Gen.Variant.Strictor.25651_4d16c46a86
HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Strictor.25651 (B) (Emsisoft), Gen:Variant.Strictor.25651 (AdAware), Backdoor.Win32.Farfli.FD, Trojan-PSW.Win32.MSNPassword.FD, Trojan.Win32.FlyStudio.FD, Trojan.Win32.IEDummy.FD, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan, Backdoor
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 4d16c46a8633eacb8a7eb43e1abc8ed3
SHA1: 14e980eef7ebd62f31889cfa335b14e93f59e297
SHA256: 40bb28de749d30c3188d227e6b3f171ce40831e87930b8f6fb1415f6dbab4021
SSDeep: 24576:a/DBjBbgRhn04iOMzl3TEjr/bMNlB V hawK8jSJwriXIbsF5x/PouH5yMAUJDei:a/FBbFRjabMVbxKESJ iYWpgUcmJQDm
Size: 1789952 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2014-06-06 10:57:06
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan-PSW. Trojan program intended for stealing users passwords.
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
cacls.exe:504
cacls.exe:1552
cacls.exe:1460
cacls.exe:1636
cacls.exe:480
attrib.exe:308
attrib.exe:1676
attrib.exe:340
attrib.exe:828
qudongrensheng.dat:1552
The Trojan injects its code into the following process(es):
wscntmx.exe:496
%original file name%.exe:464
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process wscntmx.exe:496 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\b.bat (255 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cj[1].txt (5527 bytes)
%System%\drivers\etc\hosts.ics (18190 bytes)
%System%\drivers\etc\hosts (17655 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
C:\a.bat (356 bytes)
The process %original file name%.exe:464 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\style[1].css (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (22591 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (3978 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (8891 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[2].gif (20562 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (1004 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (30383 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\941pojie[1].htm (1595 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[2].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgnav[1].gif (853 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (247 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\zs[1].jpg (49159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (2857 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[3].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1].png (362 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\046bt[1].gif (2605 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (14652 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (28985 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[3].gif (1871 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1].htm (1777 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[2].png (28003 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gg[1].png (5593 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[1].png (29443 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\top[1].png (9019 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (745 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (4402 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[1].gif (22469 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgheader[1].gif (742 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bgtitle[1].gif (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\jbc[1].gif (28161 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (2782 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[2].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\swz[1].gif (9999 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\jbc[1].gif (32881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (1587 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (1599 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[1].gif (25772 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[3].gif (37248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\zs[1].jpg (37417 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\top[1].png (9091 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\logo[1].gif (2329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (35465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jiaqun[1].htm (256 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (1765 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (32993 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (22637 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swz[1].gif (9253 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[2].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[1].gif (38279 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (38889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (1506 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (10189 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1] (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\js[1].gif (34828 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[2].gif (42863 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[1].php (1475 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[2].txt (330 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (2615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[3].php (1177 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[1].gif (32715 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[2].gif (853 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1] (1441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\046bt[1].gif (2688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (4300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (442 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[1].gif (2665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gg[1].png (10352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (916 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[2].gif (43 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (0 bytes)
The process qudongrensheng.dat:1552 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\hao123_res.tmp (35 bytes)
Registry activity
The process cacls.exe:504 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "99 35 8F 77 E9 28 CC 57 64 E9 3C 07 CB 74 86 66"
The process cacls.exe:1552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 43 B5 F9 BC 42 A7 E0 B2 AA 63 DE D8 63 E8 C2"
The process cacls.exe:1460 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3E 19 A1 39 3C 61 68 83 F9 E2 90 70 D3 60 19 72"
The process cacls.exe:1636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7C B8 46 53 AB 01 F3 D1 C5 0C 1D 4E FE 63 9A 36"
The process cacls.exe:480 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7A 9E A6 D4 97 FC 97 60 3E 3A 0D 77 D2 19 E8 C8"
The process attrib.exe:308 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1A 2C A9 DF E7 BC DC 9B 76 79 55 A3 F7 50 12 E1"
The process attrib.exe:1676 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "22 6F B8 45 2C 72 5C 57 E9 96 D8 A3 FD 78 16 36"
The process attrib.exe:340 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "32 C8 77 B7 27 3B A7 62 88 8F 59 0F 45 A9 4C 67"
The process attrib.exe:828 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F1 88 A4 9C 06 D1 2A 1A AB 3E CC 5D 67 94 63 64"
The process wscntmx.exe:496 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "83 CF D0 25 8B 15 56 65 23 1D 4E 30 33 4E 4B E3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"wscntmx" = "D:\\wscntmx.exe"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process %original file name%.exe:464 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BC BE 09 5E 69 3B 7B 32 E7 66 55 4C D7 D2 A9 FD"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"
[HKCU\Software\Microsoft\Multimedia\DrawDib]
"vga.drv 1276x846x32(BGR 0)" = "31,31,31,31"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process qudongrensheng.dat:1552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "24 51 D5 EC 37 C5 D8 77 A4 E7 61 09 72 EA B2 95"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Services\WinHelp32\Parameters]
"ServiceDll" = "%System%\ackwpw.dll"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"krnlsrvc" = "WinHelp32"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\System\CurrentControlSet\Services\WinHelp32\Parameters]
"seRVicemAIN" = "RunDllEntry"
[HKLM\System\CurrentControlSet\Services\WinHelp32]
"Description" = "Windows Help System for X32 windows desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Dropped PE files
| MD5 | File path |
|---|---|
| 623cdebf1ed65aaba993745ad979881f | c:\WINDOWS\system32\ackwpw.dll |
HOSTS file anomalies
The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 65537 bytes in size. The following strings are added to the hosts file listed below:
| 162.211.182.39 | 988.pa579.com |
| 162.211.182.39 | 999.23dpw.com |
| 162.211.182.39 | www.jyjyh.com |
| 162.211.182.39 | tuiguang.8msm.com |
| 162.211.182.39 | fe.yueworld.net |
| 162.211.182.39 | 920aa.changyc.com |
| 162.211.182.39 | xb.qicaimofang.com |
| 162.211.182.39 | www.yx003.com |
| 162.211.182.39 | www1.pkokok.com |
| 162.211.182.39 | www.75945.com |
| 162.211.182.39 | www.lpf010.com |
| 162.211.182.39 | www.6000pk.com |
| 162.211.182.39 | 9pk.2766161.com |
| 162.211.182.39 | www.zhaof7.com |
| 162.211.182.39 | www.cqhr.org |
| 162.211.182.39 | www.ddzhe.com |
| 162.211.182.39 | pk789.52fanfou.com |
| 162.211.182.39 | 160uc.com |
| 162.211.182.39 | www.1nhh.com |
| 162.211.182.39 | www.52sol.com |
| 162.211.182.39 | www.cpu500.com |
| 162.211.182.39 | www.2381sfcq.com |
| 162.211.182.39 | www.uc37.com |
| 162.211.182.39 | www.98pk97.com |
| 162.211.182.39 | www.hbcyly.com |
| 162.211.182.39 | haosf.lfweibo.com |
| 162.211.182.39 | cq.kgfanli.com |
| 162.211.182.39 | www.999yc.com |
| 162.211.182.39 | www1.jjj.com |
| 162.211.182.39 | zhaosf.acrmbs.com |
| 162.211.182.39 | www.uc900.com |
| 162.211.182.39 | www2.jjj.com |
| 162.211.182.39 | www3.jjj.com |
| 162.211.182.3 | 1711ok.zz135.com |
| 162.211.182.39 | w13518.hr.jw.tczj.net |
| 162.211.182.39 | zhaofu7.com |
| 162.211.182.39 | tuiguang.592097.com |
| 162.211.182.39 | v.yueworld.net |
| 162.211.182.39 | zhaosf.ofyn.net |
| 162.211.182.39 | dk.qicaimofang.com |
| 162.211.182.39 | 578101.com |
| 162.211.182.39 | www.578101.com |
| 162.211.182.39 | www.126disk.com |
| 162.211.182.39 | tui99.592097.com |
| 162.211.182.39 | tui99.8msm.com |
| 162.211.182.39 | dd.guidawang.com |
| 162.211.182.39 | bb.fushilu.com |
| 162.211.182.39 | www.zhaofu7.com |
| 162.211.182.39 | www.baiduzhaokf.com |
| 162.211.182.39 | www.haosf.com |
| 162.211.182.39 | www.jsl-cn.com |
| 162.211.182.39 | www.88858.com |
| 162.211.182.39 | www.heshilurong.com |
| 162.211.182.39 | www.168fm.com |
| 162.211.182.39 | www.artobrain.com |
| 162.211.182.39 | wwv.jb345.com |
| 162.211.182.39 | www.zhaosf9999.com |
| 162.211.182.39 | www.uc1000.com |
| 162.211.182.39 | www4.jjj.com |
| 162.211.182.39 | www.uc900.com |
| 162.211.182.39 | www.uc900.com |
| 162.211.182.39 | www.cctv-kowann.com |
| 162.211.182.39 | www5.jjj.com |
| 162.211.182.39 | www.artobrain.com |
| 162.211.182.39 | www.jxytqz.com |
| 162.211.182.39 | www.as9z.com |
| 162.211.182.39 | pk789.52fanfou.com:81 |
| 162.211.182.39 | 36cq.dg8681.com:3636 |
| 162.211.182.39 | www.444yx.com |
| 162.211.182.39 | www.993yx.com |
| 162.211.182.39 | jjj.com |
| 162.211.182.39 | www1.99s.com |
| 162.211.182.39 | www2.99s.com |
| 162.211.182.39 | 99s.com |
| 162.211.182.39 | www99s.com |
| 162.211.182.39 | www.uc1000.com |
| 162.211.182.39 | 2410.eodfmr.cn |
| 162.211.182.39 | www.www99s.com |
| 162.211.182.39 | www.woool99s.com |
| 162.211.182.39 | www3.99s.com |
| 162.211.182.39 | 9k1.pa579.com |
| 162.211.182.39 | www1.zhaosf.com |
| 162.211.182.39 | www2.zhaosf.com |
| 162.211.182.39 | www3.zhaosf.com |
| 162.211.182.39 | www4.zhaosf.com |
| 162.211.182.39 | www5.zhaosf.com |
| 162.211.182.39 | new.fa111.com |
| 162.211.182.39 | www.zhaosf.com |
| 162.211.182.39 | www4.99s.com |
| 162.211.182.39 | www5.99s.com |
| 162.211.182.39 | www.09445.com |
| 162.211.182.39 | www.cdxxzs.com |
| 162.211.182.39 | www.angelsimple.cn |
| 162.211.182.39 | www.lida00.cn |
| 162.211.182.39 | www.zbzishen.com |
| 162.211.182.39 | www.86jiewang.cn |
| 162.211.182.39 | www.itcr.cn |
| 162.211.182.39 | www.99u.net.ru |
| 162.211.182.39 | xp.wzca.com.cn |
| 162.211.182.39 | www.wan345.com |
| 162.211.182.39 | dns.521jjj.com |
| 162.211.182.39 | www.525uc.com |
| 162.211.182.39 | www.1cq.com |
| 162.211.182.39 | www.jjj.com |
| 162.211.182.39 | www.99s.com |
| 162.211.182.39 | www.gm005.com |
| 162.211.182.39 | www.68kf.com |
| 162.211.182.39 | wwk.astbw.com |
| 162.211.182.39 | zz.sf163.com |
| 162.211.182.39 | www.sotrip.com |
| 162.211.182.39 | 33k.pa579.com |
| 162.211.182.39 | www.555sf.com |
| 162.211.182.39 | www.66hst.com |
| 162.211.182.39 | 66hst.com |
| 162.211.182.39 | www.xin45.com |
| 162.211.182.39 | xin45.com |
| 162.211.182.39 | www.zhaocq.com |
| 162.211.182.39 | 1.52yanzheng.sinaapp.com |
| 162.211.182.39 | www.175sf.com |
| 162.211.182.39 | www.yxyhx.com |
| 162.211.182.39 | www.168fm.com |
| 162.211.182.39 | habourbiotech.com |
| 162.211.182.39 | www.pydwlm.com |
| 162.211.182.39 | www.ux99.com |
| 162.211.182.39 | www.hn17173.net |
| 162.211.182.39 | www.5s98.com |
| 162.211.182.39 | www.880s.com |
| 162.211.182.39 | www.118uc.com |
| 162.211.182.39 | www.zf777.com |
| 162.211.182.39 | 81.2381f.com |
| 162.211.182.39 | www.njkaidu.com |
| 162.211.182.39 | www.9szf.com |
| 162.211.182.39 | www.999zsf.com |
| 162.211.182.39 | www.85zf.com |
| 162.211.182.39 | www.951pk.com |
| 162.211.182.39 | www.851pk.com |
| 162.211.182.39 | 988.pa579.com |
| 162.211.182.39 | ad.97uu.com |
| 162.211.182.39 | www.i8pk.com |
| 162.211.182.39 | www.sf996.com |
| 162.211.182.39 | www.0579st.com |
| 162.211.182.39 | www.mc1314.com |
| 162.211.182.39 | gm016.comforum.php |
| 162.211.182.39 | www.whsfzx.com |
| 162.211.182.39 | dd.sh-tongy.com |
| 162.211.182.39 | 111.kaihu365.com |
| 162.211.182.39 | www.dddgm.com |
| 162.211.182.39 | www.ok126.net |
| 162.211.182.39 | www.wanshituliao.com |
| 162.211.182.39 | www.zaxue.net |
| 162.211.182.39 | www.4006517008.com |
| 162.211.182.39 | www.tcrhy.com |
| 162.211.182.39 | www.vdisk.cnyy6018 |
| 162.211.182.39 | www.sf383.com |
| 162.211.182.39 | www.001gm.net |
| 162.211.182.39 | www.006it.com |
| 162.211.182.39 | www.gm5555.com |
| 162.211.182.39 | www.yxyhx.com |
| 162.211.182.39 | h.chinagiftidea.com |
| 162.211.182.39 | www.3jidi-gz.com |
| 162.211.182.39 | www.100gczg.com |
| 162.211.182.39 | 1.consultants-sp.com |
| 162.211.182.39 | haosf.lgknow.com |
| 162.211.182.39 | www.vdisk.cnchuanqiwangzhan |
| 162.211.182.39 | www.z0137cx.comzm6x5 |
| 162.211.182.39 | habourbiotech.com |
| 162.211.182.39 | www.satsalt.com |
| 162.211.182.39 | tg1.37.com?uid=1421131 |
| 162.211.182.39 | pi.nuwa-mountain.org |
| 162.211.182.39 | www.jafdc.net |
| 162.211.182.39 | 941pk.com |
| 162.211.182.39 | www.5iwowo.com |
| 162.211.182.39 | www.bonopt.com |
| 162.211.182.39 | xu.shandonghaofanyi.com |
| 162.211.182.39 | h.chinagiftidea.com |
| 162.211.182.39 | www.sxyish.comindex1.htm |
| 162.211.182.39 | www.jzdkfj.com |
| 162.211.182.39 | henuedu.cn |
| 162.211.182.39 | www.sdjialiang.com |
| 162.211.182.39 | www.10010cq.com |
| 162.211.182.39 | www.z0137cx.comkwcs |
| 162.211.182.39 | www.0512rc.net |
| 162.211.182.39 | www.dahanjg.com |
| 162.211.182.39 | www.ht-vision.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.jfy8rv.comzjp6bw |
| 162.211.182.39 | www.yxyhx.com |
| 162.211.182.39 | www.9uzg.com |
| 162.211.182.39 | www.gm667.com |
| 162.211.182.39 | www.znspyq.com9dzf7w |
| 162.211.182.39 | www.18-81.net |
| 162.211.182.39 | www.ht-vision.com |
| 162.211.182.39 | www.gmwly.com |
| 162.211.182.39 | user.qzone.qq.com5674167 |
| 162.211.182.39 | t.qq.comchuanqisf8997 |
| 162.211.182.39 | www.njjqgck.com |
| 162.211.182.39 | www.hkalu.com |
| 162.211.182.39 | www.60sf.com |
| 162.211.182.39 | www.pk123.com |
| 162.211.182.39 | www.52anzu.com |
| 162.211.182.39 | www1.52anzu.com |
| 162.211.182.39 | 52anzu.com |
| 162.211.182.39 | www.sopojie.com |
| 162.211.182.39 | www1.sopojie.com |
| 162.211.182.39 | sopojie.com |
| 162.211.182.39 | www.wf22.com |
| 162.211.182.39 | xingyoufz.wwpan.com |
| 162.211.182.39 | www.36ok.com |
| 162.211.182.39 | www.32fa.com |
| 162.211.182.39 | wws.99acc.com |
| 162.211.182.39 | www.916cq.com |
| 162.211.182.39 | 1711ok.sh77577.com |
| 162.211.182.39 | www.18uc.com |
| 162.211.182.39 | 18uc.com |
| 162.211.182.39 | 88pk.com |
| 162.211.182.39 | www.88pk.com |
| 162.211.182.39 | 162.212.180.86 |
| 162.211.182.39 | 36ok.com |
| 162.211.182.39 | 118.99.26.156 |
| 162.211.182.39 | 23.234.60.34 |
| 162.211.182.39 | www.52anzu.net |
| 162.211.182.39 | www.77250.com |
| 162.211.182.39 | 77250.com |
| 162.211.182.39 | www1.52anzu.net |
| 162.211.182.39 | tt.1kuv.com |
| 162.211.182.39 | www1.sopojie.comforum.php |
| 162.211.182.39 | www.33ok.com |
| 162.211.182.39 | 916cq.com |
| 162.211.182.39 | 91ww.91fu.com |
| 162.211.182.39 | www1.pk777.com |
| 162.211.182.39 | www.sf999.com |
| 162.211.182.39 | www.yeahooo.net |
| 162.211.182.39 | 1.townhall.cn |
| 162.211.182.39 | www.bjjijiubao.com |
| 162.211.182.39 | 1.xa1314.com.cn |
| 162.211.182.39 | www.yvwtjf.com/rkwwcq |
| 162.211.182.39 | www.stylepacking.com |
| 162.211.182.39 | www.cnfengye.com |
| 162.211.182.39 | www.zazgame.com |
| 162.211.182.39 | www.zrplay.com |
| 162.211.182.39 | www.yczdwj.com |
| 162.211.182.39 | www.zheyutegang.com |
| 162.211.182.39 | www.sf123.com |
| 162.211.182.39 | www.daqiandoor.com |
| 162.211.182.39 | www.77d8.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.liwenjie374.cn/yjall |
| 162.211.182.39 | www.wwesf.com |
| 162.211.182.39 | www.7988ok.com |
| 162.211.182.39 | www.shfengyi.com |
| 162.211.182.39 | pg.iflu.com.cn |
| 162.211.182.39 | www.gdtrane.com |
| 162.211.182.39 | www.scxlm.com |
| 162.211.182.39 | www.kisspk.com |
| 162.211.182.39 | www.cqxz.com.cn |
| 162.211.182.39 | www.kanonsh.com |
| 162.211.182.39 | www.gm1208.com |
| 162.211.182.39 | www.provoxav.com |
| 162.211.182.39 | dgdimei.com |
| 162.211.182.39 | www.cntzdh.com |
| 162.211.182.39 | www.xinchengyunshu.com |
| 162.211.182.39 | www.hanwise.com |
| 162.211.182.39 | www.xinchengyunshu.com |
| 162.211.182.39 | ygjm.gz2.hostadm.net |
| 162.211.182.39 | www.mfttj.com |
| 162.211.182.39 | www.shenqi.com |
| 162.211.182.39 | www.52345.com |
| 162.211.182.39 | 81f.hao899.com |
| 162.211.182.39 | www.sf123.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.daqiandoor.com |
| 162.211.182.39 | www.941jb.com |
| 162.211.182.39 | 2sogo.com |
| 162.211.182.39 | mobanbbs.com |
| 162.211.182.39 | 91ww.555uc.com |
| 162.211.182.39 | 8uc.haosf33.com |
| 162.211.182.39 | 81f.hao979.com |
| 162.211.182.39 | www.99j.com |
| 162.211.182.39 | www.91ww.com |
| 162.211.182.39 | www.777uc.com |
| 162.211.182.39 | pk123.haosf321.com |
| 162.211.182.39 | pk123.92sou.com |
| 162.211.182.39 | www.xbkdq.com |
| 162.211.182.39 | 66sf.77zhao.com |
| 162.211.182.39 | www.184pk.com |
| 162.211.182.39 | www.sf999.com |
| 162.211.182.39 | www.pk777.com |
| 162.211.182.39 | www.alfatoyota.com |
| 162.211.182.39 | mobanbbs.com |
| 162.211.182.39 | www.stbshg.com |
| 162.211.182.39 | www.daqiandoor.com |
| 162.211.182.39 | www.1cq.com/1cqlwg.htm |
| 162.211.182.39 | www.xbkdq.com |
| 162.211.182.39 | www.sf123.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.buyishijia.com |
| 162.211.182.39 | www.sf999.com |
| 162.211.182.39 | www.shenqi.com |
| 162.211.182.39 | www.52345.com |
| 162.211.182.39 | www.92045.com |
| 162.211.182.39 | 92045.52yoyoo.com |
| 162.211.182.39 | 92045.92450.com |
| 162.211.182.39 | pk123.haosf321.com |
| 162.211.182.39 | pk123.92sou.com |
| 162.211.182.39 | baidu.926uu.com |
| 162.211.182.39 | baidu.jw888.com |
| 162.211.182.39 | www.926.com |
| 162.211.182.39 | 999.65zy.com |
| 162.211.182.39 | www.99j.com |
| 162.211.182.39 | www.945pk.com |
| 162.211.182.39 | 8uc.haosf33.com |
| 162.211.182.39 | www.91ww.com |
| 162.211.182.39 | www.8uu.com |
| 162.211.182.39 | 81f.hao883.com |
| 162.211.182.39 | 81f.hao979.com |
| 162.211.182.39 | 81f.hao899.com |
| 162.211.182.39 | www.81f.com |
| 162.211.182.39 | 66sf.77zhao.com |
| 162.211.182.39 | www.nihao119.com |
| 162.211.182.39 | www.66sf.com |
| 162.211.182.39 | kkkfu.sylytz.com |
| 162.211.182.39 | 83aa.sf078.com |
| 162.211.182.39 | 521fu.9173uc.com |
| 162.211.182.39 | www.777uc.com |
| 162.211.182.39 | www.pk777.com |
| 162.211.182.39 | www.30ok-1.com |
| 162.211.182.39 | www.haocq.com |
| 162.211.182.39 | sf.haocq.com |
| 162.211.182.39 | www.1000ok.com |
| 162.211.182.39 | tg1.37wan.com |
| 162.211.182.39 | wvw.rq23.com |
| 162.211.182.39 | wvw.2013wan.com |
| 162.211.182.39 | wvw.9377z.com |
| 162.211.182.39 | mmm.wopaijs.com |
| 162.211.182.39 | www.yyy279.com |
| 162.211.182.39 | wvw.9377s.com |
| 162.211.182.39 | www.zhujiutx.com |
| 162.211.182.39 | www.hbwxkj.com |
| 162.211.182.39 | www.sh-chengshan.com |
| 162.211.182.39 | zhaosfcq.com |
| 162.211.182.39 | www.subpig.net |
| 162.211.182.39 | www.jlzcfx.com |
| 162.211.182.39 | www.66sf.com |
| 162.211.182.39 | www.cdxxlh.com |
| 162.211.182.39 | www.83uc.com |
| 162.211.182.39 | www.shjwd.com |
| 162.211.182.39 | www.jingming-sh.com |
| 162.211.182.39 | www.aerosun.cn |
| 162.211.182.39 | www.qdhd.com.cn |
| 162.211.182.39 | www.flyxg.com |
| 162.211.182.39 | www.zggljt.com |
| 162.211.182.39 | www.99mc.com |
| 162.211.182.39 | www.138zg.com |
| 162.211.182.39 | www.523zg.com |
| 162.211.182.39 | www.98zg.com |
| 162.211.182.39 | www.78zg.cn |
| 162.211.182.39 | www.99ting.cn |
| 162.211.182.39 | www.27zg.com |
| 162.211.182.39 | www.92sanduo.com |
| 162.211.182.39 | www.527zg.com |
| 162.211.182.39 | www.xstylxx.com |
| 162.211.182.39 | www.xrsd-water.com |
| 162.211.182.39 | www.tttjsq.com |
| 162.211.182.39 | www.y1995.com |
| 162.211.182.39 | www.883sf.com |
| 162.211.182.39 | sf123.com |
| 162.211.182.39 | changjing.759rsq.com |
| 162.211.182.39 | xinqing.kqgf69.com |
| 162.211.182.39 | www.xahdc.com |
| 162.211.182.39 | www.haotl.com |
| 162.211.182.39 | www.chinajin-hui.com |
| 162.211.182.39 | jingcai.edtiq6.com |
| 162.211.182.39 | www.fullkang.net.com |
| 162.211.182.39 | tanxian.u895.com |
| 162.211.182.39 | www.m526.com |
| 162.211.182.39 | www.majorsoul.com |
| 162.211.182.39 | xitong.vxtui.com |
| 162.211.182.39 | www.4006517008.com |
| 162.211.182.39 | changjing.pbbxy.com |
| 162.211.182.39 | wanjia.x9858.com |
| 162.211.182.39 | jiaoliu.s9275.com |
| 162.211.182.39 | sf225.com |
| 162.211.182.39 | www.haosf.com |
| 162.211.182.39 | www.tcrhy.com |
| 162.211.182.39 | www.001gm.net |
| 162.211.182.39 | cqdl321.com |
| 162.211.182.39 | www.b9jojo.com |
| 162.211.182.39 | www.9kf.com |
| 162.211.182.39 | www.sf138.com |
| 162.211.182.39 | www.628118.com |
| 162.211.182.39 | www.hezol.com |
| 162.211.182.39 | www.qjkutrgw.com |
| 162.211.182.39 | www.ashijia.com |
| 162.211.182.39 | www.1200sf.com |
| 162.211.182.39 | www.aarongj.com |
| 162.211.182.39 | www.53my.com |
| 162.211.182.39 | www.888cnc.com |
| 162.211.182.39 | www.sf3000.com |
| 162.211.182.39 | www.29u.in |
| 162.211.182.39 | www.96sf.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.sf800.com |
| 162.211.182.39 | www.77mxd.com |
| 162.211.182.39 | www.9uzg.com |
| 162.211.182.39 | www.sf999.com.ru |
| 162.211.182.39 | www.szmajsy.com |
| 162.211.182.39 | www.jptea.cn |
| 162.211.182.39 | 521fu.52345uc.com |
| 162.211.182.39 | www.cqpk11.com |
| 162.211.182.39 | www.insdfjisd.com |
| 162.211.182.39 | www.828kk.com |
| 162.211.182.39 | www.irrchina.com |
| 162.211.182.39 | www.22nf.com |
| 162.211.182.39 | www.jiutianzs.com |
| 162.211.182.39 | www.103la.com |
| 162.211.182.39 | www.889ok.com |
| 162.211.182.39 | huanshou.8236r.com |
| 162.211.182.39 | www.1129f.com |
| 162.211.182.39 | 345ye.861sf.com |
| 162.211.182.39 | www.861sf.com |
| 162.211.182.39 | 861sf.com |
| 162.211.182.39 | www.sf985.com |
| 162.211.182.39 | www.bonopt.com |
| 162.211.182.39 | cq45.cn |
| 162.211.182.39 | www.cq45.cn |
| 162.211.182.39 | www.bgdtw.com |
| 162.211.182.39 | www.930t.com |
| 162.211.182.39 | www.tianhuao.com |
| 162.211.182.39 | www.99a.net.ru |
| 162.211.182.39 | www.hmyigou.com |
| 162.211.182.39 | www.fzjx.net |
| 162.211.182.39 | www.ez-max.net |
| 162.211.182.39 | www.zhuoranfm.com |
| 162.211.182.39 | www.ccadly.net |
| 162.211.182.39 | www.chinasysw.com |
| 162.211.182.39 | www.dyjkdd.com |
| 162.211.182.39 | www.cnbaoerte.com |
| 162.211.182.39 | www.sf895.com |
| 162.211.182.39 | www.joywei.com |
| 162.211.182.39 | www.yalincs.com |
| 162.211.182.39 | www.kkstar.com |
| 162.211.182.39 | www.949g.com |
| 162.211.182.39 | www.zhaosf.com.co |
| 162.211.182.39 | www.3000ok.com.cn |
| 162.211.182.39 | n813.com |
| 162.211.182.39 | uc88.com |
| 162.211.182.39 | qu45.com |
| 162.211.182.39 | www.aop9988.com |
| 162.211.182.39 | www.sdytgj.com |
| 162.211.182.39 | www.gzgien.com |
| 162.211.182.39 | www.chuanqige.com |
| 162.211.182.39 | 51my8.com |
| 162.211.182.39 | www.99j.com.es |
| 162.211.182.39 | www.sf452.com |
| 162.211.182.39 | www.981sf.com |
| 162.211.182.39 | www.sf382.com |
| 162.211.182.39 | www.hldly.com |
| 162.211.182.39 | www.sf062.com |
| 162.211.182.39 | www.8345sf.com |
| 162.211.182.39 | www.sdfwesq.com |
| 162.211.182.39 | www.sjxt123.com |
| 162.211.182.39 | www.daqiandoor.com |
| 162.211.182.39 | www.125sf.com |
| 162.211.182.39 | www.xieqiyy.com |
| 162.211.182.39 | www.ldyeya.com |
| 162.211.182.39 | www.088sf.net |
| 162.211.182.39 | 83so.com |
| 162.211.182.39 | www.sf421.com |
| 162.211.182.39 | www.4f920.com |
| 162.211.182.39 | www.tiaolou8.com |
| 162.211.182.39 | www.taocooler.com |
| 162.211.182.39 | www.wanpp.com |
| 162.211.182.39 | www.fhzsm.com |
| 162.211.182.39 | www.pt12319.com |
| 162.211.182.39 | www.hx-lace.com |
| 162.211.182.39 | klmy.cn.com |
| 162.211.182.39 | www.jiagao.net |
| 162.211.182.39 | 76776.com |
| 162.211.182.39 | www.htwjcy.com |
| 162.211.182.39 | www.win757.com |
| 162.211.182.39 | www.hnjxzz.cn |
| 162.211.182.39 | www.xmdvip.com |
| 162.211.182.39 | swqzp.com |
| 162.211.182.39 | www.tungsten-moly.com |
| 162.211.182.39 | jingyan.986jj.com |
| 162.211.182.39 | www.xxf888.com |
| 162.211.182.39 | www.cnrsyy.com |
| 162.211.182.39 | www.txingzuo.com |
| 162.211.182.39 | www.ykmir.com |
| 162.211.182.39 | www.xjxianping.cn |
| 162.211.182.39 | www.web01.cn |
| 162.211.182.39 | www.yijiaedu.cn |
| 162.211.182.39 | vipxun.9uzg.com |
| 162.211.182.39 | dushisuanlafen.cn |
| 162.211.182.39 | www.zzyichen.com |
| 162.211.182.39 | www.cnnoblelight.com |
| 162.211.182.39 | klkemu.net |
| 162.211.182.39 | www.faith-forever.com |
| 162.211.182.39 | www.bopuai.cn |
| 162.211.182.39 | www.xzchuitou.cn |
| 162.211.182.39 | www.ccxbzk.cn |
| 162.211.182.39 | www.915788.com |
| 162.211.182.39 | www.sdxtcnc.com |
| 162.211.182.39 | www.sz-stv.com |
| 162.211.182.39 | www.fjoss.com |
| 162.211.182.39 | www.204sf.com |
| 162.211.182.39 | www.tech-sss.com |
| 162.211.182.39 | www.mywowpl.com |
| 162.211.182.39 | www.shi-yi.net |
| 162.211.182.39 | www.hzlyfashion.com |
| 162.211.182.39 | www.freeshu.com |
| 162.211.182.39 | www.chinatianmei.com |
| 162.211.182.39 | 00pk.com |
| 162.211.182.39 | www.tqb88.com |
| 162.211.182.39 | 4593.9kf.com |
| 162.211.182.39 | www.120yi.com |
| 162.211.182.39 | www.hdmchina.com |
| 162.211.182.39 | www.zzfuxi.com |
| 162.211.182.39 | www.sdicl.com |
| 162.211.182.39 | www.ebontec.com |
| 162.211.182.39 | www.3000oksf.com |
| 162.211.182.39 | www.shqing8.com |
| 162.211.182.39 | www.666mir.com |
| 162.211.182.39 | www.adchy.com |
| 162.211.182.39 | www.pyprint.com |
| 162.211.182.39 | www.56chuanqi.com |
| 162.211.182.39 | www.simicc.com |
| 162.211.182.39 | www.a5zg.com |
| 162.211.182.39 | www.szhcgroup.com |
| 162.211.182.39 | www.57ssy.com |
| 162.211.182.39 | www.qingzhou8.com |
| 162.211.182.39 | tt292.com |
| 162.211.182.39 | www.jiatianneiyi.com |
| 162.211.182.39 | www.leeed.com |
| 162.211.182.39 | www.20020505.com |
| 162.211.182.39 | www.kl-chem.com |
| 162.211.182.39 | www.tjzssd.com |
| 162.211.182.39 | www.nnhxjh.com |
| 162.211.182.39 | www.dwmir.com |
| 162.211.182.39 | www.kk519.com |
| 162.211.182.39 | www.chinanewhope.net |
| 162.211.182.39 | www.yalimei-group.com |
| 162.211.182.39 | www.jiulongbelt.com |
| 162.211.182.39 | aaa7.9uzg.com |
| 162.211.182.39 | www.dushisuanlafen.cn |
| 162.211.182.39 | www.cn0796.com |
| 162.211.182.39 | www.hnfengyuan.com |
| 162.211.182.39 | www.yixinghai.com |
| 162.211.182.39 | www.zgtjsteel.com |
| 162.211.182.39 | www.51disky.com |
| 162.211.182.39 | www.zhybbs.com |
| 162.211.182.39 | www.91kaixue.com |
| 162.211.182.39 | www.fyplay.com |
| 162.211.182.39 | www.wowidc.com |
| 162.211.182.39 | www.jiahongtex.com |
| 162.211.182.39 | www.diselife.com |
| 162.211.182.39 | www.yygdz.com |
| 162.211.182.39 | www.kexingco.com |
| 162.211.182.39 | www.88fb.com |
| 162.211.182.39 | www.botaofan.com |
| 162.211.182.39 | www.zzhdjx.cn |
| 162.211.182.39 | www.cntuliao.com |
| 162.211.182.39 | www.m5y6.cn |
| 162.211.182.39 | www.songzhilu.com |
| 162.211.182.39 | zhaopeng.net |
| 162.211.182.39 | www.xiayunfei.com |
| 162.211.182.39 | soyoesd.cn |
| 162.211.182.39 | www.523zg.com |
| 162.211.182.39 | regongjixie.com |
| 162.211.182.39 | www.mir87.com |
| 162.211.182.39 | chinachengyang.cn |
| 162.211.182.39 | www.dgguanglin.com |
| 162.211.182.39 | www.huayuebz.com |
| 162.211.182.39 | www.xxsw028.com |
| 162.211.182.39 | www.myppchina.com |
| 162.211.182.39 | www.gzsuper.com |
| 162.211.182.39 | www.txhtc.com |
| 162.211.182.39 | www.cdcx1956.com |
| 174.128.248.72 | www.yaliwood.com |
| 162.211.182.39 | www.flower024.com |
| 162.211.182.39 | www.5ttb.com |
| 162.211.182.39 | www.i193.com |
| 162.211.182.39 | www.shweiheng.com |
| 162.211.182.39 | www.65wt.com |
| 162.211.182.39 | u17766.com |
| 162.211.182.39 | www.600sf.com |
| 162.211.182.39 | 52345.zzflt.com |
| 162.211.182.39 | www.baodaobike.com |
| 162.211.182.39 | 199.hncgfw.com |
| 162.211.182.39 | www.56fabu.com |
| 162.211.182.39 | www.pt12319.com |
| 162.211.182.39 | pk.sydahe.com |
| 162.211.182.39 | cnpeishi.cn |
| 162.211.182.39 | www.2-55.com |
| 162.211.182.39 | sogou.turuyi.com |
| 162.211.182.39 | klmy.cn.com |
| 162.211.182.39 | www.cdfufu.com |
| 162.211.182.39 | www.bzydzs.com |
| 162.211.182.39 | www.dhl.gov.cn |
| 162.211.182.39 | www.81cq.com |
| 162.211.182.39 | www.sxfyxyq.com |
| 162.211.182.39 | 111wt.com |
| 162.211.182.39 | 81sf.com |
| 162.211.182.39 | 44dy.com |
| 162.211.182.39 | 30wy.com |
| 162.211.182.39 | 999wg.net |
| 162.211.182.39 | 915m.com |
| 162.211.182.39 | 66kf.net |
| 162.211.182.39 | www.qs930.com |
| 162.211.182.39 | www.shutu.cc |
| 162.211.182.39 | sf666.75gm.com |
| 162.211.182.39 | www.kkksf.com |
| 162.211.182.39 | www.zhao3f.com |
| 162.211.182.39 | 6cq.cc |
| 162.211.182.39 | u7u73.com |
| 162.211.182.39 | sf923.com |
| 162.211.182.39 | oryin.com |
| 162.211.182.39 | gm777.com |
| 162.211.182.39 | gm333.com |
| 162.211.182.39 | cseht.com |
| 162.211.182.39 | 520f.com |
| 162.211.182.39 | 258x.com |
| 162.211.182.39 | 57ww.com |
| 162.211.182.39 | 57591.com |
| 162.211.182.39 | 33sf.com |
| 162.211.182.39 | sf509.com |
| 162.211.182.39 | 803cq.com |
| 162.211.182.39 | 25930.com |
| 162.211.182.39 | 812315.com |
| 162.211.182.39 | 11cq.cn |
| 162.211.182.39 | 94ww.com |
| 162.211.182.39 | 777wt.com |
| 162.211.182.39 | www.99mc.com |
| 162.211.182.39 | 980cq.com |
| 162.211.182.39 | hdhjgs.com |
| 162.211.182.39 | 51zzsf.com |
| 162.211.182.39 | 0574k.com |
| 162.211.182.39 | wjlon.cn |
| 162.211.182.39 | d518.com |
| 162.211.182.39 | sf29.com |
| 162.211.182.39 | 222sf.com |
| 162.211.182.39 | 23qianbao.com |
| 162.211.182.39 | 195ca.com |
| 162.211.182.39 | 118967.com |
| 162.211.182.39 | 10000ok.com |
| 162.211.182.39 | 72cq.com |
| 162.211.182.39 | 5zaoxie.com |
| 162.211.182.39 | 555beian.com |
| 162.211.182.39 | 55hj.com |
| 162.211.182.39 | 45758.com |
| 162.211.182.39 | 41345.com |
| 162.211.182.39 | 258sf.com |
| 162.211.182.39 | 9000sf.com |
| 162.211.182.39 | 87sf.com |
| 162.211.182.39 | 89946.com |
| 162.211.182.39 | 88f.com |
| 162.211.182.39 | 86rs.com |
| 162.211.182.39 | 77yu.com |
| 162.211.182.39 | 81592.com |
| 162.211.182.39 | 74981.com |
| 162.211.182.39 | 818wy.com |
| 162.211.182.39 | 9826w.com |
| 162.211.182.39 | h7fefe4r.sf19.cn |
| 162.211.182.39 | 45453.sf19.cn |
| 162.211.182.39 | www.myidc.cc |
| 162.211.182.39 | www.whygjt.com |
| 162.211.182.39 | www.nd-zk.com |
| 162.211.182.39 | haosf.com.cn |
| 162.211.182.39 | dtfy.fyplay.com |
| 162.211.182.39 | www.sf3000ok.com |
| 162.211.182.39 | www.145930.com |
| 162.211.182.39 | www.80ww.com |
| 162.211.182.39 | www.258x.com |
| 162.211.182.39 | www.sf509.com |
| 162.211.182.39 | www.tjklm.com |
| 162.211.182.39 | 17sz.net |
| 162.211.182.39 | 1.xa1314.com.cn |
| 162.211.182.39 | www.81sf.com |
| 162.211.182.39 | www.0663yh.com |
| 162.211.182.39 | whygjt.com |
| 162.211.182.39 | www.cc816.com |
| 162.211.182.39 | www.bohaomj.com |
| 162.211.182.39 | www.blbfg.com |
| 162.211.182.39 | jndd.com.cn |
| 162.211.182.39 | www.ba45.com |
| 162.211.182.39 | www.bjwztc.com |
| 162.211.182.39 | www.bangbangtuan.com |
| 162.211.182.39 | 1.wzca.com.cn |
| 162.211.182.39 | www.51yygw.com |
| 162.211.182.39 | www.912kf.com |
| 162.211.182.39 | www.eduqc.com |
| 162.211.182.39 | www.ebssfp.com |
| 162.211.182.39 | www.dingfengtop.com |
| 162.211.182.39 | www.dc-superglue.com |
| 162.211.182.39 | www.daweilp.com |
| 162.211.182.39 | www.czacyq.com |
| 162.211.182.39 | www.cqxiexin.com |
| 162.211.182.39 | www.cltqgs.com |
| 162.211.182.39 | www.cnaxchem.com |
| 162.211.182.39 | www.chengdajc.com |
| 162.211.182.39 | www.cdztnt.com |
| 162.211.182.39 | www.chinawoollen.com |
| 162.211.182.39 | www.chinaenyu.com |
| 162.211.182.39 | www.ihc360.com |
| 162.211.182.39 | www.hrener.com |
| 162.211.182.39 | www.howelltoy.com |
| 162.211.182.39 | www.fzqmw.com |
| 162.211.182.39 | www.hongweimotor.com |
| 162.211.182.39 | www.gardenhn.com |
| 162.211.182.39 | www.fzghj.com |
| 162.211.182.39 | www.fhouse360.com |
| 162.211.182.39 | www.fdzyy.com |
| 162.211.182.39 | www.fujunsh.com |
| 162.211.182.39 | www.funkan.com |
| 162.211.182.39 | www.pxfangbao.com |
| 162.211.182.39 | www.pk138.com |
| 162.211.182.39 | www.oursuzuki.com |
| 162.211.182.39 | www.movfox.com |
| 162.211.182.39 | www.nbyongxiang.com |
| 162.211.182.39 | www.maoshanchem.com |
| 162.211.182.39 | www.longyundianli.com |
| 162.211.182.39 | www.linxiatravel.com |
| 162.211.182.39 | www.jhrace.com |
| 162.211.182.39 | www.jxytoys.com |
| 162.211.182.39 | www.kpaofeite.com |
| 162.211.182.39 | www.jiang456.com |
| 162.211.182.39 | www.szgargen.com |
| 162.211.182.39 | www.szelcc.com |
| 162.211.182.39 | www.sun-sand-sea.com |
| 162.211.182.39 | www.shzhuwang.com |
| 162.211.182.39 | www.ssbrakepad.com |
| 162.211.182.39 | www.shxianghao.com |
| 162.211.182.39 | www.shchenggang.com |
| 162.211.182.39 | www.quhi-tech.com |
| 162.211.182.39 | www.sh16pu.com |
| 162.211.182.39 | www.reach-way.com |
| 162.211.182.39 | www.sddzauto.com |
| 162.211.182.39 | www.yhszy.com |
| 162.211.182.39 | www.xinfengjixie.com |
| 162.211.182.39 | www.xiduanpress.com |
| 162.211.182.39 | www.xuyetrade.com |
| 162.211.182.39 | www.xaxhny.com |
| 162.211.182.39 | www.wzxiyin.com |
| 162.211.182.39 | www.wxlujia.com |
| 162.211.182.39 | www.usnaike.com |
| 162.211.182.39 | www.tyhzh.com |
| 162.211.182.39 | www.szhmxled.com |
| 162.211.182.39 | yaosf.net |
| 162.211.182.39 | www.zjyingguan.com |
| 162.211.182.39 | www.zzwzgn.com |
| 162.211.182.39 | www.zjtsmj.com |
| 162.211.182.39 | www.zjgujia.com |
| 162.211.182.39 | www.30fu.com |
| 162.211.182.39 | www.zgshunxing.com |
| 162.211.182.39 | www.zhcrane.com |
| 162.211.182.39 | www.zhao5f.com |
| 162.211.182.39 | www.ytjiangyou.com |
| 162.211.182.39 | www.yinghongjixie.com |
| 162.211.182.39 | www.zwyt.net |
| 162.211.182.39 | zzhdjx.cn |
| 162.211.182.39 | www.szmhk.com |
| 162.211.182.39 | www.ccggge.com |
| 162.211.182.39 | www.0007590.com |
| 162.211.182.39 | 941qq.com |
| 162.211.182.39 | www4.29u.com |
| 162.211.182.39 | www.nlcoad.com |
| 162.211.182.39 | 26ss.com |
| 162.211.182.39 | zhaohaosf.net |
| 162.211.182.39 | www.eanfang.com |
| 162.211.182.39 | www.ntwmyy.com |
| 162.211.182.39 | eanfang.com |
| 162.211.182.39 | www.88pknb.com |
| 162.211.182.39 | www.hh8gg.pw |
| 162.211.182.39 | www.hycygy.com |
| 162.211.182.39 | 114code.com |
| 162.211.182.39 | www.legendpw.net |
| 162.211.182.39 | www.dgyuanyang.com |
| 162.211.182.39 | www.sf999.name |
| 162.211.182.39 | www.125kkk.com |
| 162.211.182.39 | go.sf999.com |
| 162.211.182.39 | wwww.017cq.com |
| 162.211.182.39 | cnc.sf999.com |
| 162.211.182.39 | www.xztd888.com |
| 162.211.182.39 | www.iyqxkcqw.com |
| 162.211.182.39 | www.fenfa1688.com |
| 162.211.182.39 | www.huahuiye.com |
| 162.211.182.39 | www.sdqinuo.com |
| 162.211.182.39 | www.njhxztz.com |
| 162.211.182.39 | www.qibone.com |
| 162.211.182.39 | www.aimkm.com |
| 162.211.182.39 | www.195eeweqsc.com |
| 162.211.182.39 | www.007sf.com |
| 162.211.182.39 | www.512qz.com |
| 162.211.182.39 | www.jxdpx.com |
| 162.211.182.39 | www.haosf.org |
| 162.211.182.39 | www.17123.com |
| 162.211.182.39 | 999sf.com |
| 162.211.182.39 | www.7000hj.com |
| 162.211.182.39 | 67pp.com |
| 162.211.182.39 | 56chuanqi.com |
| 162.211.182.39 | www.k8765.com |
| 162.211.182.39 | www.haosf9999.com |
| 162.211.182.39 | www.fw000.com |
| 162.211.182.39 | www.gm333.com |
| 162.211.182.39 | www.anmeiexpo.com |
| 162.211.182.39 | www.999sf.com |
| 162.211.182.39 | www.95ok.com |
| 162.211.182.39 | sedio.cc |
| 162.211.182.39 | www.5d5y.com |
| 162.211.182.39 | www.gm777.com |
| 162.211.182.39 | zhaosf.88654.com |
| 162.211.182.39 | www.xifulei.com |
| 162.211.182.39 | www.sf903.com |
| 162.211.182.39 | www.syjm.net |
| 162.211.182.39 | www.sf7000.com |
| 162.211.182.39 | www.nbwanfeng.com |
| 162.211.182.39 | 677g.com |
| 162.211.182.39 | sf63.com |
| 162.211.182.39 | www.91kang.com |
| 162.211.182.39 | cqniangzao.com |
| 162.211.182.39 | www.999ok.com |
| 162.211.182.39 | 92gg.com |
| 162.211.182.39 | 921ww.com |
| 162.211.182.39 | 520sf.com |
| 162.211.182.39 | 239ok.com |
| 162.211.182.39 | tese.29mydi.com |
| 162.211.182.39 | shdongqiao.com |
| 162.211.182.39 | sd-yuhui.com |
| 162.211.182.39 | meiri.vqkp35.com |
| 162.211.182.39 | moni.227y.com |
| 162.211.182.39 | gzonisi.cn |
| 162.211.182.39 | 345cc.cn.com |
| 162.211.182.39 | chinayat.com |
| 162.211.182.39 | www.3f6f.com |
| 162.211.182.39 | www.258sf.com |
| 162.211.182.39 | www.13su.com |
| 162.211.182.39 | www.118967.com |
| 162.211.182.39 | www.sardar.cc |
| 162.211.182.39 | www.21sjzg.com |
| 162.211.182.39 | www.0769hongri.com |
| 162.211.182.39 | www.0574k.com |
| 162.211.182.39 | www.020rencai.net |
| 162.211.182.39 | uc99.com |
| 162.211.182.39 | www.001info.com |
| 162.211.182.39 | www.67pp.net |
| 162.211.182.39 | www.666666s.com |
| 162.211.182.39 | www.66kf.net |
| 162.211.182.39 | www.5zaoxie.com |
| 162.211.182.39 | www.55hj.com |
| 162.211.182.39 | www.520sf.com |
| 162.211.182.39 | www.51miehun.co |
| 162.211.182.39 | www.51huigo.com |
| 162.211.182.39 | www.45758.com |
| 162.211.182.39 | www.5199g.com |
| 162.211.182.39 | www.30wy.com |
| 162.211.182.39 | www.941qq.com |
| 162.211.182.39 | www.922gg.com |
| 162.211.182.39 | www.88f.com |
| 162.211.182.39 | www.88102888.com |
| 162.211.182.39 | www.921ww.com |
| 162.211.182.39 | www.89946.com |
| 162.211.182.39 | www.818wy.com |
| 162.211.182.39 | www.86rs.com |
| 162.211.182.39 | www.789sf.net |
| 162.211.182.39 | www.77yu.com |
| 162.211.182.39 | www.789is.com |
| 162.211.182.39 | www.6836999.com |
| 162.211.182.39 | www.boxianfengguan.com |
| 162.211.182.39 | www.allaboutprogram.com |
| 162.211.182.39 | www.avoio.com |
| 162.211.182.39 | www.autohid.com |
| 162.211.182.39 | www.aptx4869.net |
| 162.211.182.39 | www.art-verb.com |
| 162.211.182.39 | www.94haokan.com |
| 162.211.182.39 | www.dj149.com |
| 162.211.182.39 | www.dgdtw.com |
| 162.211.182.39 | www.digrj.com |
| 162.211.182.39 | www.dgzichi.com |
| 162.211.182.39 | www.cqsfcn.com |
| 162.211.182.39 | www.dfhero.com |
| 162.211.182.39 | www.dabanwu.com |
| 162.211.182.39 | www.chuanqisifu99.com |
| 162.211.182.39 | www.chinakelly.com |
| 162.211.182.39 | www.cfaninfo.com |
| 162.211.182.39 | www.cgxgf.com |
| 162.211.182.39 | www.byetee.com |
| 162.211.182.39 | www.idcdong.com |
| 162.211.182.39 | www.i-blinks.com |
| 162.211.182.39 | www.hnlangjie.com |
| 162.211.182.39 | www.hxfamily.com |
| 162.211.182.39 | www.hzruili.com |
| 162.211.182.39 | www.hnggfz.com |
| 162.211.182.39 | www.hzkjy.com |
| 162.211.182.39 | www.hlmodule.com |
| 162.211.182.39 | www.hbwyw.net |
| 162.211.182.39 | www.hbqdxjmf.com |
| 162.211.182.39 | www.gzxlzs.com |
| 162.211.182.39 | www.gzplay.com |
| 162.211.182.39 | www.gxxjl.com |
| 162.211.182.39 | www.guanhaiyujia.com |
| 162.211.182.39 | www.dqzypx.com |
| 162.211.182.39 | www.krksjx.com |
| 162.211.182.39 | www.lishi99.com |
| 162.211.182.39 | www.leiming-bulb.com |
| 162.211.182.39 | www.lanyue2003.com |
| 162.211.182.39 | www.laosf.com |
| 162.211.182.39 | www.jzfsk.com |
| 162.211.182.39 | www.knschina.com |
| 162.211.182.39 | www.jsxgm.com |
| 162.211.182.39 | www.jshhw.com |
| 162.211.182.39 | www.jka77.com |
| 162.211.182.39 | www.jn333.com |
| 162.211.182.39 | www.j8y.net |
| 162.211.182.39 | www.jieer.net |
| 162.211.182.39 | www.jietewq.com |
| 162.211.182.39 | www.i-dphoto.com |
| 162.211.182.39 | www.pgmary.com |
| 162.211.182.39 | www.pxfyzs.com |
| 162.211.182.39 | www.pai4f.com |
| 162.211.182.39 | www.njrybj.com |
| 162.211.182.39 | www.oshococo.com |
| 162.211.182.39 | www.nibou.net |
| 162.211.182.39 | www.newseaswan.com |
| 162.211.182.39 | www.myuheng.com |
| 162.211.182.39 | www.mzwq.info |
| 162.211.182.39 | www.lypfc.com |
| 162.211.182.39 | www.lzyinfeng.com |
| 162.211.182.39 | www.ly1000.com |
| 162.211.182.39 | www.lvislife.com |
| 162.211.182.39 | www.lx188.com |
| 162.211.182.39 | www.shundaglass.com |
| 162.211.182.39 | www.shyuanli.com |
| 162.211.182.39 | www.sh-liuxin.com |
| 162.211.182.39 | www.shi18.com |
| 162.211.182.39 | www.sf920.net |
| 162.211.182.39 | www.sea-reach.com |
| 162.211.182.39 | www.sertai.com |
| 162.211.182.39 | www.sf123-1.com |
| 162.211.182.39 | www.sf123.cc |
| 162.211.182.39 | www.saiyilong.com |
| 162.211.182.39 | www.scienthoer.com |
| 162.211.182.39 | www.ruichilida.com |
| 162.211.182.39 | www.qunhuan.net |
| 162.211.182.39 | www.qmxfw.com |
| 162.211.182.39 | www.qhsdkj.com |
| 162.211.182.39 | www.twdmly.com |
| 162.211.182.39 | www.szyangcai.com |
| 162.211.182.39 | www.tococi.com |
| 162.211.182.39 | www.tcbl88.com |
| 162.211.182.39 | www.sz-wells.com |
| 162.211.182.39 | www.szpangzhi.com |
| 162.211.182.39 | www.szjundaled.com |
| 162.211.182.39 | www.szcmon.com |
| 162.211.182.39 | www.szjlskj.com |
| 162.211.182.39 | www.szabj.com |
| 162.211.182.39 | www.syzwdj.com |
| 162.211.182.39 | www.syqtdz.com |
| 162.211.182.39 | www.sxhtdl.com |
| 162.211.182.39 | www.sougousf.com |
| 162.211.182.39 | www.zwnoon.com |
| 162.211.182.39 | www.zszhongzhi.com |
| 162.211.182.39 | www.z-sheng.com |
| 162.211.182.39 | www.zpmc-cz.com |
| 162.211.182.39 | www.zjtl.com |
| 162.211.182.39 | www.zjpages.com |
| 162.211.182.39 | www.zdhw-lighting.com |
| 162.211.182.39 | www.youxi119.com |
| 162.211.182.39 | www.ysmtc8.com |
| 162.211.182.39 | www.yongdingfm.com |
| 162.211.182.39 | www.yiqi163.com |
| 162.211.182.39 | www.yingxiangceliangyi.com |
| 162.211.182.39 | www.wjnmyy.com |
| 162.211.182.39 | www.wzcjyy.com |
| 162.211.182.39 | www.wudait.com |
| 162.211.182.39 | www.xhcsolar.com |
| 162.211.182.39 | www.kmnc.net |
| 162.211.182.39 | www2.8845sf.com |
| 162.211.182.39 | 120sf.0755nk.net |
| 162.211.182.39 | www.muhon.com.cn |
| 162.211.182.39 | www1.8845sf.com |
| 162.211.182.39 | 922gg.com |
| 162.211.182.39 | www.yts189.com |
| 162.211.182.39 | www.chakansdfj.com |
| 162.211.182.39 | www.steelrq.com |
| 162.211.182.39 | yindao.jfsm79.com |
| 162.211.182.39 | www.zx0411.com |
| 162.211.182.39 | www.kt516.com |
| 162.211.182.39 | 66sf.69ao.com |
| 162.211.182.39 | www.lt925.com |
| 162.211.182.39 | www.45wj.com |
| 162.211.182.39 | www.tt371.com |
| 162.211.182.39 | www.goule88.com |
| 162.211.182.39 | www.ranwen.cm |
| 162.211.182.39 | www.verosale.com |
| 162.211.182.39 | grambox.com |
| 162.211.182.39 | down.16kbook.com |
| 162.211.182.39 | www.grambox.com |
| 162.211.182.39 | cq.51zzsf.com |
| 162.211.182.39 | www.ka688.com |
| 162.211.182.39 | www.hj010.com |
| 162.211.182.39 | cq.sf19.cn |
| 162.211.182.39 | www.64sf.com |
| 162.211.182.39 | 92045.aaabaa.com |
| 162.211.182.39 | www.921pk.com |
| 162.211.182.39 | 91ww.91fu.com |
| 162.211.182.39 | kt516.com |
| 162.211.182.39 | www.gc771.com |
| 162.211.182.39 | www.su315.com |
| 162.211.182.39 | www.jindepower.com |
| 162.211.182.39 | 88uc.sf19.cn |
| 162.211.182.39 | 99s.69ao.com |
| 162.211.182.39 | www.hrm123.net |
| 162.211.182.39 | www.bjyjy.com |
| 162.211.182.39 | www.uc99.com |
| 162.211.182.39 | wvw.9kf.com |
| 162.211.182.39 | 97sf.com |
| 162.211.182.39 | www.70uc.com |
| 162.211.182.39 | www.zhaoqiqi.com |
| 162.211.182.39 | www.hnrbysc.com |
| 162.211.182.39 | www.69ao.com |
| 162.211.182.39 | 32feef.11cq.cn |
| 162.211.182.39 | 176.01kp.com |
| 162.211.182.39 | www.kuj8.com |
| 162.211.182.39 | 81f.27-88.com |
| 162.211.182.39 | www.917se.com |
| 162.211.182.39 | www.fabumir.com |
| 162.211.182.39 | www.uc007.com |
| 162.211.182.39 | www.sf999.com.de |
| 162.211.182.39 | www.zhaosf.co |
| 162.211.182.39 | haosf12345.gm127.com |
| 162.211.182.39 | zhaosf.co |
| 162.211.182.39 | 66sf.com |
| 162.211.182.39 | www.chuanqisf.com |
| 162.211.182.39 | zhuzaigua.com |
| 162.211.182.39 | www.1pk.com |
| 162.211.182.39 | 28uc.com |
| 162.211.182.39 | www.005sf.jqjlhw.com |
| 162.211.182.39 | chenmo.cc |
| 162.211.182.39 | www.sf22.com |
| 162.211.182.39 | www.sf405.com |
| 162.211.182.39 | www.cz45.com |
| 162.211.182.39 | 115cq.com |
| 162.211.182.39 | www.803cq.com |
| 162.211.182.39 | www.25930.com |
| 162.211.182.39 | 123f.com |
| 162.211.182.39 | hongxuda.com |
| 162.211.182.39 | haocqsf.com |
| 162.211.182.39 | www.100rcw.com |
| 162.211.182.39 | www.10000ok.com |
| 162.211.182.39 | www.05uc.com |
| 162.211.182.39 | www.23qianbao.com |
| 162.211.182.39 | www.222sf.com |
| 162.211.182.39 | www.72cq.com |
| 162.211.182.39 | www.ahmcks.com |
| 162.211.182.39 | www.90zzs.com |
| 162.211.182.39 | www.csqnw.com |
| 162.211.182.39 | www.dlz888.com |
| 162.211.182.39 | www.jx789.com |
| 162.211.182.39 | www.jsywg.com |
| 162.211.182.39 | www.tccyg.com |
| 162.211.182.39 | www.wcfm103.com |
| 162.211.182.39 | www.wjdhfz.com |
| 162.211.182.39 | www.zzz7.net |
| 162.211.182.39 | www.m3088tv.com |
| 162.211.182.39 | www.cxhdl.com |
| 162.211.182.39 | www.szbiaoyu.com |
| 162.211.182.39 | www.gzpioneer.com |
| 162.211.182.39 | www.mi-sc.com |
| 162.211.182.39 | www.hosisoft.com |
| 162.211.182.39 | www.huakangpc.com |
| 162.211.182.39 | www.zjkylsk.com |
| 162.211.182.39 | www.casscno.com |
| 162.211.182.39 | www.0808sf.com |
| 162.211.182.39 | www.jinhuachang.com |
| 162.211.182.39 | www.dongya888.com |
| 162.211.182.39 | www.fhxzd.com |
| 162.211.182.39 | www.sgwjg.com |
| 162.211.182.39 | www.pntfrc.com |
| 162.211.182.39 | www.sf9.cn |
| 162.211.182.39 | www.8009178.com |
| 162.211.182.39 | www.lxsqrfms.com |
| 162.211.182.39 | www.ygpkndz.com |
| 162.211.182.39 | www.jrxktdy.com |
| 162.211.182.39 | www.1007movie.net |
| 162.211.182.39 | www.sdkjfjgf.com |
| 162.211.182.39 | 30.9youwang.com |
| 162.211.182.39 | 51huigo.com |
| 162.211.182.39 | 51sf.com |
| 162.211.182.39 | 520cq.com |
| 162.211.182.39 | 520cq.net |
| 162.211.182.39 | 765wg.com |
| 162.211.182.39 | 789is.com |
| 162.211.182.39 | www.23vo.com |
| 162.211.182.39 | 8aa.com |
| 162.211.182.39 | 91545.com |
| 162.211.182.39 | 941lt.com |
| 162.211.182.39 | 99245.com |
| 162.211.182.39 | 95sf.com |
| 162.211.182.39 | 99ting.cn |
| 162.211.182.39 | 99ting.com |
| 162.211.182.39 | aaa.xz667.com |
| 162.211.182.39 | ac198.com |
| 162.211.182.39 | aa.606wz.com |
| 162.211.182.39 | bbs.1x.la |
| 162.211.182.39 | dbconsys.com |
| 162.211.182.39 | gaosf.com |
| 162.211.182.39 | gg.herom2.net |
| 162.211.182.39 | hao-sf-123.com |
| 162.211.182.39 | haosf.org |
| 162.211.182.39 | hao119.com |
| 162.211.182.39 | laosf.com |
| 162.211.182.39 | search.sf999.com |
| 162.211.182.39 | sf3000.com |
| 162.211.182.39 | sf86.com |
| 162.211.182.39 | sf99.com |
| 162.211.182.39 | sf999.net |
| 162.211.182.39 | sfsf.d518.com |
| 162.211.182.39 | shenqi.com |
| 162.211.182.39 | www.fzrhcopper.com |
| 162.211.182.39 | ww.s1904.com |
| 162.211.182.39 | www.008fy.com |
| 162.211.182.39 | www.022hs.com |
| 162.211.182.39 | www.123qf.com |
| 162.211.182.39 | www.13xp.com |
| 162.211.182.39 | www.163fb.com |
| 162.211.182.39 | www.450sf.com |
| 162.211.182.39 | 23vo.com |
| 162.211.182.39 | www.184pk.com |
| 162.211.182.39 | www.1x.la |
| 162.211.182.39 | www.23bb.net |
| 162.211.182.39 | www.28uc.com |
| 162.211.182.39 | www.33sf.com |
| 162.211.182.39 | 450sf.com |
| 162.211.182.39 | www.55ip.com |
| 162.211.182.39 | www.58751.com |
| 162.211.182.39 | www.6090sf.com |
| 162.211.182.39 | www.67pp.com |
| 162.211.182.39 | www.77145.com |
| 162.211.182.39 | www.707wz.com |
| 162.211.182.39 | www.7pv.net |
| 162.211.182.39 | www.78x8.com |
| 162.211.182.39 | www.810f.com |
| 162.211.182.39 | www.8u8uu.com |
| 162.211.182.39 | www.915m.com |
| 162.211.182.39 | www.941cq.com |
| 162.211.182.39 | www.96cs.com |
| 162.211.182.39 | www.92gg.com |
| 162.211.182.39 | www.99245.com |
| 162.211.182.39 | www.sfniu.com |
| 162.211.182.39 | www.sihai-musical.com |
| 162.211.182.39 | www.cq588.com |
| 162.211.182.39 | 91084.com |
| 162.211.182.39 | www.dobgame.com |
| 162.211.182.39 | www.fireol.com |
| 162.211.182.39 | www.fei24.com |
| 162.211.182.39 | www.game-114.com |
| 162.211.182.39 | www.gaosf.com |
| 162.211.182.39 | www.gmhaosf.com |
| 162.211.182.39 | www.hao3a.com |
| 162.211.182.39 | www.haosf.bz |
| 162.211.182.39 | www.htdqsec.com |
| 162.211.182.39 | www.hzhswj.com |
| 162.211.182.39 | www.pk920.com |
| 162.211.182.39 | www.liwoma.com |
| 162.211.182.39 | 7000uc.com |
| 162.211.182.39 | www.nwpbl.com |
| 162.211.182.39 | www.ok3000.com |
| 162.211.182.39 | www.23c.com |
| 162.211.182.39 | www.pk555.com |
| 162.211.182.39 | www.pk920.com |
| 162.211.182.39 | www.rbtvs.com |
| 162.211.182.39 | www.91084.com |
| 162.211.182.39 | www.sdzblj.com |
| 162.211.182.39 | www.sf121.com |
| 162.211.182.39 | www.sebxa.com |
| 162.211.182.39 | www.sf3000.com |
| 162.211.182.39 | www.sf86.com |
| 162.211.182.39 | www.sf999.net |
| 162.211.182.39 | www.shuo321.com |
| 162.211.182.39 | www.shuiguanyin.com |
| 162.211.182.39 | www.sxzkzx.com |
| 162.211.182.39 | www.uc88.com |
| 162.211.182.39 | www.weihuangsz.com |
| 162.211.182.39 | www.weizhixs.com |
| 162.211.182.39 | www.wodewww.com |
| 162.211.182.39 | www.wsf520.com |
| 162.211.182.39 | 23c.com |
| 162.211.182.39 | www.xcwsg.com |
| 162.211.182.39 | www.xjlgc.com |
| 162.211.182.39 | www.zhuzaicq.com |
| 162.211.182.39 | www1.uc88.com |
| 162.211.182.39 | www2.520cq.com |
| 162.211.182.39 | www5.29u.com |
| 162.211.182.39 | www4.520cq.com |
| 162.211.182.39 | www5.520cq.com |
| 162.211.182.39 | 3000ko.com |
| 162.211.182.39 | www.sdjnxy.com |
| 162.211.182.39 | sf999.com |
| 162.211.182.39 | www.51okf.com |
| 162.211.182.39 | www.iiwoool.com |
| 162.211.182.39 | www.rxshige.com |
| 162.211.182.39 | www.dghke.com |
| 162.211.182.39 | www.7kkb.net |
| 162.211.182.39 | www.789518.com |
| 162.211.182.39 | www.cqfff.com |
| 162.211.182.39 | wewer.sf19.cn |
| 162.211.182.39 | www4.beer51.com |
| 162.211.182.39 | www.cseht.com |
| 162.211.182.39 | www.82926.com |
| 162.211.182.39 | 8uc.558uc.com |
| 162.211.182.39 | www.99cangzhou.com |
| 162.211.182.39 | www.pjzbw.com |
| 162.211.182.39 | who.hnrxyy.net |
| 162.211.182.39 | t.fiying.net |
| 162.211.182.39 | abc.jlhlbj.com |
| 162.211.182.39 | abc.njhabo.com |
| 162.211.182.39 | www.52375.com |
| 162.211.182.39 | pkpk.8musix.net |
| 162.211.182.39 | www.xdhmotor.com |
| 162.211.182.39 | www.shmeigu168.com |
| 162.211.182.39 | www.comvod.com |
| 162.211.182.39 | www.gz-sc.com |
| 162.211.182.39 | daded.sf19.cn |
| 162.211.182.39 | www.stylepacking.com |
| 162.211.182.39 | www.hnfdczj.com |
| 162.211.182.39 | www.wfxycc.com |
| 162.211.182.39 | www.26ss.com |
| 162.211.182.39 | www.hezhihui.com |
| 162.211.182.39 | www.wuxihuaxia.com |
| 162.211.182.39 | www.nblongyi.com |
| 162.211.182.39 | www.7zcq.com |
| 162.211.182.39 | 7ugg.com |
| 162.211.182.39 | www.dliuren.com |
| 162.211.182.39 | www.wmult.com |
| 162.211.182.39 | www.3159wine.com |
| 162.211.182.39 | www.sf5137.com |
| 162.211.182.39 | www.cxxcqp.com |
| 162.211.182.39 | www.qz92.com |
| 162.211.182.39 | 66.5173sf.com |
| 162.211.182.39 | www.stronger-filter.com |
| 162.211.182.39 | www1.65cf.com |
| 162.211.182.39 | i8pk.com |
| 162.211.182.39 | 88kf.aaabaa.com |
| 162.211.182.39 | 123.3csm123.com |
| 162.211.182.39 | www.trnly.com |
| 162.211.182.39 | juc.zh9sky.com |
| 162.211.182.39 | star.gamtsr.com |
| 162.211.182.39 | 111.czagl.com |
| 162.211.182.39 | 926.deepbj.net |
| 162.211.182.39 | host.ad0739.com |
| 162.211.182.39 | sea.okpro.net |
| 162.211.182.39 | www.zhaokj.com |
| 162.211.182.39 | www.yaojuezhan.com |
| 162.211.182.39 | www.tt2sf.com |
| 162.211.182.39 | www.qupaike.com |
| 162.211.182.39 | www.luowenqi.com |
| 162.211.182.39 | qqfcwgw.com |
| 162.211.182.39 | www.taosf.com.ru |
| 162.211.182.39 | www.zj-xd.com |
| 162.211.182.39 | www.mgszyc.com |
| 162.211.182.39 | sf97.dgpxoa.com |
| 162.211.182.39 | 9pk.dgjt.net |
| 162.211.182.39 | www.2umm.com |
| 162.211.182.39 | www.yxyhx.com |
| 162.211.182.39 | cq.cq890.com |
| 162.211.182.39 | 53uc.hysdwj.com |
| 162.211.182.39 | 999.niu999.com |
| 162.211.182.39 | zhaokf.com |
| 162.211.182.39 | www.sf010.com |
| 162.211.182.39 | 123.cqsf45.com |
| 162.211.182.39 | www.sfdawang.com |
| 162.211.182.39 | www.17fg.com |
| 162.211.182.39 | 1.wzca.com.cn |
| 162.211.182.39 | com.xm580.com |
| 162.211.182.39 | abc.top258.cn |
| 162.211.182.39 | www.gm7.cc |
| 162.211.182.39 | 9kf.rzsport.com |
| 162.211.182.39 | ss.sg368.com |
| 162.211.182.39 | www.yy-bags.com |
| 162.211.182.39 | video.shunlo.com |
| 162.211.182.39 | www.45yes.com |
| 162.211.182.39 | www.cnyongli.com |
| 162.211.182.39 | www.sf03.com |
| 162.211.182.39 | 223u.39010.com |
| 162.211.182.39 | bjkl.zha0sf.net |
| 162.211.182.39 | www.88kf.net |
| 162.211.182.39 | www.88kf.com |
| 162.211.182.39 | www.sf168.com |
| 162.211.182.39 | 555sf.com |
| 162.211.182.39 | www.ourbep.com |
| 162.211.182.39 | www.manmank.com |
| 162.211.182.39 | sebxa.com |
| 162.211.182.39 | hchxh.com |
| 162.211.182.39 | z34.sf19.cn |
| 162.211.182.39 | fswe233.11cq.cn |
| 162.211.182.39 | efms.115cq.com |
| 162.211.182.39 | xks22.sf19.cn |
| 162.211.182.39 | 456.wtbqsy.com |
| 162.211.182.39 | 8uc.27-88.com |
| 162.211.182.39 | www.mobilefad.com |
| 162.211.182.39 | www.sf22-2.com |
| 162.211.182.39 | www.tlsfwz.com |
| 162.211.182.39 | www.westmm.com |
| 162.211.182.39 | baidu.qss365.com |
| 162.211.182.39 | 7080st.com |
| 162.211.182.39 | qaa.xsjej.com |
| 162.211.182.39 | www.sf322.com |
| 162.211.182.39 | www.zyjms.com |
| 162.211.182.39 | yy.7080st.com |
| 162.211.182.39 | jcniao.com |
| 162.211.182.39 | letanju.com |
| 162.211.182.39 | soso.8kst.com |
| 162.211.182.39 | www.taleclub.com |
| 162.211.182.39 | 005sf.njtx168.com |
| 162.211.182.39 | 008cqsf.ccdhr.com |
| 162.211.182.39 | 008cqsf.com |
| 162.211.182.39 | 112sf.com |
| 162.211.182.39 | 114.75sf.cn |
| 162.211.182.39 | 1233.xizi30.com |
| 162.211.182.39 | 1234.57591.com |
| 162.211.182.39 | 123sf.com |
| 162.211.182.39 | 138bt.com |
| 162.211.182.39 | 138sf.com |
| 162.211.182.39 | 139.limulu.com |
| 162.211.182.39 | 163.fuatw.com |
| 162.211.182.39 | 168.w198.net |
| 162.211.182.39 | 168.zh-db.com |
| 162.211.182.39 | 178bifen.com |
| 162.211.182.39 | 17fg.com |
| 162.211.182.39 | 233sf.138sf.com |
| 162.211.182.39 | 23c.com |
| 162.211.182.39 | 23ok.com |
| 162.211.182.39 | 258.57591.com |
| 162.211.182.39 | 28yes.com |
| 162.211.182.39 | 29u.com |
| 162.211.182.39 | 500sf.com |
| 162.211.182.39 | 513ux.com |
| 162.211.182.39 | 515.zh-db.com |
| 162.211.182.39 | 51xunt.com |
| 162.211.182.39 | 520.szgumi.com |
| 162.211.182.39 | 52345.com |
| 162.211.182.39 | 523sf.com |
| 162.211.182.39 | 523u.com |
| 162.211.182.39 | 55z5.com |
| 162.211.182.39 | 666sf.com |
| 162.211.182.39 | 66cq.com |
| 162.211.182.39 | 73sf.com |
| 162.211.182.39 | 777gm.com |
| 162.211.182.39 | 7uc.com |
| 162.211.182.39 | 81f.77du.com |
| 162.211.182.39 | 81f.com |
| 162.211.182.39 | 81fu.com |
| 162.211.182.39 | 863.zh-db.com |
| 162.211.182.39 | 876sf.45195.com |
| 162.211.182.39 | 88.520axn.com |
| 162.211.182.39 | 8845.aaabaa.com |
| 162.211.182.39 | 8845.com |
| 162.211.182.39 | 8845.kt888.com |
| 162.211.182.39 | 8845.ugame123.com |
| 162.211.182.39 | 888.5index.net |
| 162.211.182.39 | 888.79yj.com |
| 162.211.182.39 | 888.manrenjian.com |
| 162.211.182.39 | 888.qu69.com |
| 162.211.182.39 | 88858.com |
| 162.211.182.39 | 88858.sz5161.net |
| 162.211.182.39 | 8uc.01744.com |
| 162.211.182.39 | 8uc.31450.com |
| 162.211.182.39 | 8uc.82506.com |
| 162.211.182.39 | 8uc.aaabaa.com |
| 162.211.182.39 | 8uc.ccdhr.com |
| 162.211.182.39 | 8uc.hiszx.com |
| 162.211.182.39 | www.qizhu.cc |
| 162.211.182.39 | 8uu.aaabaa.com |
| 162.211.182.39 | www.as9z.com |
| 162.211.182.39 | 8uu.com |
| 162.211.182.39 | 91.haosf123.com |
| 162.211.182.39 | 91wuc.com |
| 162.211.182.39 | 91ww.123uu.com |
| 162.211.182.39 | 91ww.aaabaa.com |
| 162.211.182.39 | 91ww.com |
| 162.211.182.39 | 91ww.ugame123.com |
| 162.211.182.39 | 92045.com |
| 162.211.182.39 | 920sf.com |
| 162.211.182.39 | 926.com |
| 162.211.182.39 | 92fu.com |
| 162.211.182.39 | 999hj.com |
| 162.211.182.39 | 99j.com |
| 162.211.182.39 | 9kf.com |
| 162.211.182.39 | 9pk.k197.com |
| 162.211.182.39 | 9pk.u7u73.com |
| 162.211.182.39 | ad.97uu.com |
| 162.211.182.39 | haocq.com |
| 162.211.182.39 | pk123.com |
| 162.211.182.39 | plinm.com |
| 162.211.182.39 | qiqi530.com |
| 162.211.182.39 | qq.007uc.com |
| 162.211.182.39 | sf138.com |
| 162.211.182.39 | sf168.com |
| 162.211.182.39 | sf176.com |
| 162.211.182.39 | sf215.com |
| 162.211.182.39 | sf222.com |
| 162.211.182.39 | sf30.com |
| 162.211.182.39 | sf777.com |
| 162.211.182.39 | www.xhnano.com |
| 162.211.182.39 | sogou.1000ok.com |
| 162.211.182.39 | ww.1388fu.com |
| 162.211.182.39 | www.005sf.com |
| 162.211.182.39 | www.008n.com |
| 162.211.182.39 | www.015999.com |
| 162.211.182.39 | www.023cz.com |
| 162.211.182.39 | www.023toilet.com |
| 162.211.182.39 | www.027fruit.com |
| 162.211.182.39 | www.0313hybj.com |
| 162.211.182.39 | www.0532oa.com |
| 162.211.182.39 | www.055735.com |
| 162.211.182.39 | www.07186.com |
| 162.211.182.39 | www.1000gsf.com |
| 162.211.182.39 | www.112sf.com |
| 162.211.182.39 | www.114haosf.com |
| 162.211.182.39 | www.115cq.com |
| 162.211.182.39 | www.11811445.com |
| 162.211.182.39 | www.11cq.cn |
| 162.211.182.39 | www.120sf.com |
| 162.211.182.39 | www.123cq.com |
| 162.211.182.39 | www.123f.com |
| 162.211.182.39 | www.123hj.com |
| 162.211.182.39 | www.123sf.com |
| 162.211.182.39 | www.123uu.com |
| 162.211.182.39 | www.130136.com |
| 162.211.182.39 | www.134sf.com |
| 162.211.182.39 | www.138bt.com |
| 162.211.182.39 | www.145sf.com |
| 162.211.182.39 | www.15ss.com |
| 162.211.182.39 | www.16753.com |
| 162.211.182.39 | www.17fabu8.com |
| 162.211.182.39 | www.215pk.com |
| 162.211.182.39 | www.22j.com |
| 162.211.182.39 | www.234sfww.com |
| 162.211.182.39 | www.23c.com |
| 162.211.182.39 | www.23fu.com |
| 162.211.182.39 | www.23ok.com |
| 162.211.182.39 | www.23sfu.cn |
| 162.211.182.39 | www.27sf.com |
| 162.211.182.39 | www.28yes.com |
| 162.211.182.39 | www.29u.com |
| 162.211.182.39 | www.3000ok.cc |
| 162.211.182.39 | www.3000pk.com |
| 162.211.182.39 | www.31cqsf.com |
| 162.211.182.39 | www.31i.cn |
| 162.211.182.39 | www.3300sf.com |
| 162.211.182.39 | www.33345.com |
| 162.211.182.39 | www.333ok.com |
| 162.211.182.39 | www.33pk.com |
| 162.211.182.39 | www.33wt.com |
| 162.211.182.39 | www.361cq.com |
| 162.211.182.39 | www.365taoba.com |
| 162.211.182.39 | www.371cyw.com |
| 162.211.182.39 | www.37ok.com |
| 162.211.182.39 | www.3dmeibang.com |
| 162.211.182.39 | www.3qsf.com |
| 162.211.182.39 | www.418sf.in |
| 162.211.182.39 | www.425sf.com |
| 162.211.182.39 | www.44dy.com |
| 162.211.182.39 | www.45195.com |
| 162.211.182.39 | www.34ok.com |
| 162.211.182.39 | www.8cq.cc |
| 162.211.182.39 | www.45bang.com |
| 162.211.182.39 | 34ok.com |
| 162.211.182.39 | www.45hs.com |
| 162.211.182.39 | www.4nic-dy.com |
| 162.211.182.39 | www.500sf.com |
| 162.211.182.39 | www.51sf.com |
| 162.211.182.39 | www.52058.com |
| 162.211.182.39 | www.520cq.com |
| 162.211.182.39 | www.520jy.com |
| 162.211.182.39 | pg.iflu.com.cn |
| 162.211.182.39 | zhaosf.hsdbm.com |
| 162.211.182.39 | dd.guidawang.com |
| 162.211.182.39 | www.523sf.com |
| 162.211.182.39 | www.523u.com |
| 162.211.182.39 | www.531U.com |
| 162.211.182.39 | www.533ok.com |
| 162.211.182.39 | www.53sf.com |
| 162.211.182.39 | www.53uc.com |
| 162.211.182.39 | www.53w.com.cn |
| 162.211.182.39 | www.54ss.net |
| 162.211.182.39 | www.pk920.com |
| 162.211.182.39 | www.55z5.com |
| 162.211.182.39 | www.565sf.com |
| 162.211.182.39 | www.56ss.com |
| 162.211.182.39 | cdchuanghui.com |
| 162.211.182.39 | www.57591.com |
| 162.211.182.39 | www.57f.com |
| 162.211.182.39 | www.57fg.com |
| 162.211.182.39 | www.57ww.com |
| 162.211.182.39 | www.5800sf.com |
| 162.211.182.39 | www.58sf.com |
| 162.211.182.39 | www.58uc.com |
| 162.211.182.39 | www.5index.net |
| 162.211.182.39 | www.5qu.com |
| 162.211.182.39 | www.64pk.com |
| 162.211.182.39 | www.6645.com |
| 162.211.182.39 | www.666sf.com |
| 162.211.182.39 | www.676711.com |
| 162.211.182.39 | www.677g.com |
| 162.211.182.39 | www.67m2.com |
| 162.211.182.39 | www.686f.com |
| 162.211.182.39 | www.697sf.com |
| 162.211.182.39 | www.6cq.cc |
| 162.211.182.39 | www.73sf.com |
| 162.211.182.39 | www.75sf.cn |
| 162.211.182.39 | www.777gm.com |
| 162.211.182.39 | www.77d8.com |
| 162.211.182.39 | www.77kl.com |
| 162.211.182.39 | www.79j.com |
| 162.211.182.39 | www.7j773.com |
| 162.211.182.39 | www.7uc.com |
| 162.211.182.39 | www.80845.com |
| 162.211.182.39 | www.812315.com |
| 162.211.182.39 | www.81267.com |
| 162.211.182.39 | www.81fu.com |
| 162.211.182.39 | www.823f.com |
| 162.211.182.39 | www.82506.com |
| 162.211.182.39 | www.860572.com |
| 162.211.182.39 | www.860580.com |
| 162.211.182.39 | www.87sf.com |
| 162.211.182.39 | www.8845.com |
| 162.211.182.39 | www.88845.com |
| 162.211.182.39 | www.88858.com |
| 162.211.182.39 | www.89176.com |
| 162.211.182.39 | www.8aa.com |
| 162.211.182.39 | www.8uc.com |
| 162.211.182.39 | www.900hj.com |
| 162.211.182.39 | www.909f.com |
| 162.211.182.39 | www.9100sf.com |
| 162.211.182.39 | www.915301.com |
| 162.211.182.39 | www.91545.com |
| 162.211.182.39 | www.91ff.com |
| 162.211.182.39 | www.91wuc.com |
| 162.211.182.39 | www.920666.com |
| 162.211.182.39 | www.920gg.com |
| 162.211.182.39 | www.920sf.com |
| 162.211.182.39 | www.923u.com |
| 162.211.182.39 | www.92fu.com |
| 162.211.182.39 | www.92ww.com |
| 162.211.182.39 | www.93sf.com |
| 162.211.182.39 | www.94432.com |
| 162.211.182.39 | www.95sf.com |
| 162.211.182.39 | www.96645.com |
| 162.211.182.39 | www.9800sf.com |
| 162.211.182.39 | www.980cq.com |
| 162.211.182.39 | www.99964.com |
| 162.211.182.39 | www.999hj.com |
| 162.211.182.39 | www.999wg.net |
| 162.211.182.39 | www.99a.com |
| 162.211.182.39 | www.99ji.com |
| 162.211.182.39 | www.99pk.com |
| 162.211.182.39 | www.apbfhl.com |
| 162.211.182.39 | www.aifugu.com |
| 162.211.182.39 | www.33pk.com |
| 162.211.182.39 | 33pk.com |
| 162.211.182.39 | www.bjhdshengda.com |
| 162.211.182.39 | www.bjtdyz.com |
| 162.211.182.39 | www.bsfzjx.com |
| 162.211.182.39 | www.bsrcsc.com |
| 162.211.182.39 | www.cnycta.com |
| 162.211.182.39 | www.cq45.com |
| 162.211.182.39 | www.cq91530.com |
| 162.211.182.39 | www.cqy6.com |
| 162.211.182.39 | www.csrxj.com |
| 162.211.182.39 | www.cy4f.com |
| 162.211.182.39 | www.fy371.com |
| 162.211.182.39 | www.gm888.com |
| 162.211.182.39 | www.gxxgy.com |
| 162.211.182.39 | www.gzxing.com |
| 162.211.182.39 | www.heli-cn.com |
| 162.211.182.39 | www.hnyuhai.com |
| 162.211.182.39 | www.hstztc.com |
| 162.211.182.39 | www.hwhaosf.com |
| 162.211.182.39 | www.7000uc.com |
| 162.211.182.39 | www.ksd777.com |
| 162.211.182.39 | www.laisf.com |
| 162.211.182.39 | www.laohaosf.com |
| 162.211.182.39 | www.lovewg.com |
| 162.211.182.39 | www.luckysz.com |
| 162.211.182.39 | www.mai101.com |
| 162.211.182.39 | www.mikating.com |
| 162.211.182.39 | www.mtv110.com |
| 162.211.182.39 | www.nj-row.com |
| 162.211.182.39 | www.nybxm.com |
| 162.211.182.39 | www.ocerlight.com |
| 162.211.182.39 | www.oksf.net |
| 162.211.182.39 | www.pk123.com |
| 162.211.182.39 | www.plinm.com |
| 162.211.182.39 | www.qiqi530.com |
| 162.211.182.39 | www.qzrt.com |
| 162.211.182.39 | www.recairen.com |
| 162.211.182.39 | www.rexuesf.in |
| 162.211.182.39 | www.sf0058.com |
| 162.211.182.39 | www.sf1003.com |
| 162.211.182.39 | www.sf17.com |
| 162.211.182.39 | www.sf176.com |
| 162.211.182.39 | www.sf215.com |
| 162.211.182.39 | www.sf222.com |
| 162.211.182.39 | www.sf231.com |
| 162.211.182.39 | www.sf29.com |
| 162.211.182.39 | www.sf30.com |
| 162.211.182.39 | www.sf520.com.cn |
| 162.211.182.39 | www.sf555.com |
| 162.211.182.39 | www.sf5858.com |
| 162.211.182.39 | www.sf63.com |
| 162.211.182.39 | www.sf777.com |
| 162.211.182.39 | www.sf8500.com |
| 162.211.182.39 | www.sf92045.com |
| 162.211.182.39 | www.sf930.com |
| 162.211.182.39 | www.sf99.com |
| 162.211.182.39 | www.shaibar.com |
| 162.211.182.39 | www.shamandi.com |
| 162.211.182.39 | www.ksjxyy.com |
| 162.211.182.39 | www.sktpcbic.com |
| 162.211.182.39 | www.stkj66.com |
| 162.211.182.39 | www.tj-aote.com |
| 162.211.182.39 | www.haosf999.com |
| 162.211.182.39 | www.wan45.com |
| 162.211.182.39 | www.whjdwxw.com |
| 162.211.182.39 | www.whlinuo.com |
| 162.211.182.39 | www.worldkcc.com |
| 162.211.182.39 | www.wtcqsf.com |
| 162.211.182.39 | www.xiaomeisf.com |
| 162.211.182.39 | www.xihaihotel.com |
| 162.211.182.39 | www.xindudu.com |
| 162.211.182.39 | www.xinganchem.com |
| 162.211.182.39 | www.ovytgnby.com |
| 162.211.182.39 | www.xinsf.com |
| 162.211.182.39 | www.yeschongcao.com |
| 162.211.182.39 | www.ynyeer.com |
| 162.211.182.39 | www.ysguandao.com |
| 162.211.182.39 | www.yxzhidao.com |
| 162.211.182.39 | www.zhaochenmo.com |
| 162.211.182.39 | www.zhaofg.com |
| 162.211.182.39 | www.zhaohaosf.net |
| 162.211.182.39 | www.zhaokf.com |
| 162.211.182.39 | www.zhaosf88.com |
| 162.211.182.39 | www.zhaoss.com |
| 162.211.182.39 | www1.pk123.com |
| 162.211.182.39 | www10.138sf.com |
| 162.211.182.39 | xiaomeisf.com |
| 162.211.182.39 | xinsf.com |
| 162.211.182.39 | www.500ok.com |
| 162.211.182.39 | www.wancm.com |
| 162.211.182.39 | jjj.la |
| 162.211.182.39 | zhaochenmo.com |
| 162.211.182.39 | zuhukang.com |
| 162.211.182.39 | www.shangkequ.com |
| 162.211.182.39 | www.9527cqsf.com |
| 162.211.182.39 | www.tjtuliao.com |
| 162.211.182.39 | www.szplas.com |
| 162.211.182.39 | www.hlxyx.com |
| 162.211.182.39 | www.012sf.com |
| 162.211.182.39 | www.zhaosf.cc |
| 162.211.182.39 | www.07sf.com |
| 162.211.182.39 | www.duoduosf.com |
| 162.211.182.39 | www.sf66666.com |
| 162.211.182.39 | www.my7su.com |
| 162.211.182.39 | www.725sf.com |
| 162.211.182.39 | 725sf.com |
| 162.211.182.39 | www.96sf.com |
| 162.211.182.39 | www.pk196.com |
| 162.211.182.39 | www.letanju.com |
| 162.211.182.39 | 50ss.com |
| 162.211.182.39 | www.50ss.com |
| 162.211.182.39 | sfdawang.com |
| 162.211.182.39 | taocq.com |
| 162.211.182.39 | www.73uu.com |
| 162.211.182.39 | www.taocq.com |
| 162.211.182.39 | www.30uc.com |
| 162.211.182.39 | www.nz999.net |
| 162.211.182.39 | www.ww45.com |
| 162.211.182.39 | www.xt-dz.com |
| 162.211.182.39 | www.pk99.com |
| 162.211.182.39 | www.1e2w.cn |
| 162.211.182.39 | 8845.678uc.com |
| 162.211.182.39 | cq.3q33.com |
| 162.211.182.39 | www.baojingqi.net |
| 162.211.182.39 | www.didihc.com |
| 162.211.182.39 | www.bangnijie.com |
| 162.211.182.39 | www.chenmo.cc |
| 162.211.182.39 | www.sina35.com |
| 162.211.182.39 | www.175sf.com |
| 162.211.182.39 | sf123.cc |
| 162.211.182.39 | www.shfiro.com |
| 162.211.182.39 | bjyocy.com |
| 162.211.182.39 | www.pochanlawyer.com |
| 162.211.182.39 | www.138sf.cc |
| 162.211.182.39 | 24cq.a0353.com |
| 162.211.182.39 | www.24cq.com |
| 162.211.182.39 | 99pk.com |
| 162.211.182.39 | www.22cq.com |
| 162.211.182.39 | www.888ww.com |
| 162.211.182.39 | www.2sifu.com |
| 162.211.182.39 | wvw-9kf.com |
| 162.211.182.39 | wvw.uc99.com |
| 162.211.182.39 | 123.uc99.com |
| 162.211.182.39 | 999ok.com |
| 162.211.182.39 | www.komophoto.com |
| 162.211.182.39 | tg.23u.cm |
| 162.211.182.39 | www.sf99.cc |
| 162.211.182.39 | www.80sf.com |
| 162.211.182.39 | www.33221.com |
| 162.211.182.39 | www.pk9090.com |
| 162.211.182.39 | pk9090.com |
| 162.211.182.39 | www2.uc88.com |
| 162.211.182.39 | www3.uc88.com |
| 162.211.182.39 | www4.uc88.com |
| 162.211.182.39 | 88845.com |
| 162.211.182.39 | 88845e.baba1q.com |
| 162.211.182.39 | www.sf9.com |
| 162.211.182.39 | www.700sf.com |
| 162.211.182.39 | 920gg.com |
| 162.211.182.39 | www.23c.com |
| 162.211.182.39 | www.021sx.com |
| 162.211.182.39 | www.sf78.com |
| 162.211.182.39 | www.qjfang.cn |
| 162.211.182.39 | 23c.com |
| 162.211.182.39 | www.yaofg.com |
| 162.211.182.39 | www.07ket.com |
| 162.211.182.39 | www.17hhg.com |
| 162.211.182.39 | www.46cq.com |
| 162.211.182.39 | www.wan345.com |
| 162.211.182.39 | www.htlq.com |
| 162.211.182.39 | www.nbkst.com |
| 162.211.182.39 | www.meishipai.com |
| 162.211.182.39 | www.987pk.com |
| 162.211.182.39 | www.weisf.com |
| 162.211.182.39 | www.baqisf.com |
| 162.211.182.39 | www.91530.com |
| 162.211.182.39 | www.zhaohaosf.com |
| 162.211.182.39 | www.s400.com |
| 162.211.182.39 | www.aichenmo.com |
| 162.211.182.39 | www.sf315.com |
| 162.211.182.39 | 425sf.com |
| 162.211.182.39 | www.23gg.com |
| 162.211.182.39 | yaofg.com |
| 162.211.182.39 | www.44woool.com |
| 162.211.182.39 | www.17166.com |
| 162.211.182.39 | www.wt789.com |
| 162.211.182.39 | www.591maimai.com |
| 162.211.182.39 | calds.net |
| 162.211.182.39 | www.gggsf.com |
| 162.211.182.39 | www.cecri.com |
| 162.211.182.39 | www.cnpxba.com |
| 162.211.182.39 | www.cqrcxx.com |
| 162.211.182.39 | www.zhaowt.net |
| 162.211.182.39 | 3000ak.com |
| 162.211.182.39 | www.3000ak.com |
| 162.211.182.39 | 027gg.net |
| 162.211.182.39 | www.85sf.com |
| 162.211.182.39 | www.cnxinghang.com |
| 162.211.182.39 | www.sf19.com |
| 162.211.182.39 | www.uc600.com |
| 162.211.182.39 | www.255uc.com |
| 162.211.182.39 | 255uc.com |
| 162.211.182.39 | 111.kaihu365.com |
| 162.211.182.39 | www.3000ok-1.com |
| 162.211.182.39 | www.3000ok.com |
| 162.211.182.39 | www.sf588.com |
| 162.211.182.39 | www.jjj3000ok.com |
| 162.211.182.39 | 1000ok.com |
| 162.211.182.39 | www.33ok.com |
| 162.211.182.39 | www.666923.com |
| 162.211.182.39 | www.920313.com |
| 162.211.182.39 | www.616st.com |
| 162.211.182.39 | www.53my.com |
| 162.211.182.39 | www.945176.net |
| 162.211.182.39 | www.999sf.cc |
| 162.211.182.39 | 933gg.com |
| 162.211.182.39 | haosf.com |
| 162.211.182.39 | 123.123wg.com |
| 162.211.182.39 | haosf.com.cn |
| 162.211.182.39 | www.haosf.com.cn |
| 162.211.182.39 | tg.cnm78.com |
| 162.211.182.39 | www.1213sf.com |
| 162.211.182.39 | www.678sf.com |
| 162.211.182.39 | www.250sf.com |
| 162.211.182.39 | www.92188.com |
| 162.211.182.39 | 888.hyds888.com |
| 162.211.182.39 | www.646sf.com |
| 162.211.182.39 | www.82cq.com |
| 162.211.182.39 | sf99.cc |
| 162.211.182.39 | www.50ww.com |
| 162.211.182.39 | sf590.com |
| 162.211.182.39 | www.sf590.com |
| 162.211.182.39 | www.35fg.com |
| 162.211.182.39 | www.sf526.com |
| 162.211.182.39 | www.18ux.com |
| 162.211.182.39 | www.520cq.net |
| 162.211.182.39 | www.haosf12345.com |
| 162.211.182.39 | sf22.com |
| 162.211.182.39 | pk99.com |
| 162.211.182.39 | 79j.com |
| 162.211.182.39 | 55sf.com |
| 162.211.182.39 | www.55sf.com |
| 162.211.182.39 | www.zm63.com |
| 162.211.182.39 | 926.syslx.com |
| 162.211.182.39 | 1000ok.cc |
| 162.211.182.39 | www.1000ok.cc |
| 162.211.182.39 | 3000ok.isosf.com |
| 162.211.182.39 | 3000ok.com |
| 162.211.182.39 | tt.syslx.com |
| 162.211.182.39 | www.zhaofq.com |
| 162.211.182.39 | 2013.cqmdl.com |
| 162.211.182.39 | www.19fu.com |
| 162.211.182.39 | 19fu.com |
| 162.211.182.39 | www.zhaosifu.com |
| 162.211.182.39 | www.kom999.com |
| 162.211.182.39 | www.ok777.com |
| 162.211.182.39 | www.757sf.com |
| 162.211.182.39 | www.50999.com |
| 162.211.182.39 | 33345.com |
| 162.211.182.39 | 999zg.com |
| 162.211.182.39 | www.13ss.com |
| 162.211.182.39 | www.520zf.com |
| 162.211.182.39 | 88pk.com |
| 162.211.182.39 | www.990yx.com |
| 162.211.182.39 | www.cqacura.com |
| 162.211.182.39 | www.tldsny.com |
| 162.211.182.39 | www.wzggwz.com |
| 162.211.182.39 | www.tjnhey.com |
| 162.211.182.39 | www.51friends.com |
| 162.211.182.39 | aa.707wz.com |
| 162.211.182.39 | www.cn-skf.com |
| 162.211.182.39 | www.6sf.com |
| 162.211.182.39 | www.nhfluhuijiao.com |
| 162.211.182.39 | mojingqiyuan.com |
| 162.211.182.39 | www.jianfeixy.com |
| 162.211.182.39 | www.shkingdu.com |
| 162.211.182.39 | www.707wz.com |
| 162.211.182.39 | www.suoyinm.com |
| 162.211.182.39 | www.zcmeter.com |
| 162.211.182.39 | www.115book.com |
| 162.211.182.39 | cqsf.yearwin.com |
| 162.211.182.39 | 9kst.com |
| 162.211.182.39 | 9u.7080st.com |
| 162.211.182.39 | www.118uc.om |
| 162.211.182.39 | www.haofwd.com |
| 162.211.182.39 | www.zhaowoool.com |
| 162.211.182.39 | www.gdhttz.com |
| 162.211.182.39 | www.fzdbdz.com |
| 162.211.182.39 | www.tianguhotel.com |
| 162.211.182.39 | www.chinahjly.com |
| 162.211.182.39 | tgaxved8.com |
| 162.211.182.39 | 5a189.com |
| 162.211.182.39 | 9q0s6.clydji.com |
| 162.211.182.39 | www.wuwoool.com |
| 162.211.182.39 | www.shitongdg.com |
| 162.211.182.39 | www.sbqcssf.com |
| 162.211.182.39 | www.51cssf.net.cn |
| 162.211.182.39 | www.65535cs.com |
| 162.211.182.39 | zhao.559woool.com |
| 162.211.182.39 | www.559woool.com |
| 162.211.182.39 | www.5sdl.com |
| 162.211.182.39 | www.dandong-window.com |
| 162.211.182.39 | www.xinyumen.com |
| 162.211.182.39 | www.ahzhishang.com |
| 162.211.182.39 | www.xd163.com |
| 162.211.182.39 | www.trm-china.com |
| 162.211.182.39 | www.aoyue168.com |
| 162.211.182.39 | www.gdcable.com |
| 162.211.182.39 | www.zhuwulong.com |
| 162.211.182.39 | www.szjapson.com |
| 162.211.182.39 | www.swan-storage.com |
| 162.211.182.39 | www.cseptc.com |
| 162.211.182.39 | www.zcgddz.com |
| 162.211.182.39 | www.dycssf.com |
| 162.211.182.39 | www.9965478.com |
| 162.211.182.39 | www.jshgzb.com |
| 162.211.182.39 | www.qd-qinggang.com |
| 162.211.182.39 | gzgm.27pyki.com |
| 162.211.182.39 | wupin.qxgxc.com |
| 162.211.182.39 | www.hcs888.com |
| 162.211.182.39 | www.woool578.com |
| 162.211.182.39 | www.jntex.com |
| 162.211.182.39 | 917wool.cn |
| 162.211.182.39 | chuanqifj.com |
| 162.211.182.39 | www.lqgz.com |
| 162.211.182.39 | 1.sun0319.com |
| 162.211.182.39 | www.suwoool.com |
| 162.211.182.39 | www.45ci.com |
| 162.211.182.39 | iiwoool.com |
| 162.211.182.39 | www.sdyjt.com |
| 162.211.182.39 | www1.bai12.com |
| 162.211.182.39 | www.889cs.com |
| 162.211.182.39 | www.cjphb.com |
| 162.211.182.39 | www.szosun.com |
| 162.211.182.39 | www.garment5.com |
| 162.211.182.39 | www.gm66.com |
| 162.211.182.39 | www.com15.com |
| 162.211.182.39 | www.emc120.com |
| 162.211.182.39 | ktjia.com |
| 162.211.182.39 | www.05woool.com |
| 162.211.182.39 | www.cnsjjs.com |
| 162.211.182.39 | www.jnxsfr.com |
| 162.211.182.39 | www.chinajujing.com |
| 162.211.182.39 | www.99cishan.com |
| 162.211.182.39 | www.022-baidu.com |
| 162.211.182.39 | 44woool.com |
| 162.211.182.39 | www.mm886.net |
| 162.211.182.39 | www.shyssteel.com |
| 162.211.182.39 | 3.96cs.com |
| 162.211.182.39 | www.ywool.com |
| 162.211.182.39 | www.hao123woool.com |
| 162.211.182.39 | aixin168.com |
| 162.211.182.39 | www.wooolfbw.com |
| 162.211.182.39 | www.525pc.com |
| 162.211.182.39 | www.zhaowooolsf.com |
| 162.211.182.39 | cnscn.org |
| 162.211.182.39 | www.cn-tyn.com |
| 162.211.182.39 | www.917wool.cn |
| 162.211.182.39 | www.hy225.com |
| 162.211.182.39 | www.10gamer.com |
| 162.211.182.39 | 56jm.wpgyai.com |
| 162.211.182.39 | www.zv2o.com |
| 162.211.182.39 | 001.96cs.com |
| 162.211.182.39 | www.411wed.com |
| 162.211.182.39 | www.lewoool.com |
| 162.211.182.39 | gtcc2008.com |
| 162.211.182.39 | 945pk.com |
| 162.211.182.39 | pk777.com |
| 162.211.182.39 | jgfw.qu-zhou.com |
| 162.211.182.39 | www.168gamer.com |
| 162.211.182.39 | new.guguyu.com |
| 162.211.182.39 | www.bluemuffinkids.com |
| 162.211.182.39 | web.longhoo.net |
| 162.211.182.39 | www.8090yxs.com |
| 162.211.182.39 | aszt.6268.com |
| 162.211.182.39 | kf.07073.com |
| 162.211.182.39 | www.mcncc.com |
| 162.211.182.39 | www.wudijz.com |
| 162.211.182.39 | lhzs.9377.com |
| 162.211.182.39 | lhzs.37wan.com |
| 162.211.182.39 | lhzs.yaowan.com |
| 162.211.182.39 | lhzs.49you.com |
| 162.211.182.39 | lhzs.8090yxs.com |
| 162.211.182.39 | wz.49you.com |
| 162.211.182.39 | wz.6711.com |
| 162.211.182.39 | asqx.yaowan.com |
| 162.211.182.39 | www.sifucun.com |
| 162.211.182.39 | bbs.to4f.com |
| 162.211.182.39 | www.pg666.cn |
| 162.211.182.39 | www.yeyoubbs.com |
| 162.211.182.39 | www.ucwawa.com |
| 162.211.182.39 | www.hgyouxi.net |
| 162.211.182.39 | www.xiaolou8.com |
| 162.211.182.39 | bbs.houdao.com |
| 162.211.182.39 | www.iopq.com |
| 162.211.182.39 | bbs2.okweb8.com |
| 162.211.182.39 | wangyesifu.com |
| 162.211.182.39 | ok1399.com |
| 162.211.182.39 | www.wy090.com |
| 162.211.182.39 | www.yx315.net |
| 162.211.182.39 | www.yrabc.com |
| 162.211.182.39 | 67uc.com |
| 162.211.182.39 | www.yxsjqk.com |
| 162.211.182.39 | bbs.mcncc.net |
| 162.211.182.39 | www.wangyesifu.com |
| 162.211.182.39 | bbs.games.qq.com |
| 162.211.182.39 | www.uc266.com |
| 162.211.182.39 | www.luanshi.net |
| 162.211.182.39 | bbs.freegames.com.cn |
| 162.211.182.39 | www.180b.com |
| 162.211.182.39 | www.gamemx.com |
| 162.211.182.39 | www.9kld.com |
| 162.211.182.39 | bbs2.99nets.me |
| 162.211.182.39 | www.to4f.com |
| 162.211.182.39 | ejxx.jdjy.cn |
| 162.211.182.39 | www.920520.com |
| 162.211.182.39 | www.gifts52.com |
| 162.211.182.39 | www.jjj.com.co |
| 162.211.182.39 | www.cq200.com |
| 162.211.182.39 | www.239ok.com |
| 162.211.182.39 | www.97heji.com |
| 162.211.182.39 | daquan.bxim28.com |
| 162.211.182.39 | www.173bt.com |
| 162.211.182.39 | www.1745.com |
| 162.211.182.39 | www.96sf.com |
| 162.211.182.39 | www.sffb.net |
| 162.211.182.39 | www.5uwl.net |
| 162.211.182.39 | www.qtgcjx.com |
| 162.211.182.39 | www.bdqn.net |
| 162.211.182.39 | www.52anzu.net |
| 162.211.182.39 | www1.52anzu.net |
| 162.211.182.39 | www.52anzu.com |
| 162.211.182.39 | www1.52anzu.com |
| 162.211.182.39 | www2.52anzu.com |
| 162.211.182.39 | www.sopojie.com |
| 162.211.182.39 | www1.sopojie.com |
| 162.211.182.39 | uc.sydahe.com |
| 162.211.182.39 | www.1cq.com |
| 162.211.182.39 | 1cq.com |
| 162.211.182.39 | www.tt0436.com |
| 162.211.182.39 | www.ximeiedu.com |
| 162.211.182.39 | www.zhanzz.com |
| 162.211.182.39 | dxkj888.com |
| 162.211.182.39 | www.cxzgled.com |
| 162.211.182.39 | www.sf999.com.cn |
| 162.211.182.39 | www.nbxywj.com |
| 162.211.182.39 | www.51zhaosf.com |
| 162.211.182.39 | 30okok.com |
| 162.211.182.39 | www.33345ok.com |
| 162.211.182.39 | www.lanhaibyd.com |
| 162.211.182.39 | uc.turuyi.com |
| 162.211.182.39 | www.sinomax-tip.com |
| 162.211.182.39 | www.yiyuanit.com |
| 162.211.182.39 | mg60.com |
| 162.211.182.39 | 3000ok.pro |
| 162.211.182.39 | uuu.turuyi.com |
| 162.211.182.39 | www.bjek120.com |
| 162.211.182.39 | sdjnbx.com |
| 162.211.182.39 | new.turuyi.com |
| 162.211.182.39 | www.bsssun.com |
| 162.211.182.39 | www.fu110.com |
| 162.211.182.39 | www.pdlmall.com |
| 162.211.182.39 | 23bb.net |
| 162.211.182.39 | www.tde007.com |
| 162.211.182.39 | www.500ok.com |
| 162.211.182.39 | www.hlkg.net |
| 162.211.182.39 | www.17126.com |
| 162.211.182.39 | www.ideapack.com.cn |
| 162.211.182.39 | 62bf2.mc520.com |
| 162.211.182.39 | www.tophereled.com |
| 162.211.182.39 | www.ch-gwang.com |
| 162.211.182.39 | www.sf12345.cc |
| 162.211.182.39 | sis858.com |
| 162.211.182.39 | www.sfwanjia.com |
| 162.211.182.39 | www.765cq.com |
| 162.211.182.39 | p22672.com |
| 162.211.182.39 | www.53245.com |
| 162.211.182.39 | www.335ok.com |
| 162.211.182.39 | 335ok.com |
| 162.211.182.39 | www.zglzsy.com |
| 162.211.182.39 | sf.183a8.mc520.com |
| 162.211.182.39 | jiaocheng.x9858.com |
| 162.211.182.39 | www.led58.com |
| 162.211.182.39 | miji.38yqj.com |
| 162.211.182.39 | xx.turuyi.com |
| 162.211.182.39 | www.hongchuangalye.com |
| 162.211.182.39 | jinanzhongju.com |
| 162.211.182.39 | www.87sf.com |
| 162.211.182.39 | www.e-sunisco.com |
| 162.211.182.39 | 333.sydahe.com |
| 162.211.182.39 | 185.17c94.mc520.com |
| 162.211.182.39 | 461a9.170.mc520.com |
| 162.211.182.39 | www.fg12.com |
| 162.211.182.39 | 3o8c8.feztod.com |
| 162.211.182.39 | exa.bzjaza.com |
| 162.211.182.39 | www.cqsf185.com |
| 162.211.182.39 | haosf.zhaochaye.cn |
| 162.211.182.39 | www.gw-food.com |
| 162.211.182.39 | 1h5.robszh.com |
| 162.211.182.39 | rla.graujp.com |
| 162.211.182.39 | www.sf120.com |
| 162.211.182.39 | 520.sydahe.com |
| 162.211.182.39 | v02.clydji.com |
| 162.211.182.39 | qq.turuyi.com |
| 162.211.182.39 | 2f7a6.jhtjqg.com |
| 162.211.182.39 | www.505sf.com |
| 162.211.182.39 | www.zyxxedo.com |
| 162.211.182.39 | yy.turuyi.com |
| 162.211.182.39 | xp.sydahe.com |
| 162.211.182.39 | 777.turuyi.com |
| 162.211.182.39 | www.920cq.com |
| 162.211.182.39 | www.99340.com |
| 162.211.182.39 | sss.sydahe.com |
| 162.211.182.39 | www.zhaosf.ws |
| 162.211.182.39 | 7e1.eeulus.com |
| 162.211.182.39 | www.hycartoon.com |
| 162.211.182.39 | sf.youxi366.com |
| 162.211.182.39 | www.916cq.com/1 |
| 162.211.182.39 | www.916cq.com |
| 162.211.182.39 | rhj.bnn2.com |
| 162.211.182.39 | www.tootc.com |
| 162.211.182.39 | jieshao.tgv27.com |
| 162.211.182.39 | legalweek.cn |
| 162.211.182.39 | www.chuanqisf999.com |
| 162.211.182.39 | www.gf999.com |
| 162.211.182.39 | www.baiduhaosf.com |
| 162.211.182.39 | www.nikeshoxr4.net |
| 162.211.182.39 | www.jjj.com.ru |
| 162.211.182.39 | www.tzchanghong.com |
| 162.211.182.39 | www.mxjy.net |
| 162.211.182.39 | www.qicai130.com |
| 162.211.182.39 | jiadian.66kin.com |
| 162.211.182.39 | www.sf123.org |
| 162.211.182.39 | sf123.co |
| 162.211.182.39 | www.pk930.com |
| 162.211.182.39 | www.chuanqisifu.eu |
| 162.211.182.39 | www.123dbc.com |
| 162.211.182.39 | 7pv.net |
| 162.211.182.39 | www.soojin-dance.com |
| 162.211.182.39 | ko.sydahe.com |
| 162.211.182.39 | www.0532yinli.com |
| 162.211.182.39 | www.0717bbs.com |
| 162.211.182.39 | www.pk021.com |
| 162.211.182.39 | www.cswewon.com |
| 162.211.182.39 | wb.91sbk.com |
| 162.211.182.39 | www.rfinfo.cn |
| 162.211.182.39 | www.m1ye.com |
| 162.211.182.39 | 467.2013wansf.com |
| 162.211.182.39 | www.autohome.name |
| 162.211.182.39 | sdgsdf.ezwohs.com |
| 162.211.182.39 | jptea.cn |
| 162.211.182.39 | 468dc.xfds.com |
| 162.211.182.39 | xitong.e3358.com |
| 162.211.182.39 | guaiwu.shf2.com |
| 162.211.182.39 | hbwxkj.com |
| 162.211.182.39 | jineng.kqgf69.com |
| 162.211.182.39 | cotton.687vt.com |
| 162.211.182.39 | cq.sydahe.com |
| 162.211.182.39 | ccc.turuyi.com |
| 162.211.182.39 | jj23j.60sf.cn |
| 162.211.182.39 | zfu232.sf33.cn |
| 162.211.182.39 | sdf232.60sf.cn |
| 162.211.182.39 | www.sztoled.com |
| 162.211.182.39 | 8d0m9.jhtjqg.com |
| 162.211.182.39 | sf999.at |
| 162.211.182.39 | www.esinda.com |
| 162.211.182.39 | 3159wine.com |
| 162.211.182.39 | www.gm7.cc |
| 162.211.182.39 | www.liygaya.com |
| 162.211.182.39 | www.fscdo.com |
| 162.211.182.39 | www.daosf.com |
| 162.211.182.39 | xxx.sydahe.com |
| 162.211.182.39 | 4ke.dksifw.com |
| 162.211.182.39 | zhao.turuyi.com |
| 162.211.182.39 | www.bjyadzkj.com |
| 162.211.182.39 | www.jjj.com.es |
| 162.211.182.39 | www.810sf.com |
| 162.211.182.39 | www.lc91.com |
| 162.211.182.39 | www.bjkuaike.com |
| 162.211.182.39 | www.gzanfa.com |
| 162.211.182.39 | www.49y.com |
| 162.211.182.39 | www.justice |
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name: ?????
Product Version: 1.0.0.0
Legal Copyright: ?????? ????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description: ?????
Comments: ??????????(http://www.eyuyan.com)
Language: Language Neutral
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 506947 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rdata | 512000 | 1441802 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .data | 1957888 | 179530 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 2138112 | 34688 | 20480 | 3.86761 | e71ca416dbd3f28eeee18d7eb229741e |
| .vmp0 | 2174976 | 12324 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .vmp1 | 2191360 | 1757591 | 1761280 | 5.44659 | a722de03023d950b6b6a0822c7d55755 |
| .reloc | 3952640 | 80 | 4096 | 0.099441 | 7d91e7b97cdd8e9ef3e9d2ef24334f96 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://jc.941pojie.com/tc.txt | |
| hxxp://jc.941pojie.com/ | |
| hxxp://jc.941pojie.com/cj.txt | |
| hxxp://gogozz1pj.huihaowy.com/ | |
| hxxp://jc.941pojie.com/jiaqun.htm | |
| hxxp://jc.941pojie.com/css/style.css | |
| hxxp://jc.941pojie.com/img/gif008.gif | |
| hxxp://jc.941pojie.com/img/zsf.gif | |
| hxxp://ssd.tcdn.qq.com/wpa/images/group.png | |
| hxxp://jc.941pojie.com/img/lhr.gif | |
| hxxp://c.split.cnzz.com/stat.php?id=5076676&show=pic2 | |
| hxxp://c.split.cnzz.com/core.php?web_id=5076676&show=pic2&t=z | |
| hxxp://z3.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438 | |
| hxxp://z3.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369 | |
| hxxp://c.split.cnzz.com/stat.php?id=1253112259&web_id=1253112259 | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=333037092 | |
| hxxp://icon.cnzz.com/img/pic2.gif | |
| hxxp://c.split.cnzz.com/stat.php?id=3325108&show=pic1 | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1036514576 | |
| hxxp://c.split.cnzz.com/core.php?web_id=1253112259&t=z | |
| hxxp://c.split.cnzz.com/core.php?web_id=3325108&show=pic1&t=z | |
| hxxp://z7.cnzz.com/stat.htm?id=1253112259&r=&lg=en-us&ntime=none&cnzz_eid=804168892-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined&h=1&rnd=999258932 | |
| hxxp://jc.941pojie.com/img/jbc.gif | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=895496844 | |
| hxxp://icon.cnzz.com/img/pic1.gif | |
| hxxp://pcookie.split.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB | |
| hxxp://pcookie.split.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z | |
| hxxp://z6.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005 | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=2071775127 | |
| hxxp://z6.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043 | |
| hxxp://jc.941pojie.com/img/js.gif | |
| hxxp://img.webscan.360.cn/status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1532175039 | |
| hxxp://jc.941pojie.com/img/swz.gif | |
| hxxp://jc.941pojie.com/img/gua.gif | |
| hxxp://hm.e.shifen.com/h.js?c8a6515c967e27925a2fd6685fe9963c | |
| hxxp://jc.941pojie.com/img/2014052276129177.gif | |
| hxxp://hm.e.shifen.com/hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=å¼€å¿ƒå¿«ä¹æ¯ä¸€å¤©ï¼ | |
| hxxp://jc.941pojie.com/img/046bt.gif | |
| hxxp://jc.941pojie.com/img/icon.png | |
| hxxp://static.n.shifen.com/hmt/icon/21.gif | |
| hxxp://jc.941pojie.com/img/zs.jpg | |
| hxxp://c.split.cnzz.com/stat.php?id=1253024109&web_id=1253024109 | |
| hxxp://c.split.cnzz.com/core.php?web_id=1253024109&t=z | |
| hxxp://jc.941pojie.com/img/bg.gif | |
| hxxp://z8.cnzz.com/stat.htm?id=1253024109&r=http://cctv-6.padonline.net:5566/&lg=en-us&ntime=none&cnzz_eid=none&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1415649696 | |
| hxxp://jc.941pojie.com/img/bgheader.gif | |
| hxxp://jc.941pojie.com/img/bgnav.gif | |
| hxxp://jc.941pojie.com/img/bgh.gif | |
| hxxp://jc.941pojie.com/img/gg.png | |
| hxxp://jc.941pojie.com/img/1gg.png | |
| hxxp://jc.941pojie.com/img/下载.jpg | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1153140611 | |
| hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1784473045 | |
| hxxp://z3.cnzz.com/stat.htm?id=5076676&r=http://www.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725 | |
| hxxp://jc.941pojie.com/img/top.png | |
| hxxp://z6.cnzz.com/stat.htm?id=3325108&r=http://www.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526 | |
| hxxp://jc.941pojie.com/img/logo.gif | |
| hxxp://jc.941pojie.com/img/bgtitle.gif | |
| hxxp://hm.baidu.com/h.js?c8a6515c967e27925a2fd6685fe9963c | |
| hxxp://www.lszwg.com/img/js.gif | |
| hxxp://www.941pojie.com/img/bgnav.gif | |
| hxxp://www.lszwg.com/img/icon.png | |
| hxxp://www.lszwg.com/img/下载.jpg | |
| hxxp://eiv.baidu.com/hmt/icon/21.gif | |
| hxxp://www.941pojie.com/img/gif008.gif | |
| hxxp://www.941pojie.com/img/zsf.gif | |
| hxxp://s19.cnzz.com/stat.php?id=1253024109&web_id=1253024109 | |
| hxxp://www.lszwg.com/img/jbc.gif | |
| hxxp://www.941pojie.com/img/logo.gif | |
| hxxp://s85.cnzz.com/stat.php?id=3325108&show=pic1 | |
| hxxp://c.cnzz.com/core.php?web_id=3325108&show=pic1&t=z | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1784473045 | |
| hxxp://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB | |
| hxxp://www.941pojie.com/img/bgtitle.gif | |
| hxxp://www.941pojie.com/ | |
| hxxp://www.941pojie.com/img/gg.png | |
| hxxp://www.lszwg.com/img/top.png | |
| hxxp://www.941pojie.com/img/jbc.gif | |
| hxxp://c.cnzz.com/core.php?web_id=1253024109&t=z | |
| hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369 | |
| hxxp://www.lszwg.com/img/lhr.gif | |
| hxxp://www.941pojie.com/img/swz.gif | |
| hxxp://c.cnzz.com/core.php?web_id=1253112259&t=z | |
| hxxp://c.cnzz.com/core.php?web_id=5076676&show=pic2&t=z | |
| hxxp://www.lszwg.com/img/swz.gif | |
| hxxp://www.941pojie.com/img/lhr.gif | |
| hxxp://www.lszwg.com/img/bgtitle.gif | |
| hxxp://www.lszwg.com/img/bgnav.gif | |
| hxxp://www.lszwg.com/img/1gg.png | |
| hxxp://www.lszwg.com/img/bg.gif | |
| hxxp://www.lszwg.com/img/gif008.gif | |
| hxxp://www.941pojie.com/img/js.gif | |
| hxxp://www.lszwg.com/img/046bt.gif | |
| hxxp://www.lszwg.com/img/bgh.gif | |
| hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=http://www.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725 | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=895496844 | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1153140611 | |
| hxxp://www.941pojie.com/img/gua.gif | |
| hxxp://www.941pojie.com/img/046bt.gif | |
| hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=http://www.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526 | |
| hxxp://www.lszwg.com/img/bgheader.gif | |
| hxxp://hm.baidu.com/hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=å¼€å¿ƒå¿«ä¹æ¯ä¸€å¤©ï¼ | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=333037092 | |
| hxxp://www.941pojie.com/img/bg.gif | |
| hxxp://www.941pojie.com/img/top.png | |
| hxxp://www.lszwg.com/ | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1036514576 | |
| hxxp://www.941pojie.com/img/bgheader.gif | |
| hxxp://www.941pojie.com/css/style.css | |
| hxxp://www.lszwg.com/css/style.css | |
| hxxp://www.941pojie.com/img/2014052276129177.gif | |
| hxxp://s25.cnzz.com/stat.php?id=5076676&show=pic2 | |
| hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043 | |
| hxxp://www.941pojie.com/img/1gg.png | |
| hxxp://www.941pojie.com/img/bgh.gif | |
| hxxp://pub.idqqimg.com/wpa/images/group.png | |
| hxxp://s13.cnzz.com/stat.php?id=1253112259&web_id=1253112259 | |
| hxxp://www.lszwg.com/img/logo.gif | |
| hxxp://www.lszwg.com/img/gg.png | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=2071775127 | |
| hxxp://www.941pojie.com/img/zs.jpg | |
| hxxp://www.lszwg.com/img/zs.jpg | |
| hxxp://www.lszwg.com/img/zsf.gif | |
| hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005 | |
| hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1532175039 | |
| hxxp://www.941pojie.com/img/icon.png | |
| hxxp://www.lszwg.com/img/gua.gif | |
| hxxp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z | |
| hxxp://www.941pojie.com/img/下载.jpg | |
| hxxp://www.lszwg.com/img/2014052276129177.gif | |
| hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438 | |
| qqqggg777444.jyjaj.com | |
| 941pojie.meibu.net | |
| cctv-6.padonline.net | |
| a510sf.010aimei.com |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY HTTP Request on Unusual Port Possibly Hostile
Traffic
GET /stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:19 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:19 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..
GET /stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /stat.php?id=1253112259&web_id=1253112259 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s13.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 15:18:04 GMT246d..(function(){function l(){this.c="1253112259";this.O="z";this.K="
";this.H="";this.J="";this.o="1410443284";this.M="z7.cnzz.com";this.I=
"";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_cnz
z_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,c){
try{var b=[];b.push("siteid=1253112259");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: gogozz1pj.huihaowy.com
Connection: Keep-Alive
HTTP/1.1 302 Redirect
Content-Length: 156
Content-Type: text/html
Location: hXXp://cctv-6.padonline.net:5566/
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 11 Sep 2014 13:47:51 GMT<head><title>Document Moved</title></head>.<
;body><h1>Object Moved</h1>This document may be found &
lt;a HREF="hXXp://cctv-6.padonline.net:5566/">here</a></bo
dy>HTTP/1.1 302 Redirect..Content-Length: 156..Content-Type: text/h
tml..Location: hXXp://cctv-6.padonline.net:5566/..Server: Microsoft-II
S/6.0..X-Powered-By: ASP.NET..Date: Thu, 11 Sep 2014 13:47:51 GMT..<
;head><title>Document Moved</title></head>.<bo
dy><h1>Object Moved</h1>This document may be found <
a HREF="hXXp://cctv-6.padonline.net:5566/">here</a></body&
gt;..
GET /jiaqun.htm HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: jc.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 224
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://jc.941pojie.com/jiaqun.htm
Last-Modified: Thu, 29 Aug 2013 09:28:40 GMT
Accept-Ranges: bytes
ETag: "0d46a259aa4ce1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET..........t.;N.0.E.by.qb.c.$,.=...5.:.......iG. *:.AE.....9..5...al...
`:Q.....c\...z.\..I7..q....1........m.Y).).V...XH.EZ@[email protected].
...B[..~tD..`hhJ...k{.u.....5.Gp.1..}I..Q...]...r.}.y..|.>.~q..NI.q
.[........C.K....HTTP/1.1 200 OK..Date: Thu, 11 Sep 2014 13:48:30 GMT.
.Content-Length: 224..Content-Type: text/html..Content-Encoding: gzip.
.Content-Location: hXXp://jc.941pojie.com/jiaqun.htm..Last-Modified: T
hu, 29 Aug 2013 09:28:40 GMT..Accept-Ranges: bytes..ETag: "0d46a259aa4
ce1:3e08a"..Vary: Accept-Encoding..Server: Microsoft-IIS/6.0..X-Powere
d-By: ASP.NET............t.;N.0.E.by.qb.c.$,.=...5.:.......iG. *:.AE..
...9..5...al...`:Q.....c\...z.\..I7..q....1........m.Y).).V...XH.EZ@.@
......R.Re.2.f....B[..~tD..`hhJ...k{.u.....5.Gp.1..}I..Q...]...r.}.y..
|.>.~q..NI.q.[........C.K......
GET /9.gif?abc=1&rnd=1784473045 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:18 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..
GET /9.gif?abc=1&rnd=1153140611 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:18 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..
GET /stat.htm?id=3325108&r=http://VVV.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /stat.php?id=5076676&show=pic2 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s25.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 15:18:04 GMT1f7a..(function(){function l(){this.c="5076676";this.O="z";this.K="pic
2";this.H="";this.J="";this.o="1410443284";this.M="zs25.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=5076676");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET /core.php?web_id=1253112259&t=z HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 14:03:05 GMT2ef..!function(){var p,q,r,a=encodeURIComponent,b="1253112259",c="",d=
"",e="online_v3.php",f="z7.cnzz.com",g="1",h="text",i="z",j="站&
#38271;统计",k=window["_CNZZDbridge_" b].bobject,l="http:"
,m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("
h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m
&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.crea
teScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.ph
p?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.co
m/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'>
<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="<
a href='" q "' target=_blank title='" j "'>" j "</a>",k.creat
eIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11 S
ep 2014 13:48:05 GMT..Content-Type: application/javascript..Transfer-E
ncoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep 2
014 13:48:05 GMT..Expires: Thu, 11 Sep 2014 14:03:05 GMT..2ef..!functi
on(){var p,q,r,a=encodeURIComponent,b="1253112259",c="",d="",e="online
_v3.php",f="z7.cnzz.com",g="1",h="text",i="z",j="站长ń
79;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n=l "
//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o.pus
h("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.callRequ
est([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScriptIcon
(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?web_id<<< skipped >>>
GET /core.php?web_id=1253024109&t=z HTTP/1.1
Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:12 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:12 GMT
Expires: Thu, 11 Sep 2014 14:03:12 GMT2ef..!function(){var p,q,r,a=encodeURIComponent,b="1253024109",c="",d=
"",e="online_v3.php",f="z8.cnzz.com",g="1",h="text",i="z",j="站&
#38271;统计",k=window["_CNZZDbridge_" b].bobject,l="http:"
,m="1",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("
h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m
&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.crea
teScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.ph
p?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.co
m/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'>
<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="<
a href='" q "' target=_blank title='" j "'>" j "</a>",k.creat
eIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11 S
ep 2014 13:48:12 GMT..Content-Type: application/javascript..Transfer-E
ncoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep 2
014 13:48:12 GMT..Expires: Thu, 11 Sep 2014 14:03:12 GMT..2ef..!functi
on(){var p,q,r,a=encodeURIComponent,b="1253024109",c="",d="",e="online
_v3.php",f="z8.cnzz.com",g="1",h="text",i="z",j="站长ń
79;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="1",n=l "
//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o.pus
h("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.callRequ
est([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScriptIcon
(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?web_id<<< skipped >>>
GET /cj.txt HTTP/1.1
Accept: */*
Accept-Language: en-us
If-Modified-Since: Thu, 01 Jan 1970 00:00:00 GMT
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: jc.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:29 GMT
Content-Length: 11879
Content-Type: text/plain
Content-Encoding: gzip
Content-Location: hXXp://jc.941pojie.com/cj.txt
Last-Modified: Wed, 10 Sep 2014 03:44:39 GMT
Accept-Ranges: bytes
ETag: "80ed278ca9cccf1:3e080"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........}Y..H..7).;........P.1'q..}.8..........P...aO..TZ`....55.z.
'.#b...?.8v&.D........U.$....v ...i...n..Z...J'.uo.../?).s.j...w....x.
...*s.#.}..:.:.u?..Q.-..u}$........Q.<.(.........N..N..{Q..P...J.E.
.....q.o.y~V........<3h....D.........0....W.........E..?X3..G.Om..U
...q 6.... 6U.../.;.......O....p........l.SM><...........!"!..?O
...n."v.*k6g...v.^.t.....v.s........1........X.x.}../.k...3Z.|...?Z...
..r.s..WOS.XuUw .. ^.......-......y.=....8.b|ku..<..-....T.....Fo..
4.O..{.%.<..K.x.=...[./....1[[email protected].....:..tr..s.?b.........
...A...~x....y.Dy.@J>^..4V.HH."".F..1......d....n........kZA..k.N..
..r....A.0..6..Bp#.=..Z....<....}?..F_.N...)4....v..K...u..V..Z....
;.K.W[....t..W.yr.3...p.....|.F%..../`.#...].L......cx..F.-...s...D.=.
G..\O.b.o..t. .n.Vz..b..n..0oX......3....3aV...)..On.....j........i=.
*...t.[...u'..5.[8.o..k.t.....KS..l....{........94....~.g.\..LT..k.1aw
9.R.l...D ..:&...]...y&.3}&|.....".......TM......#.^W.........F.=..LV.
.....y........]......]-G....*x......\.o.s.U..~....8BW.`....Z..f.......
r:.e...V2..2........w..:..%6...Xfg..k6.z..9,..'..(.a.>.rV...U[...u`
}.......>.....Z.Zv.C...y.k...p..x.....0...n.....X7....Y..}...4RPo..
W~:..t...j6..r.{..-........c.Yq=.j.N..;......2.......W.7.4;...f/......
.n..*Uxs..c...5.....U.z.../.d...M.....k.6S.n.ap$.._.....T.AO.5.In.....
.aNq4F....7..\....9..y]o...S...{.[...t.'I....Ufx.U.$!..%..d.'.x...\..J
..Rc.O.q.....>\.l..!C.<..8..?I..C.t.....m.7.a.2.!....^]EQ.....V(
..m............ ..1..c3S.#._/3 ...fA:...7.-....c<X.........v..[<<< skipped >>>
GET /app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Connection: Keep-Alive
Host: pcookie.cnzz.com
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDMFxExICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;....
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..
GET / HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...<<< skipped >>>
GET /img/gif008.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;....
GET /img/lhr.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:32 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid<<< skipped >>>
GET /img/swz.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x<<< skipped >>>
GET /img/js.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.<<< skipped >>>
GET /img/2014052276129177.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aX..................!..copyright. 1996 Charles H. Tupper All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;....
GET /img/046bt.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..<<< skipped >>>
GET /img/icon.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.
font>....
GET /img/zs.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.lszwg.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc<<< skipped >>>
GET /img/jbc.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:50 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................<<< skipped >>>
GET /img/js.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:53 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.<<< skipped >>>
GET /img/swz.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:55 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x<<< skipped >>>
GET /img/gua.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:56 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................<<< skipped >>>
GET /img/bgnav.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:58 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P<<< skipped >>>
GET /img/bg.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:58 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;....
GET /img/bgheader.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:59 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%<<< skipped >>>
GET /img/gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:59 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l<<< skipped >>>
GET /img/bgh.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:00 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..<<< skipped >>>
GET /img/1gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:00 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...<<< skipped >>>
GET /img/bg.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;....
GET /img/bgnav.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P<<< skipped >>>
GET /img/gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l<<< skipped >>>
GET /img/下载.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:49:04 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET<html><head><title>Error</title></head>&
lt;body>........................</body></html>..
..
GET /img/bgtitle.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:04 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...<<< skipped >>>
GET /img/top.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:05 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......F......:\.....bKGD..............pHYs..........
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1<<< skipped >>>
GET /h.js?c8a6515c967e27925a2fd6685fe9963c HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Etag: c348ff65ba11fbc940d2c432618797e4
Cache-Control: max-age=0, must-revalidate
Content-Encoding: gzip
Content-Type: application/javascript
Set-Cookie: HMACCOUNT=EF155AF42BFB7713; Path=/; Domain=hm.baidu.com; Expires=Sun, 18 Jan 2038 00:00:00 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Connection: Keep-Alive
Content-Length: 5694
Date: Thu, 11 Sep 2014 13:48:10 GMT
Server: apache...............(function(){var c={id:"c8a6515c967e27925a2fd6685fe9963c
",dm:["cctv-6.padonline.net"],etrk:[],js:"tongji.baidu.com/hm-web/js/"
,icon:'/hmt/icon/21|gif|20|20',br:false,ctrk:false,align:-1,nv:-1,vdur
:1800000,age:31536000000,rec:0,rp:[],trust:0,vcard:0,.[k......OA.9....
I..BT?......n...v.. ......dc..gF...../b1..h4...h...h...Xf.t.k.i..c;..=
../.......t.`....}.......7N3.'.i..)wb.L..._...n[|..Lk.-..a."....`9.I..
.e.... K..$1........fh......y.,L..Y^..e.l..-r....t0..^99....4~...'<
..im_........i.W...L..i).yH...X...V.......V......|....Jim)..~,X.a|%.^N
c.4..r..LY2...e.....9.<....!...[.........c2...i.....^GI...^.a......
...jgQ.>&.O/.;T.ey...&....j.8cs.....R..u..WUl...|Tc..jg.. M....w..|
..1....^.............n.xx...:N...:@9.epz.....?lb.3.$.....y _.R....S...
.i...%.0...%.w..:.8...;.s.)..E.%............8$.m...u..V....3.'..s.2.;2
...K..&.B4.l&..`s,.clf.....p..Cr... ....)..XGx.....c.....#.$..(.eu.. .
'.$...3.oD..(.......C.%..... .o0..z.4.9K..r.o.Ve..p......R.#.....$..&l
t;.2v [email protected]{b/.....7..z.p.J..P...V.X4HB.....2.%...}0......Zc.
.p2........g....#RY.s.F.I..... .E.......A..r..V....o..;p5S .v..>..6
.T.~L.Y.hn.r.,...Q?. MBA.............!..{......."E.:S.._'.d..g...0.O.=
...' .i)......{_.R....[.Y]..g....r?.....z.......vkJg..M.*..".. Mg..L..
....].l.T.i.A. ...d...T4?K.9.~j...g.yS.r..B..QS..<.8O.u......;.!.{.
S.M.......}A... ..o{.g..j.v(m.{...{....B.m.([email protected](hS..)L
.,J..3d......q..<,.._.......o.Q.s...h......UN..r.,3N...v..].......:
>..A..F.....[8..~..j ... o...<.DOl.......Y=d.....r..a5..&..\<<< skipped >>>
GET /hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=å¼€å¿ƒå¿«ä¹æ¯ä¸€å¤©ï¼ HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive
Cookie: HMACCOUNT=EF155AF42BFB7713
HTTP/1.1 200 OK
Cache-Control: private, max-age=0, no-cache
Pragma: no-cache
Content-Type: image/gif
X-Content-Type-Options: nosniff
Connection: Keep-Alive
Content-Length: 43
Date: Thu, 11 Sep 2014 13:48:11 GMT
Server: apacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: private, max-age=0, no-cache..Pragma: no-cache..Content-Type: ima
ge/gif..X-Content-Type-Options: nosniff..Connection: Keep-Alive..Conte
nt-Length: 43..Date: Thu, 11 Sep 2014 13:48:11 GMT..Server: apache..GI
F89a.............!.......,...........L..;..
GET /status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.webscan.360.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: 360Server
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip2669.............R&...PNG........IHDR......./......3......pHYs........
........MiCCPPhotoshop ICC profile..x..SwX...>..e.VB....l.."#....Y.
[email protected]....(.gA..Z.U\8.....}z............y.....&...j.
9R.<:...OH......H.. ....g......yx~t.?...o...p..$......P&W. ..."....
.R...T.......S.d.....ly|B"......I>..................(G$.@..`U.R,...
...@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0...._p..H.......K.3...
..w....!..l.Ba.).f.."...#.H..L.........8?......f.l.....k.o">!......
...N..._....p...u.k.[..V.h..][email protected].<......%b..0..>.
[email protected][email protected]..#......)..4.\,...X..P"M.y.R.D!.
.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@ ...........
\...L....D..*.A..............a.D@.$.<.B........A.T.:.............18
....\..p..`........A...a!:..b.."......"aH4... ...Q"..r...Bj.]H#.-r.9.\
@.... [email protected].]...k....=.....K.ut.}..c..1.f..a\..E
`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z..
.xb:..XF.&.!.!.%^'.._.H$....N.!%.2I.IkH.H-.S.>..i.L&..m....... ....
..O.......:...L..$R...J5e?....2B...Q.......:.ZIm.vP/S...4u.%...C..-...
.igi.h/.t.....E....k.......w......Hb(.k.{...../.L......T0.2..g...oUX*.
*|.....:.V.~...TUsU?.y..T.U..^V}.FU.P.........U..6..RwR.P.Q_.._...c...
.F..H.Tc....!..2e.XB.rV..,k.Mb[...Lv...v/{LSCs.f.f.f..q.......9..J.!..
.{-.-?-..j.f.~.7.z...b.r......up.@.,..:m:.u..6.Q....u..>.c.y.......
..G.m..........704.6..l18c...c.k.i........h...h..I.'.&..g.5x.>f.o.b
.4.e.k<abi2.......)..k.f....t...,.......9..k.a........E..J.6...<<< skipped >>>
GET /stat.php?id=3325108&show=pic1 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s85.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 15:18:05 GMT246d..(function(){function l(){this.c="3325108";this.O="z";this.K="pic
1";this.H="";this.J="";this.o="1410443285";this.M="hzs2.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=3325108");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:28 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.941pojie.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...<<< skipped >>>
GET /css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.941pojie.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.<<< skipped >>>
GET /img/zsf.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]<<< skipped >>>
GET /img/jbc.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:34 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................<<< skipped >>>
GET /img/swz.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:37 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x<<< skipped >>>
GET /img/gua.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:38 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................<<< skipped >>>
GET /img/bg.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;....
GET /img/bgheader.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%<<< skipped >>>
GET /img/bgnav.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P<<< skipped >>>
GET /img/bgh.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..<<< skipped >>>
GET /img/gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l<<< skipped >>>
GET /img/1gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...<<< skipped >>>
GET /img/logo.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:48 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.<<< skipped >>>
GET /stat.htm?id=1253112259&r=&lg=en-us&ntime=none&cnzz_eid=804168892-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined&h=1&rnd=999258932 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: z7.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:08 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /hmt/icon/21.gif HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: eiv.baidu.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Content-Type: image/gif
ETag: "762990053"
Accept-Ranges: bytes
Last-Modified: Tue, 13 Apr 2010 09:38:40 GMT
Expires: Sat, 20 Jul 2024 13:48:11 GMT
Cache-Control: max-age=311040000
Content-Length: 1119
Date: Thu, 11 Sep 2014 13:48:11 GMT
Server: BWS/1.0
Connection: Keep-AliveGIF89a........s..E.....M...................ZS.2-.YS.......2,.c[..D....
...0'..:..0.&..]Z..8..>..D.TM.................C................._..
^.....u..w........~........k.4......X..d.......=1.....a.c[.PH.h_.....b
..........PH........A..9....h`..J..1.......g`..W........2........z.#..
.p..m....jd........*.............[Q...........6..G..............6..t..
........... ..TL.....!....$....."..;0.....h.7-..............Z.........
....%..:.....H@....^W.QJ..'. !..........70.._. %.'...T.0'..Q.G?.ws....
-$........h.}w.....>...........L.....#.......:0.............\S.....
........*".....Q..............<..T.!...p.$...}........N..........d_
...........j.......VN.....o.....e........[............................
......................................................................
....................!.......,............u...,..>6.T.T..&T.".H. ...
.3^.PQ.G..:^..H.-.T....2#!........K..iP.&..03%X..x.P/^.$...`...G>Xd
....!..d.T...j.,..fQ..8l<..U%..G|.h.......$p..f......R..b.....*R@W"
2y..8..V3.LV`t.e..7.>.........\D..O.H.....$...^.]..).. ...9..E...d\
...V.U1..i......B]......c.P<0.i...v.]D..G .?p-.CD.Fi;>..v....r`.
.&........./.dp....`.....;..
GET /stat.php?id=5076676&show=pic2 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s25.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:03 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:03 GMT
Expires: Thu, 11 Sep 2014 15:18:03 GMT246d..(function(){function l(){this.c="5076676";this.O="z";this.K="pic
2";this.H="";this.J="";this.o="1410443283";this.M="zs25.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=5076676");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:19 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:19 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..
GET /9.gif?abc=1&rnd=333037092 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDMFxExICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=df2de106; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=0722dcead177bb21e29e42eb_1410443285; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:05 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDMFxEx
ICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.m
mstat.com..Set-Cookie: sca=df2de106; path=/; domain=.cnzz.mmstat.com..
Set-Cookie: atpsida=0722dcead177bb21e29e42eb_1410443285; expires=Sun,
08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com..Location: htt
p://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB..Expires: T
hu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache..Pragma: no-cach
e..GIF89a.............!.......,...........L..;....
GET /9.gif?abc=1&rnd=895496844 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:07 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:07 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..
GET /wpa/images/group.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:47:58 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:47:58 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)<<< skipped >>>
GET /img/pic2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 431
Last-Modified: Mon, 02 Dec 2013 05:46:13 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:05 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytesGIF89aP.........eee000...........................e...00...0...........
.......................................!..Powered by AFEI.!.....S.,...
.P......` .di.h.....p,.tm.x..|....a..._..1i,...&3.\2...v{.-...xL.s.g.b
-h...5......;.=g......".......m......................m..............."
.........................".......m..............."..w.....u.n..m......
....".....H......*.Q.....#J.H.b...3j..Q... C..I......9.\)b...0c..I....
8[........;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2
014 13:48:05 GMT..Content-Type: image/gif..Content-Length: 431..Last-M
odified: Mon, 02 Dec 2013 05:46:13 GMT..Connection: keep-alive..Keep-A
live: timeout=5..Expires: Fri, 12 Sep 2014 13:48:05 GMT..Cache-Control
: max-age=86400..Accept-Ranges: bytes..GIF89aP.........eee000.........
..................e...00...0..........................................
........!..Powered by AFEI.!.....S.,....P......` .di.h.....p,.tm.x..|.
...a..._..1i,...&3.\2...v{.-...xL.s.g.b-h...5......;.=g......".......m
......................m...............".........................".....
..m..............."..w.....u.n..m..........".....H......*.Q.....#J.H.b
...3j..Q... C..I......9.\)b...0c..I....8[........;....
GET /img/pic1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 428
Last-Modified: Fri, 16 Jan 2009 08:10:47 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:06 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytesGIF89a.......f..3...33.......................................!..NETSCA
PE2.0.....!..Powered by AFEI.!.......,.............I........08bX....d.
n...CS.3......_..`..H..H\8....)...S.b.UX.....(...r.L....tb]&"......#..
.o.V.a..D..o.V.a..........D..o.V.a..........D...........!.......,.....
........I........08bX....d.n...CS.3......_..`..H..H\8....).:[email protected]...
x ..........D.| .#.u.a....n~D..[....n..........D..[...n..........D....
.......;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2014
13:48:06 GMT..Content-Type: image/gif..Content-Length: 428..Last-Modi
fied: Fri, 16 Jan 2009 08:10:47 GMT..Connection: keep-alive..Keep-Aliv
e: timeout=5..Expires: Fri, 12 Sep 2014 13:48:06 GMT..Cache-Control: m
ax-age=86400..Accept-Ranges: bytes..GIF89a.......f..3...33............
...........................!..NETSCAPE2.0.....!..Powered by AFEI.!....
...,.............I........08bX....d.n...CS.3......_..`..H..H\8....)...
S.b.UX.....(...r.L....tb]&"......#...o.V.a..D..o.V.a..........D..o.V.a
..........D...........!.......,.............I........08bX....d.n...CS.
3......_..`..H..H\8....).:[email protected] ..........D.| .#.u.a....n~D..[..
..n..........D..[...n..........D...........;..
GET /stat.php?id=3325108&show=pic1 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s85.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 15:18:05 GMT1f7a..(function(){function l(){this.c="3325108";this.O="z";this.K="pic
1";this.H="";this.J="";this.o="1410443285";this.M="hzs2.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=3325108");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET /stat.htm?id=5076676&r=http://VVV.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /tc.txt HTTP/1.1
Accept: text/html, application/xhtml xml, */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Connection: Keep-Alive
Host: jc.941pojie.com
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:27 GMT
Content-Length: 29
Content-Type: text/plain
Content-Location: hXXp://jc.941pojie.com/tc.txt
Last-Modified: Tue, 22 Jul 2014 16:32:43 GMT
Accept-Ranges: bytes
ETag: "80c7b48fcaa5cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NEThXXp://gogozz1pj.huihaowy.comHTTP/1.1 200 OK..Date: Thu, 11 Sep 2014 1
3:48:27 GMT..Content-Length: 29..Content-Type: text/plain..Content-Loc
ation: hXXp://jc.941pojie.com/tc.txt..Last-Modified: Tue, 22 Jul 2014
16:32:43 GMT..Accept-Ranges: bytes..ETag: "80c7b48fcaa5cf1:3e08a"..Ser
ver: Microsoft-IIS/6.0..X-Powered-By: ASP.NET..hXXp://gogozz1pj.huihao
wy.com..
GET /stat.htm?id=1253024109&r=http://cctv-6.padonline.net:5566/&lg=en-us&ntime=none&cnzz_eid=none&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1415649696 HTTP/1.1
Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: z8.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:13 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.webscan.360.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: 360Server
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip2669.............R&...PNG........IHDR......./......3......pHYs........
........MiCCPPhotoshop ICC profile..x..SwX...>..e.VB....l.."#....Y.
[email protected]....(.gA..Z.U\8.....}z............y.....&...j.
9R.<:...OH......H.. ....g......yx~t.?...o...p..$......P&W. ..."....
.R...T.......S.d.....ly|B"......I>..................(G$.@..`U.R,...
...@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0...._p..H.......K.3...
..w....!..l.Ba.).f.."...#.H..L.........8?......f.l.....k.o">!......
...N..._....p...u.k.[..V.h..][email protected].<......%b..0..>.
[email protected][email protected]..#......)..4.\,...X..P"M.y.R.D!.
.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@ ...........
\...L....D..*.A..............a.D@.$.<.B........A.T.:.............18
....\..p..`........A...a!:..b.."......"aH4... ...Q"..r...Bj.]H#.-r.9.\
@.... [email protected].]...k....=.....K.ut.}..c..1.f..a\..E
`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z..
.xb:..XF.&.!.!.%^'.._.H$....N.!%.2I.IkH.H-.S.>..i.L&..m....... ....
..O.......:...L..$R...J5e?....2B...Q.......:.ZIm.vP/S...4u.%...C..-...
.igi.h/.t.....E....k.......w......Hb(.k.{...../.L......T0.2..g...oUX*.
*|.....:.V.~...TUsU?.y..T.U..^V}.FU.P.........U..6..RwR.P.Q_.._...c...
.F..H.Tc....!..2e.XB.rV..,k.Mb[...Lv...v/{LSCs.f.f.f..q.......9..J.!..
.{-.-?-..j.f.~.7.z...b.r......up.@.,..:m:.u..6.Q....u..>.c.y.......
..G.m..........704.6..l18c...c.k.i........h...h..I.'.&..g.5x.>f.o.b
.4.e.k<abi2.......)..k.f....t...,.......9..k.a........E..J.6...<<< skipped >>>
GET /core.php?web_id=5076676&show=pic2&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 14:03:04 GMT2f1..!function(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d
="",e="online_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:04 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:04 GMT..Expires: Thu, 11 Sep 2014 14:03:04 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d="",e="onl
ine_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we<<< skipped >>>
GET /core.php?web_id=3325108&show=pic1&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:06 GMT
Expires: Thu, 11 Sep 2014 14:03:06 GMT2f1..!function(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d
="",e="online_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:06 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:06 GMT..Expires: Thu, 11 Sep 2014 14:03:06 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d="",e="onl
ine_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we<<< skipped >>>
GET /stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytesGIF89a.............!.......,...........D..;..
GET /stat.php?id=1253024109&web_id=1253024109 HTTP/1.1
Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s19.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:12 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:12 GMT
Expires: Thu, 11 Sep 2014 15:18:12 GMT1f7a..(function(){function l(){this.c="1253024109";this.O="z";this.K="
";this.H="";this.J="";this.o="1410443292";this.M="z8.cnzz.com";this.I=
"";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_cnz
z_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,c){
try{var b=[];b.push("siteid=1253024109");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}<<< skipped >>>
GET /img/gif008.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;....
GET /img/lhr.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid<<< skipped >>>
GET /img/js.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:34 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.<<< skipped >>>
GET /img/2014052276129177.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aX..................!..copyright. 1996 Charles H. Tupper All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;....
GET /img/046bt.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..<<< skipped >>>
GET /img/icon.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.
font>....
GET /img/zs.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.941pojie.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc<<< skipped >>>
GET /img/下载.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET<html><head><title>Error</title></head>&
lt;body>........................</body></html>..
..
GET /img/top.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:47 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......F......:\.....bKGD..............pHYs..........
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1<<< skipped >>>
GET /img/bgtitle.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:48 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...<<< skipped >>>
GET /img/pic2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 431
Last-Modified: Mon, 02 Dec 2013 05:46:13 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:05 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytesGIF89aP.........eee000...........................e...00...0...........
.......................................!..Powered by AFEI.!.....S.,...
.P......` .di.h.....p,.tm.x..|....a..._..1i,...&3.\2...v{.-...xL.s.g.b
-h...5......;.=g......".......m......................m..............."
.........................".......m..............."..w.....u.n..m......
....".....H......*.Q.....#J.H.b...3j..Q... C..I......9.\)b...0c..I....
8[........;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2
014 13:48:05 GMT..Content-Type: image/gif..Content-Length: 431..Last-M
odified: Mon, 02 Dec 2013 05:46:13 GMT..Connection: keep-alive..Keep-A
live: timeout=5..Expires: Fri, 12 Sep 2014 13:48:05 GMT..Cache-Control
: max-age=86400..Accept-Ranges: bytes..GIF89aP.........eee000.........
..................e...00...0..........................................
........!..Powered by AFEI.!.....S.,....P......` .di.h.....p,.tm.x..|.
...a..._..1i,...&3.\2...v{.-...xL.s.g.b-h...5......;.=g......".......m
......................m...............".........................".....
..m..............."..w.....u.n..m..........".....H......*.Q.....#J.H.b
...3j..Q... C..I......9.\)b...0c..I....8[........;....
GET /img/pic1.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 428
Last-Modified: Fri, 16 Jan 2009 08:10:47 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:06 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytesGIF89a.......f..3...33.......................................!..NETSCA
PE2.0.....!..Powered by AFEI.!.......,.............I........08bX....d.
n...CS.3......_..`..H..H\8....)...S.b.UX.....(...r.L....tb]&"......#..
.o.V.a..D..o.V.a..........D..o.V.a..........D...........!.......,.....
........I........08bX....d.n...CS.3......_..`..H..H\8....).:[email protected]...
x ..........D.| .#.u.a....n~D..[....n..........D..[...n..........D....
.......;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2014
13:48:06 GMT..Content-Type: image/gif..Content-Length: 428..Last-Modi
fied: Fri, 16 Jan 2009 08:10:47 GMT..Connection: keep-alive..Keep-Aliv
e: timeout=5..Expires: Fri, 12 Sep 2014 13:48:06 GMT..Cache-Control: m
ax-age=86400..Accept-Ranges: bytes..GIF89a.......f..3...33............
...........................!..NETSCAPE2.0.....!..Powered by AFEI.!....
...,.............I........08bX....d.n...CS.3......_..`..H..H\8....)...
S.b.UX.....(...r.L....tb]&"......#...o.V.a..D..o.V.a..........D..o.V.a
..........D...........!.......,.............I........08bX....d.n...CS.
3......_..`..H..H\8....).:[email protected] ..........D.| .#.u.a....n~D..[..
..n..........D..[...n..........D...........;..
GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:27 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...<<< skipped >>>
GET /css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.<<< skipped >>>
GET /img/zsf.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:32 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]<<< skipped >>>
GET /img/jbc.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:38 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................<<< skipped >>>
GET /img/gua.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................<<< skipped >>>
GET /css/style.css HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.<<< skipped >>>
GET /img/gif008.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;....
GET /img/lhr.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:47 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid<<< skipped >>>
GET /img/zsf.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:50 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]<<< skipped >>>
GET /img/2014052276129177.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aX..................!..copyright. 1996 Charles H. Tupper All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;....
GET /img/046bt.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..<<< skipped >>>
GET /img/icon.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.
font>....
GET /img/zs.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.lszwg.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc<<< skipped >>>
GET /img/下载.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:49:01 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET<html><head><title>Error</title></head>&
lt;body>........................</body></html>..
..
GET /img/top.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:01 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR.......F......:\.....bKGD..............pHYs..........
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1<<< skipped >>>
GET /img/logo.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.<<< skipped >>>
GET /img/bgtitle.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...<<< skipped >>>
GET /img/bgheader.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%<<< skipped >>>
GET /img/bgh.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..<<< skipped >>>
GET /img/1gg.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...<<< skipped >>>
GET /img/logo.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285
HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:05 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NETGIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.<<< skipped >>>
GET /9.gif?abc=1&rnd=1036514576 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=d76edc3f; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:05 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkh
wCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.m
mstat.com..Set-Cookie: sca=d76edc3f; path=/; domain=.cnzz.mmstat.com..
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285; expires=Sun,
08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com..Location: htt
p://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: T
hu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache..Pragma: no-cach
e..GIF89a.............!.......,...........L..;....
GET /9.gif?abc=1&rnd=2071775127 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..
GET /wpa/images/group.png HTTP/1.1
Accept: */*
Referer: hXXp://jc.941pojie.com/jiaqun.htm
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:48:00 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:48:00 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)<<< skipped >>>
GET /wpa/images/group.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:48:01 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:48:01 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)<<< skipped >>>
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Connection: Keep-Alive
Host: pcookie.cnzz.com
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;....
GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..
GET /9.gif?abc=1&rnd=1532175039 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; cna=FZaYDIcbkhwCAcGK9OeiMQ4z
HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:07 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: sca=d8a48a1a; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cacheGIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:07 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: sca=d8a48a1a;
path=/; domain=.cnzz.mmstat.com..Set-Cookie: atpsida=f1a0a2f56ddeb4f42
9ed04e4_1410443287; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domai
n=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZa
YDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-C
ontrol: no-cache..Pragma: no-cache..GIF89a.............!.......,......
.....L..;..
GET /core.php?web_id=5076676&show=pic2&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 14:03:04 GMT2f1..!function(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d
="",e="online_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:04 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:04 GMT..Expires: Thu, 11 Sep 2014 14:03:04 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d="",e="onl
ine_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we<<< skipped >>>
GET /core.php?web_id=3325108&show=pic1&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 14:03:05 GMT2f1..!function(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d
="",e="online_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:05 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:05 GMT..Expires: Thu, 11 Sep 2014 14:03:05 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d="",e="onl
ine_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we<<< skipped >>>
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.vmp0
`.vmp1
.reloc
t$(SSh
~%UVW
u$SShe
Vh.OG
VWh.OG
[email protected]
!h.OG
w]h.OG
kernel32.dll
ole32.dll
hXXp://jc.941pojie.com/tc.txt
Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
winxnse.exe
D:\winxnse.exe
wscntfo.exe
D:\wscntfo.exe
`.data
}~/%D(
.;6 (&%
1<76 '&
1=;;6 )%#
<;76 )%#
=<<7 ))%
=<<77 '%
=<<76 ))##
==<;7 '##
=<;76 ))##
=<<6 )'#
=<;76 ))#
==<;66 )'#
=<<66 (%
e{TP.cda8U#ex'B-n}
MSVBVM60.DLL
user32.dll
5i.Id(HE
~32.bd~
.sKpK
.soAw?
.qT3<
D:\wscntmx.exe
__MSVCRT_HEAP_SELECT
KERNEL32.dll
USER32.dll
ShellExecuteExA
SHELL32.dll
GetCPInfo
@.reloc
<4,$?7/'
(3-!0,1'8"5.*2$
ADVAPI32.dll
WS2_32.dll
RegCloseKey
RegOpenKeyExA
RegSetKeySecurity
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
RegOpenKeyA
WinExec
ExitWindowsEx
MSVCRT.dll
ackpw.dll
SetImageFileKey
SOFTWARE\Microsoft\Windows NT\CurrentVersion
wininet.dll
C:\log.pif
ShellExecuteA
Shell32.dll
SYSTEM\CurrentControlSet\Services\%s\Parameters
RegOpenKeyEx(Svchost)
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
m32\svchost.exe -k krnlsrvc
%SystemRoot%\Syste
SYSTEM\CurrentControlSet\Services\%s
Rundll32 %s,RunUninsta3l
\lockmedia.tmp
hXXp://
%u MB
%s SP%d
%d.%d.%d.%d
GetProcessHeap
GET / HTTP/1.1
Host: %s:%d
Host: %s
User-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0; hXXp://VVV.baidu.com/search/spider.html)
GET %s HTTP/1.1
Referer: hXXp://%s
GET %s?=%d HTTP/1.1
Mozilla/5.0 (compatible; Baiduspider/2.0; hXXp://VVV.baidu.com/search/spider.html)
User-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0; hXXp://VVV.baidu.com/search/spider.html)
#%d<<<<<I@C<<<<<%s!
4!4,41474>4{4> >(>8>=>
%s\hao123_res.tmp
%s\ack%cpw.dll
D:\qudongrensheng.dat
WinHttp.WinHttpRequest.5.1
.aspack
.adata
.xqrq
.pH`X|
.YON=
p*.LIAt
5].NQg
=.cw| r\
C @Qb%[email protected]
l(8i?ZiDf\.SQ
%C*pig
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
comctl32.dll
gdi32.dll
msimg32.dll
msvcrt.dll
msvfw32.dll
hXXp://VVV.eyybc.com
\skinh.she
M.GG^
%s T5
]E4%F(
.Funr
.yyw'
%sX@:`
J|.jv
p4%xcEm
.Jr1Z
7.YT"
.Uf!0
!a%U}
[I(3/#N0.bd
j"%u=w
q%Xn`
@|H.NI
.wdd!
S|%u4
5.ff)
;)?/\%~|/
U%D?~;
l2.Ue
9%crU
XKw-k}
zx/%FN[
LY.eo
z{.Do%s=\RI
}j%c%Y)
Rx.GR
4o#.dM
IeS`%C
[n 4\.UY
,4.qO,
gQ'.Io
%cLur?
s%DHB
]I%%X
I %d)
.aEd(
Õ6m*
5r.US
:mD].tB
fJ.WM_
fTpe
.LLbX
f%fUZ
.fOuV12
*_.dC
&-N}<
({?.cQmR>o2.YN>
.Cqx~c
.`.Qw
.Onwj
Tn&.hL
**.dU
%s;7*
0%x@w
%C^L:
CX%xm
!n]%x
%X,Cr
*.Ea]S
Q.CGo
tn!ay%F
2.kKX
Avi.CT
xhZ_6%U
%SY!8i
&.PFy{xhsG.qmf
5.ZrW
%Ucda
n.BjCw
.um ZZE7L
/^p%u$
I.NoQY
zu.ew
D/.nT
z.LP"
.IRIx
"%Sh9
&;%sUwa
kBS%dR
SetClientCertificate
jc.941pojie.com/jiaqun.htm
VVV.941pojie.com
VVV.lszwg.com
F%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
2,iphlpapi.dll
SHLWAPI.dll
MPR.dll
VERSION.dll
WININET.dll
%x.tmp
.PAVCException@@
.PAVCNotSupportedException@@
.PAVCFileException@@
(*.prn)|*.prn|
(*.*)|*.*||
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
Kernel32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
: %d]
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
out.prn
%d.%d
%d / %d
%d/%d
Bogus message code %d
(%d-%d):
%ld%c
(*.htm;*.html)|*.htm;*.html
VVV.dywt.com.cn
.PAVCOleException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCOleDispatchException@@
.PAVCArchiveException@@
zcÁ
acb8a7eb43e1abc8ed3.exe
c:\%original file name%.exe
#include "l.chs\afxres.rc" // Standard components
UnhookWindowsHookEx
comdlg32.dll
GetViewportExtEx
.cJK`
OffsetViewportOrgEx
GDI32.dll
$p.tS&
?.QVU]9
;O.oa
oledlg.dll
}o%saW
8y%F'
w%s8,
5N
-%F;1
v&Qi%C
%5scb
.pE_4
h}.Hg
ZL2!g%D
%uK;zZ
5 `%Cj~,_h2E%q
&]""9 }$
L.pGE(*
L>y
.EXD#-/
$q.xs
s.Wrl
*&%$#$(*)(/&.-,
-(%.*,#/
keYO
bhX.Udl?W
!F.YrwE
50%x{/).yNUt
{sR>%X2 O Sb
a$#&.Lex
?G!%C
.uL`E
g1 .jb
4:%xyS
S .iQ;
]/].]-],] ]
feF%uS[/V,
%s >2
%SA4/
@Ô~l
g9.Yn
%.Enm
.GL s
C%Ds\
%S-3=
wZ]%Fzau
-2} 3G%
%cZM9!
u .tD
a isSh
=%S;u:
.DQt%,
)-N}JeQ
%3-iI}
&Bh%C
_%x&rj
/9Hh%F
#Ig%S
.Mq-D
0v4%c
N%sE=2
I J@)%S
xH.jka
c.gU5
.QnK)
_.AG)
*.Vl {).skB
fkC%D
.qK u
.BA *
.pb%3<
r_i%D
uPO%x
C].Ti
%P%f'
(%%sP
CF%c'd
>o_%uCfD
%xl__
"w%sT
Gx>c%s&
w&.StX
Bj%Xu
c`EAy%C
%u 8 <G
)P%Xq
P;D .Cs
ca)%c
uT%1U:
/- .Qd
vI%D]
7 %xlT
Cmd3&
~ p;.Nm
u'w%c<#'
%Ud5E
0m.Eb_
&.uO[
G%c }
.Vm?<
.hoK}2`
.lty,
bs%FPL
#%cR$
l .Mm
:Um%S
.kUY"
8 _;]\2
)%u(y
%cNX~
%f) a
O7V%S
2< ;.IS
ZX.Dq
k/v%X
%x `f
ßQ?%
%D Sw% 4$@
="D%s\
.CPNt
jÜ[
%7u<X(t
)%X1eA
l:%uzZP[U
P.VLA
Z-bq%F~
kn%x@
0.aX|D
[ .rK
.JjP0 ebC
i"$#%F
3m%c'M
?qP%S
uDy~)E%d
b.hL2
3A& %%x
lk ]Q.aJW
%Fw~byj
.nER'
j<%S]
T<.Ieb
.CW!X
1RUH.ly%
?%D L
%c'X(
4.Fz .q
UOrH-Kd}
uWCzV%D-x
2`L*%Uw -
!i-8}
%0s~'
.oL:)
%DNjCz
.zm4d
Tc@%D
.OE A$
<# %c
*.qmj,Z
PW!%U
`T.Le
76543:98
k/%d(
.6.HK
(.eQm
}
s.jXd
cswQw.Er
WINSPOOL.DRV
GetViewportOrgEx
OLEAUT32.dll
WINMM.dll
bHF-s.RW
.pPQX
&(/*'[0?
,./%x
.YIivz
.Gq#k.~9
-6.Ks
WEBoa
g%.fN
/0%6U|
Q.ZKS
`.wDg
*O%dgXMH
0].fC_
=3xc%C
q%ug^/ER
.,%S}{//n.ZD
*(.ut
P\RSsh
x|Kp
</`~.GYf
gVrpm%x
%xQ.9
%X$V&
.qm*SV
G.ZB5X
"I'.Zy
ScaleViewportExtEx
|q.ig
.PSFS
K>lA.mGY
COMCTL32.dll
SetWindowsHookExA
GetKeyState
.cM$\,
CreateDialogIndirectParamA
SetViewportExtEx
SetViewportOrgEx
360.cn
hosts2.exe
6.1.7601.17514 (winsp1_rtm.101119-1850)
Rasmedia.dll
Microsoft Windows Operating System
6.1.7601.17514
4.20.0
Uninstall.exe
1, 0, 6, 6
SkinH_EL.dll
1.0.0.0
(hXXp://VVV.eyuyan.com)
(*.*)
%original file name%.exe_464_rwx_007BE000_00001000:
GetKeyState
.cM$\,
CreateDialogIndirectParamA
SetViewportExtEx
SetViewportOrgEx
iexplore.exe_1688:
%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512
wscntmx.exe_496:
.text
`.data
.rsrc
@.vmp0
`.vmp1
.reloc
}~/%D(
.;6 (&%
1<76 '&
1=;;6 )%#
<;76 )%#
=<<7 ))%
=<<77 '%
=<<76 ))##
==<;7 '##
=<;76 ))##
=<<6 )'#
=<;76 ))#
==<;66 )'#
=<<66 (%
attrib -r -s -h %windir%\system32\drivers\etc\hosts.ics
attrib -r -s -h %windir%\system32\wbem\window\winxp.ics
#vb6chs.dll
%Program Files%\VB
\VB6.OLB
advapi32.dll
RegCloseKey
RegCreateKeyA
RegOpenKeyA
VBA6.DLL
e{TP.cda8U#ex'B-n}
MSVBVM60.DLL
user32.dll
5i.Id(HE
~32.bd~
.sKpK
.soAw?
.qT3<
kernel32.dll
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
Microsoft.XMLHTTP
hXXp://jc.941pojie.com/cj.txt
%System%\drivers\etc
%System%\drivers\etc\hosts
c:\windows\system32\drivers\etc\hosts
c:\windows\system32\drivers\etc\hosts.ics
c:\a.bat
c:\b.bat
zhaosf.com
Adodb.Stream
360.cn
windows
hosts2.exe
wscntmx.exe_496_rwx_0041F000_00001000:
MSVBVM60.DLL
user32.dll
svchost.exe_1368:
.text
`.data
.rsrc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
RPCRT4.dll
NETAPI32.dll
ole32.dll
ntdll.dll
RegCloseKey
RegOpenKeyExW
GetProcessHeap
NtOpenKey
svchost.pdb
\PIPE\
Software\Microsoft\Windows NT\CurrentVersion\Svchost
\Registry\Machine\System\CurrentControlSet\Control\SecurePipeServers\
5.1.2600.5512 (xpsp.080413-2111)
svchost.exe
Windows
Operating System
5.1.2600.5512
wscntmx.exe_496_rwx_00426000_00001000:
.soAw?
.qT3<
kernel32.dll
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):
cacls.exe:504
cacls.exe:1552
cacls.exe:1460
cacls.exe:1636
cacls.exe:480
attrib.exe:308
attrib.exe:1676
attrib.exe:340
attrib.exe:828
qudongrensheng.dat:1552 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\b.bat (255 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cj[1].txt (5527 bytes)
%System%\drivers\etc\hosts.ics (18190 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
C:\a.bat (356 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\style[1].css (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (22591 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (3978 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (8891 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[2].gif (20562 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (1004 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (30383 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\941pojie[1].htm (1595 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[2].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgnav[1].gif (853 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (247 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\zs[1].jpg (49159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (2857 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[3].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1].png (362 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\046bt[1].gif (2605 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (14652 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (28985 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[3].gif (1871 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1].htm (1777 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[2].png (28003 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gg[1].png (5593 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[1].png (29443 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\top[1].png (9019 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (745 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (4402 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[1].gif (22469 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgheader[1].gif (742 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bgtitle[1].gif (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\jbc[1].gif (28161 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (2782 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[2].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\swz[1].gif (9999 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\jbc[1].gif (32881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (1587 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (1599 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[1].gif (25772 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[3].gif (37248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\zs[1].jpg (37417 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\top[1].png (9091 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\logo[1].gif (2329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (35465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jiaqun[1].htm (256 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (1765 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (32993 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (22637 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swz[1].gif (9253 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[2].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[1].gif (38279 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (38889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (1506 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (10189 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\js[1].gif (34828 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[2].gif (42863 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[1].php (1475 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[2].txt (330 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (2615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[3].php (1177 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[1].gif (32715 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[2].gif (853 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\046bt[1].gif (2688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (4300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (442 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[1].gif (2665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gg[1].png (10352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (916 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[2].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\hao123_res.tmp (35 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"wscntmx" = "D:\\wscntmx.exe" - Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
127.0.0.1 localhost - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.