Download Link: hxxp://17xzb.com/soft/setup.exe File Name: setup.exe File size: 196608 bytes MD5: b8cc7a335d412dc1b0a7672fb71cb492 SHA1: ba435af57327292a55a766ca5533ab6463e166fe PEiD: ASPack v2.12 -> Alexey Solodovnikov packers: ASPack Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=89C4ECDA00AB2AB700E503120D587600DAA04D84 VirusTotal Result: 17/32 (53.13%) AntiVir: TR/Dldr.Delphi.Gen Authentium: Possibly a new variant of W32/NewMalware-LSU-based!Maximus AVG: Clicker.MCZ CAT-QuickHeal: TrojanClicker.Delf.rz DrWeb: Trojan.Click.17893 eSafe: Suspicious File F-Prot: W32/Downloader.H.gen!Eldorado F-Secure: Trojan-Clicker.Win32.Delf.rz Ikarus: Backdoor.Win32.GF.13x.A Kaspersky: Trojan-Clicker.Win32.Delf.rz Norman: W32/DLoader.FTGR Panda: Suspicious file Prevx1: Trojan.Clicker Sophos: Mal/Generic-A TheHacker: Trojan/Clicker.Delf.rz VBA32: Trojan-Clicker.Win32.Delf.rz Webwasher-Gateway: BlockReason.0 PE Header Signature: 00004550 Machine: 014C - Intel 386 Number of sections: 000A Time/Date stamp: 2A425E19 Pointer to symbol table: 00000000 Number of symbols: 00000000 Size of optional header: 00E0 Characteristics: 818E Magic: 010B Linker version (major): 02 Linker version (minor): 19 Size of code: 00060E00 Size of initialized data: 00013200 Size of uninitialized data: 00000000 Address of entry point: 0007B001 Base of code: 00001000 Base of data: 00062000 Image base: 00400000 Section alignment: 00001000 File alignment: 00000200 OS version (major): 0004 OS version (minor): 0000 Image version (major): 0000 Image version (minor): 0000 Sub system version (major): 0004 Sub system version (minor): 0000 Win32 version: 00000000 Size of image: 00080000 Size of headers: 00000400 Checksum: 00000000 Sub system: 0002 - Windows graphical user interface (GUI) subsystem DLL characteristics: 0000 Size of stack reserve: 00100000 Size of stack commit: 00004000 Size of heap reserve: 00100000 Size of heap commit: 00001000 Loader flags: 00000000 Number of RVA: 00000010 PE Sections -------------------------------------------------- Section VirtSize VirtAddr PhysSize PhysAddr Flags CODE 00061000 00001000 00028200 00000400 C0000040 DATA 00002000 00062000 00000A00 00028600 C0000040 BSS 00001000 00064000 00000000 00029000 C0000040 .idata 00003000 00065000 00000E00 00029000 C0000040 .tls 00001000 00068000 00000000 00029E00 C0000040 .rdata 00001000 00069000 00000200 00029E00 C0000040 .reloc 00008000 0006A000 00000000 0002A000 C0000040 .rsrc 00009000 00072000 00002400 0002A000 C0000040 .aspack 00004000 0007B000 00003C00 0002C400 C0000040 .adata 00001000 0007F000 00000000 00030000 C0000040 Import table (libraries: 14) kernel32.dll (imports: 3) GetProcAddress GetModuleHandleA LoadLibraryA user32.dll (imports: 1) GetKeyboardType advapi32.dll (imports: 1) RegQueryValueExA oleaut32.dll (imports: 1) SysFreeString advapi32.dll (imports: 1) RegSetValueExA version.dll (imports: 1) VerQueryValueA gdi32.dll (imports: 1) UnrealizeObject user32.dll (imports: 1) CreateWindowExA oleaut32.dll (imports: 1) SafeArrayPtrOfIndex ole32.dll (imports: 1) CreateStreamOnHGlobal oleaut32.dll (imports: 1) GetErrorInfo comctl32.dll (imports: 1) ImageList_SetIconSize urlmon.dll (imports: 1) URLDownloadToFileA shell32.dll (imports: 1) SHGetSpecialFolderLocation Process Information: Process ID 744 Filename C:\setup.exe Filesize 196608 bytes MD5 b8cc7a335d412dc1b0a7672fb71cb492 Start Reason Analysis Target COM Activities: Create Instance: C:\WINDOWS\system32\shdocvw.dll, ProgID: (Shell.Explorer.2), Interface ID: ({00000112-0000-0000-C000-000000000046}) Create Instance: shell32.dll, ProgID: (lnkfile), Interface ID: ({000214EE-0000-0000-C000-000000000046}) Get Class Object: %SystemRoot%\system32\mshtml.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) Get Class Object: C:\WINDOWS\system32\urlmon.dll, Interface ID: ({00000001-0000-0000-C000-000000000046}) File System Activities: Get File Attributes: C:\WINDOWS\Registration Flags: (SECURITY_ANONYMOUS) Find File: C:\WINDOWS/media/start.wav Delete File: C:\WINDOWS/media/start.wav Open File: \\.\PIPE\lsarpc (OPEN_EXISTING) Get File Attributes: c:\autoexec.bat Flags: (SECURITY_ANONYMOUS) Open File: c:\autoexec.bat (OPEN_EXISTING) Find File: C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk Find File: C:\WINDOWS\system32\Ras\*.pbk Find File: C:\Documents and Settings\Sandbox\Application Data\Microsoft\Network\Connections\Pbk\*.pbk Create/Open File: \Device\RasAcd (OPEN_ALWAYS) Find File: C:\WINDOWS/site2007.dll Get File Attributes: C:\WINDOWS\ Flags: (SECURITY_ANONYMOUS) Get File Attributes: C:\Documents and Settings\Sandbox\Start Menu\desktop.ini Flags: (SECURITY_ANONYMOUS) Get File Attributes: C:\Documents and Settings\Sandbox\Start Menu\Programs\desktop.ini Flags: (SECURITY_ANONYMOUS) Get File Attributes: C:\Documents and Settings\Sandbox\Start Menu\Programs\Startup\desktop.ini Flags: (SECURITY_ANONYMOUS) Copy File: C:\setup.exe to C:\Documents and Settings\Sandbox\Start Menu\Programs\Startup/explorer.exe Set File Attributes: C:\Documents and Settings\Sandbox\Start Menu\Programs\Startup/Explorer.exe Flags: (FILE_ATTRIBUTE_ARCHIVE,FILE_ATTRIBUTE_COMPRESSED,FILE_ATTRIBUTE_HIDDEN,FILE_ATTRIBUTE_NORMAL,FILE_ATTRIBUTE_SYSTEM,FILE_ATTRIBUTE_REPARSE_POINT,FILE_ATTRIBUTE_COMPRESSED,SECURITY_ANONYMOUS) Open File: C:\WINDOWS/site2007.dll (OPEN_EXISTING) Read INI Files: C:\Documents and Settings\Sandbox\Start Menu\desktop.ini [DeleteOnCopy] Owner = C:\Documents and Settings\Sandbox\Start Menu\desktop.ini [.ShellClassInfo] LocalizedResourceName = C:\Documents and Settings\Sandbox\Start Menu\Programs\desktop.ini [DeleteOnCopy] Owner = C:\Documents and Settings\Sandbox\Start Menu\Programs\desktop.ini [.ShellClassInfo] LocalizedResourceName = C:\Documents and Settings\Sandbox\Start Menu\Programs\Startup\desktop.ini [DeleteOnCopy] Owner = C:\Documents and Settings\Sandbox\Start Menu\Programs\Startup\desktop.ini [.ShellClassInfo] LocalizedResourceName = WIN.INI [windows] DragScrollInset = WIN.INI [windows] DragScrollDelay = WIN.INI [windows] DragDelay = WIN.INI [windows] DragScrollInterval = Mutexes: Creates Mutex: RasPbFile Opens Mutex: WininetStartupMutex Registry Reads: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "autosjshua" HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService "DefaultAuthLevel" HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility "DisableAppCompat" HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{00021401-0000-0000-c000-000000000046}\InProcServer32 "" _HKEY(1928)_ "NumShape" _HKEY(2004)_ "NumShape" Service Management: Open Service Manager - Name: "SCM" Open Service - Name: "RASMAN" System Info: Get System Directory Get Windows Directory Get Computer Name Get System Time User Management: Impersonate User - Domain: () User: (Sandbox) Get User Name Window: Find Window - Class Name (MS_AutodialMonitor) Window Name () Find Window - Class Name (MS_WebcheckMonitor) Window Name () Enum Windows: Destroy Window - Class Name (TListBox) Window Name () Destroy Window - Class Name (Tmainfrm) Window Name (???) Network Activities: DNS Queries: Name Query Type Query Result Successful xxx.hao256.com DNS_TYPE_A 218.16.120.193 1 xxx.txzhw.com DNS_TYPE_A 218.16.120.193 1 xxx.kszlw.com DNS_TYPE_A 218.16.120.193 1 xxx.bai1du.com DNS_TYPE_A 218.16.120.193 1 xxx.178abc.com DNS_TYPE_A 218.16.120.193 1 xxx.kkfw.com DNS_TYPE_A 218.16.120.193 1 xxx.izsw.com DNS_TYPE_A 218.16.120.193 1 xxx.5idig.com DNS_TYPE_A 218.16.120.193 1 xxx.xxzlw.com DNS_TYPE_A 218.16.120.193 1 xxx.hao12300.cn DNS_TYPE_A 218.16.120.193 1 HTTP Conversation: From SandBox:1035 to 218.16.120.193:80 - [xxx.hao12300.cn] Request: GET /soft/listwz.txt Response: 200 "OK" Request: GET /index.html Response: 200 "OK" Request: GET /index.html Response: 200 "OK" Request: GET /index.html Response: Request: GET /search.asp Response: 200 "OK" Request: GET /index.html Response: 200 "OK" TCP Connection: Outgoing connection from SandBox:1037 to remote server: 218.16.120.193 TCP port 80 Download URLs: hxxp://218.16.120.193/soft/listwz.txt (218.16.120.193) hxxxp://218.16.120.193/ (218.16.120.193) Unknown TCP Traffic: from SandBox:1044 to 218.16.120.193:80 State: Connection established, not terminated - Transferred outbound Bytes: 561 - Transferred inbound Bytes: 263 Data sent: 4745 5420 2f73 6561 7263 682e 6173 7020 GET /search.asp 4854 5450 2f31 2e31 0d0a 4163 6365 7074 HTTP/1.1..Accept 3a20 696d 6167 652f 6769 662c 2069 6d61 : image/gif, ima 6765 2f78 2d78 6269 746d 6170 2c20 696d ge/x-xbitmap, im 6167 652f 6a70 6567 2c20 696d 6167 652f age/jpeg, image/ 706a 7065 672c 2061 7070 6c69 6361 7469 pjpeg, applicati 6f6e 2f78 2d73 686f 636b 7761 7665 2d66 on/x-shockwave-f 6c61 7368 2c20 6170 706c 6963 6174 696f lash, applicatio 6e2f 7861 6d6c 2b78 6d6c 2c20 6170 706c n/xaml+xml, appl 6963 6174 696f 6e2f 766e 642e 6d73 2d78 ication/vnd.ms-x 7073 646f 6375 6d65 6e74 2c20 6170 706c psdocument, appl 6963 6174 696f 6e2f 782d 6d73 2d78 6261 ication/x-ms-xba 702c 2061 7070 6c69 6361 7469 6f6e 2f78 p, application/x 2d6d 732d 6170 706c 6963 6174 696f 6e2c -ms-application, 2061 7070 6c69 6361 7469 6f6e 2f76 6e64 application/vnd 2e6d 732d 6578 6365 6c2c 2061 7070 6c69 .ms-excel, appli 6361 7469 6f6e 2f76 6e64 2e6d 732d 706f cation/vnd.ms-po 7765 7270 6f69 6e74 2c20 6170 706c 6963 werpoint, applic 6174 696f 6e2f 6d73 776f 7264 2c20 2a2f ation/msword, */ 2a0d 0a41 6363 6570 742d 4c61 6e67 7561 *..Accept-Langua 6765 3a20 656e 2d75 730d 0a55 412d 4350 ge: en-us..UA-CP 553a 2078 3836 0d0a 4163 6365 7074 2d45 U: x86..Accept-E 6e63 6f64 696e 673a 2067 7a69 702c 2064 ncoding: gzip, d 6566 6c61 7465 0d0a 5573 6572 2d41 6765 eflate..User-Age 6e74 3a20 4d6f 7a69 6c6c 612f 342e 3020 nt: Mozilla/4.0 2863 6f6d 7061 7469 626c 653b 204d 5349 (compatible; MSI 4520 372e 303b 2057 696e 646f 7773 204e E 7.0; Windows N 5420 352e 313b 202e 4e45 5420 434c 5220 T 5.1; .NET CLR 312e 312e 3433 3232 3b20 2e4e 4554 2043 1.1.4322; .NET C 4c52 2032 2e30 2e35 3037 3237 3b20 2e4e LR 2.0.50727; .N 4554 2043 4c52 2033 2e30 2e30 3435 3036 ET CLR 3.0.04506 2e33 303b 2049 6e66 6f50 6174 682e 3129 .30; InfoPath.1) 0d0a 486f 7374 3a20 7777 772e 3569 6469 ..Host: www.5idi 672e 636f 6d0d 0a43 6f6e 6e65 6374 696f g.com..Connectio 6e3a 204b 6565 702d 416c 6976 650d 0a0d n: Keep-Alive... 0a . Data received: 4854 5450 2f31 2e31 2032 3030 204f 4b0d HTTP/1.1 200 OK. 0a44 6174 653a 2046 7269 2c20 3037 204d .Date: Fri, 07 M 6172 2032 3030 3820 3130 3a32 393a 3232 ar 2008 10:29:22 2047 4d54 0d0a 5365 7276 6572 3a20 4d69 GMT..Server: Mi 6372 6f73 6f66 742d 4949 532f 362e 300d crosoft-IIS/6.0. 0a43 6f6e 7465 6e74 2d4c 656e 6774 683a .Content-Length: 2034 340d 0a43 6f6e 7465 6e74 2d54 7970 44..Content-Typ 653a 2074 6578 742f 6874 6d6c 0d0a 5365 e: text/html..Se 742d 436f 6f6b 6965 3a20 4153 5053 4553 t-Cookie: ASPSES 5349 4f4e 4944 5343 4343 4442 4453 3d49 SIONIDSCCCDBDS=I 434b 424e 4c49 414a 464b 4444 4146 4d48 CKBNLIAJFKDDAFMH 5043 4845 4c47 483b 2070 6174 683d 2f0d PCHELGH; path=/. 0a43 6163 6865 2d63 6f6e 7472 6f6c 3a20 .Cache-control: 7072 6976 6174 650d 0a0d 0acb d1cb f7b9 private......... d8bc fcd7 d6b2 bbc4 dcce aabf d5a3 a13c ...............< 6120 6872 6566 3d22 2f22 3eb7 b5bb d8ca a href="/">..... d7d2 b33c 2f61 3e ... from SandBox:1046 to 218.16.120.193:80 State: Connection established, not terminated - Transferred outbound Bytes: 563 - Transferred inbound Bytes: 36545 Data sent: 4745 5420 2f69 6e64 6578 2e68 746d 6c20 GET /index.html 4854 5450 2f31 2e31 0d0a 4163 6365 7074 HTTP/1.1..Accept 3a20 696d 6167 652f 6769 662c 2069 6d61 : image/gif, ima 6765 2f78 2d78 6269 746d 6170 2c20 696d ge/x-xbitmap, im 6167 652f 6a70 6567 2c20 696d 6167 652f age/jpeg, image/ 706a 7065 672c 2061 7070 6c69 6361 7469 pjpeg, applicati 6f6e 2f78 2d73 686f 636b 7761 7665 2d66 on/x-shockwave-f 6c61 7368 2c20 6170 706c 6963 6174 696f lash, applicatio 6e2f 7861 6d6c 2b78 6d6c 2c20 6170 706c n/xaml+xml, appl 6963 6174 696f 6e2f 766e 642e 6d73 2d78 ication/vnd.ms-x 7073 646f 6375 6d65 6e74 2c20 6170 706c psdocument, appl 6963 6174 696f 6e2f 782d 6d73 2d78 6261 ication/x-ms-xba 702c 2061 7070 6c69 6361 7469 6f6e 2f78 p, application/x 2d6d 732d 6170 706c 6963 6174 696f 6e2c -ms-application, 2061 7070 6c69 6361 7469 6f6e 2f76 6e64 application/vnd 2e6d 732d 6578 6365 6c2c 2061 7070 6c69 .ms-excel, appli 6361 7469 6f6e 2f76 6e64 2e6d 732d 706f cation/vnd.ms-po 7765 7270 6f69 6e74 2c20 6170 706c 6963 werpoint, applic 6174 696f 6e2f 6d73 776f 7264 2c20 2a2f ation/msword, */ 2a0d 0a41 6363 6570 742d 4c61 6e67 7561 *..Accept-Langua 6765 3a20 656e 2d75 730d 0a55 412d 4350 ge: en-us..UA-CP 553a 2078 3836 0d0a 4163 6365 7074 2d45 U: x86..Accept-E 6e63 6f64 696e 673a 2067 7a69 702c 2064 ncoding: gzip, d 6566 6c61 7465 0d0a 5573 6572 2d41 6765 eflate..User-Age 6e74 3a20 4d6f 7a69 6c6c 612f 342e 3020 nt: Mozilla/4.0 2863 6f6d 7061 7469 626c 653b 204d 5349 (compatible; MSI 4520 372e 303b 2057 696e 646f 7773 204e E 7.0; Windows N 5420 352e 313b 202e 4e45 5420 434c 5220 T 5.1; .NET CLR 312e 312e 3433 3232 3b20 2e4e 4554 2043 1.1.4322; .NET C 4c52 2032 2e30 2e35 3037 3237 3b20 2e4e LR 2.0.50727; .N 4554 2043 4c52 2033 2e30 2e30 3435 3036 ET CLR 3.0.04506 2e33 303b 2049 6e66 6f50 6174 682e 3129 .30; InfoPath.1) 0d0a 486f 7374 3a20 7777 772e 6861 6f31 ..Host: www.hao1 3233 3030 2e63 6e0d 0a43 6f6e 6e65 6374 2300.cn..Connect 696f 6e3a 204b 6565 702d 416c 6976 650d ion: Keep-Alive. 0a0d 0a ... Data received: 4854 5450 2f31 2e31 2032 3030 204f 4b0d HTTP/1.1 200 OK. 0a43 6f6e 7465 6e74 2d4c 656e 6774 683a .Content-Length: 2033 3633 3135 0d0a 436f 6e74 656e 742d 36315..Content- 5479 7065 3a20 7465 7874 2f68 746d 6c0d Type: text/html. 0a4c 6173 742d 4d6f 6469 6669 6564 3a20 .Last-Modified: 5468 752c 2032 3220 4e6f 7620 3230 3037 Thu, 22 Nov 2007 2031 373a 3431 3a31 3120 474d 540d 0a41 17:41:11 GMT..A 6363 6570 742d 5261 6e67 6573 3a20 6279 ccept-Ranges: by 7465 730d 0a45 5461 673a 2022 6434 3366 tes..ETag: "d43f 6662 6465 3265 3264 6338 313a 6233 3063 fbde2e2dc81:b30c 3322 0d0a 5365 7276 6572 3a20 4d69 6372 3"..Server: Micr 6f73 6f66 742d 4949 532f 362e 300d 0a44 osoft-IIS/6.0..D 6174 653a 2046 7269 2c20 3037 204d 6172 ate: Fri, 07 Mar 2032 3030 3820 3130 3a32 393a 3436 2047 2008 10:29:46 G 4d54 0d0a 0d0a 3c21 444f 4354 5950 4520 MT..... 0a3c 6874 6d6c 3e0d 0a3c 6865 6164 3e0d .... 0a3c 6d65 7461 2068 7474 702d 6571 7569 ..... bed3 d7b0 d0de cdf8 2077 7777 2e68 616f ........ www.hao 3132 3330 302e 636e 3c2f 7469 746c 653e 12300.cn 0d0a 3c6c 696e 6b20 6872 6566 3d27 2f73 .......... .. 2020 203c 7464 3e3c 7363 7269 7074 206c 3c2f 7464 3e0d 0a20 203c 2f74 723e 0d0a .. .. 3c2f 7461 626c 653e 0d0a 3c74 6162 6c65 .... .. .. .. ....< 4120 7374 796c 653d 2242 4548 4156 494f A style="BEHAVIO 523a 2075 726c 2823 6465 6661 756c 7423 R: url(#default# 686f 6d65 7061 6765 2922 206f 6e63 6c69 homepage)" oncli 636b 3d22 7365 7448 6f6d 6550 6167 6528 ck="setHomePage( 2768 7474 703a 2f2f 7777 772e 6861 6f31 'http://www.hao1 3233 3030 2300 Data received: 2e63 6e27 2922 2068 7265 663d 226a 6176 .cn')" href="jav 6173 6372 6970 743a 3b22 3ec9 e8ce aaca ascript:;">..... d7d2 b33c 2f41 3e3c 2f54 443e 3c2f 5452 .........< 5444 2061 6c69 676e 3d6d 6964 646c 653e TD align=middle> 3c41 2068 7265 663d 226d 6169 6c74 6f3a ............< 494d 4720 6865 6967 6874 3d31 3620 7372 IMG height=16 sr 633d 222f 696d 6167 6573 2f62 6f6f 6b6d c="/images/bookm 6172 6b2e 6769 6622 2077 6964 7468 3d31 ark.gif" width=1 3620 616c 6967 6e3d 6162 734d 6964 646c 6 align=absMiddl 653e 3c2f 5444 3e0d 0a3c 5444 2061 6c69 e>.. 0d0a 3c2f 5441 424c 453e 3c2f 7464 3e0d ..
.. 3c2f 7464 3e0d 0a20 2020 203c 7464 2077
3c73 6372 6970 7420 6c61 6e67 7561 6765
3c2f 7464 3e0d 0a20 2020 203c 7464 2077
..
........ 3c2f 413e 0d0a 3c2f 5444 3e3c 2f54 523e ..
. 0a20 203c 2f74 723e 0d0a 3c2f 7461 626c . ..
.... cad7 d2b3 3c2f 6469 763e 3c2f 613e 3c2f ....
. 0a3c 7464 2063 6c61 7373 3d27 6e61 765f ...< 7464 2063 6c61 7373 3d27 6e61 765f 6c69 td class='nav_li 6e6b 3327 2061 6c69 676e 3d27 6365 6e74 nk3' align='cent 6572 273e 3c41 2063 6c61 7373 3d27 6e61 er'>...... b6a8 3c2f 613e 3c2f 7464 3e0d 0a3c 7464 ................ 3c2f 7461 626c 653e 0d0a 200d 0a3c 5441
.. d7b0 c8ed d7b0 3c2f 613e 3c2f 7464 3e0d ...... 3c41 2063 6c61 7373 3d27 6e61 7666 6f6e ................ 3c2f 7464 3e0d 0a3c 7464 2063 6c61 7373 ................ bcc6 3c2f 613e 3c2f 7464 3e0d 0a3c 7464 ..
.. .... ..
3c73 6372 6970 7420 7479 7065 3d27 7465 ....
.. 3c41 2068 7265 663d 272f 6874 6d6c 2f5a ........< 4120 6872 6566 3d27 2f68 746d 6c2f 5a58 A href='/html/ZX 414c 2f32 3030 3731 3132 302f 7a78 5f35 AL/20071120/zx_5 352e 6874 6d6c 273e 3c49 4d47 2069 643d 5.html'> 0d0a 3c2f 5444 3e3c 2f54 523e 3c54 523e .. 3c54 4420 3c74 6420 7661 6c69 676e 3d22 746f 7022 .... 3c74 6420 6865 6967 6874 3d32 3220 616c .... 3c74 723e 3c74 6420 6865 6967 6874 3d32 0d0a 3c74 723e 3c74 6420 6865 6967 6874 .... 0d0a 3c2f 7461 626c 653e 3c2f 7464 3e3c ..
< 696d 6720 7372 633d 222f 696d 6167 6573 img src="/images 2f69 7465 6d32 2e67 6966 223e 5b3c 6120 /item2.gif">[... deb9 a5c2 d43c 2f61 3e5d 3c61 2068 7265 .....]..... eed5 d0a3 bac8 c3c4 e3b5 c4bc d2bd f4b8 ................ fab3 b1c1 f73c 2f66 6f6e 743e 3c2f 613e ..... 3c2f 7464 3e3c 2f74 723e 0d0a 3c74 723e
5b3c 6120 6872 6566 3d27 2f68 746d 6c2f [........]... e6bc d2be dfa3 baca e3b7 a2b8 b4b9 c5b5 ................ e4d1 c5c7 e9bb b33c 2f66 6f6e 743e 3c2f .......
[........] 3c61 2068 7265 663d 272f 6874 6d6c 2f5a . bed6 cabc d2be dfa3 bacc ecc8 bbb5 f1ca ................ cece c2c5 afbb d8b9 e93c 2f66 6f6e 743e ......... 3c2f 613e 3c2f 7464 3e3c 2f74 723e 0d0a
[........]52............. baa1 b1c0 cbc2 feb5 c4bc d23c 2f66 6f6e ...........
[........< 2f61 3e5d 3c61 2068 7265 663d 272f 6874 /a>]............8 30c6 bdc3 d7b7 e7b8 f1d1 f9b0 e53c 2f66 0............
[........]............... bfbf d5bc e4be d6cf ded0 d43c 2f66 6f6e ...........
< 2f74 723e 3c2f 7461 626c 653e 0d0a 0d0a /tr>.... 2020 2020 2020 3c74 6162 6c65 2077 6964 .. 2020 203c 7472 3e20 0d0a 2020 2020 2020 .. 2020 2020 3c74 6420 7661 6c69 676e 3d27 .. 2020 203c 2f74 723e 0d0a 2020 2020 2020 .. 3c2f 7461 626c 653e 0d0a 2020 2020 2020
.. 3c74 6162 6c65 2077 6964 7468 3d27 3130 < 7464 2068 6569 6768 743d 2732 3227 2063 td height='22' c 6c61 7373 3d27 6c69 7374 6e65 7773 5f74 lass='listnews_t 6974 273e 3c41 2068 7265 663d 272f 6874 it'>.. d7b0 bce0 c0ed d6b8 b5bc bbb7 b1a3 d7b0 ................ d0de d3d0 382e 2e3c 2f61 3e3c 2f74 643e ....8.. 3c2f 7472 3e0d 0a3c 7472 3e3c 7464 2068 ........... 0a3c 7472 3e3c 7464 2068 6569 6768 743d ...... 0a3c 7472 3e3c 7464 2068 6569 6768 743d .......
.... c5c5 d0d0 2054 4f50 3130 3c2f 666f 6e74 .... TOP10
3c41 2068 7265 663d 272f 6874 6d6c 2f5a ...... cbae d1a7 d6ae b6fe a3ba cafd c0ed 3c2f ..............
............... b7d1 b0bc d2d7 b0c9 e82e 2e3c 2f61 3e3c ...........< 2f74 643e /td> Data received: 3c2f 7472 3e0d 0a3c 7472 3e3c 7464 2068
3c41 2068 7265 663d 272f 6874 6d6c 2f5a ..... bfbe bbb5 c4bc d2be d3ca cec6 b728 d7e9 .............(.. cdbc 293c 2f61 3e3c 2f74 643e 3c2f 7472 ..)
......... ebc0 cbc2 fecf e0b0 e9c8 ebc3 df3c 2f61 .............
bcd2 cda5 d7b0 d0de b7d1 d3c3 d4a4 cbe3 ................ 333c 2f61 3e3c 2f74 643e 3c2f 7472 3e0d 3
........... a8bf d5bc e420 c6ae b4b0 b5c4 2e2e 3c2f ..... ........
............... add1 e9cc b83c 2f61 3e3c 2f74 643e 3c2f .....
....... ccd3 a6b8 c3d7 a2d2 e2c4 c4d0 a9ce cacc ................ e23c 2f61 3e3c 2f74 643e 3c2f 7472 3e0d .
............ c9fd 20b0 e5b2 c4c0 e0bc d22e 2e3c 2f61 .. ..........
.. 2020 2020 2020 3c74 723e 200d 0a20 2020 .. 2020 2020 2020 203c 7464 3e3c 6469 7620 .. 2020 2020 3c2f 7472 3e0d 0a20 2020 2020 .. 203c 2f74 6162 6c65 3e0d 0a20 2020 2020
< 2f64 6976 3e3c 2f74 643e 0d0a 2020 2020 /div>
.. 203c 7461 626c 6520 7769 6474 683d 2731 ..
... a1cd bcc6 acd0 c0c9 cd3c 2f66 6f6e 743e ......... 3c2f 7464 3e3c 2f74 723e 3c74 723e 3c74
. 0a3c 7464 2061 6c69 676e 3d27 6365 6e74 .......
< 696d 6720 636c 6173 733d 2270 6963 3222 img class="pic2" 2073 7263 src Data received: 3d2f 5570 6c6f 6164 4669 6c65 732f 3230 =/UploadFiles/20 3037 3131 3230 3130 3239 3238 3330 342e 071120102928304. 6a70 6720 7769 6474 683d 2238 3822 2068 jpg width="88" h 6569 6768 743d 2236 3622 2062 6f72 6465 eight="66" borde 723d 2730 273e 3c2f 613e 3c2f 7464 3e0d r='0'>
< 2f61 3e3c 2f74 643e 0d0a 3c74 6420 616c /a>
..< 2f74 643e 0d0a 3c2f 7472 3e3c 7472 2076 /td>..
0d0a 2020 2020 3c74 6420 7661 6c69 676e .. .. 2020 203c 7472 3e20 0d0a 2020 2020 2020 .. 2020 2020 3c74 643e 3c74 6162 6c65 2077 < 7464 2077 6964 7468 3d22 3530 2522 2076 td width="50%" v 616c 6967 6e3d 2274 6f70 223e 3c54 4142 align="top"> 3c2f 7472 3e3c 7472 3e0d 0a3c 7464 2063 ..... 0a3c 7464 2063 6f6c 7370 616e 3d27 3227 ...< 2f74 723e 0d0a 3c74 723e 0d0a 3c74 6420 /tr>.... 0d0a 3c2f 7472 3e0d 0a3c 7472 3e0d 0a3c ......< 7464 2063 6f6c 7370 616e 3d27 3227 2061 td colspan='2' a 6c69 676e 3d22 6c65 6674 2220 7374 796c lign="left" styl 653d 2742 4f52 4445 522d 626f 7474 6f6d e='BORDER-bottom 3a20 2339 3939 3939 3920 3170 7820 646f : #999999 1px do 7474 6564 2720 636c 6173 733d 696e 6465 tted' class=inde 786c 6973 745f 7469 743e 3c41 2068 7265 xlist_tit>............ b5c4 d0c4 b5c3 cce5 bbe1 3c2f 613e 3c2f .............. 0d0a 3c74 6420 636f 6c73 7061 6e3d 2732 ........... 0a3c 7464 2063 6f6c 7370 616e 3d27 3227 ... 3c2f 7472 3e0d 0a3c 7472 3e0d 0a3c 7464 ........ 3c2f 7461 626c 653e 0d0a 3c2f 7464 3e3c
3c74 723e 0d0a 3c74 6420 636f 6c73 7061 .............. 3c74 6420 636f 6c73 7061 6e3d 2732 2720 ..< 2f74 723e 0d0a 3c74 723e 0d0a 3c74 6420 /tr>...................... 3c74 6420 636f 6c73 7061 6e3d 2732 2720 .......... 3c2f 7461 626c 653e 0d0a 3c2f 7464 3e3c
.... c9e8 bcc6 3c2f 666f 6e74 3e3c 2f73 7061 ....Mo 7265 2e2e 3c2f 666f 6e74 3e3c 2f61 3e3c re..< 2f73 7061 6e3e 3c2f 7464 3e3c 2f74 723e /span>
...... bcc6 d2aa d7a2 d2e2 b5c4 bcb8 b5e3 ceca ................ cce2 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ..
.. c8cb bfc9 d2d4 d7f6 d7d4 bcba b5c4 bfd5 ................ bce4 c4a7 b7a8 caa6 3c2f 613e 3c2f 7464 ........
............ b6a8 c2c9 3c2f 613e 3c2f 7464 3e0d 0a3c ....
c9e8 bcc6 caa6 d3eb c4e3 b7d6 cfed cbfb ................ b5c4 cad2 c4da c9e8 bcc6 b9b9 cdbc b7a8 ................ d4f2 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ..
.. ccb8 d7a1 d5ac cec0 c9fa bce4 b5c4 c9e8 ................ bcc6 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ..
.. b6a8 bcd2 d7b0 b7e7 b8f1 b4d3 c8fd b8f6 ................ bdc7 b6c8 c8eb cad6 3c2f 613e 3c2f 7464 ........
............ cace 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ..
...... b5c4 c3c0 c0f6 bcd2 bed3 c9e8 bcc6 3c2f ..............
..
... deb0 b8c0 fd3c 2f66 6f6e 743e 3c2f 7370 .....More.. 3c2f 613e 3c2f 7370 616e 3e3c 2f74 643e
b9e3 b8e6 bde7 c3c0 c5ae 4a61 6e65 74b5 ..........Janet. c4cb bdc8 cbb1 f0ca fb3c 2f61 3e3c 2f74 ...........
.......... bab6 bead 3c2f 613e 3c2f 7464 3e0d 0a3c ....
............... e4b5 c4b8 d0c7 e93c 2f61 3e3c 2f74 643e .......
......... bf20 d7b0 d0de b5e0 b7d6 c1bf 3c2f 613e . .......... 3c2f 7464 3e0d 0a3c 2f74 723e 0d0a 3c74
< 4120 6872 6566 3d27 2f68 746d 6c2f 5a58 A href='/html/ZX 414c 2f32 3030 3731 3132 332f 7a78 5f37 AL/20071123/zx_7 3334 2e68 746d 6c27 3ed0 a1bb a7d0 cdbf 34.html'>....... cdcc fcb5 c4d4 f6c8 ddc3 d8f3 c53c 2f61 ...............
.......... d0c4 c7e9 3ab4 d3c8 c8c7 e9b5 bdbe abc6 ....:........... a3c1 a6be a13c 2f61 3e3c 2f74 643e 0d0a .....
............
..< 2f74 723e 3c2f 7461 626c 653e 0d0a 3c74 /tr>..< 2f74 6162 6c65 3e0d 0a3c 7461 626c 6520 /table>..< 7464 2077 6964 7468 3d22 3530 2522 2076 td width="50%" v 616c 6967 6e3d 2274 6f70 223e 3c54 4142 align="top"> 3c2f 7472 3e3c 7472 3e0d 0a3c 7464 2063 ................. 0a3c 7472 3e0d 0a3c 7464 2063 6f6c 7370 .............. 0a3c 7472 3e0d 0a3c 7464 2063 6f6c 7370 .......< 7472 3e0d 0a3c 7464 2063 6f6c 7370 616e tr>......
... a4b1 a3d1 f83c 2f66 6f6e 743e 3c2f 7370 .....More.. 3c2f 613e 3c2f 7370 616e 3e3c 2f74 643e
............... cfc3 c53c 2f61 3e3c 2f74 643e 0d0a 3c2f ...
............... b8bd da3c 2f61 3e3c 2f74 643e 0d0a 3c2f ...
..............< 2f61 3e3c 2f74 643e 0d0a 3c2f 7472 3e0d /a>
....... ecd3 a6d4 f5c3 b4b4 a6c0 ed3c 2f61 3e3c ...........< 2f74 643e 0d0a 3c2f 7472 3e0d 0a3c 7472 /td>..
....... e5bc c7b5 c3d2 aab1 a3ca aa3c 2f61 3e3c ...........< 2f74 643e 0d0a 3c2f 7472 3e0d 0a3c 7472 /td>..
....... afb5 d8b0 e5b5 c4b0 cbb8 f6be f7c7 cf3c ...............< 2f61 3e3c 2f74 643e 0d0a 3c2f 7472 3e0d /a>
... f9d4 a4b7 c0ce c0d4 a1b7 c0b3 b13c 2f61 .............
3c41 2068 7265 663d 272f 6874 6d6c 2f57 ..... baca b5c4 beb5 d8b0 e5b5 c4b1 a3d1 f8b7 ................ a83c 2f61 3e3c 2f74 643e 0d0a 3c2f 7472 .
..
< 5441 424c 4520 7769 6474 683d 2731 3030 TABLE width='100 2527 2062 6f72 6465 723d 3020 6365 6c6c %' border=0 cell 5061 6464 696e 673d 3020 6365 6c6c 5370 Padding=0 cellSp 6163 696e 673d 313e 3c74 723e 3c74 6420 acing=1> bcd2 d7b0 d1a1 b2c4 3c2f 666f 6e74 3e3c ........< 2f73 7061 6e3e 3c73 7061 6e20 636c 6173 /span> 3c41 2068 7265 663d 272f 6874 6d6c 2f4a 3c66 6f6e 7420 636f 6c6f 723d 2723 3035 More................. f7c7 cf3c 2f61 3e3c 2f74 643e 0d0a 3c2f ............. bdcc c4e3 c8e7 bace d1a1 b9ba c8e9 bdba ................ c6e1 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ......... e2b6 c1d0 d0d2 b5c7 b1b9 e6d4 f23a bda8 .............:.. b2c4 b3ac cad0 b4e6 d4da b0d4 cdf5 ccf5 ................ bfee 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 ......... ccc4 faa3 bad4 f5d1 f9d1 a1b9 bac4 beb2 ................ c43c 2f61 3e3c 2f74 643e 0d0a 3c2f 7472 ......... bace d1a1 b9ba d3cd c6e1 bacd cdbf c1cf ................ 3c2f 613e 3c2f 7464 3e0d 0a3c 2f74 723e .. 0d0a 3c74 723e 0d0a 3c74 6420 636f 6c73 ....... bac8 e9bd bac6 e1b5 c4cb c4b8 f6d7 bcd4 ................ f23c 2f61 3e3c 2f74 643e 0d0a 3c2f 7472 ......... b9ba c7bf bbaf c4be b5d8 b0e5 b5c4 d7a2 ................ d2e2 b5e3 3c2f 613e 3c2f 7464 3e0d 0a3c ......< 2f74 723e 0d0a 3c74 723e 0d0a 3c74 6420 /tr>....5................ 3c2f 7461 626c 653e 0d0a 3c2f 7464 3e3c ..< 2f74 723e 3c2f 7461 626c 653e 3c54 4142 /tr>............
. 0a3c 5452 3e0d 0a3c 5444 2069 643d 6465 ...
0d0a 3c54 4142 4c45 2063 656c 6c53 7061 .................. 0d0a 3c54 4420 616c 6967 6e3d 6d69 6464 .. 0d0a 3c54 4420 616c 6967 6e3d 6d69 6464 ... 0a3c 5444 2061 6c69 676e 3d6d 6964 646c .. 0a3c 2f54 523e 3c2f 5441 424c 453e 0d0a .

..... b0d0 dec7 c9d3 c3c9 abb2 cab4 eec5 e43c ...............< 2f41 3e3c 2f54 443e 0d0a 3c54 4420 616c /A>

..... a1ca d220 d5b9 cfd6 cbc4 d6d6 b1ed 3c2f ... ..........

...... d4ec d3eb d6da b2bb cdac b5c4 bed3 3c2f ..............

...... b5e7 cad3 cac7 b2bb cac7 c2e4 cee9 3c2f ..............

...... c1a7 d3aa d4ec c7e9 b5f7 bcd2 283c 2f41 ............(

....... bbb5 c4bc d2be d3ca cec6 b728 3c2f 413e ...........(
3c2f 5444 3e0d 0a3c 5444 2061 6c69 676e
3c42 523e c5ae d0d4 cab1 c9d0 b4fa d1d4
............ 20ec c5b2 cabc d23c 2f41 3e3c 2f54 443e ......
< 4252 3eb4 b0a3 adcd b8b9 fdc1 edd6 bba1 BR>............. b0d1 dbbe a6a1 b13c 2f41 3e3c 2f54 443e .......< 4252 3ebf bfb5 e620 bcd2 d6d0 b5c4 d1f8 BR>.... ........ d1db d0a1 beab 3c2f 413e 3c2f 5444 3e0d .................... d1db bba8 a1b1 3c2f 413e 3c2f 5444 3e0d ......
.. 3c54 4420 6964 3d64 656d 6f31 3220 7641
..... .........s 6f67 6f75 5f61 645f 7069 6420 3d20 2279 ogou_ad_pid = "y 7331 3638 3030 223b 0d0a 3c2f 7363 7269 s16800";....