Gen.Variant.Strictor.25651_4d16c46a86

by malwarelabrobot on September 12th, 2014 in Malware Descriptions.

HEUR:Trojan.Win32.Generic (Kaspersky), Gen:Variant.Strictor.25651 (B) (Emsisoft), Gen:Variant.Strictor.25651 (AdAware), Backdoor.Win32.Farfli.FD, Trojan-PSW.Win32.MSNPassword.FD, Trojan.Win32.FlyStudio.FD, Trojan.Win32.IEDummy.FD, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan, Backdoor


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 4d16c46a8633eacb8a7eb43e1abc8ed3
SHA1: 14e980eef7ebd62f31889cfa335b14e93f59e297
SHA256: 40bb28de749d30c3188d227e6b3f171ce40831e87930b8f6fb1415f6dbab4021
SSDeep: 24576:a/DBjBbgRhn04iOMzl3TEjr/bMNlB V hawK8jSJwriXIbsF5x/PouH5yMAUJDei:a/FBbFRjabMVbxKESJ iYWpgUcmJQDm
Size: 1789952 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2014-06-06 10:57:06
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan-PSW. Trojan program intended for stealing users passwords.

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

cacls.exe:504
cacls.exe:1552
cacls.exe:1460
cacls.exe:1636
cacls.exe:480
attrib.exe:308
attrib.exe:1676
attrib.exe:340
attrib.exe:828
qudongrensheng.dat:1552

The Trojan injects its code into the following process(es):

wscntmx.exe:496
%original file name%.exe:464

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process wscntmx.exe:496 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

C:\b.bat (255 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cj[1].txt (5527 bytes)
%System%\drivers\etc\hosts.ics (18190 bytes)
%System%\drivers\etc\hosts (17655 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
C:\a.bat (356 bytes)

The process %original file name%.exe:464 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\style[1].css (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (22591 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (3978 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (8891 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[2].gif (20562 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (1004 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (30383 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\941pojie[1].htm (1595 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[2].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgnav[1].gif (853 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (247 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\zs[1].jpg (49159 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (2857 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (511 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[3].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1].png (362 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\046bt[1].gif (2605 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (14652 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (28985 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[3].gif (1871 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1].htm (1777 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[2].png (28003 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gg[1].png (5593 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[1].png (29443 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\top[1].png (9019 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (745 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (4402 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[1].gif (22469 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (753 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgheader[1].gif (742 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bgtitle[1].gif (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\jbc[1].gif (28161 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (2782 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[2].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\swz[1].gif (9999 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\jbc[1].gif (32881 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (1587 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (1599 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[1].gif (25772 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[3].gif (37248 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (409 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\zs[1].jpg (37417 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\top[1].png (9091 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\logo[1].gif (2329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (35465 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jiaqun[1].htm (256 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (1765 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (32993 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (22637 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swz[1].gif (9253 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\style[1].css (1911 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[2].gif (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[1].gif (38279 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (38889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (1506 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (205 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (10189 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic2[1].gif (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1] (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\js[1].gif (34828 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[2].gif (42863 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[1].php (1475 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bgheader[1].gif (1 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[2].txt (330 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gif008[1].gif (565 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (2615 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[3].php (1177 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (428 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[1].gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[1].gif (32715 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[2].gif (853 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1] (1441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\046bt[1].gif (2688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\2014052276129177[1].gif (832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (4300 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (442 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[1].gif (2665 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gg[1].png (10352 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (916 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[2].gif (43 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1] (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][2].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (0 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (0 bytes)

The process qudongrensheng.dat:1552 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\hao123_res.tmp (35 bytes)

Registry activity

The process cacls.exe:504 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "99 35 8F 77 E9 28 CC 57 64 E9 3C 07 CB 74 86 66"

The process cacls.exe:1552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B9 43 B5 F9 BC 42 A7 E0 B2 AA 63 DE D8 63 E8 C2"

The process cacls.exe:1460 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3E 19 A1 39 3C 61 68 83 F9 E2 90 70 D3 60 19 72"

The process cacls.exe:1636 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7C B8 46 53 AB 01 F3 D1 C5 0C 1D 4E FE 63 9A 36"

The process cacls.exe:480 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7A 9E A6 D4 97 FC 97 60 3E 3A 0D 77 D2 19 E8 C8"

The process attrib.exe:308 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1A 2C A9 DF E7 BC DC 9B 76 79 55 A3 F7 50 12 E1"

The process attrib.exe:1676 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "22 6F B8 45 2C 72 5C 57 E9 96 D8 A3 FD 78 16 36"

The process attrib.exe:340 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "32 C8 77 B7 27 3B A7 62 88 8F 59 0F 45 A9 4C 67"

The process attrib.exe:828 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F1 88 A4 9C 06 D1 2A 1A AB 3E CC 5D 67 94 63 64"

The process wscntmx.exe:496 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "83 CF D0 25 8B 15 56 65 23 1D 4E 30 33 4E 4B E3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"wscntmx" = "D:\\wscntmx.exe"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process %original file name%.exe:464 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BC BE 09 5E 69 3B 7B 32 E7 66 55 4C D7 D2 A9 FD"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Internet Explorer]
"iexplore.exe" = "Internet Explorer"

[HKCU\Software\Microsoft\Multimedia\DrawDib]
"vga.drv 1276x846x32(BGR 0)" = "31,31,31,31"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process qudongrensheng.dat:1552 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "24 51 D5 EC 37 C5 D8 77 A4 E7 61 09 72 EA B2 95"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\System\CurrentControlSet\Services\WinHelp32\Parameters]
"ServiceDll" = "%System%\ackwpw.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"krnlsrvc" = "WinHelp32"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\System\CurrentControlSet\Services\WinHelp32\Parameters]
"seRVicemAIN" = "RunDllEntry"

[HKLM\System\CurrentControlSet\Services\WinHelp32]
"Description" = "Windows Help System for X32 windows desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Dropped PE files

MD5 File path
623cdebf1ed65aaba993745ad979881f c:\WINDOWS\system32\ackwpw.dll

HOSTS file anomalies

The Trojan modifies "%System%\drivers\etc\hosts" file which is used to translate DNS entries to IP addresses.
The modified file is 65537 bytes in size. The following strings are added to the hosts file listed below:

162.211.182.39 988.pa579.com
162.211.182.39 999.23dpw.com
162.211.182.39 www.jyjyh.com
162.211.182.39 tuiguang.8msm.com
162.211.182.39 fe.yueworld.net
162.211.182.39 920aa.changyc.com
162.211.182.39 xb.qicaimofang.com
162.211.182.39 www.yx003.com
162.211.182.39 www1.pkokok.com
162.211.182.39 www.75945.com
162.211.182.39 www.lpf010.com
162.211.182.39 www.6000pk.com
162.211.182.39 9pk.2766161.com
162.211.182.39 www.zhaof7.com
162.211.182.39 www.cqhr.org
162.211.182.39 www.ddzhe.com
162.211.182.39 pk789.52fanfou.com
162.211.182.39 160uc.com
162.211.182.39 www.1nhh.com
162.211.182.39 www.52sol.com
162.211.182.39 www.cpu500.com
162.211.182.39 www.2381sfcq.com
162.211.182.39 www.uc37.com
162.211.182.39 www.98pk97.com
162.211.182.39 www.hbcyly.com
162.211.182.39 haosf.lfweibo.com
162.211.182.39 cq.kgfanli.com
162.211.182.39 www.999yc.com
162.211.182.39 www1.jjj.com
162.211.182.39 zhaosf.acrmbs.com
162.211.182.39 www.uc900.com
162.211.182.39 www2.jjj.com
162.211.182.39 www3.jjj.com
162.211.182.3 1711ok.zz135.com
162.211.182.39 w13518.hr.jw.tczj.net
162.211.182.39 zhaofu7.com
162.211.182.39 tuiguang.592097.com
162.211.182.39 v.yueworld.net
162.211.182.39 zhaosf.ofyn.net
162.211.182.39 dk.qicaimofang.com
162.211.182.39 578101.com
162.211.182.39 www.578101.com
162.211.182.39 www.126disk.com
162.211.182.39 tui99.592097.com
162.211.182.39 tui99.8msm.com
162.211.182.39 dd.guidawang.com
162.211.182.39 bb.fushilu.com
162.211.182.39 www.zhaofu7.com
162.211.182.39 www.baiduzhaokf.com
162.211.182.39 www.haosf.com
162.211.182.39 www.jsl-cn.com
162.211.182.39 www.88858.com
162.211.182.39 www.heshilurong.com
162.211.182.39 www.168fm.com
162.211.182.39 www.artobrain.com
162.211.182.39 wwv.jb345.com
162.211.182.39 www.zhaosf9999.com
162.211.182.39 www.uc1000.com
162.211.182.39 www4.jjj.com
162.211.182.39 www.uc900.com
162.211.182.39 www.uc900.com
162.211.182.39 www.cctv-kowann.com
162.211.182.39 www5.jjj.com
162.211.182.39 www.artobrain.com
162.211.182.39 www.jxytqz.com
162.211.182.39 www.as9z.com
162.211.182.39 pk789.52fanfou.com:81
162.211.182.39 36cq.dg8681.com:3636
162.211.182.39 www.444yx.com
162.211.182.39 www.993yx.com
162.211.182.39 jjj.com
162.211.182.39 www1.99s.com
162.211.182.39 www2.99s.com
162.211.182.39 99s.com
162.211.182.39 www99s.com
162.211.182.39 www.uc1000.com
162.211.182.39 2410.eodfmr.cn
162.211.182.39 www.www99s.com
162.211.182.39 www.woool99s.com
162.211.182.39 www3.99s.com
162.211.182.39 9k1.pa579.com
162.211.182.39 www1.zhaosf.com
162.211.182.39 www2.zhaosf.com
162.211.182.39 www3.zhaosf.com
162.211.182.39 www4.zhaosf.com
162.211.182.39 www5.zhaosf.com
162.211.182.39 new.fa111.com
162.211.182.39 www.zhaosf.com
162.211.182.39 www4.99s.com
162.211.182.39 www5.99s.com
162.211.182.39 www.09445.com
162.211.182.39 www.cdxxzs.com
162.211.182.39 www.angelsimple.cn
162.211.182.39 www.lida00.cn
162.211.182.39 www.zbzishen.com
162.211.182.39 www.86jiewang.cn
162.211.182.39 www.itcr.cn
162.211.182.39 www.99u.net.ru
162.211.182.39 xp.wzca.com.cn
162.211.182.39 www.wan345.com
162.211.182.39 dns.521jjj.com
162.211.182.39 www.525uc.com
162.211.182.39 www.1cq.com
162.211.182.39 www.jjj.com
162.211.182.39 www.99s.com
162.211.182.39 www.gm005.com
162.211.182.39 www.68kf.com
162.211.182.39 wwk.astbw.com
162.211.182.39 zz.sf163.com
162.211.182.39 www.sotrip.com
162.211.182.39 33k.pa579.com
162.211.182.39 www.555sf.com
162.211.182.39 www.66hst.com
162.211.182.39 66hst.com
162.211.182.39 www.xin45.com
162.211.182.39 xin45.com
162.211.182.39 www.zhaocq.com
162.211.182.39 1.52yanzheng.sinaapp.com
162.211.182.39 www.175sf.com
162.211.182.39 www.yxyhx.com
162.211.182.39 www.168fm.com
162.211.182.39 habourbiotech.com
162.211.182.39 www.pydwlm.com
162.211.182.39 www.ux99.com
162.211.182.39 www.hn17173.net
162.211.182.39 www.5s98.com
162.211.182.39 www.880s.com
162.211.182.39 www.118uc.com
162.211.182.39 www.zf777.com
162.211.182.39 81.2381f.com
162.211.182.39 www.njkaidu.com
162.211.182.39 www.9szf.com
162.211.182.39 www.999zsf.com
162.211.182.39 www.85zf.com
162.211.182.39 www.951pk.com
162.211.182.39 www.851pk.com
162.211.182.39 988.pa579.com
162.211.182.39 ad.97uu.com
162.211.182.39 www.i8pk.com
162.211.182.39 www.sf996.com
162.211.182.39 www.0579st.com
162.211.182.39 www.mc1314.com
162.211.182.39 gm016.comforum.php
162.211.182.39 www.whsfzx.com
162.211.182.39 dd.sh-tongy.com
162.211.182.39 111.kaihu365.com
162.211.182.39 www.dddgm.com
162.211.182.39 www.ok126.net
162.211.182.39 www.wanshituliao.com
162.211.182.39 www.zaxue.net
162.211.182.39 www.4006517008.com
162.211.182.39 www.tcrhy.com
162.211.182.39 www.vdisk.cnyy6018
162.211.182.39 www.sf383.com
162.211.182.39 www.001gm.net
162.211.182.39 www.006it.com
162.211.182.39 www.gm5555.com
162.211.182.39 www.yxyhx.com
162.211.182.39 h.chinagiftidea.com
162.211.182.39 www.3jidi-gz.com
162.211.182.39 www.100gczg.com
162.211.182.39 1.consultants-sp.com
162.211.182.39 haosf.lgknow.com
162.211.182.39 www.vdisk.cnchuanqiwangzhan
162.211.182.39 www.z0137cx.comzm6x5
162.211.182.39 habourbiotech.com
162.211.182.39 www.satsalt.com
162.211.182.39 tg1.37.com?uid=1421131
162.211.182.39 pi.nuwa-mountain.org
162.211.182.39 www.jafdc.net
162.211.182.39 941pk.com
162.211.182.39 www.5iwowo.com
162.211.182.39 www.bonopt.com
162.211.182.39 xu.shandonghaofanyi.com
162.211.182.39 h.chinagiftidea.com
162.211.182.39 www.sxyish.comindex1.htm
162.211.182.39 www.jzdkfj.com
162.211.182.39 henuedu.cn
162.211.182.39 www.sdjialiang.com
162.211.182.39 www.10010cq.com
162.211.182.39 www.z0137cx.comkwcs
162.211.182.39 www.0512rc.net
162.211.182.39 www.dahanjg.com
162.211.182.39 www.ht-vision.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.jfy8rv.comzjp6bw
162.211.182.39 www.yxyhx.com
162.211.182.39 www.9uzg.com
162.211.182.39 www.gm667.com
162.211.182.39 www.znspyq.com9dzf7w
162.211.182.39 www.18-81.net
162.211.182.39 www.ht-vision.com
162.211.182.39 www.gmwly.com
162.211.182.39 user.qzone.qq.com5674167
162.211.182.39 t.qq.comchuanqisf8997
162.211.182.39 www.njjqgck.com
162.211.182.39 www.hkalu.com
162.211.182.39 www.60sf.com
162.211.182.39 www.pk123.com
162.211.182.39 www.52anzu.com
162.211.182.39 www1.52anzu.com
162.211.182.39 52anzu.com
162.211.182.39 www.sopojie.com
162.211.182.39 www1.sopojie.com
162.211.182.39 sopojie.com
162.211.182.39 www.wf22.com
162.211.182.39 xingyoufz.wwpan.com
162.211.182.39 www.36ok.com
162.211.182.39 www.32fa.com
162.211.182.39 wws.99acc.com
162.211.182.39 www.916cq.com
162.211.182.39 1711ok.sh77577.com
162.211.182.39 www.18uc.com
162.211.182.39 18uc.com
162.211.182.39 88pk.com
162.211.182.39 www.88pk.com
162.211.182.39 162.212.180.86
162.211.182.39 36ok.com
162.211.182.39 118.99.26.156
162.211.182.39 23.234.60.34
162.211.182.39 www.52anzu.net
162.211.182.39 www.77250.com
162.211.182.39 77250.com
162.211.182.39 www1.52anzu.net
162.211.182.39 tt.1kuv.com
162.211.182.39 www1.sopojie.comforum.php
162.211.182.39 www.33ok.com
162.211.182.39 916cq.com
162.211.182.39 91ww.91fu.com
162.211.182.39 www1.pk777.com
162.211.182.39 www.sf999.com
162.211.182.39 www.yeahooo.net
162.211.182.39 1.townhall.cn
162.211.182.39 www.bjjijiubao.com
162.211.182.39 1.xa1314.com.cn
162.211.182.39 www.yvwtjf.com/rkwwcq
162.211.182.39 www.stylepacking.com
162.211.182.39 www.cnfengye.com
162.211.182.39 www.zazgame.com
162.211.182.39 www.zrplay.com
162.211.182.39 www.yczdwj.com
162.211.182.39 www.zheyutegang.com
162.211.182.39 www.sf123.com
162.211.182.39 www.daqiandoor.com
162.211.182.39 www.77d8.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.liwenjie374.cn/yjall
162.211.182.39 www.wwesf.com
162.211.182.39 www.7988ok.com
162.211.182.39 www.shfengyi.com
162.211.182.39 pg.iflu.com.cn
162.211.182.39 www.gdtrane.com
162.211.182.39 www.scxlm.com
162.211.182.39 www.kisspk.com
162.211.182.39 www.cqxz.com.cn
162.211.182.39 www.kanonsh.com
162.211.182.39 www.gm1208.com
162.211.182.39 www.provoxav.com
162.211.182.39 dgdimei.com
162.211.182.39 www.cntzdh.com
162.211.182.39 www.xinchengyunshu.com
162.211.182.39 www.hanwise.com
162.211.182.39 www.xinchengyunshu.com
162.211.182.39 ygjm.gz2.hostadm.net
162.211.182.39 www.mfttj.com
162.211.182.39 www.shenqi.com
162.211.182.39 www.52345.com
162.211.182.39 81f.hao899.com
162.211.182.39 www.sf123.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.daqiandoor.com
162.211.182.39 www.941jb.com
162.211.182.39 2sogo.com
162.211.182.39 mobanbbs.com
162.211.182.39 91ww.555uc.com
162.211.182.39 8uc.haosf33.com
162.211.182.39 81f.hao979.com
162.211.182.39 www.99j.com
162.211.182.39 www.91ww.com
162.211.182.39 www.777uc.com
162.211.182.39 pk123.haosf321.com
162.211.182.39 pk123.92sou.com
162.211.182.39 www.xbkdq.com
162.211.182.39 66sf.77zhao.com
162.211.182.39 www.184pk.com
162.211.182.39 www.sf999.com
162.211.182.39 www.pk777.com
162.211.182.39 www.alfatoyota.com
162.211.182.39 mobanbbs.com
162.211.182.39 www.stbshg.com
162.211.182.39 www.daqiandoor.com
162.211.182.39 www.1cq.com/1cqlwg.htm
162.211.182.39 www.xbkdq.com
162.211.182.39 www.sf123.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.buyishijia.com
162.211.182.39 www.sf999.com
162.211.182.39 www.shenqi.com
162.211.182.39 www.52345.com
162.211.182.39 www.92045.com
162.211.182.39 92045.52yoyoo.com
162.211.182.39 92045.92450.com
162.211.182.39 pk123.haosf321.com
162.211.182.39 pk123.92sou.com
162.211.182.39 baidu.926uu.com
162.211.182.39 baidu.jw888.com
162.211.182.39 www.926.com
162.211.182.39 999.65zy.com
162.211.182.39 www.99j.com
162.211.182.39 www.945pk.com
162.211.182.39 8uc.haosf33.com
162.211.182.39 www.91ww.com
162.211.182.39 www.8uu.com
162.211.182.39 81f.hao883.com
162.211.182.39 81f.hao979.com
162.211.182.39 81f.hao899.com
162.211.182.39 www.81f.com
162.211.182.39 66sf.77zhao.com
162.211.182.39 www.nihao119.com
162.211.182.39 www.66sf.com
162.211.182.39 kkkfu.sylytz.com
162.211.182.39 83aa.sf078.com
162.211.182.39 521fu.9173uc.com
162.211.182.39 www.777uc.com
162.211.182.39 www.pk777.com
162.211.182.39 www.30ok-1.com
162.211.182.39 www.haocq.com
162.211.182.39 sf.haocq.com
162.211.182.39 www.1000ok.com
162.211.182.39 tg1.37wan.com
162.211.182.39 wvw.rq23.com
162.211.182.39 wvw.2013wan.com
162.211.182.39 wvw.9377z.com
162.211.182.39 mmm.wopaijs.com
162.211.182.39 www.yyy279.com
162.211.182.39 wvw.9377s.com
162.211.182.39 www.zhujiutx.com
162.211.182.39 www.hbwxkj.com
162.211.182.39 www.sh-chengshan.com
162.211.182.39 zhaosfcq.com
162.211.182.39 www.subpig.net
162.211.182.39 www.jlzcfx.com
162.211.182.39 www.66sf.com
162.211.182.39 www.cdxxlh.com
162.211.182.39 www.83uc.com
162.211.182.39 www.shjwd.com
162.211.182.39 www.jingming-sh.com
162.211.182.39 www.aerosun.cn
162.211.182.39 www.qdhd.com.cn
162.211.182.39 www.flyxg.com
162.211.182.39 www.zggljt.com
162.211.182.39 www.99mc.com
162.211.182.39 www.138zg.com
162.211.182.39 www.523zg.com
162.211.182.39 www.98zg.com
162.211.182.39 www.78zg.cn
162.211.182.39 www.99ting.cn
162.211.182.39 www.27zg.com
162.211.182.39 www.92sanduo.com
162.211.182.39 www.527zg.com
162.211.182.39 www.xstylxx.com
162.211.182.39 www.xrsd-water.com
162.211.182.39 www.tttjsq.com
162.211.182.39 www.y1995.com
162.211.182.39 www.883sf.com
162.211.182.39 sf123.com
162.211.182.39 changjing.759rsq.com
162.211.182.39 xinqing.kqgf69.com
162.211.182.39 www.xahdc.com
162.211.182.39 www.haotl.com
162.211.182.39 www.chinajin-hui.com
162.211.182.39 jingcai.edtiq6.com
162.211.182.39 www.fullkang.net.com
162.211.182.39 tanxian.u895.com
162.211.182.39 www.m526.com
162.211.182.39 www.majorsoul.com
162.211.182.39 xitong.vxtui.com
162.211.182.39 www.4006517008.com
162.211.182.39 changjing.pbbxy.com
162.211.182.39 wanjia.x9858.com
162.211.182.39 jiaoliu.s9275.com
162.211.182.39 sf225.com
162.211.182.39 www.haosf.com
162.211.182.39 www.tcrhy.com
162.211.182.39 www.001gm.net
162.211.182.39 cqdl321.com
162.211.182.39 www.b9jojo.com
162.211.182.39 www.9kf.com
162.211.182.39 www.sf138.com
162.211.182.39 www.628118.com
162.211.182.39 www.hezol.com
162.211.182.39 www.qjkutrgw.com
162.211.182.39 www.ashijia.com
162.211.182.39 www.1200sf.com
162.211.182.39 www.aarongj.com
162.211.182.39 www.53my.com
162.211.182.39 www.888cnc.com
162.211.182.39 www.sf3000.com
162.211.182.39 www.29u.in
162.211.182.39 www.96sf.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.sf800.com
162.211.182.39 www.77mxd.com
162.211.182.39 www.9uzg.com
162.211.182.39 www.sf999.com.ru
162.211.182.39 www.szmajsy.com
162.211.182.39 www.jptea.cn
162.211.182.39 521fu.52345uc.com
162.211.182.39 www.cqpk11.com
162.211.182.39 www.insdfjisd.com
162.211.182.39 www.828kk.com
162.211.182.39 www.irrchina.com
162.211.182.39 www.22nf.com
162.211.182.39 www.jiutianzs.com
162.211.182.39 www.103la.com
162.211.182.39 www.889ok.com
162.211.182.39 huanshou.8236r.com
162.211.182.39 www.1129f.com
162.211.182.39 345ye.861sf.com
162.211.182.39 www.861sf.com
162.211.182.39 861sf.com
162.211.182.39 www.sf985.com
162.211.182.39 www.bonopt.com
162.211.182.39 cq45.cn
162.211.182.39 www.cq45.cn
162.211.182.39 www.bgdtw.com
162.211.182.39 www.930t.com
162.211.182.39 www.tianhuao.com
162.211.182.39 www.99a.net.ru
162.211.182.39 www.hmyigou.com
162.211.182.39 www.fzjx.net
162.211.182.39 www.ez-max.net
162.211.182.39 www.zhuoranfm.com
162.211.182.39 www.ccadly.net
162.211.182.39 www.chinasysw.com
162.211.182.39 www.dyjkdd.com
162.211.182.39 www.cnbaoerte.com
162.211.182.39 www.sf895.com
162.211.182.39 www.joywei.com
162.211.182.39 www.yalincs.com
162.211.182.39 www.kkstar.com
162.211.182.39 www.949g.com
162.211.182.39 www.zhaosf.com.co
162.211.182.39 www.3000ok.com.cn
162.211.182.39 n813.com
162.211.182.39 uc88.com
162.211.182.39 qu45.com
162.211.182.39 www.aop9988.com
162.211.182.39 www.sdytgj.com
162.211.182.39 www.gzgien.com
162.211.182.39 www.chuanqige.com
162.211.182.39 51my8.com
162.211.182.39 www.99j.com.es
162.211.182.39 www.sf452.com
162.211.182.39 www.981sf.com
162.211.182.39 www.sf382.com
162.211.182.39 www.hldly.com
162.211.182.39 www.sf062.com
162.211.182.39 www.8345sf.com
162.211.182.39 www.sdfwesq.com
162.211.182.39 www.sjxt123.com
162.211.182.39 www.daqiandoor.com
162.211.182.39 www.125sf.com
162.211.182.39 www.xieqiyy.com
162.211.182.39 www.ldyeya.com
162.211.182.39 www.088sf.net
162.211.182.39 83so.com
162.211.182.39 www.sf421.com
162.211.182.39 www.4f920.com
162.211.182.39 www.tiaolou8.com
162.211.182.39 www.taocooler.com
162.211.182.39 www.wanpp.com
162.211.182.39 www.fhzsm.com
162.211.182.39 www.pt12319.com
162.211.182.39 www.hx-lace.com
162.211.182.39 klmy.cn.com
162.211.182.39 www.jiagao.net
162.211.182.39 76776.com
162.211.182.39 www.htwjcy.com
162.211.182.39 www.win757.com
162.211.182.39 www.hnjxzz.cn
162.211.182.39 www.xmdvip.com
162.211.182.39 swqzp.com
162.211.182.39 www.tungsten-moly.com
162.211.182.39 jingyan.986jj.com
162.211.182.39 www.xxf888.com
162.211.182.39 www.cnrsyy.com
162.211.182.39 www.txingzuo.com
162.211.182.39 www.ykmir.com
162.211.182.39 www.xjxianping.cn
162.211.182.39 www.web01.cn
162.211.182.39 www.yijiaedu.cn
162.211.182.39 vipxun.9uzg.com
162.211.182.39 dushisuanlafen.cn
162.211.182.39 www.zzyichen.com
162.211.182.39 www.cnnoblelight.com
162.211.182.39 klkemu.net
162.211.182.39 www.faith-forever.com
162.211.182.39 www.bopuai.cn
162.211.182.39 www.xzchuitou.cn
162.211.182.39 www.ccxbzk.cn
162.211.182.39 www.915788.com
162.211.182.39 www.sdxtcnc.com
162.211.182.39 www.sz-stv.com
162.211.182.39 www.fjoss.com
162.211.182.39 www.204sf.com
162.211.182.39 www.tech-sss.com
162.211.182.39 www.mywowpl.com
162.211.182.39 www.shi-yi.net
162.211.182.39 www.hzlyfashion.com
162.211.182.39 www.freeshu.com
162.211.182.39 www.chinatianmei.com
162.211.182.39 00pk.com
162.211.182.39 www.tqb88.com
162.211.182.39 4593.9kf.com
162.211.182.39 www.120yi.com
162.211.182.39 www.hdmchina.com
162.211.182.39 www.zzfuxi.com
162.211.182.39 www.sdicl.com
162.211.182.39 www.ebontec.com
162.211.182.39 www.3000oksf.com
162.211.182.39 www.shqing8.com
162.211.182.39 www.666mir.com
162.211.182.39 www.adchy.com
162.211.182.39 www.pyprint.com
162.211.182.39 www.56chuanqi.com
162.211.182.39 www.simicc.com
162.211.182.39 www.a5zg.com
162.211.182.39 www.szhcgroup.com
162.211.182.39 www.57ssy.com
162.211.182.39 www.qingzhou8.com
162.211.182.39 tt292.com
162.211.182.39 www.jiatianneiyi.com
162.211.182.39 www.leeed.com
162.211.182.39 www.20020505.com
162.211.182.39 www.kl-chem.com
162.211.182.39 www.tjzssd.com
162.211.182.39 www.nnhxjh.com
162.211.182.39 www.dwmir.com
162.211.182.39 www.kk519.com
162.211.182.39 www.chinanewhope.net
162.211.182.39 www.yalimei-group.com
162.211.182.39 www.jiulongbelt.com
162.211.182.39 aaa7.9uzg.com
162.211.182.39 www.dushisuanlafen.cn
162.211.182.39 www.cn0796.com
162.211.182.39 www.hnfengyuan.com
162.211.182.39 www.yixinghai.com
162.211.182.39 www.zgtjsteel.com
162.211.182.39 www.51disky.com
162.211.182.39 www.zhybbs.com
162.211.182.39 www.91kaixue.com
162.211.182.39 www.fyplay.com
162.211.182.39 www.wowidc.com
162.211.182.39 www.jiahongtex.com
162.211.182.39 www.diselife.com
162.211.182.39 www.yygdz.com
162.211.182.39 www.kexingco.com
162.211.182.39 www.88fb.com
162.211.182.39 www.botaofan.com
162.211.182.39 www.zzhdjx.cn
162.211.182.39 www.cntuliao.com
162.211.182.39 www.m5y6.cn
162.211.182.39 www.songzhilu.com
162.211.182.39 zhaopeng.net
162.211.182.39 www.xiayunfei.com
162.211.182.39 soyoesd.cn
162.211.182.39 www.523zg.com
162.211.182.39 regongjixie.com
162.211.182.39 www.mir87.com
162.211.182.39 chinachengyang.cn
162.211.182.39 www.dgguanglin.com
162.211.182.39 www.huayuebz.com
162.211.182.39 www.xxsw028.com
162.211.182.39 www.myppchina.com
162.211.182.39 www.gzsuper.com
162.211.182.39 www.txhtc.com
162.211.182.39 www.cdcx1956.com
174.128.248.72 www.yaliwood.com
162.211.182.39 www.flower024.com
162.211.182.39 www.5ttb.com
162.211.182.39 www.i193.com
162.211.182.39 www.shweiheng.com
162.211.182.39 www.65wt.com
162.211.182.39 u17766.com
162.211.182.39 www.600sf.com
162.211.182.39 52345.zzflt.com
162.211.182.39 www.baodaobike.com
162.211.182.39 199.hncgfw.com
162.211.182.39 www.56fabu.com
162.211.182.39 www.pt12319.com
162.211.182.39 pk.sydahe.com
162.211.182.39 cnpeishi.cn
162.211.182.39 www.2-55.com
162.211.182.39 sogou.turuyi.com
162.211.182.39 klmy.cn.com
162.211.182.39 www.cdfufu.com
162.211.182.39 www.bzydzs.com
162.211.182.39 www.dhl.gov.cn
162.211.182.39 www.81cq.com
162.211.182.39 www.sxfyxyq.com
162.211.182.39 111wt.com
162.211.182.39 81sf.com
162.211.182.39 44dy.com
162.211.182.39 30wy.com
162.211.182.39 999wg.net
162.211.182.39 915m.com
162.211.182.39 66kf.net
162.211.182.39 www.qs930.com
162.211.182.39 www.shutu.cc
162.211.182.39 sf666.75gm.com
162.211.182.39 www.kkksf.com
162.211.182.39 www.zhao3f.com
162.211.182.39 6cq.cc
162.211.182.39 u7u73.com
162.211.182.39 sf923.com
162.211.182.39 oryin.com
162.211.182.39 gm777.com
162.211.182.39 gm333.com
162.211.182.39 cseht.com
162.211.182.39 520f.com
162.211.182.39 258x.com
162.211.182.39 57ww.com
162.211.182.39 57591.com
162.211.182.39 33sf.com
162.211.182.39 sf509.com
162.211.182.39 803cq.com
162.211.182.39 25930.com
162.211.182.39 812315.com
162.211.182.39 11cq.cn
162.211.182.39 94ww.com
162.211.182.39 777wt.com
162.211.182.39 www.99mc.com
162.211.182.39 980cq.com
162.211.182.39 hdhjgs.com
162.211.182.39 51zzsf.com
162.211.182.39 0574k.com
162.211.182.39 wjlon.cn
162.211.182.39 d518.com
162.211.182.39 sf29.com
162.211.182.39 222sf.com
162.211.182.39 23qianbao.com
162.211.182.39 195ca.com
162.211.182.39 118967.com
162.211.182.39 10000ok.com
162.211.182.39 72cq.com
162.211.182.39 5zaoxie.com
162.211.182.39 555beian.com
162.211.182.39 55hj.com
162.211.182.39 45758.com
162.211.182.39 41345.com
162.211.182.39 258sf.com
162.211.182.39 9000sf.com
162.211.182.39 87sf.com
162.211.182.39 89946.com
162.211.182.39 88f.com
162.211.182.39 86rs.com
162.211.182.39 77yu.com
162.211.182.39 81592.com
162.211.182.39 74981.com
162.211.182.39 818wy.com
162.211.182.39 9826w.com
162.211.182.39 h7fefe4r.sf19.cn
162.211.182.39 45453.sf19.cn
162.211.182.39 www.myidc.cc
162.211.182.39 www.whygjt.com
162.211.182.39 www.nd-zk.com
162.211.182.39 haosf.com.cn
162.211.182.39 dtfy.fyplay.com
162.211.182.39 www.sf3000ok.com
162.211.182.39 www.145930.com
162.211.182.39 www.80ww.com
162.211.182.39 www.258x.com
162.211.182.39 www.sf509.com
162.211.182.39 www.tjklm.com
162.211.182.39 17sz.net
162.211.182.39 1.xa1314.com.cn
162.211.182.39 www.81sf.com
162.211.182.39 www.0663yh.com
162.211.182.39 whygjt.com
162.211.182.39 www.cc816.com
162.211.182.39 www.bohaomj.com
162.211.182.39 www.blbfg.com
162.211.182.39 jndd.com.cn
162.211.182.39 www.ba45.com
162.211.182.39 www.bjwztc.com
162.211.182.39 www.bangbangtuan.com
162.211.182.39 1.wzca.com.cn
162.211.182.39 www.51yygw.com
162.211.182.39 www.912kf.com
162.211.182.39 www.eduqc.com
162.211.182.39 www.ebssfp.com
162.211.182.39 www.dingfengtop.com
162.211.182.39 www.dc-superglue.com
162.211.182.39 www.daweilp.com
162.211.182.39 www.czacyq.com
162.211.182.39 www.cqxiexin.com
162.211.182.39 www.cltqgs.com
162.211.182.39 www.cnaxchem.com
162.211.182.39 www.chengdajc.com
162.211.182.39 www.cdztnt.com
162.211.182.39 www.chinawoollen.com
162.211.182.39 www.chinaenyu.com
162.211.182.39 www.ihc360.com
162.211.182.39 www.hrener.com
162.211.182.39 www.howelltoy.com
162.211.182.39 www.fzqmw.com
162.211.182.39 www.hongweimotor.com
162.211.182.39 www.gardenhn.com
162.211.182.39 www.fzghj.com
162.211.182.39 www.fhouse360.com
162.211.182.39 www.fdzyy.com
162.211.182.39 www.fujunsh.com
162.211.182.39 www.funkan.com
162.211.182.39 www.pxfangbao.com
162.211.182.39 www.pk138.com
162.211.182.39 www.oursuzuki.com
162.211.182.39 www.movfox.com
162.211.182.39 www.nbyongxiang.com
162.211.182.39 www.maoshanchem.com
162.211.182.39 www.longyundianli.com
162.211.182.39 www.linxiatravel.com
162.211.182.39 www.jhrace.com
162.211.182.39 www.jxytoys.com
162.211.182.39 www.kpaofeite.com
162.211.182.39 www.jiang456.com
162.211.182.39 www.szgargen.com
162.211.182.39 www.szelcc.com
162.211.182.39 www.sun-sand-sea.com
162.211.182.39 www.shzhuwang.com
162.211.182.39 www.ssbrakepad.com
162.211.182.39 www.shxianghao.com
162.211.182.39 www.shchenggang.com
162.211.182.39 www.quhi-tech.com
162.211.182.39 www.sh16pu.com
162.211.182.39 www.reach-way.com
162.211.182.39 www.sddzauto.com
162.211.182.39 www.yhszy.com
162.211.182.39 www.xinfengjixie.com
162.211.182.39 www.xiduanpress.com
162.211.182.39 www.xuyetrade.com
162.211.182.39 www.xaxhny.com
162.211.182.39 www.wzxiyin.com
162.211.182.39 www.wxlujia.com
162.211.182.39 www.usnaike.com
162.211.182.39 www.tyhzh.com
162.211.182.39 www.szhmxled.com
162.211.182.39 yaosf.net
162.211.182.39 www.zjyingguan.com
162.211.182.39 www.zzwzgn.com
162.211.182.39 www.zjtsmj.com
162.211.182.39 www.zjgujia.com
162.211.182.39 www.30fu.com
162.211.182.39 www.zgshunxing.com
162.211.182.39 www.zhcrane.com
162.211.182.39 www.zhao5f.com
162.211.182.39 www.ytjiangyou.com
162.211.182.39 www.yinghongjixie.com
162.211.182.39 www.zwyt.net
162.211.182.39 zzhdjx.cn
162.211.182.39 www.szmhk.com
162.211.182.39 www.ccggge.com
162.211.182.39 www.0007590.com
162.211.182.39 941qq.com
162.211.182.39 www4.29u.com
162.211.182.39 www.nlcoad.com
162.211.182.39 26ss.com
162.211.182.39 zhaohaosf.net
162.211.182.39 www.eanfang.com
162.211.182.39 www.ntwmyy.com
162.211.182.39 eanfang.com
162.211.182.39 www.88pknb.com
162.211.182.39 www.hh8gg.pw
162.211.182.39 www.hycygy.com
162.211.182.39 114code.com
162.211.182.39 www.legendpw.net
162.211.182.39 www.dgyuanyang.com
162.211.182.39 www.sf999.name
162.211.182.39 www.125kkk.com
162.211.182.39 go.sf999.com
162.211.182.39 wwww.017cq.com
162.211.182.39 cnc.sf999.com
162.211.182.39 www.xztd888.com
162.211.182.39 www.iyqxkcqw.com
162.211.182.39 www.fenfa1688.com
162.211.182.39 www.huahuiye.com
162.211.182.39 www.sdqinuo.com
162.211.182.39 www.njhxztz.com
162.211.182.39 www.qibone.com
162.211.182.39 www.aimkm.com
162.211.182.39 www.195eeweqsc.com
162.211.182.39 www.007sf.com
162.211.182.39 www.512qz.com
162.211.182.39 www.jxdpx.com
162.211.182.39 www.haosf.org
162.211.182.39 www.17123.com
162.211.182.39 999sf.com
162.211.182.39 www.7000hj.com
162.211.182.39 67pp.com
162.211.182.39 56chuanqi.com
162.211.182.39 www.k8765.com
162.211.182.39 www.haosf9999.com
162.211.182.39 www.fw000.com
162.211.182.39 www.gm333.com
162.211.182.39 www.anmeiexpo.com
162.211.182.39 www.999sf.com
162.211.182.39 www.95ok.com
162.211.182.39 sedio.cc
162.211.182.39 www.5d5y.com
162.211.182.39 www.gm777.com
162.211.182.39 zhaosf.88654.com
162.211.182.39 www.xifulei.com
162.211.182.39 www.sf903.com
162.211.182.39 www.syjm.net
162.211.182.39 www.sf7000.com
162.211.182.39 www.nbwanfeng.com
162.211.182.39 677g.com
162.211.182.39 sf63.com
162.211.182.39 www.91kang.com
162.211.182.39 cqniangzao.com
162.211.182.39 www.999ok.com
162.211.182.39 92gg.com
162.211.182.39 921ww.com
162.211.182.39 520sf.com
162.211.182.39 239ok.com
162.211.182.39 tese.29mydi.com
162.211.182.39 shdongqiao.com
162.211.182.39 sd-yuhui.com
162.211.182.39 meiri.vqkp35.com
162.211.182.39 moni.227y.com
162.211.182.39 gzonisi.cn
162.211.182.39 345cc.cn.com
162.211.182.39 chinayat.com
162.211.182.39 www.3f6f.com
162.211.182.39 www.258sf.com
162.211.182.39 www.13su.com
162.211.182.39 www.118967.com
162.211.182.39 www.sardar.cc
162.211.182.39 www.21sjzg.com
162.211.182.39 www.0769hongri.com
162.211.182.39 www.0574k.com
162.211.182.39 www.020rencai.net
162.211.182.39 uc99.com
162.211.182.39 www.001info.com
162.211.182.39 www.67pp.net
162.211.182.39 www.666666s.com
162.211.182.39 www.66kf.net
162.211.182.39 www.5zaoxie.com
162.211.182.39 www.55hj.com
162.211.182.39 www.520sf.com
162.211.182.39 www.51miehun.co
162.211.182.39 www.51huigo.com
162.211.182.39 www.45758.com
162.211.182.39 www.5199g.com
162.211.182.39 www.30wy.com
162.211.182.39 www.941qq.com
162.211.182.39 www.922gg.com
162.211.182.39 www.88f.com
162.211.182.39 www.88102888.com
162.211.182.39 www.921ww.com
162.211.182.39 www.89946.com
162.211.182.39 www.818wy.com
162.211.182.39 www.86rs.com
162.211.182.39 www.789sf.net
162.211.182.39 www.77yu.com
162.211.182.39 www.789is.com
162.211.182.39 www.6836999.com
162.211.182.39 www.boxianfengguan.com
162.211.182.39 www.allaboutprogram.com
162.211.182.39 www.avoio.com
162.211.182.39 www.autohid.com
162.211.182.39 www.aptx4869.net
162.211.182.39 www.art-verb.com
162.211.182.39 www.94haokan.com
162.211.182.39 www.dj149.com
162.211.182.39 www.dgdtw.com
162.211.182.39 www.digrj.com
162.211.182.39 www.dgzichi.com
162.211.182.39 www.cqsfcn.com
162.211.182.39 www.dfhero.com
162.211.182.39 www.dabanwu.com
162.211.182.39 www.chuanqisifu99.com
162.211.182.39 www.chinakelly.com
162.211.182.39 www.cfaninfo.com
162.211.182.39 www.cgxgf.com
162.211.182.39 www.byetee.com
162.211.182.39 www.idcdong.com
162.211.182.39 www.i-blinks.com
162.211.182.39 www.hnlangjie.com
162.211.182.39 www.hxfamily.com
162.211.182.39 www.hzruili.com
162.211.182.39 www.hnggfz.com
162.211.182.39 www.hzkjy.com
162.211.182.39 www.hlmodule.com
162.211.182.39 www.hbwyw.net
162.211.182.39 www.hbqdxjmf.com
162.211.182.39 www.gzxlzs.com
162.211.182.39 www.gzplay.com
162.211.182.39 www.gxxjl.com
162.211.182.39 www.guanhaiyujia.com
162.211.182.39 www.dqzypx.com
162.211.182.39 www.krksjx.com
162.211.182.39 www.lishi99.com
162.211.182.39 www.leiming-bulb.com
162.211.182.39 www.lanyue2003.com
162.211.182.39 www.laosf.com
162.211.182.39 www.jzfsk.com
162.211.182.39 www.knschina.com
162.211.182.39 www.jsxgm.com
162.211.182.39 www.jshhw.com
162.211.182.39 www.jka77.com
162.211.182.39 www.jn333.com
162.211.182.39 www.j8y.net
162.211.182.39 www.jieer.net
162.211.182.39 www.jietewq.com
162.211.182.39 www.i-dphoto.com
162.211.182.39 www.pgmary.com
162.211.182.39 www.pxfyzs.com
162.211.182.39 www.pai4f.com
162.211.182.39 www.njrybj.com
162.211.182.39 www.oshococo.com
162.211.182.39 www.nibou.net
162.211.182.39 www.newseaswan.com
162.211.182.39 www.myuheng.com
162.211.182.39 www.mzwq.info
162.211.182.39 www.lypfc.com
162.211.182.39 www.lzyinfeng.com
162.211.182.39 www.ly1000.com
162.211.182.39 www.lvislife.com
162.211.182.39 www.lx188.com
162.211.182.39 www.shundaglass.com
162.211.182.39 www.shyuanli.com
162.211.182.39 www.sh-liuxin.com
162.211.182.39 www.shi18.com
162.211.182.39 www.sf920.net
162.211.182.39 www.sea-reach.com
162.211.182.39 www.sertai.com
162.211.182.39 www.sf123-1.com
162.211.182.39 www.sf123.cc
162.211.182.39 www.saiyilong.com
162.211.182.39 www.scienthoer.com
162.211.182.39 www.ruichilida.com
162.211.182.39 www.qunhuan.net
162.211.182.39 www.qmxfw.com
162.211.182.39 www.qhsdkj.com
162.211.182.39 www.twdmly.com
162.211.182.39 www.szyangcai.com
162.211.182.39 www.tococi.com
162.211.182.39 www.tcbl88.com
162.211.182.39 www.sz-wells.com
162.211.182.39 www.szpangzhi.com
162.211.182.39 www.szjundaled.com
162.211.182.39 www.szcmon.com
162.211.182.39 www.szjlskj.com
162.211.182.39 www.szabj.com
162.211.182.39 www.syzwdj.com
162.211.182.39 www.syqtdz.com
162.211.182.39 www.sxhtdl.com
162.211.182.39 www.sougousf.com
162.211.182.39 www.zwnoon.com
162.211.182.39 www.zszhongzhi.com
162.211.182.39 www.z-sheng.com
162.211.182.39 www.zpmc-cz.com
162.211.182.39 www.zjtl.com
162.211.182.39 www.zjpages.com
162.211.182.39 www.zdhw-lighting.com
162.211.182.39 www.youxi119.com
162.211.182.39 www.ysmtc8.com
162.211.182.39 www.yongdingfm.com
162.211.182.39 www.yiqi163.com
162.211.182.39 www.yingxiangceliangyi.com
162.211.182.39 www.wjnmyy.com
162.211.182.39 www.wzcjyy.com
162.211.182.39 www.wudait.com
162.211.182.39 www.xhcsolar.com
162.211.182.39 www.kmnc.net
162.211.182.39 www2.8845sf.com
162.211.182.39 120sf.0755nk.net
162.211.182.39 www.muhon.com.cn
162.211.182.39 www1.8845sf.com
162.211.182.39 922gg.com
162.211.182.39 www.yts189.com
162.211.182.39 www.chakansdfj.com
162.211.182.39 www.steelrq.com
162.211.182.39 yindao.jfsm79.com
162.211.182.39 www.zx0411.com
162.211.182.39 www.kt516.com
162.211.182.39 66sf.69ao.com
162.211.182.39 www.lt925.com
162.211.182.39 www.45wj.com
162.211.182.39 www.tt371.com
162.211.182.39 www.goule88.com
162.211.182.39 www.ranwen.cm
162.211.182.39 www.verosale.com
162.211.182.39 grambox.com
162.211.182.39 down.16kbook.com
162.211.182.39 www.grambox.com
162.211.182.39 cq.51zzsf.com
162.211.182.39 www.ka688.com
162.211.182.39 www.hj010.com
162.211.182.39 cq.sf19.cn
162.211.182.39 www.64sf.com
162.211.182.39 92045.aaabaa.com
162.211.182.39 www.921pk.com
162.211.182.39 91ww.91fu.com
162.211.182.39 kt516.com
162.211.182.39 www.gc771.com
162.211.182.39 www.su315.com
162.211.182.39 www.jindepower.com
162.211.182.39 88uc.sf19.cn
162.211.182.39 99s.69ao.com
162.211.182.39 www.hrm123.net
162.211.182.39 www.bjyjy.com
162.211.182.39 www.uc99.com
162.211.182.39 wvw.9kf.com
162.211.182.39 97sf.com
162.211.182.39 www.70uc.com
162.211.182.39 www.zhaoqiqi.com
162.211.182.39 www.hnrbysc.com
162.211.182.39 www.69ao.com
162.211.182.39 32feef.11cq.cn
162.211.182.39 176.01kp.com
162.211.182.39 www.kuj8.com
162.211.182.39 81f.27-88.com
162.211.182.39 www.917se.com
162.211.182.39 www.fabumir.com
162.211.182.39 www.uc007.com
162.211.182.39 www.sf999.com.de
162.211.182.39 www.zhaosf.co
162.211.182.39 haosf12345.gm127.com
162.211.182.39 zhaosf.co
162.211.182.39 66sf.com
162.211.182.39 www.chuanqisf.com
162.211.182.39 zhuzaigua.com
162.211.182.39 www.1pk.com
162.211.182.39 28uc.com
162.211.182.39 www.005sf.jqjlhw.com
162.211.182.39 chenmo.cc
162.211.182.39 www.sf22.com
162.211.182.39 www.sf405.com
162.211.182.39 www.cz45.com
162.211.182.39 115cq.com
162.211.182.39 www.803cq.com
162.211.182.39 www.25930.com
162.211.182.39 123f.com
162.211.182.39 hongxuda.com
162.211.182.39 haocqsf.com
162.211.182.39 www.100rcw.com
162.211.182.39 www.10000ok.com
162.211.182.39 www.05uc.com
162.211.182.39 www.23qianbao.com
162.211.182.39 www.222sf.com
162.211.182.39 www.72cq.com
162.211.182.39 www.ahmcks.com
162.211.182.39 www.90zzs.com
162.211.182.39 www.csqnw.com
162.211.182.39 www.dlz888.com
162.211.182.39 www.jx789.com
162.211.182.39 www.jsywg.com
162.211.182.39 www.tccyg.com
162.211.182.39 www.wcfm103.com
162.211.182.39 www.wjdhfz.com
162.211.182.39 www.zzz7.net
162.211.182.39 www.m3088tv.com
162.211.182.39 www.cxhdl.com
162.211.182.39 www.szbiaoyu.com
162.211.182.39 www.gzpioneer.com
162.211.182.39 www.mi-sc.com
162.211.182.39 www.hosisoft.com
162.211.182.39 www.huakangpc.com
162.211.182.39 www.zjkylsk.com
162.211.182.39 www.casscno.com
162.211.182.39 www.0808sf.com
162.211.182.39 www.jinhuachang.com
162.211.182.39 www.dongya888.com
162.211.182.39 www.fhxzd.com
162.211.182.39 www.sgwjg.com
162.211.182.39 www.pntfrc.com
162.211.182.39 www.sf9.cn
162.211.182.39 www.8009178.com
162.211.182.39 www.lxsqrfms.com
162.211.182.39 www.ygpkndz.com
162.211.182.39 www.jrxktdy.com
162.211.182.39 www.1007movie.net
162.211.182.39 www.sdkjfjgf.com
162.211.182.39 30.9youwang.com
162.211.182.39 51huigo.com
162.211.182.39 51sf.com
162.211.182.39 520cq.com
162.211.182.39 520cq.net
162.211.182.39 765wg.com
162.211.182.39 789is.com
162.211.182.39 www.23vo.com
162.211.182.39 8aa.com
162.211.182.39 91545.com
162.211.182.39 941lt.com
162.211.182.39 99245.com
162.211.182.39 95sf.com
162.211.182.39 99ting.cn
162.211.182.39 99ting.com
162.211.182.39 aaa.xz667.com
162.211.182.39 ac198.com
162.211.182.39 aa.606wz.com
162.211.182.39 bbs.1x.la
162.211.182.39 dbconsys.com
162.211.182.39 gaosf.com
162.211.182.39 gg.herom2.net
162.211.182.39 hao-sf-123.com
162.211.182.39 haosf.org
162.211.182.39 hao119.com
162.211.182.39 laosf.com
162.211.182.39 search.sf999.com
162.211.182.39 sf3000.com
162.211.182.39 sf86.com
162.211.182.39 sf99.com
162.211.182.39 sf999.net
162.211.182.39 sfsf.d518.com
162.211.182.39 shenqi.com
162.211.182.39 www.fzrhcopper.com
162.211.182.39 ww.s1904.com
162.211.182.39 www.008fy.com
162.211.182.39 www.022hs.com
162.211.182.39 www.123qf.com
162.211.182.39 www.13xp.com
162.211.182.39 www.163fb.com
162.211.182.39 www.450sf.com
162.211.182.39 23vo.com
162.211.182.39 www.184pk.com
162.211.182.39 www.1x.la
162.211.182.39 www.23bb.net
162.211.182.39 www.28uc.com
162.211.182.39 www.33sf.com
162.211.182.39 450sf.com
162.211.182.39 www.55ip.com
162.211.182.39 www.58751.com
162.211.182.39 www.6090sf.com
162.211.182.39 www.67pp.com
162.211.182.39 www.77145.com
162.211.182.39 www.707wz.com
162.211.182.39 www.7pv.net
162.211.182.39 www.78x8.com
162.211.182.39 www.810f.com
162.211.182.39 www.8u8uu.com
162.211.182.39 www.915m.com
162.211.182.39 www.941cq.com
162.211.182.39 www.96cs.com
162.211.182.39 www.92gg.com
162.211.182.39 www.99245.com
162.211.182.39 www.sfniu.com
162.211.182.39 www.sihai-musical.com
162.211.182.39 www.cq588.com
162.211.182.39 91084.com
162.211.182.39 www.dobgame.com
162.211.182.39 www.fireol.com
162.211.182.39 www.fei24.com
162.211.182.39 www.game-114.com
162.211.182.39 www.gaosf.com
162.211.182.39 www.gmhaosf.com
162.211.182.39 www.hao3a.com
162.211.182.39 www.haosf.bz
162.211.182.39 www.htdqsec.com
162.211.182.39 www.hzhswj.com
162.211.182.39 www.pk920.com
162.211.182.39 www.liwoma.com
162.211.182.39 7000uc.com
162.211.182.39 www.nwpbl.com
162.211.182.39 www.ok3000.com
162.211.182.39 www.23c.com
162.211.182.39 www.pk555.com
162.211.182.39 www.pk920.com
162.211.182.39 www.rbtvs.com
162.211.182.39 www.91084.com
162.211.182.39 www.sdzblj.com
162.211.182.39 www.sf121.com
162.211.182.39 www.sebxa.com
162.211.182.39 www.sf3000.com
162.211.182.39 www.sf86.com
162.211.182.39 www.sf999.net
162.211.182.39 www.shuo321.com
162.211.182.39 www.shuiguanyin.com
162.211.182.39 www.sxzkzx.com
162.211.182.39 www.uc88.com
162.211.182.39 www.weihuangsz.com
162.211.182.39 www.weizhixs.com
162.211.182.39 www.wodewww.com
162.211.182.39 www.wsf520.com
162.211.182.39 23c.com
162.211.182.39 www.xcwsg.com
162.211.182.39 www.xjlgc.com
162.211.182.39 www.zhuzaicq.com
162.211.182.39 www1.uc88.com
162.211.182.39 www2.520cq.com
162.211.182.39 www5.29u.com
162.211.182.39 www4.520cq.com
162.211.182.39 www5.520cq.com
162.211.182.39 3000ko.com
162.211.182.39 www.sdjnxy.com
162.211.182.39 sf999.com
162.211.182.39 www.51okf.com
162.211.182.39 www.iiwoool.com
162.211.182.39 www.rxshige.com
162.211.182.39 www.dghke.com
162.211.182.39 www.7kkb.net
162.211.182.39 www.789518.com
162.211.182.39 www.cqfff.com
162.211.182.39 wewer.sf19.cn
162.211.182.39 www4.beer51.com
162.211.182.39 www.cseht.com
162.211.182.39 www.82926.com
162.211.182.39 8uc.558uc.com
162.211.182.39 www.99cangzhou.com
162.211.182.39 www.pjzbw.com
162.211.182.39 who.hnrxyy.net
162.211.182.39 t.fiying.net
162.211.182.39 abc.jlhlbj.com
162.211.182.39 abc.njhabo.com
162.211.182.39 www.52375.com
162.211.182.39 pkpk.8musix.net
162.211.182.39 www.xdhmotor.com
162.211.182.39 www.shmeigu168.com
162.211.182.39 www.comvod.com
162.211.182.39 www.gz-sc.com
162.211.182.39 daded.sf19.cn
162.211.182.39 www.stylepacking.com
162.211.182.39 www.hnfdczj.com
162.211.182.39 www.wfxycc.com
162.211.182.39 www.26ss.com
162.211.182.39 www.hezhihui.com
162.211.182.39 www.wuxihuaxia.com
162.211.182.39 www.nblongyi.com
162.211.182.39 www.7zcq.com
162.211.182.39 7ugg.com
162.211.182.39 www.dliuren.com
162.211.182.39 www.wmult.com
162.211.182.39 www.3159wine.com
162.211.182.39 www.sf5137.com
162.211.182.39 www.cxxcqp.com
162.211.182.39 www.qz92.com
162.211.182.39 66.5173sf.com
162.211.182.39 www.stronger-filter.com
162.211.182.39 www1.65cf.com
162.211.182.39 i8pk.com
162.211.182.39 88kf.aaabaa.com
162.211.182.39 123.3csm123.com
162.211.182.39 www.trnly.com
162.211.182.39 juc.zh9sky.com
162.211.182.39 star.gamtsr.com
162.211.182.39 111.czagl.com
162.211.182.39 926.deepbj.net
162.211.182.39 host.ad0739.com
162.211.182.39 sea.okpro.net
162.211.182.39 www.zhaokj.com
162.211.182.39 www.yaojuezhan.com
162.211.182.39 www.tt2sf.com
162.211.182.39 www.qupaike.com
162.211.182.39 www.luowenqi.com
162.211.182.39 qqfcwgw.com
162.211.182.39 www.taosf.com.ru
162.211.182.39 www.zj-xd.com
162.211.182.39 www.mgszyc.com
162.211.182.39 sf97.dgpxoa.com
162.211.182.39 9pk.dgjt.net
162.211.182.39 www.2umm.com
162.211.182.39 www.yxyhx.com
162.211.182.39 cq.cq890.com
162.211.182.39 53uc.hysdwj.com
162.211.182.39 999.niu999.com
162.211.182.39 zhaokf.com
162.211.182.39 www.sf010.com
162.211.182.39 123.cqsf45.com
162.211.182.39 www.sfdawang.com
162.211.182.39 www.17fg.com
162.211.182.39 1.wzca.com.cn
162.211.182.39 com.xm580.com
162.211.182.39 abc.top258.cn
162.211.182.39 www.gm7.cc
162.211.182.39 9kf.rzsport.com
162.211.182.39 ss.sg368.com
162.211.182.39 www.yy-bags.com
162.211.182.39 video.shunlo.com
162.211.182.39 www.45yes.com
162.211.182.39 www.cnyongli.com
162.211.182.39 www.sf03.com
162.211.182.39 223u.39010.com
162.211.182.39 bjkl.zha0sf.net
162.211.182.39 www.88kf.net
162.211.182.39 www.88kf.com
162.211.182.39 www.sf168.com
162.211.182.39 555sf.com
162.211.182.39 www.ourbep.com
162.211.182.39 www.manmank.com
162.211.182.39 sebxa.com
162.211.182.39 hchxh.com
162.211.182.39 z34.sf19.cn
162.211.182.39 fswe233.11cq.cn
162.211.182.39 efms.115cq.com
162.211.182.39 xks22.sf19.cn
162.211.182.39 456.wtbqsy.com
162.211.182.39 8uc.27-88.com
162.211.182.39 www.mobilefad.com
162.211.182.39 www.sf22-2.com
162.211.182.39 www.tlsfwz.com
162.211.182.39 www.westmm.com
162.211.182.39 baidu.qss365.com
162.211.182.39 7080st.com
162.211.182.39 qaa.xsjej.com
162.211.182.39 www.sf322.com
162.211.182.39 www.zyjms.com
162.211.182.39 yy.7080st.com
162.211.182.39 jcniao.com
162.211.182.39 letanju.com
162.211.182.39 soso.8kst.com
162.211.182.39 www.taleclub.com
162.211.182.39 005sf.njtx168.com
162.211.182.39 008cqsf.ccdhr.com
162.211.182.39 008cqsf.com
162.211.182.39 112sf.com
162.211.182.39 114.75sf.cn
162.211.182.39 1233.xizi30.com
162.211.182.39 1234.57591.com
162.211.182.39 123sf.com
162.211.182.39 138bt.com
162.211.182.39 138sf.com
162.211.182.39 139.limulu.com
162.211.182.39 163.fuatw.com
162.211.182.39 168.w198.net
162.211.182.39 168.zh-db.com
162.211.182.39 178bifen.com
162.211.182.39 17fg.com
162.211.182.39 233sf.138sf.com
162.211.182.39 23c.com
162.211.182.39 23ok.com
162.211.182.39 258.57591.com
162.211.182.39 28yes.com
162.211.182.39 29u.com
162.211.182.39 500sf.com
162.211.182.39 513ux.com
162.211.182.39 515.zh-db.com
162.211.182.39 51xunt.com
162.211.182.39 520.szgumi.com
162.211.182.39 52345.com
162.211.182.39 523sf.com
162.211.182.39 523u.com
162.211.182.39 55z5.com
162.211.182.39 666sf.com
162.211.182.39 66cq.com
162.211.182.39 73sf.com
162.211.182.39 777gm.com
162.211.182.39 7uc.com
162.211.182.39 81f.77du.com
162.211.182.39 81f.com
162.211.182.39 81fu.com
162.211.182.39 863.zh-db.com
162.211.182.39 876sf.45195.com
162.211.182.39 88.520axn.com
162.211.182.39 8845.aaabaa.com
162.211.182.39 8845.com
162.211.182.39 8845.kt888.com
162.211.182.39 8845.ugame123.com
162.211.182.39 888.5index.net
162.211.182.39 888.79yj.com
162.211.182.39 888.manrenjian.com
162.211.182.39 888.qu69.com
162.211.182.39 88858.com
162.211.182.39 88858.sz5161.net
162.211.182.39 8uc.01744.com
162.211.182.39 8uc.31450.com
162.211.182.39 8uc.82506.com
162.211.182.39 8uc.aaabaa.com
162.211.182.39 8uc.ccdhr.com
162.211.182.39 8uc.hiszx.com
162.211.182.39 www.qizhu.cc
162.211.182.39 8uu.aaabaa.com
162.211.182.39 www.as9z.com
162.211.182.39 8uu.com
162.211.182.39 91.haosf123.com
162.211.182.39 91wuc.com
162.211.182.39 91ww.123uu.com
162.211.182.39 91ww.aaabaa.com
162.211.182.39 91ww.com
162.211.182.39 91ww.ugame123.com
162.211.182.39 92045.com
162.211.182.39 920sf.com
162.211.182.39 926.com
162.211.182.39 92fu.com
162.211.182.39 999hj.com
162.211.182.39 99j.com
162.211.182.39 9kf.com
162.211.182.39 9pk.k197.com
162.211.182.39 9pk.u7u73.com
162.211.182.39 ad.97uu.com
162.211.182.39 haocq.com
162.211.182.39 pk123.com
162.211.182.39 plinm.com
162.211.182.39 qiqi530.com
162.211.182.39 qq.007uc.com
162.211.182.39 sf138.com
162.211.182.39 sf168.com
162.211.182.39 sf176.com
162.211.182.39 sf215.com
162.211.182.39 sf222.com
162.211.182.39 sf30.com
162.211.182.39 sf777.com
162.211.182.39 www.xhnano.com
162.211.182.39 sogou.1000ok.com
162.211.182.39 ww.1388fu.com
162.211.182.39 www.005sf.com
162.211.182.39 www.008n.com
162.211.182.39 www.015999.com
162.211.182.39 www.023cz.com
162.211.182.39 www.023toilet.com
162.211.182.39 www.027fruit.com
162.211.182.39 www.0313hybj.com
162.211.182.39 www.0532oa.com
162.211.182.39 www.055735.com
162.211.182.39 www.07186.com
162.211.182.39 www.1000gsf.com
162.211.182.39 www.112sf.com
162.211.182.39 www.114haosf.com
162.211.182.39 www.115cq.com
162.211.182.39 www.11811445.com
162.211.182.39 www.11cq.cn
162.211.182.39 www.120sf.com
162.211.182.39 www.123cq.com
162.211.182.39 www.123f.com
162.211.182.39 www.123hj.com
162.211.182.39 www.123sf.com
162.211.182.39 www.123uu.com
162.211.182.39 www.130136.com
162.211.182.39 www.134sf.com
162.211.182.39 www.138bt.com
162.211.182.39 www.145sf.com
162.211.182.39 www.15ss.com
162.211.182.39 www.16753.com
162.211.182.39 www.17fabu8.com
162.211.182.39 www.215pk.com
162.211.182.39 www.22j.com
162.211.182.39 www.234sfww.com
162.211.182.39 www.23c.com
162.211.182.39 www.23fu.com
162.211.182.39 www.23ok.com
162.211.182.39 www.23sfu.cn
162.211.182.39 www.27sf.com
162.211.182.39 www.28yes.com
162.211.182.39 www.29u.com
162.211.182.39 www.3000ok.cc
162.211.182.39 www.3000pk.com
162.211.182.39 www.31cqsf.com
162.211.182.39 www.31i.cn
162.211.182.39 www.3300sf.com
162.211.182.39 www.33345.com
162.211.182.39 www.333ok.com
162.211.182.39 www.33pk.com
162.211.182.39 www.33wt.com
162.211.182.39 www.361cq.com
162.211.182.39 www.365taoba.com
162.211.182.39 www.371cyw.com
162.211.182.39 www.37ok.com
162.211.182.39 www.3dmeibang.com
162.211.182.39 www.3qsf.com
162.211.182.39 www.418sf.in
162.211.182.39 www.425sf.com
162.211.182.39 www.44dy.com
162.211.182.39 www.45195.com
162.211.182.39 www.34ok.com
162.211.182.39 www.8cq.cc
162.211.182.39 www.45bang.com
162.211.182.39 34ok.com
162.211.182.39 www.45hs.com
162.211.182.39 www.4nic-dy.com
162.211.182.39 www.500sf.com
162.211.182.39 www.51sf.com
162.211.182.39 www.52058.com
162.211.182.39 www.520cq.com
162.211.182.39 www.520jy.com
162.211.182.39 pg.iflu.com.cn
162.211.182.39 zhaosf.hsdbm.com
162.211.182.39 dd.guidawang.com
162.211.182.39 www.523sf.com
162.211.182.39 www.523u.com
162.211.182.39 www.531U.com
162.211.182.39 www.533ok.com
162.211.182.39 www.53sf.com
162.211.182.39 www.53uc.com
162.211.182.39 www.53w.com.cn
162.211.182.39 www.54ss.net
162.211.182.39 www.pk920.com
162.211.182.39 www.55z5.com
162.211.182.39 www.565sf.com
162.211.182.39 www.56ss.com
162.211.182.39 cdchuanghui.com
162.211.182.39 www.57591.com
162.211.182.39 www.57f.com
162.211.182.39 www.57fg.com
162.211.182.39 www.57ww.com
162.211.182.39 www.5800sf.com
162.211.182.39 www.58sf.com
162.211.182.39 www.58uc.com
162.211.182.39 www.5index.net
162.211.182.39 www.5qu.com
162.211.182.39 www.64pk.com
162.211.182.39 www.6645.com
162.211.182.39 www.666sf.com
162.211.182.39 www.676711.com
162.211.182.39 www.677g.com
162.211.182.39 www.67m2.com
162.211.182.39 www.686f.com
162.211.182.39 www.697sf.com
162.211.182.39 www.6cq.cc
162.211.182.39 www.73sf.com
162.211.182.39 www.75sf.cn
162.211.182.39 www.777gm.com
162.211.182.39 www.77d8.com
162.211.182.39 www.77kl.com
162.211.182.39 www.79j.com
162.211.182.39 www.7j773.com
162.211.182.39 www.7uc.com
162.211.182.39 www.80845.com
162.211.182.39 www.812315.com
162.211.182.39 www.81267.com
162.211.182.39 www.81fu.com
162.211.182.39 www.823f.com
162.211.182.39 www.82506.com
162.211.182.39 www.860572.com
162.211.182.39 www.860580.com
162.211.182.39 www.87sf.com
162.211.182.39 www.8845.com
162.211.182.39 www.88845.com
162.211.182.39 www.88858.com
162.211.182.39 www.89176.com
162.211.182.39 www.8aa.com
162.211.182.39 www.8uc.com
162.211.182.39 www.900hj.com
162.211.182.39 www.909f.com
162.211.182.39 www.9100sf.com
162.211.182.39 www.915301.com
162.211.182.39 www.91545.com
162.211.182.39 www.91ff.com
162.211.182.39 www.91wuc.com
162.211.182.39 www.920666.com
162.211.182.39 www.920gg.com
162.211.182.39 www.920sf.com
162.211.182.39 www.923u.com
162.211.182.39 www.92fu.com
162.211.182.39 www.92ww.com
162.211.182.39 www.93sf.com
162.211.182.39 www.94432.com
162.211.182.39 www.95sf.com
162.211.182.39 www.96645.com
162.211.182.39 www.9800sf.com
162.211.182.39 www.980cq.com
162.211.182.39 www.99964.com
162.211.182.39 www.999hj.com
162.211.182.39 www.999wg.net
162.211.182.39 www.99a.com
162.211.182.39 www.99ji.com
162.211.182.39 www.99pk.com
162.211.182.39 www.apbfhl.com
162.211.182.39 www.aifugu.com
162.211.182.39 www.33pk.com
162.211.182.39 33pk.com
162.211.182.39 www.bjhdshengda.com
162.211.182.39 www.bjtdyz.com
162.211.182.39 www.bsfzjx.com
162.211.182.39 www.bsrcsc.com
162.211.182.39 www.cnycta.com
162.211.182.39 www.cq45.com
162.211.182.39 www.cq91530.com
162.211.182.39 www.cqy6.com
162.211.182.39 www.csrxj.com
162.211.182.39 www.cy4f.com
162.211.182.39 www.fy371.com
162.211.182.39 www.gm888.com
162.211.182.39 www.gxxgy.com
162.211.182.39 www.gzxing.com
162.211.182.39 www.heli-cn.com
162.211.182.39 www.hnyuhai.com
162.211.182.39 www.hstztc.com
162.211.182.39 www.hwhaosf.com
162.211.182.39 www.7000uc.com
162.211.182.39 www.ksd777.com
162.211.182.39 www.laisf.com
162.211.182.39 www.laohaosf.com
162.211.182.39 www.lovewg.com
162.211.182.39 www.luckysz.com
162.211.182.39 www.mai101.com
162.211.182.39 www.mikating.com
162.211.182.39 www.mtv110.com
162.211.182.39 www.nj-row.com
162.211.182.39 www.nybxm.com
162.211.182.39 www.ocerlight.com
162.211.182.39 www.oksf.net
162.211.182.39 www.pk123.com
162.211.182.39 www.plinm.com
162.211.182.39 www.qiqi530.com
162.211.182.39 www.qzrt.com
162.211.182.39 www.recairen.com
162.211.182.39 www.rexuesf.in
162.211.182.39 www.sf0058.com
162.211.182.39 www.sf1003.com
162.211.182.39 www.sf17.com
162.211.182.39 www.sf176.com
162.211.182.39 www.sf215.com
162.211.182.39 www.sf222.com
162.211.182.39 www.sf231.com
162.211.182.39 www.sf29.com
162.211.182.39 www.sf30.com
162.211.182.39 www.sf520.com.cn
162.211.182.39 www.sf555.com
162.211.182.39 www.sf5858.com
162.211.182.39 www.sf63.com
162.211.182.39 www.sf777.com
162.211.182.39 www.sf8500.com
162.211.182.39 www.sf92045.com
162.211.182.39 www.sf930.com
162.211.182.39 www.sf99.com
162.211.182.39 www.shaibar.com
162.211.182.39 www.shamandi.com
162.211.182.39 www.ksjxyy.com
162.211.182.39 www.sktpcbic.com
162.211.182.39 www.stkj66.com
162.211.182.39 www.tj-aote.com
162.211.182.39 www.haosf999.com
162.211.182.39 www.wan45.com
162.211.182.39 www.whjdwxw.com
162.211.182.39 www.whlinuo.com
162.211.182.39 www.worldkcc.com
162.211.182.39 www.wtcqsf.com
162.211.182.39 www.xiaomeisf.com
162.211.182.39 www.xihaihotel.com
162.211.182.39 www.xindudu.com
162.211.182.39 www.xinganchem.com
162.211.182.39 www.ovytgnby.com
162.211.182.39 www.xinsf.com
162.211.182.39 www.yeschongcao.com
162.211.182.39 www.ynyeer.com
162.211.182.39 www.ysguandao.com
162.211.182.39 www.yxzhidao.com
162.211.182.39 www.zhaochenmo.com
162.211.182.39 www.zhaofg.com
162.211.182.39 www.zhaohaosf.net
162.211.182.39 www.zhaokf.com
162.211.182.39 www.zhaosf88.com
162.211.182.39 www.zhaoss.com
162.211.182.39 www1.pk123.com
162.211.182.39 www10.138sf.com
162.211.182.39 xiaomeisf.com
162.211.182.39 xinsf.com
162.211.182.39 www.500ok.com
162.211.182.39 www.wancm.com
162.211.182.39 jjj.la
162.211.182.39 zhaochenmo.com
162.211.182.39 zuhukang.com
162.211.182.39 www.shangkequ.com
162.211.182.39 www.9527cqsf.com
162.211.182.39 www.tjtuliao.com
162.211.182.39 www.szplas.com
162.211.182.39 www.hlxyx.com
162.211.182.39 www.012sf.com
162.211.182.39 www.zhaosf.cc
162.211.182.39 www.07sf.com
162.211.182.39 www.duoduosf.com
162.211.182.39 www.sf66666.com
162.211.182.39 www.my7su.com
162.211.182.39 www.725sf.com
162.211.182.39 725sf.com
162.211.182.39 www.96sf.com
162.211.182.39 www.pk196.com
162.211.182.39 www.letanju.com
162.211.182.39 50ss.com
162.211.182.39 www.50ss.com
162.211.182.39 sfdawang.com
162.211.182.39 taocq.com
162.211.182.39 www.73uu.com
162.211.182.39 www.taocq.com
162.211.182.39 www.30uc.com
162.211.182.39 www.nz999.net
162.211.182.39 www.ww45.com
162.211.182.39 www.xt-dz.com
162.211.182.39 www.pk99.com
162.211.182.39 www.1e2w.cn
162.211.182.39 8845.678uc.com
162.211.182.39 cq.3q33.com
162.211.182.39 www.baojingqi.net
162.211.182.39 www.didihc.com
162.211.182.39 www.bangnijie.com
162.211.182.39 www.chenmo.cc
162.211.182.39 www.sina35.com
162.211.182.39 www.175sf.com
162.211.182.39 sf123.cc
162.211.182.39 www.shfiro.com
162.211.182.39 bjyocy.com
162.211.182.39 www.pochanlawyer.com
162.211.182.39 www.138sf.cc
162.211.182.39 24cq.a0353.com
162.211.182.39 www.24cq.com
162.211.182.39 99pk.com
162.211.182.39 www.22cq.com
162.211.182.39 www.888ww.com
162.211.182.39 www.2sifu.com
162.211.182.39 wvw-9kf.com
162.211.182.39 wvw.uc99.com
162.211.182.39 123.uc99.com
162.211.182.39 999ok.com
162.211.182.39 www.komophoto.com
162.211.182.39 tg.23u.cm
162.211.182.39 www.sf99.cc
162.211.182.39 www.80sf.com
162.211.182.39 www.33221.com
162.211.182.39 www.pk9090.com
162.211.182.39 pk9090.com
162.211.182.39 www2.uc88.com
162.211.182.39 www3.uc88.com
162.211.182.39 www4.uc88.com
162.211.182.39 88845.com
162.211.182.39 88845e.baba1q.com
162.211.182.39 www.sf9.com
162.211.182.39 www.700sf.com
162.211.182.39 920gg.com
162.211.182.39 www.23c.com
162.211.182.39 www.021sx.com
162.211.182.39 www.sf78.com
162.211.182.39 www.qjfang.cn
162.211.182.39 23c.com
162.211.182.39 www.yaofg.com
162.211.182.39 www.07ket.com
162.211.182.39 www.17hhg.com
162.211.182.39 www.46cq.com
162.211.182.39 www.wan345.com
162.211.182.39 www.htlq.com
162.211.182.39 www.nbkst.com
162.211.182.39 www.meishipai.com
162.211.182.39 www.987pk.com
162.211.182.39 www.weisf.com
162.211.182.39 www.baqisf.com
162.211.182.39 www.91530.com
162.211.182.39 www.zhaohaosf.com
162.211.182.39 www.s400.com
162.211.182.39 www.aichenmo.com
162.211.182.39 www.sf315.com
162.211.182.39 425sf.com
162.211.182.39 www.23gg.com
162.211.182.39 yaofg.com
162.211.182.39 www.44woool.com
162.211.182.39 www.17166.com
162.211.182.39 www.wt789.com
162.211.182.39 www.591maimai.com
162.211.182.39 calds.net
162.211.182.39 www.gggsf.com
162.211.182.39 www.cecri.com
162.211.182.39 www.cnpxba.com
162.211.182.39 www.cqrcxx.com
162.211.182.39 www.zhaowt.net
162.211.182.39 3000ak.com
162.211.182.39 www.3000ak.com
162.211.182.39 027gg.net
162.211.182.39 www.85sf.com
162.211.182.39 www.cnxinghang.com
162.211.182.39 www.sf19.com
162.211.182.39 www.uc600.com
162.211.182.39 www.255uc.com
162.211.182.39 255uc.com
162.211.182.39 111.kaihu365.com
162.211.182.39 www.3000ok-1.com
162.211.182.39 www.3000ok.com
162.211.182.39 www.sf588.com
162.211.182.39 www.jjj3000ok.com
162.211.182.39 1000ok.com
162.211.182.39 www.33ok.com
162.211.182.39 www.666923.com
162.211.182.39 www.920313.com
162.211.182.39 www.616st.com
162.211.182.39 www.53my.com
162.211.182.39 www.945176.net
162.211.182.39 www.999sf.cc
162.211.182.39 933gg.com
162.211.182.39 haosf.com
162.211.182.39 123.123wg.com
162.211.182.39 haosf.com.cn
162.211.182.39 www.haosf.com.cn
162.211.182.39 tg.cnm78.com
162.211.182.39 www.1213sf.com
162.211.182.39 www.678sf.com
162.211.182.39 www.250sf.com
162.211.182.39 www.92188.com
162.211.182.39 888.hyds888.com
162.211.182.39 www.646sf.com
162.211.182.39 www.82cq.com
162.211.182.39 sf99.cc
162.211.182.39 www.50ww.com
162.211.182.39 sf590.com
162.211.182.39 www.sf590.com
162.211.182.39 www.35fg.com
162.211.182.39 www.sf526.com
162.211.182.39 www.18ux.com
162.211.182.39 www.520cq.net
162.211.182.39 www.haosf12345.com
162.211.182.39 sf22.com
162.211.182.39 pk99.com
162.211.182.39 79j.com
162.211.182.39 55sf.com
162.211.182.39 www.55sf.com
162.211.182.39 www.zm63.com
162.211.182.39 926.syslx.com
162.211.182.39 1000ok.cc
162.211.182.39 www.1000ok.cc
162.211.182.39 3000ok.isosf.com
162.211.182.39 3000ok.com
162.211.182.39 tt.syslx.com
162.211.182.39 www.zhaofq.com
162.211.182.39 2013.cqmdl.com
162.211.182.39 www.19fu.com
162.211.182.39 19fu.com
162.211.182.39 www.zhaosifu.com
162.211.182.39 www.kom999.com
162.211.182.39 www.ok777.com
162.211.182.39 www.757sf.com
162.211.182.39 www.50999.com
162.211.182.39 33345.com
162.211.182.39 999zg.com
162.211.182.39 www.13ss.com
162.211.182.39 www.520zf.com
162.211.182.39 88pk.com
162.211.182.39 www.990yx.com
162.211.182.39 www.cqacura.com
162.211.182.39 www.tldsny.com
162.211.182.39 www.wzggwz.com
162.211.182.39 www.tjnhey.com
162.211.182.39 www.51friends.com
162.211.182.39 aa.707wz.com
162.211.182.39 www.cn-skf.com
162.211.182.39 www.6sf.com
162.211.182.39 www.nhfluhuijiao.com
162.211.182.39 mojingqiyuan.com
162.211.182.39 www.jianfeixy.com
162.211.182.39 www.shkingdu.com
162.211.182.39 www.707wz.com
162.211.182.39 www.suoyinm.com
162.211.182.39 www.zcmeter.com
162.211.182.39 www.115book.com
162.211.182.39 cqsf.yearwin.com
162.211.182.39 9kst.com
162.211.182.39 9u.7080st.com
162.211.182.39 www.118uc.om
162.211.182.39 www.haofwd.com
162.211.182.39 www.zhaowoool.com
162.211.182.39 www.gdhttz.com
162.211.182.39 www.fzdbdz.com
162.211.182.39 www.tianguhotel.com
162.211.182.39 www.chinahjly.com
162.211.182.39 tgaxved8.com
162.211.182.39 5a189.com
162.211.182.39 9q0s6.clydji.com
162.211.182.39 www.wuwoool.com
162.211.182.39 www.shitongdg.com
162.211.182.39 www.sbqcssf.com
162.211.182.39 www.51cssf.net.cn
162.211.182.39 www.65535cs.com
162.211.182.39 zhao.559woool.com
162.211.182.39 www.559woool.com
162.211.182.39 www.5sdl.com
162.211.182.39 www.dandong-window.com
162.211.182.39 www.xinyumen.com
162.211.182.39 www.ahzhishang.com
162.211.182.39 www.xd163.com
162.211.182.39 www.trm-china.com
162.211.182.39 www.aoyue168.com
162.211.182.39 www.gdcable.com
162.211.182.39 www.zhuwulong.com
162.211.182.39 www.szjapson.com
162.211.182.39 www.swan-storage.com
162.211.182.39 www.cseptc.com
162.211.182.39 www.zcgddz.com
162.211.182.39 www.dycssf.com
162.211.182.39 www.9965478.com
162.211.182.39 www.jshgzb.com
162.211.182.39 www.qd-qinggang.com
162.211.182.39 gzgm.27pyki.com
162.211.182.39 wupin.qxgxc.com
162.211.182.39 www.hcs888.com
162.211.182.39 www.woool578.com
162.211.182.39 www.jntex.com
162.211.182.39 917wool.cn
162.211.182.39 chuanqifj.com
162.211.182.39 www.lqgz.com
162.211.182.39 1.sun0319.com
162.211.182.39 www.suwoool.com
162.211.182.39 www.45ci.com
162.211.182.39 iiwoool.com
162.211.182.39 www.sdyjt.com
162.211.182.39 www1.bai12.com
162.211.182.39 www.889cs.com
162.211.182.39 www.cjphb.com
162.211.182.39 www.szosun.com
162.211.182.39 www.garment5.com
162.211.182.39 www.gm66.com
162.211.182.39 www.com15.com
162.211.182.39 www.emc120.com
162.211.182.39 ktjia.com
162.211.182.39 www.05woool.com
162.211.182.39 www.cnsjjs.com
162.211.182.39 www.jnxsfr.com
162.211.182.39 www.chinajujing.com
162.211.182.39 www.99cishan.com
162.211.182.39 www.022-baidu.com
162.211.182.39 44woool.com
162.211.182.39 www.mm886.net
162.211.182.39 www.shyssteel.com
162.211.182.39 3.96cs.com
162.211.182.39 www.ywool.com
162.211.182.39 www.hao123woool.com
162.211.182.39 aixin168.com
162.211.182.39 www.wooolfbw.com
162.211.182.39 www.525pc.com
162.211.182.39 www.zhaowooolsf.com
162.211.182.39 cnscn.org
162.211.182.39 www.cn-tyn.com
162.211.182.39 www.917wool.cn
162.211.182.39 www.hy225.com
162.211.182.39 www.10gamer.com
162.211.182.39 56jm.wpgyai.com
162.211.182.39 www.zv2o.com
162.211.182.39 001.96cs.com
162.211.182.39 www.411wed.com
162.211.182.39 www.lewoool.com
162.211.182.39 gtcc2008.com
162.211.182.39 945pk.com
162.211.182.39 pk777.com
162.211.182.39 jgfw.qu-zhou.com
162.211.182.39 www.168gamer.com
162.211.182.39 new.guguyu.com
162.211.182.39 www.bluemuffinkids.com
162.211.182.39 web.longhoo.net
162.211.182.39 www.8090yxs.com
162.211.182.39 aszt.6268.com
162.211.182.39 kf.07073.com
162.211.182.39 www.mcncc.com
162.211.182.39 www.wudijz.com
162.211.182.39 lhzs.9377.com
162.211.182.39 lhzs.37wan.com
162.211.182.39 lhzs.yaowan.com
162.211.182.39 lhzs.49you.com
162.211.182.39 lhzs.8090yxs.com
162.211.182.39 wz.49you.com
162.211.182.39 wz.6711.com
162.211.182.39 asqx.yaowan.com
162.211.182.39 www.sifucun.com
162.211.182.39 bbs.to4f.com
162.211.182.39 www.pg666.cn
162.211.182.39 www.yeyoubbs.com
162.211.182.39 www.ucwawa.com
162.211.182.39 www.hgyouxi.net
162.211.182.39 www.xiaolou8.com
162.211.182.39 bbs.houdao.com
162.211.182.39 www.iopq.com
162.211.182.39 bbs2.okweb8.com
162.211.182.39 wangyesifu.com
162.211.182.39 ok1399.com
162.211.182.39 www.wy090.com
162.211.182.39 www.yx315.net
162.211.182.39 www.yrabc.com
162.211.182.39 67uc.com
162.211.182.39 www.yxsjqk.com
162.211.182.39 bbs.mcncc.net
162.211.182.39 www.wangyesifu.com
162.211.182.39 bbs.games.qq.com
162.211.182.39 www.uc266.com
162.211.182.39 www.luanshi.net
162.211.182.39 bbs.freegames.com.cn
162.211.182.39 www.180b.com
162.211.182.39 www.gamemx.com
162.211.182.39 www.9kld.com
162.211.182.39 bbs2.99nets.me
162.211.182.39 www.to4f.com
162.211.182.39 ejxx.jdjy.cn
162.211.182.39 www.920520.com
162.211.182.39 www.gifts52.com
162.211.182.39 www.jjj.com.co
162.211.182.39 www.cq200.com
162.211.182.39 www.239ok.com
162.211.182.39 www.97heji.com
162.211.182.39 daquan.bxim28.com
162.211.182.39 www.173bt.com
162.211.182.39 www.1745.com
162.211.182.39 www.96sf.com
162.211.182.39 www.sffb.net
162.211.182.39 www.5uwl.net
162.211.182.39 www.qtgcjx.com
162.211.182.39 www.bdqn.net
162.211.182.39 www.52anzu.net
162.211.182.39 www1.52anzu.net
162.211.182.39 www.52anzu.com
162.211.182.39 www1.52anzu.com
162.211.182.39 www2.52anzu.com
162.211.182.39 www.sopojie.com
162.211.182.39 www1.sopojie.com
162.211.182.39 uc.sydahe.com
162.211.182.39 www.1cq.com
162.211.182.39 1cq.com
162.211.182.39 www.tt0436.com
162.211.182.39 www.ximeiedu.com
162.211.182.39 www.zhanzz.com
162.211.182.39 dxkj888.com
162.211.182.39 www.cxzgled.com
162.211.182.39 www.sf999.com.cn
162.211.182.39 www.nbxywj.com
162.211.182.39 www.51zhaosf.com
162.211.182.39 30okok.com
162.211.182.39 www.33345ok.com
162.211.182.39 www.lanhaibyd.com
162.211.182.39 uc.turuyi.com
162.211.182.39 www.sinomax-tip.com
162.211.182.39 www.yiyuanit.com
162.211.182.39 mg60.com
162.211.182.39 3000ok.pro
162.211.182.39 uuu.turuyi.com
162.211.182.39 www.bjek120.com
162.211.182.39 sdjnbx.com
162.211.182.39 new.turuyi.com
162.211.182.39 www.bsssun.com
162.211.182.39 www.fu110.com
162.211.182.39 www.pdlmall.com
162.211.182.39 23bb.net
162.211.182.39 www.tde007.com
162.211.182.39 www.500ok.com
162.211.182.39 www.hlkg.net
162.211.182.39 www.17126.com
162.211.182.39 www.ideapack.com.cn
162.211.182.39 62bf2.mc520.com
162.211.182.39 www.tophereled.com
162.211.182.39 www.ch-gwang.com
162.211.182.39 www.sf12345.cc
162.211.182.39 sis858.com
162.211.182.39 www.sfwanjia.com
162.211.182.39 www.765cq.com
162.211.182.39 p22672.com
162.211.182.39 www.53245.com
162.211.182.39 www.335ok.com
162.211.182.39 335ok.com
162.211.182.39 www.zglzsy.com
162.211.182.39 sf.183a8.mc520.com
162.211.182.39 jiaocheng.x9858.com
162.211.182.39 www.led58.com
162.211.182.39 miji.38yqj.com
162.211.182.39 xx.turuyi.com
162.211.182.39 www.hongchuangalye.com
162.211.182.39 jinanzhongju.com
162.211.182.39 www.87sf.com
162.211.182.39 www.e-sunisco.com
162.211.182.39 333.sydahe.com
162.211.182.39 185.17c94.mc520.com
162.211.182.39 461a9.170.mc520.com
162.211.182.39 www.fg12.com
162.211.182.39 3o8c8.feztod.com
162.211.182.39 exa.bzjaza.com
162.211.182.39 www.cqsf185.com
162.211.182.39 haosf.zhaochaye.cn
162.211.182.39 www.gw-food.com
162.211.182.39 1h5.robszh.com
162.211.182.39 rla.graujp.com
162.211.182.39 www.sf120.com
162.211.182.39 520.sydahe.com
162.211.182.39 v02.clydji.com
162.211.182.39 qq.turuyi.com
162.211.182.39 2f7a6.jhtjqg.com
162.211.182.39 www.505sf.com
162.211.182.39 www.zyxxedo.com
162.211.182.39 yy.turuyi.com
162.211.182.39 xp.sydahe.com
162.211.182.39 777.turuyi.com
162.211.182.39 www.920cq.com
162.211.182.39 www.99340.com
162.211.182.39 sss.sydahe.com
162.211.182.39 www.zhaosf.ws
162.211.182.39 7e1.eeulus.com
162.211.182.39 www.hycartoon.com
162.211.182.39 sf.youxi366.com
162.211.182.39 www.916cq.com/1
162.211.182.39 www.916cq.com
162.211.182.39 rhj.bnn2.com
162.211.182.39 www.tootc.com
162.211.182.39 jieshao.tgv27.com
162.211.182.39 legalweek.cn
162.211.182.39 www.chuanqisf999.com
162.211.182.39 www.gf999.com
162.211.182.39 www.baiduhaosf.com
162.211.182.39 www.nikeshoxr4.net
162.211.182.39 www.jjj.com.ru
162.211.182.39 www.tzchanghong.com
162.211.182.39 www.mxjy.net
162.211.182.39 www.qicai130.com
162.211.182.39 jiadian.66kin.com
162.211.182.39 www.sf123.org
162.211.182.39 sf123.co
162.211.182.39 www.pk930.com
162.211.182.39 www.chuanqisifu.eu
162.211.182.39 www.123dbc.com
162.211.182.39 7pv.net
162.211.182.39 www.soojin-dance.com
162.211.182.39 ko.sydahe.com
162.211.182.39 www.0532yinli.com
162.211.182.39 www.0717bbs.com
162.211.182.39 www.pk021.com
162.211.182.39 www.cswewon.com
162.211.182.39 wb.91sbk.com
162.211.182.39 www.rfinfo.cn
162.211.182.39 www.m1ye.com
162.211.182.39 467.2013wansf.com
162.211.182.39 www.autohome.name
162.211.182.39 sdgsdf.ezwohs.com
162.211.182.39 jptea.cn
162.211.182.39 468dc.xfds.com
162.211.182.39 xitong.e3358.com
162.211.182.39 guaiwu.shf2.com
162.211.182.39 hbwxkj.com
162.211.182.39 jineng.kqgf69.com
162.211.182.39 cotton.687vt.com
162.211.182.39 cq.sydahe.com
162.211.182.39 ccc.turuyi.com
162.211.182.39 jj23j.60sf.cn
162.211.182.39 zfu232.sf33.cn
162.211.182.39 sdf232.60sf.cn
162.211.182.39 www.sztoled.com
162.211.182.39 8d0m9.jhtjqg.com
162.211.182.39 sf999.at
162.211.182.39 www.esinda.com
162.211.182.39 3159wine.com
162.211.182.39 www.gm7.cc
162.211.182.39 www.liygaya.com
162.211.182.39 www.fscdo.com
162.211.182.39 www.daosf.com
162.211.182.39 xxx.sydahe.com
162.211.182.39 4ke.dksifw.com
162.211.182.39 zhao.turuyi.com
162.211.182.39 www.bjyadzkj.com
162.211.182.39 www.jjj.com.es
162.211.182.39 www.810sf.com
162.211.182.39 www.lc91.com
162.211.182.39 www.bjkuaike.com
162.211.182.39 www.gzanfa.com
162.211.182.39 www.49y.com
162.211.182.39 www.justice


Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name: ?????
Product Version: 1.0.0.0
Legal Copyright: ?????? ????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 1.0.0.0
File Description: ?????
Comments: ??????????(http://www.eyuyan.com)
Language: Language Neutral

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 506947 0 0 d41d8cd98f00b204e9800998ecf8427e
.rdata 512000 1441802 0 0 d41d8cd98f00b204e9800998ecf8427e
.data 1957888 179530 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 2138112 34688 20480 3.86761 e71ca416dbd3f28eeee18d7eb229741e
.vmp0 2174976 12324 0 0 d41d8cd98f00b204e9800998ecf8427e
.vmp1 2191360 1757591 1761280 5.44659 a722de03023d950b6b6a0822c7d55755
.reloc 3952640 80 4096 0.099441 7d91e7b97cdd8e9ef3e9d2ef24334f96

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://jc.941pojie.com/tc.txt 183.60.111.247
hxxp://jc.941pojie.com/ 183.60.111.247
hxxp://jc.941pojie.com/cj.txt 183.60.111.247
hxxp://gogozz1pj.huihaowy.com/ 183.56.169.162
hxxp://jc.941pojie.com/jiaqun.htm 183.60.111.247
hxxp://jc.941pojie.com/css/style.css 183.60.111.247
hxxp://jc.941pojie.com/img/gif008.gif 183.60.111.247
hxxp://jc.941pojie.com/img/zsf.gif 183.60.111.247
hxxp://ssd.tcdn.qq.com/wpa/images/group.png
hxxp://jc.941pojie.com/img/lhr.gif 183.60.111.247
hxxp://c.split.cnzz.com/stat.php?id=5076676&show=pic2
hxxp://c.split.cnzz.com/core.php?web_id=5076676&show=pic2&t=z
hxxp://z3.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438
hxxp://z3.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369
hxxp://c.split.cnzz.com/stat.php?id=1253112259&web_id=1253112259
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=333037092
hxxp://icon.cnzz.com/img/pic2.gif 42.156.162.7
hxxp://c.split.cnzz.com/stat.php?id=3325108&show=pic1
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1036514576
hxxp://c.split.cnzz.com/core.php?web_id=1253112259&t=z
hxxp://c.split.cnzz.com/core.php?web_id=3325108&show=pic1&t=z
hxxp://z7.cnzz.com/stat.htm?id=1253112259&r=&lg=en-us&ntime=none&cnzz_eid=804168892-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined&h=1&rnd=999258932 42.156.140.20
hxxp://jc.941pojie.com/img/jbc.gif 183.60.111.247
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=895496844
hxxp://icon.cnzz.com/img/pic1.gif 42.156.162.7
hxxp://pcookie.split.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB
hxxp://pcookie.split.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
hxxp://z6.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=2071775127
hxxp://z6.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043
hxxp://jc.941pojie.com/img/js.gif 183.60.111.247
hxxp://img.webscan.360.cn/status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 220.181.158.213
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1532175039
hxxp://jc.941pojie.com/img/swz.gif 183.60.111.247
hxxp://jc.941pojie.com/img/gua.gif 183.60.111.247
hxxp://hm.e.shifen.com/h.js?c8a6515c967e27925a2fd6685fe9963c
hxxp://jc.941pojie.com/img/2014052276129177.gif 183.60.111.247
hxxp://hm.e.shifen.com/hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=开心快乐每一天!
hxxp://jc.941pojie.com/img/046bt.gif 183.60.111.247
hxxp://jc.941pojie.com/img/icon.png 183.60.111.247
hxxp://static.n.shifen.com/hmt/icon/21.gif
hxxp://jc.941pojie.com/img/zs.jpg 183.60.111.247
hxxp://c.split.cnzz.com/stat.php?id=1253024109&web_id=1253024109
hxxp://c.split.cnzz.com/core.php?web_id=1253024109&t=z
hxxp://jc.941pojie.com/img/bg.gif 183.60.111.247
hxxp://z8.cnzz.com/stat.htm?id=1253024109&r=http://cctv-6.padonline.net:5566/&lg=en-us&ntime=none&cnzz_eid=none&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1415649696 42.156.140.21
hxxp://jc.941pojie.com/img/bgheader.gif 183.60.111.247
hxxp://jc.941pojie.com/img/bgnav.gif 183.60.111.247
hxxp://jc.941pojie.com/img/bgh.gif 183.60.111.247
hxxp://jc.941pojie.com/img/gg.png 183.60.111.247
hxxp://jc.941pojie.com/img/1gg.png 183.60.111.247
hxxp://jc.941pojie.com/img/下载.jpg 183.60.111.247
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1153140611
hxxp://pcookie.split.cnzz.com/9.gif?abc=1&rnd=1784473045
hxxp://z3.cnzz.com/stat.htm?id=5076676&r=http://www.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725
hxxp://jc.941pojie.com/img/top.png 183.60.111.247
hxxp://z6.cnzz.com/stat.htm?id=3325108&r=http://www.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526
hxxp://jc.941pojie.com/img/logo.gif 183.60.111.247
hxxp://jc.941pojie.com/img/bgtitle.gif 183.60.111.247
hxxp://hm.baidu.com/h.js?c8a6515c967e27925a2fd6685fe9963c 61.135.185.140
hxxp://www.lszwg.com/img/js.gif 183.60.111.247
hxxp://www.941pojie.com/img/bgnav.gif 183.60.111.247
hxxp://www.lszwg.com/img/icon.png 183.60.111.247
hxxp://www.lszwg.com/img/下载.jpg 183.60.111.247
hxxp://eiv.baidu.com/hmt/icon/21.gif 115.239.211.92
hxxp://www.941pojie.com/img/gif008.gif 183.60.111.247
hxxp://www.941pojie.com/img/zsf.gif 183.60.111.247
hxxp://s19.cnzz.com/stat.php?id=1253024109&web_id=1253024109 1.99.192.16
hxxp://www.lszwg.com/img/jbc.gif 183.60.111.247
hxxp://www.941pojie.com/img/logo.gif 183.60.111.247
hxxp://s85.cnzz.com/stat.php?id=3325108&show=pic1 1.99.192.16
hxxp://c.cnzz.com/core.php?web_id=3325108&show=pic1&t=z 42.156.140.11
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1784473045 42.120.219.171
hxxp://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB 42.120.219.171
hxxp://www.941pojie.com/img/bgtitle.gif 183.60.111.247
hxxp://www.941pojie.com/ 183.60.111.247
hxxp://www.941pojie.com/img/gg.png 183.60.111.247
hxxp://www.lszwg.com/img/top.png 183.60.111.247
hxxp://www.941pojie.com/img/jbc.gif 183.60.111.247
hxxp://c.cnzz.com/core.php?web_id=1253024109&t=z 42.156.140.11
hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369 42.156.140.16
hxxp://www.lszwg.com/img/lhr.gif 183.60.111.247
hxxp://www.941pojie.com/img/swz.gif 183.60.111.247
hxxp://c.cnzz.com/core.php?web_id=1253112259&t=z 42.156.140.11
hxxp://c.cnzz.com/core.php?web_id=5076676&show=pic2&t=z 42.156.140.11
hxxp://www.lszwg.com/img/swz.gif 183.60.111.247
hxxp://www.941pojie.com/img/lhr.gif 183.60.111.247
hxxp://www.lszwg.com/img/bgtitle.gif 183.60.111.247
hxxp://www.lszwg.com/img/bgnav.gif 183.60.111.247
hxxp://www.lszwg.com/img/1gg.png 183.60.111.247
hxxp://www.lszwg.com/img/bg.gif 183.60.111.247
hxxp://www.lszwg.com/img/gif008.gif 183.60.111.247
hxxp://www.941pojie.com/img/js.gif 183.60.111.247
hxxp://www.lszwg.com/img/046bt.gif 183.60.111.247
hxxp://www.lszwg.com/img/bgh.gif 183.60.111.247
hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=http://www.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725 42.156.140.16
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=895496844 42.120.219.171
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1153140611 42.120.219.171
hxxp://www.941pojie.com/img/gua.gif 183.60.111.247
hxxp://www.941pojie.com/img/046bt.gif 183.60.111.247
hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=http://www.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526 42.156.140.19
hxxp://www.lszwg.com/img/bgheader.gif 183.60.111.247
hxxp://hm.baidu.com/hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=开心快乐每一天! 61.135.185.140
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=333037092 42.120.219.171
hxxp://www.941pojie.com/img/bg.gif 183.60.111.247
hxxp://www.941pojie.com/img/top.png 183.60.111.247
hxxp://www.lszwg.com/ 183.60.111.247
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1036514576 42.120.219.171
hxxp://www.941pojie.com/img/bgheader.gif 183.60.111.247
hxxp://www.941pojie.com/css/style.css 183.60.111.247
hxxp://www.lszwg.com/css/style.css 183.60.111.247
hxxp://www.941pojie.com/img/2014052276129177.gif 183.60.111.247
hxxp://s25.cnzz.com/stat.php?id=5076676&show=pic2 1.99.192.16
hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043 42.156.140.19
hxxp://www.941pojie.com/img/1gg.png 183.60.111.247
hxxp://www.941pojie.com/img/bgh.gif 183.60.111.247
hxxp://pub.idqqimg.com/wpa/images/group.png 103.7.30.59
hxxp://s13.cnzz.com/stat.php?id=1253112259&web_id=1253112259 1.99.192.16
hxxp://www.lszwg.com/img/logo.gif 183.60.111.247
hxxp://www.lszwg.com/img/gg.png 183.60.111.247
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=2071775127 42.120.219.171
hxxp://www.941pojie.com/img/zs.jpg 183.60.111.247
hxxp://www.lszwg.com/img/zs.jpg 183.60.111.247
hxxp://www.lszwg.com/img/zsf.gif 183.60.111.247
hxxp://hzs2.cnzz.com/stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005 42.156.140.19
hxxp://cnzz.mmstat.com/9.gif?abc=1&rnd=1532175039 42.120.219.171
hxxp://www.941pojie.com/img/icon.png 183.60.111.247
hxxp://www.lszwg.com/img/gua.gif 183.60.111.247
hxxp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z 42.120.219.171
hxxp://www.941pojie.com/img/下载.jpg 183.60.111.247
hxxp://www.lszwg.com/img/2014052276129177.gif 183.60.111.247
hxxp://zs25.cnzz.com/stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438 42.156.140.16
qqqggg777444.jyjaj.com 183.56.169.162
941pojie.meibu.net 112.228.25.244
cctv-6.padonline.net 183.56.169.162
a510sf.010aimei.com 61.174.41.254


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET POLICY HTTP Request on Unusual Port Possibly Hostile

Traffic

GET /stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=112051369 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:19 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:19 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..


GET /stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=129590043 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /stat.php?id=1253112259&web_id=1253112259 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s13.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 15:18:04 GMT
246d..(function(){function l(){this.c="1253112259";this.O="z";this.K="
";this.H="";this.J="";this.o="1410443284";this.M="z7.cnzz.com";this.I=
"";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_cnz
z_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,c){
try{var b=[];b.push("siteid=1253112259");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: gogozz1pj.huihaowy.com
Connection: Keep-Alive


HTTP/1.1 302 Redirect
Content-Length: 156
Content-Type: text/html
Location: hXXp://cctv-6.padonline.net:5566/
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Thu, 11 Sep 2014 13:47:51 GMT
<head><title>Document Moved</title></head>.<
;body><h1>Object Moved</h1>This document may be found &
lt;a HREF="hXXp://cctv-6.padonline.net:5566/">here</a></bo
dy>HTTP/1.1 302 Redirect..Content-Length: 156..Content-Type: text/h
tml..Location: hXXp://cctv-6.padonline.net:5566/..Server: Microsoft-II
S/6.0..X-Powered-By: ASP.NET..Date: Thu, 11 Sep 2014 13:47:51 GMT..<
;head><title>Document Moved</title></head>.<bo
dy><h1>Object Moved</h1>This document may be found <
a HREF="hXXp://cctv-6.padonline.net:5566/">here</a></body&
gt;..


GET /jiaqun.htm HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: jc.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 224
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://jc.941pojie.com/jiaqun.htm
Last-Modified: Thu, 29 Aug 2013 09:28:40 GMT
Accept-Ranges: bytes
ETag: "0d46a259aa4ce1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
..........t.;N.0.E.by.qb.c.$,.=...5.:.......iG. *:.AE.....9..5...al...
`:Q.....c\...z.\..I7..q....1........m.Y).).V...XH.EZ@[email protected].
...B[..~tD..`hhJ...k{.u.....5.Gp.1..}I..Q...]...r.}.y..|.>.~q..NI.q
.[........C.K....HTTP/1.1 200 OK..Date: Thu, 11 Sep 2014 13:48:30 GMT.
.Content-Length: 224..Content-Type: text/html..Content-Encoding: gzip.
.Content-Location: hXXp://jc.941pojie.com/jiaqun.htm..Last-Modified: T
hu, 29 Aug 2013 09:28:40 GMT..Accept-Ranges: bytes..ETag: "0d46a259aa4
ce1:3e08a"..Vary: Accept-Encoding..Server: Microsoft-IIS/6.0..X-Powere
d-By: ASP.NET............t.;N.0.E.by.qb.c.$,.=...5.:.......iG. *:.AE..
...9..5...al...`:Q.....c\...z.\..I7..q....1........m.Y).).V...XH.EZ@.@
......R.Re.2.f....B[..~tD..`hhJ...k{.u.....5.Gp.1..}I..Q...]...r.}.y..
|.>.~q..NI.q.[........C.K......


GET /9.gif?abc=1&rnd=1784473045 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:18 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..


GET /9.gif?abc=1&rnd=1153140611 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:18 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443298; expires=Sun, 08-Sep-24 13:48:18 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..


GET /stat.htm?id=3325108&r=http://VVV.941pojie.com/&lg=en-us&ntime=1410443285&cnzz_eid=665276032-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=752433526 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /stat.htm?id=5076676&r=&lg=en-us&ntime=none&cnzz_eid=37904339-1410443283-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1891023438 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /stat.php?id=5076676&show=pic2 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s25.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 15:18:04 GMT
1f7a..(function(){function l(){this.c="5076676";this.O="z";this.K="pic
2";this.H="";this.J="";this.o="1410443284";this.M="zs25.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=5076676");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET /core.php?web_id=1253112259&t=z HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 14:03:05 GMT
2ef..!function(){var p,q,r,a=encodeURIComponent,b="1253112259",c="",d=
"",e="online_v3.php",f="z7.cnzz.com",g="1",h="text",i="z",j="站&
#38271;统计",k=window["_CNZZDbridge_" b].bobject,l="http:"
,m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("
h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m
&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.crea
teScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.ph
p?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.co
m/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'>
<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="<
a href='" q "' target=_blank title='" j "'>" j "</a>",k.creat
eIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11 S
ep 2014 13:48:05 GMT..Content-Type: application/javascript..Transfer-E
ncoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep 2
014 13:48:05 GMT..Expires: Thu, 11 Sep 2014 14:03:05 GMT..2ef..!functi
on(){var p,q,r,a=encodeURIComponent,b="1253112259",c="",d="",e="online
_v3.php",f="z7.cnzz.com",g="1",h="text",i="z",j="站长ń
79;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n=l "
//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o.pus
h("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.callRequ
est([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScriptIcon
(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?web_id

<<< skipped >>>

GET /core.php?web_id=1253024109&t=z HTTP/1.1

Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:12 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:12 GMT
Expires: Thu, 11 Sep 2014 14:03:12 GMT
2ef..!function(){var p,q,r,a=encodeURIComponent,b="1253024109",c="",d=
"",e="online_v3.php",f="z8.cnzz.com",g="1",h="text",i="z",j="站&
#38271;统计",k=window["_CNZZDbridge_" b].bobject,l="http:"
,m="1",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("
h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m
&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.crea
teScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.ph
p?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.co
m/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'>
<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="<
a href='" q "' target=_blank title='" j "'>" j "</a>",k.creat
eIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11 S
ep 2014 13:48:12 GMT..Content-Type: application/javascript..Transfer-E
ncoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep 2
014 13:48:12 GMT..Expires: Thu, 11 Sep 2014 14:03:12 GMT..2ef..!functi
on(){var p,q,r,a=encodeURIComponent,b="1253024109",c="",d="",e="online
_v3.php",f="z8.cnzz.com",g="1",h="text",i="z",j="站长ń
79;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="1",n=l "
//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o.pus
h("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.callRequ
est([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScriptIcon
(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?web_id

<<< skipped >>>

GET /cj.txt HTTP/1.1
Accept: */*
Accept-Language: en-us
If-Modified-Since: Thu, 01 Jan 1970 00:00:00 GMT
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: jc.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:29 GMT
Content-Length: 11879
Content-Type: text/plain
Content-Encoding: gzip
Content-Location: hXXp://jc.941pojie.com/cj.txt
Last-Modified: Wed, 10 Sep 2014 03:44:39 GMT
Accept-Ranges: bytes
ETag: "80ed278ca9cccf1:3e080"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........}Y..H..7).;........P.1'q..}.8..........P...aO..TZ`....55.z.
'.#b...?.8v&.D........U.$....v ...i...n..Z...J'.uo.../?).s.j...w....x.
...*s.#.}..:.:.u?..Q.-..u}$........Q.<.(.........N..N..{Q..P...J.E.
.....q.o.y~V........<3h....D.........0....W.........E..?X3..G.Om..U
...q 6.... 6U.../.;.......O....p........l.SM><...........!"!..?O
...n."v.*k6g...v.^.t.....v.s........1........X.x.}../.k...3Z.|...?Z...
..r.s..WOS.XuUw .. ^.......-......y.=....8.b|ku..<..-....T.....Fo..
4.O..{.%.<..K.x.=...[./....1[[email protected].....:..tr..s.?b.........
...A...~x....y.Dy.@J>^..4V.HH."".F..1......d....n........kZA..k.N..
..r....A.0..6..Bp#.=..Z....<....}?..F_.N...)4....v..K...u..V..Z....
;.K.W[....t..W.yr.3...p.....|.F%..../`.#...].L......cx..F.-...s...D.=.
G..\O.b.o..t. .n.Vz..b..n..0oX......3....3aV...)..On.....j........i=.
*...t.[...u'..5.[8.o..k.t.....KS..l....{........94....~.g.\..LT..k.1aw
9.R.l...D ..:&...]...y&.3}&|.....".......TM......#.^W.........F.=..LV.
.....y........]......]-G....*x......\.o.s.U..~....8BW.`....Z..f.......
r:.e...V2..2........w..:..%6...Xfg..k6.z..9,..'..(.a.>.rV...U[...u`
}.......>.....Z.Zv.C...y.k...p..x.....0...n.....X7....Y..}...4RPo..
W~:..t...j6..r.{..-........c.Yq=.j.N..;......2.......W.7.4;...f/......
.n..*Uxs..c...5.....U.z.../.d...M.....k.6S.n.ap$.._.....T.AO.5.In.....
.aNq4F....7..\....9..y]o...S...{.[...t.'I....Ufx.U.$!..%..d.'.x...\..J
..Rc.O.q.....>\.l..!C.<..8..?I..C.t.....m.7.a.2.!....^]EQ.....V(
..m............ ..1..c3S.#._/3 ...fA:...7.-....c<X.........v..[

<<< skipped >>>

GET /app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Connection: Keep-Alive
Host: pcookie.cnzz.com


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDMFxExICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;....



GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..


GET / HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...

<<< skipped >>>

GET /img/gif008.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;
....



GET /img/lhr.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:32 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid

<<< skipped >>>

GET /img/swz.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x

<<< skipped >>>

GET /img/js.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.

<<< skipped >>>

GET /img/2014052276129177.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aX..................!..copyright. 1996 Charles H. Tupper  All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;
....



GET /img/046bt.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..

<<< skipped >>>

GET /img/icon.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.font>....



GET /img/zs.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.lszwg.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc

<<< skipped >>>

GET /img/jbc.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:50 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................

<<< skipped >>>

GET /img/js.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:53 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.

<<< skipped >>>

GET /img/swz.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:55 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x

<<< skipped >>>

GET /img/gua.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:56 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................

<<< skipped >>>

GET /img/bgnav.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:58 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P

<<< skipped >>>

GET /img/bg.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:58 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;
....



GET /img/bgheader.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:59 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%

<<< skipped >>>

GET /img/gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:59 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l

<<< skipped >>>

GET /img/bgh.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:00 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..

<<< skipped >>>

GET /img/1gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:00 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...

<<< skipped >>>

GET /img/bg.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;
....



GET /img/bgnav.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P

<<< skipped >>>

GET /img/gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l

<<< skipped >>>

GET /img/下载.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:49:04 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
<html><head><title>Error</title></head>&
lt;body>........................</body></html>
..
..



GET /img/bgtitle.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:04 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...

<<< skipped >>>

GET /img/top.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:05 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......F......:\.....bKGD..............pHYs.......... 
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1

<<< skipped >>>

GET /h.js?c8a6515c967e27925a2fd6685fe9963c HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Etag: c348ff65ba11fbc940d2c432618797e4
Cache-Control: max-age=0, must-revalidate
Content-Encoding: gzip
Content-Type: application/javascript
Set-Cookie: HMACCOUNT=EF155AF42BFB7713; Path=/; Domain=hm.baidu.com; Expires=Sun, 18 Jan 2038 00:00:00 GMT
P3P: CP="CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR"
Connection: Keep-Alive
Content-Length: 5694
Date: Thu, 11 Sep 2014 13:48:10 GMT
Server: apache
...............(function(){var c={id:"c8a6515c967e27925a2fd6685fe9963c
",dm:["cctv-6.padonline.net"],etrk:[],js:"tongji.baidu.com/hm-web/js/"
,icon:'/hmt/icon/21|gif|20|20',br:false,ctrk:false,align:-1,nv:-1,vdur
:1800000,age:31536000000,rec:0,rp:[],trust:0,vcard:0,.[k......OA.9....
I..BT?......n...v.. ......dc..gF...../b1..h4...h...h...Xf.t.k.i..c;..=
../.......t.`....}.......7N3.'.i..)wb.L..._...n[|..Lk.-..a."....`9.I..
.e.... K..$1........fh......y.,L..Y^..e.l..-r....t0..^99....4~...'<
..im_........i.W...L..i).yH...X...V.......V......|....Jim)..~,X.a|%.^N
c.4..r..LY2...e.....9.<....!...[.........c2...i.....^GI...^.a......
...jgQ.>&.O/.;T.ey...&....j.8cs.....R..u..WUl...|Tc..jg.. M....w..|
..1....^.............n.xx...:N...:@9.epz.....?lb.3.$.....y _.R....S...
.i...%.0...%.w..:.8...;.s.)..E.%............8$.m...u..V....3.'..s.2.;2
...K..&.B4.l&..`s,.clf.....p..Cr... ....)..XGx.....c.....#.$..(.eu.. .
'.$...3.oD..(.......C.%..... .o0..z.4.9K..r.o.Ve..p......R.#.....$..&l
t;.2v [email protected]{b/.....7..z.p.J..P...V.X4HB.....2.%...}0......Zc.
.p2........g....#RY.s.F.I..... .E.......A..r..V....o..;p5S .v..>..6
.T.~L.Y.hn.r.,...Q?. MBA.............!..{......."E.:S.._'.d..g...0.O.=
...' .i)......{_.R....[.Y]..g....r?.....z.......vkJg..M.*..".. Mg..L..
....].l.T.i.A. ...d...T4?K.9.~j...g.yS.r..B..QS..<.8O.u......;.!.{.
S.M.......}A... ..o{.g..j.v(m.{...{....B.m.([email protected](hS..)L
.,J..3d......q..<,.._.......o.Q.s...h......UN..r.,3N...v..].......:
>..A..F.....[8..~..j ... o...<.DOl.......Y=d.....r..a5..&..\

<<< skipped >>>

GET /hm.gif?cc=1&ck=1&cl=32-bit&ds=1276x846&et=0&fl=11.6&ja=1&ln=en-us&lo=0&nv=1&rnd=1926352316&si=c8a6515c967e27925a2fd6685fe9963c&st=1&v=1.0.63&lv=1&tt=开心快乐每一天! HTTP/1.1

Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hm.baidu.com
Connection: Keep-Alive
Cookie: HMACCOUNT=EF155AF42BFB7713


HTTP/1.1 200 OK
Cache-Control: private, max-age=0, no-cache
Pragma: no-cache
Content-Type: image/gif
X-Content-Type-Options: nosniff
Connection: Keep-Alive
Content-Length: 43
Date: Thu, 11 Sep 2014 13:48:11 GMT
Server: apache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Cache-Cont
rol: private, max-age=0, no-cache..Pragma: no-cache..Content-Type: ima
ge/gif..X-Content-Type-Options: nosniff..Connection: Keep-Alive..Conte
nt-Length: 43..Date: Thu, 11 Sep 2014 13:48:11 GMT..Server: apache..GI
F89a.............!.......,...........L..;..


GET /status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.webscan.360.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: 360Server
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip
2669.............R&...PNG........IHDR......./......3......pHYs........
........MiCCPPhotoshop ICC profile..x..SwX...>..e.VB....l.."#....Y.
[email protected]....(.gA..Z.U\8.....}z............y.....&...j.
9R.<:...OH......H.. ....g......yx~t.?...o...p..$......P&W. ..."....
.R...T.......S.d.....ly|B"......I>..................(G$.@..`U.R,...
...@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0...._p..H.......K.3...
..w....!..l.Ba.).f.."...#.H..L.........8?......f.l.....k.o">!......
...N..._....p...u.k.[..V.h..][email protected].<......%b..0..>.
[email protected][email protected]..#......)..4.\,...X..P"M.y.R.D!.
.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@ ...........
\...L....D..*.A..............a.D@.$.<.B........A.T.:.............18
....\..p..`........A...a!:..b.."......"aH4... ...Q"..r...Bj.]H#.-r.9.\
@.... [email protected].]...k....=.....K.ut.}..c..1.f..a\..E
`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z..
.xb:..XF.&.!.!.%^'.._.H$....N.!%.2I.IkH.H-.S.>..i.L&..m....... ....
..O.......:...L..$R...J5e?....2B...Q.......:.ZIm.vP/S...4u.%...C..-...
.igi.h/.t.....E....k.......w......Hb(.k.{...../.L......T0.2..g...oUX*.
*|.....:.V.~...TUsU?.y..T.U..^V}.FU.P.........U..6..RwR.P.Q_.._...c...
.F..H.Tc....!..2e.XB.rV..,k.Mb[...Lv...v/{LSCs.f.f.f..q.......9..J.!..
.{-.-?-..j.f.~.7.z...b.r......up.@.,..:m:.u..6.Q....u..>.c.y.......
..G.m..........704.6..l18c...c.k.i........h...h..I.'.&..g.5x.>f.o.b
.4.e.k<abi2.......)..k.f....t...,.......9..k.a........E..J.6...

<<< skipped >>>

GET /stat.php?id=3325108&show=pic1 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s85.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 15:18:05 GMT
246d..(function(){function l(){this.c="3325108";this.O="z";this.K="pic
1";this.H="";this.J="";this.o="1410443285";this.M="hzs2.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=3325108");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:28 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.941pojie.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...

<<< skipped >>>

GET /css/style.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.941pojie.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.

<<< skipped >>>

GET /img/zsf.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]

<<< skipped >>>

GET /img/jbc.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:34 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................

<<< skipped >>>

GET /img/swz.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:37 GMT
Content-Length: 20690
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/swz.gif
Last-Modified: Sun, 01 Sep 2013 06:16:54 GMT
Accept-Ranges: bytes
ETag: "0cf8bdadaa6ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..K............:.....I..J..o.....^...........r..H.E#.....ZD.(...
.....E..[.......TT.....`....d4............\.\..F#....o."...Y..q.....?.
.J..I..uc.8.._........]........K...........c.s5........U....@@...,.,.*
*..c..~C.C..}........T.....G....S*..P..}..J..U.....I........g.....z..I
..i...4...4......R..yV.2....mm.......|8.....X...u.A.....t........B..l.
....H..X..h.....[........?..O..`.............l3...o.o....``......7.7.9
9.ww.$$".".........h.hN.N|.|.............Z2.................../..NN...
..k.....K..n.K'J.*..G.....]...,....o..B..Kn.>..Z........X..{.....g.
.}.......]-..S.....N.....{...;.#.<!...[.4...{.D........./.......[..
U..`..P.sA..V..G..W..R..f..Q..g....}A..]..R.....a........a.ZZ......a.a
.....r............1.1.11J.J..{..........rr...............u.u....gg....
..=.=.??.........!..NETSCAPE2.0.....!.......,......K........H......*\.
.....#J.H.....3j...... C..I....(S.\[email protected].*
].....P.J.J....X.j......`...K....h..].....p...K....x............L.....
. ^.....*...E..d.. [..4....C7....h..?...Z5...K...........}q.m..u...06.
.&}...{......?...A..[..~v.....1.o..ax...k<?>....l....>....C.'
..}...W\|....~.M.ZA..3.}....t......N..y.}.ai..(...Mw ._qx ..AX.~..h...
........}..h.........q_.?..$.E..#...i....8.zQ*)$.MRY..x.H..C....:.g z.
...rl....q..&. .%...j.%.].).B......RT(.L".#k.j....hQ...M....Rji......G
....5.).e...)..^.*(h`......j....'..b.J.....c...........#.Z....Y.x...k.
..f ..i....N.k.P..J...*...*..|..R........r..;........-...;n...jjC@2.(.
...o..Z..{...qT..j1....je.-.....Zm...,...6<1.n.G...zzi...|. ..x

<<< skipped >>>

GET /img/gua.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:38 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................

<<< skipped >>>

GET /img/bg.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 1065
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bg.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..................f..3..............f..3..............f..3....f.
.f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3....
..........f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3
............f..3..............f..3..............f..3..............f..3
....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...f..f..f..f.ff
.3f..f..f..f..f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3
ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3..3.f3.33..3..3..3..
3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.........
....f..3..............f..3..............f..3....f..f..f..ff.f3.f..3..3
..3..3f.33.3............f..3...f..e..d..a..`..Rn.Je.Id.Gb.Mg.Oi.Qk.Pj.
Zw.Vq.^|.Xs.\y.Yt.`}.a~._|.f..Fa.Hc.Kf.Nj.Lg.Pl.So.Vt.Tp.Yv._~.[x.Zw.c
..b..^{....!.......,...............H......*\.0..l..J.H......i...c.. C.
...d.~(S.\..%.m0a.|...M..r.....O............&=.....G.5e..j..X..... ..`
........h..]..m..p...;7..r.....W.......L.pa{.. 6.......I.L..e..2k.....
..A..=.....S.FM.....b..G.....r............;w.... ........I.N.zux..k..]
;.........|...;
....



GET /img/bgheader.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%

<<< skipped >>>

GET /img/bgnav.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 3645
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgnav.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aa.N.............................................................
............EQ.Tk.Ma.CT.8Fr.$;[email protected].;M}a~.Zt.Tm.Ri.N
e.DW.CW.9Jxb..]x.Qi.H][email protected]}....Xv.c..\z.Yu.Xt.Vq.To.Jb.3Cme.
.d..c..^{.Zv.Zv.Rl.E[.7Hu5Fqb.._|.Zw.Yv.Xt.Xs.Vp.CX.BV.>Q.`}.^z.^|.
Zu.Uo.Tm.I_.AU.Ka.J`.BV.)6U`}.Sg................[z.Le.Kd.Sp.La.{|~....
.....TVX..............................................................
...... ..)..2..6..7..>..C..J..S..T..o.............................!
..&..&..(.. .. ..,........5..6..9..9..=..>..[..]..]..e..g..m..p..q.
.|...............................................0..6..G..T..W........
......................................................................
......sqo.............................................................
....................!.......,....a.N........2d..%4.(....C a..xH... ...
...... C..h... a:Vq...........H.4:^[email protected].(..H."m...P.O..e..'..U
..$x....'D@.....,[email protected]?..K..].(....e...b.......%..|..C..#)R..<
..e..3G.......C.....\('&.Y....&P|d..BE./].x..{..............._.{w...1k
....j.W^....F..[b ..1e......7.........O.~|.....2.I.-.....=T.B.DXaDc0..
E.b.`....a..f.....vx.. ..a.$.!..(.xC..ZX.......*....O.. .G..C.c.......
.6..0..I6.d..<)..TVI%.On#N...1F......L=...b.Q.-.p..&.....t.i..x....
|...&.<2I!.x ..$....)...!.x"...T....f....v....^....x..1...C..f!....
.a.,.$..'...H'....... .... J([email protected]."..B.).| ....k...
..n(..B."..2L.t..D.)..C.!x.K)..R.1......'....7....#..*....)..........&
gt;.....4.J#.8..*,....0.,..4..r#&......Q..?dPm....H1.<.H1H3...P

<<< skipped >>>

GET /img/bgh.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..

<<< skipped >>>

GET /img/gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:42 GMT
Content-Length: 23328
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......'.............sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<..Z.IDATx^....VG....T.tv..O./s2
.y..5..i...A00......j< ........b....2X..l...v.....,6x_0...,6`6.6^.J
......s...........O....D.._Fd&U..,.?cL.\..........P.?.).....2...y.....
..)....o./....E|DK.*4).._L......./?.T.w.....,....7z].Zj..r...\.o..o.?&
gt;.y:......c...Bu_...~..|..q...J......s...X.....R..{G[.;.;.....r...OG
O....T...........h.ok.....h/[email protected]...;.G.......9..ON...??......./.
.e....~..S.......Nz..$.....=..g..S....#..x..?W...,...y.c..8..~.....>
;..~}..W.t ./.u. .%..c.#.%lY..O...Y|.....N}E.....{.....&O.s....G.#G!.%
y...!...0t....C.N...........=.O.......=. .z.~..i......:..l..,.........
......=w@......}..^....k..w..e..o~.s.7..q.............;X..w'....[..[..
....lX.|."....R,.N.;G,F.<.....RX.=..a...|.,...a\"3.7...X....^..r..M
..x.....T0..g.. .B...i.?BlE.K......_..Mx..............1...c=....o.....
...{.>9..<?.-.1..g...Rr.j.......C.....{..va....:}.....;.._y)cm..
.I...h...[..z.6.K......1g.......cd,..5..n!.._...g...,....'N..{..$.....
..B.....'.:G...7!..q../N6......<./.7.V.z.h.0.{.0..?..q.....s.~v....
?....t.>@.j-'....o.E.G?w..V....d.....gP......x............O.=D>.
..D..q....`.w|q.l.....[..^........../OO.../w|...................>..
.i0.....1.k.U1N#...._._"..s.I._.|..g...O.4... .(>.n.&}..!..b.4.`..N
>..!>....8.qs8..R8..M.'.......?..Cxa.6..<..{.....C.w....(..~
...KY*..[....|[email protected]..'a...7.H.s.<.C.....y...._.:.../a...I^....
.c.W<.....<.1y.|..).........'B>...V<.=.4..G.?....YN.&l

<<< skipped >>>

GET /img/1gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:45 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...

<<< skipped >>>

GET /img/logo.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:48 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.

<<< skipped >>>

GET /stat.htm?id=1253112259&r=&lg=en-us&ntime=none&cnzz_eid=804168892-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined&h=1&rnd=999258932 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: z7.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:08 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /hmt/icon/21.gif HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: eiv.baidu.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: image/gif
ETag: "762990053"
Accept-Ranges: bytes
Last-Modified: Tue, 13 Apr 2010 09:38:40 GMT
Expires: Sat, 20 Jul 2024 13:48:11 GMT
Cache-Control: max-age=311040000
Content-Length: 1119
Date: Thu, 11 Sep 2014 13:48:11 GMT
Server: BWS/1.0
Connection: Keep-Alive
GIF89a........s..E.....M...................ZS.2-.YS.......2,.c[..D....
...0'..:..0.&..]Z..8..>..D.TM.................C................._..
^.....u..w........~........k.4......X..d.......=1.....a.c[.PH.h_.....b
..........PH........A..9....h`..J..1.......g`..W........2........z.#..
.p..m....jd........*.............[Q...........6..G..............6..t..
........... ..TL.....!....$....."..;0.....h.7-..............Z.........
....%..:.....H@....^W.QJ..'. !..........70.._. %.'...T.0'..Q.G?.ws....
-$........h.}w.....>...........L.....#.......:0.............\S.....
........*".....Q..............<..T.!...p.$...}........N..........d_
...........j.......VN.....o.....e........[............................
......................................................................
....................!.......,............u...,..>6.T.T..&T.".H. ...
.3^.PQ.G..:^..H.-.T....2#!........K..iP.&..03%X..x.P/^.$...`...G>Xd
....!..d.T...j.,..fQ..8l<..U%..G|.h.......$p..f......R..b.....*R@W"
2y..8..V3.LV`t.e..7.>.........\D..O.H.....$...^.]..).. ...9..E...d\
...V.U1..i......B]......c.P<0.i...v.]D..G .?p-.CD.Fi;>..v....r`.
.&........./.dp....`.....;..


GET /stat.php?id=5076676&show=pic2 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s25.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:03 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:03 GMT
Expires: Thu, 11 Sep 2014 15:18:03 GMT
246d..(function(){function l(){this.c="5076676";this.O="z";this.K="pic
2";this.H="";this.J="";this.o="1410443283";this.M="zs25.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=5076676");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:19 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:19 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:19 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..


GET /9.gif?abc=1&rnd=333037092 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDMFxExICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=df2de106; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=0722dcead177bb21e29e42eb_1410443285; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:05 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDMFxEx
ICAcGK9Ofx zPB; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.m
mstat.com..Set-Cookie: sca=df2de106; path=/; domain=.cnzz.mmstat.com..
Set-Cookie: atpsida=0722dcead177bb21e29e42eb_1410443285; expires=Sun,
08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com..Location: htt
p://pcookie.cnzz.com/app.gif?&cna=FZaYDMFxExICAcGK9Ofx zPB..Expires: T
hu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache..Pragma: no-cach
e..GIF89a.............!.......,...........L..;
....



GET /9.gif?abc=1&rnd=895496844 HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..


GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:07 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:07 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..


GET /wpa/images/group.png HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:47:58 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:47:58 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank
.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)

<<< skipped >>>

GET /img/pic2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 431
Last-Modified: Mon, 02 Dec 2013 05:46:13 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:05 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes
GIF89aP.........eee000...........................e...00...0...........
.......................................!..Powered by AFEI.!.....S.,...
.P......` .di.h.....p,.tm.x..|....a..._..1i,...&3.\2...v{.-...xL.s.g.b
-h...5......;.=g......".......m......................m..............."
.........................".......m..............."..w.....u.n..m......
....".....H......*.Q.....#J.H.b...3j..Q... C..I......9.\)b...0c..I....
8[........;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2
014 13:48:05 GMT..Content-Type: image/gif..Content-Length: 431..Last-M
odified: Mon, 02 Dec 2013 05:46:13 GMT..Connection: keep-alive..Keep-A
live: timeout=5..Expires: Fri, 12 Sep 2014 13:48:05 GMT..Cache-Control
: max-age=86400..Accept-Ranges: bytes..GIF89aP.........eee000.........
..................e...00...0..........................................
........!..Powered by AFEI.!.....S.,....P......` .di.h.....p,.tm.x..|.
...a..._..1i,...&3.\2...v{.-...xL.s.g.b-h...5......;.=g......".......m
......................m...............".........................".....
..m..............."..w.....u.n..m..........".....H......*.Q.....#J.H.b
...3j..Q... C..I......9.\)b...0c..I....8[........;
....



GET /img/pic1.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 428
Last-Modified: Fri, 16 Jan 2009 08:10:47 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:06 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes
GIF89a.......f..3...33.......................................!..NETSCA
PE2.0.....!..Powered by AFEI.!.......,.............I........08bX....d.
n...CS.3......_..`..H..H\8....)...S.b.UX.....(...r.L....tb]&"......#..
.o.V.a..D..o.V.a..........D..o.V.a..........D...........!.......,.....
........I........08bX....d.n...CS.3......_..`..H..H\8....).:[email protected]...
x ..........D.| .#.u.a....n~D..[....n..........D..[...n..........D....
.......;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2014
13:48:06 GMT..Content-Type: image/gif..Content-Length: 428..Last-Modi
fied: Fri, 16 Jan 2009 08:10:47 GMT..Connection: keep-alive..Keep-Aliv
e: timeout=5..Expires: Fri, 12 Sep 2014 13:48:06 GMT..Cache-Control: m
ax-age=86400..Accept-Ranges: bytes..GIF89a.......f..3...33............
...........................!..NETSCAPE2.0.....!..Powered by AFEI.!....
...,.............I........08bX....d.n...CS.3......_..`..H..H\8....)...
S.b.UX.....(...r.L....tb]&"......#...o.V.a..D..o.V.a..........D..o.V.a
..........D...........!.......,.............I........08bX....d.n...CS.
3......_..`..H..H\8....).:[email protected] ..........D.| .#.u.a....n~D..[..
..n..........D..[...n..........D...........;..


GET /stat.php?id=3325108&show=pic1 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s85.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 15:18:05 GMT
1f7a..(function(){function l(){this.c="3325108";this.O="z";this.K="pic
1";this.H="";this.J="";this.o="1410443285";this.M="hzs2.cnzz.com";this
.I="";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_
cnzz_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,
c){try{var b=[];b.push("siteid=3325108");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET /stat.htm?id=5076676&r=http://VVV.941pojie.com/&lg=en-us&ntime=1410443284&cnzz_eid=155029651-1410443284-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1501372725 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: zs25.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:18 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /tc.txt HTTP/1.1
Accept: text/html, application/xhtml xml, */*
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
Connection: Keep-Alive
Host: jc.941pojie.com


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:27 GMT
Content-Length: 29
Content-Type: text/plain
Content-Location: hXXp://jc.941pojie.com/tc.txt
Last-Modified: Tue, 22 Jul 2014 16:32:43 GMT
Accept-Ranges: bytes
ETag: "80c7b48fcaa5cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
hXXp://gogozz1pj.huihaowy.comHTTP/1.1 200 OK..Date: Thu, 11 Sep 2014 1
3:48:27 GMT..Content-Length: 29..Content-Type: text/plain..Content-Loc
ation: hXXp://jc.941pojie.com/tc.txt..Last-Modified: Tue, 22 Jul 2014
16:32:43 GMT..Accept-Ranges: bytes..ETag: "80c7b48fcaa5cf1:3e08a"..Ser
ver: Microsoft-IIS/6.0..X-Powered-By: ASP.NET..hXXp://gogozz1pj.huihao
wy.com..


GET /stat.htm?id=1253024109&r=http://cctv-6.padonline.net:5566/&lg=en-us&ntime=none&cnzz_eid=none&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=1415649696 HTTP/1.1
Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: z8.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:13 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /status/pai/hash/6330cf46f68cd2c7c40a422626d1cb30 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img.webscan.360.cn
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: 360Server
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Content-Encoding: gzip
2669.............R&...PNG........IHDR......./......3......pHYs........
........MiCCPPhotoshop ICC profile..x..SwX...>..e.VB....l.."#....Y.
[email protected]....(.gA..Z.U\8.....}z............y.....&...j.
9R.<:...OH......H.. ....g......yx~t.?...o...p..$......P&W. ..."....
.R...T.......S.d.....ly|B"......I>..................(G$.@..`U.R,...
...@"......Y.2G.....v.X..@`...B,.. 8..C.... L..0...._p..H.......K.3...
..w....!..l.Ba.).f.."...#.H..L.........8?......f.l.....k.o">!......
...N..._....p...u.k.[..V.h..][email protected].<......%b..0..>.
[email protected][email protected]..#......)..4.\,...X..P"M.y.R.D!.
.....2......w....O.N....l.~.....X.v.@~.-......g42y.......@ ...........
\...L....D..*.A..............a.D@.$.<.B........A.T.:.............18
....\..p..`........A...a!:..b.."......"aH4... ...Q"..r...Bj.]H#.-r.9.\
@.... [email protected].]...k....=.....K.ut.}..c..1.f..a\..E
`.X.&..c.X5V.5c.X7v....a..$......^...l...GXLXC.%.#....W...1.'"..O.%z..
.xb:..XF.&.!.!.%^'.._.H$....N.!%.2I.IkH.H-.S.>..i.L&..m....... ....
..O.......:...L..$R...J5e?....2B...Q.......:.ZIm.vP/S...4u.%...C..-...
.igi.h/.t.....E....k.......w......Hb(.k.{...../.L......T0.2..g...oUX*.
*|.....:.V.~...TUsU?.y..T.U..^V}.FU.P.........U..6..RwR.P.Q_.._...c...
.F..H.Tc....!..2e.XB.rV..,k.Mb[...Lv...v/{LSCs.f.f.f..q.......9..J.!..
.{-.-?-..j.f.~.7.z...b.r......up.@.,..:m:.u..6.Q....u..>.c.y.......
..G.m..........704.6..l18c...c.k.i........h...h..I.'.&..g.5x.>f.o.b
.4.e.k<abi2.......)..k.f....t...,.......9..k.a........E..J.6...

<<< skipped >>>

GET /core.php?web_id=5076676&show=pic2&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 14:03:04 GMT
2f1..!function(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d
="",e="online_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:04 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:04 GMT..Expires: Thu, 11 Sep 2014 14:03:04 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d="",e="onl
ine_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we

<<< skipped >>>

GET /core.php?web_id=3325108&show=pic1&t=z HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:06 GMT
Expires: Thu, 11 Sep 2014 14:03:06 GMT
2f1..!function(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d
="",e="online_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:06 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:06 GMT..Expires: Thu, 11 Sep 2014 14:03:06 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d="",e="onl
ine_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we

<<< skipped >>>

GET /stat.htm?id=3325108&r=&lg=en-us&ntime=none&cnzz_eid=839872230-1410443285-&showp=1276x846&t=undefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefinedundefined...&h=1&rnd=763793005 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: hzs2.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.4.1
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Last-Modified: Tue, 28 May 2013 02:57:17 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!.......,...........D..;..


GET /stat.php?id=1253024109&web_id=1253024109 HTTP/1.1
Accept: */*
Referer: hXXp://qqqggg777444.jyjaj.com:81/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: s19.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:12 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:12 GMT
Expires: Thu, 11 Sep 2014 15:18:12 GMT
1f7a..(function(){function l(){this.c="1253024109";this.O="z";this.K="
";this.H="";this.J="";this.o="1410443292";this.M="z8.cnzz.com";this.I=
"";this.q="CNZZDATA" this.c;this.p="_CNZZDbridge_" this.c;this.C="_cnz
z_CV" this.c;this.s="0";this.v={};this.a={};this.ia()}function g(a,c){
try{var b=[];b.push("siteid=1253024109");.b.push("name=" f(a.name));b.
push("msg=" f(a.message));b.push("r=" f(h.referrer));b.push("page=" f(
d.location.href));b.push("agent=" f(d.navigator.userAgent));b.push("ex
=" f(c));b.push("rnd=" Math.floor(2147483648*Math.random()));(new Imag
e).src="hXXp://jserr.cnzz.com/log.php?" b.join("&")}catch(e){}}var h=d
ocument,d=window,f=encodeURIComponent,k=decodeURIComponent,p=unescape,
q=escape;l.prototype={ia:function(){try{this.R(),this.G(),this.fa(),th
is.D(),this.l(),this.da(),this.ca(),this.ga(),this.i(),.this.ba(),this
.ea(),this.ha(),this.$(),this.Y(),this.aa(),this.na(),d[this.p]=d[this
.p]||{},this.Z("_cnzz_CV")}catch(a){g(a,"i failed")}},la:function(){tr
y{var a=this;d._czc={push:function(){return a.w.apply(a,arguments)}}}c
atch(c){g(c,"oP failed")}},Y:function(){try{var a=d._czc;if("[object A
rray]"==={}.toString.call(a))for(var c=0;c<a.length;c ){var b=a[c]
;switch(b[0]){case "_setAccount":d._cz_account="[object String]"==={}.
toString.call(b[1])?b[1]:String(b[1]);break;case "_setAutoPageview":"b
oolean"===.typeof b[1]&&(d._cz_autoPageview=b[1])}}}catch(e){g(e,"cS f
ailed")}},na:function(){try{if("undefined"===typeof d._cz_account||d._
cz_account===this.c){d._cz_account=this.c;if("[object Array]"==={}

<<< skipped >>>

GET /img/gif008.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:30 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;
....



GET /img/lhr.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid

<<< skipped >>>

GET /img/js.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:34 GMT
Content-Length: 64719
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/js.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..P.......!..31.J.>V.:B:.j.6k.>y.-v.3{.;@[email protected][email protected][#N
T%S\5\i.Ew.Ag&Mf.Rf7Xx'G|4O{9Ra<aOL.hW.zx.vE\gHcjRjqJawYis\rzanwfu}
u|..)..9..$../..2.&=........$..,..3..!..*.)8.!-.(4.;>.,D.7M.>R.(
@.7G.7C.^..r..{..FV.JT.X[.\e.kn.ou.xx.gg.|d.rr.JM.WW.HG.ZH.PP.iT.wY.hF
.wF.bb.................#.:..*-.-1.88.((.9%.11......................'..
(..:..8..%..6..3..! .0 .!!.33.C..Y..G6.Z/.Y7.H&.W'.x..f/.i5.|/.x7.g'.h
0.x'.}1.J..G.._..W..C..M..W..Z!.e..h..{..x..d..w..p..g .@@[email protected]
.ss.|......#.....1.....&..q..Y..[..F..P..E..i..W..G..S..F..V..d.....).
.8../..8..'..1..'..0...../..8../..9..)..1..'..0.......................
...!.......................#.."..A..A..A..D..a.....*..7..(..1..'..2...
.......................".. ....................#..C...................
..........................!..NETSCAPE2.0.....!...&...,......P........H
......*\......#[email protected]."G:......*.........5b......@..
.J....H.*]...S.,.$J.hj".:w.......Z.F.Z....EEf.J. N.S.b......x.........
.f..I..H..bE.u#.E..'V.2.....SF.3.....k..9...(9.^......c..M[.......f...
.acb...p...._...M....K.......#....wh....SNM1..9.._...b.9s.<L...|...
../p...g.g....w.R.]BGS.)xP...(......v.8..4.D7.r`.f.`.H.]...VUeB...1.r.
.$ .H.L&uUX11...t0j.at ...C...I...1O=.\..{t.7.%.h".Ct.S.<L.5.&J.(T.
h....l...{..._.k.(..r.).%^fr.._.Y..q..e&.2.'...g...d.^....&..>..&zR
....mT"...S.8.z..j....s.&.Z....xVc....8....1.%...7.t.a.j...C....*..S..
...>.BD.=...)Bq.qI&....}ih..?.t..%.t..{hr..?..;...2*....,....|..g..
...4.....,_.I:l..Z.9&...y.....&O..w.....(....d..b.$.......e.n=.#D.

<<< skipped >>>

GET /img/2014052276129177.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aX..................!..copyright. 1996 Charles H. Tupper  All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;
....



GET /img/046bt.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:39 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..

<<< skipped >>>

GET /img/icon.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.font>....



GET /img/zs.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:40 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.941pojie.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc

<<< skipped >>>

GET /img/下载.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
<html><head><title>Error</title></head>&
lt;body>........................</body></html>
..
..



GET /img/top.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:47 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.941pojie.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......F......:\.....bKGD..............pHYs.......... 
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1

<<< skipped >>>

GET /img/bgtitle.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.941pojie.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:48 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.941pojie.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...

<<< skipped >>>

GET /img/pic2.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 431
Last-Modified: Mon, 02 Dec 2013 05:46:13 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:05 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes
GIF89aP.........eee000...........................e...00...0...........
.......................................!..Powered by AFEI.!.....S.,...
.P......` .di.h.....p,.tm.x..|....a..._..1i,...&3.\2...v{.-...xL.s.g.b
-h...5......;.=g......".......m......................m..............."
.........................".......m..............."..w.....u.n..m......
....".....H......*.Q.....#J.H.b...3j..Q... C..I......9.\)b...0c..I....
8[........;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2
014 13:48:05 GMT..Content-Type: image/gif..Content-Length: 431..Last-M
odified: Mon, 02 Dec 2013 05:46:13 GMT..Connection: keep-alive..Keep-A
live: timeout=5..Expires: Fri, 12 Sep 2014 13:48:05 GMT..Cache-Control
: max-age=86400..Accept-Ranges: bytes..GIF89aP.........eee000.........
..................e...00...0..........................................
........!..Powered by AFEI.!.....S.,....P......` .di.h.....p,.tm.x..|.
...a..._..1i,...&3.\2...v{.-...xL.s.g.b-h...5......;.=g......".......m
......................m...............".........................".....
..m..............."..w.....u.n..m..........".....H......*.Q.....#J.H.b
...3j..Q... C..I......9.\)b...0c..I....8[........;
....



GET /img/pic1.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: icon.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine/1.3.0
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 428
Last-Modified: Fri, 16 Jan 2009 08:10:47 GMT
Connection: keep-alive
Keep-Alive: timeout=5
Expires: Fri, 12 Sep 2014 13:48:06 GMT
Cache-Control: max-age=86400
Accept-Ranges: bytes
GIF89a.......f..3...33.......................................!..NETSCA
PE2.0.....!..Powered by AFEI.!.......,.............I........08bX....d.
n...CS.3......_..`..H..H\8....)...S.b.UX.....(...r.L....tb]&"......#..
.o.V.a..D..o.V.a..........D..o.V.a..........D...........!.......,.....
........I........08bX....d.n...CS.3......_..`..H..H\8....).:[email protected]...
x ..........D.| .#.u.a....n~D..[....n..........D..[...n..........D....
.......;HTTP/1.1 200 OK..Server: Tengine/1.3.0..Date: Thu, 11 Sep 2014
13:48:06 GMT..Content-Type: image/gif..Content-Length: 428..Last-Modi
fied: Fri, 16 Jan 2009 08:10:47 GMT..Connection: keep-alive..Keep-Aliv
e: timeout=5..Expires: Fri, 12 Sep 2014 13:48:06 GMT..Cache-Control: m
ax-age=86400..Accept-Ranges: bytes..GIF89a.......f..3...33............
...........................!..NETSCAPE2.0.....!..Powered by AFEI.!....
...,.............I........08bX....d.n...CS.3......_..`..H..H\8....)...
S.b.UX.....(...r.L....tb]&"......#...o.V.a..D..o.V.a..........D..o.V.a
..........D...........!.......,.............I........08bX....d.n...CS.
3......_..`..H..H\8....).:[email protected] ..........D.| .#.u.a....n~D..[..
..n..........D..[...n..........D...........;..


GET / HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:27 GMT
Content-Length: 4023
Content-Type: text/html
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/index.html
Last-Modified: Thu, 11 Sep 2014 04:34:15 GMT
Accept-Ranges: bytes
ETag: "803d67a479cdcf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........\[email protected]* S.dw.]w.~.. H..H..$..~..Df.{-m..).
...H..-E..q.......l.n#G.={/...HY....5..q...w....-?=..m...v;.T:B.....[.
....r..ls...?.......-.wb.....%E.......o(...%..ruww;.Ig$.p.....H....C.b
...)>..'?nQG......:tp...u.....~w.......r...A.......HG.W$oHD.!.V...A
..{.;:C.".kgQ.U.{...q.'j...W.......|L..O.K.8..Q$%$..)<...s..c./.=v.
t....4:Y|[email protected]..$:.HG.K.Yf%.w.........d....F,.o=.X_.(......../W8Q..
.P.H>Q.bR.j.0X...#.m......g...prap..Vacd|h.............8.......`L.{
PA.].....e.0&.<.z..EQA...^[email protected]~.p...N_.;.(.w.?....wH...7b
..:..Z.u..$.g....C.c..9(J...DP. ...Nt..Dy.O...!..4......H..w.n....8.65
......&.6....x..G..".H.....ob.S.CT.`...S.CZ.4k..... !_3RiN..AR.;...I..
g.wH...wXc..-...Z.Zk........~...D.........^W.!..}.......*.rk7.1.N....R
F..b....G-.!....0.#.p.... ..Oe. ....O.8.Q.F.G../..a\...B..f.7.8.(.(|,.
..z........O.F..O~4\..U..@....|...%_.:...%.c...Z.........2i qD..2....H
]b....I.......B..#.^..(>yA...\...R............lO.....I<uw....C..
^..?t...........l.1Z\.......4t......k......yx.xQ...kX..R....W..&....P.
........2.10..C...0T.d..C5(J...CR ..p$..e....87.z...@,...(A.t...h.2o.L
mZ..d...Q*.&.$.h.....t....8'.B..*T..f...}..r.....{.|.r.(..#:..........
P.'.......*..-.V...........3...?-L.S ..;.d..rn7..Jfn;._..}....;8.95.ws
m.Y..0^z7...5@~g...........|:._......!....7....I.2O........eF.......&g
t;.7..$v.7...N..p)..|.|...H../........._..o..?H.CF....J.........1!t.b3
J...b.=8)k..B[...............~....V..U...&...Z....j=..N;Ts...3..?.....
.1P.U.c ..C..O.....1^..%-. j'.`:[email protected]|.O...

<<< skipped >>>

GET /css/style.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:31 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.

<<< skipped >>>

GET /img/zsf.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:32 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]

<<< skipped >>>

GET /img/jbc.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:38 GMT
Content-Length: 64494
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/jbc.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..<..........................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................q..d...d@~m.4~m....d..
... ......@~m.!..NETSCAPE2.0.....!.......,......<..................
..........(. .."4$.. #.*#.7).7).<2.=4.00/>.~;<E:@IK6.D9,f=.}:
?.??_._N.tU X]!ec.^b.er0Sd#bYD.IC:VG*UI6ZR.pP.fU.{a.{g.~s.nc%l`=}m,{k3
}q8GFGJMTNPJOS_PMMSMUYTKYXWY[j]`^^afoOKecUukHtkT.rKxpYgghiktnrwsmhqnsx
vhvwy9..C..y{.?..~..|..W..r..e...>=.=F.[..P4.e..j..q..i..`..u..z..s
0.Z.._..^..\).u..f%.DC.xF.{U..E.}p..... .00.?A.|..@?.SR.^b.a^.no....|.
.....1.......................5.....P..g..z..d..u..j..y..}..R..p..U..n.
.........................,....................-.......................
...*..J..d..}..L..g..(..............)..6.....5..'..7..8..<..G..W..H
[email protected]......................
..................................................................

<<< skipped >>>

GET /img/gua.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:41 GMT
Content-Length: 50630
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gua.gif
Last-Modified: Sat, 24 Aug 2013 07:07:52 GMT
Accept-Ranges: bytes
ETag: "094f3a598a0ce1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..[.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................................q..i...iH...<......i..
..}.m4@=..H...!..NETSCAPE2.0.....!.......,......[.....................
.......#..$..'.(..$'.(6.0?'..&..&..8..2..!.,).6 .*/.;;.!0.>1.>')
.&7.7(.49.(((&)4)[email protected]>.R#8K&>S79F2M.=e..AA*DZ5HH8NR
<PO>ST.Jc/Pn1Ng3Qk7Xt=`}F..Z..F.'R..Z.2Y.3A/.E3.S=.f..x..b.6h.&l
t;p.=q.>[email protected].|b"|DJ.LS.YB.T\.Kl.eL.mR.wY.cl.jt.~`
.s|.FFFFHTD[[VVVKZ`YYeF`_Qmmfffijujv}xxx>d.e..j$.q&.x).~*.Cj.En.Ju.
^~.P|.N|.Q..g}.zz.X..r..s..^..{.._..O..R..W..Z..l..a..w..{..]..a..d..h
..m..n..r..w..}................M..R..V."b..\..a..b.!_.!b.#k.&p.f..m..t
..{..............%o.'s.*{.-..,.....1../..3..5..9..:..=..=..=..A..B..,.
....0../..1..5..9..C..G..K..O..Q......................................
..................................................................

<<< skipped >>>

GET /css/style.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 3923
Content-Type: text/css
Content-Encoding: gzip
Content-Location: hXXp://VVV.lszwg.com/css/style.css
Last-Modified: Fri, 25 Jul 2014 01:50:27 GMT
Accept-Ranges: bytes
ETag: "8073a1ceaaa7cf1:3e08a"
Vary: Accept-Encoding
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
...........[K....^g`.C..!..{TRK..Y..c......uK.....V..........da."^..1.
y.L.d.../.&...N=..w<.L.VU.:u.W.U....[.~.._......G..>x.`U....>
..S.I....y.~n.}Y...l......../.y-]e....>......;.<......d[[email protected]..
1Z.m[.QS....?.........n..s5...q...]8.E..t..G...g..<,....yy..'./B...
..D^..U1no...P...HX.Vu...2 ?..-....X.M...A.....Y.8.dUES......U...v....
%Y......iW..e.....q..Dv.....%.....v.^..>>G...u. 2.:.".8...D%.').
...:.).v.\$...u...!ku...7.gBF...)yf...r{X......fy..l^pz(..w...,3....*.
. ='.....-H'D...1..^=.0/O.*.]..z.T..*6.2...B|..U..9.....;1z:....r.8..b
..:W.d3..4y.A....vI.$..Bkb60.!{........]..l......"...#s...\<.r.C.4.
.pSN....#Vu.KTE.8.Bc..}G.ez....He..v......u..i.Ou.v. ....P........DPD.
..........(.......3...$...*;....8..Gj.m..&.`.g....&oGy.......f....i.Wg
2.....(.nk.&'......QS.a8............|>...c.....\k29...h..9.....R..}
Q62~...{.;....BKL...f.*..:p.c. .....H?.K.Ue..Sh....9...uI5B.;.k.......
..n.-...b.T#......T..fr..}.......0..%....F.)........>.......VU1...T
c$9.M.....[%.h.uV.%..).G.q....q8....\.Ig..ri..P....d...6Q4`..m..v.].Y5
5.:......,.E..`../by.([email protected]... "@...1Po1..H..F..D[A.\.l6.d#....
.d.l.X..w..y.Yo...w...hs.d...'...!iOPnR........`..k.......Z:.U.C.\mb..
.!M%.........K...:........%....Z..2.l.Q...z...9..3..t,...2_.c......WE2
..I&*{jx;.#^^C.&..T...q"XN......n5-...TG.|E..q......_n~)3<......U..
@ ..7uM....=)(M.R..1V..[.'HYS.<k..8.Q(...s.eNGO....U.ad..f^.N}...d.
.#;W.-......''.}^.c`!] ......2)...k..p...62 ........mW=.....(.Y..jp...
.I,...=.v....<...).Mx...A.B...pNS..... ...U..6...v.l..3..X.)F;.

<<< skipped >>>

GET /img/gif008.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:46 GMT
Content-Length: 565
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/gif008.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a ..........R.......!..NETSCAPE2.0.....!.......,.... ....._....m.
..PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i
......i...9......F..!.......,.... ....._........PZ.D.6.N...}Q)....M..1
@.i,.....|.... ..K.v.....-yJ.R6;....Tx...Y Y5i......i...9.....|E..!...
....,.... .....`........PZ.D.6.N...}Q)[email protected].<..h..0.
d..U....Q6S..U.5..r...R9i....[....r1.a.7......!.......,.... ....._....
....PZ.D.6.N...}Q)[email protected],.....|.... ..K.v.....-yJ.R6;....Tx...Y Y
5i......i...9.....|E..!.3Reduced 73% @ VVV.raspberryhill.com/gifwizard
.html..;
....



GET /img/lhr.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:47 GMT
Content-Length: 81534
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/lhr.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..x....c..k............CH{.....r..............[.................
.............}.......S...lo....................................:......
......X^.............OS....(0...4......BI.......'1.loK................
................WWw.........B...kp...................lq...............
.........................lprr.....kq............$........&$...........
........1/N............XR.P4N.....$...................................
........(/......K.*.................................... .1......K%>
..............I.}.......$!=................mn...a.(d 8......X.........
..........................y..CB_......b........\..t.........}....U..(.
.....(.l..h..L..a.......................[..ke.......<..............
W........B=..........}u..........I.....c...lpr...DHW..w."_..{.......%.
...X^............!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="
..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:n
s:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:
27 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rd
f-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmpMM="http:/
/ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sT
ype/ResourceRef#" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:Origi
nalDocumentID="xmp.did:9AA6DB8038C6E31182A8FC32D61CAE1A" xmpMM:Documen
tID="xmp.did:99FEADDEC63D11E3A860CA3CB076D0A3" xmpMM:InstanceID="xmp.i
id:99FEADDDC63D11E3A860CA3CB076D0A3" xmp:CreatorTool="Adobe Photoshop
CS6 (Windows)"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid

<<< skipped >>>

GET /img/zsf.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:50 GMT
Content-Length: 85308
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/zsf.gif
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..Z....9Z.(\.,e.4i.<`.Lr.Uv.Gk.Ae.:s. f.5j.;r.4k..l.,h.4m.8n.
2m.1g..p..q.5p.9q.=x.4s.;u.6x.<x.5u.:v.6x.:y.Lu.Bn.Bt.Dw.Q{.Qw.Eu.H
v.Dy.J{[email protected]|.I}.R}.C~.H..Y..f..r..v..l..w..i..z..E..L..M..Y..U..\.
.R..Y..T..[..S..\..Z..C..K..M..N..P..S..X..P..Y..M..N..T..\..^..R..Z..
^..e..a..h..d..c..k..e..l..k..q..t..y..v..`..b..i..d..j..`..k..a..s..y
.._..^..l..t..{..{..l..d..j..j..t..{..u..|..t..z..u..y..~..v..|.....~.
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..............CWz!.......!..NETSCAPE2.0.....,......Z......9....8..."&l
t;H..6....4.."...1b.hp.G...U...d... n....H...}.H...o8.e{.......=...g..
.....Si..B.=.:..P......S.R......S.2....Sw..P..v..9.(..S..-J.....r.{.8.
N...g..m.....'..-n.l;....x..l.!C.)...i.7cN.m....q&.M;.3..W...[&hh....-
<8...qos.:8.m.o.|.M.u...O.........gk..Z..'..7.pZ....^l).f.....t....
...tRC..._H$...}.zd.I.m.........N....Z....b..5....x&.g"A. d...\..A..'"
.".TcA..h.C...S......7.y..7....I..d.KF9..U*.%.O.)..\~.e.^.i&.\N...d...
!.$..cT9..`.$C...9..c.:......L.y.......L..0.h..*.h..:..".VZ)....i2...)
.........."..\.j..(..%...L"...H2......F.*,.......J.%.n.....b.".,.k".*.
.%.h....^.........,.M..$.H&......$.. . r.%...H..L.l"q...".[r.%.3.p.q2.
...S....X.1..ol.....g..../"...2"F....5.L..8..3.H....<[email protected]

<<< skipped >>>

GET /img/2014052276129177.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 832
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/2014052276129177.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aX..................!..copyright. 1996 Charles H. Tupper  All rig
hts reserved. not to be used on another graphics download site or on s
oftware. All other uses permitted. hXXp://VVV.cyberspace.com/tup.!..
NETSCAPE2.0.....!.......,....X.....*.............0....H.........6.L...
.....? ..!.......,%...j...................<....H............!......
.,W...j...................<....H............!.......,....j.........
..........<....H............!.......,....j...................<..
..H............!.......,....j...................<....H............!
.......,....X.....*..................H...........L.........(..!.......
,1.........!..................H...........L...!.......,c.........!....
..............H...........L...!.......,..........!..................H.
..........L...!.......,....X.....)................n.H...........L.....
..>S..;
....



GET /img/046bt.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 6215
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/046bt.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89aK....!......U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...
........U...........U...........U......$..$.U$..$..$$.$$U$$.$$.$I.$IU$
I.$I.$m.$mU$m.$m.$..$.U$..$..$..$.U$..$..$..$.U$..$..$..$.U$..$..I..I.
UI..I..I$.I$UI$.I$.II.IIUII.II.Im.ImUIm.Im.I..I.UI..I..I..I.UI..I..I..
I.UI..I..I..I.UI..I..m..m.Um..m..m$.m$Um$.m$.mI.mIUmI.mI.mm.mmUmm.mm.m
..m.Um..m..m..m.Um..m..m..m.Um..m..m..m.Um..m.......U.......$..$U.$..$
..I..IU.I..I..m..mU.m..m......U...........U...........U...........U...
........U.......$..$U.$..$..I..IU.I..I..m..mU.m..m......U...........U.
..........U...........U...........U.......$..$U.$..$..I..IU.I..I..m..m
U.m..m......U...........U...........U...........U...........U.......$.
.$U.$..$..I..IU.I..I..m..mU.m..m......U...........U...........U.......
....U......!..NETSCAPE2.0.....!.......,....K..........H......*\......#
J.H..@`.1.$...9r....7..........cI........1........Ar.^.#...A0AR....]L.
K......Ux..!#.u$ ..........-..|.`f........ )R....I./1..A.(... .R..ML..
>|.....u.HP.J....s..*3.d..&.v....FO22.N...I.0A.4........r.R........
.Q.{`..{..n-p21t'.~4....@*..o...#)[email protected]<.r.....{`..!...|
..'^Xh.5[r....K..T.r..4. .......f\X.....e..QJPa..A....GC.(".fU...mEe.Z
K.FHf|.x..A.U!.a...J,iD.bo..]P.l...@...}$.(..3.W.MK.w.w..gV...&.._...A
.EG.B....}.t...J..P..1..L`.....6....F...!.......,....K..........H.....
.*\......#[email protected]``.%.E.#1r.......(...m.(0#I..<.$........C.
..I@:I....&.....l...O.:..C.. :.......).. ........H.b.8..V..H.$G.-I.f..
.*p%).Uk....%9.Z..........:...%..,I..L.......%...O.....jw......;..

<<< skipped >>>

GET /img/icon.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 409
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/icon.png
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.............r.......sRGB.........gAMA......a.... cHRM
..z&..............u0...`..:....p..Q<....IDAT8Oc`.........S6........
.K.........."......)o....mj.3.*.O..\.........w..wZ.....US.6......_s...
p....='R...X.?i.......?.|...2......h...#..k....=.............0 4D.....
2u......c.O>[.?a....9../.:........R...K....f...A...3%.c6...........
CK.2P.F..zs8..|w.p...0...c....m..a..5.........p.d<..?....IEND.B`.font>....



GET /img/zs.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:48:57 GMT
Content-Length: 86867
Content-Type: image/jpeg
Content-Location: hXXp://VVV.lszwg.com/img/zs.jpg
Last-Modified: Thu, 11 Sep 2014 06:25:03 GMT
Accept-Ranges: bytes
ETag: "8089eb1e89cdcf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
......JFIF.....`.`.....C..............................................
......................C...............................................
..........................p.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..R.....
E.-5.(.8....ca.B..A....T..m.r.......O.;[email protected] ..Q..?.
...6...)...s.{........7.B.^I."q $b.0G#...UYHLr?*..*....2[-.i...T..j..0
.._.&..../.z...3..H.X...GWn...$m....I.?....%..>..M_.6..q.R.......oL
.39F.,q..'..U..........r......v/A..H..;....NFu!@'wV?..&Hq.g=..r.d.....
$u..q"X.-.e..4.:H9^GL..bdVm....9.G..4.R.I...c.Jj....[D].X.\3..U8&...?.
.U..Zl..@\.o....;......w..l) ..^...........8..j.]...#.#p....W.C$....*
[...Z...~. H..$cs....."...4`.....6...f ...p..z{#..b[=.qS..k.. ^....r_.
......I.=..c...A2..tU.J.;dnU_AT....#.'...M.z.......FI=.ri..C...ds..j.6
.....}9.b.FM...#.e. .g.....kr...Hs....}.X...w..<r...12.....Q.~.j..W
...L..T^.".....s.....D..e.m.03OY[$.1.......N.1...*..P.!G'..;$.B...9?..
;B.U.c...g.X.c.^(K[..Xr..q.....*a~P.@<..Nx..mP..........vw....c.jR[
.RRe-$....?...&~..j...Lc..C..(&G..)..G%.SiX....%..n......2..p...(.<
..@2B..%..`*.q.....j...-.L.W..P=..dDa.~....ZEf ...).hd.9E.3...e.Wc

<<< skipped >>>

GET /img/下载.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 404 Not Found
Date: Thu, 11 Sep 2014 13:49:01 GMT
Content-Length: 83
Content-Type: text/html
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
<html><head><title>Error</title></head>&
lt;body>........................</body></html>
..
..



GET /img/top.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:01 GMT
Content-Length: 23243
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/top.png
Last-Modified: Thu, 14 Aug 2014 07:47:38 GMT
Accept-Ranges: bytes
ETag: "089c3494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR.......F......:\.....bKGD..............pHYs.......... 
.... .IDATx...{t..}.......nt..J .Q....M.z..-.....5Y..d.h...:.Lv}.MN2..
Y....&qv2.x.....8^;.# vlZR2.i..![[email protected]. ..4..zW...]....."myN....
QU}..}.......{....F.m..F...H?....F.m..F.q..s.m..F.m...f.m..F.m...C.9..
F.m...{.m..F.m..F..1..s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..1.
.s.m..F.m...f.m..F.m...C.9..F.m...{.m..F.m..F..x....f.m..F.m....f.....
.......6.h...6.$..Q#...?....h..6.h.G.u(.m..F.m..F.?..C.n3.6.h..6.x.Ay.
...F....&o.qu..p.P..|..O.......(.Y|.Z.d?.......xy...".......n....l_D..
X.d....&n.......^..._.Mn%......-.Xg.~..~....Xg......_.7<#...S.W..R.
...Jb-.....G..D..U]Wm.q% ~..^..88....#........%...W.A.K/.uC..........
KL.....-......................u.g.x..;NA..@$.>...^O~.GJ<D`#.E$w.
.X....\b....]..O.u..].p....9v..^............*.......G.F.S..*.A].G~..o#
..1r.8C.M...w...M...<.........0/...U..g..&...06>.Ek.U.r....c[.$.
...aX..7_.......-.Z...x.m.R.O..Kl....u...\..'9:4..|......si.....{R@k..
.U5g....r...,{.ws...*..px.4..M.....4B.-.....-.<....]....K_...."Nj`.
.5C.)>..........5c1.....1..A..s.. (....}.[........:zo..5=.s..&.;7y#
.v.U..e.".........=........-.3...........C.L>.c[....L....g)A.t.|g.u
.....\..Q...?.. ......dE.j.-.;..;.i .......8.......q..w..k`G..|.?....g
..Y...~......'.._mT.b..j.....E.0~v....n...^.RXV.7...b... ...P(..=y..O_
................>.b...;.r.]Y....y.f... ..3c\...|..n..<.....W.6=K
....3.Y.0........R.g'.fX........ds....)...7vo[..~...............[S..4?
tK.b......._.n...;........n.6.....^.....s..........?}Y.i5..Y.....1

<<< skipped >>>

GET /img/logo.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.

<<< skipped >>>

GET /img/bgtitle.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:02 GMT
Content-Length: 3274
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgtitle.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a~.#....Z........W..~..|....Z..=..............B..o}....'|...."`..
..%T.....q. x..|.....{.......:........... ...|....kM..........!...~...
.!.........{............. }.... ......x.....{..}.......... ...........
.|....".. }..........G........"......{........z..y..z........\.....M..
z....................x....!^.......!...{........T..Y.......m..:.......
.p.....!..<..5........"...L....=o.*K..v..v..y.1.........i.!..... ..
H..#....._..o..6..L..N......{.6e.#.."..!..`.. ..l.."~....K.. .........
...t..K..~....*n.)......L..z....].."..>.."z..y..........8..Q.....-l
....bn....Cu.0...|....8..;L....?.. .....G............k.'..<........
......\........7..#.....J..Li..o..w....(..*..x..}..m...m.&W....$..%..&
..LQ....O~....2u..w....[.....8i.%k.$..&..... .....)........... .......
..}...........z.... ,....~.#......(.$H[.8l..X......#J.H.....3j...... C
..I....(S.\.....0c...h..l..%...]-Cz.<;.....H.*].....P.J.J....X.j...
...`...K....h..]..j.6...K..S)f.~]{ ........L...... ^......#K.L.....3k.
......C..M.....f.KG*..p.$.9......s...........N...... _.......K.N......
k....q...L..v..%p.....m.......O...............(....h...&....6....F(...
V..mK...;..b.3*H........(....,....0.(..4.h..8....<....@.)..D.i..H&.
..L6...*.0...\.....p..W.S..O.)..d.i..h....l....p....C,..#.ly..q......*
....j....yB=...'9..#...NJi=.f....v.....*....j...............*....j....
..................J..D>......F ...Vk...f....v..... ....k...........
... .....-.\\...= ..=....=..L...'....7....G,...Wl...g....w... .,..$.l.
.(....,[email protected].../[email protected]'...L7...PG-..TWm..Xg...

<<< skipped >>>

GET /img/bgheader.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 1978
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgheader.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.........................a}....BV..........Yu....Rk.^z....Ja.Nf.
=P.......... 8[xxxTo.......]x....I_....w..TVU...F[.d........3Ak...9M|.
...........[w....Vq.:Jw......IJK# ESm....e.._{.Uo....b..hhi4EoG]....OU
[email protected]....]dw
............Ys..........o~.............Pe.9Et...DX. <]...Mc........
..Xt.........._|.Pi.\i....Nj.......Qg....7Jx...'4Q...Jb...............
.........................Wq.b...................................... (C
..................Og....Zx............................................
........\y........................................Ph..................
.w..\a_`ab...1Dk............L_........................................
...DS....f..............\u.Kd.~~}...\s.sus>N}......]m.......Ql.....
.................,[email protected]...... C..I
....(S.\.....0c..I....8s...3e...]...a....s.`.....8."....S!.......;v.L1
.K....h..].....p...K....x............L...... ....c8.#.A..l...\0..u.R..
...104$H..j.......3..m.v...s...........N...... _.......K.N......k..=..
.:n.........i..O.v.....u..............t...k68...{..........D(...Vh...f
....v... .(..$.h..(....,....0.(..4.h..8~H..;..c;.....D.A...B. )...!.uD
iC.0L&......T....D...C.......D.A.l....p.)..t.i..x....|......*....j...&
....6....F*...Vj..i..............o.I.....H..Dd.S....U..0.E.u...5?x.F..
. ....k...&....6....F ...Vk...f....v..... ....k.......J....J......k..i
..f;D...... ..O...V]Xa..Dx0....1D...b...[.H..w... .,..$.l..(....,....0
.,..4.l..8....<[email protected]#=..IS....o|...[.K..4c...H....?.%

<<< skipped >>>

GET /img/bgh.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 5439
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/bgh.gif
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a.......Wr.Jb.\v.Gb....Id.To.Yt.Pi....Mb....Nh.`}.H^.Fa.Me.Yt.j..
Wr.Yv....t..DY.Rk.z..k..^|.Nf.Ys.Nf.Sl.n..m.....a..|.....Ok.^{.q.....P
j.{..Nc....v..^y.Rk.f.....CX.H\.Ri.o..Xo.Un.J`.Qe.f..Vt....Yu.Rj.G\.k.
.F[.Xo.Pg.CZ.l..Tk.f..d..b..b..a~.c..c..e..d..a..`}._|.c..\x.c.....e..
^z.Xs.d..[w.`{.Zv.^{.]y.Kf.Je.b..]z.\y.Yv.Rn.Up.Vq._z.`..`}.[x.Tp.a|.b
..Mg._|.So.f.._|.\x.Up._~.Hc.Nj.Zt.[w.a..Lg.Qm.Pl.Uq.Pl.Xs.a~.Hc....Vq
.a~.~..Tm.e..Sn....d.....Vr.Mg.Zw.}..Zt.c..p..b..^z.Wr.d.._{.`{.t..Ni.
[x.Lf.Vq.Wt.Xs.Vt.Lf.^}....w..x..e..]{.q..Yv.Rm.Zu.b}.Up.[u.e..p..e..[
u._{.......]{.Xu....Qm.^{.Kb.b..]|.]x.]z.Rn.Rl.b..Og.c..c.....Ur.c..Sn
....l..n..h..u..To.Qh.Pl.......]z.Ld....~..Tm.s..Vo.Zv....g..`~.w..\w.
l..x..c~....Xt.Od.y..]y.Qj.K_.b.....Kc.[v....g..f........Rn....`..o...
..Vq.......!.......,.............t...C."..).7...#i..Q.D..4......./....
...K.x..u.w...X|.0.h.....S.P....M3.pAS.&...vbH.E&.).1....#..G.}s.5MQ.H
g....)E.D.vL..../#..5`.jN.d.|.......S.-.W...U...........eZ..."..I^.XI.
461....sF..I..\3....9.T.E.....^.W-../Jh...{.U.................n.../'~.
Zv.S...........g.*..y.Sd.g..;z%.....^H<.].'.~.Y...L......h...|....4
X...N.`..>...\(......a&v.(.....!.*..H....bzU......P..9.h`.>.h!..
..a......H..$.?6...Q*[email protected][email protected]'.R
..g.|.)..q.Z.......{...".8.&.yFJ...ZJ...(*).......vjj..B..>....@G".
...v.:E...* ....k.Z.........Z..c....l..BK...2.,~.2....&k ..z.n..r....*
$...:K.T..K ..hQE.T.kG.........o..2r...../..v........`.;...?.o..7.q...
L...3...&.|..*....`.{L..t.H.........0.:..3.R.}s...|.4Z....I....M..

<<< skipped >>>

GET /img/1gg.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:03 GMT
Content-Length: 56287
Content-Type: image/png
Content-Location: hXXp://VVV.lszwg.com/img/1gg.png
Last-Modified: Thu, 14 Aug 2014 07:47:36 GMT
Accept-Ranges: bytes
ETag: "05c92394b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
.PNG........IHDR..............</.....sRGB.........gAMA......a.... c
HRM..z&..............u0...`..:....p..Q<...]IDATx^......u........d%Z
.d[.,..l X....-K.eI.D...#..1.x.....b...6......9..sN..........F.....} .
uOOOoOuMW..{!&...?m.m.m.m.m.m.m.m.m.a...\...=s..p..W...^...]..'.....|.
..........b.;&X._ ...3...}e..x0..1..c8^p$.{.Y...$..........y|...`..q..
.x.mX....<.&....x......{...m7{.`y.M1o,....%.g.5.....9c./....C......
}...8`^Z4p..o.6..T|?...I...k..V4...M..h%\........>q.M.-.5..n.m.[.@.
....................[.....r.....y....JMe.T...)....e......5.......O...p
R.4.........[.N......M...|V.h>..9...vV.....{Z...m......%....{..`.Ey
...C...a,.i...e..,.t\..v^..ZvU~........_.].?.........a..9.........tM..
...........g.......)......?Y.Y.g......?.].?.....[w1..p................
_s^~..9...0...wW...3.......z..... .q.]y....[W.......O[@[@[@[@[@[@[@[@[
`.......#..... ...B./Z(.....ys$o.,).=]...#O..._..b .`8....tRn...o.l,..
nk>[email protected]/..m='.ay..9c.....B...........a...>.
.........KX^..a..;i......SK...ZvE~n9..F.t.5.....0..s../..Y...........
$?..".{..'...]....>...h;.........,i......v....<.......6k......rZ
.C......w..B;..;....:......5....:#...,...'....'.@8<................
...n....'r.....s.,im.b(..sg...Se..)2{*m...>......Se..i...<...Ny.
..xP.h7..n.28.......@*..2H 4P.....w.1@.....`[email protected].$..@...
.G..~....!..c.6B.':..'...>...h...Fn.D`....}..&.........Na.Q.4....2.
...y......... L0......h..h..........m{...........-.'`..&,o.r.....x};..
k8&?.z\.t.i.q......|.....k....k{....................y..9q..._.F...

<<< skipped >>>

GET /img/logo.gif HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: VVV.lszwg.com
Connection: Keep-Alive
Cookie: CNZZDATA5076676=cnzz_eid=155029651-1410443284-&ntime=1410443284; CNZZDATA3325108=cnzz_eid=665276032-1410443285-&ntime=1410443285


HTTP/1.1 200 OK
Date: Thu, 11 Sep 2014 13:49:05 GMT
Content-Length: 4437
Content-Type: image/gif
Content-Location: hXXp://VVV.lszwg.com/img/logo.gif
Last-Modified: Thu, 14 Aug 2014 07:47:37 GMT
Accept-Ranges: bytes
ETag: "80f22a494b7cf1:3e08a"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
GIF89a..F....a..a..b..c..c..d..d..d..d..e..e..e..e..e..f..f..f..f..g..
f..g..f..i..m..n..k..p..s..w..t..}..{..|....d..^..j..g..j..l..n..r..s.
.t..u..u..v..x..y..z..{..|..}..~......................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
...........!.......,......F.....#..H.....%.\......#J.H.....!:...... J
P.....(S.\9q.I.....xL..r:`....g../=.......H3>P.r`[email protected]....
..`...{u...Q.V%.....Y ...taZ.;[email protected]....|.\.......#Kf....$.3K6r
.a..X14.C.4i.Yw.........c.p......7..."......>...H......4hd..`..\...
.V...i..%.....z...3..._...'1b.....}.`h.C.V...u.P..V.........%.,!..A..^
*....p..6..YyB.; l..<.YdS.)....,..b3.. ..,..F,*vaK.-.pK..^....UgI.`
...*_Y..<.\.AxL.(.;;\..r;P.....(..4.I#...S.09.P..z.b.#...b @:.W..%#
.k.E....qh.2.......a.&......X....`..MH.U..f..b.O.c.1..P...L.B..-..B.*.
.K..a..;...ZW ....]A...V..I*.........t."s....c...m`.M%Vt....h...0B..e.
...)^...)......)`A\9i%2]a..p.j....!{...Ze.%....k6....6.....fKb...Zn.(.
.j....."........K3....@\...&A.qNp.m.1p.[..&?.......C...v...!..j.'.

<<< skipped >>>

GET /9.gif?abc=1&rnd=1036514576 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.mmstat.com
Set-Cookie: sca=d76edc3f; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:05 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkh
wCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:05 GMT; path=/; domain=.m
mstat.com..Set-Cookie: sca=d76edc3f; path=/; domain=.cnzz.mmstat.com..
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285; expires=Sun,
08-Sep-24 13:48:05 GMT; path=/; domain=.cnzz.mmstat.com..Location: htt
p://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: T
hu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache..Pragma: no-cach
e..GIF89a.............!.......,...........L..;
....



GET /9.gif?abc=1&rnd=2071775127 HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; sca=d76edc3f; atpsida=f1a0a2f56ddeb4f429ed04e4_1410443285


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: atpsida=f1a0a2
f56ddeb4f429ed04e4_1410443286; expires=Sun, 08-Sep-24 13:48:06 GMT; pa
th=/; domain=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.g
if?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 G
MT..Cache-Control: no-cache..Pragma: no-cache..GIF89a.............!...
....,...........L..;..


GET /wpa/images/group.png HTTP/1.1
Accept: */*
Referer: hXXp://jc.941pojie.com/jiaqun.htm
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:48:00 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:48:00 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank
.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)

<<< skipped >>>

GET /wpa/images/group.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pub.idqqimg.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: NWS_UGC_HY
Connection: keep-alive
Date: Thu, 11 Sep 2014 13:48:01 GMT
Cache-Control: max-age=2592000
Expires: Sat, 11 Oct 2014 13:48:01 GMT
Last-Modified: Fri, 12 Apr 2013 09:22:21 GMT
Content-Type: image/png
Content-Length: 1827
X-Cache-Lookup: Hit From Disktank
.PNG........IHDR...Z.........w.{'....PLTEV...dE)r.Ip..........F.......
.F..Kyy...r.....~E ......m..c..........d3.....S.....r...S1...#.....c..
......A..l3....d.............ynvc......"..][email protected]..............&..I
...\BH.....................rHh........z4$...X..0.....R.....s@6...{RL(.
......Xs.y......S........%.........vb...4......bW...[%..........L..t..
s..c>'...2..............wsw..i.............yM...WwaR...?-.fU...~K;.
`H...t..V..:..d...........h/#.......Z74..........pt5(...K...vb=......l
M.........N.kr......I A............pVs..k.....f'.p.....c..%...SG.J;..r
6......fBr..o=5...T..J...jB......5.....|......n^....XLm3#......y.f.}X.
...]6...,y....8..........q.D-Mt....^* z= y>#.dK...^...........>.
.s..J..............B....q...................xy...'..t.....7..M...~Re..
......s: .K(.rP`)..^=.........3......G:V......WE..2.....pHYs..........
.......IDAT8....T.U...lCs..It.....5r,*....I.K.].5p.d....2.4Fw.m}.....e
.v7r.........S.D.IVR.&.....y8G;.................N.r...9.t......p9.....
].......,Ko..i.......Mh.|@..hyw..9...n..qo-....C.....s.fpo..:{..vtQQG.
.......'..zmr.......H...m.u4.;..t...7....C.........a...?....{)...W..4.
..u......(....l..Q.|......R.u.3K.;.!..}vy([.e.~YhG[^. y......C...<.
...~.<-^I3......$..B....z...?$......u...S.7....qF$?.wF..G..lkC#...=
...A...C.......#x...Ea.yvS(..P..e..2..*....yD]]d.\.....{..h.....5.UK.@
J....ux7...>5.H_....}...T]2x,EO7SEmf.6.u:sk(..4...-.,...o6;B...Me.
.\..._.]SSs..._....?g.,.x.$.tL...)..u.<Mv`4..Q<QiU.1O.X%......q.
.-.w.h... **.....e}..E...'...51t...0...0v....)^1.'.^..U.u`| 3.8l.)

<<< skipped >>>

GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Connection: Keep-Alive
Host: pcookie.cnzz.com


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;....



GET /app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z HTTP/1.1

Accept: */*
Referer: hXXp://VVV.lszwg.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: pcookie.cnzz.com
Connection: Keep-Alive
Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:06 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: cna=FZaYDIcbkhwCAcGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz.com
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 200 OK..Server: Te
ngine..Date: Thu, 11 Sep 2014 13:48:06 GMT..Content-Type: image/gif..C
ontent-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CURa A
DMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: cna=FZaYDIcbkhwCA
cGK9OeiMQ4z; expires=Sun, 08-Sep-24 13:48:06 GMT; path=/; domain=.cnzz
.com..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-Control: no-cache.
.Pragma: no-cache..GIF89a.............!.......,...........L..;..


GET /9.gif?abc=1&rnd=1532175039 HTTP/1.1
Accept: */*
Referer: hXXp://cctv-6.padonline.net:5566/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: cnzz.mmstat.com
Connection: Keep-Alive
Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443286; cna=FZaYDIcbkhwCAcGK9OeiMQ4z


HTTP/1.1 302 Found
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:07 GMT
Content-Type: image/gif
Content-Length: 43
Connection: keep-alive
P3P: CP="NOI DSP COR CURa ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"
Set-Cookie: sca=d8a48a1a; path=/; domain=.cnzz.mmstat.com
Set-Cookie: atpsida=f1a0a2f56ddeb4f429ed04e4_1410443287; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domain=.cnzz.mmstat.com
Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZaYDIcbkhwCAcGK9OeiMQ4z
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Pragma: no-cache
GIF89a.............!.......,...........L..;HTTP/1.1 302 Found..Server:
Tengine..Date: Thu, 11 Sep 2014 13:48:07 GMT..Content-Type: image/gif
..Content-Length: 43..Connection: keep-alive..P3P: CP="NOI DSP COR CUR
a ADMa DEVa PSAa PSDa OUR IND UNI PUR NAV"..Set-Cookie: sca=d8a48a1a;
path=/; domain=.cnzz.mmstat.com..Set-Cookie: atpsida=f1a0a2f56ddeb4f42
9ed04e4_1410443287; expires=Sun, 08-Sep-24 13:48:07 GMT; path=/; domai
n=.cnzz.mmstat.com..Location: hXXp://pcookie.cnzz.com/app.gif?&cna=FZa
YDIcbkhwCAcGK9OeiMQ4z..Expires: Thu, 01 Jan 1970 00:00:01 GMT..Cache-C
ontrol: no-cache..Pragma: no-cache..GIF89a.............!.......,......
.....L..;..


GET /core.php?web_id=5076676&show=pic2&t=z HTTP/1.1
Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:04 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:04 GMT
Expires: Thu, 11 Sep 2014 14:03:04 GMT
2f1..!function(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d
="",e="online_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:04 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:04 GMT..Expires: Thu, 11 Sep 2014 14:03:04 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="5076676",c="pic2",d="",e="onl
ine_v3.php",f="zs25.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we

<<< skipped >>>

GET /core.php?web_id=3325108&show=pic1&t=z HTTP/1.1

Accept: */*
Referer: hXXp://VVV.941pojie.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: c.cnzz.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Tengine
Date: Thu, 11 Sep 2014 13:48:05 GMT
Content-Type: application/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Thu, 11 Sep 2014 13:48:05 GMT
Expires: Thu, 11 Sep 2014 14:03:05 GMT
2f1..!function(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d
="",e="online_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站
;长统计",k=window["_CNZZDbridge_" b].bobject,l="http
:",m="0",n=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push
("h=" f),o.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"==
=m&&k.callRequest([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.cr
eateScriptIcon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.
php?web_id=" b:"hXXp://quanjing.cnzz.com","pic"===h?(r=l "//icon.cnzz.
com/img/" c ".gif",p="<a href='" q "' target=_blank title='" j "'&g
t;<img border=0 hspace=0 vspace=0 src='" r "'></a>"):p="&l
t;a href='" q "' target=_blank title='" j "'>" j "</a>",k.cre
ateIcon([p])))}();..0..HTTP/1.1 200 OK..Server: Tengine..Date: Thu, 11
Sep 2014 13:48:05 GMT..Content-Type: application/javascript..Transfer
-Encoding: chunked..Connection: keep-alive..Last-Modified: Thu, 11 Sep
2014 13:48:05 GMT..Expires: Thu, 11 Sep 2014 14:03:05 GMT..2f1..!func
tion(){var p,q,r,a=encodeURIComponent,b="3325108",c="pic1",d="",e="onl
ine_v3.php",f="hzs2.cnzz.com",g="1",h="pic",i="z",j="站长&
#32479;计",k=window["_CNZZDbridge_" b].bobject,l="http:",m="0",n
=l "//online.cnzz.com/online/" e,o=[];o.push("id=" b),o.push("h=" f),o
.push("on=" a(d)),o.push("s=" a(c)),n ="?" o.join("&"),"0"===m&&k.call
Request([l "//cnzz.mmstat.com/9.gif?abc=1"]),g&&(""!==d?k.createScript
Icon(n,"utf-8"):(q="z"==i?"hXXp://VVV.cnzz.com/stat/website.php?we

<<< skipped >>>

The Trojan connects to the servers at the folowing location(s):

%original file name%.exe_464:

.text
`.rdata
@.data
.rsrc
@.vmp0
`.vmp1
.reloc
t$(SSh
~%UVW
u$SShe
Vh.OG
VWh.OG
[email protected]
!h.OG
w]h.OG
kernel32.dll
ole32.dll
hXXp://jc.941pojie.com/tc.txt
Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
winxnse.exe
D:\winxnse.exe
wscntfo.exe
D:\wscntfo.exe
`.data
}~/%D(
.;6  (&%
1<76  '&
1=;;6  )%#
<;76  )%#
=<<7  ))%
=<<77  '%
=<<76 ))##
==<;7   '##
=<;76 ))##
=<<6  )'#
=<;76 ))#
==<;66 )'#
=<<66  (%
e{TP.cda8
U#ex'B-n}
MSVBVM60.DLL
user32.dll
5i.Id(HE
~32.bd~
.sKpK
.soAw?
.qT3<
D:\wscntmx.exe
__MSVCRT_HEAP_SELECT
KERNEL32.dll
USER32.dll
ShellExecuteExA
SHELL32.dll
GetCPInfo
@.reloc
<4,$?7/'
(3-!0,1'8"5.*2$
ADVAPI32.dll
WS2_32.dll
RegCloseKey
RegOpenKeyExA
RegSetKeySecurity
RegEnumKeyExA
RegDeleteKeyA
RegCreateKeyExA
RegCreateKeyA
RegOpenKeyA
WinExec
ExitWindowsEx
MSVCRT.dll
ackpw.dll
SetImageFileKey
SOFTWARE\Microsoft\Windows NT\CurrentVersion
wininet.dll
C:\log.pif
ShellExecuteA
Shell32.dll
SYSTEM\CurrentControlSet\Services\%s\Parameters
RegOpenKeyEx(Svchost)
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
m32\svchost.exe -k krnlsrvc
%SystemRoot%\Syste
SYSTEM\CurrentControlSet\Services\%s
Rundll32 %s,RunUninsta3l
\lockmedia.tmp
hXXp://
%u MB
%s SP%d
%d.%d.%d.%d
GetProcessHeap
GET / HTTP/1.1
Host: %s:%d
Host: %s
User-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0;  hXXp://VVV.baidu.com/search/spider.html)
GET %s HTTP/1.1
Referer: hXXp://%s
GET %s?=%d HTTP/1.1
Mozilla/5.0 (compatible; Baiduspider/2.0;  hXXp://VVV.baidu.com/search/spider.html)
User-Agent: Mozilla/5.0 (compatible; Baiduspider/2.0;  hXXp://VVV.baidu.com/search/spider.html)
#%d<<<<<I@C<<<<<%s!
4!4,41474>4{4
> >(>8>=>
%s\hao123_res.tmp
%s\ack%cpw.dll
D:\qudongrensheng.dat
WinHttp.WinHttpRequest.5.1
.aspack
.adata
.xqrq
.pH`X|
.YON=
p*.LIAt
5].NQg
=.cw| r\
C @Qb%[email protected]
l(8i?ZiDf\.SQ
%C*pig
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
comctl32.dll
gdi32.dll
msimg32.dll
msvcrt.dll
msvfw32.dll
hXXp://VVV.eyybc.com
\skinh.she
M.GG^
%s T5
]E4%F(
.Funr
.yyw'
%sX@:`
J|.jv
p4%xcEm
.Jr1Z
7.YT"
.Uf!0
!a%U}
[I(3/#N0.bd
j"%u=w
q%Xn`
@|H.NI
.wdd!
S|%u4
5.ff)
;)?/\%~|/
U%D?~;
l2.Ue
9%crU
XKw-k}
zx/%FN[
LY.eo
z{.Do
%s=\RI
}j%c%Y)
Rx.GR
4o#.dM
IeS`%C
[n 4\.UY 
,4.qO,
gQ'.Io
%cLur?
s%DHB
]I%%X
I %d)
.aEd(
Õ6m*
5r.US
:mD].tB
fJ.WM_
fTpe
.LLbX
f%fUZ
.fOuV12
*_.dC
&-N}<
({?.cQm
R>o2.YN>
.Cqx~c
.`.Qw
.Onwj
Tn&.hL
**.dU
%s;7*
0%x@w
%C^L:
CX%xm
!n]%x
%X,Cr
*.Ea]S
Q.CGo
tn!ay%F
2.kKX
Avi.CT
xhZ_6%U
%SY!8i
&.PFy{xh
sG.qmf
5.ZrW
%Ucda
n.BjCw
.um ZZE7L
/^p%u$
I.NoQY
zu.ew
D/.nT
z.LP"
.IRIx
"%Sh9
&;%sUwa
kBS%dR
SetClientCertificate
jc.941pojie.com/jiaqun.htm
VVV.941pojie.com
VVV.lszwg.com
F%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
2,iphlpapi.dll
SHLWAPI.dll
MPR.dll
VERSION.dll
WININET.dll
%x.tmp
.PAVCException@@
.PAVCNotSupportedException@@
.PAVCFileException@@
(*.prn)|*.prn|
(*.*)|*.*||
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
Kernel32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
: %d]
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
out.prn
%d.%d
%d / %d
%d/%d
Bogus message code %d
(%d-%d):
%ld%c
(*.htm;*.html)|*.htm;*.html
VVV.dywt.com.cn
.PAVCOleException@@
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCOleDispatchException@@
.PAVCArchiveException@@
zcÁ
acb8a7eb43e1abc8ed3.exe
c:\%original file name%.exe
#include "l.chs\afxres.rc" // Standard components
UnhookWindowsHookEx
comdlg32.dll
GetViewportExtEx
.cJK`
OffsetViewportOrgEx
GDI32.dll
$p.tS&
?.QVU]9
;O.oa
oledlg.dll
}o%saW
8y%F'
w%s8,
5N
-%F;1
v&Qi%C
%5scb
.pE_4
h}.Hg
ZL2!g%D
%uK;zZ
5 `%Cj~,_h2E%q
&]""9 }$
L.pGE(*
L>y
.EXD#-/
$q.xs
s.Wrl
*&%$#$(*)(/&.-, 
-(%.*,#/
keYO
bhX.Udl?W
!F.YrwE
50%x{/
).yNUt
{sR>%X2 
O Sb
a$#&.Lex
?G!%C
.uL`E
g1 .jb
4:%xyS
S .iQ;
]/].]-],] ]
feF%uS[/V,
%s >2
%SA4/
@Ô~l
g9.Yn
%.Enm
.GL s
C%Ds\
%S-3=
wZ]%Fzau
-2} 3G%
%cZM9!
u .tD
a isSh
=%S;u:
.DQt%,
)-N}JeQ
%3-iI}
&Bh%C
_%x&rj
/9Hh%F
#Ig%S
.Mq-D
0v4%c
N%sE=2
I J@)%S
xH.jka
c.gU5
.QnK)
_.AG)
*.Vl {
).skB
fkC%D
.qK u
.BA *
.pb%3<
r_i%D
uPO%x
C].Ti
%P%f'
(%%sP
CF%c'd
>o_%uCfD
%xl__
"w%sT
Gx>c%s&
w&.StX
Bj%Xu
c`EAy%C
%u 8 <G
)P%Xq
P;D .Cs
ca)%c
uT%1U:
/- .Qd
vI%D]
7 %xlT
Cmd3&
~ p;.Nm
u'w%c<#'
%Ud5E
0m.Eb_
&.uO[
G%c }
.Vm?<
.hoK}2`
.lty,
bs%FPL
#%cR$
 l .Mm
:Um%S
.kUY"
8  _;]\2
)%u(y
%cNX~
%f) a
O7V%S
2< ;.IS
ZX.Dq
k/v%X
%x `f
ßQ?%
%D Sw% 4$@
="D%s\
.CPNt
jÜ[
%7u<X(t
)%X1eA
l:%uzZP[U
P.VLA
Z-bq%F~
kn%x@
0.aX|D
[ .rK
.JjP0 ebC
i"$#%F
3m%c'M
?qP%S
uDy~)E%d
b.hL2
3A& %%x
lk ]Q.aJW
%Fw~byj
.nER'
j<%S]
T<.Ieb
.CW!X
1RUH.ly%
?%D L
%c'X(
4.Fz .q
UOrH-Kd}
uWCzV%D-x
2`L*%Uw -
!i-8}
%0s~'
.oL:)
%DNjCz
.zm4d
Tc@%D
.OE A$
<# %c
*.qmj,Z
PW!%U
`T.Le
76543:98
k/%d(
.6.HK
(.eQm
 }
s.jXd
 cswQw.Er
WINSPOOL.DRV
GetViewportOrgEx
OLEAUT32.dll
WINMM.dll
bHF-s.RW
.pPQX
&(/*'[0?
,./%x
.YIivz
.Gq#k.~9
-6.Ks
WEBoa
g%.fN
/0%6U|
Q.ZKS
`.wDg
*O%dgXMH
0].fC_
=3xc%C
q%ug^/ER
.,%S}{/
/n.ZD
*(.ut
P\RSsh
x|Kp
</`~.GYf
gVrpm%x
%xQ.9
%X$V&
.qm*SV
G.ZB5X
"I'.Zy
ScaleViewportExtEx
|q.ig
.PSFS
K>lA.mGY
COMCTL32.dll
SetWindowsHookExA
GetKeyState
.cM$\,
CreateDialogIndirectParamA
SetViewportExtEx
SetViewportOrgEx
360.cn
hosts2.exe
6.1.7601.17514 (winsp1_rtm.101119-1850)
Rasmedia.dll
Microsoft Windows Operating System
6.1.7601.17514
4.20.0
Uninstall.exe
1, 0, 6, 6
SkinH_EL.dll
1.0.0.0
(hXXp://VVV.eyuyan.com)
(*.*)

%original file name%.exe_464_rwx_007BE000_00001000:

GetKeyState
.cM$\,
CreateDialogIndirectParamA
SetViewportExtEx
SetViewportOrgEx

iexplore.exe_1688:

%?9-*09,*19}*09
.text
`.data
.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
SHLWAPI.dll
SHDOCVW.dll
Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
IE-X-X
rsabase.dll
System\CurrentControlSet\Control\Windows
dw15 -x -s %u
watson.microsoft.com
IEWatsonURL
%s -h %u
iedw.exe
Iexplore.XPExceptionFilter
jscript.DLL
mshtml.dll
mlang.dll
urlmon.dll
wininet.dll
shdocvw.DLL
browseui.DLL
comctl32.DLL
IEXPLORE.EXE
iexplore.pdb
ADVAPI32.dll
MsgWaitForMultipleObjects
IExplorer.EXE
IIIIIB(II<.Fg
7?_____ZZSSH%
)z.UUUUUUUU
,....Qym
````2```
{.QLQIIIKGKGKGKGKGKG
;33;33;0
8888880
8887080
browseui.dll
shdocvw.dll
6.00.2900.5512 (xpsp.080413-2105)
Windows
Operating System
6.00.2900.5512

wscntmx.exe_496:

.text
`.data
.rsrc
@.vmp0
`.vmp1
.reloc
}~/%D(
.;6  (&%
1<76  '&
1=;;6  )%#
<;76  )%#
=<<7  ))%
=<<77  '%
=<<76 ))##
==<;7   '##
=<;76 ))##
=<<6  )'#
=<;76 ))#
==<;66 )'#
=<<66  (%
attrib -r -s -h %windir%\system32\drivers\etc\hosts.ics
attrib -r -s -h %windir%\system32\wbem\window\winxp.ics
#vb6chs.dll
%Program Files%\VB
\VB6.OLB
advapi32.dll
RegCloseKey
RegCreateKeyA
RegOpenKeyA
VBA6.DLL
e{TP.cda8
U#ex'B-n}
MSVBVM60.DLL
user32.dll
5i.Id(HE
~32.bd~
.sKpK
.soAw?
.qT3<
kernel32.dll
SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN
Microsoft.XMLHTTP
hXXp://jc.941pojie.com/cj.txt
%System%\drivers\etc
%System%\drivers\etc\hosts
c:\windows\system32\drivers\etc\hosts
c:\windows\system32\drivers\etc\hosts.ics
c:\a.bat
c:\b.bat
zhaosf.com
Adodb.Stream
360.cn
windows
hosts2.exe

wscntmx.exe_496_rwx_0041F000_00001000:

MSVBVM60.DLL
user32.dll

svchost.exe_1368:

.text
`.data
.rsrc
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
RPCRT4.dll
NETAPI32.dll
ole32.dll
ntdll.dll
RegCloseKey
RegOpenKeyExW
GetProcessHeap
NtOpenKey
svchost.pdb
\PIPE\
Software\Microsoft\Windows NT\CurrentVersion\Svchost
\Registry\Machine\System\CurrentControlSet\Control\SecurePipeServers\
5.1.2600.5512 (xpsp.080413-2111)
svchost.exe
Windows
Operating System
5.1.2600.5512

wscntmx.exe_496_rwx_00426000_00001000:

.soAw?
.qT3<
kernel32.dll


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    cacls.exe:504
    cacls.exe:1552
    cacls.exe:1460
    cacls.exe:1636
    cacls.exe:480
    attrib.exe:308
    attrib.exe:1676
    attrib.exe:340
    attrib.exe:828
    qudongrensheng.dat:1552

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    C:\b.bat (255 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\cj[1].txt (5527 bytes)
    %System%\drivers\etc\hosts.ics (18190 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
    C:\a.bat (356 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\style[1].css (16 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\core[1].php (753 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jbc[1].gif (22591 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swz[1].gif (3978 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gg[1].png (8891 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[2].gif (20562 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][2].txt (1004 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[2].gif (30383 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\941pojie[1].htm (1595 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[2].gif (832 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic1[1].gif (428 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@mmstat[2].txt (170 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgnav[1].gif (853 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][1].txt (247 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\zs[1].jpg (49159 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1] (2857 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][2].txt (511 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[3].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\6330cf46f68cd2c7c40a422626d1cb30[1].png (362 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\046bt[1].gif (2605 bytes)
    %Documents and Settings%\%current user%\Cookies\index.dat (14652 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\1gg[1].png (28985 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[3].gif (1871 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lszwg[1].htm (1777 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgheader[1].gif (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[2].png (28003 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gg[1].png (5593 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\1gg[1].png (29443 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\top[1].png (9019 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][1].txt (745 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[1].php (4402 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\js[1].gif (22469 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@cnzz[1].txt (165 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[1].gif (117 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\core[1].php (753 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgheader[1].gif (742 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@mmstat[1].txt (170 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bgtitle[1].gif (3 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\jbc[1].gif (28161 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\6330cf46f68cd2c7c40a422626d1cb30[1].png (2782 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\icon[1].png (409 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\icon[1].png (409 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\gif008[1].gif (565 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gif008[1].gif (565 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[2].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\swz[1].gif (9999 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\jbc[1].gif (32881 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\046bt[1].gif (1587 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\style[1].css (1911 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\lszwg[1].htm (1599 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\pic2[1].gif (431 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\gua[1].gif (25772 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\7f114.tmp (15 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[3].gif (37248 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\icon[1].png (409 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\zs[1].jpg (37417 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\top[1].png (9091 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\logo[1].gif (2329 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\zs[1].jpg (35465 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\jiaqun[1].htm (256 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\logo[1].gif (1765 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[2].gif (32993 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gua[1].gif (22637 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swz[1].gif (9253 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\style[1].css (1911 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgnav[2].gif (117 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\zsf[1].gif (38279 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\lhr[1].gif (38889 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\core[1].php (1506 bytes)
    %Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][2].txt (205 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\top[1].png (10189 bytes)
    %Documents and Settings%\%current user%\Cookies\[email protected][1].txt (615 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\pic2[1].gif (431 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bg[1].gif (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\stat[1].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\js[1].gif (34828 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\2014052276129177[1].gif (832 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[2].gif (42863 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[1].php (1475 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bgheader[1].gif (1 bytes)
    %Documents and Settings%\%current user%\Cookies\Current_User@cnzz[2].txt (330 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\gif008[1].gif (565 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[2].gif (2615 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[3].php (1177 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\pic1[1].gif (428 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\stat[1].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\logo[1].gif (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\lhr[1].gif (32715 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[2].gif (853 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\bg[1].gif (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\046bt[1].gif (2688 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\2014052276129177[1].gif (832 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bg[1].gif (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\stat[2].php (4300 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\group[1].png (442 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\bgh[1].gif (2665 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\gg[1].png (10352 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\group[1].png (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\bgtitle[1].gif (916 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\stat[2].gif (43 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\hao123_res.tmp (35 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "wscntmx" = "D:\\wscntmx.exe"

  5. Restore the original content of the HOSTS file (%System%\drivers\etc\hosts):
    127.0.0.1 localhost
  6. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  7. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now