Analysis Date2015-01-21 02:14:50
MD51658041c9857dea2d125c7df6815e9fb
SHA1188e65c3fc08de642740bddc69aeb085c97f42ed

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 092e164daa50385128d3c5b319373035 sha1: 2eb99403e1719d12eac2774ec4022c70b5c9c3a3 size: 23552
Section.rdata md5: 4e7f519777030dd2f0ea0d2092babed3 sha1: fb84d751c3b62a4a520b71ee2c2702ca14591d38 size: 4608
Section.data md5: f6d93c048bf148a2daee8a6b0505e38b sha1: 83ca6a92e89470b5ead78e6d4da29e5437addf6d size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: e54fb9d10079d85f58ecde9f0fc36889 sha1: 91604252ffd51bf2bae4ad423b4319fe03edee06 size: 111616
Timestamp2009-06-18 21:33:23
PackerNullsoft PiMP Stub -> SFX
PEhash0c79b59ef84bbc307b8091012ce81e0ce6335da0
IMPhash7fa974366048f9c551ef45714595665e
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)TR/Dldr.Chindo.200012
AVBullGuardno_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftno_virus
AVEset (nod32)NSIS/TrojanDownloader.Chindo.E
AVFortinetW32/Chindo.B!tr.dldr
AVFrisk (f-prot)no_virus
AVF-Secureno_virus
AVGrisoft (avg)no_virus
AVIkarusno_virus
AVK7no_virus
AVKasperskyHEUR:Downloader.NSIS.Feasu.heur
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Start Menu\Programs\Pc6Soft\uninst.lnk
Creates Filesetup_001.exe
Creates FileBaiduPlayerNetSetup_472.exe
Creates FileIQIYIsetup_l_spl004@kb010.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates Fileins1256858.exe
Creates FilePIPE\wkssvc
Creates File2345Explorer_329242_silence.exe
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Program Files\Pc6Soft\Uninstall.exe
Creates FileG30769_s_0529.exe
Creates File\Device\Afd\Endpoint
Creates File9377mycs_Y_mgaz2_01.exe
Creates FileG0828_s_70988.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\i.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\3.ico
Creates Filesetup_3386.exe
Creates FileWanDouJia_runk4_kb.exe
Creates FilePIPE\srvsvc
Creates FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Creates FileBrowser_V3.0.1167.3_r_4279_(Build14091614).exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileBaiduBrowserOnlineSetupSilent-494-ftn_30000046.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\nsProcess.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\1.ico
Creates FileQQBrowser_Setup_Hk_78653.exe
Creates FileC:\Documents and Settings\Administrator\Desktop\Intrenet Explorer.lnk
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\Inetc.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\System.dll
Deletes Filesetup_001.exe
Deletes FileBaiduPlayerNetSetup_472.exe
Deletes FileIQIYIsetup_l_spl004@kb010.exe
Deletes Fileins1256858.exe
Deletes File2345Explorer_329242_silence.exe
Deletes FileG30769_s_0529.exe
Deletes File9377mycs_Y_mgaz2_01.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\i.rar
Deletes FileG0828_s_70988.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\3.ico
Deletes Filesetup_3386.exe
Deletes FileWanDouJia_runk4_kb.exe
Deletes FileBrowser_V3.0.1167.3_r_4279_(Build14091614).exe
Deletes FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Deletes FileBaiduBrowserOnlineSetupSilent-494-ftn_30000046.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\1.ico
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsd1.tmp
Deletes FileQQBrowser_Setup_Hk_78653.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\Inetc.dll
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy2.tmp\System.dll
Creates Process
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexPc6Soft
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSint.dpool.sina.com.cn
Winsock DNSxiazai.9377.com
Winsock DNSdown.yinyue.fm
Winsock DNSw.x.baidu.com
Winsock DNSpconline.org.cn

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ Pid 0

Network Details:

DNSint.dpool.sina.com.cn
Type: A
180.149.136.250
DNSpconline.org.cn
Type: A
222.186.60.68
DNSpconline.org.cn
Type: A
222.186.60.69
DNSpconline.org.cn
Type: A
222.186.60.70
DNSpconline.org.cn
Type: A
222.186.60.2
DNSaaa.163vv.com
Type: A
222.186.60.23
DNSaaa.163vv.com
Type: A
222.186.60.60
DNSaaa.163vv.com
Type: A
60.222.232.224
DNSaaa.163vv.com
Type: A
222.186.60.18
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.5
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.6
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.3
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.4
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.2
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.3
DNSswwx.n.shifen.com
Type: A
123.125.65.175
DNSdl.p2sp.n.shifen.com
Type: A
61.135.185.123
DNSdldir1.qq.com.cdngc.net
Type: A
174.35.56.227
DNSdldir1.qq.com.cdngc.net
Type: A
174.35.56.163
DNSg.quwen320.com
Type: A
219.238.237.210
DNSdown.gtm.ucweb.com
Type: A
120.196.208.98
DNSdown.gtm.ucweb.com
Type: A
211.103.82.247
DNSna.b9.aicdn.com
Type: A
108.186.7.131
DNSna.b9.aicdn.com
Type: A
72.8.188.90
DNSna.b9.aicdn.com
Type: A
72.8.188.94
DNSna.b9.aicdn.com
Type: A
72.8.188.98
DNSna.b9.aicdn.com
Type: A
108.186.7.129
DNSna.b9.aicdn.com
Type: A
108.186.7.130
DNSdownload.pps.tv.webscache.com
Type: A
119.188.40.81
DNSdownload.2345.com
Type: A
60.191.187.15
DNSdownload.2345.com
Type: A
60.191.223.2
DNSdownload.2345.com
Type: A
60.191.223.4
DNSdownload.2345.com
Type: A
60.191.223.15
DNSdownload.2345.com
Type: A
61.147.127.202
DNSdownload.2345.com
Type: A
61.147.127.203
DNSdownload.2345.com
Type: A
61.160.245.8
DNSdownload.2345.com
Type: A
61.160.245.11
DNSdownload.2345.com
Type: A
61.160.245.14
DNSdownload.2345.com
Type: A
122.228.248.3
DNSdownload.2345.com
Type: A
218.75.155.244
DNSdl.wandoujia.com
Type: A
125.39.216.11
DNSs.lllsoo.com
Type: A
42.120.61.139
DNSdown.yinyue.fm
Type: A
DNSxiazai.9377.com
Type: A
DNSw.x.baidu.com
Type: A
DNSdl.p2sp.baidu.com
Type: A
DNSdldir1.qq.com
Type: A
DNSdown2.uc.cn
Type: A
DNSsoft.lvbaoranshiye.com
Type: A
DNSdl.static.iqiyi.com
Type: A
DNSdownload.2345.cn
Type: A
HTTP GEThttp://int.dpool.sina.com.cn/iplookup/iplookup.php
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://down.yinyue.fm/open/setup_3386.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://xiazai.9377.com/20140928/9377mycs_Y_mgaz2_01.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://w.x.baidu.com/go/full/2/30769
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://w.x.baidu.com/go/full/1/70988
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.p2sp.baidu.com/BaiduPlayerContent/BaiduPlayerNetSetup_472.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dldir1.qq.com/invc/tt/QQBrowser_Setup_Hk_78653.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://g.quwen320.com/d/ins1256858.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://down2.uc.cn/pcbrowser/down.php?pid=4279
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://soft.lvbaoranshiye.com/SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.rar
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://w.x.baidu.com/go/mini/8/30000046
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.static.iqiyi.com/hz/IQIYIsetup_l_spl004@kb010.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://download.2345.cn/silence/2345Explorer_329242_silence.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.wandoujia.com/files/inst/WanDouJia_runk4_kb.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://s.lllsoo.com/click/66947
User-Agent: NSIS_Inetc (Mozilla)
Flows TCP192.168.1.1:1031 ➝ 180.149.136.250:80
Flows TCP192.168.1.1:1034 ➝ 222.186.60.68:21
Flows TCP192.168.1.1:1039 ➝ 222.186.60.23:80
Flows TCP192.168.1.1:1040 ➝ 8.37.235.5:80
Flows TCP192.168.1.1:1041 ➝ 123.125.65.175:80
Flows TCP192.168.1.1:1042 ➝ 123.125.65.175:80
Flows TCP192.168.1.1:1043 ➝ 61.135.185.123:80
Flows TCP192.168.1.1:1044 ➝ 174.35.56.227:80
Flows TCP192.168.1.1:1045 ➝ 219.238.237.210:80
Flows TCP192.168.1.1:1046 ➝ 120.196.208.98:80
Flows TCP192.168.1.1:1047 ➝ 108.186.7.131:80
Flows TCP192.168.1.1:1048 ➝ 123.125.65.175:80
Flows TCP192.168.1.1:1049 ➝ 119.188.40.81:80
Flows TCP192.168.1.1:1050 ➝ 60.191.187.15:80
Flows TCP192.168.1.1:1051 ➝ 125.39.216.11:80
Flows TCP192.168.1.1:1052 ➝ 42.120.61.139:80

Raw Pcap
0x00000000 (00000)   47455420 2f69706c 6f6f6b75 702f6970   GET /iplookup/ip
0x00000010 (00016)   6c6f6f6b 75702e70 68702048 5454502f   lookup.php HTTP/
0x00000020 (00032)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000030 (00048)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000040 (00064)   696c6c61 290d0a48 6f73743a 20696e74   illa)..Host: int
0x00000050 (00080)   2e64706f 6f6c2e73 696e612e 636f6d2e   .dpool.sina.com.
0x00000060 (00096)   636e0d0a 436f6e6e 65637469 6f6e3a20   cn..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   55534552 20616e6f 6e796d6f 75730d0a   USER anonymous..
0x00000010 (00016)   50415353 20494555 73657240 0d0a5349   PASS IEUser@..SI
0x00000020 (00032)   5a452031 2e69636f 0d0a5459 50452049   ZE 1.ico..TYPE I
0x00000030 (00048)   0d0a5041 53560d0a 54595045 20490d0a   ..PASV..TYPE I..
0x00000040 (00064)   504f5254 20313932 2c313638 2c34382c   PORT 192,168,48,
0x00000050 (00080)   312c342c 31320d0a 53495a45 20312e69   1,4,12..SIZE 1.i
0x00000060 (00096)   636f0d0a 52455452 20312e69 636f0d0a   co..RETR 1.ico..
0x00000070 (00112)   20323031 35203032 3a32303a 33312047    2015 02:20:31 G
0x00000080 (00128)   4d540d0a 0d0a3c68 746d6c3e 0a20203c   MT....<html>.  <
0x00000090 (00144)   68656164 3e0a2020 20203c74 69746c65   head>.    <title
0x000000a0 (00160)   3e343034 204e6f74 20466f75 6e643c2f   >404 Not Found</
0x000000b0 (00176)   7469746c 653e0a20 203c2f68 6561643e   title>.  </head>
0x000000c0 (00192)   0a20203c 626f6479 3e0a2020 20203c68   .  <body>.    <h
0x000000d0 (00208)   313e4e6f 7420466f 756e643c 2f68313e   1>Not Found</h1>
0x000000e0 (00224)   0a202020 203c703e 596f7572 2062726f   .    <p>Your bro
0x000000f0 (00240)   77736572 2073656e 74206120 72657175   wser sent a requ
0x00000100 (00256)   65737420 74686174 20746869 73207365   est that this se
0x00000110 (00272)   72766572 20636f75 6c64206e 6f742075   rver could not u
0x00000120 (00288)   6e646572 7374616e 642e3c2f 703e0a20   nderstand.</p>. 
0x00000130 (00304)   2020203c 703e4e6f 20737563 68206669      <p>No such fi
0x00000140 (00320)   6c65206f 72206469 72656374 6f72792e   le or directory.
0x00000150 (00336)   3c2f703e 0a20203c 6872202f 3e0a2020   </p>.  <hr />.  
0x00000160 (00352)   3c616464 72657373 3e4d6963 726f736f   <address>Microso
0x00000170 (00368)   66742d49 49532f37 2e303c2f 61646472   ft-IIS/7.0</addr
0x00000180 (00384)   6573733e 0a20203c 2f626f64 793e0a3c   ess>.  </body>.<
0x00000190 (00400)   2f68746d 6c3e0a                       /html>.

0x00000000 (00000)   47455420 2f6f7065 6e2f7365 7475705f   GET /open/setup_
0x00000010 (00016)   33333836 2e657865 20485454 502f312e   3386.exe HTTP/1.
0x00000020 (00032)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000030 (00048)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000040 (00064)   6c61290d 0a486f73 743a2064 6f776e2e   la)..Host: down.
0x00000050 (00080)   79696e79 75652e66 6d0d0a43 6f6e6e65   yinyue.fm..Conne
0x00000060 (00096)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000070 (00112)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000080 (00128)   3a206e6f 2d636163 68650d0a 0d0a6e20   : no-cache....n 
0x00000090 (00144)   636f6d6d 616e642e 0d0a3230 30205377   command...200 Sw
0x000000a0 (00160)   69746368 696e6720 746f2042 494e4152   itching to BINAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f323031 34303932 382f3933   GET /20140928/93
0x00000010 (00016)   37376d79 63735f59 5f6d6761 7a325f30   77mycs_Y_mgaz2_0
0x00000020 (00032)   312e6578 65204854 54502f31 2e310d0a   1.exe HTTP/1.1..
0x00000030 (00048)   55736572 2d416765 6e743a20 4e534953   User-Agent: NSIS
0x00000040 (00064)   5f496e65 74632028 4d6f7a69 6c6c6129   _Inetc (Mozilla)
0x00000050 (00080)   0d0a486f 73743a20 7869617a 61692e39   ..Host: xiazai.9
0x00000060 (00096)   3337372e 636f6d0d 0a436f6e 6e656374   377.com..Connect
0x00000070 (00112)   696f6e3a 204b6565 702d416c 6976650d   ion: Keep-Alive.
0x00000080 (00128)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x00000090 (00144)   6e6f2d63 61636865 0d0a0d0a 30205377   no-cache....0 Sw
0x000000a0 (00160)   69746368 696e6720 746f2042 494e4152   itching to BINAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f676f2f 66756c6c 2f322f33   GET /go/full/2/3
0x00000010 (00016)   30373639 20485454 502f312e 310d0a55   0769 HTTP/1.1..U
0x00000020 (00032)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000030 (00048)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000040 (00064)   0a486f73 743a2077 2e782e62 61696475   .Host: w.x.baidu
0x00000050 (00080)   2e636f6d 0d0a436f 6e6e6563 74696f6e   .com..Connection
0x00000060 (00096)   3a204b65 65702d41 6c697665 0d0a4361   : Keep-Alive..Ca
0x00000070 (00112)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000080 (00128)   63616368 650d0a0d 0a6e7472 6f6c3a20   cache....ntrol: 
0x00000090 (00144)   6e6f2d63 61636865 0d0a0d0a 30205377   no-cache....0 Sw
0x000000a0 (00160)   69746368 696e6720 746f2042 494e4152   itching to BINAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f676f2f 66756c6c 2f312f37   GET /go/full/1/7
0x00000010 (00016)   30393838 20485454 502f312e 310d0a55   0988 HTTP/1.1..U
0x00000020 (00032)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000030 (00048)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000040 (00064)   0a486f73 743a2077 2e782e62 61696475   .Host: w.x.baidu
0x00000050 (00080)   2e636f6d 0d0a436f 6e6e6563 74696f6e   .com..Connection
0x00000060 (00096)   3a204b65 65702d41 6c697665 0d0a4361   : Keep-Alive..Ca
0x00000070 (00112)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000080 (00128)   63616368 650d0a0d 0a6e7472 6f6c3a20   cache....ntrol: 
0x00000090 (00144)   6e6f2d63 61636865 0d0a0d0a 30205377   no-cache....0 Sw
0x000000a0 (00160)   69746368 696e6720 746f2042 494e4152   itching to BINAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f426169 6475506c 61796572   GET /BaiduPlayer
0x00000010 (00016)   436f6e74 656e742f 42616964 75506c61   Content/BaiduPla
0x00000020 (00032)   7965724e 65745365 7475705f 3437322e   yerNetSetup_472.
0x00000030 (00048)   65786520 48545450 2f312e31 0d0a5573   exe HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204e53 49535f49   er-Agent: NSIS_I
0x00000050 (00080)   6e657463 20284d6f 7a696c6c 61290d0a   netc (Mozilla)..
0x00000060 (00096)   486f7374 3a20646c 2e703273 702e6261   Host: dl.p2sp.ba
0x00000070 (00112)   6964752e 636f6d0d 0a436f6e 6e656374   idu.com..Connect
0x00000080 (00128)   696f6e3a 204b6565 702d416c 6976650d   ion: Keep-Alive.
0x00000090 (00144)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x000000a0 (00160)   6e6f2d63 61636865 0d0a0d0a 494e4152   no-cache....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f696e76 632f7474 2f515142   GET /invc/tt/QQB
0x00000010 (00016)   726f7773 65725f53 65747570 5f486b5f   rowser_Setup_Hk_
0x00000020 (00032)   37383635 332e6578 65204854 54502f31   78653.exe HTTP/1
0x00000030 (00048)   2e310d0a 55736572 2d416765 6e743a20   .1..User-Agent: 
0x00000040 (00064)   4e534953 5f496e65 74632028 4d6f7a69   NSIS_Inetc (Mozi
0x00000050 (00080)   6c6c6129 0d0a486f 73743a20 646c6469   lla)..Host: dldi
0x00000060 (00096)   72312e71 712e636f 6d0d0a43 6f6e6e65   r1.qq.com..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a3a20   : no-cache....: 
0x000000a0 (00160)   6e6f2d63 61636865 0d0a0d0a 494e4152   no-cache....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f642f69 6e733132 35363835   GET /d/ins125685
0x00000010 (00016)   382e6578 65204854 54502f31 2e310d0a   8.exe HTTP/1.1..
0x00000020 (00032)   55736572 2d416765 6e743a20 4e534953   User-Agent: NSIS
0x00000030 (00048)   5f496e65 74632028 4d6f7a69 6c6c6129   _Inetc (Mozilla)
0x00000040 (00064)   0d0a486f 73743a20 672e7175 77656e33   ..Host: g.quwen3
0x00000050 (00080)   32302e63 6f6d0d0a 436f6e6e 65637469   20.com..Connecti
0x00000060 (00096)   6f6e3a20 4b656570 2d416c69 76650d0a   on: Keep-Alive..
0x00000070 (00112)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x00000080 (00128)   6f2d6361 6368650d 0a0d0a6e 74726f6c   o-cache....ntrol
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a3a20   : no-cache....: 
0x000000a0 (00160)   6e6f2d63 61636865 0d0a0d0a 494e4152   no-cache....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f706362 726f7773 65722f64   GET /pcbrowser/d
0x00000010 (00016)   6f776e2e 7068703f 7069643d 34323739   own.php?pid=4279
0x00000020 (00032)   20485454 502f312e 310d0a55 7365722d    HTTP/1.1..User-
0x00000030 (00048)   4167656e 743a204e 5349535f 496e6574   Agent: NSIS_Inet
0x00000040 (00064)   6320284d 6f7a696c 6c61290d 0a486f73   c (Mozilla)..Hos
0x00000050 (00080)   743a2064 6f776e32 2e75632e 636e0d0a   t: down2.uc.cn..
0x00000060 (00096)   436f6e6e 65637469 6f6e3a20 4b656570   Connection: Keep
0x00000070 (00112)   2d416c69 76650d0a 43616368 652d436f   -Alive..Cache-Co
0x00000080 (00128)   6e74726f 6c3a206e 6f2d6361 6368650d   ntrol: no-cache.
0x00000090 (00144)   0a0d0a6f 2d636163 68650d0a 0d0a3a20   ...o-cache....: 
0x000000a0 (00160)   6e6f2d63 61636865 0d0a0d0a 494e4152   no-cache....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f536f48 7556415f 342e332e   GET /SoHuVA_4.3.
0x00000010 (00016)   302e312d 63323034 39303030 30332d6e   0.1-c204900003-n
0x00000020 (00032)   672d6e74 692d732d 782e7261 72204854   g-nti-s-x.rar HT
0x00000030 (00048)   54502f31 2e310d0a 55736572 2d416765   TP/1.1..User-Age
0x00000040 (00064)   6e743a20 4e534953 5f496e65 74632028   nt: NSIS_Inetc (
0x00000050 (00080)   4d6f7a69 6c6c6129 0d0a486f 73743a20   Mozilla)..Host: 
0x00000060 (00096)   736f6674 2e6c7662 616f7261 6e736869   soft.lvbaoranshi
0x00000070 (00112)   79652e63 6f6d0d0a 436f6e6e 65637469   ye.com..Connecti
0x00000080 (00128)   6f6e3a20 4b656570 2d416c69 76650d0a   on: Keep-Alive..
0x00000090 (00144)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000a0 (00160)   6f2d6361 6368650d 0a0d0a0a 494e4152   o-cache.....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f676f2f 6d696e69 2f382f33   GET /go/mini/8/3
0x00000010 (00016)   30303030 30343620 48545450 2f312e31   0000046 HTTP/1.1
0x00000020 (00032)   0d0a5573 65722d41 67656e74 3a204e53   ..User-Agent: NS
0x00000030 (00048)   49535f49 6e657463 20284d6f 7a696c6c   IS_Inetc (Mozill
0x00000040 (00064)   61290d0a 486f7374 3a20772e 782e6261   a)..Host: w.x.ba
0x00000050 (00080)   6964752e 636f6d0d 0a436f6e 6e656374   idu.com..Connect
0x00000060 (00096)   696f6e3a 204b6565 702d416c 6976650d   ion: Keep-Alive.
0x00000070 (00112)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x00000080 (00128)   6e6f2d63 61636865 0d0a0d0a 76650d0a   no-cache....ve..
0x00000090 (00144)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x000000a0 (00160)   6f2d6361 6368650d 0a0d0a0a 494e4152   o-cache.....INAR
0x000000b0 (00176)   59206d6f 64652e0d 0a323030 20504f52   Y mode...200 POR
0x000000c0 (00192)   5420636f 6d6d616e 64207375 63636573   T command succes
0x000000d0 (00208)   7366756c 2e0d0a35 30302055 6e6b6e6f   sful...500 Unkno
0x000000e0 (00224)   776e2063 6f6d6d61 6e642e0d 0a353530   wn command...550
0x000000f0 (00240)   20466169 6c656420 746f206f 70656e20    Failed to open 
0x00000100 (00256)   66696c65 2e0d0a                       file...

0x00000000 (00000)   47455420 2f687a2f 49514959 49736574   GET /hz/IQIYIset
0x00000010 (00016)   75705f6c 5f73706c 30303440 6b623031   up_l_spl004@kb01
0x00000020 (00032)   302e6578 65204854 54502f31 2e310d0a   0.exe HTTP/1.1..
0x00000030 (00048)   55736572 2d416765 6e743a20 4e534953   User-Agent: NSIS
0x00000040 (00064)   5f496e65 74632028 4d6f7a69 6c6c6129   _Inetc (Mozilla)
0x00000050 (00080)   0d0a486f 73743a20 646c2e73 74617469   ..Host: dl.stati
0x00000060 (00096)   632e6971 6979692e 636f6d0d 0a436f6e   c.iqiyi.com..Con
0x00000070 (00112)   6e656374 696f6e3a 204b6565 702d416c   nection: Keep-Al
0x00000080 (00128)   6976650d 0a436163 68652d43 6f6e7472   ive..Cache-Contr
0x00000090 (00144)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x000000a0 (00160)   6f2d6361 6368650d                     o-cache.

0x00000000 (00000)   47455420 2f73696c 656e6365 2f323334   GET /silence/234
0x00000010 (00016)   35457870 6c6f7265 725f3332 39323432   5Explorer_329242
0x00000020 (00032)   5f73696c 656e6365 2e657865 20485454   _silence.exe HTT
0x00000030 (00048)   502f312e 310d0a55 7365722d 4167656e   P/1.1..User-Agen
0x00000040 (00064)   743a204e 5349535f 496e6574 6320284d   t: NSIS_Inetc (M
0x00000050 (00080)   6f7a696c 6c61290d 0a486f73 743a2064   ozilla)..Host: d
0x00000060 (00096)   6f776e6c 6f61642e 32333435 2e636e0d   ownload.2345.cn.
0x00000070 (00112)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x00000080 (00128)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x00000090 (00144)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000a0 (00160)   0d0a0d0a 6368650d                     ....che.

0x00000000 (00000)   47455420 2f66696c 65732f69 6e73742f   GET /files/inst/
0x00000010 (00016)   57616e44 6f754a69 615f7275 6e6b345f   WanDouJia_runk4_
0x00000020 (00032)   6b622e65 78652048 5454502f 312e310d   kb.exe HTTP/1.1.
0x00000030 (00048)   0a557365 722d4167 656e743a 204e5349   .User-Agent: NSI
0x00000040 (00064)   535f496e 65746320 284d6f7a 696c6c61   S_Inetc (Mozilla
0x00000050 (00080)   290d0a48 6f73743a 20646c2e 77616e64   )..Host: dl.wand
0x00000060 (00096)   6f756a69 612e636f 6d0d0a43 6f6e6e65   oujia.com..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a6865   : no-cache....he
0x000000a0 (00160)   0d0a0d0a 6368650d                     ....che.

0x00000000 (00000)   47455420 2f636c69 636b2f36 36393437   GET /click/66947
0x00000010 (00016)   20485454 502f312e 310d0a55 7365722d    HTTP/1.1..User-
0x00000020 (00032)   4167656e 743a204e 5349535f 496e6574   Agent: NSIS_Inet
0x00000030 (00048)   6320284d 6f7a696c 6c61290d 0a486f73   c (Mozilla)..Hos
0x00000040 (00064)   743a2073 2e6c6c6c 736f6f2e 636f6d0d   t: s.lllsoo.com.
0x00000050 (00080)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x00000060 (00096)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x00000070 (00112)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000080 (00128)   0d0a0d0a 61636865 2d436f6e 74726f6c   ....ache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a6865   : no-cache....he
0x000000a0 (00160)   0d0a0d0a 6368650d                     ....che.


Strings
 " "E
.
,/KPip
msctls_progress32
MS Shell Dlg
/ P6pL
Please wait while Setup is loading...
/-P?pR
SysListView32
( <^'^
*?|<>/":
	\:?"	
													
^.;099
0a&H#3"
0Qan"4
0UX{tgz 
$0|yX?
11111111111
'1A(d*a
1D9:=.
1/osd}
1r3>ij
1r}a7)
2223WopprsEEJKKKMLL
2mA13y
2xs~6;LNL,
2+`%yM
3333330
358K&'#
3B]:C {
.}3FIM
=~<~3m
3/Pu+v
4A-O%(
4DDFfg0
"4!H`L
 4.I@vN2{
4LMsq_P
}4mcT!
4VYCCF
4X,NLWXUS668
56')sf@
\(5hit
66fff6
6(O0mzpHK
,6SV7jj6
73zc:eDX
>|8122Bs3
83~jL7
8`6g#5
8;!GGG
8HQ<$Q
8NCRCu
9JC0X>
9t,5&?
A1};2*
A3W%T{
A@9PJw
:a$DE%CML
AdjustTokenPrivileges
ADVAPI32
ADVAPI32.dll
.AF=_MCD%
!a>?iF
}[[aK@
A> Ksy
aOOx[JJgSCC%QBB
AppendMenuA
+[B<00D
B0JHN}
BDIPGGDBA
BeginPaint
bF35kU
bgKnVD
BGvANyG:
BLnhA=x
blxOo1
"'^`bn
`BP[kw
.[bu"}[5
b	=Uf	
CallWindowProcA
	cDgdQ
cgs6@#
C==G*Z[
CharNextA
CharPrevA
CheckDlgButton
clLaZ0
CloseClipboard
CloseHandle
CoCreateInstance
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
CoTaskMemFree
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
cY$G@p
Cz.+p8
... %d%%
+**%	D
D$0+D$(P
dAEY-5
@.data
d; d*#!
DDD5Vn
$DDDDDDDDVn
DDDwvk
D$(+D$ SSP
.DEFAULT\Control Panel\International
DefWindowProcA
DeleteFileA
DeleteObject
DestroyWindow
DGAL,35
D*%H IkkN
DialogBoxParamA
DispatchMessageA
dk};"n
D$$Ph(
DrawTextA
d[|r=wm.
D$(SPS
|e>--9;Er
e;GXf"I
;eIR%]=
<EjtU+B
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
EpMA\N
E.p!s+
er<bJ_
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
E,sf:K|
[e$v&ia
ExitProcess
ExitWindowsEx
ExpandEnvironmentStringsA
E?YVjRHC
eZ(f!l
FaPG;`
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
 ?FOW;8Gn
F"pfLW
FreeLibrary
,fR~Nrn
.f-t$M
(+^GBQS	
g	BX4::<?
GDI32.dll
!GD{Oy
gd#;Y1
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
(g?@<fh
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
++g	p4
Gp{jjj
@G{;]w
gW%Ybr`
;.,~\H
{{{{{{{{{{{{{{{{{{{{{{{{{{]>=?H
H::2H;;1H::6H::+G:: G99
h2Ic^o
;h6_T,I 
~+H8QYa
h!`cA@
@HdQG`
HE*hal
{hffyji
;HioDH\
 HJ;N=
h?sllte6
http://nsis.sf.net/NSIS_Error
H v?s	
i0Bf/M
i&5sHk
i7|0~n
I!9BSI
iddPN~
IHDR=[
iHtxMY
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
incomplete download and damaged media. Contact the
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu`
InvalidateRect
IsWindow
IsWindowEnabled
IsWindowVisible
%i.W6[I
Iw NCB
jB/c~v/.=
J<<BJ<<@I;;EI;;<H::4F99,G::
*jD_q-$
\JJX[IIdYHHPUEE&QBB
jk(*<a?
@J-	KI
J&}]/L
j	@o*0
J<<QJ<<MK==RJ<<KH::=G99'E88
j,@rE.f
JVSm-+
K426E~
KERNEL32
KERNEL32.dll
khN]fb
*~kHy54
k{_Q^G5
kv	ScjA7(
kWWuYGGSVEE9sbb
*?/laN;f
L==/E88
lf8lfd
L==^K==]K==aJ<<LH::+A44
L&}lif%.
]LLNQBB
%{lLs2
"Lm33l
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
LookupPrivilegeValueA
lP,eHK
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
l!W:]#
:m.~5~
m7 +	@
:MA x6
m}C[%[
,m``	,E
MessageBoxIndirectA
MH$R,c
\Microsoft\Internet Explorer\Quick Launch
MIHJK$'*)&
mjk;.	
MMM1MA
More information at:
MoveFileA
MoveFileExA
{M?+pZ
`=mRsO<
;mu}@/
MulDiv
MultiByteToWideChar
.ndata
nhb`bhknn
NqXK}hlRs
NSIS Error
~nsu.tmp
NullsoftInst\U
NulluN	E
nYYUSCC*RBB
OB)}Z]
	\\\OFFF
@oHU%g
ole32.dll
OleInitialize
OleUninitialize
^oMYx=.?
:]OnD)
[O%%OOOPUd
OpenClipboard
OpenProcessToken
OpRq03H2%rQ^
O??qL>>lL==VH;;&A44
<]oU,V
PeekMessageA
Pk6;.I
\*p!)lM
PostQuitMessage
PPPPPP
P!qoW{
)PRC=8!
P@@sH;;CE88
P!VI@D
Pz-)j#
#%q& (
-<>_QB)
qDCHMO0/.-67
:Qk0>>
$!R+aTC
`.rdata
ReadFile
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RemoveDirectoryA
[Rename]
r<@[Ex
%RgjjYPUZUVj
RichEd20
RichEd32
RichEdit
RichEdit20A
Richu)
>RlbE4
R	P=@%
RTwwTuw
s0l^3B
S:6K(##"
SCC%QBB
ScreenToClient
SearchPathA
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
SHAutoComplete
SHBrowseForFolderA
SHELL32.dll
ShellExecuteA
shfffi
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHLWAPI
ShowWindow
s>/J;o
s+	k)7
softuW
Software\Microsoft\Windows\CurrentVersion
SQSSSPW
&`StH#
|S&Vah
!SXsr<=
SystemParametersInfoA
> _?=t
T[aeW^
T`-DPc[
t{ffffn
TgT#Vx,S
!This program cannot be run in DOS mode.
& T!I 
tIDATx
_^[t	P
TrackPopupMenu
T}v]||C
{|'[t=w
$UegQ8
U_JmKnR
umVAwE
u=Nk^Z
u~P|h/}5
upyz<;:977BFI
USER32.dll
_UUm5j7
%u.%u%s%s
UV6S4^-{2
U//<zt
v+=0m^
v%54TK
///vBBB
verifying installer: %d%%
VerQueryValueA
VERSION.dll
vf@"gg
V$NPcn
\vNtfn
V`#:#q
:Vq&E1ApY
Vu|K(%#&'149;><:?
v]UROQ
W/3},{
:w>4w[t4
w\8gQBO
WaitForSingleObject
wD33Vffff
WriteFile
WritePrivateProfileStringA
wsprintfA
W_}uI3
wwwwwwwwwwwwwvfn
)W+yt{
x@,^@?
!x|~:~a$/
[X_>e.
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.45</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>
XPN."\
xt3.+,,,568BBCCCGI
xwc~g/
xxpp,*
xz=nn(
y g#e=
YHHXwff
{&YJn,
y<L_50
y-R {\=
,YrgWW
Y^slNU
y`=td:
Yu5	kD
yX	A}W(,Y^
yyHaOO
%z.	3DOytld
z9>awW7m
Z~9@	p
Z(Be^HD
Z~f+'1
ZII?XGGKXGG?TDD0SDD
(zikk#;e
|ZJ)|.
@zKC<iO
^}Z{Oc
zqW]u5
 *zV_2-T
zWn5HZ
:(z}WY
z|\ZHG