Analysis Date | 2015-01-21 08:40:31 |
---|---|
MD5 | 16eabf0771598243ac5497a60880d693 |
SHA1 | f02c94de382a7593bebf9e0b80a8ad74d8c52b6c |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 7ebfade271f75cb4c180603ab653af42 sha1: 45720e3559680fe044efceba32f55e60ed85f918 size: 23552 | |
Section | .rdata md5: 9d6e96915262c9d1129a16fa0b02a19a sha1: e46950b3424baeebebe8ab21b9f9674839c38bd6 size: 4608 | |
Section | .data md5: dbf10679c897d0edeee280fffdad552f sha1: f257e37a5d8648d6123cef40868059ee78a136b9 size: 1024 | |
Section | .ndata md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0 | |
Section | .rsrc md5: 0116c372633c89bf4758489792916f62 sha1: ac6ccb128d957f5c855acff9d169bd634b918960 size: 27648 | |
Timestamp | 2009-06-18 21:33:27 | |
Packer | Nullsoft PiMP Stub -> SFX | |
PEhash | 4af83691957ff9812f1cf5f159c232d531a19e47 | |
IMPhash | 099c0646ea7282d232219f8807883be0 | |
AV | 360 Safe | no_virus |
AV | Ad-Aware | no_virus |
AV | Alwil (avast) | no_virus |
AV | Arcabit (arcavir) | no_virus |
AV | Authentium | no_virus |
AV | Avira (antivir) | TR/Dldr.Chindo.121403 |
AV | BullGuard | no_virus |
AV | CA (E-Trust Ino) | no_virus |
AV | CAT (quickheal) | no_virus |
AV | ClamAV | no_virus |
AV | Dr. Web | no_virus |
AV | Emsisoft | no_virus |
AV | Eset (nod32) | NSIS/TrojanDownloader.Chindo.E |
AV | Fortinet | W32/Chindo.B!tr.dldr |
AV | Frisk (f-prot) | no_virus |
AV | F-Secure | no_virus |
AV | Grisoft (avg) | no_virus |
AV | Ikarus | no_virus |
AV | K7 | no_virus |
AV | Kaspersky | HEUR:Downloader.NSIS.Feasu.heur |
AV | MalwareBytes | no_virus |
AV | Mcafee | no_virus |
AV | Microsoft Security Essentials | no_virus |
AV | MicroWorld (escan) | no_virus |
AV | Rising | no_virus |
AV | Sophos | no_virus |
AV | Symantec | no_virus |
AV | Trend Micro | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Registry | HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝ NULL |
---|---|
Registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝ 1 |
Creates File | C:\Documents and Settings\Administrator\Start Menu\Programs\Pc6Soft\uninst.lnk |
Creates File | setup_001.exe |
Creates File | BaiduPlayerNetSetup_472.exe |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\1.ico |
Creates File | ins1256858.exe |
Creates File | PIPE\wkssvc |
Creates File | C:\Program Files\Pc6Soft\Uninstall.exe |
Creates File | G30769_s_0529.exe |
Creates File | 9377mycs_Y_mgaz2_01.exe |
Creates File | G0828_s_70988.exe |
Creates File | setup_3386.exe |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\NSISdl.dll |
Creates File | \Device\Afd\AsyncConnectHlp |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\Inetc.dll |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\3.ico |
Creates File | IQIYIsetup_l_spl004@kb010.exe |
Creates File | C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat |
Creates File | C:\Documents and Settings\Administrator\Cookies\index.dat |
Creates File | 2345Explorer_329242_silence.exe |
Creates File | PIPE\lsarpc |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\i.rar |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\System.dll |
Creates File | PIPE\srvsvc |
Creates File | WanDouJia_runk4_kb.exe |
Creates File | Browser_V3.0.1167.3_r_4279_(Build14091614).exe |
Creates File | SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nsi2.tmp |
Creates File | BaiduBrowserOnlineSetupSilent-494-ftn_30000046.exe |
Creates File | C:\Documents and Settings\Administrator\Desktop\Intrenet Explorer.lnk |
Creates File | QQBrowser_Setup_Hk_78653.exe |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\nsProcess.dll |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\1.ico |
Deletes File | setup_001.exe |
Deletes File | BaiduPlayerNetSetup_472.exe |
Deletes File | IQIYIsetup_l_spl004@kb010.exe |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\3.ico |
Deletes File | ins1256858.exe |
Deletes File | 2345Explorer_329242_silence.exe |
Deletes File | G30769_s_0529.exe |
Deletes File | 9377mycs_Y_mgaz2_01.exe |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\System.dll |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nsy1.tmp |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\i.rar |
Deletes File | G0828_s_70988.exe |
Deletes File | setup_3386.exe |
Deletes File | WanDouJia_runk4_kb.exe |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\NSISdl.dll |
Deletes File | Browser_V3.0.1167.3_r_4279_(Build14091614).exe |
Deletes File | SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.exe |
Deletes File | BaiduBrowserOnlineSetupSilent-494-ftn_30000046.exe |
Deletes File | QQBrowser_Setup_Hk_78653.exe |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp |
Deletes File | C:\Documents and Settings\Administrator\Local Settings\Temp\nso3.tmp\Inetc.dll |
Creates Process | |
Creates Mutex | c:!documents and settings!administrator!local settings!history!history.ie5! |
Creates Mutex | Pc6Soft |
Creates Mutex | WininetConnectionMutex |
Creates Mutex | c:!documents and settings!administrator!cookies! |
Creates Mutex | c:!documents and settings!administrator!local settings!temporary internet files!content.ie5! |
Winsock DNS | xiazai.9377.com |
Winsock DNS | down.yinyue.fm |
Winsock DNS | w.x.baidu.com |
Winsock DNS | pconline.org.cn |
Process
↳ C:\Program Files\Internet Explorer\iexplore.exe
Registry | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Window_Placement ➝ NULL |
---|---|
Registry | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Locked ➝ 1 |
Creates File | C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat |
Creates File | C:\Documents and Settings\Administrator\Cookies\index.dat |
Creates File | PIPE\lsarpc |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat |
Creates Mutex | _SHuassist.mtx |
Creates Mutex | Shell.CMruPidlList |
Process
↳ Pid 0
Network Details:
DNS | int.dpool.sina.com.cn Type: A 180.149.136.250 |
---|---|
DNS | pconline.org.cn Type: A 222.186.60.70 |
DNS | pconline.org.cn Type: A 222.186.60.2 |
DNS | pconline.org.cn Type: A 222.186.60.68 |
DNS | pconline.org.cn Type: A 222.186.60.69 |
DNS | aaa.163vv.com Type: A 60.222.232.224 |
DNS | aaa.163vv.com Type: A 222.186.60.18 |
DNS | aaa.163vv.com Type: A 222.186.60.23 |
DNS | aaa.163vv.com Type: A 222.186.60.60 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.234.4 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.235.2 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.235.3 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.235.5 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.235.6 |
DNS | opt.xdwscache.glb0.lxdns.com Type: A 8.37.234.3 |
DNS | swwx.n.shifen.com Type: A 123.125.65.175 |
DNS | dl.p2sp.n.shifen.com Type: A 61.135.185.123 |
DNS | dldir1.qq.com.cdngc.net Type: A 174.35.56.86 |
DNS | dldir1.qq.com.cdngc.net Type: A 174.35.56.154 |
DNS | g.quwen320.com Type: A 219.238.237.210 |
DNS | down.gtm.ucweb.com Type: A 121.14.161.99 |
DNS | down.gtm.ucweb.com Type: A 123.150.188.48 |
DNS | na.b9.aicdn.com Type: A 108.186.7.129 |
DNS | na.b9.aicdn.com Type: A 108.186.7.130 |
DNS | na.b9.aicdn.com Type: A 108.186.7.131 |
DNS | na.b9.aicdn.com Type: A 72.8.188.90 |
DNS | na.b9.aicdn.com Type: A 72.8.188.94 |
DNS | na.b9.aicdn.com Type: A 72.8.188.98 |
DNS | download.pps.tv.webscache.com Type: A 119.188.40.81 |
DNS | download.2345.com Type: A 60.191.223.4 |
DNS | download.2345.com Type: A 60.191.223.15 |
DNS | download.2345.com Type: A 61.147.127.202 |
DNS | download.2345.com Type: A 61.147.127.203 |
DNS | download.2345.com Type: A 61.160.245.8 |
DNS | download.2345.com Type: A 61.160.245.11 |
DNS | download.2345.com Type: A 61.160.245.14 |
DNS | download.2345.com Type: A 122.228.248.3 |
DNS | download.2345.com Type: A 218.75.155.244 |
DNS | download.2345.com Type: A 60.191.187.15 |
DNS | download.2345.com Type: A 60.191.223.2 |
DNS | dl.wandoujia.com Type: A 125.39.216.11 |
DNS | s.lllsoo.com Type: A 42.120.61.139 |
DNS | down.yinyue.fm Type: A |
DNS | xiazai.9377.com Type: A |
DNS | w.x.baidu.com Type: A |
DNS | dl.p2sp.baidu.com Type: A |
DNS | dldir1.qq.com Type: A |
DNS | down2.uc.cn Type: A |
DNS | soft.lvbaoranshiye.com Type: A |
DNS | dl.static.iqiyi.com Type: A |
DNS | download.2345.cn Type: A |
HTTP GET | http://int.dpool.sina.com.cn/iplookup/iplookup.php User-Agent: NSISDL/1.2 (Mozilla) |
HTTP GET | http://down.yinyue.fm/open/setup_3386.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://xiazai.9377.com/20140928/9377mycs_Y_mgaz2_01.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://w.x.baidu.com/go/full/2/30769 User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://w.x.baidu.com/go/full/1/70988 User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://dl.p2sp.baidu.com/BaiduPlayerContent/BaiduPlayerNetSetup_472.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://dldir1.qq.com/invc/tt/QQBrowser_Setup_Hk_78653.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://g.quwen320.com/d/ins1256858.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://down2.uc.cn/pcbrowser/down.php?pid=4279 User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://soft.lvbaoranshiye.com/SoHuVA_4.3.0.1-c204900003-ng-nti-s-x.rar User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://w.x.baidu.com/go/mini/8/30000046 User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://dl.static.iqiyi.com/hz/IQIYIsetup_l_spl004@kb010.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://download.2345.cn/silence/2345Explorer_329242_silence.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://dl.wandoujia.com/files/inst/WanDouJia_runk4_kb.exe User-Agent: NSIS_Inetc (Mozilla) |
HTTP GET | http://s.lllsoo.com/click/66947 User-Agent: NSIS_Inetc (Mozilla) |
Flows TCP | 192.168.1.1:1031 ➝ 180.149.136.250:80 |
Flows TCP | 192.168.1.1:1034 ➝ 222.186.60.70:21 |
Flows TCP | 192.168.1.1:1039 ➝ 60.222.232.224:80 |
Flows TCP | 192.168.1.1:1040 ➝ 8.37.234.4:80 |
Flows TCP | 192.168.1.1:1041 ➝ 123.125.65.175:80 |
Flows TCP | 192.168.1.1:1042 ➝ 123.125.65.175:80 |
Flows TCP | 192.168.1.1:1043 ➝ 61.135.185.123:80 |
Flows TCP | 192.168.1.1:1044 ➝ 174.35.56.86:80 |
Flows TCP | 192.168.1.1:1045 ➝ 219.238.237.210:80 |
Flows TCP | 192.168.1.1:1046 ➝ 121.14.161.99:80 |
Flows TCP | 192.168.1.1:1047 ➝ 108.186.7.129:80 |
Flows TCP | 192.168.1.1:1048 ➝ 123.125.65.175:80 |
Flows TCP | 192.168.1.1:1049 ➝ 119.188.40.81:80 |
Flows TCP | 192.168.1.1:1050 ➝ 60.191.223.4:80 |
Flows TCP | 192.168.1.1:1051 ➝ 125.39.216.11:80 |
Flows TCP | 192.168.1.1:1052 ➝ 42.120.61.139:80 |
Raw Pcap
0x00000000 (00000) 47455420 2f69706c 6f6f6b75 702f6970 GET /iplookup/ip 0x00000010 (00016) 6c6f6f6b 75702e70 68702048 5454502f lookup.php HTTP/ 0x00000020 (00032) 312e300d 0a486f73 743a2069 6e742e64 1.0..Host: int.d 0x00000030 (00048) 706f6f6c 2e73696e 612e636f 6d2e636e pool.sina.com.cn 0x00000040 (00064) 0d0a5573 65722d41 67656e74 3a204e53 ..User-Agent: NS 0x00000050 (00080) 4953444c 2f312e32 20284d6f 7a696c6c ISDL/1.2 (Mozill 0x00000060 (00096) 61290d0a 41636365 70743a20 2a2f2a0d a)..Accept: */*. 0x00000070 (00112) 0a0d0a ... 0x00000000 (00000) 55534552 20616e6f 6e796d6f 75730d0a USER anonymous.. 0x00000010 (00016) 50415353 20494555 73657240 0d0a5349 PASS IEUser@..SI 0x00000020 (00032) 5a452031 2e69636f 0d0a5459 50452049 ZE 1.ico..TYPE I 0x00000030 (00048) 0d0a5041 53560d0a 54595045 20490d0a ..PASV..TYPE I.. 0x00000040 (00064) 504f5254 20313932 2c313638 2c35302c PORT 192,168,50, 0x00000050 (00080) 312c3139 2c313337 0d0a5349 5a452031 1,19,137..SIZE 1 0x00000060 (00096) 2e69636f 0d0a5245 54522031 2e69636f .ico..RETR 1.ico 0x00000070 (00112) 0d0a3031 35203038 3a34323a 33332047 ..015 08:42:33 G 0x00000080 (00128) 4d540d0a 0d0a3c68 746d6c3e 0a20203c MT....<html>. < 0x00000090 (00144) 68656164 3e0a2020 20203c74 69746c65 head>. <title 0x000000a0 (00160) 3e343034 204e6f74 20466f75 6e643c2f >404 Not Found</ 0x000000b0 (00176) 7469746c 653e0a20 203c2f68 6561643e title>. </head> 0x000000c0 (00192) 0a20203c 626f6479 3e0a2020 20203c68 . <body>. <h 0x000000d0 (00208) 313e4e6f 7420466f 756e643c 2f68313e 1>Not Found</h1> 0x000000e0 (00224) 0a202020 203c703e 596f7572 2062726f . <p>Your bro 0x000000f0 (00240) 77736572 2073656e 74206120 72657175 wser sent a requ 0x00000100 (00256) 65737420 74686174 20746869 73207365 est that this se 0x00000110 (00272) 72766572 20636f75 6c64206e 6f742075 rver could not u 0x00000120 (00288) 6e646572 7374616e 642e3c2f 703e0a20 nderstand.</p>. 0x00000130 (00304) 2020203c 703e4e6f 20737563 68206669 <p>No such fi 0x00000140 (00320) 6c65206f 72206469 72656374 6f72792e le or directory. 0x00000150 (00336) 3c2f703e 0a20203c 6872202f 3e0a2020 </p>. <hr />. 0x00000160 (00352) 3c616464 72657373 3e4d6963 726f736f <address>Microso 0x00000170 (00368) 66742d49 49532f37 2e303c2f 61646472 ft-IIS/7.0</addr 0x00000180 (00384) 6573733e 0a20203c 2f626f64 793e0a3c ess>. </body>.< 0x00000190 (00400) 2f68746d 6c3e0a /html>. 0x00000000 (00000) 47455420 2f6f7065 6e2f7365 7475705f GET /open/setup_ 0x00000010 (00016) 33333836 2e657865 20485454 502f312e 3386.exe HTTP/1. 0x00000020 (00032) 310d0a55 7365722d 4167656e 743a204e 1..User-Agent: N 0x00000030 (00048) 5349535f 496e6574 6320284d 6f7a696c SIS_Inetc (Mozil 0x00000040 (00064) 6c61290d 0a486f73 743a2064 6f776e2e la)..Host: down. 0x00000050 (00080) 79696e79 75652e66 6d0d0a43 6f6e6e65 yinyue.fm..Conne 0x00000060 (00096) 6374696f 6e3a204b 6565702d 416c6976 ction: Keep-Aliv 0x00000070 (00112) 650d0a43 61636865 2d436f6e 74726f6c e..Cache-Control 0x00000080 (00128) 3a206e6f 2d636163 68650d0a 0d0a6e20 : no-cache....n 0x00000090 (00144) 636f6d6d 616e642e 0d0a3230 30205377 command...200 Sw 0x000000a0 (00160) 69746368 696e6720 746f2042 494e4152 itching to BINAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f323031 34303932 382f3933 GET /20140928/93 0x00000010 (00016) 37376d79 63735f59 5f6d6761 7a325f30 77mycs_Y_mgaz2_0 0x00000020 (00032) 312e6578 65204854 54502f31 2e310d0a 1.exe HTTP/1.1.. 0x00000030 (00048) 55736572 2d416765 6e743a20 4e534953 User-Agent: NSIS 0x00000040 (00064) 5f496e65 74632028 4d6f7a69 6c6c6129 _Inetc (Mozilla) 0x00000050 (00080) 0d0a486f 73743a20 7869617a 61692e39 ..Host: xiazai.9 0x00000060 (00096) 3337372e 636f6d0d 0a436f6e 6e656374 377.com..Connect 0x00000070 (00112) 696f6e3a 204b6565 702d416c 6976650d ion: Keep-Alive. 0x00000080 (00128) 0a436163 68652d43 6f6e7472 6f6c3a20 .Cache-Control: 0x00000090 (00144) 6e6f2d63 61636865 0d0a0d0a 30205377 no-cache....0 Sw 0x000000a0 (00160) 69746368 696e6720 746f2042 494e4152 itching to BINAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f676f2f 66756c6c 2f322f33 GET /go/full/2/3 0x00000010 (00016) 30373639 20485454 502f312e 310d0a55 0769 HTTP/1.1..U 0x00000020 (00032) 7365722d 4167656e 743a204e 5349535f ser-Agent: NSIS_ 0x00000030 (00048) 496e6574 6320284d 6f7a696c 6c61290d Inetc (Mozilla). 0x00000040 (00064) 0a486f73 743a2077 2e782e62 61696475 .Host: w.x.baidu 0x00000050 (00080) 2e636f6d 0d0a436f 6e6e6563 74696f6e .com..Connection 0x00000060 (00096) 3a204b65 65702d41 6c697665 0d0a4361 : Keep-Alive..Ca 0x00000070 (00112) 6368652d 436f6e74 726f6c3a 206e6f2d che-Control: no- 0x00000080 (00128) 63616368 650d0a0d 0a6e7472 6f6c3a20 cache....ntrol: 0x00000090 (00144) 6e6f2d63 61636865 0d0a0d0a 30205377 no-cache....0 Sw 0x000000a0 (00160) 69746368 696e6720 746f2042 494e4152 itching to BINAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f676f2f 66756c6c 2f312f37 GET /go/full/1/7 0x00000010 (00016) 30393838 20485454 502f312e 310d0a55 0988 HTTP/1.1..U 0x00000020 (00032) 7365722d 4167656e 743a204e 5349535f ser-Agent: NSIS_ 0x00000030 (00048) 496e6574 6320284d 6f7a696c 6c61290d Inetc (Mozilla). 0x00000040 (00064) 0a486f73 743a2077 2e782e62 61696475 .Host: w.x.baidu 0x00000050 (00080) 2e636f6d 0d0a436f 6e6e6563 74696f6e .com..Connection 0x00000060 (00096) 3a204b65 65702d41 6c697665 0d0a4361 : Keep-Alive..Ca 0x00000070 (00112) 6368652d 436f6e74 726f6c3a 206e6f2d che-Control: no- 0x00000080 (00128) 63616368 650d0a0d 0a6e7472 6f6c3a20 cache....ntrol: 0x00000090 (00144) 6e6f2d63 61636865 0d0a0d0a 30205377 no-cache....0 Sw 0x000000a0 (00160) 69746368 696e6720 746f2042 494e4152 itching to BINAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f426169 6475506c 61796572 GET /BaiduPlayer 0x00000010 (00016) 436f6e74 656e742f 42616964 75506c61 Content/BaiduPla 0x00000020 (00032) 7965724e 65745365 7475705f 3437322e yerNetSetup_472. 0x00000030 (00048) 65786520 48545450 2f312e31 0d0a5573 exe HTTP/1.1..Us 0x00000040 (00064) 65722d41 67656e74 3a204e53 49535f49 er-Agent: NSIS_I 0x00000050 (00080) 6e657463 20284d6f 7a696c6c 61290d0a netc (Mozilla).. 0x00000060 (00096) 486f7374 3a20646c 2e703273 702e6261 Host: dl.p2sp.ba 0x00000070 (00112) 6964752e 636f6d0d 0a436f6e 6e656374 idu.com..Connect 0x00000080 (00128) 696f6e3a 204b6565 702d416c 6976650d ion: Keep-Alive. 0x00000090 (00144) 0a436163 68652d43 6f6e7472 6f6c3a20 .Cache-Control: 0x000000a0 (00160) 6e6f2d63 61636865 0d0a0d0a 494e4152 no-cache....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f696e76 632f7474 2f515142 GET /invc/tt/QQB 0x00000010 (00016) 726f7773 65725f53 65747570 5f486b5f rowser_Setup_Hk_ 0x00000020 (00032) 37383635 332e6578 65204854 54502f31 78653.exe HTTP/1 0x00000030 (00048) 2e310d0a 55736572 2d416765 6e743a20 .1..User-Agent: 0x00000040 (00064) 4e534953 5f496e65 74632028 4d6f7a69 NSIS_Inetc (Mozi 0x00000050 (00080) 6c6c6129 0d0a486f 73743a20 646c6469 lla)..Host: dldi 0x00000060 (00096) 72312e71 712e636f 6d0d0a43 6f6e6e65 r1.qq.com..Conne 0x00000070 (00112) 6374696f 6e3a204b 6565702d 416c6976 ction: Keep-Aliv 0x00000080 (00128) 650d0a43 61636865 2d436f6e 74726f6c e..Cache-Control 0x00000090 (00144) 3a206e6f 2d636163 68650d0a 0d0a3a20 : no-cache....: 0x000000a0 (00160) 6e6f2d63 61636865 0d0a0d0a 494e4152 no-cache....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f642f69 6e733132 35363835 GET /d/ins125685 0x00000010 (00016) 382e6578 65204854 54502f31 2e310d0a 8.exe HTTP/1.1.. 0x00000020 (00032) 55736572 2d416765 6e743a20 4e534953 User-Agent: NSIS 0x00000030 (00048) 5f496e65 74632028 4d6f7a69 6c6c6129 _Inetc (Mozilla) 0x00000040 (00064) 0d0a486f 73743a20 672e7175 77656e33 ..Host: g.quwen3 0x00000050 (00080) 32302e63 6f6d0d0a 436f6e6e 65637469 20.com..Connecti 0x00000060 (00096) 6f6e3a20 4b656570 2d416c69 76650d0a on: Keep-Alive.. 0x00000070 (00112) 43616368 652d436f 6e74726f 6c3a206e Cache-Control: n 0x00000080 (00128) 6f2d6361 6368650d 0a0d0a6e 74726f6c o-cache....ntrol 0x00000090 (00144) 3a206e6f 2d636163 68650d0a 0d0a3a20 : no-cache....: 0x000000a0 (00160) 6e6f2d63 61636865 0d0a0d0a 494e4152 no-cache....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f706362 726f7773 65722f64 GET /pcbrowser/d 0x00000010 (00016) 6f776e2e 7068703f 7069643d 34323739 own.php?pid=4279 0x00000020 (00032) 20485454 502f312e 310d0a55 7365722d HTTP/1.1..User- 0x00000030 (00048) 4167656e 743a204e 5349535f 496e6574 Agent: NSIS_Inet 0x00000040 (00064) 6320284d 6f7a696c 6c61290d 0a486f73 c (Mozilla)..Hos 0x00000050 (00080) 743a2064 6f776e32 2e75632e 636e0d0a t: down2.uc.cn.. 0x00000060 (00096) 436f6e6e 65637469 6f6e3a20 4b656570 Connection: Keep 0x00000070 (00112) 2d416c69 76650d0a 43616368 652d436f -Alive..Cache-Co 0x00000080 (00128) 6e74726f 6c3a206e 6f2d6361 6368650d ntrol: no-cache. 0x00000090 (00144) 0a0d0a6f 2d636163 68650d0a 0d0a3a20 ...o-cache....: 0x000000a0 (00160) 6e6f2d63 61636865 0d0a0d0a 494e4152 no-cache....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f536f48 7556415f 342e332e GET /SoHuVA_4.3. 0x00000010 (00016) 302e312d 63323034 39303030 30332d6e 0.1-c204900003-n 0x00000020 (00032) 672d6e74 692d732d 782e7261 72204854 g-nti-s-x.rar HT 0x00000030 (00048) 54502f31 2e310d0a 55736572 2d416765 TP/1.1..User-Age 0x00000040 (00064) 6e743a20 4e534953 5f496e65 74632028 nt: NSIS_Inetc ( 0x00000050 (00080) 4d6f7a69 6c6c6129 0d0a486f 73743a20 Mozilla)..Host: 0x00000060 (00096) 736f6674 2e6c7662 616f7261 6e736869 soft.lvbaoranshi 0x00000070 (00112) 79652e63 6f6d0d0a 436f6e6e 65637469 ye.com..Connecti 0x00000080 (00128) 6f6e3a20 4b656570 2d416c69 76650d0a on: Keep-Alive.. 0x00000090 (00144) 43616368 652d436f 6e74726f 6c3a206e Cache-Control: n 0x000000a0 (00160) 6f2d6361 6368650d 0a0d0a0a 494e4152 o-cache.....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f676f2f 6d696e69 2f382f33 GET /go/mini/8/3 0x00000010 (00016) 30303030 30343620 48545450 2f312e31 0000046 HTTP/1.1 0x00000020 (00032) 0d0a5573 65722d41 67656e74 3a204e53 ..User-Agent: NS 0x00000030 (00048) 49535f49 6e657463 20284d6f 7a696c6c IS_Inetc (Mozill 0x00000040 (00064) 61290d0a 486f7374 3a20772e 782e6261 a)..Host: w.x.ba 0x00000050 (00080) 6964752e 636f6d0d 0a436f6e 6e656374 idu.com..Connect 0x00000060 (00096) 696f6e3a 204b6565 702d416c 6976650d ion: Keep-Alive. 0x00000070 (00112) 0a436163 68652d43 6f6e7472 6f6c3a20 .Cache-Control: 0x00000080 (00128) 6e6f2d63 61636865 0d0a0d0a 76650d0a no-cache....ve.. 0x00000090 (00144) 43616368 652d436f 6e74726f 6c3a206e Cache-Control: n 0x000000a0 (00160) 6f2d6361 6368650d 0a0d0a0a 494e4152 o-cache.....INAR 0x000000b0 (00176) 59206d6f 64652e0d 0a323030 20504f52 Y mode...200 POR 0x000000c0 (00192) 5420636f 6d6d616e 64207375 63636573 T command succes 0x000000d0 (00208) 7366756c 2e0d0a35 30302055 6e6b6e6f sful...500 Unkno 0x000000e0 (00224) 776e2063 6f6d6d61 6e642e0d 0a353530 wn command...550 0x000000f0 (00240) 20466169 6c656420 746f206f 70656e20 Failed to open 0x00000100 (00256) 66696c65 2e0d0a file... 0x00000000 (00000) 47455420 2f687a2f 49514959 49736574 GET /hz/IQIYIset 0x00000010 (00016) 75705f6c 5f73706c 30303440 6b623031 up_l_spl004@kb01 0x00000020 (00032) 302e6578 65204854 54502f31 2e310d0a 0.exe HTTP/1.1.. 0x00000030 (00048) 55736572 2d416765 6e743a20 4e534953 User-Agent: NSIS 0x00000040 (00064) 5f496e65 74632028 4d6f7a69 6c6c6129 _Inetc (Mozilla) 0x00000050 (00080) 0d0a486f 73743a20 646c2e73 74617469 ..Host: dl.stati 0x00000060 (00096) 632e6971 6979692e 636f6d0d 0a436f6e c.iqiyi.com..Con 0x00000070 (00112) 6e656374 696f6e3a 204b6565 702d416c nection: Keep-Al 0x00000080 (00128) 6976650d 0a436163 68652d43 6f6e7472 ive..Cache-Contr 0x00000090 (00144) 6f6c3a20 6e6f2d63 61636865 0d0a0d0a ol: no-cache.... 0x000000a0 (00160) 6f2d6361 6368650d o-cache. 0x00000000 (00000) 47455420 2f73696c 656e6365 2f323334 GET /silence/234 0x00000010 (00016) 35457870 6c6f7265 725f3332 39323432 5Explorer_329242 0x00000020 (00032) 5f73696c 656e6365 2e657865 20485454 _silence.exe HTT 0x00000030 (00048) 502f312e 310d0a55 7365722d 4167656e P/1.1..User-Agen 0x00000040 (00064) 743a204e 5349535f 496e6574 6320284d t: NSIS_Inetc (M 0x00000050 (00080) 6f7a696c 6c61290d 0a486f73 743a2064 ozilla)..Host: d 0x00000060 (00096) 6f776e6c 6f61642e 32333435 2e636e0d ownload.2345.cn. 0x00000070 (00112) 0a436f6e 6e656374 696f6e3a 204b6565 .Connection: Kee 0x00000080 (00128) 702d416c 6976650d 0a436163 68652d43 p-Alive..Cache-C 0x00000090 (00144) 6f6e7472 6f6c3a20 6e6f2d63 61636865 ontrol: no-cache 0x000000a0 (00160) 0d0a0d0a 6368650d ....che. 0x00000000 (00000) 47455420 2f66696c 65732f69 6e73742f GET /files/inst/ 0x00000010 (00016) 57616e44 6f754a69 615f7275 6e6b345f WanDouJia_runk4_ 0x00000020 (00032) 6b622e65 78652048 5454502f 312e310d kb.exe HTTP/1.1. 0x00000030 (00048) 0a557365 722d4167 656e743a 204e5349 .User-Agent: NSI 0x00000040 (00064) 535f496e 65746320 284d6f7a 696c6c61 S_Inetc (Mozilla 0x00000050 (00080) 290d0a48 6f73743a 20646c2e 77616e64 )..Host: dl.wand 0x00000060 (00096) 6f756a69 612e636f 6d0d0a43 6f6e6e65 oujia.com..Conne 0x00000070 (00112) 6374696f 6e3a204b 6565702d 416c6976 ction: Keep-Aliv 0x00000080 (00128) 650d0a43 61636865 2d436f6e 74726f6c e..Cache-Control 0x00000090 (00144) 3a206e6f 2d636163 68650d0a 0d0a6865 : no-cache....he 0x000000a0 (00160) 0d0a0d0a 6368650d ....che. 0x00000000 (00000) 47455420 2f636c69 636b2f36 36393437 GET /click/66947 0x00000010 (00016) 20485454 502f312e 310d0a55 7365722d HTTP/1.1..User- 0x00000020 (00032) 4167656e 743a204e 5349535f 496e6574 Agent: NSIS_Inet 0x00000030 (00048) 6320284d 6f7a696c 6c61290d 0a486f73 c (Mozilla)..Hos 0x00000040 (00064) 743a2073 2e6c6c6c 736f6f2e 636f6d0d t: s.lllsoo.com. 0x00000050 (00080) 0a436f6e 6e656374 696f6e3a 204b6565 .Connection: Kee 0x00000060 (00096) 702d416c 6976650d 0a436163 68652d43 p-Alive..Cache-C 0x00000070 (00112) 6f6e7472 6f6c3a20 6e6f2d63 61636865 ontrol: no-cache 0x00000080 (00128) 0d0a0d0a 61636865 2d436f6e 74726f6c ....ache-Control 0x00000090 (00144) 3a206e6f 2d636163 68650d0a 0d0a6865 : no-cache....he 0x000000a0 (00160) 0d0a0d0a 6368650d ....che.
Strings
" "GE. . msctls_progress32 MS Shell Dlg Please wait while Setup is loading... SysListView32 *?|<>/": 0c%%\\))8?GlQV !1fD=0oh. 1!t)|-l 1'[vKu 2"&,\45> +#-28< #:]2UOr 2?Xs/C $(.469+A $(.469=EFHJ $(.469=EFM $(.469=ET $(.469F $(.46%A $(.46J 4e uCI '4=|I2 {4Q95Z* {5/`<l0 5s,A?k 5+X8$F 6AD}II ^(7@E# 85^O5n ;8721^. @8e&/+ ?[8?GOQY ^&8{{M 8NCRCu 8nDDbih/[g 8$n?'N =:953,& /953,& ]:953,& AdjustTokenPrivileges ADVAPI32 ADVAPI32.dll AppendMenuA @a tx& B$1_`ajbgA B9Y^Tr BeginPaint Bf<"-# 'B(?k> BM%1B. bMf.~L BZTc-, c0]n5I| CallWindowProcA CE=+FU CharNextA CharPrevA CheckDlgButton C#[/>iiD>8!#7 CL(jm?C CloseClipboard CloseHandle CoCreateInstance COMCTL32.dll CompareFileTime Control Panel\Desktop\ResourceLocale CopyFileA CoTaskMemFree CreateBrushIndirect CreateDialogParamA CreateDirectoryA CreateFileA CreateFontIndirectA CreatePopupMenu CreateProcessA CreateThread CreateWindowExA @|c{SHK 'C wI* c|XqeNb< ... %d%% D$0+D$(P D0.xrRM ^d3XNQ( !d"(.469=EFHJMTr @.data D$(+D$ SSP .DEFAULT\Control Panel\International DefWindowProcA DeleteFileA DeleteObject DestroyWindow DialogBoxParamA DispatchMessageA dnzzqqmhcd Dooo'MMM d:##(r DrawTextA D$(SPS ed))dd++ee///^^^O e:jvod EmptyClipboard )::::EMT EnableMenuItem EnableWindow EndDialog EndPaint Eq'<J,YX Error launching installer Error writing temporary file. Make sure your temp folder is valid. ErT,-468 ExitProcess ExitWindowsEx ExpandEnvironmentStringsA F9K-0 f9y EY- FillRect FindClose FindFirstFileA FindNextFileA FindWindowExA FN?NMM FreeLibrary FVf&?_ Fx>Ux<} 'fz8 S GDI32.dll GetClassInfoA GetClientRect GetCommandLineA GetCurrentProcess GetDeviceCaps GetDiskFreeSpaceA GetDiskFreeSpaceExA GetDlgItem GetDlgItemTextA GetExitCodeProcess GetFileAttributesA GetFileSize GetFileVersionInfoA GetFileVersionInfoSizeA GetFullPathNameA GetLastError GetMessagePos GetModuleFileNameA GetModuleHandleA GetPrivateProfileStringA GetProcAddress GetShortPathNameA GetSysColor GetSystemDirectoryA GetSystemMenu GetSystemMetrics GetTempFileNameA GetTempPathA GetTickCount GetUserDefaultUILanguage GetVersion GetWindowLongA GetWindowRect GetWindowsDirectoryA GlobalAlloc GlobalFree GlobalLock GlobalUnlock [@[gq~Ah-H HEB=:`^[@ HEB=:953-\2 HEB=:953,&"\f He&ja9 HH,?1: h#NKrx\ ;HP;Msrf hs#n,D http://nsis.sf.net/NSIS_Error h|u%qE1 i=:953,&H i=;:953,M iC+:DlR Id4dU* ImageList_AddMasked ImageList_Create ImageList_Destroy incomplete download and damaged media. Contact the Installer integrity check has failed. Common causes include installer's author to obtain a new copy. Instu` InvalidateRect i[S75; IsWindow IsWindowEnabled IsWindowVisible jc%xqC JhLO>~r j~,]K*` jmxG6_ J~W2k"B j_w<U4 K1&T7 @ K@\btF ?KdkKv KeAmoXs~ KERNEL32 KERNEL32.dll KKKKQKT kS<$m,0 {l :>_ lc%%\\))dd++ee//>nl LoadBitmapA LoadCursorA LoadImageA LoadLibraryA LoadLibraryExA LookupPrivilegeValueA lstrcatA lstrcmpA lstrcmpiA lstrcpynA lstrlenA luunniiDu LxqfM= lYl0dmj ^::::::;M !"%,[M ]:::::::M M3z[#Kv M/A7e] MessageBoxIndirectA \Microsoft\Internet Explorer\Quick Launch MMMMMMMMMMMM More information at: MoveFileA MoveFileExA m:::::::R MS(h`y MulDiv MultiByteToWideChar /_]`n5> .ndata ((ndSd ni&w]3 I NlP/?#} nnngwwp ~nnnnnnngx NSIS Error ~nsu.tmp NullsoftInst^U NulluN E ||offZZZJj oHE8o> /oK,e; ole32.dll OleInitialize OleUninitialize /oMjFW,S4 ~{onyR OpenClipboard OpenProcessToken [^O] Q _('oT^ p5*@pW PeekMessageA PostQuitMessage p]Pm9< PPPPPP p r}k! {{]^///^^^^Q QaN7ZT {.Qfi6 -.Qmca qqqqqqq)A qr>}7Q R:953,& `.rdata ReadFile RegCloseKey RegCreateKeyExA RegDeleteKeyA RegDeleteKeyExA RegDeleteValueA RegEnumKeyA RegEnumValueA RegisterClassA RegOpenKeyExA RegQueryValueExA RegSetValueExA RemoveDirectoryA [Rename] RHEB=:953,& RichEd20 RichEd32 RichEdit RichEdit20A Richu) rt;FC< RYL.oa s8E"u7T` sAk>:w ScreenToClient SearchPathA SelectObject SendMessageA SendMessageTimeoutA SeShutdownPrivilege SetBkColor SetBkMode SetClassLongA SetClipboardData SetCurrentDirectoryA SetCursor SetDlgItemTextA SetErrorMode SetFileAttributesA SetFilePointer SetFileTime SetForegroundWindow SetTextColor SetTimer SetWindowLongA SetWindowPos SetWindowTextA SHAutoComplete SHBrowseForFolderA SHELL32.dll ShellExecuteA SHFileOperationA SHFOLDER SHGetFileInfoA SHGetFolderPathA SHGetPathFromIDListA SHGetSpecialFolderLocation shGW3l1 SHLWAPI ShowWindow softuW Software\Microsoft\Windows\CurrentVersion spSH"u SQSSSPW SSS)}}} SSSSSSSS svvvvvvvgA Swwwj=B> SystemParametersInfoA sz=.Cb;RRf > _?=t T>: {a TFB=:953,& !This program cannot be run in DOS mode. _^[t P TrackPopupMenu "tt1o6 t.)tczB u5N*.Hc uee*))))00 ;;;Ueee *{u}@g ulid\VL unpacking data: %d%% USER32.dll U^sK<T %u.%u%s%s v95DpA verifying installer: %d%% VerQueryValueA VERSION.dll "vf%^_ /Vs^k2 "}v^U|$ ~~vvphh ~~vvpphc_ ~~vvvlia<< ?W*.5o W7'''''7A w93\#_ WaitForSingleObject WBl:, ob wP|ooCG wqxp>T WriteFile WritePrivateProfileStringA wsprintfA WU'%]469=EFHJNl0#A }w(v5Gh; WWWtF> wwwwww wwwwwwww wwwwwwwwwx wwwwwwx wwwwwx wY)e7yZ *%W-Z~ xD#} k= xgsTMJ <?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Nullsoft.NSIS.exehead" type="win32"/><description>Nullsoft Install System v2.45</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly> xthbZQO;? XYYYYO# yOk0:,J- Ysssssss )$yS#Z(H yv^VZ/ }}}yyyti=BF }}}yyytt }}}yyyttp }}}yyyttpD }}}yyyttppGW Y)zL8e z#\2U( >z>B?X zmg]/0 }zwmmhvLHFFHJMZ