Analysis Date2018-04-22 17:11:32
MD52879668bcd76d9f047ebbe395c369280
SHA19709bddfb0cdbebb0cf2f3b42809058d26fbb122

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 0bc2ffd32265a08d72b795b18265828d sha1: dd2a446014a37556f39173b802c63a4e46e09366 size: 23552
Section.rdata md5: f179218a059068529bdb4637ef5fa28e sha1: 6035d27db526131eb0f29aee60cfcdbb5072ed7d size: 4608
Section.data md5: 975304d6dd6c4a4f076b15511e2bbbc0 sha1: 1f65340672c91ffd0f2583ff104beaece43c7855 size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: c4b5771be1ea0cf8c9046b82dca7d1ba sha1: 33d513919664558611b1df46a91c09beb7d768a8 size: 30208
Timestamp2009-12-05 22:50:46
PackerNullsoft PiMP Stub -> SFX
PEhash61e1378a95bd69acfb853aedfeb419efc7434c34
IMPhash099c0646ea7282d232219f8807883be0
AVArcabit (arcavir)Application.Bundler.CZ
AVAuthentiumError Scanning File
AVGrisoft (avg)Error Scanning File
AVAvira (antivir)TR/Dldr.Chindo.B.375
AVAlwil (avast)Downloader-VRF [Trj]
AVAlwil (avast)Trojan-gen
AVAlwil (avast)Win32:Trojan-gen
AVAd-AwareApplication.Bundler.CZ
AVBitDefenderApplication.Bundler.CZ
AVBullGuardError Scanning File
AVClamAVNo Virus
AVDr. WebTrojan.DownLoader11.31584
AVEmsisoftApplication.Bundler.CZ
AVMicroWorld (escan)Application.Bundler.CZ
AVCA (E-Trust Ino)Error Scanning File
AVFortinetW32/Chindo.B!tr.dldr
AVFrisk (f-prot)No Virus
AVF-SecureNo Virus
AVIkarusTrojan-Downloader.NSIS.Chindo
AVK7Error Scanning File
AVKasperskyError Scanning File
AVMalwareBytesError Scanning File
AVMcafeeGeneric StartPage.at
AVMicrosoft Security EssentialsNo Virus
AVNANOError Scanning File
AVEset (nod32)NSIS/TrojanDownloader.Chindo.C
AVPadvishNo Virus
AVCAT (quickheal)No Virus
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecNo Virus
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)No Virus
AVWindows DefenderNo Virus
AVZillya!Error Scanning File

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\9709bddfb0cdbebb0cf2f3b42809058d26fbb122.exe

Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
Creates FileC:\Users\desktop.ini
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\AppData
Creates FileC:\Users\Phil\AppData\Local
Creates FileC:\Users\Phil\Desktop\desktop.ini

Process
↳ C:\Windows\explorer.exe

Creates FileC:\
Creates FileC:\Users\desktop.ini
Creates FileC:\Users
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\AppData
Creates FileC:\Users\Phil\AppData\Roaming
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MusicForMac
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Creates FileC:\
Creates FileC:\ProgramData
Creates FileC:\ProgramData\Microsoft\desktop.ini
Creates FileC:\ProgramData\Microsoft
Creates FileC:\ProgramData\Microsoft\Windows
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
Creates FileC:\Users\Phil
Creates FileC:\Users\Phil\Desktop\desktop.ini
Creates FileC:\
Creates FileC:\Users
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
Creates FileC:\Users\Public\desktop.ini
Creates FileC:\Users\Public
Creates FileC:\Users\Public\Desktop\desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini
Creates FileC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\BaiduPlayerNetSetup_461.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\setup_3386.exe

Process
↳ C:\Program Files (x86)\Internet Explorer\iexplore.exe

Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Windows\System32\oleaccrc.dll
Creates File\??\Nsi
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\Cookies\Low
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\History\Low
Creates FileC:\Users\Phil\Favorites
Creates FileC:\Users\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\PrivacIE\Low
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\IECompatCache\Low
Creates FileC:\Users\Phil\AppData\Roaming\Microsoft\Windows\IETldCache\Low
Creates FileC:\Users\Phil\AppData\Local\Temp\Low
Creates MutexLocal\!BrowserEmulation!SharedMemory!Mutex
Creates Mutex
Creates MutexRasPbFile
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\VerCache ➝
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CompatibilityFlags ➝
0

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\9377chiyue_Y_mgaz.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\2345Explorer_329242_silence.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\ins1256858.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\IQIYIsetup_l_spl004@kb010.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\nsj9363.tmp\WanDouJiaSetup_runk4_kb.exe

Process
↳ C:\Program Files (x86)\Internet Explorer\iexplore.exe

Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Windows\System32\oleaccrc.dll
Creates Mutex

Network Details:

DNSint.dpool.sina.com.cn
Type: A
123.125.29.252
HTTP GEThttp://int.dpool.sina.com.cn/iplookup/iplookup.php
User-Agent: NSIS_Inetc (Mozilla)
Flows TCP192.168.1.1:1031 ➝ 123.125.29.252:80

Raw Pcap
0x00000000 (00000)   47455420 2f6e6373 692e7478 74204854   GET /ncsi.txt HT
0x00000010 (00016)   54502f31 2e310d0a 436f6e6e 65637469   TP/1.1..Connecti
0x00000020 (00032)   6f6e3a20 436c6f73 650d0a55 7365722d   on: Close..User-
0x00000030 (00048)   4167656e 743a204d 6963726f 736f6674   Agent: Microsoft
0x00000040 (00064)   204e4353 490d0a48 6f73743a 20777777    NCSI..Host: www
0x00000050 (00080)   2e6d7366 746e6373 692e636f 6d0d0a0d   .msftncsi.com...
0x00000060 (00096)   0a                                    .

0x00000000 (00000)   47455420 2f69706c 6f6f6b75 702f6970   GET /iplookup/ip
0x00000010 (00016)   6c6f6f6b 75702e70 68702048 5454502f   lookup.php HTTP/
0x00000020 (00032)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000030 (00048)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000040 (00064)   696c6c61 290d0a48 6f73743a 20696e74   illa)..Host: int
0x00000050 (00080)   2e64706f 6f6c2e73 696e612e 636f6d2e   .dpool.sina.com.
0x00000060 (00096)   636e0d0a 436f6e6e 65637469 6f6e3a20   cn..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f676f2f 66756c6c 2f312f37   GET /go/full/1/7
0x00000010 (00016)   30383836 20485454 502f312e 310d0a55   0886 HTTP/1.1..U
0x00000020 (00032)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000030 (00048)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000040 (00064)   0a486f73 743a2077 2e782e62 61696475   .Host: w.x.baidu
0x00000050 (00080)   2e636f6d 0d0a436f 6e6e6563 74696f6e   .com..Connection
0x00000060 (00096)   3a204b65 65702d41 6c697665 0d0a4361   : Keep-Alive..Ca
0x00000070 (00112)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000080 (00128)   63616368 650d0a0d 0a                  cache....

0x00000000 (00000)   47455420 2f6e6373 692e7478 74204854   GET /ncsi.txt HT
0x00000010 (00016)   54502f31 2e310d0a 436f6e6e 65637469   TP/1.1..Connecti
0x00000020 (00032)   6f6e3a20 436c6f73 650d0a55 7365722d   on: Close..User-
0x00000030 (00048)   4167656e 743a204d 6963726f 736f6674   Agent: Microsoft
0x00000040 (00064)   204e4353 490d0a48 6f73743a 20777777    NCSI..Host: www
0x00000050 (00080)   2e6d7366 746e6373 692e636f 6d0d0a0d   .msftncsi.com...
0x00000060 (00096)   0a                                    .

0x00000000 (00000)   47455420 2f676f2f 6d696e69 2f322f33   GET /go/mini/2/3
0x00000010 (00016)   30383633 20485454 502f312e 310d0a55   0863 HTTP/1.1..U
0x00000020 (00032)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000030 (00048)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000040 (00064)   0a486f73 743a2077 2e782e62 61696475   .Host: w.x.baidu
0x00000050 (00080)   2e636f6d 0d0a436f 6e6e6563 74696f6e   .com..Connection
0x00000060 (00096)   3a204b65 65702d41 6c697665 0d0a4361   : Keep-Alive..Ca
0x00000070 (00112)   6368652d 436f6e74 726f6c3a 206e6f2d   che-Control: no-
0x00000080 (00128)   63616368 650d0a0d 0a                  cache....

0x00000000 (00000)   47455420 2f636c69 636b2f36 36393437   GET /click/66947
0x00000010 (00016)   20485454 502f312e 310d0a55 7365722d    HTTP/1.1..User-
0x00000020 (00032)   4167656e 743a204e 5349535f 496e6574   Agent: NSIS_Inet
0x00000030 (00048)   6320284d 6f7a696c 6c61290d 0a486f73   c (Mozilla)..Hos
0x00000040 (00064)   743a2073 2e6c6c6c 736f6f2e 636f6d0d   t: s.lllsoo.com.
0x00000050 (00080)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x00000060 (00096)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x00000070 (00112)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x00000080 (00128)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f676f2f 6d696e69 2f382f33   GET /go/mini/8/3
0x00000010 (00016)   30303030 30343620 48545450 2f312e31   0000046 HTTP/1.1
0x00000020 (00032)   0d0a5573 65722d41 67656e74 3a204e53   ..User-Agent: NS
0x00000030 (00048)   49535f49 6e657463 20284d6f 7a696c6c   IS_Inetc (Mozill
0x00000040 (00064)   61290d0a 486f7374 3a20772e 782e6261   a)..Host: w.x.ba
0x00000050 (00080)   6964752e 636f6d0d 0a436f6e 6e656374   idu.com..Connect
0x00000060 (00096)   696f6e3a 204b6565 702d416c 6976650d   ion: Keep-Alive.
0x00000070 (00112)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x00000080 (00128)   6e6f2d63 61636865 0d0a0d0a            no-cache....

0x00000000 (00000)   47455420 2f666176 69636f6e 2e69636f   GET /favicon.ico
0x00000010 (00016)   20485454 502f312e 310d0a41 63636570    HTTP/1.1..Accep
0x00000020 (00032)   743a202a 2f2a0d0a 41636365 70742d45   t: */*..Accept-E
0x00000030 (00048)   6e636f64 696e673a 20677a69 702c2064   ncoding: gzip, d
0x00000040 (00064)   65666c61 74650d0a 55736572 2d416765   eflate..User-Age
0x00000050 (00080)   6e743a20 4d6f7a69 6c6c612f 342e3020   nt: Mozilla/4.0 
0x00000060 (00096)   28636f6d 70617469 626c653b 204d5349   (compatible; MSI
0x00000070 (00112)   4520382e 303b2057 696e646f 7773204e   E 8.0; Windows N
0x00000080 (00128)   5420362e 313b2057 4f573634 3b205472   T 6.1; WOW64; Tr
0x00000090 (00144)   6964656e 742f342e 303b2053 4c434332   ident/4.0; SLCC2
0x000000a0 (00160)   3b202e4e 45542043 4c522032 2e302e35   ; .NET CLR 2.0.5
0x000000b0 (00176)   30373237 3b202e4e 45542043 4c522033   0727; .NET CLR 3
0x000000c0 (00192)   2e352e33 30373239 3b202e4e 45542043   .5.30729; .NET C
0x000000d0 (00208)   4c522033 2e302e33 30373239 3b204d65   LR 3.0.30729; Me
0x000000e0 (00224)   64696120 43656e74 65722050 4320362e   dia Center PC 6.
0x000000f0 (00240)   30290d0a 486f7374 3a20662e 73687569   0)..Host: f.shui
0x00000100 (00256)   616e7368 616e6261 2e636f6d 0d0a436f   anshanba.com..Co
0x00000110 (00272)   6e6e6563 74696f6e 3a204b65 65702d41   nnection: Keep-A
0x00000120 (00288)   6c697665 0d0a0d0a                     live....

0x00000000 (00000)   47455420 2f6e6373 692e7478 74204854   GET /ncsi.txt HT
0x00000010 (00016)   54502f31 2e310d0a 436f6e6e 65637469   TP/1.1..Connecti
0x00000020 (00032)   6f6e3a20 436c6f73 650d0a55 7365722d   on: Close..User-
0x00000030 (00048)   4167656e 743a204d 6963726f 736f6674   Agent: Microsoft
0x00000040 (00064)   204e4353 490d0a48 6f73743a 20777777    NCSI..Host: www
0x00000050 (00080)   2e6d7366 746e6373 692e636f 6d0d0a0d   .msftncsi.com...
0x00000060 (00096)   0a636f6d 70617469 626c653b 204d5349   .compatible; MSI
0x00000070 (00112)   4520382e 303b2057 696e646f 7773204e   E 8.0; Windows N
0x00000080 (00128)   5420362e 313b2057 4f573634 3b205472   T 6.1; WOW64; Tr
0x00000090 (00144)   6964656e 742f342e 303b2053 4c434332   ident/4.0; SLCC2
0x000000a0 (00160)   3b202e4e 45542043 4c522032 2e302e35   ; .NET CLR 2.0.5
0x000000b0 (00176)   30373237 3b202e4e 45542043 4c522033   0727; .NET CLR 3
0x000000c0 (00192)   2e352e33 30373239 3b202e4e 45542043   .5.30729; .NET C
0x000000d0 (00208)   4c522033 2e302e33 30373239 3b204d65   LR 3.0.30729; Me
0x000000e0 (00224)   64696120 43656e74 65722050 4320362e   dia Center PC 6.
0x000000f0 (00240)   30290d0a 486f7374 3a20662e 73687569   0)..Host: f.shui
0x00000100 (00256)   616e7368 616e6261 2e636f6d 0d0a436f   anshanba.com..Co
0x00000110 (00272)   6e6e6563 74696f6e 3a204b65 65702d41   nnection: Keep-A
0x00000120 (00288)   6c697665 0d0a0d0a                     live....

0x00000000 (00000)   47455420 2f642f69 6e733132 35363835   GET /d/ins125685
0x00000010 (00016)   382e6578 65204854 54502f31 2e310d0a   8.exe HTTP/1.1..
0x00000020 (00032)   55736572 2d416765 6e743a20 4e534953   User-Agent: NSIS
0x00000030 (00048)   5f496e65 74632028 4d6f7a69 6c6c6129   _Inetc (Mozilla)
0x00000040 (00064)   0d0a486f 73743a20 672e7175 77656e33   ..Host: g.quwen3
0x00000050 (00080)   32302e63 6f6d0d0a 436f6e6e 65637469   20.com..Connecti
0x00000060 (00096)   6f6e3a20 4b656570 2d416c69 76650d0a   on: Keep-Alive..
0x00000070 (00112)   43616368 652d436f 6e74726f 6c3a206e   Cache-Control: n
0x00000080 (00128)   6f2d6361 6368650d 0a0d0a              o-cache....

0x00000000 (00000)   47455420 2f687a2f 49514959 49736574   GET /hz/IQIYIset
0x00000010 (00016)   75705f6c 5f73706c 30303440 6b623031   up_l_spl004@kb01
0x00000020 (00032)   302e6578 65204854 54502f31 2e310d0a   0.exe HTTP/1.1..
0x00000030 (00048)   55736572 2d416765 6e743a20 4e534953   User-Agent: NSIS
0x00000040 (00064)   5f496e65 74632028 4d6f7a69 6c6c6129   _Inetc (Mozilla)
0x00000050 (00080)   0d0a486f 73743a20 646c2e73 74617469   ..Host: dl.stati
0x00000060 (00096)   632e6971 6979692e 636f6d0d 0a436f6e   c.iqiyi.com..Con
0x00000070 (00112)   6e656374 696f6e3a 204b6565 702d416c   nection: Keep-Al
0x00000080 (00128)   6976650d 0a436163 68652d43 6f6e7472   ive..Cache-Contr
0x00000090 (00144)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x000000a0 (00160)                                         

0x00000000 (00000)   47455420 2f6f7065 6e2f7365 7475705f   GET /open/setup_
0x00000010 (00016)   33333836 2e657865 20485454 502f312e   3386.exe HTTP/1.
0x00000020 (00032)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000030 (00048)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000040 (00064)   6c61290d 0a486f73 743a2064 6f776e2e   la)..Host: down.
0x00000050 (00080)   79696e79 75652e66 6d0d0a43 6f6e6e65   yinyue.fm..Conne
0x00000060 (00096)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000070 (00112)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000080 (00128)   3a206e6f 2d636163 68650d0a 0d0a       : no-cache....

0x00000000 (00000)   47455420 2f66696c 65732f74 68697264   GET /files/third
0x00000010 (00016)   2f57616e 446f754a 69615365 7475705f   /WanDouJiaSetup_
0x00000020 (00032)   72756e6b 345f6b62 2e657865 20485454   runk4_kb.exe HTT
0x00000030 (00048)   502f312e 310d0a55 7365722d 4167656e   P/1.1..User-Agen
0x00000040 (00064)   743a204e 5349535f 496e6574 6320284d   t: NSIS_Inetc (M
0x00000050 (00080)   6f7a696c 6c61290d 0a486f73 743a2064   ozilla)..Host: d
0x00000060 (00096)   6c2e7761 6e646f75 6a69612e 636f6d0d   l.wandoujia.com.
0x00000070 (00112)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x00000080 (00128)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x00000090 (00144)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000a0 (00160)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f73696c 656e6365 2f323334   GET /silence/234
0x00000010 (00016)   35457870 6c6f7265 725f3332 39323432   5Explorer_329242
0x00000020 (00032)   5f73696c 656e6365 2e657865 20485454   _silence.exe HTT
0x00000030 (00048)   502f312e 310d0a55 7365722d 4167656e   P/1.1..User-Agen
0x00000040 (00064)   743a204e 5349535f 496e6574 6320284d   t: NSIS_Inetc (M
0x00000050 (00080)   6f7a696c 6c61290d 0a486f73 743a2064   ozilla)..Host: d
0x00000060 (00096)   6f776e6c 6f61642e 32333435 2e636e0d   ownload.2345.cn.
0x00000070 (00112)   0a436f6e 6e656374 696f6e3a 204b6565   .Connection: Kee
0x00000080 (00128)   702d416c 6976650d 0a436163 68652d43   p-Alive..Cache-C
0x00000090 (00144)   6f6e7472 6f6c3a20 6e6f2d63 61636865   ontrol: no-cache
0x000000a0 (00160)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f426169 6475506c 61796572   GET /BaiduPlayer
0x00000010 (00016)   436f6e74 656e742f 42616964 75506c61   Content/BaiduPla
0x00000020 (00032)   7965724e 65745365 7475705f 3436312e   yerNetSetup_461.
0x00000030 (00048)   65786520 48545450 2f312e31 0d0a5573   exe HTTP/1.1..Us
0x00000040 (00064)   65722d41 67656e74 3a204e53 49535f49   er-Agent: NSIS_I
0x00000050 (00080)   6e657463 20284d6f 7a696c6c 61290d0a   netc (Mozilla)..
0x00000060 (00096)   486f7374 3a20646c 2e703273 702e6261   Host: dl.p2sp.ba
0x00000070 (00112)   6964752e 636f6d0d 0a436f6e 6e656374   idu.com..Connect
0x00000080 (00128)   696f6e3a 204b6565 702d416c 6976650d   ion: Keep-Alive.
0x00000090 (00144)   0a436163 68652d43 6f6e7472 6f6c3a20   .Cache-Control: 
0x000000a0 (00160)   6e6f2d63 61636865 0d0a0d0a            no-cache....

0x00000000 (00000)   47455420 2f393730 39626464 66623063   GET /9709bddfb0c
0x00000010 (00016)   64626562 62306366 32663362 34323830   dbebb0cf2f3b4280
0x00000020 (00032)   39303538 64323666 62623132 322e6578   9058d26fbb122.ex
0x00000030 (00048)   652f3430 2e6a7067 20485454 502f312e   e/40.jpg HTTP/1.
0x00000040 (00064)   310d0a41 63636570 743a202a 2f2a0d0a   1..Accept: */*..
0x00000050 (00080)   41636365 70742d4c 616e6775 6167653a   Accept-Language:
0x00000060 (00096)   20656e2d 75730d0a 55736572 2d416765    en-us..User-Age
0x00000070 (00112)   6e743a20 4d6f7a69 6c6c612f 342e3020   nt: Mozilla/4.0 
0x00000080 (00128)   28636f6d 70617469 626c653b 204d5349   (compatible; MSI
0x00000090 (00144)   4520382e 303b2057 696e646f 7773204e   E 8.0; Windows N
0x000000a0 (00160)   5420362e 313b2057 4f573634 3b205472   T 6.1; WOW64; Tr
0x000000b0 (00176)   6964656e 742f342e 303b2053 4c434332   ident/4.0; SLCC2
0x000000c0 (00192)   3b202e4e 45542043 4c522032 2e302e35   ; .NET CLR 2.0.5
0x000000d0 (00208)   30373237 3b202e4e 45542043 4c522033   0727; .NET CLR 3
0x000000e0 (00224)   2e352e33 30373239 3b202e4e 45542043   .5.30729; .NET C
0x000000f0 (00240)   4c522033 2e302e33 30373239 3b204d65   LR 3.0.30729; Me
0x00000100 (00256)   64696120 43656e74 65722050 4320362e   dia Center PC 6.
0x00000110 (00272)   30290d0a 41636365 70742d45 6e636f64   0)..Accept-Encod
0x00000120 (00288)   696e673a 20677a69 702c2064 65666c61   ing: gzip, defla
0x00000130 (00304)   74650d0a 486f7374 3a20662e 73687569   te..Host: f.shui
0x00000140 (00320)   616e7368 616e6261 2e636f6d 0d0a436f   anshanba.com..Co
0x00000150 (00336)   6e6e6563 74696f6e 3a204b65 65702d41   nnection: Keep-A
0x00000160 (00352)   6c697665 0d0a0d0a                     live....

0x00000000 (00000)   47455420 2f536f48 7556415f 342e332e   GET /SoHuVA_4.3.
0x00000010 (00016)   302e312d 63323034 39303030 30332d6e   0.1-c204900003-n
0x00000020 (00032)   672d6e74 692d732d 782e6578 65204854   g-nti-s-x.exe HT
0x00000030 (00048)   54502f31 2e310d0a 55736572 2d416765   TP/1.1..User-Age
0x00000040 (00064)   6e743a20 4e534953 5f496e65 74632028   nt: NSIS_Inetc (
0x00000050 (00080)   4d6f7a69 6c6c6129 0d0a486f 73743a20   Mozilla)..Host: 
0x00000060 (00096)   736f6875 74762e7a 796a6b77 65616c74   sohutv.zyjkwealt
0x00000070 (00112)   682e636f 6d0d0a43 6f6e6e65 6374696f   h.com..Connectio
0x00000080 (00128)   6e3a204b 6565702d 416c6976 650d0a43   n: Keep-Alive..C
0x00000090 (00144)   61636865 2d436f6e 74726f6c 3a206e6f   ache-Control: no
0x000000a0 (00160)   2d636163 68650d0a 0d0a                -cache....

0x00000000 (00000)   47455420 2f323031 34303430 312f3933   GET /20140401/93
0x00000010 (00016)   37376368 69797565 5f595f6d 67617a2e   77chiyue_Y_mgaz.
0x00000020 (00032)   65786520 48545450 2f312e31 0d0a5573   exe HTTP/1.1..Us
0x00000030 (00048)   65722d41 67656e74 3a204e53 49535f49   er-Agent: NSIS_I
0x00000040 (00064)   6e657463 20284d6f 7a696c6c 61290d0a   netc (Mozilla)..
0x00000050 (00080)   486f7374 3a207869 617a6169 2e393337   Host: xiazai.937
0x00000060 (00096)   372e636f 6d0d0a43 6f6e6e65 6374696f   7.com..Connectio
0x00000070 (00112)   6e3a204b 6565702d 416c6976 650d0a43   n: Keep-Alive..C
0x00000080 (00128)   61636865 2d436f6e 74726f6c 3a206e6f   ache-Control: no
0x00000090 (00144)   2d636163 68650d0a 0d0a                -cache....


Strings
 " "
EH.
1s%P
bsJP2
Js2P
msctls_progress32
MS Shell Dlg
Please wait while Setup is loading...
ssPP
SysListView32
^,& }$:=
=[- >-
        
-!>-+:
/:=.= 
*?|<>/":
	)&:}-
01;v=(J&se
0 1@;Z
03|(+,
05 Z[&
05Z~6/
068'!d3
0`8~10
082An#
.0 B$yZ
>0B$_z
{';0C'
0C}8b?
0Da@-r
0D{g98"t
(0%D=L
0e7;<Z
_0f mI
0F>VPx
0F?w|l
0gp;'T
0Hz"$+
0 K6|_gb
 0khOcj4
0\koNn
0M5K0zG
0NH	U>
0O6a~(Nl
0	=oDD
0PeTk|
;0$@qD
@0r;\'
0SU4DC
0s;W\X
0t~SPG
/	0[Va^
0vFMH 
0WIRHC
0,]$Z>,
0[zV$yl
:\_'1	
100519104300Z
10 uh, J
111~SSS
121018000000Z
121221000000Z
12GwiE
130519105400Z
13AP&/lm
140907163813Z0#
150519105400Z0
\1; #8
1[Ai/z
1=B,{A
1_cK0$
}1Ec[l
1f\^W;
;-1i[g<r
1j&3OF
1jM\@S
1Jt7<0
*1lAHA
1lEc7VZ
1M:zqf
1,*n3f
;1N?d0
1nJ*KR
]1NvmD
1o$XTT
1q1r~d"
}1r".['
1sE>	^
 1Swf2g
1*s)x0
#1$Ti[
$1T(o 
1V$z!oV
1)-X9I3
1=xxg@
1.y0`,
$$1+Zx
200519104300Z0X1
200-[78
201229235959Z0b1
201230235959Z0^1
20(&Sr
211=}Twe
]21u /
=22}%*
;]23ea
")2[6\
2;8kDe
2A+$w3
2boxK%
2HtJ-eG
2{H.wQk
2I	2M8
2\Jl#W
2KDV&&
2;KQMF
2")ob'
2[Pj!r
2,Q'<ac
=2(tsP
2'tTWks
2U44+$
2;v4i0
2Vorx@
2VY{Ii
2>Xasc
2?x(Ok
2Ygk=A
$/3!']
*(\3?,
31I:M|!
32gq@#
=\32j,
3330XXX
+3|4i*
35ZRqU
360}As_
36EU(Epg
39TwDd
39Vhxi
`*3[9#w
3aAf[d
3A^g`<'
3AjJky$`1K
=3,AtR
3B:'fK
3;BHR"$
^3C4Fg
3=cMR(
:=3CrH
3d;Y@6
3ebRV+
3E-o0c
3EXnRD
3)EY_q
3!_FNY
3f}UM\
(3`[`G
3g(R<`H
3j[{3bn
3J`6fT
3jAot'
~/3J!K
3KAwH^
3_lOyk
3lq.O?
3M]{3A
3M~<hnQ6
3;"<ml&R
3{!]OD
3P7[Gg$
*~/3qEq
3q)ky|
3^=rR|
3~u0}}
3ums]V
|3vE9Aaa
3Vqc'qK
3]w?jH
3?y2x'
3#'yip
3z 4	KV)
45W}e<
45Yt]#TF
4+7~#6K
47#s4k
]_4%8&
)4)<<b
4B$mx::9
4c[>@(D
4CNsXP
4\E=kp
\4e;QeDPF
4fq/9bW
4gjR	r
^4gWv\
4GY;S_
4hn4!&
4,`^I`+
4ijjZf
4iO|i<
4iqjdj
4]J^Hqf
4"==k,
4	k,bd
4?[kIW}
4_#kXT
4mT`Rqp
4n=C;pQ(LaZ
4nGf[nn
4[|nod
\4P*Jr
["4QLS
4qZ:_h
?4r]] 
4?RjV,
4-SFv9
4U3XKd
4\WpL&l
4W)V=W
_4x{"Uw`X
<'4Yk:
4\`yP3
$$+5! .
+5]#$3
= 53cANE~
53*wy~9
<.54lZ
5| ;bL
5d,D|tI
5e"^pM1nT
{5eVv.
5f>%CWrv
5g.f!sK
.5)ggI
5Gm\yM
5hGiO	]Q
5I"nmN
5kLu0>
=5=L^|
5=L<B?N3
:5{M%q
5/N2b2.1
+5N	M"Y
-5n_T[
5	oHc(
5pA;75
5qm7V\
5qQA^yV
5s$6`9
.5#/T}9
5't&C4
5TwcS/d
5v&{:DL7
]\5]\W
5zrg|&J
6_0+,p`
=^61oko
61QOO{
|<62bw9
`6*5T`
66xtT'
:6&%7J
6>9gyJ
.{6b\m'
6c SrDW1
6dB^pN
6dGT.RKa
6DsH5}mp
6dVvU7
6#e3@qBK
6ePU<0U
6E?V=o
6_ewy#
6fe;HKn
6gtN}!
{6Gu2I
6]H@1kC
6I6/f5
6	{.J/
6']j/4H
6Jsh6f
6K*`9x
6&KH[ 
6Lj~T8,
(6Mu%J~
6$m`X2
6nS})4
.6"PYTB
6S-zSN
6.V/n9	
6vq[X`P
6X\EA.A-
6y_wk+
-6Zhmk
6ZmHHk
6\ZM	N8w
6Zo<l=D0r"
~6|zq:
7+2A8j
73Yq	3
.`7[4K&S
+74XAA
76L"k"
7]';6t
@@@`777-
789 \p2
78.oM5
79ytc*
7a'*&(
7]A1Eq
+7aN#8n
7>- &b
7b,%G+
7Bg8ah
\7CMR	/
:7=[-d
@7Db7p
=`7DL!
7,f F;
7)	fQ.
7FW~{az'
~7GIJU.
7Gm\Mi
+7}@h}6L
7H8I'@
 7I$R2	h
7;iuVT
7%JAn;
7nLS{B
7n)%Sb
7o{IP"E/m$^
7OXas'
7Plm,_e
7PRA7o
7#"PtL
7puI%c !
7|pY,y
'$7Q>#
7qU7}vbqk%
7R[[7{ko)uyO
#7-rGb
7tTCd'l
}7 U>/7
^7U`I6
\{7Umc
7U$+Y!1>+
7W@G_	J
`!7XHgZ
7%'@XL
,7Xm2^
7:/>Y&
'}7>Y~E
7Z>&wp
(_`&_&8
] +8?"
!80Y[uf
8.4st;
8~!.\7@
8{85Oe
#8!9IT
8a/D$y"=
8#a?K+f
8B1R5l
8c&M)'dH
{8dI	U
8\dm,4
8_k6%&
8k~p?>G?J
8^k|+UV(R
8l1B0-9
8	l}H?
8lT/+|
?8m[ M
8mSJ~j
_8(&N<
8NCRCu
8t~>IKR>
 '8T|k
8uS]:{C
8V/*Y1
8$W&`[
<8WU_]-
8]X	X 
=8xYQP
8y}iCJ
8ytNMQ
8.|>z<E
@8z'QL
@	,<~9
$9"?:&
"900]}
91/K[/
$.92L^x
94k\bbd4
'9-5AC-	C
/9}5Zv
97hcyA
_;9943b
99hQxI
9'B#OL
9|C\hgZ
'9DZ+r2
<[9E/5B
9*fDLMX
-*9>"g
9+~G,D
9g?&F%%
9)JNkL2
9jN!ktW
9kH,jz
)9[&l)
9,=m97z
9[+MH<
&9$:n9
9Nyx*H
9o#>/!
>9<o2w
{9o!bz{
9O=j*-
9P'Xzg"
9SJY.S
=~-9[t'
9|tplV=
,9|X.^
9<y^fm
 9zD*G
9?/zt3
9Zwwdo
a2kKtR
A5fMA+
A6e3I	
A8h*r*
/a8q)b
@(a9j,1
Aa5>6n
AAA_ggg
aA;/NDz7X#,
aa,p\"
A@AYy6
a%Bpds
?|A?c>
!A~ca0
AcZ&nf
`~a!?:d
	a)!D4
'aDa[=
AdjustTokenPrivileges
ad@)k;
+A<d l
;ADPU|X
ADVAPI32
ADVAPI32.dll
ae`!/	
aE@[Xe
aeXm^aN
a-?FH^
aH6OiE
@AHbka
'Ah'|l
,$ah'Tf%
a~&hX/
.a#i$5
a~)iI-7^
A;?i{O
+AJ6S[FU
aJO/)?>
$AjQXw
!aj~`W
'=a=JYI
AkK?"L
&	ak?o
al1)G#
A!&l*+l
A.LMnv`i
alYyH6
aMwBi7
|a>n50W K
*anhYp
)An/"`P
Ao6\	C!%
ao-v^}
<A@O-W
A$=P@:
@+aPo*
AppendMenuA
A/p "xC
A(qGh%
aq[V6[m
$ar>;`
!Ar_#+
&arK6_
At@<IZ
*A\u/]
AuR6VF
AVz:V\
&_};Aw
aw=j+9
aX2B7.
Ax	2(J
aX(DJB,
ax<&+g
AxxY^#
.a{Y?(<
AYoHF.
a]zbave
$B0naU?$b
*|!B)2
B3%	7<
$b4N@0
B)?,54
b/&5G	$
b(5hax
b7N(a`
B8Tbz!/f<
b*9eT|
B/=][9r
BA2?A9
<?ba\>5
":b\[AZ);
BB&2}5K	B
&bB	8`
BBBp;;;>
|\bc5M
BE47j'
^be9ur
BeginPaint
bEo_&Y%
bE/w{xa0
BfC(m3
b-F($'e
Bf{t`9
|bFw}#
Bfx(VH#
B[hDFh^`
B/i|02
bI,0ol5
>BJ1#hU
Bj>%x^A
:?bk=%
b@k@"?
=Bk_1l
Bk"aV+
BlsJLhl:
bM0[a`
b^$Mmb|.
`_#b[N`
bnAEbA
bNYQ80XY
;boFdqs
bo,,htC
BOvj,ZjpG
bOW{0R3Q
B)Pm>7
bpmPXl
bpx]Ho
BQLv%P
bR73,E
BRhOci
BSI/.;
bSXpI8KS
}bt=$	
}>B/,t
<BT722
btGV	r
b\TO{-
b'U2ag|
b/}vr 
}Bv~yU
bwLbbS
BW~PuY
/bWv!E
BX$Gr9m6
.b|YPZ
bz#96"5
b-zje*W
	C0Y	/o
C1J$K(#
c3;&uA;/N
 ^>C;5
[C_<(5
$c5om 
C ~5w4t
c}60Uq
c\6O& R"
c6ur[8
{c8[\w
c+agO6m
CallWindowProcA
Caq%g%I
Cb3!{[[
C^bx	=
CCo:uW`9
]c@cuz
|cdi*(
cDIR>3
c`,D@J}
ce bnY
ce:\nE-G2
cEt]i4ak
CFQ?)g
cFs08x
cgmW""
CGytl&
CharNextA
CharPrevA
CheckDlgButton
ch*imv!
cHS9N$
c_Ij@4	
C]iq3G
Cj3/]>
c+jYhO:!N
{}ckK[M
CK^::[l
CloseClipboard
CloseHandle
cm^; r{
cM	xJCY4
CN1%0#
Cn3rCT
-/cNeGh
_C.N]K
C=n"L=
CNLsMI
 Cno?]
c%>"=o#
CoCreateInstance
cO\)jA
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
>:COq~
CoTaskMemFree
+cP6\g
C	p70W
-\c=pIWdb
CQ/h]m
c@qLI*
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
%CRVdY
|C`-.S
_cSItP
cSSP8S
cT|CE;
Cth r,
CTmuiu
c)|U6o
CUD0hz(
cUKdvA
cv-lC4|
 cv?[M	
CvNX	R
cWe-eTj
.cW:ig
Cwx)u.cG1
#cX^-~
C<<"*X
CX=W5}
cy%/%A
}c\y'A?N
CY$tJ3
C	yXuc
#cZ].,gS
cZ}~xR
... %d%%
D$0+D$(P
D2"m93
=|d2Y7
>D5b$p8
D^!(5l
`D6XC4x
d;)7ay
DARe{%
D!A:rJs
@.data
\da-`x
*db#6g
d$bA9#
d	bg}?
dBu"nZo:S
@Dca[d
DC*`nA]
dc{odadm
|dc&Q`
?d:%CS
d.#D$[^
DDDI{{{
D$(+D$ SSP
d#=.Dwr$1
:d]e2`0
.DEFAULT\Control Panel\International
DefWindowProcA
DeleteFileA
DeleteObject
DestroyWindow
@DE)yN
d._eyW
D\@'&h
dh@&=8(
d@HG1z+
`>DHOm
DialogBoxParamA
dI;| \C%g
DispatchMessageA
Di	yuk
D?$J<j
Dj&}zI
{d.K?<
Dk.:$`
dK9KF;
[D(k+G
d?KYzCp
@dLc%2
}-DNB6(y
D"No}$P
dO1eH0
@do]H2i
)DOP"D
D>P^]]
|!DP;DlO
dPq!MN
 DQ(*)
D@_qN`
DR{~18
DrawTextA
drdo3V
D$(SPS
Ds@|U}
dS#xZrP
dTq7#!
''DTQfq
dTuyX;/
duC-/_
Durbanville1
duttw(
dVAY\;
D;V:Jv
D>$VSA
DVvV7#
d";]W_
)DwlY~
dY*bpq
dYl-fS
DzG@EU
dz!Q:c
};'(&e]
<_\E',
E00{;P
e}0EKX
#e1CFkX
E1lkt~
]e5_?"G
E5G\(4
e5J=L5
E5w\NC
*E7}0Ja'2V
'^/<E7H
;E7M_=
;E7s0s
E9b`\n
E<A^A(u
EaBDA:
:eb)"-
E^}	@?b
!(!EBsO
E	"CFI
e/CL?r
ECN}!XA
{e{c Oeq
e-d|#0
e+D]`<G
|E;+dLb
ED_U4=
e]d#wMl?
e=`^%e
eeeeeeeee
&e$eV6
<*ef<<#
eg%g|WK
Eg%-Sp;@Q
Eh!;D	\
-	E(HH
Ei<8/6
=EibkH
	EiiwD
+Eij0t
eizN{T
EjTVg^kf
E$J!v_(
eLbz4E
ellRaZ
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
E(N O?
e>n+Wa%
E"obul
E\oD<B
>EOViY
?EP4	M
E+-/pq
\E	Q^@
 Eqf~9[}
E&r~P|
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
eSJ\,)b
EsW(lC
\e	t|'
eT>4B07
ETe$	e
_	$eU:
ev/=1mB/
e,v\ xSM
ewA=Bu
EWG$[Q
ex3!y|
e x9&?E
>e|xH|.]4
ExitProcess
ExitWindowsEx
#exm.-
ExpandEnvironmentStringsA
(eXQu;s
<Exwfm
E[YfDV
eYk("D]
e[Yv?q
F,'$	)
f]+~"0
F02KLw
)&F0B2
f1?G0r
:f1Q\]
f<5^	G
F6&zH{
%&@F74
F@7|Zq
f=7Z*xRo
f8Mzp#
!f"aRG\
F#]AX-8
fcaacopefm
FDDUif:
fdE_*Z9+
.Fe0Ix
FE?1:A
<Fed5E
!F+=eS
{fE-zEe
FFF#LLL
F_fZ#>
,`FG3~
.`Fg8v
FG	fe2
fGqNB(!
}fh@=<
fhH`@9
]!f;Hrt
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
*{FJ].~
> F:j8/
FJ,9^N
f jv*5
{Fk#V.G~
fK'.	W
F!lpp4Y{
FLqu[ADn
>%.FM}
%!}Fmw
Fn/ _[
FN7bnV
FNNNN@
~FN)x<$
f"n&^%ys@
fO9+f%
f&p]85
f@p]g1
F{ph:5
f:{PS2
f<q]7mJ#s\
FreeLibrary
F,R/	h
F**r+Y
FSJ-)&!
+FS-vm0
f-^t24f}+R
fTfL7Y<
ftuCYN
FUj,%O
fuw~WOQl
FuZA)}M
fv?B$5/
fVK`x`
f}v+nQ
))Fw"+>
/{FW/	
	fW^QT
{F=W$s
fw;VUu
	!f,xr
FZ9oEo@
fzZ`EX
!?g0@c
G0np3Ao
<g0u,y
<G36sk'
/G3qX]
G4'}D)
,G4K^{
G6	8-Dj
G6j]$7
g=6;\L
G6.#S%d
g]6 .u
g6ZFL[
g7rLal;
\G^[7Y
g8^gXl
}{:g 9
]g9CVD?+
GaajK[
ga/CEO
ga?"`cwY1
gaVJn&
GB`&yk!
GC.90R
{G^D_d
GDI32.dll
gdm$%t
Gdy@*1
GdZ7Mv
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
ge{VI%
_gf751{h
gG8pJU4P
Gh4=j+
<Gh<9O
G<)h!s2
G}|I;+.@
gj kkM
~/?g[K
gKLomK
gl+d6(_
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
gl]p6\
+gM`{I?O
gnQ3}'
GNu	Fre
G{NU_r
+gOD*Y
!gOv4n
G=Ow}C
Gp@8vt
G{Pb1\
g+q.;,)
Gru)r@
G%\<rW,.
GsT }-H"
gT!93k	
;gtBRf
/,Gte,
<GtEY/
gtkcap 
G!tNKoQR
GtP<~Z
GU3#.Vi,
<{Gwfr
_gWFyR
Gwv,!U
GwVX&%F
%Gx#}\/
GXcH0Ry:b
Gx<hqt}
GxJTJ 
[gY{a{
G@YiiO> 
GYN` F*ur
G/y[nY*
G ZN	9J{
|H!]/@|
H`1_8<
!H38`W
H3/a?'
h3P^BN
h3(%swb
H4@7c`
=h4RG7
H4WXJh
h5{eQ=
h5Ioxj
?h!6Hc
h8TP3k
h9kehI4
h/&)9S
/h.*{B
hbOBM.
H cCL1
)]heSS
hH}/!K
,hI6lB_
].hieK/?
^hi<_k
%H }il
hJVjTN
hk*]o	
' H<l9
hmv)tD
|@hmW3
h:M)zk
,HnJ,E
h)nJER
ho9Jvg	
_hOl?u
}ho	nb
HPH}DS_F
H~p/I_
&HPVl7
)&hq02
Hq_NyL
hqR);A
'HQ/v	
hqVAjF
HqW)O#}
hrf@Xi
hrhkGT
hS85(h
hT<%&n
http://aia.trustasia.com/ca.cer0
!http://aia.trustasia.com/code.cer0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
http://crl.trustasia.com/ca.crl0;
!http://crl.trustasia.com/code.crl0=
http://nsis.sf.net/NSIS_Error
http://ocsp.thawte.com0
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
http://ts-ocsp.ws.symantec.com07
htyxvL
'hUS~#
H!VFNMX 
h;vWfw4_
_HVX	o
HW<`1`0
h(Wi+j6l
h!}x{{{
:/hX["'
hxkjUyN
 Hx^o?j
HXv5<e
>h~Z1G
HZbURh;
'I+1=f
I23P#k
i?,34N~
i:3)6L
<I3Bz`
+I3Gg2
!I4('Z\uPL-
i50{9:
I	[7j>U
i"7n1c1
i7z~zPr
I8{{T!
I9\4gj
i-9,k!j*
&>?i_a3
ia7H28
`/!iAo3
,I;$aXTdm]
I*`/B 
IB01V:3
]Ib51N*
iC1/x*
Ic?kcw
$idHDh}=
~ID`xG
ifm9"V=
IG&EAzqMY
>ig*x&
^iG[xq
iH,>"hJ
|-ihhN
IHV?J_
IH,y17B
I}HZX_
IIc`l,
II!=Gn~
i:i[Ri
/ I&J|^
I-jL&e
$i/&jR1
[I{@kA5F
=@-iKH
I*Ky`8f
$i^l`a
iLm]'{
@+I$l/meS^
*-I"]m
+iM_5g$
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
]Im;.k
>|Imuc
incomplete download and damaged media. Contact the
"In.Hm
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu_
InvalidateRect
iO!_PG
I<o}<R
&]IO{Z
IparEB+K
;IQHRB1a
IQ"'~O
-i'qs/O
iq w5u
I~r4t;<
iRichu
==Ir}W
IsWindow
IsWindowEnabled
IsWindowVisible
I"t=}(
i\T+7p?C
`IT."A
iTS4zc
IUBdOa
iv9YXj
I^vD&AT
,IW	2I
I}Y< "5
i z$06
I,ZL*bVN
(izRGM
Izrm=hl
^)j%?\
-!*j):
+))$<j
)J	?	-
 j-[1C`
j2&cBv
j2sM0&
=[J!5 
j6'R 1
j7^\2w
J8:A]{
j)8;?l
/J%8r6
J-C0>"
jcQ:"R
J">"dY
jE^Y(-6
JF~~^-
j?F	 Y!X
{J@^!G
JGIXlv
J)gN&0
jgpW@	
J	<-H/
)JH1kAE8
jh["k/2
%'jH'M'
JI+ILc
JJJ2bjo
JJJ2HHHEEEEHHHHxHHH
JJJ2JJJ
jl66HN<
@_j%lGz
,}J?MBJ
jM|NS^7
[JN~w~8c
jpS>3~Q^
Jq}<w*ve
JQW}?Wq
jRB	1j(
J#Sf!=
Js+}Kq
)j*S_N
-J)Ta(FT
JT<l/H
:`J@t s
-jUOt$^
?jV[%@
\J: V|
)jV6I!:
}jw'3y
J*wc|,67&
j.w+"cY
>JX9Aw@
!jY&O~P
jZM|CJ
K=^	+?/
,k;~0K
,!K1=hl
K1iWd~
k!4W_+
"K]%5}
k^*5mH
	;K7!=
K7;9cF
@k8B8c
K8NO7ylB
K$&8Q#qs
k9x)Q\b
@KB!|)
KBb9f-7r
kb=d-W,Z
KBFl<8
kbpOESG
kC6H`3
KCJD6`
Kd#G-fK
 kd/HwC
[K!d)jt
K>dnC"
`kdQ3!e
KE6]a_
	:KEbDB
KERNEL32
KERNEL32.dll
Kew}KW
?kF7+*
KFDI=UF
kFr[DOyN1
Kg\aR6P
kGr`}zp
kGum }g
k%H0W~
-khiL-
\k>[hp
;kh%Wv
-KIdcA
Ki/[Jj
k=[K5qO
_	K~kj`
 KKKby
KKK!FFF#R_g
KKK!HHHDEEEGEEEYHHH
KKK!HHHDEEEGGGGhHHH
kk}@nc!?
%}KKuq8
%KmNce
,kn5Y4s
Kn	c6b6q
k:n cv
K!(N!{s
KnSZq.
K~/o%QJ>&E
K/O*Un
KpWRZF
K|Q^fDj-m
kQpVHgze
Ks\5v4
k]s}F5s(h
k@S*Y@
k.>t*2
*KTB@f
?k`t/d
kT/DCyn-*
}[@%ku
KuE;_Q)#
(Ku@Ic
K	uj7@
K]UO9+
kU'o$E
k@]*V;|u
kWzziNs
k%Y:9Tq
k$#YiU
%kz/}[
KZ/B2r
k^;Z>W
^L/:$[
@_"L|^
L	. &&
L?+}0G
"L1:RmH
!L2o|-
l<+5tP
L<=#6.O"M
L9N_AN
la#{ %
la:mg2s
lamQJ^QPHJ
l	|aPq|
LazE+&Q}=/
lBa^cc|
lbgN+=
[	^lCe
lCo^H#
L?"#cr.
LC;XsT
#L:+!D
LD"J7a,
LD!l(<"#
LdPoYv
l)e)\?
="LE+"
L:`%e6-uLe
L?E#K:
lf [ixD
*L@FUU
*L#h=1E
L&hx@G
  !l);i
li{4o/xa
li534,6
*{l#;J
*LJc:s
LJorI8
Ljy`{(
L"kQQ)
~LKtWy0t
LlB4ak
lLLGuG9
l-l-PT
}!l_ls
lLwQF1x
LM9RY>
LNg4wm_
~L	~*ni'
&lNQFo6
l$nrm-2
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
}lO*e8
LookupPrivilegeValueA
LoZ9$gA
l[@[PGFMv"V*
Lp[*o~
l;Q+a.psjSd
L#]qe59
L-r=.?
lRa=({
lRBD3Jx
:L)Rov
lS0'"D
l!SIb+B[
)|;LsK
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
#??lu1
 lUpsn
LV`4oX
LVa#a>
Lv^Bu/	
lX6Y3D
ly?_+#)
ly!YkHS
L+zB@-	
=@{M` 
M;2HsxQ
m3ev8q@
m-(3m^
M!\5kX
M5Nh|B
<M5~Sx
m-5=Y%'
m*6>YO
 M77k)3
mA8pR!
mBto%u{
M>;cox^
mcW[xh
mD&rra
=ME6=6b
me\p%0
MessageBoxIndirectA
mf+>ss,
m`gB*Q
m{gEEi
$@&mGi
m{;g&)n4
Mh[5n&
MH^a/D
MhSNR)
)MI6^7
MIcBAw
\Microsoft\Internet Explorer\Quick Launch
Mi{KSy#
m[%("J
MJ#]18p
~mj9N5
Mj-TA6)
\m\kM*
mKtqaZp
Ml!|(E>
M*LqZh
m.LTd 
>M?md-
***;mmm
mm[rC'
MNB#W#
:.MNcl3
Mn\OJ 
M?OG7T
More information at:
m@oRTij
MoU8f=
MoveFileA
MoveFileExA
mPsnNO
MQ-+?@
M,Q5>6
MQa>(/
mQnKRo9
=MRcI%
&mR_}K
Mrnx;}&
mS"r=i
M/TH(kd
mTpg1\
m,_U9._>A
M!U@&iP
MulDiv
MultiByteToWideChar
}&M\-Un|
^[_Muo:am
m,U|poC(
M(**UX(U
mv8zvzu
mV+aff
M~<v-e
m&VHe	Mx
mv:y,G
m.w6I~
Mwo?LLW
m.	X3>
[}M/x3
=M^xU|
M`y5M=
\MzuAPY-)
;mz>wZ
!n^$>.
n0ek|u
@N0PWN
n"0T	.
N!0y8g
n`;>1x
n\(!2F
n4$3$h
N7^#R&
N7xX&bC
$(N87$V
N)8H~ 
N8sm<O474
N?aJOh
Nb4q L
$%NbFG
NCXO` K
.ndata
N!dK]RK
n-D/M~`n
{?NEwBix^
n_e^+Z~
Nf#0~|
nfAChA
/Nf}h|
n^@f(x
^n`f#(y
nh*'G^
nh;J|%
n i{: 
NibfaEq,}
n,iN+]
n\>iY_9
N+)j3Q
nJa[-f
')NjDn
N.JE#7
n*(:jR
!N.K$+
^N"KD@
)nk;hj
n>.lRP
_nMKnO
"nMmSH
nnCv^SEy
N/}NDm
(N,NqL
&n-,'NY
NOMh+>(^
$nOTi{
`nPgCg;z
nPsH*n
npWAF{
\Nq3kl
n|,~@q\8B
n-qE3N
n"Q]\JB
:,n	R]
N)R^(b
;}&@NrF
NSIS Error
~nsu.tmp
`NT6&Zb
NT8L_H
nte7 v
{N{:th
nTjY)"
nt%u'`
Nt{uUW@
NullsoftInstuT
NulluM	E
nUPzlxa
#.$n+V
|n;)vJ
n 	v':O
NvpjQ_+
nw	/Pd
N,w\yN"#
n)}]x=
<N<&+Y	
nyN|-w	Z
nzI\)]*
n>zOdlT
O0	n_@
O1><R;4
o/3EkX
O3Iu6h
/O58zrBG
	o6/3V
o*6<7H
<?	?o81
o9C_k:
oci#Sz~
o&*d},
OD0!#|
,-:odp
O[!'^E
OF.]0Td
>]#ofb
[O!g7N
OgB	-T
=OHaf!g
OHEk?O
oHg(?9
OH]k"e
@~.oi%
+:o`IGS
o iLWBu
|Oj(3J,
o<k?w9~
ole32.dll
OleInitialize
OleUninitialize
!\o]$+Mt
oOC<M.
OO_ryq
OpenClipboard
OpenProcessToken
	Oqnl)p
OR3-0MNqT
[OR8'k
<.^os i
o}_t[m
]oTmMO
ou#lljS
OUx<4|
o}UzWD
ovRSDh
=O_<XT
O@yI$kGG
O;$YNl}
 oz&gyf"r^P
*o#ZIb
>>>P,,,
)P;,\	
p0$w*4
P/0<x "
P1B_to
P1@CRUdh\t
	.P2lFS^
P\3bQ]
P3IEQI
P4RKUn
	P\5AL
P^5n PEbFiN
P6oKFXO
P:}$6u
\p7=:Ph
p8eo^qB
P8pxHJ
P8-|Uo:
p$#$An
P(aS\n
pA~yrUGC
pb3'7g&tH
pbGA;oJ
P$&BO5
|#^"Pc/
pcKzH9
PC=l*U
	PC*NZi
pCz~~i
P:#D@8
P	,dUv
PEA+Ai
PeekMessageA
PFG0+W<
pF[l<'
pGO=8d
p-G<r\Z/
PGup q
([^pGX=
p^#I:4]
`pi,dlw
piGdW	
p`J3Mw
PkhHOK8V
P L:o>np
pLS'n3n?
pl@w`c
~p! lY
p!MEiX
p\mL"2
!!!pMMM
(pn5QM
PNLEsn
p&nq=@
pnW!/-
PoEF`/
PostQuitMessage
pou}dg
PPPPPP
P<P/_|u
PQE2vN
Pqv7)g
-p]rjaN
>pR|z<D
ps7lBW
	Ps&h'7
Ptiw~T
.`:[pTv
PuI#Z=
)P<v-B
PVo6pL
-@PwHd"
pwwwww
pwwwwwx
#P~;w\X9
pxpV!jx
p-XTqb
py!eK0
}PY,hH
Q:"05Jz
q#&26d
Q3*fP{$p
Q3vr9\
*q4Ji7
^q4Tv/
q(^`)5&
Q!5PRU
/<"Q6:
@{q7(T
Q9+t:%U
~q<A&'
"Q'A7:n
qA9]s1
+qAeW+/Y@0
QAkMYR
Q^%a]n_
Q=APah
QB1TN:}
<qBQ'D
QBs}wd
&q=b$vK
(q;&.C
Q!}CeORN
qch/fH
q*c},&v?
qcz58!
q|df7w:
:qdpp&
Qd@ZWV
![~;Qe
qE4pgC
=QfhE&c
q|f[w4av
qGDij/[
QH*.e	`c
Q(i%*C%P-
qJ2<vf
QJ5M9]~
*q"	jPp
&~Qjs#;
/q^\k?
)q]K|	
qkt]gR
qL~G'N
q	lmf.
-QL-v/P
--^qM{
qmaXb<[
_Q_MIg
qMJN%H#H
qmlsP)f
"q&N k
 \QNpT)
#QO8lhfa8
:qOD2`[}
*qOoX|5
<Q/Q|cCF
Qq^[fe
\QqM9T&
qqqqqqqq
Q.QYF|Ur
qr8(U($i
"qs]7]T
QSt if
QTDv=B~
.&Qt=e
QuNTG]
&];q?V
?Q.;vm
>QVr6pf
Q#v,rz]
q" vvk
~Qw57L7S
Q)W9~^
;QX?a7
Qx`WX2)u
@/Q&?&y
qyHj['
R`0*Ft
`>r@1NY
R$2f-d
r2J.1t
R	6nZd
R.;6`p
r7S>c@
)R93i:
r9467}- r
R9;ygE,J
RAA+ug7
Rb~HvK
"rC5M)v
=:rcee
RdAiR+
`.rdata
RDmY~+)
Rdv#"y
'RE9	i
ReadFile
Re$AXO
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RemoveDirectoryA
[Rename]
R]E!%S
rfH}z5
r/&F=q
Rfz&E6v
Rh5Ekz
rh77e'
*RH:EV
RHnIys0
rhQ*A=
rh*`UV"
:RHxHV\z
RI8]g9P\
RichEd20
RichEd32
RichEdit
RichEdit20A
-rIH4'
R[JW>p
RK<1,]
rkPOy'
rKu\Jj
R-K~ViUB
\]!;\rL
-=R~@}l
rLny<^D
>*RN<!
rndp<^
	`rni3
RN<&,X
!RodB 
rOm9JC
R*p*3c
$RPokD{
r-P<=q<
R<!>$.q
rq@2${
RQiwkx
'-rqo<
r $QYR
RR!KCD
Rsd=!P
RswZ\a
r|^=@t
rt5$b&
Rt.q?yw
:*RuD\/
RU.D	Z7
RUMv%i
rVHB(D
R]WaZX
`rw@<Q3
,rWy4E
r\&}X-
R`_X:"
r@X(W!-
RxXr.c1
/rX"..Z3
% R"~Y
r\+Ykf
RYxBMI
R,yyEl
}^R`$Z7
/rZ&hf
rZ/Mwl
/(`_S`+
s0?mgv?Q$Sz
/s0;mVi#D
 s;2EL
S3=M'q
s:;3O!
%S)3	u
s3{+vp
*s58`0
|~"s5%o
s5%z%Y
s<6<;~
S6IMQ:^
S7>>{P
S7&^uw
%;S?8@
{S;>8G=
s8k+.nW
S	,@8U
S[8Uu	
s97Z'%;Dn
s-9{N9Wq
S'^9TD-
S9$%$!U
!S{!A3j
sav>?Z
(@s[b<:_
S,B; $
S<b1CM
Sbd4cmx-
'`sBF|
S_.*Bn
SbP$]!
s\bzE!rV
ScnoeF2'
ScreenToClient
sD TPw
S;DZiZ0
SearchPathA
se;-c"
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
`se?wZ
sfN<a|ny
sFSfU`_-
!sg{or
S+G'[r
SHAutoComplete
SHBrowseForFolderA
SHELL32.dll
ShellExecuteA
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHLWAPI
ShowWindow
s$Hv|/
Shv/%;
`)s'#I
+si0e,
siB d{ Z
sIIwNIO
s@Il:kl
s*j"Qf[
 @s,k\b
\sKQ9xU
	sL:6	/
SLQK[=`M
:(sl^RL
smuIO,.
".Snu2
_S[>o|7
softuV
Software\Microsoft\Windows\CurrentVersion
=({SP}
(SP!re
:sQc/Er%K
sQ`~D$U
SQSSSPW
sQW/1@o
s.r$Gqp
s{RMC,k
S*RS}zZ_
SrT;zPKwrX
s-scjRr
sT%$!6
)STC\3
stNb^V_
s'UsC9#CR
_:*)S(v
)Sv 2k
s}vVTG
sw#1Sgw
swkToE
S\wlzn
?!sXUp
(@sy@B<
Symantec Corporation100.
Symantec Corporation1402
'Symantec Time Stamping Services CA - G2
'Symantec Time Stamping Services CA - G20
+Symantec Time Stamping Services Signer - G40
SystemParametersInfoA
> _?=t
T+^{{]
T*-0 h
t1'rUN
t28]jU
t3Q\t^
[t6<:=
t6CI~ R
T8^cjl
*T*9wA|S
tBDEK_<
tB[GD}
tC:2_8*;
?TCAm7Ig
TCI.G&
tCpGR>w;
T`CRXl
tCU8/\
T%-d2f
'tDBi* #
td""$D
-t|DlY
tDvaT5`
TeH.Oh
TeZfn4
?TfT}>
tG07z%
TG^$(=4;
Tg>)$ h
Thawte1
Thawte Certification1
Thawte Timestamping CA0
!This program cannot be run in DOS mode.
TI5>V?
-!ti}B
/TiJM	R&+"
TimeStamp-2048-10
TimeStamp-2048-20
tI'u(n
ti*wfC
=T&j~` w
T-&j_+Y
t]k qNI
:T }~L
tL3LxB
TL5>M"
_ tLE ;
>+TlmIM
t^m{A%
&$"t=mc
T=MrNV
TmSUZB
tNO#ff
T N;;V
_^[t	P
tP	':	
~tpo;$Oql
#tQ-,5
TQ$IZeib
T?qjbe
*t]$Q;n
T>Q]N}
TrackPopupMenu
trJis-
TrustAsia Code Signing CA
TrustAsia Code Signing CA0
TrustAsia Root CA0
TrustAsia Technologies, Inc.1
TrustAsia Technologies, Inc.1"0 
%T$Sfy
Ts[:IGl-s
ts'l ?
T<'\sU
tSUYbn
.tu1%w
T>v[5p
tW6v9.
t %W8W
Tws4nM
Ty2mPEO
tY[K'p
Tyr1'Y
']	t@Z
>T]zN_
U2 48X
u3gpv\
u3I:YrS
u49-,?B
U4{BO 
u8AS-V
U8wPOI~*
u9U9QUn
^Ua1i0W
>/'uaIW
u'aJy1
:)-'UB
uB_0`v
u*bP0v
&Uc+<-
uC	v-b
#+)u>d
U.d&FR*
U$:dHf<
(u-eS_
U([ETp
}ue}wV
u^f	:w
u $g:_0
=<UG2S
uGmZiK
u%i2t!
uIo=L:I
uIrnX=u
<U&J{)
.	U+!J
uj$1sQ
"u*jhTHG
!ujuu:
:>'U{Jz
ukYMSW
|;U+m*
U]Mo92<
uM^[vDN`
uN*+?|
`UnHbK5V
unpacking data: %d%%
+`	UO'
{uo6^VV
Uo;PU<
uPeREQJ
+U-)PF
uQ}b?K
u@"qcM,
UQKo4e
>ur5*d
Ur^P;?
uRXBIz
us)2bS Z \
USER32.dll
usxC-3
Utt@F<
utZ[/iA
-u`uC{A
%u.%u%s%s
***;uuu
U	U+)^Z
uV`c)8~
UVqoKR
 uvu	L
;uVxb8X&
uw9t1M
u`@Woq1J9
U*Ydd	z
Uzs3Lo
v)*>)-
v+/"!%
})V##0( 
V$}%32
\V5B)O
V5)egY3e
v6B<;;
?v784)E
v($7N/
V\7p9+U
v95LpA
V.a+@0
[Vb++2B
v!%>b~T9
_Vc3U/'
~%VCal
!!vC>=G
VCj9n1
;vdH'n
V>*^DNT
"vDPS6:
Ve2`yW
=.Ve\}7
v(e?.;C
@^v!|EQ
verifying installer: %d%%
VerQueryValueA
VERSION.dll
|,:V`F
=V)g5s
#Vh;+@
V\:h4 P& 
~,(v?i
|V@i}F+
	vIMp=
v%{J`G
VJW#7+>
vL3{F=
V`m2RI
VM-}g3
vnd%`Z&
?vnLa!*lL
V^n	sQ
v.n$@T
Vn(ZP 
voH7!{
\voib9
>V.`o{s
v%&<p>
*VP80~
~Vp9F]
V% POs
(Vq9LsD
Vq\f/UB
v"Qi#I
Vq]N/?
vR+#1'
vRkK]Y1
vrWYQ}S
v_S^2c
vSBJGg
v"sFdZ
V`TDz	
=vUbb[:
VXdHR>@	/B
vxn?,,
 v?'Z~
VZ4Sd6L2
v!Zm0}u
\VZz?<r{n
-# W	~
W{)/&>
	W2_"8zNS
w>2|h=
 w3{5rbf@
W`5}oH
)::W.6
W729al-
w.7gd}
W7iOz	
W7+q=W3
W%7Tx"
W=8=6Y
W8R 3.
w)8\Xa
*W=96rR
"w}9eEk
`-w9	p%
$.W9y$
@W& A=
WaD8QN
w|aG@I
WaitForSingleObject
wA:^]jGXK
wamCTgz
WaO&	q
w}auiaH
~/>Wb*#
wB5)fz
w&\B9@
wDiwx7pgX
wd*wV4e
WD @ZE
?wE0\B
@we3f!
`_w~es
Western Cape1
Wf4D2w
*wFH=Wk
&`^Wfqu
Wg{,:W!9
`w^h?`I
whOq^v
`W'IJ/
WJ;NQ|(
WjP|f3
WJr6HG
WJV)PX^
wKA{X#h!>d
+&${#Wke
WK}EB	P
Wki"B3/
wK|LVg
WL0i:`
w-L7.f
~w%L96
W/[%l$Dh
`W(l~LZ
"wLSo;
?{wmyL
WN0O^g
!WN(3"
woM[!T
^wP#7q
wp.,n:
~wp?n!u
.()#WQ
WriteFile
WritePrivateProfileStringA
*wRq|0Dc
Wr&YmCs
\ws6m_
W*S8|/R
wsprintfA
W+Sydf
&W/TXB
 WV>:p
W*vt-[
wwwwww
wwwwwwp
wwwwwww
wwwwwwww
wwwwwwwww
wwwwwwwwwwp
wwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwx
wwwwwxp
wwwxxw
wx;Kc{
WXzn.K
wY|DEs7
WYn9Qp
%wZL**Q3pN
W,z\.X
 >x]|`
 =X~<[*
|X1}'-
+x1g b
~X;1nH
x$1or&
x26>y2
X{:"7&[
\X77g_o|
Xa-5Qz!
`\x~B[
x_@B+t
xCrV]6
xDk1CB
xD=MdHdc
`$+xDq
XDTO;A
X-E}$L`
X?F>-X#
+xG{0l
"XG2SR
!!XG(g
xG	i*?^=
:XgSDJ
XHBSCD
%X^#hP$
/X\i6T
Xiv+:R4
Xjdp,W
~xJFm5
+""Xk,
xm?*2Q
XMkS=E.\ a
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>
xMOP*n
Xm'qwG
xm+>_s<
"X+nU+
XN-xD<
x)O6>^
xo9C}V
	x ~Ogru
X'oO9mG
XPa~q;
XPazeo
!xPjvX
xPm	6kh-
	^X'~Q
[XQ2/rd
].x=qs
xQ/vGUIM
XrG8-V
X?RZ<&
XScHGYO 
xSE,-<
xsi|Q#(
XSrMoh
}$XT(q
X&T*X	[
==XUz~
X[V\#=^
XVIv&{
Xv^~$p\
X_>W/?j
xwmLVI
Xx5QZ6
xX}AJk
x]X$)J
X^YhgN
x?ZpXt
xzRWFS{
XZ,ww:}
y",'[)
!Y_0e:
Y*3!-nK
Y`&3xdp
[y\6hR
y8cO><
y8eO Q
Y8W]4G
y{8Y,R
.Y9c3,
Ya9}PD
:yaM5_
yaO`%/8
Y B'dq#A
y#C<d.Uc
YD{3?,
YDE\2-A
y+df`>V<+
YdgA[%
yENVz3R
YEUJ/!
YF^c?J
YFj\ot
yfOmrPvNB$w_ }M/D
yF]\>P
yFX&s@
YGCJMA
Y@*}GE
Y>GT8(lz	
yikX\|
{YjE8:^&
Y\Jl)	
`!=Yj>+W%
":yK1R
Y,KW 3Aq
!ylj~Y
YLW2vf;
y'N/+8
_yni@S
$yNMr>
y"op)E#
Y	(P&[
ypM!8"
=;%yq`[
:Yq@	#
yq}kq9
$YQn9s
`y~R\}<
)yRew]O
yRF1a'
(YSR9F@
Yt3Zw'
||{YU4
yun$o<E
y<v=.'(=9
yV)X=!8
;^YW!{
yX?(P2
y:XY);
y"y	0%hs
yYW{>=
{Y<zdCN
y\zT>:
,[-;z)
#*<`z`
Z_0BM:
Z2QD&}sF
='*z%5
Z5H)rp
z6Edy#
z6J4i"Q:
z6=%k<
Z~6+Q@I_R
-){z9T{;
Z>9w\x
Z(&b6;
ZBezvW
Zcn/g0
zcyF}5
Z@_-d_(
ZDdxG/T
zd!TQ'~
ZFVuiR
Z. g8\
``Z-~gD
ZGOd"I
z	HiMqA`
zHm7]U
z?h}R^=
ZI]avb
Zi	cCg
Z=[I/Gcc
+ZI.(.of
ZJC?2JRu
Z.jT	i
]Zk$N^
z>kvlzS
Zl~%6h
zlyf!JO
zlzh~>
]z(m7#f
Z$~Mg)
zmNrF1
}ZnBVH
+ZNvEo
Zo=;z<
zP(?H_=
^z%qbB
zqM''-
(zQ[V^K
Z")r}6
Zr(P<@
ZS1C96
ZSe3gd7
zs&_h9
zsLvc"
Z]@t+(
z(tJX@-
 zUNhTF
Z;\v0y
zvG#$3
zw1H)6
Zwb.[<
|`Zwl=
Z\{#Y]
zYMRBb
&ZZ~+>
'Zza"f uEe
~zz?F{
zZY6X	(