://wmploc.dll/RT_STRING/#1748;ReleaseDate=res://wmploc.dll/RT_STRING/#1744;WM/ParentalRating=res://wmploc.dll/RT_STRING/#1752;
/:*?"<>|
Microsoft Windows Media Configuration Utility
12.0.7601.17514 (win7sp1_rtm.101119-1850)
Windows
Operating System

msdcsc.exe_1916:

.text
`.itext
`.data
.idata
.rdata
@.reloc
B.rsrc
kernel32.dll
Windows
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
EVariantBadIndexError
ssShift
htKeyword
EInvalidOperation
%s_%d
EInvalidGraphicOperation
SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
%s, ClassID: %s
%s, ProgID: "%s"
ole32.dll
USER32.DLL
uxtheme.dll
DWMAPI.DLL
clWebSnow
clWebFloralWhite
clWebLavenderBlush
clWebOldLace
clWebIvory
clWebCornSilk
clWebBeige
clWebAntiqueWhite
clWebWheat
clWebAliceBlue
clWebGhostWhite
clWebLavender
clWebSeashell
clWebLightYellow
clWebPapayaWhip
clWebNavajoWhite
clWebMoccasin
clWebBurlywood
clWebAzure
clWebMintcream
clWebHoneydew
clWebLinen
clWebLemonChiffon
clWebBlanchedAlmond
clWebBisque
clWebPeachPuff
clWebTan
clWebYellow
clWebDarkOrange
clWebRed
clWebDarkRed
clWebMaroon
clWebIndianRed
clWebSalmon
clWebCoral
clWebGold
clWebTomato
clWebCrimson
clWebBrown
clWebChocolate
clWebSandyBrown
clWebLightSalmon
clWebLightCoral
clWebOrange
clWebOrangeRed
clWebFirebrick
clWebSaddleBrown
clWebSienna
clWebPeru
clWebDarkSalmon
clWebRosyBrown
clWebPaleGoldenrod
clWebLightGoldenrodYellow
clWebOlive
clWebForestGreen
clWebGreenYellow
clWebChartreuse
clWebLightGreen
clWebAquamarine
clWebSeaGreen
clWebGoldenRod
clWebKhaki
clWebOliveDrab
clWebGreen
clWebYellowGreen
clWebLawnGreen
clWebPaleGreen
clWebMediumAquamarine
clWebMediumSeaGreen
clWebDarkGoldenRod
clWebDarkKhaki
clWebDarkOliveGreen
clWebDarkgreen
clWebLimeGreen
clWebLime
clWebSpringGreen
clWebMediumSpringGreen
clWebDarkSeaGreen
clWebLightSeaGreen
clWebPaleTurquoise
clWebLightCyan
clWebLightBlue
clWebLightSkyBlue
clWebCornFlowerBlue
clWebDarkBlue
clWebIndigo
clWebMediumTurquoise
clWebTurquoise
clWebCyan
clWebPowderBlue
clWebSkyBlue
clWebRoyalBlue
clWebMediumBlue
clWebMidnightBlue
clWebDarkTurquoise
clWebCadetBlue
clWebDarkCyan
clWebTeal
clWebDeepskyBlue
clWebDodgerBlue
clWebBlue
clWebNavy
clWebDarkViolet
clWebDarkOrchid
clWebMagenta
clWebDarkMagenta
clWebMediumVioletRed
clWebPaleVioletRed
clWebBlueViolet
clWebMediumOrchid
clWebMediumPurple
clWebPurple
clWebDeepPink
clWebLightPink
clWebViolet
clWebOrchid
clWebPlum
clWebThistle
clWebHotPink
clWebPink
clWebLightSteelBlue
clWebMediumSlateBlue
clWebLightSlateGray
clWebWhite
clWebLightgrey
clWebGray
clWebSteelBlue
clWebSlateBlue
clWebSlateGray
clWebWhiteSmoke
clWebSilver
clWebDimGray
clWebMistyRose
clWebDarkSlateBlue
clWebDarkSlategray
clWebGainsboro
clWebDarkGray
clWebBlack
comctl32.dll
AutoHotkeysd-C
AutoHotkeys
\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\
ssHotTrack
TWindowState
poProportional
TWMKey
KeyPreview
WindowState
OnKeyDownL
OnKeyPress
OnKeyUpH
GlassFrame.Bottom
GlassFrame.Enabled
GlassFrame.Left
GlassFrame.Right
GlassFrame.SheetOfGlass
GlassFrame.Top
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
Uh.ID
User32.dll
TKeyEvent
TKeyPressEvent
HelpKeyword nA
crSQLWait
%s (%s)
imm32.dll
TSocketPort
%d.%d.%d.%d
0.0.0.0
PSAPI.dll
TDCWebCam
127.0.0.1
BuildImportTable: can't load library:
BuildImportTable: ReallocMemory failed
BuildImportTable: GetProcAddress failed
BTMemoryLoadLibary: BuildImportTable failed
BTMemoryGetProcAddress: no export table found
BTMemoryGetProcAddress: DLL doesn't export anything
BTMemoryGetProcAddress: exported symbol not found
1.2.3
127.0.0.1:1604
#KCMDDC51#-
5.3.0
cmd.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hkey
\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
*.torrent
\Internet Explorer\iexplore.exe
explorer.exe
wlanapi.dll
80211_SHARED_KEY
user32.dll
TUploadFTP
notepad.exe
KEYNAME
%ShortCut#
RELATEDCMD
ping 127.0.0.1 -n 4 > NUL && "
DRKey
CRKey
DelMSKey
InstallHKEY
ActiveOnlineKeylogger
UnActiveOnlineKeylogger
KeylogOn
ActiveOfflineKeylogger
UnActiveOfflineKeylogger
ActiveOnlineKeyStrokes
UnActiveOnlineKeyStrokes
OpenWebPage
tmpprint.txt
URLUpdate
MSGBOX
#BOT#VisitUrl
#BOT#OpenUrl
HTTP://
hXXp://
BTRESULTOpen URL|
Command successfully executed!|
#BOT#URLUpdate
BTERRORUpdate from URL| Error on downloading file check if you type the correct url...|
BTRESULTUpdate from URL|Update : File Downloaded , Executing new one in temp dir...|
#BOT#URLDownload
GetActivePorts
out.txt
tmp.txt
DDOSHTTPFLOOD
DDOSUDPFLOOD
%IPPORTSCAN
SAPI.SpVoice
WEBCAMLIVE
WEBCAMSTOP
PASSWORD
FTPFILEUPLOAD
URLDOWNLOADTOFILE
UPLOADEXEC
UPANDEXEC
FTPPORT
FTPPASS
FTPUSER
FTPHOST
FTPROOT
FTPUPLOADK
FTPSIZE
BTRESULTUDP Flood|UDP Flood task finished!|
PortScanAdd
BTRESULTVisit URL|finished to visit
BTERRORVisit URL|An exception occured in the thread|
POST /index.php/1.0
BTRESULTHTTP Flood|Http Flood task finished!|
Mozilla
BTRESULTDownload File|Mass Download : File Downloaded , Executing new one in temp dir...|
BTERRORDownload File| Error on downloading file check if you type the correct url...|
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ERR|Cannot listen to port, try another one..|
TCaptureWebcam
taskmgr.exe
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
DC3_FEXEC
Windows NT 4.0
Windows 2000
Windows XP
Windows Server 2003
Windows Vista
Windows 7
Windows 95
Windows 98
Windows Me
S-%u-
FAKEMSG
MSGICON
MSGTITLE
MSGCORE
deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
inflate 1.2.3 Copyright 1995-2005 Mark Adler
C:\Users\"%CurrentUserName%"\AppData\Roaming\dclogs\2017-05-27-7.dc
DBv}.Bv
advapi32.dll
RegOpenKeyExA
RegCloseKey
GetKeyboardType
keybd_event
VkKeyScanA
UnhookWindowsHookEx
SetWindowsHookExA
MsgWaitForMultipleObjectsEx
MsgWaitForMultipleObjects
MapVirtualKeyA
LoadKeyboardLayoutA
GetKeyboardState
GetKeyboardLayoutNameA
GetKeyboardLayoutList
GetKeyboardLayout
GetKeyState
GetKeyNameTextA
ExitWindowsEx
EnumWindows
EnumThreadWindows
EnumChildWindows
ActivateKeyboardLayout
gdi32.dll
SetViewportOrgEx
version.dll
WinExec
PeekNamedPipe
GetWindowsDirectoryA
GetProcessHeap
GetCPInfo
CreatePipe
RegQueryInfoKeyA
RegOpenKeyA
RegFlushKey
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
wsock32.dll
shell32.dll
ShellExecuteExA
ShellExecuteA
SHFileOperationA
URLMON.DLL
URLDownloadToFileA
wininet.dll
InternetOpenUrlA
HttpQueryInfoA
FtpPutFileA
winmm.dll
netapi32.dll
gdiplus.dll
GdiplusShutdown
msacm32.dll
ntdll.dll
WS2_32.DLL
SHFolder.dll
SHELL32.DLL
AVICAP32.DLL
1!1,1=1|1
6 6$6(6,606
=!=$=)=-=1=
01m1
0 0$0(0,0004080<0@0
<!=$=)=-=4=
;"<?<_<|<
; ;$;(;,;0;4;8;<;@;
7 8$888<8
= =$=(=,=0=4=8=
UntKeylogger
KWindows
UntActivePorts
UntControlKey
UntCaptureWebcam
UntWebCam
UrlMon
(UntUploadFTPThread
UntFTP
_UntUDPFlood
YUntScanPorts
0UntPasswordAndData
XUntHTTPFlood
UntCPU
66006666
No help found for %s#No context-sensitive help installed
No help found for context$No topic-based help system installedNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Invalid clipboard format Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
- Dock zone has no controlLError loading dock zone from the stream. Expecting version %d, but found %d.
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active$%s not in a class registration group
Property %s does not exist
Thread creation error: %s
Thread Error: %s (%d)
Unsupported clipboard format
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Failed to create key %s
Failed to get data for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
External exception %x
Interface not supported
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Operation not supported
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Application Error1Format '%s' invalid or incompatible with argument
!'%s' is not a valid integer value('%s' is not a valid floating point value!'%s' is not a valid date and time
'%s' is not a valid GUID value
I/O error %d
1, 0, 0, 1
MSRSAAP.EXE
4, 0, 0, 0

notepad.exe_560:

.text
`.data
.rsrc
@.reloc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
GDI32.dll
USER32.dll
msvcrt.dll
COMDLG32.dll
SHELL32.dll
WINSPOOL.DRV
ole32.dll
SHLWAPI.dll
COMCTL32.dll
OLEAUT32.dll
VERSION.dll
Av.TBv
ntdll.dll
RegCloseKey
RegCreateKeyW
RegOpenKeyExW
GetProcessHeap
SetViewportExtEx
GetKeyboardLayout
_amsg_exit
_acmdln
ShellExecuteExW
notepad.pdb
name="Microsoft.Windows.Shell.notepad"
version="5.1.0.0"
<description>Windows Shell</description>
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
<windowsSettings>
<dpiAware xmlns="hXXp://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
===111*!
'141133!/!(!(!""/""
;;;;4;3423332
keYM
,k<.KQ
.WF"hB
dx.Rl
V.xOx_T
<'<.<9<_<
/.SETUP
%s%c*.txt%c%s%c*.*%c
*.txt
mshelp://windows/?id=5d18d5fb-e737-4a73-b6cc-dccc63720231
\StringFileInfo\xx\OriginalFilename
\sppsvc.exe
\slui.exe
\sppuinotify.dll
Text Documents (*.txt)
6.1.7600.16385 (win7_rtm.090713-1255)
NOTEPAD.EXE
Windows
Operating System
6.1.7600.16385

notepad.exe_560_rwx_00060000_00001000:

kernel32.dll

notepad.exe_560_rwx_00070000_00001000:

user32.dll

notepad.exe_560_rwx_00160000_00001000:

C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    wmplayer.exe:2776
    notepad.exe:1956
    %original file name%.exe:2928
    LocalnJhGiFZrWl.exe:1780

  2. Delete the original Backdoor file.
  3. Delete or disinfect the following files created/modified by the Backdoor:

    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\wmsetup.log (7518 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp29642.WMC\allservices.xml (1 bytes)
    C:\Users\"%CurrentUserName%"\AppData\Local\Temp\tmp31061.WMC\serviceinfo.xml (908 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalnJhGiFZrWl.exe (1350 bytes)
    C:\Users\"%CurrentUserName%"\AppData\LocalMaMWGJRGaK.mp3 (3 bytes)
    C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe (5220 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "MicroUpdate" = "C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe"

  5. Remove the references to the Backdoor by modifying the following registry value(s) (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "UserInit" = "C:\Windows\system32\userinit.exe,C:\Users\"%CurrentUserName%"\Documents\MSDCSC\msdcsc.exe"

  6. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  7. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now