Analysis Date2015-01-19 16:55:47
MD5a8c2e2c44de08da685210532f8c596e7
SHA10846d787ace92aa8c9796c500512657558da5618

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: c69726ed422d3dcfdec9731986daa752 sha1: 4546608e3b1a2ab1d69a34018d2ddfa7fa411885 size: 23040
Section.rdata md5: a2c7710fa66fcbb43c7ef0ab9eea5e9a sha1: 60485025c47935e745e57b6efc7042f2261b7d53 size: 4608
Section.data md5: e59cdcb732e4bfbc84cc61dd68354f78 sha1: ffc24489dd56b406f9078ba1cb9c71e9b430dbee size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: 782b8aa74dd32f4aef551bb3d1e465bf sha1: ca8f1d05c05e161ba4efc6d9089702fbbda4d2b4 size: 112128
Timestamp2009-12-05 22:50:41
VersionLegalCopyright: BEARPC¾«Ñ¡Èí¼þ¼¯
ProductName: ·ßÅ­µÄСÄñ
FileDescription: ·ßÅ­µÄСÄñPCºº»¯°æ
FileVersion: 1.0.0
CompanyName: www.bearpc.net
PackerNullsoft PiMP Stub -> SFX
PEhash33eaad3caa2a475fb3a0ab3b1c6f43ecac557792
IMPhash7fa974366048f9c551ef45714595665e
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)no_virus
AVBullGuardno_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftno_virus
AVEset (nod32)no_virus
AVFortinetno_virus
AVFrisk (f-prot)no_virus
AVF-Secureno_virus
AVGrisoft (avg)no_virus
AVIkarusno_virus
AVK7no_virus
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp\Base64.dll
Creates FileBF-BFVCenter[[AB027]].exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileOfficeAssist.0405.80.1119.exe
Creates File1
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp\System.dll
Creates File1.rar
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FilePPTV_forqd2015.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\Program Files\3.ico
Creates FileC:\Program Files\1.ico
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp\Inetc.dll
Creates Filehkyl_yls_hk2014_200lm.exe
Creates FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp\ExecCmd.dll
Creates File-2000_1_mp.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileMM-liao8302.exe
Creates Fileyx_dts.exe
Creates Filesetup_95165069.exe
Deletes FileBF-BFVCenter[[AB027]].exe
Deletes Filehkyl_yls_hk2014_200lm.exe
Deletes FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Deletes File-2000_1_mp.exe
Deletes FileOfficeAssist.0405.80.1119.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst1.tmp
Deletes File1.rar
Deletes File1
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp
Deletes FileMM-liao8302.exe
Deletes Fileyx_dts.exe
Deletes Filesetup_95165069.exe
Deletes FileC:\Program Files\3.ico
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB027]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB027]].exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1119.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1119.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\-2000_1_mp.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\-2000_1_mp.exe"
Creates Processhkyl_yls_hk2014_200lm.exe
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\hkyl_yls_hk2014_200lm.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\hkyl_yls_hk2014_200lm.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_dts.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_dts.exe"
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex1.ico
Winsock DNSint.dpool.sina.com.cn
Winsock DNSsoftonline.b0.upaiyun.com
Winsock DNS121.43.69.253

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB027]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB027]].exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\hkyl_yls_hk2014_200lm.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\hkyl_yls_hk2014_200lm.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1119.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1119.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\-2000_1_mp.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\-2000_1_mp.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_dts.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_dts.exe"

Process
↳ hkyl_yls_hk2014_200lm.exe

Network Details:

DNSint.dpool.sina.com.cn
Type: A
180.149.136.250
DNSna.b9.aicdn.com
Type: A
72.8.188.94
DNSna.b9.aicdn.com
Type: A
72.8.188.98
DNSna.b9.aicdn.com
Type: A
108.186.7.129
DNSna.b9.aicdn.com
Type: A
108.186.7.130
DNSna.b9.aicdn.com
Type: A
108.186.7.131
DNSna.b9.aicdn.com
Type: A
72.8.188.90
DNSdownload012.rdb.cnc.ccgslb.com.cn
Type: A
218.60.107.12
DNSdownload012.rdb.cnc.ccgslb.com.cn
Type: A
61.179.105.147
DNSmmliao.jianting.net
Type: A
122.227.42.227
DNSwww.fengzhangyu.com
Type: A
223.6.254.23
DNSc01.i06.arnic.hadns.net
Type: A
183.56.172.47
DNSc01.i06.arnic.hadns.net
Type: A
222.186.20.122
DNSc01.i06.arnic.hadns.net
Type: A
58.220.2.5
DNSc01.i06.arnic.hadns.net
Type: A
113.17.184.10
DNSc01.i06.arnic.hadns.net
Type: A
121.10.117.139
DNSc01.i06.arnic.hadns.net
Type: A
121.10.117.139
DNSc01.i06.arnic.hadns.net
Type: A
183.56.172.47
DNSc01.i06.arnic.hadns.net
Type: A
222.186.20.122
DNSc01.i06.arnic.hadns.net
Type: A
58.220.2.5
DNSc01.i06.arnic.hadns.net
Type: A
113.17.184.10
DNScdn.coop.baofeng.com
Type: A
119.188.72.240
DNScdn.coop.baofeng.com
Type: A
122.142.74.12
DNScdn.coop.baofeng.com
Type: A
182.18.51.104
DNScdn.coop.baofeng.com
Type: A
218.60.99.66
DNScdn.coop.baofeng.com
Type: A
58.20.193.222
DNSmeipin.souxuncn.com
Type: A
183.136.235.13
DNSdown.woka123.cn.w.alikunlun.com
Type: A
106.120.181.50
DNSdown.woka123.cn.w.alikunlun.com
Type: A
27.221.34.120
DNSdown.woka123.cn.w.alikunlun.com
Type: A
106.120.181.40
DNSsoftonline.b0.upaiyun.com
Type: A
DNSwdl1.cache.wps.cn
Type: A
DNSd.qq66699.com
Type: A
DNSdl.nx5.com
Type: A
DNSdl.baofeng.com
Type: A
DNSdown.woka123.cn
Type: A
HTTP GEThttp://int.dpool.sina.com.cn/iplookup/iplookup.php
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://121.43.69.253/1.ico
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://softonline.b0.upaiyun.com/SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.rar
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://wdl1.cache.wps.cn/wps/download/OfficeAssist.0405.80.1119.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://mmliao.jianting.net/mmliao/MM-liao8302.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://www.fengzhangyu.com/MDg0NmQ3ODdhY2U5MmFhOGM5Nzk2YzUwMDUxMjY1NzU1OGRhNTYxOC5leGU=/40.html
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://d.qq66699.com/yx/dts/sqft/905848/yx_dts.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.nx5.com/apk/20141222/setup_95165069.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.baofeng.com/BFVCenter/BF-BFVCenter[[AB027]].exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://meipin.souxuncn.com/meipin/affairs/-2000_1_mp.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://down.woka123.cn/qudao/hk/hkyl_yls_hk2014_200lm.exe
User-Agent: NSIS_Inetc (Mozilla)
Flows TCP192.168.1.1:1031 ➝ 180.149.136.250:80
Flows TCP192.168.1.1:1032 ➝ 121.43.69.253:80
Flows TCP192.168.1.1:1033 ➝ 72.8.188.94:80
Flows TCP192.168.1.1:1034 ➝ 218.60.107.12:80
Flows TCP192.168.1.1:1035 ➝ 122.227.42.227:80
Flows TCP192.168.1.1:1036 ➝ 223.6.254.23:80
Flows TCP192.168.1.1:1037 ➝ 183.56.172.47:80
Flows TCP192.168.1.1:1038 ➝ 121.10.117.139:80
Flows TCP192.168.1.1:1039 ➝ 119.188.72.240:80
Flows TCP192.168.1.1:1040 ➝ 183.136.235.13:80
Flows TCP192.168.1.1:1041 ➝ 106.120.181.50:80
Flows TCP192.168.1.1:1042 ➝ 72.8.188.94:443
Flows TCP192.168.1.1:1043 ➝ 72.8.188.94:443

Raw Pcap
0x00000000 (00000)   47455420 2f69706c 6f6f6b75 702f6970   GET /iplookup/ip
0x00000010 (00016)   6c6f6f6b 75702e70 68702048 5454502f   lookup.php HTTP/
0x00000020 (00032)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000030 (00048)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000040 (00064)   696c6c61 290d0a48 6f73743a 20696e74   illa)..Host: int
0x00000050 (00080)   2e64706f 6f6c2e73 696e612e 636f6d2e   .dpool.sina.com.
0x00000060 (00096)   636e0d0a 436f6e6e 65637469 6f6e3a20   cn..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f312e69 636f2048 5454502f   GET /1.ico HTTP/
0x00000010 (00016)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000020 (00032)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000030 (00048)   696c6c61 290d0a48 6f73743a 20313231   illa)..Host: 121
0x00000040 (00064)   2e34332e 36392e32 35330d0a 436f6e6e   .43.69.253..Conn
0x00000050 (00080)   65637469 6f6e3a20 4b656570 2d416c69   ection: Keep-Ali
0x00000060 (00096)   76650d0a 43616368 652d436f 6e74726f   ve..Cache-Contro
0x00000070 (00112)   6c3a206e 6f2d6361 6368650d 0a0d0a68   l: no-cache....h
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f536f48 7556415f 342e332e   GET /SoHuVA_4.3.
0x00000010 (00016)   302e312d 63323034 39303030 30332d6e   0.1-c204900003-n
0x00000020 (00032)   672d6e74 692d732d 782e7261 72204854   g-nti-s-x.rar HT
0x00000030 (00048)   54502f31 2e310d0a 55736572 2d416765   TP/1.1..User-Age
0x00000040 (00064)   6e743a20 4e534953 5f496e65 74632028   nt: NSIS_Inetc (
0x00000050 (00080)   4d6f7a69 6c6c6129 0d0a486f 73743a20   Mozilla)..Host: 
0x00000060 (00096)   736f6674 6f6e6c69 6e652e62 302e7570   softonline.b0.up
0x00000070 (00112)   61697975 6e2e636f 6d0d0a43 6f6e6e65   aiyun.com..Conne
0x00000080 (00128)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000090 (00144)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x000000a0 (00160)   3a206e6f 2d636163 68650d0a 0d0a       : no-cache....

0x00000000 (00000)   47455420 2f777073 2f646f77 6e6c6f61   GET /wps/downloa
0x00000010 (00016)   642f4f66 66696365 41737369 73742e30   d/OfficeAssist.0
0x00000020 (00032)   3430352e 38302e31 3131392e 65786520   405.80.1119.exe 
0x00000030 (00048)   48545450 2f312e31 0d0a5573 65722d41   HTTP/1.1..User-A
0x00000040 (00064)   67656e74 3a204e53 49535f49 6e657463   gent: NSIS_Inetc
0x00000050 (00080)   20284d6f 7a696c6c 61290d0a 486f7374    (Mozilla)..Host
0x00000060 (00096)   3a207764 6c312e63 61636865 2e777073   : wdl1.cache.wps
0x00000070 (00112)   2e636e0d 0a436f6e 6e656374 696f6e3a   .cn..Connection:
0x00000080 (00128)   204b6565 702d416c 6976650d 0a436163    Keep-Alive..Cac
0x00000090 (00144)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 68650d0a 0d0a       ache....he....

0x00000000 (00000)   47455420 2f6d6d6c 69616f2f 4d4d2d6c   GET /mmliao/MM-l
0x00000010 (00016)   69616f38 3330322e 65786520 48545450   iao8302.exe HTTP
0x00000020 (00032)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000030 (00048)   3a204e53 49535f49 6e657463 20284d6f   : NSIS_Inetc (Mo
0x00000040 (00064)   7a696c6c 61290d0a 486f7374 3a206d6d   zilla)..Host: mm
0x00000050 (00080)   6c69616f 2e6a6961 6e74696e 672e6e65   liao.jianting.ne
0x00000060 (00096)   740d0a43 6f6e6e65 6374696f 6e3a204b   t..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a7472 6f6c3a20 6e6f2d63   he....trol: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 68650d0a 0d0a       ache....he....

0x00000000 (00000)   47455420 2f4d4467 304e6d51 334f4464   GET /MDg0NmQ3ODd
0x00000010 (00016)   68593255 354d6d46 684f474d 354e7a6b   hY2U5MmFhOGM5Nzk
0x00000020 (00032)   32597a55 774d4455 784d6a59 314e7a55   2YzUwMDUxMjY1NzU
0x00000030 (00048)   314f4752 684e5459 784f4335 6c654755   1OGRhNTYxOC5leGU
0x00000040 (00064)   3d2f3430 2e68746d 6c204854 54502f31   =/40.html HTTP/1
0x00000050 (00080)   2e310d0a 55736572 2d416765 6e743a20   .1..User-Agent: 
0x00000060 (00096)   4e534953 5f496e65 74632028 4d6f7a69   NSIS_Inetc (Mozi
0x00000070 (00112)   6c6c6129 0d0a486f 73743a20 7777772e   lla)..Host: www.
0x00000080 (00128)   66656e67 7a68616e 6779752e 636f6d0d   fengzhangyu.com.
0x00000090 (00144)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x000000a0 (00160)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x000000b0 (00176)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000c0 (00192)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f79782f 6474732f 73716674   GET /yx/dts/sqft
0x00000010 (00016)   2f393035 3834382f 79785f64 74732e65   /905848/yx_dts.e
0x00000020 (00032)   78652048 5454502f 312e310d 0a557365   xe HTTP/1.1..Use
0x00000030 (00048)   722d4167 656e743a 204e5349 535f496e   r-Agent: NSIS_In
0x00000040 (00064)   65746320 284d6f7a 696c6c61 290d0a48   etc (Mozilla)..H
0x00000050 (00080)   6f73743a 20642e71 71363636 39392e63   ost: d.qq66699.c
0x00000060 (00096)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a74 696f6e3a 204b6565   che....tion: Kee
0x000000a0 (00160)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x000000b0 (00176)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000c0 (00192)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f61706b 2f323031 34313232   GET /apk/2014122
0x00000010 (00016)   322f7365 7475705f 39353136 35303639   2/setup_95165069
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a55   .exe HTTP/1.1..U
0x00000030 (00048)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000040 (00064)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000050 (00080)   0a486f73 743a2064 6c2e6e78 352e636f   .Host: dl.nx5.co
0x00000060 (00096)   6d0d0a43 6f6e6e65 6374696f 6e3a204b   m..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a0a74 696f6e3a 204b6565   he.....tion: Kee
0x000000a0 (00160)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x000000b0 (00176)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000c0 (00192)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f424656 43656e74 65722f42   GET /BFVCenter/B
0x00000010 (00016)   462d4246 5643656e 7465725b 5b414230   F-BFVCenter[[AB0
0x00000020 (00032)   32375d5d 2e657865 20485454 502f312e   27]].exe HTTP/1.
0x00000030 (00048)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000040 (00064)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000050 (00080)   6c61290d 0a486f73 743a2064 6c2e6261   la)..Host: dl.ba
0x00000060 (00096)   6f66656e 672e636f 6d0d0a43 6f6e6e65   ofeng.com..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a6565   : no-cache....ee
0x000000a0 (00160)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x000000b0 (00176)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000c0 (00192)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f6d6569 70696e2f 61666661   GET /meipin/affa
0x00000010 (00016)   6972732f 2d323030 305f315f 6d702e65   irs/-2000_1_mp.e
0x00000020 (00032)   78652048 5454502f 312e310d 0a557365   xe HTTP/1.1..Use
0x00000030 (00048)   722d4167 656e743a 204e5349 535f496e   r-Agent: NSIS_In
0x00000040 (00064)   65746320 284d6f7a 696c6c61 290d0a48   etc (Mozilla)..H
0x00000050 (00080)   6f73743a 206d6569 70696e2e 736f7578   ost: meipin.soux
0x00000060 (00096)   756e636e 2e636f6d 0d0a436f 6e6e6563   uncn.com..Connec
0x00000070 (00112)   74696f6e 3a204b65 65702d41 6c697665   tion: Keep-Alive
0x00000080 (00128)   0d0a4361 6368652d 436f6e74 726f6c3a   ..Cache-Control:
0x00000090 (00144)   206e6f2d 63616368 650d0a0d 0a0a6565    no-cache.....ee
0x000000a0 (00160)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x000000b0 (00176)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000c0 (00192)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f717564 616f2f68 6b2f686b   GET /qudao/hk/hk
0x00000010 (00016)   796c5f79 6c735f68 6b323031 345f3230   yl_yls_hk2014_20
0x00000020 (00032)   306c6d2e 65786520 48545450 2f312e31   0lm.exe HTTP/1.1
0x00000030 (00048)   0d0a5573 65722d41 67656e74 3a204e53   ..User-Agent: NS
0x00000040 (00064)   49535f49 6e657463 20284d6f 7a696c6c   IS_Inetc (Mozill
0x00000050 (00080)   61290d0a 486f7374 3a20646f 776e2e77   a)..Host: down.w
0x00000060 (00096)   6f6b6131 32332e63 6e0d0a43 6f6e6e65   oka123.cn..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a6565   : no-cache....ee
0x000000a0 (00160)   702d416c 6976650d                     p-Alive.

0x00000000 (00000)   804c0103                              .L..

0x00000000 (00000)   802b01                                .+.


Strings
 " "
E
.
080404e4
1.0.0
BEARPC
CompanyName
FileDescription
FileVersion
,/KPip
LegalCopyright
msctls_progress32
MS Shell Dlg
/ P6pL
/-P?pR
ProductName
StringFileInfo
SysListView32
Translation
VarFileInfo
VS_VERSION_INFO
www.bearpc.net
^&.	\[
>{/&}#
!.)?*-
.:,@{>[
*?|<>/":
\=@_~-
+&{?)(
	\:?"	
													
04J4zR
0+5fFF
0(6EP(o7U
0='6Wm,b
*0?8	w
^.;099
[0<,DS*
'[0DxMo
0eTBJ 
0|G3F==
0{G7dS4
0Hfh:&4F
/0hI-P
	0hT^t }-Y
$0'i}T
0Jt$hV=.
0K(~0x;
.. 0L.Bef
0L#bv$n
=[0Lp{
0M~/~F
0\O:p%
0Qan"4
0q.)f7
0R;7c*
]\$0s)
0:,si:$ g
0,TJx6
0VgfUC
0wkIBQ1
0w[RjK}O
0wRT| vJ
0X_0-4
$0|yX?
$}]0ZP
11111111111
[_*17[/
1A3F?G
'1A(d*a
1D20h]
=(1d5_
1D9:=.
1D]@Wa
1&		ec
?&1_j#
\]1K1l
1`LwH2@K
1PmpHE?
1Qa]R:
 1QE&g
1(T!R1J
1:U@E:
1;Ut5H
1VnB3}
21#omz
2223WopprsEEJKKKMLL
2|53`6
{25<P0|
2B]+%Y
2^HAr83
)=2< hs>
[2I0Xk
2mA13y
*2OCQP
2OE}4 
-"2oq}N
2pcHqF
,/^2(q
2q,QNxt%m
~2qszY
2=UyA:
2vk5_*
2`wJ|ng
2$wkF\
!2,wzzv
2XEh2'
2Y7|Va
}2yt6)
\.2yW|8
3333330
|33*I2> 
3<4?F<
358K&'#
3"]:/6y@mKG
371;)hJ
!,39Tz	
}|*3[a}
3^%}@D
3d*d{x
&3dnxCI:y1
3feN[w
@[/ 3H
[3h?5(b
;3^IK[
+~3&!L"1
=~<~3m
*3o{wN
3T%"0]
3T>|?HN
3T#>-\}}M&
3v%KW~&
3 +$,Vn 
|3=w9D_
3W{}EI
3?'$:X
41JXoQ=
48{@d\
4AaU5z
4bRZzq
4cn> j@
}.4dAv.
4	dbG9
4DDFfg0
4e-}Cnk
.!4EjQ
4) EsL
4esW10
#(4:Gp
4`H0vN
"4!H`L
 4.I@vN2{
4mNpoG|
4N*5$3
4N>M5TXE
	4oW-@
'4o<XSt
4S mvu
4Tafkv8
4T`*NO<
4T|O{:6
]4TuhZ'WA
?4u6AYGO
'4,&uk
4VYCCF
4X,NLWXUS668
&4y8j~Qt
-^4'YB
4*_yf-
`?>{![5
5	1)!/
5{5#,4
57FU0h
}5dW%U
5eb0Yo
5F3,2[\
5g;s)m
5hpF ;*
5":&hR
_5|i.OD
5^LXNP
.5ma?BH
5NMb05
"	5_{O
5`owZbE
5P5iVs
5P$U@4
]@\5S6
5SvW1Lo
5.U>f+
5vD}B9
5$@\w,
5[W)3D
5`w$qa
5)>:z<
61/7f@L
`6]1XX 
-< &66
66fff6
6(6\kE
6;)aHP
!6>BM5
6b$/PB,b
/6}~=D9
~6I$W2
.-6i^Y
6k3Wc@
-6kET#\
6k]l>U
6K?	W~.
\^~|6L
%6!Mwc
6M/whW
['6_oK@
6p[[3xER
6'pZvO
/6Q`  >
}6	RzfE'I
$/6/@'s
% /6$S%
6S'.lF^)
`6)sx4FQ
%6TTL5z&
6xZoZS
]6y#zP
^7</&;
 -"\@7
#&,"7)
74LD&l
74's1#c
764;M@d
7b899/
7bM77b
[\-7BMA
[-7f,9^
=7)H5D
7hIg,i
7H,+,s
7@H(Y:%r
7i8w@Cs
@}7J= i
7^KuJ6z
,7lk1srI
7lU9tK
7lVkcd
{7$N0S
7(n'92B
&7%!">-;{oC9
7Poj?:
7prB4M1
7*pv:1
7<)P(VWX
7(Q&<Q
7Qu7xlh6m
7RmBKb)
7S|)$m=
7*$TkK
#/=7$;W
7"-X{(
7XJ#9Y-]
7./|?Z)
;:80Q?
>|8122Bs3
83~jL7
86b(]6N\
8`6g#5
8*9~.C~
8ANoR+
8($Ew"
8fGXj>
8FhW?~"
`)8GA>
8;!GGG
8h#}/B4
8HQ<$Q
8kd&vV
&[8m>m
8NCRCu
8p,bb.I
8Ps4s'
[<,>-8R
8_#$r2
8S{`GE
8`UL~)kP
8;!UN;
8Un#Z2
8*[VEf
8v]Lx=
.8vQ\&
8w#4m@F
8;{WFV
8x7s	m
8x9'j\
8Z&OW7
(8ZvY2r
94")(-
94A%%h.
9,'6IM
9`&^bs
"9{?c~
9+'dZ 
9JC0X>
9L/aZ[
,9M4s:
=9}N<A"2
9P45dp2
9]Q7Xq
9qTs._
@/9S`$
9sH+>J3
!9TVzV
%9V?$')}@
9x^<yHZ
9%#{)Y4F 
\9+z{ 
9{z~EOIN
&-9Zxg 
A{0-{K
A"&0Kw
&a39E:?
;a!3U`P
A=5kRI
;a7_2DAh
a7>Xh-
*A7$Z91
A@9PJw
aA/rSRc
>'$Ab;
A~B~aB
+ACX&c
:a$DE%CML
AdjustTokenPrivileges
ad$t? >
ADVAPI32
ADVAPI32.dll
aE),3h#T
.AF=_MCD%
aF_TOv
'a:g#y!
a<}h85D
A#h]h!
{:a'h=V^
!a>?iF
Aj8[{Oy\
A:J"Dp
aJ@;Gs
A&JiU?!{E
A=#J@;m
a K]	T
A}kXT&
aKZ9k-
A'l]!%F=
Am}7(H
am	8MB
A?n3~;
a:n$fc)Q	
aNH:)b%
aOOx[JJgSCC%QBB
[ A p0
A.PdjK
AppendMenuA
aqpn)4
		|.A:\S
A}s`f##H
#:aSkH
aS^z=-
A-TMr1
~aU+,@
au@29]
aV2][v
a]v7Y>c
AvMv\P
<AWc)Aw4
#Aw Qy
^aX"%*
AxKYE/
`A Xwy)
A?y F;
AZ@=\$}
a#zi8fu
A	znJ*T#
azXp0G=
=""~*}b
b %:_*
]? B;|
+[B<00D
b!2{5'O
{b4fUv
:b 4IB
+B4T2_S
b/74Zi
@]$B8?
B8xpTsui
[B90!:6HcUD
b	'AH+
B@ARU)2
b@bh;Ll
#B*{c"	
BcZGnm
(B^d	'
BDIPGGDBA
b(DxI.G
BeginPaint
bfqsU2
Bg96jh
bgoWb;
}|Bg-[X
_B{hW_
:_>-bI
biLl/Z s
 BiwUp]3
BJ1,w"?
/*bJ=:*D
)bkF)p"
('<b}	k p
$b(]?L
blCMa9
]BlFId
blxOo1
"'^`bn
bn1]K,
Bn]>g!
BN'.x:
"@bo[`
Bo>:g-=
`BP[kw
'Bqik@
bQV1~%
Br=2ue
>BS}z8
bte|:F
btS[9#
BTT=JA
bU\bG>$
B	umRfLd
-B=;]V
bvG&eX
,bvj`d
BvP,Aq2
B(wXVyMQ
bX9<W=}<
B^_X}E
,b([XH
bXHl/m
-b@XzR
#{@By$A
^B<yur
)B@zo)g
BzvQ9)
Bz?W=T3N
BZ"Y	1
.c	15E
,c2t>@
}c3i 8>aX0
c?7Y6'
C`8vv6
C:aa(z
CA^d}8K
<ca@en
CallWindowProcA
cbx0#=
C,~c0 V
}cc F|
C"d:drTOn
	cdF|=)
	cDgdQ
C}dLv#-
C%dX8S
	"=ce9,
)cEO'Bg
CeQRnI
C.e|RG
Cfg"X#P
cf%JFb
cgs6@#
C==G*Z[
CharNextA
CharPrevA
CheckDlgButton
cH/$ n
;chS>|
cify3=8U
CJ_ ;b
cJ)d4n
CjF8jI	
C#K(ib
*Ck!k{:G
CkzV-/
^cl84$\
CloseClipboard
CloseHandle
C&L.sY8
c~_m'B
'cmR3mI0
.cNW=,
CoCreateInstance
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
CoTaskMemFree
=]CPh}
^#c}q;B
C{>qF4
cQFr8}EQ
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
?Cs_Mj
@CSvKf
:C.SW+i
>#ct~$"3
C:T{6"
CuATQ 
cvbK>0
>c_+VJ
cW0yE4#
|cwgyv
CxF ?0
c xiX|
C+xZ.Dj
cz7<s^
cZgABX
Cz.+p8
CZx"WF
czyjJ:l
... %d%%
@/d'^>
+**%	D
D$0+D$(P
d0\UCsS&
=~D4aI
D4vTc.T
D7ab&$
,D7\[Z
d8*H;m
D8Ice_
D9dYWf
d9eh|\
D	^9|R
[(d~)a
Dallhk>
@.data
	}#dCg
DDD5Vn
$DDDDDDDDVn
DDDwvk
!ddFf_
D$(+D$ SSP
D,}}dx
d])E-&
de0{B[@
.DEFAULT\Control Panel\International
DefWindowProcA
D)Ej*Ey)
DeleteFileA
DeleteObject
DestroyWindow
DE-wI%
DGAL,35
D)#>GN
dgV<>g
]d;h 8fO#
D*%H IkkN
Di@=/;
DialogBoxParamA
d$i;D1u
di#k3+
DispatchMessageA
djU!Knp
dk4aEp
dk};"n
~d()kR
<DK{*]X
D%^l0V
dL1# ,
dl?*N%
dL.ty	
D@`m2s
Dm,Da'?H
dMY`!P
&dN\Wj+_i=Y
doA@$@
do)i@H
}.DOp0 i
?dp<'@
D$$Ph,
d._puM
D/qdl/d
;`dqHb
DQiD-M
Dqy08N
DrawTextA
d[|r=wm.
Ds7',{a
D$(SPS
DtGzGt
D%TjcE
DtR\@x%
DtT!`s
/dU	5(84
d u/b_#
D_:;%W
DW703G
`dWpPn
'#Dw;x
~|'DxiO
/dx],S
d,&*#y
dyAzRp
Dy%SYg
, }DYzyH|
d*zL(:
D!~Zt@$
''<_e+
@$%e	|
	e0zu7^<
e?1L:@
e-{2Tr
E4)U{	
E58f3	
e5c{A%
E5<Hdn
?[e&7[6R
e$'&7d
E|"8/e
|e>--9;Er
eAY#FF
EB	byM
ebEdQp
!EBHk:
e}dVnX
e"e7Zf
(E`fCy'
@Ef"hW
eg]6,)
EgH*R>G
E<H).n
eiklin
e.j1Zr
Ej%8%'
"elAz[$
em7q9ub[
EmgYXe
EmptyClipboard
e/m[Rs
EnableMenuItem
EnableWindow
EndDialog
EndPaint
#(eOt<
EOY'Bvj
EpMA\N
E.p!s+
_e 'Q=
>{Eqf$VD
eqmMCv
eqz-%g
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
"ErU7^
;E>[s]
eS\@5{
)etpmn_A
E%u16n
e u!4E
}[EUR$
e.UXbd
e;V3XB
E@V+d"2
E:V^eq
[e$v&ia
#E$w?d
ewJLr_a
E!wQ)A
_eXb9L
ExitProcess
ExitWindowsEx
}Ex?mI
ExmXq-A
ExpandEnvironmentStringsA
~EY%d6
#Eyf*}
e	YF6*
)ey]N>
}E['yn
EyZ~ydo,
EzeB-b
eZ(f!l
EZjBTy
E,`Z=k
EZYXH_+
f,- 1,
F2%9"f
f2BJs'#Rg
f42qKR
'?"f,6
.`f8\5
F)9nb>
f_`/a%
F`A$js
FaPG;`
F\<a#x
'f>B6>
FBxm@e
FCm`7#
Fdhw-x
F}&,e>
#-F)E%
=fEJXs
f#e^oD{m]1d@
fFG~*1
f~-g1e\@
F.g>@^Y
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
	F;\k?
	Fkpld+
fKZO)r
`flsEmz
fM'<4Y
fn7jYSk
fn7lDz
fNOL@1
!FNS8s
#FO-DY
 ?FOW;8Gn
fP\E'@
F"pfLW
F+p*GJ
$fP\lB
fp`WN{3~
,`>fpXX8
~`F`!]	@q 
!Fq-_e
F/qXN0
FrCy)~|w
FreeLibrary
,fR~Nrn
Fsc8R#
+F^%so
Fs	q,'&P
FsW5Uv#_
%fT=7U
:fTo**[
F?v]P8
fx!<%{
fx=I?0T<Oik
FxRbu|!
FY>_.=
;f!>Y5
fyHcLf
F'YYOG
Fz6HE]j
fZzl&a
|)G))!
)*-}G@
--,G00[
g0T!I~
G2:C_)2
(g;4=DDg
g[^4;h
gb,0_t`1\
gb32Q^
(+^GBQS	
g	BX4::<?
G+~by`
gc(&Su
"GcWM{%
GDI32.dll
!GD{Oy
gd#;Y1
gD)Y=&gJ
.GE'cI
ged<VU
G]Elyd5
^G+E&T
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
g#e{{x
GF[7nx,
(g?@<fh
}GFqg@
GFY4N;3b
[:gg<}
@~g!	G|
G\g^M!
(gGPiz
gH7X"%&
]?ghPX
G~I} *
GI{&l3
{gIv"B
=#(;Gj
.G^JSq:
G;K5@;
Gk`8f1
}{Gkm|
#||_Gl
Gl6;[M
g%L+}D
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
_gM'_+
gME9Zr
g%^n%b
"gOirP
gO+l"nD\xT|^
++g	p4
)`Gp7!
Gp{jjj
gqQvrApn
%gq"Vw
GrXCs<
"g}TD}1
g#t|[K
GtNC>n
@gt_Ux
Gu54j]
g`"UkL
gu&(N]
G	 ?  v
^_GV<d
~g*v<q
@G{;]w
gWcDjy@$?
:'GWdO
Gw Iu{
gW\X`!
gW%Ybr`
G;x/`8
Gx cbnua
GxsrfWA
GzT1Fz_k
gzT!	I
`(h^` 
;.,~\H
{{{{{{{{{{{{{{{{{{{{{{{{{{]>=?H
-/<h0e
H0FvP}X
h0I8{ 
H|0PLc
\h|1Hd
h22,9K
h_2!6 
h2av%+
H::2H;;1H::6H::+G:: G99
h2Ic^o
H2wE.o
h3&iE`
H6 r1/
^h79T5
:H8m,1
%h8&n1
H9gEDr
HAzh^t
`hb}P(
@h*C&/~\
h!`cA@
H^*cN^
@hC	#TC
H?dB1Y
HDPu$8
HE*hal
{hffyji
`-hG^;=
hg8HIG
H*Gb3/N@O$1#(
HG]bQ\1XbH:
hGJ\W&
;HGM?4
Hg}M;l
..hhg6b
	H;ibG
`:|Hir=e"
hj1}dx
 HJ;N=
HKl*Qc{.9
hks`jB
H:?+L0
HldY:Y
`HLXHj
hm_?8d-
h-m['uV\
<HMv`D-
HnO%}[
H;n!Z$
}H"+of
HOLVq<_t
Hpb	vI
HQ?8jE#
hR~g^1
h?sllte6
H_]s'n
H^SOKf
H<tf/<
hTL)} bzr@$
http://nsis.sf.net/NSIS_Error
^HU18>
hU6zR[
h''U]o
HURE<Zz
h v2>V
*hV32t
^h~	[VF
)HV.Hx
H v?s	
H"!X3D
H}Xc;;
HXMwW$
)hXPQ`
i0Bf/M
+-	i2{|
i2_lCRM
I2m~)O!l
I3;Ep}
i&5sHk
I78Gg^
I/7;fD
i8v3T1
I!9BSI
<i!/a@
(ia1^!Y
I	=*aR
#	icK-i
@	<icP0
iddPN~
I+dN"{
i>Do0)
I<E8K<
iEY(El
i&gjv%"
 =iH5o
IHDR=[
iHtxMY
IIbVU=
I+]~J;
I(j?#C!"
/i"j&T(
I.k20x
il-aJ2
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
incomplete download and damaged media. Contact the
InHn\-
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu`
InvalidateRect
$iNz{Lo>]
/:iOO;zNY
i	p3*Bg
iP'I9GY
\$ipj(u7
i@\QhL
iQ\Qz-.
I-QyxP
:i[qZ	
iRichu
IRYSoiK>
IsWindow
IsWindowEnabled
IsWindowVisible
.[I[Tc
iTcS7o
`It>&D
%i.W6[I
i`)W8,$
Iw NCB
iwVT[zck
-I?"x$
]|'_&[Iyz
IZ>4|p
@;$/j&
J0c.1G}
j%0;(o
)~ j?1
J1k	{#
J20(Fr#)/9N
j/2VgX
j3DNx)"I
j4!Pn'
j4WwiRY
j6}<m\
J6 ]S~
|J81>Fi
J(8|md
j8^QWnj
j8$-[V
J9cKkf
J?9]=y
>Ja6U&
J*aLMGw
JAqLa5]
j/'Ay@
jB/c~v/.=
J<<BJ<<@I;;EI;;<H::4F99,G::
J$B(UP
jc`r5E@
jdC,A@
.'jE{P,
J$f"Q	J
J$-GndW
%jg}T/sg9
Jg(ub|;
J`hBpkW
j\hI"O
^ji5[r
JIo`N@~7
;J IR=r:}
\JJX[IIdYHHPUEE&QBB
@J-	KI
J)%KLdr7
+JL\Sg
J%%mg.9
J>MiQAg
J+*mJC`
).]j+N
@JnKljf
jnm{YN
j	@o*0
|j	O3	
J`op26
=;"JPk
jpQNYIz,
jQC9,^
J<<QJ<<MK==RJ<<KH::=G99'E88
j,@rE.f
J-/r(R
JSB~ ]
Jsm &A
jSRC92n
jt2S`4
J#UU,2
jv=b5{ (
j-V&D!
JVSm-+
JW	^Dg
j|}@X@
jXbELkL[
-jX~jv
jxn|$6
jyKSSP
	|~^j-Z<
Jz31D1p
K/\<}@
(-k15b
K3Ep@$I
K426E~
K7e_!k
%@>k.8`N
K[9R9{
Ka}'`o
KAu{S5p
kb*AG0
%kbr`HC
k+D-P:1@
kE=!BKQ
KejJ!ww
KERNEL32
KERNEL32.dll
<Kf:ei
kH;18a
&KHa8}
K#hl$q
khN]fb
*~kHy54
@k	j2l'
 kJE7g&
kjH*dF
k|JKd-
kKp6ue
K!< ms
kNHdJx
KO{{{,4
kQ*;'7;/?/:
k{_Q^G5
KraW'A
KRn"oZIT
|KrVH>
KS|i;(`
k;:-T;
k #Tk~-n
kT}uq)
Ku>6)si
kuAFXu
Ku>:Z!}~
>k._v{
?/'	k&v%
#K;*wA
kwCtql3
kWWuYGGSVEE9sbb
KX9P[,]
K X=eZ1pm
k\Xu{\
kx#uU-~
k^Y5SH
kY+7e^4fv
kYJ.:o
k|{}yk-fTq
*{k)yN
kyU3KFW
kz1:s@
[kzUA~!e2
l051a0%
l0dQ$z
@L,0OV
l!*1-7
L1%dlx3
`$l^2F
L2W,@3
~~L4OJ
l4Pi1"
l5wgvO
L.+6+[
l7GO=@6
|L7<o!
L8{ Mb
*?/laN;f
,	l[/}b
<%lB1u
+>lbc_/
l="(bK
?l(C_t_
-lC^=U@a&X
L/dGLa
[LdO+o8
ldQs><
LdUwM{c
L==/E88
%|L e`z7
"&lF1{
lf8lfd
lg`5iE
LgIi"`
l-:\Gv
L\hvra
%lInf/
L[JFD@'
lKCYZR-
L==^K==]K==aJ<<LH::+A44
L{-Kv`
L	'l@?
`l#lAr
LL\F-J
]LLNQBB
"Lm33l
\ln@cg
;L<no&
l>NW2F
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
LookupPrivilegeValueA
LO~|T4
-@lp`$
Lp~U}X
L%?-q]c\
lrd/%&
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
LT>U&u)
L<uIZi
lUjl,r
\=L<vd
!LVu' 
LWr)@F
?@lX=0
<	LY;C
=LZIbLL
~\m{(.
<M,[*{}
{m3(&hnA
M;3l"R
m3ta(<
%`\M/5
M6e:V	Y
m6g|a@
m7 +	@
;m7/7.Z
M7ds+Kb
~m[7QyI
m8T;Bz
"}?m9&
^m`99l()
m!9+C-
m9f:9 
=M[9v+
M9_v~O
%?mA!9r1
:MA x6
m~>$b"#
Mb88ai
m}C[%[
M`c	z\
'm,DsZ
,m``	,E
M>^^E5
m'Eg"(;
Megi3j
mEhsw:<w
MessageBoxIndirectA
	-mF`"
mF#DM 
M)G%]a
Mg'MTf
.MH,0t
m*HdNf
MH#~&I
MHQ#uu 
MH$R,c
\Microsoft\Internet Explorer\Quick Launch
MIHJK$'*)&
MI[sY2
mJfFa;
mjk;.	
m?j T8
mkIe#XO
MKq}SO
Ml	Oh*y
-M\\mii
MMM1MA
M@muI\N
M:`n'<
M[n5ZC
Mng!Wr
m-O\7m
More information at:
MoveFileA
MoveFileExA
=/m<)p5
Mp=[)BB*
&mPRR%
{M?+pZ
	M#]QC
mRYI=S
ms5TM)
Msh[)r
%Ms&rVX
mt2 qz7
MtCR//
;mu}@/
MulDiv
MultiByteToWideChar
:M|UNL
MUR`_V
\mw>|}
M}"WE<
]MW[n^
<M?:wV
"=MXJ)
MY11OUHV
M\Yo9w
=![myWbi'
mz7=1,V
mZ~!cv3
"m\ZF*
mzgtu?"
##>	~n
+]/#N{^
N0wxK5
N1|fH]
n/1	+YZ	d!
/n)3/g
",n3-/okG6
'N421waQ
N@#4kY@
N5GTdVa
N*6D|j
:n7FU3
+N7-gA
%N995)?
nbE|	)wRV
\;n{$C9
<NC-.B
NcY$OK
,@NCZ&
.ndata
{NEncQrE
NF3V.~2
'N-?FYA
nG$AMdM
nhb`bhknn
|n~hIJ
:>Nh_v
ni89]o
niHEZZ
ni[uZS
N/Jb%w
nj%V"Q.>[
NLan`w]
NLm_w<
(nLwxq
<NmnUW
	-nM_P
nn9~u3
	,nn_n
nn\r7j+
nnxk\7
N^_o?h
NOhSvd
NPi%Tg
	"NQ+4
;nQ{Dxb
*N>q<IMC
+NqNe}
NqXK}hlRs
@*n=:R
NR 4L4
ns7l)$
NSIS Error
~nsu.tmp
N%T>B#U
n=~TGc>r9
Nu0AN.\
NU]3UB
n[U4]'S
NullsoftInst
NullsoftInst1p
NulluN	E
NV@n7{y
nvO%R_
..nW'z
nx &K=V
[=Nykh
nYYUSCC*RBB
n~z5+v
#NZak]
n$ZZ^=so%
o-[`!&
O0v>g>
O13m*]+n
o1PU(M6
,o1SCw
/o-290
O2$c<n"
o2`eN 
@O,/4p
o5=iE|
`o!5:Y
o^_6;0
 o6R.L
o@6U'WN
(oA(12K
:#]oA8N&J
!:O\>AHX] 
OB7!.b
OB)}Z]
oE[Ui(
	\\\OFFF
o%Gkh9h
o>HF	 2@
\o	hpW
o"hR|\
@oHU%g
o:ICc	
OJC_#j
o&J$ZL
}o*k#4
ole32.dll
OleInitialize
OleUninitialize
o-LU3O
o @:/M
O)}MVm1
oM`~vV
"$(On6D
Onhb+t
+ONS`I
[O%%OOOPUd
)oO*pZ
o:oYK39`s
Op8^GFlAR
)op!]AB
"opBN8
OpenClipboard
OpenProcessToken
!oq:(I
O??qL>>lL==VH;;&A44
>o-q>u3s_}
$os0@:
os3lhXb
(OSEUP
osx-MF
OTe/i?
OVM~s#
"=OV[p%
{OWNcw
oy8/fH"
oY^jeV
oy,	mXQ
oZdY`D6
Oz[,Ii
oZ|m{'
'p\/{-`
+_P#'$
p/[0DaOl
p)2rhq]
p3mBxa
(P3Qnns
_,+-p>63R
P98Cp?
*P"9a~
P9[(b;e
:\=P?a7
PaBuFH
PaerP&
p?;AKyW
&P~.aSn
(P	C1A
pc)pp!
<Pc!Q&=_
p= c.u%
p]e;7;
(p%E98
 pEaJ^
PeekMessageA
PE':xA
P*FrohY*n'0
p!|frW
Pg2fH(
PgTg4x
P:\&hB
pi&p4o
pIqXvqd
PiudnJ
pJ5fMW
pJ#Ql,
#P$k`!
Pk6;.I
pKoyp}
pLbTz>f
'P~lJ^w.
\*p!)lM
p[LxJs
<p;"m.P
PMpL2I
pOhGV`
PostQuitMessage
(!pp9q
PPPPPP
PPSg,>;pM
p,Qb{$
PQbvIl=
 P@qm/
P!qoW{
PQ.%>U
)PRC=8!
prCA9e
}Pr}Ir<O
P@@sH;;CE88
psMY~N(
]pts^B
p:tYHjFp
P@tY<L=x%!pD
pV%`B-
P!VI@D
PW-:jN
pw-u`h
/=P)|w_ w5JM
~p!<Xk
PXq*_TH
PxtfR\5
	pYAB	Sk;h
Pz-)j#
.pzN4z4
	PZyD{
#%q& (
Q0SmD(
Q0u	#I4%j&
q0v#!k.
<{Q&>1
Q/|1R0~
|Q)3*G
q\3u0}[
Q}]:4%
~q4BT4{
Q\4U:`o
~Q]56t
."q5Dp
Q.5J})
Q\`>*)6)
q<7XLU
q>"A;t
-<>_QB)
\"QBRG
qDCHMO0/.-67
QDH/LsG
qDuqGf
qe6.}$<
,QeFQi
qEopt	
^qfkq[
{qG#(A
qgJu	D
}qH&j?
*QI=|$
qimSP-)
qIr?0Y,m
qj*UMf
:Qk0>>
qk_!4G
@$qki?
QL!AzYq
q!]Ledm
q>LGkOt
Q<M2ps
	qM3PU
Q),M}~E
q$MN	)
QmOZ#b,
,qm!TD
 !Qn.o
QoJ&kd
 Q O(o3
*Qoskm
QQ0,]pf
qt/)m)zuI
QT*qyB
QTw#}{X
%^qTzq
QU}u M
q{==vD
q,vJw}
qVSwnR
@qvUy@
#q]w]/
q'[>W^$
qWj9xH/{k42
QXCx9]
q*X@K'
QXK}]4`
q;xlnt-
QXSg6=l
qz~@4I3e
*(R :#
r>	0Zh
[R1h\%
r3GOqR"
R3:ZS|
r,69xI
r&6@Da
R_793LN
(r7+BU)
R[?7oEgK
r7-Q2:
!)_R8*	Jm
$!R+aTC
)RbHo*-j
R'b;IFO
r:bR(){m
R;C~79
`.rdata
]rD+LE
rd}NYT
ReadFile
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RemoveDirectoryA
[Rename]
reP,n	
r<@[Ex
[@=Rg5
%RgjjYPUZUVj
@rg~vd
r:	g%{W
rGye&X {
[{\rH7H
rHCm,7
r~H+#K
}__r_i
RichEd20
RichEd32
RichEdit
RichEdit20A
rIU8&L
rJw-:=
rK^lKQ3
>RlbE4
/rm2gZ
R] m>f<Z
++}Rn%)
	R):nDD!
RnY*>_
rO>{	v8
R	P=@%
>RpH<So~
R@p|(x
RQ	(db
rQDfA~
^rqyGS
^rreHD
r#s3aM
rtAN#zS
;rtQ5^f
RTwwTuw
'Rvp3 
!R]wf#
rX;):=
Rxs9=d
r^YVqk^k#
R[z!3aw
~{/S&,
!S0%!$
S|15$|$
=s+,4E
^S4?ey
S58$"e78]4~
S:6K(##"
{$%|S9
S99lD4 ZL
s[9rik*N"
SaeT@\*
sAF*Fh
sAg$c'
s|A<J;6
SB -wj#
_{/S;C
SCC%QBB
SCFMbL6
ScreenToClient
SDJW,F(q
SearchPathA
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
~S?eVP,
SgcL@p
SHAutoComplete
SHBrowseForFolderA
SHELL32.dll
ShellExecuteA
shfffi
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHLWAPI
ShowWindow
S[I+?B"
s)jf[A
s+	k)7
Skj`=o
: >S]L
`*Sl0Vyu
sm.4Im
sMogYb
softuW
Software\Microsoft\Windows\CurrentVersion
SOs~#o
s:q6rYz
SqHRP_o
SQ@`]o
SQSSSPW
sqxfQ<zi
:>sQyf
SSq?=9
SS"R<{6>
stYVcy
su"_Xc
|S&Vah
sv.bQi
SV&("{V
S@vY]m
sWq7XRf
s/xDtg
!SXsr<=
Syl^o)5
SystemParametersInfoA
:^s`Z=
SZ@H@)'g
S`Z&+K
> _?=t
t,0uN~
	t1]vI
T2gg?e
~.%?~t>3GS
t:6{&b
t~#7n"
{[T7XP
T$]A7^
tAsqpq
tB-<aw
Tc2aOb
t,CigVxM
TdN@3=
T`-DPc[
`T_dqp
[$TEEaTI
t{ffffn
&TG#Cc+
tGyegV(:
THGGmt
!This program cannot be run in DOS mode.
Th|#YU
& T!I 
tIDATx
t?]JJB
T	'JU(
tKf!21q
t=KsL~
-%?(t)l9
Tl$'ce
]TNDCP
TNjN%uQ7
t{)Nr2Nv
_^[t	P
tPVZQ}
"t)\QuJ
TrackPopupMenu
t[r)h'
*$tSDFUu
&{:tSH
&#t~|t
^T#U'?at{"<K
tu}@B_
turSs(
^"tVg%
%TWA~	
,T+Wr=Q!
tw@t	,
tX\., 
\TxO,1
	tx=ua
Tz0VkWp
!@^#.U
u*0mPXyp
,u1+9\MN
\u:1oV
u)1pgH
!u^1ZQ
!u24|@q
u4x<_\zXD@*
u]5p0DMd(
#U`6C*
U7>pB>
/u8[s)
;uA8:;
>ua^O:
Ua=suP
Ub]5*	
(U~bQu
_UB_zh4
ucK)@Q
uc>W@y
ucY+8|j
UdV%Ni
U|e\ _
U.E(e8!n
$UegQ8
u/fh0#`F
uFyu#+*85
&ug1Bb
 U.HC&`c
U HTv$
U<}#I@d4u
\Ui K1_h
.?UIKK:~D>
u<IVVy%
UJgfb&i)s
UjKnO<
U_JmKnR
 u{J'MW
uj+:tq
U)J>vi
Um{*AZ#
U#mC=>
u=Nk^Z
+UNroO
|%upW)
upyz<;:977BFI
%UqZP3
urBylj
ur/{ER
urPzPPcn
_ US|:|`
USER32.dll
:UsY#P
UTi/XZ2
_UUm5j7
%u.%u%s%s
UV6S4^-{2
uVPD%b
UW*i9D
-UxFfv.i5
UxQFFX
^Uy,"]
:-uZ,D
U//<zt
)]*v<{
_V0~W=O
v%54TK
v5d-A>
-v5M~0
V[5N#vHZQ
%v=7S]` j
V9%QAw
V9`=Y]
V@=	B9
v-BaBX
///vBBB
VbVmOt
vc9v3;
v]cEBf@
^@VD#a
v)(dcT
v!diP4y
V; E5hC
verifying installer: %d%%
VerQueryValueA
VERSION.dll
vf@"gg
vFrx4(
*@{vG!X
VH 5b}
ViaFZ_
viDXi#
{/v#iX
vj]9@.
*Vj*e	
VjHW)X
Vk\mIe
)V@Ktk
v>l|J|q
vloY`Nx<
VLpMCmx
&vM^>i
;V`mKa
-vnLPQ
V$NPcn
VnVq\Y
vpm.E~
vpUzkf
Vqa>oWC
$Vq|:f
.#VQyU
]\?v[,r]
	*{V(rY
vS3N6T
VT0";c?
Vu|K(%#&'149;><:?
Vu)l.[m
VUTD?^
&VUyQ+
v#Vh;+@
,v#z0c
vZA-03
VZI^)0
V/Zrpk
/W0(g'
w0nwfA6
!W0!?r
W-0Wsv
W138ET
W1(k6J
'w1ukP
`W2RmB1
w$<31=
w4ZcTd
w"5uF;
@w6!HG
w7c'	iE
|<w7ja2
w\>7q<
;W8)X\_M
_`w9HVX"
wA9_wJ
WaEqJt+
wAHmv$
WaitForSingleObject
Wa$UVH
w:B(C[
WBdY)Z
&_WB!F
w/b{J2g
>wc5>R
wD33Vffff
!]WdI2g
W*D?LG
W@e(wu
_wg0E"w
wgf(@i%T
wg"gu<=
W\gO}X;
WHdTZ:U
~Wh<h@
*wH&V8zP_
&$w,%i
Wi~n~K
w#Je0W
|Wl0XWFGhK
-W|l>b
W~ln H
;WL^Ni
|WMD)\
?	w^Ne~
[wNTF.)vc
w~NuFC
Wo4Tmx|
Wo,fwV
wout$<
(;wOuX
WOz$%-
WQel:n
?w_}:qJ}Y
WriteFile
WritePrivateProfileStringA
*wRO=R
wsprintfA
W.SS\7,
wsV^[b
{.WT	.
w#UcV{
W_}uI3
wwwwwwwwwwwwwvfn
W_XQt	
WxR6iu
wy@>GJl|
wzE/#c}D
%!w)Zo
,>+#]x
x@,^@?
]&~|X((
x0>kM$z
x4ws)x
X9SrzyAd
~'xa=/
!x|~:~a$/
-{)Xa]
Xa.#^6
x(Aly_
'\]xA.w
X_B{BA
;xblq%4P
xb,.Pwm
xCbq,~
Xcgzu2
XCH*<G)
}x#cnZ4
_>xD i
XdpA4	W
xe{~,\
[X_>e.
@&_XeS
x+F)+=
/$|[XF
XF&>;!
\x{F[f
$Xf/kc
X,fw[T
Xho'e'|
XH[p!FLC"
;&-Xi 
;x	I8F}
xi+n&H
'Xj"li2
xJ	y>A7x!?
x-[&k	
x+.(kw
XlV#A|^.Y
$!x*~MK
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
xNau6c
(xoB]nE
X`o:Wp[
?x,:p!
Xp^gu?
xPI]1F
XPN."\
&!^XpS
xQ~6Vp
X/q.!\bx
x%Qj<f
-XQsxEu
xQ"X09\
x,RkbC}
Xs>:li=
_Xs @uK
|_XT=[
xt3.+,,,568BBCCCGI
,@xtAT
{\Xts-
xu./5z
xvH6c@
xvneL]
.xVO3%P
XvTVcm
XWB3)b
xxpp,*
]xYj3R(
XYorS0Si
XyxD@'f{
%`:Y~"
'y01kg
Y(1\M'
)Y6D-p
Y6vOvDE
<Y>7{3
Y78#|c
</Y7fx
y8e iO
!#y8TV
y	$925
y_Aan~
YAIJ~H
yb ap9@
'/yb'Hj+
@ycV:^
Y[dcdT
!Y=dQo
^y>@DR
~YeZ^a
yfcxnK
yF=}K{
"yFOI6
y^F@WrF
y g#e=
YG`I^j
\[yG(U
YHHXwff
yIdI#)
y\I Mk
{&YJn,
yjq#oB
~#yk4c
^ykD,Z	T
 Y@KuS
y<L_50
Y*	l DP
YLKQxb
ylv@	pu%
Y!Lwu|
.,ym.@/
Ym	8LY
|YmP^yOwM
ynDtr\L
:;,^yp;|
'Y"po8
^Y=QDG
y-R {\=
Y:_Ra"
,YrgWW
Yr*OQkF(
yS3XB%B
y`=td:
Yu5	kD
Yutf/9
yVFCHz
YvHcUH
YVRwIc{OC
Y$~vy>
Y	$w@3
-Y(wDW.
ywO[5j
ywWyFk
yX	A}W(,Y^
	<YxU$
yyHaOO
Y&z&Pf
 YZq:n
|]&*%z"
:'\$,z
z0*~$$
z0k{8hMPpa
z|:0*QP'
:z1l-	
Z1QY"-
Z1*Z7-
`Z2q9+!P^
z;3/{&
Z/ #3"
><Z'6'$
z6B7^U
Z`6xb'j
Z8g0A-(
z9>awW7m
`z9$P<
Z~9@	p
>Z>b{_
Z(Be^HD
zbLKBG
zBptym
ZCf2IX5N
zCoNuJ<F
zC$Rk\
zcVI-Q
zDB>MvH
\ZdhA9IQb
%Zd_nQ
ZDVo@w
zDX)d-
Z|e}SyaX
Z~f+'1
z@f;+qP#
z~~G!A
z<ga#K
:z!gD]0V
ZII?XGGKXGG?TDD0SDD
(zikk#;e
zINK?O
-z#i'nO
|ZJ)|.
+(ZJ@)
Z:[,jAb.
[ZJwz1P
Z|*`JZx
@zKC<iO
zk/K<f
ZL+\b-!
z*LVuy
z,MoR_
Z] +\n
	Z"]nJ
ZnZ,Lx@
ZonkmV
ZOV#g^I
Z>&O")X
z?P== 
_ZP6n~l
zpY=s{
Z*<qjN
`ZQJ?Wm[V;
zqW]u5
zQ)@xi
zR:XOes< '
>zU;3aT
&z^UKr:
zu_LzVs
 *zV_2-T
Z@/vLz
ZwaIzI*
z_WBnk
)ZWloG
zWn5HZ
:(z}WY
z;xohOJq
~z!Xt6C
z|\ZHG