Trojan.Win32.Swrort.3_5f89a33e74
not-a-virus:AdWare.Win32.InstallMonster.fzgq (Kaspersky), Trojan.Win32.Swrort.3.FD (Lavasoft MAS)
Behaviour: Trojan, Adware
The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.
| Requires JavaScript enabled! |
|---|
MD5: 5f89a33e74db0332b9de404c125e8dd5
SHA1: d33b16950873b175f271b9205ed70eaeb1c01556
SHA256: 4a8b27d238a81a47ae27b3a32af4b2fa7c99a23947b8a77228cd70a475ef32dd
SSDeep: 196608:QIqBmLVH8k267lMI6XQUcaVERaU4r3ldkdAthxmtYGZpvg1YmH6FFe3:27DqlMI6gU1eaEdA1yNmKe
Size: 12781744 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2009-06-19 00:33:23
Analyzed on: WindowsXP SP3 32-bit
Summary:
Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).
Payload
No specific payload has been found.
Process activity
The Trojan creates the following process(es):
9EPostService.exe:1816
9EPostService.exe:1088
unstall.exe:2016
WriteMbox.exe:2364
%original file name%.exe:1416
kuwo_jm429.exe:1072
KwWallpaper.exe:2876
taskkill.exe:832
taskkill.exe:1968
taskkill.exe:1852
taskkill.exe:2012
taskkill.exe:424
taskkill.exe:1368
taskkill.exe:912
SoftWare SVC.exe:1096
SoftWare SVC.exe:136
regsvr32.exe:1324
regsvr32.exe:1556
regsvr32.exe:1612
regsvr32.exe:648
regsvr32.exe:364
regsvr32.exe:516
regsvr32.exe:912
KwLnkTipWnd.exe:3024
BrowserSafe.exe:1712
kwAdb.exe:3376
kwAdb.exe:3448
KwMusic.exe:1292
Netsh.exe:340
Netsh.exe:1252
KwConfig.exe:412
The Trojan injects its code into the following process(es):
KwService.exe:1620
IESandBox.exe:968
Mutexes
The following mutexes were created/opened:
No objects were found.
File activity
The process WriteMbox.exe:2364 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (11 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsf10.tmp (0 bytes)
The process %original file name%.exe:1416 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns8.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.sys (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsA.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsB.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\System.dll (11 bytes)
%Program Files%\9ENetwork\Uninst.bat (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns6.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EUninst.bat (82 bytes)
%WinDir%\SoftWare SVC.exe (11893 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Md5dll.dll (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsExec.dll (6 bytes)
%Program Files%\9ENetwork\9EPostService.exe (9451 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\unstall.exe (621 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsm7.tmp (388 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EÈüþ°²×°ÓÅ»¯.bat (233 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns9.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.exe (1499 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns4.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Version.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EService.bat (116 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns5.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\kuwo_jm429.exe (416230 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns3.tmp (6 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns6.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Version.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns8.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Md5dll.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.sys (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsm7.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns9.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsv1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\kuwo_jm429.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns5.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsExec.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsA.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsB.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns3.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns4.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\unstall.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.exe (0 bytes)
The process kuwo_jm429.exe:1072 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\kuwo\kuwomusic\bin\skin\base\RecoTipDialog.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\tta.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\conf.ini (107 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DeskLyric.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwMusic.xml (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistRootPanel.xml (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\DOWNLOAD_ARTISTPIC\49FF334D.dat (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\wav.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\loading.gif (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\Encode.exe (784 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\öÃâ€ÃƒËœÃ‚¿Ã¡ÃŽÃ’ÒôÀÖ.lnk (599 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModMusicTool\conf.txt (713 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\fullplaycontrol.xml (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\DownloadUpdate.exe (6360 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\Base64.dll (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_COLOR_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_PIC_nomal.jpg (871 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WpAbmTip_Start.xml (570 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\conf.ini (113 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwService.exe (1856 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_4a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WpAbmTip_Close.xml (556 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\FirstPlayApeWnd.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ShutDownTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PathListDialog.xml (688 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ac3.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\cda.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\Microsoft.VC90.CRT.manifest (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwEmptyWebDlg.xml (190 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_5a.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KwMusicNsis.dll (14184 bytes)
%Program Files%\kuwo\kuwomusic\bin\runshelldraw_x86.exe (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\userinfo2012.zip (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\DOWNLOAD_ARTISTPIC\1F628AB6.dat (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SaveLyricDeltaWnd.xml (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserfaceWnd.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ShutDownSettingDialog.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModPlaylist.dll (23424 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwKickDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLnkTipWnd.exe (5064 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_COLOR_nomal.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_ac3.dll (19152 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwInfos.exe (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\netsong.zip (30464 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\KwDownloadLnk.ico (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\BindConfig.ini (213 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_4b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\dks.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwAndroidUsbCopy.xml (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\desk_compositor_x86.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\m4a.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_5b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\miniplaylist.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\MatroskaSplitter.ax (8560 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\instAD.dat (228 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad04.jpg (784 bytes)
%Documents and Settings%\%current user% (4 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch\¿áÎÒÒôÀÖ 2014.lnk (777 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModAppStore.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModAndroidMgr.dll (9608 bytes)
%Program Files%\kuwo\kuwomusic\bin\CoreAVC0.ax (6584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WallpaperTipWnd.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\Default.jpg (5520 bytes)
%Program Files%\kuwo\kuwomusic\1.txt (12 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\msvcr90.dll (22552 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModGameEntry.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwTagLib.dll (25824 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\conf.ini (105 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwRecoSong.dll (1552 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_3a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MultiLoginManager.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIAvMgr.dll (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\DuiLib.dll (25776 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ape.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\bk.jpg (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\mylk.dat (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLyric.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\small.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad01.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\AdbWinUsbApi.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPlayControl.dll (7192 bytes)
C:\$Directory (976 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DownloadFinishTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DownloadSettingDialog.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwMinisiteDlg.xml (660 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwVipOpenPage.xml (590 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mp3.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperPlayerWnd.xml (534 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\changeautoskintimewnd.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\MediaInfo.dll (32824 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\lyricshow\LyricTheme.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\bk.jpg (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\WriteMbox.exe (9320 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_COLOR_nomal.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\cursor\hand-open.cur (766 bytes)
%Program Files%\kuwo\kuwomusic\bin\IEProxy.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\out_kw_ds.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\DshowPlayer.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\small.jpg (15 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpdateTipDialogEx.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\DumpReport.exe (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\small.jpg (9 bytes)
%Program Files%\kuwo\kuwomusic\bin\IESandBox.exe (13584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\TipDlg.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_mpg123.dll.manifest (406 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwWallpaper.exe (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwHttp.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\mylkx.dat (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserFeedbackDlg.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\Microsoft.VC90.CRT.manifest (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\startpage.xml (244 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\conf.ini (91 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\EqDlgAttribute.xml (169 bytes)
%System%\config (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RealEggSmashDlg.xml (407 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\MP2.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\Eq_Kweq.dll (1856 bytes)
%WinDir% (96 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_3b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_2a.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_COLOR_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_2b.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\music[1].htm (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KuWoNsis_new.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModMusicTool\conf.txt (713 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIDeskLyric.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwRestoreBackList.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\CloseBtn.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperOpWnd.xml (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\userinfo2012.zip (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CopyNotifyDialog.xml (436 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicTree.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\System.dll (11 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\vipMbox_new.zip (15168 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpdateTipDialog.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\tyyykw.wav (26688 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AutoLoginTip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\msvcp90.dll (19152 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLib.dll (13368 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\nowbg.gif (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\kwjserror.html (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\BkImage.png (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SynExistListTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\MakeLrcWndRes\lrc_finish_icon.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Zlib.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwTaskbarNotifierDialog.xml (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\config.ini (10932 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad02.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ExitTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Win7Trait.dll (13 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\logindlgex.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mp1.ico (784 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\¿áÎÒÒôÀÖ 2014.lnk (771 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwConfig.exe (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\lidx.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\lrcx.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\casullisten.pl (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwHttpRequestMgr.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ListBuddyWnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\hanzi_pinyin.dict (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModResource\NetSong-artists.pl (9608 bytes)
%WinDir%\KwYlx.dat (25 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\playlist.gif (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MuiscTreeInfoWnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_1a.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KillProcDLL.dll (10 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModResource\NetSong-artists.pl (9608 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\skin.dat (33633 bytes)
%Program Files%\kuwo\kuwomusic\bin\CWmpPlayer.dll (23424 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\searchtip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\bk.jpg (3312 bytes)
%WinDir%\Prefetch\REGSVR32.EXE-25EEFE2F.pf (32 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMusicCore.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMV.dll (15536 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitSongDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\ReconEngine.exe (8184 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\LrcUploadFailTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\runshelldraw_x64.exe (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_mpg123.dll (28288 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Program Files%\kuwo\kuwomusic\bin\CKuwoPlayer.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\sharesong.zip (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPopupWnd.dll (12536 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwUserKick.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLyricShow.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\desk_compositor_x64.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwDataDef.dll (8184 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\desktopInfoWnd.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwPopupRbWebDlg.xml (190 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\setup.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwServiceProxy.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_1b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\msgbox.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\changeskinwnd.xml (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\lyricshow\LyricTheme.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIAndroidUsbDevice.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\Uninstall.exe (12494 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_4a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\flac.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_3a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\KwMusic.exe (19096 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_4b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModSkinManage.dll (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\small.jpg (7 bytes)
%Program Files%\kuwo\kuwomusic\readme.txt (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\iconTip.xml (277 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIVIPMan.dll (6360 bytes)
%Program Files%\kuwo\kuwomusic\bin\Vol.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WebPopupDlg.xml (427 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicToolDown.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\bk.jpg (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\bk.jpg (1202 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLog.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\small.jpg (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MakeLyricDlg.xml (9 bytes)
%Program Files%\kuwo\kuwomusic\KwMusicSetup.exe (183968 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwUpdate.dll (4992 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwSongCache.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpLyricDlg.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\UINowPlaying.dll (13368 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\KW_SEARCH_SONG\jay.dat (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_PIC_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\aac.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLocalMusic.dll (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicTool.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\conf.ini (95 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\In_Wma.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CreateNewList.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\mvloading.swf (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\cue.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RemoteUserLoginAfter.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KWUpdate.exe (30344 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\OpenUploadLocal.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistRootPanel2.xml (784 bytes)
%Documents and Settings%\All Users\Start Menu\¿áÎÒÒôÀÖ 2014.lnk (759 bytes)
%System% (688 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\BackToOldVer.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\desktopTip.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\minierror.htm (798 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_3b.png (1 bytes)
%WinDir%\Prefetch\9EPOSTSERVICE.EXE-099C9721.pf (16 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPlaylistPanel.dll (20624 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitMvDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\GameIcon.ico (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperNcWnd.xml (449 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WallpaperPreviewWnd.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\PlayerCore.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\skin.xml (12 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\songcomment.zip (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\ShellDl.exe (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_2a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistStyle3.xml (388 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\SimpleSC.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\vipMbox_new.zip (15168 bytes)
%Program Files%\kuwo\kuwomusic\bin\Module.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\wma.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\mvmodbar.xml (3 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014.lnk (765 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AlreadDownloadDialog.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad03.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\pd.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DeskLyricUnlock.xml (494 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\baidu.pl (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\ccenter.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIMusicTree.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\LrcUploadSuccTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KuwoSyncMobile.dll (1552 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\sharesong.zip (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\MpaDecFilter.ax (30464 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Program Files%\kuwo\kuwomusic\bin\AdbWinApi.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwEqDlg.xml (7 bytes)
%WinDir%\Prefetch\SOFTWARE SVC.EXE-084F9A5B.pf (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_2b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\functionwnd.xml (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\KuwoDaemon.apk (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\msvcr90.dll (22552 bytes)
%Program Files%\kuwo\kuwomusic\bin\msvcp90.dll (19152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsxD.tmp (731729 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModDownload.dll (11048 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SynLsTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\Microsoft.VC90.CRT.manifest (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIMiniPanel.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\logindlg.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_APE.dll (62984 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_mp4.dll (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\mvloading.html (888 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CloudLoginBallon.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwVipWebDlg.xml (534 bytes)
%Program Files%\kuwo\kuwomusic\msvcp90.dll (21088 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\minidlg.xml (16 bytes)
%Program Files%\kuwo\kuwomusic\bin\kwAdb.exe (20416 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\EnterBtn.png (3 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\Èüþ˵Ã÷.lnk (766 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserLoginGuide.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModUpdateWeb.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ModifyLyricRelationWnd.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwCloudCenterBox.xml (623 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ogg.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RemoteUserLoginBefore.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mid.ico (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_PIC_highlight.jpg (1 bytes)
%Documents and Settings%\All Users\Desktop\¿áÎÒÒôÀÖ 2014.lnk (759 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModConfig.dll (2392 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_5a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\gameBoxLoading.htm (799 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIDownload.dll (13584 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\nsisSlideshowx.dll (2392 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_1a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\msvcr90.dll (26424 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_1b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitVipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Conf\default\config.ini (7637 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\DownloadUpdate.ini (120 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwConfig.xml (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModSynList.dll (6584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\cursor\hand-close.cur (766 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\songcomment.zip (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KeywordSafeTip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ThumbnailToolbar.bmp (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\Kwwebpopup.xml (417 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_5b.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\w7tbp.dll (9 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\cache\KW_SEARCH_SONG\jay.dat (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_PIC_nomal.jpg (871 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\forcechangeskinwnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwDPGame.exe (8560 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\inetc.dll (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\netsong.zip (30464 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMusic.exe (54196 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AutoRunShowTipWnd.xml (3 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KuWoNsis_new.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad02.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\inetc.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KillProcDLL.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\Base64.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\SimpleSC.dll (0 bytes)
%Program Files%\kuwo\kuwomusic\1.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\w7tbp.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad01.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad03.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\instAD.dat (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad04.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmC.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KwMusicNsis.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\nsisSlideshowx.dll (0 bytes)
The process KwWallpaper.exe:2876 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473321334926.jpg (1921 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\wp.ini (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473518690014.jpg (353 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473516821210.jpg (1725 bytes)
%Program Files%\kuwo\kuwomusic\bin\Log\act.log (767 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473519658028.jpg (353 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473320578232.jpg (549 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473055636025.jpg (2078 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473517759929.jpg (1098 bytes)
The process KwService.exe:1620 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
C:\KwDownload\Temp\F53A522FF938F1F4.zip (64019 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\kmap\F53A522FF938F1F4.kmap (172 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\config.ini (1318 bytes)
%Program Files%\kuwo\kuwomusic\bin\Log\act.log (491 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\index\update.txt (536 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\setup.xml (3 bytes)
The Trojan deletes the following file(s):
C:\KwDownload\Temp\.testfile (0 bytes)
The process regsvr32.exe:364 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%WinDir%\WMSysPr9.prx (316 bytes)
The process KwLnkTipWnd.exe:3024 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\config.ini (1380 bytes)
The process kwAdb.exe:3448 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\adb.log (38 bytes)
The process KwMusic.exe:1292 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\date.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topnav.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\zone.js (33 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listenicon2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask5.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_fc.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mv_btn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\error.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqtongming.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan10.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\small.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike1.gif (462 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ieerror.jpg (15 bytes)
%Program Files%\COMMON FILES (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\concertbanner.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\close.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan4.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\prev.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\rplay_h.gif (9 bytes)
%System%\Macromed\Flash (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scon.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fankui.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\commdemo.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\navbg.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\Thumbs.db (745 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addlist.png (1 bytes)
%WinDir%\Temp\Perflib_Perfdata_678.dat (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\line.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listbgt2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_btn.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¾Âµ仳¾Éµç̨ -4459_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\playlist.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\80ºóµç̨ -4953_0.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\big.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tcjdt.png (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiushi.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollmiddle.png (957 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjsuggest.gif (222 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\local2014.js (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\dax.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\dax.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\33606748.dat (4037 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-80ºóµç̨ -4953.pl.temp (155 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_9.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\anow.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sright.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_4.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjnew1.gif (613 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tcjdt.png (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbghover.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\originalcom.js (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navbg.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\closed.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\MV2.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\albumpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\paoBg.png (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic2.jpg (22 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\ape.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_btn2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_2.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\bangpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addgedan.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\jiazai.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask2.png (19 bytes)
C:\$Directory (5153 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_3.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\prev_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbg.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\next_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hdpic.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading22.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\É˸õç̨ -6003_0.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\message.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\em.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\play_z.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shou2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fousplay.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\topic.css (23 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\yindao.png (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\topic.css (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan6.png (165 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\Radio.zip (1882 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\em.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightnavnow.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\otherbtn.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\radio\radio.conf (15168 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan5.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dragarrow.png (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\abg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_radio.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiuchang.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\icon1.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\alBg.gif (61 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\icon.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwo.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan4.png (126 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan1.png (137 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\high.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Thumbs.db (5064 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zone2.js (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\searchnoresult.js (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\icon.png (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\4FDFB85C.dat (3317 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\navbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplay.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bz_vip.gif (366 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\diantai_play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbtn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_play.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\singer.png (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\jxj.js (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_13.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\download.css (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_tit_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\bangpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\kuwobox.png (2 bytes)
%Documents and Settings%\%current user%\My Documents (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphobottom.gif (2 bytes)
%System%\config (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiuchang.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zone2page.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_2.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedan.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\two.css (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scon.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\Btn.png (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\no_copyright.txt (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\init.html (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan8.png (344 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btntop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more4.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\big.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightIcon.png (4 bytes)
%Documents and Settings%\All Users\Application Data (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\artist.js (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\tree.js (3712 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gotop.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pageH.png (1864 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplayhover.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\close.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\close.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipno.jpg (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\tequanInfo.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sright.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\singer.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\topic.css (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\024C3854.dat (88 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\61D38DD6.dat (3026 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\topic.js (40 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zonegedan.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wireshark.txt (5481 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\play.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_1.jpg (22 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pic160bg2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\playlist.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\jianjie.html (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_omxe.dll (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\one.css (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_bang.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\cookie.js (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songerdiantai.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\hsot_xuan.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\music1.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\abg2.png (1 bytes)
%System% (11992 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonegedanpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\album_img.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\music.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnmiddle.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\vipMbox_new.zip (5388 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\search.js (6624 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\gedan.js (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addlist.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan8.png (172 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\icon.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\vipNoTitle_2012-10.css (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonemvgedan.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\left_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dragarrow.png (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonegedan.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\feedback.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask1.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\music2.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\version.ini (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tanbtn.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask5.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon1.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img (45 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\feedback.jpg (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listenicon.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\diantai_playH.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\local2014.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading1.gif (49 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedanhov.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hot.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\download.css (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\right_j.jpg (520 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\class.gif (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\init.html (145 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013 (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\album.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\low.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\index.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone.css (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModMusicTool\ksong.ini (126 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\init.html (290 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\yindao.png (794 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbghover.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_8.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\lanmu_img.jpg (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplayHover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topic_play_jx.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\low.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\gedanpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipno.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newpho.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fankui.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bodyBg.jpg (7 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.9.0.Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_x-ww_9e7eb501 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbtnhover.png (1 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\otherbtn.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalpage.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading3.gif (98 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996_0.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan3.png (290 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjnew1.gif (613 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newpho.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\1AF9CC01.dat (3039 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\jquery.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\mvlistbg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone2.css (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\mvlistbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqplayhover.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_9.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zone.js (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucanggray.gif (1810 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\adx.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_12.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-»ªÓïºÃ¸èµç̨ -19625.pl.temp (153 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\dhj.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_no.gif (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\prev.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchnoresult.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\onepage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\comment_title.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Btn.png (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan1.png (274 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\icon1.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gedanNew.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan5.png (254 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\rplay_no.gif (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892_0.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzone.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan9.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scon.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\host_mo.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\onepage.js (11 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hgaoqing.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightnavnow1.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topicSearch.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\line.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\mvgedan.js (1568 bytes)
%Documents and Settings%\%current user%\Cookies (96 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_3.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\mvlistbg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_7.jpg (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sanjiao.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_7.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\navtan.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diary.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\next_hover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModMusicTool\conf.txt (688 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan7.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\right_j.jpg (520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbottom.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\subnav.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892_1.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\low.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒøèµç̨ -6007_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pageH.png (932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\allInOneNoTitle.js (63 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\alBg.gif (61 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\original.js (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\loaderror.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask2.png (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_newsong.jpg (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\close.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\top.png (225 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\search_cat.html (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightIconHover.png (4 bytes)
%WinDir%\Fonts (480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonegedanpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwomusic2.jpg (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\select.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan11.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan12.png (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_vorbis.dll (1281 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqplayhover.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pic160bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphomiddle.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucang.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\add.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonemvpage.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\search_cat.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\onepage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sousuo.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newnum1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shiting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newnum1.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIconHover.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\artist.js (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\left_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\version.ini (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_h_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\error.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newnum.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan3.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_iconH.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\page.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\trp.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment_title.jpg (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\gray_btn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\blank.gif (98 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan2.png (131 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\line.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996_1.jpg (3 bytes)
%WinDir%\Microsoft.NET\Framework\v4.0.30319 (1536 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_tag.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\mvpage.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topnav.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask1.png (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\fans.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\zz_vip.gif (372 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting.gif (1 bytes)
%WinDir%\WinSxS (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\mvgedan.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tq.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¿áÎÒøèµç̨ -6007.pl.temp (152 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\artistpage.html (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\getRequest.js (985 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\originalcontent.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiaguanzhu.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\fans.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\date.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\adxhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\z.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\kw_scroll.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjlike1.gif (231 bytes)
%WinDir% (1264 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan2.png (131 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\shoujiadimg.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_iconH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\cookie.js (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_13.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\em.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\5700E407.dat (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\picBg120.png (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_CDReader.dll (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\bang.js (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\download.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\otherbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djnewplayhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModNotify\no_copyright.txt (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading1.gif (98 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navtan.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_DeFX.dll (62 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btnbottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqplay.png (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473320578232.jpg (57 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\gedanpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_wave.dll (784 bytes)
%WinDir%\Temp\Perflib_Perfdata_610.dat (100 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\comment.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtnhover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adx.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hot.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcom.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_DeFX.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan3.png (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\music.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diantai.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\small.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\close_hover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\leftIcon.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ablue2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon1.png (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_flac.dll (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\twoartpage.js (8 bytes)
%Documents and Settings% (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjlike2.gif (323 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ.pl (1056 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\jxjpage.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\rplay_no.gif (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIcon.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shou.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\icon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow1.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\base.css (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragicon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\jquery-1.4.2.min.js (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IN_TTA.DLL (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\album_img.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topnav.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\downloadAD.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\jquery-1.4.2.min.js (1202 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_radio.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\zone.css (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqtongming2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn4.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mv_btn.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\adx.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\right_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\left_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more4.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerdiantai.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan4.png (126 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbottom.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\516ED6BE.dat (2197 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\comment_title.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\topicpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\5239D28D.dat (2526 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_izOzone.dll (12024 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listenicon.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\trp.gif (43 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songerdiantai.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\icon2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\banner.jpg (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragarrow.png (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\index.css (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\line.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist2.png (1940 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\right_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\page.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shijian.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchnoresult.js (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\twoflpage.js (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\nav_a_z.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonemvpage.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\originalpage.html (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gamers.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\hotzone.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sleft.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\share_icon.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\radio\period_radio.conf (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrolltop.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newpho.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\left_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\277E9CAE.dat (3069 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_h.gif (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\239E6EC3.dat (2357 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipsecsice.jpg (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\topiccom.js (21 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\select.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\originalpage.html (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hsot_xuan.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\page.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addH.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow.gif (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_izOzone.dll (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\picBg120.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\jquery.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\dhj.js (45 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\27A51D5A.dat (5011 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiazai.jpg (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\index.dat (1460 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\downloadAD.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\6892A63D.dat (4966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone2.js (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\yindao.png (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btnmiddle.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\bg_re.png (1846 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzonehover.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\gray_btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchcat.js (4784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nav_a_z.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_play1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_bang.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwo.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\629C102A.dat (4631 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\erji.gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_ac3.dll (19096 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan7.png (270 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_4.jpg (37 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplayhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\topicpage.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\play_z.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-ÃÂøÂçºì¸èµç̨ -18239.pl.temp (152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjsuggest.gif (444 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\baiduplayer.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone.js (3104 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\listbgt.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightnavnow1.gif (1 bytes)
%WinDir%\pchealth\helpctr (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songerbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\jxj.js (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fousplay.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\ape.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djzone.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\right_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\546A54BF.dat (2289 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newphobottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\zonepage.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shiting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading22.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\originalcom.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask5.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\big.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\onepage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\haveselect.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gamers.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID126.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon.png (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\jiaguanzhu.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\quku.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\mvgedan.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\jiazai.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\leftIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\twoartpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjlike1.gif (231 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒÈȸèµç̨ -6001_0.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\line.png (958 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892.pl.temp (149 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\searchpage.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_jx_play.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\bang.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\common.css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerbtn.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\fans.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\mvpage.html (3 bytes)
%Documents and Settings%\All Users\Start Menu\Programs (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\yellow_z.png (966 bytes)
C:\ (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÃÂñÃÂ×é1-ĬÈÃÂÃÂñÃÂ.pl (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topic.js (2336 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_wave.dll (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jianjie.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djnewplay.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btnbottom.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shijian.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_jxj.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topiccom.js (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantgai_cont_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music1.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_omxe.dll (34561 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\play.png (2 bytes)
%Program Files%\Windows NT (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djzonehover.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\topiccom.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_newsong.jpg (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\comm.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\original.css (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\quku.html (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\nav_a_z.png (2 bytes)
%Documents and Settings%\%current user%\Application Data (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play1.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan5.png (127 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addlist2.png (970 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\tequanInfo.js (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon.png (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mv_btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoflpage.js (3104 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\right_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Update\updateconf.ini (197 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\b_play_h_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqtongming2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\bang.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pageH.png (932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan9.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\kuwobox.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\ÃÂøÂçºì¸èµç̨ -18239_1.jpg (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\dhj.js (3408 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\gray_btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\closed.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\MV.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\search.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchpage.html (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shou.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\anow.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\gedanpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrolltop.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\version.ini (60 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\3636CFF8.dat (3436 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\MV2.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\album_img.jpg (30 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan10.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\goListenBtn.png (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\Log\act.log (12942 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\download.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\qq.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\next.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\common.css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_3.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\bg_re.png (923 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ablue.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\icon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\subnav.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_CDReader.dll (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\jiaguanzhu.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\index.css (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\searchnoresult.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fousplayHover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplay.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\pic100_1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\closed.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\downloadAD.html (1 bytes)
%Documents and Settings%\All Users\Start Menu (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_1.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\zone2.css (7 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan11.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\tree.js (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming2.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\dhj.html (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\ape.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gedanNew.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¾Âµ仳¾Éµç̨ -4459.pl.temp (153 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fankui.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music2.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_fc.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\hdpic.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\searchcat.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn2.gif (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\close_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\index.css (4784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\trp.gif (86 bytes)
%Program Files% (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topicSearch.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipok.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\7C3220AF.dat (3040 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ablue2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\shoujiadimg.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\albumpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\getRequest.js (989 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjnew2.gif (612 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan8.png (172 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbghover.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mvbg2.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hgaoqing.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\lanmu_img.jpg (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\search.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\config.ini (46396 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sousuo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addlist2.png (970 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipsecsice.jpg (21 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\message2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn3.png (1 bytes)
%Program Files%\Adobe\Reader 9.0\Reader (192 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\diantai_play.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_APE.dll (62984 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID167.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\host_mo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\bodyBg.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\artist.js (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\leftIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\music2.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jxjpage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\download_btn_bg.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_flac.dll (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_5.jpg (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjlike2.gif (323 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mvbg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\class.gif (357 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\message.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbtnhover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1] (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\mylkx.dat (62 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songerbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\baiduplayer.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\hotzone.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_playH.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\47D18107.dat (2713 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\onepage.js (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\artistpage.html (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnbottom.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\prev_hover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\kw_scroll.js (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\gedan.js (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\comm.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\commdemo.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\abg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songershoucanggray.gif (905 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\new_like_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan3.png (145 bytes)
%Program Files%\Common Files\VMware\Drivers (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\top.png (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\download_btn_bg.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\loaderror.html (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next_hover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_1.jpg (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_icon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_2.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\erji.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan4.png (252 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\bang.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\searchnoresult.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.png (1916 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100_1.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiushi.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addgedanhov.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\add.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\90ºóµç̨ -4954_1.jpg (196 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\nav_a_z.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\originalcontentpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\topicSearch.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dragicon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\mo.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\onepage.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightIcon.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jquery.js (6008 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\index.dat (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fousplayHover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sright.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\searchpage.html (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\download.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\local2014.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\close.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\27990426.dat (3656 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songershoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\bangpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwomusic2.jpg (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\original.js (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\download.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading3.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newphomiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gotop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\vipNoTitle_2012-10.css (11 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqplay.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newphomiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID123.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\icon.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\paoBg.png (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\hdpic.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\play_z.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoartpage.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close_hover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\high.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\music1.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\high.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_4.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\one.css (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-90ºóµç̨ -4954.pl.temp (155 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalcontentpage.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\allInOneNoTitle.html (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\diantai_playH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoartpage.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_radio.gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\qq.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan7.png (135 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\host_mo.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\download.js (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\picBg120.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\nowbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\haveselect.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dragicon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\z.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev_hover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\jianjie.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_tag.jpg (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan5.png (127 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\originalcontent.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV2.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonepage.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\loaderror.html (939 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tanbtn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqtongming.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\2E0CA178.dat (308 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\hotzone.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ieerror.jpg (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gamers.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\twoflpage.js (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\download_btn_bg.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew2.gif (1224 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zone2page.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjsuggest.gif (222 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\comment.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan6.png (165 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\blank.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\kuwobox.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_btn.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_5.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shijian.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_5.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\play.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg2.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\zz_vip.gif (368 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\203B42C6.dat (2247 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tq.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan8.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\275F2B1F.dat (5905 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shiting.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask2.png (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan8.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\original.css (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\allBtn.gif (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sanjiao.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adxhover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¿áÎÒÈȸèµç̨ -6001.pl.temp (152 bytes)
%Documents and Settings%\All Users (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan7.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\comm.js (11880 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\twoartpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\yellow_z.png (966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan6.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\one.css (14 bytes)
%Program Files%\Adobe\Reader 9.0 (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hot2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\left_j.jpg (514 bytes)
%Program Files%\kuwo\kuwomusic\bin\kid.ini (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\É˸õç̨ -6003_1.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\download.js (16 bytes)
%WinDir%\Microsoft.NET\Framework (96 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listenicon2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\index.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\haveselect.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\botom.png (200 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan6.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\common.css (4784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\select.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\Server\config.ini (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_bang.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\left_j.jpg (514 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sousuo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\twoflpage.html (3 bytes)
%Documents and Settings%\All Users\Documents (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\base.css (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\topicpage.html (17 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_vorbis.dll (8560 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_diary.jpg (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwo.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\lanmu_img.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModNotify\no_rigth.zip (146 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID185.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\nav_a_z.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btntop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\shoujiadimg.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\line.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\subnav.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btntop.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.png (2 bytes)
%Documents and Settings%\%current user% (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\add.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\original.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\yellow_z.png (1932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\twoflpage.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songershoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zonemvgedan.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_play_jx.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcontent.js (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\APPLICATION DATA (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan2.png (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\allInOneNoTitle.js (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\twoartpage.js (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play_hover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\two.css (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\dhj.js (54 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollmiddle.png (957 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\gedan.js (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_mp4.dll (8560 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\90ºóµç̨ -4954_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\original.css (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-É˸õç̨ -6003.pl.temp (153 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_jxj.jpg (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_diantai.jpg (27 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\DD_belatedPNG.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\quku.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\artistpage.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\mo.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan1.png (137 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\bz_vip.gif (366 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shoucang.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_jxj.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_diary.jpg (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listbgt2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon2.png (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songershoucanggray.gif (905 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\zone.css (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\searchcat.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\paoBg.png (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipok.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\z.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\small.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\album.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\message2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\KW_MUSICRADIO_PICS\595567 (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\pic100_1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask1.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addgedan.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\rplay_h.gif (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_btn2.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_icon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\jxjpage.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\topic.js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan3.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\80ºóµç̨ -4953_1.jpg (196 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mvbg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan7.png (135 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\ÃÂøÂçºì¸èµç̨ -18239_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒÈȸèµç̨ -6001_1.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\tips_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\DD_belatedPNG.js (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pic160bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nowbg.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiushi2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\search_cat.html (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jxj.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiuchang.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn3.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\botom.png (200 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\245D4C1D.dat (5672 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more3.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topic_jx_play.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gedanNew.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\next.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_5.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\tips_play_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\bang.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\feedback.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_1.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mvbg2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\commdemo.js (11040 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\navtan.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\mo.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\base.css (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\index.js (9984 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbtn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newphobottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pic160bg2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon1.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\top_icon_btn.png (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan4.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\banner.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_12.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading3.gif (49 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\kw_scroll.js (20 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\album.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwomusic.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\allBtn.gif (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\allInOneNoTitle.html (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\share_icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollmiddle.png (1914 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¾Âµ仳¾Éµç̨ -4459_1.jpg (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoflpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\pic100.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew1.gif (1226 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\sprdtasks.ini (446 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading22.gif (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\blank.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tanbtn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\download.css (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\netsong.zip (5490 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newnum.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sanjiao.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIconHover.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\albumpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒøèµç̨ -6007_1.jpg (3 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.9.0.Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_x-ww_b7353f75 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_tit_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\top_icon_btn.png (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ieerror.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gotop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan5.png (6 bytes)
%Program Files%\kuwo\kuwomusic\bin (292 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiushi2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightnavnow.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_3.jpg (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hot2.gif (1 bytes)
%System%\wbem\Logs (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\hsot_xuan.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbg.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon.png (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\pic100.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996.pl.temp (152 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\erji.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ablue.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\concertbanner.jpg (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan12.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\tree.js (56 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\adxhover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\date.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\new_like_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btnmiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_8.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shou2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\b_play_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\dhj.html (17 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbottom.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_4.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrolltop.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\mvpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addgedanhov.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\two.css (24 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjnew2.gif (612 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\line.png (958 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hgaoqing.gif (2 bytes)
%Program Files%\kuwo\kuwomusic (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sleft.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantgai_cont_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_diantai.jpg (27 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonepage.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\playlist.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\banner.jpg (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan6.png (330 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\DD_belatedPNG.js (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\anow.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\add.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\nav_a_z.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_newsong.jpg (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\MV.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\goListenBtn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\abg2.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sleft.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\error.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\originalcontentpage.html (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\IN_TTA.DLL (57 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike2.gif (646 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\searchnoresult.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\goListenBtn.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwomusic.jpg (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\tips_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\tips_play_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_2.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_tag.jpg (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\kws12.tmp (406 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\nowbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplay.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIcon.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\leftIcon.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\singer.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading1.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\bg_re.png (923 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.jpg (2 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantgai_cont_bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\local2014.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan10.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\small.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike1.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sright.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\line.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\big.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_h.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\dax.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_9.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_4.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tcjdt.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navbg.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\closed.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\paoBg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic2.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\bangpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\bang.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbg.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hdpic.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\em.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\topic.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\otherbtn.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\erji.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiuchang.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\alBg.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music1.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\high.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Thumbs.db (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\mvlistbg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplay.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_izOzone.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\singer.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_13.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\kuwobox.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphobottom.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\download_btn_bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\no_copyright.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan8.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more4.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\artist.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pageH.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplayhover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\close.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonemvpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\playlist.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\one.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\two.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnmiddle.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\search.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonemvgedan.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tanbtn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask5.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\feedback.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedanhov.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\right_j.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonegedan.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\album.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\low.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\init.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbghover.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_8.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplayHover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipno.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\top.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bodyBg.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading3.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan3.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\getRequest.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_omxe.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone2.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzone.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_no.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchnoresult.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan5.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan9.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topicSearch.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\mvgedan.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_3.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_7.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sanjiao.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topic.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerbtn.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplay.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fankui.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\select.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan11.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_radio.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphomiddle.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucang.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\search_cat.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\onepage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sousuo.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIconHover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_iconH.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment_title.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\blank.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topnav.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\commdemo.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiaguanzhu.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\fans.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\date.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_iconH.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\cookie.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading1.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navtan.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollmiddle.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtnhover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adx.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcom.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_DeFX.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\music.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diantai.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diary.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan7.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow1.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragicon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\jquery-1.4.2.min.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IN_TTA.DLL (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\downloadAD.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn4.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mv_btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerdiantai.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragarrow.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchnoresult.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIcon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\hotzone.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\share_icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrolltop.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newpho.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addH.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipsecsice.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_playH.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hsot_xuan.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\page.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jquery.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\tequanInfo.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\original.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiazai.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\bg_re.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzonehover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\left_j.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchcat.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nav_a_z.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btntop.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwo.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_play_jx.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_ac3.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan7.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjsuggest.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\baiduplayer.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\botom.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\listbgt.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_12.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonegedanpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_jx_play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bz_vip.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_tit_bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\tree.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jianjie.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shijian.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topiccom.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zone2page.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_newsong.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\quku.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\nav_a_z.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoflpage.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\dhj.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\gedanpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\version.ini (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\album_img.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_fc.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_3.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\subnav.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplayhover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplay.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_1.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\ape.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\trp.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music2.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\index.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jxjpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\albumpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_APE.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan4.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\host_mo.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_flac.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\class.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\top_icon_btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\onepage.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\artistpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnbottom.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\gedan.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\new_like_icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedan.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\loaderror.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next_hover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_1.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_2.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan4.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100_1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\mo.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\picBg120.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\download.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\play_z.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoartpage.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close_hover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucanggray.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_vorbis.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalcontentpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\allInOneNoTitle.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoartpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\download.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\haveselect.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_wave.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev_hover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\z.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_tag.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV2.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ieerror.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gamers.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_5.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone2.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\zz_vip.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan8.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shiting.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adxhover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\comm.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan6.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\common.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_bang.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\topicpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\lanmu_img.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan1.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\shoujiadimg.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\yellow_z.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcontent.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\allBtn.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\allInOneNoTitle.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play_hover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_mp4.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\original.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\qq.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_h_bg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_jxj.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbg.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shoucang.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipok.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gotop.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_icon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan3.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nowbg.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jxj.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn3.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more3.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gedanNew.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_5.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\bang.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tq.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\base.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\index.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new2.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\kw_scroll.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\gray_btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoflpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew1.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\yindao.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading22.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\download.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIconHover.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_CDReader.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\DD_belatedPNG.js (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan5.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\concertbanner.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan12.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\dhj.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbottom.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_4.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\mvpage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hgaoqing.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonepage.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\banner.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan6.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\anow.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sleft.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\error.html (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike2.gif (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\goListenBtn.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_2.jpg (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\vipNoTitle_2012-10.css (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIcon.png (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message.png (0 bytes)
The process IESandBox.exe:968 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#js.miaozhen.com\settings.sxx (208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\q[1].k (4920 bytes)
%Program Files%\kuwo\kuwomusic\bin\Log\act.log (3174 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[6].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[2].txt (960 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[4].htm (1508 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\crossdomain[1].xml (264 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[1].page (1114 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[1].txt (603 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\setCookie2013[1].htm (2 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[2].txt (1668 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swfobject[1].js (562 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[1].txt (1263 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\#SharedObjects\QEA5Z3QJ\js.miaozhen.com\m.sxx (179 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1] (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (219 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[1].htm (684 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\c[1].swf (469 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[2].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[9].htm (685 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swfobject[1].js (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\kuwofx[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[3].htm (686 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\crossdomain[1].xml (215 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index1[1].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[8].htm (686 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[5].htm (685 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mookie1[1].txt (162 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx (543 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (12532 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\index2[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[7].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mookie1[2].txt (364 bytes)
The Trojan deletes the following file(s):
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[1].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[2].txt (0 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#js.miaozhen.com\settings.sol (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swfobject[1].js (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[1].txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[2].txt (0 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mookie1[1].txt (0 bytes)
Registry activity
The process 9EPostService.exe:1816 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "48 DD C8 AA C4 D4 47 66 0F 0C 72 9B 79 36 85 93"
The process 9EPostService.exe:1088 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3B D7 F6 6A 83 43 0C 8C 8F FF 39 F2 56 1A D2 81"
The process unstall.exe:2016 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A3 5D 27 AB 28 C6 F4 4C 11 03 BE A7 50 B8 7E 3F"
The process WriteMbox.exe:2364 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Classes\.CUE]
"(Default)" = "kwfile_CUE"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc]
"Progid" = "kwfile_lrc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CUE\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_lrc\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\lrc.ico"
[HKCU\Software\Classes\kwfile_CUE\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CUE]
"Progid" = "kwfile_CUE"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx]
"Progid" = "kwfile_lrcx"
[HKCR\kwfile_CUE\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\CUE.ico"
[HKCR\kwfile_lrcx\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\lrcx.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CUE\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx\UserChoice]
"Progid" = "kwfile_lrcx"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\UserChoice]
"Progid" = "kwfile_lrc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc]
"kwbak" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks\UserChoice]
"Progid" = "kwfile_dks"
[HKCU\Software\Classes\kwfile_CUE\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx\UserChoice]
"kwbak" = ""
[HKCR\kwfile_dks\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\dks.ico"
[HKCR\kwfile_CUE\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_lrc\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CUE\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_lrcx\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_CUE\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CUE\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "7E 13 97 A8 23 D2 02 19 C7 80 52 30 D8 F6 4B DF"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_CUE\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKCR\.cue]
"(Default)" = "kwfile_CUE"
[HKCR\kwfile_CUE\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_CUE\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_dks\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\kwfile_CUE\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
The process %original file name%.exe:1416 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0B 2A 0C F6 64 98 83 04 F9 51 2C FC 10 99 39 B6"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.919yi.cn/?id=PATTERN&m=000C295C9464&s=Mf1570b3cc56ec0ed1a5b850bae7e4b44"
[HKLM\SOFTWARE\9ENetwork]
"9e" = "http://www.919yi.com/post_report.php"
"POST21" = "id=PATTERN&vm=1&DC=VMware SVGA II&report=HDH,MKW×tamp=20160912185517&info=NT5.1.2600,Service Pack 3,UnknownProductType|000C295C9464|A8A67A25&sign=M793e912843d823481ffcd33389259cc6&version=v0.2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\9ENetwork]
"SIGN" = "M5595cf403efae26c33c58c913d5cb96f"
[HKLM\SOFTWARE\Microsoft\SoftWare Reporting]
"UserId" = "PATTERN"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.919yi.cn/?id=PATTERN&m=000C295C9464&s=Mf1570b3cc56ec0ed1a5b850bae7e4b44"
[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.919yi.cn/?id=PATTERN&m=000C295C9464&s=Mf1570b3cc56ec0ed1a5b850bae7e4b44"
[HKLM\SOFTWARE\Microsoft\SoftWare Reporting]
"Macaddress" = "000C295C9464"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Policies\Microsoft\Internet Explorer\Main]
"Start Page" = "http://www.919yi.cn/?id=PATTERN&m=000C295C9464&s=Mf1570b3cc56ec0ed1a5b850bae7e4b44"
[HKLM\SOFTWARE\Microsoft\DirectUpdate\Debug\ThirtyMKW]
"ThirtyMKW" = "W"
[HKLM\SOFTWARE\Microsoft\SoftWare Reporting\Reporting\Reporting]
"HTTP POST" = "http://www.919yi.com/post_report_use.php"
[HKLM\SOFTWARE\9ENetwork]
"IEHome" = "http://www.919yi.cn/?id=PATTERN&m=000C295C9464&s=Mf1570b3cc56ec0ed1a5b850bae7e4b44"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsmE.tmp\KwMusicNsis.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsmE.tmp\nsisSlideshowx.dll, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsmE.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsk2.tmp\,"
The process kuwo_jm429.exe:1072 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda]
"Progid" = "kwfile_CDA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP1\UserChoice]
"Progid" = "kwfile_MP1"
[HKCR\.ogg]
"(Default)" = "kwfile_OGG"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_MP1\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_TTA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx\UserChoice]
"kwbak" = ""
[HKCR\kwfile_ape\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\ape.ico"
[HKCR\kwfile_AAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTA\UserChoice]
"Progid" = "kwfile_TTA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MP1\UserChoice]
"kwbak" = ""
[HKCR\kuwo\Shell\open]
"(Default)" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"
[HKCR\kwfile_WAV\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_FLAC\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\FLAC.ico"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"HelpLink" = "http://www.kuwo.cn"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP2\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_AC3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
"Progid" = "kwfile_MP3"
[HKCR\PROTOCOLS\Handler\kuwo]
"CLSID" = "{3050f3DA-98B5-11CF-BB82-00AA00BDCE0C}"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCR\kwfile_lrc\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\lrc.ico"
[HKCR\.wma]
"kwbak" = "WMAFile"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"
[HKCU\Software\Classes\.CDA]
"(Default)" = "kwfile_CDA"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"DisplayIcon" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice]
"Progid" = "kwfile_ape"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_WAV\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_M4A\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_M4A\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\M4A.ico"
[HKCR\.mp2]
"kwbak" = "mpegfile"
[HKCR\.flac]
"(Default)" = "kwfile_FLAC"
[HKCR\kuwo\Shell]
"(Default)" = ""
[HKCR\kwfile_AAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\.dks]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AC3\UserChoice]
"Progid" = "kwfile_AC3"
[HKCU\Software\Classes\kwfile_ape\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_ape\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_CDA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP1\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
[HKCU\Software\Classes\kwfile_wma\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AC3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"Publisher" = "¿áÎҿƼ¼"
[HKCU\Software\Classes\.MP2]
"(Default)" = "kwfile_MP2"
[HKCR\kwfile_ape\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_CDA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP1\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"NoModify" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_M4A\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_CDA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kuwo]
"URL Protocol" = ""
[HKCR\kwfile_AC3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\.AC3]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTA\UserChoice]
"kwbak" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Classes\.M4A]
"(Default)" = "kwfile_M4A"
[HKCU\Software\Classes\.MP3]
"kwbak" = ""
[HKCR\kwfile_OGG\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_TTA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"Contact" = "¿áÎҿƼ¼£¨±±¾©£©ÃÂøÂç¼¼ÊõÓÃÂÃÂÞ¹«Ë¾"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKCR\.mp1]
"(Default)" = "kwfile_MP1"
[HKCU\Software\Classes\kwfile_MP2\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_ape\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_ape\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\Directory\shell\kwopen]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_TTA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\.ape]
"(Default)" = "kwfile_ape"
[HKCR\kwfile_WAV\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_wma\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_M4A\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_FLAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Classes\kwfile_MP3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_FLAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_lrcx\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks]
"Progid" = "kwfile_dks"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice]
"kwbak" = ""
[HKCR\kwfile_MP3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_TTA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\.OGG]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_OGG\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_MP1\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_FLAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_MP3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_AC3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_AAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav]
"kwbak" = ""
[HKCR\.mp3\OpenWithList\KwMusic.exe]
"(Default)" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"Readme" = "%Program Files%\kuwo\kuwomusic\readme.txt"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"
[HKCR\kuwo\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe,0"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_MP1\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCR\.wma]
"(Default)" = "kwfile_wma"
[HKCU\Software\Classes\.AAC]
"(Default)" = "kwfile_AAC"
[HKCU\Software\Classes\kwfile_MP3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\kwfile_MP2\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\.TTA]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_MP2\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_M4A\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_MP1\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_WAV\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"UninstallString" = "%Program Files%\kuwo\kuwomusic\uninstall.exe"
[HKCU\Software\Classes\kwfile_M4A\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_FLAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]
"Progid" = "kwfile_M4A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP2\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Classes\kwfile_FLAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_WAV\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\.mp3]
"(Default)" = "kwfile_MP3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3]
"Progid" = "kwfile_MP3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx]
"kwbak" = ""
[HKCR\.ogg]
"kwbak" = ""
[HKCU\Software\Classes\.WMA]
"(Default)" = "kwfile_wma"
[HKCR\kwfile_wma\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp1]
"Progid" = "kwfile_MP1"
[HKCR\kwfile_MP2\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AC3\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice]
"Progid" = "kwfile_AAC"
[HKCR\.wav]
"kwbak" = "soundrec"
[HKCR\kwfile_dks\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\dks.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.OGG\UserChoice]
"Progid" = "kwfile_OGG"
[HKCU\Software\Microsoft\Internet Explorer\Styles]
"MaxScriptStatements" = "4294967295"
[HKCR\kwfile_TTA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"
[HKCU\Software\Classes\.WAV]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]
"Progid" = "kwfile_FLAC"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]
"kwbak" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"URLInfoAbout" = "http://www.kuwo.cn"
[HKCR\kwfile_TTA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCR\kwfile_CDA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CDA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_OGG\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_OGG\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\OGG.ico"
[HKCU\Software\Classes\kwfile_OGG\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_CDA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.mp3]
"kwbak" = "mp3file"
[HKCU\Software\Classes\.MP1]
"(Default)" = "kwfile_MP1"
[HKCR\kwfile_wma\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\wma.ico"
[HKCR\kwfile_MP3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"DisplayName" = "¿áÎÒÒôÀÖ 2014"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"
[HKCU\Software\Classes\kwfile_M4A\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKCR\kwfile_AC3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
"Progid" = "kwfile_wma"
[HKCU\Software\Classes\.MP2]
"kwbak" = ""
[HKCR\kwfile_AAC\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\AAC.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_MP3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav]
"Progid" = "kwfile_WAV"
[HKCR\kwfile_MP2\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_WAV\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\Directory\shell\kwopen\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \dir %1"
[HKCU\Software\Classes\kwfile_wma\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_AC3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\.lrc]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_MP3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\.cda]
"(Default)" = "kwfile_CDA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc]
"Progid" = "kwfile_lrc"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_wma\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\Directory\shell\kwplaylist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_ape\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks\UserChoice]
"Progid" = "kwfile_dks"
[HKCR\kwfile_WAV\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\WAV.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\UserChoice]
"Progid" = "kwfile_lrc"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%System%]
"netsh.exe" = "Network Command Shell"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP1\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\kwfile_wma\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_CDA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_OGG\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg]
"kwbak" = ""
[HKCR\kwfile_wma\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CDA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_WAV\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"DisplayVersion" = "7.7.0.1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AC3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CDA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\kwfile_OGG\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCR\.dks]
"kwbak" = ""
[HKCR\.mp1]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\.lrcx]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_FLAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_WAV\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_AC3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_OGG\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\kwfile_OGG\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\.lrc]
"kwbak" = ""
[HKCU\Software\Classes\.MP1]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_AAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kuwo\Shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_ape\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3]
"kwbak" = ""
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
[HKCR\kwfile_ape\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4A\UserChoice]
"Progid" = "kwfile_M4A"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
"Progid" = "kwfile_WAV"
[HKCR\.wav]
"(Default)" = "kwfile_WAV"
[HKCR\.aac]
"(Default)" = "kwfile_AAC"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"VersionMinor" = "7.7.0.1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta]
"Progid" = "kwfile_TTA"
[HKCU\Software\Classes\kwfile_TTA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_wma\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_FLAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_M4A\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_AAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx]
"Progid" = "kwfile_lrcx"
[HKCR\kwfile_MP1\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_M4A\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\SOFTWARE\Classes\kuwo\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe,0"
[HKCR\kwfile_FLAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.m4a]
"(Default)" = "kwfile_M4A"
[HKCR\.mp2]
"(Default)" = "kwfile_MP2"
[HKCR\kwfile_MP2\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_TTA\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\TTA.ico"
[HKCR\.lrc]
"(Default)" = "kwfile_lrc"
[HKCR\kwfile_TTA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_AAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKCU\Software\Classes\kwfile_CDA\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.ac3]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_MP1\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\MP1.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_CDA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_AC3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3]
"Progid" = "kwfile_AC3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_wma\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\kwfile_M4A\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"NoRepair" = "0"
[HKCU\Software\Classes\.OGG]
"(Default)" = "kwfile_OGG"
[HKCR\kwfile_CDA\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\CDA.ico"
[HKCU\Software\Classes\.APE]
"kwbak" = ""
[HKCU\Software\Classes\kwfile_TTA\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\.m4a]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3]
"kwbak" = ""
[HKCR\.tta]
"(Default)" = "kwfile_TTA"
[HKCR\kwfile_lrc\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\UserChoice]
"Progid" = "kwfile_CDA"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"InstallLocation" = "%Program Files%\kuwo\kuwomusic"
[HKCU\Software\Classes\.TTA]
"(Default)" = "kwfile_TTA"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_WAV\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AC3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg]
"Progid" = "kwfile_OGG"
[HKCU\Software\Classes\.WMA]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M4A\UserChoice]
"kwbak" = ""
[HKCU\Software\Classes\.dks]
"(Default)" = "kwfile_dks"
[HKCU\Software\Classes\kwfile_MP1\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_OGG\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP2\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP1\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_ape\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\kwfile_ape\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_FLAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\.cda]
"kwbak" = "CDAFile"
[HKCR\kuwo]
"(Default)" = "URL:kuwo Protocol"
[HKCU\Software\Classes\.FLAC]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Classes\.lrcx]
"(Default)" = "kwfile_lrcx"
[HKCR\kwfile_MP2\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"URLUpdateInfo" = "http://www.kuwo.cn"
[HKCR\kwfile_FLAC\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsmE.tmp\KwMusicNsis.dll,"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLAC\UserChoice]
"Progid" = "kwfile_FLAC"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]
"kwbak" = ""
[HKCR\.dks]
"(Default)" = "kwfile_dks"
[HKCR\kwfile_MP1\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.wma\OpenWithList\KwMusic.exe]
"(Default)" = ""
[HKCU\Software\Classes\kwfile_CDA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_M4A\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\kwfile_TTA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\.tta]
"kwbak" = ""
[HKCR\kwfile_lrcx\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\lrcx.ico"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
"Progid" = "kwfile_MP2"
[HKCR\.lrcx]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrcx\UserChoice]
"Progid" = "kwfile_lrcx"
[HKCU\Software\Classes\kwfile_MP2\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.aac]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_wma\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_TTA\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_AC3\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\AC3.ico"
[HKCR\kwfile_MP1\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"VersionMajor" = "7.7.0.1"
[HKCR\kwfile_M4A\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_OGG\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\.AAC]
"kwbak" = ""
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3B 53 F5 48 A0 73 9E 6A FB 2A 29 8F 05 E7 10 9A"
[HKCR\kwfile_AAC\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_M4A\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp1]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma]
"Progid" = "kwfile_wma"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"BuildTime" = "2014/7/29"
[HKCR\kwfile_ape\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCR\kwfile_MP3\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\MP3.ico"
[HKCU\Software\Classes\.FLAC]
"(Default)" = "kwfile_FLAC"
[HKCR\.flac]
"kwbak" = ""
[HKCU\Software\Classes\.MP3]
"(Default)" = "kwfile_MP3"
[HKCR\kwfile_wma\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\.lrcx]
"(Default)" = "kwfile_lrcx"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Classes\kwfile_WAV\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCR\kwfile_FLAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape]
"Progid" = "kwfile_ape"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_OGG\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCR\kwfile_MP2\DefaultIcon]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\res\icons\MP2.ico"
[HKCU\Software\Classes\kwfile_OGG\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\.CDA]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_TTA\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\.M4A]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_ape\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Classes\.APE]
"(Default)" = "kwfile_ape"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac]
"Progid" = "kwfile_AAC"
[HKCU\Software\Classes\kwfile_AC3\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\kwfile_WAV\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP3\shell\playlist]
"(Default)" = "¼ÓÈë ¿áÎÒÒôÀÖ ²¥·ÅÃÂñÃÂ"
[HKCR\.ape]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dks\UserChoice]
"kwbak" = ""
[HKCR\.ac3]
"(Default)" = "kwfile_AC3"
[HKCU\Software\Classes\kwfile_wma\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKCU\Software\Classes\.WAV]
"(Default)" = "kwfile_WAV"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]
"Progid" = "kwfile_MP2"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.FLAC\UserChoice]
"kwbak" = ""
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_AC3\shell\openkw\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
[HKCU\Software\Classes\kwfile_MP3\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_WAV\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\kwfile_AAC\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\.lrc]
"(Default)" = "kwfile_lrc"
[HKCU\Software\Classes\kwfile_FLAC\shell\openkw]
"(Default)" = "Óà ¿áÎÒÒôÀÖ ²¥·Å"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KwMusic7]
"Copyright" = "¿áÎÒ¹«Ë¾±£ÃÂôËùÓÃÂȨÀû¡£"
[HKCR\Directory\shell\kwplaylist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \dirlist %1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\kwfile_MP2\shell\playlist\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe \list %1"
[HKCU\Software\Classes\.AC3]
"(Default)" = "kwfile_AC3"
[HKCR\kwfile_dks\shell\open\command]
"(Default)" = "%Program Files%\kuwo\kuwomusic\KwMusic.exe %1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
"IntranetName" = "1"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
"UNCAsIntranet" = "1"
To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kwmusic" = "%Program Files%\kuwo\kuwomusic\Kwmusic.exe /autorun"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process KwWallpaper.exe:2876 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1E 00 00 00 01 00 00 00 00 00 00 00"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "42 8D AE 48 68 D2 56 24 1E 9A C3 80 03 31 A0 E6"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process KwService.exe:1620 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D6 14 61 B1 FD 2C D2 DE 3E 53 F8 51 6D 4A 17 6B"
[HKCU\Software\Microsoft\Windows Media\WMSDK\General]
"ComputerName" = "XP8"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows Media\WMSDK\General]
"VolumeSerialNumber" = "2829482533"
"UniqueID" = "{29D64238-C698-4D3C-8D8D-0285C5746621}"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\MediaPlayer\Player\Settings]
"Client ID"
The process taskkill.exe:832 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "56 90 76 20 67 7A 49 96 DF 51 30 9B 51 61 9B 20"
The process taskkill.exe:1968 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8B D0 5C C3 9D 6B F6 4F B6 B5 49 FD 66 5F 5A E0"
The process taskkill.exe:1852 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0A 32 28 8F 68 C2 CE 8A 29 FC 87 7D 78 69 38 48"
The process taskkill.exe:2012 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4C AD 8A 2C 42 33 29 F0 5D A5 8F 91 73 FD 49 9D"
The process taskkill.exe:424 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C1 D2 97 10 4D 30 BC 96 FD 2F 77 4B E9 5E 9C 87"
The process taskkill.exe:1368 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "10 21 D9 87 73 68 16 60 59 80 75 0D 10 D6 6F F9"
The process taskkill.exe:912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D6 FD 42 57 A4 89 E4 5B 2A 59 87 19 51 5F E7 3D"
The process SoftWare SVC.exe:1096 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4A 7B D3 7D A3 65 27 FC 69 03 FD 30 81 9B D1 37"
[HKLM\SOFTWARE\Microsoft\SoftWare Reporting\ect]
"MKW" = "2016-09-12 18:55:20"
The process SoftWare SVC.exe:136 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F2 FC 4A EB AD 1F 8E C2 05 25 48 55 0B 9F 40 81"
The process regsvr32.exe:1324 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AA 78 20 25 86 7C 89 5D 9E 0F 4B 56 98 4D 79 4C"
The process regsvr32.exe:1556 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "3E 1F DF C9 F2 01 5B F6 84 DB 7B C0 4D B4 0E 22"
The process regsvr32.exe:1612 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "AB 99 DF 49 AA 6D 64 E4 4C B0 0A 31 08 1E 7D C2"
[HKCR\CLSID\{F23B1F18-CB1A-47ED-A1FE-B60494A626D0}\InprocServer32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\CoreAVC0.ax"
[HKCR\CLSID\{345CAA15-4F12-4A28-AFE9-383625563A83}\InprocServer32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\CoreAVC0.ax"
[HKCR\CLSID\{F23B1F18-CB1A-47ED-A1FE-B60494A626D0}\InprocServer32]
"ThreadingModel" = "Both"
[HKCR\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{09571A4B-F1FE-4C60-9760-DE6D310C7C31}]
"FriendlyName" = "CoreAVC Video Decoder"
[HKCR\CLSID\{F23B1F18-CB1A-47ED-A1FE-B60494A626D0}]
"(Default)" = "CoreAVC Video Decoder Info"
[HKCR\CLSID\{345CAA15-4F12-4A28-AFE9-383625563A83}]
"(Default)" = "CoreAVC Video Decoder About"
[HKCR\CLSID\{09571A4B-F1FE-4C60-9760-DE6D310C7C31}\InprocServer32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\CoreAVC0.ax"
"ThreadingModel" = "Both"
[HKCR\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{09571A4B-F1FE-4C60-9760-DE6D310C7C31}]
"CLSID" = "{09571A4B-F1FE-4C60-9760-DE6D310C7C31}"
[HKCR\CLSID\{09571A4B-F1FE-4C60-9760-DE6D310C7C31}]
"(Default)" = "CoreAVC Video Decoder"
[HKCR\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{09571A4B-F1FE-4C60-9760-DE6D310C7C31}]
"FilterData" = "02 00 00 00 00 02 60 00 02 00 00 00 00 00 00 00"
[HKCR\CLSID\{345CAA15-4F12-4A28-AFE9-383625563A83}\InprocServer32]
"ThreadingModel" = "Both"
The process regsvr32.exe:648 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "DC 46 A4 7E AE 04 89 67 F7 39 77 00 1E 05 EF F6"
[HKCR\DirectShow\MediaObjects\2eeb4adf-4578-4d10-bca7-bb955f56320a]
"(Default)" = "WMAudio Decoder DMO"
[HKCR\CLSID\{2eeb4adf-4578-4d10-bca7-bb955f56320a}\InprocServer32]
"ThreadingModel" = "Both"
[HKCR\DirectShow\MediaObjects\2eeb4adf-4578-4d10-bca7-bb955f56320a]
"InputTypes" = "61 75 64 73 00 00 10 00 80 00 00 AA 00 38 9B 71"
"OutputTypes" = "61 75 64 73 00 00 10 00 80 00 00 AA 00 38 9B 71"
[HKCR\CLSID\{2eeb4adf-4578-4d10-bca7-bb955f56320a}\InprocServer32]
"(Default)" = "%System%\wmadmod.dll"
[HKCR\CLSID\{2eeb4adf-4578-4d10-bca7-bb955f56320a}]
"(Default)" = "WMAudio Decoder DMO"
"MERIT" = "8390656"
The Trojan deletes the following registry key(s):
[HKCR\DirectShow\MediaObjects\2eeb4adf-4578-4d10-bca7-bb955f56320a]
The process regsvr32.exe:364 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "66 D7 80 B0 F0 51 76 1A D6 70 35 CB 53 78 A5 0C"
The process regsvr32.exe:516 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\MiscStatus]
"(Default)" = "0"
[HKCR\Interface\{516DC048-6382-47A9-B7E9-29ACBADBF8B9}\TypeLib]
"Version" = "1.0"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}]
"AppID" = "{E590F520-E7BB-47E7-A98E-CFCF7B521E28}"
[HKCR\TypeLib\{5278E16A-7CEB-4F5B-9A2F-A3720F337996}\1.0]
"(Default)" = "KuwoQuickLaunch 1.0 ÀàÃÂÿâ"
[HKCR\KuwoQuickLaunch.QuickLaunch.1\CLSID]
"(Default)" = "{40D1050C-16B1-445B-80CE-5E172A92A851}"
[HKCR\KuwoQuickLaunch.QuickLaunch\CurVer]
"(Default)" = "KuwoQuickLaunch.QuickLaunch.1"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\MiscStatus\1]
"(Default)" = "132497"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\ToolboxBitmap32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll, 102"
[HKCR\Interface\{20809876-E366-4F04-B47F-EBDC96D36A27}]
"(Default)" = "IQuickLaunch"
[HKCR\KuwoQuickLaunch.QuickLaunch.1]
"(Default)" = "QuickLaunch Class"
[HKCR\KuwoQuickLaunch.QuickLaunch]
"(Default)" = "QuickLaunch Class"
[HKCR\AppID\Kuwo.QuickLaunch.DLL]
"AppID" = "{E590F520-E7BB-47E7-A98E-CFCF7B521E28}"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}]
"(Default)" = "QuickLaunch Class"
[HKCR\Interface\{516DC048-6382-47A9-B7E9-29ACBADBF8B9}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\Version]
"(Default)" = "1.0"
[HKCR\KuwoQuickLaunch.QuickLaunch\CLSID]
"(Default)" = "{40D1050C-16B1-445B-80CE-5E172A92A851}"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\TypeLib]
"(Default)" = "{5278E16A-7CEB-4F5B-9A2F-A3720F337996}"
[HKCR\Interface\{516DC048-6382-47A9-B7E9-29ACBADBF8B9}\TypeLib]
"(Default)" = "{5278E16A-7CEB-4F5B-9A2F-A3720F337996}"
[HKCR\TypeLib\{5278E16A-7CEB-4F5B-9A2F-A3720F337996}\1.0\FLAGS]
"(Default)" = "0"
[HKCR\Interface\{20809876-E366-4F04-B47F-EBDC96D36A27}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{516DC048-6382-47A9-B7E9-29ACBADBF8B9}]
"(Default)" = "_IQuickLaunchEvents"
[HKCR\TypeLib\{5278E16A-7CEB-4F5B-9A2F-A3720F337996}\1.0\HELPDIR]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\ProgID]
"(Default)" = "KuwoQuickLaunch.QuickLaunch.1"
[HKCR\Interface\{20809876-E366-4F04-B47F-EBDC96D36A27}\TypeLib]
"Version" = "1.0"
[HKCR\TypeLib\{5278E16A-7CEB-4F5B-9A2F-A3720F337996}\1.0\0\win32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CB 66 B7 57 4E 59 A7 32 D1 E4 79 7C CD 81 1F 06"
[HKCR\Interface\{20809876-E366-4F04-B47F-EBDC96D36A27}\TypeLib]
"(Default)" = "{5278E16A-7CEB-4F5B-9A2F-A3720F337996}"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\InprocServer32]
"(Default)" = "%Program Files%\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll"
[HKCR\Interface\{20809876-E366-4F04-B47F-EBDC96D36A27}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"
[HKCR\Interface\{516DC048-6382-47A9-B7E9-29ACBADBF8B9}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\InprocServer32]
"ThreadingModel" = "Apartment"
[HKCR\CLSID\{40D1050C-16B1-445B-80CE-5E172A92A851}\VersionIndependentProgID]
"(Default)" = "KuwoQuickLaunch.QuickLaunch"
[HKCR\AppID\{E590F520-E7BB-47E7-A98E-CFCF7B521E28}]
"(Default)" = "KuwoQuickLaunch"
The process regsvr32.exe:912 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "1F 9E 03 48 3A 9E D0 E4 26 2F E2 B5 BA DB A5 52"
The process KwLnkTipWnd.exe:3024 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "93 F3 00 CE 03 B4 79 CE 9F C8 1F 55 86 D4 43 61"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
The process BrowserSafe.exe:1712 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E3 04 AC 6B A3 13 68 FB 27 11 B4 84 50 AF BF 49"
The process kwAdb.exe:3376 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4F 38 78 E6 50 4F EE 3F 6B 22 42 CE 6E E7 0E B1"
The process kwAdb.exe:3448 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A3 57 56 8A C7 6E 5B 1D FC C2 48 37 3F 54 FA 63"
The process KwMusic.exe:1292 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1C 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\kuwo\kuwomusic\bin]
"WriteMbox.exe" = "WriteMbox"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "65 51 8F E7 8B 91 3D 60 1F 48 4F 83 0E 6C A8 D8"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The Trojan disables automatic startup of the application by deleting the following autorun value:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KwService"
The process Netsh.exe:340 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"BitNames" = " NAP_TRACE_BASE NAP_TRACE_NETSH"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"Guid" = "710adbf0-ce88-40b4-a50d-231ada6593f0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"Guid" = "b0278a28-76f1-4e15-b1df-14b209a12613"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "54 AC 73 6E 63 07 CA B8 FC 93 7C 53 2D 01 04 B4"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\kuwo\kuwomusic\bin]
"KwService.exe" = "%Program Files%\kuwo\kuwomusic\bin\KwService.exe:*:Enabled:¿áÎÒºËÃÂÄ·þÎñ"
The process Netsh.exe:1252 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"Guid" = "8aefce96-4618-42ff-a057-3536aa78233e"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"MaxFileSize" = "1048576"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"ConsoleTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"BitNames" = " NAP_TRACE_BASE NAP_TRACE_NETSH"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableFileTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh\Napmontr]
"Guid" = "710adbf0-ce88-40b4-a50d-231ada6593f0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"Active" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappprxy]
"LogSessionName" = "stdout"
"ControlFlags" = "1"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"Guid" = "b0278a28-76f1-4e15-b1df-14b209a12613"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\eappcfg\traceIdentifier]
"Guid" = "5f31090b-d990-4e91-b16d-46121d0255aa"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"EnableConsoleTracing" = "0"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "77 10 B7 7A 23 7F AA FE 7B 62 D3 5E 31 61 4B 0A"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileDirectory" = "%windir%\tracing"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Tracing\FWCFG]
"FileTracingMask" = "4294901760"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\NAP\Netsh]
"LogSessionName" = "stdout"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\qagent\traceIdentifier]
"BitNames" = " Error Unusual Info Debug"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\QUtil]
"ControlFlags" = "1"
Adds a rule to the firewall Windows which allows any network activity:
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\%Program Files%\kuwo\kuwomusic\bin]
"KwMusic.exe" = "%Program Files%\kuwo\kuwomusic\bin\KwMusic.exe:*:Enabled:¿áÎÒÒôÀÖ"
The process IESandBox.exe:968 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1D 00 00 00 01 00 00 00 00 00 00 00"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"@xpsp3res.dll,-20001" = "Diagnose Connection Problems..."
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"Name" = "IESandBox.exe"
[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"
[HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication]
"ID" = "1405931047"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "66 57 82 9C B2 39 6A 5A F4 E5 D4 35 D7 91 34 4E"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"
The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"
The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:
"ProxyBypass" = "1"
Proxy settings are disabled:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"
The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"
The Trojan deletes the following value(s) in system registry:
[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"
The process KwConfig.exe:412 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:
[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "89 7D 28 7D EE 9A 16 84 EB 12 3C 9C ED 3C A4 F8"
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"
Dropped PE files
| MD5 | File path |
|---|---|
| 32db45f842b824c88585ccd0c48174e8 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\KWMUSIC\DownloadUpdate.exe |
| 8b646e2f2af04d1937f507be2911c679 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsmE.tmp\KwMusicNsis.dll |
| 7ed256ddcf5033826b8befee618e60e5 | c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsmE.tmp\nsisSlideshowx.dll |
| 4ccaaf82e1c8e5350a5d66d7870275bb | c:\Program Files\9ENetwork\9EPostService.exe |
| 94b89d412b47e80dd03af9e6b2e8f486 | c:\Program Files\kuwo\kuwomusic\KwMusic.exe |
| 85a72cac299e909b422020cb350bf79d | c:\Program Files\kuwo\kuwomusic\KwMusicSetup.exe |
| fa79ab24700979b5783f13b989f6a1b3 | c:\Program Files\kuwo\kuwomusic\Uninstall.exe |
| e0682c6a3d2da735d25243dac3ec0b9a | c:\Program Files\kuwo\kuwomusic\bin\AdbWinApi.dll |
| 3912b6c12d864e12456833091bc74ae8 | c:\Program Files\kuwo\kuwomusic\bin\AdbWinUsbApi.dll |
| 3fbf61a8c6256fef4673d08f69fbbb23 | c:\Program Files\kuwo\kuwomusic\bin\CKuwoPlayer.dll |
| a9ab1efb964010413165f1b58a0794a6 | c:\Program Files\kuwo\kuwomusic\bin\CWmpPlayer.dll |
| 75d137762c16c0790ddc2c5c844d788a | c:\Program Files\kuwo\kuwomusic\bin\CoreAVC0.ax |
| 4938946adb8f31c2781c3396c4c2d232 | c:\Program Files\kuwo\kuwomusic\bin\DshowPlayer.dll |
| 897f2cff2eaddfb73bf6266dc247c50f | c:\Program Files\kuwo\kuwomusic\bin\DuiLib.dll |
| 525888de20bb58203ca30bec7972d7e4 | c:\Program Files\kuwo\kuwomusic\bin\DumpReport.exe |
| b90eb5ec0ce4cc2957da016b97cdb555 | c:\Program Files\kuwo\kuwomusic\bin\Encode.exe |
| d0b5e214e1a723cd6ae56fa98a99759b | c:\Program Files\kuwo\kuwomusic\bin\IEProxy.dll |
| 81270ef060287eace1fc82f67c18f6eb | c:\Program Files\kuwo\kuwomusic\bin\IESandBox.exe |
| e0e0f4597784627ac938e5e96598804c | c:\Program Files\kuwo\kuwomusic\bin\KWUpdate.exe |
| 10e0df16d26d3b2fbfe484bfb43f2991 | c:\Program Files\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll |
| 553d0ecd2fa70b80ddb1b3032ca5fdbd | c:\Program Files\kuwo\kuwomusic\bin\KuwoSyncMobile.dll |
| b38287d1d9ea105caf02a2285e60fcd3 | c:\Program Files\kuwo\kuwomusic\bin\KwConfig.exe |
| e4037991729505a0519486499d17c24a | c:\Program Files\kuwo\kuwomusic\bin\KwDPGame.exe |
| 87b652dd41fe0e1c400f67cb32c13233 | c:\Program Files\kuwo\kuwomusic\bin\KwDataDef.dll |
| 580eae152888f35fd1da0445b8a15151 | c:\Program Files\kuwo\kuwomusic\bin\KwHttp.dll |
| 7fd4319529c2c987d42c762a4515690b | c:\Program Files\kuwo\kuwomusic\bin\KwHttpRequestMgr.dll |
| bcbc6482bb2bc4d52d5052ac22ac83d9 | c:\Program Files\kuwo\kuwomusic\bin\KwInfos.exe |
| 53e84f698fc6ee4ede63e36358dd42a8 | c:\Program Files\kuwo\kuwomusic\bin\KwLib.dll |
| 5d121d62c3411a24ff8d9bee64491d42 | c:\Program Files\kuwo\kuwomusic\bin\KwLnkTipWnd.exe |
| 3a459991d2ca99e5b187a040696b28ea | c:\Program Files\kuwo\kuwomusic\bin\KwLog.dll |
| d105d204982e39b0c56d2a932ee8bfb6 | c:\Program Files\kuwo\kuwomusic\bin\KwMV.dll |
| 9251b80e4b3b305f6f3e065fa0267d5a | c:\Program Files\kuwo\kuwomusic\bin\KwModAndroidMgr.dll |
| 9ab3d665c5a878b024a43f048702978e | c:\Program Files\kuwo\kuwomusic\bin\KwModAppStore.dll |
| ecae364b70579b5daf6338127ac23857 | c:\Program Files\kuwo\kuwomusic\bin\KwModConfig.dll |
| b9fa58a8ac2a4e5e21574e30ca408d33 | c:\Program Files\kuwo\kuwomusic\bin\KwModDownload.dll |
| ef2628007b79f050a6b13e1d1d7780ed | c:\Program Files\kuwo\kuwomusic\bin\KwModGameEntry.dll |
| 5cc869ba592026ebe9b93901aad2528f | c:\Program Files\kuwo\kuwomusic\bin\KwModLocalMusic.dll |
| f346c827b22ea79fde1453445507ac5c | c:\Program Files\kuwo\kuwomusic\bin\KwModLyric.dll |
| 9f7c594b6d2d986cdfaacc4cfc0c4d95 | c:\Program Files\kuwo\kuwomusic\bin\KwModLyricShow.dll |
| f7c914ca7f50f180699b3569b48ed6a9 | c:\Program Files\kuwo\kuwomusic\bin\KwModPlaylist.dll |
| c22eb31719a28b71a519d22785726a54 | c:\Program Files\kuwo\kuwomusic\bin\KwModSkinManage.dll |
| 5211a460e0e7d2b7239900d839a6c4dc | c:\Program Files\kuwo\kuwomusic\bin\KwModSynList.dll |
| 480f704fd385d48612209e437e86bc98 | c:\Program Files\kuwo\kuwomusic\bin\KwModUpdateWeb.dll |
| 99264cdfc4bd8aee3519e6b9104be3cb | c:\Program Files\kuwo\kuwomusic\bin\KwMusic.exe |
| 40d74b7bd3d6417c1fa1ac60e27add1e | c:\Program Files\kuwo\kuwomusic\bin\KwMusicCore.dll |
| 73ccc2e39a9889e3e6e4cb88a2f4ca1d | c:\Program Files\kuwo\kuwomusic\bin\KwRecoSong.dll |
| 2aa20a507adec5ada7732f39d45fb41c | c:\Program Files\kuwo\kuwomusic\bin\KwService.exe |
| 821fb0cf3b762cc49d0944afd095a2e5 | c:\Program Files\kuwo\kuwomusic\bin\KwServiceProxy.dll |
| 7d2cb33853db9da35aafe139fe9bc4db | c:\Program Files\kuwo\kuwomusic\bin\KwSongCache.dll |
| 75afb89b0454f8f4d79e6cbe343c5fbd | c:\Program Files\kuwo\kuwomusic\bin\KwTagLib.dll |
| 38f819308d742cacea18090b1a000563 | c:\Program Files\kuwo\kuwomusic\bin\KwUpdate.dll |
| 6f5d60812e510169e4e7bab996f46703 | c:\Program Files\kuwo\kuwomusic\bin\KwWallpaper.exe |
| ac63d81d4d1023c9d2baf377cb4b2b12 | c:\Program Files\kuwo\kuwomusic\bin\MatroskaSplitter.ax |
| bf1373a048889b0649430245e143ab72 | c:\Program Files\kuwo\kuwomusic\bin\MediaInfo.dll |
| 8b0c464c5a0c2d8065955f7e0db6b904 | c:\Program Files\kuwo\kuwomusic\bin\MpaDecFilter.ax |
| bf7a19c5a5b73f385edadbb6ad0303bd | c:\Program Files\kuwo\kuwomusic\bin\PlayerCore.dll |
| dfc467f7e462680df9f42de87e34e5a1 | c:\Program Files\kuwo\kuwomusic\bin\ReconEngine.exe |
| 06f27320f3db7bbb0a80d435b6464a1d | c:\Program Files\kuwo\kuwomusic\bin\ShellDl.exe |
| a8be0591914a90124a5d8867e1ad2bba | c:\Program Files\kuwo\kuwomusic\bin\UIAndroidUsbDevice.dll |
| d42521c5b2057e5a0b2d576bd18aab35 | c:\Program Files\kuwo\kuwomusic\bin\UIAvMgr.dll |
| ac74290d78c1faa2546e492fac4f8af8 | c:\Program Files\kuwo\kuwomusic\bin\UIDeskLyric.dll |
| 3e9be093bb9d40a42fd8900a69ca9f35 | c:\Program Files\kuwo\kuwomusic\bin\UIDownload.dll |
| 8e5cbfdcfe23a474532012a96a209ec7 | c:\Program Files\kuwo\kuwomusic\bin\UIMiniPanel.dll |
| d211f87eee5d71a68d7ad316abd3593e | c:\Program Files\kuwo\kuwomusic\bin\UIMusicTree.dll |
| f45473afba206a88464179e52bfe65f0 | c:\Program Files\kuwo\kuwomusic\bin\UINowPlaying.dll |
| de0f0a1e86154edb857c44eeae4b10eb | c:\Program Files\kuwo\kuwomusic\bin\UIPlayControl.dll |
| 01aa3895773065e84da7bbf544a70c7d | c:\Program Files\kuwo\kuwomusic\bin\UIPlaylistPanel.dll |
| fd33f4d7b0e7150df07fa84ec0f7399e | c:\Program Files\kuwo\kuwomusic\bin\UIPopupWnd.dll |
| 5ae9684c60d374533813a9bd80e0336f | c:\Program Files\kuwo\kuwomusic\bin\UIVIPMan.dll |
| 36b9d0b4f16f5e81cb3829a91cf0e350 | c:\Program Files\kuwo\kuwomusic\bin\Vol.dll |
| ee2a64938afa832a683cc9d928fd2c5a | c:\Program Files\kuwo\kuwomusic\bin\Win7Trait.dll |
| c79494477fed60814c368554a155f695 | c:\Program Files\kuwo\kuwomusic\bin\WriteMbox.exe |
| 03124a57847248f5a5fcbeaf5c9169e5 | c:\Program Files\kuwo\kuwomusic\bin\Zlib.dll |
| c54f4d6b8ab98983bba488939b98ce36 | c:\Program Files\kuwo\kuwomusic\bin\ccenter.dll |
| fba8899e062afba9ad7b357e8f067b21 | c:\Program Files\kuwo\kuwomusic\bin\desk_compositor_x64.dll |
| 5a71a1c7261302d4808c6b35f16a1f3b | c:\Program Files\kuwo\kuwomusic\bin\desk_compositor_x86.dll |
| 73becb26ded198f3f46d0ea42e5a2fba | c:\Program Files\kuwo\kuwomusic\bin\kwAdb.exe |
| 501ed5939878b19e4532fe41896c5e45 | c:\Program Files\kuwo\kuwomusic\bin\lidx.dll |
| 6de5c66e434a9c1729575763d891c6c2 | c:\Program Files\kuwo\kuwomusic\bin\msvcp90.dll |
| e7d91d008fe76423962b91c43c88e4eb | c:\Program Files\kuwo\kuwomusic\bin\msvcr90.dll |
| 5d7d8e98ce2fe70717954e9e641f49b3 | c:\Program Files\kuwo\kuwomusic\bin\pd.dll |
| 89ccade6ce9ba82a888b9a5ea120de33 | c:\Program Files\kuwo\kuwomusic\bin\plugin\Eq_Kweq.dll |
| 4b6f96a834b9e5e126f087aebb64906a | c:\Program Files\kuwo\kuwomusic\bin\plugin\In_Wma.dll |
| ede606112ec71d4f9c321713a6fe93f6 | c:\Program Files\kuwo\kuwomusic\bin\plugin\in_APE.dll |
| 58663949dcf8d3047aea0a5a66de66cb | c:\Program Files\kuwo\kuwomusic\bin\plugin\in_ac3.dll |
| f5327e03ab9e42e276178233ac28e5f3 | c:\Program Files\kuwo\kuwomusic\bin\plugin\in_mp4.dll |
| f9fbfe6544e1cce537b4304f23e34c1a | c:\Program Files\kuwo\kuwomusic\bin\plugin\in_mpg123.dll |
| 6de5c66e434a9c1729575763d891c6c2 | c:\Program Files\kuwo\kuwomusic\bin\plugin\msvcp90.dll |
| e7d91d008fe76423962b91c43c88e4eb | c:\Program Files\kuwo\kuwomusic\bin\plugin\msvcr90.dll |
| a6f1974a8498bee6259f97884cfad1d2 | c:\Program Files\kuwo\kuwomusic\bin\plugin\out_kw_ds.dll |
| a8114e4adcd6063cd6315fa142231b0f | c:\Program Files\kuwo\kuwomusic\bin\runshelldraw_x64.exe |
| afbaaf74fd230258b0dc2b5859a94746 | c:\Program Files\kuwo\kuwomusic\bin\runshelldraw_x86.exe |
| 6de5c66e434a9c1729575763d891c6c2 | c:\Program Files\kuwo\kuwomusic\msvcp90.dll |
| e7d91d008fe76423962b91c43c88e4eb | c:\Program Files\kuwo\kuwomusic\msvcr90.dll |
| c6f81d853b683684aacb6601a9e815fd | c:\WINDOWS\SoftWare SVC.exe |
| d833d5b4eaa59a95ee31a9a0b3b4dbe2 | c:\WINDOWS\system32\drivers\BrowserSafe.sys |
HOSTS file anomalies
No changes have been detected.
Rootkit activity
Using the driver "%System%\drivers\BrowserSafe.sys" the Trojan controls operations with a system registry by installing the registry notifier.
Propagation
VersionInfo
No information is available.
PE Sections
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Section MD5 |
|---|---|---|---|---|---|
| .text | 4096 | 23096 | 23552 | 4.43854 | 092e164daa50385128d3c5b319373035 |
| .rdata | 28672 | 4496 | 4608 | 3.59023 | 4e7f519777030dd2f0ea0d2092babed3 |
| .data | 36864 | 110424 | 1024 | 3.20088 | f6d93c048bf148a2daee8a6b0505e38b |
| .ndata | 147456 | 57344 | 0 | 0 | d41d8cd98f00b204e9800998ecf8427e |
| .rsrc | 204800 | 239352 | 239616 | 3.94408 | 83ded819ff30ab2f95865f3ae4f4fc7c |
Dropped from:
Downloaded by:
Similar by SSDeep:
Similar by Lavasoft Polymorphic Checker:
URLs
| URL | IP |
|---|---|
| hxxp://log.kuwo.cn/music.yl | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=1&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&kid= | |
| hxxp://static.verycdn.net/today_recommend/tool_new/126.gif | |
| hxxp://static.verycdn.net/today_recommend/tool_new/123.gif | |
| hxxp://static.verycdn.net/today_recommend/tool_new/185.gif | |
| hxxp://static.verycdn.net/today_recommend/tool_new/confall.txt | |
| hxxp://static.verycdn.net/today_recommend/tool_new/167.gif | |
| hxxp://xnop027.tlgslb.com/pagesig/vipMbox_new/7.7.0/sig.htm | |
| hxxp://xnop027.tlgslb.com/pagesig/vipMbox_new/7.7.0/vipMbox_new.zip | |
| hxxp://uh1.kuwo.cn/uc/s?m=19;QklFQAoAAEYQFwgzHB8KQQ0ASQ== | |
| hxxp://pg1.kuwo.cn/regsvr.auth?104&EAFYSgQODR1JVVUvW1ZbY0BRU1hPBwodSVVVXFlfXhBJVVVcWV9eEElVVFxPGQNBGlhVXFksXBlMJlxYX1tIVhwXWCE8PCdjJlJLW0dfQBEmNVc4WEkdUhpYDhkeADFKFFFXVUcKFkU= | |
| hxxp://uh1.kuwo.cn/uc/s?m=37;QigwPyAsMRdXUktcR14xcEsxVEBJQyllLTouOzomIGcmNioqPQ== | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18239&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18892&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-19625&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4459&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4953&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4954&size=20&offset=0&kid= | |
| hxxp://gnop013.tlgslb.com/mbox_data/dataset/Radio/radio.zip | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4996&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6003&size=20&offset=0&kid= | |
| hxxp://kuwo.verycdn.net/mbox_data/no_copyright_new.zip | |
| hxxp://xnop027.tlgslb.com/star/MusicTopToday/js01/topmusic/recIndex2014.data?newtime=0.9586088943741652 | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6007&size=20&offset=0&kid= | |
| hxxp://pg2.kuwo.cn/q.k?op=query&cont=tree&node=1&level=3&maxchd=50&fmt=json&kset=default&src=mbox&callback=showQuKuTreeFromInternet&time=20168122056&version=MUSIC_7.7.0.1_P2T1&uid=0&kid=6424671 | |
| hxxp://pg1.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6001&size=20&offset=0&kid= | |
| hxxp://pg1.kuwo.cn/pic.web?type=startup_pic&date=20160912&duration=7&from=pc&wallpaper=1&width=1276&height=846&ver=MUSIC_7.7.0.1_P2T1&id=6424671&uid=&name= | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473055636025.jpg | |
| hxxp://static.verycdn.net/today_recommend/setCookie2013.html | |
| hxxp://pg1.kuwo.cn/vip/zadan/index2.html?13118169329556000021010 | |
| hxxp://pg1.kuwo.cn/vip/zadan/index1.html?13118169329556000015247 | |
| hxxp://static.verycdn.net/star/upload/2/2/1473609345490_.jpg | |
| hxxp://static.verycdn.net/star/upload/7/7/1473434658615_.jpg | |
| hxxp://static.verycdn.net/star/upload/6/6/1472207043078_.jpg | |
| hxxp://static.verycdn.net/star/upload/9/9/1462442619481_.jpg | |
| hxxp://static.verycdn.net/star/upload/11/11/1473390677979_.jpg | |
| hxxp://pg1.kuwo.cn/vip/zadan/js/swfobject.js | |
| hxxp://static.verycdn.net/star/upload/14/14/1472798447454_.jpg | |
| hxxp://static.verycdn.net/star/upload/0/0/1471241513120_.jpg | |
| hxxp://static.verycdn.net/today_recommend/mbox2013/config/kuwofx.js | |
| hxxp://static.verycdn.net/star/upload/6/6/1473054658982_.jpg | |
| hxxp://static.verycdn.net/star/upload/4/4/1473213016500_.jpg | |
| hxxp://static.verycdn.net/star/upload/1/1/1473503786209_.jpg | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473320578232.jpg | |
| hxxp://pg1.kuwo.cn/vip/zadan/ShowEgg.swf?94766.17852897952 | |
| hxxp://static.verycdn.net/star/upload/6/6/1472640248934_.jpg | |
| hxxp://static.verycdn.net/star/upload/14/14/1473651505534_.jpg | |
| hxxp://static.verycdn.net/star/upload/7/7/1473572609703_.jpg | |
| hxxp://static.verycdn.net/star/upload/9/9/1473416107497_.jpg | |
| hxxp://static.verycdn.net/star/upload/15/15/1473653699055_.jpg | |
| hxxp://static.verycdn.net/star/upload/6/6/1467861701110_.jpg | |
| hxxp://pub.funshion.com/interface/mc?mcid=1245 | |
| hxxp://static.verycdn.net/star/userpl2015/10/13/1467860925171_132026710b.jpg | |
| hxxp://pg1.kuwo.cn/vip/st/GetBeatFlashUrl | |
| hxxp://static.verycdn.net/star/upload/13/13/1467861765917_.jpg | |
| hxxp://static.verycdn.net/star/upload/6/6/1453875830150_.jpg | |
| hxxp://static.verycdn.net/star/upload/0/0/1473064611280_.jpg | |
| hxxp://static.verycdn.net/star/upload/8/8/1450837723704_.jpg | |
| hxxp://webstat.kuwo.cn/kuwo/fengxing/hsy_ip_pv.jpg | |
| hxxp://static.verycdn.net/star/upload/4/4/1457596018948_.jpg | |
| hxxp://static.verycdn.net/crossdomain.xml | |
| hxxp://static.verycdn.net/star/upload/8/8/1444307264344_.jpg | |
| hxxp://static.verycdn.net/star/upload/2/2/1465184432195_.jpg | |
| hxxp://static.verycdn.net/star/upload/8/8/1424057719960_.jpg | |
| hxxp://static.verycdn.net/star/upload/0/0/1473577543328_.jpg | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473321334926.jpg | |
| hxxp://static.verycdn.net/star/upload/12/12/1376042900860_.jpg | |
| hxxp://static.verycdn.net/star/upload/11/11/1473645199771_.jpg | |
| hxxp://static.verycdn.net/star/upload/3/3/1404128033575_.swf | |
| hxxp://static.verycdn.net/star/upload/10/10/1386901161434_.jpg | |
| hxxp://static.verycdn.net/star/upload/10/10/1473645136042_.jpg | |
| hxxp://static.verycdn.net/star/upload/13/13/1376038278733_.jpg | |
| hxxp://static.verycdn.net/star/upload/13/13/1385020775085_.jpg | |
| hxxp://static.verycdn.net/star/upload/3/3/1372746952099_.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/61/56/3263549297.jpg | |
| hxxp://static.verycdn.net/star/upload/10/10/1413192688282_.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/25/41/1997281419.jpg | |
| hxxp://static.verycdn.net/star/upload/3/3/1467862157203_.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/23/85/340244866.jpg | |
| hxxp://deliver.kuwo.cn/yl_res_manage.search | |
| hxxp://static.verycdn.net/star/upload/11/11/1473639534987_.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/40/21/541440606.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/80/35/1564836158.jpg | |
| hxxp://static.verycdn.net/star/userpl2015/10/13/1470910911030_132026710b.jpg | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473516821210.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/5/95/4228075837.jpg | |
| hxxp://static.verycdn.net/star/upload/15/15/1467861880943_.jpg | |
| hxxp://pg2.kuwo.cn/f.page?op=query&uid=0&kid=6424671&cont=block&src=mbox&fmt=json&pn=0&rn=20&version=MUSIC_7.7.0.1_P2T1&ttime=20168122056 | |
| hxxp://static.verycdn.net/star/upload/9/9/1473064589545_.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/kwgg_371.js?time=20168122056 | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/kwgg_328.js?time=20168122056 | |
| hxxp://static.verycdn.net/star/upload/14/14/1456814275214_.jpg | |
| hxxp://static.verycdn.net/star/upload/2/2/1357790699490_.jpg | |
| hxxp://static.verycdn.net/star/upload/4/4/1473603310164_.jpg | |
| hxxp://static.verycdn.net/star/upload/0/0/1473603326304_.jpg | |
| hxxp://static.verycdn.net/star/upload/10/10/1473517608458_.jpg | |
| hxxp://static.verycdn.net/star/upload/13/13/1473517589485_.jpg | |
| hxxp://static.verycdn.net/star/upload/7/7/1473517310391_.jpg | |
| hxxp://static.verycdn.net/star/upload/11/11/1473645302555_.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/kwgg_328.js?time=0.7255580838426173 | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/kwgg_371.js?time=0.6817576852176765 | |
| hxxp://static.verycdn.net/star/upload/8/8/1473492812184_.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4839/index.htm?ver= | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4892/index.htm?ver= | |
| hxxp://static.verycdn.net/star/upload/15/15/1473492953071_.jpg | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473517759929.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4708/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://static.verycdn.net/star/upload/4/4/1473645059028_.jpg | |
| hxxp://static.verycdn.net/star/upload/14/14/1473492918254_.jpg | |
| hxxp://static.verycdn.net/star/upload/8/8/1473517623144_.jpg | |
| hxxp://static.verycdn.net/star/upload/12/12/1473577611660_.gif | |
| hxxp://static.verycdn.net/star/upload/12/12/1473517282076_.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5331/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4480/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473518690014.jpg | |
| hxxp://static.verycdn.net/star/upload/5/5/1473517459509_.jpg | |
| hxxp://uh1.kuwo.cn/uc/s?m=28;QigwPyAsMRdXUktcR14xcEsxVEBJQw1PFwMMCw== | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5750/index.htm?ver= | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5751/index.htm?ver= | |
| hxxp://static.verycdn.net/star/upload/9/9/1376990222297_.png | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4708/_3_1464245780569.swf | |
| hxxp://static.verycdn.net/star/upload/9/9/1371611988633_.jpg | |
| hxxp://static.verycdn.net/star/upload/3/3/1380793603683_.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5331/_2_1461809875271.swf | |
| hxxp://static.verycdn.net/star/albumcover/300/41/20/3020449513.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/41/7/2438451804.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/21/82/526441.jpg | |
| hxxp://static.verycdn.net/star/albumcover/300/33/5/1112781587.jpg | |
| hxxp://static.verycdn.net/star/upload/7/7/1444901569447_.jpg | |
| hxxp://static.verycdn.net/star/upload/14/14/1378203225934_.jpg | |
| hxxp://static.verycdn.net/star/userpl2015/10/13/1473608305185_132026710_100.jpg | |
| hxxp://static.verycdn.net/star/upload/15/15/1401091378655_.jpg | |
| hxxp://static.verycdn.net/star/upload/1/1/1473603270577_.jpg | |
| hxxp://static.verycdn.net/star/upload/11/11/1473603291211_.jpg | |
| hxxp://pg1.koowo.com/g.real?aid=html_ad_4839&ver=&type=show&cid=6424671 | |
| hxxp://static.verycdn.net/today_recommend/images/201609/1473519658028.jpg | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4162/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4480/1473242726679.swf | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4839/1473242698107.swf | |
| hxxp://static.verycdn.net/star/upload/3/3/1473517571907_.jpg | |
| hxxp://static.verycdn.net/star/upload/7/7/1473517326599_.jpg | |
| hxxp://static.verycdn.net/star/upload/4/4/1473493595908_.jpg | |
| hxxp://static.verycdn.net/star/userpl2015/69/76/1469617950004_190971769_100.jpg | |
| hxxp://pg1.kuwo.cn/searchkey/searchkey.txt | |
| hxxp://deliver.kuwo.cn/yl_res_manage.spread?uid=6424671&version=MUSIC_7.7.0.1_P2T1&source=kuwo_jm429.exe&t=618703 | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4892/_1453189156821.swf | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5750/1473056615593.swf | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv5751/1473056769752.swf | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/adv4162/_4_1464245796316.swf | |
| hxxp://static.verycdn.net/lyrics/img/kwgg/personalAd.js | |
| hxxp://js.miaozhen.com.w.kunlunle.com/c.swf | |
| hxxp://uh1.kuwo.cn/uc/s?m=48;T1FXWF9YXxs0MDYlKjBZDk5LVUJYMD4SLVRJBxwYAX8TCFFeUEELWBxJEBwNDhpF | |
| hxxp://pg1.kuwo.cn/ip_domain | |
| hxxp://img4.kwcdn.kuwo.cn/star/upload/4/4/1473213016500_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4162/_4_1464245796316.swf | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/9/9/1473416107497_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/3/3/1380793603683_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/9/9/1473064589545_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6001&size=20&offset=0&kid= | |
| hxxp://img4.sycdn.kuwo.cn/star/albumcover/300/33/5/1112781587.jpg | |
| hxxp://vip.kuwo.cn/vip/zadan/ShowEgg.swf?94766.17852897952 | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4996&size=20&offset=0&kid= | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473320578232.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/15/15/1401091378655_.jpg | |
| hxxp://fpagedata.kuwo.cn/f.page?op=query&uid=0&kid=6424671&cont=block&src=mbox&fmt=json&pn=0&rn=20&version=MUSIC_7.7.0.1_P2T1&ttime=20168122056 | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4839/1473242698107.swf | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/8/8/1450837723704_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/4/4/1457596018948_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/9/9/1376990222297_.png | |
| hxxp://img1.sycdn.kuwo.cn/star/albumcover/300/80/35/1564836158.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/albumcover/300/41/7/2438451804.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/3/3/1473517571907_.jpg | |
| hxxp://updatepage.kuwo.cn/pagesig/vipMbox_new/7.7.0/vipMbox_new.zip | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=1&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&kid= | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/0/0/1473064611280_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/13/13/1467861765917_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4953&size=20&offset=0&kid= | |
| hxxp://img1.sycdn.kuwo.cn/star/albumcover/300/5/95/4228075837.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/4/4/1473645059028_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/10/10/1413192688282_.jpg | |
| hxxp://skeylist.kuwo.cn/searchkey/searchkey.txt | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/2/2/1473609345490_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18239&size=20&offset=0&kid= | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/8/8/1473492812184_.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473518690014.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/11/11/1473645302555_.jpg | |
| hxxp://config.kuwo.cn/uc/s?m=37;QigwPyAsMRdXUktcR14xcEsxVEBJQyllLTouOzomIGcmNioqPQ== | |
| hxxp://config.kuwo.cn/uc/s?m=28;QigwPyAsMRdXUktcR14xcEsxVEBJQw1PFwMMCw== | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/kwgg_328.js?time=20168122056 | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473516821210.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/kwgg_371.js?time=0.6817576852176765 | |
| hxxp://img3.sycdn.kuwo.cn/star/albumcover/300/23/85/340244866.jpg | |
| hxxp://vip.kuwo.cn/vip/zadan/js/swfobject.js | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/15/15/1473492953071_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/14/14/1378203225934_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4954&size=20&offset=0&kid= | |
| hxxp://artistpicserver.kuwo.cn/pic.web?type=startup_pic&date=20160912&duration=7&from=pc&wallpaper=1&width=1276&height=846&ver=MUSIC_7.7.0.1_P2T1&id=6424671&uid=&name= | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/3/3/1372746952099_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/11/11/1473639534987_.jpg | |
| hxxp://g.koowo.com/g.real?aid=html_ad_4839&ver=&type=show&cid=6424671 | |
| hxxp://topmusic.kuwo.cn/today_recommend/tool_new/185.gif | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/12/12/1376042900860_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4459&size=20&offset=0&kid= | |
| hxxp://img1.sycdn.kuwo.cn/star/upload/7/7/1473517310391_.jpg | |
| hxxp://down.koowo.com/mbox_data/dataset/Radio/radio.zip | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/2/2/1465184432195_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/8/8/1424057719960_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4480/1473242726679.swf | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4480/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://topmusic.kuwo.cn/today_recommend/tool_new/confall.txt | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/7/7/1473517326599_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/13/13/1385020775085_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6003&size=20&offset=0&kid= | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/7/7/1444901569447_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4839/index.htm?ver= | |
| hxxp://img2.kwcdn.kuwo.cn/star/upload/3/3/1404128033575_.swf | |
| hxxp://config.kuwo.cn/uc/s?m=48;T1FXWF9YXxs0MDYlKjBZDk5LVUJYMD4SLVRJBxwYAX8TCFFeUEELWBxJEBwNDhpF | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/personalAd.js | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/6/6/1467861701110_.jpg | |
| hxxp://img1.sycdn.kuwo.cn/star/upload/6/6/1453875830150_.jpg | |
| hxxp://vip.kuwo.cn/vip/st/GetBeatFlashUrl | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/12/12/1473577611660_.gif | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473519658028.jpg | |
| hxxp://img4.kwcdn.kuwo.cn/star/upload/6/6/1473054658982_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/1/1/1473503786209_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/kwgg_371.js?time=20168122056 | |
| hxxp://img4.sycdn.kuwo.cn/star/userpl2015/10/13/1470910911030_132026710b.jpg | |
| hxxp://img1.kwcdn.kuwo.cn/star/upload/6/6/1472640248934_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/12/12/1473517282076_.jpg | |
| hxxp://updatepage.kuwo.cn/pagesig/vipMbox_new/7.7.0/sig.htm | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-19625&size=20&offset=0&kid= | |
| hxxp://topmusic.kuwo.cn/today_recommend/mbox2013/config/kuwofx.js | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/10/10/1473517608458_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/0/0/1473577543328_.jpg | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6007&size=20&offset=0&kid= | |
| hxxp://img4.sycdn.kuwo.cn/star/userpl2015/69/76/1469617950004_190971769_100.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv5331/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://mc.funshion.com/interface/mc?mcid=1245 | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/9/9/1371611988633_.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/tool_new/126.gif | |
| hxxp://topmusic.kuwo.cn/today_recommend/tool_new/123.gif | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/7/7/1473434658615_.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473055636025.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/4/4/1473603310164_.jpg | |
| hxxp://img1.sycdn.kuwo.cn/star/upload/0/0/1473603326304_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/13/13/1376038278733_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/15/15/1473653699055_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/10/10/1386901161434_.jpg | |
| hxxp://config.kuwo.cn/uc/s?m=19;QklFQAoAAEYQFwgzHB8KQQ0ASQ== | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv5751/index.htm?ver= | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/8/8/1473517623144_.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473321334926.jpg | |
| hxxp://img2.kwcdn.kuwo.cn/crossdomain.xml | |
| hxxp://img1.sycdn.kuwo.cn/star/upload/9/9/1462442619481_.jpg | |
| hxxp://img2.kwcdn.kuwo.cn/star/upload/14/14/1472798447454_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/8/8/1444307264344_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/2/2/1357790699490_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/kwgg_328.js?time=0.7255580838426173 | |
| hxxp://img3.sycdn.kuwo.cn/star/albumcover/300/40/21/541440606.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/userpl2015/10/13/1467860925171_132026710b.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/14/14/1473492918254_.jpg | |
| hxxp://qukudata.kuwo.cn/q.k?op=query&cont=tree&node=1&level=3&maxchd=50&fmt=json&kset=default&src=mbox&callback=showQuKuTreeFromInternet&time=20168122056&version=MUSIC_7.7.0.1_P2T1&uid=0&kid=6424671 | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv5750/index.htm?ver= | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4708/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/11/11/1473603291211_.jpg | |
| hxxp://js.miaozhen.com/c.swf | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/15/15/1467861880943_.jpg | |
| hxxp://js01.kuwo.cn/star/MusicTopToday/js01/topmusic/recIndex2014.data?newtime=0.9586088943741652 | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/10/10/1473645136042_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/7/7/1473572609703_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4892/index.htm?ver= | |
| hxxp://img4.sycdn.kuwo.cn/star/userpl2015/10/13/1473608305185_132026710_100.jpg | |
| hxxp://img2.kwcdn.kuwo.cn/star/upload/0/0/1471241513120_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/albumcover/300/41/20/3020449513.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4162/index.htm?ver=MUSIC_7.7.0.1_P2T1 | |
| hxxp://ipdomainserver.kuwo.cn/ip_domain | |
| hxxp://vip.kuwo.cn/vip/zadan/index1.html?13118169329556000015247 | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv5750/1473056615593.swf | |
| hxxp://reg.kuwo.cn/regsvr.auth?104&EAFYSgQODR1JVVUvW1ZbY0BRU1hPBwodSVVVXFlfXhBJVVVcWV9eEElVVFxPGQNBGlhVXFksXBlMJlxYX1tIVhwXWCE8PCdjJlJLW0dfQBEmNVc4WEkdUhpYDhkeADFKFFFXVUcKFkU= | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4892/_1453189156821.swf | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/11/11/1473390677979_.jpg | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv4708/_3_1464245780569.swf | |
| hxxp://wa.kuwo.cn/lyrics/img/kwgg/adv5331/_2_1461809875271.swf | |
| hxxp://img3.sycdn.kuwo.cn/star/albumcover/300/25/41/1997281419.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/6/6/1472207043078_.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/tool_new/167.gif | |
| hxxp://gxh2.kuwo.cn/newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18892&size=20&offset=0&kid= | |
| hxxp://down.kuwo.cn/mbox_data/no_copyright_new.zip | |
| hxxp://img2.sycdn.kuwo.cn/star/albumcover/300/61/56/3263549297.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/14/14/1473651505534_.jpg | |
| hxxp://vip.kuwo.cn/vip/zadan/index2.html?13118169329556000021010 | |
| hxxp://img1.sycdn.kuwo.cn/star/upload/3/3/1467862157203_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/14/14/1456814275214_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/5/5/1473517459509_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/albumcover/300/21/82/526441.jpg | |
| hxxp://topmusic.kuwo.cn/today_recommend/setCookie2013.html | |
| hxxp://topmusic.kuwo.cn/today_recommend/images/201609/1473517759929.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/4/4/1473493595908_.jpg | |
| hxxp://img2.sycdn.kuwo.cn/star/upload/11/11/1473645199771_.jpg | |
| hxxp://img3.sycdn.kuwo.cn/star/upload/13/13/1473517589485_.jpg | |
| hxxp://img4.sycdn.kuwo.cn/star/upload/1/1/1473603270577_.jpg | |
| uh2.kuwo.cn |
IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)
ET POLICY User-Agent (NSIS_Inetc (Mozilla)) - Sometimes used by hostile installers
ET POLICY HTTP Request on Unusual Port Possibly Hostile
ET POLICY Outdated Windows Flash Version IE
ET POLICY Unsupported/Fake Windows NT Version 5.0
Traffic
GET /today_recommend/tool_new/confall.txt HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: topmusic.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc: &id:&reqsrc:CGetToolConf::UpdateConfigFile
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:53:55 GMT
Content-Type: text/plain
Content-Length: 624
Last-Modified: Tue, 07 Jun 2016 12:27:40 GMT
ETag: "5756bdbc-270"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:01:31 GMT
Cache-Control: max-age=900
Vary: Accept-Encoding
Age: 83
Powered-By-VeryCDN: HIT from cuc-ta-1-2-c1112, HIT from utn-jn-1-2-c1132
Connection: close[MUSICTOOL]..toolcount=11..[TOOL1]..id=14..sig1=..sig2=..name=........
..[TOOL2]..id=167..sig1=3754979047..sig2=3941480309..name=............
[TOOL3]..id=185..sig1=12978532..sig2=658577042..name=..........[TOOL4]
..id=100..sig1=1946912705..sig2=4029858148..name=....K....[TOOL5]..id=
12..sig1=..sig2=..name=VIP......[TOOL6]..id=165..sig1=1834598554..sig2
=2756411536..name=..........[TOOL7]..id=13..sig1=..sig2=..name=.......
.[TOOL8]..id=11..sig1=..sig2=..name=..........[TOOL9]..id=104..sig1=32
20088749..sig2=2555964265..name=..............[TOOL10]..id=333..sig1=.
.sig2=..name=..........<!--htm finished-->....
GET /mbox_data/no_copyright_new.zip HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: down.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/zip
Content-Length: 146
Last-Modified: Thu, 13 May 2010 06:12:42 GMT
Accept-Ranges: bytes
Cache-Control: s-maxage=86400
Date: Mon, 12 Sep 2016 15:44:37 GMT
Age: 648
Powered-By-VeryCDN: HIT from utn-sy-1-3-c1321, MISS from utn-sy-1-2-c1391
Connection: closePK........{q.<................no_copyright.txt1.2.3.4.5.6.7.8.PK...
.......{q.<...................... .......no_copyright.txtPK........
..>...>.......
GET /ip_domain HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ipdomainserver.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:56:01 GMT
Content-Type: text/javascript
Content-Length: 56
Connection: keep-alive
Set-cookie: ad_dist=;domain=kuwo.cn
Cache-Control: no-cache
Vary: Accept-Encodingvar _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}HTTP/1.1 200 O
K..Server: nginx..Date: Mon, 12 Sep 2016 15:56:01 GMT..Content-Type: t
ext/javascript..Content-Length: 56..Connection: keep-alive..Set-cookie
: ad_dist=;domain=kuwo.cn..Cache-Control: no-cache..Vary: Accept-Encod
ing..var _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}..
..
GET /ip_domain HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ipdomainserver.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0; ad_dist=
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:56:05 GMT
Content-Type: text/javascript
Content-Length: 56
Connection: keep-alive
Set-cookie: ad_dist=;domain=kuwo.cn
Cache-Control: no-cache
Vary: Accept-Encodingvar _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}HTTP/1.1 200 O
K..Server: nginx..Date: Mon, 12 Sep 2016 15:56:05 GMT..Content-Type: t
ext/javascript..Content-Length: 56..Connection: keep-alive..Set-cookie
: ad_dist=;domain=kuwo.cn..Cache-Control: no-cache..Vary: Accept-Encod
ing..var _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}..
GET /today_recommend/tool_new/185.gif HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:16:18 GMT
Content-Type: image/gif
Content-Length: 4744
Last-Modified: Thu, 31 Jan 2013 06:42:11 GMT
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 11:13:12 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Etag: "510a1243-1288"
Age: 84630
Powered-By-VeryCDN: HIT from cuc-bj-1-1-c1112, HIT from utn-jn-1-2-c1132
Connection: close.PNG........IHDR...(...(.............tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:DACDFD485B9E11E29A01A040
AAE9EC44" xmpMM:DocumentID="xmp.did:DACDFD495B9E11E29A01A040AAE9EC44"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:DACDFD465B9E11E29A
01A040AAE9EC44" stRef:documentID="xmp.did:DACDFD475B9E11E29A01A040AAE9
EC44"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>.x......IDATx......`....>x$.......5..{.X
8.....!a.g..-.4.<....nl..E~...f:.D...Z...f....8.g...Z..M.....}.....
.VB./\.GR_...c......fd..........-aca`ceaX.-.......N`e..K.....a.....l.}
....10I.0d~.....N.C....."[email protected]....!... ......}......
..F&.v........... C..0..4..9........o..`x....0..3..o..&.g`.veX~^.a..j.
.S.._.J.X8.....1.......*..7.......... !...H~1.,.)...~....5C..4.#...6..
..W.......@......(.......i.uW.",..Q.`1..I......M.@.(.....Y...F..Ypya.A
...s..-...p................8...N[.Ai.S..F...uw...q......k...x.6)JbM...
.8........l..f.D.H.:=,.Q.... .....H..D.>Qq..w..Kf..\..[Y.}./...<<< skipped >>>
GET /q.k?op=query&cont=tree&node=1&level=3&maxchd=50&fmt=json&kset=default&src=mbox&callback=showQuKuTreeFromInternet&time=20168122056&version=MUSIC_7.7.0.1_P2T1&uid=0&kid=6424671 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: qukudata.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:26 GMT
Content-Type: text/javascript; charset=utf-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Mon, 12 Sep 2016 15:55:18 GMT
Vary: Accept-Encoding1eee..............yS[Y./...Sy#.....3....n......WfgwtT(Ai.-$_..E=...`.&
lt;....6.13.....M..A..Wx..[.GB.G2r.y..T......g........_......D.U.Z....
..V}.._._.....:._..us...]...>.......[M..Z.....t ..I..}.......kj.a.!
M.......v..H...U..2\..#.g.#9d0\.M....?....).o".V.(.....|6Q.$I9y.....s7
............Agj...r.g}T[.._...`.C..._ ........T..CM.?...'......B?."(.&
h.a....$.0.J.9.I..e:..P`.".'..(..........=yx...F)..9^.,...k.f...g.....
^.P....GVyY..A.y9....G~..?..}...$.."_.k............ .,....Z..X..!..,..
.2.'../.......O....=.q..i..^...8b...^6.w;....O.y.j.cW2...~gbx.\..O|;..
..z./..~e%-C............7.k..<....9..T`....t......&..Oa..... ......
.......v....j...4_...dM..]0TU.?...D.y'.{.%.....9s.2w..!.K,.....#.....*
*.z.{.k............z......ms..f.wz 1....5.....D...y.l.1l....B........e
...Q/r.DB......f.8."......L.K.....g.......F._e...g4.d/..H.b.....\&..g.
.z._.g.$.5.m.M..`..._^.........|....k ..Jz..oC......2...)..y~!.Gh.2L..
4.<.Jq$[.f.=.......k..Z....R..0...2.,.<.....o.xF......OxyR.s|RUV
e..n.n.oV3.4}..v..n..{SX..*sSH........]..Yy.......!/.....Q.$...Z.= ~2.
2u..3~.*.$K..zF.c.~..4..n.%z...yv.f..3...dE..Y..V...f..?.%..R&|....r.S
.sg......(....J%s.s.r.I'-....uMV..I.$..j...(ZA.M`3Y.M.|.=..z..O.....gM
.py_H.....R<hE...."..*........0..Xu....s.\..X....j|.[... .......$d.
....4.O.=............)...E.4I.I"....j...7.&..H.-}f....N.5>c.O.@6..!
.k...."...g.l..gu....k6...i...?O..e...c.b.y.j........... n.;.....8.a..
....s~IDQW4.f0omv.<..tM.A.&..E...&.)..:b.-8.=.....{4..j"(a...1w...^
"...HL.5....%.]..'....0.b.'s. )...5.c.!..3.5..:/...:.Qd^.T..n..;..<<< skipped >>>
GET /lyrics/img/kwgg/adv4708/index.htm?ver=MUSIC_7.7.0.1_P2T1 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:33:13 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4837
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "137172e-12e5-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:43:25 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1346
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:300px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="300">..<param nam
e="movie" value="_3_1464245780569.swf" /><param name="allowScrip
tAccess" value="always"/><param name='wmode' value='opaque' />
;<param name="quality" value="high" /><embed src="_3_14642457
80569.swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/g<<< skipped >>>
GET /lyrics/img/kwgg/adv5331/index.htm?ver=MUSIC_7.7.0.1_P2T1 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:28:28 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4838
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "135d522-12e6-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:46:36 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1628
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:300px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="300">..<param nam
e="movie" value="_2_1461809875271.swf" /><param name="allowScrip
tAccess" value="always"/><param name='wmode' value='opaque' />
;<param name="quality" value="high" /><embed src="_2_14618098
75271.swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/g<<< skipped >>>
GET /lyrics/img/kwgg/adv4480/index.htm?ver=MUSIC_7.7.0.1_P2T1 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:54:39 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4850
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "1371719-12f2-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:03:40 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 59
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:300px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="300">..<param nam
e="movie" value="1473242726679.swf" /><param name="allowScriptAc
cess" value="always"/><param name='wmode' value='opaque' />&l
t;param name="quality" value="high" /><embed src="1473242726679.
swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/getf<<< skipped >>>
GET /lyrics/img/kwgg/adv4839/index.htm?ver= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:01 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4850
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "14501c1-12f2-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:07:43 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 46
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:287px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="287">..<param nam
e="movie" value="1473242698107.swf" /><param name="allowScriptAc
cess" value="always"/><param name='wmode' value='opaque' />&l
t;param name="quality" value="high" /><embed src="1473242698107.
swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/getf<<< skipped >>>
GET /lyrics/img/kwgg/adv4892/index.htm?ver= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:44:06 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4833
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "13ac167-12e1-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:13:57 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 770
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:287px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="287">..<param nam
e="movie" value="_1453189156821.swf" /><param name="allowScriptA
ccess" value="always"/><param name='wmode' value='opaque' />&
lt;param name="quality" value="high" /><embed src="_145318915682
1.swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/ge<<< skipped >>>
GET /lyrics/img/kwgg/adv5750/index.htm?ver= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:32:52 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 5084
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "13607ef-13dc-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:44:09 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1366
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:287px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="287">..<param nam
e="movie" value="1473056615593.swf" /><param name="allowScriptAc
cess" value="always"/><param name='wmode' value='opaque' />&l
t;param name="quality" value="high" /><embed src="1473056615593.
swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/getf<<< skipped >>>
GET /lyrics/img/kwgg/adv5751/index.htm?ver= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:36:45 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 5084
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "1364206-13dc-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:04:42 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1437
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:287px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="287">..<param nam
e="movie" value="1473056769752.swf" /><param name="allowScriptAc
cess" value="always"/><param name='wmode' value='opaque' />&l
t;param name="quality" value="high" /><embed src="1473056769752.
swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/getf<<< skipped >>>
GET /lyrics/img/kwgg/adv4839/index.htm?ver= HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:01 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4850
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "14501c1-12f2-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:07:43 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 48
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:287px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="287">..<param nam
e="movie" value="1473242698107.swf" /><param name="allowScriptAc
cess" value="always"/><param name='wmode' value='opaque' />&l
t;param name="quality" value="high" /><embed src="1473242698107.
swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/go/getf<<< skipped >>>
GET /lyrics/img/kwgg/adv4708/_3_1464245780569.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4708/index.htm?ver=MUSIC_7.7.0.1_P2T1
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:45:06 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 28818
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "1371703-7092-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:58:57 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 634
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS..u..x....T.].....KqB.....N...;......R.X.......R..[).xi............
>...H.X........s....u...D..0..r:..........qp.1....!.=|e.....~~^2...
.......>........D.ED..(.}.=.l..=|..... @.}.}\..\<=X....y........
!..... `..i.(`..............G$...h......tWP.[...n............o...b$...
j.....*&%,'.?G...#..OADHX._X._D.&,!#"-#*. $%#$..b.....B..l.l.l..,./$./
".........O..I..pO........W....ON..{.....E .....3tt...}a.^.......>.
.....<.(TF.......Q...gB...AFDYBXIMTY."".*!,,....*.&)-....$...F.s..h
.O{.....?i..?h.!._4=..g......J. .H..A.E.$U.....%. .J..J..Rjbb.........
.%..A.....S....u..)y........ .._.$.....%._4...../...y.wl..E......O..%.
`.o.........`/.....j...T.....^....a..`....bo.7P0......-.6......!'....2
%..6A.V..........4H............%.'..g~.....i.i..00.....{...g..{...w...
.....|..,. ........(..O..X..........`..bba...h..0.0........p...L.,l.\.
.9.>%..JXD.]......$.bh.....(sh.6. ....r.C5:.yx.........o ..........
;.'...b`aaab....b.I......... L.T.2.....fW.....h..........).....{[email protected]
.E.x......Pb}[M..\..Y.f.k.7o.4]......]... ......IvM...p.z-.2`o...<k
.......-..V';].S...}k.[..K'$ry..LU.U..K.s..A.&...m......{..F#...D)4..M
.<..|.....^..%8:\L e0..1..A..C..(G^..Sr.h...E..zA.]:..9..........M.
.J.J...A...3.=..fr#....S.x......g...o.b..........YN..$.IV.]9w.iPw..)nU
l.&....5....$/;.R.M......f.....AOk\.7.3...3"..x.u..$.Z...". ....F...D.
I3..5.uz.....b........v<q.u].........}q..O5w..:...0. ;>.._......
.k0[..|{...Wu.a.......*NT-..S....K.oV2.......z...1-5N=.........D.H..u.
i...82...B..........1..`..oe.c. ..Z....j...4m..i....9.y`.........e<<< skipped >>>
POST /uc/s?m=19;QklFQAoAAEYQFwgzHB8KQQ0ASQ== HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 0
Host: config.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc: &id:&reqsrc:isCancelUpdate
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:09 GMT
Content-Type: text/html
Connection: close
Content-Length: 4MQA9..
GET /star/upload/2/2/1473609345490_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:08:34 GMT
Content-Type: image/jpeg
Content-Length: 37763
Last-Modified: Sun, 11 Sep 2016 15:48:00 GMT
Expires: Sat, 10 Dec 2016 16:00:36 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 85615
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......Z......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:ac5004e7-cc07-114
d-bf38-ee9fb50a262c" xmpMM:DocumentID="xmp.did:E87530AE766111E6BB67C18
D5C1BAB8D" xmpMM:InstanceID="xmp.iid:E87530AD766111E6BB67C18D5C1BAB8D"
xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"> <xmpMM:Der
ivedFrom stRef:instanceID="xmp.iid:96a3cde7-30e6-0244-bfe3-40939ab5556
2" stRef:documentID="xmp.did:ac5004e7-cc07-114d-bf38-ee9fb50a262c"/>
; </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xp
acket end="r"?>....Adobe.d.........................................
......................................................................
......................................................................
...............................................................!..1..A
".Q.a2.qB#...3$...Rb%.C......XY.T.&Vv.7w8........................!1..A
Qaq......."...2R....Bb.r..#S..3.4T...$.............?.......&.......1y.
..'...^5....w..bC.r.4W.!.....x$.X...R.P....i....o...C.c..`.O.t.N.;[p..
8Dfy}.....|l....V/...|\[email protected]...#....^n<<< skipped >>>
GET /star/upload/1/1/1473503786209_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 13:09:07 GMT
Content-Type: image/jpeg
Content-Length: 42397
Last-Modified: Sat, 10 Sep 2016 10:28:39 GMT
Expires: Fri, 09 Dec 2016 13:09:06 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 182783
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......F......Adobe.d............
......................................................................
......................................................................
......................................................................
...................!1A"..Qa2q.B....R#...b.r....3$4..CSDcs.%...T.U&5...
...................!1..AQ.aq.".....2...B#...R.br......3C.............?
.....N.k.O....... .S:}.|.........5....4...Ef..b;.~.X...d.!P(...v.&.q.g
9.!..)-.X\..$9|..m..{:Fk4...J6...Wn. ....... .nC..%',.......;\al.;X...
^.H..g*...&.P...AzW..IZc...3#mQE_....R^HH.h. #......k.B.kCj.\.>?...
i....1_....~.q.e....PZA.B...U.*..E.........X...n/b.]......>...L.s.~
..R.D...h..>?/.R.e..V.X...>.N%e>wSQ..Q.0rX.4...u......xj!dv..
[email protected]=......D....U.<..-`...C.'.H.&.j.G..f...
V......p..f.o..l;.....KK.......,l..x........q........R.....~..?=T..e..
.I..Vb..v.[.\m...x...sk./..7~%...D `d.......T0.j.2..z.=...E..:.2.D.Hk.
..O..<xC....g....N...K\.n.....H.{.......s/.....4]:./...Ad...J.G.C..
..^.|)%..G".55%....... ................f..c..BcC(n.U.-...v....M..Q....
..#....E!X.h.Ua....*8OY.Q.Sh.O.j)-......-&.,.....Z}.R.Q..czy.bOZ...tM#
.........D.}.?x.h...r....\.Y`...XDI...W....TJ}I.n...e.......g.......#.
4.~&......Vs...Wv.*.X.w,...U..h....Y*p.......BK.*.C".....][email protected]..
.U.Z....R...../.. .Q...V..=u0...E.6..<!2.*...V..eW-Z....N.:f.P.b...
[.......6.....D_.....".7..S...o._*~..\[email protected]....&...~.(.....Z........
s...e.f.%....M.<Z.......W...[o......".u1.G..1.,..@.^...L.W.~...<<< skipped >>>
GET /star/upload/9/9/1473416107497_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Sep 2016 15:40:56 GMT
Content-Type: image/jpeg
Content-Length: 8704
Last-Modified: Fri, 09 Sep 2016 10:07:22 GMT
Expires: Thu, 08 Dec 2016 15:40:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 260074
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive.....fExif..MM.*...............`...........`..........................
.....................................(...........1...........2........
...i..........................'.......'.VVV.meitu.com.2016:09:05 01:01
:50...........0221.......................x...........x................
.............N...........V.(.....................~...................H
.......H.......C......................................................
..............C.......................................................
..................d...................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?..R.......b..P..
.1@.(........b..P...K1.@.'..|.........../.v1x../(...$S...." ..>....
.k...q...<....*T..S.._...b..._...$..Vr}..Q.H....K.....(.....5s....E
...O.?k(Mi.z.Li....am}g:\.\...4g*..!.. ..M;3.MI].).(......(..........b
....=.k...o.h..._.d....U.r.H..=.\ok..i..4.........g........8... .dP...
......W...G.TW.....1..*N.Z..9..............._...wy{.]TH.<q...g...&g
t;.gkq..*MA.M|....H.Sw....V}A.k...o.E...e..../..E.........Ww!x.`......
.<%....V....S..C....B...(......(....9-/........&..-..6...{t..$A..'.
.P.kG9....0T..nij.k.......<]..^..i..T.h..M9yLE..n....:..iR.J.N[<<< skipped >>>
GET /star/userpl2015/10/13/1467860925171_132026710b.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 25 Aug 2016 04:07:55 GMT
Content-Type: image/jpeg
Content-Length: 35446
Last-Modified: Thu, 07 Jul 2016 03:03:08 GMT
Expires: Wed, 23 Nov 2016 04:00:26 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1597656
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....C..............................................
......................C...............................................
........................,.,.."........................................
...c.........................!1A....Qaq....$.....#4....5DT&CU.."26ER
detBFSVcfu.....bv..r..............................................I...
....................!1.AQ..aq......."2...$B.....45Rbr....#%....&3E....
..........?..]........& ...l.k..y..T....=(.o.;,...6....C|.]...........
.0>J8.......BRo.<G.&.......*.R.~F.W}....Ea..H.:P-I....m;.M.....w
..m.G...R.;.d>Eq..%...u.x....._*.".&.....D.h....1......J...,Ex....,
..B;....T_i.Y...b...F..y.Jf....*...2.q..[...|.....A..w......!H|..I..,.
..,k......]..k....H...._...mA0..L.&....z.....P.,...@;.V..*lX.$&.......
....V?..m.j......yd.i.6...y......."....$......R..3.M9z.....j]q......].
..Ey.|...F.].*..z...kn.a(y......Y..................&.....hV...J..*j..Z
.G).z.h..u.V.,.IR...!.<T.y.......j.....b).....O...L`...A3y .....V;0
. *...9v...aYd.-..4..(.G...PC....J......E`.."...h.(...8..7*...m.......
......L...".X<.AD.....a....l.....G...[ v.p...o>..PW?....M^.v.R..
......0....U`.cx...3.r..6...f..aI........Wj..AR.....Ej........u/>.}
Iz..|[email protected]..`.9.>=.....)r.......-..H..{{l.....[p..t
.#N]4........IfRF......5N............o.<.,`.Q....A_t{........ Z}..(
.:...... .:.%5)....Cn..1.....9.nez.....%.z......G. .#.p....1.....5....
..j..u..:*......n.z.M..O-{..\g..h&........._n._...oz..r7..,.G^q.....j.
v......:..o..L.]..\.U.h..........vn....l.....f.T....[......SO>.<<< skipped >>>
GET /star/upload/8/8/1450837723704_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 22 Aug 2016 17:17:02 GMT
Content-Type: image/jpeg
Content-Length: 13686
Last-Modified: Wed, 23 Dec 2015 02:28:13 GMT
Expires: Sun, 20 Nov 2016 17:17:02 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1809509
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
[email protected]....;{o..6..-
|o..{xb..z.i.qA.,i.(..A.....].....k.)....5.r.I.]7c.<"..iC...a.....}
.n..w....'....0....>%. .o.....U..6.5,.P.....*.%J....I........=l..B0
.R.P...n...u_e5%.j..B...>4.x...69A.........T....P...V...v.....M.][k
d.n....(.o.T.......Z.{~V....r...V....n./.....t.WU..;m....%d...8r......
.q.]l..;.a..Vt.I....;. 5..m.........>1....S....w!....9...I...H..p..
......7.&.{J......{5kw..B.j....{h.B....o.G..............GR...|u.=_K...
Mf....^^hz..LE..y9..S4O4KbN.`Y......y.Dk..:.b..)F.H...|..VI].~ky..#-..
. Q...E.../z/I)YF...V.Wkt.P....5...M....P]..G4..i.[. ...:J,%tyXF.^H%.H
..W.&.7.......k..R.F.W..[......e..J....M.B.q....(.....].. x.\...n..S`.
...W ..d..bI.y Q...'...o.....z9..m5...o6.i..c.M...\#..W..l.c...k.&....
..o..{2...UC..C*..'..1.. ...19......<.1X...a...1m. *.$.}.V......,.&
lt;..)e.....I..Z.N.........../....K.'.Q..K..g.&.X.h.mW..])x...b..A<<< skipped >>>
GET /star/upload/8/8/1424057719960_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 20 Aug 2016 08:41:33 GMT
Content-Type: image/jpeg
Content-Length: 4329
Last-Modified: Mon, 16 Feb 2015 03:35:25 GMT
Expires: Fri, 18 Nov 2016 08:41:32 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 2013238
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....d.d......Ducky.......<......Adobe.d.................
......................................................................
..........................................................d.d.........
......................................................................
..........!1.AQa".q.2...BRb$..r.#3Cc.....4D......................!.1.A
.".Qaq.2..............?..2d>$9..|J..~-...]).uC...!.n.Kh.#...D.....P
,.....m..v..7R......%G....C.`....G....d{r$HZ.G.e%....._2.~.....MQ....u
y.$A.$2.V.jQ.Dz....N.].....pr......,$H!=Dv...b....C.4....5....;....>
;..WE..4.....f....5\...............>5}'...<.........{7..{N#!kU..
...O.~...u<d9..W...M).P!4..U.o<YH0.[e.[R$.....2.5...k..YI.w..h,E
....a.....&K...Oa.p.8.`.U..k7.....MM.CL.'>T...e..j..&.B.......Z.F..
.7..j.2#..#.zCz. q(m&.Q.......y.7~..{..rc....... v..V..],...V.<..%.
Y........9..y.J.j.x...#t..8O.>...p....$.,...,...-U..B...ZS....,.I..
W.c.ph.%kYY...X..].d..#C..0.....uA(KC.Y5.T.1.Kj.9..S..._p\..R\..(S|kT.
[email protected][......{...x:a.#:..*E9.y.; .._.=.^.o..x.....P....U..Q@..
..W.I.]..."-.u.1..c}B.....U.KC..|8bUj<..6...o.....T$.....\....R.. a
;Y....a%kX...W.o..i8Wa..F.",..........2o..^:.... >Ru.........a...QF
q.fEi.W...1.-....f&...Kq...Q.....0.......\..v.9j..B.5....5)#.8p.).[%..
..Ke....i..kZ..I........].&..2...]....#J.B...6.y....G....c ..po..e..Y.
\X..].G..*..F.6...S..,..*....2.qY_}g8 P.*>..L......S/Hh.c.....&...(
.... `B Z.|1.U....s.......q.Mm...8...$....N#p..{8/7i.....C...4.5../h..
...a..g4......@.`6.k.%.H....8S..ES...8e_^D.;p.N...:(k....|.Q..|.t.<<< skipped >>>
GET /star/upload/11/11/1473645199771_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 02:00:10 GMT
Content-Type: image/jpeg
Content-Length: 20520
Last-Modified: Mon, 12 Sep 2016 01:45:25 GMT
Expires: Sun, 11 Dec 2016 01:52:11 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 50122
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
.................................................................D....
......................................................................
..............!1..A".Qa2#...Bq.3$.8..4...w...Rb.Cu.WX...cs..&v.9......
[email protected][email protected](......_....
.R]..cn>[email protected][email protected][email protected]...:..l.....q...D....<......
#..e....f..6>R.I)1*...g....M[D....5..UM../..Qw.Q.t..g.em..Y...CO.%.
...X..RY!.q#6."(.".\..&......A.@.{....F.l.p.P[lT.vM.""..A.TA%D^H...sU.
.;..2%..r....v^N.-.o<.^.F.O.......q..".Q7T.h6j....v#.-...zjf.A.....
E.pS.....*[email protected][email protected][email protected][email protected]:[&.
..G...6b.B.d....v.I..>...I.Y....C..46......U...aW..7C]........m.,g@
.C......~"..2^.:.....?.Z........(u.T/....t.o....c....]B~6......Uf.T..S
.].~C..']5M.S%U].x.4..Q=U......{Q....Z.Y".k...2 P.].Qy.s.G.$Pu...NJ(&g
t;....x.....e:.I..F.V...mA.Ci...8...x!1$T_.h:.[.X....<.......HQ....
.7^wti..hI..5O..U|*."........{#^.Y..N}.....t.S.Qg..G....e...Pc.E.9.4.A
Z.b."...."..n......F.....}.n....h;%.x.6.~..e......../..^([email protected].(
..E.|..N.Z....e.>.S}.U........./.IUUt..@.~.mJ}....I..6.K...mF3....d
..u..P......t].....xvS.V..S.%F....w%...J.....M..%2..!N<..?uQ.lo....
h....h....h.......i......ri....?T$..A..4....1..rf{..../..k&"..L.......
.BD......../.t...8T..s.; ...T.qF..l..(...n].bXU.....i...*h............
...gF.G.N?.E..lZv.....e.&.....0l*..{N8......;.U....z4.p.>..;...<<< skipped >>>
GET /star/upload/13/13/1385020775085_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 22 Aug 2016 12:25:20 GMT
Content-Type: image/jpeg
Content-Length: 3061
Last-Modified: Thu, 21 Nov 2013 07:59:33 GMT
Expires: Sun, 20 Nov 2016 12:25:19 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1827012
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF..............Exif..II*...............b...........j...(.....
......1.......r...2.......................i...............H.......H...
....VVV.meitu.com.2008:11:13 21:55:46...........425...................
..`....................................................C..............
................................#....!!!..$'$ &. ! ...C........... ...
......d.d...........
....................................................}........!1A..Qa."
q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwx
yz....................................................................
..........................................................w.......!1..
AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghi
jstuvwxyz.............................................................
.......................?........i1..!h...../|]...[.K.c.....dP.z..'..i\
...Y.....K..kz6....=..mq.l.}[email protected]...".(([email protected].&
gt;../-.U...yb./......Z...v..._.i.X...=..l.J. eYXr....Bi...E.Iq%....e.
.3.f.........T.....P..P.uE..9z.`:[email protected]}F;P......... .
...3.....#.....7......sHez...P...P.uE..9{.b.........$(.......|1.o.k.."
.%..-.... ..;.b2:d.Zi>....I%h.5}&.E.6.rP.FF2..E.s?Y....h..n..-]..5.
...........@.=..P...UE..9;.`:[email protected].. .a.g%....8....gYo....'A.b.rF.n.
|.....?.)......W....z...H6r.Q.......,mG..H.#..z]...D.s.e#R..}I<z.9.
.m...;...zM...W........G.A.y#..(.....P.UE..9z.`>."P...c%......;Y'r.
..g.i....#0.R.h.l..8$}G..2;.G.Cl..^Y.}..........-..P...........}..<<< skipped >>>
GET /star/upload/10/10/1413192688282_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 24 Aug 2016 04:07:07 GMT
Content-Type: image/jpeg
Content-Length: 17672
Last-Modified: Mon, 13 Oct 2014 09:31:36 GMT
Expires: Tue, 22 Nov 2016 04:07:06 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1684105
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive.....0Exif..MM.*.......1..............VVV.meitu.com....C..............
......................................................C...............
........................................................d.d...........
....................................................}........!1A..Qa."
q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwx
yz....................................................................
..........................................................w.......!1..
AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghi
jstuvwxyz.............................................................
.......................?........A9Q.*..#.9....m....^....E..{_T..D..n..
.$.8....E.$d.1..t.<..]...7}.....i .....=..j....t.b.x.g....(..E.M>
;zy..$...z&...e.;l........Qy.I.....]....5u}..-l.....Lo...B........._..
=2!>..k.V.~.g.:..\].4p.I3.P..$.......!...N...\......M..$.....?.?...
...>.|C.'.../....-oA.=7.?.5H..#...#%.^.......'N..s.k..hr]%.Gku..r.U
q.2...J.R..;Z ..6...L.0y4.EU...89*p^...<...h.v.v...E......!.}b-SA..
....._..Z.>............R.n.O.}.I....R[..M..6....$q.C..U........ .6.
...{y..L......Q........$......$~...7?.....m......>,|.....3....9....
.~.x.\.....A..As..7.^.qms..>.......o..77....t.1..%..5.....vOF......
....h:.~.....iS..I7..w}......c..#..;...1...8?..............z..._....3.
./.~D...q...G[..^......B.....K.{...I.........U.................M......
xX.8S.Q3....].[.Z...]...w.W..=/k...b 6...q...v..~4.c{k.....{[email protected]...
'.=..qIl...ko..%;Y..J..e.>.z.....2...p=x.s.S^......n.......j.Mv<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4953&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:11 GMT
Content-Type: text/html; charset=gbk
Content-Length: 974
Connection: close
Expires: Mon, 12 Sep 2016 15:55:26 GMT
Vary: Accept-Encodingsuccess.-4953.20.20.103135...............3130295597,1291564518.0.91623
.F.I.R...........1056281702,3995589812.0.293574......Radio In My Head.
3633181261,1138358655.0.292015......................-(................
......).3404235119,2241057940.0.150065...........3267273195,4011643915
.0.146193...............1386469378,2332805106.0.164029................
...898822692,3909220077.0.265964.................3184537439,3781408808
.0.63740.............3925283803,3159077478.0.988790...................
326003443,3130885570.0.269408.............2362327227,285492258.0.21590
1......u............4121575398,4272484243.0.324167.............2202846
795,3525556507.0.203315.................3253794869,1231330358.0.59837.
................1869447357,1195821993.0.165793...............304301399
1,4018951649.0.86531..................3295702032,1098281893.0.1014338.
..................1397463112,3814225141.0.292491.......&..............
..868024730,461728427.0.85525.5566......3897572244,2852288998.0...
POST /music.yl HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 236
Host: log.kuwo.cn
Connection: Close
MiUwOTxTUkM6TVVTSUNfNy43LjAuMV9QMlQxfEFDVDpJTlNUQUxMX1NUQVRFfFM6S3dNdXNpY3xTdWNjZXNzfHxQUk9EOk1VU0lDfFZFUjo3LjcuMC4xX1AyVDF8UExBVDpXSU4zMnxGUk9NOmt1d29fam00MjkuZXhlfFVJOnx7a3V3b19qbTQyOS5leGV9fEs6NTkyMTE4MDk4fFJFU0VORDowfFU6NjQyNDY3MT4A
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: text/html
Content-Length: 12
Connection: closeR290IGl0IQA9..
GET /today_recommend/tool_new/123.gif HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 08:12:06 GMT
Content-Type: image/gif
Content-Length: 2976
Last-Modified: Sat, 14 Aug 2010 13:33:50 GMT
ETag: "4c669b3e-ba0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 07:23:03 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 81381
Powered-By-VeryCDN: HIT from ctc-cz-1-3-c1111, HIT from utn-cz-1-1-c1131
Connection: close.PNG........IHDR...(...(........m....tEXtSoftware.Adobe ImageReadyq.e&
lt;...BIDATx..X]l.W............q.$u.4N........B.!..i%.."@<!T!...$$.
Am.xCB...WH.R5mR.'-i...c......z.......wg6.7I.B.........;.9.;.ZH).>.
?....C<.y......5.o.<x...A...\>........... -....Hk..-W.^..K"t~
F........R..=..M..>.....5?.s..@k....~..../'.&..5.mi..F...!..6r.1ke.
...~....2Fm=.....H.Jf.....pJ.4.w....d..*/.:..|......S........*..l.....
.E.O.......\...%....e.........4.;.....K....._.h8..........;F......6...
/&N'8....%.'v..-....(...~..I.|..O.xd..J\(../........3.. .V.*{...O...&l
t;T.X.I|P.t..W.E....%.-Q.[.O...`....W..........a.&m..w......%.W../fm.,
q.b..Sct.P....JC..U.........'g.:..|...7..v.S...v.`w.).c.U..M....7g...U
."..z1......0.;.$....z....|....k..W.K....ug......u......b(-z..C.......
:....Ze...k....r'..b.s(J.).Y[...d.........B..l.).DJ.p...=h.R.D_.a'..I.
........L..Q%.<.......gb=G.... ..j....kL.[.6.Ip!|..T]..L7I.hz.....J
.4..).1`...k.L..m..,.#.....`.3T..L...88...0...0.".4..&..D.zXS.B.......
......t.b..N....KM|P.......k......G.|..I.H2b......xXi....7d..IEB......
..5^.R......^...kXu.....;^.F.).$!A..nh.!...\#@KyA .5\....C$.z...>F.
:|?.`0....ni.=`FV..o;u. ....g^4.2...b.R..... _..;m...d6.U.....M....qM.
.Gg.2............ci.R...D.....)............o..8Y.!...T..|Tb.x....i....
*.[.$p.0i.MY.G.n..V..a6n.N/.. .&.m...4ob30.;L`..._....&S8....\./......
.I.e...YL..]l.Iz....!.%..^[email protected],..L,..-q.mL..p p.Sh....F
...-...M.......J.tF......}...I3.a.....4$.....:}.T..4..v...T.>C.....
....e.^.S.....)...o...h....7G..u......i...~.H.7..dC.FP2.75..X.0.o.<<< skipped >>>
GET /lyrics/img/kwgg/adv4162/index.htm?ver=MUSIC_7.7.0.1_P2T1 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:47:28 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 4837
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "1371706-12e5-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:04:06 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 496
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "htt
p://VVV.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xm
lns="hXXp://VVV.w3.org/1999/xhtml">..<head>..<meta http-eq
uiv="Content-Type" content="text/html; charset=gb2312" />..<meta
http-equiv="X-UA-Compatible" content="IE=7" />..<title>.....
.....</title>..<style type="text/css">..html{overflow-x:hi
dden;overflow-y:hidden;}..body{margin:0px;}..</style>..<style
>...updateMboxPage{zoom:1;position:absolute;left:0;top:0;z-index:10
01;margin:0px;padding:0px;width:100px;height:300px; background:#000;-m
oz-opacity:0;filter:alpha(opacity=0);opacity:0;display:block;}...close
Icon{ width:40px; height:18px; display:block; position:absolute; top:0
; right:0; line-height:18px;font-size:12px;font-weight:bold;text-decor
ation:none;color:#fff;background:#6e777b;z-index:1005;}..</style>
;..<script>function killerr(){return true;}window.onerror=killer
r;</script>..</head>..<body style="border:0px; margin:0
; background-color:white;">..<div id="swfdiv">..<object id
="swf" codebase="hXXp://download.macromedia.com/pub/shockwave/cabs/fl
ash/swflash.cab#version=7" width="100" height="300">..<param nam
e="movie" value="_4_1464245796316.swf" /><param name="allowScrip
tAccess" value="always"/><param name='wmode' value='opaque' />
;<param name="quality" value="high" /><embed src="_4_14642457
96316.swf" quality="high" pluginspage="hXXp://VVV.macromedia.com/g<<< skipped >>>
POST /music.yl HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 360
Host: log.kuwo.cn
Connection: Close
MiUwOTxTUkM6TVVTSUNfNy43LjAuMV9QMlQxfEFDVDpBcHBTdGFydHxTOkt3TXVzaWN8TnVtOjc5MjF8RXhpdDoxfFR5cGU6YXV0b3xTVEFSVFRNOjgwNzh8T1NWOjUuMS4yNjAwfENQVTozMzkyKjF8TUVNOjUxMXxGUkVFTUVNOjI0MnxNVVNJQ0FQUDp8U1lTU1RBUlRUSU1FOjU4OTE0MHxQUk9EOk1VU0lDfFZFUjo3LjcuMC4xX1AyVDF8UExBVDpXSU4zMnxGUk9NOmt1d29fam00MjkuZXhlfFVJOnx7a3V3b19qbTQyOS5leGV9fEs6NTkyMTE4MDk4fFJFU0VORDowfFU6PgA=
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:21 GMT
Content-Type: text/html
Content-Length: 12
Connection: closeR290IGl0IQA9..
GET /star/upload/6/6/1473054658982_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.kwcdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/jpeg
Content-Length: 9747
Last-Modified: Mon, 05 Sep 2016 05:43:18 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Mon, 05 Sep 2016 07:08:12 GMT
Age: 636439
Powered-By-VeryCDN: HIT from utn-cz-1-1-c1112, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P.....ShXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:DocumentID="xmp.did:3A2B9D736F6E11E68F14A87C8
A3F70A8" xmpMM:InstanceID="xmp.iid:3A2B9D726F6E11E68F14A87C8A3F70A8" x
mp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"> <xmpMM:Deriv
edFrom stRef:instanceID="adobe:docid:photoshop:80027864-6f6d-11e6-b5ba
-acc32d1c914b" stRef:documentID="adobe:docid:photoshop:80027864-6f6d-1
1e6-b5ba-acc32d1c914b"/> </rdf:Description> </rdf:RDF>
</x:xmpmeta> <?xpacket end="r"?>....Adobe.d...............
......................................................................
............................................................d.d.......
......................................................................
.................!.1A".Qa2..q...B#3....$%..br.Ss4E.Rc5.....&..........
...............!1..AQa"..q.2....Rbr#3....B...$....CS%.cs......45......
.......?......2.. ...K.......~P.Gn0......(i $.8ep...g..\s......Q....7b
...{..Id.s....,.l....A..q-7q....S.....iJ..B.....of......X..(..e.t.e...
..1*qW=(e.)..J.....B.W.H.n......S.~......m..V... .......Y~E.....-%<<< skipped >>>
GET /today_recommend/images/201609/1473519658028.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 12:23:32 GMT
Content-Type: image/jpeg
Content-Length: 52737
Last-Modified: Sat, 10 Sep 2016 15:00:58 GMT
ETag: "57d4202a-ce01"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 17:48:09 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 38002
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
...............!.1..AQa".q.2...B#....Rb.r3.7.......$t.5u.6Vv..CS4T..G8
..cs....DF..%Ue.&......................!1.AQ..3...Daq."R..2#B.........
...?..T...............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................W..\...X....[.i9NzOE.H._Qp9...?-.n<<< skipped >>>
GET /star/upload/6/6/1472640248934_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.kwcdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/jpeg
Content-Length: 13361
Last-Modified: Wed, 31 Aug 2016 10:36:40 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Wed, 31 Aug 2016 10:44:19 GMT
Age: 1055471
Powered-By-VeryCDN: HIT from ctc-fs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P...../hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"
xmpMM:InstanceID="xmp.iid:200EAF4A6F6711E6BA17AC1843DCB73E" xmpMM:Doc
umentID="xmp.did:200EAF4B6F6711E6BA17AC1843DCB73E"> <xmpMM:Deriv
edFrom stRef:instanceID="xmp.iid:200EAF486F6711E6BA17AC1843DCB73E" stR
ef:documentID="xmp.did:200EAF496F6711E6BA17AC1843DCB73E"/> </rdf
:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end=
"r"?>....Adobe.d...................................................
......................................................................
........................d.d...........................................
.................................................!.1..A".2#.QaB$qRb...
.....3.Sc.D&.....................!..1..AQ".a.2.qB...Rb#........r3....C
S$4.............?.u.H$.|....Ru..."[email protected].".%.....
....j.qrej..1..Zj.HI.u$ .t..z. ..].;IB..,.<.A....CSW.NN...[....b...
xh.S,b...p4.Cx....S.h4^...u..Q.B.<.i....%......kr...y.g...<A....
.?.g.L.......)...$L.$...P..u........5CN.j8..J.\H..D.....".......p-<<< skipped >>>
GET /star/upload/0/0/1471241513120_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.kwcdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/jpeg
Content-Length: 16741
Last-Modified: Mon, 15 Aug 2016 06:04:49 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Mon, 05 Sep 2016 03:11:08 GMT
Age: 650662
Powered-By-VeryCDN: HIT from ctc-tz-1-2-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......Z...../hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"
xmpMM:InstanceID="xmp.iid:FF8AD7ED628811E6BB67C066B20826C1" xmpMM:Doc
umentID="xmp.did:FF8AD7EE628811E6BB67C066B20826C1"> <xmpMM:Deriv
edFrom stRef:instanceID="xmp.iid:FF8AD7EB628811E6BB67C066B20826C1" stR
ef:documentID="xmp.did:FF8AD7EC628811E6BB67C066B20826C1"/> </rdf
:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end=
"r"?>...XICC_PROFILE......HLino....mntrRGB XYZ .........1..acspMSFT
....IEC sRGB.......................-HP ..............................
..................cprt...P...3desc.......lwtpt........bkpt........rXYZ
........gXYZ...,[email protected]
ew.......$lumi........meas.......$tech...0....rTRC...<....gTRC...&l
t;....bTRC...<....text....Copyright (c) 1998 Hewlett-Packard Compan
y..desc........sRGB IEC61966-2.1............sRGB IEC61966-2.1.........
.........................................XYZ .......Q........XYZ .....
...........XYZ ......o...8.....XYZ ......b.........XYZ ......$....<<< skipped >>>
GET /crossdomain.xml HTTP/1.1
Accept: */*
Accept-Language: en-US
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.kwcdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Content-Type: text/xml
Content-Length: 177
Last-Modified: Wed, 02 May 2012 05:50:06 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Wed, 07 Sep 2016 01:13:15 GMT
Age: 484937
Powered-By-VeryCDN: HIT from ctc-tz-1-2-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive<?xml version="1.0" encoding="UTF-8"?>.<cross-domain-policy&g
t;. <allow-access-from domain="*" /> . . <site-control permit
ted-cross-domain-policies="all" />.</cross-domain-policy>.HTT
P/1.1 200 OK..Server: nginx..Content-Type: text/xml..Content-Length: 1
77..Last-Modified: Wed, 02 May 2012 05:50:06 GMT..Cache-Control: s-max
age=15552000..Accept-Ranges: bytes..Vary: Accept-Encoding..Date: Wed,
07 Sep 2016 01:13:15 GMT..Age: 484937..Powered-By-VeryCDN: HIT from ct
c-tz-1-2-c1111, HIT from utn-cz-1-1-c1131..Connection: keep-alive..<
;?xml version="1.0" encoding="UTF-8"?>.<cross-domain-policy>.
<allow-access-from domain="*" /> . . <site-control permitted
-cross-domain-policies="all" />.</cross-domain-policy>...
GET /lyrics/img/kwgg/kwgg_328.js?time=20168122056 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:52:41 GMT
Content-Type: application/x-javascript
Content-Length: 4952
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "1357103-1358-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:07:18 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1495
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alivevar param=window.top.location.href;var mboxVer="";var vidx1=param.inde
xOf('v=');if(vidx1>=0){vidx2=param.indexOf('&', vidx1 1);if(vidx2
>vidx1 2){mboxVer=param.substring(vidx1 2,vidx2);}else{mboxVer=para
m.substring(vidx1 2);}}var mboxExternalVer="";try{mboxExternalVer=wind
ow.external.callkwmusic('GetVer');} catch(e){};mboxVer = mboxExternalV
er;var recom_2013_r4_ie6sign = '0';try {if (!-[1,] && !window.XMLHttpR
equest) {recom_2013_r4_ie6sign = 1}} catch (e) {};var unSupportAdsArr
= ['5478','5325','5324','5347','5348','5345','5346','5380','5381','543
3','5417','5383','5382','5452','5453','5454','5455','5448','5449','544
2','5443','5444','5445','5446','5447','1046','5546','5545','5544','554
3','5547','5567','5568','5575','5569','5570','5571','5572','5573','545
3','5452','5449','5448','5588','5589','5611','5610','5609','5608','560
7','5656','5655','5654','5653','5652','5651','5650','5649','5663','566
2','5661','5660','5659','5658','5673','5672','5671','5670','5669','566
8','5667','5666','5665','5664','5708','5707','5706','5705','5704','570
3','5702','5701','5700','5699','5698','5697','5696','5695','5739','574
0','5741','5742','5743','5744','5745','5746','5747','5748','5749'];fun
ction recom_2013_r4_isSupportAd(index){var _isSupportAd = true;if (rec
om_2013_r4_ie6sign == 1) { for (var _index = 0; _index < unSupportA
dsArr.length; _index ) { regStr = unSupportAdsArr[_index];if(recom_20
13_r4[index].indexOf(regStr)!=-1) {_isSupportAd = false;break;}}}retur
n _isSupportAd;}recom_2013_r4=new Array();var d = new Date(); var<<< skipped >>>
GET /lyrics/img/kwgg/kwgg_371.js?time=0.6817576852176765 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:37:30 GMT
Content-Type: application/x-javascript
Content-Length: 5192
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "13576fa-1448-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:57:43 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1094
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alivevar param=window.top.location.href;var mboxVer="";var vidx1=param.inde
xOf('v=');if(vidx1>=0){vidx2=param.indexOf('&', vidx1 1);if(vidx2
>vidx1 2){mboxVer=param.substring(vidx1 2,vidx2);}else{mboxVer=para
m.substring(vidx1 2);}}var recom_2013_2t_ie6sign = '0';try {if (!-[1,]
&& !window.XMLHttpRequest) {recom_2013_2t_ie6sign = 1}} catch (e) {};
var unSupportAdsArr = ['5478','5325','5324','5347','5348','5345','5346
','5380','5381','5433','5417','5383','5382','5452','5453','5454','5455
','5448','5449','5442','5443','5444','5445','5446','5447','1046','5546
','5545','5544','5543','5547','5567','5568','5575','5569','5570','5571
','5572','5573','5453','5452','5449','5448','5588','5589','5611','5610
','5609','5608','5607','5656','5655','5654','5653','5652','5651','5650
','5649','5663','5662','5661','5660','5659','5658','5673','5672','5671
','5670','5669','5668','5667','5666','5665','5664','5708','5707','5706
','5705','5704','5703','5702','5701','5700','5699','5698','5697','5696
','5695','5739','5740','5741','5742','5743','5744','5745','5746','5747
','5748','5749'];function recom_2013_2t_isSupportAd(index){var _isSupp
ortAd = true;if (recom_2013_2t_ie6sign == 1) { for (var _index = 0; _i
ndex < unSupportAdsArr.length; _index ) { regStr = unSupportAdsArr
[_index];if(recom_2013_2t[index].indexOf(regStr)!=-1) {_isSupportAd =
false;break;}}}return _isSupportAd;}recom_2013_2t=new Array();var d =
new Date(); var timehours = d.getHours();recom_2013_2t[0]='<iframe
width="100" height="287" scrolling="no" frameborder="0" src="http:<<< skipped >>>
POST /music.yl HTTP/1.1
Content-Type: application/x-www-form-urlencoded
User-Agent: NSIS_Inetc (Mozilla)
Host: log.kuwo.cn
Content-Length: 104
Connection: Keep-Alive
Cache-Control: no-cache
MiUwOTxTUkM6TVVTSUNfNy43LjAuMV9QMlQxfEFDVDpCSU5EX0lOU1RBTEx8Ujp8UzpLd011c2ljfHtrdXdvX2ptNDI5LmV4ZX18VTo
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:10 GMT
Content-Type: text/html
Content-Length: 12
Connection: keep-aliveR290IGl0IQA9HTTP/1.1 200 OK..Server: nginx/0.7.64..Date: Mon, 12 Sep 2
016 15:55:10 GMT..Content-Type: text/html..Content-Length: 12..Connect
ion: keep-alive..R290IGl0IQA9..
GET /g.real?aid=html_ad_4839&ver=&type=show&cid=6424671 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4839/index.htm?ver=
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: g.koowo.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:40 GMT
Content-Type: text/html; charset=ISO-8859-1
Content-Length: 0
Connection: keep-alive
Vary: Accept-EncodingHTTP/1.1 200 OK..Server: nginx..Date: Mon, 12 Sep 2016 15:55:40 GMT..C
ontent-Type: text/html; charset=ISO-8859-1..Content-Length: 0..Connect
ion: keep-alive..Vary: Accept-Encoding..
GET /kuwo/fengxing/hsy_ip_pv.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: webstat.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 404 Not Found
Server: nginx/0.6.38
Date: Mon, 12 Sep 2016 15:55:18 GMT
Content-Type: text/html
Content-Length: 529
Connection: close<html>..<head><title>404 Not Found</title><
/head>..<body bgcolor="white">..<center><h1>404 N
ot Found</h1></center>..<hr><center>nginx/0.6.
38</center>..</body>..</html>..<!-- The padding t
o disable MSIE's friendly error page -->..<!-- The padding to di
sable MSIE's friendly error page -->..<!-- The padding to disabl
e MSIE's friendly error page -->..<!-- The padding to disable MS
IE's friendly error page -->..<!-- The padding to disable MSIE's
friendly error page -->..<!-- The padding to disable MSIE's fri
endly error page -->....
GET /today_recommend/mbox2013/config/kuwofx.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: topmusic.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:46:21 GMT
Content-Type: application/x-javascript
Last-Modified: Thu, 24 Sep 2015 03:08:42 GMT
Content-Encoding: gzip
Expires: Mon, 12 Sep 2016 15:50:35 GMT
Cache-Control: max-age=900
Vary: Accept-Encoding
Age: 689
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-cz-1-1-c1131
Accept-Ranges: bytes
Content-Length: 730
Etag: "5603693a-53e"
Connection: keep-alive..........mTkk.0........$.......;...cl...(...j..d.QJ....4]H.!W...s..l%
..?.....TP..5e..;v.....}BV,..v].".......f..H.T..q..^..:.ea.e..Bq.`1G.s
..$...C.......V`i....;.....Z.{.....S..jS.q...g..t .....;Q.Uk..J....W9/
..a..:....6Y.,. u...-.../..n...XH.s.&.b...H.U`..e.du..$'%Z.*bmD.......
H3...X.y.L...E...T.o.f..G.Q./e.....p.3.-=..../1Sq...g,.9-.?}`?.~..1...
`....-;...[V.e.g....d....5.5..(;..U...L.....%......(..e.QnU.,........4
....`BC...t.7$..fG...hDg......pN..........F!..6.>$.. .t..l....F..M4
.74...Q.9d...1.....|..#_.....?.~...k..!...wJ}XE..3....{u,1....#0.z...@
.o......h8.!...h..I...oFj.....<z.6@.`.Na..067-..tz..3..#0C.`.......
.........,...%.f...j.~H{s<.............][email protected]}.... n......\
.;...0..r...K....g<~......cx.....1|>...HTTP/1.1 200 OK..Server:
nginx..Date: Mon, 12 Sep 2016 15:46:21 GMT..Content-Type: application/
x-javascript..Last-Modified: Thu, 24 Sep 2015 03:08:42 GMT..Content-En
coding: gzip..Expires: Mon, 12 Sep 2016 15:50:35 GMT..Cache-Control: m
ax-age=900..Vary: Accept-Encoding..Age: 689..Powered-By-VeryCDN: HIT f
rom cmc-jz-1-1-c1111, HIT from utn-cz-1-1-c1131..Accept-Ranges: bytes.
.Content-Length: 730..Etag: "5603693a-53e"..Connection: keep-alive....
........mTkk.0........$.......;...cl...(...j..d.QJ....4]H.!W...s..l%..
?.....TP..5e..;v.....}BV,..v].".......f..H.T..q..^..:.ea.e..Bq.`1G.s..
$...C.......V`i....;.....Z.{.....S..jS.q...g..t .....;Q.Uk..J....W9/..
a..:....6Y.,. u...-.../..n...XH.s.&.b...H.U`..e.du..$'%Z.*bmD.......H3
...X.y.L...E...T.o.f..G.Q./e.....p.3.-=..../1Sq...g,.9-.?}`?.~..1.<<< skipped >>>
POST /music.yl HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 232
Host: log.kuwo.cn
Connection: Close
MiUwOTxTUkM6TVVTSUNfNy43LjAuMV9QMlQxfEFDVDpET1dOQ09ORnxTOkt3TXVzaWN8RkFJTEVEOjF8UFJPRDpNVVNJQ3xWRVI6Ny43LjAuMV9QMlQxfFBMQVQ6V0lOMzJ8RlJPTTprdXdvX2ptNDI5LmV4ZXxVSTp8e2t1d29fam00MjkuZXhlfXxLOjU5MjExODA5OHxSRVNFTkQ6MHxVOjY0MjQ2NzE AA==
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:40 GMT
Content-Type: text/html
Content-Length: 12
Connection: closeR290IGl0IQA9..
GET /lyrics/img/kwgg/personalAd.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:54:53 GMT
Content-Type: application/x-javascript
Content-Length: 3093
Last-Modified: Mon, 12 Sep 2016 15:40:38 GMT
ETag: "641db08-c15-53c5151538980"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:24:53 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 84
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive//read a cookie..function getCookie(cookieName){.. var arg = cookie
Name "=";.. var alen = arg.length;.. var clen = document.cooki
e.length;.. var i = 0;.. while (i < clen) {.. var j =
i alen;.. if (document.cookie.substring(i, j) == arg) {..
var endstr = document.cookie.indexOf(";", j);.. if
(endstr == -1) {.. endstr = document.cookie.length;..
}.. var ret = unescape(document.cookie.substring(
j, endstr));.. if (ret != "") {.. return ret
;.. }.. }.. i = document.cookie.indexOf(" ",
i) 1;.. if (i == 0) .. break;.. }.. return "
";..}..//delete a cookie..function delCookie(cookieName){.. var exp
= new Date();.. exp.setTime(exp.getTime() - 100);.. document.co
okie = cookieName "=; path=/; domain=kuwo.cn; expires=" exp.toGMTS
tring();.. document.cookie = cookieName "=; path=/; expires=" e
xp.toGMTString();..}..//add a cookie..function addCookie(cookieName, c
ookieValue){.. var expdate = new Date();.. var argv = addCookie.
arguments;.. var argc = addCookie.arguments.length;.. var expire
s = (argc > 2 && argv[2] != 0) ? argv[2] : null;.. var path = (a
rgc > 3) ? argv[3] : null;.. var domain = (argc > 4) ? argv[4
] : null;.. var secure = (argc > 5) ? argv[5] : false;.. if (
expires != null) {.. expdate.setTime(expdate.getTime() (expir
es * 1000));.. }.. document.cookie = cookieName "=" esca<<< skipped >>>
GET /today_recommend/images/201609/1473321334926.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 19:50:38 GMT
Content-Type: image/jpeg
Content-Length: 85810
Last-Modified: Thu, 08 Sep 2016 07:55:34 GMT
ETag: "57d11976-14f32"
Accept-Ranges: bytes
Expires: Sun, 11 Sep 2016 17:04:53 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 72754
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
................!1..AQ.aq"...2B...R#...br.3....$.....CSs.u.6v7.c.4Tt.%
5V...D.G8....F.Ue.&.....................1!..AQ...3.Daq"R...2#.B.......
.....?..U.............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..........................................................NH0>.....
....`.........P....9(....29....A4i.4..TH....KK.M9.....T.=.............
......................................................................
..............................................W.z.i.Xb.q..../0.....p.'
0.\..jG4.......p6HuP=..f...[5H..SW#]..k.w..Z...{.I....1Z.G.........*..
d...W..vH..t...<...2...........9.......>..:..{..D......|.v...0.l
.c..8TP.)..J.....:.s4....Z.$.-..x..jk.#[....i..OQ.......Q.............
..5..........[u...-..H..7...h..xn..]T..1...[........<;..~b.......n.
...SW..v..........q_....G(.d./.XqU.YA<s0...\X..9...FD..............
..................................................................<<< skipped >>>
GET /newradio.nr?type=1&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:05 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1833
Connection: close
Expires: Mon, 12 Sep 2016 15:55:20 GMT
Vary: Accept-Encodingsuccess.-19625..............hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201
308/1377056413071.jpg.hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201308/13
77056428814.jpg.2008-08-08.2016-02-05.0.0~24.4.200.-6003..........http
://img1.kwcdn.kuwo.cn:81/star/tags/201203/1331101145819.jpg.hXXp://img
1.kwcdn.kuwo.cn:81/star/tags/201203/1331100823968.jpg.2008-08-08.2016-
01-26.0.0~24.4.1405.-18239..............hXXp://img1.kwcdn.kuwo.cn:81/s
tar/tags/201203/1331021713041.jpg.hXXp://img1.kwcdn.kuwo.cn:81/star/ta
gs/201203/1331024459542.jpg.2008-08-08.2016-02-01.0.0~24.4.1271.-4459.
.............hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201203/13310214769
94.jpg.hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201203/1331024088189.jpg
.2012-05-11.981.0.0~24.4.1740.-4954.90.......hXXp://img1.kwcdn.kuwo.cn
:81/star/tags/201202/1329895005888.jpg.hXXp://img1.kwcdn.kuwo.cn:81/st
ar/tags/201202/1329895027635.jpg.2012-05-08.2016-01-04.0.0~24.4.1070.-
18892......................hXXp://img1.kwcdn.kuwo.cn:81/star/tags/2013
07/1375165767612.jpg.hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201307/137
5238555519.jpg.2008-08-08.2016-02-01.0.0~24.4.1606.-4996..............
......hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201203/1331014928201.jpg.
hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201203/1331014947357.jpg.2012-1
1-14.2016-01-26.0.0~24.4.3817.-4953.80.......hXXp://img1.kwcdn.kuwo.cn
:81/star/tags/201202/1329894978685.jpg.hXXp://img1.kwcdn.kuwo.cn:81/st
ar/tags/201202/1329894962918.jpg.2012-05-08.2016-02-05.0.0~24.4.802.-6
007..............hXXp://img1.kwcdn.kuwo.cn:81/star/tags/201203/133<<< skipped >>>
GET /pagesig/vipMbox_new/7.7.0/sig.htm HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: updatepage.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: DnionOS/1.2.1.12
Date: Mon, 12 Sep 2016 15:30:42 GMT
Content-Type: text/html; charset=UTF-8
Content-Length: 106
Last-Modified: Thu, 03 Mar 2016 08:16:31 GMT
ETag: "950024-6a-52d209dab35c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:13:08 GMT
Cache-Control: max-age=3600
Vary: Accept-Encoding
Age: 3138
Via: CT-CNC-ZJHZ-P-6-47 (DLC-3.0), CT-GDFSSSD-C-97-106 (DLC-3.0)
Connection: closesig1=227516712.sig2=3485242675.update=hXXp://updatepage.kuwo.cn/pagesi
g/vipMbox_new/7.7.0/vipMbox_new.zip...
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4459&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:10 GMT
Content-Type: text/html; charset=gbk
Content-Length: 968
Connection: close
Expires: Mon, 12 Sep 2016 15:55:25 GMT
Vary: Accept-Encodingsuccess.-4459.20.20.3253627...................24959457,2429270747.0.12
3994.................982775465,294072185.0.340933.......&..........161
4396700,4133841088.0.117427...................546144105,3179080320.0.1
041061.........................2676425201,1711240849.0.363246.Beyond..
........3394725786,3428913806.0.982118.................167139620,56281
9563.0.5000619.................2748895825,1801875516.0.152057.........
....1935605062,4009338915.0.75819................(....).1574910147,421
5988623.0.3565359.............1153367192,4110913747.0.559223..........
.................563191643,273312245.0.888605.............187860898,13
72089059.0.396553.......&............2321868703,3076344754.0.216396...
............4056629298,2410288787.0.216877.......................64605
4677,1702708245.0.5068607...........455208345,2023890162.0.216443.....
............4236029108,2200623892.0.310071.................1556321322,
133596015.0.3678092...............1753464376,3217059050.0...
GET /c.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv5750/1473056615593.swf
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: js.miaozhen.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: Tengine
Content-Type: application/x-shockwave-flash
Content-Length: 2793
Connection: keep-alive
Accept-Ranges: bytes
ETag: "3061300640"
Last-Modified: Tue, 25 Jun 2013 02:22:35 GMT
Date: Mon, 12 Sep 2016 14:26:24 GMT
Via: cache4.l2et15[0,304-0,H], cache7.l2et15[0,0], kunlun7.cn44[0,200-0,H], kunlun6.cn44[2,0]
Cache-Control: max-age=7200
Expires: Mon, 12 Sep 2016 14:26:24 GMT
Age: 5384
X-Cache: HIT TCP_MEM_HIT dirn:9:455374736
X-Swift-SaveTime: Mon, 12 Sep 2016 14:38:01 GMT
X-Swift-CacheTime: 7200
Timing-Allow-Origin: *
EagleId: 7522074614736957689257685eCWS."...x..XKs...n. ..I....-....eI&)Y.m.K...%c..AJ.d'.r...Z`...E.q^Nl.
%;..DQ..-. U....r.1.JU.9..C.9%Jw.>..B..*..t........=...O..}).8..w..
.....|.....6.%..FYw.|~.s.&v/.H.9.ajb..j..Y.....h<.g.Ua.......z..EG/
^.].l..oz..oUL..bg.....nCE.Y.h..Y`...F.....TI)Tvi..^........gV..A...z.
....q.5K.S.......P.t.F.......-..Q..S.;..u.=.{&.....r..S.....=.!..[....
..U-...5.. ....K.[..CY...Vq..f.h.H....-.......\..... .$e.V1v.G..@.....
d.....5.;....XU..o...W.Ob.c.R4...M6.;..*f.B...l.....n...m.f.j...#....~
......^1..8j..5^v..3......eS......Q.l.uM.u.8.......{...........N. X.f1
H..."ZiC....ob..... =/:U.~.0...N.....:..c.......A. ..u.....(.K....5]..
j..`d..Y2..^Y;..w...nb1m....".`bg.dm.EY..]..U}w...PSaC.u....K?.T.8..z.
Y........B..M.../....iVq.8v...&.m.].-. .Z..%..].$T..BC.......:..U^.%0.
:...K?^...M.M.35o......5.o\.#{.R.w/:..y..j.m..&.v..U.4f.Tc....:T.g.. W
q..G.g..).o...=..>LA.p#.].I..t...nd ..@......."d.2.,m.}.C...N..h.bF
.K<z.T...%].se!...!g~h.D. .]EZi.H.C..ktC..;.[x'....z...m:.P....n..L
..J...PGZ...p.!q....%R...`...! U).2.$8C.......t...}.~..R.... G..P|3.~M
d...9O.z..4...yJ>.2T.].....)#...v..q.z<_.aO.......-2.Rz..\.p..n.
.'.KG.fR..B.......t. .dc......f9.."1T.)E.T.........(.........=.9.C....
[email protected]...,......G.......2.....F.)FC.y6.}....:,..P)7.AF..;..:
..a....%..3.K.. #..y"MP...vr/.,d..........rX.M.sDy|..O0n......i#...T.z
2..$..F....H....._..S.}.....e..8.!../......gE..a^O.m....N....t$......s
b9...B.H...H|[email protected],.(...#j..e...|,7B....M..?......k..d.i.a.
'.'.......SJN.N2.EA=.)..<..S.B...'@..........C%.x..:Q.."./E.q^O<<< skipped >>>
GET /lyrics/img/kwgg/adv4892/_1453189156821.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4892/index.htm?ver=
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:39:57 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 24640
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "13ac16f-6040-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:04:39 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1071
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS.be..x....X[Q....J!.K...;.I.b..Jqk.......'x(Z...P.P.h.E..k..7.;sf..
......Zk?...z..o.v.`m.....4..(.....!'......_J.B.Y|[email protected].....|
..|.n...%%%......x.*x.}.<,|x...@.,.$@m....\<...X....t...........
.X'w>.kgK.> gG~...~A>...p.....l,<.........P.(;X.....9..qw.
..p`Q..c.e...s.f.......3......# $ (. (. $...................U._S5m<
,.-<,..da..........L......lm.... ..)Y....'......_...../............
b..k....fe.W..o...)....a.de......ggg-%().$.....)H.D...E.............J.
...../..........h......./.... ....?.J.*([email protected]..... .. ..J(......
.}.6nv^6..n...\...7w..8%...U.....J..'6...M..J.....fB.S..h../6.."X.}a.
.O..[....w.....?K.......?...w....bX[I.tvs....pqq.....................T
.i..&.O...oEP........n.G..$.`#....Z.....gT..=....... .).00......"@.o..
-....e`.....c<.Xca...@., ..>.3............'[email protected]..
[email protected] >HP.B.N...kA...\D%l.v.....8..U.sOA5..Ka........
..<.....W....b`a.`.b.....^L, 6.. ..........Rt...J.d..,.............
.x.............m......c.*...].....F..../.yI..." }..%.w.......K..dR....
?{...... ..ZG....H.`....9.b...i........i...,..K.KiB.]......a...J......
[email protected]..... ........i.(....Hu3.....o%....`.q.x...FABz!...s......&..<
..... N...bqhC......p...3...4.......ep.o...?.}....A*...w.5......E.9.bZ
Y.....I.s'...T...d.~.5p...5...n{.h.....CL..L..|...YF..@CI[..[.NI.....
....GG......V{G$(......71p..:.......eW.?.M.0Y&..k....I8*.....v^..;|2."
.....Y.`......#..'..]m"..>,[email protected].........>...h9..
y.B{/..J.,."..5Xu.4Q.`..P......$z<.N.....'^..LAJ.Ib#.. }..>.<<< skipped >>>
GET /lyrics/img/kwgg/adv5750/1473056615593.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv5750/index.htm?ver=
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:51:35 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 23279
Last-Modified: Mon, 12 Sep 2016 15:40:37 GMT
ETag: "13607f5-5aef-53c5151444740"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:21:35 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 263
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS..a..x..x.T.M.e.... .!...{..\.i.I....CB.....!.....M ....|3.....=...
...{.......v. ....o....Y<....B.......m....T. g...........0.........
...KHH.....................F../..6.V`.7O.W..?....^.b44...............
......k......................,.........=.&..........JF...............O
.._c...F..%......)......)..%....)(...O....k...........sq.s.....s.....p
Wk.[..V.?<.D9.......V.'...........q....xz<........m]. .Oq.77g. .
?.9|.<.]..|,.m.l. [......)=.LM.?.r...Oo.O.........f....p..[.<...
.d....\<<-\.l.d..&.....y.d...e....x..........9..>d..........'
...............B.D..;.9<...A..............UPH.G.[VFH.KZV^..O.....\m
...6..`W._v....a..Sb4.R..M..W....$._-........,H..Z....'....M.!...7..&l
t;........S.d....{..?I$.`;.}'....I.Q0...y\x\....:...JJ..t.?....'.e....
..4.}.ZGr.... *..fa.d.Iei.....qG.......>..........?.F._]....J..F...
[email protected].....\...........Nb4..R.5M*.W....;...'...??;./.??. ..Hq.!...l\
.O.([email protected]..}.Q.G.'F.ga.p......q.ss..>.&. .,.'?.?...4.....
.V..[V@..._..)R._P.[JHPN.WN^..W......._c....-.....i.g.h..z.>......O
..fa...........m..d . '.%.........r.q........P.k..o..._u.SS.Y.O......S
...............4.#...@D........^H.O..7CAB~2$...TTT..44tt44.?..........
..1&:..?=.o.c/.....`[email protected]@.Cx..|y.../..]DPP..1..0.r.<..OO...$.Q..
.q....HH.....(hX...%!............h^`X.s...%z..Y(m.&N.........|.l......
.@..@@z.DCCDADFC.C.....\.RZ.(.o......*...~...}...........L..........9.
S.xHx....#` ...p..s.e~qs.....c.}..h.:..?p=...`n..S...I.Ak.B"F.^.......
`x20o..l.l.F..\..7/.g.......#@.w.v. ......=.....P..w).....C.......<<< skipped >>>
GET /lyrics/img/kwgg/adv4839/1473242698107.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4839/index.htm?ver=
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:44:07 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 27995
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "14501c2-6d5b-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:59:25 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1752
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS.I...x....T\..-.....Nph.Bpm.%..4....%.C#..Bp.................w.{..o
..c.Z..]5..W....{.@.{.%.@.....|..F..D]-..5.e.... n./Ob.6......^^^.^..N
....BBB.\<.<<./..n>.w3ov....8.?..-.......N.......<..hi.
.....?h!n.f.N...`'GNo3gNn....x^...\-...\.....%....u0s..Vsu..ts{.7s....
.f.6..u....r.r.g..pYJ.\.<\[email protected].~a^ ..0...`.-...*..f.f.f...
....y.........\....r...dak.....g&.(..R..O[...H.........sZ:X:ZB..^.....
.`a 'WG3wq3gg.[.._....n6N`{/3OKv......g......LE...pGG.....5,...l7-.gKN
.K7'.W..K:../...a......l. -...akk!, .#................................
#.o6i'.._..;[email protected]..,[email protected](--().................
.Z..zZZ..:9.c...\.,.RJ..o..........2.Ks..H...K....?A.f....$ ...-.#..W.
[.......KV...........o6.....59.....IA....O...%...EP.. .....x..........
.2..V..........|.........!.<..4..G.w.. *..l...t.6.|......NZj[.1Z]&g
t;...g)K.[y_WKM_U-..=X..V.....P./e.o{....\........W.......M=.5j)'WKj&g
t;.~v0.......7...P....$.qr.r...C..z$...........!..^!.........h.^.V<
VB|\B/bZ.r....B.B\B..\.<VV@.^^!^..y. <...$.._._R...[.......4/...
..?......V.........b.u..{...8.;..wgj)...:5..-........,"...............
...........x....-........................#,d%h..-.......ss[....q..[X..
.Y..\f.@Z..;....oc.<...,!/~r}1..1...B.,~....y......W.." !.\......(H
H.HH(.(._......x...@G.. ..#....Q.Q.PQ..111...........`....x...........
.z........k(..p.^.....p....f........ x$xD..._........@...../I..n.CG@..
.]../=Q.9..k.5^.....3.-_......$........'p8..i..%.q.h.\>..#..U.h..w.
..n..G.J...@... .x..........'........Ln...Xoa..G...{u.._...(..^.&l<<< skipped >>>
GET /lyrics/img/kwgg/adv4162/_4_1464245796316.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4162/index.htm?ver=MUSIC_7.7.0.1_P2T1
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:44:47 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 32293
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "137170b-7e25-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:54:36 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1068
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS.B...x....P...%zp.`...ppwww?..................$!.}....;w...7.U.U{.Z
.....Vw......=!."..4.......F...........>N.....G"@[.........l.\l.n6.
...... v.../............(J.o...w 7...v.....-,]<=D.....q......l.`.K.
........vN6...t..... ...n........(e.-.m)..\.!....-.)..x)Y)-=..........
=.?iA.... .N.VN. .S..W.$ ...../........_.*............<. ^mNnA.....
L.o..Nw..Y..o.. .R...s...[.....NN..B.{hB...hwm...vM......./...wGEEP...
..... -.w....,...........q..rr.KJI.p.......J.J..B.[....].<. .......
.....RSs....{>.'..<.R.\...\.|2<....|..|.<|.|......R..H.G..
7;/.X.....v....;...D........_A...MR._.....R...,....K......W...........
.[........o...b.8B......r.[b....]..,<D->|p....G.............j.Oz
...W...%...AQJ.......>.......w..4Qr..K....f...v..........&.>.6.R
.G.w.?"...0o..8.0,.0..........6....`a..p.4._.d.$T..",.<.?.El..<.
.,<.",.<2............@....|[email protected]%...Mi...,!..v..2.. m.:X..
.w.W......O/.....<.2.._...R8.[....<...<._..6.....G..|[email protected]
....p.\..J.|..........y...-..@..[.... ..*[email protected]].Wi......Iy.U%..
.*.......>~.......5..<z..6.........?..K.#G.b.....?h>.!.Z...ul
)...]~...3...j...'..>[email protected].............>....mMj.
.3..[T.../V..z.K\.........[m.}.:Q;.wvto........=...v...w.?L...z.p..p..
...G..s....;nM...IkId/i%.&:.........M..........(......Y..\t.N....p."u.
3b.....H....9.....o.js5....!\...._.1.=.........6x..%Y..V..}.2t.......y
*.. .m..![....-ZeT.2q..].$..N................(.......2{^i\...?.S.G..,W
.dP....[.....A.FK..g......J..F.6.'....N...u.X&.. 8.%..m.!A...i....<<< skipped >>>
GET /today_recommend/setCookie2013.html HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: topmusic.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:50:10 GMT
Content-Type: text/html
Last-Modified: Thu, 08 Nov 2012 04:09:41 GMT
Content-Encoding: gzip
Expires: Mon, 12 Sep 2016 15:51:33 GMT
Cache-Control: max-age=900
Vary: Accept-Encoding
Etag: "509b3085-90d"
Age: 633
Content-Length: 896
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-cz-1-1-c1131
Accept-Ranges: bytes
Connection: keep-alive...........V.n.6.}...Q.I^bQ^.b.-...t...H..}....&"Q.EY.....%i.].tX.,..(
.{...!.........3..e.>\.y7.3.....1...S.....;..b6U.....L........z....
m..8...O/......n{z.3.u..:CC...Y'{`.'''...B.cK.:E.z../.X%......M.......
_.Zs...l...t..Y.7.qD.B.0.r{...L....U.....U.....M[E.....y.F...*......a.
...(..j`p?...3.. ....F.oC..6.l....h lTq.n.....ybF...`.~../..(.....,a4]
77.VB........^...A.c.w.H.T...$A0`.....t ...f.,H..&..h.J8.\>b.P....#
.Q`...$_c..>..#[email protected]..)...-.g).y.eM...y..*.....c?.......,....e(.#.
..Vug[P!Z..r.....&..\b......y.i..R.-B..FFX.}-F.gd.h..R...w.i.......y|.
.LZ....:..P...,-...lj...[.,.MPX.R. a..e.5..5EEB.NS.....#..SQBH..}s....
..~e?._^...Wq..~.........V....M.N|.D.C...P(.3.G......K.=...,S.H8......
...IO.\42..g2x..=.Y!0M...7.$x.....C.Y.)X.i.!?..............R.h.....N..
rt....Ze.&clV.!X[[email protected]..%\..k
...p.~Ht.].|....v-...g..C...=N.....C.A{vOe..~....?..[a...... ....HTTP/
1.1 200 OK..Server: nginx..Date: Mon, 12 Sep 2016 15:50:10 GMT..Conten
t-Type: text/html..Last-Modified: Thu, 08 Nov 2012 04:09:41 GMT..Conte
nt-Encoding: gzip..Expires: Mon, 12 Sep 2016 15:51:33 GMT..Cache-Contr
ol: max-age=900..Vary: Accept-Encoding..Etag: "509b3085-90d"..Age: 633
..Content-Length: 896..Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111,
HIT from utn-cz-1-1-c1131..Accept-Ranges: bytes..Connection: keep-aliv
e.............V.n.6.}...Q.I^bQ^.b.-...t...H..}....&"Q.EY.....%i.].tX.,
..(.{...!.........3..e.>\.y7.3.....1...S.....;..b6U.....L........z.
...m..8...O/......n{z.3.u..:CC...Y'{`.'''...B.cK.:E.z../.X%......M<<< skipped >>>
GET /lyrics/img/kwgg/adv4839/1473242698107.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4839/index.htm?ver=
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:44:07 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 27995
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "14501c2-6d5b-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:59:25 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1751
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS.I...x....T\..-.....Nph.Bpm.%..4....%.C#..Bp.................w.{..o
..c.Z..]5..W....{.@.{.%.@.....|..F..D]-..5.e.... n./Ob.6......^^^.^..N
....BBB.\<.<<./..n>.w3ov....8.?..-.......N.......<..hi.
.....?h!n.f.N...`'GNo3gNn....x^...\-...\.....%....u0s..Vsu..ts{.7s....
.f.6..u....r.r.g..pYJ.\.<\[email protected].~a^ ..0...`.-...*..f.f.f...
....y.........\....r...dak.....g&.(..R..O[...H.........sZ:X:ZB..^.....
.`a 'WG3wq3gg.[.._....n6N`{/3OKv......g......LE...pGG.....5,...l7-.gKN
.K7'.W..K:../...a......l. -...akk!, .#................................
#.o6i'.._..;[email protected]..,[email protected](--().................
.Z..zZZ..:9.c...\.,.RJ..o..........2.Ks..H...K....?A.f....$ ...-.#..W.
[.......KV...........o6.....59.....IA....O...%...EP.. .....x..........
.2..V..........|.........!.<..4..G.w.. *..l...t.6.|......NZj[.1Z]&g
t;...g)K.[y_WKM_U-..=X..V.....P./e.o{....\........W.......M=.5j)'WKj&g
t;.~v0.......7...P....$.qr.r...C..z$...........!..^!.........h.^.V<
VB|\B/bZ.r....B.B\B..\.<VV@.^^!^..y. <...$.._._R...[.......4/...
..?......V.........b.u..{...8.;..wgj)...:5..-........,"...............
...........x....-........................#,d%h..-.......ss[....q..[X..
.Y..\f.@Z..;....oc.<...,!/~r}1..1...B.,~....y......W.." !.\......(H
H.HH(.(._......x...@G.. ..#....Q.Q.PQ..111...........`....x...........
.z........k(..p.^.....p....f........ x$xD..._........@...../I..n.CG@..
.]../=Q.9..k.5^.....3.-_......$........'p8..i..%.q.h.\>..#..U.h..w.
..n..G.J...@... .x..........'........Ln...Xoa..G...{u.._...(..^.&l<<< skipped >>>
GET /mbox_data/dataset/Radio/radio.zip HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: down.koowo.com
Connection: Close
HTTP/1.1 200 OK
Server: DnionOS/1.2.1.8
Date: Mon, 12 Sep 2016 15:55:23 GMT
Content-Type: application/zip
Content-Length: 125102
Connection: close
Last-Modified: Sun, 11 Sep 2016 09:11:10 GMT
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 10:07:43 GMT
Cache-Control: max-age=21600
Vary: Accept-Encoding
Via: GNOP013-ZJFYSX-9-190 (DLC-3.0), gnop013-CT-GDST-80-61 (DLC-3.0)
ETag: "57d51fae-1e8ae"
Age: 3278
X-Cache: HIT from gnop013-CT-GZDG-91-68-B.fastcdn.comPK........a. IH...=...&.......radio.confUT......W...Wux.............\.
...8n...w.............4....d.;.]....,.%.,.......?..#.....].g.=.w..S.W.
..w.......N.{........{...g=.8.........G'=;..I..~x......Z...Z ~~Vk..d.V
.AVk..d.v.]/S.A...k..:.....Z...TkP....T.V.A.n..T.V.A.n..T.V.A.n...t...
J.f..4h..J.f..4h..I.f..4h......4=.Y...6k...3...n.....A.C.5.zh..]......
.5.zh...M[.....p..`..a....g...a..^nX....k0.r..L5=...o...o...o..T.Lk0..
..SZOk...<SAMOk.......Y.....rkg.<.t......s.......a.s.'.r..V...Rd
.I.H.uf.#U....tYG.O.ut.l...E..?G.....]4..st.....%u]..1t.".[9.d....)...
K.={:..i...E...K....Es....&w.Q......w?H.......pt..../..x?..4.....I..j&
......y..S......._..L./vj...<..A.....|[email protected]..
.? .....h.....I......]..&!B?H..t9P..t9X.....i.^...I....&!F?x.....j.f..
.I....&.F?......j....j....j....j.z...4........B.~.5.r...$...][email protected]{
.5-....$...a.....&aR?....~t.D...I....&.T?8..R..m.J...Y(...f.T?X..R..m.
J...Y(...f.T......p.P....B.~ 7.....l.:...R.u.Q..n6J...F....(up7.......
.ws...w..,..n......Z.....Xwp7k....f.Z....e.8......n......<.z.EIWG..
.8..K....T].]J......G...8......n.~...Y.9..f..H..M........O....n.~...Y.
9..f..:wV.o..Y...p.~...U....W..:(\....p.~...U....x...........s.....uP.
.?.A.*.\....s.....uP..?.A.*.\....s.w%)]..W..:(\....p.~.w= .\..V......s
.KZ..z......j...]..?.......V.....Vh..p....p.....U....Wa.:(\....p.....U
....Wa....[...lB.up..5...&.X.]t.y...Pc..lB.up..5.........j...M....6..:
8.....`.j...M....5..:...zZ...Pc..kB.u...5.A.&.X...Pc..kB.u...5.A.&.X..
.Pc..kB.u...5.A.&.X..Z.F{...@.}ut...WG.@.}ut...WG.!Cm..Z....x_.;..<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-19625&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:10 GMT
Content-Type: text/html; charset=gbk
Content-Length: 959
Connection: close
Expires: Mon, 12 Sep 2016 15:55:25 GMT
Vary: Accept-Encodingsuccess.-19625.20.20.312359.................1438916071,2317424465.0.20
3534.................2790738647,2014277437.0.3258996.................7
1759785,909094364.0.514219.................3734312670,2024378602.0.989
40...........1205685606,193591165.0.105423...........2799866569,209646
1658.0.1213917.................3678072903,1246967123.0.1953570........
...........3531519060,2233693186.0.82703.......&................805433
142,4092762143.0.58606.........................3028619977,1601918608.0
.263027.................2197293702,3515686233.0.3195883...............
3092025724,257604845.0.280866...................3632894872,1935809588.
0.279153...............1278005477,3633202934.0.496818.COLOR&..........
......19528357,955177676.0.79499.............1640922867,3351346056.0.3
25263.................3576079539,3679031028.0.2863569.................
....3733891140,450585126.0.927080...............3226382792,2696785999.
0.238814.................2401970589,2942671494.0...
GET /ip_domain HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ipdomainserver.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:56:01 GMT
Content-Type: text/javascript
Content-Length: 56
Connection: keep-alive
Set-cookie: ad_dist=;domain=kuwo.cn
Cache-Control: no-cache
Vary: Accept-Encodingvar _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}HTTP/1.1 200 O
K..Server: nginx..Date: Mon, 12 Sep 2016 15:56:01 GMT..Content-Type: t
ext/javascript..Content-Length: 56..Connection: keep-alive..Set-cookie
: ad_dist=;domain=kuwo.cn..Cache-Control: no-cache..Vary: Accept-Encod
ing..var _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}..
..
GET /ip_domain HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ipdomainserver.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0; ad_dist=
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:56:04 GMT
Content-Type: text/javascript
Content-Length: 56
Connection: keep-alive
Set-cookie: ad_dist=;domain=kuwo.cn
Cache-Control: no-cache
Vary: Accept-Encodingvar _ip_domain_="";try{cbDomain(_ip_domain_);}catch(e){}..
GET /today_recommend/tool_new/167.gif HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/gif
Content-Length: 1574
Last-Modified: Wed, 11 Apr 2012 02:10:17 GMT
Accept-Ranges: bytes
Cache-Control: max-age=86400
Vary: Accept-Encoding
Etag: "4f84e809-626"
Via: JSTZ_24_148 (DLC-3.0)
Date: Sun, 11 Sep 2016 22:35:42 GMT
Expires: Sun, 11 Sep 2016 12:01:52 GMT
Age: 80008
Powered-By-VeryCDN: HIT from cuc-xg-1-2-c1112, HIT from utn-jn-1-2-c1132
Connection: closeGIF89a(.(......I.D.t..U/[.f.d|...S..0.v..R#..H.E!...L9#....V...`..e.e*
....].&k...h...s.[..=....Ek.Y"....e".o..v...SMG*i.TeS1.j5".9...U.E..P.
p.7(F..}..j.{".v:Aj6..&..7..f..PfSF.R..h......}.E....$b.zrDU=D..r.y;..
o"Y...&i>q.....a..u..x.M......[q;.*:!Peu.H...F.#..wN.W,\.JL.;BNeC .
}[email protected]/.V.(.@`vB...qaB..{.;...z.x1.....!.b &...^ 4.2.......b..
[email protected],{...|o?%.{..A.....z........a....!.......,....(.(....
..|.........qz.......q.z'x.......'z|pz{.......zp.....{..oIDa!%>y...
..........D5R4....4.6......7.D.W)....d-aQ>D6..........VN....V5R....
B.."`,1...."]>..6.N.xD.......&=z.H8..I...T........\...I....4H....%K
[email protected]..@...[...X.I../.dP."../#..][email protected].#!
.....ha.FZ..>.8"FI..8tx...re4h<.Uq'J. ..D0.A.a.L.0.7#H...x..r..d
.*.php....fv...#1..m:. `.H.#..... J.-..p..AD...Y...#......a..y.$.a`...
[email protected].%....`..gi. .4........F..h...l$H.sH.....b!
..w...... C:`[email protected]...."..Hq.A.?d....d.C......C.@d.&R0N.b.
...aQ...N....`. ..*.`..g.1..B....a.a..(.`..k:.C..b...*dp..\..d.'......
...^.zh..F.(.h.0...R....t....(PB.8$ ..l.A..`<....p.....@.......'.J
.\..........>.....`@....Q.'.........Wl.E..f.A.b.P...,...PH....Bk...
[email protected].!D.MD.&..pa1.@.;...3...'$........
.TPG.[..............!..D.6....9'....x./.<[email protected]/`@.,.y..v....V.
Q..O0q..h4.v.ul.&.J.a..9.6...L.s.W....O.1..i..C..s c.P.1..A\`F[...:.7H
Ny........iN.A.<....Q....>y.7.>y..3....w.....a...3q..........
..a..y..Hph..=.@D....}..woyT.sp..JH......}..........@.. ......1...<<< skipped >>>
GET /today_recommend/images/201609/1473320578232.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:39:29 GMT
Content-Type: image/jpeg
Content-Length: 56219
Last-Modified: Thu, 08 Sep 2016 07:42:58 GMT
Accept-Ranges: bytes
Expires: Sun, 11 Sep 2016 17:04:09 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 85160
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-jy-2-5-c1131
Etag: "57d11682-db9b"
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
.................!.1A..Qa".q...2B....R#.br.3.t.7..C.5u.6.....Ss$4..Vv.
..c..8...DT%.U.....................!.1A..Qq2".3a....B#..............?.
.T....................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
....................................P.................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
.............................6....#.v.nP.q_.*......R. .......ZJ...<<< skipped >>>
GET /interface/mc?mcid=1245 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: mc.funshion.com
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx/1.2.0
Date: Mon, 12 Sep 2016 15:55:19 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
Vary: Accept-Encoding
Cache-Control: no-cache, no-store
P3P: CP="NOI DEV PSA PSD IVA PVD OTP OUR OTR IND OTC"
Pragma: no-cache
Set-cookie: _mc_uuid={"uuid":"4e1201f0790111e6af1597a0533ad8a0"};expires=Sat, 12 Sep 2026 15:55:19 GMT;path=/;domain=mc.funshion.com;
Content-Encoding: gzip
Set-Cookie: __sid__=; Expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.mc.funshion.com14........................0..
GET /vip/zadan/index2.html?13118169329556000021010 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Wed, 03 Feb 2016 09:57:25 GMT
X-Server: ecomserver47
Content-Encoding: gzip
Vary: Accept-Encoding4bc.............Y.o..........X...K.-P..Y...qd.....cu.$.>......G@...
.&..8nQ.ic.M.........?cR.....}.-.G.&.j...ggfw~3.;;W:......g.Q.5..#G~Q.
/..^.l...$....*5.....0".l5Y..I ..e........>....RV..1.7H.rHd.4`..,d
..#.h...".Q..e.r...U..2.Y.rdM..rX*5.S-.".....2ba.Lq.A..8.W..[..x......
7ae.x..U<..g.....:q..-....II........Y..h.3?.p.,.Nq.................
.XM[...oG.....er..t9./.q..D.p.3...B...'f.D#Y.@JX/....f,4..`V...&l....L
..IH........i..8..A......EdU...kL.#........b:v]...t]p.!.ppG../....6."`
.n.w..e.f....@Lj7|.O...B.e..=...CDDM..6eu.p.A.2.."4..d....`.B.XH.....
.STA4.cX...N"..HQx.....YlNF.5...D.?.'.....0...E6....x...Eh..B5......C.
...s.R......O.z.0..H&...&...QMQd .y.R....EI.c1.C....E'....tI...v.G~.Y.
.h....%U.........*..&".Yq...G.o7!....a.46.}.....y.tk...;.....l....}...
..........O.....b....;.a ......aqv.0.... g...,mMY.k.>..o......i=X..
...`8...YBB[.%^.b..FG.dB../..xY.....x..L.&..r./j..Z^[email protected].[.....U.
.~....pi..x..r..;zkH.D..p....2M...g..-...._....D.j.P<m..Y6m..z.._..
....;w.............7.q...~.......o>.4..Y....G..C6."....$V..a..`.t..
......A.E.l@(z...J.....K....<H...q.......q..#V...h.....AW..bA..S|..
..aw...'Oz.o..}.{..!r.6...........x.....U9..{..I.. .....w...xY0.2.[.&.
\~<..O...\:]YX....K0a1.6......ba...... .....W^._..46a..Z.N$../.R")M
/...i.?....2n}..A...X1...J..\!.p'!....EVCW.TFm..i...8.7o.c...........
#y......i..I7CW....!.....V.......k.Ky`.....K. J'`.h1j)......b..1..T...
.b4.p..D(.c....N)..v.v8.4.jx..j..B2..&?|.#..?.3.. .39..s:).S.....tCR..
....z!.M.......d4U.m'.v.l...p.U..j..0jgJ.....N...k.~..}.v..4.4..@B<<< skipped >>>
GET /vip/zadan/js/swfobject.js HTTP/1.1
Accept: */*
Referer: hXXp://vip.kuwo.cn/vip/zadan/index2.html?13118169329556000021010
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: text/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Tue, 30 Jul 2013 06:05:52 GMT
X-Server: ecomserver46
Content-Encoding: gzip
Vary: Accept-Encoding4b5.............Z.w.8..... ....c......yI.v.m..Iw..{O......&4K...3.....
...[.ei$.f>............Vxi...9....t.j6....(.F..x..9k&.a$;6..... ..b
"x"..<.E\K..vq~]..x"LD.i.X8..M.<......DuI.. ....l<.........O.
...K.(4.%.x...n...7...jM.}...q..-......dl....d..w.=~c.....Ns4..&......
.22..}...a...c.0...HR..o...0.K..B?Z......T.......#.F.}..|.......v.z}..
}.....b..'...........4...b]....a&.a.....l"h...s.......KN.......j...I..
.W6....'">.A..F....Oq..ew.n6..0..k..`..&..tR..f.j......G=.. .(.d.!k
....Hu.4..x..w...&.;....0..q^..7M..o.7.>.#.y..i.....j)..l.a....6...
...}..X8.L........GA....7.........m././.fdF$.....B.4..k...........V...
..D...2,ky-O..*.hcj>.(.&.......g..w..z{}&.v.Bk.A....q.%..{....j....
....A.}......w.......6fv^d].$/;%[email protected]..../\.R8.k.......B..U:..Z
R..<".;.E......i<..q.#[email protected]....'...`[email protected].
.....]k...H.q.\.lqn..[|d/.Z|h....p...6.......vWvz.z..Y...J.......&.HW.
H.v.......D.......a4.,.I...1....e...x.........`..U:.[....=P.c.."..<
..f.x{yq....~..O.>...K..N .ul.^@...{c)..n....>.U..Ey..G........V
.6...q.X....Y...im..A..v..x...h21...........H.......6....Ri..-B.yq...
e7....cv....*......s..M(C....EgZ.;y]....8..".O...7OM#.q....:.......XL.
{..t3.q.....L..e....G....cRS...;.n..hX.o.N.../.g..W.w.Bb..b88....^&...
R..!..8[..r..q.8...d...\....X...,_.R`^. z.._.3.;.|..C.'.]:.];.RF....!
E...=:@.....2.../.n..h..z.?..y.`1.f......8M.`0O......7K..2.bW0..Y.jf.k
n..y........Vy.-6.IP.pf..WX...s.0..%...i)@k.X...!Mt.... (.....'....2o.
8z..3....k..!...\K.6..a..|u\..L.:....0;.e2.<.$.q.~...C"U!t.LR.<<< skipped >>>
GET /vip/zadan/ShowEgg.swf?94766.17852897952 HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://vip.kuwo.cn/vip/zadan/index1.html?13118169329556000015247
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 27569
Connection: keep-alive
Accept-Ranges: bytes
ETag: W/"27569-1441692557000"
Last-Modified: Tue, 08 Sep 2015 06:09:17 GMT
X-Server: ecomserver47
Vary: Accept-EncodingCWS.-...x...y`SE.7~g....I.&..BA."k...VA..P...-.R.4K..4...@].D........"
. ...-../..........9so....~......Y..93s..9g....!..=.I.\.%I:..kL.N..B..
.....".D1j..7&....F-Z.h..cF....F.x.......3f.(F$Z.I.....Q........<..
...n...c-.q...\..4...xD...G.#..`4..5z.h0...C.x./9......}.n........"...
.P..h<yT.!.I......@.>.......u.t........&:>c.>.=..k.....Z..
S..D.......>.N4...[....E..]X.....d.;E.G.._......_Z!..u1G_28.*....q.
).}.1.B.<. a....xi...|.4.wvv.n.....b..tI..|...^l.....pTz&..(I.K...)
8ZrJ#...8....D.d...E..6.........?{...k...,....N....N..*).c...*..G..b.F
.......Y*Z...q9.M..1..D0> .M.."A_T-..}.....X..b....E..&.}Z...l.e-Q?
.....{...U...q..e...'.#`V...'.J..t...Ih.%...g....FmF0...n........*..h.
&.9S..gT%}...1..x.!.L.5%.\..AMs...L..@m./...G.....%..$.....X.Bu.jQ...(
....1c!.f.A.u./.#B.%......'bQ}j...:. .U...f.l.c-..!..h(6 ....s....`4..
..B....zh........J...)....X..e1jY....27..V..[..N.....Y.G..:........PG.
1.._4.Q..3=.....6o..Bp.Fg...$..[0.P...b.Q.......g.O...')...g..y'.W.V..
Q.N*......,..$.,.#..0...Wl....t..p.../(mh.u.s...L.&'.......yvz.....5.g
.I..Zd..R%{<.F.[ieZ,*v.r..6.....B.h....*..E.c.............9..L.F[fb
.=L.d..XnKs..wye.).....s.9....%q.85..DY,^....u...ey.........%}...n....
..r..d<.J..wpkqf..0.......5.............t?>......Y...8..@...{.F.
=..*.F....%.=..Ekq.UM$}...H........(i3...0m.f.^....}l.a!..F;......kj..
....7..?......)..,A9.F..MVq.E..%.5'.J.....6...^.......Z......F....V...
.....W..-vj...i.......KM.8.`.V .D.A.M"Uj.q82...a..B...(....d........G.
Q.hV......4."c.......u--...]Z.U...Z...M...XTx;b...m.F..OI....rA..~<<< skipped >>>
GET /pic.web?type=startup_pic&date=20160912&duration=7&from=pc&wallpaper=1&width=1276&height=846&ver=MUSIC_7.7.0.1_P2T1&id=6424671&uid=&name= HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: artistpicserver.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc:kuwo_jm429.exe&id:6424671&reqsrc:CWallpaperDownload::LoadServerList
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:18 GMT
Content-Type: text/html
Content-Length: 2755
Connection: close
Vary: Accept-Encoding{"result":[{"album":"y/mwrtK7yfo=","albumid":"MTMwMzE1Ng==","artist":"
vKq/y/bB0t0=","artistid":"MTEwNjMx","date":"MjAxNjA5MTI=","hasecho":"M
A==","height":"NzY4","id":"OTU2MDg5MQ==","mvid":"NzU1MzI2","name":"y/m
wrtK7yfotKLXn07ChtrTzu7DO99POM6G31vfM4sf6ufrT77DmKQ==","nsig1":"MzMzMz
UyMzQxMA==","nsig2":"OTIyMDQ5NzM0","path":"aHR0cDovL3RvcG11c2ljLmt1d28
uY24vdG9kYXlfcmVjb21tZW5kL2ltYWdlcy8yMDE2MDkvMTQ3MzA1NTYzNjAyNS5qcGc="
,"width":"MTAyNA=="},{"album":"vNLT0NCh0ak=","albumid":"MjMyNTM=","art
ist":"0e7Xzw==","artistid":"NDg0NQ==","date":"MjAxNjA5MTM=","hasecho":
"MA==","height":"NzY4","id":"Mzk1OTQ0","mvid":"MA==","name":"0KHRqQ=="
,"nsig1":"NDE5OTc1MzIz","nsig2":"Mzk2ODQ1MDk2","path":"aHR0cDovL3RvcG1
1c2ljLmt1d28uY24vdG9kYXlfcmVjb21tZW5kL2ltYWdlcy8yMDE2MDkvMTQ3MzMyMDU3O
DIzMi5qcGc=","width":"MTAyNA=="},{"album":"yLzJ1Q==","albumid":"NzEx",
"artist":"y /pqg==","artistid":"ODA=","date":"MjAxNjA5MTQ=","hasecho":
"MQ==","height":"NzY4","id":"ODU5NTg=","mvid":"NDk3NjQ=","name":"yLzJ1
Q==","nsig1":"MjQxMjM1NzYwOA==","nsig2":"MTQ5MjkxNzM2Ng==","path":"aHR
0cDovL3RvcG11c2ljLmt1d28uY24vdG9kYXlfcmVjb21tZW5kL2ltYWdlcy8yMDE2MDkvM
TQ3MzMyMTMzNDkyNi5qcGc=","width":"MTAyNA=="},{"album":"vei4 dHM","albu
mid":"NTU5ODU1","artist":"xuvH2A==","artistid":"MTM4Mw==","date":"MjAx
NjA5MTU=","hasecho":"MQ==","height":"NzY4","id":"NzE3OTk5NA==","mvid":
"NzQwNzIw","name":"vei4 dHMLSi158rTvuehttfztvqht9b3zOLH ik=","nsig1":"
MTA5NTM0NTE5MQ==","nsig2":"MzYzMzg4Mjk3","path":"aHR0cDovL3RvcG11c2ljL
mt1d28uY24vdG9kYXlfcmVjb21tZW5kL2ltYWdlcy8yMDE2MDkvMTQ3MzUxNjgyMTI<<< skipped >>>
POST /uc/s?m=28;QigwPyAsMRdXUktcR14xcEsxVEBJQw1PFwMMCw== HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 0
Host: config.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc:kuwo_jm429.exe&id:6424671&reqsrc:ConfigUpdateThread
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:24 GMT
Content-Type: text/html
Connection: close
Content-Length: 6616W0FJUlVJXQpJc0FwcGx5PTAKW0Jyb3dzZXJzXQpCcm93c2VyQ291bnQ9MwpCcm93c2VyUH
JvYzE9Y2hyb21lCkJyb3dzZXJQcm9jMj1maXJlZm94CkJyb3dzZXJQcm9jMz1pZXhwbG9y
ZQpbRFlUXQpBbGxvd0R5dFRhY3RpY3M9MQpBbGxvd1BlcmNlbnQ9NTAKQWxsb3dGb3JjZU
F1dG9SdW49MQpBbGxvd0NvcFBQUz0xCkFsbG93VjI9MApbRmlsZUFzc29jXQppc2NoZWNr
bWJveD0wCltGaXJld2FsbENoZWNrXQpDaGVja0hvc3RDbnQ9MwpDaGVja0hvc3QxPTEwMD
g1MjA0ODQKQ2hlY2tIb3N0Mj0zNTQ2NTU4NzM0CkNoZWNrSG9zdDM9MTAwODU5MTUzMwpb
R2FtZVRvb2xzVXBkYXRlXQpHYW1lVG9vbHNVcGRhdGVTdkRhdGU9MjAxMi4xMC4xOApHYW
1lVG9vbHNVcGRhdGVTdk51bWJlcj0xCltHYW1lc10KR2FtZUNvdW50PTEKR2FtZVByb2Mx
PXdvdwpbSW5mb0FkXQppbnRlcnZhbD0xMApkZWxheT0xNQpudW09MApbS3dETlNdCkFkZH
Jlc3M9NjAuMjguMjAxLjQ1ClBvcnQ9NTMKW0t3TWluaVNpdGVdClN0YXJ0TWluaVNpdGU9
MQpbTGlzdEFkXQppbnRlcnZhbD0xMApkZWxheT0xNQpudW09MApbTG9hZGluZ0FkXQpzaW
duYXR1cmUxPTIyODA5ODk1ODMKc2lnbmF0dXJlMj01OTE3MDYwMjIKdXJsPWh0dHA6Ly9w
YS5rdXdvLmNuL21ib3hfZGF0YS9hZHZfemlwL211c2ljXzUuMC4xLjJfQkNTMi0xNi0wOS
0xMi0yMy0zMC56aXAKW0xvZ01zZ10KTXNnTnVtPTI1Ck1zZ05hbWUwPVVOSU5TVEFMTApN
c2dJbnRlcnZhbDA9MTQ0MApNc2dEYWlseVRpbWVzMD0xCk1zZ05hbWUxPUlOU1RBTExfU1
RBVEUKTXNnSW50ZXJ2YWwxPTE0NDAKTXNnRGFpbHlUaW1lczE9MQpNc2dOYW1lMj1GSVJT
VF9HRVRfTFlSSUMKTXNnSW50ZXJ2YWwyPTE0NDAKTXNnRGFpbHlUaW1lczI9MQpNc2dOYW
1lMz1SRVBPUlRFUlIKTXNnSW50ZXJ2YWwzPTAKTXNnRGFpbHlUaW1lczM9MTAwMApNc2dO
YW1lND1QTEFZX01VU0lDCk1zZ0ludGVydmFsND0wCk1zZ0RhaWx5VGltZXM0PTEwMDAwCk
1zZ05hbWU1PVAyUF9LV01VU0lDCk1zZ0ludGVydmFsNT0wCk1zZ0RhaWx5VGltZXM1PTEw
MDAwCk1zZ05hbWU2PUNIQU5HRV9TS0lOCk1zZ0ludGVydmFsNj0wCk1zZ0RhaWx5VGltZX
M2PTEwMDAwCk1zZ05hbWU3PURPV05fTVVTSUMKTXNnSW50ZXJ2YWw3PTAKTXNnRGFp<<< skipped >>>
GET /today_recommend/images/201609/1473518690014.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 14:57:53 GMT
Content-Type: image/jpeg
Content-Length: 49708
Last-Modified: Sat, 10 Sep 2016 14:44:50 GMT
ETag: "57d41c62-c22c"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 17:05:42 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 12391
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
................!.1A..Qa.q."....2...B#...Rbr3.......$.5u.6v7..S.4Tt.V.
GCcs.%.8...D.Ue.F......................!1.A..Q.3."2.Daq.RB#...........
....?..T....................................................&.........
......................................................................
.................................J.P..................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
................................................n..`A.7..,.........@h3
>h.....d....p...7.Qm....g...I.>..._.V,.....d..c.X.....c.]...e..D
...E0.v^....>...o!R....O...%..l....................................
.....................................................................k
7^..v..76...UXs.....@.{..^.....%.._.vm...0r..N.{...VG.wG./.... ......r
...0.xt.9]....^.:..o "Y{......9.S.......(......j..W.R=1\..]...W.db<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6007&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:12 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1105
Connection: close
Expires: Mon, 12 Sep 2016 15:55:27 GMT
Vary: Accept-Encodingsuccess.-6007.20.20.7192493...................63427122,3835846420.0.71
93440...............1392816205,3496579603.0.7190414...................
......1198874255,1035541931.0.7189892.................4051100874,18028
80965.0.7187928.................3999431891,1827885286.0.7188045.......
......712876572,1908876153.0.7187925..........Jaiho.1563882797,3730134
231.0.7187128.G.E.M.....................3264621468,1598674718.0.718612
7.....&......&......&............495620052,2212332008.0.7186112.......
&....&SING....&..............544557511,1843606841.0.7186129.....&.....
...........3492252882,1803534795.0.7186125.......&..............381917
7224,843281173.0.7186126.......&....&......&....[..........]......2241
36793,3615237464.0.7186128.......&..........4278459077,3194522365.0.71
86130.................253048455,3342949114.0.7182616..............-(..
..................................).1731802010,159511408.0.7183671....
...................2930647947,1150973466.0.7183589...............99313
4774,3210322186.0.7183005.....................1954346820,2331208614.0.
7183264.....[........]..........1010009390,967658182.0...
GET /vip/zadan/index1.html?13118169329556000015247 HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Wed, 03 Feb 2016 09:57:19 GMT
X-Server: ecomserver46
Content-Encoding: gzip
Vary: Accept-Encoding485.............V]k$E.}.a.C.@w&....Yd>.aM$.......P.].].............
HV....AT$. . ...$..oUuO....d...S....TU....}p...&.T......P.PL.p.i...._.
Z..*....I...*...v.K1.......a8t.k=)%..a.JO.L1.b..T...`dc... )..>..,.
>>..rN$^...m.7....(....}4B....4.v>.,.n..7 L.P...DN.. O=.-.L..
.?.jw...l.\RAB`.3R2a!Q\8......s....K5...z..R....m|.#^H..........z....@
.w..j...%[email protected]...$1V.n%4....
$..wK..HL...}=..I..b .ch..) t........G.....2.s.8.x..8.."..^.0..!..#).C
...2...LEhk..f.KC..@..{$..7.......f.,../...*.^.g.:..R.z.[.E..x..V.....
7._.}.......bl.RA..`.N.Y7..lk..&...;7....yB.C..FAv_U.wL.V"..b.4.....;|
.h[..Si....R..d.V[......y.p.-......R.....#.....:G.$5...6......-l..%.^]
~...._......7.^\=.....gO.g........g/..../.$...T..2PEE[*.[k.-..d....#..
.6....f.@D}....... g.E[...{h..!2....!.S.VV..L0._..fp...5G.5[........ .
..jUG.....ojb..n.>.\.i...~..-.......)1...Z'...8........OY>',3.1.
Y...5o.*..c~...G...i.....e.o..ts......?~u..w...~?..u.....'.......%~E.U
..SJ.....f.....d.?,.\2.?r..... .......N...,.........tK_.]4.......0R}..
^. ......G..i:@..%4!.....f._....w.Pc.....b..y..Gk.....0..l}HP$h0..RY.u
..p.....x.......-........o.....)g.C...Cf.p!..a.V.A....o.|........0..
font>....
GET /vip/zadan/js/swfobject.js HTTP/1.1
Accept: */*
Referer: hXXp://vip.kuwo.cn/vip/zadan/index1.html?13118169329556000015247
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:20 GMT
Content-Type: text/javascript
Transfer-Encoding: chunked
Connection: keep-alive
Last-Modified: Tue, 30 Jul 2013 06:05:52 GMT
X-Server: ecomserver47
Content-Encoding: gzip
Vary: Accept-Encoding4b5.............Z.w.8..... ....c......yI.v.m..Iw..{O......&4K...3.....
...[.ei$.f>............Vxi...9....t.j6....(.F..x..9k&.a$;6..... ..b
"x"..<.E\K..vq~]..x"LD.i.X8..M.<......DuI.. ....l<.........O.
...K.(4.%.x...n...7...jM.}...q..-......dl....d..w.=~c.....Ns4..&......
.22..}...a...c.0...HR..o...0.K..B?Z......T.......#.F.}..|.......v.z}..
}.....b..'...........4...b]....a&.a.....l"h...s.......KN.......j...I..
.W6....'">.A..F....Oq..ew.n6..0..k..`..&..tR..f.j......G=.. .(.d.!k
....Hu.4..x..w...&.;....0..q^..7M..o.7.>.#.y..i.....j)..l.a....6...
...}..X8.L........GA....7.........m././.fdF$.....B.4..k...........V...
..D...2,ky-O..*.hcj>.(.&.......g..w..z{}&.v.Bk.A....q.%..{....j....
....A.}......w.......6fv^d].$/;%[email protected]..../\.R8.k.......B..U:..Z
R..<".;.E......i<..q.#[email protected]....'...`[email protected].
.....]k...H.q.\.lqn..[|d/.Z|h....p...6.......vWvz.z..Y...J.......&.HW.
H.v.......D.......a4.,.I...1....e...x.........`..U:.[....=P.c.."..<
..f.x{yq....~..O.>...K..N .ul.^@...{c)..n....>.U..Ey..G........V
.6...q.X....Y...im..A..v..x...h21...........H.......6....Ri..-B.yq...
e7....cv....*......s..M(C....EgZ.;y]....8..".O...7OM#.q....:.......XL.
{..t3.q.....L..e....G....cRS...;.n..hX.o.N.../.g..W.w.Bb..b88....^&...
R..!..8[..r..q.8...d...\....X...,_.R`^. z.._.3.;.|..C.'.]:.];.RF....!
E...=:@.....2.../.n..h..z.?..y.`1.f......8M.`0O......7K..2.bW0..Y.jf.k
n..y........Vy.-6.IP.pf..WX...s.0..%...i)@k.X...!Mt.... (.....'....2o.
8z..3....k..!...\K.6..a..|u\..L.:....0;.e2.<.$.q.~...C"U!t.LR.<<< skipped >>>
GET /vip/st/GetBeatFlashUrl HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://vip.kuwo.cn/vip/zadan/ShowEgg.swf?94766.17852897952
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: vip.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:21 GMT
Transfer-Encoding: chunked
Connection: keep-alive
X-Server: ecomserver47
Vary: Accept-Encoding2cb..[{"id":5,"start":"2015-04-02 00:00:00","url":"http:\/\/img2.kwcdn
.kuwo.cn\/star\/upload\/3\/3\/1404128033575_.swf ","end":"2015-12-31 2
3:59:59"},{"id":7,"start":"2015-04-23 00:00:00","url":"http:\/\/imagex
c.kuwo.cn\/kuwolive\/swf\/redPacketPaoNan.swf","end":"2015-04-23 23:59
:59"},{"id":4,"start":"2015-03-31 15:00:00","url":"http:\/\/img2.kwcdn
.kuwo.cn\/star\/upload\/15\/15\/1404284342783_.swf","end":"2015-04-01
23:59:59"},{"id":6,"start":"2015-03-04 15:00:00","url":"http:\/\/img2.
kwcdn.kuwo.cn\/star\/upload\/3\/3\/1404128033576_.swf ","end":"2015-03
-05 11:00:00"},{"id":3,"start":"2014-07-01 15:00:11","url":"http:\/\/i
mg2.kwcdn.kuwo.cn\/star\/upload\/15\/15\/1404284342783_.swf","end":"20
14-12-31 15:00:16"}]..0..HTTP/1.1 200 OK..Server: nginx..Date: Mon, 12
Sep 2016 15:55:21 GMT..Transfer-Encoding: chunked..Connection: keep-a
live..X-Server: ecomserver47..Vary: Accept-Encoding..2cb..[{"id":5,"st
art":"2015-04-02 00:00:00","url":"http:\/\/img2.kwcdn.kuwo.cn\/star\/u
pload\/3\/3\/1404128033575_.swf ","end":"2015-12-31 23:59:59"},{"id":7
,"start":"2015-04-23 00:00:00","url":"http:\/\/imagexc.kuwo.cn\/kuwoli
ve\/swf\/redPacketPaoNan.swf","end":"2015-04-23 23:59:59"},{"id":4,"st
art":"2015-03-31 15:00:00","url":"http:\/\/img2.kwcdn.kuwo.cn\/star\/u
pload\/15\/15\/1404284342783_.swf","end":"2015-04-01 23:59:59"},{"id":
6,"start":"2015-03-04 15:00:00","url":"http:\/\/img2.kwcdn.kuwo.cn\/st
ar\/upload\/3\/3\/1404128033576_.swf ","end":"2015-03-05 11:00:00"},{"
id":3,"start":"2014-07-01 15:00:11","url":"http:\/\/img2.kwcdn.kuw<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18892&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:09 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1224
Connection: close
Expires: Mon, 12 Sep 2016 15:55:24 GMT
Vary: Accept-Encodingsuccess.-18892.20.20.6358725.Amy Stroup.Sabotage.4150398161,2727439548
.0.5577271.Toni Braxton.Unbreak My Heart.1487361203,71468181.0.1956298
.Elin Lanto.I Can Do It (Watch Me Now).3248391494,807427633.0.3475370.
Kacey Musgraves.Merry Go 'Round.4136035731,77202208.0.1472429.Brandi C
arlile.Heaven.1486884896,1839088337.0.61314.Michael Jackson.Dangerous.
3834870412,1674463182.0.2782318.98...Don't Stop The Love.3582897282,17
21175211.0.1032732.Carpenters.Yesterday Once More.3619892229,373814897
0.0.451678.Deep Side.Booty Music.3003604809,2820553932.0.6482791.Tim M
cGraw.Felt Good On My Lips.2948759868,2626593336.0.516913.Ronan Keatin
g.The Long Goodbye.2042331938,3401331855.0.3224103........Someday You'
ll Be.132841795,1433866655.0.195627.Backstreet Boys.Quit Playing Games
(With My Heart).3307780193,1103509598.0.4020062.Tom Odell.Grow Old Wi
th Me.538434308,593165797.0.211780.Leo Sayer.More Than I Can Say.11830
19590,141047955.0.2200387.Bob Seger.Beautiful Loser.813021300,17615711
81.0.2442751.The Corrs.So Young.1302205821,645325446.0.1837892........
..Don..t Speak (I Came to Make a Bang!).2882134383,519199098.0.337345.
Sarah Connor.French Kissing.659403508,3971583386.0.356624.Adele.Chasin
g Pavements.1135096756,30739783.0...
GET /today_recommend/tool_new/126.gif HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 10:04:37 GMT
Content-Type: image/gif
Content-Length: 3885
Last-Modified: Sat, 14 Aug 2010 13:33:44 GMT
ETag: "4c669b38-f2d"
Accept-Ranges: bytes
Expires: Tue, 13 Sep 2016 02:13:15 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 83665
Powered-By-VeryCDN: HIT from ctc-nn-1-1-c1113, HIT from utn-cz-1-1-c1131
Connection: close.PNG........IHDR...(...(........m....tEXtSoftware.Adobe ImageReadyq.e&
lt;....IDATx..Y[.d.U...W..uWOwO.\{...0...a.#...)...."E ..O....o. .....
%.$.E..(...`..8......=.[.....~..o.s.z&?.zT.u..g.o.k.o..G.y.....p...G..
E.RA.........w...]L.........t>.F..O%...UGjf...%...p...(~7. ........
g.'/....(...,.|H^.78.J......../(...'_P.k........a..Mb.,.fo*.&'Ms....T*
'(^g._.7.#LG....4.......f.IS5..M..i.z.....=c.{'e...Al..X....A...)D1Y*.
L2Ul.(.. q|.pAJ..H..mC..w...b.i..}YW.H......(c..Z...Q..2....S.#i......
j.A.`..sx.....RMS.$.\...:...H.........\.....Y<.3.z....;B...=.4..8..
(L"h..y9.6..U...'W.|~...S ....`.&r..:..8.[1ql...K.\..7.1.4H...kj..:..!
$..h..(..d.;...$./.,@..B.........$.>......o\..>....52.`{o..^....
...y...id......Q.`..%...U..a.>...*.^.L6.na..YbU2..r....[.Qi..h.....
v...............s.8.\..E5.6L...X...p..F..D........XQ.Bv$...,...".\3h..
.t...)......z.h.&.7.........p.....~.....g..i.z.!.............`s.Z..[.|
.F..j........g.&.q*9.....=.M....Fa....w...OL.r......~..[......t..{.i..
. ...y_..5b....Z.f..,..G......b.1h..5.I..h.....^..Z^?.?......7.....f..
\...s.......7...:.7' L:w...lp...O=b...B..#...-........%.R..'..{....m.L
.g|.........W_...c>^.......p....?.$.........:[email protected]=f.w[._.X...;.
Zd0...odh.......RN4..`...l...YP....,...........y~....2}[../..._..7o...
.....Q..#..t.........`J.G.yG.k;9..j1:D..E#.I.h...o>.....%XU..i.."..
*..\..[.I..,[email protected].=..........Z5.V6...~B....,...... .......n
.A.......#..{[.\.6....\s..S..(.^....1.}.~..?...i.......1~..M../=.....j
.fm..k..X.n.....Pm..g....v..w. ....R#......N....X.......{.9..^.7'.<<< skipped >>>
POST /uc/s?m=37;QigwPyAsMRdXUktcR14xcEsxVEBJQyllLTouOzomIGcmNioqPQ== HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 0
Host: config.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc: &id:&reqsrc:CGetToolConf::UpdateKsongConfigFile
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:55:13 GMT
Content-Type: text/html
Connection: close
Content-Length: 160W05ld2VzdFNvZnRdDQp2ZXJzaW9uPUtXU0lOR18zLjEuMC4wX01CDQp1cmw9IGh0dHA6Ly
9rLmt1d28uY24vDQpzaWduYXR1cmUxPTEyNTIyNDUxMDgNCnNpZ25hdHVyZTI9MjExNTgx
ODE3MQ0KaW50cm89DQoA..
GET /star/upload/9/9/1462442619481_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 27 Jul 2016 06:53:33 GMT
Content-Type: image/jpeg
Content-Length: 90483
Last-Modified: Thu, 05 May 2016 09:59:34 GMT
Expires: Tue, 25 Oct 2016 06:53:33 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4093318
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......d.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:A8714636A712E611A
70DBF253D524260" xmpMM:DocumentID="xmp.did:C6D3BC0212A711E6840CE675DFF
DDB09" xmpMM:InstanceID="xmp.iid:C6D3BC0112A711E6840CE675DFFDDB09" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:AB714636A712E611A70DBF253D524260" stRef:doc
umentID="xmp.did:A8714636A712E611A70DBF253D524260"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
......................................................................
................................................!.1.A"..Qa2.q#.B34....
RbS$U.T5...Cc6....r..sWDd%&V.......................!1..AQ.aq"......2..
....BR#.b3$.r.S...CTs4%...c.D..EU.............?.5....K}b....I..N....@#
B..../...v1M.g.C.[....G.(...oW..3ZCk...%J...........V..n..&$.S......a:
X8.O...N.~...m.....Z.S.%......P.....J.r..sc..... ..!G]....o\.3$a..<<< skipped >>>
GET /star/upload/6/6/1453875830150_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 25 Jul 2016 06:39:23 GMT
Content-Type: image/jpeg
Content-Length: 72789
Last-Modified: Wed, 27 Jan 2016 06:22:35 GMT
Expires: Sun, 23 Oct 2016 06:39:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4266969
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive.....6Exif..MM.*.............................b...........j.(..........
.1.........r.2...........i....................'.......'.Adobe Photosho
p CS5 Windows.2016:01:26 14:37:34............................,........
...,...........................................&.(....................
.....................H.......H.......^Photoshop 3.0.8BIM..........Z...
%G..Z...%G......`.8BIM.%......]E%.t1Y.UQm.V.I.8BIM.:.....w............
..printOutput........PstSbool.....Inteenum....Inte....Img ....printSix
teenBitbool.....printerNameTEXT.......8BIM.;....................printO
utputOptions........Cptnbool.....Clbrbool.....RgsMbool.....CrnCbool...
..CntCbool.....Lblsbool.....Ngtvbool.....EmlDbool.....Intrbool.....Bck
gObjc..........RGBC........Rd [email protected] [email protected]
[email protected]#Rlt............Bld UntF#Rlt............RsltU
ntF#Pxl@R..........vectorDatabool.....PgPsenum....PgPs....PgPC....Left
UntF#Rlt............Top UntF#Rlt............Scl UntF#[email protected]..
.......H.......H......8BIM.&................?...8BIM...........x8BIM..
..........8BIM..................8BIM'.................8BIM.......H./ff
...lff........./ff...............2.....Z...........5.....-..........8B
IM.......p............................................................
....................................................8BIM..........8BIM
..................................8BIM.0....................8BIM.-....
........8BIM...............@[email protected]......
.........,...,.....3.0.0.x.3.0.0..................................<<< skipped >>>
GET /star/upload/11/11/1473639534987_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 00:30:25 GMT
Content-Type: image/jpeg
Content-Length: 29319
Last-Modified: Mon, 12 Sep 2016 00:10:59 GMT
Expires: Sun, 11 Dec 2016 00:30:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 55510
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......F......Adobe.d............
......................................................................
......................................................................
......................................................................
................!..1.AQ".a2.q..B..#....Rb.3$.r..4U.CSc.%....D.6s.T.5E.
V......................!1.AQ...aq"....2.....BR..b#C...S$............?.
[email protected]~l......i3.....-.n3v....P...~...#E..../..U.C....Op..)9N
C. ...y..^A...4u....q.)....l .....=.e.l..r..=.o..f..Bv. .....:>..P.
..c!.!...w......aF...5Y5... .E...Z..n3....\.~*..b.0...$d... j.........
..L.fk_......7...}|..8.\.ca.....8.c.H.%#BG..O] ....6eo.............D..
h..M...D.6.......".....0.X.....D.;tH.7D...D....!.l.h..6Q$.6.$P...D.a4H
...Q ..J@=.Q .n..v.4H....l.R...~.H...../... Wly}..p..?.......#..)H@.*J
.m...D...JB.....m).m.G...D..R...N.&3....Ym%KZ........Y.<n...s?.2.N.
n:..RIH..zx.....?...]O....u.1...s9.....o.n..........<.5_....w9...yJ
.........V..W..ri..1dP......Y8.<.e..N........|.....|...m...(\Wq..*.
[email protected]@,).....v......q......;..AR.Q..l...!GD.#P...\.x.nt.....
...8..R.F.a03.9..'..5...v.-.N....~~.K..v..c.9..6]..\.<....r..x.....
....Kjqi.....<.II.wl&.(...lohz.C^.q.....V..!...V...u.E%....YZw$:5i.
.6...u..0c...zb9...u..l...8.a8...?.$X$..\.0T7-W...m.k...o....w......N.
._&.."w1....H..l..<t......v.z.X..y..r.k..2.....-...;v..@.(...Z$P..Q
!...D........`.G.....P.....e.8.&...QD..`.h..l.H@6.$..e.....D...y.!..(.
..)H@6.$ .<h....*$ ".|(.....$p....j...JB.. .h.@;........ .V. ..<<< skipped >>>
GET /star/upload/9/9/1473064589545_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 05 Sep 2016 10:09:35 GMT
Content-Type: image/jpeg
Content-Length: 17747
Last-Modified: Mon, 05 Sep 2016 08:28:50 GMT
Expires: Sun, 04 Dec 2016 10:01:46 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 625590
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?..%........)...Z..v.........
.Q..%..K#..7.<.....X.X8v....J.....JZ&..Ou.k....? .<F#.S...#...J.
.........m..._wUc......^&.....<O...R.....L.].q.m-..K....{yE...m...[
.a.F`".%.rT......e.........Ju%7:.18zPn4.....K~V.&....[.../../.tD...u..
..M?.....Ckw.=...{.2.-..5.M-........X.....x..Rt..q.W.wwt..w!..%.....F*
.....gy7% j......o...M..V.....z....Z}..kGV.. h..%...h..3h.._d.......6.
.u.2...e.#.N....Y8...{S....v..u......Cq.z'.<V^.-...[.&......o...2.4
mz%H.....;....b.t..W6.]...Z.....f...]_..Y..V.&.K}|..o.O.......c...".\.
...V..S1[X..7..;a.\..........3~." ..`..S.h..d.....W.]......_..:.._:..4
....RZ......m....k......;..h../..SC5...0.....w....,.wb..q.z..<.....
c.F.QI.:\.......k{..w.^.pO....;..M..I%.F.KYr.Y .....t<w[.........h.
...5.........[.;Z..O.m.C-..;..ue}k;c.O.|.dp...2|l9....P.i..&.:..2._.9=
JU...F.Wr.VUh....5jE. kn.]..........4.KC..k.G..t}o.Z..../M......T.<<< skipped >>>
GET /star/upload/11/11/1473645302555_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 02:00:14 GMT
Content-Type: image/jpeg
Content-Length: 227890
Last-Modified: Mon, 12 Sep 2016 01:47:08 GMT
Expires: Sun, 11 Dec 2016 01:52:15 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 50123
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveGIF89a%........................'..6..&..4..'..8!.)$.7#.32.98#4 %. .D..
F).U,.I4.X5.M&.i9.I6%W:&K5*d<%:C'pC.YC [E3ML2hE)vI){Q eJ5vL3jU7uW9i
Q-ua=VSGw[ChWEzdDolRwueE;F.W6.O-.c:.g;.[B.iI.fD.pN.tS.{Y.lQ.lE.rI.ze.{
d..]..Z..t..j..k...................x.l= .T,.\7.a:.T .]B.{U.vQ..}..n\aJ
..a.q<XM({.e...jc;5B...\.\7Q....8..................................
.....................................................!.......!..NETSCA
PE2.0.....,....%..........-%.-- .....................................
.....!.!...%../........................ -9::;;A....................97.
7.('......... ....K.......%..7u..."...R..X-.,Z.n....W/D.B<`0l..d...
..m..j. ..........J........w._.....lf......(...V...0I.4pV...s....S&Xp
....x....-V...r.3.......&ac..<h.....>.J.......P..........4d.....
.p...."..9yj..v.X.2.eT...a.LA`].....Vd`.l.K.1...6.. M.@4..=(..E-..|C3S
..r.m.0....V..:<.X..:.`O......UAmp.d .....%')[email protected]`..QW!4.Y.A./8..
.A.'.P..W.>.........T....#..`.,.........T....V....Zl..V...E.#....H"
..._.-.W.pm9.t.N..j..p.7.`."P#..N..$."SM...?....U.....r..#W.6.Vj...X.
0..[.m.6.p.x$.(Q........0.5'H...iS5.!...0....j..........1...w...1%.UA.
7...*}...m..Y),......&.J#....G....gW=....B.....Gj.`.....l.M7..: ...Z".
)6."...*.....P..h...8........,.U.[.hR...)...%....._.~).~$o.%. ..%a.F.J
N-.0/...k................(....C.1`...:.I.d1..,.!....`..&.j.P).>..A.
...........-......L.".../h.....L.e.../.|....z6.A.\MR.i.\y.moA,...]....
..uZqu.J.O.:. ..>....%[email protected]_i \..].u..0/....&<J...6...T?..6..
.<..F...B|}.j.[o......]....fP..]{-P...g@.#[..K.=.....?.......s.<<< skipped >>>
GET /star/upload/9/9/1371611988633_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 27 Jul 2016 15:11:33 GMT
Content-Type: image/jpeg
Content-Length: 8379
Last-Modified: Wed, 19 Jun 2013 03:19:47 GMT
Expires: Tue, 25 Oct 2016 15:11:32 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4063447
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, MISS from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....d.d.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?...l.(<t.iI...._.o.....Q.
E..uP......c..b.&$E=.6..5....o.7....hzP.j .....9..Z...\Zj...g.....2..@
ahf..1WR..3..,Cq..{.<..&..|..|l.|C../.....f..o.{...$..q...I# .R...;
h.6x}9...>.......~"..}k..mQ.sGt..X..P.x .pA... ......N..aUr...u.o..
.u..Cn..At..I....o,........rU.)...I...c.....o....t{...t...(.r....i.. v
"....N.3..S...Zu?t.e?........x..Yk{..[.)n.tW(....a.......zJ....|^3.:5.
.....].;.t..y.S...O..C...2.5.dN.\]..j.~.|.q.J.J..9......W.1..'...o...
(..W.}wF...M....x#=.`.v7N...S...SfU.........(.G...}/...HA.R.#.....gBs.
..}..u.]O.W....;...~.{.U.o.....8.f8..I..p..R2.T}T.E.Kn...........e.xI5
...\..{....ib9.}.F.{...Pu`.k....(..,.O.z..>/Z....q...P.v....#...c..
......K..7....U.....GG..|5.B|{....y...8...m..e.r..YY.a.....i.N..2p....
...~...|k...E....x".mg.Rk..h.Tg....q.a\.V2..|....c...W..axK.........h.
b.)*9...a.....=..j...........s...=.....4.|...!......2..^(,.g...W..<<< skipped >>>
GET /star/upload/3/3/1380793603683_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 25 Jul 2016 02:37:28 GMT
Content-Type: image/jpeg
Content-Length: 5557
Last-Modified: Thu, 03 Oct 2013 09:46:41 GMT
Expires: Sun, 23 Oct 2016 02:30:56 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4281492
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?...;O%...i..... j..{X....G.c
....z.6.b.Z.d.!...s"......TP.......(<.. ..U.Y.TGu..n.!....Y.52...q.
.2.k.................r;.Z...^BN.).#..iGD7w.SR.!...}...zRi.B-.......>
;{g.GZqw.R].z...kd.d....RH`...-R)..f.|u..oAh...1..&YC...... Q|B..HT.x.
.q..m.":..x....,e...o..Wq...W..*.5......Tk.v.1.-.......^...J.tb...:#ZV
..-...G......9?.e*2K]Q.j.y2...I$..p......vmuc2.'Gy|.R...I.wE-H..[..&".
..#.Wl..1.4..nS.../\w.i...a>..V.l.........W....DKg...7.V..j:.U..K..
.W.....[.G..1..S{.F.#....=....$x...(......}.qpH6.'.<...$bOw:.vX\L.;
.z.^....W..jM...`.tr)..lV...s.=.E._...'G_.x.E...I.....>..BK..g7.Fy.
......d...3P.....s.......p.N....w, E4t....k.H.N..X.7......j.B..5fe*s..
A..5./S....w/....>w.Q\.iN....N.*F...P..E./v..i\.:.;u-...W.]....uo..
.;...C.w.*.....Si....y........K.|......B....vRp.z...{....O...Z.....\rq
[email protected][.."...4..![.r.W....>z.l...(.\t>".....D.m#&l<<< skipped >>>
GET /star/albumcover/300/41/20/3020449513.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 10:08:17 GMT
Content-Type: image/jpeg
Content-Length: 23019
Last-Modified: Fri, 09 Sep 2016 01:41:19 GMT
Expires: Fri, 09 Dec 2016 10:08:15 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 193645
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?.....
.S.,.l..@...]..9a...}k.....$.>..h........a...&B.Sw...J.......a.....
....*e4..\d)K.H.. .z.Io.\C..Dr......U^.Dd..B..Ki.Y.e...Y..N[..........
,P.e.I..._o...h.9>.M......ZtJ.dS......N.J7o.k......S.....0.nn.'..WW
....>[...cD... ......=.......X.,..}NPRU..6{.....G_.T..h..;#8.sE..'z
...K.-cv..4a..H.....<K...n..l..S.....8.cI;jr".k.].M.........g...z..
.M..O..z..o...{T/..[jrt....#... ...{....Tb.2.{...{..9.O.....$...1...?.
4...|..z.O.$...K.Y.......~...{Ts.iR.9O..zV....j.lM....z..e..I.c..cR7..
h...........b...........b.F.0...,....O9....*y......].d.FEKm..s.}..?J..
R.nB9....K6...I.?3z7..?..f.6PYyK.e].g$.......K...QI...*HS..4#!....D...
r....O...<.)$UlD)i#...;V...Ego.G.!.v....k.....4..]*...h.A4.n..K.8..
.y.....S....(..L....l. 4&C.....p...<.....#..N1............8e..DT.,.
.En..Y...y..#...0j..0..&.rF...W.i.h..Z\..5.<..........M$.n.........
.<...u........?.u. ..).=x......S.O..1.V.#.....s............5..V<<< skipped >>>
GET /star/albumcover/300/21/82/526441.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 08 Sep 2016 10:08:52 GMT
Content-Type: image/jpeg
Content-Length: 13929
Last-Modified: Wed, 07 Sep 2016 03:28:08 GMT
Expires: Wed, 07 Dec 2016 10:00:59 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 366409
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...q.
*.y.U]...i..._.G.y..b...,r:....p....<.q..q.Z...i..........c...33..U
O.......CD...5.{y..l....~...\4.`.I...ZM.<.^...X..ho.j.QM. z.....sF.
......'z.x'......b.SN.....r2.rx<...5.g#@[email protected]#9....g.#...
.8.....]..c.27...==.....wm.....51bT.*G......U../,.*Y..r..c......`.)..G
b.i.! ..Oo_..M:`..v.*.p..8 [email protected]...|{...?Z....f....
...D..w....~..~...i....b..............0.k}4..#.anF;.?.G.C.\=...<2)=
....?L.GU#.........t]wN.....m...88...#....3..0.|'.,.\...$.. .F^.......
..t....-]R..2.....z..........(...J..P.R.R..QE..QE...QE.|[email protected]
.. .v..r..]5.....L..:..l.d.1...Z.......<~4.m. .v.9........lj.;{..@.
............{_...\`LYI$p..P7..zu.....N)1.....7#..H.....C.........yl..j
\e.#...P.D`t.J..`x5!\/.4.>}..L..S.J.2x.`v.l..8....M..>=. .......
W^.C/..4....C0......>.$.=....~.#...Kn.....S*....JCl...F...........1
.0....=....g.nP..c.[)... C..B8;.o..UX7...g*z...d...1.JU}..q..R..X.<<< skipped >>>
GET /star/upload/7/7/1444901569447_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 26 Jul 2016 15:32:53 GMT
Content-Type: image/jpeg
Content-Length: 4524
Last-Modified: Thu, 15 Oct 2015 09:32:58 GMT
Expires: Mon, 24 Oct 2016 15:32:52 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4148569
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......F.....yhXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.5-c01
4 79.151481, 2013/03/13-12:09:15 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:39471AFC212068118
3D183E669551FF6" xmpMM:DocumentID="xmp.did:D81D09786A8611E5BED9B4E1DED
859B6" xmpMM:InstanceID="xmp.iid:D81D09776A8611E5BED9B4E1DED859B6" xmp
:CreatorTool="Adobe Photoshop CC 2014 (Macintosh)"> <xmpMM:Deriv
edFrom stRef:instanceID="xmp.iid:a596cbe3-0574-4f31-8e6d-6d422a2b36c4"
stRef:documentID="xmp.did:39471AFC2120681183D183E669551FF6"/> <
/rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket
end="r"?>....Adobe.d...............................................
......................................................................
............................d.d.......................................
..................................................!1.A..Q".a..q2..B#..
b3..$.........................!..1A.Qaq."..........2BRbr.............?
.....u*..6..}km*.&I#Q.J.T.0(....(.U5"..LH.I.....e.. .V.F...J(...w...e.
B..I$..............d...l:W...I0..mP-..Zj.......$.>......T...z2....}
h...6......K6H...*.).Lp...;.UL.!....c-...l?.j.7jka..y.1...?J.V..ib<<< skipped >>>
GET /star/userpl2015/10/13/1473608305185_132026710_100.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 15:50:39 GMT
Content-Type: image/jpeg
Content-Length: 2934
Last-Modified: Sun, 11 Sep 2016 15:30:27 GMT
Expires: Sat, 10 Dec 2016 15:42:41 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 86703
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......d.d..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...(.
..(....{{m..Kyy2.o..wn..S........>/.].....F.|r.R@yn.!;HP...l.ewt..i
6.......].i.)....2.#........$eA.dg......m.B.(.,(...(...(...(.#....W..g
.|9...J.!....M..X.;Tn...d.p6..x.Z./g.<I....n../...G..,8...0.pz.4...
..U..V.V{.d.2........}.....Z.h[`d....J..<q.a.zg..5.WN.e.KB"b.$..<
;}....y..b.s.]..qt.Z~.4w7....mm.....&.X....0...{.....E...Xh....n...{y.
....n2..$c.....A...S.(.V.WS.L.Z,0.Yw4.. ...q.9....3.p-.i..........qd..
.U.@...;Fx.<.w8.4Z..Eg......[..bAo8%D...%H8'[email protected]@..Uk..o4*c..|..
T0^...FKg8 .l...`^X.i.{.....[ ..c....2.....I.....b ....,...d..._..8;\.
Pdgn...U.`2i......M!Y.S..2..d...3.U=7Kh..Yo..[.F..#.f.....P.6.,@)....~
...4u=.R..^..n....|1.......}0.@../...7..^Y.o4P....2.B{e{..........q*..
......$! .v.`[email protected]...\X...y&(.B2.......c......e.9.....Riw.Aes'...,
X(.......0......v..h.<.6.....w@(.X.L2[..Y@/.F.A.`....=m9;.i.-..o..i
:.Iq.W.%.Z....s0....p6.\..G<..-m4.X....m..mQ...J...AGV;..b.....<<< skipped >>>
GET /star/upload/1/1/1473603270577_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:11:14 GMT
Content-Type: image/jpeg
Content-Length: 91217
Last-Modified: Sun, 11 Sep 2016 14:06:44 GMT
Expires: Sat, 10 Dec 2016 16:03:19 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 85470
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.....,.,......Exif..MM.*.............................V......
.....^.(.......................i.........f.......H.......H............
..0221....................0100........................................
...............C......................................................
..............C.......................................................
................,.,.."................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?....0;T..:.....c
#.A....Np9.1..........8.#......2...A.~...eS9...1..r1..H..=.O.}j.'d....
.K..Cw..z_O%....n..y.....V=pp:.9.*P1....3.'.^..c.P.p3.;g.L..r......r..
..q..~=.28.N.........o!.ny.=..zt.....=.z~.m.... .;.:.;...<(,@....A.
...zq....H....$.d....0I8 ..A....f...t.....*...|.eG.......S..b.d.....z.
.....H.......9.....N*UR....A,@.9....r....~.w._..CmYo}o.....dD.A!x.....
{g.{...S. ...I.....9...x.J..8..0.<g......OU.. rq.0.O.`w$`z..Qu.ai..
N...{......9`9''...?.....l....x#........T......Q.....{... .p........9$
.`.....z..'mS~~d%..#...........A... n....8..d.G|.0s.9....|....O8..l.h.
p..I.A....#*9..x..>{.~.....D......$.p.<.x..\..l....rH9.:`..=.*P.
cq..:...s..$..q.pP...z{....:.n.._...a.K.;....o...S....I<../...9<<< skipped >>>
GET /star/upload/3/3/1473517571907_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 08:10:57 GMT
Content-Type: image/jpeg
Content-Length: 90156
Last-Modified: Sat, 10 Sep 2016 14:18:27 GMT
Expires: Sat, 10 Dec 2016 08:03:01 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 114288
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.....,.,......Exif..MM.*.............................V......
.....^.(.......................i.........f.......H.......H............
..0221....................0100...................................&....
...............C......................................................
..............C.......................................................
................,.,.."................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?...kM.u=...V`...
.F4.........G.y%.%....G.....,.(--fd....%.C...W0.HDQ...:....byj.I.....u
%.z\/}}....L...Z....ZJ...\X.h,...L."...R:.k....~..N.T.=.tIdF.....DX.a.
...cH.'Yr....*S.....N..'./y%...mc.b...'...VV....[t.........d6r.J.'.Y .
..c..^.[[email protected]..^.-.O ...O=..d.c.ui.&...9eF.3/4.,..
..O......(Vd71..Y..$. eR..Ksy.rN.......x/Q-,l......YM...].....;U.8./".
o3G....3.........c......Mj./..........7y..j.......;.vq..$... In-..y...
.{..a..y....n..C.....{.V.p.. X..E.Ue...c0.(....#.....m.JI5..Sd*.. ./%e
..n....3#..V...E..q.f...By........4.O...E......i..G.......qm[x#...3(9&
lt;..N4.W.(R....N6z^...=..M..3..:.T).N.Yr.N..kKYrF6W.e.I.......1[.=..2
......Q..:F.g..(y%..gg"..m.........5O...spZ&..T.;.5.L..Qi..4-,C.".<<< skipped >>>
GET /star/upload/7/7/1473517326599_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 15:59:07 GMT
Content-Type: image/jpeg
Content-Length: 65915
Last-Modified: Sat, 10 Sep 2016 14:14:22 GMT
Expires: Fri, 09 Dec 2016 15:59:09 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 172599
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..p.....
.....^.#...#..D..UN..g.....q...\.k<qH..`.][....`....s..9u...".A...d
...>.q.4..j...O.7N...kwv....=/f..t..%m.._M..rs..r..d...q...;..QX.A.
..M.....2..t..'..=....9...eq...q..Fy..j.m0]...2..$aNq.O.`.H......Q..v.
. .>.}-..Is....d..^...].7h.t....y. <n........Tn`V21'[email protected]
..8.zU..n.....S~.d.....A.....q.v.K*oe.2.PH' .......pzR./k$...{j.w....M
)T.Rv.N6........w.uP.e`...m.3.i..@.._\;.......|.(.a..<..r:........A
[email protected]<.O4..[{....wz.....T...UA8J\.Q..OT............
RVM.([email protected]..:W;qm.WL......Q...T.....c.W.%.3lm......g
y.........CXr....o u.....`.......3X.:iF.E9.......v...?un...w...3.....#
;.a..$........7.....Gqp.....9.[{.....l....dv9.]]...o\/..)8....8...rr..
.s..D.].F./.w...I..q.1.N :<.....D.)U..R..R.R...n.o.<.8s.E..Z..M.
.I.W..n .R.\[email protected]..\.......y'...2.O..O..A....Z9#a...``..p...
..B..cIm...l...W..z.Xa.........u*.N..Z..Qm'.z>}...R.c......%.e.<<< skipped >>>
GET /star/userpl2015/69/76/1469617950004_190971769_100.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 03:11:01 GMT
Content-Type: image/jpeg
Content-Length: 11567
Last-Modified: Wed, 27 Jul 2016 11:06:04 GMT
Expires: Sun, 11 Dec 2016 03:11:00 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 45888
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....C..............................................
......................C...............................................
........................d.d.."........................................
.../...............................!"..#1.$2AB.3Q.....................
............<........................!...1A"Q.a..#2.....b.qr...$3BC
Rc..............?.eqn........F.A<......EG...;vT_......[..ed.._...*(
...gf.;9............;|..}..a2.L....3.W..../dUO.e...w_..%..!..A....U.x.
....O._..s].W..'./tUE_.A......;m.m.....N)[email protected]....#
W.U....*..i\.....5\.F....70J.#.....A0...=...j?..H.'cv..r.*....3\.P<
.4.vP.W._[..9..5D.5=.c..x4.k\...k\./".P.a..c....{K...z...5".MO....z*..
.Tb]Y...Nq.....>~\....,....$.v.....7...^...1d.D. ....j.k.b .....&.^
.k.j..F. [email protected](.F..W.X15U\.3..|....9Z/.N...t...iZ....0es...r".
.s..Bx...T..h.}...3tR%...:*..7n...j5....;..Dk<UU......N.<.zA$..}
..1.\7[..z},(......[..`......Oz.....s.f.?....A..x.U.cF.9./.u...^.._i..
....j=.a..3yx.(U.\..|^......O4UQ....lT........5{...O6....4V.......*1;5
......%}*..AzI...^..*J.4r....R...q.....C9U.Up......;x......%.M#.F..?.S
;.i..p<..>.a..l....w..r..6..p..r0).......Th...B...A|.y."......\.
E.".S..D..1....wkS.%.b...4...(.b4..'...R..F}@.y..C.z.X.=......K..kU...
..#U[.Ew.....W....^.k..wEZ!I..;~.Ir.H.Dd..HvC.8....dk.$..n3l..4:5...V.
H.R...9./...<....'w........BsU.Gy....r..g.=..Dc...EWws<S..\...r.
.2.C.^.a@$G.....z....=..H....|.vN.Yv,b/...{;9...*...../..{.~...vO...q.
9......*..c...-...x.#;x...m.=......v.k..DE^......S.t.........k.<<<< skipped >>>
POST /music.yl HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 444
Host: log.kuwo.cn
Connection: Close
MiUwOTxTUkM6TVVTSUNfNy4yLjAuN19CQ1M5OHxBQ1Q6RFlUX01BSU5SVU58UzpLd011c2ljfE5DSEVDSzoxfERZVFJVTjowfFRBQ1RJQ1M6MXxNT0RQRVJDOjgwfE1PRFJFVDoxfEZPUkNFQVI6MXxBUlJFRzE6MXxBUlJFRzI6MHxSV1JFRzotMXxEWVRQQVRIOnx8SEs6MHxIS0FUOjB8V1NWUkFTOjB8U1RBUlRVUF9ISzotMXxIS0FMTE9XOjF8UlZFUjpNVVNJQ183LjcuMC4xX1AyVDF8UFJPRDpNVVNJQ3xWRVI6Ny4yLjAuN19CQ1M5OHxQTEFUOldJTjMyfEZST006a3V3b19qbTQyOS5leGV8VUk6fHtrdXdvX2ptNDI5LmV4ZX18Szo1OTIxMTgwOTh8UkVTRU5EOjB8VTo2NDI0NjcxPgA=
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:56:14 GMT
Content-Type: text/html
Content-Length: 12
Connection: closeR290IGl0IQA9..
GET /star/upload/7/7/1473517310391_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 16:00:17 GMT
Content-Type: image/jpeg
Content-Length: 58828
Last-Modified: Sat, 10 Sep 2016 14:14:06 GMT
Expires: Fri, 09 Dec 2016 15:52:20 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 172518
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,......hXXp://ns.adobe.com/xap/1.0/.<?xpacket begi
n="..." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adob
e:ns:meta/" x:xmptk="XMP Core 4.4.0-Exiv2"> <rdf:RDF xmlns:rdf="
hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description r
df:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http
://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/
sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5 Windows" xmpM
M:InstanceID="xmp.iid:3E2376614B1811E6A850B4D12E0C8D8F" xmpMM:Document
ID="xmp.did:3E2376624B1811E6A850B4D12E0C8D8F"> <xmpMM:DerivedFro
m stRef:instanceID="xmp.iid:3E23765F4B1811E6A850B4D12E0C8D8F" stRef:do
cumentID="xmp.did:3E2376604B1811E6A850B4D12E0C8D8F"/> </rdf:Desc
ription> </rdf:RDF> </x:xmpmeta>
<<< skipped >>>
GET /lyrics/img/kwgg/adv5331/_2_1461809875271.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv5331/index.htm?ver=MUSIC_7.7.0.1_P2T1
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:28:52 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 30165
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "135d523-75d5-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:58:46 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1631
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS..{..x....t......3..Ll{b...;.m....3.dbOl.......}..=..sj...U.<..z
...}...G..O....@........@....@S^.1..w.k['..=.2sgg{^&&777F76F;G3&....&f
V&VV....'.[g#w.['r2A..#...L.-..-.lI......8....;....?..N.F@;c........=.
.#3.?.."^QG...........?*..k#'s.%G;S..._..5..*'......5........w.'.H..G.
.........E...............?y....X.A.F@#g...9.......YxYYx98.........ha..
.e..J.~......l.......0.K....2._...<.AL* ';.G.._9.....<........HZ
L.......o..."..""..\..,,.......,\.<<b........./..........i.....d
..M.........P.9.E....D....*...-.%..%...-.../.....k.9Z.....v6.v..F.N...
. .WT...o..Z.Ob......`........../...ML.....8.............wq.....4a.Y..
....-e....4.5.s.1r.4....01......dngb.f..b0..z.3.W..tIL.^..I......=....
$.`?.. ....o..b..g.s.s.."#!-....g....*@.o.......e.}.........`d.pT0.T..
~...uB.C....o..0p..(.H.....(..`.....Pp..`P.p..?.aP.....d,...p.F..."..X
*......W...l....8......3.A.....g!.1..?..H8...K...........!.].8.$*..)4.
.]X.........5 .K%.......Md.[..d.H.....Z2.}}[email protected]@...U....#.`..
y..(.S}_.ZIGY.}..j..7.x...l'.4.43.a.pdyb..#Q^.z72[..G.u^9c.r l.o..W...
]...4$.\Y.....cC..T...,...G.[:...K.....r .<[email protected]..'....9{1..PPM...
.....hG.......Z*.,.........pL ........I....]WsW.g.^...J...........F...
.I.x.ek... B...S....1..t.t.......'\%[email protected].[..{..q...Ysw.z..
J?...`.8......|...k...=.YWt9-`...~..G...{q..j..c.&.......Q.......B.d..
...W..w..m.....}...o.".^A.n..wx.]....3 )...0|y........:...(?..<L~r.
.'..1....j.F\R...a...a..[..!r.W........&....*/B.... t.0!\%.#)F.(@\.R.'
}..,....*..j,...:.L....d.E.....0E4.?.._7...".9g....q.B\c".".,em<<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4996&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:11 GMT
Content-Type: text/html; charset=gbk
Content-Length: 978
Connection: close
Expires: Mon, 12 Sep 2016 15:55:26 GMT
Vary: Accept-Encodingsuccess.-4996.20.20.588558.............2266609430,1797347526.0.169744.
..........1792602666,32810588.0.239002...................244383111,697
854241.0.658147.......43........2809102811,3968324378.0.327178........
...................1529967426,80069885.0.225397.......................
....................2783048186,1834476297.0.408782....................
.......1482097518,4261768796.0.395026...................2050579177,375
9306619.0.129839.....................111860691,1752111988.0.64840.....
........498170202,143252791.0.4815862.......&................236426678
2,2902086857.0.90334.................816163120,905081219.0.62527......
.....1308467774,2829231657.0.130594.............4091191610,4012584107.
0.78824.................132683438,3535705944.0.291647.................
..445727277,2762395120.0.829982.............2780199054,2606497102.0.55
5757...................3788799939,1311519039.0.153232...............20
65676057,382409092.0.59573...................436828936,1970333728.0...
GET /star/MusicTopToday/js01/topmusic/recIndex2014.data?newtime=0.9586088943741652 HTTP/1.1
Accept-Encoding: gzip, deflate
Accept-Language: en-us
Referer: file://%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\quku.html
Accept: text/plain, */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: js01.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: DnionOS/1.2.1.12
Date: Mon, 12 Sep 2016 15:55:24 GMT
Content-Type: application/octet-stream
Content-Length: 49941
Last-Modified: Mon, 12 Sep 2016 13:00:32 GMT
Expires: Mon, 12 Sep 2016 15:55:54 GMT
Cache-Control: max-age=60
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6
Via: CT-CNC-ZJHZ-P-6-42 (DLC-3.0), CT-GDFSSSD-C-97-106 (DLC-3.0)
Connection: keep-alivevar indexjsondata={"ver":"1473685233913","jdtlist":[{"nodeid":"0","sou
rce":"21","sourceid":"hXXp://album.kuwo.cn/album/h/mbox?id=1908","name
":"............","disname":"............","info":"","pic":"hXXp://img3
.kwcdn.kuwo.cn/star/upload/11/11/1473639534987_.jpg","listen":"0","lik
e":"0","tips":"","isnew":"0","newcount":"0","extend":"|MUSIC_COUNT=0|"
},{"nodeid":"0","source":"21","sourceid":"hXXp://album.kuwo.cn/album/h
/mbox?id=2087","name":"...............","disname":"...............","i
nfo":"","pic":"hXXp://img3.kwcdn.kuwo.cn/star/upload/7/7/1473434658615
_.jpg","listen":"0","like":"0","tips":"","isnew":"0","newcount":"0","e
xtend":"|MUSIC_COUNT=0|"},{"nodeid":"0","source":"17","sourceid":"http
://g.koowo.com/g.real?aid=text_ad_3821&url=hXXp://vip1.kuwo.cn/fans/fa
ns/template/index.html?key=zhanggr20160904&fromSrc=18","name":".......
..............","disname":".....................","info":"","pic":"htt
p://img3.kwcdn.kuwo.cn/star/upload/2/2/1473609345490_.jpg","listen":"0
","like":"0","tips":"","isnew":"0","newcount":"0","extend":"|MUSIC_COU
NT=0|"},{"nodeid":"0","source":"21","sourceid":"hXXp://album.kuwo.cn/a
lbum/h/mbox?id=911","name":"..................","disname":"...........
.......","info":"","pic":"hXXp://img2.kwcdn.kuwo.cn/star/upload/11/11/
1473390677979_.jpg","listen":"0","like":"0","tips":"","isnew":"0","new
count":"0","extend":"|MUSIC_COUNT=0|"},{"nodeid":"0","source":"21","so
urceid":"hXXp://album.kuwo.cn/album/h/mbox?id=2140","name":"..........
..BGM...............","disname":"............BGM...............","<<< skipped >>>
GET /star/upload/7/7/1473434658615_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Sep 2016 15:40:50 GMT
Content-Type: image/jpeg
Content-Length: 40970
Last-Modified: Fri, 09 Sep 2016 15:16:36 GMT
Expires: Thu, 08 Dec 2016 15:32:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 260079
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......I......hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:4a4c522f-4c75-b34
9-9cc6-ea5971397380" xmpMM:DocumentID="xmp.did:BBE526F8767F11E68352997
2ECD7D6AA" xmpMM:InstanceID="xmp.iid:BBE526F7767F11E683529972ECD7D6AA"
xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"> <xmpMM:Der
ivedFrom stRef:instanceID="xmp.iid:904b7ab0-0f0c-c644-a5c1-32ae8397aa0
e" stRef:documentID="adobe:docid:photoshop:90b5d519-767f-11e6-8c0d-ab5
1cc70fe2c"/> </rdf:Description> </rdf:RDF> </x:xmpme
ta> <?xpacket end="r"?>...XICC_PROFILE......HLino....mntrRGB
XYZ .........1..acspMSFT....IEC sRGB.......................-HP ......
..........................................cprt...P...3desc.......lwtpt
........bkpt........rXYZ........gXYZ...,[email protected]
dd........vued...L....view.......$lumi........meas.......$tech...0....
rTRC...<....gTRC...<....bTRC...<....text....Copyright (c) 199
8 Hewlett-Packard Company..desc........sRGB IEC61966-2.1............sR
GB IEC61966-2.1..................................................X<<< skipped >>>
GET /star/upload/14/14/1473651505534_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 04:09:22 GMT
Content-Type: image/jpeg
Content-Length: 38373
Last-Modified: Mon, 12 Sep 2016 03:30:32 GMT
Expires: Sun, 11 Dec 2016 04:01:23 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 42369
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:E5F2256A1A77E6119
5D288805FCC1B41" xmpMM:DocumentID="xmp.did:B057CC2E775111E6A26389AA105
97E9F" xmpMM:InstanceID="xmp.iid:B057CC2D775111E6A26389AA10597E9F" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:FB1196153E77E61195D288805FCC1B41" stRef:doc
umentID="xmp.did:E5F2256A1A77E61195D288805FCC1B41"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;...XICC_PROFILE......HLino....mntrRGB XYZ .........1..acspMSFT....IE
C sRGB.......................-HP ....................................
............cprt...P...3desc.......lwtpt........bkpt........rXYZ......
..gXYZ...,[email protected]....
...$lumi........meas.......$tech...0....rTRC...<....gTRC...<....
bTRC...<....text....Copyright (c) 1998 Hewlett-Packard Company..des
c........sRGB IEC61966-2.1............sRGB IEC61966-2.1...............
...................................XYZ .......Q........XYZ .......<<< skipped >>>
GET /star/upload/6/6/1467861701110_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 07 Jul 2016 03:41:14 GMT
Content-Type: image/jpeg
Content-Length: 16801
Last-Modified: Thu, 07 Jul 2016 03:15:43 GMT
Expires: Wed, 05 Oct 2016 03:35:10 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 5832858
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
......................................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?....Z.z....s.3.e<|..TP...
ul........t`.....U...[#.J.?...J..U..xj../..>....V..$9..i..*..ya..".
...Z.....O..k..}..<5.._r)K.....1;........drO.G...........y....%..#.
..o._r=_.....]....G..yp.M;..%............G..K.......J....%.. _..];...#
X.. .M.T..4......@`0.9.$g.....7.^......Q..].N.......S...<D...7.....
.5..z#.1.#... ...z......:.......0...Np.;....R.(...#.x.i.XGS.|3...m.O.x
.\...N"..kx...7......w....Q.K.]._...\..#3.../eGo...].. .Y.W.$l....2g..
.x|..........e0J.......Z..4.u[.'Y....ba..fl....pA.G........,.>~.>
;Yr.jV}s_71......5..Cu..T.....]w."./.sP.....5J1.c=...x...Z....M..kE..9
&. ....Z....?..5q.{../..o....j?.^ ..f..P."....k.O.....T1:uH.Z...w\m ..
_H..c.....p.q.$.=....r.).m......O...7w.O1. HG*?.P..a..uS.."i^../.o/...
...".X.@?(rT~D......I.#.K...C3>...8...wQ......m.R.J.".NH..8.(\...V.
<......t...._...=.....~...#..#........."...>..k9X......by..d<<< skipped >>>
GET /star/upload/0/0/1473064611280_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 05 Sep 2016 10:09:46 GMT
Content-Type: image/jpeg
Content-Length: 13483
Last-Modified: Mon, 05 Sep 2016 08:29:12 GMT
Expires: Sun, 04 Dec 2016 10:01:58 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 625545
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?......_/.9e.% ...T.........1
.1..3n0....g.F..G3...~....k....mL..K..\..vb..h.m3J.<pl....%<....
.....A..}../...]|.....-3Ta1..}..C.......d),,P...:... .E..m......NPij..
....m..|#.x.u...mF..Cul.s..i3..&....[lF...$..........w....U..u_..?....
.......O...]......i.P.w...o ....Ug...$.....u.]. $.wn..; ....-..j\.V...
$..k6.u}..t?..n...w.O.......W.h..> .:\...:....:.[.......J......M-.|
=~.#...H..j.T._.>|6..O.^^..m..z6.N...=..E*...>..(...K..Ws.U.....
..oC.........w.<.......*.)...oq?.[.>..|{...I....]......V.P.w..$.
m|=.{MCT7V.CqT.................z.,NGVT.....FI.84.2.7.-....v...........
j...]...5._..{..^.c....r-..<.{.x..~.{..Xj..{.it.R....y.n...{k.}|d7O
.`....g..M8)n......[S..J.........Y7y)J..5..i t....5..X.....X....HO...c
..cS..Pks.I=.......2F]..m.M.y@[.^(.9.5L..t...0n>4.e.....;....'~)...
.5....e....$.|\...?.}.O......T.........O?.>x...............].C.<<< skipped >>>
GET /star/upload/8/8/1444307264344_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 28 Jun 2016 14:13:34 GMT
Content-Type: image/jpeg
Content-Length: 5915
Last-Modified: Thu, 08 Oct 2015 12:27:54 GMT
Expires: Mon, 26 Sep 2016 14:13:33 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6572517
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?.....I.G.E.G.L.....9..My.s.|
f....?....\..\..~...........;[email protected].*....c.B.3..B..-..o!...Q.XdY
.&.s. .do....\W....G.....N....s.m.[tU....*:~U.2.T...aICwp...1..a......
p.;.......6..=...UO.....]9os.....i-.....Zk).T.ox.].....7..b-P..Es../k.
.E..`.uK......_.B..i(....EB...........x....Z.x......._.....RI ]..2. .
d...s..."F?.".G........T..T....."oa........Z....>..k,6WK... .C..M.1
^..WA...j..8....a..(G.G.p.........~4....o..Z.M2.(........!...:..{.....
....Jm6}.s.p.4...MS_........C<..v..........u.s.........{Z..jb......
......=..*..o6..ZN=A...4....P..J......?...X.-Os..........)T......5...1
pv.6.L.o.,....L.r...H.....]o.......n.....pfr.1..50......WRVH.h...[j.y.
...bVX...} .]....Z..34...?.R|^.K.....-..v.<...k..}o..>...)......
....l.....K. ............ .....Y.Xw]I..S..8...vqZ....v......ym.V......
.C...8........LS.....m."...b$...<.......I...h.-.`...k....V....$<<< skipped >>>
GET /star/upload/12/12/1376042900860_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 30 Jun 2016 21:25:21 GMT
Content-Type: image/jpeg
Content-Length: 5013
Last-Modified: Fri, 09 Aug 2013 10:08:18 GMT
Expires: Wed, 28 Sep 2016 21:25:21 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6373811
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive.....0Exif..II*.......1...............VVV.meitu.com....C..............
.......................%...#... , #&')*)..-0-(0%()(...C...........(...
((((((((((((((((((((((((((((((((((((((((((((((((((......d.d...........
....................................................}........!1A..Qa."
q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwx
yz....................................................................
..........................................................w.......!1..
AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghi
jstuvwxyz.............................................................
.......................?......].....y.).....R.s}...z..:......zF.s....N
[email protected].[gcs{?...
......&t.v..\...63.^;.N..Mh...........{i......4Ss...z.......R...a.b...
.u.6.Z..0.er..x'..R.Q..s.E..E&B..~L.5i.P{...a......4l......k)A1].b..6.
HC .{..w. t-Y^kv.../.r...H.j%....5.*.V.s_......Hb.O.t#......I\.5.7x.t.
.....W..y..k.....;..O.E.[.M...*&.....TK...U..F.g..U..U.M...?..Y:=b....
.:.;TpC.....vz.(...~.. b.e.F..'...r......\..*<.....f..........k...W
J2vG$.Yv......S........8....e.Z9jf....Ë.[...r......z.....'......:..8
...uW$._.e.o.W6q....e.]..(...,Lj =.....P|....R9..._.z.<...>...g`
QM.F..........`.-[...6....j....gc....u............N^..)C....<7.....
.....n.F...k.%Zwg.B....9o... <~]......>.w.../......|D.Q.q...V.-.
....G...!....sU.iP\.X...].//.....G......4.O..b..........WZ....I&Ry....
..R.M....N..z.....VV.g....0.[....z&..i9_...*..^...}...G....!..l@..<<< skipped >>>
GET /star/upload/13/13/1376038278733_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 02 Jul 2016 07:31:48 GMT
Content-Type: image/jpeg
Content-Length: 3197
Last-Modified: Fri, 09 Aug 2013 08:51:16 GMT
Expires: Fri, 30 Sep 2016 07:25:56 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6251025
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C.....................................%...#... , #&')*)..-0-(0%()(.
..C...........(...((((((((((((((((((((((((((((((((((((((((((((((((((..
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?.....:6,".T"[email protected]..
.r..P....{.R}).../.?...y=.....:}.f.......{qB.....yk....Y...7.....0h."3
....r...=......t...f..k..IX^Z.6q.XO....rI.eXV....j..MP. J.4..LzP"(....
.j."U.B....-~..4mS.K..'?b..f..I....G.\......9=y.!.x.!O..g...>9.C..z
%...........G..k.G..Zn..>. ['uq. Lc......28..Hl.W..X.(....^/..oR..
%.. .l|...);!..^..._.wr.K......Y.j..2...._.Z.. ..S.t.w]....#. .?.C..l.
4.#........]~.....R..K...E.i.....".....z..'.....S.*V"7..&T$...#.Y.,.Z)
.p....9....H..>..w....M.. T8.e..q....h..W..][email protected]..$..EP..L
G.......:.)r.yp....c. .....)l.).#...n.Z..Y ....a..?....]..ua......DL@Y
....I!W.6....s........k..S...nx_....w.>.i.[.T..?..y...J|..cL].%..w.
.........WL....V.$y.{... ...R.."......E1.......?...............5..B...
....SGi..<[email protected]..{9.k).^....f..S.g.
..2..I..\.j...:..7...l....'Q...Brk.:).=..Z.g.x.*...*P...UfU.!`.`..<<< skipped >>>
GET /star/albumcover/300/25/41/1997281419.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Sep 2016 09:07:18 GMT
Content-Type: image/jpeg
Content-Length: 12570
Last-Modified: Fri, 09 Sep 2016 01:41:49 GMT
Expires: Thu, 08 Dec 2016 08:59:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 283694
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...(.
..(...(...(...(...(...(...(...(... "....k...`.r 3.#l@...<g...?.,u;.
.&...2lkyeR[=..p..S.d. ....)..QE..QE..QE..QE..QE..QE..QE..QE..QE..QE..
QE..QE..QE..QE..QE..QE..........Z&.g .N.3...zl=..I<.....z4."....o..
...8...3W[....\..vz........yp[[email protected]....
9...Z[...oXxS.!fU..!Dy z..U...i~(.]>.K.....\...#. ..p....]..rF/DzW.
.Qm...i.K......N..g..Zu.C.......9.5.d..88..8o...4..C.[..0..$.C.......*
K.(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...FP.U. ..
{.....FA..@.[xR.!".b.....=x..9tm>.m OKky.....B...c..k.5..Z.....Pj_`
2.0.p..r.P..=1..Z..........}......&c.m...<...kNM/[email protected]
@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@[email protected]@.a^..A..%...[
{...%F..d..#.V.W....q..H'....6?1M[...._.-O.W..^........M..Y=. ..v....h
:.w.....U!.....1.........>M>....?.9..6e..-.{f.?...V... .C..>#
.z..Vk..y.`...a.........A.i......".tx.U#....n..b.ox([email protected]@..Q<<< skipped >>>
GET /star/albumcover/300/40/21/541440606.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 06 Sep 2016 16:10:22 GMT
Content-Type: image/jpeg
Content-Length: 19612
Last-Modified: Tue, 06 Sep 2016 09:35:54 GMT
Expires: Mon, 05 Dec 2016 16:02:36 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 517511
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...8.
.,7H..T..F.y.Q.M......v{...qV.....Z8..d..M..5>.1l;T......n..$hn...N
Ezw..8nt..W.<9i.....y.!i..]g..6j.q.z..DV.~.....&.............h.....
.8.)7f.....,.%...0.\.,1.H.m$....~.D..*....S....C...>Rx.u....x... ..
6.L..%...8.\..tu(ex.X.e......w=.L.i...)s&..u.*.......h..^..1....A^`..f
..:.q..s. .~...k..C......!'.A....3.~u..j.....e.q.w......r.........E..C
...$z.x...Vt.j.n....B..8..t..<...T....[1.6... .1.0.......l.".....E.
.`.....f^.. [email protected]_CV..(.....y.z...Dy4_@KQ(....U....i....|..i.d4
.4.....|.q.......(5.BQE..(..@^.. @....f0{.RF...M4$U...ri.pG....=.....
5..2U%....;.....U.>`i.Y...b.z._...B.......8<..Z...w8.k..)`..$../
9....!.V..#.....66.R'...5 .....">."...rd.E"..p(.Q. .z|..1.$8......x
.Y.b6.Z6`.....x..>......:nr.-k>-.M...h..2. ......\.....WP.......
...U'o......7.x..?...:K..c.J.@O'...1\..g.N.`iL......i...B.x.$.}..<.
....{._j.....;.....G^..*..&9.g.......M..a.2..;...........iX..8..W.<<< skipped >>>
GET /lyrics/img/kwgg/kwgg_371.js?time=20168122056 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:37:30 GMT
Content-Type: application/x-javascript
Content-Length: 5192
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "13576fa-1448-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:57:43 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1094
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alivevar param=window.top.location.href;var mboxVer="";var vidx1=param.inde
xOf('v=');if(vidx1>=0){vidx2=param.indexOf('&', vidx1 1);if(vidx2
>vidx1 2){mboxVer=param.substring(vidx1 2,vidx2);}else{mboxVer=para
m.substring(vidx1 2);}}var recom_2013_2t_ie6sign = '0';try {if (!-[1,]
&& !window.XMLHttpRequest) {recom_2013_2t_ie6sign = 1}} catch (e) {};
var unSupportAdsArr = ['5478','5325','5324','5347','5348','5345','5346
','5380','5381','5433','5417','5383','5382','5452','5453','5454','5455
','5448','5449','5442','5443','5444','5445','5446','5447','1046','5546
','5545','5544','5543','5547','5567','5568','5575','5569','5570','5571
','5572','5573','5453','5452','5449','5448','5588','5589','5611','5610
','5609','5608','5607','5656','5655','5654','5653','5652','5651','5650
','5649','5663','5662','5661','5660','5659','5658','5673','5672','5671
','5670','5669','5668','5667','5666','5665','5664','5708','5707','5706
','5705','5704','5703','5702','5701','5700','5699','5698','5697','5696
','5695','5739','5740','5741','5742','5743','5744','5745','5746','5747
','5748','5749'];function recom_2013_2t_isSupportAd(index){var _isSupp
ortAd = true;if (recom_2013_2t_ie6sign == 1) { for (var _index = 0; _i
ndex < unSupportAdsArr.length; _index ) { regStr = unSupportAdsArr
[_index];if(recom_2013_2t[index].indexOf(regStr)!=-1) {_isSupportAd =
false;break;}}}return _isSupportAd;}recom_2013_2t=new Array();var d =
new Date(); var timehours = d.getHours();recom_2013_2t[0]='<iframe
width="100" height="287" scrolling="no" frameborder="0" src="http:<<< skipped >>>
GET /lyrics/img/kwgg/kwgg_328.js?time=0.7255580838426173 HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:52:41 GMT
Content-Type: application/x-javascript
Content-Length: 4952
Last-Modified: Sun, 11 Sep 2016 15:40:35 GMT
ETag: "1357103-1358-53c3d334e62c0"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:07:18 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1495
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alivevar param=window.top.location.href;var mboxVer="";var vidx1=param.inde
xOf('v=');if(vidx1>=0){vidx2=param.indexOf('&', vidx1 1);if(vidx2
>vidx1 2){mboxVer=param.substring(vidx1 2,vidx2);}else{mboxVer=para
m.substring(vidx1 2);}}var mboxExternalVer="";try{mboxExternalVer=wind
ow.external.callkwmusic('GetVer');} catch(e){};mboxVer = mboxExternalV
er;var recom_2013_r4_ie6sign = '0';try {if (!-[1,] && !window.XMLHttpR
equest) {recom_2013_r4_ie6sign = 1}} catch (e) {};var unSupportAdsArr
= ['5478','5325','5324','5347','5348','5345','5346','5380','5381','543
3','5417','5383','5382','5452','5453','5454','5455','5448','5449','544
2','5443','5444','5445','5446','5447','1046','5546','5545','5544','554
3','5547','5567','5568','5575','5569','5570','5571','5572','5573','545
3','5452','5449','5448','5588','5589','5611','5610','5609','5608','560
7','5656','5655','5654','5653','5652','5651','5650','5649','5663','566
2','5661','5660','5659','5658','5673','5672','5671','5670','5669','566
8','5667','5666','5665','5664','5708','5707','5706','5705','5704','570
3','5702','5701','5700','5699','5698','5697','5696','5695','5739','574
0','5741','5742','5743','5744','5745','5746','5747','5748','5749'];fun
ction recom_2013_r4_isSupportAd(index){var _isSupportAd = true;if (rec
om_2013_r4_ie6sign == 1) { for (var _index = 0; _index < unSupportA
dsArr.length; _index ) { regStr = unSupportAdsArr[_index];if(recom_20
13_r4[index].indexOf(regStr)!=-1) {_isSupportAd = false;break;}}}retur
n _isSupportAd;}recom_2013_r4=new Array();var d = new Date(); var<<< skipped >>>
GET /today_recommend/images/201609/1473517759929.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 14:57:53 GMT
Content-Type: image/jpeg
Content-Length: 108316
Last-Modified: Sat, 10 Sep 2016 14:29:19 GMT
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 17:05:19 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 12393
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
................!..1AQ"..aq2....B#..Rb...r3...C.$u.67.....Ss.Tt.5Vv..4
.%G.8c...F..D.Ue......................!.1.AQ".a2.q.3...BR#.D.....b....
........?.. @.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@.
P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....
@.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](...
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]
([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@
.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](....
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](..
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@.
P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....
@.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](...
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]
([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](..<<< skipped >>>
GET /star/upload/8/8/1473492812184_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 08:10:49 GMT
Content-Type: image/jpeg
Content-Length: 47194
Last-Modified: Sat, 10 Sep 2016 07:25:44 GMT
Expires: Fri, 09 Dec 2016 08:02:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 200685
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?...(..-.
.|...4....0..?..}...<......zd.....Q..0.z.c.....8.Qv..rOQ.....\..N.W
.k....@.:.>..Z(.....$.A.....QC...............G....Hp......?...z.O.0
L.s.....P........T......F....i..j..-vm........4z7k.....].'...B..E..7W)
eeg............I...v?...(g.I.4Q.r3......'.....O.?...........:...b..kRx
gH.......\3.wM..9..........VRj.....&.cao..76...^.....@.....~.?....?...
.o.....Y.....>.O....Dv..|V.'..e...|...6...u..c...G.r.v.e..%...<.
cy%'.....[.[....$V.YY..[}.4....K.t.2..9...Ztk:.U*.N.*..........E...E/r
r.......PU..S..#.i....6...>X..W....... .^.K..'j.m.......M:..6.xX...
.....)..b*.G"G....x........,~M....:...;...Acm.....&..G.II..]\...x...."
.X....v h~E.....Q.....9......0..(...E......%..k....d.J..N.*...@r.]&.'f
..Qz$..J.M...t........x.t.87...',.7..........J...:pK....,:P..N.s......
.G....v.....Y....?t.. .J.gi.B..R..VU e#.....rv.T.....M<.u.$....6.1r
.g..h....&....Z($...4.`K......'..T.Q,.)u.......p....1..G,.n. ..p.N<<< skipped >>>
GET /star/upload/8/8/1473517623144_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 07:47:42 GMT
Content-Type: image/jpeg
Content-Length: 68800
Last-Modified: Sat, 10 Sep 2016 14:19:18 GMT
Expires: Sat, 10 Dec 2016 07:39:45 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 115674
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
.....................<CREATOR: gd-jpeg v1.0 (using IJG JPEG v80), q
uality = 90........,.,..".............................................
...............}........!1A..Qa."q.2....#B...R..$3br........%&'()*4567
89:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...................................
......................................................................
.....................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&
'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz............................
........................................................?..?....A$..^0
=H8.q.9...k...-.L..d.....<..~A.5.......d.g.y...t9.<g...&.....$g.
.........N...$.....^.J.N..~...}. Ck.....'.3..$..#'..j.[.`09.>.}....
.O5v..p......<.........x-.|........x.<[email protected].....{....]>.$.
n....oE...........z.q.\...iE.....=.#.....#=x.....c.$.Lq.2:....S.kZ.\..
H...........:.w.OW...........T..H.3..r8.~^.#.29<.Wc.rWv.q...'.$.w..
..s...r..1.O..y<[email protected]...'.X.X..........pFpFy..A.
..#.9..o..g...=..z....j.v.....:...d..:.j.%...p0J.W#.>l.g.r....'...[
...v..'7.. '..F08......0i|..1... .s....1..=y.v.3..............k.;.Y..n
e.....dU-...`..H.m.5...Q..{...l.....-...x7..&.Z?...F."2..I,O".*..N.IJ.
)......N......sJ.M\........k.....u]......M,.D..3G$.. ;.,..8-..#.;....4
v,P.Oy...%.B...c."Z..e&..G.4 3b evf.@......{.O..N...{.:...<.....f..
..2......;.2...o...Z4L./..mRF......... ......i...;.|9.q.....V..g..<<< skipped >>>
GET /star/upload/5/5/1473517459509_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 15:58:21 GMT
Content-Type: image/jpeg
Content-Length: 61115
Last-Modified: Sat, 10 Sep 2016 14:16:35 GMT
Expires: Fri, 09 Dec 2016 15:50:25 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 172636
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?...;v.%I
..0'.../Zs..2.'=....l.N..O....m..L.=..........-.>....=.;IL|........
..N}.......?..~?.i..q...9........M..Z.q.o......._...,..B7...|t....zWo-
.H.._C..?...,.G$._N1....z....wqqqv..=4...:....F..8.........^...J...y..
.On......k..g.'.$c..G.\...-.q.;.....0.k...J)7...^....W...~..g.x..E..p.
-....._...C... ..6"....<i&....0 .I.H .c..G\W.. ....}.....rI..m....q
... 8...>(...dFb...30......k...:.m.t....]z........~./3.Ko...9..N..
..=.~85.Z@6........{[email protected]>......UglB.e#.$.....e)$.........
...~...b.%..<z....J.H..NH...?L..."^..#!.c9#..#....V8U.nG.pEi..&....
i....1z7...0. [email protected]#*....y..;....5X..!@^I$.}N..7......~..TC.w...0
..d.E.>.<'X...E....t.4.....2.".}..O.J.J..J.r.JK.WF.{k..-.......=
...).R.s.._.....]k.m.....>...`...'..T.L.h.. .........../.....~...x-
.._.x[P.o<@.2...-..<.%.\.Q..,$E....5O...L.<sy.MF........u..J.
..;....'K.B[.2.4..1..h.D.#d}..!.V)...}c...MV..t....1\.=n....n.....<<< skipped >>>
GET /searchkey/searchkey.txt HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: skeylist.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc:kuwo_jm429.exe&id:6424671&reqsrc:CSearchInput::_DownloadDefText
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:47 GMT
Content-Type: text/plain; charset=GB2312
Content-Length: 135
Connection: close
Last-Modified: Sun, 11 Sep 2016 15:42:01 GMT
ETag: "1eaa55a-87-53c3d386ea440"
Accept-Ranges: bytes
Vary: Accept-Encoding..........OST.........................................................
.......................................3..... lost in the stars....
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-4954&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:10 GMT
Content-Type: text/html; charset=gbk
Content-Length: 968
Connection: close
Expires: Mon, 12 Sep 2016 15:55:25 GMT
Vary: Accept-Encodingsuccess.-4954.20.20.340489.................3264118389,2212454324.0.349
4513.................1120611125,624819069.0.819342.............1207578
410,1500326088.0.98019.................2515360419,3995565190.0.986096.
..............156062657,3861714323.0.896518...............2701282501,1
193826190.0.891401.Kelly Clarkson.Because Of You.1389869469,4216903795
.0.3191612.........................239447020,234926046.0.156522.......
........4184104281,83259626.0.1094230.By2............2201393684,267232
4142.0.1032476.................1325011878,4272087609.0.322953.........
........1689871630,3617632849.0.909773...............4229821512,384125
2364.0.1169159.Kimberley......3508559158,753523444.0.1105371....F.....
.....2240185325,1939921760.0.2836690..................Sorry.2887498811
,744485029.0.3405564.............3029593164,1464548694.0.1038414......
.......1743529097,1215617545.0.1086819.............3584569488,36762526
20.0.5739994.Nightwish.She is My Sin.38598299,913527076.0...
GET /star/upload/14/14/1472798447454_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.kwcdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/jpeg
Content-Length: 21307
Last-Modified: Fri, 02 Sep 2016 06:33:12 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Fri, 02 Sep 2016 06:40:55 GMT
Age: 897275
Powered-By-VeryCDN: HIT from ctc-tz-1-2-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......d.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:A4C322843556E6119
256D2E78A3B24B8" xmpMM:DocumentID="xmp.did:E2BBAB83563611E69AA6B26FCB9
40115" xmpMM:InstanceID="xmp.iid:E2BBAB82563611E69AA6B26FCB940115" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:802351DF3656E6119256D2E78A3B24B8" stRef:doc
umentID="xmp.did:A4C322843556E6119256D2E78A3B24B8"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
..................d.d.................................................
....................................................!"..1#$Aa2%&QC4..B
RF...b3S.DTde.6(..........................!..1"..A2#.Qa.qB3$...b%.....
RC..r4E....Ss.DT.&F7.............?.......0..;t.i..9'.VY6.......j..h...
(.-0).E.n.."/[email protected]'H...?........Y.,@.'..?....q...ny
5r..K.S.\..R.....)RL..i ...5|.?......;O._.......?.....^.>._..r.<<< skipped >>>
GET /star/upload/3/3/1404128033575_.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://vip.kuwo.cn/vip/zadan/ShowEgg.swf?94766.17852897952
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.kwcdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Content-Type: application/x-shockwave-flash
Content-Length: 26133
Last-Modified: Sun, 15 Feb 2015 07:22:28 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Tue, 06 Sep 2016 01:26:49 GMT
Age: 570523
Powered-By-VeryCDN: HIT from ctc-tz-1-2-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-aliveCWS.....x....\Tm./[email protected].=..x?....w..
.s..}ft..U....]k.....j..........^.. ......].-E....y9.;....$.....E..<
;==9=.8.\[email protected]/.GWF.I.S....f.6.n6N.t.......$....z98..u
t.45w.g.i....e.............X..9.h:9.K........Z...8YZ....M...4..8......
.....s.]..-.y..$/7.?......&..(..5naQn...p1.........)[email protected].[P.G.
....g.N.6...%...t.\.s.....f.~uvw.?..............-..o..D-.\.L.$M...m.La
...8\....<M=,8,a~...-.?:$pf....m............v..v..R.purw1......EUUT
.......BY^.$p................ ....\...........P..9.....k.Nf.0..Y3..a..
*..m.. .0^..Uyy!a!nn.>..A.>..Ya.~aY..aA..yn.Y...b.|...6....]..NQ
p6uq..yJ...*..N. j.O.$..M..T....qB...<.|..rB.2... p.......q.....#..
_.....?......90....C..,.J..rH.....8`v..KI5..Et<......Q..-t.:.....|.
...a..@.@[email protected]......`..0q..p.....qp...p..../$.8.$ .....3.A
G'....KI.{.....!^...(...... .... .......L..~.(...^........d...d$..2...
P.........(A...]........L..!(H..x.HD.o....e....h.......~8...>..>
....... H;[email protected].. .1D..>.....J.w.........Q_.....r..G....
...7;iT..4....U(..q...=..d.T.U..s..F..}...P.y.........t.........o.Q.@.
..7;....A...........M........Ge(.....0.XW.b.>..@d!...C..f. .M....g
./H.C.. ..A.b.'.....B.`d....>H.d...\.BH.@$p.JO....k*[email protected]
.....l....Q$.........<.SI..q..I....... ....4_.j }#.2P."......0.~..?
.4.'.sp..G. .~W..Q#!. [email protected]..&2.I..........T../...@~. .4.l...#yG"M.
.L..~...(c.~cKg$./.....$..P.......Z........E.... .E.!.<..h.........
.MN.{\..([email protected]...=....V(.{7...^....._.....J)}r?.......<<< skipped >>>
POST /uc/s?m=48;T1FXWF9YXxs0MDYlKjBZDk5LVUJYMD4SLVRJBxwYAX8TCFFeUEELWBxJEBwNDhpF HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Content-Length: 0
Host: config.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc:kuwo_jm429.exe&id:6424671&reqsrc:UpdateUserConfig
HTTP/1.1 200 OK
Server: nginx/0.7.64
Date: Mon, 12 Sep 2016 15:56:01 GMT
Content-Type: text/html
Connection: close
Content-Length: 264W1VwZGF0ZV0NCnZlcnNpb249TVVTSUNfOC40LjEuMF9VRzINCmZpbGVuYW1lPUt3TXVzaW
NfZm9yY2VfOC40LjEuMF9VRzJfMC56aXANCnNpZ25hdHVyZTE9MTQzNDU1MTg0OQ0Kc2ln
bmF0dXJlMj0zOTk2MjEzMTgwDQpbTmV3ZXN0U29mdF0NCnZlcnNpb249TVVTSUNfOC40Lj
EuMF9VRzINCmludHJvPQ0KW1VwZGF0ZVRpcHNdDQpkZWxheT0wDQoA..
GET /star/upload/4/4/1473213016500_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.kwcdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Content-Type: image/jpeg
Content-Length: 13051
Last-Modified: Wed, 07 Sep 2016 01:42:30 GMT
Cache-Control: s-maxage=15552000
Accept-Ranges: bytes
Vary: Accept-Encoding
Date: Wed, 07 Sep 2016 04:08:01 GMT
Age: 474449
Powered-By-VeryCDN: HIT from utn-cz-1-1-c1112, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P...../hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c06
7 79.157747, 2015/03/30-23:40:42 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CC 2015 (Windows)"
xmpMM:InstanceID="xmp.iid:65F94C43740311E69B089F290F12485B" xmpMM:Doc
umentID="xmp.did:65F94C44740311E69B089F290F12485B"> <xmpMM:Deriv
edFrom stRef:instanceID="xmp.iid:65F94C41740311E69B089F290F12485B" stR
ef:documentID="xmp.did:65F94C42740311E69B089F290F12485B"/> </rdf
:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end=
"r"?>...XICC_PROFILE......HLino....mntrRGB XYZ .........1..acspMSFT
....IEC sRGB.......................-HP ..............................
..................cprt...P...3desc.......lwtpt........bkpt........rXYZ
........gXYZ...,[email protected]
ew.......$lumi........meas.......$tech...0....rTRC...<....gTRC...&l
t;....bTRC...<....text....Copyright (c) 1998 Hewlett-Packard Compan
y..desc........sRGB IEC61966-2.1............sRGB IEC61966-2.1.........
.........................................XYZ .......Q........XYZ .....
...........XYZ ......o...8.....XYZ ......b.........XYZ ......$....<<< skipped >>>
POST /yl_res_manage.search HTTP/1.1
Host: deliver.kuwo.cn
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
Cache-Control: no-cache
Accept-Encoding: zlib
Content-Length: 176
Connection: Keep-Alive
NxENFQdbNhsjNjBPLiJyBEggKh8WDx0dOGMCfDIEFSlEDTgEBBR8EgUSP1QFaXhXEGBHHFwkCnsTeyE5cxFBDRAXBQR3Tk8dWkdWRS1GH1wuRjNLNHo2MTAiNTYyG0ccS05uE2s4cRBpKX0BMVtLYmd EwUhfwNqPSd5dXVLOEQYRGE=
HTTP/1.1 200 OK
Server: nginx/1.4.6
Date: Mon, 12 Sep 2016 15:55:36 GMT
Content-Type: text/plain
Content-Length: 2313
Connection: close
Content-Encoding: zlib
Expires: Mon, 12 Sep 2016 15:55:36 GMTK..............V.W...z...p.............0.Ty.....A.......|.........&...
>..Ldw..;[email protected]..;..0.....R~..P$_...rnd(..lv....I(-...ec.........
hT..->.< U....uP... .....HTd...7.......t..K.c..Zb*..^..Hm....q..
X.$......H....Q.1{... ..O....&.`.A.Y`.NfE....b...J-.M.y6.w"5F..N.B.C..
.....S'X.eM..UD..n.Z.N~,..........K..r........\...u.X.......,.7.M.a...
4.C...g..p..........`NO..4..Tc.J..y.....i......A...b......xT.|!..]F'.a
o..T...Wv`.y...........f... ..o.n.\fF.S...wm.Yt....Dq..K....O.jr......
.#.......(.l...h..1%0.3...2w|..4vq.../Ll..,[email protected].`B.Zr$..qH]
H.......rc3.H......ezEE(.64.-........TM..>/D..<.A...Z....J..*.d~
.V4.....B1..s:.....tW..U..L.nA?..5....lMP....`k..n../a."p.U......!P..w
....[.na...]. A.Hf.}...v..:Yk".....S.w]Pz.,....3.....V' ...z.....B...E
.l...S.q.>.TK|p.E.[....NU;'.Tr.]@..R...k?..K4.#.e..x.0@P9...<..?
.....?a.~V={j.. .^j.H..^.QC....I.IV....].V.w...!...:Y.j..<Td.b.z.sb
..c.e&A.b`~..f.2.......%s.u..b.O.##...0t._.6{....."..W[....'2......Nb5
....m[.<.7...`.....nC.mB..a.....T.9..(...~.....a=..Va4..`7..B....Z8
..;}.p.vl*7.Ss..........W.^Zk...[.\...[#..j]>q.'3R.....@(8.*&...8.x
[email protected].(...".AZ.v[.<\..8R../.2...u.x...W.O.."..%Vqa^..N.m.<
;....bP..(~.4..q`.8).1.(.3..0.d=...=.I8.2..q{.&.CUY.h....e\...r.....="
.........^.q{...v[.T2..)..V....`..F..w..~i.^.Kd(@...es~.1....z..:...K.
p.....B.M./H....~...Z....2s..U..o..l6!.r.A...|f...D..R...Bc..ki!......
:.[...r53k..q.[.GR...r.q....O'b......p.i5...ds.*...b,v....(r.W.. .<
."M5`.]o..C|.x..P-...Y..V.Y......s..Y.@<.X..0...C*..g.XRb=""..Z<<< skipped >>>
GET /star/upload/3/3/1467862157203_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 24 Jul 2016 02:22:38 GMT
Content-Type: image/jpeg
Content-Length: 9611
Last-Modified: Thu, 07 Jul 2016 03:23:20 GMT
Expires: Sat, 22 Oct 2016 02:22:38 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4368774
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
......................................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?....CV...q.N.. ....-.-n9.ut.
r.w.s..I .E.;...Z.K.....:.{n;M.5(..9.....SI........~.&..&.D~'.w.#.....
.[..<..........P......o......w....}[email protected]......^u.D..v.....H
.......j.>........=.....M.}K..kz.(.f~......'..x.s..`..........-..m.
0r.'....-[;.......~...B.o.x.S..FwK.......N....=.j.#UsS......S...F.o..
....%$.....z..z...s....KdH.>.?..i.N..G...EF....n......E..1/.. ....(
i.p..._...#....../Kw".....J;...{8<?. K..=....;..,...'.>q..|.4...
.S.[,>..G...QLg...$Z....2.O'.Z....]C...1..."....b...I ..m.,.-.L`.1.
U.&t.......o?.......|Rnf....b(...g.8....$.&N....!9..6!,......M]..K.N..
..}.D.....NrG...,[email protected]..>.z #.l.D.w........5b..I}.[..
.m......2&2.w>j.....q..]cNS..x....e0..N..]XZ.K........]...5..l.~.Q.
..!Y........g........'[email protected].;y...OBK..^..Bc*..NW..j. .
lo1U.9.`_.U...,.<~Ke...Lg.....!.A.....z.z.-..qn0.|.9..{.z.....f<<< skipped >>>
GET /star/albumcover/300/80/35/1564836158.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 10:08:56 GMT
Content-Type: image/jpeg
Content-Length: 14027
Last-Modified: Mon, 12 Sep 2016 01:41:28 GMT
Expires: Sun, 11 Dec 2016 10:00:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 20798
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?....(
[email protected]@....L.K.R..Z(...JZ(.....(.i.-%..v.........~.......
[email protected].....?....h.....I.....Rg.....8...sE.)[email protected]%/4.w
......1A4R~4.w...h....>...J^........z...)i)[email protected].&8.@.'QN...
....ZNiy....4w......i:[email protected]~....
P....:.K..J(...(4P.E.....([email protected]@..R...Q.{PE...b.1.-.%...q.G......
...4.w.E.P.R..(...ZJ3@.%-.........8.......~....~.Q.Q.j.(.~....9..(.!.@
.....sE.....9.....J9...(..(...R..P..{R`....P..9./..x...._......h.f....
.)psH{P.E%[email protected]^.c.^E.%.&..c..P(.E..g...P.....J.ZL...?.......C..
..e.:...)SU.M...5..QM ...4qG5G.4.....L..at.,.....21..q.9...T...f~.....
Q....-}..c..d...7.BU.g.8......I{.Ir....N..V0.1pH#.U?.?cO..../o[.}.(...
}......n-..i..%[email protected]\.....F.,.H.$..\.=. _..a........4
r .M..U..d.....N.c.q...85.s..[j......p.nR.NJ...Y.........0............
.4M4_..|(.I.....9.....x.-9.....X#.ya..X.2.........4...a........%.5<<< skipped >>>
GET /star/albumcover/300/5/95/4228075837.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 08 Sep 2016 13:09:11 GMT
Content-Type: image/jpeg
Content-Length: 10336
Last-Modified: Mon, 05 Sep 2016 23:05:24 GMT
Expires: Wed, 07 Dec 2016 13:09:10 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 355583
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...(.
..(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...
(... ;.s.x~T....?*v'..4Vs]...g=1.......Q`.F.......?*o.&.....a..J '...;
...........i..s.^.....$......P..........F...5 .r......\...?..G .h.. .j
W%I.2?..&.tx.?..G ..F.....x..:...).........O.........k........Z..z/..(
.a.bt.W5..{..=.....k....E......=.N...............Z..z/..(.a.Q.Q\..o...
_..R.V.8./..)r..DtTW.w..)q.E<y.r..X...D..\......'cT..uTW...*...2..F
.n. x.....*N...$C......(.Ac.h................!R..oJY>".J...<....
..t.".d'..4W....YW.=.6.....G.{..2..."K.1\D....%Oc.~..'$.a..:/..&.h[.VL
}.n.o. |H.BH.g...".....G.Q^0.=.$p..j...0.n........O..6. 7.f.P..b....".
.2=...;_.."...b...X.#?......V.K.C.....?.a..D=r?.....a.....(@:.... Q.4.
..C.R.(..*.#9..@.=.4..j^..(..)....i5)..`f.,g......J1..1.....;..H..L...
#.9.A..)..H.*.h.......b.q.?Zn).G.1Rb.....b..6.!.S...O...... gf8Q....!.
c].....;\....D... ..[.e...E..[......3.....t.......I$.F.....q......<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-18239&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:09 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1008
Connection: close
Expires: Mon, 12 Sep 2016 15:55:24 GMT
Vary: Accept-Encodingsuccess.-18239.20.20.3200976.............2691282077,2439328429.0.11851
31.....Alex..........213708594,3569749960.0.6404490...................
......2381643413,221941387.0.5748059.......................1339133181,
1900276282.0.781690.........................2660363306,719668580.0.846
597.........................68407423,4026469053.0.3612009.............
........3270568087,4047384145.0.388187.........................1129054
947,1389999305.0.706607.................803888860,272200957.0.3356083.
..................264363408,3825220221.0.6276077.................27534
583,3526585285.0.3165396.....&..................777827618,2525807435.0
.874900...............1814397573,4124020893.0.4860547.................
......297204771,3405072269.0.6469664.................3616159354,106146
0611.0.5271666...................2385801008,3101331189.0.4821702......
.......4040872187,2253271338.0.4148755.................41027940,173940
2353.0.3630144...................1974518634,728809126.0.3610889.......
....4141689038,3031998189.0...
GET /lyrics/img/kwgg/personalAd.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:54:53 GMT
Content-Type: application/x-javascript
Content-Length: 3093
Last-Modified: Mon, 12 Sep 2016 15:40:38 GMT
ETag: "641db08-c15-53c5151538980"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:24:53 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 79
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive//read a cookie..function getCookie(cookieName){.. var arg = cookie
Name "=";.. var alen = arg.length;.. var clen = document.cooki
e.length;.. var i = 0;.. while (i < clen) {.. var j =
i alen;.. if (document.cookie.substring(i, j) == arg) {..
var endstr = document.cookie.indexOf(";", j);.. if
(endstr == -1) {.. endstr = document.cookie.length;..
}.. var ret = unescape(document.cookie.substring(
j, endstr));.. if (ret != "") {.. return ret
;.. }.. }.. i = document.cookie.indexOf(" ",
i) 1;.. if (i == 0) .. break;.. }.. return "
";..}..//delete a cookie..function delCookie(cookieName){.. var exp
= new Date();.. exp.setTime(exp.getTime() - 100);.. document.co
okie = cookieName "=; path=/; domain=kuwo.cn; expires=" exp.toGMTS
tring();.. document.cookie = cookieName "=; path=/; expires=" e
xp.toGMTString();..}..//add a cookie..function addCookie(cookieName, c
ookieValue){.. var expdate = new Date();.. var argv = addCookie.
arguments;.. var argc = addCookie.arguments.length;.. var expire
s = (argc > 2 && argv[2] != 0) ? argv[2] : null;.. var path = (a
rgc > 3) ? argv[3] : null;.. var domain = (argc > 4) ? argv[4
] : null;.. var secure = (argc > 5) ? argv[5] : false;.. if (
expires != null) {.. expdate.setTime(expdate.getTime() (expir
es * 1000));.. }.. document.cookie = cookieName "=" esca<<< skipped >>>
GET /lyrics/img/kwgg/personalAd.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:54:53 GMT
Content-Type: application/x-javascript
Content-Length: 3093
Last-Modified: Mon, 12 Sep 2016 15:40:38 GMT
ETag: "641db08-c15-53c5151538980"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:24:53 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 80
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive//read a cookie..function getCookie(cookieName){.. var arg = cookie
Name "=";.. var alen = arg.length;.. var clen = document.cooki
e.length;.. var i = 0;.. while (i < clen) {.. var j =
i alen;.. if (document.cookie.substring(i, j) == arg) {..
var endstr = document.cookie.indexOf(";", j);.. if
(endstr == -1) {.. endstr = document.cookie.length;..
}.. var ret = unescape(document.cookie.substring(
j, endstr));.. if (ret != "") {.. return ret
;.. }.. }.. i = document.cookie.indexOf(" ",
i) 1;.. if (i == 0) .. break;.. }.. return "
";..}..//delete a cookie..function delCookie(cookieName){.. var exp
= new Date();.. exp.setTime(exp.getTime() - 100);.. document.co
okie = cookieName "=; path=/; domain=kuwo.cn; expires=" exp.toGMTS
tring();.. document.cookie = cookieName "=; path=/; expires=" e
xp.toGMTString();..}..//add a cookie..function addCookie(cookieName, c
ookieValue){.. var expdate = new Date();.. var argv = addCookie.
arguments;.. var argc = addCookie.arguments.length;.. var expire
s = (argc > 2 && argv[2] != 0) ? argv[2] : null;.. var path = (a
rgc > 3) ? argv[3] : null;.. var domain = (argc > 4) ? argv[4
] : null;.. var secure = (argc > 5) ? argv[5] : false;.. if (
expires != null) {.. expdate.setTime(expdate.getTime() (expir
es * 1000));.. }.. document.cookie = cookieName "=" esca<<< skipped >>>
GET /lyrics/img/kwgg/personalAd.js HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:54:53 GMT
Content-Type: application/x-javascript
Content-Length: 3093
Last-Modified: Mon, 12 Sep 2016 15:40:38 GMT
ETag: "641db08-c15-53c5151538980"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 16:24:53 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 84
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive//read a cookie..function getCookie(cookieName){.. var arg = cookie
Name "=";.. var alen = arg.length;.. var clen = document.cooki
e.length;.. var i = 0;.. while (i < clen) {.. var j =
i alen;.. if (document.cookie.substring(i, j) == arg) {..
var endstr = document.cookie.indexOf(";", j);.. if
(endstr == -1) {.. endstr = document.cookie.length;..
}.. var ret = unescape(document.cookie.substring(
j, endstr));.. if (ret != "") {.. return ret
;.. }.. }.. i = document.cookie.indexOf(" ",
i) 1;.. if (i == 0) .. break;.. }.. return "
";..}..//delete a cookie..function delCookie(cookieName){.. var exp
= new Date();.. exp.setTime(exp.getTime() - 100);.. document.co
okie = cookieName "=; path=/; domain=kuwo.cn; expires=" exp.toGMTS
tring();.. document.cookie = cookieName "=; path=/; expires=" e
xp.toGMTString();..}..//add a cookie..function addCookie(cookieName, c
ookieValue){.. var expdate = new Date();.. var argv = addCookie.
arguments;.. var argc = addCookie.arguments.length;.. var expire
s = (argc > 2 && argv[2] != 0) ? argv[2] : null;.. var path = (a
rgc > 3) ? argv[3] : null;.. var domain = (argc > 4) ? argv[4
] : null;.. var secure = (argc > 5) ? argv[5] : false;.. if (
expires != null) {.. expdate.setTime(expdate.getTime() (expir
es * 1000));.. }.. document.cookie = cookieName "=" esca<<< skipped >>>
GET /today_recommend/images/201609/1473516821210.jpg HTTP/1.1
Accept: */*
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 14:57:53 GMT
Content-Type: image/jpeg
Content-Length: 78710
Last-Modified: Sat, 10 Sep 2016 14:13:41 GMT
ETag: "57d41515-13376"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 17:05:19 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 12391
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
.................!1..AQ.aq"....2...B#..R3.....br...$...CS..%5u.6v7..s.
4Tt.Vc..D.G8.UF..e.'......................!1Q.A...a.R....2.q.."B3.Db#.
...........?..U.......................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
..................................................................<<< skipped >>>
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6001&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:14 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1165
Connection: close
Expires: Mon, 12 Sep 2016 15:55:30 GMT
Vary: Accept-Encodingsuccess.-6001.20.20.7192493...................63427122,3835846420.0.71
90414.........................1198874255,1035541931.0.7189892.........
........4051100874,1802880965.0.7187928.................3999431891,182
7885286.0.7188045.............712876572,1908876153.0.7187128.G.E.M....
.................3264621468,1598674718.0.7186127.....&......&......&..
..........495620052,2212332008.0.7186112.......&....&SING....&........
......544557511,1843606841.0.7186129.....&................3492252882,1
803534795.0.7186125.......&..............3819177224,843281173.0.718612
6.......&....&......&....[..........]......224136793,3615237464.0.7186
128.......&..........4278459077,3194522365.0.7186130.................2
53048455,3342949114.0.7182616..............-(.........................
...........).1731802010,159511408.0.7183671.......................2930
647947,1150973466.0.7183589...............993134774,3210322186.0.71830
05.....................1954346820,2331208614.0.7180760..............-(
......................).3408240533,3150334849.0.7180472.......&.......
...............3417956844,1718789487.0.7181058........Here We Are-(...
...................).1053210713,3225816485.0...
GET /lyrics/img/kwgg/adv4480/1473242726679.swf HTTP/1.1
Accept: */*
Accept-Language: en-US
Referer: hXXp://wa.kuwo.cn/lyrics/img/kwgg/adv4480/index.htm?ver=MUSIC_7.7.0.1_P2T1
x-flash-version: 11,6,602,168
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: wa.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:44:47 GMT
Content-Type: application/x-shockwave-flash
Content-Length: 36008
Last-Modified: Sun, 11 Sep 2016 15:40:36 GMT
ETag: "1371732-8ca8-53c3d335da500"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 15:58:40 GMT
Cache-Control: max-age=1800
Vary: Accept-Encoding
Age: 1788
Powered-By-VeryCDN: HIT from cuc-xh-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveCWS.....x....T.....8..]...h...58........I......].;.%.........}......x.
[email protected]...@......`c.......|j.R.^.v..|.-A*k77'>VVOOO
.O..G. V /// .; ;;............ 5........f.`'7.....m.SGw7A*...z.;......
.....................................^.Rv&...*........&v...\.....`;s.N
........,...C......dcf......s.qp2......K..<...h.fbn.f.W0.3..3;.....
....._............[.....`.OL..qkn..j..]..\/s3V.;.{..7.Wz...kn.g..bo.&d
..d.63....................X....tH.3ST......./oW75.....U....U..........
...FQ.O.......BVB.....6....qpK...@.^I. P...]..CL........'..1./4.G3.?x.
;...............n.........-..#......y$$xD%@.... v..._.....c.p.{X.K.8..
..N&....0%H..U...'.|..C../.....d..&.?...f.o&$...Ip.x.x.%A...q..D%..x9.
.....B3.................O....f.{.....C........([email protected].
.........k[..k........a/'.3[.7.S....R.j......Ri......-..2>...>J.
f>.f..T........M3..K..Op...?..P...n..T.K.:.*...... ..f...K......qq.
.(^S.............c.........x!...!...=.............dg.e....d...$.K..U'.
\ . .._.......`[email protected] ..$/......7.._...F....#VR.....w._;@.....5.
;......;.;z..S.....e.........)&%...G....|..$...8..D..(.....8c._..U..m.
..?.c.....Wi..........U.P/..`.,...z...}=..`a..............".....zFEEA.
[email protected].`0.^z.y....z.....X8x.hD.7P.h...
...BA...c....a_............@......W..A0qf...SK....C.2....Bs...W..I..'x
.:.h(X(X......(Lh.J ........3;NB...\`..s\..%....`0a0...EUGIy1Y..|o...C
.).....T1.......ijQY.....#.......`f..x.H....|......RY.<=.....}.....
Kh4.4..........?qU)...N.$...4.a...*9.<!..Tk2..(.ju.Q=4...$U_8..<<< skipped >>>
GET /today_recommend/images/201609/1473055636025.jpg HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: topmusic.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:28:17 GMT
Content-Type: image/jpeg
Content-Length: 128516
Last-Modified: Mon, 05 Sep 2016 06:07:16 GMT
ETag: "57cd0b94-1f604"
Accept-Ranges: bytes
Expires: Mon, 12 Sep 2016 17:28:01 GMT
Cache-Control: max-age=86400
Vary: Accept-Encoding
Age: 15786
Powered-By-VeryCDN: HIT from cmc-jz-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: close......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
................!..1..A"Q2..aq.#B...R3....br$..C.u.67......4Tt.%5Vv..S
s.G8....c.&F..D.Ue.'......................!1.AQ...aq2..."..3...RD.B#.b
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected](
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@.
P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....
@.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](...
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]
([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@
.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](....
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](..
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....@.
P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.....
@.P([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](...
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](.
[email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]
([email protected]([email protected]([email protected]([email protected]([email protected]([email protected]([email protected](..<<< skipped >>>
GET /star/upload/10/10/1473517608458_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 07:51:22 GMT
Content-Type: image/jpeg
Content-Length: 59751
Last-Modified: Sat, 10 Sep 2016 14:19:04 GMT
Expires: Sat, 10 Dec 2016 07:43:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 115452
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....,.,......Exif..MM.*.............................V......
.....^.(.......................i.........f.......H.......H............
..0221....................0100........................................
...............C......................................................
..............C.......................................................
................,.,.."................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?....1.Wq..;.....
...5...v..........u.Zt..0..t.`~B....<....7.~_...Zp.B.....q.........
.......Q6n......GeQ...c.cY.\..i.Vn.I5...'...VS...g....mk.F9eV=2T..NE'.
....._......%t..l.z[......I..vm.#8..|zw.[R..m..R...<?.^...<t....
.....F.s .^*.U.w^.R[P..m.g .....z.j..... q..j.......O.zw.VQ:*..l....Of
.......N.Sh.b.. g.?.*...........u.s.L.g.......v...>..S......;...T.$
..'.'<....d..m.......a....N6...99..{~8..j...4...2........<D.`..y
.?.j.h........(..$.r1.....02Z...-.c....;s..}.s.L..V..B..'.n..9...G..v.
g......]$...vvvw...01.|......{..{Rll...28.[).&p.$.%Fs....x;Gp..>...
)...08.#.q.3...........U......S.j....q...J..[....Nq.z.....k !...@....=
[email protected]\...,..rvi.%m,.....G......*F.'..T<..?L<<< skipped >>>
GET /star/upload/14/14/1473492918254_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 08:10:52 GMT
Content-Type: image/jpeg
Content-Length: 84780
Last-Modified: Sat, 10 Sep 2016 07:27:30 GMT
Expires: Fri, 09 Dec 2016 08:02:54 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 200684
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
...~._.....m.....{...K...|D..Z....:G.......7qqy}wu...o]JDU.H....>..
...>4........g.>....5O.j....]jW...*ZA...O.......U.=.r....-....Y.
..U..?.k.W....?m.....t.I../..N_..|..../.F.4...f..2$['.u.{(N........<
;....I...x..H..]...i.......I.<......QK._.j....>3^Y.{&...w....w.E
.I...\.....0< ...%*..I....h.V/........#?.U.h.q...97..0.3J.gV.<4i
{9K...Bu*%....4y(S..i.Jq....J./ZO././.....~:....]-.x..>&...~ .d.kmF
..i..x%U....SMkY.7.[5.X`t \...#..1.'.I#......o...h.m.MC...{..|7..x..h.
.&.8<'.k.. ..|m...}.W.%,./.0.f.....s}.Q.~......_..,.......5.|S...k.
..x.T..C*.m/-5.&..O..5.p/4.B.w.......".nS..3.... ...5ef.yq.z.G..qt...b
)JVqnP..U.R.).K..2.F..:U....j.-......qnM..Wwq....U/&..P..=..o.....z..O
.>.......xy.N.me....0.._._.h. .u<.j..s.h...7.W...!..[..O......G.
<|c.,...... d.4....7g..'.>$....Ykz.../..h...j......k6....o.@..^[
-R.Dl. `.V.........Zy..bc.F.3.AB.LT*:T...:.*..J.....k..iFrKS.=8{h}<<< skipped >>>
GET /star/upload/15/15/1473492953071_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 08:10:50 GMT
Content-Type: image/jpeg
Content-Length: 69024
Last-Modified: Sat, 10 Sep 2016 07:28:05 GMT
Expires: Fri, 09 Dec 2016 08:02:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 200685
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....,.,......Exif..MM.*.............................b......
.....j.(...........1.........r.2...........i.................H.......H
....Adobe Photoshop 7.0.2012:03:22 10:15:49...........................
....................hXXp://ns.adobe.com/xap/1.0/.<?xpacket begin=".
.." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns
:meta/" x:xmptk="XMP Core 4.4.0-Exiv2"> <rdf:RDF xmlns:rdf="http
://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:a
bout="" xmlns:xapMM="hXXp://ns.adobe.com/xap/1.0/mm/" xapMM:DocumentID
="adobe:docid:photoshop:d1665559-73c4-11e1-b1bf-9462f8c09519" xapMM:In
stanceID="uuid:e38decb2-73c4-11e1-b1bf-9462f8c09519"/> </rdf:RDF
> </x:xmpmeta>
<<< skipped >>>
GET /star/upload/12/12/1473517282076_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 16:11:01 GMT
Content-Type: image/jpeg
Content-Length: 53107
Last-Modified: Sat, 10 Sep 2016 14:13:39 GMT
Expires: Fri, 09 Dec 2016 16:11:00 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 171874
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?........
...L.:....p.0G|......f\.X.....=..^.......v...7Q....N..8.f},...s....l.~
|.._.O........ww.....>/........J......g1..W.g..=...3E[............q
.......?>.p...=......rn)^......].].q>eu..[..?Qh....[J..._.@(..?.
........QI.D.......?J..^y>....T..............>.W_.J.._...q..H...
....8'.....:v..q.^..iB...........6.J.....j..Zh...F1.p.?{#<.`...#...
.8..=..T...t...u.h.W'..s.=?....Q..M.5.{......mCr.;.....d..}.T1....`c..
.......D.>@.J.,T.`.? .N.RH..W.h......5.....!k)...L.H.2......C....(.
I.........|.INj.i...W....9.;H.x..{q*......-............N.Oqa..X..O..R.
...W..b.J....D|BW....9._.....8.M....H.0......ZM....EF;G.....B.YKw..b.&
lt;9d.=....\[email protected]#...X.q ......e....S.)I5..............$k.Q.jZ&
lt;....i......u:..x{D....<.Y.0..,.."2...2..1W.x.Cb.Z......m...T1...
E3"|.h......Qc.T.M&.....G..(.V9mu;.x....7U..KB..9ue.I-...s..CP.{....%.
..Rd........*2.X.T....%I.~m....IM..:..c'....~_....].a...Bt...AFr..<<< skipped >>>
GET /star/upload/2/2/1357790699490_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 23 Aug 2016 22:54:38 GMT
Content-Type: image/jpeg
Content-Length: 11199
Last-Modified: Thu, 10 Jan 2013 04:05:05 GMT
Expires: Mon, 21 Nov 2016 22:54:37 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1702860
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive.....0Exif..II*.......1...............VVV.meitu.com....C..............
......................................................C...............
........................................................d.d...........
....................................................}........!1A..Qa."
q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwx
yz....................................................................
..........................................................w.......!1..
AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghi
jstuvwxyz.............................................................
.......................?.. {..MD.1..t..R.K[.i/......d....)..w...xcps..
/.h..;...F5....z...^........5\m.l.....-c..M... . .(1.A..{....]M4..i..{
.....,.^.z[{.U...R.....i.<y7.G...(.[..........Q...J...^...m....C$..
... &...oKh....{..J/....H.........c...;..........;....iY...:.[...Ko..3
...T.\.....{..l..4.T.....;....D".....$...s.U....z..8....W.n.........8;
.`v [email protected];.J...1..K.1S.wmz[G....W...}{zkm{kx&..$.F
...Z...'......$.>.......U^-kR..m.I;>.7.....e.........V.^{jz2i'81
.P...X..e.....$...M............^kAC..m&.w....|...............[.?.8.O=~
...f......-...C...Y.c>...=H.........yz....}..L..F..'b...'.c#.4.....
..;..\..\....&.iq....c..r_y..........|,..`.e.m.c..M.q^/.......F.U...c'
..M...f.M. ........S..!..7..%.z=.N.>d.v.\...7..|G5....y.....S.<.
.w..3M.. m...A;.i.|.AvGo......<.FkN..0......d..'$.....M7gk....;,.e.
.'V...F..^.]h..~..{>.....@\yW.....r@...^.0;...L...NV...J..0Ok..<<< skipped >>>
GET /star/upload/4/4/1473603310164_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:01:13 GMT
Content-Type: image/jpeg
Content-Length: 53798
Last-Modified: Sun, 11 Sep 2016 14:07:23 GMT
Expires: Sat, 10 Dec 2016 15:53:15 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 86065
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
.....................<CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), q
uality = 75........,.,..".............................................
...............}........!1A..Qa."q.2....#B...R..$3br........%&'()*4567
89:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...................................
......................................................................
.....................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&
'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz............................
........................................................?...d!...9=j5.
...........9I$.....II..~.N....{.Q..s.s..W..R.O.j..;..9.....:.....wwgv.
.2..[.l.$P...........;z..3.L*..9..PS....Z..z.T.....M..~..S*....:.RU...
.bp8..S&.V.t..=.o..BK......n...mZ....z......=......(*.dzz....Z..E%~n.8
.....=..OCXV....w...r. .......kKp..8..O9\.{z..L.......I@]....1.l.y.p..
Vf.j.........;[email protected]...^..hM).WTf.......e.......H.W.f..P|.r........K}
..S.3..v.:...5!B...U..i..S.I{.Q..........<;w. ...Jw..c.4U.L.M.D..c.
.?P.W...'.G...;S....XE..J..nD?...Z..4NH!.V............i..c...Xb.^Io.~h
.%WW...YW.....xBZ.y..,..,%_lL/nVt....@........@. ..M..3...cog.i{&.%.ms
)&....i.=.......[...9.I...s........S...J.0SRJ.z ..Jq...R..k..q...KM...
.~..7.c./$./n...ye}.Gg2.{...".7iu..l....q..)...*Yo...x./.... .V.h...Y.
.km....}!-..[......IE......|.m..W.O.E.....1.#NTP..V.n.._"YQ....g ...[.
..S....\N...Q)$.#....@<.q_Q...pP......S.W.4..y.6..[/N......-...<<< skipped >>>
GET /star/upload/13/13/1473517589485_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 07:50:07 GMT
Content-Type: image/jpeg
Content-Length: 94006
Last-Modified: Sat, 10 Sep 2016 14:18:45 GMT
Expires: Sat, 10 Dec 2016 07:42:09 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 115528
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive....'"Exif..MM.*...............D...........F..........................
.................................................(...........1........
...2...........i............. ............'.......'.Adobe Photoshop CS
6 (Windows).2016:09:09 22:24:59.............0221......................
.,...........,...............................n...........v.(..........
...........~..........%........H.......H.........XICC_PROFILE......HLi
no....mntrRGB XYZ .........1..acspMSFT....IEC sRGB....................
...-HP ................................................cprt...P...3de
sc.......lwtpt........bkpt........rXYZ........gXYZ...,....bXYZ...@....
dmnd...T...pdmdd........vued...L....view.......$lumi........meas......
.$tech...0....rTRC...<....gTRC...<....bTRC...<....text....Cop
yright (c) 1998 Hewlett-Packard Company..desc........sRGB IEC61966-2.1
............sRGB IEC61966-2.1.........................................
.........XYZ .......Q........XYZ ................XYZ ......o...8.....X
YZ ......b.........XYZ ......$.........desc........IEC hXXp://VVV.iec.
ch............IEC hXXp://VVV.iec.ch...................................
...........desc........IEC 61966-2.1 Default RGB colour space - sRGB..
..........IEC 61966-2.1 Default RGB colour space - sRGB...............
.......desc.......,Reference Viewing Condition in IEC61966-2.1........
...,Reference Viewing Condition in IEC61966-2.1.......................
...view.........._...............\.....XYZ .....L.V.P...W..meas.......
.........................sig ....CRT curv.......................#.<<< skipped >>>
GET /f.page?op=query&uid=0&kid=6424671&cont=block&src=mbox&fmt=json&pn=0&rn=20&version=MUSIC_7.7.0.1_P2T1&ttime=20168122056 HTTP/1.1
Accept-Encoding: gzip, deflate
Accept-Language: en-us
Referer: file://%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\quku.html
Accept: */*
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: fpagedata.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:33 GMT
Content-Type: text/javascript; charset=utf-8
Content-Length: 5560
Connection: keep-alive
Vary: Accept-Encoding
Content-Encoding: gzip
Expires: Mon, 12 Sep 2016 15:14:36 GMT
Vary: Accept-Encoding...........[kO.I.. ..)C4$..{..Tn;.(.....Z.V#.z..86.M2h.G.B..H.CB....`H
......../.S.6`0..9.Z./U..U.....V..3.x*.=...]>S{.1.3q..'.8......F..
3....x`../.q&..B...i..#;r.^.X?.o....".oJ....p..I..........:S-.H...;...
..."._.x....n.Y...6F.q.^*.......w.....7...oz..P...L.....v.1..D.H..D.H4
S5dK.ub.?.U...$..D./.O...^..AdK1,.........h......v.SS...?(.N4...knwK&g
t;......q.....o-.n.....[KO>.Yx3..8...*.0=...0..bH.fR...}..c';.L...O
.....c:......g.. .A..*...L.....~..r|....7..w..W|f.G>..W[..f.. .w:ci
..P..w....;/x{..\q.....|..|......o.........d.=E.N....ej..}.q..g....m7.
....SQM&n.-cl...wd./.2E.tSc......1|G...$c...>.G...X.....R1.g|....@.
g...Kg.Y[.<1.n.z,.MbR. .i..1....}..]._....nR....x........Ie.R..?...
y......*......w*.Y....:5."..y.k!..D<8O....S.<.d.V...W.pG.)9h,D..
Y.V...........~........B...s.m[...#.?K...;.)..[.z..>V.2..).|.C.a.D5
-.J.I3d....C0?2.LU.A..! t.........Y.9.:..b....~^.....%..N|.....Std..J.
.Z....e.[........k.....6.:g..m....'3.l...?..V.=...0.......2.....C....T
...Uq.uP...[.D,....]V.....d.....($.H..>K|..g.P.n.c.}....0..eh..6...
.....!..p6.e.U...T..z>..z.......hTUY]S,y/...o#.(..T..x..x<....}.
DH%x..~...?. .a9o.9m..X....w^N1S.-........GU. ".(...P.*...z.......\...
....w_....w.a.4.O.6.$...(....I%..D.|..K4].o..D3M..s........o..&..-..s^
.z.W...F.b.@=~..M........G........d.._...5....m.g...M1.a_.d..........o
.........1.....gv|.a........:k.E..7... .e2_...w0...Pgh....(lI...Eg.1..
...e........;[email protected]...#<.....:.c..ta.S~c..~.2.......K..K3,"...
;....Yq....hh.Xu...|...T .P-..7]..k`.....t....4..S...".i...g..}.:.<<< skipped >>>
GET /star/upload/6/6/1472207043078_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 28 Aug 2016 01:08:19 GMT
Content-Type: image/jpeg
Content-Length: 44241
Last-Modified: Fri, 26 Aug 2016 10:16:42 GMT
Expires: Sat, 26 Nov 2016 01:00:47 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1349230
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......F.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:9DE44B49EF65E611B
365B316412B7EAA" xmpMM:DocumentID="xmp.did:7E4DE502681A11E699AAD147EBC
9D942" xmpMM:InstanceID="xmp.iid:7E4DE501681A11E699AAD147EBC9D942" xmp
:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:781B0C671768E611B64A87FA46B8C619" stRef:doc
umentID="xmp.did:9DE44B49EF65E611B365B316412B7EAA"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
......................................................................
.............................................!1A".Qa2..q.B...R#3...bS$
.r.Cc.....s.4...%5U..6FV.....Tt..W......................!1..AQ.aq"....
..2....BR.b#...r...3.S....C.$T............?...W.....\.i.w].'...D.D..P:
RQKG...wGt.x.......&..53.)B.L......M.7.(...D1..1!Q.K......F...b..:...
.u$.....p....C......t.....@.'e.......%..x..( ..;.j;.......C.S.].D.<<< skipped >>>
GET /star/upload/15/15/1473653699055_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 07:09:04 GMT
Content-Type: image/jpeg
Content-Length: 38419
Last-Modified: Mon, 12 Sep 2016 04:07:05 GMT
Expires: Sun, 11 Dec 2016 07:01:04 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 31586
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*[email protected]://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c01
1 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:b5d57c07-9e51-eb4
8-839f-8d309b4cfdaf" xmpMM:DocumentID="xmp.did:623DA0D8775F11E6BCA1DAE
1B980C9AE" xmpMM:InstanceID="xmp.iid:623DA0D7775F11E6BCA1DAE1B980C9AE"
xmp:CreatorTool="Adobe Photoshop CS6 (Windows)"> <xmpMM:Derived
From stRef:instanceID="xmp.iid:454CD2B65A77E61195D288805FCC1B41" stRef
:documentID="adobe:docid:photoshop:1164f91f-767b-11e6-8c0d-ab51cc70fe2
c"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> &
lt;?xpacket end="r"?>...XICC_PROFILE......HLino....mntrRGB XYZ ....
.....1..acspMSFT....IEC sRGB.......................-HP ..............
..................................cprt...P...3desc.......lwtpt........
bkpt........rXYZ........gXYZ...,[email protected]......
..vued...L....view.......$lumi........meas.......$tech...0....rTRC...&
lt;....gTRC...<....bTRC...<....text....Copyright (c) 1998 Hewlet
t-Packard Company..desc........sRGB IEC61966-2.1............sRGB IEC61
966-2.1..................................................XYZ .....<<< skipped >>>
GET /star/upload/13/13/1467861765917_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 07 Jul 2016 03:41:09 GMT
Content-Type: image/jpeg
Content-Length: 14004
Last-Modified: Thu, 07 Jul 2016 03:16:48 GMT
Expires: Wed, 05 Oct 2016 03:35:05 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 5832863
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*............... .......................................
............................................................(.........
..1...........2.......................i...........g.........Canon.Cano
n EOS 5D Mark III......'.......'..VVV.meitu.com.2016:07:01 10:05:06.".
........................"...........'...........0...........2.........
..........0230........................................................
......................................................................
..00..........00..........0100....................X...........g.......
......................................................................
..........1...........2.......%...4.......E...5.......\...............
........2015:12:01 00:00:00.2016:05:27 16:34:28..-..O.................
..........i.......@[email protected]..............
.........EF24-105mm f/4L IS USM.000061df1a............................
...........(................................ ......H.......H..........
C....................................................................C
......................................................................
...................................................................}..
......!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXY
Zcdefghijstuvwxyz.....................................................
......................................................................
...w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJ
STUVWXYZcdefghijstuvwxyz..........................................<<< skipped >>>
GET /star/upload/4/4/1457596018948_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 28 Jun 2016 11:48:06 GMT
Content-Type: image/jpeg
Content-Length: 28641
Last-Modified: Thu, 10 Mar 2016 07:44:30 GMT
Expires: Mon, 26 Sep 2016 11:42:16 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6581246
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....,.,...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?......Q..D.KP.............MP
......./[email protected]......}..~..h.f...Q.7.......6-o..G.u....o
..M............7..b..mw..?.n.........ow....n......h.......][email protected]|..
}....AKb.7..W.w=....E..........-p.n .....u.......r ..................s
...O..5.:.H...?..9....S..-.. ..nvg....c..V..qvx.W...i....y......4...x.
.......a..g.*....&..My..?W....H..k....?....rMz..>.?... .Jk..N......
...q=.8..........=..,>.s.J...D.e.._............4..e....{........0.2
.o5..........H....A.........S.....@?...........z.............b^j:.'.F.
..x....[.OT......<....5....b.....<....3..Tu.........}R.:.....K..
....ee....mY.......idr.(...;....&....6.T.......>]......x. ..ma.....
[email protected]......:SHE...y....-j[.N8.C..IbT..8...L.5..b.k..Mmn..W..y.0.
......;u..b...KJ...._._...#Qo.8.........Wf]...v..<Qey.. .;....v.$c.
=.S..z.h....)............H.Yw.@Hc..|..{d..........g..V\e.....t.q.r<<< skipped >>>
GET /star/upload/0/0/1473577543328_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 07:10:32 GMT
Content-Type: image/jpeg
Content-Length: 19939
Last-Modified: Sun, 11 Sep 2016 06:57:53 GMT
Expires: Sat, 10 Dec 2016 07:02:34 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 117899
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
.................................................................D....
......................................................................
....................!..1AQ".aq.2..R#.....B$.b..r....3Cs%...Sc.4D......
..................!.1.AQaq".....2.....B..Rbr#.3...C...cs$5............
?.......f|...[r...*.UD..M.ub6..\........j.....5.5Lb...~...2rV.&,[8....
.~&.__....\.i....=.....]..=........[6.)v...k...m.b....,..[.W..2O....b.
{..:$x...........K'....bFu..s...........G.6.....C..^..w.......[P~..Nk.
.c........[..Y|..T.q..K. [email protected].@[email protected]{.>.\..q.g~
M.:..jU...M....1.y?L...:.m)\..|./.......;../o.T....j.....B..mv...t....
....m._Rc._$..Y,..".... d.q.$. ...f...K....k....-.....{. .P......W.d9.
._P.....g....V.......U E.9 X..[...^....ZoPBJV.:Z@%...6.JV.w)$.Z..F.T..
.I.v..I.j..>....2.T.-....k....y}.\....%......w.\....k.. ..0.8P-.RR.
..HR.,...* .m.. w"..*4.4........Rq..q....{H.A....|.].......G.}1>K..
:...}...c..}...Z.....:F.)...../........A=.?...\.]...|.z....8..)x.#..[.
..w3..~..:8:.k..0y. ... WUw.W.~..\.]u..e..mE .._P...Y......&.:...|..9}
.......&.m8?j.c*$...R..^...z7.n.......S[.....Af....Ug.T...Y....O}f..&l
t;V.tX.R.$V..TD.. B.....W.lmA.Vc....0.K......F...6..p8.........._...~.
5......\.j...x#..O......g...<..BST.....*..O.>....J..lo\L..v.o..1
d..|<I....a.m...?"~&.r.Uw......n..G.K..&.\..$...w].._./..k(.r..%.r\
..!en..._X`.Z...{*..I....}..|..^..72o.u...O.....Bj.R2.2..yd .Y..W<<< skipped >>>
GET /star/upload/10/10/1386901161434_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 02 Jul 2016 07:31:50 GMT
Content-Type: image/jpeg
Content-Length: 3947
Last-Modified: Fri, 13 Dec 2013 02:19:20 GMT
Expires: Fri, 30 Sep 2016 07:31:48 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6251023
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?.....V.K.i*D..I..'.k..ANwz..
........8..x$.p..9..uI ]..6..@.&.,GdH.#.Z.R.......;f.J..1..\~..b......
.......I..[.].11.. .4........Y.s.1..2V5j...Z.Y.`.W:1.Sz.....q4.a.t....
...S...,./AZ....W.........O5s.%F.......J..1g...n...kB...B....zr...Z...
...nEfKv..ea......e.....i.4......O....6.E).Q.s...c.E;.!*...P.a .p. .n.
..FD~..L...~...08.j%;.%s..W.n..X.Fe..EL*.9.."|4..w4$......e.".SL.n.'..
YOL..[..<..K....u.....A"...)...q..-..7....V.q..Y.P*....y7..k.....uv
..C..{.F& 4:M........A....F.qE..~.?.|g{ic...N....-..........>.\..H.
..R[2c. .A.>[email protected]..".V.=})h;.U...u.OcS(......5..,Dx'
.*}.{i.%..<F.."..... kpO..=.z...f/.......l...M...........r.*i6.tF[.
._jG...&..(..................u...{.F......(.._....x-..f..4...^._...C..
|...t..Q.bx5".o9..zN=.}........<c.|9...M.xW^.Z.S.J].....V...%..T...
GqQ)8.Zr...0...YXr K.s".,u..i.FH..Kf2...."...f.Ol..Bln........;..C<<< skipped >>>
GET /star/upload/3/3/1372746952099_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 03 Jul 2016 06:22:21 GMT
Content-Type: image/jpeg
Content-Length: 4344
Last-Modified: Tue, 02 Jul 2013 06:35:50 GMT
Expires: Sat, 01 Oct 2016 06:16:23 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 6168793
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, MISS from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....d.d.....0Exif..MM.*.......1..............VVV.meitu.com.
...C.....................................%...#... , #&')*)..-0-(0%()(.
..C...........(...((((((((((((((((((((((((((((((((((((((((((((((((((..
....d.d...............................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
[email protected]. ...g.
#4.......w.|.q..p...D...A...G".}....h..Z.-.!......P.E......R.b....se..
g.....e..e.....-.X.....i.-..[.^$7WB.7.....{n..S..4t>...-u..&[x..D.}
..b.$s.......N...V.I;...........q.xRbD.(....'.....A..I .........-4..B.
k..].D........{._....L....i...`6.....M.....&3.|[email protected].%
.J..]..S...P.K........8>Y.4..D..b.{.!..[D..y.dF3.".fh.e...t.^.....0
cT........... ...1Qwr.......... ...,...wy'...Ds....O}P......7.:DS..M..
|..K.W.<.Pi......9n...!..M....m..T.L`.#..&..<.QP.......4H..k..e.
.'......O....&....R}......(.....`% :..X..xn.ba.dA........R:......zx...
...'.Go [email protected].#..Z..\[.=.g.GtT.l.W.....W,....{...(.W..
k.]..f....x.1.. ..$.c.P0...09(...8.j..t..i)..i...$...xc..9\.Ry........
.emN...tw..R...3..[..P.B..p..h.....B..J.-.Wi.a...k.s..!..B..W p..<.
;.......h.q.......Z..e%..0.........Uk.{.7ZP.Lz...\X.X..\5..}..c.O.<<< skipped >>>
GET /star/albumcover/300/23/85/340244866.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img3.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 07 Sep 2016 16:10:11 GMT
Content-Type: image/jpeg
Content-Length: 22933
Last-Modified: Wed, 07 Sep 2016 09:44:02 GMT
Expires: Tue, 06 Dec 2016 16:02:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 431121
Powered-By-VeryCDN: HIT from ctc-cs-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?..>
;....6.e....Bq...T..z..-. [email protected];&.....1.d.5......MB8Yoo...v'8. c..
...1.t..m.5......Fyv*..c...W.J...&.hu....e..%...^.Z.i$..WB.!pH...'...
{.N.d.!.C ..z`..VN.qo{%.....*..Lo.....S.1.M.d....;'F..n.....{V.....R..
...=f/.j.WW&].x"[X..L.....s...6.. -..'.v..g..2[b.o....*....x.H...K;.Y.
Y.A..0e..'....c\..j<K...r....an&?)GR.....x.t...H.j... ;....$.....~.
...~.....?,........vV..{.........q...r...Kx............ .>&_.oub..K
...3Gt.yX~>..'...`..q|...........Z...........@P?...`...XQ..........
'....q..y,.;.r.Fv..q.9.8'.'.c. ....X.. .1y.Td.F.....m$.9.x... j.w..H..
F..Mw.....X.....j..|..V.H ...@.{...Z.......b......o.0..... .........t.
.\.g....T.L."...$..[...RH....=*....6...........-.{.R...............N.
w..A...Z%[email protected]/.Q.r.F^.rl4...Qm.dp9...c.^=..........^T.~..
)..ylw(...#....Z.%............q^I..K...%...i.|.....?,WM...<e..b..X.
.=.z...=.6v..l.....B0....99.....L.g....W2..j....4O..Tz../...T.ydf.<<< skipped >>>
GET /yl_res_manage.spread?uid=6424671&version=MUSIC_7.7.0.1_P2T1&source=kuwo_jm429.exe&t=618703 HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: deliver.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx/1.4.6
Date: Mon, 12 Sep 2016 15:55:58 GMT
Content-Type: text/plain
Content-Length: 232
Connection: close
Expires: Mon, 12 Sep 2016 15:55:58 GMTViJ7XRRBOUsqZ3gXUxI3XA9la0JDEBkdI2MKfD5IEHQNSzZKCEwuVgsRMyUze3VFHGMRRQ
9xDTpLL2M3VzEdcmdocmRRdHNRJjlrK00gZSZTEjZwIHQsQ1pDT1pbcQJFeBZNDHVcH1oq
ZjVJImlwa0R6IQ4fXVwvZzpJI2sRWy0VTBZ3SUlLXktHdi9yM1QbQRd1WAxyG3EXZGQ/Mj
M2MzYGJXwjLkYzVjRmLFUq..
GET /pagesig/vipMbox_new/7.7.0/vipMbox_new.zip HTTP/1.1
Accept: */*
Connection: Close
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: updatepage.kuwo.cn
HTTP/1.1 200 OK
Server: DnionOS/1.2.1.12
Date: Wed, 31 Aug 2016 05:13:27 GMT
Content-Type: application/zip
Content-Length: 511009
Last-Modified: Thu, 03 Mar 2016 08:16:31 GMT
ETag: "950023-7cc21-52d209dab35c0"
Accept-Ranges: bytes
Expires: Thu, 22 Sep 2016 13:46:37 GMT
Cache-Control: max-age=2592000
Vary: Accept-Encoding
Age: 1735728
Via: CT-CNC-ZJHZ-P-6-47 (DLC-3.0), CT-GDFSSSD-C-97-106 (DLC-3.0)
Connection: closePK..........]G................vipMbox_new/PK.........{cH...20..._~.. .
..vipMbox_new/allInOneNoTitle.html.<ks.....L...3'mgn".y.y...s....L.
rn..., ..YV,9q....A.$..%.....R PR...f._..l../....e.In....J.k..^{......
...3....}./DZ.....z?=.G......>.:.......?.)A.....#...gEF...|F.......
.H..5>>.2.....Q._P....X..f...%......t#... .=>x...O....cR.L.;.
)..{4s.y~......'*....G.,..!...P.C......)=ye...I...^.!.9n........."p...
.o.c-.,...p...}..zHY..89.q..K.}.........\[email protected])
~.`.F..b../;F.|....M,N.~.`..[....M.....'...N}..R..#........N....L..)/.
.B?/...v8..uq..{.0M.H~<..........%J.M.O...p...C.c1.!`er )0..`....r.
..d.(...#...t..4D.........ZuzG....GR>.".( ..y.{..ve.L...9.$......./
6 Y..n..M...X0..v.1.:.dJ.I*.C^0A9....&......=. ...M.....|7%..{K...-K.h
<Jq2K..P..P..)...o. ...7.J.b...&.v.Q].........f.....*.X...W....>
R/o....}uy^.2)^....O.wS.n....l...j..w...u..F.De.G....!......n.@#......
..p.....b..<!.h..-.....%M. ..b..j.xC.=..8q.........L.1u..n...P...6.
.<.n7`..x..._..8.0.....pI`.........4...A..;...S....vwV.........:.T.
(.)G&.?._..S..[y}-..6u.e.=Tu#.;.16D5D7..R.;/*.. [7......m..!..|.r.....
?Rk....g.....Fi.{uq...........B.......*.!.{...t......?.....%....1....Y
.gG .........x.....?/.K/p..gd.s0... .E....q.j...*.c.4 j.v...v...f6....
..y.M*t.}..5..g....Sh...u.......L..|JIw..A..E..O..A..*..7.t..1....;.|*
..]...`.....>....8&...h....`E.I...x\*.....V.............f..N.......
.K{........ru.2....D..~..T1.&X...Y.....S..(a.L6....-k......(......n...
c..a.....I..Cuy.._.fA.V.........|c...3.B.[ 8......:z.Hf?.E..Z~..EA<<< skipped >>>
GET /star/upload/11/11/1473390677979_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Fri, 09 Sep 2016 03:29:20 GMT
Content-Type: image/jpeg
Content-Length: 19170
Last-Modified: Fri, 09 Sep 2016 03:03:29 GMT
Expires: Thu, 08 Dec 2016 03:21:26 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 303970
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......Exif..II*.................Ducky.......<......Adobe.d.........
......................................................................
......................................................................
......................................................................
................!..1.AQ".a2.q..B#....R...br.3.S$....Cs.4..............
.........!..1AQ..aq..."....2B#...Rb.r..3.....4............?...j.#.....
P.,/H.P.C&\[email protected].......)\Z...XX...s...Bl.I.e..ZE. .L......e!.*..-......
.D,[email protected]...&a.
....kR.<.rjY@,5.)[email protected]..[..I..q..K-....H.<..4.G..<..Q4....:..
.....4a..u.cq....#C..d!R.:.2.Q......he...i.b.avj...b%.!..`.R(....&..V.
c,.nET...x..........gJ.."[email protected]#.H...U......-.}?.....
[email protected]"..y..B.Ij[....^..NMi........{[email protected]?....=..........8q..
..;.............Y:....R..;../.......>K..?....{N.?.1w[..!..W........
s..8.......H.....G.i....]..|I.. ~d.O.....a....{.%.../V_...j?{N.?.qw[..
....m.T......X{......kX...zG....{. .8.-..}...yN./...[.......n.>....
..s..X............q?...S...8.....p....m......s...w[......*X........;..
5.....&_!...V.h....S....]..|D.(wWN<..Q..=r.uY.c...>%.......A[..#
.y7^...Q...1m94......M.D)..jYH...%[email protected]....;..s.rda........_.P
;Y"sr<G...<...w.m....1..*.o.2..b....'%..f$f3h1......F.....o.....
..H......lc/.2..Pn..o3J.x{..?.h$..y.tDr...?..b......h.'. sf)rT}.......
r6)pn..42..%....Y.{.J....:R..I.o.....V.,g....E..........p..f..!.....q@
H#.).["........A..zc..RGJa._G...(..Z..^.H..Q!.MJG.E.KcH.H...*.U,k7<<< skipped >>>
GET /star/upload/7/7/1473572609703_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 06:21:39 GMT
Content-Type: image/jpeg
Content-Length: 54111
Last-Modified: Sun, 11 Sep 2016 05:35:39 GMT
Expires: Sat, 10 Dec 2016 06:13:41 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 120833
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......Exif..II*.................Ducky.......F......Adobe.d............
......................................................................
......................................................................
......................................................................
...................!.1.AQ".aq2.B#....Rb3.rC$.....S4.%...5...cs..D...E&
6........................!1.AQa..q...."...2B.R#..br..3.....$..CSc%....
............?...#.~Cb.\3..G..g.......R..]}zW.x.!....TF.i..<{6....f.
U.4.).\"U5..7./[email protected]". #..?.".eT. .A.#M;u..>
;....k..q.b..b[y....V.]U.._.;n..>#.O_Lk."........R^I|{RH.Z.d.9'o..#
R{.~..^..4....;...M6..*...I.....7.....5 C..c........n..e..@./..5.. .0g
.?s..;2JK=...T........tU.T....C0..........Q.fb.s._....r........8..y..A
..8..I.}=U$.Z]._.5.3iM.i......?u.F..b([email protected];G.....|..~em.[.m
Krh!R.|..^.6f/j..a.......2..a ...N.....b6[..:v......Oq.#..@?..P.u.8S.
..T}..........UO.I..C 1.G#@.J..I.z...'MT..'..\..g7.q.q^G.t...kV<.Q.
A6....?..gv...../.|..q%.\G.. C...X...........Q..%].O.).H....h..^U.`t..
......^........o...K...F....B..i.._...=MRT.....:j.#...VB.....B..T.....
..D..K.... .).0."..Ia....Wz.;..$.}..)>.........J.[S...Yy...5.<R.
..8I...j.m.$....M.wf.>=][email protected])U...k\...f51.....J...u.(....1..;k..K
m....h.ph.....P..m..".........S.;....nT...:u..b.*1.R..#X$.v]5f.......Y
..\..Zj..:#Z.....Er...q.....x......%.S...F.....C.h.H.FG..t$~.$.i.1...C
..zx-N..^.1c..I=...... .7..i.U.j....R.T{M.. ..[.N....LnX....eS..c^.{t.
..S..aq..y...J...........P.....T.............b....c...s....,~@C...<<< skipped >>>
GET /star/userpl2015/10/13/1470910911030_132026710b.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 25 Aug 2016 03:41:23 GMT
Content-Type: image/jpeg
Content-Length: 42212
Last-Modified: Thu, 11 Aug 2016 10:14:57 GMT
Expires: Wed, 23 Nov 2016 03:41:24 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1599250
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.....H.H.....C..............................................
......................C...............................................
........................,.,.."........................................
...l...........................!1A..Qaq...$%4......#5...&3DET."6FUVde.
2CSftu'BR....brv.....7.......8G.......................................
....E.......................!1.AQ...aq"...........$2B..#%Rb..45r...3E.
D.............?.......`GH.../...(......:DF_e.w|eS....-...#..V.u....o..
.~.a*;.......).-...#..^....>..f.4.....F..g.Q..,.2.o.V:..u^...j../..
...<&.`q._..C.e...4.D{[email protected]__....n..U.$..X.x
.n.r<, .8....X..}H.t...F.... .0.....DJ.....,O.....-.....7&......t..
4....w..v2..&9^.6..,...1..'.j.....j..Kn.k..j.:.0.h*...".......x...!"..
...2.....<P.6...b.".l.. .....r.:..o*.->Izi......c4.E.~.L..LAK.{u
.,x/..........W.p.NU...n..|...9.N..t/N-.w...Qu'[email protected].
....|[email protected]*....T.@..]P..J...6r[.yEX._..}...9
53^....a.....;......8=.U.7uI.D.t8...'e......1...X7-..............8....
_.....R7FB...^..h.G....6..v...] ..Z.R..../.JW)a.k..p..V.e...........~.
..[[email protected]_.....%.. [email protected]|.<...R.5
.Z....Yz.....=.r....>....w...L.7UW .."`.L.q........f.d..7..,.U...R.
.......CKb..P.....V..<...9%.[....Gb....<Z...l.........7<..V.W
.......ezb..M...).!..A.f.9.R..84.(.Z..I........T.t.Q.d.3.....t..[.._.K
.omS....*[email protected].._Bl.9s5._|......XlG..oY3Z.....;.#..a...s....R
R.}35#.%3...8[..!.:yx..0..Z.W................. .......Z)^L.....<<<< skipped >>>
GET /star/upload/15/15/1467861880943_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 24 Jul 2016 10:29:17 GMT
Content-Type: image/jpeg
Content-Length: 19618
Last-Modified: Thu, 07 Jul 2016 03:18:43 GMT
Expires: Sat, 22 Oct 2016 10:29:15 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4339577
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.....H.H.....0Exif..MM.*.......1..............VVV.meitu.com.
...C..................................................................
..C...................................................................
......................................................................
}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUV
WXYZcdefghijstuvwxyz..................................................
......................................................................
......w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFG
HIJSTUVWXYZcdefghijstuvwxyz...........................................
.........................................?....5mN.....P..3.... ..}q...
........R.|A..................slD\dt?..E.I.@..>.{$rO..30?)...,TW..
.F....u....3.<.~..r..L.-....{5O3..........\.q.v......G...&....&..j7
.F.u....6..C.*..O*. .==.l<.,2....].&..v...y../.....$>...o.......
...0.....f...S.W...5...O...sZK...Wr\..v.............}b..y,..0.<.cm.
<..B#.`.&.`...k.[..l..6.h..^..../..W..>&... Ss../.Hq.....2z....%
J.iJ..{U04.\..u..h...o./..eY.....b.&.Nv3m?.b.s.O<s...`..%.........K
U....s......?.|U...]......s.......2...U.Rk.E..g.8rOM....9.-s^k}$.j..t.
....u.g=}...^....{z.6..krj..-.^...&...w..=y5..S...........5.5.?d...[..
....$l......H9".0v.....:.q..q.^=..R._..~q...~c....^..5._...jE.|b.-.K=#
........v.......Z9/...m........>..b.|....c..~..... 7......&..?._..!
.......j......v.`X..Kg..S\x.......gm<....*..PkG%..?.~..L...n<G/.
.M.N.G%..kf...aJ..O<W.I..C..m7..\........-......~'..^..X.h.5.."<<< skipped >>>
GET /star/upload/14/14/1456814275214_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 25 Jul 2016 11:14:35 GMT
Content-Type: image/jpeg
Content-Length: 93716
Last-Modified: Tue, 01 Mar 2016 06:35:41 GMT
Expires: Sun, 23 Oct 2016 11:08:00 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4250460
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive.....6Exif..MM.*.............................b...........j.(..........
.1.........r.2...........i....................'.......'.Adobe Photosho
p CS5 Windows.2016:03:01 14:36:43............................,........
...,...........................................&.(....................
.....................H.......H........Photoshop 3.0.8BIM.......7..Z...
%G..Z...%G..Z...%G..Z...%G..Z...%G..Z...%G......`.8BIM.%......a...Ub..
.m'..2..8BIM.:.....w..............printOutput........PstSbool.....Inte
enum....Inte....Img ....printSixteenBitbool.....printerNameTEXT.......
8BIM.;....................printOutputOptions........Cptnbool.....Clbrb
ool.....RgsMbool.....CrnCbool.....CntCbool.....Lblsbool.....Ngtvbool..
...EmlDbool.....Intrbool.....BckgObjc..........RGBC........Rd doub@o.
.........Grn [email protected] [email protected]#Rlt.........
...Bld UntF#Rlt............RsltUntF#[email protected].....
PgPsenum....PgPs....PgPC....LeftUntF#Rlt............Top UntF#Rlt......
......Scl UntF#[email protected].&..........
......?...8BIM...........x8BIM............8BIM..................8BIM'.
................8BIM.......H./ff...lff........./ff...............2....
.Z...........5.....-..........8BIM.......p............................
......................................................................
..............8BIM..........8BIM..................................8BIM
.0....................8BIM.-............8BIM...............@[email protected]
IM............8BIM.......C...............,...,.....3.0.0.x.3.0.0..<<< skipped >>>
GET /star/upload/4/4/1473645059028_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 01:59:12 GMT
Content-Type: image/jpeg
Content-Length: 21213
Last-Modified: Mon, 12 Sep 2016 01:43:04 GMT
Expires: Sun, 11 Dec 2016 01:51:12 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 50186
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
.................................................................D....
......................................................................
.................!...1.AQ".a2.q......B#...Rbr3$CS.....4%5.....W.......
................!1..A..Qa"2q..B.b#.RC............?....&`.0........7...
....0...1....9yx`.U#*.......V.7.....:.<.h..G...;.....}...~....R....
...:~..... ..:.0.....Cxr..j..N..;m3*...0.2.g...lj.K.V...W..A.?.m......
6.........~...nW.N$%.......RR..k.,.KH...t<S........viM:.Kx4....$..q
.t.....(z.L......O.m.|.x.kT].jXn.|C.E.8Bt.:4....8...%.T....T...X<..
>,s...v.f.o.).c....$.3m.Q...rQFhQ.#..".9...S\..f...5_,...\.2...0...
t......y,..]......:SZj5...S...t...HM2R........|..F.........Mi.....aH.l
&.38.M}Z..O._.!..p.`.x....5A.......f.3.....A..x...l.............?.`...
....p..'........Q?..o/..6:...Y.vN..-..km.).{....U.-...5..F.H558..6.T.q
M...q..W..%...^}..`\..\.Z..Z[5)F...$`7.-Y.y..w!...-..m..5!n\..[.P.k.4.
_uk [.zht.U..x..eg.[.H.\..n...2.su.S...N.....k9..s..D..powKC.v..6.....
.@......)Y.-Xgr....zqg.\?6.q.......K.W...~.`..N.V. ..S..1.(Gx.......z.
...H..=...pHl..^.........(....g.9....a..J.......p...Y.8..e#.!.......$.
.|..5.@~..........~...a....f..Q....D.P`.5.... .8..}:z.V.@..........`.0
.....h...A..7...5..f......k......,.*..\...EvS..[i.j?`H$...m...k...:.)O
:[email protected].)......JV..=...#,...IjA..........-w.......K
.$.,.r.)J..%B.F..a..\U.m...R...*u..Q...bF.i.sC..]..i.(.. >]).E<<< skipped >>>
GET /star/upload/12/12/1473577611660_.gif HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 07:10:26 GMT
Content-Type: image/gif
Content-Length: 346056
Last-Modified: Sun, 11 Sep 2016 06:59:01 GMT
Expires: Sat, 10 Dec 2016 07:02:27 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 117910
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-aliveGIF89ad...............'..6..)..8..%..;..*..6..9$..- 4.!F..U..I..X..H..
Y..M..c..c..q..d..w..h..W!.D'.R .j#.h#.u).L. w. S-$d3"p.)-E:sG.yL!~P!r
J3WH-1PJ=bU\`N.......'..'..,.. ... .*%.)(..#.9).P..V#.\%.L8.K2.O3.b'.b
3.f).c).l2.O4.VC.jM.nN.aM.pS..k..Z..V..h..j..x..o..}.............18..5
....:A..-.............................................................
...............................................!..NETSCAPE2.0.....!...
....,....d.............................................$.#$..%$.......
.....%. %..%.......%..... ............................................
....."@........Y.`.Q.F..D|..........D...7B..I....20......!0c......"<
;\....gO...|P..!...$.Z.aB.......k..W.x....W.e]...F,..jd....vZ6C....K..
n:[........rr... .p.y.......c..........."1.H.....Nh.x.....E...RD..3c..
......q.%.....j.e06.m......f......!B...um..m .wB9....}...yu...~.......
[email protected].!.O^.m.HE.). h.....<l....eX......l ...*......
...s.X..[..eV..m.#58Z.H"....Y>Vs.wC.fdo...N.^...^{u.e.z.-.^...C.{..
.....u.=...`...T B.E....*.'h.....@.`..|..Zk...blB..J.<.H.*..x...x..
Y.4..Y-^....m.)"6..MsBnC.P,....]...^}.*.y.>..:U2....P.......`X.7_}.
...a....?..hPe.!.P$.N.....P@[email protected]$9......D.A..
.*pv....!."...H6...... y.t.j......`.f....J...".CO<...N...DAdd...@3.
L.d..s`C...3......C...H.f.Zk.....'..oO. ."spA:l.U....Dq'.5.H'..o.-...^
...A"...#.M..".... C.....>...Gf........3.x..S.I..#P...Xn@fA-Vm;6.TA
d.R{.B.8.s....@.,.6....Pn...&.J.8...(.8.*....!. ).`.....r9....B./....T
..7e..v..Y....O...........%.m.....o....?.$.K......f..2f..12K......<<< skipped >>>
GET /star/upload/9/9/1376990222297_.png HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 23 Jul 2016 11:02:32 GMT
Content-Type: image/png
Content-Length: 20225
Last-Modified: Tue, 20 Aug 2013 09:17:00 GMT
Expires: Fri, 21 Oct 2016 11:02:29 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4423989
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive.PNG........IHDR...d...d.....p..T....sRGB.........gAMA......a.....pHYs
..........o.d..N.IDATx^u]u.U..}..v....BA.....D...%.BT.ETJ@@..;..CBBi..
|....[k...........n.{....5kf.I............q.MO........{...{?/...Y....3
...|~.M.....g.7<O...|.q.....gyL.........m..^.T.wS.wn:.?....'\....:w
.~.9.s......s....7.k.\.....]o...u...G.\J.P$x.....s......r.=),.W..#..%.
.P.....#.Q0Rz..K(H..W.......f.w..wlQdU...WFPHX\.....$.......)......u=.
.....u......(,.."..vJ.....U...[.?. ..J..e.y".G.......}WB6A.,..W..wM...
.?..U....S..n...XoMz.?.E.,,.[d}Y-..V...vcB........w.ZL..$Y.ea.n...^L.I
...........Wwp.......l.t'{.-~...x........#%xeI....o..SR\a..7.a..B.s.w.
5........Yi....MZ....O..7.....`.......\l.^..0.,O.Z.y).F.._.R'~.N&..4..
........:............,.....Vxps....$[St...#...9k.".z..k..N..?Z...3a.-.
...-.M.K.jOX@.{3K....{.s.^.f!...b...oB./. ..-.\.|.Y.{?k0..k.I([email protected].
H~/.......7........1(. <.M..,..\...._P^.%[email protected]\..b....rg.Z...EI
.A.)........../...?.l&...0.....2Z.&$.....c.!.?...P.,'..KntH (8(5.}~...
.........[..\._..Y...)&.$,F..pq.V...].][email protected]...
....[b...\p.E.....f.... ..?. ..b~>[email protected]..!....2K.-,]....[
....p..V. .....w[.........bT.$crv.".....yF...V...;.../...rF.2...1.....
...V.V.....Ug......$.....OX.9.IX....e.7..q.m....w........=?..M.s..A.X\
....UD...._.!g.n..f.9.K.AKJ...Xl...9?...YG..xs..t..X..o.U...}B......{!
.......k...Ib. D.G.3.J.=..b.H ..;....r................J.]...Z.{..w...(
.E.6..........YHH...n..e.!&..n.dL.!.....Y...^...}8..!ip.1tf........_.w
.&..zKr <,..q..O........C.j5....X.Ck.|.=<.X1.\..`...]...%.~.<<< skipped >>>
GET /star/albumcover/300/41/7/2438451804.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Thu, 08 Sep 2016 10:08:53 GMT
Content-Type: image/jpeg
Content-Length: 16846
Last-Modified: Thu, 08 Sep 2016 00:57:59 GMT
Expires: Wed, 07 Dec 2016 10:00:59 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 366409
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?...k.
.Z6.f`...J....'e...|.z.]..u>.r....9.I...y1....^t.:..............8#)
.7c.dkW7...;W.....89.^.T.m.I....$.B...T.%.d.SPns.rj.9.k...a...........
EfL...IS .........K1...Rd.=EJ..0........<........,.@.@*..1Z...QU'..
.....e.aUE....Iu....20-."....J.t....u....A...H.DR6z.N.....k.>.[h.R.
...n...?......G..z4m.:.o.2...rj........&..If>.M[B...II=x........MQ.
..^.....51.ni...4...8.n..$L...LU`ri.y.sH.]i..Y...@jM......#..f.E=.....
h[.^sWb......p.ni.. ..r.Eh.....x&.80.VU....$.w..R..G.Znl.Y*O<(.Y...
..{......A.Yn76.....I.R.=..]..."...7.. ..Y].*vF.2.8?......T...#...q...
.c.I\..O.}T$0.....9....'...-...lQ.9s.....VZ|..2..)....Eq...99..V%d....
.R...N..k..z.m."..y{.....66.v-..4.............>..``t=.a&.\.~.a.. ..
NY6.?..7x.........t......8b.d.W...}?F.......%...qJ.....Q..f...........
.......w5.c6....T...u..d0,M.H..c....o}.. 7amc3..?(...U...k..T.(=.qT,nb
.z.1.0H.3..U..Q..q.$.Y=.... ...*;.d..s......%9...C y....y5w..%..,.<<< skipped >>>
GET /star/albumcover/300/33/5/1112781587.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 07 Sep 2016 10:08:46 GMT
Content-Type: image/jpeg
Content-Length: 15598
Last-Modified: Wed, 07 Sep 2016 02:58:26 GMT
Expires: Tue, 06 Dec 2016 10:00:55 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 452816
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?.....
[email protected]%)....BiM0.`.qM..aj...&.)D..m'.0......=........zCq....
.}........8]{..X.[.z.\................V.......[.z..Y..L..XIu.Vc...F..i
..lw..V.Ph....|[email protected]@[email protected]@[email protected]@[email protected];T,h..M4..h...i..M.4..
...lUy....P<...J.$... J=j.......sSq..oza.....C.ZW..8..&>.\.7y...
.c.O..Z......z5.....J.G..77.......K.z....sk;...K.....Eu.W....F .u..Z0_
c..;......ZI3\..]9..ns......h...L...>.(...(...(...(...(...j3JM4.@.
4.Ji....Li.qU.z.c.T.J|.U.$...Y*.6M8.M.Kab2.&...}*Hm%.|*..,2.>......
Mo....5....ZQC.#...;...s..E...a...Wc....f..I..... .....^.Lg.r}6.Ms....
m..]..I..)3,e3....$s....;..X.%.ugc.T.M.O.c..........[..&....y.}...y...
%..=EbM.;...=.....9` ..y.U<[email protected].]...:m....>../O.....
."........!;~Pp3.:...5.Z|B.T..^[L.?......o.9...3..b...L}...._.5V_.F...
.F...?...&....l..nRH.D...e.>....p..........B..&...?. ...m...Bn...T
,M.R>..Xx.J..V.P.I.C......<..b.a.h...h..^......k^.RS......B.<<< skipped >>>
GET /star/upload/14/14/1378203225934_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 24 Jul 2016 10:29:17 GMT
Content-Type: image/jpeg
Content-Length: 6382
Last-Modified: Tue, 03 Sep 2013 10:13:43 GMT
Expires: Sat, 22 Oct 2016 10:29:17 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4339585
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....d.d......Ducky.......P......Adobe.d....................
......................................................................
.......................................................d.d............
......................................................................
.........!...1.A".Qa2B...q.#...Rr3C...b&6'.....................!..1.AQ
..aq"........R#...2BrbC.............?..p...Z.nJ.a.;...J.$....'./..=...
).s;.KW...T..N..f...ut..}..h...-^.....(.O..d.*...\.....\Ww.:.]a..b.l..
.m....}.5.'.s.1y....o...6...R......qm.Y.&..*u-.#M..% Q....|..\T&x)...J
).=..K....nR..T).P........j|....].R..Y..V&.}......X.&...6..L.8..u...K.
.j...?...o..N*...m......Uk{w...p,..<bb.*.v*...... ........q...^\W5.
...J...v.-/%...Vb....~.8.2#[email protected]...'I.{B.0... G.bk<..[V.wI.
...o.u.....9&J.B.IQ.....2.9.[....c.,=...1..2..%rN[wf./.CndH..q...UIb..
..l.j...N8..S.!.......mz.....<..Tv.a..xj.F.P .~..j..>F....F..3..
I..)...sH....I.....M,..E1V....Xa .j....M0.X'.u.}...(.sR...$..C6....2.p
iCM2<.$...UI9..B9.zU.....ETcy.s..s.].........K..._P....A.}M....w=.K
...&...LK....yp.6..L..n.Q..6..)...B.@.._.....r...s{...&....DIM>.j.A
yH..G....9W...71..a.k8.D..T..M...aO..~...T.._F....t..Cd...e%.....%8Q.z
..'onr....-.^T....... ..sN..c'.n..0Y.W_.Oc.q..n.....~Zx....v..;.g..Fz.
.nja.Ad.-.R.F...|.(R....wpA..c..#.b.D...cS....>g......'.p9...j\d;.C
.......8.....Q(J.*[email protected].[..............|k^.......b.^..NA.....Uo.R..
.. ..2.x.,.V..^.i;;o............Z.O.*..P.B=.....J.s..-.....Y{....5.,\.
...a....2....Z)^US....d..T6.8i......... .[.LY.T. ..e'Sp.....P....V<<< skipped >>>
GET /star/upload/15/15/1401091378655_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Tue, 26 Jul 2016 15:32:03 GMT
Content-Type: image/jpeg
Content-Length: 6947
Last-Modified: Mon, 26 May 2014 08:03:06 GMT
Expires: Mon, 24 Oct 2016 15:32:02 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 4148620
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....d.d......Ducky.......P......Adobe.d....................
......................................................................
.......................................................d.d............
......................................................................
...........!..1AQ".a2.q...B#...Rr3Tu....D5..b..CS$%7..................
.....!1.AQ..aq.."...2r.....BR....3S..b...#C$45............?.......4!..
CB...4!..CB...4!(.N>.[i%kUh...I...t$$..J.bk(.9q...*.P..^p...W.V.iD.
..S]..D....C.B.........y.F..;.8.a)6..._.}[email protected]..]. .l..............
.ki...8.'...}............._..N!..hB....#....\CjZ../,.....*=.<....8.
..#..-.TH..v..2.8.x. .$.....t..... u...Y/.D......V...}..JR<J.8....#
qND. _q....... _q.8_.v.<k,6..7...w..."2.?s....E...v.i.Z..)....w...u
..z..mk...&h....sg...t.Q.m..j5..d.r...,O.......Sm....P}....u. ........
(..c.!.}!DJ.U.....#.E..A.....^n..&.-m........si..R...V.X....w.fCu.k~.X
?...w.fCu.S&.[.hB....)./e..O^-.....fRZ.....%....%4YF...n.P5.ys.HS...#.
...bv>O.*:..1"...$x...,N..&.#}.........v.Hot.-..).D.vI...W..M.n.]N.
.eP.F..)..../...-..N.Jb2...R.%..........D.z.`CW....d...;...O%.AP.M...;
...N...aZ^.E.... u......a.._0.S...!........X...[0{,Qm..r;..H.o@}...G..
..N.........Xs5]F...B.(.#..n.,...F.....x............d.....SoL.l...j8R\
F4...n1...k.(>.Uu.y.K...J.'.>......?.wN.MJq.......b..>.n.6..7
.b0x..Z..o......R6z.....l*T.........>....;O...O,....$..>;...(-..
....#.(....6G.......~j......y..*...r..8[.)D.. A.B.w..JT.........wZ.r..
eY>Qm....].f..a.Z...k..[.....H....KiZw..Q.\.I.........=%......S<<< skipped >>>
GET /star/upload/11/11/1473603291211_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 15:57:58 GMT
Content-Type: image/jpeg
Content-Length: 59546
Last-Modified: Sun, 11 Sep 2016 14:07:05 GMT
Expires: Sat, 10 Dec 2016 15:50:00 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 86267
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,......Exif..MM.*.............................V......
.....^.(.......................i.........f.......H.......H............
..0221....................0100.......................8................
...............C......................................................
..............C.......................................................
................,.,.."................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?....M...$. .....
.<.v....A.}q.z.?.....bN;...3..(K....'......J...........@<.....8.
.~...^..h..*..w.......kQ.S....$...a.r.=..gey....k........~.. |.}.$..C.
[email protected]'.x.H..x.)!.X0d.6(...S....x^".?...N5.......G/ 8v
.)X....2e...j.|7.v...uwtD.....a.R........~.~._.....|L.5..|.....u..5..P
.....m..df.......[).h..!.1..#...].....&.. u.>O..W..P........;.x....
.u.=..lg2(-....... .S.w:/.}"..5.F...Z4..b.i...$.G#5...U..."......c..$.
Bq..I'..s..<....r.i....TR..q.......2I...[|=.........;v,...N{.L...y.
[email protected]..<.1..I...$.]........l..]...e...dd..g.x...b.x.-
:.p.8U]...v......N6..s....k...k.A...9....#..Py... .W=..\.4.d{w......[.
)$.*.<...8...../.;@.\...$1$.......PH....S..2K.....b.'9....9.><<< skipped >>>
GET /star/upload/4/4/1473493595908_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img4.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sat, 10 Sep 2016 08:10:50 GMT
Content-Type: image/jpeg
Content-Length: 69954
Last-Modified: Sat, 10 Sep 2016 07:38:48 GMT
Expires: Fri, 09 Dec 2016 08:02:54 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 200703
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-cz-1-1-c1131
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?....<
...8R...9$ewc8.....V....cEb2A,.@..?..._......aH=....s.{........`.7c...
.*[email protected]];..y....r.v.p....q...........@G eDu......F.rx..9
8.<V..8x..P....q.xl..9......,...\...F1....3.....(8*b=.k............
...,...79..GN..F6.O......v..I8!..'...A....Akl..I.yQ....<w.`.$...q[.
@..fh.E...3.A=Nq.v0..t..x.^._]^........8a.1.`..F.8..:~9.X..`D.F8d..`.S
.......MO.......x.^......M..J.3..P..q...#......{.?K...}Z.QhI.Ilm..J...
.r.....<..W.....6. z.gg...kv...P.sl{....KWf.M)=^..{.km.G..i....aU..
. .H..#.....8..4.2..............A.z......]l...|Ix......{.......A.A...w
.....}:..E..,.......s..[..*w. q;H.7s. .T....'.niKEv.v.....?.....b1.}z.
.[s..,R........M4=.......9.........`...e.~axyG8...j....\.z......H..2*.
.............00..^8...Hi..w.v...y..^..\........|.>zX.....I.t.....mn
.S.e........H.s...[*s..........:3a..>.`.8....`v..f...4f.#..K... ...
.\...L.T{.T;..BI.px.....&.G....!.{w.....rri...#!..n..gq......H.D.A<<< skipped >>>
GET /star/upload/2/2/1465184432195_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 21 Aug 2016 14:52:00 GMT
Content-Type: image/jpeg
Content-Length: 25223
Last-Modified: Mon, 06 Jun 2016 03:35:28 GMT
Expires: Sat, 19 Nov 2016 14:51:57 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 1904612
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive.....fExif..MM.*......................................................
.....................................(...........1...........2........
...i..........................'.......'.VVV.meitu.com.2016:06:06 11:39
:46...........0221....................................................
.............N...........V.(.....................~..........&3.......H
.......H.......C..............................................!.......
.."$".$.......C.......................................................
................,.,...................................................
............}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:
CDEFGHIJSTUVWXYZcdefghijstuvwxyz......................................
......................................................................
..................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()
*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...............................
.....................................................?.."...M.i4....m.
c.V.e.W....K...&j.k..DQRF&..... v8.v.R!f".2....i...f.s&.|..)a.K\..^Sj8
R.. ..~...p..5.....:.....GrO.y...nw.%.~I9'.....X. n8.)........zv.?".Z.
.Z#.......ty.u...gfjh.>f.X.W.l..5......9...o..a4r...^..qft.........
.........]>.z......4..b.A.p\W....Er.Q..0JN.4.O..v.<...z....W6..v
.sS.I.e'...n..8#..l..VqR..6...s$|D.^b.!X.(..5..,L.....A.?.....;h.tV'.Z
......:..sZ...umB...w...c....:....B..Q.(.............47n.....4..Hb.08.
Q.......a..O3..u].K.....Ci. .KV5k.. ....T#i....=..o.%.d..b...m.*a....:
E..i.] .H.....U...>b.9&.\[email protected]...`4....!57...R..0..R...z.<<< skipped >>>
GET /star/upload/10/10/1473645136042_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 02:00:14 GMT
Content-Type: image/jpeg
Content-Length: 23444
Last-Modified: Mon, 12 Sep 2016 01:44:21 GMT
Expires: Sun, 11 Dec 2016 01:52:15 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 50118
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......Exif..II*.................Ducky.......P......Adobe.d............
......................................................................
.................................................................D....
......................................................................
.................!...1.AQ".aq..2#....B...Rb3..r$....Sd..%&.....C45E.F.
G......................!.1..AQ"..2...aq.B3............?...)......^.i.,
.......Yc.z..h.$..P#..*\&....FX...>.W.B.P.|q...@h..>=1}...._.iH.
....G>;SP....%(&.8....&....}..U.G9W. .........V.u.... .krUnA.3.i.q.
u:....>X..i..........|....{..4dS..ab...L..H9.......y.)T..p>.....
....(...C C.*.%d.JW...k.a...>.i.Y....>..d.7Z.........b%..x56x...
[email protected].\.iTv.i.Yn)..(......6....u..x..K....U*:..... ...k.....{8
.s9{.X....6'L.(...z...._mz....oz.i..(...2.....E.....qeCRR.#..rq=....1.
.....Q....k..o.^G...t..1....................^p.Z....5A.w..m.M.2n.Y..:.
zB.......z$'..p[[email protected].)..R....5W..K...hg...3q.3...N ...
B......@..?...._#z..?*y....[Zj.<A....)3.tp..e-..... .y.h|3.l..`.$.C
gA.4...H..AI...!.=.4...." 2.s....................!@..._<N..K..../..
A..G.$.3e.R>y.6.&.H.28S:..G..?O..\.?.BRhk..I;&.|.n..'....Q!..:.w.[.
F...\...i...."-......5.P..db...;o.........xg.....X.q..mO.O. ...._... .
.!o.d...p.6|.3.&.......n...E7......3.m%!4W.F,Eb..^.V...". .....(.V..e.
G.........h. .O.Nt....K..yV......|..<.Ah........Uq' S.N.=-..Ht2.j..
Q...0..wG....u.#....Hr.%@V.T`.:.s.-(. \I..H)$..F%.!.....u.S...t..8>
%*[email protected]: ...*....i...&.R.<........=........NDf1.Ed..J..e.~.R..<<< skipped >>>
GET /star/albumcover/300/61/56/3263549297.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img2.sycdn.kuwo.cn
Connection: Keep-Alive
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:08:08 GMT
Content-Type: image/jpeg
Content-Length: 20562
Last-Modified: Fri, 08 Jul 2016 07:01:23 GMT
Expires: Sat, 10 Dec 2016 16:08:11 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 85644
Powered-By-VeryCDN: HIT from ctc-bv-1-1-c1111, HIT from utn-jy-2-5-c1131
Connection: keep-alive......JFIF.............C................................... $.' ",#..(
7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222
222222222222222222222......,.,..".....................................
.......................}........!1A..Qa."q.2....#B...R..$3br........%&
'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz...........................
......................................................................
.............................w.......!1..AQ.aq."2...B.....#3R..br...$4
.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................
................................................................?..]..
......<.... ...rI..Bl.'.T.......8......!.T.Oj...r(.A...@.....`...M.
.n.H.....JxS..8=.H....V...a.y...B....q.9..M.`.......r~....g.j.....S.m.
{S1.b...E#..>i.C...y......l>......2...).@p~..]o....;`..i.}.O..9.
k}G..^;3..=.<E..h.....">=?.z.x<W1.T.. .1.q......=p.:...]Xe...
...S.K..T.sN.. .......gr..$................ ....8..-.W..Co<.D......
..z.Ms#..Y.\.ft%.;..*..1.\...<.h.,.K..#.z...Z.Q..%.#ns..H..J..8....
.&$..O.\.....,=z..e,[email protected][email protected]\...W..b..(.... v....
^|.&{4..0-A$...r.v=.k.V-...~.R8.$.S..MI5...B..~Ty..21...5.G..H....K...
......9%l`...>QR..2.1...8.Kk.!Q....U.........G.... j.....v0..*@..3.
.|0..M.$2F......T......*.......... [email protected]/...I..I...=1U..............
#[f{sN......z..N1......5...L....5,hz...%.##..L......"...8..d.../.y#...
<q........@.'...OVq...........0..8'..X......8.rG....V...#.D.).cc..{
.......uf...W........W{.\..v.K{..KkI[...}z..#.U0...g.._.Z.....Lx.~<<< skipped >>>
GET /star/upload/0/0/1473603326304_.jpg HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: img1.sycdn.kuwo.cn
Connection: Keep-Alive
Cookie: mbox=MUSIC_7.7.0.1_P2T1; mboxRun=kuwo; client=WEB; version=7.7.0.1_P2T1; game_mbox_id=6424671; mboxsid=0
HTTP/1.1 200 OK
Server: nginx
Date: Sun, 11 Sep 2016 16:00:04 GMT
Content-Type: image/jpeg
Content-Length: 77200
Last-Modified: Sun, 11 Sep 2016 14:07:40 GMT
Expires: Sat, 10 Dec 2016 15:52:10 GMT
Cache-Control: max-age=7776000
Accept-Ranges: bytes
Vary: Accept-Encoding
Age: 86133
Powered-By-VeryCDN: HIT from cuc-yj-1-1-c1111, HIT from utn-jn-1-2-c1132
Connection: keep-alive......JFIF.....,.,.....C..............................................
......................C...............................................
........................,.,.."........................................
....................}........!1A..Qa."q.2....#B...R..$3br........%&'()
*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................
......................................................................
..........................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.
....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz.......................
.............................................................?..<..
eS..x....*........Zk..A`I.9.|.....u`:._.~f...{>.....r?.... ........
.!K....3.J.Y.,...&.&] H..<...)o. .`.#...j...J. O......O.k....X`Vv..
T9...9oQ_.........1.v.. -...9..p...E...H....*c.[......$...\.....E....=
.........*N<.75.._Ky..|.. ...h!....r........^F,...w.<....=C....
R..g.3a.%W......w.vF...f.".....7.W.L..9[t....W..E....w..6.!Z(.`C.Y.q.F
a..w.........%..1.89{.&.........K...%..ZT.Vx.>X.5.V~..=uJ<.u<
....q.CF..?0...Q....I>.'w..b$ ...U.^...0...W.^(.u}....D..6..wz|..@.
C....... ...6$......|<..{..O.G.DWR.....[..E........d._..5.<.*4.N
zT...d.y....^h..]-..;W.V..EQ.S.9...?.z..H...2..p...{.k..m.B..7.Q.A....
........-..Q./.=.[.}.4...EPp..F......[.s....o.._k......,...a.N....!un.
".....g.T....yV...OA......,....`dImV......<.1Y...'$.].....W1..M.7V.
.d...kk6{xn...T.G.{\.*JU#6......]........i=..^'._..<?2A.[".y....<
;..........w.i.......<..[5..s..yS-..yn....b.Wqs....,...Y.,GoC.Z<<< skipped >>>
GET /regsvr.auth?104&EAFYSgQODR1JVVUvW1ZbY0BRU1hPBwodSVVVXFlfXhBJVVVcWV9eEElVVFxPGQNBGlhVXFksXBlMJlxYX1tIVhwXWCE8PCdjJlJLW0dfQBEmNVc4WEkdUhpYDhkeADFKFFFXVUcKFkU= HTTP/1.1
Accept: application/xml,application/xhtml xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Accept-Language: zh-CN,zh;q=0.8
Accept-Charset: GBK,utf-8;q=0.7,*;q=0.3
Host: reg.kuwo.cn
Connection: Close
Cookie: kwreqinfo=client:KWMUSIC&version:MUSIC_7.7.0.1_P2T1&instsrc:kuwo_jm429.exe&id:&reqsrc:MyMusic::ApplyIDFromServer
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:12 GMT
Content-Type: text/html
Content-Length: 10
Connection: close
Expires: Mon, 12 Sep 2016 15:55:21 GMT
Vary: Accept-EncodingID=6424671..
GET /newradio.nr?type=4&uid=0&login=0&ver=MUSIC_7.7.0.1_P2T1&fid=-6003&size=20&offset=0&kid= HTTP/1.1
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10
Host: gxh2.kuwo.cn
Connection: Close
HTTP/1.1 200 OK
Server: nginx
Date: Mon, 12 Sep 2016 15:55:12 GMT
Content-Type: text/html; charset=gbk
Content-Length: 1037
Connection: close
Expires: Mon, 12 Sep 2016 15:55:27 GMT
Vary: Accept-Encodingsuccess.-6003.20.20.3197448...........1939034236,2204802977.0.6343632.
..............3975874449,778483178.0.1072737...................3757159
114,3953912647.0.1152665....................(The King 2 Hearts OST Par
t.1).1521730880,1757969142.0.2344870.....................2550778742,10
73070864.0.63740.............3925283803,3159077478.0.221787...........
....425744640,1592226912.0.80403.............2851669580,1731112650.0.1
030965.................1258478612,2835149182.0.203342.............3052
809319,2750681439.0.1037648...............2290261277,2720017671.0.3565
398............-(............................).3513212294,3381600762.0
.616788..........2009.3652768491,847253743.0.679685...................
3056585167,1529195348.0.535231...............1339369443,2815129510.0.6
18994...................3422019819,2056157656.0.158864................
.....3249036353,161687877.0.3033713...............1694047619,396067511
2.0.844353....................(......................).1103399205,1945
331707.0.1032753.................4240160040,1452418235.0...
The Trojan connects to the servers at the folowing location(s):
.text
`.rdata
@.data
.rsrc
@.reloc
UU U!"UU#$UUUU%&'UUU(U)*U UUU,-.UU/0123UUUUUU4UUUUUUU5UUUUUU6789:;UUUUUUUU<UUU=>?@ABCDUUUUEUUUUFUUUUUUGUUHIUUUUUJKUUULLUUMUUUUUUUUUNUUOUPQRSUUTz
!"FFF#F$Fÿ&F'()FFFFFFFFFFFFF*FFFFFFFFFFFF FF,-FFFFFFFFFFF.F/FFFFFFFFFFFFFF01FF234FF56789FFFFFFFF:;FF<=>FF?FFFFF@ABFFFFFCFDFFFFFE
8%u*@Sj%
t.Gj:W
u%SVj
Unsupported protocol
URL using bad/illegal format or missing URL
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
FTP: weird server reply
FTP: The server failed to connect to data port
FTP: Accepting server connect has timed out
FTP: The server did not accept the PRET command.
FTP: unknown PASS reply
FTP: unknown PASV reply
FTP: unknown 227 response format
FTP: can't figure out the host in the PASV response
FTP: couldn't set file type
FTP: couldn't retrieve (RETR failed) the specified file
HTTP response code said error
FTP: command PORT failed
FTP: command REST failed
Operation was aborted by an application callback
A libcurl function was given a bad argument
An unknown option was passed in to libcurl
SSL peer certificate or SSH remote key was not OK
Problem with the local SSL certificate
Peer certificate cannot be authenticated with given CA certificates
Problem with the SSL CA cert (path? access rights?)
Unrecognized or bad HTTP Content or Transfer-Encoding
Invalid LDAP URL
Issuer check against peer certificate failed
Login denied
TFTP: File Not Found
TFTP: Access Violation
TFTP: Illegal operation
TFTP: Unknown transfer ID
TFTP: No such user
Caller must register CURLOPT_CONV_ callback options
Error in the SSH layer
Unable to parse FTP file list
Please call curl_multi_perform() soon
CURLSHcode unknown
Protocol option is unsupported
Protocol is unsupported
Socket is unsupported
Operation not supported
Address family not supported
Protocol family not supported
Winsock version not supported
Unknown error %d (%#x)
Pipe broke: handle 0x%p, url = %s
In state %d with no easy_conn, bail out!
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
Internal error clearing splay node = %d
Internal error removing splay node = %d
23[^;
=]=I99[^;
httponly
skipped cookie with bad tailmatch domain: %s
#HttpOnly_
%s cookie %s="%s" for domain %s, path %s, expire %lld
%s%s%s
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
# Fatal libcurl error
WARNING: failed to save cookies in %s
Could not resolve %s: %s
init_resolve_thread() failed for %s; %s
getaddrinfo() failed for %s:%d; %s
%s:%d
%5[^:]:%d:%5s
Resolve %s found illegal!
Added %s:%d:%s to DNS cache
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Closing connection %d
Curl_addHandleToPipeline: length: %d
Found bundle for host %s: %p
Server doesn't support pipelining
Connection %d seems to be dead!
About to connect() to %s%s port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
Protocol %s not supported or disabled in libcurl
[^:]:%[^
:]://%[^
<url> malformed
SMTP.
smtp
http_proxy
[%*45[0123456789abcdefABCDEF:.]%c
;type=%c
%s://%s%s%s:%hu%s%s%s
Port number too large: %lu
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
%s://%s
Found connection %d, with requests in the pipe (%d)
Re-using existing connection! (#%ld) with host %s
User-Agent: %s
Connection #%ld to host %s left intact
Send failure: %s
Recv failure: %s
[%s %s %s]
Failed to set SO_KEEPALIVE on fd %d
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Couldn't bind to interface '%s'
Local Interface %s is ip %s using address family %i
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
Local port: %hu
Bind to local port %hu failed, trying next
bind failed with errno %d: %s
getpeername() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
ssloc inet_ntop() failed with errno %d: %s
Failed connect to %s:%ld; %s
Could not set TCP_NODELAY: %s
TCP_NODELAY set
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
Failed to connect to %s: %s
couldn't connect to %s at %s:%d
%s:%s
%sAuthorization: Basic %s
The requested URL returned error: %d
%s auth using %s with user '%s'
%s, d %s M d:d:d GMT
If-Modified-Since: %s
If-Unmodified-Since: %s
Last-Modified: %s
Referer: %s
Accept-Encoding: %s
Chunky upload is not supported by HTTP 1.0
Host: %s%s%s
Host: %s%s%s:%hu
PTF://
Range: bytes=%s
Content-Range: bytes %s%lld/%lld
Content-Range: bytes %s/%lld
PTF://%s:%s@%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
%s%s=%s
Internal HTTP POST error!
Content-Type: application/x-www-form-urlencoded
Failed sending HTTP POST request
Failed sending HTTP request
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %s
HTTP error before end of send, stop sending
HTTP/%d.%d =
HTTP =
RTSP/%d.%d =
HTTP 1.0, assume close after body
HTTP/1.0 proxy connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 connection set to keep alive!
operation aborted by callback
seek callback returned error %d
the ioctl callback returned %d
ioctl callback returned error %d
Rewinding stream by : %zd bytes on url %s (zero-length body)
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
HTTP server doesn't seem to support byte ranges. Cannot resume.
Problem (%d) in the Chunked-Encoded data
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Operation timed out after %ld milliseconds with %lld bytes received
No URL set!
[^?&/:]://%c
Issue another request to this URL: '%s'
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Disables POST, goes with %s
--:--:--
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
@Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d
Adding handle: send: %d
Adding handle: recv: %d
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
Server %s is not blacklisted
- Conn %d (%p) send_pipe: %d, recv_pipe: %d
d:d:d
d:d
0123456789
%d.%d.%d.%d
CLIENT libcurl 7.31.0
MATCH %s %s %s
DEFINE %s %s
WSAStartup failed (%d)
insufficient winsock version to support telnet
%s IAC %s
%s IAC %d
%s %s %s
%s %s %d
%s %d %d
Sending data failed (%d)
%s IAC SB
%s (unsupported)
%d (unknown)
USER,%s
7[^= ]%*[ =]%5s
Syntax error in telnet option: %s
Unknown telnet option %s
%c%c%c%c%s%c%c
%c%c%c%c
7[^,],7s
%c%s%c%s
WS2_32.DLL
failed to load WS2_32.DLL (%d)
failed to find WSACreateEvent function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSAEnumNetworkEvents function (%d)
WSACreateEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACloseEvent failed (%d)
FreeLibrary(wsock2) failed (%d)
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
got option=(%s) value=(%s)
blksize is larger than max supported
%s (%d)
blksize is smaller than min supported
%s (%ld)
%s (%d) %s (%d)
invalid tsize -:%s:- value in OACK packet
%s%c%s%c
tftp_send_first: internal error
Received last DATA packet block %d again.
Received unexpected DATA packet block %d, expecting block %d
Timeout waiting for block %d ACK. Retries = %d
tftp_rx: internal error
Received ACK for block %d, expecting %d
tftp_tx: giving up waiting for block %d ack
tftp_tx: internal error, event: %i
TFTP finished
bind() failed; %s
TFTP response timeout
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
LDAP local: %s
LDAP local: trying to establish %s connection
LDAP local: Cannot connect to %s:%hu
LDAP local: ldap_simple_bind_s %s
LDAP remote: %s
There are more than %d entries
LOGIN %s %s
LOGIN
AUTHENTICATE %s %s
AUTHENTICATE %s
No known authentication mechanisms supported!
LIST "%s" *
SELECT %s
FETCH %s BODY[%s]
APPEND %s (\Seen) {%lld}LOGINDISABLED
STARTTLS not supported.
STARTTLS denied. %c
Access denied. %c
Access denied: %d
Authentication failed: %d
IMAPS not supported!
%cd
%s %s
USER %s
APOP %s %s
AUTH %s %s
AUTH %s
STLS not supported.
PASS %s
POP3S not supported!
SMTP
EHLO %s
HELO %s
MAIL FROM:%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s SIZE=%s
RCPT TO:%s
RCPT TO:<%s>
Got unexpected smtp-server response: %d
Remote access denied: %d
MAIL failed: %d
RCPT failed: %d
SMTPS not supported!
PORT
Preparing for accepting server on data port
FTP response timeout
FTP response aborted due to select/poll error: %d
CWD %s
getsockname() failed: %s
failed to resolve the address provided to PORT: %s
socket failure: %s
bind(port=%hu) on non-local address failed: %s
bind(port=%hu) failed: %s
bind() failed, we ran out of ports!
%s |%d|%s|%hu|
Failure sending EPRT command: %s
,%d,%d
Failure sending PORT command: %s
Connect data stream passively
PRET %s
PRET STOR %s
PRET RETR %s
REST %d
SIZE %s
MDTM %s
APPE %s
STOR %s
%c%c%c%u%c
Illegal port number in EPSV reply
%d,%d,%d,%d,%d,%d
Skips %d.%d.%d.%d for data connection, uses %s instead
Bad PASV/EPSV response: d
Can't resolve proxy host %s:%hu
Can't resolve new host %s:%hu
Failed to do PORT
dddddd
ddd d:d:d GMT
Last-Modified: %s, d %s M d:d:d GMT
unsupported MDTM reply format
Got a d response code instead of the assumed 200
ftp server doesn't support SIZE
RETR %s
Failed FTP upload:
RETR response: d
PBSZ %d
ACCT %s
Access denied: d
ACCT rejected by server: d
Got a d ftp-server response when 220 was expected
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
PROT %c
Entry path is '%s'
QUOT command failed with d
MKD %s
Failed to MKD dir: d
PRET command not accepted: d
Remembering we are in dir "%s"
Failure sending ABOR command: %s
server did not report OK, got %d
QUOT string not accepted: %s
TYPE %c
Connecting to %s (%s) port %d
Wildcard - START of "%s"
Wildcard - "%s" skipped by user
Failure sending QUIT command: %s
Uploading to a URL without a file name!
FTPS not supported!
Couldn't open file %s
Can't open %s for writing
Can't get the size of %s
Refusing to issue an RTSP request [%s] without a session ID.
Transport:
Transport: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Range: %s
%s %s RTSP/1.0
Session: %s
%s%s%s%s%s%s
Unable to read the CSeq header: [%s]
Got RTSP Session ID Line [%s], but wanted ID [%s]
%%X
login
password
%s:%s:%s
%s:%.*s
%s:%s:x:%s:%s:%s
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%s, opaque="%s"
%s, algorithm="%s"
Failed to resolve "%s" for SOCKS4 connect.
SOCKS4%s request granted.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
User was rejected by the SOCKS5 server (%d %d).
SOCKS5 GSSAPI per-message authentication is not supported.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
Failed to resolve "%s" for SOCKS5 connect.
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Establish HTTP proxy tunnel to %s:%hu
%s:%hu
%s%s%s:%hu
Host: %s
CONNECT %s HTTP/%s
%s%s%s%s
HTTP/1.%d %d
TUNNEL_STATE switched to: %d
Received HTTP code %d from proxy after CONNECT
.jpeg
.html
; filename="%s"
%s; boundary=%s
Content-Type: multipart/mixed, boundary=%s
Content-Type: %s
couldn't open file "%s"
--%s--
%c%c==
%c%c%c=
%s xxxxxxxxxxxxxxxx
00000001
12345678
%s/%s
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s
0123456789-
Visual C CRT: Not enough memory to complete call to strerror.
Operation not permitted
Inappropriate I/O control operation
Broken pipe
GetProcessWindowStation
curl_easy_perform() failed: %s
SOFTWARE\Microsoft\SoftWare Reporting\Reporting\Reporting
HTTP POST
SOFTWARE\Microsoft\SoftWare Reporting\ect
SOFTWARE\Microsoft\SoftWare Reporting\Reporting\Reporting\Debug
SoftWare Support Service
M-%.2d-%.2d
SOFTWARE\Microsoft\SoftWare Reporting\temp
QQPCTray.exe
M-%.2d-%.2d %.2d:%.2d:%.2d
QQBrowser.exe
UCBrowser.exe
KuGou.exe
Client.exe
pptv_shenjiangtulong.exe
KwMusic.exe
GamePlaza.exe
ihelper.exe
QyClient.exe
SOFTWARE\Microsoft\SoftWare Reporting
report=
OpenSCManager failed (%d)
OpenService failed (%d)
QueryServiceStatusEx failed (%d)
StartService failed (%d)
Current State: %d
Exit Code: %d
Check Point: %d
Wait Hint: %d
F:\pack\service\PostService - test\Release\SoftWare SVC.pdb
SHLWAPI.dll
KERNEL32.dll
ADVAPI32.dll
WS2_32.dll
WLDAP32.dll
PeekNamedPipe
GetProcessHeap
GetCPInfo
SoftWare SVC.exe
curl_easy_cleanup
curl_easy_duphandle
curl_easy_escape
curl_easy_getinfo
curl_easy_init
curl_easy_pause
curl_easy_perform
curl_easy_recv
curl_easy_reset
curl_easy_send
curl_easy_setopt
curl_easy_strerror
curl_easy_unescape
curl_escape
curl_formadd
curl_formfree
curl_formget
curl_free
curl_getdate
curl_getenv
curl_global_cleanup
curl_global_init
curl_global_init_mem
curl_maprintf
curl_mfprintf
curl_mprintf
curl_msnprintf
curl_msprintf
curl_multi_add_handle
curl_multi_assign
curl_multi_cleanup
curl_multi_fdset
curl_multi_info_read
curl_multi_init
curl_multi_perform
curl_multi_remove_handle
curl_multi_setopt
curl_multi_socket
curl_multi_socket_action
curl_multi_socket_all
curl_multi_strerror
curl_multi_timeout
curl_multi_wait
curl_mvaprintf
curl_mvfprintf
curl_mvprintf
curl_mvsnprintf
curl_mvsprintf
curl_share_cleanup
curl_share_init
curl_share_setopt
curl_share_strerror
curl_slist_append
curl_slist_free_all
curl_strequal
curl_strnequal
curl_unescape
zcÁ
C:\Windows\SoftWare SVC.exe
2016-09-12
2016-09-12 18:55:20
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
:#:(:-:9:\:
0#0(0-090\0
9*9/999{9: :$:(:,:0:
7(7,70747
6"7(7,70747
?'?,?9?>?
? ?$?0?4?
combase.dll
Emscoree.dll
- CRT not initialized
- Attempt to initialize the CRT more than once.
- floating point support not loaded
kernel32.dll
USER32.DLL
2.exe
software installnation report
%s is installed.
Stopping %s.
%s is stopped.
%s failed to stop.
%s is removed.
!"#$%&'()* ,-./012345678
18:55:20
9EPostService.exe_1088:
.text
`.rdata
@.data
.rsrc
@.reloc
u.hpWD
UU U!"UU#$UUUU%&'UUU(U)*U UUU,-.UU/0123UUUUUU4UUUUUUU5UUUUUU6789:;UUUUUUUU<UUU=>?@ABCDUUUUEUUUUFUUUUUUGUUHIUUUUUJKUUULLUUMUUUUUUUUUNUUOUPQRSUUTus@
!"FFF#F$Fÿ&F'()FFFFFFFFFFFFF*FFFFFFFFFFFF FF,-FFFFFFFFFFF.F/FFFFFFFFFFFFFF01FF234FF56789FFFFFFFF:;FF<=>FF?FFFFF@ABFFFFFCFDFFFFFE
%u$Wj%
t.Gj:W
Unable to parse FTP file list
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Access Violation
TFTP: File Not Found
Login denied
Issuer check against peer certificate failed
Invalid LDAP URL
Unrecognized or bad HTTP Content or Transfer-Encoding
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with given CA certificates
Problem with the local SSL certificate
SSL peer certificate or SSH remote key was not OK
An unknown option was passed in to libcurl
A libcurl function was given a bad argument
Operation was aborted by an application callback
FTP: command REST failed
FTP: command PORT failed
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: The server did not accept the PRET command.
FTP: Accepting server connect has timed out
FTP: The server failed to connect to data port
FTP: weird server reply
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
URL using bad/illegal format or missing URL
Unsupported protocol
Please call curl_multi_perform() soon
CURLSHcode unknown
Winsock version not supported
Protocol family not supported
Address family not supported
Operation not supported
Socket is unsupported
Protocol is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
Could not resolve %s: %s
getaddrinfo() failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
%s:%d
Added %s:%d:%s to DNS cache
Resolve %s found illegal!
%5[^:]:%d:%5s
Curl_addHandleToPipeline: length: %d
About to connect() to %s%s port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
Protocol %s not supported or disabled in libcurl
http_proxy
Port number too large: %lu
%s://%s%s%s:%hu%s%s%s
;type=%c
[%*45[0123456789abcdefABCDEF:.]%c
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
User-Agent: %s
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
Closing connection %d
Connection %d seems to be dead!
Server doesn't support pipelining
Found bundle for host %s: %p
Connection #%ld to host %s left intact
smtp
SMTP.
<url> malformed
:]://%[^
[^:]:%[^
Re-using existing connection! (#%ld) with host %s
Found connection %d, with requests in the pipe (%d)
%s://%s
Internal error removing splay node = %d
Internal error clearing splay node = %d
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
In state %d with no easy_conn, bail out!
Pipe broke: handle 0x%p, url = %s
[%s %s %s]
Send failure: %s
Recv failure: %s
%s cookie %s="%s" for domain %s, path %s, expire %lld
#HttpOnly_
skipped cookie with bad tailmatch domain: %s
httponly
23[^;
=]=I99[^;
%s%s%s
# Fatal libcurl error
# Netscape HTTP Cookie File
# hXXp://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
WARNING: failed to save cookies in %s
Failed to set SIO_KEEPALIVE_VALS on fd %d: %d
Failed to set SO_KEEPALIVE on fd %d
bind failed with errno %d: %s
Local port: %hu
Couldn't bind to '%s'
getsockname() failed with errno %d: %s
Bind to local port %hu failed, trying next
Name '%s' family %i resolved to '%s' family %i
Couldn't bind to interface '%s'
Local Interface %s is ip %s using address family %i
ssloc inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
getpeername() failed with errno %d: %s
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Failed to connect to %s: %s
Trying %s...
sa_addr inet_ntop() failed with errno %d: %s
couldn't connect to %s at %s:%d
Failed connect to %s:%ld; %s
0123456789
%d.%d.%d.%d
%s%s%s%s%s%s
Session: %s
%s %s RTSP/1.0
Range: %s
Referer: %s
Accept-Encoding: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Transport: %s
Transport:
Refusing to issue an RTSP request [%s] without a session ID.
Got RTSP Session ID Line [%s], but wanted ID [%s]
Unable to read the CSeq header: [%s]
SMTP
EHLO %s
HELO %s
No known authentication mechanisms supported!
AUTH %s %s
LOGIN
AUTH %s
MAIL FROM:%s SIZE=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s
RCPT TO:<%s>
RCPT TO:%s
Got unexpected smtp-server response: %d
STARTTLS denied. %c
STARTTLS not supported.
Remote access denied: %d
Access denied: %d
Authentication failed: %d
MAIL failed: %d
RCPT failed: %d
SMTPS not supported!
USER %s
APOP %s %s
%s %s
STLS not supported.
Access denied. %c
PASS %s
POP3S not supported!
IMAPS not supported!
%cd
LOGIN %s %s
AUTHENTICATE %s %s
AUTHENTICATE %s
LIST "%s" *
SELECT %s
FETCH %s BODY[%s]
APPEND %s (\Seen) {%lld}LOGINDISABLED
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
invalid tsize -:%s:- value in OACK packet
%s (%ld)
blksize is smaller than min supported
%s (%d)
blksize is larger than max supported
%s (%d) %s (%d)
got option=(%s) value=(%s)
tftp_rx: internal error
Timeout waiting for block %d ACK. Retries = %d
Received unexpected DATA packet block %d, expecting block %d
Received last DATA packet block %d again.
tftp_tx: internal error, event: %i
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
bind() failed; %s
tftp_send_first: internal error
%s%c%s%c
TFTP finished
TFTP response timeout
Can't get the size of %s
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
There are more than %d entries
LDAP remote: %s
LDAP local: ldap_simple_bind_s %s
LDAP local: Cannot connect to %s:%hu
LDAP local: trying to establish %s connection
LDAP local: %s
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
CLIENT libcurl 7.31.0
MATCH %s %s %s
DEFINE %s %s
insufficient winsock version to support telnet
WSAStartup failed (%d)
%s %d %d
%s %s %d
%s %s %s
%s IAC %d
%s IAC %s
Sending data failed (%d)
%d (unknown)
%s (unsupported)
%s IAC SB
Unknown telnet option %s
Syntax error in telnet option: %s
7[^= ]%*[ =]%5s
USER,%s
%c%c%c%c%s%c%c
%c%s%c%s
7[^,],7s
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
PORT
Failure sending PORT command: %s
,%d,%d
Failure sending EPRT command: %s
%s |%d|%s|%hu|
bind() failed, we ran out of ports!
bind(port=%hu) failed: %s
bind(port=%hu) on non-local address failed: %s
socket failure: %s
failed to resolve the address provided to PORT: %s
getsockname() failed: %s
Connect data stream passively
STOR %s
APPE %s
SIZE %s
RETR %s
ftp server doesn't support SIZE
PBSZ %d
Access denied: d
ACCT %s
ACCT rejected by server: d
Connecting to %s (%s) port %d
Failure sending QUIT command: %s
Uploading to a URL without a file name!
FTPS not supported!
FTP response aborted due to select/poll error: %d
FTP response timeout
MDTM %s
Bad PASV/EPSV response: d
Can't resolve new host %s:%hu
Can't resolve proxy host %s:%hu
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
Illegal port number in EPSV reply
%c%c%c%u%c
ddd d:d:d GMT
dddddd
unsupported MDTM reply format
QUOT string not accepted: %s
Wildcard - "%s" skipped by user
Wildcard - START of "%s"
Preparing for accepting server on data port
CWD %s
Failed FTP upload:
RETR response: d
server did not report OK, got %d
Failure sending ABOR command: %s
Remembering we are in dir "%s"
PRET RETR %s
PRET STOR %s
PRET %s
REST %d
Got a d response code instead of the assumed 200
TYPE %c
Failed to do PORT
PRET command not accepted: d
Failed to MKD dir: d
MKD %s
QUOT command failed with d
Entry path is '%s'
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
Got a d ftp-server response when 220 was expected
%sAuthorization: Basic %s
%s:%s
%s auth using %s with user '%s'
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %d
The requested URL returned error: %s
If-Unmodified-Since: %s
Last-Modified: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Failed sending HTTP request
%s%s=%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
PTF://%s:%s@%s
Content-Range: bytes %s/%lld
Content-Range: bytes %s%lld/%lld
Range: bytes=%s
PTF://
Host: %s%s%s:%hu
Host: %s%s%s
Chunky upload is not supported by HTTP 1.0
HTTP error before end of send, stop sending
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
RTSP/%d.%d =
HTTP =
HTTP/%d.%d =
%s, algorithm="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"
%s:%s:x:%s:%s:%s
%s:%.*s
%s:%s:%s
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
SOCKS4%s request granted.
Failed to resolve "%s" for SOCKS4 connect.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
--:--:--
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
Received HTTP code %d from proxy after CONNECT
CONNECT %s HTTP/%s
%s%s%s%s
Host: %s
%s%s%s:%hu
%s:%hu
Establish HTTP proxy tunnel to %s:%hu
TUNNEL_STATE switched to: %d
HTTP/1.%d %d
%%X
password
login
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
operation aborted by callback
ioctl callback returned error %d
the ioctl callback returned %d
seek callback returned error %d
Problem (%d) in the Chunked-Encoded data
HTTP server doesn't seem to support byte ranges. Cannot resume.
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Rewinding stream by : %zd bytes on url %s (zero-length body)
Operation timed out after %ld milliseconds with %lld bytes received
No URL set!
[^?&/:]://%c
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Disables POST, goes with %s
Issue another request to this URL: '%s'
Conn: %d (%p) Receive pipe weight: (%d/%d), penalized: %d
Site %s:%d is pipeline blacklisted
Server %s is blacklisted
Server %s is not blacklisted
- Conn %d (%p) send_pipe: %d, recv_pipe: %d
Adding handle: recv: %d
Adding handle: send: %d
d:d
d:d:d
%s xxxxxxxxxxxxxxxx
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s
%s/%s
12345678
00000001
%c%c==
%c%c%c=
0123456789-
.jpeg
.html
; filename="%s"
--%s--
couldn't open file "%s"
Content-Type: %s
Content-Type: multipart/mixed, boundary=%s
%s; boundary=%s
Visual C CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
GetProcessWindowStation
curl_easy_perform() failed: %s
Software Report Svc
OpenSCManager failed (%d)
OpenService failed (%d)
QueryServiceStatusEx failed (%d)
StartService failed (%d)
Current State: %d
Exit Code: %d
Check Point: %d
Wait Hint: %d
C:\Users\Administrator\Desktop\PostService\Release\PostService.pdb
SHLWAPI.dll
KERNEL32.dll
ADVAPI32.dll
WS2_32.dll
WLDAP32.dll
PeekNamedPipe
GetCPInfo
GetProcessHeap
PostService.exe
curl_easy_cleanup
curl_easy_duphandle
curl_easy_escape
curl_easy_getinfo
curl_easy_init
curl_easy_pause
curl_easy_perform
curl_easy_recv
curl_easy_reset
curl_easy_send
curl_easy_setopt
curl_easy_strerror
curl_easy_unescape
curl_escape
curl_formadd
curl_formfree
curl_formget
curl_free
curl_getdate
curl_getenv
curl_global_cleanup
curl_global_init
curl_global_init_mem
curl_maprintf
curl_mfprintf
curl_mprintf
curl_msnprintf
curl_msprintf
curl_multi_add_handle
curl_multi_assign
curl_multi_cleanup
curl_multi_fdset
curl_multi_info_read
curl_multi_init
curl_multi_perform
curl_multi_remove_handle
curl_multi_setopt
curl_multi_socket
curl_multi_socket_action
curl_multi_socket_all
curl_multi_strerror
curl_multi_timeout
curl_multi_wait
curl_mvaprintf
curl_mvfprintf
curl_mvprintf
curl_mvsnprintf
curl_mvsprintf
curl_share_cleanup
curl_share_init
curl_share_setopt
curl_share_strerror
curl_slist_append
curl_slist_free_all
curl_strequal
curl_strnequal
curl_unescape
zcÁ
%Program Files%\9ENetwork\9EPostService.exe
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
7 7$7(7,7074787<7
6 7$7(7,7074787`7}7
9 9$9(9,9094989<9
? ?$?(?,?0?
>1>6><>_>
78W8h8y8H:
mscoree.dll
yKERNEL32.DLL
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
WUSER32.DLL
software installnation reporting
%s is installed.
Stopping %s.
%s is stopped.
%s failed to stop.
%s is removed.
!"#$%&'()* ,-./012345678
KwMusic.exe_1292:
.text
`.rdata
@.data
.rsrc
u.hHMS
Nxhp%S
Nxhx%S
NxPhx%S
FTPh\
SSSSh
L$dSSh
Uxs.Ux?=XxN;Xx1
Xxt.Vx
button_breathskin.png
NETTIMER_ONTIMER: bOnline1: %d, m_bOnline: %d
CheckNetData.txt
NETTIMER_ONTIMER: bOnline1: %d, m_bOnline1: %d
KwExternal.exe
hXXp://
FUNCTION:EXTERNAL|SOURCE:%s|RUNCOUNT:%d|RUN:%d
%d_%d_%d
KWUpdate.exe
hXXp://msclick.kuwo.cn/SubmitTask.do
kwmusic.exe
system32\taskkill.exe
/f /pid %d
/f /pid %d
kwservice.exe
Speed.txt
WinMain InitHttpMgr
WinMain LogInit
WinMain InitKwHttpMgr
WinMain ExcuteCmdLineBeforeUI
LogMsg
dyt.exe
TargetExe1
TargetExe2
skin\base\KwMusic.xml
restore.png
max.png
changeskin.png
hXXp://g.koowo.com/g.real?aid=text_ad_1824&url=hXXp://x.kuwo.cn/KuwoLive/OpenLiveRoomLinkForKw?from=1001003087
LiveShowUrl
Num:%d|Exit:%d|Type:%s|STARTTM:%d|OSV:%s|CPU:%d*%d|MEM:%d|FREEMEM:%d|MUSICAPP:%s|SYSSTARTTIME:%u
KwConfig.exe
hXXp://VVV.kuwo.cn/skin/
hXXp://vip.kuwo.cn/vip2013/st/PayInfo2013
hXXp://vip.kuwo.cn/vip2013/
hXXp://vip.kuwo.cn/vip2013/jsp/tequan.jsp?src=
hXXp://kuba.kuwo.cn/cafe/st/Ba?baId=3595
hXXp://k.kuwo.cn
hXXp://shouji.kuwo.cn
hXXp://game.kuwo.cn
hXXp://VVV.kuwo.cn/
menu_more_login_2.png
menu_more_login_1.png
menu_more_mini_2.png
menu_more_mini_1.png
menu_more_musictool_2.png
menu_more_musictool_1.png
back_to_old_version_2.png
back_to_old_version_1.png
menu_more_config_2.png
menu_more_config_1.png
menu_more_exit_2.png
menu_more_exit_1.png
UIDeskLyric.dll
KwLnkTipWnd.exe
tray_menu_pre.png
tray_menu_play.png
tray_menu_pause.png
tray_menu_next.png
mutebtn_tray.png
mutedbtn_tray.png
_2.png
_1.png
KwMusic.txt
%d&%ld&%ld
|*.AAC;*.AC3;*.APE;*.CDA;*.FLAC;*.M4A;*.MP1;*.MP2;*.MP3;*.OGG;*.RMP;*.TTA;*.WAV;*.WMA|AAC
(*.aac)|*.AAC|AC3
(*.ac3)|*.AC3|APE
(*.ape)|*.APE|CDA
(*.cda)|*.CDA|FLAC
(*.flac)|*.FLAC|MP4
(*.mp1;*.mp2;*.mp3)|*.mp1;*.mp2;*.mp3|OGG
(*.ogg)|*.OGG|TTA
(*.tta)|*.TTA|WAV
(*.wav)|*.WAV|WMA
(*.wma)|*.WMA||
changeskinnew.png
LyricBkMask-10.png
LyricBkMask.png
KwMusic.exe
DownloadSongExeStartup
gameurl/?
gameurl=
.lrcx
BTN:WEB_PLAY|PARAM:
CWebHandler.log
DataRepair.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KwService.exe
"%s%s" /S=autorun
NCHECK:%d|DYTRUN:%d|TACTICS:%d|MODPERC:%d|MODRET:%d|FORCEAR:%d|ARREG1:%d|ARREG2:%d|RWREG:%d|DYTPATH:%s||HK:%d|HKAT:%d|WSVRAS:%d|STARTUP_HK:%d|HKALLOW:%d
MUSIC_7.2.0.7_BCS98
MUSIC_7.2.0.7_BCS97
gamebutton.txt
hXXp://g.koowo.com/g.real?aid=text_ad_1649&ver=
hXXp://game.kuwo.cn/g/st/mbox2013game
hXXp://g.koowo.com/g.real?aid=text_ad_1712&url=
hXXp://topmusic.kuwo.cn/today_recommend/miniTC/second/contentvip2013.html
hXXp://topmusic.kuwo.cn/today_recommend/miniTC/four/content2013A.html
URLBase64
URLBase64
MinisiteIsLogin
minisite.txt
skin\base\KwMinisiteDlg.xml
MiniSite,Url:%s
modUpdateWeb_1
error_404.html
KwMiniSite::CMiniSiteDlg::IsShowMiniSite
UIAvMgr.txt
&client=rcmweb&name=
%s&p=%d
&ThirdLogin=
Windows Media
Monkey's Audio
.flac
.jpeg
" width="200" font="PopUp.Title"/>
<Progress name="AddLocalSongProgress" padding="20,10,20,0" mouse="false" max="100" height="8" bkimage="progress_common_1.png" fgimage="progress_common_2.png"/>
" width="70" height="30" setcursor="true" statusimage="Config_Button.png" font="PopUp.SectionTitle" hottextcolor="#ffffffff" pushedtextcolor="#ffffffff" focusedtextcolor="#ffffffff" />
startupcmd
ret = %d, result = %d
kwmusic.log
0MUSIC_NO_ALIVE: b2012Exist=%d, bOtherAlive=%d
//gameurl/
icourl
name:%s, url:%s
gameicon.txt
nameexist:%s
\kwmusic.exe
res\icons\GameIcon.ico
,Url:%s
GameIcon.ico
KwDPGame.exe
&ver=%s&uid=%s&bid=%s
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\%s\UserChoice
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
ASC:0|EPOS:%d|UAC:1|MST:%d|MASK:0x%x
ASC:1|EPOS:%d|UAC:0|MST:%d|MASK:0x%x
WriteMbox.exe
ASC:0|EPOS:%d|UAC:0|MST:%d|MASK:0x%x
%s|%s
b.jpg
DOWNPACK_NAME:%s,DOWNPACK_ID:%s
%d.%d.%d
HARDWARE\DESCRIPTION\System\CentralProcessor\%d
%u*%u
PATH:%s
hXXp://mboxzhaoge.kuwo.cn/zhaoge/album/share.jsp?rid=
&url=
LiveShowMD5Key
UserHotkey
HotKey
webregistersvr2012
newlogin
ThirdLoginName
ThirdLoginImage
IsThirdLogin
UserLoginType
DontRemPass
AlbumPicConfUrl
ProblemReport
Unable to load MediaInfo.dll
<Button name="close" padding="0,10,10,0" width="22" height="22" statusimage="Config_CloseBtn.png" />
..." padding="15,0,0,0" width="195" font="PopUp.SectionTitle" />
" padding="0,0,0,0" width="75" setcursor="true" font="PopUp.SectionTitle" textcolor="#FF46B4E6" hottextcolor="#FF46B4E6" pushedtextcolor="#FF46B4E6" focusedtextcolor="#FF46B4E6" visible="false"/>
" statusimage="Config_Button.png" visible="false" hottextcolor="#FF000000" pushedtextcolor="#FF000000" focusedtextcolor="#FF000000" />
iexplore.exe
Encryption in, src is %s.
checknewver.log
MUSIC_3.2.0.0
hXXp://config.kuwo.cn
%s;%s,%s,CHECK_UPDATE
Encrypt string Error! string is %s, length is %u.
Encrypt string Success! string is %s, length is %u.
Get Config Request: HTTP Request is error!
result config content is %s
Config file: content is %s
Win7Trait.dll
tasktk.exe
report
%s|%u|%s
CSRC:%d|RCODE:%d
KERNEL32.DLL
GetSystemWindowsDirectoryA
GetProcessHandleCount
DBGHELP.DLL
USER32.DLL
PSAPI.DLL
Wtsapi32.dll
ADVAPI32.DLL
%s\ddddddd_%s%s%s.exception
%s\ddddddd_%s%s%s.dmp
DumpReport.exe
void, Value: X
char, len: %d, value(s):
short, len: %d, value(s):
int, len: %d, value(s):
WORD, len: %d, value(s):
unsigned int, len: %d, value(s):
float, Value: %f
btFloat, len (bytes): %d, value(s):
long, len: %d, value(s):
unsigned long, len: %d, value(s):
TerminateThread %d
optimization.txt
player:%s
update.txt
PLAYERCMD
%s\%s
SendMessage to Close Player %s.
%sKwUpdate.dll
\setup.xml
0123456789
.0123456789
%s;%s,%s,%s,%s
update.log
is update: %s
%s\kuwodata\kwmusic2013\Conf\user\config.ini
%s\kuwodata\kwmusic2013\Update\uppack
%s /S
skin\base\UpdateTipDialog.xml
6.0.0.1
ShowImportance
icon_updatetipdlg_level.png
Default.FontName
icon_updatetipdlg_arraw.png
Default.FontName.Bold
icon_updatetipdlg_mask.png
modhotkey
musictoolwnd.log
,Sig:%u,%u,Path:%s
,Sig:%u,%u,Per:%u
,Sig:%u,%u
CDownMusicToolEx,%u,%u
MUSICTOOL%d
RunAsAdmin %s
/S /D=%skwplugins
InstParam.ini
CDownMusicToolEx::GetExePath
plugin.xml
skin\base\MusicToolDown.xml
conf.txt
ksong.ini
MUSIC_6.0.0.0
%s;%s,%s,GET_KWSING_SOFT
hXXp://topmusic.kuwo.cn/today_recommend/tool_new/confall.txt
url:%s,Error:%d
hXXp://60.28.217.171:2502/AppRunServer/GetAppRun.do?
MUSIC_8.0.0.0
CDownMusicTool,%u,%u
CDownMTool::GetExePath
Base/EqDlgAttribute.xml
skin\base\KwEqDlg.xml
(*.feq;*.tteq_cfg;*.eqf)
*.feq;*.tteq_cfg;*.eqf
.tteq_cfg
(*.feq)
*.feq
skin\base\MusicTool.xml
MusicBox_TXT_Msg
icon_tool_AutoShutDown.png
btn_musictool_bk.png
GameToolsUrl
hXXp://topmusic.kuwo.cn/today_recommend/newgamebox_b/gamebox.html
KwGameWndUrl
KwGameWebWndWidth
KwGameWebWndHeight
mutedbtnempty.png
mutedbtnhalf.png
mutedbtn.png
mutedbtnplus.png
d:d
DefaultAlbumPic.png
%d KB/s
icon_tool_AddToolBtn_5.png
icon_tool_AddToolBtn_%d.png
CPlayControlNotify::GetAlbumHttpPath
playcontrol.txt
CPlayControlNotify::GetAlbumHttpData
OpenFile wrong pic %s
hXXp://artistpic.kwcdn.kuwo.cn:81
/pic.web?type=rid_pic&pictype=url&size=300&rid=
hXXp://artistpicserver.kuwo.cn
/pic.web?type=rid_pic&pictype=url&size=70&rid=
NO_PIC: %s
SetBkImage(%s)
CasualListenWhiteHeart_PlayControl_3.png
CasualListenWhiteHeart_PlayControl_1.png
CasualListenWhiteHeart_PlayControl_2.png
User32.dll
res\icons\ThumbnailToolbar.bmp
playcontrol_play_mode_singleonce.png
playcontrol_play_mode_single.png
playcontrol_play_mode_order.png
playcontrol_play_mode_circle.png
playcontrol_play_mode_random.png
\res\param.dat
Vol.dll
hVolCheck=0x%p, GetProcessSystemVolume hr=0x%p, bMuted=%d, level=%f
CheckVolume.txt
CHECK_MUTE:1|UNSET_MUTE:0x%p|SET_VOL_RES:0x%p|SET_VOL:%f
ModMusicTool\ksong.ini
SIZING: %d,%d,%d,%d
HighQualityLogin
menu_common_nstatus.png
btn_mqselect.png
openurl
Exist icon,show tool:%s
hXXp://topmusic.kuwo.cn/today_recommend/tool_new/
KWGameBox\config.ini
KWPet\Config.ini
Conf\user\config.ini
\KwNetDrive.exe
\KwSing.exe
OpenURL
%s cmd %s
/s kwm /k %s /u %s /p %s /d show
/s kwm /k %s /d show
ModuleData\ModMusicTool\conf.txt
kuwo\ModuleData\ModMusicTool\conf.txt
/url=
game.kuwo.cn
OPEN WEB
skin\base\functionwnd.xml
btn_main_myicon_3.png
btn_main_myicon_4.png
keydown_confirm
keydown_down
keydown_up
keydown_esc
%s%s%u
MBOXLOG?stype=type_soperation&pos=-1&snum=%s&operationtype=noop&searchtype=music&refaddr=noref
btn_netsong_searchhide.png
btn_netsong_searchdrop.png
hXXp://skeylist.kuwo.cn/searchkey/searchkey.txt
DefaultUrl
STYPE:%s|SORGINKEY:%s|STIPPOS:%s|SKEY:%s|SNUM:%s|STIME:%s|SRESULT:%s|SEARCHTYPE:%s|SCOUNT:%s
STYPE:%s|SORGINKEY:%s|STIPPOS:%s|SKEY:%s|SNUM:%s|SHOWDHJ:%s|DHJNAME:%s
type_soperation
operationtype
STYPE:%s|OPERATIONTYPE:%s|POS:%s|SNUM:%s|SEARCHTYPE:%s|REFADDR:%s|SORGINKEY:%s|STIPPOS:%s|SKEY:%s
STYPE:%s|SNUM:%s|STIME:%s|SRESULT:%s|SEARCHTYPE:%s|SORGINKEY:%s|STIPPOS:%s|SKEY:%s
skin\base\searchtip.xml
Main.ChannelTitle
keywordcolor
defaultword%d
history%d
hXXp://search.kuwo.cn
SearchServerDNS%d
hXXp://tips.kuwo.cn:80/t.s?c=mbox&w=
hXXp://jiucuo.search.kuwo.cn/correct.s?key=
hXXp://img1.kwcdn.kuwo.cn:81/star/starheads/
snum=%s
lCookie:%d
NetSongLib.txt
bOnlyNoSilence:%d
TYPE:CHANGEDNS CURDNS:%d URL:%s
OpenFile Failed:%s
KEY:%s|ISGET:%d|ISLOCAL:%d|SEARCHSVR:%d|SEARCHSVR_C:%d|SEARCHSVR_R:%d|SEARCHSVR_D:%d
PopUp.Title
Config_CloseBtn.png
ape.html
apeExplainUrl
skin\base\AutoRunShowTipWnd.xml
skin\base\startpage.xml
res\tyyykw.wav
skin\startpage\startpage_locallist.xml
../startpage\Default.jpg
worker thread is on, wait for timer. %u
download_font_msYahei.txt
Exit signaled. %u, diff time: %u
timer signaled. %u, diff time: %u
P2PStartDown: %s
CopyFile ERROR CODE: %d
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
%s, RET: %u, ERROR: %u
"%s-%s"
MSYH.TTF
MSYHBD.TTF
OnLogin
#FF46B4E6 hXXp://mbox.kuwo.cn/
<f Default.FontName>Hi
<u><a #FF46B4E6 hXXp://mbox.kuwo.cn/>
kuwodata\KWMUSIC\Conf\user\config.ini
\bin\KwMusic.exe
skin\base\BackToOldVer.xml
hXXp://down.kuwo.cn/mbox/kwmusic2012.exe
KwMusicURL
hXXp://kuba.kuwo.cn/cafe/st/Ba?baId=1818
KwMusicBackToOldVerOf2012.exe
Wallpaper.log
/call?method=setWallpaperOn&type=%s&onOff=%d&takeEffect=%d&saveConf=%d&cookie=KwMusic
KwWallpaper.exe"
WpAbmTip_Start.xml
WpAbmTip_Close.xml
skin\base\WallpaperPreviewWnd.xml
skin\base\WallpaperTipWnd.xml
DeleteDir("%s")%s|SPSELECT:%d|ABMSELECT:%d
.thumb.jpg
UILibLoadImage("%s", "%s") ==> %dkernel32.dll
%s: JSON parse failed: %s
1179873086
1762481905
wp.ini
resendlog.log
hXXp://log.kuwo.cn
/music.yl
Send Msg to Server Request Error!
Send Msg to Server Out
KuDaemon.exe
KuCache.exe
ISREPORT
KPlugin.txt
%s /S /D=%skwplugins
RunAsAdmin %s %s
GetPluginInfo %d
for i = %d
Load_Plugin %d
WEBLOG
SetDefualtUrl
netsong.log
error.html
Web_NavigateFailed:%s IsExistFile=%d
DocumentComplete:%dms, channel:%d
NavigateComplete:%dms, channel:%d
Web_OnCreate_HtmlView
Web_ReCreate:%d channel:%d %s
Web_OnCreate:%dms, channel:%d
ShowTime:%dms, channel:%d
;key=
PageReady:%dms, channel:%d
%s,%d
url_error
url_time:
UrlTime
hXXp://60.28.201.10/client/hljok/%s
url_error:
TIME_%s:%d,%d
TIME_%s:%d,%d Part %d,%d,%d,%d
WebFirstShowApeTip
hXXp://mbox.kuwo.cn:8080/ur/ierepair/jserror.html
iefixurl
hXXp://topmusic.kuwo.cn/today_recommend/setCookie2013.html
kwjserror.html
quku.html
hXXp://mboxspace.kuwo.cn/ucm/mbox2013/home_2014.jsp
LoadPage:%d
rid=%s,name=%s,artist=%s,album=%s;
<Default name="Label" value="font="Default.FontName" textcolor="#FF333333""/>
<Control name="hq_perfect_img" width="16" height="17" bkimage="vip_logo.png" padding="0,6,0,0" />
<Control name="hq_super_img" width="16" height="17" bkimage="vip_logo.png" padding="0,6,0,0" />
list_netsong_play_1.png
list_netsong_play_3.png
list_netsong_play_4.png
skin\base\UserFeedbackDlg.xml
CWebControlMgr::CWebControlMgr
CHANNEL:%s
X.dat
webcache\
%s %d&%ld&%ld
web.log
menu_add_to_2.png
menu_add_to_1.png
menu_earch_2.png
menu_earch_1.png
UserLogin?
ShowOperation
URLBase64?
hXXp://mbox.kuwo.cn:8080/ur/reflect/mbox_question.jsp
Login %s
webcontrolmgr
netsong.txt
IESandBox.exe
WebRecommend_1
BTN:WEB_DOWNLOAD|PARAM:
weblist/?
weblist?
CWebReCommendData::_OnWebList
skin\base\AutoLoginTip.xml
checkbox_autologin
skin\base\WebPopupDlg.xml
\thirdlogin\bind_kuwo.htm?t=
hXXp://webstat.kuwo.cn/pet.web?s=mbox&ver=%s&t=open&softid=%s
IUserMan::User_Login
User_Login
userinfo.txt
%s/u.s?type=logout&uid=%u&sid=%u&req_enc=gbk&res_enc=gbk
%d%d%d
Login
UserInfo.txt
%s/u.s?type=login&uname=%s&pwd=%s&pk=%s&dev_key=%s&dev_name=%s&req_enc=gbk&res_enc=gbk
nSession = %d, nCode = %d
errcode_%d;url_%s
LOGIN
LOGINTO
nickname
AddDlg.txt
hXXp://i.kuwo.cn
hXXp://loginserver.kuwo.cn
hXXp://kzone.kuwo.cn
hXXp://play.kuwo.cn
res\loginbanner1.png
loginbanner1.png
clogindlg
skin\base\logindlg.xml
loginbanner2.png
loginbanner_Skin.png
loginbanner_Cloud.png
loginbanner_EggSmash.png
loginbanner.png
login
password
rempassword
autologin
password_errtip
getpassword
%s/US/FindPassword?uname=%s&ver=%s
LoginDlgEx
skin\base\logindlgex.xml
qqlogin
wblogin
renrenlogin
qqweibologin
kuwologin
CallLogin?
hXXp://i.kuwo.cn/US/platform/orig.htm
ThirdPartUrl
GetLoginParams
LoginResult?
GetDevKey
\error_404.html
ver=%s&branch=vipclient&pk=%s
third login result: %s
CThirdPartLoginDlg::OnLoginResult
UserLoginInfo.log
THIRDLOGIN
btn_musictool_close.png
Default.FontName.UnderLineBold
ballonvert_1.png
ballonvert_2.png
ballonvert_3.png
ballonvert_4.png
ballonhorz.png
%s/p/%s
%s/play/st/Play?rid=%s
%s%s%s%s%s
%s/mlog/client/CheckFileService?userId=%s
%s/mlog/client/UploadFileService?userId=%s&len=%u
skin\base\UserfaceWnd.xml
HTTP/1.0
content-type:application/x-www-form-urlencoded
Content-Length: %d
jpg Files (*.jpg)|*.jpg||
*.jpg
userface.jpg
%.0f%c
%s/US/LoginFromMboxCloud.jsp?uid=%ld&uname=%s&pwd=%s&sid=%d&devname=%s&devid=%d
%s/US/LogoutFromMbox2013.jsp?uid=%ld
%s/US/LoginFromMbox2013.jsp?uname=%s&pwd=%s&auto=1&v=%s&sid=%u&devid=%u&devname=%s
%s/US/LoginFromMbox2013.jsp?uname=%s&pwd=%s&v=%s&sid=%u&devid=%u&devname=%s
%s/US/HeadPicForMbox?uid=%ld
GetUrlResult
%s/US/client/uinfo2012.jsp?uid=%ld
%s\face\tmp.jpg
%s\face\%ld.jpg
%s\face
modhttp_4
/u.s?type=kick&uname=%s&pwd=%s&sid=%u&dev_id=%u&req_enc=gbk&res_enc=gbk
/u.s?type=getsessions&uid=%u&sid=%u&req_enc=gbk&res_enc=gbk
CUserInfoNotify::GetLoginCountInfo
BTN:USER_PANEL_LOGIN
relogin
logininfolabel
file='btn_userinfo_level.png' dest='0,8,18,20' source='%d,0,%d,12'
vip_%d.png
defaultface.jpg
%sface\%ld.jpg
LoaduserPhoto%s
UserLoginArea
write cookie,url
login_ip
login_region
login_time
listpaneltopborder.png
labLoging
Login.LabelText
hXXp://i.kuwo.cn/US/2013/kwmusic/reg.htm
Regist_Web
spread.log
sprdtasks.ini
daily max request = %d, requested = %d
daily max task = %d, completed = %d
task list is not empty: %d
spreadurl
url is invalid: %s
%s?uid=%s&version=%s&source=%s&t=%d
begin geting tasklist, url=%s, taskId=%d
CP2PSpreadManager::ExecuteNextTask
%u-%u
RET:%d|SIG1:%u|SIG2:%u|DSIZE:%d|SPAN:%u|FRATE:%d
start download: (%u, %u)
finish download: (%u, %u)
download failed: (%u, %u)
download progress: (%u, %u), rate = %d, speed = %d
request task list start, filepath = %s, filesize = %d
CP2PSpreadManager::HttpRequestOb_DownloadBegin
CP2PSpreadManager::HttpRequestOb_DownloadStopped
request task list finish: %s
CP2PSpreadManager::HttpRequestOb_DownloadFinish
open file failed: %d
read file failed: %d
write file failed: %d
copy file failed: %d
RET:%d|RESION:%s|NUM:%d
request task list failed: %d
CP2PSpreadManager::HttpRequestOb_DownloadFailed
RET:0|RESION:HTTPERROR_%d|NUM:0
skin\base\ListBuddyWnd.xml
{"source":"4","sourceid":"%s","name":"%s","id":"4","back":"true"}{"source":"13","sourceid":"%s","name":"%s|%s","id":"13","back":"true"}Config.DefaultText
new_song.png
Default.FontName.UnderLine
_4.png
_3.png
_6.png
_5.png
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=drag&searchtype=music&refaddr=noref
list_netsong_defartist.png
list_netsong_quility_3.png
%.2d %s
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=song&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=ref&searchtype=music&refaddr=refartist
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=ref&searchtype=music&refaddr=refalbum
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=down&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=%s&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=downall&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=playall&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=addall&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=%d&%s&operationtype=mvall&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=-1&%s&operationtype=sortsong&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=-1&%s&operationtype=sortartist&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=-1&%s&operationtype=sortalbum&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=-1&%s&operationtype=sorthq&searchtype=music&refaddr=noref
MBOXLOG?stype=type_soperation&pos=-1&%s&operationtype=sorthot&searchtype=music&refaddr=noref
list_netsong_sort_1.png
list_netsong_sort_2.png
MBOXLOG?stype=type_stime&%s&stime=%d&sresult=fail&searchtype=music
url_error:%s;search;%s
SearchNoResult.html?
MBOXLOG?stype=type_stime&%s&stime=%d&sresult=suc&searchtype=music
?key=%s
search_cat.html
%d,%d,%d,%d
DHJFinish?w=%d&h=%d&type=%[^&]&advicex=%d&advicey=%d&btnx=%d&btny=%d
tab_netsong_specially_1.png
btn_netsong_play.png
btn_netsong_operation.png
list_netsong_add_3.png
list_netsong_MV_3.png
list_netsong_download_3.png
list_netsong_head_1.png
list_netsong_head_2.png
list_netsong_head_3.png
list_netsong_headsep.png
nowbg.gif
WebLoading.png
Main.Loading
jiazai.jpg
Main.Loading.UnderLine
operation
NetSong.ListSelect
NetSong.ListHover
playlist.gif
?key=%s&showadvice=0
dhj.html
pos err!ipos=%d,iSize=%d
netsongdata.txt
PlaylistData.txt
NetSong-artists.pl
NetSong.pl
_DownFile OpenFile Faild %s
fopen_s Faild %s
hXXp://down.kuwo.cn/mbox_data/dataset/ArtistList/Recommendzip_CT.zip
bangdan.zip
_HttpDownBangDan
starmenu2.0.xml
CNetSongData::_HttpDownNode
OpenFile failed:%s
_HttpDownNode
myfavorite.txt
_HttpDownBangDan ok
artistnewconf.xml
favoratecateconf.xml
OnAddMission:%s,%s
NetDrive.txt
GetMessage:%d
KwNd\ModuleData\ModPlayList\ShortCut.pl
MSG_ADDMISSION:%d
\\.\Pipe\KuWoNdAddMissionPipe_20110427
ReadFile:%d
MSG_ADDMISSION out
%u|%u|%u|%s
%u|%u
%u|%u|%u|%u
\\.\Pipe\KuWoNdDownStatePipe_20110427
AppInterface.txt
strMsg=%s
\2014\KwResource\bin\release\pdb\KwMusic.pdb
GdiplusShutdown
gdiplus.dll
URLDownloadToFileA
urlmon.dll
InternetCrackUrlA
WININET.dll
KERNEL32.dll
MsgWaitForMultipleObjects
UnregisterHotKey
RegisterHotKey
GetKeyState
GetKeyNameTextA
EnumChildWindows
USER32.dll
GDI32.dll
COMDLG32.dll
RegOpenKeyExA
RegCloseKey
RegCreateKeyExA
ADVAPI32.dll
ShellExecuteA
SHFileOperationA
ShellExecuteExA
SHELL32.dll
ole32.dll
OLEAUT32.dll
MSVCP90.dll
??0ProcessExecutor@Process@KwLib@@QAE@XZ
??1ProcessExecutor@Process@KwLib@@QAE@XZ
?SetWorkDirectory@ProcessExecutor@Process@KwLib@@QAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?Exec@ProcessExecutor@Process@KwLib@@QAEHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_N@Z
?OpenUrl@utility@KwLib@@YA_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_N@Z
?ReadString@REG@KwLib@@YA_NPAUHKEY__@@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@1AAV45@@Z
?WriteString@REG@KwLib@@YA_NPAUHKEY__@@PBD11@Z
?DeleteKey@REG@KwLib@@YA_NPAUHKEY__@@PBD1@Z
?Encode@UrlEncode@KwLib@@YAHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAV34@@Z
?EncodeQuery@UrlEncode@KwLib@@YAHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAV34@@Z
?Decode@UrlEncode@KwLib@@YAHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAV34@@Z
?ReadString@REG@KwLib@@YA_NPAUHKEY__@@PBD1QADI@Z
?ReadDWORD@REG@KwLib@@YA_NPAUHKEY__@@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@1AAI@Z
?win32exec@utility@KwLib@@YAPAXPBD0_N@Z
KwLib.dll
?LogUserActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0PBD_N@Z
?LogInit@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?LogFeatureMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z
?MakeHttpParam@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV12@H@Z
?LogABActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PBD@Z
?LogClientErrorMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@000@Z
?LogServerErrorMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@00000@Z
KwLog.dll
?SetRankingState@CNetSongInfo@@QAEXE@Z
?SetMsShow@CNetSongInfo@@QAEXH@Z
?GetMsShow@CNetSongInfo@@QAEHXZ
?GetNetUrl@CNetSongList@@QAE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
KwDataDef.dll
?SetSendSizeMsg@CControlUI@DuiLib@@UAEX_N@Z
?GetSendSizeMsg@CControlUI@DuiLib@@UAE_NXZ
?GetCreateWindowStyle@CKwBaseDialog@DuiLib@@UBEJXZ
?OnSetAlphaTranspanrent@CKwBaseDialog@DuiLib@@UAEXE@Z
?IsDragOperatorAccept@CAcceptDrag@DuiLib@@UAEHXZ
?IsShowCheckBox@CListUI@DuiLib@@UBE_NXZ
?IsDragOperatorAccept@CListUI@DuiLib@@UAEHXZ
DuiLib.dll
KwMusicCore.dll
KwModConfig.dll
?CallJScript@CInterProcessHtmlView@@QAE_NABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z
??_7IWebAction@@6B@
?ShowIE@CInterProcessHtmlView@@QAEXHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
??0CInterProcessHtmlView@@QAE@XZ
?SetAction@CInterProcessHtmlView@@QAEXPAVIWebAction@@@Z
?Create@CInterProcessHtmlView@@QAE_NPAUHWND__@@KUtagRECT@@_NHH@Z
?Navigate2@CInterProcessHtmlView@@QAEXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@K@Z
??1CInterProcessHtmlView@@QAE@XZ
?Move@CInterProcessHtmlView@@QAEXABUtagRECT@@@Z
?Web_ReCreate@IWebAction@@UAEXPAVCInterProcessHtmlView@@@Z
?Web_OnCreate@IWebAction@@UAEXPAVCInterProcessHtmlView@@@Z
?Web_OnShow@IWebAction@@UAEXPAVCInterProcessHtmlView@@@Z
?Web_DocumentComplete@IWebAction@@UAEXV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?Web_OnAutoCloseTimeout@IWebAction@@UAEXXZ
?Web_OnWndClose@IWebAction@@UAEXXZ
?Web_OnNoSupportJs@IWebAction@@UAEXXZ
?Web_NavigateFailed@IWebAction@@UAEXV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?Web_NavigateComplete2@IWebAction@@UAEXV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?GetHWnd@CInterProcessHtmlView@@QAEPAUHWND__@@XZ
?Notify_Show@CInterProcessHtmlView@@UAEX_N@Z
?Notify_Size@CInterProcessHtmlView@@UAEXUtagRECT@@@Z
?OnNavigateComplete2@CInterProcessHtmlView@@UAEXPBD@Z
?OnDocumentComplete@CInterProcessHtmlView@@UAEXPBD@Z
?OnNavigateError@CInterProcessHtmlView@@UAEXPBD@Z
?Destory@CInterProcessHtmlView@@QAEXXZ
?GetLocationURL@CInterProcessHtmlView@@QAE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ
?IsDocumentComplete@CInterProcessHtmlView@@QAE_NXZ
?OnDrop@CInterProcessHtmlView@@QAEXHHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?IsDropTarget@CInterProcessHtmlView@@QAE_NHH@Z
IEProxy.dll
InitKwHttpMgr
UninitKwHttpMgr
GetKwHttpMgr
KwHttp.dll
PathIsURLA
SHLWAPI.dll
COMCTL32.dll
AfxGetHttpRequestMgr
KwHttpRequestMgr.dll
MSVCR90.dll
_amsg_exit
_acmdln
_crt_debugger_hook
SensApi.dll
KwServiceProxy.dll
KwSongCache.dll
KwTagLib.dll
WINMM.dll
IPHLPAPI.DLL
WS2_32.dll
GetProcessHeap
WaitNamedPipeA
.?AVIKwHttpRequestObserver@@
.?AVIKeyFrameAnimation@DuiLib@@
.?AVIWebAction@@
.?AVIHttpNotify@@
.?AVCHotKeyConfig@@
.?AVIHotKeyData@@
.?AV?$holder@W4eMsgLevel@@@Variant@KwLib@@
.?AVIHotKeyObserver@@
.?AW4eMsgLevel@@
.?AVCInterProcessHtmlView@@
.?AVCWebControl@@
.?AV?$holder@PAVCWebControl@@@Variant@KwLib@@
.?AVCWebControlMgr@@
.?AVIWebPopupDlgObserver@@
.?AVIWebCallObserver@@
.?AVCAutoLoginTip@@
.?AV?$MemberFunctionRunner@VCLoginBanner@@@Thread@KwLib@@
.?AVCLoginBanner@@
.?AVCLoginDlg@@
.?AVCLoginDlgEx@@
.?AVCThirdPartLoginDlg@@
.?AV?$holder@W4HTTP_ERROR_RESON@@@Variant@KwLib@@
.?AVIHttpObserver@@
.?AW4HTTP_ERROR_RESON@@
.?AVCFunctionCrtCreator@@
.?AVCSearchCmd@@
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.4148" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
kwService.exe
IESandBox.exe_968:
.text
`.rdata
@.data
.rsrc
>%uEV
FTPh
.TxN;Xx
kernel32.dll
HKEY_CURRENT_CONFIG
HKEY_DYN_DATA
HKEY_PERFORMANCE_DATA
HKEY_USERS
HKEY_LOCAL_MACHINE
HKEY_CURRENT_USER
HKEY_CLASSES_ROOT
KWIEHost.txt
%s,%d
case CALL_NAVIGATE %s
Advapi32.dll
RegDeleteKeyExA
Miss Call:%s
WEBLOG
Navigate:%s
SetParent time = %d
SetWindowPos %s time = %d
kwjserror.html
document.write("1111111111111111111111111111111111111111111111111")JSSupportRet:%u
JSSupportRet ErrorCode:%u
NOSUPPORTJS
Unable to load MediaInfo.dll
KERNEL32.DLL
GetSystemWindowsDirectoryA
GetProcessHandleCount
DBGHELP.DLL
USER32.DLL
PSAPI.DLL
Wtsapi32.dll
ADVAPI32.DLL
%s\ddddddd_%s%s%s.exception
%s\ddddddd_%s%s%s.dmp
void, Value: X
char, len: %d, value(s):
short, len: %d, value(s):
int, len: %d, value(s):
WORD, len: %d, value(s):
unsigned int, len: %d, value(s):
float, Value: %f
btFloat, len (bytes): %d, value(s):
long, len: %d, value(s):
unsigned long, len: %d, value(s):
\2014\KwResource\bin\release\pdb\IESandBox.pdb
KERNEL32.dll
MsgWaitForMultipleObjects
USER32.dll
GDI32.dll
RegDeleteKeyA
RegCloseKey
RegQueryInfoKeyA
RegEnumKeyExA
RegOpenKeyExA
RegCreateKeyExA
ADVAPI32.dll
ole32.dll
OLEAUT32.dll
COMCTL32.dll
MSVCP90.dll
?ReadString@REG@KwLib@@YA_NPAUHKEY__@@PBD1QADI@Z
KwLib.dll
ccenter.dll
?LogClientErrorMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@000@Z
?LogInit@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
?LogUserActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0PBD_N@Z
KwLog.dll
KwModConfig.dll
MSVCR90.dll
_amsg_exit
_acmdln
_crt_debugger_hook
WININET.dll
GetProcessHeap
.?AVCMsgCenter@@
.?AV?$_IDispEventLocator@$0NAC@$1?DIID_DWebBrowserEvents2@@3U_GUID@@B@ATL@@
.?AV?$IDispEventSimpleImpl@$0NAC@V?$WBEventImpl@VCKwNdHtmlView@@@KwNdWB@@$1?DIID_DWebBrowserEvents2@@3U_GUID@@B@ATL@@
.?AV?$IDispEventImpl@$0NAC@V?$WBEventImpl@VCKwNdHtmlView@@@KwNdWB@@$1?DIID_DWebBrowserEvents2@@3U_GUID@@B$1?LIBID_SHDocVw@@3U4@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AVIWebCallMusic@@
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.4148" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
KwService.exe_1620:
.text
`.rdata
@.data
.rsrc
FTPhT
.Tx[KUx
dyt.exe
TargetExe1
TargetExe2
\StringFileInfo\XX\FileVersion
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PPStream
PPStream.exe
%s\%s
3,1,0,1060
NCHECK:%d|DYTRUN:%d|TACTICS:%d|MODPERC:%d|MODRET:%d|ALLOWPPS:%d|PARAM:%s|HASPPS:%d|PPSVER:%d|PPSRUN:%d|STARTPPS:%d|DYTPATH:%s|PPSFUN:1
MUSIC_7.2.0.7_BCS98
MUSIC_7.2.0.7_BCS97
PPSKernel.exe
PlayerCore.dll
Unable to load MediaInfo.dll
KERNEL32.DLL
GetSystemWindowsDirectoryA
GetProcessHandleCount
DBGHELP.DLL
USER32.DLL
PSAPI.DLL
Wtsapi32.dll
ADVAPI32.DLL
%s\ddddddd_%s%s%s.exception
%s\ddddddd_%s%s%s.dmp
void, Value: X
char, len: %d, value(s):
short, len: %d, value(s):
int, len: %d, value(s):
WORD, len: %d, value(s):
unsigned int, len: %d, value(s):
float, Value: %f
btFloat, len (bytes): %d, value(s):
long, len: %d, value(s):
unsigned long, len: %d, value(s):
\2014\KwResource\bin\release\pdb\KwService.pdb
KERNEL32.dll
USER32.dll
RegOpenKeyExA
RegCloseKey
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
OLEAUT32.dll
KwDataDef.dll
MSVCP90.dll
?ReadString@REG@KwLib@@YA_NPAUHKEY__@@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@1AAV45@@Z
KwLib.dll
SetSysMsgWnd
pd.dll
KwMV.dll
ccenter.dll
KwModConfig.dll
?LogClientErrorMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@000@Z
?LogUserActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0PBD_N@Z
KwLog.dll
InitKwHttpMgr
UninitKwHttpMgr
KwHttp.dll
VERSION.dll
IMM32.dll
SHLWAPI.dll
MSVCR90.dll
_amsg_exit
_acmdln
_crt_debugger_hook
.?AVCMsgCenter@@
.?AVCServiceMsgCenter@@
%Program Files%\kuwo\kuwomusic\bin
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.4148" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
KwService.exe_1620_rwx_01B71000_0009E000:
%UUUU
!!&((())%%%"
T?:%U?
o?.Vo?N
b?/%c?{Sc?4>.}6>/#8>
q.CUN3C
2FL?~\3F
$.Gk7.G
SG;%SG
MSG;bSG
%dGc:dG
iGM.iG%CiG
.zG&DzG]YzG
((-111..***())/113// (
y?zEo?.bd?
*{?.cu23456789:;
2345678
Warning: dropped %u input bytes
AudioCoding.com MPEG-4 General Audio player
MPEG-4 Files (*.MP4)
AAC Files (*.AAC)
%d/%d
%d BPM
%s AAC %s%s, %d sec, %d kbps, %d Hz
MP4 Files (*.mp4)
*.mp4
AudioCoding.com MPEG-4 General Audio player 2.1 beta compiled on Jul 9 2004.
Visit the website for more info.
Copyright 2002-2003 AudioCoding.com
Unsupported Audio track type.
mdia.minf.stbl.stsd.mp4a.esds.decConfigDescr.avgBitrate
Number of channels not supported for playback.
AudioCoding.com MPEG-4 General Audio player: 2.1 beta compiled on Jul 9 2004
mdia.minf.stbl.stsd.*.esds.decConfigDescr.avgBitrate
mdia.minf.stbl.stsd.*.width
mdia.minf.stbl.stsd.*.height
a=mpeg4-iod: "data:application/mpeg4-iod;base64,%s"
.PAVMP4Error@@
%s, %.3f secs, %u kbps, %u Hz
%s, %.3f secs, %u kbps, %ux%u @ %.2f fps
Payload %s for track %u
moov.mvhd.modificationTime
moov.trak[%u]
trak.tkhd.trackId
trak.mdia.hdlr.handlerType
moov.mvhd.timeScale
moov.mvhd.duration
Dumping %s meta-information...
operation not permitted in read mode
no such property - %s
type mismatch - property %s type %d
no such property %s
type mismatch - property %s - type %d
trak.mdia.mdhd.timeScale
tkhd.flags
moov.iods.esIds
esIds[%u].id
tref.mpod
%s.%s
entries.trackId
mdia.minf.dinf.dref
dref.entryCount
url .location
mdia.minf
mdia.minf.stbl.stsd
mdia.minf.stbl.stsd.entryCount
mdia.minf.stbl.stsd.mp4s.esds.ESID
mdia.minf.stbl.stsd.mp4s.esds.decConfigDescr.objectTypeId
mdia.minf.stbl.stsd.mp4s.esds.decConfigDescr.streamType
tkhd.volume
mdia.minf.stbl.stsd.mp4a.timeScale
mdia.minf.stbl.stsd.mp4a.esds.ESID
mdia.minf.stbl.stsd.mp4a.esds.decConfigDescr.objectTypeId
mdia.minf.stbl.stsd.mp4a.esds.decConfigDescr.streamType
tkhd.width
tkhd.height
mdia.minf.stbl.stsd.mp4v.width
mdia.minf.stbl.stsd.mp4v.height
mdia.minf.stbl.stsd.mp4v.esds.ESID
mdia.minf.stbl.stsd.mp4v.esds.decConfigDescr.objectTypeId
mdia.minf.stbl.stsd.mp4v.esds.decConfigDescr.streamType
mdia.minf.stbl.stsz.sampleSize
mdia.minf.stbl.stsd.rtp .tims.timeScale
tref.hint
udta.hnti.sdp
udta.hinf
moov.mvhd.nextTrackId
Track index doesn't exist - track %d type %s
Track id %d doesn't exist
moov.trak[%u].%s
moov.iods.ODProfileLevelId
moov.iods.sceneProfileLevelId
moov.iods.visualProfileLevelId
moov.iods.audioProfileLevelId
moov.iods.graphicsProfileLevelId
moov.udta.hnti.rtp .sdpText
udta.hnti.rtp
mdia.mdhd.timeScale
mdia.mdhd.duration
mdia.minf.stbl.stsd.*.esds.decConfigDescr.objectTypeId
mdia.minf.stbl.stsd.*[0].esds.decConfigDescr.decSpecificInfo[0].info
mdia.minf.stbl.stsd.*[0].esds.decConfigDescr.decSpecificInfo
decSpecificInfo[0].info
udta.hnti.sdp .sdpText
trak.udta.hinf.payt.payloadNumber
AllocRtpPayloadNumber
%s.edts.elst.entries[%u].%s
edts.elst.entryCount
<%u bytes>
IOD SDP = %s
moov.iods
URLFlag
data:application/mpeg4-od-au;base64,%s
OD data URL = "%s"
mdia.minf.stbl.stsd.mp4s.esds.decConfigDescr
decConfigDescr.bufferSizeDB
slConfigDescr.predefined
data:application/mpeg4-bifs-au;base64,%s
Scene data URL = "%s"
decConfigDescr.objectTypeId
decConfigDescr.streamType
decConfigDescr.maxBitrate
decConfigDescr.avgBitrate
decConfigDescr.decSpecificInfo
slConfig.useAccessUnitEndFlag
mdia.minf.stbl.stsd.*.esds
slConfigDescr.useAccessUnitEndFlag
moov.udta.meta.ilst.*[%u].data.metadata
moov.udta.meta.ilst.*[%u]
moov.udta.meta.ilst.*[%u].name.metadata
udta.meta.ilst.%s.data
moov.udta.meta.ilst.%s.data
moov.udta.meta.hdlr
hdlr.handlerType
hdlr.reserved2
moov.udta.meta.ilst.
nam.data
data.metadata
nam.data.metadata
wrt.data
wrt.data.metadata
alb.data
alb.data.metadata
ART.data
ART.data.metadata
too.data
too.data.metadata
cmt.data
cmt.data.metadata
day.data
day.data.metadata
moov.udta.meta.ilst.trkn.data
moov.udta.meta.ilst.trkn.data.metadata
moov.udta.meta.ilst.disk.data
moov.udta.meta.ilst.disk.data.metadata
Opera
moov.udta.meta.ilst.gnre.data
gen.data
moov.udta.meta.ilst.gnre
moov.udta.meta.ilst.gnre.data.metadata
gen.data.metadata
moov.udta.meta.ilst.tmpo.data
moov.udta.meta.ilst.tmpo.data.metadata
moov.udta.meta.ilst.cpil.data
moov.udta.meta.ilst.cpil.data.metadata
moov.udta.meta.ilst.covr.data
moov.udta.meta.ilst.covr.data.metadata
moov.udta.meta.ilst.----[%u].name
name.metadata
moov.udta.meta.ilst.----[%u].data.metadata
udta.meta.ilst.----[%u]
moov.udta.meta.ilst.----[%u].data
moov.udta.meta.ilst.----[%u].mean
mean.metadata
com.apple.iTunes
moov.udta.meta
Length is %d
ReadAtom: type = %s data-size = %I64u (0x%I64x)
Warning: atom type %s is suspect
Info: atom type %s is unknown
Warning: %s atom size %I64u is suspect
FindAtom: matched %s
FindProperty: matched %s
FindProperty: no match for %s
ReadProperties: insufficient data for property: %s pos 0x%I64x atom end 0x%I64x
ReadChildAtoms: of %s
Warning: In atom %s unexpected child atom %s
Warning: In atom %s multiple child atoms %s
Warning: In atom %s missing child atom %s
ReadChildAtoms: finished %s
Write: type %s
Write: finished %s
type %s
%s = %u (0xx)
%s = %u (0xx)
%s = %u (0xx)
%s = %u (0xx)
%s = %I64u (0x6I64x)
%s = %I64u (0x%0*I64x) <%u bits>
%s = %f
%s = %ls
%s = %s
%s = <%u bytes>
Warning: Mandatory descriptor 0xx missing
Warning: Descriptor 0xx has more than one instance
trak.tkhd.duration
trak.mdia.mdhd.duration
trak.tkhd.modificationTime
trak.mdia.mdhd.modificationTime
trak.mdia.minf.stbl.stsz.sampleSize
trak.mdia.minf.stbl.stsz.sampleCount
trak.mdia.minf.stbl.stsz.entries.sampleSize
trak.mdia.minf.stbl.stsc.entryCount
trak.mdia.minf.stbl.stsc.entries.firstChunk
trak.mdia.minf.stbl.stsc.entries.samplesPerChunk
trak.mdia.minf.stbl.stsc.entries.sampleDescriptionIndex
trak.mdia.minf.stbl.stsc.entries.firstSample
trak.mdia.minf.stbl.stco.entryCount
trak.mdia.minf.stbl.stco.entries.chunkOffset
trak.mdia.minf.stbl.co64.entryCount
trak.mdia.minf.stbl.co64.entries.chunkOffset
trak.mdia.minf.stbl.stts.entryCount
trak.mdia.minf.stbl.stts.entries.sampleCount
trak.mdia.minf.stbl.stts.entries.sampleDelta
trak.mdia.minf.stbl.ctts.entryCount
trak.mdia.minf.stbl.ctts.entries.sampleCount
trak.mdia.minf.stbl.ctts.entries.sampleOffset
trak.mdia.minf.stbl.stss.entryCount
trak.mdia.minf.stbl.stss.entries.sampleNumber
ReadSample: track %u id %u offset 0x%I64x size %u (0x%x)
ReadSample: isSyncSample %u
WriteSample: track %u id %u size %u (0x%x)
WriteChunk: track %u offset 0x%I64x size %u (0x%x) numSamples %u
trak.mdia.minf.stbl.stsd.*.esds.decConfigDescr.bufferSizeDB
trak.mdia.minf.stbl.stsd.*.esds.decConfigDescr.maxBitrate
trak.mdia.minf.stbl.stsd.*.esds.decConfigDescr.avgBitrate
trak.mdia.minf.stbl.stsd
*.dataReferenceIndex
trak.mdia.minf.dinf.dref
*.location
dref url = %s
Warning: Zero sample duration, stts entry %u
trak.mdia.minf.stbl
ctts.entryCount
ctts.entries.sampleCount
ctts.entries.sampleOffset
stss.entryCount
stss.entries.sampleNumber
ReadChunk: track %u id %u offset 0x%I64x size %u (0x%x)
RewriteChunk: track %u id %u offset 0x%I64x size %u (0x%x)
trak.edts.elst
elst.entryCount
elst.entries.mediaTime
elst.entries.segmentDuration
elst.entries.mediaRate
elst.entries.reserved
edts.elst
trak.edts
GetSampleIdFromEditTime: when %llu sampleId %u start %llu duration %lld
trak.tref.hint.entries[0].trackId
trak.udta.hnti.rtp .snro.offset
trak.udta.hnti.rtp .tsro.offset
ReadPacket: %u
udta.hnti.rtp .tsro
trak.udta.hinf.payt.rtpMap
trak.mdia.minf.stbl.stsd.rtp .maxPacketSize
%s/%u%c%s
m=%s 0 RTP/AVP %u
a=control:trackID=%u
a=rtpmap:%u %s
a=mpeg4-esid:%u
trak.udta.hnti.sdp .sdpText
trak.udta.hinf
hinf.trpy.bytes
hinf.nump.packets
hinf.tpyl.bytes
hinf.maxr.bytes
hinf.dmed.bytes
hinf.dimm.bytes
hinf.pmax.bytes
hinf.dmax.milliSecs
trak.mdia.minf.hmhd
hmhd.maxPduSize
hmhd.avgPduSize
hmhd.maxBitRate
hmhd.avgBitRate
hinf.maxr.granularity
RtpPacket: %u
RtpData: %u
trak.tref.hint.entries
trak.mdia.minf.stbl.stsd.*[%u]
ReadDescriptor: tag 0xx data size %u (0x%x)
Overran descriptor, tag %u data size %u property %u
key-indicator-length
keywordCount
keywords
%Program Files%\kuwo\kuwomusic\bin\KwService.ini
1">"?">">">
1">"?"=4
2"="="="="="=
#!<9!=!=!=!
.text
`.rdata
@.data
.rsrc
@.reloc
You can convert this file to MP4 if you like. This does not involve re-encoding, only the container format is changed. Advantages of MP4 files are that they are playable by a lot more players and they will have a lot of support in the future.
KwWallpaper.exe_2876:
.text
`.rdata
@.data
.rsrc
@.reloc
[HxyYIx.SHx
KERNEL32.DLL
GetSystemWindowsDirectoryA
GetProcessHandleCount
DBGHELP.DLL
USER32.DLL
PSAPI.DLL
Wtsapi32.dll
ADVAPI32.DLL
%s\ddddddd_%s%s%s.exception
%s\ddddddd_%s%s%s.dmp
Time of Exception: d:d:d.d %d/%d/%d (D/M/Y)
Exception Code: 0xX
Access Violation Address: 0xX
Exception Address Details: 0xX [%hs]:0xX %s
Exception Address Details: 0xX [UNKNOWN]
Process Path: %s
Current Directory: %s
Command Line: %s
Process ID: %u
Thread ID where exception has occurred: 0xX
Failed to initialize Debug Help Library, Error:%d
Failed in call to CreateToolhelp32Snapshot, Error:%d
Computer Name: %s
User Name: %s
Number of Processors: %d
Page size: %d bytes
Lowest Memory Address: 0xX
Highest Memory Address: 0xX
Memory Load: %d
Physical Memory: %d Kbytes
Physical Memory (available): %d Kbytes
Page File: %d Kbytes
Page File (available): %d Kbytes
Virtual Memory: %d Kbytes
Virtual Memory (available): %d Kbytes
Total number of pages commited by the system: %d
Current maximum number of page commits that can be performed by the system: %d
Maximum number of page commit totals that have occured since last reboot: %d
Total amount of physical memory, in pages: %d
Total amount of physical memory available to user processes, in pages: %d
Total amount of system cache memory, in pages: %d
Total amount of the sum of paged and nonpaged kernel pools, in pages: %d
Total amount of paged kernel memory pool, in pages: %d
Total amount of nonpaged kernel pool, in pages: %d
Page Size: %u bytes
Total number of open handles: %u
Total number of processes: %u
Total number of threads: %u
Page Faults: %u
Peak Working Set Size: %d Kbytes
Working Set Size: %d Kbytes
Peak Paged pool usage: %d Kbytes
Paged pool usage: %d Kbytes
Peak Non-paged pool usage: %d Kbytes
Non-paged pool usage: %d Kbytes
Peak Pagefile usage: %d Kbytes
Pagefile usage: %d Kbytes
Private usage: %d Kbytes
GDI Objects %u
USER Objects %u
User32.dll is not loaded, not bothering to report GUI resource usage
Handle Count: %u
Windows 95
Windows 98
Windows ME
Windows 2000 Domain Controller
Windows 2000 Server
Windows 2000 Professional
Windows Server 2003 R2 Domain Controller
Windows Server 2003 Domain Controller
Windows Server 2003 R2
Windows Server 2003
Windows XP
Windows Server "Longhorn" Domain Controller
Windows Server "Longhorn"
Windows Vista
v%d.%d
Current Build: %d
Service Pack: %s
Web Edition,
SOFTWARE\Microsoft\Windows NT\CurrentVersion
Registered Organisation: %s
Registered Owner: %s
Unknown Windows version
Floating-point operations are emulated using software
The Atomic Compare and Exchange operation (cmpxchg) is available
The Atomic Compare and Exchange operation cmpxchg) is not available
The Atomic Compare and Exchange 128-bit operation (cmpxchg16b) is available
The Atomic Compare and Exchange 128-bit operation (cmpxchg16b) is not available
The Atomic Compare 64 and Exchange 128-bit operation (cmp8xchg16b) is available
Data execution prevention (DEP) is not enabled
The Atomic Compare 64 and Exchange 128-bit operation (cmp8xchg16) is not available
Floating-point operations are implemented using hardware
Data execution prevention (DEP) is enabled
Native Number of Processors: %d
Native Page size: %d bytes
Native Lowest Memory Address: X
Native Highest Memory Address: X
Wow64 System Directory:%s
Session ID: %u
Published application name: %s
Family: %u, Address:
Client build number: %u
Client Directory: %s
Client display width: %u
Client display height: %u
Client color depth: Unknown, numeric value:%u
Client HardwareId: %u
Client Name: %s
Client product identifier: %d
Client protocol type: Unknown, numeric value:%d
Domain name: %s
User name: %s
Windows Station: %s
Working Directory: %s
Windows Directory: %s
Windows Directory: [UNKNOWN]
System Directory: %s
Shared Windows Directory: %s
Shared Windows Directory: [UNKNOWN]
Monitors: %d
Virtual Screen %d, %d, %d, %d
Active Display (Bits per Pixel): %d
Active Display (Width): %d
Active Display (Height): %d
Active Display (Refresh Rate): %d
Mouse Buttons: %d
Profile Guid: %s
Profile Name: %s
ANSI Code Page: %d
OEM Code Page: %d
User Default Lang ID: %d
System Default Lang ID: %d
User Default Locale ID: %d
System Default Locale ID: %d
Name: %s
Process ID: %d
Threads: %d
Reference Count: %d
Parent Process ID: %d
Base Priority: %d
Failed in call to Process32First, Error:%d
File Version: %d.%d.%d.%d
Path: %s
Global Usage Count: %d
Process Usage Count: %d
HMODULE: 0xX
Size: %d
Failed in call to Module32First, Error:%d
EAX X
EBX X
ECX X
EDX X
ESI X
EDI X
CS:EIP X:X
SS:ESP X:X
EBP X
DS X
ES X
FS X
GS X
Flags X
Thread ID: 0xX
Priority Level: %d
Delta Priority: %d
References: %d
Creation Time: d:d:d.d %d/%d/%d (D/M/Y)
Failed in call to Thread32First, Error:%d
0xX [%hs]:0xX %s
0xX [UNKNOWN]
%hs 0xX
%hs line %u
Frame Pointer: 0xX
Unable to get base address of the memory at 0xX
Unable to get read access to memory, Address: 0xX, Base Address: 0xX, Size: %d, Error:%d
0xX
void, Value: X
char, len: %d, value(s):
short, len: %d, value(s):
int, len: %d, value(s):
WORD, len: %d, value(s):
unsigned int, len: %d, value(s):
float, Value: %f
btFloat, len (bytes): %d, value(s):
long, len: %d, value(s):
unsigned long, len: %d, value(s):
Wallpaper.log
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
REG::WriteString return %d: %s\%s=%s
REG::DeleteKey return %d: %s\%s
User32.dll
\KwWallpaperOpWnd.xml
%s-%s
<Button name="guid_close" width="19" height="20" float="true" pos="-24,10,-5,30" statusimage="tipclose.png" setcursor="true"/>
%s: DOWNLOAD STATUSINFO={date=hdhdhd, ec=%d, pos=%d, count=%d%s: %s DONE
%s: ShellExecuteEx FAILED with lpFile=%s, lpParameters=%s
method=%s&type=%s&onOff=%d&takeEffect=%d&saveConf=%d&cookie=%s
play/?play=%s&num=%s&musicrid0=%s&name0=%s&artist0=%s&album0=%s&mkvrid0=%s&hasecho0=%s&mkvnsig10=%s&mkvnsig20=%s
ServerPort
ProblemReport
AdvSkinUrl
SkinConfUrl
AutoSkinConfUrl
StartPageConfUrl
LyricBkConfUrl
AlbumPicConfUrl
NewSkinUrl
SoundSkinConfUrl
DontRemPass
UserLoginType
IsThirdLogin
ThirdLoginImage
ThirdLoginName
newlogin
webupdatesvr
webskinsvr
webregistersvr2012
HTTPProxyUsed
HTTPProxyHost
HTTPProxyPort
HTTPProxyUser
HTTPProxyPass
HotKey
UserHotkey
hXXp://artistpicserver.kuwo.cn
StartPageConfUrlWP
/pic.web?type=startup_pic
&date=ddd
width=%d&height=%d
%s: %s
%s: FAILED OpenSession(%s)
JSON parse failed: %s
JSON formate error, no result: %s
wp.ini
desktopTip.xml
\KwMusic.exe
has_msg
DESKTOPTIP:MSGCLICK
kernel32.dll
\kuwodata\kwmusic2013\Conf\user\config.ini
\KwMusic.exe"
%s: JSON parse failed: %s
hXXp://
1179873086
1762481905
%s: MakeDir(%s) FAILED
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
ASC:0|EPOS:%d|UAC:1|MST:%d
kwmusic.exe
ASC:1|EPOS:%d|UAC:0|MST:%d
WriteMbox.exe
ASC:0|EPOS:%d|UAC:0|MST:%d
desktopInfoWnd.xml
webstub
hXXp://topmusic.kuwo.cn/today_recommend/mbox2013/qj/dydq.htm
showwindowex?width=%d&height=%d
DESKTOPTIP:URLFAILED|RETRYCOUNT:%d
MediaInfo.dll
Unable to load MediaInfo.dll
\2014\KwResource\bin\release\pdb\KwWallpaper.pdb
KERNEL32.dll
USER32.dll
RegOpenKeyExA
RegCloseKey
ADVAPI32.dll
ShellExecuteExA
SHELL32.dll
ole32.dll
OLEAUT32.dll
GdiplusShutdown
gdiplus.dll
MSVCP90.dll
?ReadString@REG@KwLib@@YA_NPAUHKEY__@@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@1AAV45@@Z
?Decode@UrlEncode@KwLib@@YAHABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAV34@@Z
?WriteString@REG@KwLib@@YA_NPAUHKEY__@@PBD11@Z
?DeleteKey@REG@KwLib@@YA_NPAUHKEY__@@PBD1@Z
KwLib.dll
?LogUserActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0PBD_N@Z
?MakeHttpParam@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ABV12@H@Z
?LogFeatureMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z
?LogABActMsg@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PBD@Z
?LogInit@@YAXABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z
KwLog.dll
KwDataDef.dll
DuiLib.dll
AfxGetHttpRequestMgr
KwHttpRequestMgr.dll
GetKwHttpMgr
InitKwHttpMgr
UninitKwHttpMgr
KwHttp.dll
KwModConfig.dll
MSVCR90.dll
_amsg_exit
_acmdln
_crt_debugger_hook
KwMusicCore.dll
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.30729.4148" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
3=3W3_3h3r3
.opt.jpg
KwLnkTipWnd.exe_3024:
.text
`.rdata
@.data
.rsrc
@.reloc
L$ SSh
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
operator
GetProcessWindowStation
USER32.DLL
kernel32.dll
\kuwodata\kwmusic2013\Conf\user\config.ini
\KwMusic.exe /itwrun
BkImage.png
CloseBtn.png
EnterBtn.png
\Release\KwLnkTipWnd.pdb
KERNEL32.dll
GetKeyState
USER32.dll
GDI32.dll
ADVAPI32.dll
SHELL32.dll
gdiplus.dll
COMCTL32.dll
GetCPInfo
zcÁ
%Program Files%\kuwo\kuwomusic\bin\KwLnkTipWnd.exe
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
5*6064686<6
=$=*=3=:=\=
mscoree.dll
KERNEL32.DLL
Remove it with Ad-Aware
- Click (here) to download and install Ad-Aware Free Antivirus.
- Update the definition files.
- Run a full scan of your computer.
Manual removal*
- Scan a system with an anti-rootkit tool.
- Terminate malicious process(es) (How to End a Process With the Task Manager):
9EPostService.exe:1816
9EPostService.exe:1088
unstall.exe:2016
WriteMbox.exe:2364
%original file name%.exe:1416
kuwo_jm429.exe:1072
KwWallpaper.exe:2876
taskkill.exe:832
taskkill.exe:1968
taskkill.exe:1852
taskkill.exe:2012
taskkill.exe:424
taskkill.exe:1368
taskkill.exe:912
SoftWare SVC.exe:1096
SoftWare SVC.exe:136
regsvr32.exe:1324
regsvr32.exe:1556
regsvr32.exe:1612
regsvr32.exe:648
regsvr32.exe:364
regsvr32.exe:516
regsvr32.exe:912
KwLnkTipWnd.exe:3024
BrowserSafe.exe:1712
kwAdb.exe:3376
kwAdb.exe:3448
KwMusic.exe:1292
Netsh.exe:340
Netsh.exe:1252
KwConfig.exe:412 - Delete the original Trojan file.
- Delete or disinfect the following files created/modified by the Trojan:
%Documents and Settings%\%current user%\Local Settings\Temp\nsk11.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns8.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.sys (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsA.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsB.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\System.dll (11 bytes)
%Program Files%\9ENetwork\Uninst.bat (25 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns6.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EUninst.bat (82 bytes)
%WinDir%\SoftWare SVC.exe (11893 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Md5dll.dll (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsExec.dll (6 bytes)
%Program Files%\9ENetwork\9EPostService.exe (9451 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\unstall.exe (621 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\nsm7.tmp (388 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EÈüþ°²×°ÓÅ»¯.bat (233 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns9.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\BrowserSafe.exe (1499 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns4.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\Version.dll (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\9EService.bat (116 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns5.tmp (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\kuwo_jm429.exe (416230 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsk2.tmp\ns3.tmp (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RecoTipDialog.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\tta.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\conf.ini (107 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DeskLyric.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwMusic.xml (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistRootPanel.xml (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\DOWNLOAD_ARTISTPIC\49FF334D.dat (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\wav.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\loading.gif (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\Encode.exe (784 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\öÃâ€ÃƒËœÃ‚¿Ã¡ÃŽÃ’ÒôÀÖ.lnk (599 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModMusicTool\conf.txt (713 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\fullplaycontrol.xml (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\DownloadUpdate.exe (6360 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\Base64.dll (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_COLOR_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_PIC_nomal.jpg (871 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WpAbmTip_Start.xml (570 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\conf.ini (113 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwService.exe (1856 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_4a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WpAbmTip_Close.xml (556 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\FirstPlayApeWnd.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ShutDownTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PathListDialog.xml (688 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ac3.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\cda.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\Microsoft.VC90.CRT.manifest (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwEmptyWebDlg.xml (190 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_5a.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KwMusicNsis.dll (14184 bytes)
%Program Files%\kuwo\kuwomusic\bin\runshelldraw_x86.exe (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\userinfo2012.zip (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\DOWNLOAD_ARTISTPIC\1F628AB6.dat (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SaveLyricDeltaWnd.xml (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\desktop.ini (67 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserfaceWnd.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ShutDownSettingDialog.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModPlaylist.dll (23424 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwKickDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLnkTipWnd.exe (5064 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_COLOR_nomal.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_ac3.dll (19152 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwInfos.exe (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\netsong.zip (30464 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\KwDownloadLnk.ico (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\BindConfig.ini (213 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_4b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\dks.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwAndroidUsbCopy.xml (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\desk_compositor_x86.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\m4a.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_5b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\miniplaylist.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\MatroskaSplitter.ax (8560 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\instAD.dat (228 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad04.jpg (784 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\Internet Explorer\Quick Launch\¿áÎÒÒôÀÖ 2014.lnk (777 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModAppStore.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModAndroidMgr.dll (9608 bytes)
%Program Files%\kuwo\kuwomusic\bin\CoreAVC0.ax (6584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WallpaperTipWnd.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\Default.jpg (5520 bytes)
%Program Files%\kuwo\kuwomusic\1.txt (12 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\msvcr90.dll (22552 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModGameEntry.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwTagLib.dll (25824 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\conf.ini (105 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwRecoSong.dll (1552 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_3a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MultiLoginManager.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIAvMgr.dll (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\DuiLib.dll (25776 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ape.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\bk.jpg (3312 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\mylk.dat (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLyric.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\small.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad01.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\AdbWinUsbApi.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPlayControl.dll (7192 bytes)
C:\$Directory (976 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DownloadFinishTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DownloadSettingDialog.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwMinisiteDlg.xml (660 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwVipOpenPage.xml (590 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mp3.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperPlayerWnd.xml (534 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\changeautoskintimewnd.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\MediaInfo.dll (32824 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\lyricshow\LyricTheme.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\bk.jpg (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\WriteMbox.exe (9320 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_COLOR_nomal.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\cursor\hand-open.cur (766 bytes)
%Program Files%\kuwo\kuwomusic\bin\IEProxy.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\out_kw_ds.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\DshowPlayer.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\small.jpg (15 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpdateTipDialogEx.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\DumpReport.exe (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\5\small.jpg (9 bytes)
%Program Files%\kuwo\kuwomusic\bin\IESandBox.exe (13584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\TipDlg.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\Kuwo.QuickLaunch.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_mpg123.dll.manifest (406 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwWallpaper.exe (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwHttp.dll (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\mylkx.dat (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserFeedbackDlg.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\Microsoft.VC90.CRT.manifest (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\startpage.xml (244 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\conf.ini (91 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\EqDlgAttribute.xml (169 bytes)
%System%\config (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RealEggSmashDlg.xml (407 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\MP2.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\Eq_Kweq.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_3b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_2a.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_COLOR_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_2b.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\music[1].htm (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KuWoNsis_new.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModMusicTool\conf.txt (713 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIDeskLyric.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwRestoreBackList.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\CloseBtn.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperOpWnd.xml (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\userinfo2012.zip (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CopyNotifyDialog.xml (436 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicTree.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\System.dll (11 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\vipMbox_new.zip (15168 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpdateTipDialog.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\tyyykw.wav (26688 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AutoLoginTip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\msvcp90.dll (19152 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLib.dll (13368 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\nowbg.gif (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\kwjserror.html (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\BkImage.png (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SynExistListTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\MakeLrcWndRes\lrc_finish_icon.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Zlib.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwTaskbarNotifierDialog.xml (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\config.ini (10932 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad02.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ExitTipDialog.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Win7Trait.dll (13 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\logindlgex.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mp1.ico (784 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\¿áÎÒÒôÀÖ 2014.lnk (771 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwConfig.exe (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\lidx.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\lrcx.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\casullisten.pl (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwHttpRequestMgr.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ListBuddyWnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\hanzi_pinyin.dict (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModResource\NetSong-artists.pl (9608 bytes)
%WinDir%\KwYlx.dat (25 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\playlist.gif (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MuiscTreeInfoWnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_1a.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\KillProcDLL.dll (10 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModResource\NetSong-artists.pl (9608 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\skin.dat (33633 bytes)
%Program Files%\kuwo\kuwomusic\bin\CWmpPlayer.dll (23424 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\searchtip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\bk.jpg (3312 bytes)
%WinDir%\Prefetch\REGSVR32.EXE-25EEFE2F.pf (32 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMusicCore.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMV.dll (15536 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitSongDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\ReconEngine.exe (8184 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\LrcUploadFailTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\runshelldraw_x64.exe (3616 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Program Files%\kuwo\kuwomusic\bin\CKuwoPlayer.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\sharesong.zip (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPopupWnd.dll (12536 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwUserKick.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLyricShow.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\desk_compositor_x64.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwDataDef.dll (8184 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\desktopInfoWnd.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwPopupRbWebDlg.xml (190 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\setup.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwServiceProxy.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_1b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\msgbox.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\changeskinwnd.xml (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\lyricshow\LyricTheme.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIAndroidUsbDevice.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\Uninstall.exe (12494 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_4a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\flac.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_3a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\KwMusic.exe (19096 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_4b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModSkinManage.dll (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\1\small.jpg (7 bytes)
%Program Files%\kuwo\kuwomusic\readme.txt (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\iconTip.xml (277 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIVIPMan.dll (6360 bytes)
%Program Files%\kuwo\kuwomusic\bin\Vol.dll (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WebPopupDlg.xml (427 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicToolDown.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\6\bk.jpg (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\bk.jpg (1202 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwLog.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\serverskin\2\small.jpg (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MakeLyricDlg.xml (9 bytes)
%Program Files%\kuwo\kuwomusic\KwMusicSetup.exe (183968 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwUpdate.dll (4992 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwSongCache.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UpLyricDlg.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\UINowPlaying.dll (13368 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\KW_SEARCH_SONG\jay.dat (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_PIC_highlight.jpg (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\aac.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModLocalMusic.dll (7192 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\MusicTool.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\localskin\1\conf.ini (95 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\In_Wma.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CreateNewList.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\mvloading.swf (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\cue.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RemoteUserLoginAfter.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KWUpdate.exe (30344 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\OpenUploadLocal.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistRootPanel2.xml (784 bytes)
%Documents and Settings%\All Users\Start Menu\¿áÎÒÒôÀÖ 2014.lnk (759 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\BackToOldVer.xml (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\desktopTip.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\minierror.htm (798 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_3b.png (1 bytes)
%WinDir%\Prefetch\9EPOSTSERVICE.EXE-099C9721.pf (16 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIPlaylistPanel.dll (20624 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitMvDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\GameIcon.ico (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwWallpaperNcWnd.xml (449 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\WallpaperPreviewWnd.xml (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\PlayerCore.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\skin.xml (12 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\songcomment.zip (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\ShellDl.exe (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_2a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\PlaylistStyle3.xml (388 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\SimpleSC.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\vipMbox_new.zip (15168 bytes)
%Program Files%\kuwo\kuwomusic\bin\Module.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\wma.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\mvmodbar.xml (3 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014.lnk (765 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AlreadDownloadDialog.xml (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\instAD\ad03.jpg (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\pd.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\DeskLyricUnlock.xml (494 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\baidu.pl (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\ccenter.dll (5520 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIMusicTree.dll (2392 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\LrcUploadSuccTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KuwoSyncMobile.dll (1552 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\sharesong.zip (5 bytes)
%Program Files%\kuwo\kuwomusic\bin\MpaDecFilter.ax (30464 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\desktop.ini (159 bytes)
%Program Files%\kuwo\kuwomusic\bin\AdbWinApi.dll (3616 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwEqDlg.xml (7 bytes)
%WinDir%\Prefetch\SOFTWARE SVC.EXE-084F9A5B.pf (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_2b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\functionwnd.xml (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\KuwoDaemon.apk (1552 bytes)
%Program Files%\kuwo\kuwomusic\bin\msvcr90.dll (22552 bytes)
%Program Files%\kuwo\kuwomusic\bin\msvcp90.dll (19152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsxD.tmp (731729 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModDownload.dll (11048 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\SynLsTipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\Microsoft.VC90.CRT.manifest (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIMiniPanel.dll (5064 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\logindlg.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_APE.dll (62984 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_mp4.dll (9320 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\mvloading.html (888 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\CloudLoginBallon.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwVipWebDlg.xml (534 bytes)
%Program Files%\kuwo\kuwomusic\msvcp90.dll (21088 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\minidlg.xml (16 bytes)
%Program Files%\kuwo\kuwomusic\bin\kwAdb.exe (20416 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\DeskTipWndRes\EnterBtn.png (3 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\¿áÎÒÒôÀÖ 2014\Èüþ˵Ã÷.lnk (766 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\UserLoginGuide.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModUpdateWeb.dll (1856 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\ModifyLyricRelationWnd.xml (6 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwCloudCenterBox.xml (623 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ogg.ico (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\RemoteUserLoginBefore.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\mid.ico (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_PIC_highlight.jpg (1 bytes)
%Documents and Settings%\All Users\Desktop\¿áÎÒÒôÀÖ 2014.lnk (759 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModConfig.dll (2392 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_5a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\html\gameBoxLoading.htm (799 bytes)
%Program Files%\kuwo\kuwomusic\bin\UIDownload.dll (13584 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\nsisSlideshowx.dll (2392 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_1a.png (1 bytes)
%Program Files%\kuwo\kuwomusic\msvcr90.dll (26424 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\DeskLyric\DL_Themes_1b.png (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwLimitVipDlg.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\Conf\default\config.ini (7637 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\KWMUSIC\DownloadUpdate.ini (120 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KwConfig.xml (3312 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwModSynList.dll (6584 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\cursor\hand-close.cur (766 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\songcomment.zip (784 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\KeywordSafeTip.xml (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\res\icons\ThumbnailToolbar.bmp (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\Kwwebpopup.xml (417 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_Themes_5b.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\w7tbp.dll (9 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\Res\cache\KW_SEARCH_SONG\jay.dat (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\DeskLyric\DL_PIC_nomal.jpg (871 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\forcechangeskinwnd.xml (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwDPGame.exe (8560 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsmE.tmp\inetc.dll (784 bytes)
%Program Files%\kuwo\kuwomusic\KWMUSIC\ModuleData\ModWebUpdate\zip\netsong.zip (30464 bytes)
%Program Files%\kuwo\kuwomusic\bin\KwMusic.exe (54196 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\base\AutoRunShowTipWnd.xml (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473321334926.jpg (1921 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\wp.ini (1 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473518690014.jpg (353 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473516821210.jpg (1725 bytes)
%Program Files%\kuwo\kuwomusic\bin\Log\act.log (767 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473519658028.jpg (353 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473320578232.jpg (549 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473055636025.jpg (2078 bytes)
%Program Files%\kuwo\kuwomusic\bin\skin\startpage\wallpaper\1473517759929.jpg (1098 bytes)
C:\KwDownload\Temp\F53A522FF938F1F4.zip (64019 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\kmap\F53A522FF938F1F4.kmap (172 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\p2pconf\index\update.txt (536 bytes)
%WinDir%\WMSysPr9.prx (316 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\adb.log (38 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\date.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topnav.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\zone.js (33 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listenicon2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask5.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_fc.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mv_btn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\error.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqtongming.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan10.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\small.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike1.gif (462 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ieerror.jpg (15 bytes)
%Program Files%\COMMON FILES (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\concertbanner.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\close.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan4.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\prev.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\rplay_h.gif (9 bytes)
%System%\Macromed\Flash (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scon.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fankui.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\commdemo.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\navbg.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\Thumbs.db (745 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addlist.png (1 bytes)
%WinDir%\Temp\Perflib_Perfdata_678.dat (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\line.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listbgt2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_btn.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¾Âµ仳¾Éµç̨ -4459_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\playlist.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\80ºóµç̨ -4953_0.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\big.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tcjdt.png (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiushi.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollmiddle.png (957 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjsuggest.gif (222 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\local2014.js (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\dax.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\dax.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\33606748.dat (4037 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-80ºóµç̨ -4953.pl.temp (155 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_9.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\anow.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sright.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_4.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjnew1.gif (613 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tcjdt.png (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbghover.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\originalcom.js (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navbg.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\closed.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\MV2.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\albumpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\paoBg.png (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic2.jpg (22 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\ape.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_btn2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_2.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\bangpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addgedan.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\jiazai.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask2.png (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_3.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\prev_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbg.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\next_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hdpic.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading22.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\É˸õç̨ -6003_0.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\message.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\em.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\play_z.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shou2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fousplay.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\topic.css (23 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\yindao.png (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\topic.css (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan6.png (165 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\Radio.zip (1882 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\em.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightnavnow.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\otherbtn.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\radio\radio.conf (15168 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan5.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dragarrow.png (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\abg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_radio.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiuchang.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\icon1.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\alBg.gif (61 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\icon.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwo.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan4.png (126 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hot2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan1.png (137 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\high.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Thumbs.db (5064 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zone2.js (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\searchnoresult.js (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\icon.png (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\4FDFB85C.dat (3317 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\navbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplay.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bz_vip.gif (366 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\diantai_play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbtn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_play.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\singer.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\jxj.js (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_13.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\download.css (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_tit_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\bangpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\kuwobox.png (2 bytes)
%Documents and Settings%\%current user%\My Documents (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphobottom.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiuchang.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zone2page.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_2.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedan.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\two.css (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scon.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\Btn.png (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\no_copyright.txt (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\init.html (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan8.png (344 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btntop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more4.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\big.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightIcon.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\artist.js (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\tree.js (3712 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gotop.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pageH.png (1864 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqplayhover.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\close.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\close.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipno.jpg (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\tequanInfo.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sright.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\singer.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\topic.css (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\024C3854.dat (88 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\61D38DD6.dat (3026 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\topic.js (40 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zonegedan.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\wireshark.txt (5481 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\play.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_1.jpg (22 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pic160bg2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\playlist.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\jianjie.html (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_omxe.dll (7726 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\one.css (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_bang.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\cookie.js (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songerdiantai.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\hsot_xuan.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\music1.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\abg2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonegedanpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\album_img.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\music.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnmiddle.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\search.js (6624 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\gedan.js (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addlist.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan8.png (172 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\icon.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\vipNoTitle_2012-10.css (23 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonemvgedan.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\left_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dragarrow.png (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zonegedan.js (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading2.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\feedback.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask1.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\music2.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\version.ini (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tanbtn.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask5.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon1.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\feedback.jpg (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listenicon.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\diantai_playH.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\local2014.js (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading1.gif (49 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addgedanhov.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hot.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\download.css (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\right_j.jpg (520 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\class.gif (357 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\init.html (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\album.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\low.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\index.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone.css (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModMusicTool\ksong.ini (126 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\init.html (290 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\yindao.png (794 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbghover.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_8.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\lanmu_img.jpg (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplayHover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topic_play_jx.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\low.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\gedanpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipno.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum1.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newpho.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fankui.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\bodyBg.jpg (7 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.9.0.Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_x-ww_9e7eb501 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbtnhover.png (1 bytes)
%Documents and Settings%\%current user%\Cookies\[email protected][1].txt (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\otherbtn.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalpage.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading3.gif (98 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996_0.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan3.png (290 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjnew1.gif (613 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newpho.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\1AF9CC01.dat (3039 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\jquery.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\mvlistbg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\zone2.css (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\mvlistbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqplayhover.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_9.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zone.js (33 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucanggray.gif (1810 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\adx.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_12.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-»ªÓïºÃ¸èµç̨ -19625.pl.temp (153 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\dhj.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_no.gif (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\prev.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchnoresult.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\onepage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\comment_title.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\Btn.png (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan1.png (274 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\icon1.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gedanNew.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan5.png (254 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\rplay_no.gif (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892_0.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzone.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan9.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scon.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\host_mo.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\onepage.js (11 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hgaoqing.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightnavnow1.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topicSearch.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\line.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\mvgedan.js (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_3.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\mvlistbg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_7.jpg (15 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sanjiao.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_7.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\navtan.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diary.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\next_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan7.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\right_j.jpg (520 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbottom.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\subnav.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892_1.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\low.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒøèµç̨ -6007_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pageH.png (932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\allInOneNoTitle.js (63 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\alBg.gif (61 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\original.js (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\loaderror.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mask2.png (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_newsong.jpg (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\close.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\top.png (225 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\search_cat.html (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightIconHover.png (4 bytes)
%WinDir%\Fonts (480 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonegedanpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwomusic2.jpg (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\select.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan11.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan12.png (3 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_vorbis.dll (1281 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqplayhover.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\pic160bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newphomiddle.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songershoucang.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\add.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonemvpage.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\search_cat.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\onepage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sousuo.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newnum1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shiting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newnum1.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIconHover.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\artist.js (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\left_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\version.ini (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_h_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\error.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newnum.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan3.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_iconH.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\page.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\trp.gif (43 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment_title.jpg (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\gray_btn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\blank.gif (98 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan2.png (131 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\line.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996_1.jpg (3 bytes)
%WinDir%\Microsoft.NET\Framework\v4.0.30319 (1536 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_tag.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\mvpage.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topnav.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask1.png (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\fans.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\zz_vip.gif (372 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\mvgedan.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\comment.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tq.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¿áÎÒøèµç̨ -6007.pl.temp (152 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\artistpage.html (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\getRequest.js (985 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\originalcontent.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiaguanzhu.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\fans.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\date.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\adxhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\z.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\kw_scroll.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjlike1.gif (231 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan2.png (131 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\shoujiadimg.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_iconH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\cookie.js (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_13.jpg (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\em.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\5700E407.dat (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\picBg120.png (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_CDReader.dll (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\bang.js (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\download.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\otherbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djnewplayhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModNotify\no_copyright.txt (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading1.gif (98 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\navtan.gif (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_DeFX.dll (62 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btnbottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqplay.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\gedanpage.html (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_wave.dll (784 bytes)
%WinDir%\Temp\Perflib_Perfdata_610.dat (100 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\comment.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtnhover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adx.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hot.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcom.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_DeFX.dll (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan3.png (145 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\music.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_diantai.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\small.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\close_hover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\leftIcon.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ablue2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon1.png (10 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_flac.dll (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\twoartpage.js (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjlike2.gif (323 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ.pl (1056 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\jxjpage.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\rplay_no.gif (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightIcon.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shou.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\icon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow1.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\base.css (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragicon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\jquery-1.4.2.min.js (2392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IN_TTA.DLL (1856 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\album_img.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topnav.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\downloadAD.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\jquery-1.4.2.min.js (1202 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_radio.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\zone.css (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqtongming2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn4.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mv_btn.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\adx.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\right_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\left_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more4.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerdiantai.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan4.png (126 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbottom.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\516ED6BE.dat (2197 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\comment_title.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\topicpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\5239D28D.dat (2526 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_izOzone.dll (12024 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listenicon.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\trp.gif (43 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songerdiantai.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\icon2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\banner.jpg (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dragarrow.png (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\index.css (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\line.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist2.png (1940 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\right_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\page.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shijian.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchnoresult.js (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\twoflpage.js (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\nav_a_z.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonemvpage.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\originalpage.html (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gamers.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\hotzone.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sleft.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\share_icon.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\radio\period_radio.conf (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrolltop.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newpho.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\left_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\277E9CAE.dat (3069 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\rplay_h.gif (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\239E6EC3.dat (2357 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\more3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipsecsice.jpg (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\topiccom.js (21 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\select.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\originalpage.html (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\hsot_xuan.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\page.png (1918 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addH.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\rightnavnow.gif (2 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\dsp_izOzone.dll (2105 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\picBg120.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\jquery.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\dhj.js (45 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\27A51D5A.dat (5011 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\jiazai.jpg (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\index.dat (1460 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\downloadAD.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\6892A63D.dat (4966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone2.js (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\yindao.png (17 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btnmiddle.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\bg_re.png (1846 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djzonehover.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\gray_btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\searchcat.js (4784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nav_a_z.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_play1.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_bang.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwo.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\629C102A.dat (4631 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\erji.gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_ac3.dll (19096 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan7.png (270 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_4.jpg (37 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplayhover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\topicpage.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\play_z.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-ÃÂøÂçºì¸èµç̨ -18239.pl.temp (152 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjsuggest.gif (444 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\baiduplayer.html (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\zone.js (3104 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\listbgt.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\rightnavnow1.gif (1 bytes)
%WinDir%\pchealth\helpctr (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songerbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\jxj.js (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fousplay.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\ape.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djzone.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\right_iconH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\546A54BF.dat (2289 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newphobottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\zonepage.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\xiushi2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shiting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading22.gif (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\originalcom.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask5.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\big.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\onepage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\haveselect.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gamers.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID126.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon.png (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\jiaguanzhu.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\quku.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\mvgedan.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\jiazai.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\leftIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\twoartpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjlike1.gif (231 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒÈȸèµç̨ -6001_0.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\line.png (958 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-³¬¼¶ºÃÌýµÄÓ¢Îĸèµç̨ -18892.pl.temp (149 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\searchpage.html (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_jx_play.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\bang.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\common.css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\songerbtn.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\fans.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\mvpage.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\yellow_z.png (966 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÃÂñÃÂ×é1-ĬÈÃÂÃÂñÃÂ.pl (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topic.js (2336 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\in_wave.dll (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jianjie.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djnewplay.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btnbottom.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shijian.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_jxj.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\topiccom.js (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantgai_cont_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\abg2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music1.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listbgt2.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dsp_omxe.dll (34561 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\play.png (2 bytes)
%Program Files%\Windows NT (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\djnew\djzonehover.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\topiccom.js (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_newsong.jpg (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\comm.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\original.css (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\quku.html (18 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\nav_a_z.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_play1.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan5.png (127 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addlist2.png (970 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\tequanInfo.js (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\icon.png (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mv_btn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoflpage.js (3104 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\right_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Update\updateconf.ini (197 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\b_play_h_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\qqtongming2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\bang.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pageH.png (932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan9.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\kuwobox.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\ÃÂøÂçºì¸èµç̨ -18239_1.jpg (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\dhj.js (3408 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\gray_btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\closed.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\MV.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\search.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\searchpage.html (28 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shou.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\anow.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\gedanpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrolltop.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\version.ini (60 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\3636CFF8.dat (3436 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\MV2.jpg (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\album_img.jpg (30 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan10.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\goListenBtn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\b_play_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\download.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\qq.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\next.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\common.css (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_3.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\bg_re.png (923 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ablue.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\icon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\subnav.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_CDReader.dll (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\jiaguanzhu.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\index.css (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\searchnoresult.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fousplayHover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\fousplay.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\pic100_1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\closed.png (959 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\downloadAD.html (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_1.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\zone2.css (7 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.8.0.Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_x-ww_77c24773 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan11.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\tree.js (56 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\qqtongming2.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\dhj.html (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\ape.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gedanNew.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¾Âµ仳¾Éµç̨ -4459.pl.temp (153 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\fankui.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\music2.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\zone\diantai_fc.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\hdpic.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\searchcat.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn2.gif (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\close_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\index.css (4784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\trp.gif (86 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topicSearch.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipok.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\7C3220AF.dat (3040 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ablue2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\shoujiadimg.jpg (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\albumpage.html (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\js\getRequest.js (989 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjnew2.gif (612 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan8.png (172 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbghover.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mvbg2.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hgaoqing.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\lanmu_img.jpg (19 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\search.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sousuo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addlist2.png (970 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\vipsecsice.jpg (21 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\message2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn3.png (1 bytes)
%Program Files%\Adobe\Reader 9.0\Reader (192 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\diantai_play.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_APE.dll (62984 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID167.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\host_mo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\bodyBg.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\artist.js (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\leftIconHover.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\music2.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\jxjpage.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\download_btn_bg.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_flac.dll (3312 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_5.jpg (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dhjlike2.gif (323 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mvbg.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\class.gif (357 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\message.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbtnhover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1] (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songerbtn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\baiduplayer.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\hotzone.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\diantai_playH.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\47D18107.dat (2713 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\onepage.js (21 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\artistpage.html (20 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btnbottom.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\prev_hover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\kw_scroll.js (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\gedan.js (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\comm.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\commdemo.js (673 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\abg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songershoucanggray.gif (905 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\new_like_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan3.png (145 bytes)
%Program Files%\Common Files\VMware\Drivers (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\top.png (229 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\download_btn_bg.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\loaderror.html (941 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next_hover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_1.jpg (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\right_icon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_2.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\erji.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan4.png (252 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\bang.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\searchnoresult.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.png (1916 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100_1.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiushi.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\addgedanhov.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shou.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\add.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\90ºóµç̨ -4954_1.jpg (196 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\nav_a_z.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\originalcontentpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\topicSearch.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dragicon.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\mo.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\onepage.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightIcon.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jquery.js (6008 bytes)
%Documents and Settings%\%current user%\Local Settings\History\History.IE5\index.dat (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\fousplayHover.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sright.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\searchpage.html (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\download.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\local2014.js (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\close.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\27990426.dat (3656 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\songershoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\bangpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwomusic2.jpg (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\original.js (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\download.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading3.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\newphomiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\gotop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\addlist.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\vipNoTitle_2012-10.css (11 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqplay.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newphomiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID123.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\icon.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\paoBg.png (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\hdpic.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\loading2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\play_z.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\twoartpage.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\close_hover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\high.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\music1.jpg (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\high.jpg (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_4.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\one.css (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-90ºóµç̨ -4954.pl.temp (155 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\originalcontentpage.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\allInOneNoTitle.html (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\diantai_playH.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoartpage.html (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_radio.gif (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\qq.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan7.png (135 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\host_mo.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\more3.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\download.js (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\picBg120.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\nowbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\haveselect.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\dragicon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\z.html (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\prev_hover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\jianjie.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shouting2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_tag.jpg (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan5.png (127 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\originalcontent.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\MV2.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zonepage.html (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\loaderror.html (939 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tanbtn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\qqtongming.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Cache\webcache\2E0CA178.dat (308 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\hotzone.html (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ieerror.jpg (30 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gamers.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\twoflpage.js (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\download_btn_bg.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew2.gif (1224 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\zone2page.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjsuggest.gif (222 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\comment.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan6.png (165 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\blank.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\kuwobox.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\new_btn.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_5.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shijian.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_5.jpg (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\play.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mvbg2.png (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\zz_vip.gif (368 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\203B42C6.dat (2247 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tq.jpg (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan8.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\275F2B1F.dat (5905 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shiting.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\mask2.png (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan8.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btn4.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\original.css (13 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\allBtn.gif (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sanjiao.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\adxhover.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-¿áÎÒÈȸèµç̨ -6001.pl.temp (152 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan7.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\comm.js (11880 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\twoartpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\yellow_z.png (966 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan6.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\one.css (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\hot2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\left_j.jpg (514 bytes)
%Program Files%\kuwo\kuwomusic\bin\kid.ini (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\É˸õç̨ -6003_1.jpg (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\download.js (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listenicon2.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\index.js (601 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\newnum.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\haveselect.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\botom.png (200 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\listenicon.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\add.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan6.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbtn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\common.css (4784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\select.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\Server\config.ini (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_bang.jpg (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\left_j.jpg (514 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\sousuo.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\twoflpage.html (3 bytes)
%Documents and Settings%\All Users\Documents (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\base.css (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\topicpage.html (17 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_vorbis.dll (8560 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_diary.jpg (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwo.jpg (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\lanmu_img.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModNotify\no_rigth.zip (146 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModDownload\icon_tool_ID185.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\nav_a_z.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btntop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\shoujiadimg.jpg (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\line.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\subnav.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btntop.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\add.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\original.js (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\yellow_z.png (1932 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\play.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\twoflpage.html (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songershoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\zonemvgedan.js (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\topic_play_jx.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\originalcontent.js (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting2.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\APPLICATION DATA (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan2.png (262 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\js\allInOneNoTitle.js (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\twoartpage.js (8 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play_hover.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\pic160bg2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\css\two.css (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\dhj.js (54 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollmiddle.png (957 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\gedan.js (19 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\in_mp4.dll (8560 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\90ºóµç̨ -4954_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shouting2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\original.css (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-É˸õç̨ -6003.pl.temp (153 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\index_jxj.jpg (14 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_diantai.jpg (27 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\DD_belatedPNG.js (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\focusbg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\quku.html (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\artistpage.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\mo.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\btn.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\tan1.png (137 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\bz_vip.gif (366 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shoucang.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_jxj.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_diary.jpg (26 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\listbgt2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon2.png (12 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\songershoucanggray.gif (905 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\css\zone.css (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\searchcat.js (601 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\paoBg.png (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\vipok.jpg (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\z.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\small.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\album.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\message2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\KW_MUSICRADIO_PICS\595567 (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\pic100_1.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\mask1.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addgedan.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\rplay_h.gif (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\new_btn2.gif (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\left_icon.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\next.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\jxjpage.html (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\topic.js (31 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan3.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\80ºóµç̨ -4953_1.jpg (196 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mvbg.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tan7.png (135 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\ÃÂøÂçºì¸èµç̨ -18239_0.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒÈȸèµç̨ -6001_1.jpg (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\tips_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\DD_belatedPNG.js (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pic160bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\nowbg.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\xiushi2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\search_cat.html (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\jxj.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiuchang.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\btn3.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\botom.png (200 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Res\cache\HTTPTMPCACHE\245D4C1D.dat (5672 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\more3.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\topic_jx_play.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\gedanNew.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\next.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tiyan_5.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\tips_play_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\bang.png (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\feedback.jpg (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_1.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\mvbg2.png (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\commdemo.js (11040 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\navtan.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\mo.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\base.css (1568 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrollbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\index.js (9984 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\focusbtn.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new2.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newphobottom.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\pic160bg2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\icon1.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\top_icon_btn.png (7 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan4.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\banner.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\original\icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_12.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading3.gif (49 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\kw_scroll.js (20 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\js\album.js (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\kuwomusic.jpg (9 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\allBtn.gif (5 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\allInOneNoTitle.html (32 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\shoucang.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\share_icon.png (5 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollmiddle.png (1914 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¾Âµ仳¾Éµç̨ -4459_1.jpg (196 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\twoflpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\imgs\pic100.png (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjnew1.gif (1226 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\kuwomusic.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\Conf\user\sprdtasks.ini (446 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\loading22.gif (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\blank.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\tanbtn.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\download.css (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\ablue.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\newnum.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sanjiao.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIconHover.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\albumpage.html (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\Pic\¿áÎÒøèµç̨ -6007_1.jpg (3 bytes)
%WinDir%\WinSxS\Policies\x86_Policy.9.0.Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_x-ww_b7353f75 (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantai_tit_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\listbgt.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\top_icon_btn.png (7 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\ieerror.jpg (15 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\focusbg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\gotop.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\tips_play.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan5.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\xiushi2.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\rightnavnow.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tiyan_3.jpg (37 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\hot2.gif (1 bytes)
%System%\wbem\Logs (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\hsot_xuan.jpg (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\scrollbg.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon.png (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\imgs\pic100.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModPlayList\²¥·ÅÃÂñÃÂ-ÒôÀÖµç̨-Ò»ÈËÒ»Ê׳ÉÃûÇúµç̨ -4996.pl.temp (152 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\erji.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\ablue.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\concertbanner.jpg (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan12.png (3 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\icon2.png (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\tree.js (56 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\adxhover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\shouting.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\date.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\new_like_icon.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\btnmiddle.gif (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\vipMbox_new\vipMbox_new\img\tequan2013_8.jpg (18 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\shou2.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\b_play_bg.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\dhj.html (17 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\scrollbottom.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_4.jpg (784 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\scrolltop.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\mvpage.html (6 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addgedanhov.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\css\two.css (24 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\dhjnew2.gif (612 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\topic\line.png (958 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\imgs\pic100.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\hgaoqing.gif (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\sleft.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\zone\diantgai_cont_bg.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_diantai.jpg (27 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\new_btn.png (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\zonepage.html (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\playlist.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\original\banner.jpg (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\tan6.png (330 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\js\DD_belatedPNG.js (12 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\anow.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\add.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\nav_a_z.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\index_newsong.jpg (10 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\MV.jpg (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\goListenBtn.png (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\abg2.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\sleft.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\error.html (2 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\originalcontentpage.html (4 bytes)
%Program Files%\kuwo\kuwomusic\bin\plugin\IN_TTA.DLL (57 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\dhjlike2.gif (646 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\js\searchnoresult.js (3 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\goListenBtn.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\kuwomusic.jpg (9 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\tips_play.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\tips_play_hover.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vipMbox_new\img\tequan2013_2.jpg (16 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\index_tag.jpg (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\kws12.tmp (406 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\nowbg.gif (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\djnew\djnewplay.png (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\leftIcon.png (8 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\leftIcon.png (4 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\zip\temp\netsong\netsong\img\addH.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\topic\singer.png (1 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\loading1.gif (49 bytes)
%Documents and Settings%\All Users\Application Data\kuwodata\kwmusic2013\ModuleData\ModWebUpdate\res\netsong\img\original\bg_re.png (923 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\message.png (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\netsong\img\topic\line.jpg (2 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#js.miaozhen.com\settings.sxx (208 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\q[1].k (4920 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[6].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\mc[1].htm (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[2].txt (960 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[4].htm (1508 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\crossdomain[1].xml (264 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\f[1].page (1114 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@miaozhen[1].txt (603 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\setCookie2013[1].htm (2 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[2].txt (1668 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\swfobject[1].js (562 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@kuwo[1].txt (1263 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\#SharedObjects\QEA5Z3QJ\js.miaozhen.com\m.sxx (179 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[1].htm (684 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\c[1].swf (469 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[2].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[9].htm (685 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\swfobject[1].js (10 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQISTQM\kuwofx[1].js (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[3].htm (686 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\OPQNSD2J\crossdomain[1].xml (215 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index1[1].htm (2 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[8].htm (686 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[5].htm (685 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mookie1[1].txt (162 bytes)
%Documents and Settings%\%current user%\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx (543 bytes)
%Documents and Settings%\%current user%\Cookies\index.dat (12532 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\index2[1].htm (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\4DQJW9YN\index[7].htm (1502 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WLMVCPYN\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@mookie1[2].txt (364 bytes) - Delete the following value(s) in the autorun key (How to Work with System Registry):
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kwmusic" = "%Program Files%\kuwo\kuwomusic\Kwmusic.exe /autorun" - Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
- Reboot the computer.
*Manual removal may cause unexpected system behaviour and should be performed at your own risk.