Analysis Date2015-02-01 05:15:38
MD54182655957ee177710fc313e9c00fe42
SHA155ec90a61e939bc2b02209941b59cb3dc9e63051

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: c69726ed422d3dcfdec9731986daa752 sha1: 4546608e3b1a2ab1d69a34018d2ddfa7fa411885 size: 23040
Section.rdata md5: a2c7710fa66fcbb43c7ef0ab9eea5e9a sha1: 60485025c47935e745e57b6efc7042f2261b7d53 size: 4608
Section.data md5: e59cdcb732e4bfbc84cc61dd68354f78 sha1: ffc24489dd56b406f9078ba1cb9c71e9b430dbee size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: fd1ecb3697f8f058fdbc07838ba9fa61 sha1: 0ade53c66e5243b5ab4c6bd6bcd3d63ad6428643 size: 12288
Timestamp2009-12-05 22:50:41
VersionLegalCopyright: BEARPC¾«Ñ¡Èí¼þ¼¯
ProductName: ·ßÅ­µÄСÄñ
FileDescription: ·ßÅ­µÄСÄñPCºº»¯°æ
FileVersion: 1.0.0
CompanyName: www.bearpc.net
PackerNullsoft PiMP Stub -> SFX
PEhashfbb97a2292df48ff7da08ac1ff2399774ba7a8e5
IMPhash7fa974366048f9c551ef45714595665e
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)no_virus
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)no_virus
AVBullGuardno_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftno_virus
AVEset (nod32)NSIS/TrojanDownloader.Chindo.R
AVFortinetno_virus
AVFrisk (f-prot)no_virus
AVF-Secureno_virus
AVGrisoft (avg)no_virus
AVIkarusno_virus
AVK7Unwanted-Program ( 004b1ff81 )
AVKasperskyno_virus
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileBF-BFVCenter[[AB005]].exe
Creates File1
Creates File1.rar
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn2.tmp\Base64.dll
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates Fileyx_cqby.exe
Creates File\Device\Afd\Endpoint
Creates Filezhezi_setup_Z7FE.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn2.tmp\ExecCmd.dll
Creates FileQQGame_setup_wb_20007.EXE
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn2.tmp\System.dll
Creates File9377mycs_Y_mgaz2_1201B.exe
Creates FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileMM-liao8302.exe
Creates FileC:\Program Files\2.ico
Creates Filesetup_95165069.exe
Creates FileOfficeAssist.0405.80.1122.exe
Creates FileC:\Program Files\4.ico
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn2.tmp\inetc.dll
Deletes FileQQGame_setup_wb_20007.EXE
Deletes File9377mycs_Y_mgaz2_1201B.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nss1.tmp
Deletes FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Deletes FileBF-BFVCenter[[AB005]].exe
Deletes File1.rar
Deletes File1
Deletes FileMM-liao8302.exe
Deletes Filesetup_95165069.exe
Deletes FileOfficeAssist.0405.80.1122.exe
Deletes FileC:\Program Files\4.ico
Deletes Fileyx_cqby.exe
Deletes Filezhezi_setup_Z7FE.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn2.tmp
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_cqby.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_cqby.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\QQGame_setup_wb_20007.EXE /S" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\QQGame_setup_wb_20007.EXE /S"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB005]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB005]].exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"
Creates Process9377mycs_Y_mgaz2_1201B.exe
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1122.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1122.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex2.ico
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSint.dpool.sina.com.cn
Winsock DNSt.cn
Winsock DNSmmliao.jianting.net

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1122.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1122.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\QQGame_setup_wb_20007.EXE /S" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\QQGame_setup_wb_20007.EXE /S"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB005]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB005]].exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_cqby.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_cqby.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"

Process
↳ 9377mycs_Y_mgaz2_1201B.exe

Network Details:

DNSint.dpool.sina.com.cn
Type: A
180.149.136.250
DNSt.cn
Type: A
114.134.80.138
DNSmmliao.jianting.net
Type: A
122.227.42.227
DNS37w.xdwscache.glb0.lxdns.com
Type: A
183.136.208.114
DNSdldir3.tcdn.qq.com
Type: A
182.118.37.13
DNSwww.bangshijz.com
Type: A
42.121.255.144
DNSdownload012.e.chinacache.com.cn
Type: A
218.60.107.12
DNSdownload012.e.chinacache.com.cn
Type: A
61.179.105.147
DNSna.b9.aicdn.com
Type: A
108.186.7.129
DNSna.b9.aicdn.com
Type: A
108.186.7.130
DNSna.b9.aicdn.com
Type: A
108.186.7.131
DNSna.b9.aicdn.com
Type: A
72.8.188.90
DNSna.b9.aicdn.com
Type: A
72.8.188.94
DNSc01.i06.arnic.hadns.net
Type: A
58.220.2.5
DNSc01.i06.arnic.hadns.net
Type: A
113.17.184.10
DNSc01.i06.arnic.hadns.net
Type: A
121.10.117.139
DNSc01.i06.arnic.hadns.net
Type: A
183.56.172.47
DNSc01.i06.arnic.hadns.net
Type: A
222.186.20.122
DNScdn.coop.baofeng.com
Type: A
182.18.51.104
DNScdn.coop.baofeng.com
Type: A
218.60.99.66
DNScdn.coop.baofeng.com
Type: A
58.20.193.222
DNScdn.coop.baofeng.com
Type: A
119.188.72.240
DNScdn.coop.baofeng.com
Type: A
122.142.74.12
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.6
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.3
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.4
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.2
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.3
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.5
DNSd.14yaa.com
Type: A
DNSdldir3.qq.com
Type: A
DNSwdl1.cache.wps.cn
Type: A
DNSpubliclist.b0.upaiyun.com
Type: A
DNSdl.nx5.com
Type: A
DNSdl.baofeng.com
Type: A
DNSxiazai.9377.com
Type: A
HTTP GEThttp://int.dpool.sina.com.cn/iplookup/iplookup.php
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://t.cn/RZIvNie
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://mmliao.jianting.net/mmliao/MM-liao8302.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://d.14yaa.com/yx/cqby/sqft/905848/yx_cqby.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dldir3.qq.com/minigamefile/QQGame_setup_wb_20007.EXE
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://www.bangshijz.com/NTVlYzkwYTYxZTkzOWJjMmIwMjIwOTk0MWI1OWNiM2RjOWU2MzA1MS5leGU=/40.html
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://wdl1.cache.wps.cn/wps/download/OfficeAssist.0405.80.1122.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.nx5.com/apk/20141222/setup_95165069.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.baofeng.com/BFVCenter/BF-BFVCenter[[AB005]].exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://xiazai.9377.com/20150105/9377mycs_Y_mgaz2_1201B.exe
User-Agent: NSIS_Inetc (Mozilla)
Flows TCP192.168.1.1:1031 ➝ 180.149.136.250:80
Flows TCP192.168.1.1:1032 ➝ 114.134.80.138:80
Flows TCP192.168.1.1:1033 ➝ 122.227.42.227:80
Flows TCP192.168.1.1:1034 ➝ 183.136.208.114:80
Flows TCP192.168.1.1:1035 ➝ 182.118.37.13:80
Flows TCP192.168.1.1:1036 ➝ 42.121.255.144:80
Flows TCP192.168.1.1:1037 ➝ 218.60.107.12:80
Flows TCP192.168.1.1:1038 ➝ 108.186.7.129:443
Flows TCP192.168.1.1:1039 ➝ 108.186.7.129:443
Flows TCP192.168.1.1:1040 ➝ 108.186.7.129:443
Flows TCP192.168.1.1:1041 ➝ 108.186.7.129:443
Flows TCP192.168.1.1:1042 ➝ 58.220.2.5:80
Flows TCP192.168.1.1:1043 ➝ 182.18.51.104:80
Flows TCP192.168.1.1:1044 ➝ 8.37.235.6:80

Raw Pcap
0x00000000 (00000)   47455420 2f69706c 6f6f6b75 702f6970   GET /iplookup/ip
0x00000010 (00016)   6c6f6f6b 75702e70 68702048 5454502f   lookup.php HTTP/
0x00000020 (00032)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000030 (00048)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000040 (00064)   696c6c61 290d0a48 6f73743a 20696e74   illa)..Host: int
0x00000050 (00080)   2e64706f 6f6c2e73 696e612e 636f6d2e   .dpool.sina.com.
0x00000060 (00096)   636e0d0a 436f6e6e 65637469 6f6e3a20   cn..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f525a49 764e6965 20485454   GET /RZIvNie HTT
0x00000010 (00016)   502f312e 310d0a55 7365722d 4167656e   P/1.1..User-Agen
0x00000020 (00032)   743a204e 5349535f 496e6574 6320284d   t: NSIS_Inetc (M
0x00000030 (00048)   6f7a696c 6c61290d 0a486f73 743a2074   ozilla)..Host: t
0x00000040 (00064)   2e636e0d 0a436f6e 6e656374 696f6e3a   .cn..Connection:
0x00000050 (00080)   204b6565 702d416c 6976650d 0a436163    Keep-Alive..Cac
0x00000060 (00096)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x00000070 (00112)   61636865 0d0a0d0a 76650d0a 43616368   ache....ve..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f6d6d6c 69616f2f 4d4d2d6c   GET /mmliao/MM-l
0x00000010 (00016)   69616f38 3330322e 65786520 48545450   iao8302.exe HTTP
0x00000020 (00032)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000030 (00048)   3a204e53 49535f49 6e657463 20284d6f   : NSIS_Inetc (Mo
0x00000040 (00064)   7a696c6c 61290d0a 486f7374 3a206d6d   zilla)..Host: mm
0x00000050 (00080)   6c69616f 2e6a6961 6e74696e 672e6e65   liao.jianting.ne
0x00000060 (00096)   740d0a43 6f6e6e65 6374696f 6e3a204b   t..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a0a                       he.....

0x00000000 (00000)   47455420 2f79782f 63716279 2f737166   GET /yx/cqby/sqf
0x00000010 (00016)   742f3930 35383438 2f79785f 63716279   t/905848/yx_cqby
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a55   .exe HTTP/1.1..U
0x00000030 (00048)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000040 (00064)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000050 (00080)   0a486f73 743a2064 2e313479 61612e63   .Host: d.14yaa.c
0x00000060 (00096)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f6d696e 6967616d 6566696c   GET /minigamefil
0x00000010 (00016)   652f5151 47616d65 5f736574 75705f77   e/QQGame_setup_w
0x00000020 (00032)   625f3230 3030372e 45584520 48545450   b_20007.EXE HTTP
0x00000030 (00048)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000040 (00064)   3a204e53 49535f49 6e657463 20284d6f   : NSIS_Inetc (Mo
0x00000050 (00080)   7a696c6c 61290d0a 486f7374 3a20646c   zilla)..Host: dl
0x00000060 (00096)   64697233 2e71712e 636f6d0d 0a436f6e   dir3.qq.com..Con
0x00000070 (00112)   6e656374 696f6e3a 204b6565 702d416c   nection: Keep-Al
0x00000080 (00128)   6976650d 0a436163 68652d43 6f6e7472   ive..Cache-Contr
0x00000090 (00144)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x000000a0 (00160)                                         

0x00000000 (00000)   47455420 2f4e5456 6c597a6b 77595459   GET /NTVlYzkwYTY
0x00000010 (00016)   785a546b 7a4f574a 6a4d6d49 774d6a49   xZTkzOWJjMmIwMjI
0x00000020 (00032)   774f546b 304d5749 314f574e 694d3252   wOTk0MWI1OWNiM2R
0x00000030 (00048)   6a4f5755 324d7a41 314d5335 6c654755   jOWU2MzA1MS5leGU
0x00000040 (00064)   3d2f3430 2e68746d 6c204854 54502f31   =/40.html HTTP/1
0x00000050 (00080)   2e310d0a 55736572 2d416765 6e743a20   .1..User-Agent: 
0x00000060 (00096)   4e534953 5f496e65 74632028 4d6f7a69   NSIS_Inetc (Mozi
0x00000070 (00112)   6c6c6129 0d0a486f 73743a20 7777772e   lla)..Host: www.
0x00000080 (00128)   62616e67 7368696a 7a2e636f 6d0d0a43   bangshijz.com..C
0x00000090 (00144)   6f6e6e65 6374696f 6e3a204b 6565702d   onnection: Keep-
0x000000a0 (00160)   416c6976 650d0a43 61636865 2d436f6e   Alive..Cache-Con
0x000000b0 (00176)   74726f6c 3a206e6f 2d636163 68650d0a   trol: no-cache..
0x000000c0 (00192)   0d0a                                  ..

0x00000000 (00000)   47455420 2f777073 2f646f77 6e6c6f61   GET /wps/downloa
0x00000010 (00016)   642f4f66 66696365 41737369 73742e30   d/OfficeAssist.0
0x00000020 (00032)   3430352e 38302e31 3132322e 65786520   405.80.1122.exe 
0x00000030 (00048)   48545450 2f312e31 0d0a5573 65722d41   HTTP/1.1..User-A
0x00000040 (00064)   67656e74 3a204e53 49535f49 6e657463   gent: NSIS_Inetc
0x00000050 (00080)   20284d6f 7a696c6c 61290d0a 486f7374    (Mozilla)..Host
0x00000060 (00096)   3a207764 6c312e63 61636865 2e777073   : wdl1.cache.wps
0x00000070 (00112)   2e636e0d 0a436f6e 6e656374 696f6e3a   .cn..Connection:
0x00000080 (00128)   204b6565 702d416c 6976650d 0a436163    Keep-Alive..Cac
0x00000090 (00144)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 61636865 2d436f6e   ache....ache-Con
0x000000b0 (00176)   74726f6c 3a206e6f 2d636163 68650d0a   trol: no-cache..
0x000000c0 (00192)   0d0a                                  ..

0x00000000 (00000)   804c0103                              .L..

0x00000000 (00000)   802b01                                .+.

0x00000000 (00000)   804c0103                              .L..

0x00000000 (00000)   802b01                                .+.

0x00000000 (00000)   47455420 2f61706b 2f323031 34313232   GET /apk/2014122
0x00000010 (00016)   322f7365 7475705f 39353136 35303639   2/setup_95165069
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a55   .exe HTTP/1.1..U
0x00000030 (00048)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000040 (00064)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000050 (00080)   0a486f73 743a2064 6c2e6e78 352e636f   .Host: dl.nx5.co
0x00000060 (00096)   6d0d0a43 6f6e6e65 6374696f 6e3a204b   m..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a7472 6f6c3a20 6e6f2d63   he....trol: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 61636865 2d436f6e   ache....ache-Con
0x000000b0 (00176)   74726f6c 3a206e6f 2d636163 68650d0a   trol: no-cache..
0x000000c0 (00192)   0d0a                                  ..

0x00000000 (00000)   47455420 2f424656 43656e74 65722f42   GET /BFVCenter/B
0x00000010 (00016)   462d4246 5643656e 7465725b 5b414230   F-BFVCenter[[AB0
0x00000020 (00032)   30355d5d 2e657865 20485454 502f312e   05]].exe HTTP/1.
0x00000030 (00048)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000040 (00064)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000050 (00080)   6c61290d 0a486f73 743a2064 6c2e6261   la)..Host: dl.ba
0x00000060 (00096)   6f66656e 672e636f 6d0d0a43 6f6e6e65   ofeng.com..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a2d63   : no-cache....-c
0x000000a0 (00160)   61636865 0d0a0d0a 61636865 2d436f6e   ache....ache-Con
0x000000b0 (00176)   74726f6c 3a206e6f 2d636163 68650d0a   trol: no-cache..
0x000000c0 (00192)   0d0a                                  ..

0x00000000 (00000)   47455420 2f323031 35303130 352f3933   GET /20150105/93
0x00000010 (00016)   37376d79 63735f59 5f6d6761 7a325f31   77mycs_Y_mgaz2_1
0x00000020 (00032)   32303142 2e657865 20485454 502f312e   201B.exe HTTP/1.
0x00000030 (00048)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000040 (00064)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000050 (00080)   6c61290d 0a486f73 743a2078 69617a61   la)..Host: xiaza
0x00000060 (00096)   692e3933 37372e63 6f6d0d0a 436f6e6e   i.9377.com..Conn
0x00000070 (00112)   65637469 6f6e3a20 4b656570 2d416c69   ection: Keep-Ali
0x00000080 (00128)   76650d0a 43616368 652d436f 6e74726f   ve..Cache-Contro
0x00000090 (00144)   6c3a206e 6f2d6361 6368650d 0a0d0a63   l: no-cache....c
0x000000a0 (00160)   61636865 0d0a0d0a                     ache....


Strings
 " "
E

080404e4
1.0.0
BEARPC
CompanyName
FileDescription
FileVersion
LegalCopyright
msctls_progress32
MS Shell Dlg
ProductName
StringFileInfo
SysListView32
Translation
VarFileInfo
VS_VERSION_INFO
www.bearpc.net
 ~$</]
'~.*")?
*?|<>/":
\=@_~-
)0/?4n
05De-~
06]G;v
	0_757
/07@ h]mY.
_09Sxl8
09tbe7
0CFrg P\J4
0C~{Ni
0co	+	"/^J|
0cOU$M
[0<,DS*
0=e}$z
0Fa9]v
0h4Iz;
0Hfh:&4F
'@=0;ismT>
0K(~0x;
;0lcw.
,0-N80
0^:Nd	
0n*=s)
0Qan"4
0Q#zrG
0R;7c*
0%\s}!
0:,si:$ g
0sWN[h)-
0<tIY~
| 1)]$
}1-/\[|#
11j?t"
>>13wU1
1~^&53
1|8{c?	
(1|AM4
\1a+\N
1A[Y0u^	
1D9:=.
1~ -F1
_/1F{vi
1GR>RlF}
+\\1gU
1'$+i(
1^!k\W
1mD$P]3H.
1^'~oMQ
1PLL*@
1,>)pMe
1>Q"3I
@1]S1Q
/1xnZt
1zlE8O_
21pT,H
2.5Ih$
2ADj$2
2+@a*W?
	2*_ C
2Cy,n)
2FxI$F
2H]qekl#_
2i*]#*>
2j0r4@!
2>J._6+
2L{0C~@
2l1	p4
2mA13y
2mi`UJ
=>2N^O
,}2o|3
2OE}4 
2ooB`<
2pQ"{*
2qp?u7
2tnB6Vgi
"~2V3@
2YA"6=
2zwC"N
3"/^=%
{+32`]/LL3%QO~
3<4?F<
350@A!
3"]:/6y@mKG
371;)hJ
3+afs=`^
{3,,B5'
3ch.C7
3'cpS>4
{3.CSA
3!]+D)
3~d*e	
3Dy*EY
=?]3^f
#3FE3^+
3Jy%!4
+~3&!L"1
3l]h S9
=~<~3m
3O=)o*
*3o{wN
3Q`H=7
3`QsZ%
3}RnR[
3RT6\q
3\_s,A
3sQ#Rx
@;=3Xe
<3y5]dVL
,	_4**
%[46w*
$4<:*8
4^8}He
{4Cl9&'
4D Sk	
}#4fc16
#(4:Gp
&4Ia.2
('4&}Jb5
4Kg/]R
4{!kkw
4m7G$a
4mg2g}.
4N>M5TXE
^4`PDi
@4qF}*.
4qZE%u
4S mvu
+4u\ZC
4,!.V}
4Va|;f
4yTN6s8
&]4z|c
4#z}Pf"
4zyzx[X
`?>{![5
,.5*,&
5'0`0;-}}_`
51cs48QO
53-I?*.S
5Aq0Mk
}5dW%U
/5F@~>jsR
#@5|g6
5g;s)m
5":&hR
5Ivh\i
='5izWA
5JjvD_
5j-(q}Z69
5^LXNP
`5NlSo
5qpad,
5Vx!6U
:5\WHn
	)5z~i
,%	(6|
6}>b+1
6b]QnqhB=N
6CtuX&
6D<$&@
6d;g+a|[
6gbHn6
6GD/Eh 
6G;W32Z-
6K"E'LGx
6KMwpk
\^~|6L
6mNUy\2
?:6(&p
6Pe]jm
6QT\VmBX-
% /6$S%
6t"[Q>9
|6UrAc
6!?V|{
6vy:ky>
<6Xu5!hW')
6~YBCS^
6ZGf5*
6z>]V|
7{)36&
7#6}pwR]
7a>FiD
7Cr_l:
7fq;QX
-7fyvD
7HZ4#@
7i;'+"
7IG>0#
{7]joj
7KOz<c
7LgB&y
7l!GtO
]7,op*
-``7P4FEom
7*pv:1
7Qu7xlh6m
7QX5Ko
=7Ri<V
7sCD._
<(}7TI4
\7t*\y\y
7v|IZ-
7y'osO
$8*2;^;p:
84C#R6
85 05Y
8$5 4\
8`6g#5
8))84R
8])aAw
8aX(3L5
8c!h58y
8ea[k8
8HPw^#'
8J|y(7
8kN9}E
8,]l5J
8LZE>!
*:^8m"
8`mJnV
`8m|/jo
8NCRCu
8n] 	E
8%ng1a8
_8NTpX
8;@(ON
8##,OP
#8peW\I
8RzF{NL
8[U4Ui
8uPFF;*
/8"USEi4
8]^"vlp
8v]Lx=
8VpaNo6
8;{WFV
^8,{Wk
8w.qDg
*"98sI:
\+9arr
	]/9cA;
9CBV+dC	
@9{EB0
9&FBb	
!9FgsOXH
9	g'`9
9H~DZ*;
9<Hq1$s
\9)#lJ
9m9YsO
>9`O6y
!9p7[tOA
9sH+>J3
9 }StBD
9t3YfF
9@W5O%
9y:d?..
9z	'cO
>A\0J\
A"&0Kw
A=0:myN
a//0Pl1
a16hN_
$a#2VAI
&a<![3
+A5R*=i
+A7AF5
)A8H:w
A8;r,S5Q97D
Ab*lD?
$ab*ME
a"cgW5
Ac%;UZf
AcVsWr
AdjustTokenPrivileges
ADVAPI32
ADVAPI32.dll
AE6]oq^
aE{_fo
Ae;IR`
/aeNez
A-f)aV
aF{Lvbr
].-aG&r8
$aHwi2mq
AiAU@XP'
!a>?iF
?AiPi 
aJ@;Gs
aJ&(w\
aKZ9k-
AlT)dp
A?n3~;
a~n;`iIW
ao="~?W
AP%+,;
A'>p1*w
ap JgGHh
AppendMenuA
a/QC5D
AR{Kh{
\A-RQ5
AsC95H
\a*}[<\T
)a|t9S
A("TcHz
?\Atiz
au@29]
a[#v-3
AWk`@m&
awW)BulQ
A&y/HY7
Ay^Nsca
a:yoI_
a>&zc9
A&,`z?t
B0R7^l2{5
B3`#n*
b5X{sp
b 6q]T
b`9HJiA
	B/awn
BCU` Y
"){bcw
B:CY n#	
;-=*bD
:bD? !
BdI0AF
bd(JzI(
,b^dl6t
BeginPaint
b">F=2
BFeUoK
Bg96jh
bG&q`X4
):B h	
BH^(og
bi}e</@
'"B>K;
bk7tUhz9C
bkaL-*
\B	kKja
-`#b>lf
]BlFId
b-L<r|>v
}BN=#z
^BON`>
^BpK$!99al
bq$^C|
B $=R07
Br=2ue
bRKL'U
bs+5Xa
<bSb1Q
|$B[SNyL
+b*tI2
Btr:^8\]s
buPU<X
]BvjTMI
B#+,W"
Bw%[_f
bw$?k)
BWt+e*
bW\Yq4!P
\bxC?{
b)Zd( 
c2|V2S
C3(r76
c[@7)<
c!7i}H
@?,cAajb
"cA^bq
\.c~AF
CallWindowProcA
`:c"$ba
CcJE}@(
Cclx%7
>c#/;CN
CcZF<!
C"d:drTOn
=CdGjYY
`CFaE <
CF azx#iA
(cfCXC'
`CFdtk
=^*>cg
C,GMYmRE
cG|U/P
CharNextA
CharPrevA
CheckDlgButton
(C!HgE)
cIhsCF
CI|~ zy
CJG)>m
c@jis N
*Ck!k{:G
^C*LB@G3
'clDrCX&
CloseClipboard
CloseHandle
"C;mD#3
Cn[7tY
:Cn8a<
cNE*ET$U
CNWb0B
cNx)x{
CoCreateInstance
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
CoTaskMemFree
cpZLd"
Cql.u\
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
CRq9dT!
c&r}YGX*
c;sc#9G
c[[tGc
.CTzT`B
cu($\,
CuATQ 
Cuj	?XD?'G
CxM7J5
CzLo9O
C<ZYF;q
... %d%%
)%_&d$
 ,:"*%D
D$0+D$(P
-D\]0V
<d.1%"
D1!$.L
d1Q_JK
)d28vLV
}d3;O/a
[.d4VS
D4vTc.T
d!5\h>
d8*H;m
DA{a63
dAmyZ_
@.data
}D`c5p
`d,cAN
d c gD
dcXJ!C
D$(+D$ SSP
DD*UY2u.
.DEFAULT\Control Panel\International
DefWindowProcA
DeleteFileA
DeleteObject
DestroyWindow
&D&fcuT.
 dG?	5M
)D=G7b;
=d]g'G
D?#GK?g\
dhDHKe
dHKC0S
D`Hrnf
DialogBoxParamA
DispatchMessageA
\d/J#j
djU!Knp
dk4aEp
~dk^G]
dk};"n
~d()kR
DK<<?s
dl&AyA
.dm{dI
d$Mj}e
`d <MO)IF
DMZo}N
Dn+!}>
?]DnnQ
do9AUO=
DpB	?X9l	
{DPCO9
D$$Ph,
D+q[)&
D/qdl/d
{dq-M0
(dqN_w~D
d;quHds
DrawTextA
dS4)y{
DScVx.a
D$(SPS
=dsv8[2h
D%TjcE
DT?Jh-
DtQ!G{
{,|du+
<Du'4[
Duf:};
d"% ugW+
{[du	V
DuwwHL
dV35C[
d^Vg8!|
dV.L;\l
DW703G
dXokZO
,DxQjA
>d(ylMbY
dZD&x"oG?
D[Z{{L
dzqR}R
-d:zVCT
dzW.~Iz
-:`>E\
E0{JISq
E_\14,(
&E2*i<
E3k;oO
E"3qI1#T
e3	VHd
E4)U{	
|E/56a
e5c{A%
%E5gIz k
E;6J}/
e"6NZlY
,_}eBB
.ec!5X
EChsp'
EcH\uC
e}@#dv52
/edVJ=
ee)4J9A
EFb{j19unC
eg=R9n
eh^ZgI
ei6[H}
E%iAFx
E.iLZ#
EJ[?QJ
e<kzA)5
e.L+XPXE
>+eMhE
EmptyClipboard
	<e-[N
EnableMenuItem
EnableWindow
EndDialog
EndPaint
eNtjd8
EOMBoD
}e!pd`n[
eP?|]&s
E.p!s+
EqRb%i9
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
,ERSp@:	
(ERvSr
ES(<qg
 <&.eT
ETFQqU
> ETW	
^euB84p
}[EUR$
>^euTH
[e$v&ia
(~EW+-
E!wQ)A
[EX9UT
EXB>'w
ExitProcess
ExitWindowsEx
ExpandEnvironmentStringsA
)ey]N>
eYuU<	
[EYW["
~&e[?za
]`/<ezL
e]zm+8|
F`0_RCqXN
|F1>HU
f1OW8y
F\264#
f2BJs'#Rg
F;4lNE
f4.M`M
F5ogtQczt
F6rFX%
fa'G^wD
F\<a#x
fcmoP^
F\eA6s
(>;FeC
<"ferq-p
(FetA}
fF8~I*
F"F=z.I
'':f=G
fg!IvK
f?hk!R
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
fi nehE
fJ[?5D
f<JAF4
FKA(?G|*
FkJH)H
f.@"$Lz;
F^MGl9
fm$uUPm
f'@N:2
#FO-DY
)f O.i
'F_P#9=
FPq,Dr
F/qXN0
FreeLibrary
f\R{\tL
`+F's4
f-/tE.
{f+[tg
fU~fZ?
_}fXmN
	fxR+f
fyW%+Lr
f!z0ub&
FzXp+~H%
#g0E>(
	"'/g)1
g=1Y<r
g2@"\22
{g_3Lr
G3/~m5
(g;4=DDg
G[70E8r[
g`7hUa
G8DmOG
g8z]#nw
g";AA^F
g\)=>b
g$B8%JE
gcv[.q
GDI32.dll
G>Di4T
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
G,(f8V
(gGPiz
gikC*}F
g^iV%~
.g\j+^
|'GjtU
G<^`jzk
_#<g"k
@gkEvZ
-G>KI	
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
Gm#XmbU
 goiN_[
.gO#L0
GOPT@qS'
(GP(-\r
g*ptA`z
GpU*\'
gPXx@t
(=g};q
G.R7Oq/+/t'
?{[GR9
gR/O	+
GRp(Nb
gso@oFe
G$t)Df
GT\m`+{%
GTyXY%/R
Gu@#JE
G~vp~+
@~gw>0'
g]Wk|9
gW%Ybr`
Gxjsr9
g+XyH=8
@GZ:$NTZ
;gZVz[
H0FvP}X
H2=A~Yt82k
H	?3$@
+}h3:U
H),7d,
+h8)3b
H8b_b[,#3
h9pn!F
]@ha2H
?ha:qva
HB3k(`
h_#&BF?
h!`cA@
H^*cN^
hCN7#f
H~CNP_8;
hCung&
HD}/@g
h-D)t3
He3EN:
._hg[d
;HGM?4
h~H+6~75
-h`@Ha
HhAg&g
H-*_~H t
>hI6vi
+h`j$g
hJ.>?Nm:>|
`&`H)N~
hN18*2&
`HoUQ'
hovBSj
hP7v/]
h{.p`G
HPL,7`
h:p*^X
hQ63f6%
 }hR	g
[h^rh$
HRVBW_%	S
_hr@z!
HsM3=?
&hsN`/A	
H^SOKf
hSRH]n
*)Hsr`x
HsZ^z3~
H<tf/<
\<hTk[
HTt"1	
http://nsis.sf.net/NSIS_Error
%HUc,W
hU}".HRq
hu:'@N
/HUz:T
h v2>V
hVL*8Q5
hVQ~qV
,h+vrHvwR
hvrL]g
HWOHx_G
hx\aa]
HySuYnu}
Hz2A+D
>\]hZ4
i0Bf/M
`:	i2'{
i5_sw%
\i5vVV
{I,6,0
i8oZ(l
i8|pgpN
I9+jha
(|I)>A
I	=*aR
iBc)i/1rw
Ic	91*
Id.%>4
.ieiIp++
#I	Eo^sb
\~IFC7
I'gX`.
~IHk#V
iI0$?d
I#K@vo.
il-aJ2
ILf[d8+
Im3aIa
im-6SKA
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
I.MQXC1
imY){$
iN9VdSZ
incomplete download and damaged media. Contact the
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu`
InvalidateRect
	Ipf;B
iP'I9GY
iPt@9?u
Iqj g~
I-QyxP
iRichu
irLX_#
?*i+rw
IS/9f-Qv
I{sfWX
ISI~8G f
IsWindow
IsWindowEnabled
IsWindowVisible
|i.t2'
~ItCGU
,iu(\9JPukW
/ iw0FY
Iw/uxx
ix(_Jnv
I'xKZjR
i=y=<y
]i=Z9%
izW:wd
_}$,`j
@;$/j&
@!;j$	
j14C.B DfV[
J2!^;6O
J3!u~*
"j;4<;
-=J	~&<\4
J5e 8F
J;5#MO
j7!,-gd.f
~J9f~%
j"9*Se
J?9]=y
>Ja6U&
\Jan_e]BQ
%Jbf;*
jb?qoJc
J'Bs5t
J<[!c4D
#	Jd%*
-JDbB!5
jDreN$
%#JDTv
jFv0qceMF
==jG-*
+JG0A;m
[_JG&F.
Jgg]]/
J`hBpkW
jh|f_D
Jh&{s&
J]H_^u!x
JIUM.i
j)$j~4
jJ80(U
Jjc9A'
=?j.K,P
J-Ky}@
j.L{`1
jlaM<OP
J`op26
jpQNYIz,
jQZuTp
!^}JRK]6q 
"jsHNa
j\sK%2
Jsm &A
),JUn[
jv=b5{ (
J$@Wk.,
J?#wx=u.
(%(?jX
!}$jX0qa
J.xa_6"
>jyg)o
j(\Yp>
k	<+,:
`&^K(:
k0RM^`
K\1]FTxh?N
k2p;H|
,K33-be
-k	}5^
=k_5d>
K}6)(0
%@>k.8`N
=K8two
kA1eq9
.?KA]d
KA^dyh-
# kAR]
KB;w=i
k.D+&}Jrp
KeaU9h
@KE)B2
k}e|BjRY
:KEL9a
KERNEL32
KERNEL32.dll
kEV4.~w`K
)$KF8&&_
k$f*YI
kgDqV.ri+
kgE@OR&~;
]KGLP#
kH;18a
k.Hrd!)
k[hxfV
*~kHy54
@KJE>)
</	k%Jvo(
kjYHV=>mb&U_J
kKL.#&
.}KKVf
k:	-L?
K_]LL?
>kM]NFu
;?koye
kqNmN 
KRg24*<%A
 KrMrr6
KS\BJm
KTnj|a
>k._v{
?KvJ2A
?~kw5_
k[wxI|
>KxoG:
kY8WU-0v
Kyq'=E
kyxY\-&
$kZ)`\l
@-!Kzl'
[!{&L]
l!*1-7
L-1?m\o
l=1QVyy6H
L1+vW*%
^l2k$|
L2Z_dG
L*(3J=u
{L3Y\~X
l4<_jn
L5"myZ
>"[l61
`l6N5:G{
l7,60y=
L7s>.lP
l|8mr}
"L'Ad*J,_
LA}~q7(
\LcsJj
l)[D%?
ldDc-,L
l;dv3S
LdXLg]
l*F&u@d
lg'\H'
l$HGM{
Lh*gy6
,Lh$Qsv
lH}[u1
;/L~(I
)L,I!$
lJBgip<
-.LjD#
LjHc{z:x
lJ<Ut{,@
l(L]\`
)/>L=l
	ll2PC
L>)Lb\
LLGNW&
l,lP,G
"Lm33l
LMBISK
\ln@cg
l]O+5i
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
LookupPrivilegeValueA
!LpopG
L[p`&s4
_LQNit
LRgrFq
ls~0Qq
lS'^+9p
ls<9V+
lSF7v	
l)SMF-,EJ
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
%$'L"t
	"&+:LT{
L{t=h_
<$l",U
lUgYG=~L
lUJxu&G
L#]\-W
LxB@:9
lX*oF5
L)Z[{%
|>#m|*
#(},m@
M0a=S(
M0f8]wJqh
:?M0M($T
M3M&b#
m\3O#b
M4,N:M
M%4#s`-
,M{7/UV
m!7x@'
"'M]8.5
M\a#G-=N
	Ma}!t
<MATdn
M=b\Kz{l
MC_`:i
mdioj/p
mdTFRT(
m/E?]~
Megi3j
MessageBoxIndirectA
mevJFQ>R
M=Fxb@
^m~#'G
M.G*%<
*MG43S
M^H]}>
m{h~13O
MH#~&I
MhRt`4
\Microsoft\Internet Explorer\Quick Launch
miZ5p)
)m	jRsN
m?j T8
MJ@_Z=
m)k<3@|
?MkZGi
mN_?)<
mNdI=0
m_n+Ft
+MNhJHl
-Mn!o@
MooHS	
More information at:
=MOV$%
mov2|=6!
MoveFileA
MoveFileExA
M^PBu%>
[mp cL
M.'p'S
:>MpVNK
{M?+pZ
mq*f$B
Mr4!l	)/
mROMBqs:
MRTe<4
mSO6R>
)	m\?T
mT#C5]
MUKGjR@
MulDiv
MultiByteToWideChar
}mv601
M=v$ mDZn
m#VO66
mw2A=_
m.wCVw
]MW[n^
MWQPZH
M#wQ_Ve
mx1]y}
m^x[wF/B[7
(|)M]y!,
m_;y8M
MYFDzD
~&	= N
n03}	!#%
n074hK-
N0E*/P
N2tN+=
N3dmuh
N6O :{
N6O~]Q
n7=l!1
naI$(])
nBg\q2
nC:(b[>
N{CIst
.ndata
nddRp=-
ND?x1X`P
NESW`f
_>N.<"#f
@^N`f-
\NF9up
n'GYf&
nh_u<w
:>Nh_v
N|@[In
@NJ@N:xy
nj%V"Q.>[
N+k/V 
nly3q8
NmJs:Zr
nm:y#Rh
n*nf{|
`Nn~ f
}N`njs
nn\r7j+
!NObHy
n^'>+q
nQ5_Y"
nr3'?C
NRF6y	
n-&RL3
NSIS Error
n*S$ jZt
~nsu.tmp
N/=$t1
N%T>B#U
nT=^*v
nUj40pC]
NUL?I*a
NullsoftInst
NulluN	E
NUMciR'
nvZ\9]
nXC+_b
NyaxKy
%|*NYr
O%(0;1
O1AoV4
o$1Ew"D
o1PU(M6
O,24G'
o@>2DmQ
o2$H$>
O2n/H3
o3usxP
:o5+t`
O6F\zo\0
O7Kt8~
O9}B8N
O!9n@d
o;_#AZ	
|]<o	b
|ob@m0bR
o/BQN4
~oBt_	
O@Ca[J
OCBPg&
OCV\oZ
OdggF2
O"DJ!X
oe<vE!s;R
(Of=4H\
o=F<&:C)
O+FGAa
of	mk&
ogVS_W(O
oHaH4s
o>HF	 2@
\o	hpW
o[i9.A}
o	/iik
OjVc2s
%o+=\k
OKj^+2
ole32.dll
OleInitialize
OleUninitialize
]oMO#	
OnU18""&
+$-O'O
O_O*,Q
$O@p/E	`
OpenClipboard
OpenProcessToken
`?op;M
OpN}9P
O({	Q}
;O#Q$f
orgzEa+
OrkoS`
<oS4CiP
{osR!L!U
OTcZZC
[otnUi
Otw"K(
Ouba"<iy>
O!uo_RJ
ov>z`#^
-Ow%I;
[o&WyF
o}xfdFa
Oxou?S
oY^jeV
oYo$bE
>-/o-zf
p)2rhq]
P2,&x5l
	p4)*H
P(:?5ZtG
_,+-p>63R
P6g:B^7
+p;6_N
P``6x:
P8|{4O
PaerP&
pA/ E{y
pAJsFh,
Pame)-3s
Pb 	6&
pcE6	{
Pd{fbd
pdxfRMN
PeekMessageA
PeQfV{U
: pE/Q!m
[PFH|1
PfJo[98
PGx)ai
Ph`h<u
PHO.(=_u>
Ph/;+p
P'j~Tn
\*p!)lM
P/M])T%
PnnZ*L
pO27zU
pOhGV`
PoS{$e
PostQuitMessage
P:{P>"	
#pPohD
PPPPPP
p_ppzO
PQ;fH^
P!qoW{
pQ@ZM\
)PRC=8!
p{RH?}r
PrmI3,
}PsM)28Z<
]$P"t[
)&_)pU4
P$\u?W
!PVp@1
'@PwS!5h(
pW~$u_
pxGz&b
p:Xs7#
P{XX>	J
PY/> E
$*Pz&*
pz9,UNBR
q/*1wz
Q2R9[rd
q\3u0}[
~q4BT4{
Q\4U:`o
Q*8T%d
><!qAKl'
,qbP!J<
QB!y|5H
qceWT.
QcG*7U	
qd`C[>
Qe'_6I/
QEZk_$
!qF4evZL
Q?glH9
Q^GP}f
qH0[&x
QH_59U
QH}r'f9
QHWD7f
QHwr)9
>q#I8*;U
;qIjhfb~
+#qJ%6
[qJgd:
qj*UMf
q"kh&@0m
]"ql%A
qm5[mTK
QM@jQi
q$MN	)
q'OYH	
q$p|UJm
Q~Q`;5c5l
?_Qrq>
	QTa-4
q\"T;c
qt;+UN#
q{==vD
QwBs(^in
Q+YcZ=
qZP$f3
QzPkHh
+?QZXxns
~*".R<
R0}?QC
R1	Z.`
>R25XM
~$r`\2m<
&%r3(t
R[?7oEgK
R\+8	B
R8.b'L
?r8y,0P
RbBlA-
r)CU3F
`.rdata
]rD+LE
rDq7 00cQM
ReadFile
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
re~H@T
RemoveDirectoryA
[Rename]
retFCT
R>fEN^
R/gD.&@
rg!hLk
]rhCCT
RHe0oC
RichEd20
RichEd32
RichEdit
RichEdit20A
Ri{)$w
R*%^"J
r)}J<q
#<"R[K
(rK~oX
r}k[UT
R>l:BZ
R+L}ceY
rlHtt t
R.lzOG
rMsspWW
r+<%~N
(Rn$$B
	\rnJ.k
r}o#jW
R@rg4/V
RrP,+1
!RsxEN
r+ #th
rT"uG3
rTZ<-(
/ru!Bg
',/ruKQ
rw5t	sC
'r$w9AO
!R]wf#
RycqWBq^0
r\YVEq
;rZ=~9
]s<0N2
S20^	t
&S23bF6'
`@S3)X
S5Ew		\
's(6.BA
&S7S ~
S88L;re
{$%|S9
sa=3/#
,SAL+g
.S;?b[
s+$BHf
?^=[s C
{scPN}*
ScreenToClient
s}{-DV
SearchPathA
sekCzFn%,)
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
`.s~	Ev
sF&S1{
SG~M(	
SHAutoComplete
SHBrowseForFolderA
SHELL32.dll
ShellExecuteA
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
{SHhlb
SHI5XA
SHLWAPI
ShowWindow
SJ{d;'
s)jf[A
s.Ki2M
SmNVcq
S".M#u
softuW
Software\Microsoft\Windows\CurrentVersion
;-(sP>
SqL=w$
sq)Q)X
SQSSSPW
:>sQyf
SRBfjv
?SrJ%3n
SR]j\ld
SRP[s7u
sRYJVL
#&@SSSi
.{S=tj5`)
STjB21o>E
{*St|vT
!s-&<U(
su=7q/
S%+!|#uf
S!u_FJz
:su	Z8
,s`V3N
s!WI2D
S}W:je"
~&Swl%
sxizue
S]X-u8
Sy+IcW%
%SYM:Bh
SystemParametersInfoA
sYv.!l
~{SZ:+
,SZVa;
> _?=t
T1SM>Y
T+&2BqF
t@._\3_
t33~$;
t4{UV)
%}t<5HF
T>9Ygc
tB0EtkQ*
TB+K=r 
tcKjj&
	.t=c'P*
TD{pv6
TDr;n0
t%Dz[y
tFr`PF?1A
 t^>GQ
\th2#5
!This program cannot be run in DOS mode.
TIW%!k
tJ}0 r]r=
t kB"-4
t[KtKi
TlC3Z4Ni
tLO9{W
'tlUgmI
t]:O{}
#t(oOq8st
_^[t	P
tpaY^#
tPVZQ}
T&/r5U
TrackPopupMenu
t+RX5T
T]s !<(
)T+s]B|4
tSJgeb
TT<]vF
;tu1/G
tu~BG>
tUW2n%O
t=v?>07s
t V\&1^
'T=vCs
`TvKyv
tw*[%0L
tXw@y\f
Tykof'
Tym:rZ)
:Ty*uL
TZ[9oO
tzAc9"
tZdeP1
 TzH/B
u0B-$O
\u:1oV
]U[1>~pe
u2xG,mi
	{-U	3
U37B+F
u)=?@4JX
?U4L53h
U4N[Dy 
(U6RCj
U70Qb+
u_9YDkB
;uA8:;
Ua\j07
+UA(Y@|
<$!u_az
@ubEg6
uB &*M
U":Bmk
=<\UbTJ
Uc	lHV
u^CR,O1h
UdV%Ni
U|e\ _
"U\eFz
_uE` K
`/u?ga
U!G`i)ZC
Uh*pbY4
U#i34#
$u~ifZ
&+\]UIR
u<IVVy%
u^Iz,:
%UjI7|
u|J,+Jn
UjKnO<
 u{J'MW
"uJ&^N`l
UK&nW/
uk, wU
%(ULj|
%uLy/o
*!U!@N
|$UNH56M
%|uO[5W
U:*OOq'
UpE4CT
>;upfv
up{Gv|
%UqZP3
u^R&1T:
USER32.dll
uTB{(y
##U-U2
uuCv;#
~UufMV
%u.%u%s%s
uW~mLaT
UW^-U:
UxgU!z
UxQFFX
Ux]yL'v
uY68]3
uzCj,t
&:Uzpo
v0H&{U
,[v1bEp
V!3z\Z
V4rTz%
;V{7e75
v7j/]{
%v=7S]` j
v8l$[d!z
:V92.\
VA./]<
vaA_2q
!vASS>C
V?)|bK)*vQ;
=V+b+.W
}vBX,,
v]cEBf@
vC(ev0
\]vcp.
V%	{D#
Vd>9b}
VDL$wu
:<ve1a wA
veNte 
verifying installer: %d%%
VerQueryValueA
VERSION.dll
veSlHP
Vf)_(=
v({f91
v@F91S\
vG/AA]
VgXmHC5
Vj;+T=J
V`=kN3
vLI/c#
[?"VN&
vN;"36`*Ke
VnavW:;
vnmI4bV
v?nUp)$
VpZ^l,i
~v^~Q2
v{QBl-
VQo<F>
V!R-^"k.
(V$+"S+
Vs55xq
%vS!>B
VS(ED,
V\;sx1
VTs8$d
v#Vh;+@
%:vWr ,
vwv	}Z
=vx|6s
vY]~?E6
vYY.;fVc
VZT\Y|
.+<'w>
w-=/;-
W(:0SM
w]1m&k
w?_1Z)
.W20PP
w2LrLv
,w32iJ
W33/-w!
W3*Yk[
*}#w4_N
w(4";x
W6hz~*[r
W%7ov.
W8b$xFr
W&8L6]
},W8We$
_`w9HVX"
+#/``W9M
w]A(5*Z
WaitForSingleObject
waZ`#x
W,Bjxk
W_bmyF
Wf %<b
wFGK}k
WFS-7P
w[*Fwq64:
w$G+a\
wGCjFm
W\gO}X;
/wgtvtN
<>WH!	
`Wh9[W
w!&H@E
W"Hs$)
	wJ(k &
&WjKu"
)wjuq+
}_'Wk]
wKdFr(
wkjX5h
]wLM])
Wnk]k0
?WN	y*
(;wOuX
-!*wp9
wpU+= ~
wQ~	6D6
Wqp-XU
wREP F$
WriteFile
WritePrivateProfileStringA
	_WSnV
wsprintfA
W{t+I`
Wt?/ps6~
wT,!Q_
w`U!6x
W,uD{M
@^w'uw
Wv[}&+
+wvW^s
wV$zbk
"!<|ww
]WWjnmr35
W_XQt	
wxX3C~
Wy"Q|M
{w=Yz%
)WzpM|
/w~Z"~PZ;
x@,^@?
-X0ipy
?X3'*#
x-`3>Z
<-x5X2
X[6p=P
X6RfXM	
X*.~7~f
X,AJ.h"
xA$K'P|
?xCTsY
+xCwQ0
XcZj;G
xd!-|nF
[X_>e.
{xE-gd3
X(EojipNg0
xE;`-T
x+F)+=
\x{F[f
x},+~G
xg8(-a
X]G-L!
`$X(g";>Ws.zj
*xj*UI
 x?LpZ
x\M>55~
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
(xoB]nE
x.Ogf|
XoK4W)_7
Xp23.i
X*p|bp3*8
Xp^gu?
\XPh&F\
X/q.!\bx
`xQIr[
X\RuO\%l
*xSKpNDlz
XS:]UJ
_Xs @uK
,@xtAT
^xvEErj
xvH6c@
x@%])xw
XXZ8Ca%
#xZ#Tz
y}1JTP
y|[>-.$2
Y2c {Z
y2ERnCJ
y5F;Ey
Y`6I`m
Y7SbE"D'
y9.[z]
/Y;A6%
yA)7P;
yb ap9@
, "yB&m
y$BR]Z!
Yb%VQY
Y~cBtoNL
yDAl>x
Y-E;^A2>Kg
%yE%u0<
y<FC=Uit
yfV)Hp
#ykn:B
yl	RYwN#
ylu:d%
Ym+!Q~(:
Ym	TE8
Yn>^3f
yP6F$&M
\_y~p9
YqQs9&
YQv|:`
y^%`_*$?s
,}Y)s~
>]@Y#S
Ytk6#q
Ytx|.M?j
~yu@Jk
yv8TUU5
yve2yd
@!Y[WA%*%
yW.c7s
YW%&W8a
yX	A}W(,Y^
Y#;]X_+i-
Y`xiNM
)Yy9F!$
y~\y*@q
yz1IG\
\+_.z#-
z|:0*QP'
\-z0um
z2k kX
z2X{#w
Z3~z.x
Z6=e1&
Z8${e6X
za>Ln%
Z<:^bQqr
ZCjO&4U
Z:CpDL
Z:dmBr
^zd O!
zDX)d-
)zdYTy
zeX@^9
Z~f+'1
Zf4n	x
z?f+g	
Zfon0O
zH<5BBw
:z,#_I
#/zj@ 
 @Z^+j
Zjcrs!
_	zjjS
]zk4kjk
@zKC<iO
z%*/kq!
ZL4]z0
Zmd#6Pm_
zm`&J\u
Z] +\n
Zn	.7M0
z-O	^!
?-Zo8f
ZoDh|Jj
ZPLP%i39
;Z;#*PN
z=^q[(>
Z`qR4M
zTY7K^C`
zuAd130
=ZuurP
."z+vb!
~`)\zW
:(z}WY
zxo~Z60
zYR7dk-
/ZY!U"
zy!ycT9
zZe8\U3.fyx
Z]zu^g@