Analysis Date2015-09-17 14:25:48
MD519298027d2acb7138d3047bef82fb103
SHA1a5bcf322f9fdf1ba3b1af997aa2216f1a2754f6a

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 system file
Section.text md5: 69000f0a253c48efb60d02bbe6bc6c2c sha1: c6c2a8fd37deed65038ea06729a9f8cc5e4e36c7 size: 294912
Section.rdata md5: 9301bbddebafcfa7aa8373f210cf6427 sha1: 6dc9fd43893376e46c5d13945dbfd2f0376d87bf size: 46592
Section.data md5: a74baca2e3e164ce3d9cee8821da6f2a sha1: 71a2c24ac98e0635f2494e7fd661257d28bfaa6a size: 5632
Section.rsrc md5: 01388b519a537c3faa2b211c3f15bd2f sha1: e382dfa4865a5ccf87ebacf4da22456c53f6b2ad size: 104448
Section.reloc md5: 7eb32ede7d7ffcfcf370d5ad65442828 sha1: d7072a8e7b7404ffb2d944226911d65cbcda82e9 size: 9728
Timestamp2015-09-02 00:22:07
Pdb pathP:\work\Refer\closely\achieve\unre.pdb
VersionLegalCopyright: © Microsoft Corporation. All rights reserved.
InternalName: BoxStub.exe
FileVersion: 10.0.30203.0
CompanyName: Microsoft Corporation
ProductName: Microsoft® .NET Framework
ProductVersion: 10.0.30203.0
FileDescription: Box Stub
OriginalFilename: BoxStub.exe
PackerMicrosoft Visual C++ ?.?
PEhashf67d21416b987f2564f1b7e44d8c65e1cb1e656f
IMPhash81eba609f09f83ae8dff82a3ad01aaef
AVRisingno_virus
AVMcafeeGenericR-EJS!19298027D2AC
AVAvira (antivir)TR/Crypt.Xpack.248982
AVTwisterTrojan.Girtk.DVOB.cjrk
AVAd-AwareGen:Variant.Symmi.54551
AVAlwil (avast)Trojan-gen:Win32:Trojan-gen
AVEset (nod32)Win32/Kryptik.DVOB
AVGrisoft (avg)Crypt4.CEBA
AVSymantecTrojan.Ransomlock.AK
AVFortinetW32/Kryptik.DTTK!tr
AVBitDefenderGen:Variant.Symmi.54551
AVK7Trojan ( 004cd7091 )
AVMicrosoft Security EssentialsError Scanning File
AVMicroWorld (escan)Gen:Variant.Symmi.54551
AVMalwareBytesBackdoor.Bot
AVAuthentiumW32/Trojan.PORI-8214
AVFrisk (f-prot)no_virus
AVIkarusTrojan.Win32.Crypt
AVEmsisoftGen:Variant.Symmi.54551
AVZillya!Trojan.Kryptik.Win32.786819
AVKasperskyTrojan-Downloader.Win32.Upatre.eqkp
AVTrend Microno_virus
AVCAT (quickheal)no_virus
AVVirusBlokAda (vba32)no_virus
AVPadvishno_virus
AVBullGuardGen:Variant.Symmi.54551
AVArcabit (arcavir)Gen:Variant.Symmi.54551
AVClamAVno_virus
AVDr. WebTrojan.MulDrop6.3201
AVF-SecureGen:Variant.Symmi.54551
AVCA (E-Trust Ino)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates Processregsvr32.exe

Process
↳ regsvr32.exe

Creates Processregsvr32.exe

Process
↳ regsvr32.exe

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\2a89521acd\c984f294 ➝
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\\x00
RegistryHKEY_LOCAL_MACHINE\software\2a89521acd\7bf7927d ➝
869\\x00
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\regsvr32.exe ➝
8888
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
RegistryHKEY_CURRENT_USER\software\2a89521acd\7bf7927d ➝
869\\x00
RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1206 ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1206 ➝
NULL
RegistryHKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\regsvr32.exe ➝
8888
RegistryHKEY_CURRENT_USER\SOFTWARE\2a89521acd\c984f294 ➝
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\\x00
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates File\Device\Afd\AsyncConnectHlp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Application Data\oqofu\oqofu.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\35.43.113[1].htm
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\microsoft[1].htm
Creates File\Device\Afd\Endpoint
Deletes Filec:\malware.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\35.43.113[1].htm
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\658HSJSD\microsoft[1].htm
Creates Process"C:\WINDOWS\system32\regsvr32.exe"
Creates Process"C:\WINDOWS\system32\regsvr32.exe"
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates MutexDE7B2F08C5C35678
Creates MutexGlobal\A0B9737978FF60B0
Winsock DNSmicrosoft.com
Winsock DNS35.43.113.90

Process
↳ "C:\WINDOWS\system32\regsvr32.exe"

Creates Mutex5734B585673D7847

Process
↳ "C:\WINDOWS\system32\regsvr32.exe"

RegistryHKEY_LOCAL_MACHINE\SOFTWARE\2a89521acd\c984f294 ➝
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\\x00
RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\C8C320A1278184FC\18D937A5EC00831B ➝
18D937A5EC00831B\\x00
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\29C451E2C02CF348596\CEAF97F8C25A54887C5 ➝
CEAF97F8C25A54887C5\\x00
RegistryHKEY_CURRENT_USER\SOFTWARE\2a89521acd\c984f294 ➝
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)\\x00
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\NetFx20SP1_x86.exe
Creates FilePIPE\wkssvc
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Process"C:\Documents and Settings\Administrator\Local Settings\Temp\NetFx20SP1_x86.exe" /quiet /norestart
Winsock DNSdownload.microsoft.com

Process
↳ "C:\Documents and Settings\Administrator\Local Settings\Temp\NetFx20SP1_x86.exe" /quiet /norestart

Creates FileC:\WINDOWS\SYSTEM32\REDIR.EXE
Creates FileC:\WINDOWS\SYSTEM32\COMMAND.COM
Creates FileC:\WINDOWS\TEMP\scs2.tmp
Creates FileC:\WINDOWS\SYSTEM32\HIMEM.SYS
Creates FileC:\WINDOWS\SYSTEM32\DOSX.EXE
Creates FileC:\WINDOWS\SYSTEM32\MSCDEXNT.EXE
Creates FileC:\WINDOWS\TEMP\scs1.tmp
Creates FileC:\Documents and Settings\Administrator\Local Settings\TEMP\NETFX2~1.EXE
Deletes FileC:\WINDOWS\TEMP\scs1.tmp
Deletes FileC:\WINDOWS\TEMP\scs2.tmp

Network Details:

DNSmicrosoft.com
Type: A
134.170.185.46
DNSmicrosoft.com
Type: A
134.170.188.221
DNSa767.dscms.akamai.net
Type: A
23.3.98.10
DNSa767.dscms.akamai.net
Type: A
23.3.98.32
DNSdownload.microsoft.com
Type: A
HTTP GEThttp://microsoft.com/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP POSThttp://35.43.113.90/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
HTTP GEThttp://download.microsoft.com/download/0/8/c/08c19fa4-4c4f-4ffb-9d6c-150906578c9e/NetFx20SP1_x86.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Flows TCP192.168.1.1:1031 ➝ 188.113.169.39:8080
Flows TCP192.168.1.1:1031 ➝ 188.113.169.39:8080
Flows TCP192.168.1.1:1032 ➝ 35.43.113.90:80
Flows TCP192.168.1.1:1034 ➝ 134.170.185.46:80
Flows TCP192.168.1.1:1035 ➝ 55.230.107.52:443
Flows TCP192.168.1.1:1036 ➝ 205.70.220.121:80
Flows TCP192.168.1.1:1037 ➝ 35.43.113.90:80
Flows TCP192.168.1.1:1038 ➝ 162.136.79.127:80
Flows TCP192.168.1.1:1039 ➝ 43.64.88.190:80
Flows TCP192.168.1.1:1040 ➝ 79.179.97.21:8080
Flows TCP192.168.1.1:1041 ➝ 123.5.221.228:80
Flows TCP192.168.1.1:1042 ➝ 23.3.98.10:80
Flows TCP192.168.1.1:1043 ➝ 10.182.78.250:80
Flows TCP192.168.1.1:1044 ➝ 62.158.158.90:80
Flows TCP192.168.1.1:1045 ➝ 189.63.30.142:80
Flows TCP192.168.1.1:1046 ➝ 63.12.244.18:443
Flows TCP192.168.1.1:1047 ➝ 94.131.200.75:80
Flows TCP192.168.1.1:1048 ➝ 53.113.215.9:80
Flows TCP192.168.1.1:1049 ➝ 17.164.168.175:80

Raw Pcap
0x00000000 (00000)   7a                                    z

0x00000000 (00000)   47455420 2f204854 54502f31 2e310d0a   GET / HTTP/1.1..
0x00000010 (00016)   55736572 2d416765 6e743a20 4d6f7a69   User-Agent: Mozi
0x00000020 (00032)   6c6c612f 342e3020 28636f6d 70617469   lla/4.0 (compati
0x00000030 (00048)   626c653b 204d5349 4520362e 303b2057   ble; MSIE 6.0; W
0x00000040 (00064)   696e646f 7773204e 5420352e 313b2053   indows NT 5.1; S
0x00000050 (00080)   56313b20 2e4e4554 20434c52 20322e30   V1; .NET CLR 2.0
0x00000060 (00096)   2e353037 3237290d 0a486f73 743a206d   .50727)..Host: m
0x00000070 (00112)   6963726f 736f6674 2e636f6d 0d0a4361   icrosoft.com..Ca
0x00000080 (00128)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000090 (00144)   63616368 650d0a0d 0a                  cache....

0x00000000 (00000)   504f5354 202f2048 5454502f 312e310d   POST / HTTP/1.1.
0x00000010 (00016)   0a436f6e 74656e74 2d547970 653a2061   .Content-Type: a
0x00000020 (00032)   70706c69 63617469 6f6e2f78 2d777777   pplication/x-www
0x00000030 (00048)   2d666f72 6d2d7572 6c656e63 6f646564   -form-urlencoded
0x00000040 (00064)   0d0a5573 65722d41 67656e74 3a204d6f   ..User-Agent: Mo
0x00000050 (00080)   7a696c6c 612f342e 30202863 6f6d7061   zilla/4.0 (compa
0x00000060 (00096)   7469626c 653b204d 53494520 362e303b   tible; MSIE 6.0;
0x00000070 (00112)   2057696e 646f7773 204e5420 352e313b    Windows NT 5.1;
0x00000080 (00128)   20535631 3b202e4e 45542043 4c522032    SV1; .NET CLR 2
0x00000090 (00144)   2e302e35 30373237 290d0a48 6f73743a   .0.50727)..Host:
0x000000a0 (00160)   2033352e 34332e31 31332e39 300d0a43    35.43.113.90..C
0x000000b0 (00176)   6f6e7465 6e742d4c 656e6774 683a2034   ontent-Length: 4
0x000000c0 (00192)   30380d0a 43616368 652d436f 6e74726f   08..Cache-Contro
0x000000d0 (00208)   6c3a206e 6f2d6361 6368650d 0a0d0a4a   l: no-cache....J
0x000000e0 (00224)   6a354e69 73633541 4a627369 70775a52   j5Nisc5AJbsipwZR
0x000000f0 (00240)   66485756 68436764 786c376d 4c5a7541   fHWVhCgdxl7mLZuA
0x00000100 (00256)   38586457 532f6676 54716c75 57796269   8XdWS/fvTqluWybi
0x00000110 (00272)   64346268 7779734a 4c425a42 70464136   d4bhwysJLBZBpFA6
0x00000120 (00288)   6c30306f 52687533 32366f74 5a546250   l00oRhu326otZTbP
0x00000130 (00304)   6438746e 45586968 4e304654 63624439   d8tnEXihN0FTcbD9
0x00000140 (00320)   49657761 2f54616b 41516c62 73686c66   Iewa/TakAQlbshlf
0x00000150 (00336)   444a6c6f 632f7248 69707033 4c464d63   DJloc/rHipp3LFMc
0x00000160 (00352)   4246365a 59496658 39345777 33554b49   BF6ZYIfX94Ww3UKI
0x00000170 (00368)   4f414a2b 5068322f 43437455 6f76306a   OAJ+Ph2/CCtUov0j
0x00000180 (00384)   356e3749 376d5076 65555773 542b3138   5n7I7mPveUWsT+18
0x00000190 (00400)   512b556d 4b637941 58335564 6e657679   Q+UmKcyAX3Udnevy
0x000001a0 (00416)   716c3738 43586258 62717235 44532f79   ql78CXbXbqr5DS/y
0x000001b0 (00432)   37676967 67335655 5536446c 36382f72   7gigg3VUU6Dl68/r
0x000001c0 (00448)   69526774 666e464b 4d33374c 446a3130   iRgtfnFKM37LDj10
0x000001d0 (00464)   4f6c6665 666a3832 7a505363 38645835   Olfefj82zPSc8dX5
0x000001e0 (00480)   4d614a39 4b657755 412f7635 7177755a   MaJ9KewUA/v5qwuZ
0x000001f0 (00496)   66757063 614d442b 576a6a38 7a68376e   fupcaMD+Wjj8zh7n
0x00000200 (00512)   6b4d584f 67566b75 33375634 7176346a   kMXOgVku37V4qv4j
0x00000210 (00528)   69636637 5a7a4e36 32752f66 514f6a79   icf7ZzN62u/fQOjy
0x00000220 (00544)   79796943 7a58396b 436c4f2f 744b3230   yyiCzX9kClO/tK20
0x00000230 (00560)   637a6e63 72665869 7545564c 525a7435   czncrfXiuEVLRZt5
0x00000240 (00576)   30673453 306a4864 75503965 59643773   0g4S0jHduP9eYd7s
0x00000250 (00592)   68772f7a 77363877 31646b42 66704e6d   hw/zw68w1dkBfpNm
0x00000260 (00608)   6a355463 6435656a 3170372f 515a7835   j5Tcd5ej1p7/QZx5
0x00000270 (00624)   626e4d57 513d3d                       bnMWQ==

0x00000000 (00000)   6d                                    m

0x00000000 (00000)   4d                                    M

0x00000000 (00000)   68                                    h

0x00000000 (00000)   ba                                    .

0x00000000 (00000)   47455420 2f646f77 6e6c6f61 642f302f   GET /download/0/
0x00000010 (00016)   382f632f 30386331 39666134 2d346334   8/c/08c19fa4-4c4
0x00000020 (00032)   662d3466 66622d39 6436632d 31353039   f-4ffb-9d6c-1509
0x00000030 (00048)   30363537 38633965 2f4e6574 46783230   06578c9e/NetFx20
0x00000040 (00064)   5350315f 7838362e 65786520 48545450   SP1_x86.exe HTTP
0x00000050 (00080)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000060 (00096)   3a204d6f 7a696c6c 612f342e 30202863   : Mozilla/4.0 (c
0x00000070 (00112)   6f6d7061 7469626c 653b204d 53494520   ompatible; MSIE 
0x00000080 (00128)   362e303b 2057696e 646f7773 204e5420   6.0; Windows NT 
0x00000090 (00144)   352e313b 20535631 3b202e4e 45542043   5.1; SV1; .NET C
0x000000a0 (00160)   4c522032 2e302e35 30373237 290d0a48   LR 2.0.50727)..H
0x000000b0 (00176)   6f73743a 20646f77 6e6c6f61 642e6d69   ost: download.mi
0x000000c0 (00192)   63726f73 6f66742e 636f6d0d 0a436163   crosoft.com..Cac
0x000000d0 (00208)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x000000e0 (00224)   61636865 0d0a0d0a 4a627369 70775a52   ache....JbsipwZR
0x000000f0 (00240)   66485756 68436764 786c376d 4c5a7541   fHWVhCgdxl7mLZuA
0x00000100 (00256)   38586457 532f6676 54716c75 57796269   8XdWS/fvTqluWybi
0x00000110 (00272)   64346268 7779734a 4c425a42 70464136   d4bhwysJLBZBpFA6
0x00000120 (00288)   6c30306f 52687533 32366f74 5a546250   l00oRhu326otZTbP
0x00000130 (00304)   6438746e 45586968 4e304654 63624439   d8tnEXihN0FTcbD9
0x00000140 (00320)   49657761 2f54616b 41516c62 73686c66   Iewa/TakAQlbshlf
0x00000150 (00336)   444a6c6f 632f7248 69707033 4c464d63   DJloc/rHipp3LFMc
0x00000160 (00352)   4246365a 59496658 39345777 33554b49   BF6ZYIfX94Ww3UKI
0x00000170 (00368)   4f414a2b 5068322f 43437455 6f76306a   OAJ+Ph2/CCtUov0j
0x00000180 (00384)   356e3749 376d5076 65555773 542b3138   5n7I7mPveUWsT+18
0x00000190 (00400)   512b556d 4b637941 58335564 6e657679   Q+UmKcyAX3Udnevy
0x000001a0 (00416)   716c3738 43586258 62717235 44532f79   ql78CXbXbqr5DS/y
0x000001b0 (00432)   37676967 67335655 5536446c 36382f72   7gigg3VUU6Dl68/r
0x000001c0 (00448)   69526774 666e464b 4d33374c 446a3130   iRgtfnFKM37LDj10
0x000001d0 (00464)   4f6c6665 666a3832 7a505363 38645835   Olfefj82zPSc8dX5
0x000001e0 (00480)   4d614a39 4b657755 412f7635 7177755a   MaJ9KewUA/v5qwuZ
0x000001f0 (00496)   66757063 614d442b 576a6a38 7a68376e   fupcaMD+Wjj8zh7n
0x00000200 (00512)   6b4d584f 67566b75 33375634 7176346a   kMXOgVku37V4qv4j
0x00000210 (00528)   69636637 5a7a4e36 32752f66 514f6a79   icf7ZzN62u/fQOjy
0x00000220 (00544)   79796943 7a58396b 436c4f2f 744b3230   yyiCzX9kClO/tK20
0x00000230 (00560)   637a6e63 72665869 7545564c 525a7435   czncrfXiuEVLRZt5
0x00000240 (00576)   30673453 306a4864 75503965 59643773   0g4S0jHduP9eYd7s
0x00000250 (00592)   68772f7a 77363877 31646b42 66704e6d   hw/zw68w1dkBfpNm
0x00000260 (00608)   6a355463 6435656a 3170372f 515a7835   j5Tcd5ej1p7/QZx5
0x00000270 (00624)   626e4d57 513d3d                       bnMWQ==

0x00000000 (00000)   a9                                    .

0x00000000 (00000)   5d                                    ]

0x00000000 (00000)   3a                                    :

0x00000000 (00000)   47                                    G

0x00000000 (00000)   99                                    .

0x00000000 (00000)   33                                    3

0x00000000 (00000)   77                                    w

0x00000000 (00000)   59                                    Y

0x00000000 (00000)   81                                    .

0x00000000 (00000)   70                                    p


Strings
:     .
00-+ 
 
CC
.
\
00-+ .
6
.
..
..l
.
.
].
/
;.
.

>>]]||
040904b0
10.0.30203.0
](|2
- abort() has been called
About4Quit the application; prompts to save documents
&About Zortam Mp3 Media Studio ...
Add Cover Art from Image file	Alt+Z
Add Image
Additional Help Online
Add Leading Zero to Track Number	Ctrl+0
&Add media to Mp3 Library	Ctrl+M
All Tags	Alt+F5
Analyze Track Volume 	Alt+A
Android Zortam Mp3 Cover Art Fetcher 
April
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
Box Stub
BoxStub.exe
Change Specific Tags	Ctrl+R
Change the window position
Change the window size
Check for updates ...
Check integrity of Mp3 &Library
Clear All	C
CompanyName
&Computer	Alt+F
&Copy	Alt+C
Copy ID3v&1 To ID3v2 Tags	Ctrl+F3
Copy ID3v&2 To ID3v1 Tags	Ctrl+F4
Copy Image
Cover Art and Lyrics	Alt+F8
Cover Art Finder	Alt+F2
Cover Art Only	Alt+F6
- CRT not initialized
dddd, MMMM dd, yyyy
December
Decrease Volume	-
Delete All ID3 Tags	Ctrl+F5
Delete Cover Art From ID3 Tags	Ctrl+F6
&Delete	Del
Delete Image
Delete Lyrics From ID3 Tags	Ctrl+F7
Delete Track Tag Volume Info
?Display program information, version number and copyright
DMicrosoft Visual C++ Runtime Library
DOMAIN error
Down
DUMMY
ECONOUT$
&Edit ID3 Tags	Ctrl+E
EHH:mm:ss
Enlarge the window to full size"Switch to the next document window&Switch to the previous document window9Close the active window and prompts to save the documents
Exit
E&xit	Alt+F4
&Export Mp3 Library To CSV File
Export Mp3 Library To &HTML
February
&File
FileDescription
FileVersion
Find Song Lyrics	Ctrl+L
- floating point support not loaded
Friday
Get cover art
Get cover art	Get lyric	Get lyric
Get Image From Internet
Get More Info About Song
                                 H
         (((((                  H
&Help
         h((((                  H
ID3 Tags - Change Case	Ctrl+F2
Increase Volume	+
&Info	Ctrl+I
InternalName
January
jjjjj
July
June
LegalCopyright
Lyrics and Cover Art Finder	Alt+F3
Lyrics Finder	Alt+F1
Lyrics Only	Alt+F7
March
Microsoft
Microsoft Corporation
 Microsoft Corporation. All rights reserved.
MM/dd/yy
Monday
&Mp3 Library	Alt+M
Mp3 Player	Alt+P
&Mp3 Tagging
mscoree.dll
 .NET Framework
&New Mp3 Library	Ctrl+N
New Zortam Mp3 Library
Next Pane5Switch back to the previous window pane
nKERNEL32.DLL
Normalize Track Volume 	Alt+N
Normalize Volume
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
October
Open
Open an existing document
&Open Mp3 Library	Ctrl+O
Open Zortam Mp3 Library
Open Zortam Visual Player	Ctrl+Z
&Options	Alt+O
OriginalFilename
Paste Image
Pause	P
&Play	Ctrl+P
Play	Ctrl+P
Previous Pane
Print Mp3 Library
ProductName
ProductVersion
Program: 
<program name unknown>
- pure virtual function call
R6002
R6008
R6009
R6010
R6016
R6017
R6018
R6019
R6024
R6025
R6026
R6027
R6028
R6030
R6031
R6032
R6033
Ready
Reduce the window to an icon
Release Notes
&Rename Filename using ID3 Tags	Alt+R
Rip Audio CD	F2
runtime error 
Runtime Error!
Saturday
Save as Zortam Mp3 Library
Save Image to File
Save Mp3 Library &As
&Save Mp3 Library	Ctrl+S
&Save Windows Position
SCRL
Search For Duplicate Mp3 Files	Ctrl+D
Search Info On Amazon.com	Alt+S
Search Mp3 &Library
Search Songs	Ctrl+F
Select All	Ctrl+A
Send to Playlist
September
'Show or hide the toolbar
SING error
Status bar
Stop	S
StringFileInfo
Sunday
(Switch to the next window pane
&Synchronize ID3 Tags	Ctrl+F1
>*]?|T
TFRMDESTINATIONSETTINGS
TFRMDESTNAME
TFRMDIAGNOSTIC
TFRMEXTENDEDINFO
TFRMFADE
TFRMFILEISMISSING
TFRMFILENAMETOTAG
TFRMINFO
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
Thursday
*>?]T|i
TLOSS error
Toggle ToolBar
&Toolbar
&Tools
Translation
Tuesday
- unable to initialize heap
- unable to open console device
Undo Track Volume
- unexpected heap error
- unexpected multithread lock error
"Update Tag with Amazon Information
VarFileInfo
&View
VS_VERSION_INFO
Wav and Mp3 Converter	F3
Wednesday
Without Cover Art
Without Cover Art And Lyrics
Without Lyrics
Write ID3 Tags From &Filename	Ctrl+W
WUSER32.DLL
Zortam Autotag
Zortam Autotag	Ctrl+Z
&Zortam's On-line Forum
=<.*,$
                          
-++++++++++++++++++++/
,)*************)-
,++++++++++++++++++++-
####%%$$$$$%%%%&
+(./,-
"0:0?0
0 0@0`0|0
0 0'0-0v0
0)050:0J0O0U0[0q0x0G1M1R1X1i1
	0;0C0
!010:0C0H0N0T0l0r0y0
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
070A0\0d0j0x0
0@8S1~
0T0X0h0l0p0x0
0U0g0q0}0
0%\Wx"}
1''(''(''(''('''-
_+--''''10-------0000007
101@1D1T1X1h1l1t1
//-/+1111
1%1+13191@1S1z1
1$1,141<1D1L1T1\1d1l1t1|1
1	1$1A1G1T1|1
1)1B1R1^1g1m1z1
1#2D2'4
1,2D2K2S2X2\2`2
1.3.6.1.5.5.7.3.2
%)+/}148
1<:;6 7'
1(JGGGGGGGOOOORRSSSeeeeeeegottt{{t{{{{{
1(JGGGGGGGOOOORRSSSSeeeeeeekkrt{tttt{{{
1(JGGGGGGOOOORRSSSeeeeeegkrtt{{{{{{
1(JGGGGGOOOORSSSSeeeeeeeottt{{{{{{{
1&JxzY
1Q2^2s2y2
1#QNAN
1(RMdddddeegggggjjrrrrrxreeeeTkotttttt
1#SNAN
1V2\2x2
1Y1_1t1{1
1&'''''''''''''''''''''ZleeeeeTkkkrsttt
20&Ylm
21282>2
(2,2024282<2H2L2|2
2 2024282@2X2
2 21272>2i2
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
`222222(((((((((((((((&4
2*292F2R2b2i2x2
2:3@3D3H3L3
;|2~>a?
2	Alignment
2h9h:l:p:t:x:|:
2kAd{Q
2l?t?|?
2MR}vG
^2ScIqe
@ 2ys?
322223333499AAABBBBBBEFFMMMMMMMPPQQPMCCMMMMMNNNNNNNNQQRRRRRRRRRWWYYYYr
322333334999AABBBBEEEFFMMMMMMPPQQQQQQPMMMMPNNNNNNQQQQRRRRRRRRVYYYYYYYs
322333399999AABBBBEEEFMMMMMMOPPQQQQQQRQMMMNNNNNNQQQQRRRRRRRRRWYYYYYYY
3233334999AAABBBBEEEFMMMMMMOPPQQQQQQQQUQMPNNNNQQQQQRRRRRRRRVWYYYYYYYY
3233334999AABBBBEEEFFMMMMMMMPPQQQI88888886677788888888888888888:SYYYY
3-323X3{3
3 3@3`3|3
3333344999AABBBBEEFFFMMMMMMPPPQQ
33334999AAAABBBEEEFFFMMMMMMPPPQ5
33339499AAABBBBBEFFFMMMMMMPPPQQ
3$3*3?3k3
33349999AAABBBBBEFFMMMMMMPPPQQQ
3(3.373=3F3R3X3`3f3r3x3
3-353E3V3
3.4;4T4r4
3<4B4l4r4x4
363<3Q3X3^3c3i3v3
3:#7	7
37xxwww
;,;3;9;
:,:3:9:@:Y:i:u:~:
3M3\3e3
@3nl2^
43399999AABBBBBEEFFMMMMMMPPQQQQ
4344999AABBBBBBBEEMMMMMMMPPQQQQ
4344999ABBBBBEEFFMMMMMMMPPQQQVq
434499AAABBBBBEEEFMMMMMMMPQQQQQ
44449AAABBBBBEFFFMMMMMMMPPQVqqq
4$4-474T4k4p4u4
4-464N4q4~4
44999AAABBBBBEFFFMMMMMMPPUllqqq
4499AAAABBBBBEFFMMMMMMMQVVlqqqq
4499AAABBBBBBEFMMMMMMMQlVVlqqqq
4(4H4h4
%4.4x 
4-5=5F5O5U5q5v5
474i4p4t4x4|4
:-:4:8:<:@:D:H:L:P:
4C5r5x5
4F5i5s5
::'5";
)5"'(-$'
506X6z6
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
5!5.5>5O5[5h5s5z5
5=6P6o6
585X5t5x5
{~5i}y
>(>/>5>=>J>q>w>
5/r*&j.,
=*>5>R>t>
5S8W8[8_8c8g8k8o8s8w8{8
656>6J6
6                                                                                          6
6+616:6?6E6K6P6U6h6n6}6
6$6+61676D6Y6{6
6%6+62686?6E6M6T6Y6a6j6v6{6
6$6@6`6
6!6/6=6l6w6
6$747H7\7h7p7
=!=6=<=B=Z=`=}=
;6<<<@<D<H<
6p!r-E
-6|t!f}
6V9Z9^9b9f9j9n9r9
<!<6<?<W<
7111111111111111111111+ZkeeeeeTTTkkkoppts
7+727K7_7e7n7
7'747J7c7h7n7
7%7*727C7J7P7V7]7g7
7*7<7A7
7<7B7Z7:8`8f8
798Y8h8u8
<7<B<_<l<
?.?7?=?F?K?Z?
7G9b9x9
;7|G;p
7http://xrecode.com/xrecode2/samplefiles/filenames2.txt.
-;8::::::::::::<+
%=:?<)*8
84<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
868@8F8N8W8h8{8
8"8'8-8E8N8]8s8
8%8:8C8[8
8'898K8]8o8
889B9m9
8@8H8L8d8h8
8\8M1/8
8+9D9I9j9w9
8+9I9O9T9Z9u9~9
,8AAABBBBBBBCCM=(
,8AABBBBBBBBCCM=(
;8;?;D;H;L;m;
;(<8<H<X<h<
9499ABBBBBEBEFMMMMMMTVVVVqqqqqq
949AAABBBBBEEEMMMMMMMTVVllqqqqq
949AABBBBBEEFMMMMMMQVVVVVqqqqqr
949BBBBBBFFMMMMPVVVVVVVlqqrrrrr
94AABBBBBBEEFMMMMMQVVVVVlqqqqrq
94AABBBBBBEFFMMMMPVVVVVVVqqqrrr
94AABBBBBBFFFMMMMUVVVVVVXqqrrrr
94AABBBBBEFFMMMMQVVVVVVVlqqrrrr
94ABBBBBBBFMMMMMUVVVVVVlqqrrrrr
95:\:|:
9	:7:Z:`:
9$959E9_9M:[:s:y:
9#9C9H9
9b=e\!S
$9J	p)
;9;\;o;
a$%%%%%%%%%%%%%%%%%%+++4
A44BBBBBCMMMMMMUVVVVVVXqqqrrrrr
A44BBBBBCMMMMMPVVVVVVVXqqqrrrrr
A4AABBBFFMMMMMQVVVVVVlqqqqrrrrr
A4ABBBBBEFFMMMMUVVVVVVlqqqrrrrr
aaaa????????????%
,:AABBBBBBBCCCM=+
A@@ABBBFFMMMMMUVVVVVVVXqqrrrrrr
abcdef
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
AcceptSecurityContext
AcquireCredentialsHandleA
ActiveControl
ActivePage
AdjustTokenGroups
ADVAPI32.dll
a+EWWWW]
(af\e:
+>AHHHHHHHHHHGGJJJJJB-
AJJJddeTU
akBottom
akLeft
akRight
alBottom
alClient
	Alignment
AlignWithMargins	
:ALK2u
All Files (*.*)
All Files (*.*)|*.*
Anchors
ANSI_CHARSET
AP4J$Rm
aRfy-c
Arg list too long
?!?a?s?
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<at,<rt"<wt
August
AutoSize
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
a}@X8L
}@;@*B
B9S.LY
BAABBBBFMMMMMMUVVVVVVXXqrrrrrrr
BAABBBFFMMMMMMUVVVVVVlqqrrrrrrr
BABBBBBMMMMMMMVVVVVVVqqrrrrrrrs
BABBBBFMMMMMMMUVVVVVVXqrrrrrrrs
Bad address
bad allocation
bad exception
Bad file descriptor
BALTIC_CHARSET
 Base Class Array'
 Base Class Descriptor at (
__based(
,:BBBBBBBBCCCCM=(
BBBBBBBBCMMMMPQVVVVXqXYrrrrrrss
BBBBBBBMMMMMMMUVVVVVXqqrrrrrrrs
bbodgUaY
bCancel
bClose
bCloseClick
bCopyToClipboard
bCopyToClipboardClick
<b<d>I53
BeginPaint
Bevel1
Bevel2
BevelBottom
BevelOuter
BISSUVY
bLoadClick
BorderStyle
BPkz}vY
bResetToDefault
bResetToDefaultClick
Broken pipe
bsDialog
bsNone
bsSizeToolWin
button
Button1
Button1Click
bvNone
>B>[>w>
~/BYzl
{?c?2{7
Cancel
Cancel	
Caption
Caption2
Caption2Left
cbStrip
cbStripClick
+\cccccccccccccccccc\-
__cdecl
CheckRadioButton
=%===C=J=P=k=r=x=
ckqvoaw
 Class Hierarchy Descriptor'
	clBtnFace
ClientHeight
ClientWidth
ClL:	e
CloseHandle
__clrcall
clWindowText
coAllowClick
coAllowFocus
coAutoSpring
coDraggable	coEnabled
Columns
CombineRgn
COMDLG32.dll
 Complete Object Locator'
coParentBidiMode
coParentColor
`copy constructor closure'
CopyImage
	Copy to c
Copy to clipboard
coResizable
CorExitProcess
coShowDropMark	coVisible
coSmartResize
Courier New
CreateCompatibleBitmap
CreateCompatibleDC
CreateEllipticRgn
CreateFileA
CreateFileW
CreatePopupMenu
CreateSolidBrush
CreateWindowExA
crHandPoint
CSDQ+~
Cursor
D$1}F6
d<<AGGGGGGGGGOOOOOOOOeTTTTTTTTTooopppppppx
@.data
dddd, MMMM dd, yyyy
d.(dGGGGGOOORRSSSeeeeeegrtt{{{{{{{{{
d.(dGGGGOOOORSSSSeeeeegrst{{{{{{{
d.(dGGGOOOORSSSSeeeeegr{{{{{{{{{
d.(dGGOOOORRSSSeeeeegrs{{{{{{{{{{
d.(dGGOOORRSSSeeeeegk{y{{{{{{{~~
d.(dGOOOORSSSeeeeeggzy{{{{{{~~~
d.(dGOOORSSSeeeeggky{{{{{{~~
d.(dOOOORRSSSeeeeggr{{{{{{{~~~
December
DecodePointer
Default	
DEFAULT_CHARSET
`default constructor closure'
DefWindowProcA
delall
 delete
 delete[]
DeleteCriticalSection
DeleteDC
DeleteObject
DesignSize
desk.cpl
d<<FFFGGGGGGGGOOOOOOOOOSTTTTTTTTTooooppppr
d<<FFGGGGGGGGGOOOOOOOOOTTTTTTTTTTooopppppr
d<<FGGGGGGGGGGOOOOOOOOSTTTTTTTTToooopppppx
d<<FGGGGGGGGGOOOOOOOOOTTTTTTTTTToooppppppx
d<<<FGGGGGGGOOOOOOOOeTTTTTTTTToooooopppppz
d<<<GGGGGGGGOOOOOOOOOeTTTTTTTTTooooppppppx
d.(gOOORRSSSeeeeggr{{{{{{~~~
d.)gOOORSSSeeeeggg{{{{{{~~~
d.)gOORSSSeeeeeggr{{{{{~~~
dGSx~~
dHJJJNSe
Diagnostic
DialogBoxParamA
DIISSV
Directory not empty
DisplayName
d.)jddeeggggjrrrx~~
d.)jOORSSSeeeeggkr{{{{~~~
~dK9]O
d.)[[[mmmmv
Domain error
DoubleBuffered
DoubleBuffered	
:^;d;r;
DrawTextA
>&>.>>>D>U>
dVista
`dynamic atexit destructor for '
`dynamic initializer for '
:	;,;E;
E0_0h0
__eabi
Ea:d*m
eAlias
eAliasExit
eAmIg8g5
EBBBBBBBCMMMPPQVVVVXXYYrrrrrrss
EBBBBBBBMMMMMMQVVVVXqqrrrrrrrrs
EBBBBBBCCCMPMNNVVVXXYrrrrrrrrrs
EBBBBBCCCCMMNNNQVVXXYrrrrrrrrr
EBBBBCCCCCMMMQNQVXXYrrrrrrrrrs
eDestNameChange
eDestNameExit
;e@{fksi
"e<}fl
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
EIISSU
EJJ4_E
e!jppp
\ ]EMMOPPSTThht}}}}}
Enabled
EncodePointer
EndDialog
EndPaint
EnterCriticalSection
EnumPrintersA
EOSThVr
ePattern
ePatternKeyDown
ePatternKeyPress
Error 0x%x finding cert chain
eStrip
ETtz}rZ
Exec format error
ExitProcess
ExplicitHeight
ExplicitLeft
ExplicitTop
ExplicitWidth
eYVEKx
f-00f=
F1VBpv
F2O$;#.
__fastcall
FavoriteLinks
FBBBBCCCCMMMMMQQUXXrrrrrrrrrrs
FBBBCCCCCMMMMMMNQXXrrYrrrrrrs
FBBCCCCCCMMMMMMNNRqYrrrrrrrss
FBBCCCMMMMMMMMNNNNRXrrrrrrrss
FBCCCCCMMMMMMNNNNNNRXYrrrrss
fdoAllowMultiSelect
February
f>e:ur
fFht|}r
FH9;*2
Fh=@UE
Fhyra_
File exists
FileMask
	File Name
Filename too long
File too large
	FileTypes
FillRect
FillRgn
Filter
FindTextA
FJJJNdeo
FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. FLAC - Free Loseless Audio Codec. Resulting file will always be loseless, regardless of settings. 
FLAC Settings
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
\ ]FMMOPPTTUhh{}}}}
\ ]FMOPPTTUhht}}}}
FOejrrtpUV
FOgjrz{pU
Font.Charset
Font.Color
Font.Height
	Font.Name
Font.Style
FORdegkTU
	FormClose
FormCreate
FormCreate	OnKeyDown
FormKeyDown
FormResize
FormShow
FP1C%	
FreeEnvironmentStringsW
FreeLibrary
Friday
frmDestinationSettings
frmDestName
frmDiagnostic
frmExtendedInfo
frmFade
frmFileIsMissing
frmFilenameToTag
frmInfo
fsBold
Function not implemented
;]	F.w
;&;>;g;
[g35A$
gbAddInputSettings
gbNeroAACSettings
GDI32.dll
GetACP
GetActiveWindow
GetClientRect
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetCPInfo
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetCursorPos
GetDlgItem
GetEnvironmentStringsW
GetFileType
GetLastActivePopup
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetObjectA
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoW
GetStdHandle
GetStockObject
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount
GetUserObjectInformationW
GetVersion
GetWindowDC
GetWindowLongA
+@GFFFGGGGGGGGGGOOOOB-
+@G<FFGGGGGGGGGGGOOOB-
+@GFFGGGGGGGGGGGOOOPC-
%GFFIOOOSSSTUhhhhhUUUlquvvvv
+@GFGGGGGGGGGGGOOOOPC-
+@GFGGGGGGGGGGOOOOOSC-
GGJJSdeeo
GGRddekTU
Glyph.Data
gR&SzK
gV#W{<
`h````
Header.AutoSizeIndex
Header.DefaultHeight
Header.Font.Charset
Header.Font.Color
Header.Font.Height
Header.Font.Name
Header.Font.Style
Header.Height
Header.Options
Header.ParentFont	
Header.SortColumn
Header.Style
HeapAlloc
HeapCreate
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
Height
h<<FFGGGGGOOOOOOOOOeTTTTTTTTToooopppppppp{
h<<FFGGGGGOOOOOOOOOSTTTTTTTTToooooppppppp{
h<FFGGGGOOOOOOOOOOOSTTTTTTTTooooppppppppp
hFGGGGGGGOOOOOOOOOOSTTTTTTTTooppppppppppp
h<<<FGGGGGGOOOOOOOOOTTTTTTTTTTooooopppppp{
h<<<FGGGGGGOOOOOOOOSTTTTTTTTTTooooppppppp{
h<<<GGGGGGGGOOOOOOOOeTTTTTTTTooooopppppppz
h<<<GGGGGGGOOOOOOOOOSTTTTTTTTToooooppppppz
}h|}Gm
`h`hhh
HHHIdj
HHHINg
[HHHJd
_^^/hhi/iij/fff/```"
HH:mm:ss
HHt$HHt
HJJJMdeo
H\ky#s
= =$=h>l>p>t>x>|>
HluG=*
<H<N<V<
hoAutoResize
hoColumnResize
hoDisableAnimatedResize
hoDrag
hoHeaderClickAutoSort
hoHeightDblClickResize
hoShowSortGlyphs	hoVisible
=h=q=w=
hsFlatButtons
http://flac.sourceforge.net
,http://rarewares.org/dancer/dancer.php?f=226
HUw!Hmu
_hypot
>I12==
i2c+IO.b
i>_A9|kA
%Ib%8*
_Id%.q
?If90t
iFGGGGGGGGGOOOOOOOOSTTTTTTooooppppppppppp
iFGGGGGGGGOOOOOOOOOeTTTTTTooooopppppppppp
iFGGGGGGGOOOOOOOOOOTTTTTTTToooopppppppppp
i<FGGGGGGOOOOOOOOOOeTTTTTTTTooopppppppppp{
i<FGGGGGOOOOOOOOOOOeTTTTTTToToopppppppppp
\%iFOOPPTTUhhz}}}
iGGGGGGGGGGGOOOOOPPPTTTTTToooUUppppppppqqq
iGGGGGGGGGGGOOOOPPPPTTTTToooUUpppppppppqqq
iGGGGGGGGGGOOOOOOOPSTTTTTToooUpppppppppqq
iGGGGGGGGGGOOOOOPPPPSTTToooUUpppppppppppq
iGGGGGGGGGGOOOOPPOPPSTTTTooUUUppppppppppq
iGGGGGGGGGOOOOOOOPPPPTTTooUUpppppppppppq
igr7c^
Illegal byte sequence
ImageIndex
\ iMOPSTThhlt}}}
Improper link
Inappropriate I/O control operation
in,En!P
InitializeCriticalSectionAndSpinCount
InitializeSecurityContextA
Input/output error
InterlockedDecrement
InterlockedIncrement
Interrupted function call
Invalid argument
InvalidateRect
Invalid seek
invalid string position
>{{IOW
Is a directory
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
J7JJ4DE
J7JJ8C
January
%JBBBBBFMMOOPPQTTUUhquv}v}}}}
j{eXkMi
jGGGGGGGGOOOOOOOOOPPSSoooUUppppppppppppq
jGGGGGGGOOOOOOOOOOOOPSSoooppUpppppppppq
jGGGGGGGOOOOOOOOOOOSSSTooUpppUppppppppq
jGGGGGGOOOOOOOOOOOOOPPSToopUUppppppppqq
jGGGGGOOOOOOOOOOOOOPPPPPSoUUppppppppqqq
jGGGGGOOOOOOOOOOOOOPPPPSooUUppppppppqqq
jGGGGOOOOOOOOOOOOOPPPPPPPSToppppppppqq
jGGGOOOOOOOOOOOOOOPPPPPPPPQTTTUppppqq
jGGGOOOOOOOOOOOOOPPPPPPPPSPQTTooUUUppq
jGGOOOOOOOOOOOOOPPPPPPPPSSSSSQUUUUUUUUUUUUpeWEEEEEEEEEEEEEEEEEEEED+b
jGGOOOOOOOOOOOOPPPPPPPPPPSSSQUoUUUUUUUUUUUUd.++++%%%%%%%%%%%%%%%%%$b
JGJJSdeeo
jGOOOOOOOOOOOOOPPPPPPPPSSSSSSQQUUUUUUUUUUpppUUUpppppppqqqq
jGOOOOOOOOOOOOPPPPPPPPPPPSSSQQQQUUUUUUUUUUpq
jGRSdegkTU
j,h(8E
j(h]a/C
JJJJ H
j@j ^V
:J*)[-lU
JOJJ8C
jXhh3E
:%:J:Y:a:n:z:
Jzae[u
"JzJJ J
"JzJJ"JZJJ J
K{;+#0
K9:::::;;;;;;<<<A<AFFGGGGGGGGGGOOOOOOOOOOOPPPSSPOOOOOOOOOOOPPPPPPPPPPPPPQQQQQQQQQQQQUUUUUUUUU
%KBBBBFMMOOPPTTTUhltv}}}}}
 KBBBEFMOOPPTTTUhlu}}}}}}}
kernel32
KERNEL32.dll
KeyPreview	
kfY5;D
KillTimer
Kpk?,N
>@>K>Q>a>f>w>
L:::;;;;;;AAAAAAAFFGGGGGGGGOOOOOOOOOOORSSSSSSSSSSSSeOOOOPPPPPPPPSSSSSQQQQQQQQQQQQQUUUUUUUUUUU
L::;;;;;;AAAAAAAFFGGGGGGGGOOOOOOOOOOORSSSSSSSSSSSSSSTPOPPPPPPPPSSSSSSQQQQQQQQQQQQUUUUUUUUUUUU
L::::;;;;;;AAAAAAFFGGGGGGGGGOOOOOOOOOORSSSSSSSSSSSSOOOOOPPPPPPPPPSSSSSQQQQQQQQQQQQUUUUUUUUUUU
L:;;;;;A<AAAAAFFGGGGGGGGOOOOOOOOOOOOPPSSSSS
L:;;;;;<<AAAAAAFFGGGGGGGGOOOOOOOOOOOOSSSSSSSH
L::;;;;;<<AAAAAFGGGGGGGGGOOOOOOOOOOOORSSSSSSSSQQQQQTQTPPPPPQQQQQQQQQQQQQUUUUUUUUUUUVVVUUUUUUV
L::::;;;;;;;AAAAFFFFGGGGGGGGOOOOOOOOOOPSSSSSSSSSSOOOOOOOOPPPPPPPPSSSSSQQQQQQQQQQQQQUUUUUUUUUU
L:;;;;<<<AAAAFFFGGGGGGGGOOOOOOOOOOOOPSSSSS=
Label1
Label2
Label3
Label4
Label5
[ LBBBFMMOPPPTTUUquv}}}}}
[ LBBFMMOPPSTTUhl}}}}}}}
[ LBEMMOOPPTTUhlu}}}}}}
LCMapStringW
{:l<c<P:
LeaveCriticalSection
\ LEFMOOPPTTUUht{}}}}}
l|hghPh
Lines.Strings
lMoreInfoLink
lMoreInfoLinkClick
LoadCursorA
LoadIconA
LoadLibraryA
LoadLibraryW
LoadStringA
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
:.;L;r;
lstrcatA
lstrcpyA
lvFiles
lvFilesCompareNodes	OnGetText
lvFilesGetText
M<075'#
M%?{#4
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
Margins.Bottom
Margins.Left
Margins.Right
Margins.Top
	MaxLength
MBCCCCCMMMMMMNNNNNNQVVVYYYrs
MCCCCMMMMMMMNNNNNQQQQVXXYYYYYYYr\%%%%%$%%%%%%""$"
MCCCMMMMMMMNNNNNQNQQQRRVYYYYYrYrr
MCCCMMMMMMMNNNNNQNQQQRVYYYYYYrYrl]]]]]]]]fffffig] 
MessageBoxA
MessageBoxW
Microsoft Unified Security Protocol Provider
miDelete
miDeleteClick
MM/dd/yy
[ `mmmoxy
ModalResult
Monday
='=,=M=S=q=
MSVCRT90.DLL is missign from your system. Please go to the following link and install  Microsoft Visual C++ 2008 Redistributable Package. 
M t7;9
m&"u,&
MultiByteToWideChar
>>>>>>>>>>>>>>?mUUUUllqtvvv
?%?M?X?
n*9?B}
Nd1n-k$
Negotiate
 new[]
_nextafter
No child processes
No error
NOJZJJ
No locks available
No space left on device
No such device
No such device or address
No such file or directory
No such process
Not a directory
Not enough space
November
(null)
nuXh5M
nWk,r}
:>=n=x=
Nz`3Ys
o5_:]9G>
October
oEIISUr
ofAllowMultiSelect
ofEnableSizing
ofHideReadOnly
OldCreateOrder
,[OMMMMFCCCCMMM=(
`omni callsig'
,[OMOPPQQMCMMMM=+
OnChange
OnClick
OnClose
OnCompareNodes
OnCreate
OnExit
	OnGetText
	OnKeyDown
OnKeyPress
OnResize
OnShow
OnURLClick
,[OOPPQQQQQPMMP=(
Operation not permitted
operator
Options
o!q9_(
:+;=;O;u;
PADTPF0
PageControl1
PageControl2
Panel1
Panel2
Panel3
Panel4
ParentBackground
ParentColor
ParentDoubleBuffered
ParentFont
ParentFont	
__pascal
PATPF0
::;pEFI
Permission denied
PixelsPerInch
`placement delete closure'
`placement delete[] closure'
poNone
,[POPQQQQQRUQMN=(
	PopupMenu
PopupMenu1
poScreenCenter
Position
PPPPPPPP
,[PPPQQQQQUUVVQ=+
ppqqpq
,[PPQQQQQQRVVVq^(
,[PQQQQQRUVVVVq_(
PrintScale
PsAVU[
PSSSSS
PSSSSVh,
__ptr64
+puw[T
P:\work\Refer\closely\achieve\unre.pdb
}|Qh8H
Q_O+rq
,^QQQQQTUVVVVVq_(
QQSVWd
QueryPerformanceCounter
qUUUUUV
R>	2	x`
RaiseException
rbfZtc
`.rdata
ReadFile
ReadOnly	
Read-only file system
ReAlloc
RegisterClassExA
reInfo
reInfoURLClick	ShowCaret
ReleaseDC
@.reloc
        <requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
      </requestedPrivileges>
      <requestedPrivileges>
Reset to Default
Resource deadlock avoided
Resource device
Resource temporarily unavailable
__restrict
Result too large
reTags
reTagsKeyPress	ShowCaret	
`rfT0c
RGSgnrztUV
Rich-5
<rkRdO
rqq|lll[
R{`s#<
RtlUnwind
!%^%&*r&'+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&(+t&'+t%&*r "%^"$'*
R;Z<+2y
S)9Q0#
Saturday
Sc]2c7
`scalar deleting destructor'
ScrollBars
Seconds
Secur32.dll
    </security>
    <security>
SelectObject
SendMessageA
September
SetBkMode
SetDlgItemInt
SetEndOfFile
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
SetTimer
SetUnhandledExceptionFilter
SetWindowLongA
SetWindowRgn
SetWindowTextA
=-S*GY
ShowSelRange
ShowWindow
;S;`;j;x;
ssBoth
^SSSSS
ssVertical
__stdcall
`string'
string too long
Sunday
s=x=~=
SysTabControl32
sYYZ|%
TabOrder
TabStop
taCenter
Tahoma
TBevel
tbPosition
tbStart
TButton
	TCheckBox
tCHt(Ht 
	TComboBox
TEdit	eDestName
TerminateProcess
TextHeight
TextOutA
TFileOpenDialog
TfrmDestinationSettings
TfrmDestName
TfrmDiagnostic
TfrmExtendedInfo
TfrmFade
TfrmFileIsMissing
TfrmFilenameToTag
TfrmInfo
	TGroupBox	GroupBox1
+t HHt
ThinTrackBar1
ThinTrackBar2
__thiscall
!This program cannot be run in DOS mode.
Thursday
	TickMarks
< tK<	tG
TLabel
TlAgJ1
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
tmBoth	TickStyle
	TMenuItem
	tmTopLeft	TickStyle
toAcceptOLEDrop
toAutoDeleteMovedNodes
toAutoDropExpand
toAutoScrollOnExpand
toAutoSort
toAutoTristateTracking
toCop{
toEditOnClick
toFullRepaintOnResize
toFullRowSelect
to=h^E
toInitOnSave
toNodeHeightResize
ToolbarWindow32
Too many links
Too many open files
Too many open files in system
TOpenDialog
TopTanel
toShowButtons
toShowDropmark
toShowRoot
toShowTreeLines
toThemeAware
toUseBlendedImages
toUseExplorerTheme
toVariableNodeHeight
toWheelPanning
TPageControl
TPanel
TPanel	pButtons1
TPm%!`
TPopupMenu
,^TQQQUUVVVVVXr_(
tR99u2
Transparent
Transparent	
t*=RCC
TreeOptions.AutoOptions
TreeOptions.MiscOptions
TreeOptions.PaintOptions
TreeOptions.SelectionOptions
tRHtCHt4Ht%HtFHHt
TRichEditURL
  </trustInfo>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
tsFromFile
tsManually
tsNone
TSpeedButton
t"SS9] u
tsTags
<+t"<-t
	TTabSheet
TThinTrackBar
TTwoCaptionGroupBox
t$<"u	3
Tuesday
tuw<f8e
;t$,v-
TVirtualStringTree
TwoCaptionGroupBox1
 Type Descriptor'
`typeof'
>!?;?U?
`udt returning'
UlSa[L
__unaligned
UnhandledExceptionFilter
UNICODE
Unknown error
Unknown exception
|u[P/}
UpdateWindow
UQPXY]Y[
URPQQh 
USER32.dll
UTF-16LE
,^UTTUUVVVVqqqrc(
uTVWh)
?UUUUUU
?UUUUUV
&`UUUUVVlllqquvc%->>>
|uV_L4
}{uxl=|i,n^6xtl
?uZEeu
%&*V+-0\+-0\+-0\+-0\+-0\+-0\+,0\+-0\+,0\+-0\%'+V
v+6Hfj
V9iteO
`vbase destructor'
`vbtable'
`vcall'
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
`virtual displacement map'
Visible
v	N+D$
?/?:?V?\?q?x?~?
W1^1d1
w3utcb
WantReturns
WantTabs	
+WdOOOOGGGGGGOOOOOOSC-
Wednesday
WideCharToMultiByte
WideText
Window
Windows App
WINSPOOL.DRV
WordWrap	
wqps[s
WriteConsoleW
WriteFile
+WSOOOSSSSOGOOOOOOOSC-
+WSOOOSSSSSSPOOOOOOSC-
WTSAPI32.dll
WTSEnumerateSessionsA
wwwwwwww(
wxqwwp
	X 9} 
X;;;;;A<AAAAAFFGGGGGGGGOOOOOOOOOOOOPPSSSSS
X;;;;<AAAAAFFFGGGGGGGGGOOOOOOOOOOOPSSSSSSJ
X;;;<<AAAAAFFGGGGGGGGGGOOOOOOOOOOOSSSSSSSJ
X;<AAAAFFFFGGGGGGGGOOOOOOOOOOOOPPSSeooooor
X;;;<<AAAAFFFGGGGGGGGGGGOOOOOOOOOOSSSSSSSJ
X;;;;<<AAAAFFFGGGGGGGGGOOOOOOOOOOOPPSSSSSJ
X;;<<<AAAAFFGGGGGGGGGGGOOOOOOOOOOPSSSSSSSJ
X;;<<<AAAAFGGGGGGGGGGGGOOOOOOOOOOPSSSSSSSg
X;;<<<AAAFFGGGGGGGGGOOOOOOOOOOOOPPSSSSSeox
X;;<<AAFFFFGGGGGGGGOOOOOOOOOOOOPPSSSSeooor
?](XbApn
xKIs*&
xppwpp
xpxxxx
x[$ttb
xwwwwsSg
Y;AAAAFFFGGGGGGGGGGOOOOOOOOOOSkTTTTooooopr
Y;<AAAAFFFGGGGGGGGGOOOOOOOOOOOOSeoTToooppr
Y;AAAAFFGGGGGGGGGGGOOOOOOOOOSTTTTToooooppr
Y;<AAAAFFGGGGGGGGGGOOOOOOOOOOOSTTTTToooppr
Y;<<AAAFFFFGGGGGGGGOOOOOOOOOOOPPPSTTkooopr
Y;AAAFFGGGGGGGGGGGOOOOOOOOOSTTTTTToooooopx
Y;<AFFGGGGGGGGGGGOOOOOOOOOSTTTTTTooooooppx
Y<<AFFGGGGGGGGGGOOOOOOOOOSTTTTTTkooooooppx
]y@aN+bK
yEOSUhV
Y<<FFFGGGGGGGGGGOOOOOOOOPTTTTTTTTkoooopppx
Y<<FFFGGGGGGGGGOOOOOOOOOeTTTTTTTTooooopppx
^^yGFc
.y.luC
You can load Metadata from text file. File must be in format like in any those files: http://xrecode.com/xrecode2/samplefiles/filenames1.txt,
Yr_XH:N
z$}	?}
|:z3eH
<&=Z;4+
z<8t!N
+ZdOSSSSSSSSSSeeTSOSC-
+ZeOSSSSSSSSSSeTTTTeC-
+ZePSSSSSSSSSeTTTTTsZ-
+ZePSSSSSSSSSSeTTTTrE-
+ZeSSSSSSeeeTTTTTTTsZ-
+ZeSSSSSSSSSTTTTTTTsZ-
+ZgSeeeeTTTTTToooop{^-
+ZgSSSeeeeTTTTkoooo{^-
+ZgSSSSSeeeTTTTTTootZ-
ZOq>TX
?zsG`A
+ZSOOSSSSSSSSSeeOOOSC-
+ZSOOSSSSSSSSSSOOOOSC-
))+{))+z))+z2.*<
/~~~/}}~/}}}/|||/{{{/zz{/zzz/yyy/xxy/xxx/www/vvv/uuv/uuu/ttt/sss/mmm/XWU: