Analysis Date2014-04-17 14:59:39
MD59e6a4a044198a2bb7f3387e1d86135f2
SHA1beb0880cafc474b8659473afcda36b5c54c86e2a

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 9d64b6ac6eb1aa41e38f6cc8798b652e sha1: f4a3d9f95186a438562e94d405bfef3355c6cb1f size: 23552
Section.rdata md5: f179218a059068529bdb4637ef5fa28e sha1: 6035d27db526131eb0f29aee60cfcdbb5072ed7d size: 4608
Section.data md5: af685ae5a632e08acd6c90a62cdfc3bb sha1: efc7ece496385ad53dda894ae310ffa90b2fc571 size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: 231540232604cde6b2c67e6548e8cdc0 sha1: a23137d61db0f7ee9b8e1f709c17f4275a9de9e2 size: 27648
Timestamp2009-12-05 22:50:35
PackerNullsoft PiMP Stub -> SFX
PEhash748aeee351b8ababe0ec184b10dab3485264f491
IMPhash099c0646ea7282d232219f8807883be0
AVavgWin32/Heri
AVaviraProgramFilesDir/[UnknownDir] <<< ADWARE/Adware.Gen

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CLASSES_ROOT\CLSID\{30E7B485-2705-7529-3AA6-C604A4D8153C}\ ➝
revenuestreaming browser enhancer\\x00
RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\AppDataLow\Software\{94C1BCC8-4F4A-D0BE-97F3-B67B231B005E}\aff_id ➝
revenuestreaming_2
RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\xqlyeqdxyq\DisplayName ➝
Advanced Performance Platform Revenuestreaming.\\x00
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\fwovtriaczyfxhx ➝
C:\WINDOWS\System32\regsvr32.exe /s "C:\Documents and Settings\Administrator\Local Settings\Temp\nss4.tmp.dll"
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30E7B485-2705-7529-3AA6-C604A4D8153C}\NoExplorer ➝
1
Creates FileC:\WINDOWS\system32\xqlyeqdxyq.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nss4.tmp.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsw3.tmp\System.dll
Creates File\Device\Afd\AsyncConnectHlp
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nse2.tmp
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates File\Device\Afd\Endpoint
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsw3.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsj1.tmp
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsw3.tmp\System.dll
Creates Process"C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\tslgjhnnbbbqrsru.dll"
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSrevenuestreaming.net

Process
↳ C:\Program Files\Internet Explorer\iexplore.exe

RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Creates Mutex_SHuassist.mtx
Creates MutexShell.CMruPidlList

Process
↳ "C:\WINDOWS\system32\regsvr32.exe" /s "C:\WINDOWS\system32\tslgjhnnbbbqrsru.dll"

RegistryHKEY_CLASSES_ROOT\CLSID\{30E7B485-2705-7529-3AA6-C604A4D8153C}\ ➝
revenuestreaming browser enhancer\\x00
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\fwovtriaczyfxhx ➝
C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\tslgjhnnbbbqrsru.dll"
RegistryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30E7B485-2705-7529-3AA6-C604A4D8153C}\NoExplorer ➝
1
Creates FilePIPE\lsarpc
Creates MutexGlobal\afxOpenEvent1337

Network Details:

DNSrevenuestreaming.net
Type: A
64.74.223.44
HTTP GEThttp://revenuestreaming.net/bc/nsi_install.php?inst_result=success&aff_id=revenuestreaming_2&id=7d2c1ab9d1cfe00d7254c93d819c053475c383b2
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Flows TCP192.168.1.1:1032 ➝ 64.74.223.44:80

Raw Pcap
0x00000000 (00000)   47455420 2f62632f 6e73695f 696e7374   GET /bc/nsi_inst
0x00000010 (00016)   616c6c2e 7068703f 696e7374 5f726573   all.php?inst_res
0x00000020 (00032)   756c743d 73756363 65737326 6166665f   ult=success&aff_
0x00000030 (00048)   69643d72 6576656e 75657374 7265616d   id=revenuestream
0x00000040 (00064)   696e675f 32266964 3d376432 63316162   ing_2&id=7d2c1ab
0x00000050 (00080)   39643163 66653030 64373235 34633933   9d1cfe00d7254c93
0x00000060 (00096)   64383139 63303533 34373563 33383362   d819c053475c383b
0x00000070 (00112)   32204854 54502f31 2e310d0a 41636365   2 HTTP/1.1..Acce
0x00000080 (00128)   70743a20 2a2f2a0d 0a416363 6570742d   pt: */*..Accept-
0x00000090 (00144)   456e636f 64696e67 3a20677a 69702c20   Encoding: gzip, 
0x000000a0 (00160)   6465666c 6174650d 0a557365 722d4167   deflate..User-Ag
0x000000b0 (00176)   656e743a 204d6f7a 696c6c61 2f342e30   ent: Mozilla/4.0
0x000000c0 (00192)   2028636f 6d706174 69626c65 3b204d53    (compatible; MS
0x000000d0 (00208)   49452036 2e303b20 57696e64 6f777320   IE 6.0; Windows 
0x000000e0 (00224)   4e542035 2e313b20 5356313b 202e4e45   NT 5.1; SV1; .NE
0x000000f0 (00240)   5420434c 5220322e 302e3530 37323729   T CLR 2.0.50727)
0x00000100 (00256)   0d0a486f 73743a20 72657665 6e756573   ..Host: revenues
0x00000110 (00272)   74726561 6d696e67 2e6e6574 0d0a436f   treaming.net..Co
0x00000120 (00288)   6e6e6563 74696f6e 3a204b65 65702d41   nnection: Keep-A
0x00000130 (00304)   6c697665 0d0a0d0a                     live....


Strings
 " "
.
.
............
EH.
1s%P
bsJP2
Js2P
msctls_progress32
MS Shell Dlg
ssPP
SysListView32
        
*?|<>/":
*_01]|F
[0a}f<
-0G>P}my
$]0J/?
*,0jd"
\@0scMy
0*ZYWg
\_"1>0
111~SSS
16% B%Ss
18mmiUU~
1BS_",L
1EDQb+
1i5dgE
^1Pc*S
1QjfQH
1<t@En
)^1x-D
'2:;0#`
2e0;>)
2m51]/J
2qMs~+u
2TZOU 
	2,X.o
3330XXX
-{3e8N~tCCj
3h&.RT
,3I$a<
3=JL$H4P
3'K1=?
<3k%C2,
3l*h	'
3MFoR(
3<\&S!
3sSjU3
3tuNNf
44aB01aXa21
4c6I,V
4jk0uK
4Mlvqsm
4Mt@}r
4O@mq9
`4x|_]O
&}53-'
!@5.7D
58sVd?L
5bsM41<
 5Cmrw
)%5-F`
5_,f1"'
5L*S5U4
5(:MAN
5TUFIY
`5\v6c&
5W.h:{8
6)0jLC&
61iF6S
62[%nk
62}UVt
{6!5se
;6~?_G
6p`s de
6u$*!3p
72ke1224Y
@@@`777-
7A %tb
7'b`>j]
7D6g}R
7wQl0!
82oH}\
8Dv_g*
8[gV%5
8i#Qif
\8jszL
8NCRCu
90E1k[
930$]X'
9e),REmT
9F"}/ 
*9HKxc	
9<m0]/
9#M/ F\
`*9.PA
9!RGT(zU
9smZmL
9u},JV
9V[V)$
9Z&)Wlf
aa7'iG
AAA_ggg
+ABIJF:y_p
AdjustTokenPrivileges
ADVAPI32
ADVAPI32.dll
A@;E |
AE\+|h[
af?7sT
A Hr@BE
a%@@ID !+
a(kD-K T
@ALs[PT
aNOxxe
aO'3Pw
a!_P`Hi
AppendMenuA
AQIAIIX
	a r ~
'(Ar=<k
'asWaa
Aud;&_
AUVKV@"
AWEXT^
a}xE?F
a@YfH.
B1m7Hwq
B6zV7_
BBBp;;;>
bce:2	
Bco/~p
BeginPaint
@BE"Z(y
Bfmf[I
b}fu22
bfy-Z>D
)Bg-5w
b=i.a{
"B>Ibc 
bIhJL7
B""IK#
bKF"JA
BK#p<c
Bo[3'O
bPL	.IF\
"|bsA(
B\SB7&
&b/_/u
^B_ur+EbH
	BwCsmD
C1(8-w
^$C4-(
+<Ca+5
CallWindowProcA
caS~op
+cASY+qq
cBa#yL
:.!CcL?
c)eCjK
))CGYOX
CharNextA
CharPrevA
|-chcm7
CheckDlgButton
cIpmplI^
 c[JH[
cjhiij
Cjrce.
ckCJoD
-\[c/l
CloseClipboard
CloseHandle
c/mvg6
CoCreateInstance
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
CoTaskMemFree
Cp"I!,A
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
*CU;]T
{(cVK 
... %d%%
D`{*(@
D$0+D$(P
D0lv9[
\D;;0)x
D%1|<[
D166&&
(d5J&$
d#7E|F.M
+`D7{u/T
@.data
dc{odadm
DD9A9D
DDDI{{{
D$(+D$ SSP
.DEFAULT\Control Panel\International
DefWindowProcA
d-,EkJ6Z
DeleteFileA
DeleteObject
DestroyWindow
deVRQF
dFDB,Za
d\GT\2
d@`h14
dH(#:M9e
DialogBoxParamA
DIh!C	
}dIHrL2R
DispatchMessageA
d}nG=;I
DO%2FT
DrawTextA
D$(SPS
(_dT@[
{dTkg6l
$dWCH<
dzca*J
D:#zxA,
}e0d<A
E$0.e:
E%7!LS
e87AIn
`E8[.Y
.EC%*D
-eDjT*
eeeeeeeee
EEQQX(
Eezf`(
@e%(G.{
Eg7h:K
egn^;3
e+^L+F
EmptyClipboard
E-	~Mu
emW0Rm
EnableMenuItem
EnableWindow
EndDialog
EndPaint
[eNom(
*Ep`Cn	
]. %e Q$
%@EQ;ek(
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
eR%]@|U
{<##es
et1L`V$
+EUm)F
EVdz3h
=[,evV
ExitProcess
ExitWindowsEx
ExpandEnvironmentStringsA
{EyOlm
Ezsr/&
F0Cgr=
f`2l e
f}8Pbf
f AvOD
fcaacopefm
 [(Fc.z
FFF#LLL
}fIbXy
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
)^fj;a
fjWks[,23
FL)t'j
f-m5W&q9I
,f.mm-
f:N:fj<
FNNNN@
FN;Pk8\(
fNV/>k7?
-?F_oy
FqJaV@
fqVf!|
FreeLibrary
fr"z%3
fTELY`((
.fu0nI
f?us3o
~fyh5+<
f';yT#J
F|Zu/5
?->%g[
+G8!d!
"|>G9D
g9gkg9OK
g$(aL}
'gA>SY
	gccnZme
GDI32.dll
gDn=K4b
$G_DPUXB@
GD$QT;
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
g?*{:f?
GFj@(5
g	K{mA.
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
gq*%I2k
gTW/s8(
Gx;eu?vh0
G^yeI$
>?g{z)
h1K&HWm
%h1QQ;S^
H3v~&{
H@A$@ 
HcY@GC*Y
&heny(p
:Hfb6E
(H<gf%
#hiAf1
)hi}*D
%hjXDJ*Y
HkEOm'
)H<M6U
HN!=@$
"&H!O{
HO	P)v
H@POW!o
H$qiXnL
hq;MA;W@
http://nsis.sf.net/NSIS_Error
,hUa>f?
HXo4n,
hz[NG3=S
hzRrI/
i0w,hziH6
i|1a"U
i2l*o)5
i2=X?\q
	i3>P7
 I%4[}
I4l~Cd^
iatsr|
IBRi$3
*/I=C>;
i_Cqn 
iFfWOCU
I(`(hB
ii-]Da
<^+]IJK:
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
iMR!k*
incomplete download and damaged media. Contact the
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu_
InvalidateRect
Ipna2i
i%Q4V"
IsWindow
IsWindowEnabled
IsWindowVisible
iXO}enb?
Iy4WjM)
`(#>J9_6
j	Cvuys-
jD'	JS9
 _|j:/es
Jgi*Zt^
]jHM_8aj
JJJ2bjo
JJJ2HHHEEEEHHHHxHHH
JJJ2JJJ
jlTEg,w
jNU'WA
@j}\pG\
/j !r f
*j*s9<K
J`S	Ti
J";[vUB
j[xkX(KE[~
\k3NB._H
K;4NrZ
	K9yCm
!Ka+FJ
*kc{O%
KERNEL32
KERNEL32.dll
K_{[fV
^KjXm	
#KkBW*
 KKKby
KKK!FFF#R_g
KKK!HHHDEEEGEEEYHHH
KKK!HHHDEEEGGGGhHHH
KK_#.U
`KlbF3
|,K/o#q
]k[*Q_e
kqF'1|d	
!KQH@Ct
K'%u}}
ku4`m0
)k^^'{WYP
kZCC`;
KZLmFd
KzWKvB
L=2NjN
L5`wo.
L8w5dp
L9.tC=
&lBQcJ
$"lEoI
"Le&[x
Lf#E:-O
LhH<c3
lm1BS5
Lm6ClcBC`
lm$o- ,,
	`l{%nO
LNuWRJ
LnwxqgMR
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
LookupPrivilegeValueA
lQWgx'
lr4]?]
lShD1f
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
LVF[H&
lvq`PM]
LY!DPN
=Lz>$H
LZXdY%1
m]7v1_
$M8X_7
mB+QOF
md&R"-
)M#ea$
MEb**"
MessageBoxIndirectA
^	mHP?|
MHR>5jp
\Microsoft\Internet Explorer\Quick Launch
mIufgL4`
mjI	,C
]MLjgZl
***;mmm
MnbVckY
More information at:
MoveFileA
MoveFileExA
mq`71Qy
^M=(ql
	=M$%rd~
MsK9MS
"MT1CM
mt+ge_<Y
MulDiv
MultiByteToWideChar
mx:@@i
MyCEm]
MY<=D|
mZjSI5
+n!(	>
n38-~&O
N_$+4]i
n7eAc;
N}]"8m
NAJ`}}
NAp/h=
/	nBi"
.ndata
N+dHfye{/
N_E;\W
<{}n-g
)NG=},
n=I~6w1t
N^ijaf.}.
nJan1z
NMgb5_ %LR
\&N)ni
n'n^w-
noED+-
nQX*(nmB}
NRPfa-
NSIS Error
~nsu.tmp
NucuQu'p
NullsoftInst
NulluM	E
nYG y~
_~o0	2
o0%#zuZ
O'2yU3@
*OB>D7o
oC=COb
+'"Oe?
o[e-v)#
o%FYv~
o;L]>5
ole32.dll
OleInitialize
OleUninitialize
oMHFMrp
OpenClipboard
OpenProcessToken
]oq5wX
OsK,a(
}OSxyK
ou53><
o	v`hNi
ovks$l
oVuRd{
O)yirZ
oZc,'_
>>>P,,,
P?1pxO8
PeekMessageA
PE=[~j
PFv#J]IB
ph*ZZD2
P)i++'
!!!pMMM
PostQuitMessage
PPDQb$
PPPPPP
#pP?V=
PPV_>x{
PR%1k]
PrbbU.
P+s<o8)
p~,t;Y
Pu-]O6
P=);wv
pwwwww
pwwwwwx
px=;_k
q?a}<@
{]qbt2
q~Czp:
]qd Ay
qE23VI
QI d!	
Qj`^Pn1{
qkQ +\r
ql?*Kn
<Q|LM<
q$@[M6
 )QO"~
Q~+OC{
QPHYQ&
qQDz+cQ
	<Qq`P
qqqqqqqq
qRP&NM
quYekT
(Qv[/_
QWt?qx
,Q|zz)
r<8Q:v
R}8x)6{
RbferfD
`.rdata
ReadFile
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RemoveDirectoryA
[Rename]
RichEd20
RichEd32
RichEdit
RichEdit20A
R?I\n_Qqs
rM7YM?
R.n%DSZ
R{os>Ov
r-_:QPFNn
RS	$/t
=RX/UW_Cf
ryj%*,
R$Y><nl
:RzqwQ
>S#2Pm
ScreenToClient
ScSeWg
SC\<vIa@
SearchPathA
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
sFC&S)^^
Sf|EmF
SHAutoComplete
SHBrowseForFolderA
SHELL32.dll
ShellExecuteA
sH{e&o
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHLWAPI
ShowWindow
'SIP~=
sJc%Tc
;S`lB_
\!s%M@r
S<@mxv
softuV
Software\Microsoft\Windows\CurrentVersion
SQSSSPW
srC|cz
|[s@S&
SS{GOc
{	St5w
suQYTH
SUtd	+
SV8F>{
@^SVOX
SystemParametersInfoA
> _?=t
t0foio
T`4En!y
T5U^H3:.
%'T]6D
T'6)F}-G
T7/*eZI
"taDg\/j
t=aIR%
!This program cannot be run in DOS mode.
?thYv+
TI!\u8
T{Jn6]EPD
T=	/L}
tL?;I 
tlx~:<t
tma;9,M
[tn0pwp
TNirWyg
_^[t	P
t#~q=Nl
TrackPopupMenu
tX*_"yiF
'_;U1{6
U20RI=
u49-l'z
U#5&IFeT
U:<}<7
Ua?xqE8
ub*+b)n$
+ubYAN<
U'*^c.
ug+Ujd
Uk?5,>
U+LclW
u-nIV[u0
unpacking data: %d%%
,Uo]]yF9+
upjh,,\
u<s[.2
USER32.dll
ut0@%0
UUEQQT
%u.%u%s%s
***;uuu
UUUTUUQ
UUUUUU
Uw$nTM%
+uwz9~
uX	B$O<$##
V2U)05
v8}tP!r
vc!=yx
VDiE0T
verifying installer: %d%%
VerQueryValueA
VERSION.dll
vf sX,4
#Vh;+@
*VkeWX
]vlkkJ]J"
V<ln<w
Vo9[=;o
VO_]j{
Vq$Tlm!
vur.1~.
;vusk05
v>vi~{z
-vVo*mY
v/VuZ<
vX1>,,
]v@ZX$
W0[	=.q
	w24]H@;
%;W7q0
>w7^:;r
W7z9L.
WaitForSingleObject
@&#W^c
%-wD1B
)w+EigsW
WGOoau
$~Wjs/7?w
:wk6lOe8
[wKQiC
w}mx;!
w@&n&;
wnkDx;
WouTY={
WriteFile
WritePrivateProfileStringA
#Ws3%M
wsprintfA
w"Tmvk
w|T^u<m
w.UNCHM
w$Vh1Y\
wwwwww
wwwwwwp
wwwwwww
wwwwwwww
wwwwwwwww
wwwwwwwwwwp
wwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwx
wwwwwxp
wwwxxw
?wzsCwE
x + $*
&X2~kO
x4E(n#
X4@x=-
x7rXCA
^X=	88
Xa"Cxrf
Xbo,JR
XIQKm	Z
X,]Je9G
xl%\!M
	XLMpP`
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="highestAvailable" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
x"Ox7`-
xPQm:3
xrP*Zl(
x]utNIj
-<;/}XX
Xz1=C^ P
XZZZS;
Y,&$1m{K
Y{;8]iE
Y<Adq2KYC&r
	yC1@X)
yD?rt_g
]y-E#4
YF5~>X
YG5Wu}
Y`[&:J0x
yk|R=R|
yKTAB*
ylYM["
~)yn|=
@yO|'4 6
YpAKc9
Ysjw)b)S
.ytM4k
\YUB2Y,T
 	}ywe
yX^jien
Y<YL x
YY@*ZG
Z00C4}p
Z1f0[Mn
Z=8!c;
z(]|Am
<.zANo
z&Cd3/}#H
{ZD DuBQ
Zf)a*WB
zg]sHv
z]guyYU
"zlc=$q
zL>`gI
ZMc^ S
zMkEAi
z~<N	+
zngqgB
:Zp4*n
ZRt|/a
z"uO~%
ZVcaWQmR
zW,oO5$
ZY2i>yM