Analysis Date2015-01-31 22:01:06
MD5288f6862b5741f4bab67e0717f778326
SHA1e0778280dea9cc5334c315fa70e0ac4b890586cc

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 0bc2ffd32265a08d72b795b18265828d sha1: dd2a446014a37556f39173b802c63a4e46e09366 size: 23552
Section.rdata md5: f179218a059068529bdb4637ef5fa28e sha1: 6035d27db526131eb0f29aee60cfcdbb5072ed7d size: 4608
Section.data md5: 975304d6dd6c4a4f076b15511e2bbbc0 sha1: 1f65340672c91ffd0f2583ff104beaece43c7855 size: 1024
Section.ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0
Section.rsrc md5: 5da4c88cb9b1d217bc9916aa1400bbc8 sha1: e870d78a874ffa3ed7c56ad4dc94a88d374da8ce size: 17408
Timestamp2009-12-05 22:50:46
VersionLegalCopyright: BEARPC¾«Ñ¡Èí¼þ¼¯
ProductName: ·ßÅ­µÄСÄñ
FileDescription: ·ßÅ­µÄСÄñPCºº»¯°æ
FileVersion: 1.0.0
CompanyName: www.bearpc.net
PackerNullsoft PiMP Stub -> SFX
PEhashdbe25aaa4f9a4ac33c5f18abb45b56837826809a
IMPhash099c0646ea7282d232219f8807883be0
AV360 Safeno_virus
AVAd-Awareno_virus
AVAlwil (avast)Malware-gen:Win32:Malware-gen
AVArcabit (arcavir)no_virus
AVAuthentiumno_virus
AVAvira (antivir)no_virus
AVBullGuardno_virus
AVCA (E-Trust Ino)no_virus
AVCAT (quickheal)no_virus
AVClamAVno_virus
AVDr. Webno_virus
AVEmsisoftno_virus
AVEset (nod32)NSIS/TrojanDownloader.Chindo.R
AVFortinetno_virus
AVFrisk (f-prot)no_virus
AVF-Secureno_virus
AVGrisoft (avg)no_virus
AVIkarusno_virus
AVK7Unwanted-Program ( 004b1ff81 )
AVKasperskyno_virus
AVMalwareBytesno_virus
AVMcafeeno_virus
AVMicrosoft Security Essentialsno_virus
AVMicroWorld (escan)no_virus
AVRisingno_virus
AVSophosno_virus
AVSymantecno_virus
AVTrend Microno_virus
AVVirusBlokAda (vba32)no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

RegistryHKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝
NULL
RegistryHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝
1
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy3.tmp\System.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat
Creates FileBF-BFVCenter[[AB005]].exe
Creates File1
Creates File1.rar
Creates FileC:\Documents and Settings\Administrator\Cookies\index.dat
Creates FilePIPE\lsarpc
Creates Fileyx_cqby.exe
Creates File\Device\Afd\Endpoint
Creates Filezhezi_setup_Z7FE.exe
Creates FileC:\Program Files\3.ico
Creates FileQQGame_setup_wb_20007.EXE
Creates FileC:\Program Files\1.ico
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy3.tmp\ExecCmd.dll
Creates File9377mycs_Y_mgaz2_1201B.exe
Creates FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy3.tmp\inetc.dll
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nst2.tmp
Creates FileMM-liao8302.exe
Creates Filesetup_95165069.exe
Creates FileOfficeAssist.0405.80.1122.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy3.tmp\Base64.dll
Deletes FileQQGame_setup_wb_20007.EXE
Deletes File9377mycs_Y_mgaz2_1201B.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsn1.tmp
Deletes FileSoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe
Deletes FileC:\Documents and Settings\Administrator\Local Settings\Temp\nsy3.tmp
Deletes FileBF-BFVCenter[[AB005]].exe
Deletes File1.rar
Deletes File1
Deletes FileMM-liao8302.exe
Deletes Filesetup_95165069.exe
Deletes FileOfficeAssist.0405.80.1122.exe
Deletes Fileyx_cqby.exe
Deletes FileC:\Program Files\3.ico
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_cqby.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_cqby.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB005]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB005]].exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1122.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1122.exe"
Creates Process9377mycs_Y_mgaz2_1201B.exe
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\QQGame_setup_wb_20007.EXE /S" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\QQGame_setup_wb_20007.EXE /S"
Creates ProcessC:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"
Creates Mutexc:!documents and settings!administrator!local settings!history!history.ie5!
Creates Mutex3.ico
Creates MutexWininetConnectionMutex
Creates Mutexc:!documents and settings!administrator!cookies!
Creates Mutexc:!documents and settings!administrator!local settings!temporary internet files!content.ie5!
Winsock DNSint.dpool.sina.com.cn
Winsock DNSt.cn
Winsock DNSmmliao.jianting.net

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\QQGame_setup_wb_20007.EXE /S" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\QQGame_setup_wb_20007.EXE /S"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\OfficeAssist.0405.80.1122.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\OfficeAssist.0405.80.1122.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\setup_95165069.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\setup_95165069.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\yx_cqby.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\yx_cqby.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\BF-BFVCenter[[AB005]].exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\BF-BFVCenter[[AB005]].exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\9377mycs_Y_mgaz2_1201B.exe"

Process
↳ C:\WINDOWS\system32\cmd.exe /C copy /b "C:\Program Files\MM-liao8302.exe" + "C:\WINDOWS\Fonts\gulim.ttc" "C:\Program Files\MM-liao8302.exe"

Process
↳ 9377mycs_Y_mgaz2_1201B.exe

Network Details:

DNSint.dpool.sina.com.cn
Type: A
180.149.136.250
DNSt.cn
Type: A
114.134.80.138
DNSmmliao.jianting.net
Type: A
122.227.42.227
DNS37w.xdwscache.glb0.lxdns.com
Type: A
183.136.208.114
DNSdldir3.tcdn.qq.com
Type: A
182.118.37.13
DNSwww.buptinnovation.com
Type: A
223.6.254.23
DNSdownload012.e.chinacache.com.cn
Type: A
61.179.105.147
DNSdownload012.e.chinacache.com.cn
Type: A
218.60.107.12
DNSna.b9.aicdn.com
Type: A
72.8.188.90
DNSna.b9.aicdn.com
Type: A
72.8.188.94
DNSna.b9.aicdn.com
Type: A
108.186.7.129
DNSna.b9.aicdn.com
Type: A
108.186.7.130
DNSna.b9.aicdn.com
Type: A
108.186.7.131
DNSc01.i06.arnic.hadns.net
Type: A
113.17.184.10
DNSc01.i06.arnic.hadns.net
Type: A
121.10.117.139
DNSc01.i06.arnic.hadns.net
Type: A
183.56.172.47
DNSc01.i06.arnic.hadns.net
Type: A
222.186.20.122
DNSc01.i06.arnic.hadns.net
Type: A
58.220.2.5
DNScdn.coop.baofeng.com
Type: A
218.60.99.66
DNScdn.coop.baofeng.com
Type: A
58.20.193.222
DNScdn.coop.baofeng.com
Type: A
119.188.72.240
DNScdn.coop.baofeng.com
Type: A
122.142.74.12
DNScdn.coop.baofeng.com
Type: A
182.18.51.104
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.6
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.3
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.234.4
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.2
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.3
DNSopt.xdwscache.glb0.lxdns.com
Type: A
8.37.235.5
DNSd.14yaa.com
Type: A
DNSdldir3.qq.com
Type: A
DNSwdl1.cache.wps.cn
Type: A
DNSpubliclist.b0.upaiyun.com
Type: A
DNSdl.nx5.com
Type: A
DNSdl.baofeng.com
Type: A
DNSxiazai.9377.com
Type: A
HTTP GEThttp://int.dpool.sina.com.cn/iplookup/iplookup.php
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://t.cn/RZIvJQB
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://mmliao.jianting.net/mmliao/MM-liao8302.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://d.14yaa.com/yx/cqby/sqft/905848/yx_cqby.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dldir3.qq.com/minigamefile/QQGame_setup_wb_20007.EXE
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://www.buptinnovation.com/ZTA3NzgyODBkZWE5Y2M1MzM0YzMxNWZhNzBlMGFjNGI4OTA1ODZjYy5leGU=/40.html
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://wdl1.cache.wps.cn/wps/download/OfficeAssist.0405.80.1122.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.nx5.com/apk/20141222/setup_95165069.exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://dl.baofeng.com/BFVCenter/BF-BFVCenter[[AB005]].exe
User-Agent: NSIS_Inetc (Mozilla)
HTTP GEThttp://xiazai.9377.com/20150105/9377mycs_Y_mgaz2_1201B.exe
User-Agent: NSIS_Inetc (Mozilla)
Flows TCP192.168.1.1:1031 ➝ 180.149.136.250:80
Flows TCP192.168.1.1:1032 ➝ 114.134.80.138:80
Flows TCP192.168.1.1:1033 ➝ 122.227.42.227:80
Flows TCP192.168.1.1:1034 ➝ 183.136.208.114:80
Flows TCP192.168.1.1:1035 ➝ 182.118.37.13:80
Flows TCP192.168.1.1:1036 ➝ 223.6.254.23:80
Flows TCP192.168.1.1:1037 ➝ 61.179.105.147:80
Flows TCP192.168.1.1:1038 ➝ 72.8.188.90:443
Flows TCP192.168.1.1:1039 ➝ 72.8.188.90:443
Flows TCP192.168.1.1:1040 ➝ 72.8.188.90:443
Flows TCP192.168.1.1:1041 ➝ 72.8.188.90:443
Flows TCP192.168.1.1:1042 ➝ 113.17.184.10:80
Flows TCP192.168.1.1:1043 ➝ 218.60.99.66:80
Flows TCP192.168.1.1:1044 ➝ 8.37.235.6:80

Raw Pcap
0x00000000 (00000)   47455420 2f69706c 6f6f6b75 702f6970   GET /iplookup/ip
0x00000010 (00016)   6c6f6f6b 75702e70 68702048 5454502f   lookup.php HTTP/
0x00000020 (00032)   312e310d 0a557365 722d4167 656e743a   1.1..User-Agent:
0x00000030 (00048)   204e5349 535f496e 65746320 284d6f7a    NSIS_Inetc (Moz
0x00000040 (00064)   696c6c61 290d0a48 6f73743a 20696e74   illa)..Host: int
0x00000050 (00080)   2e64706f 6f6c2e73 696e612e 636f6d2e   .dpool.sina.com.
0x00000060 (00096)   636e0d0a 436f6e6e 65637469 6f6e3a20   cn..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f525a49 764a5142 20485454   GET /RZIvJQB HTT
0x00000010 (00016)   502f312e 310d0a55 7365722d 4167656e   P/1.1..User-Agen
0x00000020 (00032)   743a204e 5349535f 496e6574 6320284d   t: NSIS_Inetc (M
0x00000030 (00048)   6f7a696c 6c61290d 0a486f73 743a2074   ozilla)..Host: t
0x00000040 (00064)   2e636e0d 0a436f6e 6e656374 696f6e3a   .cn..Connection:
0x00000050 (00080)   204b6565 702d416c 6976650d 0a436163    Keep-Alive..Cac
0x00000060 (00096)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x00000070 (00112)   61636865 0d0a0d0a 76650d0a 43616368   ache....ve..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f6d6d6c 69616f2f 4d4d2d6c   GET /mmliao/MM-l
0x00000010 (00016)   69616f38 3330322e 65786520 48545450   iao8302.exe HTTP
0x00000020 (00032)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000030 (00048)   3a204e53 49535f49 6e657463 20284d6f   : NSIS_Inetc (Mo
0x00000040 (00064)   7a696c6c 61290d0a 486f7374 3a206d6d   zilla)..Host: mm
0x00000050 (00080)   6c69616f 2e6a6961 6e74696e 672e6e65   liao.jianting.ne
0x00000060 (00096)   740d0a43 6f6e6e65 6374696f 6e3a204b   t..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a0a                       he.....

0x00000000 (00000)   47455420 2f79782f 63716279 2f737166   GET /yx/cqby/sqf
0x00000010 (00016)   742f3930 35383438 2f79785f 63716279   t/905848/yx_cqby
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a55   .exe HTTP/1.1..U
0x00000030 (00048)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000040 (00064)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000050 (00080)   0a486f73 743a2064 2e313479 61612e63   .Host: d.14yaa.c
0x00000060 (00096)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x00000070 (00112)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x00000080 (00128)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x00000090 (00144)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f6d696e 6967616d 6566696c   GET /minigamefil
0x00000010 (00016)   652f5151 47616d65 5f736574 75705f77   e/QQGame_setup_w
0x00000020 (00032)   625f3230 3030372e 45584520 48545450   b_20007.EXE HTTP
0x00000030 (00048)   2f312e31 0d0a5573 65722d41 67656e74   /1.1..User-Agent
0x00000040 (00064)   3a204e53 49535f49 6e657463 20284d6f   : NSIS_Inetc (Mo
0x00000050 (00080)   7a696c6c 61290d0a 486f7374 3a20646c   zilla)..Host: dl
0x00000060 (00096)   64697233 2e71712e 636f6d0d 0a436f6e   dir3.qq.com..Con
0x00000070 (00112)   6e656374 696f6e3a 204b6565 702d416c   nection: Keep-Al
0x00000080 (00128)   6976650d 0a436163 68652d43 6f6e7472   ive..Cache-Contr
0x00000090 (00144)   6f6c3a20 6e6f2d63 61636865 0d0a0d0a   ol: no-cache....
0x000000a0 (00160)                                         

0x00000000 (00000)   47455420 2f5a5441 334e7a67 794f4442   GET /ZTA3NzgyODB
0x00000010 (00016)   6b5a5745 3559324d 314d7a4d 30597a4d   kZWE5Y2M1MzM0YzM
0x00000020 (00032)   784e575a 684e7a42 6c4d4746 6a4e4749   xNWZhNzBlMGFjNGI
0x00000030 (00048)   344f5441 314f445a 6a597935 6c654755   4OTA1ODZjYy5leGU
0x00000040 (00064)   3d2f3430 2e68746d 6c204854 54502f31   =/40.html HTTP/1
0x00000050 (00080)   2e310d0a 55736572 2d416765 6e743a20   .1..User-Agent: 
0x00000060 (00096)   4e534953 5f496e65 74632028 4d6f7a69   NSIS_Inetc (Mozi
0x00000070 (00112)   6c6c6129 0d0a486f 73743a20 7777772e   lla)..Host: www.
0x00000080 (00128)   62757074 696e6e6f 76617469 6f6e2e63   buptinnovation.c
0x00000090 (00144)   6f6d0d0a 436f6e6e 65637469 6f6e3a20   om..Connection: 
0x000000a0 (00160)   4b656570 2d416c69 76650d0a 43616368   Keep-Alive..Cach
0x000000b0 (00176)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x000000c0 (00192)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f777073 2f646f77 6e6c6f61   GET /wps/downloa
0x00000010 (00016)   642f4f66 66696365 41737369 73742e30   d/OfficeAssist.0
0x00000020 (00032)   3430352e 38302e31 3132322e 65786520   405.80.1122.exe 
0x00000030 (00048)   48545450 2f312e31 0d0a5573 65722d41   HTTP/1.1..User-A
0x00000040 (00064)   67656e74 3a204e53 49535f49 6e657463   gent: NSIS_Inetc
0x00000050 (00080)   20284d6f 7a696c6c 61290d0a 486f7374    (Mozilla)..Host
0x00000060 (00096)   3a207764 6c312e63 61636865 2e777073   : wdl1.cache.wps
0x00000070 (00112)   2e636e0d 0a436f6e 6e656374 696f6e3a   .cn..Connection:
0x00000080 (00128)   204b6565 702d416c 6976650d 0a436163    Keep-Alive..Cac
0x00000090 (00144)   68652d43 6f6e7472 6f6c3a20 6e6f2d63   he-Control: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 76650d0a 43616368   ache....ve..Cach
0x000000b0 (00176)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x000000c0 (00192)   6368650d 0a0d0a                       che....

0x00000000 (00000)   804c0103                              .L..

0x00000000 (00000)   802b01                                .+.

0x00000000 (00000)   804c0103                              .L..

0x00000000 (00000)   802b01                                .+.

0x00000000 (00000)   47455420 2f61706b 2f323031 34313232   GET /apk/2014122
0x00000010 (00016)   322f7365 7475705f 39353136 35303639   2/setup_95165069
0x00000020 (00032)   2e657865 20485454 502f312e 310d0a55   .exe HTTP/1.1..U
0x00000030 (00048)   7365722d 4167656e 743a204e 5349535f   ser-Agent: NSIS_
0x00000040 (00064)   496e6574 6320284d 6f7a696c 6c61290d   Inetc (Mozilla).
0x00000050 (00080)   0a486f73 743a2064 6c2e6e78 352e636f   .Host: dl.nx5.co
0x00000060 (00096)   6d0d0a43 6f6e6e65 6374696f 6e3a204b   m..Connection: K
0x00000070 (00112)   6565702d 416c6976 650d0a43 61636865   eep-Alive..Cache
0x00000080 (00128)   2d436f6e 74726f6c 3a206e6f 2d636163   -Control: no-cac
0x00000090 (00144)   68650d0a 0d0a7472 6f6c3a20 6e6f2d63   he....trol: no-c
0x000000a0 (00160)   61636865 0d0a0d0a 76650d0a 43616368   ache....ve..Cach
0x000000b0 (00176)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x000000c0 (00192)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f424656 43656e74 65722f42   GET /BFVCenter/B
0x00000010 (00016)   462d4246 5643656e 7465725b 5b414230   F-BFVCenter[[AB0
0x00000020 (00032)   30355d5d 2e657865 20485454 502f312e   05]].exe HTTP/1.
0x00000030 (00048)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000040 (00064)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000050 (00080)   6c61290d 0a486f73 743a2064 6c2e6261   la)..Host: dl.ba
0x00000060 (00096)   6f66656e 672e636f 6d0d0a43 6f6e6e65   ofeng.com..Conne
0x00000070 (00112)   6374696f 6e3a204b 6565702d 416c6976   ction: Keep-Aliv
0x00000080 (00128)   650d0a43 61636865 2d436f6e 74726f6c   e..Cache-Control
0x00000090 (00144)   3a206e6f 2d636163 68650d0a 0d0a2d63   : no-cache....-c
0x000000a0 (00160)   61636865 0d0a0d0a 76650d0a 43616368   ache....ve..Cach
0x000000b0 (00176)   652d436f 6e74726f 6c3a206e 6f2d6361   e-Control: no-ca
0x000000c0 (00192)   6368650d 0a0d0a                       che....

0x00000000 (00000)   47455420 2f323031 35303130 352f3933   GET /20150105/93
0x00000010 (00016)   37376d79 63735f59 5f6d6761 7a325f31   77mycs_Y_mgaz2_1
0x00000020 (00032)   32303142 2e657865 20485454 502f312e   201B.exe HTTP/1.
0x00000030 (00048)   310d0a55 7365722d 4167656e 743a204e   1..User-Agent: N
0x00000040 (00064)   5349535f 496e6574 6320284d 6f7a696c   SIS_Inetc (Mozil
0x00000050 (00080)   6c61290d 0a486f73 743a2078 69617a61   la)..Host: xiaza
0x00000060 (00096)   692e3933 37372e63 6f6d0d0a 436f6e6e   i.9377.com..Conn
0x00000070 (00112)   65637469 6f6e3a20 4b656570 2d416c69   ection: Keep-Ali
0x00000080 (00128)   76650d0a 43616368 652d436f 6e74726f   ve..Cache-Contro
0x00000090 (00144)   6c3a206e 6f2d6361 6368650d 0a0d0a63   l: no-cache....c
0x000000a0 (00160)   61636865 0d0a0d0a                     ache....


Strings
 " "
E

080404e4
1.0.0
BEARPC
CompanyName
FileDescription
FileVersion
LegalCopyright
msctls_progress32
MS Shell Dlg
Please wait while Setup is loading...
ProductName
StringFileInfo
SysListView32
Translation
VarFileInfo
VS_VERSION_INFO
www.bearpc.net
_+|`=?
}#|{/$:
@][.=/
*?|<>/":
\">;`\
+{;<>)
}&&@0=2
05# SL
0/By<i
0bZfEm`
0,cwDR'F3
 %0#d)
0DL!4P
0EV$$6
{0f6fOYk[~DN)
0]<F$c
=0~H/]
0'-h7s
0H7vcU
,+0hL!
&|0=j%
`+<0K(
0!L?Hp
0MCb+=
~0md.0D
0mF>xnG]
0M{H$tj
:0"|Os
0!_oUH/O
+0+qu6
0'rd=D
0>$REU]BPb
0rHfscn4
*0TSJT5 
0U5>uHU
 '0>Up
$0v[t'
\0Y@4!K
<0YIz:
0zd,L 
^<{10[1
1(63-c
{_1~67
1F{IFo
1gm0+*
1;.HhK
-_1-na
1o,vom
1S0+z3
;'1#Tc
/:1TPI
1[_`vB
1xm0RX
1Y[\'I
2(0RM(
22:(2h>7S:bx
;22j7X
24"8H4
25PIJC
2`6?P=|&
27#}aR
2=9R5z
2a r;T`
2|cB]6
)2c_zD
2}h/c[q;8Z
*2Ie j
2i>{g%N
:%2/$k
+2#o|$
2P4V^xG`
2q]%.MCu
2r~}G]
\2\RRy
2s]#44
+-2_SW
2tqDDF
2u	h1)S
2W?#y%.$]I
2X!7Y1JE6~VnN
]2*Ym!
2((Z8B
2z8j(O
3~^]--
3^0K.#\
32kF--b
? 33K!
3*5mQE
	_@37|
*37Gf6
3)8\tm
\3~a6g
3=ApP38
3bq>dAK
3cQxu!
3DdRx>
3Dw-WH
3EEmG.
3/hR'~U
]-=3I},
.3I2~E
3iHV~_
3Iy:ZG
3J.|3F
3J<Mvz
3K4h#N
3""k7{p
 3kZfH
3l;bVZ2
3lGk*w2
[?:3mGW
3`N@.3+
3n#h:,
3%NQ}uwg(
3Nufql
)	'3Ny
3O/:EL{
.,3owL	
3PD3 'z4
3p~p"\LB
3([Q!_
3\qa<P
3QR0!f
3qVQE T]5
3qY49AL
3q&Z_Uo
3tdJ~IU
"3Ux5n
3}}[V]
3@V(8jM
3wcVmdu
3wra$n
3x.iUu
$3}z(w
40r|mm_o	0
4^_6ud
	4#b7a<C4
;4cf/l
4ck-J-
4Cn>Lz
4feJ>Ra
^4!f"p4K
4Ge=ta
4@kc;H'
\4%l4P
4qlUB%
4Q~=t|
(4rYY2
-4	Sa!
:4S=!V
4.|}Vp
4+)VvW
4{w#c0 l
4xjkD:
50UiP&
'5(39N
(53(OI
 5fD:B
5/j15[
5jAX*#x
}5m3g-
5@?*PB
5QkK2~
5VMT~=
5@vnbP
	;+5}X
5Xrm%<
5ycpM.
',6%(`)
6a#lmf
6b"j6C
6,CJ,cs
`6Cvb2
6dy.4V
6f=RqTg
$6|H*`
6Iqn*rmB"
6J5d0L
>6jsI'|
^6k+6*
6M,.tx
6nC;W66EK
/6o<)t\}
_=6*PHi&
6pUgaF8
{*`6rg-
]6]tDY
&6v0}2
6vDg{C
6x=a<[
<6|xD`
6>x"l>P
6yiA&m
6yl8T,
70>0(z
`<'72"
72M0;C
.7"$3z
74g<HS
74oBy[
76{'2c
77$9;>
7/9eI\
7B@%d8%
7bgK*Gg
7BUkZX
_%7C@[
7C\Gh}y[!
%7cl8I
'7EZLM
&7F{o=F
7g8al$C
7gfXp|4
7gRP4o6h
7.@j:6E
7]>j(Ur`
7kb}yG
$7L cz
=?7M6@
7O'>6*7
7O.rZ&
7%q5AS
7R81edN
7rf^_f
7?_[|RK
7'&Ro?\
7s!b#V
[@7TTH
7:UN:6
7[/UNl
7XXSn>
7?y#8B
7y/ry.
,7Y'>wz
7z|jFH
}&,$&8
*(,`8}/+
82hkmvI{
82Mf@:M*l8
]8]@4CF
88B.[1
~8|>8Nyz
8A}3 0g9T
,8B]hF
8E$6e0
8@f3~*n
}\8{gh1j(
8iifQhN?
8"_IuX
8JM)q}Aq{
|8::-K
8KB.)i
8KEYgn!
8<l]`r
8#Mh&$:.
8n99%i
8NCRCu
,8@N)kqb
8$o%>K
	8o^:w
8Pe]yq
*=8qMYo%
8qTdn#<
8$r~l\L
`8T@;e
'8V=I}^$
-;-9#^
9}.2@l
92#Y>[
+9\6RV
9}*7+_
9/82@vQ)
#;^9;9N}
9a9tk>
9bbR|I
_9Cb)#
[,]|9d
9&e3:;i
9ghuHu
9h"CCK
?,9j6ZZq
_9K{l8
9kUQhNU4Q
9Nic1S
=9r$/(
9sg59bDm
:9S?\	Q
<<9t,>
\>9U&_?`
<9W8.p
9x| %F
9Y`lwb
a1&?]y
*A3|h>
A47Yp`W
A^~@(,6
A=6Do!+
.	"A6|,x
a:8(xyR
A9%~0A;UUN
AA-vC|
[a'c9{HK3
a%Cb~g3
^aCbXOI*`l
A$@<Cl[H(
acy=hM
aDIM*e,
AdjustTokenPrivileges
ADVAPI32
ADVAPI32.dll
adz-ze
AE12I/
>aE7)w
!a?}EPlh
aeTg]y{Cu
_$Afxq
[AgB>3
=AGj*;
AH:0y~9#}7
a}!hg""
aHHGi	
 ]'aHo`
aJBS2r
AjY.)j
a@KriRfK?
a>l/j.
a&MkBl
#/am<La
aNCk8<$
aN[m}^
aN(PF 
Anzo[3
ap]0^?-
AppendMenuA
appK0U
a*q,r*
.A>QTl
A$'Q;x
ar(;]<;?0
AR9	wo
As&HF9
'asilss`
a<u.~\
A\u>g{
AUXr}57
A']$vP
=Av|xa
A'[\W"
AwpU~&+
A!Xkj3
AxV>Gk
ay5~ur%&
=Ay+W 
B$0My$
B_0]uZ
b21PCW
B2jX5F
<b3n0l0
B:4.WA
!)+|b5
B;77hY
{[B8C\
b:8eh3
B8Gd=2
}B9MKh
!`%B9q3
ba[KQ=
b@aW&:
bBQ0K'
bc!u%:|
BE)c	K
BeginPaint
bfk~\PdP
BGl;>{6
B%h}0hg
BhjL{V
%bi7,M
Bi(CKr
bID	5`
{*bIHN
BiR[;w2]Y
 BIU@A
B#	IvR
B>IxIc
$"&b.J
Bk@YkM
.bLqp)
bMeSA9
BmqY5\
BMz,(pwE
]B|'O_'
{|b"	oC
b?:-p"
bPt('5
)BQE4W
;bqo{g
bS3>|+
BS?e7J
BuO0'6r
.bwo7)
B}>Wp8
b"xT&EF
![bx!U]
&#)[c]
%:^;c=
)?#{"C
;*C04o_
c}*1Pt
C2S8M'
c4=]6y
c4cYN]
(#C5^1
c7t&*q~
C8-"!UG
'C9>4D4
&;c/9U]
caG^%I
CallWindowProcA
C@a|z|l
@c_%Bl
CBnB.:
C|cPi)
.CCQt~
C-dAHq
CdT1IIS
C(EH]B
cEy~^&
CfR#)l
CF^ZL%
cg8!_d
cg\qnQh,Q
C..H,'
<ChAnd
CharNextA
CharPrevA
CheckDlgButton
CHox.gd
#Ci!3BcS
c&j?^C
c'k'KZ
CloseClipboard
CloseHandle
."c(`m}
=#CM~$&
*Cm J&ix.
	cMUL&5h
C#MYQ-
`.?C=N
|C ;Nw
CoCreateInstance
C#oLXbH
COMCTL32.dll
CompareFileTime
Control Panel\Desktop\ResourceLocale
CopyFileA
CoTaskMemFree
@{>c}OVd:
C:Q9Ww8
CqsI)m3
c#r-	-
C|r?B[
C-r/C~
CreateBrushIndirect
CreateDialogParamA
CreateDirectoryA
CreateFileA
CreateFontIndirectA
CreatePopupMenu
CreateProcessA
CreateThread
CreateWindowExA
{	c/rH$gmUC
crvK_$]E
cs`27b"
csOK77
cTqM\2
.C*T rQu
CTWAm	p
;C]U5|;
|Cuah3
 c@V3L
cVf=<N
?cW+M|
CX~xgq
CyB_eQ
cY&#h]e
C;yX9W[
_CZ1U`<ti
cZ4Z8C-
c%ZWN_
... %d%%
|d|)0B<t[
D$0+D$(P
d0N^$q
``d1N*K!
d)2oIy
D2~.zD
D(53km0
` d[69	
	D6{F[s
/d7d{l8b
D7m/}JiN
d80qEB@>
dARQ>v.R}`J
@.data
dc6~%,>
&D[&cQ
d^CvX$Ps
dD\6N/
|DD^Fg
D$(+D$ SSP
`~DDTsq
()dDv-g
%]|_De
DE5]ii
D#ebck
.DEFAULT\Control Panel\International
DefWindowProcA
DeleteFileA
DeleteObject
DestroyWindow
*DF7/>
D"FCrg
%d>FU[
=DGa+@
Dhl]`	
}dhXr4
DialogBoxParamA
*/DI}e<?%:
DispatchMessageA
d=j!1A
dJ4 }U
D_JNes
|d@kKT
d|K|MqC
?dkNa`
dLJ=},
D^?m^B
DnG:X"EkS
d;O> e	1K-n
dPcvf#
D pO!a:Ho
)dp_	+p
DpuM v
DQ5chOVK
dR'7D0
DrawTextA
%+drZX
DS3,|E
*Ds}Nx2
D$(SPS
d_-t"$
Dt=\c5SGb%
DUa% A
{<dxFL
+Dx=Hv@m
<d!yBU
dyRya_
dzYadb
e0|uYM
?e!3d-
E5IL\#
e6qL9b
*;;*e7y
=!,"e8	
e8K;3 
e`9Urr
EA CD~
~(eag]
EAhB7J
!e(b/9
ebE-85
e^[c00
ec$|noJ
EcSjec
EDAu$R
EDu2y*
ee5QY?e
E^eJ^/w\
ee"\K>J
,efF-[
E	fX%P
EHaWPb
:EH!bR7%UQ,
e`HQp=w
+*_eI7
E_>JUH
Ek'/[P1
EkyQ*|i!
El>I0e
EmBSWp
EmptyClipboard
EnableMenuItem
EnableWindow
EndDialog
EndPaint
e%OR7@
eP?mNkR
E+Q2n*
e*Q	DWj
%EqY0\
Error launching installer
Error writing temporary file. Make sure your temp folder is valid.
E;;,r"S
[es>8`4%
ET4bBL
eUk|#;5B<
e:up0l
]E}V(j
}=EV	U
>EW}H=tT
E XB^R E
ExitProcess
ExitWindowsEx
ExpandEnvironmentStringsA
ExReKw4
eY0AQAl
|{EyiU
' F}~>
;F!1lJ]rQoU
&f4a<y
(F4(n#A
+f4Q/1
F6C,Ut
f$6I}J
f7f 'nW7U`
#f7Hl!g
F&"7P/p
f93Vn 
F9`~hOo
F/A2e>
^f`=AquV
fb0y~~
f-BxsUq v|
f%+CNv
_FC"+W
FdU6a	F
Fd&V_d
_|Fe Y9
Ff9BfS
FFG^D6
(>FfwN
fgBWQT
FG&`{Tm
:)~Fgto
FH" {<
f:H#0m,
FhRN4&
FillRect
FindClose
FindFirstFileA
FindNextFileA
FindWindowExA
F^Ip=<
)F,J|N
Fjxw)l\
fL:4S&
{fl-hIM
fmh^5c
}F;Mj{4KtV
F(*mpx6
[(f=oj
F*%+Op
</:F'q
FqoT^Y
FreeLibrary
[f=rS9
Fsf=n1BK
fTS~g o
}FT&sgz]O
}'F,TZ
f$U$?C
FuONrdG
Fv@8		
f^VlmGp0
f>V"WF
Fwrmt"sN
-@f[].>ws
F"%#Ws
FX%HA=z
Fx.mp?
,*?fxo
(f:/yg
FZu^:]
')$@=g
G09[a 
g0fi|/
;^G0gX
G[0ki\
g	;1vn
!g?3=(,
g30eD:
'G3Wm0-
g]4p5<Am
]G4&U_
G^(5D-
g5h{4Zw
g	#5iK
G6Ae4w
g_6!/l
.g[{>7
<G8h>Ri
g9l2?R
G%a 5t
ga|(i%
+;g!<Cg
G?CgOD
gc[w2I@
gCXUdOF
gD/0f&
GDI32.dll
Gd?*k'g
#gDyK 
G;"e_	
[(gE&4k
GetClassInfoA
GetClientRect
GetCommandLineA
GetCurrentProcess
GetDeviceCaps
GetDiskFreeSpaceA
GetDiskFreeSpaceExA
GetDlgItem
GetDlgItemTextA
GetExitCodeProcess
GetFileAttributesA
GetFileSize
GetFileVersionInfoA
GetFileVersionInfoSizeA
GetFullPathNameA
GetLastError
GetMessagePos
GetModuleFileNameA
GetModuleHandleA
GetPrivateProfileStringA
GetProcAddress
GetShortPathNameA
GetSysColor
GetSystemDirectoryA
GetSystemMenu
GetSystemMetrics
GetTempFileNameA
GetTempPathA
GetTickCount
GetUserDefaultUILanguage
GetVersion
GetWindowLongA
GetWindowRect
GetWindowsDirectoryA
G/f4/3
(@Gf4")5
gH {`.
GH9W|t
GhsI%s
G~h&Txy
gH@ZQ&
Gi~?$E:|
gij^Da
gjlJ{$
g_}.KQ
GlobalAlloc
GlobalFree
GlobalLock
GlobalUnlock
g=lo%L`FF
gLol;q
=gl<Y(
Gm%L,K
GML:q]
>`G.`m.W
gm_/>y
Gn153H
goCb.0
GoNJ{_
>G(^os
/	G;osE
Gp&He.I
< (gPw
#g(%QB
g=qy%On(`
&GR~7z
g!rjXK
GrrB)%
gRrr4p
GS!	4/
GSF{D}
gt>,F<
GU!:\:
g u:HO
GUt>d!
gu;y68]
;G[wJ&X
gw#Un)u
g"xf@K
)	GxK6)
~GXR/pJ
$gXwpS
G*y9Gw~
g`~yP^
\Gz0q-
GZX-#;
h0o"}^4
H3jIugK
h3*+@u 3
}H4%1P
h4Aq{N
;+h 5Cn
h7$_#QT
`]-H7z
H+94K/
H)A{,6
,H`<]b;
!hBf,f
=HC3V/
hca7_z
H[?Cck{
HD6p7~
HD%&@D
heI+xp
h	;ES~
He[>]U
hF>2fD0,
HF74"W
H>_FIP
>HfP&Z.Y"
hgd< :
H^GQ3V
HHA(X1
h)i3~;g
(" HIMm5
hJSE\>
H_k>b7
&H),kp
HkS^%58
H^kteB
h?)l*_
h]~l}F
HM/&P4
H{mrF^d
HMX<@q
hOL80_]
h)OUp#
Hp6e4x
[h)paU
h{[q?{VU)
hRjxHo
hRsA,1X%
~h<S	^l
hTE{6U
http://nsis.sf.net/NSIS_Error
=\#<~hu
+)hUom
&hxRzC
Hyh%8a(jA
hz;G(V
HZ:r+4);
\I0hg<X_1
I*0Kn.
i0NLaj
_i6%`l*3^]
i7?Le}7
i7x>Li0W
i9Q1IHY
iAI$7|
I?AmlQG
IC .Ci
iE"}l#;o
IeWtT:
%i\fjQ
[i]g)2
/I:'G6=
_i&~gF+
%I/GL@
iG{!<Y
~iIj^y
iikFyE7
_IJjl~s
iJlC;(
IjTkP@
ikz0SH
ILh!@A>
i(lsS<L
ImageList_AddMasked
ImageList_Create
ImageList_Destroy
imo:A}i
im={#q
.I,My38
Im{yg!
i'N1;]
incomplete download and damaged media. Contact the
I%[]njb
iN]^+Or
Installer integrity check has failed. Common causes include
installer's author to obtain a new copy.
Instu_
InvalidateRect
iNxi9/V
In.y 5
IOQ'ng
ioY?Nz
I{p/5%
+i#p`R
Ipvz,\
IPWOC ~e
:IQ ~ 
{~iQ6R
IQ7Ww0
iQ-9ir
iqbf-@t
i(}Q@.l
iqsi3j
IqX6V/f
.I=RI)_
iRichu
}i[]s}
IsWindow
IsWindowEnabled
IsWindowVisible
Itgp m
>,} Iu
$&.Iu^
I[uGDH
'IU,;i
Iu/"nG
iVv.nu
@]{I_W
iWy3CY
>,i;X.
iX9~u)
		.IxbP
Ix_QT~J)
I!:x&S
ixYr^]Z
IZ^:TK
j0kN8'
\-[J0M
j0P/Y13kPX
j^%2(Z<
>J/+3p
:J3Zl{G=I
J46FV#$
  |j4c
J4}I49
j}?bV/
J':b@`X
]+J~by
Jc1c{4
|)JC?deF
j,]Czs
Jd'[+4
,jE&j.
JG.:.Xc
(:-\+JH
j?hC=4CN
 JHgbC
$JHkd&
Jh'oQn8
JiawZk
+jI'mx7
_j',JZ
@_J$K	=
)Jk~Q~
[JLO[G
jMc$m=
-$*J?n
Jn!B_9
?JN.k8r
_j<%O){;
JO4Q@m
jOdCVYj<:
jp-:)]
j :'PHH
\,jRJzB*+
jSOdZTq
=.(JU2|
Juf{p_
JuNup1
juqWoo
JWxN	}
jYK{ M 
}JYqu3p
/jZ*^)*
^JZ>:SZ8\Mn
~`$K=_
K0 N?[
K37'mL
[k3b=~
` K3T7
"K%4CN
K5C0BS
k6;`'E
(K8p-;
k8p;ny
K8?tGCv\
k;8X\YO
K=#9aF'
k"a-&|
k^c%f,
_}Kd-3
KdJh3y5
kEP)33
KERNEL32
KERNEL32.dll
(~ KF|
KFRL#v
K.G^	Dl
=kH5@q
kH/o%j
`)/K	I"
<(kIW.
	]kl}NT
kmL|"!
kMs0[T
=K'n,v
%ko4sqXC
	/K,OGl
$/ko&q(
?K=p1us)
@#kP:j= S
|-k+Q0
Kr;D\O
\k,>S<
\=	(ksB3Q2C4G0
K#=/tF!
k`V4*[
?k w`]
kWDNB^ud
?kX6;:
Ky\0RnJ
Kyk9[]\
KZEU|@
"|=>+[L$
L0$jhuQ\
l7"1#g
L7NGK`5
/L7xi]
)`l8)&
L`8m4+
L	9@]8
l!!9SI
"@la/9
 ['LaC
lb={)+
lB6lr-7N
;Lbg<bG
L-)BTK(
`l-)c<
l	c19~
,Lc+*n
ldSb5Y:<
LEi`Bq
LEv[2]T|+
L{fV~,
L\/:Gl
LH{uxl
|Lhx&"
LI'I}K+
L)Iqn9@
ljJPzRM$XF~
L KH>]
`;l$KhD!2
L@k?J:
lK<;RR
>#LK't
\(lKYl
L#M%r8
l&[NhU
^lNIms
L=nULh\
)_LNUo
LoadBitmapA
LoadCursorA
LoadImageA
LoadLibraryA
LoadLibraryExA
LookupPrivilegeValueA
lQ:LR=
Lr.1bVJ
_lSP_@"
L&sQgc
lstrcatA
lstrcmpA
lstrcmpiA
lstrcpynA
lstrlenA
]LtaMZ
L>*TF}
l #tT^$m
~LVe3M
&lvr)g
LW}iD^
L'%Xmmzp
=LXQ,Y3
ly3|='I
*=(lyd
L;Yz:n{.
L`|zE!
#m0?4D;"p
M<.=2P
[m3{N,q/;
m4$=|8
M4fEMe
'm4j	O
M4xC;5
?M@5R=
M656wH,
!m79Nh
m7K~UD
<m?(7Q6
;`	 m[Az
""_Mc8
M^C}m[
mdu#\7J;
MessageBoxIndirectA
mf8C":^
=M&?H+
mHuaiV
mi2RQ.'h
\Microsoft\Internet Explorer\Quick Launch
MJg	)tc
Mj+(h<
M.j{>P
MkB %9o5V
MKB&]Q
m#kmy;#
mlA7rZ1
]MlGc	
mM-di~
mm?E6$
>M*MEW/
mM-S\H
M!|m X
mm],YL
=mn^3I
MN'#>b
mnT,+i)#
More information at:
MoveFileA
MoveFileExA
+mPH;t
.m+-}q
MQ=-h|
;M>q)Y9}
mr:zvJ
?m*{s9&
=MS	CQ
mt1)@J
MUb+fS
MulDiv
MultiByteToWideChar
mV('^'
\mv1NM|.al
M&*&V[8
mW\BmX
M"w*e;
mWL-OV
'M~Xibr
(m[ZuI
n:<1S5
N2ndx		
]}n<3J
"n7a[G
`n7)aMI
n<7m?Q
n#7se#
n!a*% 
N.`agxpqTw
NbjE]y
)nC.=(
*nCQ^M
.ndata
nD_f4(
NFP,}>
NfryM\
<Ng	"1
"nG4WC
<N)G6d
nG*'rM
N-hG%|
Ni0%E)31
/[<n J
NJff58
Nk2zX@
N}"K4w
NK-[Zd
n;,%N~eo
_NNOXr}
no{$ty0V*
&nPm-r'
;NPODir?
"N:,'#PrH
+|`nq._
NQ9mZM
{nQg="
NSIS Error
~nsu.tmp
-Nt4IAj
'*nt9.u
n(TG$t
{nu}dG
NUE%kkJ
NullsoftInstRz
NulluM	E
nv	Oj1y<
N%vvt5
NWj&Z=
$NWKse
n|x>9c
)NxrsDi
/:NZbvJ
o1`3u!9
o^2B:\
~o4u_p66@<
O7)'U5Z
_O;8	L
O]a1YN
@&OA"pS
_$O@BF/
Oblx5C
\o$bUA
oBz#9VC
oC#?k2
|o[dgC2J
O)DjiH%
O#d/TH
OEipNL;
oF4!Hr}
og*|&|V
)"oH_0P0Q
OH8hc><D
oH=Bv/
 ~\O k
ole32.dll
OleInitialize
OleUninitialize
olKmCE2&
<;=%/om7
*om|F$ Y
o?>MRB
oM`S(D
+OM\uC
On(@;rX
o>Oei#Z
}{O	Ol
ooZ-,q
<	\OP,
"?[&OP
OpenClipboard
OpenProcessToken
o|P(SL
OQD$ERY
oqj]>z
os~VB#
oTK3.>'
*O^Un#yA
OVfktB_
O?$\`W
:Ow2V/K-
ow/ sRk
o'ws.>t
OWtE/>}
ox,DDmA
OX'K>	*
O-YbC{
@ -oyN
o).:yS
{"O`z]
oz82cY
)P0Y4>
:p3k;r
P56@7Dh0
p=6 tk
	p8NSf
&P	-9<
p9u),S
 pB|4(
(PDb5O.
P#e2lG
PeekMessageA
pFTU+d
pGh^0J
#<pgPP
PI	VMlU
|#p&J]
,/p#Jwj
PJxP>:B
plP=#~
pMwTNF
[:.PM z
PostQuitMessage
}^POV>
PP,LWz
p	{pN.
PPPPPP
pQ75_!
P#R(73
PrkE<&@
+pr_qZ1
PsJ>\%Y
p*t2@J
PT8Vu'
pTb-	R
*PUb93
p*uFcpo
pVgNzY
P<V(pm`
|\PWCK
	pxGZC>w
pyTE+J
p(Y/TO
.PZd8|
p,#!ZQ
^pzynW
q;1H@R
q]1#z1
:Q])3U
Q48P4_
Q5=^K*
q)6*|+
q6NaVh
Q7'S?:dN8
+Q8_K9:
Q[9|eh
q]a$;]
]QB%@@
q_ddMy
Qd!#Oq4
qEGiO'g^
QE*U|2eH
qF~[--
]qF9z}
qgj/ w*u&
QGyG{O
+QGyh`.
-Q-HS"
q;/I7C
%QIB#qja
q=Idtg
_QIG5hq
'?qI?H
Q(IL:}
)q"j6N?
QJpN;p#
qk8j-%E
q,_kl 
QLF	!J
"q~)lM
'<qLrY
Q{""(m
_@QM4&
Q-M;G/M
qmuGoa
qN|obK>
\qn%Q22oct*sB
`[^}QO
QO1ww%Du
$Qp)1V
qp2W(W
Q/Pyg6
	QR-J>
Qr|[-VHo0
Q&\=S`
qSfjFe
?Q%sg=
qT/9vHL
[^Q&teY
Qt?OJ-b6x<
:qU"[9
QuXlh[L}
QvQAG	
q=|w3+p
qXeaF:
qX-@Fno
Q@zR;b
!r$*?$
/\R:^&
_~R0(P)6
<R0T/jKr
`R1'Lfp
R5e}$2b
R5t4pL
r8p<Hi
r8v9xh
(-	ra1
r->A/S
RB5?)E
Rb"5YU
}RBCE%
R{^bJE
r *c!R|
`.rdata
R=dM<x
ReadFile
RegCloseKey
RegCreateKeyExA
RegDeleteKeyA
RegDeleteKeyExA
RegDeleteValueA
RegEnumKeyA
RegEnumValueA
RegisterClassA
RegOpenKeyExA
RegQueryValueExA
RegSetValueExA
RemoveDirectoryA
[Rename]
r@*`FL!:]
]rfusH)
Rfv$G/N)
+{!r'G
rG|I*(
rgT"'fG
Rgwk=D
/rI4j7
RichEd20
RichEd32
RichEdit
RichEdit20A
rim2~k
)) rJg
)rjZI>
'RK5'hz
r@KC7b
RK@oTA(
r`#k\S
)^;rl'
+rl?<Y9
=%RMmA
	rM}N|
#RN8H9
'rn,'Y
rO3j<#
Rof8p`=
^Roub<
\r;p)"
RPc+*=A
]rPpNy
r'Q0kid
rq2fx6o
rQ5u\y
*{R'|s
?rsfTPp
RtcA ~
},R}"u
$ru}UI
rv	`?,
rVazpM
%r+~vH
rv:@qc
rwC~	e
R=W#^U
rXHf{g
rXv	.[
ry%CvD'%
RzdD69
R>@z%OV5
;)=[ S
S'0'tu
{ <s0v
s1DXu%
.-!+S3h
|@S7u:
S7WIAI
s]+9;>
@s9jaS
s	*a.'.
SB1c^OI:
s`CHYS
ScreenToClient
sDgq]#
_Sd]M6
Sdonu{7P>
S,DZ~i
sE 8^Ku
SearchPathA
+Se>L`
SelectObject
SendMessageA
SendMessageTimeoutA
SeShutdownPrivilege
SetBkColor
SetBkMode
SetClassLongA
SetClipboardData
SetCurrentDirectoryA
SetCursor
SetDlgItemTextA
SetErrorMode
SetFileAttributesA
SetFilePointer
SetFileTime
SetForegroundWindow
SetTextColor
SetTimer
SetWindowLongA
SetWindowPos
SetWindowTextA
.s,F4'!
SF%z*-
S{GlT+
SHAutoComplete
SHBrowseForFolderA
SHbzrqRi
SHELL32.dll
ShellExecuteA
SHFileOperationA
SHFOLDER
SHGetFileInfoA
SHGetFolderPathA
SHGetPathFromIDListA
SHGetSpecialFolderLocation
SHLWAPI
ShowWindow
sHx^%4
<Sk7Cu^r
s+!L,2
s%lsP q
s'&Lx,
softuV
Software\Microsoft\Windows\CurrentVersion
-s~P(A
S(pavbRPn
'S(PD4
 ]Sp!WRt(
S`}'px
`S"(q.^o
SQSSSPW
&sQZfpr
@)*&SU
]svSOr[
S/#w5L
SWQVt!a
_Sx0P6m
SXk#OkaJ7
)SXz/\
SystemParametersInfoA
	s(Yx8~
S&YYS7
SZU<b$
> _?=t
${ }%t
+(=.t<
t},\{:
t0=Nhq
t1E7|D|z
\T235^k
>{T2cc
*=T3+6pQ
=`t3N\
t4[+AWp
t&|87=
t8#Jazu
T)8KG]G
t9du_]@
T9:XodG 
Ta>@?YD
|#;T#B
*Tb:EHx
t-CC_;8
Tcezy]	
t>`e4q
.TeQn]
^]T^F[
-~tf)3
t	fGi,
%tg|	f ~
Tg><Q\
T&g.yb
!This program cannot be run in DOS mode.
([^Tic
>]T,iN
T@J4\X
tJIC2),8
t$KP^B
t<k{Xc
TK ZM:
tL7ZZ6
/tl&F7
|TLg?S
T**{L(s(
TnmVK>
tn`OGn
TN^R^Sq;
T ;o&\
to2I*K
{T}od9
to(+ex
_^[t	P
tpIzk5;
"TP&|jhr
#tP{!k
TQ)Zy,
`[??tr
TrackPopupMenu
Tr[PE{E
 tRuzE=
ts[ytL
}&TV@K
^,T}(VMtPu7<K
Tv!r_7f
)tw} !9
tx!i5>
``txv]
TyNX	=
<TY%O?*
T\yo/8
TY>W[L
T<yWm|+
Tyz5kA
)},)U!
&.+U`<
U0;sU6
u49-,?B
U4a9ks
U4:.e+
}U55` 
u77I"E})cS
U7C\\K
U 7Td:6
u*8iI6
U|9+W;
UA6#P&3
]UasYO^
Ua,vEP
#)Ub)4h
U{'D<	
u=D9k`
u~E\?6
}UED6}
Ugam 5]Ta
UgBIdR7/
`ugNA2
uGsd#>f
{uHdd<
Uhn#*f
UIN[~t-.d
@#_u~"J
uj)?CE
[U!+|K
UK+	_'
'Uk-Iy7
`uLlc'
-uly0jq
um{^=|{
unpacking data: %d%%
U`ONWz
UP'N`v
-UQ5pK<
UR]_0vQ
UREy>|<
Ur?!Os&
U(?R"t.:
USER32.dll
U,sH 1
%u.%u%s%s
#	UW}	
!uW:g$
<_'u.x7
uxFscta
Uy7p,n
Uyu1lC
u}+`zx
~(v[=_
%v	|=,
#:V@~+
	^<?\V
V|,>=1
V]2{~[
 .v26v
V3TRSY
?V8Rm`
=V%9`.
v95LpA
"<vAq2
v^D	j_
v%dsz~
veAO8J
vEo2=x+
_V]]Ep
V_EqiO
verifying installer: %d%%
VerQueryValueA
VERSION.dll
VeV=q~8
>+vFybh
vFYhdr[)
VFZidF
V<GY&>Z
#Vh;+@
VH8Qm`
;vkb'u
^<v;;l
\.VL#T
V~M~9s
^VM>l-J
Vnm|E`
vo+P$Z
vPJXyg;
{VP:NRASU
%Vp	%vk
V"r7cX
v	R7#z
~Vr9JQ<
VRMu,4
vSeN:'
v?SQWr
	v:T}'"
vtT1V*
VTujRY
v[u6+v
vvcH~%
]VY)58
<v]|Ym
V%zC_n
?[w'~:
"w ^[1
w1#~';b
W\1+wT
w,2GpB
w3?#?A
W3^hHu
w@3rP^v
@}w+"5
w5e4v2
W81w~!)
W8KA	9sK
>w8MIHxO}
W9n F+
w9wBa!l
waD=^s
WaitForSingleObject
w(bopy=
w;&d{o*
$wD(YT
wd]Z:a
wEF\!r
WE%(~l
$wEm`,
wesuSY
WF7oY[
W+Gd9Eg
w@G#Uz
w%Hkf^
)wH]wk<
	wi0 o
 wIr(#
W>i/@`Z
wJLZ60
WJ"S2Y
-W*kpd
W@~+	l
 W$.L~
w{*lCp
wM;|MSm
wo*t9K
w*pcU8
=>WP;U
'^ W!q
Wq``WO8U
WriteFile
WritePrivateProfileStringA
wS$<))B
w#~-SF?
wsprintfA
wt3STK
WT]/)K
W)Tk*X
w!tyCC
W|`ub<Y{
-=*w~;v
wVBK7Jq
',W;WM
*w)x&h
w.#.y$
|`W+ysSfU"
Wz3cbN
!+wzt_o
~[~+$x
x06M\?
(#X0S$
x	1hzGFq
x'2&(v
X3%PaH
X,_4=w \
\X5JQuC
X$6l>FFOn99
X!)9LM~
+xC'g6
`XCQ"(
XD;)dq
xE|5-/
xg4D)^
!X/gfE
:XIl9#S
?{XJ4`.
~xjS6F
xk,.bdZ
x*(kFU
'X>(M2
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.46</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="requireAdministrator" uiAccess="false"/></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/></application></compatibility></assembly>
xmO^Ww+
{x?'n%
XN")4$
x~N8WZrf
XnU$*":
xp9&&p
<xsF)TV
}:xSwk09
x*t	TPPq
xu\FI&
[#% $&xw
Xw/'e=
XX!5hK
x[&xl~
xx[mod
-x>_Xp
XXUQ|E/
X/yy2W!
Xzt86#[
XZvhn,
 ]<Y<$
+Y0la2w
y{0VGO_
Y-1<U`
}y$2={`pOD
Y2Vf>3xJ
y2YPi%
Y3!U0@
-Y61.wb 
Y,!}9UN1
ya_79y
y}{B(3
yB`gEf
Y`&D@B`
y!:E@H{	
$y~F5o
yg[$AE
yGaZ#O
y?<G}zpU
yH7.R>e"
yhs^Qfp
Y_HY(`
Y%[}@i
Y{iHm0A
Y_\j=]c
yJSu5'
}y*k8l
Yk.mu$C
Yk%{tp
Y^L{LyV
ylV?AP^
ym|edXg
yM^ lm
YnmuFU
(Y+oBs
yO(S t
yp3g2J
ypHx5=
Y<)POn
YpX{EN
{Y/"qA
 YS6 9
ys>O/Y
YS.wUO
yUH%8%l
!YUX`+\Im
yV9|tqt
~y@ VP
_!Y'w^
YWjPx4 ;k
	yW@N,
yw:	p{0c
yx^N-D
!,y"yM
Yy[o.)Kb;
Yy%;$w*
y\zF5%
\_.	/z
Z3GV{C5i
Z<5`op\
,z6Hb,Ai
]Z&6`Y
}@^z7\J 
!Z7x/}7
Z	8[[z
Z9CJ(@t
z9OnC4
Za3R{m
ZAB{Yi
z|\*AE
Z|`a(i
*zbA`7
zb/Bpl0
Z=B;BY
Zbl[1^
] &Zc$8SE
	[Z"d#
"ZdK&E
ZE&)sm
Zfm{LJ1$E=
ZgDxUh
zH/dNoR
@zI&i'D
!}zI}L4
Z	Jh8RY
zlnXY'k
zmf%x5V
ZN0O{;K
]*Z|o`
#`:Z<o
zO+&}2
ZOF25tz
[ZopT a
}zp5Gc
Z``P/g
. zRW|@
ZSTfxo
Z^T+ J
/z t"k
ztL8Erc
>_#ZUg
]ZuVj*r
[zv"# 
^)ZvS2
/zvxJD[
_%*zvy
<Z~W)i
.zY-?R3
'zZD%|
zzEVt*
zZh@@I
zz'hjLp[
Z{+[ZJ?b
_z)Z,M+0Ia)